# Lamp handover

## Shared refactor — 14 September 2026

The edition now selects shared SendGrid transport from Base while retaining its own durable send policy. Accepted responses may lack a remote receipt; uncertain outcomes remain distinct and are not automatically repeated. Owner SQL uses the shared generated-D1 mechanism after core; the edition wrapper owns its permanent ledger and path. Apply additive0011 to retain actual nullable provider receipts independently of existing local correlation, preserving prior claim fingerprints and archive history. Authoring1.1 includes changed-input diagnostics, retained baseline extraction, mapped comparison and portable adjacent release receipts verified against a clean clone. Source integrity does not establish product or deployment acceptance; the remaining obligations below are preserved.


## Release boundary

Lamp 1.1.0 updates the retained local 1.0.0 release. The Worker, D1, R2,
Queue and owner setup/deployment commands have been exercised on an owner
installation. Dated observations are recorded below. Exact source/tag identity,
frozen verification, restored native publication and CI deployment belong to the
separate release receipt; owners should verify their own installation when
adopting this source.

## Runtime shape

- One Worker dispatches by `LAMP_PAGE_HOST` and `LAMP_APP_HOST`. The page host serves public artifacts and signed intake endpoints; the app host serves sign-in, protected operator routes, Start server-function transport, health, and application assets. Missing required bindings name the exact variable, and unknown or cross-surface hosts return 404.
- Hono remains authoritative for public snapshot artifacts, feeds, widgets, health, native sign-in requests, and `/api/app`. TanStack Start server-renders `/signin` and authenticated `/app` documents and owns only the opaque `/_serverFn/` transport. It does not replace the R2 snapshot renderer or its shared incident/email rendering path.
- Public reads use versioned R2 snapshot artifacts and make no D1 read. Snapshot generation uses a durable retry record and conditional pointer advancement; a retained snapshot can be labelled stale after a failed rebuild.
- The page, history, Atom feed, widget, status payload, favicon and Open Graph artwork, and permanent incident pages share the snapshot renderer. Initial HTML contains complete public incident fields and works without script; the live region refreshes only a bounded current summary.
- The local public-status refinement renders real snapshot data in a pale full-width status band, open component rows with 90-day daily records, and a full-width vertical chronology. Current incidents, scheduled maintenance, and resolved incidents appear once in that chronology; the subscribe form sits below the timeline at every width. Public timestamps retain machine-readable instants for local display.
- The initial public page loads four same-origin artifacts: stylesheet, script, favicon that composites the configured logo and status mark, and cartographic artwork. The stylesheet embeds the bundled Open Sans variable face (normal 400–700), with no third-party font request; CSP narrowly permits `font-src 'self' data:` for that face.
- D1 stores product facts, audit records, and snapshot-build state. R2 stores public artifacts and uploaded originals. Queues carry health and delivery commands; Cron processes due publication, maintenance, delivery recovery, and snapshot retries.
- Development initializes buyer-configured page settings and an empty snapshot only. Test fixtures own their D1 state, sessions, and product records.
- `pnpm build` emits the Start client at `dist/client` and the generated deployable Worker configuration at `dist/server/wrangler.json`. The generated config carries `nodejs_compat`, points to the client output, and is never edited or committed.
- With no configured mail sender, local sign-in and subscription confirmation are unavailable; the script-disabled subscription response reports an honest 503. With no AI provider, the composer hides suggestion controls, and a provider failure leaves publication paths intact.
- Removing access and erasing an operator are distinct operations. Erasure revokes access, removes personal values from the operator, magic-link, and target audit records, and retains opaque audit action, actor, target ID, and time facts. The setup-operator guard remains service-side.

## Completion changes

- Setup initializes real resources before the first Worker deployment, supports a fresh restore target, and applies buyer sidecar migrations after core migrations.
- Export reads D1 records consistently and preserves original R2 bytes plus HTTP/custom metadata. Import validates archive and migration hashes before touching its target, refuses populated targets, and leaves a failed restore unpublished for recovery into a fresh target.
- SendGrid uses a durable envelope claim for at-most-once submission, disables tracking, verifies signed events and distinguishes acceptance from recipient delivery.
- Owner instructions use ordinary Git with agent-chosen updates and recorded-intent verification. The accepted public design is unchanged.

## Local validation scope

`pnpm verify` runs real Workers behavior suites, the local baseline pack, public/browser checks, a production-artifact Start check, and an isolated Axe WCAG 2.2 AA check against public, operator, subscription-token, sign-in, and widget surfaces. The automated check does not assert a manual accessibility evaluation.

The checked-in visual fixtures come from accepted local owner-preview browser captures with API-created records. They document the product UI only; browser, source-review, frozen clean-clone, deployment, and provider evidence remain external records.

The three settled 12ui candidate-D conversions for top status, component health, and history are retained outside the repository at `/Users/zemaj/.orchestrator/evidence/statuspage/lamp-selected-section-styles/`, with their source kits in `/Users/zemaj/.orchestrator/evidence/statuspage/lamp-section-design-alternatives/`. They supplied hierarchy and spacing guidance only. Owner overrides keep Open Sans and all real shared-renderer content, configured favicon/logo, live component charts, incident facts, timestamps, links, and controls. Generated assets, generic branding, invented copy, and unanchored plan content were excluded rather than shipped.

## Migration and release record

`RELEASE.json` declares1.1.0 with previousVersion1.0.0, retains the unchanged product guarantees, and introduces `0010_mail_send_ledger.sql`. The original release record is preserved at `release-history/1.0.0.json`; core migrations `0001` through `0009` remain unchanged. `migrations/core/0009_historical_claim_ledger.sql` adds immutable source-claim events, maintenance transition ledger triggers, and `incident_updates.is_retroactive`. Apply it before starting the updated Worker. Existing aggregate history is intentionally not backfilled because it cannot establish source-claim provenance.

Migration0010 adds the durable SendGrid send ledger. Release validation checks new migrations against the retained prior release. Resend remains the default adapter; SendGrid is explicitly selected and reconciles signed receipts without blindly resending an ambiguous request. `OPERATIONS.md` describes setup, both providers, archive recovery and owner migrations.

## Commands

```sh
pnpm install
pnpm exec playwright install chromium
pnpm dev
pnpm verify
pnpm run setup
pnpm run deploy -- --dry-run
pnpm run export
pnpm run import
```

`pnpm run setup` and a real deploy require owner-controlled Cloudflare credentials, distinct hostnames, sender configuration, and DNS records. `pnpm run deploy -- --dry-run` is a local compilation and generated-configuration check; it does not contact Cloudflare. Before a local tag, freeze the final source, run `pnpm install && pnpm verify` in a clean clone, exercise the generated `dist/server/wrangler.json` artifact, and record the exact commit, verifier result, and authorized tag externally. Deployment, DNS, live mail delivery, and provider checks remain owner-controlled external work. This handover describes local runtime evidence; tag, frozen-verifier, deployment, DNS, live-mail, and provider evidence belong to external release records.

## Hosted acceptance evidence — 2026-09-13

The owner installation is live at `https://lamp.justevery.com` with operators at
`https://lamp-app.justevery.com`. Native sign-in and invitation mail, confirmed
subscription, incident/report publication, configured AI, scheduled maintenance,
alert intake, script-free public reading, signed SendGrid delivery, received
DKIM coverage of both unsubscribe headers, no tracking, controlled webhook HMAC
and one-click unsubscribe are recorded externally. Setup preserved the original
James setup operator. Temporary acceptance operators entered through real emailed
links after an explicitly authorised owner-admin allow-list insertion.

Live acceptance found and corrected reserved receipt-route precedence, unsupported
Worker redirect mode, public Worker-to-Worker routing, and protected Cloudflare
archive tables. The retained webhook 404 attempts subsequently delivered through
normal scheduled retries. A real malformed R2 pointer retained warmed snapshots
beyond 10 seconds; cold requests returned 503. The exact original object and metadata
were restored and public reads recovered. This is not an independent provider
outage deployment.

The latest application deployment uses runtime `bee81fd`, including long-destination
subscriber erasure through literal matching. Archive correction `b824089` excludes
Cloudflare-reserved tables without excluding similarly named owner tables. Evidence is in the completion directory named in
`ACCEPTANCE.md`. Remote archive equality has passed 39 tables, 119 rows and 98 R2 objects, including
original bytes and HTTP/custom metadata. Temporary production records are removed;
original owner access and anonymised audit attribution remain. The separate final
release receipt identifies native publication from the isolated restored
deployment, integrated CI and the release tag. Consult that receipt when assessing
completion; this source handover does not replace installation-specific proof.

## Cold snapshot replica correction

PAGE-006/007 now uses the `SNAPSHOT_CACHE` SQLite Durable Object to retain one
complete published generation independently of R2 and process/edge cache state.
The real-time publication requirement rules out KV negative-cache propagation.
R2 stays authoritative and portable; public reads remain D1-free. Fresh isolates
serve timestamped last-known HTML/feed/widget after R2 failure. The independent
health route still reports failure, and no-snapshot installs remain 503. Neither
the Worker nor replica can serve through their own simultaneous unavailability.

The replica transaction rejects incomplete and older generations. R2 archives
include its input bundle; restored installations prime it, with minute-scheduler
rebuild for legacy archives. Deployment waits for retained readiness. See
OPERATIONS.md. Focused real-workerd tests cover cold restart, first publication
after a missing read, new query variants, malformed R2 pointers, complete version
switching, UTF-8 integrity and restore priming. Full exact-candidate/hosted receipts
remain the completion team's responsibility; this correction has not been deployed
by its implementation worker.

Follow-up publication regression closes the first-replica-failure window: retain
the complete R2-persisted generation before changing the R2 selector, and reuse
one prepared version across retries. Real-renderer/R2/SQLite tests now reject the
first and replacement replica PUTs, lose an acknowledgment, and fail selector
writes. They prove prior/no selector remains until retention, matching retry
versions, and visible failed/pending work. OPERATIONS.md states the selector-repair
case explicitly: the newer complete replica may serve last-known state during
R2 failure while the prior R2 selector awaits repair.

## Edition authoring conversion — 2026-09-14

Lamp now uses the common edition-owned source protocol in `AUTHORING.md`.
The comparison parent is `3481401773321069d97704e0f2adaf6f25ce848b`; application
source, existing tests, migration history, dependency lock and runtime deployment
configuration are preserved. The actual widget origin parser has a selectable
local module identity; it stays in its current runtime location. There is no
Status family or separate consumer instruction replacement.

The shared source CLI, operations description and local checks add no hosted
proof. `pnpm verify` now checks source lock integrity and read-only operations
metadata before the existing product suites. Exact clean-clone and local source
release receipts for this conversion are reported separately; historical hosted
acceptance above applies to its recorded deployment, not automatically to this
source revision. Product requirements and existing limitations remain unchanged.
