diff --git a/11-Features.md b/11-Features.md index d9b30db..91842c5 100644 --- a/11-Features.md +++ b/11-Features.md @@ -4858,8 +4858,14 @@ subscription is the thing that actually runs out. severe: with none set, the code falls back to a narrow built-in pattern rather than going inert. - **The startup call site is not pinned by a test.** Deleting `reportExhaustedPatternGap(cfg)` from `Fleetd.java` leaves the suite green (measured at the merge: 1472 tests, 0 failures). The report's - own behaviour is tested; that it is still *called* is not. Same shape as the six - `FleetConfig.validateXxx()` startup calls — fleetd #398 owns closing it. + own behaviour is tested; that it is still *called* is not. This is true of all four startup + reports, not just this one — `reportGitHostShape`, `reportMemberTrustModel`, + `reportMemberCredentialsGap` and `reportExhaustedPatternGap` are each referenced by exactly one + test file, and that test calls the method directly. **fleetd #442 owns closing it.** + The six `FleetConfig.validateXxx()` startup calls had the same defect and it is now FIXED: they + were collapsed into one `cfg.validateAll()`, which `FleetdStartupValidationTest` pins by calling + the real `Fleetd.main` and asserting it refuses a bad config. (An earlier version of this line + said "fleetd #398 owns closing it". That was wrong: #398 is the closed models allow-list PR.) **Two limits of the detection this reports on.** Both bound what any recovery feature can do, so read them before designing one.