Skip to content

finding(sideshow): findings 006 and 007 from the xorml harvest - #140

Merged
arcaven merged 1 commit into
mainfrom
build/sideshow/harvest-2026-10-02
Oct 2, 2026
Merged

arcaven merged 1 commit into
mainfrom
build/sideshow/harvest-2026-10-02

Conversation

@arcaven

@arcaven arcaven commented Oct 2, 2026

Copy link
Copy Markdown
Member

Two lessons from the xorml work change how doctor findings and reinstalls should be read, and the graph holds neither. Docs only.

item: harvest of aae-orc-xorml half 2 (#138, #139) and aae-orc-mobz8.

changes

  • finding-006: doctor's content census trusted bmad's own manifest, which travels with the content, so an overwrite read as healthy. Records feat(doctor): recompute a store version against the pack's file-manifest.csv #139's end-to-end result and the operator's "yes default" ruling: anchoring to the signed copy waits on aae-orc-wk92.
  • finding-007: install copies over an existing version and never deletes, so a store version holds the union of every source installed at it.
  • question-five-layer-doctor: a layer-1 progress paragraph back-referencing both.

gates: kos validate (7 findings, 0 failures); YAML parses; no em dash outside the kos separator, no banned words, no host names or home paths.

blast radius: _kos/ only.

Refs: aae-orc-xorml, aae-orc-mobz8, aae-orc-wk92

…from the xorml harvest

Refs: aae-orc-xorml, aae-orc-mobz8, aae-orc-wk92

@arcavenai arcavenai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve at c05e69a. Merge recommended.

I traced every code claim against origin/main 1b5d716.

finding-006

  • checkContentCensus (internal/doctor/layer1.go:165) reads _config/files-manifest.csv from inside the store version (:170). That file arrives with the pack content, so the reference is replaced along with the content. The cited c33fdd2 (#137) is on main and predates #139, which is the right "before" anchor.
  • #139's store-file-manifest (registered at layer1.go:29, implemented in internal/doctor/file_manifest.go) recomputes against file-manifest.csv. Its detail strings match the finding: "%d files match" at :112, and "%d differ (first: ...)", with missing and unlisted groups, at :115-122.
  • "The published r2 reports unavailable" is consistent with the artifact. I listed the published bmad-v6.12.0-r2 tarball: it carries no file-manifest.csv among its 2383 entries, because it predates sideshow-packs#40.
  • The 2023 count matches that release's sibling file-manifest.csv (2023 rows).
  • The end-to-end overwrite result and the 2026-09-30 ruling are recorded as observed and relayed. I did not re-run the overwrite.

finding-007

  • InstallFromLocal (internal/pack/pack.go:439-637) does MkdirAll, UnfreezeTree, then a filepath.WalkDir copy, then verifyExecManifest at :569.
  • The only os.Remove calls in the function are the current symlink at :590 and a registry entry at :601. Neither removes store files, so a version directory accumulates the union of its sources, as stated.
  • The survival of the earlier manifest in finding-006's run is what that code predicts.

Node

  • question-five-layer-doctor gains one dated "Layer 1 progress" paragraph that back-references both findings. Nothing else in the node changes, and the PR does not touch a charter.

Numbering, validation, redaction, style

  • 006 and 007 are free: main ends at finding-005, and no other open PR adds a finding.
  • kos validate at head reports 7 findings with 0 duplicate-id failures. Its 5 graveyard-section warnings are on existing nodes, are identical on main, and none are in this diff.
  • I scanned the title, body, commit message and diff for org, client, environment, host and home-path tokens and for instance ids, and found none. A positive control confirmed the pattern matches. The only em dash is the kos separator in the commit subject.
  • There is no first-person plural. The open questions in finding-007 are left open rather than decided.

@arcavenai

Copy link
Copy Markdown
Member

Correction to my review 5391307474 (the verdict stands). I wrote that kos validate shows "5 graveyard-section warnings ... none are in this diff". That was wrong on two counts:

  • kos validate reports 30 nodes: 11 passed, 19 warnings, 0 failed, 0 parse errors.
  • One of the 19 is on question-five-layer-doctor, the node this PR edits: "edge target 'aae-orc::question-sideshow-install-architecture' not found in nodes/".

That warning comes from a cross-graph edge the node already carries. The PR does not cause it: diff of the full kos validate output at origin/main 1b5d716 and at c05e69a differs on one line only: the findings count, 5 to 7.

@arcaven
arcaven marked this pull request as ready for review October 2, 2026 11:57
@arcaven
arcaven merged commit c206f40 into main Oct 2, 2026
10 checks passed
@arcaven
arcaven deleted the build/sideshow/harvest-2026-10-02 branch October 2, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants