Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions AUDIT_OPEN.md
Original file line number Diff line number Diff line change
Expand Up @@ -572,3 +572,18 @@ Validation: lint; 1,411 runtime tests; 100 script tests with one existing skip;
symlink loaded duplicate project-error classes and failed two unrelated identity
checks; installing this worktree's web dependencies resolved both. Original
failure log retained in the private execution receipts.

## 2026-09-27 — rehearsal transport and completed coordination wording

An exact production backup booted under Nucleus v1.1.1, but the rehearsal
client lost its connection because the image default enabled TLS. Start the
proof engine with explicit `/data`, host, non-TLS transport and memory budget,
matching its loopback-only client. A restored 352-run store then exposed all
five waiting decisions and passed the candidate fingerprint preflight. Keep
independent history-count/digest verification in the release receipt; an empty
preflight alone is not evidence that a populated backup restored correctly.

The real standalone API/client coordination completed through both normal merge
approvals and its compatibility scan. Its client description still said the
check was owed despite the complete badge. It now points to the actual check
result below without asserting an obsolete pending state.
7 changes: 5 additions & 2 deletions scripts/ship-backup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -275,15 +275,18 @@ cmd_rehearse() {

# Same posture as the teploy.yml accessory: no-auth pgwire, no clustering,
# and the engine memory budget set above the 512 MB default so a real store
# is not rejected on load during the proof.
# is not rejected on load during the proof. Explicitly name the restored
# mount and local non-TLS transport: image defaults enable TLS, while the
# rehearsal client uses plain pgwire on its loopback-only published port.
docker run -d --name "$name" \
-p 127.0.0.1::5432 \
-v "$rehearsal/$(basename "$NUCLEUS_DATA_REL"):/data" \
-e NUCLEUS_ALLOW_NO_AUTH=1 \
-e NUCLEUS_ALLOW_INSECURE_CLUSTER=1 \
-e NUCLEUS_ALLOW_INSECURE_REPLICATION=1 \
-e NUCLEUS_MAX_MEMORY_MB="${SHIP_REHEARSE_MAX_MEMORY_MB:-1024}" \
"$image" >/dev/null
"$image" start --data /data --host 0.0.0.0 --no-tls \
--max-memory "${SHIP_REHEARSE_MAX_MEMORY_MB:-1024}" >/dev/null

local endpoint timeout elapsed=0
endpoint="$(docker port "$name" 5432/tcp | head -1)"
Expand Down
2 changes: 1 addition & 1 deletion web/src/routes/coordination.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ function childView(record: CoordinationRecord, which: "api" | "client"): ChildVi
line:
which === "api"
? `Merged as ${child.anchorSha ?? "an unproven commit"} — that commit is the compatibility anchor for the client change. Delivery approval happens on the Deliveries surface.${run}`
: `Merged as ${child.mergedSha ?? "an unproven commit"} — the pair now owes its compatibility check before it can be called done. Delivery approval happens on the Deliveries surface.${run}`,
: `Merged as ${child.mergedSha ?? "an unproven commit"} — see the pair’s compatibility result below. Delivery approval happens on the Deliveries surface.${run}`,
};
case "delivered":
return {
Expand Down
Loading