From 13d1b459fc01b4a44b39b8d1225fafec19a45a3f Mon Sep 17 00:00:00 2001 From: archipelago Date: Tue, 6 Oct 2026 23:39:39 -0400 Subject: [PATCH] Record three-node purchase deployment and remaining live acceptance gates --- docs/https-app-gate-followup-20261006.md | 25 ++++++++++++++++ docs/paid-content-recovery-followup.md | 37 ++++++++++++++++++++++++ 2 files changed, 62 insertions(+) diff --git a/docs/https-app-gate-followup-20261006.md b/docs/https-app-gate-followup-20261006.md index a37a36e9..17bde711 100644 --- a/docs/https-app-gate-followup-20261006.md +++ b/docs/https-app-gate-followup-20261006.md @@ -109,3 +109,28 @@ staging/rollback before using it as repair. Preserve existing CA identities and custom certificates; do not blindly regenerate trust. A client must explicitly trust the node's public CA for normal browser validation. Keep normal-trust acceptance open pending a tested provisioning repair and the operator's access URL. + +### Dev nginx reload mismatch found during the integrated purchase rollout + +On 7 October UTC, the new backend wrote its playback proxy route but requests +still reached the old SPA. `nginx -t` and `systemctl reload nginx` both reported +success; the master error log showed wildcard IPv4/IPv6 port 443 bind failures. +Tailscale owned its tailnet port 443, while the old nginx workers still served the +original address-specific LAN/WireGuard listeners. The wildcard disk configuration +was already present in the pre-deployment backup. + +`sites-available/archipelago` and `sites-enabled/archipelago` were separate regular +files. Both were backed up, and only their canonical wildcard HTTPS listeners +were changed to the two addresses already served by nginx: 192.168.63.240 and +10.44.0.1. Validation and reload then succeeded in practice: the new proxy returned +401 for unauthenticated GET and 405 for HEAD/POST, and owner RPC access passed. +Tailscale was not restarted or reconfigured. Original configs are in the dev +`support/integrated-purchase-backend-20261007T030942Z-2791483` backup directory. + +Durable source/upgrade handling remains required before release: preserve the +recognized address-specific node-HTTPS profile when a template is installed, +account for enabled files that are not symlinks, and verify effective route/listener +behavior rather than treating a successful reload command as proof that nginx +accepted the new configuration. The existing per-address retarget helper ignores +wildcard-only configs. This live repair is not a claim that the general migration +or IPv6 HTTPS/companion trust acceptance is complete. diff --git a/docs/paid-content-recovery-followup.md b/docs/paid-content-recovery-followup.md index 70fd13cd..99dde93f 100644 --- a/docs/paid-content-recovery-followup.md +++ b/docs/paid-content-recovery-followup.md @@ -735,3 +735,40 @@ The deployable UI and evidence are preserved under Its index SHA256 is `6fd81faf0d057b1c689610ebfbd04193071e282d85e27ec07b34f927525be1f5`. It requires the matching purchase backend and is not yet deployed. The prior qualified backend and dashboard remain live on dev, Yaya and Framework. + +### Integrated purchase candidate deployed — 7 October UTC + +Local source commit `49703d7e` passed 1,889 isolated backend tests with zero +failures and five existing skips; 406 inputs remained unchanged through the +22m24s production build. Binary SHA256: +`f150ffd6007639a672844a8d450c9564dc41d820440655319d67d3df2a332250`. +The matching dashboard's 1,375 tests, typecheck, build and 21 local responsive +cases are recorded above. + +Both layers are now deployed to dev, Yaya and the actual Framework. Health, +node identity, remembered session key, private node catalog, app container IDs +and start times, and stopped/uninstalled decisions were preserved on all three. +Each layer has its own rollback receipt. The new route returns 401 to anonymous +GET and 405 to HEAD/POST on all three nodes. Owner RPC passed on dev/Yaya; +Framework's normal authenticated browser acceptance still needs TOTP. + +Actual Apps screens passed at 390px and 1440px on dev and Yaya, with no JavaScript +page errors or horizontal overflow. Initial smoke failures were harness selectors +for hidden responsive tabs/images; screenshots showed the rendered app grid. +Visible selectors were corrected without extending timeouts; earlier logs remain. +Dev also required the pre-existing nginx/Tailscale listener correction documented +in `https-app-gate-followup-20261006.md`. Yaya's V4V remained running and its +private signed catalog was byte-for-byte preserved. + +All deployment scripts, receipts and browser/endpoint evidence are retained at +`~/.local/state/archipelago/release-qualification/deployed-purchase-49703d7e/`. +No new real payment, OTA, public catalog or source publication occurred. + +This is incremental deployment, not complete payment/rental acceptance. Durable +external-invoice and on-chain recovery remain unfinished. Large-film rental +activation remains off: the current integrity guard can scan the whole film on +every range request, exceed the header deadline and commit a lease after timeout. +The separate readiness/index work must remove those scans from request paths, +verify chunks and start the original clock only after explicit ready/start. +IndeeHub private app packaging, distributed announcement delivery and actual +registration/payment/playback acceptance remain open.