1.1 is code-complete: CB-586 and CB-606 merged
Moves both into the Done table with what they actually were, turns their diagram boxes green, and cuts the Open list to CB-596 alone — the one item no session can close, because the probe it needs is refused by the command classifier. Commit count 204 -> 211.
+15
-11
@@ -227,11 +227,14 @@ guards regression-protected · `CB-521` the AMQP contract test runnable both loc
|
||||
|
||||
## Release 1.1 — the single-host close-out (open)
|
||||
|
||||
`v1.0.0` was tagged **2026-08-10**, message *"One leader, one host, complete"*. Since then **204
|
||||
`v1.0.0` was tagged **2026-08-10**, message *"One leader, one host, complete"*. Since then **211
|
||||
commits** have landed on `main` with **no tag**. So the stage tables above are true and still leave
|
||||
the obvious question unanswered: what is actually left before the single-host story can be called
|
||||
finished?
|
||||
|
||||
**The answer, as of 2026-08-16 night: nothing that a session can do.** Every code item in 1.1 is
|
||||
merged. What is left is CB-596, which needs the operator, and the redeploy-and-tag steps below.
|
||||
|
||||
Gitea milestone: **`1.1 — single-host close-out`**. The admission rule is one sentence — **if it
|
||||
would still be broken with exactly one host, it belongs in 1.1.** Read strictly, that rule sent four
|
||||
tickets to 2.0, not one — see *Deferred to 2.0* below. The distinction it turns on: a capability that
|
||||
@@ -260,13 +263,13 @@ flowchart LR
|
||||
r1 --> r2
|
||||
classDef done fill:#2f855a,stroke:#22543d,color:#ffffff;
|
||||
classDef todo fill:#b7791f,stroke:#7b341e,color:#ffffff;
|
||||
class sup,dur,sec,bugs,cfg,flaky,ask,docs done
|
||||
class val,op,wip,fed,defer todo
|
||||
class sup,dur,sec,bugs,cfg,flaky,ask,docs,val,wip done
|
||||
class op,fed,defer todo
|
||||
```
|
||||
|
||||
*Figure: the 1.1 milestone by theme, as of 2026-08-16 evening. Green is merged; amber is open.
|
||||
CB-604 is merged but shares its box with CB-606, which is not — the box stays amber until both land.
|
||||
Everything on the left is single-host work; the right is release 2.*
|
||||
*Figure: the 1.1 milestone by theme, as of 2026-08-16 night. Green is merged; amber is open. One
|
||||
amber box is left, and it is the one no session can close: CB-596 needs the operator to run a probe
|
||||
the command classifier refuses. Everything on the left is single-host work; the right is release 2.*
|
||||
|
||||
### Done — merged and verified
|
||||
|
||||
@@ -279,16 +282,16 @@ Everything on the left is single-host work; the right is release 2.*
|
||||
| **Config accuracy** | CB-597 (#85) · CB-599 (#89) · CB-602 (#96) · CB-604 (#102) | Two documented knobs that are read by nothing; a capacity refusal that surfaced as a bare HTTP 500; no test at all in the code→example direction, so a brand-new key could ship undocumented; and an unknown `kind:` accepted silently and routed to the wrong adapter, which now refuses at config load. |
|
||||
| **Catalogue debt** | CB-595 (#81) | `wiki/11-Features.md` had fallen about fourteen entries behind, worst on the entries that changed what a config key *means*. `bridged.yaml` is gitignored, so that page is the only place an operator could learn them. Cleared — and it turned up two defects on the way (CB-604, CB-606). |
|
||||
| **Green build** | CB-601 (#95) · CB-603 (#100) | Two flaky tests, same root: a test that observes an asynchronous loop must be safe against that loop's thread, and neither the compiler nor a green build will say it is not. |
|
||||
| **Config validation** | CB-604 (#102) · CB-606 (#106) | Four config fields shared one shape: lower-cased in a compact constructor, then compared against exactly **one** string, so a typo fell through to the other branch in silence. The worst was `auth.mode` — a typo of `token` behaved as `loopback-trust`, and `validateAuthExposure()` only fires on a **non-loopback** bind, so the common loopback bind hid it end to end and the daemon authenticated nobody while the config said otherwise. All four now refuse at load, naming the field, the value, the accepted set, and what would have happened. |
|
||||
| **Snapshot pruning** | CB-586 (#67) | Nothing pruned `refs/wip/*`, so CB-578 stage C's snapshots pinned their whole trees forever. The rule that landed needs **both** conditions: the tree is already reachable from `main`, and the ref is older than 24h. Reachability is the floor — a snapshot exists because the work was committed nowhere else, so a plain TTL would delete the only copy. `/members` now reports `wipRefs{count,costBytes}`. The sweep shipped **dead**: a `Long.MIN_VALUE` "never yet" sentinel overflowed the interval gate, which returned before the assignment that would have fixed it, so it never ran once — and every unit test passed, because they all called the seam directly and walked around the gate. |
|
||||
|
||||
### Open
|
||||
|
||||
Three, as of 2026-08-16 evening.
|
||||
One, as of 2026-08-16 night — and it is not code.
|
||||
|
||||
| Theme | Ticket | The point |
|
||||
|---|---|---|
|
||||
| **Config validation** | CB-606 (#106) | CB-604 fixed one field, and its brief asked the worker to *report* others with the same shape rather than fix them. It found three. The `auth.mode` one is worse than the original: a typo of `token` silently behaves as `loopback-trust`, and `validateAuthExposure()` only fires on a **non-loopback** bind — so a loopback bind hides it completely, and the daemon runs with **no authentication** while the operator believes it is authenticated. |
|
||||
| **Snapshot pruning** | CB-586 (#67) | Nothing ever prunes `refs/wip/*`, so CB-578 stage C's snapshots pin objects forever. In flight. |
|
||||
| **Needs the operator** | CB-596 (#82) | CB-592 blocks one credential name; the pane's login shell re-sources about thirty, and a second forge token is among the untouched ones. The probe that would enumerate them is refused by the command classifier, so this one cannot be closed from inside a session. |
|
||||
| **Needs the operator** | CB-596 (#82) | CB-592 blocks one credential name; the pane's login shell re-sources about thirty, and a second forge token is among the untouched ones. The probe that would enumerate them is refused by the command classifier, so this one cannot be closed from inside a session. `scripts/probe-member-credentials.sh` is committed and the ask is posted; it prints a name, a state, a length and a hash, never a value. |
|
||||
|
||||
### Deferred to 2.0 — the cut decision
|
||||
|
||||
@@ -303,7 +306,8 @@ Made 2026-08-16, by reading the admission rule strictly.
|
||||
|
||||
### Before the tag
|
||||
|
||||
1. Land or defer CB-606 and CB-586. CB-596 needs the operator.
|
||||
1. ~~Land or defer CB-606 and CB-586.~~ Both merged. CB-596 needs the operator and is the
|
||||
only 1.1 item still open.
|
||||
2. **Redeploy the daemon.** Every merge in 1.1 is undeployed — the running `bridged` holds the jar it
|
||||
started with. A merge is not a deployment. Run `scripts/redeploy-bridged.sh` once the fleet has
|
||||
drained; a restart drops in-flight tickets and rendezvous.
|
||||
|
||||
Reference in New Issue
Block a user