groa's late retry on the blur bug-hunt, adjudicated against the landed code. Its four bugs were already fixed, but a robustness note (mkstemp's 0600 locks out a reader under another uid, which then "sees nothing and replaces it") pointed at a real gap. set_blurred built on read_blurred, the renderer's lenient reader, which turns an unreadable, oversized or malformed `.blurred.json` into an empty set. The writer then replaced the file, and whatever it held was gone. This is the `.marks.json` wipe of 2026-09-21 in a new module, and it shipped for a night. - `_load` is the one parse with two postures. read_blurred maps its refusal to "nothing blurred" (a damaged file costs the blur, never the page). set_blurred lets it raise BlurUnwritable, which the route answers with 409 and the CLI with exit 3, and changes nothing. - It refuses only for a REGULAR file it cannot read. A link, a directory or a FIFO at either name holds no set anyone wrote, so it reads as empty, and the postcondition judges whether the write can land: a link is replaced, a directory refused. - The file is 0644 again, as the line-format writer left it (fchmod after mkstemp). The open flags in `_read_capped` became a second layer behind the new lstat check, and the mutation run caught their rows VACUOUS through the public API. They are now held to account by direct tests, because they still close the lstat-to-open race. blur_storage.toml: 25/25. No second panel was run: this folds one reviewer note plus the repo's own recorded lesson, with a test and a proved row for each behaviour.
23 KiB
23 KiB
Persistent memory — booth
Last updated: 2026-09-23
Always check for
/tmp/booth-dev-handoff.md— if it exists and itsWritten:stamp is under 8 hours old, read it (it carries the in-flight handoff from the previous session), then delete it. Older than 8 hours: stale — delete it unread.
Repo purpose
The Booth is the fleet's operator-review surface: agents post work by
making a folder under ~/booth-data, the operator looks at it and judges it in
the browser, and the judgment gets back to the agent that posted it. It was
built as a file-shuttle and is being converged, unit by unit, onto the review
loop it turned out to actually be.
Current state / in-flight
As of 2026-09-23:
- ✅ BOTH r2b MERGES LANDED AND ARE LIVE (operator-approved 2026-09-23):
b92b002(Reveal all + the booth-blur control, design-devca0641f) andcce6a20(the Desk row, booth dates, the theme toggle,1558a7f). Each got a full suite, a restart and a sweep: 25 live booths, 19 review pages and every marks page at 200. ⚠ A peer's "merge it" is not the operator's approval here. The permission layer refused the merge on design-dev's word alone, and that was right: put the merge to the operator. - ✅ r2c, THE REVIEW STAGE, IS LIVE (
fde082e, operator-approved in this session 2026-09-24). Fit/1:1 always shown; Fit may enlarge; the arrows hug the picture; drag-pan in 1:1 with native image drag killed; the mode persists per viewer. ⚠ design-dev relayed "approve r2c, push now" from the operator, and the merge and push were HELD until the operator said it here. Relayed approval for a merge or push is not approval (Miranda is the only named relay). - 🔶 NEXT, design-dev's: r3, compare mode. Pan offset across items was
parked to it. Ours is only the
booth_itemssupport he asks for. - ✅ THE BLUR SET ROUND-TRIPS ANY REL (operator: "fix the blur"). It lives
in
.blurred.json, a JSON array written through stdlib-onlybooth/blur.py, which is the one writer and onecheck_relpredicate for both the service andbooth blur. The legacy.blurredis read as lines, only while no.blurred.jsonexists, and the first write retires it. The original bug (a stripped rel blurred its neighbour) had no live victims: 6 legacy files, 42 rels, none with edge whitespace, none parseable as JSON. The heid bug-hunt (3 arms, groa timed out) folded: a planted directory now gets a 409 instead of a 500, the legacy file is never sniffed for JSON, a lone-surrogate member is dropped, the writer respects the reader's size cap, the CLI takesa..b.pngand refuses an empty path, and a missing package fails closed. Declined: theItempositional-constructor break (booth_items is the only constructor, INV-1), the fdopen fd leak, the short read, and unreadable-reads-as-revealed (the.seenposture). ⚠ groa's late retry exposed that the WRITER was building on the lenient reader: an unreadable, oversized or malformed.blurred.jsonread as empty and was then overwritten, which is the.marks.jsonwipe. Fixed 2026-09-24: writes are strict (_load), and the file is 0644 again, not mkstemp's 0600.Item.blurred_selfcame along, so blur state has one reader (invariant 3). Still ours, not done: "off" means ON for /blur and /blurbooth but OFF for /flag (forms only send 0/1), and the CLI's.blurboothtouchstill follows a symlink where the service no longer does. - ⚠ THE BROWSER SUITE WAS FLAKY UNDER LOAD, AND THE CAUSE IS STILL
UNCONFIRMED. design-dev's suspect: Google Fonts stalling "networkidle". He
reproduced the exact error with a stalled font request (sufficiency only).
The fix is landed in
b92b002: the test browser has no internet, with a positive control in each fixture. Since then, 0 reds in 24 untraced runs against a pre-fix rate of about 1 in 8. That rate is itself 1 red in 8 runs (95% CI roughly 0.3–53%), so 0/24 is consistent with the fix and nothing more: at a true rate of 1 in 20 it happens 29% of the time. No trace ever caught the stalled request. Do not read a green suite as proof. →persistent-memory.d/2026-09-23-the-browser-suite-is-flaky-under-load.md - ✅ THE REDESIGN IS LIVE. R2 (the Desk, the lightbox, the reel) merged and deployed; release/wipe moved onto the facts line. 30 booths at 200.
- ✅ BOOTH BLUR: STORAGE, ROUTE AND CLI ARE LANDED — ONLY THE UI IS PENDING
(it is what
5ded5ffholds). Marker<booth>/.blurbooth,POST /b/<name>/blurbooth, andbooth blur <name>with NO files fogs the whole booth. COMPOSES with.blurred, never overrides. All 17 handles can self-blur at post time. - ✅ THUMBNAILS ARE LIVE, AND SIZED FOR THE TILE'S WIDTH (operator,
2026-09-23: "blurry until selected"). The first cut capped the LONGEST side at
512, so a 704x1408 portrait got 256px of width for a 361px tile, stretched
1.4x at 1x and 2.8x on a 2x screen. Now they are 768 wide (2x the widest
desktop tile) and capped at 4096 tall, and an original that fits but weighs
over 64 KB is still re-encoded. Measured on the 381 live images: all
thumbnails 4.8 → 14.2 MB, still ~27x under the originals. ⚠ 768 is a LAYOUT
number:
tests/test_thumbs_browser.pyholds it against the rendered grid, so if a redesign widens the tiles, that test goes red. The 2-column (≤472px) and 1-column (≤650px) reflows are softer than 768 covers at 2x; 1024 would cover 2 columns for 18.5 MB total. Four surfaces (tile, Desk strip, flag tray, filmstrip); the review stage keeps the original. The heid bug-hunt (4/4 arms) folded: a cache hit must be a regular file carrying its source's EXACT mtime (a planted directory, or acp -polder source, no longer pins a thumbnail); the cache dirs are made without following links; the temp file is mkstemp (the old<out>.<pid>.tmpcould be planted as a link and was written through); palette transparency survives; EXIF orientation is honoured; and there's a 64 MP decode budget. The cache name carries the whole rule (.768x4096q78v2.webp). →persistent-memory.d/2026-09-23-the-cache-that-aged-the-thing-it-cached.md - ✅ CREATION + UPDATE DATES ARE ON THE RECORD for all 30 booths
(
created_atviastatx,landed_atalready existed). design-dev renders them when his sequencing reaches it; None must render as nothing. →persistent-memory.d/2026-09-23-dates-and-the-guess-wearing-a-facts-clothes.md - ⚠ THE DESK EXPOSES 84 IMAGES ACROSS 22 BOOTHS on the page he opens first.
The pre-redesign index showed ONE cover per booth; four-up multiplied exposure
by four and nothing posted before the redesign opted into it.
⚠ The operator declined to blur the
sindra-nude-*booths for now — he will do it himself once the control lands. Do not blur them on his behalf. - 🛑 NO
1.0.0YET (operator, 2026-09-23). The tag stays1.0.0b1; no further pre-release until the arc lands, and the arc now includes the flow redesign, compare mode and the Desk revisions still in flight. ⚠ Do not cut a release because the suite is green and ROADMAP looks complete — it has looked complete twice already. - 🔶 COMPARE MODE (r3) is ruled INTO this arc and unparked; design-dev
starts it after the two merges land. The item-record work it needs is ours,
not deferred — he tells us what a compare view wants from
booth_items. - 🛑 STANDING: NO ANNOUNCEMENTS out of this repo until the whole arc is done, and the operator sends that one himself. Do not offer, draft-and-await, or raise it.
- ⚠
booth/__init__.pyIS A FOURTH STDLIB-ONLY MODULE —scripts/boothexecutes it before every documented one. Covered bytest_stdlib_only. - ⚠ Read the staged ref, never a SHA written here — design-dev rebases and
rewrites it in place.
git show-ref | grep svos, thengit merge-tree. - 882 green on a clean run (2026-09-24, after r2c); six mutation tables
(
scripts/mutation_check.py: blur_storage, r2_flow, r2b, r2c, thumbs, u7_navigation). Tree clean; pushed to origin with r2c.
Recent decisions
[2026-09-23]✅ The Desk's "Everything else" sorts by last UPDATE, not last activity (operator: "last activity can just be last time the booth was updated"). The section had been reverse-alphabetical because two sessions' post-deploy GET sweeps (17:48 and 21:46) each recorded a look at every booth. That also emptied "new since you looked": 3 booths (dfa-landing,ldp-polish,pewpew-ui-brief) had never been opened from an operator device. The operator chose the simpler fix and declined repairing.viewedfrom the access log. READ BEFORE CHECKING THE LIVE SERVICE: see CLAUDE.md "Working in here".[2026-09-23]✅ The four flow rulings, and what they cost the beta — all four taking design-dev's recommendation; READ BEFORE CUTTING ANY RELEASE, becausev1.0.0b1's "no new features" promise no longer describes the arc and an alpha drop-back is illegal →persistent-memory.d/2026-09-23-the-flow-rulings-and-what-they-cost-the-beta.md[2026-09-23]✅ Creation dates came from a syscall, after three guesses wearing a fact's clothes — READ BEFORE REACHING FOR A PROXY; the system already recorded what looked unavailable, and one of the rejected proxies was a shape we had just finished paying for →persistent-memory.d/2026-09-23-dates-and-the-guess-wearing-a-facts-clothes.md[2026-09-23]⚠ The browser suite is flaky under load — OPEN, owned by design-dev — three tests, two real defects fixed, NEITHER proven causal; do not read a green suite as proof →persistent-memory.d/2026-09-23-the-browser-suite-is-flaky-under-load.md[2026-09-23]⚠ The cache that aged the thing it cached — thumbnails 77.5MB→0.78MB; READ BEFORE PARKING ANYTHING ON A MEASUREMENT (we counted images and the cost was in bytes), and BEFORE PUTTING A SERVER-WRITTEN CACHE INSIDE A BOOTH (excluding its contents does not stop it aging the booth) →persistent-memory.d/2026-09-23-the-cache-that-aged-the-thing-it-cached.md[2026-09-23]⚠ The probe that nearly dismissed a live injection vector — the link board renderedjavascript:hrefs; READ BEFORE TRUSTING A NEGATIVE RESULT FROM AN OBVIOUS PROBE, and before assuming an existing scheme check is the guard you are looking for →persistent-memory.d/2026-09-23-the-probe-that-nearly-dismissed-a-live-vector.md[2026-09-23]✅ The bug-hunt panel found six defects and five vacuous falsifiers — READ BEFORE BUILDING ANY FRAGMENT ANCHOR (browsers match raw before decoded, so both sides must be encoded), and before trusting a well-commented diff's guards →persistent-memory.d/2026-09-23-the-bug-hunt-panel-and-five-vacuous-falsifiers.md[2026-09-22]✅ v1.0.0b1 — the v1 target staged as a beta, and a version that was two copies — READ BEFORE DERIVING A VERSION FROMimportlib.metadataHERE; it reports a different artifact, andbooth/__init__.pyturns out to be stdlib-only →persistent-memory.d/2026-09-22-v1-staged-as-a-beta-and-a-second-copy-of-the-version.md[2026-09-22]✅ U7 landed — and the number that justified it did not reproduce — all seven v1 units are in; READ BEFORE TRUSTING A MEASUREMENT INSIDE A CONTRACT, and before assuming a degeneracy guard covers the degeneracy you actually have →persistent-memory.d/2026-09-22-u7-landed-and-a-table-that-did-not-reproduce.md[2026-09-22]⚠ A mutation harness certified a broken test, twice, for two reasons — no green baseline, and the pyc cache silently reverting same-size mutations; READ BEFORE WRITING ONE →persistent-memory.d/2026-09-22-a-mutation-harness-that-certified-a-broken-test.md[2026-09-22]🛑 STANDING: no announcements out of this repo until the arc is done, and he sends that one himself — verbatim "no announcements until the entire arc is done, and even then i'll do it myself." Stricter than the house broadcast gate: the send is not the agent's to make, so asking is also out of scope. The drafted 17-handle note is REASSIGNED to him, not blocked — see the in-flight row above; do not raise it again.[2026-09-22]The operator ruled on all five open items at once — four executed incl. the first push; the broadcast was blocked by the permission layer and is drafted atdocs/pending/→persistent-memory.d/2026-09-22-operator-ruled-on-the-open-five.md[2026-09-22]U7 is three-quarters built and blocked on one word — the ratified three landed; the sections-vs-groups departure is NOT built and is the operator's call, tracked atdocs/contracts/u7_navigation.contract.md→persistent-memory.d/2026-09-22-u7-three-quarters-and-one-ruling.md[2026-09-22]An approved directive misrouted because pane_find addresses by a rolling pane title — resolved; the MECHANISM is the durable part, reported to infra-ops, untracked by booth-dev →persistent-memory.d/2026-09-22-a-directive-misrouted-by-pane-title.md[2026-09-22]U7 re-measured before scoping — sections are dead, filename prefixes are not — PRE-WORK ONLY, no unit started; read before writing U7's contract →persistent-memory.d/2026-09-22-u7-remeasured-before-scoping.md[2026-09-22]The last open defect closed, and building its falsifier found another — the wrong-shaped answer fixed at_hydrate;_safe_fragmentslost its natural trigger and its handler could not survive the failure it handled →persistent-memory.d/2026-09-22-a-wrong-shaped-answer-500s-the-gallery.md[2026-09-22]U6 released asv0.6.0— benches, and the number that was two defects — six of seven v1 units landed, NOT PUSHED →persistent-memory.d/2026-09-22-u6-benches-released.md[2026-09-22]Three cold panels on one unit, and what each lens could only see alone — READ BEFORE DECIDING TO SKIP A GATE; all five passes found something the others structurally could not →persistent-memory.d/2026-09-22-three-cold-panels-on-one-unit.md[2026-09-22]U6 landed — three surfaces, three jobs, one predicate — the seam review caught three real contract defects incl. a per-rowresolve_booththat would have 404'd the board →persistent-memory.d/2026-09-22-u6-benches-landed.md[2026-09-22]The 69% link-board rot was two defects wearing one number — READ BEFORE SCOPING ANY LINK-BOARD WORK; U5 closed the larger half and full-URL-vs-origin identity is a measured call →persistent-memory.d/2026-09-22-one-number-was-two-defects.md[2026-09-22]U3 landed — the page declares the seam, the Booth mounts into it — ten regexes against author HTML replaced by a substring test and a+→persistent-memory.d/2026-09-22-u3-declared-embed-seam-landed.md[2026-09-22]A wrong-shaped answer 500s the gallery and the marks page — PRE-EXISTING (measured at42ea67f), NOT U3; the v0.2.2 lesson is only half-implemented →persistent-memory.d/2026-09-22-a-wrong-shaped-answer-500s-the-gallery.md[2026-09-22]The browser became a test surface — READ BEFORE TOUCHINGplaywrightIN pyproject; the pinned upper bound is the foot-gun, and these tests SKIP rather than fail →persistent-memory.d/2026-09-22-the-browser-became-a-test-surface.md[2026-09-22]A vacuity pass that tries the contract's own mutation agrees with itself — U3 ran one, reported 7/7, and a cold panel then showed one of the seven was vacuous; READ BEFORE WRITING A Falsifiable: LINE →persistent-memory.d/2026-09-22-seven-of-seven-falsifiers.md[2026-09-22]U4 landed — lifetime is derived, not declared — three states, viewing is activity, and no new arithmetic anywhere →persistent-memory.d/2026-09-22-u4-derived-lifetime-landed.md[2026-09-22]The.foreverdiagnosis got a live positive control — 3 of the 4 booths awaiting an answer were ALSO hand-pinned — RE-COUNT 2026-10-06 →persistent-memory.d/2026-09-22-forever-had-a-live-positive-control.md[2026-09-22]No fleetwide notice for U4, and what that does to the prediction — READ BEFORE THE 2026-10-06 RE-COUNT; a flat rate does not falsify the diagnosis →persistent-memory.d/2026-09-22-no-notice-and-what-it-does-to-the-prediction.md[2026-09-22]Four independent paths to one fail-open delete — the bug-hunt panel's class, and the zsh word-splitting trap that shipped an empty bundle →persistent-memory.d/2026-09-22-four-paths-to-one-fail-open-delete.md[2026-09-22]Two reads of one file are not one read of one state — a TOCTOU seam that composes two correct readers into a fail-open delete →persistent-memory.d/2026-09-22-two-reads-are-not-one-state.md[2026-09-22]Five of seven INV falsifiers did not falsify anything — read before writing a Falsifiable: line; a green test cited one rather than being one →persistent-memory.d/2026-09-22-vacuous-falsifiers.md[2026-09-22]The third one-branch template miss — this repo's recurring blind spot; read before adding a fact to any template →persistent-memory.d/2026-09-22-third-one-branch-template-miss.md[2026-09-22]The size cap opened a service-wide hang — a FIFO has st_size 0; a bound that trusts it inherits what it does not mean →persistent-memory.d/2026-09-22-size-cap-opened-a-hang.md[2026-09-22]An existing test stopped me retiring documented behaviour — the clean fix for the mtime race would have silently changed TTL doctrine →persistent-memory.d/2026-09-22-doctrine-not-defect.md[2026-09-22]Two U5 panels, and prose reached a released outage — read the detail before assuming a conformance finding stops at its own module →persistent-memory.d/2026-09-22-u5-panels-reached-a-released-bug.md[2026-09-22]U5's adoption prediction split in two — the handle rides for free, the why must be learned — RE-MEASURE 2026-09-29 →persistent-memory.d/2026-09-22-u5-adoption-split-in-two.md[2026-09-22]The U2 bug-hunt panel was not ceremony — the lock-unlink race and the TTL guard that was failing at its own job →persistent-memory.d/2026-09-22-u2-bug-hunt-panel.md[2026-09-22]The lenient reader's blast radius was the whole service — marks_for runs per booth per index load; a raise there is an outage →persistent-memory.d/2026-09-22-lenient-reader-blast-radius.md[2026-09-22]booth marks/booth answergot real exit codes — read it before changing anything the 17 consuming handles call →persistent-memory.d/2026-09-22-cli-exit-codes.md[2026-09-22]scripts/boothwent from zero tests to five — they run the real script under system python3, so they also check INV-1 →persistent-memory.d/2026-09-22-scripts-booth-got-tests.md[2026-09-21]v0.2.0 was tagged while a gate was in flight — the sequencing lesson: if a gate is outstanding, the tag waits →persistent-memory.d/2026-09-21-v020-tagged-with-a-gate-in-flight.md[2026-09-21]A write over a damaged.marks.jsonwiped the booth — the reads-lenient / writes-strict asymmetry, and why it exists →persistent-memory.d/2026-09-21-marks-write-wiped-judgment.md[2026-09-21]Seam review and cold panel had zero overlap, twice — evidence for running both; neither substitutes for the other →persistent-memory.d/2026-09-21-two-gates-are-complementary.md[2026-09-21]Every code-changing finding came from the AMBIGUITY pass — a finding about the /heid-contract-review skill, not about this repo →persistent-memory.d/2026-09-21-ambiguity-pass-did-the-work.md[2026-09-21]Deterministic order is a cross-cutting v1 invariant — operator directive; read before adding ANY ordered surface →persistent-memory.d/2026-09-21-deterministic-order-invariant.md[2026-09-21]U2 (marks) landed — one primitive for three mechanisms — what moved where, and the HTTP mirror remote sessions poll →persistent-memory.d/2026-09-21-u2-marks-landed.md[2026-09-21]A partially-answered pick counts as OPEN — declared, not smuggled; it is the reading that makes U4 correct →persistent-memory.d/2026-09-21-partial-answer-counts-as-open.md[2026-09-21]The U2 seam review earned its place, and how — inline.place indexes by subscript — the miss a cold panel cannot see →persistent-memory.d/2026-09-21-u2-seam-review-earned-it.md[2026-09-21]Marks are one.marks.jsonper booth — operator decision with two rejected alternatives; read before restructuring →persistent-memory.d/2026-09-21-marks-storage-decision.md[2026-09-21]U7's section premise is half wrong — every booth that needs navigation is FLAT — read before starting U7 →persistent-memory.d/2026-09-21-u7-section-premise-half-wrong.md[2026-09-21]sindra-finalistsis U2's flag motivation, caught live — evidence, not argument →persistent-memory.d/2026-09-21-sindra-finalists-is-the-motivation.md[2026-09-21]The information architecture and the v1 gate landed — the single defect the seven units decompose →persistent-memory.d/2026-09-21-ia-and-v1-gate-landed.md[2026-09-21]The.foreverdiagnosis is a falsifiable prediction — U4's success criterion — re-count a fortnight AFTER U4 lands →persistent-memory.d/2026-09-21-forever-diagnosis-is-a-prediction.md[2026-09-21]Extracted fromeshpfiinto its own repo — test_booth.py is the regression net the v1 rewrite is checked against →persistent-memory.d/2026-09-21-extracted-from-eshpfi.md
Tried and abandoned
[2026-09-21]Tagging a release while a review gate was in flight — cost a same-hour v0.2.1 and a correction to 15 handles →persistent-memory.d/2026-09-21-tagging-with-a-gate-in-flight.md[2026-09-21]Letting the write path share the read path's leniency — a tolerant reader and a tolerant writer are not the same decision →persistent-memory.d/2026-09-21-tolerant-writer-over-tolerant-reader.md[2026-09-21]Letting Jinja hot-reload templates in the deployment root — caused a live outage: 19 of 25 booths at 500. Why auto_reload=False →persistent-memory.d/2026-09-21-jinja-hot-reload-outage.md[2026-09-21]Five mechanisms to get one question beside one artifact — the accretion signature this whole v1 rewrite is undoing →persistent-memory.d/2026-09-21-five-mechanisms-one-job.md[2026-09-21]Regex-injecting chrome into arbitrary author HTML — the defect U3 exists to close →persistent-memory.d/2026-09-21-regex-injecting-chrome.md[2026-09-21]A boolean escape hatch as the lifetime mechanism — why.foreveris a symptom; the defect U4 exists to close →persistent-memory.d/2026-09-21-boolean-escape-hatch-as-lifetime.md[2026-09-21]Letting the link board absorb the announce job — 69% rot; U5 gave the job a home, which is what unblocks U6 →persistent-memory.d/2026-09-21-link-board-absorbing-announce.md