Conformance updates.

This commit is contained in:
2026-08-18 10:33:26 -04:00
parent c7e32d8e07
commit 6967eef59c
5 changed files with 319 additions and 15 deletions
+99 -1
View File
@@ -6,7 +6,7 @@ Compiler environment.
| | |
|---|---|
| Scope | All instances. Staging entries are marked `srv-b`. |
| Updated | 2026-08-17, after work order 003 |
| Updated | 2026-08-18, after repository seeding and container standardisation |
| Method | `PROCESS.md` section 7 |
| Rule | Append only. Never edit an entry except to add a `Resolution` line. |
| Numbering | Sequential, never reused. See §0 on the renumbering. |
@@ -634,6 +634,100 @@ device class.
---
### F-029 — pip cache written into the repository working tree
CT 100. Repository seeding.
**Observed:** `git add -A` staged 465 files where 28 were expected. The extra
437 were `.cache/` — pip's download cache.
**Cause:** **Proven.** The service user's home is the install directory, so
`$HOME/.cache` **is** `/var/www/mechcomp/.cache`. `make deps` wrote there.
**Correction:** `.cache/`, `.local/`, `.ssh/`, `.gitconfig` and `.lesshst`
added to `.gitignore`; the cache unstaged before committing.
**Consequence:** Setting the service user's home to `install_dir` is correct
and matches YunoHost convention, but it means **any tool writing to `$HOME`
writes into the working tree**. `.gitignore` must anticipate that from the
first commit.
Method note: reading the staged list by eye showed nothing wrong. Counting it
and grouping by top-level directory found the problem immediately. **Verify by
counting, not by scanning** — a long correct-looking list is exactly where an
extra 437 files hide.
---
### F-030 — a network command in a work order could hang indefinitely
`srv-b`. Repository seeding.
**Observed:** An SSH authentication test was issued with neither
`ConnectTimeout` nor `BatchMode`. Gitea's SSH is on port 42022, so the attempt
on 22 hung and the operator had to interrupt it.
**Cause:** **Proven.** Missing timeout options, and an incorrect assumption
about the port.
**Correction:** Re-issued with `-o ConnectTimeout=10 -o BatchMode=yes -p 42022`,
after a `timeout`-wrapped reachability probe that could not hang.
**Consequence:** **Every network command in a work order carries an explicit
timeout.** A command that can hang strands the session, and the operator cannot
tell a hang from slow progress. Reachability is probed with `timeout` before any
client is invoked.
Also recorded, having been got wrong twice: Gitea **deploy tokens** are
account-level under user Settings, not repository settings. Repository-scoped
credentials are **deploy keys**. SSH here is on **42022**, so remotes need
`ssh://git@host:42022/owner/repo.git` — the `git@host:path` shorthand cannot
carry a port.
---
### F-031 — a standard was asserted from a check that never examined the thing
CT 100, CT 101, CT 102. Container standardisation.
**Observed:** The architect stated that CT 100 and CT 101 had no mail agent, and
standardised CT 102 by purging Postfix to match. The first run of
`ct-baseline.sh` reported a mail agent installed on **both** CT 100 and CT 101.
CT 102 — the container just "corrected" — was the only one conforming.
**Cause:** **Proven.** The earlier assertion came from inspecting Postfix
configuration and `/etc/aliases` **on `srv-b`**, during work order 002. That
established what the host does. It said nothing about the containers, and the
containers were never examined.
**Correction:** Postfix purged from CT 100 and CT 101. Queues were checked first
and both were empty, so nothing was lost. Re-run: 62 passed, 0 failed.
**Consequence:** **A standard asserted from a proxy observation is not a
standard.** The check must examine the thing being standardised. This is the
same class as F-027 — a result that cannot distinguish the case it claims to
test — but reached through inference rather than through shell semantics.
It is also the justification for `ct-baseline.sh` existing. Divergence had been
discovered by asking, one property at a time, whenever something behaved oddly.
That does not terminate: every check finds a new difference because nothing
states what "the same" means. The script is that statement, and it disagreed
with the architect on its first run.
---
### F-032 — the same host defects were discovered independently by two projects
`srv-b`. Cross-project.
**Observed:** Kane Fabric's `INFRASTRUCTURE_BASELINE.md`, written independently,
records `nesting=1,keyctl=1` against `226/NAMESPACE` systemd failures, and that
minimal Debian CTs lack a generated `en_US.UTF-8`. These are F-003 and F-004,
found again on the same host, in different words, at a different time.
**Cause:** **Proven.** Both are properties of the Proxmox/Debian 12 host, not of
either application. Neither project's documentation was visible to the other.
**Correction:** None required — both projects reached the correct conclusion.
**Consequence:** **Host-level requirements belong to the host, not to whichever
project discovered them first.** `ct-baseline.sh` encodes them once and checks
every container on `srv-b` regardless of owner, so the third project does not
have to discover them a third time.
Note that `keyctl=1` is required **only where Docker runs**. CT 101 was proven
to work with `nesting=1` alone (F-003). Kane Fabric's baseline currently
specifies both; if CT 102 runs no containers, `keyctl` can be dropped.
---
## Open, not closed
| # | Status |
@@ -649,5 +743,9 @@ device class.
| F-026 | **Corrected** 2026-08-17. Reboot persistence proven. |
| F-027 | **Corrected** 2026-08-17. Applies retroactively to F-018's proofs. |
| F-028 | **Corrected** 2026-08-17. |
| F-029 | **Corrected** 2026-08-18. |
| F-030 | **Corrected** 2026-08-18. |
| F-031 | **Corrected** 2026-08-18. Root cause of `ct-baseline.sh`. |
| F-032 | **Closed** 2026-08-18. No correction required; encoded in `ct-baseline.sh`. |
Everything else is closed with a proven cause and a proven correction.