diff --git a/reports/maintenance-2026-09-24.md b/reports/maintenance-2026-09-24.md index 41bb211..d4545c1 100644 --- a/reports/maintenance-2026-09-24.md +++ b/reports/maintenance-2026-09-24.md @@ -153,13 +153,17 @@ This section was first blocked on backups. The user then asked for the HIGH find | Container | Image | Image ID | |---|---|---| | homeschool_db | mysql:8.4.11 | sha256:ee241324a55f… | -| homeschool_backend | homeschool-backend | sha256:51b49afb4ec4… | -| homeschool_frontend | homeschool-frontend | sha256:f9a737699cda… | +| homeschool_backend | homeschool-backend (v1.1.0) | sha256:1eb66dc84e67… | +| homeschool_frontend | homeschool-frontend (v1.1.0) | sha256:50f1de90c447… | ### Post-deploy regression After the HIGH deploy, `POST /api/sessions/{id}/timer` returned **500 on every call**: 8 failures, 0 successes, starting 06:43 UTC. FastAPI 0.141 raises on a failed lazy-load of `current_block.subject.options` during response serialization, where 0.115 silently skipped it. The first smoke test didn't cover timer actions. Fixed in v1.1.0 by eager-loading `Subject.options` in `sessions.py` and `dashboard.py`. The smoke test now covers the full timer lifecycle, the TV dashboard with an active block, schedule/subject writes, and every parameterless GET route (from the OpenAPI spec). +### v1.1.0 deploy verification + +All 3 containers are healthy with 0 restarts, and log rotation is active (10m × 3). Public `/api/health` returns 200. Production timer actions return 200 (4 of 4 right after the deploy). Tagged `v1.1.0` and pushed. The pre-review rollback images (`rollback-20260924`) were pruned by the user; `rollback-20260924b` (the HIGH-fix build) remains. + ### Post-update scan (trivy HIGH/CRITICAL) | Image | Before | After |