diff --git a/machine-docs/REVIEW-samever.md b/machine-docs/REVIEW-samever.md index a3dd93c..0b4f59b 100644 --- a/machine-docs/REVIEW-samever.md +++ b/machine-docs/REVIEW-samever.md @@ -9,7 +9,44 @@ ## Gate verdicts -(none yet — waiting for Builder M1 claim) +### M1: PASS @2026-06-17T04:27Z + +Cold-verified from own clone `/srv/cc-ci/cc-ci-adv` @ b29bb3f (claim c5a0d20). Implemented + unit-tested +gate. Independent (not trusting Builder's tests) — re-ran the suite AND wrote my own break-it probes. + +**Evidence:** +1. **Unit suite cold:** `pytest tests/unit/test_upgrade_base.py -v` → **13 passed** (8 prior unchanged + + 5 new). The 8 prior (override / EXPECTED_NA / main-tip / head==main-tip skip / no-predecessor / + other-rung) still green ⇒ override/ref/skip paths untouched. +2. **My own primitive probes** (direct import, adversarial inputs): + - `newest_older_version` strictly-older semantics: suffix tags (`-rootless`) ordered correctly; + head-version BETWEEN tags → newest strictly older; **equal-key tag EXCLUDED** (1.0.0+3.5.3 vs + 1.0.0+3.5.3 → None); head-is-oldest → None; None/empty safe; recipe-major ordering beats app + (9.9.9+99.0.0 < 10.0.0+1.0.0). ✓ + - `_VERSION_LABEL_RE`: parses quoted, unquoted, single-quoted labels; **`.chaos-version` → None** + (not matched); chaos-then-real picks the real label. ✓ +3. **My own resolver-chain probes** (monkeypatched canonical + recipe_tags, direct `resolve_upgrade_base`): + - **canonical==head (TEETH):** `10.8.0+26.6.3` → base `10.7.1+26.6.2`, `kind=version`, + `reason="step-back: …"`; asserted `version != head` AND `version_key(base) < version_key(head)`. + **Never a same-version no-op; strictly older.** ✓ + - **canonical≠head (version-bump path):** uses canonical unchanged AND `recipe_tags` is NOT consulted + (patched it to raise — no raise) ⇒ discourse #4 / version-bump PRs cannot be perturbed by this gate. ✓ + - **canonical==head, no older tag:** `kind=skip`, reason `"base == head (…) and no older published + predecessor"` ⇒ declared, not silent. ✓ + - **head_version=None (compose unreadable):** canonical stays primary (prevb behavior preserved). ✓ +4. **sort_versions refactor behavior-preserving:** `version_key` lifted verbatim from the old inline + key; `test_warm_reconcile.py` version-ordering tests pass (8 passed; single failure unrelated). +5. **Pre-existing failures disclosed honestly:** `test_meta::test_generated_doc_table_in_sync` and + `test_warm_reconcile::test_traefik_spec_is_stateless_with_setup` FAIL on **parent 279d84d** too + (re-ran in a temp worktree — both fail there); samever diff touches neither SPECS nor the doc table. + Out of scope, NOT a regression. + +**F1d-2:** step-back returns `kind="version"` ⇒ inherits the same pinned-tag deploy path as any +canonical base (no new deploy code) — the on-disk tree is checked out at the pinned older tag. This is +an M1 (unit) claim; the REAL pinned-deploy proof belongs to **M2** (live CI, evidenced base