docs: F-037, the ingress corrections, and the priority order reversed
HANDOFF section 4 said WORK-ORDER-004 was pending and that CIVICVS could not see any of this work. It was rewritten thirty-two minutes after1fdb115closed the ingress, in the same session, against the work order's old state rather than its new one -- so HEAD described a world where the thing you were already looking at did not exist. Section 11 row 7 carried the same staleness. Both corrected, and the correction says how it happened, because section 0 was added to prevent exactly this and did not. Three things1fdb115recorded as unsettled were never promoted into section 11 and are now rows 8 through 10: TLS renewal has never been observed to succeed for this name and is first due before 2026-12-10; the composer has no acceptance criteria of its own, only the path to it does; and the service is world-reachable and unauthenticated, which section 4 item 5 called a conscious decision to be made before publishing and which publishing has now made due. Priority items 1 and 2 reversed. The original case for authorship first was that records made before the field exists can never be attributed. That was too strong, and too strong because the field is excluded from both hashes: a record regenerated later keeps its input_id. What it does not keep is build_id, which covers Shapely and GEOS, and boolean results on near-degenerate geometry shift between GEOS releases -- the F-034 mechanism. Attribution is recoverable, not free. The residual argument stands and the field landed first at48d5665. Recorded under item 2, because it is the first thing STL export runs into: length_view is not in COMMON_GROUPS, so the Full Length branch is unreachable from the composer and every export would silently be a 100 mm preview. The sweep must equal model_length_mm(p), already published as LENGTH_MM, or the record's VOLUME_MM3 and MASS_G describe a different object than the file beside them. Also split the roadmap's STL/STEP bullet: STEP needs the kernel, STL does not, and one line implying both was left behind by the section 5 correction. F-037: a tar stream rooted at "." re-owned the repository root. tar x ran as root and applied the "." entry's ownership to /var/www/mechcomp; the chown that followed named only src and tests. Everything below the root was correct, so 547 tests passed and only git noticed. Corrected by chown on one path, owner only, no -R. safe.directory was not added -- that is F-008 and would have masked this and every later instance. Two of F-037's three consequences are process defects of mine rather than facts about the environment. The verification step ran before the landing that destroyed it, so a git status ahead of the breaking step reads as a pass -- the F-027 pattern in a new place. And section 7 says record a failure before correcting it; I corrected first. Both recorded rather than quietly fixed. PROCESS section 3 gains two REQs, because the delivery path as documented produces F-037 every time: the chown must name the directory the files land in, and a tar transport must name its top-level directories rather than root at ".". pct push is simpler for a single file and cannot reproduce it at all. Section 8 gains the bytecode rule: PYTHONDONTWRITEBYTECODE=1 and clear __pycache__ between mutations. A stale .pyc masked a real defect once and every mutation result reported before that was optimistic by an unknown amount. A mutation surviving on stale bytecode is indistinguishable from one surviving on a weak test. Open question 11 is new and is CIVICVS's: ct-baseline.sh exits 0 with the F-037 condition present, so by section 9a the ownership of a service working tree is not part of the container standard. Whether it should be is a decision about host property covering three projects.
This commit is contained in:
@@ -130,6 +130,18 @@ always the same, so nothing has to be remembered between sessions.
|
||||
repository operations run as the service user, and a root-owned file inside the
|
||||
tree causes exactly that failure later.
|
||||
|
||||
**REQ (F-037)** — The `chown` must name the directory the files landed *in*, not
|
||||
only the files. A tar stream rooted at `.` carries an entry for the destination
|
||||
directory itself, and `tar x` as root rewrites that directory's ownership.
|
||||
Naming only the payload subdirectories leaves the repository root `root:root`,
|
||||
and git then refuses the worktree with the F-008 message — which invites the
|
||||
F-008 mistake as its own remedy. Fix the owner. Never add `safe.directory`.
|
||||
|
||||
**REQ (F-037)** — Verification that depends on the repository being intact must
|
||||
run *after* the landing, and a landing step must not be able to destroy the
|
||||
check that would have caught it. A `git diff` placed before the step that broke
|
||||
git reports nothing wrong and looks like a pass.
|
||||
|
||||
**REQ** — An assistant delivering files states, in this order: what the archive
|
||||
contains, where it expands, what it overwrites, and how to verify it landed
|
||||
correctly. "Overwrites nothing" is a claim that must be checked, not assumed.
|
||||
@@ -139,6 +151,11 @@ correctly. "Overwrites nothing" is a claim that must be checked, not assumed.
|
||||
Prefer one tarball that expands over the existing tree. Individual file paths
|
||||
are error-prone to transcribe through a file manager.
|
||||
|
||||
Name the payload's top-level directories explicitly, when creating the archive
|
||||
and when extracting it: `tar cf - -C <dir> src tests`, never `-C <dir> .`. The
|
||||
second form is what produced F-037. For a single file, `pct push` is simpler and
|
||||
cannot reproduce it at all.
|
||||
|
||||
### Delivering a single small file
|
||||
|
||||
For anything that fits comfortably on screen, a heredoc in the `srv-b` shell is
|
||||
|
||||
Reference in New Issue
Block a user