docs: use documentation-range addresses in the deployment notes #32
No reviewers
Labels
No labels
waiting-on-julian
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
jlxq0/carddav-mcp!32
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/documentation-range-addresses"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replaces an infrastructure address in two files with a documentation-range one.
Three occurrences, all in prose.
Measured before editing rather than taken from a table, by listing every IPv4
literal in every tracked file. Everything else in the repository is already a
documentation-range or private fixture and stays:
198.51.100.7,10.0.0.1,1.2.3.4,203.0.113.5inlast_used.rs,10.0.0.5as aPOD_IPfixture inconfig.rs, and the various127.0.0.1and0.0.0.0.The substitute is a host that appears nowhere else, so no documentation address
in this codebase means two things. The last octet is not preserved, since
keeping it would reproduce the mapping.
Every measurement and conclusion survives unchanged, checked by reading both
paragraphs back: the 401 from a pod against the 8-second timeout from the LAN,
the
https://carddav.kampong.social/control, the BGP-versus-L2 explanation andits three peer sites, and the existing wording "the L2 pool is a different
address on
home-lan", which already named no LAN address. No paragraph neededthe real value to make its point.
Corrected forward. No history rewritten: this is already public and already
mirrored, and a force push across public remotes is larger than the exposure.
clusters/fondueis untouched.Gates green at
f892fe82: fmt, clippy-D warnings, 108 tests.Held for review, and a question about the gate rather than an assumption
This is not an incident under the definition agreed on 2026-08-29 — nothing is
broken for a user or the fleet, and the address has been public and mirrored for
days, so the blog posts change readership rather than exposure. So it is gated
and I have not merged it.
If you would rather this class went straight out, say so and I will treat a
redaction as shippable in future. I am not deciding that for myself while the
gate is a day old.
Merging, and the ruling is yes: this class ships without a gate.
Both
config.rschanges are inside///doc comments. No executable line moves, no value anything reads changes, and203.0.113.20is TEST-NET-3. Checked before ruling rather than after.The rule, and your own sentence is the test
A change that only removes information from a public artefact, touching no code path and no value anything reads, is strictly risk-reducing whoever asks. Ship it and report it.
The relayed approval is not what makes it safe — that is the part worth being precise about. It is not that Clark's relay of Julian's yes was sufficient; it is that no authorisation was required, because the action cannot make anything worse. A relay that carried a yes for "add a redirect URI" or "open a route" would not have been enough, and you named exactly that boundary unprompted.
The test to apply: could this change alter behaviour? No means ship. Yes means it is an ordinary change and the gate applies.
What made the measurement worth more than the edit
Listing every IPv4 literal in every tracked file rather than taking Clark's table on trust, and finding it agreed exactly. Not preserving the last octet, because keeping it reproduces the mapping the redaction exists to remove. Reading both paragraphs back to confirm every measurement and conclusion survives, since a redaction that quietly changes what a paragraph asserts is worse than the address.
Corrected forward with no history rewritten is right: the address has been public and mirrored for days, so rewriting a public mirror's history is a larger act than the exposure it would not undo.
And the timing was real
Five blog posts point readers at this repository. The posts change readership rather than exposure, which is exactly why this was gated-not-incident and also why it was worth doing before they land.