diff --git a/AUDIT_OPEN.md b/AUDIT_OPEN.md index 519632a..3407b32 100644 --- a/AUDIT_OPEN.md +++ b/AUDIT_OPEN.md @@ -572,3 +572,18 @@ Validation: lint; 1,411 runtime tests; 100 script tests with one existing skip; symlink loaded duplicate project-error classes and failed two unrelated identity checks; installing this worktree's web dependencies resolved both. Original failure log retained in the private execution receipts. + +## 2026-09-27 — rehearsal transport and completed coordination wording + +An exact production backup booted under Nucleus v1.1.1, but the rehearsal +client lost its connection because the image default enabled TLS. Start the +proof engine with explicit `/data`, host, non-TLS transport and memory budget, +matching its loopback-only client. A restored 352-run store then exposed all +five waiting decisions and passed the candidate fingerprint preflight. Keep +independent history-count/digest verification in the release receipt; an empty +preflight alone is not evidence that a populated backup restored correctly. + +The real standalone API/client coordination completed through both normal merge +approvals and its compatibility scan. Its client description still said the +check was owed despite the complete badge. It now points to the actual check +result below without asserting an obsolete pending state. diff --git a/scripts/ship-backup.sh b/scripts/ship-backup.sh index a40c7a3..30d3000 100755 --- a/scripts/ship-backup.sh +++ b/scripts/ship-backup.sh @@ -275,7 +275,9 @@ cmd_rehearse() { # Same posture as the teploy.yml accessory: no-auth pgwire, no clustering, # and the engine memory budget set above the 512 MB default so a real store - # is not rejected on load during the proof. + # is not rejected on load during the proof. Explicitly name the restored + # mount and local non-TLS transport: image defaults enable TLS, while the + # rehearsal client uses plain pgwire on its loopback-only published port. docker run -d --name "$name" \ -p 127.0.0.1::5432 \ -v "$rehearsal/$(basename "$NUCLEUS_DATA_REL"):/data" \ @@ -283,7 +285,8 @@ cmd_rehearse() { -e NUCLEUS_ALLOW_INSECURE_CLUSTER=1 \ -e NUCLEUS_ALLOW_INSECURE_REPLICATION=1 \ -e NUCLEUS_MAX_MEMORY_MB="${SHIP_REHEARSE_MAX_MEMORY_MB:-1024}" \ - "$image" >/dev/null + "$image" start --data /data --host 0.0.0.0 --no-tls \ + --max-memory "${SHIP_REHEARSE_MAX_MEMORY_MB:-1024}" >/dev/null local endpoint timeout elapsed=0 endpoint="$(docker port "$name" 5432/tcp | head -1)" diff --git a/web/src/routes/coordination.tsx b/web/src/routes/coordination.tsx index f6531cd..c503b6f 100644 --- a/web/src/routes/coordination.tsx +++ b/web/src/routes/coordination.tsx @@ -170,7 +170,7 @@ function childView(record: CoordinationRecord, which: "api" | "client"): ChildVi line: which === "api" ? `Merged as ${child.anchorSha ?? "an unproven commit"} — that commit is the compatibility anchor for the client change. Delivery approval happens on the Deliveries surface.${run}` - : `Merged as ${child.mergedSha ?? "an unproven commit"} — the pair now owes its compatibility check before it can be called done. Delivery approval happens on the Deliveries surface.${run}`, + : `Merged as ${child.mergedSha ?? "an unproven commit"} — see the pair’s compatibility result below. Delivery approval happens on the Deliveries surface.${run}`, }; case "delivered": return {