From 205c6df730a09873e7a4c5b0a16fcf0036b6310e Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Wed, 12 Aug 2026 19:21:56 +0300 Subject: [PATCH] Record production email attribution limits --- docs/verification.md | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/docs/verification.md b/docs/verification.md index 44a8fe0..5d5c287 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -58,6 +58,32 @@ results from product limits and unknown production properties. frozen hackathon-test checkout, change shared Caddy, save Google Play Console fields, or push the public Git remote. +### Read-only production attribution and operations observations + +- The production application was still running revision `dafcdb3` when checked + on 2026-08-12; the email-boundary commits above were therefore not active + there. Its Oban table had no pending email/support worker backlog. The only + observed worker group was 1,440 completed request-expiry jobs. +- Since the current production container started, the database contained 44 + public support submissions: 32 were still pending contact verification and + 12 had verified contact addresses. There were no content-removal notices in + the same interval and none of those support requests had a recorded staff + response email. The deployed code attempted one confirmation for each public + submission and one receipt after each successful contact verification, so + these rows can account for up to 56 support-email attempts. The process-level + legacy metric reported 60 successful SMTP deliveries and two exceptions, but + it did not carry a purpose label. The exact purpose of each legacy delivery + is therefore unknown and must not be inferred from those aggregates. +- `SUPPORT_OPERATOR_EMAIL_MODE` was absent in the production environment and + the deployed default was `disabled`; verified support requests therefore did + not generate an operator-inbox alert in that observed configuration. +- The workstation-scheduled encrypted off-site backup completed successfully + at 2026-08-12 00:04:48 EEST, including its isolated restore drill. The new + restore-verified heartbeat implementation was committed later that day, so + the external monitor did not yet have a backup section or heartbeat to + evaluate. Enabling freshness alerts still requires an operator-selected + maximum acceptable age; the repository does not invent an RPO. + ## Current local quality and dependency-security proof on 2026-08-10 - The complete isolated `scripts/quality.sh` pipeline passed in user-systemd