docs: record final development verification

This commit is contained in:
SimpleTest 2026-07-24 15:45:32 +03:00
parent c952f3cc61
commit a95ebf71c6

View File

@ -3,6 +3,83 @@
Observed through 2026-07-24 in the local workspace. This report separates observed Observed through 2026-07-24 in the local workspace. This report separates observed
results from product limits and unknown production properties. results from product limits and unknown production properties.
## Final local development audit on 2026-07-24
These observations apply to the local checkout, its isolated test projects, and
`https://whoneedhelp.imalto.site`. No push, test/production deployment, Devpost
edit, branch, or tag was made.
- The separate Firebase project `who-need-help-dev-firebase` uses the free Spark
plan, has Gemini and Analytics disabled, and contains the development Android
app `org.whoneedhelp.mobile.development`. Its public Android configuration and
a dedicated FCM service-account credential are present only in the ignored
mode-`0600` development `.env`. The service account has the exact Firebase
Cloud Messaging API Admin role. `check-environment-readiness.sh .env
--require-release` reports zero blocking items and zero local-only warnings.
- The current development workers were recreated with that FCM configuration
only after a mode-`0600` custom-format database backup was written to
`output/backups/dev-before-fcm-workers-20260724-114450.dump` and its checksum
and archive catalog passed. Web replicas, proxy, database, test, production,
public Git, and Devpost were not changed.
- The complete Android/browser development replay passed on the stable Android
37.1 Google APIs image with Google Play Services `262031038`. It completed a
magic-link login, Android-to-browser chat, browser-to-Android chat, FCM device
registration, a real FCM system notification, foreground live-location
sharing, and stop-sharing cleanup. The exact fixture retained two messages
and six tracking samples during verification, then cleanup restored the
original database counts with zero current tracking positions. Evidence is
`output/android-browser-development-e2e/20260724121700-2530398`; the
run-scoped container, AVD volume, image, and database fixture were absent
afterward.
- A separate signed development smoke passed on Android 37.1. Android verified
the exact App Link host, the implicit same-origin deep link opened the app,
the home and `/safety` DOM assertions passed, an unrelated HTTPS origin was
not claimed, and no WebView load or TLS error was recorded. Evidence is
`output/android-development-smoke/20260724124143-3282044`; its exact
container, volume, and image were absent afterward.
- `./scripts/test.sh` passed all 356 ExUnit tests. The final isolated browser
suite passed all 42 scenarios in Chromium, Firefox, and WebKit after updating
one stale assertion to the product's already-covered double-blind review
reveal behavior. Evidence is `output/e2e/20260724122808-2848321`; all
run-scoped containers, networks, database volume, and images were absent
afterward.
- `./scripts/quality.sh` passed ShellCheck, Hadolint at the configured threshold,
actionlint, every Compose render, Prometheus and Alertmanager validation,
Helm lint, tracked-source and image scans, formatting, warnings-as-errors
compilation, xref, strict Credo, Sobelow, Dialyzer, Hex/npm audits, all 356
ExUnit tests, and the isolated release/rollback/migration drills. The quality
project's exact temporary resources were absent afterward.
- The final isolated 30-second load run used 3 web and 2 worker replicas with 40
public HTTP, 40 WebSocket, and 8 authenticated mutual-aid virtual users. It
completed 38,364 HTTP requests and 34,890 checks with zero failures, including
1,729 authenticated chat/tracking iterations. HTTP p95 was 6.776 ms and the
authenticated HTTP p95 was 9.88 ms. These are workstation measurements, not
production limits or minimum resource requirements.
- During that load, PostgreSQL peaked at 21 client backends with at least 76
connection slots of observed headroom. It recorded zero rollbacks, deadlocks,
conflicts, temporary files, or lock-waiting backends. Ecto telemetry across
the three web replicas observed 186,908 queries with a 0.250 ms average total
duration; the largest individual statement maximum in `pg_stat_statements`
was 8.300 ms. The exact application-table cleanup diff was empty. Evidence is
`output/performance/final-local-audit-load`.
- Observed load peaks were 335.7 MiB for one web replica, 239.5 MiB for one
worker, 141.6 MiB for PostgreSQL, and 307.2 MiB for the isolated proxy.
CPU peaks occurred under the deliberately concurrent workstation replay and
are retained in `resource-summary.json`; no arbitrary production threshold is
inferred from them.
- The follow-up resilience drill restarted and sequentially replaced all 3 web
and 2 worker replicas. It recorded 1,244 readiness samples with zero failures,
observed all replacement web nodes, and passed the cross-node PubSub probe.
Application logs contained no error, fatal, panic, timeout, deadlock, or
out-of-memory marker. Evidence is
`output/resilience/final-local-audit-resilience`; the exact isolated load
project and resources were absent afterward.
- A visible Chrome session on the development origin rendered the real MapLibre
landing-page demo with its three synthetic markers and zoom controls. The
unauthenticated Requests navigation correctly redirected to login and showed
the access guard. The isolated browser suite covers the authenticated request
map, viewport discovery, clustering, and request lifecycle.
## Local dev hardening audit on 2026-07-23 ## Local dev hardening audit on 2026-07-23
These observations apply only to the local checkout, its Compose project, and These observations apply only to the local checkout, its Compose project, and
@ -32,18 +109,13 @@ edit, branch, or tag was made during this audit.
port 2525. A real application-generated Google ownership-verification message port 2525. A real application-generated Google ownership-verification message
was accepted in 853 ms and observed in the Gmail inbox from was accepted in 853 ms and observed in the Gmail inbox from
`dev@whoneedhelp.com`. `dev@whoneedhelp.com`.
- `./scripts/check-environment-readiness.sh .env` now reports external SMTP, - At this point in the audit, `./scripts/check-environment-readiness.sh .env`
the support inbox, application secrets, Google sign-in, browser VAPID, still reported the four Firebase Android values and the FCM service-account
Android App Links, and Android signing inputs as ready. Its two remaining credential as blockers. They were subsequently configured and externally
development blockers are the four public Firebase Android values and the FCM exercised as recorded in the final 2026-07-24 audit above.
service-account credential. No release-readiness claim is made until those - The user subsequently accepted Firebase's separate terms in the authenticated
credentials are imported and provider/device behavior is exercised. dev-port Chrome session. A separate Spark-plan development Firebase project
- The existing Google Cloud project `who-need-help-development` was selected in was then created and configured as recorded in the final audit above.
the Firebase console through the user's already authenticated dev-port Chrome
session. Firebase requires the account holder to accept its Terms before it
can add Firebase services to that existing project. That legal acceptance
remains pending explicit user confirmation; no Firebase project, app,
service account, credential, or environment value was created or changed.
- Real browser Web Push was exercised on the development origin through the - Real browser Web Push was exercised on the development origin through the
user's existing dev-port Chrome profile. The exact origin permission was user's existing dev-port Chrome profile. The exact origin permission was
changed from `Ask (default)` to `Allow`; the application registered a second, changed from `Ask (default)` to `Allow`; the application registered a second,
@ -1479,10 +1551,10 @@ None of the observations below describe the current delivery path.
Compose project, containers, PostgreSQL volume, and images were absent after Compose project, containers, PostgreSQL volume, and images were absent after
cleanup. Evidence is retained at cleanup. Evidence is retained at
`output/external-boundaries/local-boundaries-fix-20260723`. `output/external-boundaries/local-boundaries-fix-20260723`.
- Firebase Android and server FCM credentials are intentionally still absent. - Firebase Android and server FCM credentials were subsequently configured in a
Adding Firebase to the existing Google Cloud development project is pending separate development-only Spark project and exercised as recorded in the
explicit acceptance of the separate Firebase terms. No test or production final 2026-07-24 audit above. No test or production provider configuration was
provider configuration was changed. changed.
## Known work before a public production launch ## Known work before a public production launch
@ -1512,14 +1584,11 @@ None of the observations below describe the current delivery path.
Google OAuth client on its exact HTTPS callback origin after the tested Google OAuth client on its exact HTTPS callback origin after the tested
release is explicitly promoted. The test client and callback have already release is explicitly promoted. The test client and callback have already
completed real registration and returning-user login. completed real registration and returning-user login.
- Development VAPID is configured, and a real development browser subscription - Development VAPID and isolated Firebase/FCM are configured. Real development
plus one external adapter delivery completed successfully. Configure isolated browser Web Push and Android-emulator FCM delivery both completed
Firebase/FCM credentials, then verify a physical Android development device successfully. Before a public mobile release, repeat FCM and background
before repeating browser and Android delivery against each promoted origin. tracking on a physical Android device and repeat browser/Android delivery
Direct Web Push/FCM adapters, registration lifecycle, private payload shape, against each explicitly promoted origin. APNs and iOS are outside the current
retries, invalid-device cleanup, and Android deep-link handling are
implemented and locally tested. Browser provider delivery is now observed on
development; Android FCM delivery is not. APNs and iOS are outside the current
scope. scope.
- Load-test representative data and traffic, then set measured pool, resource, - Load-test representative data and traffic, then set measured pool, resource,
autoscaling, and action-limit policies. autoscaling, and action-limit policies.