docs: record installer acceptance and post-release work

This commit is contained in:
archipelago
2026-10-05 18:18:11 -04:00
parent a6b9e7ab49
commit 2aa77d1b7b
4 changed files with 176 additions and 1 deletions
+10
View File
@@ -1542,3 +1542,13 @@ physical save/open acceptance and the existing release gates.
(save/open/cancel) accepted: “works, we can proceed”. Viewer and physical upload
acceptance retained. Close this manual gate; other release/security/Angor gates
remain open. No fleet OTA, ISO or public demo publication inferred.
### Operator accepts Angor discovery limitation — 2026-10-05
The operator explicitly accepted releasing with incomplete historical project
discovery documented as a known limitation ("that's fine for now"). Funding
commitments for all35 reference projects were verified;34 original signed
announcements remain unrecovered from the sources checked. This releases the
all-project-discovery publication hold, not a claim that recovery passed. Track
recovery separately and retain the limitation in release notes. Other artifact,
upgrade, security and publication checks remain required.
+94
View File
@@ -0,0 +1,94 @@
# Work requested after 1.9.0-alpha
Status: queued by the operator on 2026-10-05. Complete the current release first;
these requests do not silently expand its artifact scope. No implementation or
acceptance is claimed by this backlog.
## 1. Distributed IndeeHub publishing and paid viewing
- Recover and reconcile the earlier design in
[the streaming plan](phase4-streaming-ecash-plan.md) and
[the distribution design](dht-distribution-design.md) against current source.
Their implementation/status statements are historical, not fresh evidence.
- Review current primary Nostr, Cashu and Bitcoin/Lightning specifications before
selecting the protocol. Distinguish interoperable standards from custom events.
- Publishing through one instance's Backstage must make the content discoverable
through other instances' **Archipelago** content source. This source is intended
to become the default eventually; do not change the default without qualification.
- Reuse supported node-to-node discovery/transports and the file-payment method
negotiation: show methods the recipient actually accepts. Include Cashu and
Lightning to the automatically provisioned ecash Lightning address from first
use; do not require a producer to operate LND to receive initial payments.
- Pay the producer's wallet, verify settlement before granting access, and make
payment retries/delivery recovery idempotent. Keep producer revenue separate
from any optional hosting/relay bandwidth charges in the older plan.
- Define timed viewing entitlements, start/expiry semantics, reconnect, resume,
seek, device/session scope and clock/error handling. Evaluate encrypted media
and authorized key delivery without claiming that delivered video or keys can
be made impossible to copy or revoked retroactively.
- Use the operator's video uploaded to **Yaya Cloud**, publishing through Backstage
for the demo. Identify the exact file and preserve the source; do not select an
unrelated personal video or publish other Cloud contents. Payment-test amounts
need explicit bounded authorization before real funds are spent.
- Deliver a coherent demo: publish on one node, discover on another, select a
supported payment method, pay producer, watch, resume without repayment, and
enforce expiry. Cover publisher outage, duplicate events, wrong mint, failed/
delayed payment, restart and lost responses. Preserve privacy and access rules.
- Treat this as the foundation for future fully featured node-sharing apps,
introduced and qualified individually.
## 2. IndeeHub native Nostr signer and companion reliability
- Reproduce intermittent native-signer login failure and companion grey screen
requiring refresh/re-login. Inspect both browser and actual Android WebView.
- Cover iframe origins, signing permissions, redirects, callback/session state,
background/resume, expired sessions, refresh and cancellation without weakening
authentication or exporting signing keys. Preserve useful errors and recovery.
- Consult existing signer bridge documentation and prior origin/reload fixes;
do not assume those earlier fixes address this fresh report.
## 3. Node peering and discovery
- Diagnose Yaya ↔ Archy dev: requests appear approved/pending but neither node
appears in the other's peers; the flow is also slow.
- Trace request, delivery, approval, identity, persistence and both-node peer-list
reconciliation. Test restart, retry/duplicates, offline recovery and reciprocal
visibility; distinguish requested, approved, connecting and connected states.
- Show Nostr requests in the appropriate discovery/request UI.
- Rename **Find Nodes** to **Connect with Nodes**, consistently with accessibility,
navigation and translation conventions.
## 4. Framework Monitoring
- Investigate the reported non-working Monitoring screen on Framework with
read-only diagnostics first. Verify actual metrics, loading/error states,
permissions and refresh/reconnect on that node. Preserve wallet/radio state.
## 5. Immich / Nextcloud files in Cloud
- Assess integration so installed Immich/Nextcloud files appear under the correct
Cloud Files categories, without duplicating storage or exposing another user's
private data. Determine supported APIs, user identity/permissions, thumbnails,
originals, virtual paths and large-library pagination/indexing.
- Define view/download/edit/delete semantics per source. Preserve application
ownership, databases, metadata and trash/versioning; do not directly mutate
application-managed storage to bypass its API.
- Test installation/removal, permissions, unavailable apps, overlapping filenames,
duplicate detection and category accuracy before enabling an integration.
## 6. Web5 header and node connection flow planning
- Inspect the top-bar **Wallet** label in Web5. The operator requests removing
this cosmetic label; preserve any actual wallet navigation or accessibility
function until its role is established, and report if it is more than a label.
- Plan a less hidden, clearer discovery and peering journey on mobile and desktop
using the existing design system, visual styles and components. This is a flow
and information-placement change, not a visual redesign.
- Include visible entry to **Connect with Nodes**, incoming/outgoing Nostr
requests, approval, pending/connecting/connected status, reciprocal peer
confirmation, offline/retry recovery, and clear return paths. Show how this
relates to existing peers and node details rather than adding duplicate flows.
- Produce reviewable mobile/desktop flow plans before broad navigation changes;
cover first connection and repeat use, touch/keyboard access, empty/error
states, and the current Yaya/dev approval bug. Keep diagnostic implementation
details out of normal user-facing steps.
+54 -1
View File
@@ -75,7 +75,8 @@ whenever human acceptance is needed.
the existing field. `/tmp/archy-190-final-search-live.log`. Earlier grouping
and transaction-rail results are retained.
- [ ] **Angor:** dev full-chain acceptance after unpruned Bitcoin sync; retain
all-project discovery requirement and 34 unrecovered original announcements.
the operator-accepted historical discovery limitation (34 unrecovered announcements);
recovery is follow-up work, not a publication blocker.
Publish tested explorer/API app update and optional relay in signed catalog.
- [ ] **Post-release demo deployment:** operator requests updating the existing
public software demo at https://demo.archipelago-foundation.org/ through its
@@ -815,3 +816,55 @@ Demo archive33ec4111…6fae8 matches after private server transfer; both tested
IDs loaded successfully without changing running demo containers. Clearing only
unused build cache recovered1.743GB; no additional historical ISO, image, volume
or application data was deleted. Final publication capacity must be rechecked.
### Operator accepts Angor discovery limitation — 2026-10-05
The operator explicitly accepted releasing with incomplete historical project
discovery documented as a known limitation ("that's fine for now"). Funding
commitments for all35 reference projects were verified;34 original signed
announcements remain unrecovered from the sources checked. This releases the
all-project-discovery publication hold, not a claim that recovery passed. Track
recovery separately and retain the limitation in release notes. Other artifact,
upgrade, security and publication checks remain required.
### Work explicitly queued after this release
The operator requested returning to distributed IndeeHub, signer/companion login,
node peering, Framework Monitoring and external-app Cloud integration after
1.9.0-alpha. All details are retained in
[the post-release backlog](post-1.9.0-work-backlog.md). These additions do not
expand or delay the current release's artifact scope.
### Final RC3 installed-artifact qualification — 2026-10-05
Final raw ISO `archipelago-installer-1.9.0-alpha-unbundled-x86_64.iso` is byte-for-byte
the tested RC3 (SHA256 `aad5f0350428976969043079a63b0e7a8264dcee2574526bd34719c798c750af`).
Actual installation completed to a disposable80GiB disk with encrypted data.
Installed legacy BIOS/SATA and UEFI/SATA boot, mounted encrypted data, healthy
backend1.9.0-alpha with completed startup recovery, and private dashboard pass.
The initial SeaBIOS/NVMe boot could not find the disk; the same installed disk
boots with SATA. Installer logs show both GRUB installations succeeded. This
is not a claim of physical legacy-BIOS/NVMe support.
The final installed script retries without changing container IDs/start times
or managed File Browser credentials. Normal dashboard setup/login, Cloud token
and authenticated listing pass; anonymous and admin/admin access are rejected.
Initial test omitted CSRF and correctly received403; corrected normal-cookie/
CSRF flow passes. Onboarding also replaces the initial SSH password as expected.
The fixture was corrected to retain its own generated password privately; no
production credentials or access controls were changed.
After UEFI boot the installed nginx passes32 IPv4/IPv6 public-source rejection
cases including unknown Host/SNI, forged forwarding headers, assets, RPC and
WebSocket upgrade requests. Early health showed startup recovery still running;
subsequent explicit status/recovery assertions pass after61seconds.
Evidence: `/tmp/archy-190-rc3-installed-test-2.log`,
`/tmp/archy-190-rc3-uefi-acceptance-2.log`,
`/tmp/archy-190-rc3-uefi-healthy.log`. Unsupported virtual EDAC remains separate
from the supported service checks.
Artifacts are ready for operator signing, not publication. The final signed
OTA apply/rollback test necessarily follows signing. Mirror/tag parity, public
artifact downloads, catalog promotion, fleet discovery and demo deployment
remain required. The Angor historical limitation is explicitly accepted and
documented in [known limitations](release-1.9.0-known-limitations.md).
+18
View File
@@ -0,0 +1,18 @@
# 1.9.0-alpha: Angor historical discovery
Historical project discovery is incomplete. Funding commitments for all35
reference projects were verified, but34 original signed announcements were not
recovered from the relays and archives checked. They are not proven globally
lost. One recovered project passes Explore, details, statistics and public
TLS/WebSocket acceptance using the self-hosted services.
The operator explicitly accepted shipping with this limitation on2026-10-05.
Recovery remains follow-up work; this acceptance does not mean all-project
discovery passed. Retain the original relays alongside the self-hosted relay.
Full indexing requires a synced, unpruned Bitcoin node and indexing dependencies.
The dev node is still syncing; full-chain evidence comes from Shorty.
Evidence and inventory: [client acceptance](angor-client-acceptance-20261001.md),
[project recovery inventory](angor-project-recovery-20261001.json), and
[release acceptance](release-1.9.0-acceptance.md).