diff --git a/docs/specs/SPEC-008-one-host-per-tenant.md b/docs/specs/SPEC-008-one-host-per-tenant.md index c2793de..01b3897 100644 --- a/docs/specs/SPEC-008-one-host-per-tenant.md +++ b/docs/specs/SPEC-008-one-host-per-tenant.md @@ -567,6 +567,7 @@ Moving a tunnel tenant's local shares into its bucket (a `--cloud` re-add covers - DEC-012 (lead, build batch 3): a member's `hits` keeps SPEC-007's rule of one account call and no bucket read, so it never refuses a machine row. It must not print a bare 0 for a link it cannot count: when the count is 0 and the id is not one of this install's own cloud adds (`r2-own`), it prints the count and then `this machine counts cloud links only; if is a machine link, its stats are on the tenant's origin: hits there`. This replaces the round-2 build rule that a member refuses a machine row. - DEC-013 (lead, review fix pass): the Worker passes a 502 through unchanged instead of answering the offline page. TASK-1a(e) measured that a pass-through cannot tell a dead live port (Caddy answers 502 for the closed port, and Cloudflare swaps it for its own page) from Caddy itself being down: both arrive as the same 502. The offline page said "the machine serving this link is offline" for a machine that was up with one dead dev server. Cloudflare's signals for an unreachable origin (530, 520 to 527) still map to the offline page. The cost: with cloudflared up and Caddy itself dead, a visitor sees Cloudflare's 502 page, not the offline page. `WORKER_VERSION` is 4 for it. - DEC-014 (lead, on Han's go, 2026-10-07): P2 reached its end state by direct setup instead of `migrate`. The Air origin held no shares and an empty index, so `migrate` had nothing to carry, and its preflight refused because an ssh session on the Mini cannot write the login Keychain. The Mini ran `share setup s.han.ws --tunnel-name air-share-m --force` from a GUI session (the name `migrate` itself would pick), then the Air ran `share teardown --yes`, which left the DNS record alone (it pointed at the new tunnel) and deleted the `air-share` tunnel. A future move of a non-empty origin still needs `migrate` and a Keychain path that works over ssh. +- DEC-015 (Han, 2026-10-07): D6 ran early, one day after D3, on Han's explicit second go after the lead warned it removes the D3 rollback path. Worker `share-f-d-foundation` is deleted (GET answers 404) and the old `files` publisher token is revoked. A rollback of the fold now starts by redeploying that Worker from v0.8.0 `bin/share`. - Round 1 (seven fresh-context reviewers, 2026-10-01): eleven criticals, all folded. Warnings that do not change the design went to `docs/implementation-notes/one-host-per-tenant.md` for the builder. | Change | Why (reviewer) | diff --git a/docs/verification/one-host-per-tenant.md b/docs/verification/one-host-per-tenant.md index 285c59f..dbac506 100644 --- a/docs/verification/one-host-per-tenant.md +++ b/docs/verification/one-host-per-tenant.md @@ -392,8 +392,9 @@ Han typed the go in the operator session. Snapshots: `tests/prod-snapshot.sh` be | post | ungated local and cloud add; gated local and cloud add with group:dwarves-ops; rm all | 200 no-store; 302 to Access with per-app kid; 404 after rm | pass | | post | `stop` then `start` with one machine and one cloud link | while stopped: machine 503, cloud 200; after start: machine 200, a68960 302, healthz 200 | pass | | P1 (2026-10-07) | Air `brew upgrade share` 0.5.2 to 0.9.0; Mini `share import --probe` | probe output; Air state | `share-import 1`; the Air served s.han.ws with no shares and an empty index | +| D6 (2026-10-07) | early, on Han's explicit second go after the warning that it removes the D3 rollback path: guard (no custom domain and no route uses the script), then DELETE Worker `share-f-d-foundation`; revoked the old `files` publisher token (id prefix d587e267) | `GET workers/scripts/share-f-d-foundation`; token list; live links; pre/post snapshot diff | delete 200, GET 404; revoke 200, 0 matching tokens left; f.d.foundation/ba6377 301, s.d.foundation 302 with kid 514f3068, healthz 200 (s) and 301 (f); the snapshot diff is only the removed script | | P2 (2026-10-07) | `migrate` refused at preflight (`mini-tieubao cannot write and read back a Keychain item`), nothing changed; then DEC-014: Mini `setup s.han.ws --tunnel-name air-share-m --force`, Air `teardown --yes` | s.han.ws/healthz via DoH; Mini `share profiles`; ungated add/rm round trip; post snapshot | healthz 200 three times; `default serving s.han.ws`; add 200, 404 after rm; DNS CNAME points at `air-share-m`, the `air-share` tunnel is gone | Finding (fixed in #47): `setup --alias` prints "nothing was published; the Access app of ba6377 waits in access-pending" at exit after a successful fold. `access_gate` sets `held_access_id` and the fold path never clears it, so the EXIT trap prints a false notice. `access-pending` stayed empty, so nothing is at risk. Fixed in #47, ships with the next release. -Open: the Share Bar After-state box (GUI, not checked), and D6, due on or after 2026-10-13 (delete Worker share-f-d-foundation after seven days, a second go). The old `files` publisher token is revoked at D6. +Open: the Share Bar After-state box (GUI, not checked). D6 ran early on 2026-10-07, so the D3 rollback list no longer applies: rolling back now means redeploying the Worker from v0.8.0 `bin/share` first.