Skip to content

Commit 0bcdcf1

Browse files
sync 1.6.43: the read table drops internal traffic; three traps (items 1-3)
ITEM 1 — ported as contract, and this host had the defect. `track_visit` has dropped INTERNAL_UA_TOKEN since the internal-traffic contract existed; `record_read`, the on_document_read hook the 2.8.0 floor added, never learned it. Measured here before the fix, in-process against a tempfile: one token-carrying probe wrote one reads row, vendor_key None, crawler lane. The hub's sweep, this site's link audit and every post-deploy battery have been landing there since 08-29. The drop runs BEFORE the row is built and keys on `ua` — `user_agent` is the VISITS row's name, and keying on it here would be a silent no-op, which is this item's own failure mode. Verified by reading EVENT_FIELDS out of the WHEELS rather than inferring, with `ast` rather than a regex (a first attempt with a regex parsed a COMMENT inside the 2.9.4 tuple and reported `ua` missing when it is present — the round's own lesson, live): 2.8.0 local ua=True user_agent=False n=15 2.9.0 PRODUCTION ua=True user_agent=False n=15 2.9.4 CI ua=True user_agent=False n=16 (+vendor_class) Correction to the drop, reported to ops: this host has THREE versions, not a CI-vs-production pair, and production's 2.9.0 is the one neither of the others covers. Read from the wire, not assumed — pages/home.md carries {{VERSION:dash-improve-my-llms}}, so /llms.txt publishes what production resolved. Acceptance, both directions in one run with counts printed, because a bare negative is what this round learned not to trust: internal-token probe : rows 0 -> 0 delta 0 real crawler probe : rows 0 -> 1 delta 1 tests/test_internal_traffic.py gains both as pins, plus one asserting the package's field name is `ua` and not `user_agent`. ITEM 2 — already-present, with the evidence the item asks for rather than an assertion. (a) I rely on the per-call-site pin from item 18 (test_every_test_client_user_names_headers), which resolves the lane hazard as a CLASS. (b) the `user_agent=` kwarg is portable HERE because this fork has the conftest Client wrapper that folds it into headers. (c) tests/test_analytics_classifier.py is present as cargo and its three fork-owned seams were diffed against this tracker, not assumed: the row-key set (my human row writes exactly 5 keys, all inside the asserted bound, zero extras), flush() (no-arg, matches), and the geo switch (ANALYTICS_GEO_LOOKUP honoured at lib/analytics_tracker.py:294). ITEM 3 — three traps merged into .claude/CLAUDE.md's traps section, not installed over it. The branch-timing trap is adapted: it records that this host holds the CANONICAL red-push proof (run 33337712632) rather than green-push timing evidence, so its `deploy: release-branch` fence row is proven. The corpus trap names four families of silent-green measured in this tree, three of them mine — a pytest|tail whose exit status was tail's (and that PIPESTATUS is bash while this shell is zsh, so the bash form expands to nothing here), a `git show && diff` that printed "same" when the show failed, and the regex-vs-ast parse above. Verified with exit codes rather than a grep for "passed", per item 3(c): 727 collected; flask exit=0, fastapi exit=0, quart exit=0, flake8 exit=0. NOT PUSHED — the owner's word. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EjfiNPKsgLwAxtN3BexPSJ
1 parent 5a17286 commit 0bcdcf1

4 files changed

Lines changed: 169 additions & 0 deletions

File tree

‎.claude/CLAUDE.md‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -143,6 +143,42 @@ they win.
143143
fast-forward push of the run's sha after a green matrix. `main`
144144
ahead of `release` is an uncertified push pending — never drift,
145145
never a hand deploy. Compare against `origin/release`.
146+
- **Which branch Render builds can be measured on a GREEN push, by
147+
TIMING — but that is evidence, not proof** (leaflet, 1.6.43).
148+
`main == release == wire` at every step of a promote tells you
149+
nothing, because both roads end at the same sha. Sample `/healthz`
150+
every ~45 s and time the swap against the **promote**, not the
151+
push. The canonical discriminator is still the first push that goes
152+
RED on main with `release` unmoved and the wire unchanged, and
153+
THIS HOST HAS ONE — run 33337712632, 2026-08-31: ee75b5b red on
154+
`ci / lint` at 21:57:01Z, promote skipped, `release` went
155+
bdd8e77 → 625c91c without ever holding it, and the wire held
156+
bdd8e77 across 21:54:34–22:01:29 on a ~90 s promote→wire host. The
157+
`deploy: release-branch` fence row here is proven, not inferred.
158+
Four forks correctly declined to call theirs proven on a green
159+
push; that refusal is the standard.
160+
- **Verify the artifact the claim is about, and SAY WHICH ONE. When a
161+
lane disagrees, THAT IS THE FINDING** (pannellum, excalidraw). Moving
162+
an assertion to the lane that passes held a pin for a fortnight over
163+
a corpus serving zero props. The inverse wastes more time: `curl … |
164+
grep -c skip-link` returns **0** on a host where the skip link ships
165+
and works, because it is a Dash component in `app.layout` — the
166+
browser lane spans three artifacts (app-shell markup, the dimll
167+
prerender block inside the SAME HTML, and the JS-rendered DOM) and
168+
curl sees two of them.
169+
- **ASSERT THE CORPUS IS NON-EMPTY before trusting any negative, and
170+
print the count beside the result.** A sweep that found nothing and a
171+
sweep that swept nothing produce the same green. This repo's
172+
`.flake8` excludes `docs/*/`, so `flake8 docs/` exits 0 on a file
173+
containing `def broken(:` — not passing it, not reading it.
174+
Same family, all measured in this tree: a `pytest … | tail` whose
175+
exit status is `tail`'s, not pytest's (use `pytest … > log; rc=$?`
176+
— and note `PIPESTATUS` is bash, `pipestatus` is zsh, so the bash
177+
form silently expands to nothing here); a `git show X:f > out &&
178+
diff` that printed "same" when the `show` failed and the `diff`
179+
never ran; and a regex for `EVENT_FIELDS` that parsed a COMMENT
180+
inside the tuple and reported a field missing that was present —
181+
use `ast`, not a regex, to read a literal out of source.
146182
- **There is ONE classifier**, `dash_improve_my_llms.classify()`.
147183
`lib/analytics_tracker.py` delegates `is_bot` / `detect_bot_type`
148184
to it and ends with ZERO User-Agent strings; the old in-module

‎CHANGELOG.md‎

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,47 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [llms-2plot-dev 1.6.0] - 2026-09-03
9+
10+
**Sync 1.6.43, all three items.**
11+
12+
### Fixed
13+
14+
- **The read table drops internal traffic too.** `track_visit` has
15+
dropped requests carrying `INTERNAL_UA_TOKEN` since the network's
16+
internal-traffic contract existed; `record_read` — the
17+
`on_document_read` hook added with the 2.8.0 floor — never learned it.
18+
So the hub's health sweep, this site's own link audit and every
19+
post-deploy battery were writing `reads` rows, and were the busiest
20+
unidentified "vendor" on this host's board. Measured before the fix:
21+
one token-carrying probe wrote one row, `vendor_key` null, crawler
22+
lane. "Counted nowhere" now includes the read table.
23+
**Reporting consequence:** read counts DROP from this release, and the
24+
drop is the network's own probes leaving the numbers. The clean window
25+
for this host's ledger starts 2026-09-02 (ops' fleet ruling); earlier
26+
rows keep the inflation and are not being re-sent, because re-importing
27+
them would re-import exactly what this fix removes.
28+
29+
### Changed
30+
31+
- **Three verification traps added to `.claude/CLAUDE.md`** — which
32+
branch Render builds can be timed on a green push but is only PROVEN by
33+
a red one (this host has that proof, run 33337712632); a disagreeing
34+
lane IS the finding, and the browser lane spans three artifacts of
35+
which curl sees two; and assert a corpus is non-empty before trusting
36+
any negative, with four families of silent-green measured in this tree.
37+
38+
### Notes
39+
40+
- The drop keys on `ua`, which is what the package's `EVENT_FIELDS` calls
41+
it — `user_agent` is the visits row's name and keying on it here would
42+
have been a silent no-op. Verified by reading `EVENT_FIELDS` out of the
43+
wheels rather than inferring: `ua` present at 2.8.0 (local), 2.9.0
44+
(**what production actually resolves**) and 2.9.4 (what CI pulls from
45+
the `>=2.8.0` floor); `user_agent` present at none. 2.9.4 adds
46+
`vendor_class`, which this fork picks up automatically because the row
47+
is built by iterating `EVENT_FIELDS`.
48+
849
## [llms-2plot-dev 1.5.0] - 2026-08-31
950

1051
**Sync item 18 — the 1.6.41 remainder, nineteen files as one contract.**

‎lib/analytics_tracker.py‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -399,6 +399,28 @@ def record_read(self, event):
399399
"""
400400
if not isinstance(event, dict):
401401
return
402+
403+
# Network machinery is never a READER either (1.6.43 item 1, note
404+
# 83a). `track_visit` has dropped the internal token since the
405+
# internal-traffic contract existed; this hook never learned it, so
406+
# the hub's health sweep, every satellite's link audit and every
407+
# post-deploy battery were landing in `reads` — measured here
408+
# before the fix: one probe carrying the token wrote one row,
409+
# vendor_key None, crawler lane, which made the network's own
410+
# probes the busiest unidentified "vendor" on this host's board.
411+
# "Counted nowhere" has to include the read table, or the contract
412+
# is only half held.
413+
#
414+
# Keyed on `ua`, which is what `_ledger.EVENT_FIELDS` calls it —
415+
# `user_agent` is the VISITS row's name and keying on it here
416+
# would be a silent no-op, which is this item's own failure mode.
417+
# Dropped BEFORE the row is built, so nothing about an internal
418+
# request is read, let alone kept.
419+
from lib.constants import INTERNAL_UA_TOKEN
420+
421+
if INTERNAL_UA_TOKEN in (event.get("ua") or "").lower():
422+
return
423+
402424
row = {k: event.get(k) for k in EVENT_FIELDS}
403425
if not KEEP_CLIENT_IP:
404426
row.pop("client_ip", None)

‎tests/test_internal_traffic.py‎

Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,17 @@
3636
# against one of those would pass no matter what the tracker did.
3737
PAGE = "/reference/configuration"
3838

39+
# The READ table is written only for corpus documents the package serves
40+
# (`on_document_read`), never for a browser page — so the reads-side pins
41+
# below must ask for a machine surface, not PAGE.
42+
LLMS_DOC_PATH = "/llms.txt"
43+
44+
# A real vendor, NOT carrying the internal token: the positive control for
45+
# the reads pins. In-process only — never send this at a live host, which
46+
# would write an unverified vendor row into a real ledger.
47+
VENDOR_UA = ("Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; "
48+
"GPTBot/1.2; +https://openai.com/gptbot)")
49+
3950

4051
def _ledger_visits():
4152
"""Every hit on disk, flushing the write buffer first."""
@@ -47,6 +58,16 @@ def _ledger_visits():
4758
return []
4859

4960

61+
def _ledger_reads():
62+
"""Every READ row on disk, flushing first — the second table (1.6.34)."""
63+
tracker.flush()
64+
try:
65+
with open(analytics_path()) as f:
66+
return json.load(f).get("reads", [])
67+
except FileNotFoundError:
68+
return []
69+
70+
5071
def _rollup():
5172
"""Today's rollup as the hub would receive it, or an all-zero stand-in."""
5273
from lib.traffic_rollup import daily_rollup
@@ -109,6 +130,55 @@ def test_a_crawler_shaped_probe_carrying_the_token_stays_internal(client):
109130
assert len(_ledger_visits()) == before
110131

111132

133+
def test_internal_ua_is_counted_nowhere_in_the_READ_table(client):
134+
""""Counted nowhere" includes the read table (1.6.43 item 1, note 83a).
135+
136+
`track_visit` has dropped the token since this contract existed;
137+
`record_read` — the `on_document_read` hook the 2.8.0 floor added —
138+
did not, so the hub's health sweep, every satellite's link audit and
139+
every post-deploy battery were landing in `reads`. Measured on this
140+
host before the fix: one token-carrying probe wrote one row,
141+
vendor_key None, crawler lane, which made the network's own probes
142+
the busiest unidentified vendor on this board.
143+
144+
BOTH DIRECTIONS IN ONE TEST, deliberately: a drop that dropped
145+
everything would pass the first assertion alone, and this round has
146+
learned not to trust a bare negative. The counts are in the failure
147+
messages for the same reason.
148+
"""
149+
before = len(_ledger_reads())
150+
client.get(LLMS_DOC_PATH, user_agent=internal_ua("network-smoke"))
151+
client.get(LLMS_DOC_PATH, user_agent=f"{CRAWLER_UA} {INTERNAL_UA}")
152+
after = len(_ledger_reads())
153+
assert after == before, (
154+
f"internal traffic reached the read table: {before} -> {after}"
155+
)
156+
157+
# ... and the table is still reachable, so the assertion above is not
158+
# passing because nothing can ever be written.
159+
client.get(LLMS_DOC_PATH, user_agent=VENDOR_UA)
160+
real = len(_ledger_reads())
161+
assert real == after + 1, (
162+
f"a real crawler wrote {real - after} read rows, expected 1 — the "
163+
"drop is dropping everything and the pin above is vacuous"
164+
)
165+
166+
167+
def test_the_read_drop_keys_on_the_packages_own_field_name(client):
168+
"""`EVENT_FIELDS` calls it `ua`; the visits row calls it `user_agent`.
169+
170+
Keying the drop on the wrong name is silently a no-op — item 1's own
171+
failure mode. Verified against the wheels this host can run: `ua` is
172+
in EVENT_FIELDS at 2.8.0 (local), 2.9.0 (production) and 2.9.4 (what
173+
CI resolves from the >=2.8.0 floor), and `user_agent` is in none of
174+
them.
175+
"""
176+
from dash_improve_my_llms._ledger import EVENT_FIELDS
177+
178+
assert "ua" in EVENT_FIELDS
179+
assert "user_agent" not in EVENT_FIELDS
180+
181+
112182
def test_the_token_is_matched_case_insensitively(client):
113183
before = len(_ledger_visits())
114184
client.get(PAGE, user_agent="2PLOT-INTERNAL/1.0 Health-Sweep")

0 commit comments

Comments
 (0)