docs: consolidate release scope and record migration recovery checks

This commit is contained in:
archipelago
2026-09-30 10:52:41 -04:00
parent acf544500f
commit 7c4169867c
4 changed files with 35 additions and 12 deletions
+21
View File
@@ -144,3 +144,24 @@ The installed-node drop-in persists through service restart/reboot but is not th
fleet delivery mechanism. Automatic migration and signed catalog/OTA/ISO release fleet delivery mechanism. Automatic migration and signed catalog/OTA/ISO release
validation remain pending; the source manifest declares the same network mode. validation remain pending; the source manifest declares the same network mode.
Private deployment addresses, branch details and state archives are not committed. Private deployment addresses, branch details and state archives are not committed.
### Managed automatic migration and archive restore
The new runtime candidate migrated an existing managed fixture from pasta to
slirp without a manual unit edit. It preserved the account, saved Source and
mount set, saved a private stopped-state archive plus the previous unit, restored
Source API access, and cleared the pending restart marker. A management-service
restart preserved the new container identity/start time and did not create
another archive. The archive extracted into an isolated scratch directory and
compared cleanly, including the database and Compose directory. Rootless archive
ownership required scratch cleanup inside `podman unshare`; no production data
was overwritten. Native Bitcoin and LND IDs/start times remained unchanged.
This optimized candidate predates the final bounded backup-retry guard; that
latest source passed the isolated 1,605-test suite and must also be exercised in
the final release build. A fixture-only systemd start failure was then injected during a security
directive migration. The failure retained the durable restart marker. After
removing the injected failure, the reconciler restarted the service without a
manual container start, restored Source API access and cleared the marker.
Reverse install order, final-build retry-budget coverage, full reboot and
signed delivery remain open.
+1 -1
View File
@@ -35,7 +35,7 @@ See the Framework incident and 1.8.21 execution records for evidence/limits.
| App disappearance/readiness | Durable inventory and safe lifecycle repair; delayed HTTP and desktop/mobile hard-refresh checks passed | Final lifecycle/reboot gate on candidate | | App disappearance/readiness | Durable inventory and safe lifecycle repair; delayed HTTP and desktop/mobile hard-refresh checks passed | Final lifecycle/reboot gate on candidate |
| X250 GitWorkshop/Nginx | Missing build contexts restored, dependency/build checks and live UI passed; Nginx slow pull diagnosed; truthful progress label | Verify both artifact payloads contain all build contexts | | X250 GitWorkshop/Nginx | Missing build contexts restored, dependency/build checks and live UI passed; Nginx slow pull diagnosed; truthful progress label | Verify both artifact payloads contain all build contexts |
| PRs 161/162 | Reviewed, repaired, merged/closed normally; combined regression suite passed | Candidate funded Tor-only purchase, change and Files acceptance | | PRs 161/162 | Reviewed, repaired, merged/closed normally; combined regression suite passed | Candidate funded Tor-only purchase, change and Files acceptance |
| Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration/rollback, failure retry, reverse install order, reboot convergence, production Source API/UI, signed delivery | | Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration, scratch restore and failure retry passed; still need reverse install order, reboot convergence, production Source API/UI, signed delivery |
| Angor headless store service | Current official guide reviewed: standard Mempool with optional strfry relay | Implement using app-development docs; safe dependency/relay integration; official logo; API and lifecycle acceptance | | Angor headless store service | Current official guide reviewed: standard Mempool with optional strfry relay | Implement using app-development docs; safe dependency/relay integration; official logo; API and lifecycle acceptance |
Durable payment receipts after a lost seller response remain a separately Durable payment receipts after a lost seller response remain a separately
+7 -8
View File
@@ -6,8 +6,8 @@ Reviewed both open PRs from the repository pull-request list: [#161](https://sou
and [#162](https://source.archipelago-foundation.org/lfg2025/archy/pulls/162). and [#162](https://source.archipelago-foundation.org/lfg2025/archy/pulls/162).
Both branches were updated from main, repaired and tested independently and Both branches were updated from main, repaired and tested independently and
together. Their existing remote branches were advanced without rewriting the together. Their existing remote branches were advanced without rewriting the
contributors' history. They remain open for integration into the release after contributors' history. Both were subsequently merged and closed and are now
1.8.21; no reviewed code was merged into main or deployed to a live wallet. integrated on main. Candidate live-wallet acceptance remains pending.
The signed 1.8.21 artifacts are unchanged. The signed 1.8.21 artifacts are unchanged.
| Candidate | Tested commit | Isolated backend result | | Candidate | Tested commit | Isolated backend result |
@@ -95,8 +95,8 @@ Logs on the development box:
## Next-release acceptance and limits ## Next-release acceptance and limits
- Integrate the reviewed branches and repeat the release gates against the - Both reviewed branches are integrated on main alongside the lifecycle fixes.
final release commit if additional code changes land. Repeat release gates against the final release commit after remaining changes.
- Perform funded peer-to-peer acceptance on the candidate build, including a - Perform funded peer-to-peer acceptance on the candidate build, including a
Tor-only purchase and a purchase requiring change, before the next release. Tor-only purchase and a purchase requiring change, before the next release.
The new review branches were not deployed to funded live wallets here. The new review branches were not deployed to funded live wallets here.
@@ -109,8 +109,8 @@ Logs on the development box:
ordinary write failures and truncated input are tested to clean up. The final ordinary write failures and truncated input are tested to clean up. The final
filename is published only after complete input, and existing files remain filename is published only after complete input, and existing files remain
protected. protected.
- The separately reported X250 kiosk version-selector rendering issue remains - The separately reported X250 kiosk selector is fixed and verified on the
open in `TODO.md` and requires validation on the actual kiosk. actual kiosk; see the lifecycle evidence and consolidated release checklist.
## Authorized merge — 2026-09-30 ## Authorized merge — 2026-09-30
@@ -122,6 +122,5 @@ Gitea normal merges completed and read-back confirmed `merged=true`, `state=clos
- #161: `3daea6623be3e2c7222101b8e6ac411423c7e16c`. - #161: `3daea6623be3e2c7222101b8e6ac411423c7e16c`.
- #162: `b02ba4100d922dd1b75c6a78121ef446c2159a54`. - #162: `b02ba4100d922dd1b75c6a78121ef446c2159a54`.
Local next-release lifecycle work will be integrated with this main before the Local next-release lifecycle work was integrated with main at `d69e8452`. Funded release acceptance and the documented delivery-receipt
next release. Funded release acceptance and the documented delivery-receipt
limitation remain as recorded above; merging does not claim a new release. limitation remain as recorded above; merging does not claim a new release.
+6 -3
View File
@@ -1,6 +1,9 @@
# Repair and release execution — 2026-09-29 # Repair and release execution — 2026-09-29
**Status: IN PROGRESS. Do not publish an OTA or ISO until the release gates pass.** **Status: 1.8.21 PUBLISHED — see the completion record at the end.**
The next release is tracked in [the current execution checklist](next-release-20260930.md).
The dated entries below preserve the investigation history.
User requires all tasks completed and tested on the development box before the User requires all tasks completed and tested on the development box before the
next OTA and raw ISO. Passing unit tests alone does not establish live correctness. next OTA and raw ISO. Passing unit tests alone does not establish live correctness.
@@ -52,8 +55,8 @@ next OTA and raw ISO. Passing unit tests alone does not establish live correctne
- [x] Live waiting/UI verified on dev; recovery covered by deterministic tests. - [x] Live waiting/UI verified on dev; recovery covered by deterministic tests.
- [x] Framework operator acceptance and authorization to release recorded. - [x] Framework operator acceptance and authorization to release recorded.
- [x] Release version/changelog, catalog/image implications, signing prepared. - [x] Release version/changelog, catalog/image implications, signing prepared.
- [ ] Signed OTA built, tested, published to git and ngit. - [x] Signed OTA built, tested, published to git and ngit.
- [ ] Raw ISO built, boot-tested, signed and published; download command supplied. - [x] Raw ISO built, boot-tested, signed and published; download command supplied.
Tests must not wipe/recreate wallets, prune the operator's existing full chain, Tests must not wipe/recreate wallets, prune the operator's existing full chain,
or claim that arbitrary failures can never happen. Record material gaps before or claim that arbitrary failures can never happen. Record material gaps before