Verify fresh IndeeHub backup restores and record remaining release tasks

This commit is contained in:
archipelago
2026-10-07 14:43:22 -04:00
parent 7fb7ee80f2
commit d4f3cceb52
8 changed files with 440 additions and 17 deletions
+89
View File
@@ -126,6 +126,11 @@ Private backup and artifacts are under
should continue on the phone after app close, with native controls, queue,
artwork, authorization and video PiP. Physical V4V acceptance is open.
21. **Public files/folders — queued, perform last:** Make public in both More
menus, discovery by non-peered/non-federated nodes, the same peer-sharing
pricing interface with blue tints instead of orange, optional charging and
a tiny blue marker at the icon's top-left. Full scope is backlog task21.
## Additional release-regression items
- Paid-file recovery must never issue a second payment; source protections and
@@ -223,3 +228,87 @@ release receipt or preservation check as a stop-and-investigate condition.
passes unchanged/additive schema and rejects four data/schema/history
mutations. Full Rust and real supervised Podman/systemd qualification remain
required before integration or IndeeHub activation.
## Operator PiP acceptance and continued release work — 2026-10-07
- Operator confirmed the delivered companion PiP works (“works great”). Record
this as operator acceptance of the reported PiP flow, not independent proof
of every rotation/network/expiry case or native V4V background-audio support.
- Retained updater is now integrated locally at `7fb7ee80`. The combined isolated
backend suite passed **2,000 tests, zero failures, five ignored**. Prior notes
saying integration/Rust qualification are pending are historical.
- Real disposable Quadlet/Podman AutoRemove primitive qualification passed:
injected target failure, restoration from the original writable-layer image,
preserved volume bytes and original configuration. The full seven-member
application drain/cutover adapter is still not qualified by this primitive test.
- Evidence: `/tmp/archy-resumed-20261007-integrated-full-backend.log` and
`/tmp/archy-resumed-20261007-runtime-primitives-recheck.log`.
- Active work: require restoration of each fresh database backup in an owned,
network-isolated PostgreSQL before IndeeHub target startup. Hash verification
alone is insufficient. All 21 controller tests pass; real restore/fault checks
passed, including the actual production restore method, rejection of truncated
and wrong-database dumps, owned fixture cleanup and retained admission fences.
Evidence: `/tmp/archy-20261007-fresh-backup-restore.log`.
This script change needs a fresh embedded-controller backend
build; do not call the older 2,000-test result evidence for this new change.
- Task21 is appended at the end, including the operator's explicit requirement
to reuse peer-sharing pricing with blue tints. It is not implemented yet.
### Current status overview requested by the operator
“Nearly finished” means implemented with a bounded acceptance/review step left;
“In progress” still includes substantive implementation or distributed testing.
No percentage is inferred from test counts.
| Task | Status | Remaining work |
| --- | --- | --- |
| 1 IndeeHub publishing/paid viewing | In progress | Full supervised cutover, distributed publication/payment/timed playback |
| 2 Native signer/companion grey screen | Nearly finished | Physical login/resume/session recovery acceptance |
| 3 Peering/discovery | In progress | Reciprocal offline/reconnect and expanded connection UX |
| 4 Framework Monitoring | Nearly finished | Owner-browser Monitoring check |
| 5 Immich/Nextcloud | Slightly started | Design assessment exists; connectors unimplemented |
| 6 Web5 connection journey | In progress | Deferred final flow review and expanded UX |
| 7 Companion launch speed | In progress | Actual device measurements and remaining latency work |
| 8 Fleet acceptance | In progress | Full supported-function/fault matrix |
| 9 AIUI/provider/funding | In progress | Provider/funding and companion acceptance |
| 10 Offline/network map | In progress | Real outage and recovery qualification |
| 11 Web5/Cloud/tab speed | In progress | Complete performance evidence |
| 12 Fleet metrics/FIPS | In progress | Fleet failure and transport qualification |
| 13 V4V Yaya demo | In progress | Browser demo live; native phone background playback remains |
| 14 Peer files/Indee streaming | In progress | Distributed timed playback |
| 15 MeshCore | Queued | Two-radio work and acceptance |
| 16 Web5 cards/footer | Nearly finished | Final visual/functional review |
| 17 HTTPS apps | In progress | Exact hostname/trust and companion acceptance |
| 18 Firewall/tunnel | In progress | Read-only UI done; settings persistence/reboot/rollback qualification |
| 19 Media guide/Cloud PiP | Nearly finished | PiP operator-accepted; finish reusable contract and remaining edge cases |
| 20 Native background media | In progress | Cloud PiP done; native audio service/controls and device checks remain |
| 21 Public files/folders | Queued, final task | Shared pricing interface with blue tints, unrelated-node discovery and tiny marker |
Completed subitems: Framework LND startup incident, companion download/viewer
acceptance, physical upload acceptance, APK55 delivery and reported Cloud PiP
flow. Earlier complete UI/Android suites pass; a fresh backend rebuild is required
for the final restore barrier. OTA/ISO is not ready: payment/recovery, IndeeHub,
fleet/device qualification, mirror review/parity and final artifact gates remain.
### Fresh backup barrier qualification result
- Final controller:21 pure tests pass. Real production restore-barrier tests
pass on PostgreSQL15.17 and16.13, including valid restoration, wrong-database
and truncated-dump refusal, retained admission, owned fixture cleanup, and
four original data/schema/history mutation rejections.
- The first PG15 attempt failed during pg_restore. That attempt's command error
log was in an automatically removed fixture directory, so its exact cause is
not proven. Readiness inspection found the bootstrap Unix-socket server could
be mistaken for the final server. The controller/fixture now wait for TCP
readiness; both final version runs pass. Do not erase the failed attempt.
- The backend rebuild begun before the readiness edit was interrupted deliberately
because its embedded source was stale and it competed with restore tests.
**Final embedded-controller backend rebuild/suite and deployment remain pending.**
The prior 2,000-pass receipt applies to `7fb7ee80`, not this changed controller.
- Durable logs:
`~/.local/state/archipelago/release-qualification/indeehub-backup-restore-20261007/`.
- No live app/container, database, wallet, catalog, payment or public file was
changed. Disposable fixtures used network-none and no live volumes.
+37 -2
View File
@@ -1,7 +1,7 @@
# Managed update runtime recovery
Status: isolated source implementation; Rust and real Podman/systemd qualification
pending. No live update, snapshot, stop, backup or rollback has been performed by
Status: integrated candidate; combined Rust suite and real Podman/systemd
recovery primitives pass. Full application cutover qualification is pending. No live update, snapshot, stop, backup or rollback has been performed by
this work. Active deployed source is unchanged.
The managed path captures original source Quadlet bytes, mode, immutable image,
@@ -75,3 +75,38 @@ and PostgreSQL timeout remain failed/incomplete attempts, not acceptance.
Evidence: `/tmp/archy-resumed-20261007-updater-full-backend.log`,
`/tmp/archy-resumed-20261007-indeehub-controller-tests-final.log`, and
`/tmp/archy-resumed-20261007-indeehub-postgres-restore.log`.
## Integrated candidate checkpoint — 2026-10-07
Local integration at `7fb7ee80` passes the complete isolated backend suite:
2,000 passed, zero failed, five ignored. The stale receipt fixture failure above
is resolved by the already-integrated correction. Disposable real Quadlet
AutoRemove recovery primitives pass with injected target failure, original
writable-layer/configuration restoration and unchanged persistent fixture bytes.
Repeatable fixture: `tests/lifecycle/supervised-runtime-primitives.py`.
This does not qualify the complete seven-member app drain/cutover adapter.
The fresh-backup restore barrier is being added after this checkpoint; its
qualification and new embedded-controller build remain separate from these
previously passing results. No live IndeeHub deployment has been changed.
Fresh database backup restoration now runs through the controller's production
method in a disposable network-none PostgreSQL with no external mounts or
published ports. The original local image is pinned, dump restore must exactly
match captured database commitments, and durable proof binds the operation,
image, dump hash and baseline. Ownership-checked cleanup survives retry and
refuses foreign fixtures. Verification rejects a missing/stale restore proof.
All21 pure controller tests pass. The real PostgreSQL fixture passes valid
restoration, rejects truncated and wrong-database dumps, checks cleanup and
retained admission on failure, and retains the four prior mutation rejection
checks. Evidence: `/tmp/archy-20261007-fresh-backup-restore.log`.
Final real restore-barrier checks pass on PostgreSQL15.17 and16.13 after waiting
for the final TCP server instead of the temporary Unix-socket bootstrap server.
The initial PG15 restore failure is retained as failed evidence; its private
command stderr was removed by fixture cleanup, so no exact cause is claimed.
The stale backend compile was interrupted after the readiness edit; a fresh
backend build/suite remains required for the final embedded controller.
Volume-archive restore and the full supervised app cutover remain open gates.
+29
View File
@@ -549,3 +549,32 @@ and video, with video using picture-in-picture where the device supports it.
reconnect, completion and reopen states, then publish the reusable contract
for other audio/video apps. No live app deployment or payment is accepted
from browser-only tests.
## 21. Public files and folders — final task
Added by the operator on 2026-10-07. Perform after the existing tasks, including
previously deferred work. Status: queued; no public visibility has been changed.
- Add **Make public** to the More menus for both files and folders. Public means
discoverable by any node, including nodes with no peering or federation
relationship to the owner. Relationship approval must not be required merely
to discover a public item.
- Reuse the existing **Share with peers pricing interface**, including optional
charging and its supported pricing/payment choices. Use the existing brand
**blue tints instead of orange** for this public-sharing variant; do not create
a separate pricing interaction or change the peer-sharing colour treatment.
- Place a very small blue public-state marker at the **top-left of the file or
folder icon**. Keep the marker readable and accessible without covering the
thumbnail or replacing the existing icon.
- Separate public discoverability from paid access: listed paid content must
still enforce its price/entitlement. Reuse settlement and recovery protections
so retries do not charge twice.
- Make folder scope explicit in the reused flow, including existing/new children,
nested items and individual visibility/pricing overrides. Preserve private
items until the owner actually applies the action; provide a way to withdraw
public sharing and reflect that state in menus, listings and markers.
- Qualify file/folder menus, shared pricing UI with blue styling, tiny marker,
unrelated-node discovery, paid access, withdrawal and mobile/desktop layouts.
No live file publication or real payment is authorized merely by adding this
task to the backlog.
+5 -3
View File
@@ -128,9 +128,11 @@ does not close a release gate.
## Known release blockers
1. IndeeHub distributed paid playback and supervised cutover rollback.
2. Physical companion background media and video PiP.
3. Framework owner-browser Receive/balance confirmation still documented as
pending in the incident record.
2. Companion native background audio/media; operator accepted delivered Cloud
PiP on 2026-10-07. Detailed interruption/expiry cases remain distinct.
3. Framework Monitoring owner-browser acceptance. The earlier LND startup,
Receive and false-zero incident is closed with operator acceptance; it is
not a release blocker. Paid-file settlement/recovery is a separate open gate.
4. Fleet-wide offline/reconnect and FIPS acceptance.
5. Firewall/tunnel persistence and reboot qualification.
6. HTTPS hostname/trust and companion acceptance.