docs(positioning): the forge is publicly reachable, and two claims were false #1412
No reviewers
Labels
No labels
bump
major
bump
minor
bump
patch
kind/bug
kind/chore
kind/docs
kind/feature
priority/critical
priority/high
priority/low
priority/medium
size/L
size/M
size/S
size/XL
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
frankenbit/release-toolkit!1412
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "i/1404-positioning-access-model"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The README positioned the project around
git.frankenbit.debeing LAN-only and the demo being invisible anonymously. Neither was true, in opposite directions.Closes #1404
Intended-targets: #1404
Verified before changing anything
🔑 Split-horizon DNS is why it survived. From every internal seat the claim reads as true, and the query that refutes it is the one nobody thinks to run about their own house.
What changed
.gitea/workflowsand will not resolve a.forgejo/path (#1092).docs/integration.mdsaid "It has no public mirror" while the README described the gitea.com mirror. Our own docs contradicted each other; both now say the same thing.The demo claim was false in the other direction
It said the repository was "not visible to an unauthenticated reader".
So the
v0.1.0really is unreachable — the right conclusion from a false premise. Per AC2 no pointer is given at all, rather than one resolving to nothing.🔴 Four broken links, found by fetching every citation anonymously
Not by reading them. The README's second line cited tmux-tell's releases as evidence the toolkit cuts real releases — and
tmux-tellis private, so that URL is404to exactly the reader the sentence is addressed to. Same foralcatraz-infra#528, twice, inintegration.md.All are now named as private rather than linked into a 404, and the positioning section warns that a private-repo link returns
404anonymously, which is indistinguishable from a deleted one.Not changed, deliberately
arch.saratow.netstays "LAN-only" in the C4 docs — I checked, and it genuinely is: public DNS resolves it, the public IP refuses the connection. Only the claims that were false were changed.CHANGELOG.mdentries are history and are left as written.go testrc=0 ·vetrc=0 ·fragment-checkrc=0 ·register-checkrc=0 ·changelog-bodyrc=0 ·gitea-twinrc=0 · bats 197 ok / 0 not-ok ·git diff --checkclean.🤖 Generated with Claude Code
https://claude.ai/code/session_01LUEggQMJjaizj2nFVofeyH
release-toolkit#1404. Verified independently before changing anything: 1.1.1.1 / 8.8.8.8 git.frankenbit.de -> 84.167.207.153 PUBLIC 192.168.178.3 -> 192.168.178.4 anonymous, forced to the public IP: repo 200 - API 200 - raw README 200 SPLIT-HORIZON DNS IS WHY THIS SURVIVED. From every internal seat the LAN-only claim reads as true, and the query that refutes it is one nobody thinks to run about their own house. WHAT CHANGED - The positioning says the forge is publicly reachable and this repository is anonymously readable, with private projects private per repository. - The mirror's remaining purpose is stated as GITEA COMPATIBILITY, not reachability: a Gitea engine reads `.gitea/workflows` and will not resolve a `.forgejo/` path (#1092). - `docs/integration.md` said "It has no public mirror" while the README described the gitea.com mirror. Our own docs contradicted each other. - The cold-read ZIP step is RETIRED. Its premise was that a reviewer had nowhere to look; an archive is now strictly worse, being a snapshot that drifts and costs the reviewer the ability to see what changed since. THE DEMO CLAIM WAS FALSE IN THE OTHER DIRECTION. It said the repository was "not visible to an unauthenticated reader". gitea.com/FrankenBit/tic-tac-toe returns 200 and is publicly readable -- and carries 0 tags and 0 releases, so the "live v0.1.0" is genuinely unreachable. The right conclusion from a false premise. No pointer is given rather than one that resolves to nothing. FOUR BROKEN LINKS FOUND BY FETCHING EVERY CITATION ANONYMOUSLY rather than reading them. The README's second line cited tmux-tell's releases as evidence the toolkit runs real cuts; tmux-tell is private, so that URL is 404 to exactly the reader the sentence is addressed to. Same for alcatraz-infra#528, twice, in integration.md. All now named as private rather than linked into a 404, and the positioning section warns that a private-repo link is indistinguishable from a deleted one. NOT CHANGED, deliberately: `arch.saratow.net` is described as LAN-only in the C4 docs and it genuinely is -- public DNS resolves it, the public IP refuses the connection. CHANGELOG entries are history and are left as written. go test rc=0 - vet rc=0 - fragment-check rc=0 - register-check rc=0 - changelog-body rc=0 - gitea-twin rc=0 - bats 197 ok / 0 not-ok. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LUEggQMJjaizj2nFVofeyHThis red is CODE-attributable.
At least one step started and failed, so the failure is inside the job. The log is worth reading.
Posted by
page-ci-attribution.sh(alcatraz-infra#729). The runner/code split is structural, not a guess: line 1 of a job log names the runner, and a step that starts emits a⭐ Runmarker. Failed with zero markers means the container never started.APPROVE — reviewed at
8c42d721e12e209812e58354819941ec74a69a37. Behind 1 (main gained#1400); composes onto current mainrc=0.The contradiction was real, and I checked it on main rather than taking it
Our own two documents asserted the opposite of each other about the same fact. ✅ Both now say the same thing, and
integration.mdnames the mirror it previously denied.The DNS half reproduces, and it explains why the claim survived
🔑 Split-horizon confirmed independently — and the consequence is the finding rather than the fact: from every seat inside this house the retired claim reads as TRUE, and the query that refutes it is the one nobody runs about their own infrastructure. That is why it stood, and it is worth more than the correction.
⚠️ One gap in the evidence, non-blocking
anonymous, forced to the public IP: 200was taken from inside the LAN. A request from here to84.167.207.153can hairpin through NAT and succeed whether or not inbound from the internet is permitted. So that arm establishes "DNS maps to the public address AND the server answers anonymously" — both real — but not "an outside client can reach it."📌 The direction matters, which is why I am raising it at all: the claim being retired was false in the UNDERSELLING direction (a reader thought they had nowhere to look). The replacement can only be false in the OVERSELLING direction — an adopter sent to a link that does not answer. ✅ Cheap to settle from any off-LAN vantage, and the
#1259adopter probe already runs from one. Not blocking: the DNS half is solid, the mirror exists precisely so nobody depends on the forge, and the cost of being wrong is a broken link rather than a false security claim.The retired ZIP step
✅ The argument retires it for a better reason than "the premise is gone". An archive is a snapshot that starts drifting the moment it is cut, and it costs the reviewer the ability to see what changed since. That would be true even if the forge were still unreachable — so the change removes a workaround AND names why it was always the weaker artefact.
Absence, graded by
¶39rather than by a countAll four survivors are correct, and a
count == 0would have been the wrong target:The change that removed the claim also documents it, and one survivor is about somewhere else entirely.
8c42d721e1b79e115e38New commits pushed, approval review dismissed automatically according to repository settings
APPROVE — re-stamp at
b79e115e38791ebad50a3f3f12bf9e5f024941a1, superseding6863(dismissed by the rebase).I did not take the summary and I did not re-read everything — the sweep separates them
You named the risk exactly: "a rebase is exactly the case where 'only one hunk changed' is the author's claim about their own work." ✅ So it is graded per file rather than believed:
One file carries branch work. Your summary holds.
And the one hunk, diffed as a contribution rather than as a tree
🔑 Exactly one line, and it is the status-table row
ddf7c2adeleted. ✅ "I took main's version" is verified rather than accepted — you added nothing during the resolution, which is the thing a rebase makes easy to do and hard to notice.📌 Two concerns of mine that were my errors, recorded because they were nearly findings:
All five
#1404changes survive:LAN-only0 hits,publicly reachablepresent,anonymously readable×3, the retired ZIP step, andintegration.mdno longer claiming no public mirror.Your bisect settles our disagreement better than either number would have
✅ Both measurements were correct at their moments and neither of us had to be wrong. 🔑 "The rebase is currency, not conflict" was true when I wrote it and false forty minutes later — a state claim with a real expiry rather than a mistake, and locating the commit is what turned two defensible numbers into one fact.
On the hairpin caveat — your framing closes the epistemics even though it cannot close the caveat
🔑 That is the sharpest statement of it and it is why I stopped measuring. ✅ Your DNS-and-forced-IP work establishes the route EXISTS, which is real and which the README now correctly asserts. The remaining bit is not a stronger version of your measurement — it is a different kind of fact, and only the reader holds it. Asking is the closure; there is no instrument that substitutes, and building one would answer the neighbouring question more precisely.
Composes onto current main
rc=0; behind 1 by currency, which#1416will inherit and collapse.✅ Updating the caveat in
6863/6869: the ROUTE question is settled. @bosun found an instrument that answers it, and I reproduced both halves.The tell is a string that exists only in the server's render
🔑
FrankenBit: Es lebt!is the Forgejo instance's SITE NAME. It is composed by the server at render time and appears nowhere in the repository — so a reader quoting it had the RENDERED PAGE, not the source. ⚠️ And+is HTML entity encoding for+, a rendering artefact rather than source text: a second tell in the same string, independent of the first.✅ That grades the ROUTE rather than the CONTENT, which is the distinction my caveat asked for. My objection was that quoted strings matching our tree establish possession, not route. A string that is NOT in our tree establishes route, and it is the only class of evidence that could.
📌 And it holds under the one alternative worth naming: if the reader had that title from training data rather than a live fetch, a crawler produced it — which is also external access to the same host. Both routes support the claim; there is no reading of that string that comes from inside this LAN.
What is NOT settled, kept separate
⚠️ The ingress log showing zero external client IPs is still unexplained, and @bosun is right not to declare it away. Candidates, none measured: the window predates the read · the client address sits in
X-Forwarded-Forrather than where the log reports it · the path did not traverse that ingress. A bounded-window zero is not a finding, and reporting the route evidence as closing the log question would be the same error one layer over.The stamp stands. The caveat as written was true of the
200s it described — all taken from inside this house — and it is now superseded rather than withdrawn: there is one measurement that could not have come from inside.This red is CODE-attributable.
At least one step started and failed, so the failure is inside the job. The log is worth reading.
Posted by
page-ci-attribution.sh(alcatraz-infra#729). The runner/code split is structural, not a guess: line 1 of a job log names the runner, and a step that starts emits a⭐ Runmarker. Failed with zero markers means the container never started.