Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/specs/SPEC-008-one-host-per-tenant.md
Original file line number Diff line number Diff line change
Expand Up @@ -567,6 +567,7 @@ Moving a tunnel tenant's local shares into its bucket (a `--cloud` re-add covers
- DEC-012 (lead, build batch 3): a member's `hits` keeps SPEC-007's rule of one account call and no bucket read, so it never refuses a machine row. It must not print a bare 0 for a link it cannot count: when the count is 0 and the id is not one of this install's own cloud adds (`r2-own`), it prints the count and then `this machine counts cloud links only; if <id> is a machine link, its stats are on the tenant's origin: <me> hits <id> there`. This replaces the round-2 build rule that a member refuses a machine row.
- DEC-013 (lead, review fix pass): the Worker passes a 502 through unchanged instead of answering the offline page. TASK-1a(e) measured that a pass-through cannot tell a dead live port (Caddy answers 502 for the closed port, and Cloudflare swaps it for its own page) from Caddy itself being down: both arrive as the same 502. The offline page said "the machine serving this link is offline" for a machine that was up with one dead dev server. Cloudflare's signals for an unreachable origin (530, 520 to 527) still map to the offline page. The cost: with cloudflared up and Caddy itself dead, a visitor sees Cloudflare's 502 page, not the offline page. `WORKER_VERSION` is 4 for it.
- DEC-014 (lead, on Han's go, 2026-10-07): P2 reached its end state by direct setup instead of `migrate`. The Air origin held no shares and an empty index, so `migrate` had nothing to carry, and its preflight refused because an ssh session on the Mini cannot write the login Keychain. The Mini ran `share setup s.han.ws --tunnel-name air-share-m --force` from a GUI session (the name `migrate` itself would pick), then the Air ran `share teardown --yes`, which left the DNS record alone (it pointed at the new tunnel) and deleted the `air-share` tunnel. A future move of a non-empty origin still needs `migrate` and a Keychain path that works over ssh.
- DEC-015 (Han, 2026-10-07): D6 ran early, one day after D3, on Han's explicit second go after the lead warned it removes the D3 rollback path. Worker `share-f-d-foundation` is deleted (GET answers 404) and the old `files` publisher token is revoked. A rollback of the fold now starts by redeploying that Worker from v0.8.0 `bin/share`.
- Round 1 (seven fresh-context reviewers, 2026-10-01): eleven criticals, all folded. Warnings that do not change the design went to `docs/implementation-notes/one-host-per-tenant.md` for the builder.

| Change | Why (reviewer) |
Expand Down
3 changes: 2 additions & 1 deletion docs/verification/one-host-per-tenant.md
Original file line number Diff line number Diff line change
Expand Up @@ -392,8 +392,9 @@ Han typed the go in the operator session. Snapshots: `tests/prod-snapshot.sh` be
| post | ungated local and cloud add; gated local and cloud add with group:dwarves-ops; rm all | 200 no-store; 302 to Access with per-app kid; 404 after rm | pass |
| post | `stop` then `start` with one machine and one cloud link | while stopped: machine 503, cloud 200; after start: machine 200, a68960 302, healthz 200 | pass |
| P1 (2026-10-07) | Air `brew upgrade share` 0.5.2 to 0.9.0; Mini `share import --probe` | probe output; Air state | `share-import 1`; the Air served s.han.ws with no shares and an empty index |
| D6 (2026-10-07) | early, on Han's explicit second go after the warning that it removes the D3 rollback path: guard (no custom domain and no route uses the script), then DELETE Worker `share-f-d-foundation`; revoked the old `files` publisher token (id prefix d587e267) | `GET workers/scripts/share-f-d-foundation`; token list; live links; pre/post snapshot diff | delete 200, GET 404; revoke 200, 0 matching tokens left; f.d.foundation/ba6377 301, s.d.foundation 302 with kid 514f3068, healthz 200 (s) and 301 (f); the snapshot diff is only the removed script |
| P2 (2026-10-07) | `migrate` refused at preflight (`mini-tieubao cannot write and read back a Keychain item`), nothing changed; then DEC-014: Mini `setup s.han.ws --tunnel-name air-share-m --force`, Air `teardown --yes` | s.han.ws/healthz via DoH; Mini `share profiles`; ungated add/rm round trip; post snapshot | healthz 200 three times; `default serving s.han.ws`; add 200, 404 after rm; DNS CNAME points at `air-share-m`, the `air-share` tunnel is gone |

Finding (fixed in #47): `setup --alias` prints "nothing was published; the Access app of ba6377 waits in access-pending" at exit after a successful fold. `access_gate` sets `held_access_id` and the fold path never clears it, so the EXIT trap prints a false notice. `access-pending` stayed empty, so nothing is at risk. Fixed in #47, ships with the next release.

Open: the Share Bar After-state box (GUI, not checked), and D6, due on or after 2026-10-13 (delete Worker share-f-d-foundation after seven days, a second go). The old `files` publisher token is revoked at D6.
Open: the Share Bar After-state box (GUI, not checked). D6 ran early on 2026-10-07, so the D3 rollback list no longer applies: rolling back now means redeploying the Worker from v0.8.0 `bin/share` first.
Loading