# JOURNAL Append-only, newest last. One block per session or run. Not a changelog: this records what happened on the day a number was produced, so a later postmortem can find it. ## 2026-08-11 Audit second pass [no task] Command: none. Source reading only. Outcome: finished. `AUDIT.md` grew from 565 to 771 lines with a `## Second-pass findings` section: 4 new P0, 6 new P1, 13 P2, 5 additions to the Phase 1 list. Produced: commit `6d9df5b`, `AUDIT.md:566`. ## 2026-08-11 Audit Phase 1 implemented [#203] Command: `python worker_scene.py worker_script.py worker_vision.py session_manager.py`, `pytest -q --ignore=test_api.py` in the orchestrator. Outcome: finished. All self-checks pass, 108 orchestrator tests pass. No GPU work, no pipeline run. `test_api.py` was skipped because fastapi is not installed in the workpc venv. Produced: `decisions/audit-phase1.md`, `caveats/audit-open.md`, `ROADMAP.md`, and this scaffold. One existing test asserted the bug: `test_name_binding.test_conflict_flags_and_stays_unnamed` relied on orphan flags leaking into every chapter, because it never created panel rows. It now creates them. ## 2026-08-11 Orchestrator half committed and deployed [no task] Command: `pytest -q --ignore=test_api.py`, then `docker compose up -d --build orchestrator` on homesrv. Outcome: finished. 108 tests pass. Commits `1c60710` (orchestrator half) and `94bd4d8` (minio pin) in `/mnt/server/home/kami/docker-apps`. Orchestrator and minio both answer health on homesrv. The rebuild recreated `minio` as a side effect and it crash-looped with `exec format error`: the compose pin was the arm64 manifest digest of `minio/minio:latest` and homesrv is amd64. Repinned to the amd64 digest. Nothing about Phase 1 caused this, but any compose action that recreates minio would have hit it, so it was latent, not new. Still unrun against a real chapter. ## 2026-08-11 S3 viewer and storage swap, tasks #116/#117 [#116 #117] Command: docker compose on homesrv, `dig`, `openssl s_client`. No pipeline, no GPU. Outcome: partial. Viewer works, storage swap staged and unfinished. #117 needed no new software. `stowage` at `~/docker-apps/stowage` was already configured against the manga MinIO and had been dead since 2026-07-19 with `exec /sbin/tini: exec format error`: its digest pin was the arm64 manifest. Repinned to amd64 `sha256:91be7f13`, chowned `data/` to uid 65532 for the new image, and it serves. MinIO had the identical bug, repinned to `sha256:a1a8bd4a`. A sweep of all 470 local images on homesrv found exactly those two arm64; nothing else in the homelab is affected. #116 is staged, not done. `rustfs` runs alongside MinIO on `127.0.0.1:9010/9011`, pinned `sha256:19b105cc`, data at `/mnt/hdd2/rustfs`. Buckets are empty: the `mc` mirror of `audio layers manga panels raw video` (350M, all in `manga`) has NOT run. `/mnt/hdd2/minio/data` is untouched and is the rollback. RustFS is `1.0.0-beta.12`, labeled `build-type=prerelease`. Cutover would give rustfs 9000/9001 and repoint `MINIO_ENDPOINT=minio:9000` in the orchestrator plus `stowage/config.yaml`; `transport.py:95` needs no change if rustfs takes `192.168.1.104:9000`. Side quest, unrelated to the pipeline: the shared 41-domain cert stopped renewing. Root cause was DNS, not nginx. Every `*.kvmx.ru` name pointed at a hard A record for `109.229.102.117` while the line had moved to `109.229.127.149`; the Mercusys DDNS at `kvmx-home.mercusysddns.com` was correct the whole time but nothing in the zone referenced it. Fixed with `CNAME * -> kvmx-home.mercusysddns.com` at reg.ru. Certificate now issues. Two measurement traps worth remembering. The ISP transparently intercepts ports 80 and 443 by Host/SNI, so `curl` from workpc to ANY address returns kvmx.ru content and proves nothing about external reachability; bare TCP connects also succeed against arbitrary addresses and then hang. Three wrong root causes came out of trusting those probes before checking them. Also patched `~/scripts/migrate-kvmx-https.sh:54` on homesrv. `need_stream_module` used `sudo -n nginx -V` and `sudo -n nginx -T`; the NOPASSWD rule covers only `nginx -t`, so it reported "stream module is not loaded" whenever it meant "could not ask for a password". Both checks now run without sudo. `bash -n` passes and both conditions evaluate true.