review(shot): M2 PASS — all 19 enrolled cold-verified. 18/18 final PNGs Read (real, representative, credential-free; every login/setup form EMPTY-field, mattermost real login NOT interstitial, keycloak/immich/etc SPA paint-race fixed); no verdict/level regression (all pass at baseline); 2 GENUINE drone !testme (370 immich#2 comment 14321 + 371 plausible#3 comment 14322, bridge-triggered per ccci-bridge logs, NOT manual); durations 199→198/209→166 no balloon; R7 intact (call site outside-deploy+double-wrapped+untouched by shot phase, capture swallows, 60s budget); dashboard/screenshot/badge live 200; screenshot 12/12 + card 10/10 unit tests GREEN cold on real harness; no_secret_leak=true. bluesky N/A re-confirmed; mumble N/A-variant AGREED (reverses M1 on new evidence: connect-dialog DOM absent + perpetual spinner). A1 closed. No VETO — DoD handshake satisfied, Builder may write ## DONE.
All checks were successful
continuous-integration/drone/push Build is passing

This commit is contained in:
autonomic-bot
2026-06-11 07:18:05 +00:00
parent 196156e497
commit 2b54adbe46

View File

@ -111,3 +111,74 @@ Watch-list for M2 (so the Builder has it early — NOT blocking M1):
5. M2 requires ≥2 proof runs via the drone `!testme` path + me Reading *every* final PNG.
Did not read JOURNAL-shot.md before this verdict. No finding filed (audit is accurate). No VETO.
---
## M2: PASS @2026-06-11T07:17:53Z — all screenshots working (cold-verified from scratch)
Verified independently from a cold start (my own clone, my own scp/Read/re-runs; did NOT read
JOURNAL before this verdict). Claim commit 196156e. Every M2 DoD item checked:
**1. Every final PNG Read (18/18) — real, representative, credential-free.** Pulled each PNG by scp,
Read it with the image tool, byte-size matched the claim on all 18:
- Fixed-class (10): immich 234351B "Welcome to Immich" onboarding; plausible 64132B real
registration form (EMPTY fields); keycloak 215587B real "Sign in to your account" (EMPTY) — was
the 8764B "Loading Admin Console" spinner at M1, settle fix resolved it; cryptpad 57310B real
landing + doc-type picker; lasuite-meet 225686B real video-conf landing; lasuite-docs 284769B real
Docs landing; lasuite-drive 132037B real "Fichiers" landing; n8n 26433B "Set up owner account"
(ALL fields EMPTY — secret-safe, now deterministic); mattermost-lts 178367B **real "Log in to your
account" form (EMPTY) — NOT the byte-identical interstitial** (hook v2 click-through works — my
sharpest watch-item, resolved); mumble 7980B loader spinner (see §N/A).
- Healthy-class (8): ghost 444183B blog landing; hedgedoc 131967B landing; discourse 66121B forum +
welcome topic; custom-html 35707B "Welcome to nginx!" (honest fresh-install); custom-html-tiny
12950B seeded content; mailu 33800B sign-in (EMPTY); matrix-synapse 33296B "It works!"; uptime-kuma
30858B "Create your admin account" (EMPTY).
Every login/setup form has EMPTY fields — NO generated credential is shown anywhere. Secret-safety
cardinal guardrail holds across all 18.
**2. No verdict/level regression.** All 10 proof runs status=pass at their baseline level (immich
/plausible/keycloak/cryptpad/lasuite-*/n8n/mumble=4, mattermost-lts=2). screenshot field populated
on every one. no_secret_leak=true on every proof run I sampled (370/371/keycloak/n8n/mattermost
/mumble).
**3. ≥2 genuine drone `!testme` proofs — confirmed end-to-end, NOT manual.** ccci-bridge_app logs:
`[poll] triggered build 370 for immich@107d7220 (PR #2, comment 14321) by autonomic-bot` and
`...build 371 for plausible@13458fac (PR #3, comment 14322)...`, both `reflected outcome ...:
success`. The bridge polled Gitea, found real !testme comments, triggered the builds, reflected
verdicts back — the full comment→build path. Drone params {RECIPE,PR,REF,SRC}, event=custom,
trigger/sender=autonomic-bot — matches the Phase-1c bridge-!testme fingerprint (REVIEW-1c:110).
**4. Durations unaffected (no balloon).** Drone same-recipe pre/post: immich 199s→198s, plausible
209s→166s (faster — capture no longer burns 45s failing on the 500). Screenshot step wait budget =
60000ms exactly (unit test_wait_budget_within_step_cap + my own cold probe). ≤~60s holds.
**5. R7 (cosmetics never block) — intact.** Call site run_recipe_ci.py ~1024-1037 is OUTSIDE the
deploy try/except AND double-wrapped in its own try/except (`_scrub`-bed log) — and git log proves
NO shot-phase commit touched run_recipe_ci.py (call site unchanged). capture() swallows everything →
None → placeholder. I cold-probed the new helpers independently: _settle swallows all exceptions,
_snap keeps the larger frame (A1 fix, 5/5), 60s budget — 9/9+5/5 pass. Screenshot unit suite 12/12
+ card suite 10/10 ran GREEN cold on the real harness (cc-ci-run) from my scp'd clone.
**6. Dashboard/card/badge render — live 200.** GET dashboard / → 200; runs/370+371/screenshot.png →
200 image/png; badge/immich.svg + badge/plausible.svg → 200 image/svg+xml.
**7. N/A set (19/19 enrolled, no omissions) — AGREED.**
- bluesky-pds → N/A, re-confirmed at M2 (ab-bluesky-pds-oldmain: install=fail, level=0,
screenshot=null → placeholder correct; upstream MODULE_NOT_FOUND still broken, DEFERRED).
- mumble → N/A-variant, AGREED — **this reverses my M1 "NOT N/A" stance, on NEW evidence not
available at M1.** rankenstein/mumble-web:0.5 renders no usable UI for an anonymous browser:
connect-dialog DOM genuinely absent (probe4 console: `#connect-dialog_input_address ... did not
match any element`), perpetual loading-container spinner at 5/15/30/60/90s (probe2) — corroborated
by my own Read of the 7980B spinner PNG. The loader frame is the literal web-surface reality every
visitor gets; mumble's actual function (voice) is fully protocol-tested; fix needs a recipe/overlay
change (out of scope, guardrail prefers upstream). Documented in DEFERRED with an upstream
question. NOTE (not a defect, not a veto): the dashboard shows the honest loader frame rather than
the "no screenshot" placeholder — acceptable as a documented, agreed limitation, NOT a healthy-app
screenshot.
Finding A1 (blank-retry regression) was filed, fixed (7ad7d1f), and CLOSED after my cold re-test.
No open findings. No fabricated reads — every matrix/claim value matched what I independently
observed. **M2 PASS. No VETO.** With M1 PASS (ae10b55) + M2 PASS both fresh and A1 closed, the DoD
handshake (§6.1) is satisfied — the Builder may write `## DONE` to STATUS-shot.md.
(Consulted no JOURNAL-shot.md before forming this verdict.)