docs: record server rollout of session and memory fixes
Publish documentation / publish (push) Successful in 32s
Publish documentation / publish (push) Successful in 32s
This commit is contained in:
+9
-5
@@ -12,17 +12,21 @@ Authentik, internal catalog/embedding services, and the PSD workspace repository
|
|||||||
`docs/operations/server-upgrade-gitea-workspace-v2.md`. Treat its operator gates and rollback
|
`docs/operations/server-upgrade-gitea-workspace-v2.md`. Treat its operator gates and rollback
|
||||||
requirements as mandatory; do not replace the running server stack in place.
|
requirements as mandatory; do not replace the running server stack in place.
|
||||||
|
|
||||||
## Session composer and empty Memory fix prepared — 2026-09-14
|
## Session composer and empty Memory fix deployed — 2026-09-14
|
||||||
|
|
||||||
The embedded shell now caps its height at the portal mount height, keeping steering
|
The embedded shell now caps its height at the portal mount height, keeping steering
|
||||||
and Stop & save visible. Empty authoritative Memory archives return zero results
|
and Stop & save visible. Empty authoritative Memory archives return zero results
|
||||||
without requiring embedding/BM25; SQL-rule embedding is lazy and shared. The live
|
without requiring embedding/BM25; SQL-rule embedding is lazy and shared. The live
|
||||||
empty PSD archive reproduces 503 with the current image and succeeds with the
|
empty PSD archive reproduces 503 with the current image and succeeds with the
|
||||||
candidate. 54 Memory tests, 90 frontend tests, five browser scenarios and both image
|
candidate. 54 Memory tests, 90 frontend tests, five browser scenarios and both image
|
||||||
builds passed. Candidate core/frontend tags are `49333a2d-session-memory-fix`;
|
builds passed. The owner authorized the restart and core/frontend were recreated on
|
||||||
production recreation awaits the release-window confirmation required by the server
|
2026-09-14 at 17:18 CEST with tags `49333a2d-session-memory-fix`, from code committed
|
||||||
handoff. See `docs/reports/2026-09-14-session-layout-memory-fix.md` for evidence,
|
as `d6cdffea`. Both are healthy; production Memory search returns `[]`, Omics serves
|
||||||
prepared rollback and resolved deployment commands.
|
the corrected CSS, native doctor passes 13/13 checks, and admissions are reopened.
|
||||||
|
Session inventory is preserved. Backups and rollback images are retained. Native
|
||||||
|
CLI diagnostics must run as installation owner UID 10001 with access to Compose;
|
||||||
|
see `docs/reports/2026-09-14-session-layout-memory-fix.md` for exact commands and
|
||||||
|
the remaining interactive browser acceptance.
|
||||||
|
|
||||||
## Full/embedded shell and bilingual interface
|
## Full/embedded shell and bilingual interface
|
||||||
|
|
||||||
|
|||||||
@@ -2,9 +2,14 @@
|
|||||||
|
|
||||||
## Stato
|
## Stato
|
||||||
|
|
||||||
Correzioni implementate e immagini candidate costruite; **rilascio operativo non
|
**Rilascio operativo eseguito il 14 settembre 2026 alle 17:18 CEST**, dopo
|
||||||
ancora eseguito**. Il runbook `docs/operations/server-codex-handoff.md` richiede
|
l'autorizzazione esplicita del proprietario al riavvio. Core e frontend sono healthy;
|
||||||
conferma della finestra prima della ricreazione dei servizi operativi.
|
le nuove ammissioni sono riaperte (`active: false`, `admissions: 0`). Non risultavano
|
||||||
|
processi Pi RPC attivi prima del fermo. L'inventario resta identico: una sessione
|
||||||
|
`open` e una `closed`, entrambe non archiviate.
|
||||||
|
|
||||||
|
Il checkout operativo `/srv/thothii-v2/source/ThothII` è stato aggiornato in
|
||||||
|
fast-forward al commit Gitea `d6cdffea629daf92cae8392eb1ebb3bb6f275f55`.
|
||||||
|
|
||||||
## Cause e correzioni
|
## Cause e correzioni
|
||||||
|
|
||||||
@@ -25,7 +30,7 @@ Nessuna migrazione, modifica di card, indice, DWH o autenticazione è necessaria
|
|||||||
|
|
||||||
## Verifiche eseguite
|
## Verifiche eseguite
|
||||||
|
|
||||||
- Riproduzione live: `tht memory search` restituisceva 503.
|
- Riproduzione live: `tht memory search` restituiva 503.
|
||||||
- Confronto delle immagini attuale/candidata, con PostgreSQL e Qdrant reali e
|
- Confronto delle immagini attuale/candidata, con PostgreSQL e Qdrant reali e
|
||||||
montaggi read-only: attuale exit 1/status 503; candidata exit 0/`[]`. La
|
montaggi read-only: attuale exit 1/status 503; candidata exit 0/`[]`. La
|
||||||
configurazione diagnostica non contiene credenziali DWH e non interroga il DWH.
|
configurazione diagnostica non contiene credenziali DWH e non interroga il DWH.
|
||||||
@@ -40,28 +45,41 @@ Nessuna migrazione, modifica di card, indice, DWH o autenticazione è necessaria
|
|||||||
smoke della configurazione frontend superato.
|
smoke della configurazione frontend superato.
|
||||||
- Screenshot verificati in `frontend/test-results/visual-review/`.
|
- Screenshot verificati in `frontend/test-results/visual-review/`.
|
||||||
|
|
||||||
## Consegna candidata
|
## Immagini distribuite e controlli server
|
||||||
|
|
||||||
Base operativa verificata e pulita: `49333a2d35664b7237c3ddc2a9f10a605dcc84ce`.
|
Le immagini candidate già collaudate sono quelle ora in esecuzione. Container core
|
||||||
La patch `/tmp/thoth-session-memory-fix.patch` supera `git apply --check`
|
`1e71b0abd5aa` e frontend `45387534e8ad` avviati rispettivamente alle 15:18:43 e
|
||||||
contro `/srv/thothii-v2/source/ThothII`.
|
15:18:49 UTC. Catalogo, Qdrant, embedding e Omics web non sono stati ricreati.
|
||||||
|
Nginx Omics è stato verificato e ricaricato per risolvere gli indirizzi aggiornati.
|
||||||
|
|
||||||
| Immagine candidata | ID |
|
| Immagine distribuita | ID |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| `thothii-v2-core:49333a2d-session-memory-fix` | `sha256:ff4c435abd67c57e1e91e6e560dae73e67350ca499a5aedca3ffa517b9f59ee0` |
|
| `thothii-v2-core:49333a2d-session-memory-fix` | `sha256:ff4c435abd67c57e1e91e6e560dae73e67350ca499a5aedca3ffa517b9f59ee0` |
|
||||||
| `thothii-v2-frontend:49333a2d-session-memory-fix` | `sha256:35933317769f3e12953f3b144d51f8fc2e7e9f7c4830eba80cc626f757f5bf0d` |
|
| `thothii-v2-frontend:49333a2d-session-memory-fix` | `sha256:35933317769f3e12953f3b144d51f8fc2e7e9f7c4830eba80cc626f757f5bf0d` |
|
||||||
|
|
||||||
Copie protette di operator.env, descriptor e override sono già in
|
Controlli dopo il riavvio:
|
||||||
`/srv/thothii-v2/backups/20260914-session-memory-fix` (directory 0700).
|
|
||||||
Le immagini correnti sono conservate anche con tag
|
|
||||||
`before-session-memory-fix-20260914`. Non è stato fatto un nuovo backup dei dati:
|
|
||||||
questa preparazione non ha modificato dati e non sostituisce un backup coerente
|
|
||||||
nella finestra operativa, se richiesto dal runbook di rilascio.
|
|
||||||
|
|
||||||
## Comandi risolti per la finestra da confermare
|
- `memory search` e `memory solved-search` nel core distribuito: exit 0, `[]`.
|
||||||
|
- `workflow-doctor`: `ready: true`, un workspace; inventario sessioni invariato.
|
||||||
|
- HTTP `/health`: `status: ok`; tutti i servizi richiesti healthy.
|
||||||
|
- Omics serve config embedded/en e asset con HTTP 200: `index-BpY9Lzwz.js`,
|
||||||
|
`index-BhJrKSGn.css`; verificata nel CSS la regola di altezza corretta.
|
||||||
|
- `/datamart-builder/api/me` senza login continua a rispondere 403.
|
||||||
|
- `nginx -t` superato; reload completato; TTL manifest Django trascorso.
|
||||||
|
- `tht status`: exit 0; `tht doctor --json`: `ok: true`, 13/13 controlli passati.
|
||||||
|
- Nessun errore di avvio rilevato nei log core.
|
||||||
|
|
||||||
Verificare nuovamente lo stato delle sessioni e gestire quelle attive prima del
|
Backup protetto in `/srv/thothii-v2/backups/20260914-session-memory-fix`
|
||||||
riavvio. Il seguente launcher conserva progetto, env file e ordine degli override:
|
(directory 0700): operator.env, descriptor e override precedenti, archivio di data,
|
||||||
|
workspace-registry e Pi creato a core fermo, dump logico PostgreSQL e snapshot nativo
|
||||||
|
Qdrant. Elenco tar e `pg_restore --list` validati; tutti gli SHA256 verificati.
|
||||||
|
Le immagini precedenti restano anche con tag `before-session-memory-fix-20260914`.
|
||||||
|
Nessuna migrazione o modifica al DWH. Il rollback normale resta applicativo.
|
||||||
|
|
||||||
|
## Comandi di rilascio e diagnostica
|
||||||
|
|
||||||
|
Il seguente launcher conserva progetto, env file e ordine degli override. Le
|
||||||
|
ammissioni sono state bloccate e il core fermato prima del backup:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
thoth_fix_compose() {
|
thoth_fix_compose() {
|
||||||
@@ -76,24 +94,38 @@ thoth_fix_compose() {
|
|||||||
}
|
}
|
||||||
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-activate
|
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-activate
|
||||||
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-status
|
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-status
|
||||||
sudo git -C /srv/thothii-v2/source/ThothII apply /tmp/thoth-session-memory-fix.patch
|
thoth_fix_compose stop --timeout 45 core
|
||||||
```
|
```
|
||||||
|
|
||||||
Dopo gestione delle sessioni e backup nella finestra, aggiornare esclusivamente
|
Dopo il backup è stato aggiornato esclusivamente `THTII_RELEASE_IMAGE_TAG` in
|
||||||
`THTII_RELEASE_IMAGE_TAG` in `/srv/thothii-v2/operator/operator.env` al valore
|
`/srv/thothii-v2/operator/operator.env` a `49333a2d-session-memory-fix`, preservando
|
||||||
`49333a2d-session-memory-fix`, preservando gli altri valori e i permessi.
|
altri valori, proprietario e permessi. Avvio e reload eseguiti:
|
||||||
Quindi:
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
thoth_fix_compose up -d --no-deps --no-build core frontend
|
thoth_fix_compose up -d --no-deps --no-build core frontend
|
||||||
sudo docker exec omics_portal-nginx-1 nginx -t
|
sudo docker exec omics_portal-nginx-1 nginx -t
|
||||||
sudo docker exec omics_portal-nginx-1 nginx -s reload
|
sudo docker exec omics_portal-nginx-1 nginx -s reload
|
||||||
sudo tht --installation /srv/thothii-v2/source/ThothII/deploy/psd-server-v2/thothii-installation.yaml status
|
|
||||||
sudo tht --installation /srv/thothii-v2/source/ThothII/deploy/psd-server-v2/thothii-installation.yaml doctor --json
|
|
||||||
```
|
```
|
||||||
|
|
||||||
Attendere il TTL di 30 secondi del manifest Django, verificare asset/config e
|
Il CLI legge i segreti soltanto con l'UID proprietario (10001). L'invocazione
|
||||||
Memory; provare input/arresto nel portale prima della riapertura:
|
come root viene rifiutata dal controllo di proprietà; nessun file segreto è stato
|
||||||
|
modificato. Per la diagnostica è stata usata una configurazione Docker temporanea
|
||||||
|
vuota, evitando la directory `/root/.docker` inaccessibile a quell'UID:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo install -d -m 0700 -o 10001 -g 1006 /tmp/thoth-owner-docker
|
||||||
|
thoth_fix_cli() {
|
||||||
|
sudo env DOCKER_CONFIG=/tmp/thoth-owner-docker \
|
||||||
|
setpriv --reuid=10001 --regid=1006 --groups=1006,1014,988 \
|
||||||
|
/usr/local/bin/tht --installation \
|
||||||
|
/srv/thothii-v2/source/ThothII/deploy/psd-server-v2/thothii-installation.yaml "$@"
|
||||||
|
}
|
||||||
|
thoth_fix_cli status
|
||||||
|
thoth_fix_cli doctor --json
|
||||||
|
```
|
||||||
|
|
||||||
|
Riapertura dopo i controlli runtime:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-deactivate
|
thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js maintenance-deactivate
|
||||||
@@ -101,6 +133,16 @@ thoth_fix_compose exec -T core node /app/backend/dist/operator-command.js mainte
|
|||||||
|
|
||||||
Rollback applicativo: ripristinare l'operator.env protetto, ricreare solo
|
Rollback applicativo: ripristinare l'operator.env protetto, ricreare solo
|
||||||
core/frontend con lo stesso launcher, verificare e ricaricare nginx. Per riallineare
|
core/frontend con lo stesso launcher, verificare e ricaricare nginx. Per riallineare
|
||||||
anche i sorgenti usare `git apply --reverse --check` e poi `git apply --reverse`
|
anche i sorgenti preparare il revert del solo commit `d6cdffea`, preservando le
|
||||||
sulla sola patch preparata, senza reset di altre modifiche. Non occorre ripristinare
|
modifiche successive. Non occorre ripristinare
|
||||||
PostgreSQL o indici per un rollback di queste due correzioni.
|
PostgreSQL o indici per un rollback di queste due correzioni.
|
||||||
|
|
||||||
|
|
||||||
|
## Accettazione interattiva
|
||||||
|
|
||||||
|
Le prove browser automatiche su input e arresto sono passate prima del rilascio;
|
||||||
|
la distribuzione degli asset corretti è verificata attraverso il proxy reale.
|
||||||
|
Resta da confermare il comportamento nella sessione autenticata del proprietario,
|
||||||
|
ricaricando la pagina Omics. Il collaudo non ha creato sessioni workflow reali né
|
||||||
|
invocato un modello generativo; non sostituisce l'accettazione interattiva completa
|
||||||
|
Omics/IdP documentata nella matrice di autenticazione.
|
||||||
|
|||||||
Reference in New Issue
Block a user