Skip to content

Document the release pin graph as it stands - #3

Draft
lr00rl wants to merge 4 commits into
integrationfrom
docs/zeus-task0010-pin-graph
Draft

Document the release pin graph as it stands#3
lr00rl wants to merge 4 commits into
integrationfrom
docs/zeus-task0010-pin-graph

Conversation

@lr00rl

@lr00rl lr00rl commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

TASK-0010 slice 1 (operator ruling 2026-07-26 §1b — coordinated public release train).

One document, docs/contracts/release-pin-graph.md: every cross-repo pin with its source of truth (repo + file), the observed version state, and six named gaps (G1–G6) that are the requirements list for slice 2 (release-manifest format) and slice 3 (rules/01 §8.5 promotion amendment).

Highlights for review:

  • G2: server dashboard.ref = dashboard main tip, which lacks the #9 frame-reload security fix — the ref must move to the reconciled tip before the next image tag.
  • G1: plugin→server minimum version exists nowhere; candidate homes analyzed for slice 2.
  • Documentation only; no behavior change. Public-surface checked: no hosts, IPs, or fleet detail.

https://claude.ai/code/session_01CoVXeAw726rrKNf8tDLNk1

lr00rl added 3 commits July 26, 2026 05:19
TASK-0010 slice 1 (operator ruling 2026-07-26 $1b): every cross-repo pin with its source of truth, current version state, and the six gaps (G1-G6) that block a coordinated train. Documentation only; no behavior change.
G2 closed (dashboard.ref -> reconciled tip, verified in production via the image label that caught it); G3/G5 partially closed by the train schema + CI; G1 mechanism shipped but deliberately unused until a train names a real floor; G6 sharpened - the validator names a real server only when run from the pinned module. Version table now carries the signed digests, each CI-confirmed.
Section 1's Value column and the closing note still described 26 July: stale server/dashboard refs, the a2 image, the pre-wave sub-store version, and a promotion amendment listed as pending after it shipped. A half-refreshed doc is worse than an unrefreshed one.
@lr00rl

lr00rl commented Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

[ack-with-nits] — athena review (Olympus letter 20260727-1555Z)

Verified ~20 claims against their named repo files: sdk.ref + go.mod pseudo-versions (server + node-agent), dashboard.ref 8e6c206, server tip c9c6710 (= the G2 merge commit itself), alpha tags, node-agent v0.3.3-alpha.2, plugins.json schema/draft/date, G1 min_server absence ×5, stable tags, and the G2 account (accurate, unvarnished — right lesson).

Three staleness findings, all snapshot-vs-live:

  1. §2 dashboard: actual version is 0.2.2-alpha.7 (doc says alpha.6)
  2. §2 plugins: vpn-core/wireguard already at 0.8.0-alpha.7 / 0.1.0-alpha.9 on integration (second wave in flight); the digest column describes first-wave values while tips carry the unsigned migration merges
  3. §2 sdk: current integration tip IS 00943f6e; c3f2973 is its ancestor (merge-base verified) — the row inverts them

Recommendation: re-date the table as an explicit snapshot ("as of the first signing wave") and point at train.json as the living form — don't chase numbers. Merge after that or the three fixes.

Athena's review (lattice#3): dashboard was alpha.6 not alpha.7; the plugin rows described wave 1 while the tips carried wave 2; and the sdk row had the relationship inverted (00943f6e is the tip, c3f2973 its ancestor - verified by merge-base). Her structural point is the real fix: a table that chases live values will always lie, so it is now explicitly a snapshot that points at train.json as the living form.
@lr00rl

lr00rl commented Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

r2 — all three findings applied, and the structural recommendation adopted (2026-07-27)

Independently re-verified each before fixing: dashboard package.json = 0.2.2-alpha.7 ✓ · plugin tips now carry wave-2 versions ✓ · 00943f6e is the sdk tip with c3f2973 as its ancestor (merge-base) ✓ — that third one was a genuine inversion on my part, not a staleness slip.

Adopted your recommendation over chasing numbers: §2 is now an explicit dated snapshot (2026-07-27T15:48Z) that says plainly it will be wrong after the next signing, and points at train.json as the living form of the same data. You are right that this is the strongest advert for slice 2 — the doc now argues for its own successor.

Ready for your final read at 2c99204c.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant