Files
archy/docs/post-1.9.0-progress-20261006.md
T

122 lines
6.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Post-1.9.0 work: qualification checkpoint
2026-10-06. These follow-ups are not a new published OTA/ISO. The immutable
1.9.0-alpha release and public demo are already published. This checkpoint does
not replace the scope in [the complete backlog](post-1.9.0-work-backlog.md).
## Implemented and deployed on dev/Yaya
- AI provider setup, private credential handling and Routstr funding entry:
actual status endpoints and browser UI checks passed. No paid inference was
performed. Physical companion and successful paid-provider response remain
separate acceptance gates.
- Reciprocal approved peering: both actual nodes retain each other as Observer,
with fresh contact timestamps. Live browser checks on both nodes at 390 and
1440 pixels show exactly one reciprocal peer and navigate to connection setup.
No peer RPC fixtures were used for these checks. Restart recovery and broader
failure/trust/duplicate coverage remain in the acceptance matrix.
- Fleet/monitoring improvements: real metrics verified on dev/Yaya, with honest
unavailable/stale states. Full Fleet actions, authorization and mixed-version
failure matrix is not complete.
## Latest incident and candidate
Yaya's internet and physical interfaces were working. Its authentication signing
key had been left root-owned during earlier diagnostic remediation. The previous
loader ignored read/write failures and used an ephemeral key; restarts changed
CSRF tokens while sessions remained valid. The owner/mode were corrected without
rotating the existing key, and the repaired session survived another management
restart. The kiosk again displayed the real Wi-Fi and Ethernet interfaces.
Candidate `7e11f78e` adds bounded stale-CSRF recovery and distinguishes failed
interface retrieval from an empty successful result. It also combines the
container-store ownership, node-scoped catalog/player and FIPS follow-ups.
- Full isolated backend: **1,707 passed, zero failures, four explicit skips**.
- Full dashboard suite: **1,254 passed / 157 files**; production UI build passed.
- Candidate browser: 390/1440 pixels, injected stale-token or failed-interface
response followed by real authenticated Yaya data; exactly one recovery retry.
- Production backend build is still pending at this checkpoint. These results
do not establish live acceptance of that combined candidate.
Separate hardening `aa10bd12` + `a2e61382` removes ephemeral-key fallback, preserves
valid bytes, requires private durable creation, rejects damaged/unreadable keys,
propagates storage failure before RPC dispatch, and handles concurrent creation.
Its isolated full suite is compiling; it is not deployed. See
[session recovery](session-recovery-followup.md).
## V4V
Versioned app image and node-only manifest are prepared; the original demo catalog,
actual login-background promotion and app/player bridge are implemented. Focused
player/bridge tests and image build passed. Yaya's existing Portainer app/data
remain untouched. The final image is being loaded into isolated qualification
storage; no Yaya-only catalog has been signed or enabled yet.
A cleanup bug stopped the first isolated fixture: the backend confused containers
from another Podman storage root with ghosts. Store/owner checks are fixed and
focused tests pass. Deploy that fix, prove the final fixture survives cleanup,
then test actual authenticated playback, pause/close/reopen, unchanged iframe,
seek/resume and app relock. Only then enable the signed Yaya-DID catalog and
complete upgrade/restart/rollback and mobile/companion acceptance.
## IndeeHub and FIPS
Signer fixes passed focused tests, production build and authenticated Yaya browser
login/reload. Actual companion background/resume remains unverified. Publish the
required app update at the end, after integrated qualification.
The distributed Archipelago source and full publish/discover/pay-producer/timed
viewing flow are not complete. The design review and selected Yaya video are
prepared. Implement durable entitlements, settlement correlation and original
signed discovery; qualify retries/outages/expiry without double payment. No new
real spending is authorized by this checkpoint.
FIPS-required peer media requests and bounded local-cache HTTP streaming are
implemented in the combined candidate. Seller-side full-buffer reading and the
complete IndeeHub media path remain open; no end-to-end all-media-FIPS claim.
## Other active tasks
| Task | Remaining acceptance or work |
|---|---|
| Connection UX | Flow plan written; broad navigation changes and lifecycle acceptance remain. |
| Connect with Nodes / Nostr requests | Implemented; retain full request/retry/trust matrix and companion acceptance. |
| Offline indicators/order/map | Fixture-tested changes; qualify real outages, stale metrics and recovery. |
| Navigation and app launch speed | Establish before/after distributions; actual companion remains required. |
| Framework Monitoring | Existing kiosk is signed out and RPC returns 401; not a passed monitoring check. |
| Native companion reliability | No ADB device attached at checkpoint; browser tests do not substitute. |
| Immich/Nextcloud libraries | Assessment/proposed authenticated API integration only; no enabled connector. |
| Cosmetic Web5 Wallet label | Removed; legitimate wallet/hardware functions preserved. |
| Mirrors, catalog, app updates, OTA/ISO | Integrate/review once through ngit; mirror exact accepted history to Gitea. Required artifact gates remain. |
## Latency evidence and limitations
The first live dev mobile connection-navigation check exceeded five seconds.
A diagnostic repeat navigated in 763 ms. The saved dev diagnostic session was
stale and restored through remember-me; after capturing refreshed cookies, the
four node/viewport checks passed. Retain the initial failure: this does not prove
that the operator's intermittent delay is solved. Cold peer visibility in these
runs took roughly 3.1–4.6 seconds, including initial navigation/render/tab click;
these are not isolated API latency or a before/after performance comparison.
## Retained earlier limitations
- Angor: operator accepted incomplete historical discovery for release on
2026-10-05. All 35 reference commitments were verified, but 34 original signed
announcements remain unrecovered from the queried sources. Recovery is open.
- Framework radio/hardware investigation remains operator-deferred.
- Earlier Framework LND incident remains separately closed with operator
acceptance; do not reopen it as the explanation for unrelated failures.
## Local evidence
No credentials or raw private inventories are included here. Qualification logs:
`/tmp/archy-session-recovery-backend.log`,
`/tmp/archy-session-recovery-full-ui.log`,
`/tmp/archy-session-recovery-browser.log`,
`/tmp/archy-peering-live-browser-2.log`,
`/tmp/archy-peering-live-browser-diagnostic.log`,
`/tmp/archy-session-key-backend-2.log`,
`/tmp/archy-framework-monitoring-current-3.log`.