authorgravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-05 02:25:55-07:00
committergravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-05 15:36:02-07:00
log58a05c402b8eaf144eb87dba875171880a10b09d
treeb1021b9cc77b7439936846e43fa54f955813d2ba
parent1b39c599adc0da4b903d160236d31172e251645b
signature Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU

Record verified Shale production upgrade

Assisted-by: gpt-6

1 files changed, 2 insertions(+), 0 deletions(-)

tools/shale-migration.md+2
......@@ -58,6 +58,8 @@ The October 5 `r1763-g9f5b1c7.zig.0.16.0` upgrade rehearsal passed anonymous rea
5858
5959Shale allocates an issue number from the issue with the highest SQLite row ID. The importer now inserts by destination number, including remapped collisions. The already-imported database needs `--repair-issue-order` once while its job is stopped: the guarded repair saves a SQLite backup, swaps six imported surrogate IDs, rewrites foreign keys and ledger references, and verifies every table's contents using issue UUIDs. Native IDs, public numbers, timestamps, comments, labels, attachments and history remain intact. It refuses duplicate numbers or changes to native issue IDs. On the repaired native-auth clone, the actual Rust Backend created `home-infra` #41, `react-mutation` #20 and `chat` #8, then commented on and closed the disposable `home-infra` issue. Fresh import, repeated import, repeated repair, and refusal checks passed.
6060
61Production upgraded to `r1763` on October 5 in release `9ef0e1fd9c7a72bc`, from main `38ee0683`. The pre-cutover Shale recovery snapshot is `globe/prod/shale@native-auth-20261005T091312Z`. Fresh normal and guest sign-in callbacks returned 200; the existing Clover session and identity remained intact. All 452 imported issue routes passed concurrent anonymous checks (192 successful reads and 260 expected private-page denials), all 24 attachment hash/access checks passed, and all 556 issues remained unique with valid foreign keys. Native `chat` #1 remains Todo. The live proof is recorded in `/var/lib/studio/shale-upgrade-0680d28c/upgrade-validation.json`.
62
6163The October 4 transport check inspected the then-pinned image in disposable containers without mounting real app data. Its embedded Git endpoint and account settings use HTTP and personal access tokens; no SSH listener, authorized-key interface, or forced-command handler was found. The [official installation](https://astheno.software/shale/installation/) and [configuration reference](https://astheno.software/shale/reference/environment/) also expose HTTP serving and OAuth login without SSH configuration. A `git` account must either use a Shale-aware SSH bridge or await native SSH support. Direct filesystem Git commands would bypass Shale's authorization.
6264
6365Zenith's Shale app directory contains a small SQLite database and 419 MB of owned repositories. `bash tools/import-shale.sh shale-preview-4eea0e3b` copied `data`, `repositories_owned`, and `repositories_mirrors` opaquely from the read-only `storage1/apps@hourly-2026-09-26_05-00` snapshot. It verified checksums and SQLite integrity, then restarted the preview. Both sides had 11 top-level owned repository directories; the preview had one healthy Nomad allocation and returned HTTPS 200. Repository contents were not inspected.