Files
esh-pfi-infrastructure/persistent-memory.d/2026-09-30-worldtree-u11a-off-u11b-gate.md
T

34 lines
3.4 KiB
Markdown

# Worldtree U11a: legacy memory plane OFF; U11b deletion gated; legacy archive (2026-09-30)
`[2026-09-30]` Prime ruled at 0100, in worldtree-dev's session (thread `01M3RNRC8RE87AJ3M6XBNVHAYP`): the legacy plane goes OFF, not read_only, on demo AND personal, as soon as the b192 image (64f79b38) lands. The read_only window was skipped. Accepted risk: skaldsong/wizard-v2, personal's only Tier-3 client, is not remembered until it adopts the record profile.
**The flips:**
- Config went through the config repo, `~/development/worldtree-instance-configs`, and was deployed with `deploy-wt-config`:
- 63cf268 sets writer and reader enabled and `legacy.mode: "off"`;
- 0a1387e captured the U10 memory_tagger and U9 forget-policy host edits that had never reached the repo;
- b6fdd81 enables the #308 metrics on personal.
- DEMO flipped at 0115 and PERSONAL at 0120. The gauge reads `worldtree_memory_legacy_mode{kind="off"} 1.0` on both; personal's reading came after its metrics were added at 0124.
- ⚠ `off` MUST be quoted. PyYAML safe_load is YAML 1.1, so a bare `off` becomes False and the strict LegacyMode enum refuses the boot. I found this at the first flip; worldtree-dev later made the loader say "write it quoted" (7a83f2f1).
- Rollback: `legacy.mode: "live"` in the repo, then deploy.
**The U11b gate (Prime 0320 via worldtree-dev, thread `01M3SGEQDRQD7DWBVT4K73FAHP`):**
- DELETE the live legacy data on both instances after **3 consecutive PASS batches at off**. A FAIL restarts the count.
- infra-hermes runs the daily batch, `scripts/wt-memory-gate-batch`, in a detached worktree at demo's deployed sha. Its exit codes are 0 PASS / 1 FAIL / 2 error / 3 refused / 4 busy.
- Count: 20260930T090608Z PASS (user median 0.83). That run started by accident from a test meant to be `--dry-run`. worldtree-dev's controls 080927Z and 082829Z each FAILed by one flip and were the instrument check, not the streak.
- Step 5 is mine:
1. Run `scripts/wt-h2-count.py` VERBATIM inside each api container. The rehearsal on copies read 0 on both instances.
2. Delete LIVE, with the api running, using literal paths.
3. Send worldtree-dev the stamp.
- b192 re-creates an empty `context_promotion/ledger.db` at boot; that is residue.
- `/embed` retires in b193. Evidence from the Skuld ledger: demo had 436 calls, the last on 08-31; personal had 5, the last on 08-05. Demo's ledger has been idle since 09-14.
**Legacy archive (worldtree-dev GO, done 0957, restore drill passed):**
- corviduo-dev `/var/lib/wt-legacy-archive/` (root 0700, unencrypted): tar.zst plus per-file sha256 plus MANIFEST, demo 51 files and personal 1,426.
- A DEDICATED restic repo: rest-server-nh3 `/nh3-dev/wt-legacy-archive/`, snapshot `98dc64e0`, password `nh3-dev/wt-legacy-archive/restic-password`, mirrored to ana-nas. It is NOT in the main /home sweep, whose 12-month retention would break the 30-day rule.
- The drill: every file's sha matched, sqlite integrity_check was ok, and the one-flipped-byte negative control was caught.
- **Contract rev 1.2: DESTROY WHOLE at retirement-done or 2026-10-30, whichever is first, or on any subject-erasure request.**
1. `rm /var/lib/wt-legacy-archive` on corviduo-dev.
2. `rm /volume1/Backup/restic/nh3-dev/wt-legacy-archive` on nh3-nas.
3. The ana-nas mirror's `--delete` follows; verify it.
4. `secret rm` the password AND purge Vaultwarden's trash (crypto-shred), and check for NAS share snapshots.