๐Ÿ“ OVERSEER_Checkpoint_2026-10-05.mdv4.5.1 · 2026-10-02

OVERSEER Checkpoint โ€” v1.0, Chapter 1

Period: 2026-09-30 โ†’ 2026-10-05 (checkpoint taken 05/10/2026 ~11:57 AEDT) Participants: Andrew.human & Claude.ai Follows: OVERSEER_Checkpoint_2026-09-30.md and OVERSEER_Transcript_2026-09-30.md

Times marked "Live" are Live's own clock (Singapore, SGT = UTC+8). Sydney moved to daylight saving (AEDT = UTC+11) on 4 Oct, so Live is now 3 hours behind Sydney.


1. Where things stand in one paragraph

COI_Chain 1.0.2 is installed on Live and its test suite passes 14/14 on Live. Its first real runs were checked line by line against SMF's own DB and disk: the search-file findings were all real, and they were faults in ISE's .json files, never in the forum. The SMF-side findings (orphan files, rows with no owner) are SMF's business and COI 1.0.3 will stop reporting them. Along the way a Python break on Live (ResultFormatter / zoneinfo) blinded both COI and PDF search for a morning; it is fixed. Dev's Python 3.8 was rebuilt with SSL and given a source-built 32-bit PyMuPDF, and a new 32-bit PDF indexer (v8.6.0) now works on Dev where the old one silently indexed nothing. Live's search files are currently behind the forum (see ยง6) and need indexer runs before the next mirror is a good copy.


2. COI_Chain โ€” versions and status

Version What changed Status
1.0.1 Absolute paths after the move to Collabware/OVERSEER superseded
1.0.2 Test suite only: one row per INSERT (CentOS 6 SQLite 3.6.20 has no multi-row VALUES); parked test files kept inside /tmp/coitest/parked; test prints its own and COI's version; whole bundle carries one number installed on Live, 14/14 on Live
1.0.3 Not built โ€” see ยง4 planned

Running it

Andrew's coichecks (a script, not an alias) runs snapshot โ†’ check โ†’ compares counts with the previous report in /backup/coi_*.txt.

Open: coichecks sends the snapshot's output to /dev/null, so a failed snapshot silently falls back to the old picture. Add a guard:

python3 COI_Chain.py --snapshot > /dev/null || { echo "SNAPSHOT FAILED -- check not run"; return 1; }

3. How the findings were verified (the method that worked)

Every COI claim was checked SMF-first, never against ISE's own files alone:

  1. SMF row: SELECT โ€ฆ FROM smf209_attachments WHERE id_attach IN (โ€ฆ)
  2. Disk: ls -l /var/www/html/attachments*/<id>_*
  3. Any post linking to it: SELECT โ€ฆ FROM smf209_messages WHERE body LIKE '%attach=<id>%'
  4. Only then: is the ID in the .json file?

Example โ€” 2419: no row, no file, no post โ†’ SMF has no trace; only media_store.json still listed it โ†’ ISE's file was wrong. Andrew removed the entry.

All 59 search-file claims from the first run (24 "in ISE but gone from the forum", 35 "on the forum but missing from ISE") were confirmed this way on 1 Oct. The 4 that later read as indexed were picked up by an ISEpdf run at 00:17 Live, after the report.

Lesson recorded: Claude must not present guesses about why a fault exists as findings, and must not claim what SMF's own tools check without reading their code (the claim that SMF's "Attachment Integrity Check" covers the same ground was wrong โ€” it reported "No errors were found!").


4. Decisions made this chapter

# Decision Notes
D1 SMF is gospel for its own territory. COI stops judging SMF's folders and rows (files with no row, rows with no owner, missing files, etc.) SMF's own integrity check says "No errors were found!". These lines stay in 1.0.2 output until 1.0.3.
D2 RC 8 = error; clean up before continuing (Andrew chose option A) With D1 in place, the remaining RC is driven by ISE's files only.
D3 The chain is a web, not a loop โ€” every pair of things that should agree gets its own test Pairs listed in ยง5.
D4 Add image checks: every image/video in media_store must have an embedding and a caption; leftovers for deleted attachments are faults; captions MediaProcessor gave up on (3 failures) are information only Treat embeddings/captions "like media/audio" โ€” a second layer built from media_store, checked both ways.
D5 Prove COI by breaking Dev after copying its DB, attachments and ISE_Data; then restore/mirror back Dev owns no stores, so it is the safe machine to break.
D6 Don't reinvent SMF's checks โ€” tie each .json entry back through its DB row, its post, and the physical file; extra fields may be added to the .json entries to make that possible Added fields are a fingerprint for comparing, never a second source of truth.
D7 Delivery rules made standing in preferences (version/date bump, manual history entry, version printed at start, dotted never-reused zip names, xmllint, unasked changes listed before making them, release card) Saved 30 Sep; extended 4 Oct to "every executable".

Still undecided


5. COI 1.0.3 โ€” the agreed design (not yet built)

Drop: every SMF-territory check (D1).

Pairs to test (D3):

Pair Must agree on
attachment row โ†” post post exists (id_msg โ†’ messages)
attachment row โ†” member member exists (avatars)
attachment row โ†” file file in the folder id_folder names, at the row's size
attachment row โ†” each store entry exists iff it should
post โ†” store entry entry's recorded post matches (needs added field)
file โ†” store entry entry's recorded hash/size match (needs added fields)
media_store โ†” audio_store every audio entry is an mp3/wav also in media_store
pdf_store โ†” file file really is a PDF by content
media_store โ†” embeddings โ†” captions D4

Also in 1.0.3:

Still needed from Andrew before building: one entry per store (read-only command was given), plus the embeddings/captions sizes.


6. Live's search files โ€” state at the last real run (5 Oct, 07:37 Live)

ISE file Missing (on forum, not in file) Stale (in file, gone from forum) Cause
media_store 50 (7042โ€“7125), incl. 6 thumbnails 1 (2963) MediaIndexer not run since; plain run (no args) rebuilds from SMF and drops 2963
audio_store 5 (6941, 6954, 7105, 7107, 7118) โ€” Clone's job, then json_push_audio_Clone_to_Live
pdf_store 18: 7 stuck (below) + 7132, 7134 + 7123โ€“7144 4 (6970, 7033, 7041, 7049) pdf_store.json dated 4 Oct 18:18 Live โ€” older than the 03:25 indexing โ€” a restore put back an older copy. 7144 confirmed a real PDF (file: PDF document 1.4), so a normal/--fastest run will pick these up
misc_store 1 (5461 Groq.json) โ€” stuck (below)
SMF side 47 rows with no post/member โ€” SMF's territory (D1)

Stuck โ€” skipped by every run, full or not (needs the --single trace):

Ways to clear the stale entries (Andrew's choice):

Facts found about the indexers


7. The Python break on Live (5 Oct) and its fix

Symptom: --snapshot failed (No module named 'backports', then 'zoneinfo'), so every check compared against an old snapshot โ€” giving false lines (86 "files with no row", stale entries for anything uploaded after 30 Sep). PDF search itself could not load either.

Cause:

Fix applied on Live:

  1. python3.6 -m pip install backports.zoneinfo
  2. ResultFormatter line 77 replaced with:
    try:
    from zoneinfo import ZoneInfo
    except ImportError:
    from backports.zoneinfo import ZoneInfo

    (backup: ResultFormatter.py.bak)

  3. --snapshot โ†’ RC 0.

Open: the same change must go into Andrew's master with a version/date bump, or the next deploy undoes it. Note: 7.4.3 in the v9.9 zip also imports zoneinfo unconditionally โ€” rolling back to it would not help.


8. Python on all three machines

Live

Clone

Dev (32-bit)


9. Tools delivered this chapter

Zip Contents Notes
COI_Chain_v1.0.2.zip COI_Chain.py, test, manual, .htaccess installed on Live
ISE_Indexers_v9.9.1.zip --single ID_ATTACH added to PDFIndexer 8.6.0, MiscIndexer 7.5.0, MediaIndexer ISE v9.9.1 (code added only) installed on Live. PDFIndexer's --single still pays the full-disk file sweep (minutes) โ€” proposed fix 8.6.1, not built
PDF-32bit-Indexer_v8.6.0.zip superseded โ€” its manual was an older copy don't use the manual from it
PDF-32bit-Indexer_v8.6.0.1.zip PDF-32bit-Indexer.py v8.6.0 + Andrew's latest manual with one entry added see below

PDF-32bit-Indexer.py v8.6.0


10. OVERSEER folder ownership


11. Open items (in a sensible order โ€” timing is Andrew's call)

  1. ResultFormatter fix into the master (+ version/date bump).
  2. Bring Live's search files up to date: PDFIndexer (--fastest is quick), plain MediaIndexer, clear the 4 stale PDF entries.
  3. Mirror Clone and Dev after (2) โ€” otherwise they copy Live's out-of-date files. gzip each first; never mirror during an indexer run.
  4. Trace the stuck 8 (7 PDFs, Groq.json) with --single.
  5. Switch Live's python3/pip3 links to 3.8 (Clone the same, when ready).
  6. Copy Dev's PyMuPDF 1.14.21 wheel to /backup.
  7. Decide PDF-32bit-Indexer points 2 and 3.
  8. Add the snapshot-failure guard to coichecks.
  9. Answer the open questions in ยง4 (gold standard; where MediaProcessor runs; manual vs scheduled indexing).
  10. Send store samples + embeddings/captions sizes โ†’ build COI 1.0.3 (ยง5).
  11. PDFIndexer 8.6.1 โ€” --single without the full-disk sweep (if wanted).
  12. Convert the in-place writers (IndexBuilder, MediaIndexer, MiscIndexer, orphan_check) to temp-file-and-swap โ€” still open from 30 Sep.
  13. Wire the gated mirror, ls diff and daily cron (after 1.0.3, so RC 8 means something).
  14. Install COI on Clone and Dev; Dev break-test (D5).
  15. Tighten Collabware permissions; confirm OVERSEER ownership held.

12. Standing rules in force

OVERSEER Checkpoint 2026-10-05, ~11:57 AEDT