claim(M1): canonical sweep machinery built + live-proven on custom-html
continuous-integration/drone/push Build is passing
continuous-integration/drone/push Build is passing
M1 (machinery works locally, each piece proven) — code HEAD d4cc9e4, unit suite 295 passed:
- M1.1 tagged-promote gate + promote-tested-version: live proof-A wrote a fresh canonical
(commit df2e273 = the tag commit, correcting samever's main-HEAD 2b82eba); live proof-C
green-untagged → 0 promotes, canonical byte-identical (tagged-gate blocks untagged).
- M1.2 sweep_decision (version-keyed trigger) + vendored faithful recipe-mirror-sync.sh
(smoke-tested: faithful no-op main/tags push, closed merged-upstream PR #2, left PR #5);
nightly_sweep rewritten (mirror_sync -> trigger -> run_on_tag). Live SKIP demo on custom-html.
- M1.3 all 21 used-recipes enrolled. M1.4 hollow-sweep fix (CCCI_REPO=/etc/cc-ci). M1.5 weekly timer.
- M1(A) reattach: live proof-B --quick reused the retained volume green; known-good unchanged.
Evidence + verify recipes in STATUS-canon.md; reasoning in JOURNAL-canon.md; DECISIONS appended.
Gate: M1 CLAIMED, awaiting Adversary.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
69f59fdcc5
commit
626badd333
@@ -92,3 +92,41 @@ disk (orchestrator) rather than silently drop recipes if it binds.
|
||||
Retirement requires plausible's canonical to actually land at its latest green release so the dynamic
|
||||
resolver picks the right base — so this is sequenced AFTER M2 promotes plausible. Keep the pin if
|
||||
plausible can't go green dynamically (record why).
|
||||
|
||||
## 2026-06-17 — M1 built + live-proven (CLAIMED)
|
||||
|
||||
All M1 code landed (HEAD d4cc9e4). Reasoning behind the choices:
|
||||
|
||||
- **Tagged-gate computes `tagged` at the call site, not inside the gate** — keeps
|
||||
`should_promote_canonical` pure (the Adversary anti-anchoring + the existing unit-test contract).
|
||||
`is_released_version` lives in warm_reconcile (owns version logic + recipe_tags I/O).
|
||||
- **Promote the TESTED version (divergence fix, d4cc9e4):** the Adversary's pre-claim probe flagged
|
||||
that the gate checks `head_version` but promote recorded `latest_version(recipe_tags)`. Live proof-A
|
||||
made this concrete and favourable: the OLD record had commit `2b82eba` (a merge-to-main commit),
|
||||
but the tag `1.13.0+1.31.1` actually points to `df2e273`. Recording the tested version's head_ref
|
||||
now writes the TAG commit — strictly more correct. Sweep path was already safe (head==tag), but the
|
||||
manual `RECIPE=<r>` path needed it.
|
||||
- **Why a vendored mirror-sync script, not the nix-store open-recipe-pr.sh:** the recipe clones on
|
||||
cc-ci have INCONSISTENT remotes (n8n: origin=mirror; mumble: origin=coopcloud; ghost/discourse:
|
||||
origin=mirror, no `upstream`). open-recipe-pr.sh assumes origin=coopcloud → would force-sync mirror
|
||||
main to *mirror* main (no-op) for most. The vendored `scripts/recipe-mirror-sync.sh` pins an
|
||||
explicit coopcloud `upstream` remote from the recipe name, syncs main+TAGS (canon needs upstream
|
||||
tags for the trigger), and authes via the bot token (self-contained, not host .git-credentials).
|
||||
Behaviour matches the phase's described open-recipe-pr.sh --reconcile-only (faithful, close
|
||||
merged-upstream PRs, leave unrelated). See DECISIONS.
|
||||
- **Why test the TAG via checkout+CCCI_SKIP_FETCH (run_on_tag), not just REF=tag:** REF alone (no SRC)
|
||||
takes fetch_recipe's `abra recipe fetch` branch (ignores REF) AND would set `ref` → should_promote
|
||||
blocks. Staging the tag in the clone + CCCI_SKIP_FETCH makes head=tag with REF empty → promote
|
||||
allowed, and exercises the real "cold on the tagged release" path.
|
||||
|
||||
### Live proof evidence (cc-ci, /root/canon-verify @ d4cc9e4)
|
||||
- proof-A (promote): canonical.json fresh ts 065027Z, commit df2e273 (=tag commit). Note: because
|
||||
custom-html canonical already == latest, run_on_tag here re-promoted an EQUAL version → the samever
|
||||
step-back fired (base 1.11.0+1.29.0). That is an artifact of bypassing the trigger for the proof;
|
||||
the REAL sweep SKIPs equal-version (sweep_decision), so the step-back never fires in the sweep — to
|
||||
be shown live in M2 (canonical(older)→new tag, base=canonical, no step-back).
|
||||
- proof-B (reattach): --quick reattached the retained volume, green (4 tests passed), known-good
|
||||
version+commit UNCHANGED (df2e273); ts re-stamped only by the idle-status write (write_registry
|
||||
stamps ts on every status write) — NOT a promote.
|
||||
- proof-C (untagged→no-promote): green cold run (level 5/5) on an untagged head (label 1.13.1+1.31.1)
|
||||
→ 0 promote log lines, canonical.json byte-identical before/after. Tagged-gate works live.
|
||||
|
||||
Reference in New Issue
Block a user