From 7c4169867c18afcb743ef88353ed3f4e2796dcf9 Mon Sep 17 00:00:00 2001 From: archipelago Date: Wed, 30 Sep 2026 10:52:41 -0400 Subject: [PATCH] docs: consolidate release scope and record migration recovery checks --- docs/gitea-portainer-repair-20260930.md | 21 +++++++++++++++++++++ docs/next-release-20260930.md | 2 +- docs/pr-review-20260930.md | 15 +++++++-------- docs/repair-release-20260929.md | 9 ++++++--- 4 files changed, 35 insertions(+), 12 deletions(-) diff --git a/docs/gitea-portainer-repair-20260930.md b/docs/gitea-portainer-repair-20260930.md index 60d8b45d..a1757616 100644 --- a/docs/gitea-portainer-repair-20260930.md +++ b/docs/gitea-portainer-repair-20260930.md @@ -144,3 +144,24 @@ The installed-node drop-in persists through service restart/reboot but is not th fleet delivery mechanism. Automatic migration and signed catalog/OTA/ISO release validation remain pending; the source manifest declares the same network mode. Private deployment addresses, branch details and state archives are not committed. + +### Managed automatic migration and archive restore + +The new runtime candidate migrated an existing managed fixture from pasta to +slirp without a manual unit edit. It preserved the account, saved Source and +mount set, saved a private stopped-state archive plus the previous unit, restored +Source API access, and cleared the pending restart marker. A management-service +restart preserved the new container identity/start time and did not create +another archive. The archive extracted into an isolated scratch directory and +compared cleanly, including the database and Compose directory. Rootless archive +ownership required scratch cleanup inside `podman unshare`; no production data +was overwritten. Native Bitcoin and LND IDs/start times remained unchanged. + +This optimized candidate predates the final bounded backup-retry guard; that +latest source passed the isolated 1,605-test suite and must also be exercised in +the final release build. A fixture-only systemd start failure was then injected during a security +directive migration. The failure retained the durable restart marker. After +removing the injected failure, the reconciler restarted the service without a +manual container start, restored Source API access and cleared the marker. +Reverse install order, final-build retry-budget coverage, full reboot and +signed delivery remain open. diff --git a/docs/next-release-20260930.md b/docs/next-release-20260930.md index 2881a925..17837eda 100644 --- a/docs/next-release-20260930.md +++ b/docs/next-release-20260930.md @@ -35,7 +35,7 @@ See the Framework incident and 1.8.21 execution records for evidence/limits. | App disappearance/readiness | Durable inventory and safe lifecycle repair; delayed HTTP and desktop/mobile hard-refresh checks passed | Final lifecycle/reboot gate on candidate | | X250 GitWorkshop/Nginx | Missing build contexts restored, dependency/build checks and live UI passed; Nginx slow pull diagnosed; truthful progress label | Verify both artifact payloads contain all build contexts | | PRs 161/162 | Reviewed, repaired, merged/closed normally; combined regression suite passed | Candidate funded Tor-only purchase, change and Files acceptance | -| Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration/rollback, failure retry, reverse install order, reboot convergence, production Source API/UI, signed delivery | +| Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration, scratch restore and failure retry passed; still need reverse install order, reboot convergence, production Source API/UI, signed delivery | | Angor headless store service | Current official guide reviewed: standard Mempool with optional strfry relay | Implement using app-development docs; safe dependency/relay integration; official logo; API and lifecycle acceptance | Durable payment receipts after a lost seller response remain a separately diff --git a/docs/pr-review-20260930.md b/docs/pr-review-20260930.md index 6169f790..1713c708 100644 --- a/docs/pr-review-20260930.md +++ b/docs/pr-review-20260930.md @@ -6,8 +6,8 @@ Reviewed both open PRs from the repository pull-request list: [#161](https://sou and [#162](https://source.archipelago-foundation.org/lfg2025/archy/pulls/162). Both branches were updated from main, repaired and tested independently and together. Their existing remote branches were advanced without rewriting the -contributors' history. They remain open for integration into the release after -1.8.21; no reviewed code was merged into main or deployed to a live wallet. +contributors' history. Both were subsequently merged and closed and are now +integrated on main. Candidate live-wallet acceptance remains pending. The signed 1.8.21 artifacts are unchanged. | Candidate | Tested commit | Isolated backend result | @@ -95,8 +95,8 @@ Logs on the development box: ## Next-release acceptance and limits -- Integrate the reviewed branches and repeat the release gates against the - final release commit if additional code changes land. +- Both reviewed branches are integrated on main alongside the lifecycle fixes. + Repeat release gates against the final release commit after remaining changes. - Perform funded peer-to-peer acceptance on the candidate build, including a Tor-only purchase and a purchase requiring change, before the next release. The new review branches were not deployed to funded live wallets here. @@ -109,8 +109,8 @@ Logs on the development box: ordinary write failures and truncated input are tested to clean up. The final filename is published only after complete input, and existing files remain protected. -- The separately reported X250 kiosk version-selector rendering issue remains - open in `TODO.md` and requires validation on the actual kiosk. +- The separately reported X250 kiosk selector is fixed and verified on the + actual kiosk; see the lifecycle evidence and consolidated release checklist. ## Authorized merge — 2026-09-30 @@ -122,6 +122,5 @@ Gitea normal merges completed and read-back confirmed `merged=true`, `state=clos - #161: `3daea6623be3e2c7222101b8e6ac411423c7e16c`. - #162: `b02ba4100d922dd1b75c6a78121ef446c2159a54`. -Local next-release lifecycle work will be integrated with this main before the -next release. Funded release acceptance and the documented delivery-receipt +Local next-release lifecycle work was integrated with main at `d69e8452`. Funded release acceptance and the documented delivery-receipt limitation remain as recorded above; merging does not claim a new release. diff --git a/docs/repair-release-20260929.md b/docs/repair-release-20260929.md index bc5a4e96..c83b9f6f 100644 --- a/docs/repair-release-20260929.md +++ b/docs/repair-release-20260929.md @@ -1,6 +1,9 @@ # Repair and release execution — 2026-09-29 -**Status: IN PROGRESS. Do not publish an OTA or ISO until the release gates pass.** +**Status: 1.8.21 PUBLISHED — see the completion record at the end.** + +The next release is tracked in [the current execution checklist](next-release-20260930.md). +The dated entries below preserve the investigation history. User requires all tasks completed and tested on the development box before the next OTA and raw ISO. Passing unit tests alone does not establish live correctness. @@ -52,8 +55,8 @@ next OTA and raw ISO. Passing unit tests alone does not establish live correctne - [x] Live waiting/UI verified on dev; recovery covered by deterministic tests. - [x] Framework operator acceptance and authorization to release recorded. - [x] Release version/changelog, catalog/image implications, signing prepared. -- [ ] Signed OTA built, tested, published to git and ngit. -- [ ] Raw ISO built, boot-tested, signed and published; download command supplied. +- [x] Signed OTA built, tested, published to git and ngit. +- [x] Raw ISO built, boot-tested, signed and published; download command supplied. Tests must not wipe/recreate wallets, prune the operator's existing full chain, or claim that arbitrary failures can never happen. Record material gaps before