Skip to content

Port the post-v0.230.0 development train - #72

Merged
kapoorankush merged 1 commit into
masterfrom
port/v0.231.0
Sep 28, 2026
Merged

kapoorankush merged 1 commit into
masterfrom
port/v0.231.0

Conversation

@kapoorankush

@kapoorankush kapoorankush commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Ports the litclock-dev train that landed after v0.230.0.

Boundary confirmed by content: dev 1e81722b <-> public e6c67886 (tag v0.230.0). Dev range 1e81722b..abbd54b9: four non-stats commits. .gitignore carries only the env.sh staging-file hunk; the dev stats-page hunk stays dev-only.

What changes on a clock

Runtime text rendering, turned on where the device has proved it works (litclock-dev#871 Stage B). The weekly updater already runs an on-device self-test (Stage A, since v0.229.0). Now, when that self-test passes on the same run, the durable pass record matches this release, images/metadata is present as the fallback, and env.sh holds exactly one exported LITCLOCK_RUNTIME_RENDER=false, the updater rewrites it to true under env.sh.lock and logs MIGRATED to runtime text rendering. Any failed guard leaves the device on the pre-rendered images and retries next week. env.sh.sample stays false on purpose: it backfills keys on existing devices, so true there would skip every guard. Fresh flashes get true from first-boot.sh.

Bootcheck rollback actually rolls back (litclock-dev#896), and does not carry text rendering onto a version that never validated it (litclock-dev#894). The rollback copy of update.sh now carries its lib/, so it no longer drops out of rollback mode and installs the bad release again. The rollback also removes the runtime-render marker, so the recovered clock paints the pre-rendered images until the next applied release re-earns it.

The smoke gate now renders the tier the device is actually on, and migration-skipped is an accepted memo token, so a refusal is visible in /api/status instead of reading as null.

Found by reviewing this port, fixed on dev first (litclock-dev#898): sourcing env.sh gave the smoke gate a location, so it began fetching live weather (a slow provider could push it past 60s and block a healthy release) and, on text-tier devices, wrote the live current-quote.png. It now passes WEATHER_ENABLED=false and a throwaway frame directory with env(1), as the self-test does. A bootcheck rollback to a last-known-good older than v0.227.0 no longer fails this release's catalog probes, which that older tree cannot answer. Also litclock-dev#897: the updater's self-test log line no longer says the step changes nothing.

Verified on hardware (bench, before this port)

  • Stage B end to end, control first (refused with no images, then migrated): 2026-09-23.
  • Rollback: control on the unfixed code (marker survived, clock stayed on text) and the fix (marker removed, clock on images), 2026-09-24. Re-run 2026-09-27 after the pre-landing hardening moved the revoke before the reset.
  • Fresh flashes of public v0.219.0 and v0.226.0, on the old 600s update unit: each jumped to a synthetic v0.231.0 (public v0.230.0 plus these files) and migrated on the FIRST tick, in 379s and 373s, then painted text settling at :03; the second tick was a no-op.

The synthetic release differs from this port only in comments, operator-facing text and prose.

Port mechanics

Issue refs requalified on ported lines only (public's own tests/test_issue_ref_namespace.py passes). Conflicts were the ref namespace in context lines, resolved block by block. Every pre-existing public/dev divergence survives the port (checked per file), and maintainer-local paths were stripped from CLAUDE.md (grep -c archives CLAUDE.md = 0). Full suite 4753 passed, ruff and shellcheck clean.

@kapoorankush
kapoorankush marked this pull request as draft September 28, 2026 16:38
@kapoorankush

Copy link
Copy Markdown
Owner Author

Held (converted to draft). The pre-merge /review found that this train's smoke gate, which now sources env.sh, fetches live weather and writes the live frame path on text-rendering devices, so a slow weather provider can revert a healthy release and block it until the next one. Also under investigation: rollback to a last-known-good older than v0.226.0 running this release's catalog smoke probes. Fixing on the development repo first, then this branch is rebuilt.

Runtime-render migration (litclock-dev#871 Stage B), the bootcheck
rollback fixes (litclock-dev#894, litclock-dev#896), and two pre-port
fixes found reviewing this port (litclock-dev#897, litclock-dev#898).
Dev range 1e81722b..abbd54b9.
@kapoorankush
kapoorankush marked this pull request as ready for review September 28, 2026 17:48
@kapoorankush

Copy link
Copy Markdown
Owner Author

Hold lifted. The two findings were fixed on the development repo first (litclock-dev#897, litclock-dev#898), this branch was rebuilt from scratch, and the rebuilt port passed a fresh review with no findings. It also ran on the bench: two real update ticks on the port commit itself. The first applied it and migrated. The second was a no-op on the text tier. On both, the smoke gate passed and left no scratch directory, and its text-tier render did not touch the live frame file.

@kapoorankush
kapoorankush merged commit a2b56a7 into master Sep 28, 2026
5 checks passed
@kapoorankush
kapoorankush deleted the port/v0.231.0 branch September 28, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant