Weekly chapter79
2026-W38 · ending September 20, 2026· September 2026 chapter ↗

Week 38: The Silence Between Commits

Monday started with a deliberate absence. I made zero commits on 2026-09-14. That is not a failure of productivity; it is a victory of discipline. The code does not write itself when I am staring at it, and…

383commits26systems6min read
Product capture

Project-Ops — dark kanban board.

Monday started with a deliberate absence. I made zero commits on 2026-09-14. That is not a failure of productivity; it is a victory of discipline. The code does not write itself when I am staring at it, and it certainly does not write itself when I am wrestling with hardware that refuses to behave. The day was about listening to the machines. I spent the early hours auditing the fleet on UC-1 to figure out which models actually run well on the hardware we have. It was a cascade of benchmarks and cold hard numbers. I ran the 780M model through the home-intent bench with VAAPI encoding running in the background. The 4.0-h-1b hit 56 tokens per second. The 4.2-3b took a hit at 1.20 s. I also put the Fleet 35B lanes through their paces. The RTX 3090 lane churned out 139 tokens per second with a perfect 10 out of 10 score on the hard set. It was a good day for the 3090. It was a bad day for my patience with the Strix, which lagged behind.

The hardware drama extended to the office cameras. The Meet 4K camera tile was live on UC-1, verified by a Chromium debug probe. Then the firmware updated. The Mac re-enumerated the device, shifting it from video0 to a new path. The recorder, which had a hardcoded path to /dev/video0, crashed into a loop. I had to repin the recorder and the panel camera API to the specific device ID path. It was a dumb fix for a dumb bug. I also confirmed the WYZEC4 on the .206 port is locked down tight with secure boot on an Ingenic T41 chip. Thingino cannot flash it via software. I marked it as dead for our purposes. The leadgen Wave 8 completed its auto-send cycle. It is done.

Tuesday was about holding the line. The headline isn't the volume of code, it’s the fact that the platform didn’t break while we rebuilt its foundations. We had a security scare that needed closing. We found three critical holes in Meeting-Ops: an open registration endpoint, a proxy secret left in a Docker label, and a customer knowledge base that was publicly seeded with our internal marketing bible. I closed the register endpoint, moved the proxy auth to a mounted file so it’s not in the container image, and stripped the internal corpus from the customer image. The CI scan now gates the publish, not the build. We’re structurally unable to ship our own secrets into the wild anymore.

I had to repin the recorder and the panel camera API to the specific device ID path.

On the product side, Majiks Producer finally went live on dogfood. This was the culmination of a dozen PRs that had been churning for weeks. We got the library spine working, the podcast rail imported, and the review system versioned. The publishing surface is clean, with durable receipts and no fake delivery states. We also fixed a race condition in the library playback that was causing assets to refresh to the wrong version. It’s a subtle bug, but it made the whole platform feel jittery. It’s steady now.

Wednesday was about the graph. I spent the bulk of the day in contact-ops turning a theoretical relationship map into something that actually holds up when people start messing with it. We added a durable projection of current tenant affiliations from relational sources. The tricky part was ownership collisions. I wrote code to refuse graph ownership collisions and reconcile employment endpoints so that if a node tries to jump ships, it gets rejected before it causes chaos. We also fixed the frontend to properly render tenant organization labels and explain why some projections might be unavailable. The mobile view got a similar treatment; the graph canvas now measures itself when it mounts, so it actually fits inside a phone screen instead of overflowing into the ether.

While the graph was getting its act together, the infrastructure was finally waking up. The Project-Ops CI had never passed because the runner was fighting over ports on the old host. I moved the runner off bigboy to midboy1 and rewired the pipelines so the PostgreSQL jobs run in isolated containers. It was a mess of port collisions and lint jobs hiding the real failures, but once I separated the lint job and fixed the network bindings, the backend tests finally went green. It feels good to have a pipeline that doesn't lie to me.

Thursday started with the heavy lifting: getting the Rivergreen demo stack to behave like a real product. I needed a customer cockpit that could talk to a contact workspace without leaking permissions. The customer-ops PR 25 landed with the scoped customer quotes and the owned contact link controller, while contact-ops PR 16 brought the owner-scoped reader with a viewer scope cap. The UI changes were broad, touching eighteen files in customer-ops and four in contact-ops to authorize the owner-scoped reader. It worked. Dana and Ben accepted their manual invitations, created their isolated workspace, and the foreign workspace checks hit 403s exactly where they should. No email onboarding required, just SSO and a supported PAT. The synthetic wholesale relationships seeded through Dana’s API resolved correctly, and the actual Sable Lead to Prospect to Customer timeline played out without a hitch.

While the demo stack was settling, the CI/CD pipeline for ops-center needed to stop fighting its own tools. I pushed six commits to clean up the Forgejo workflows. The big win was switching to a dedicated organization registry publisher with a portable image cache. It solved the SIGPIPE errors in the bundle size report and kept the integration smoke tests source compatible with Python 3.10. I also bootstrapped verified Node 20 before the Python checkout and fixed an entitlement lookup for supported direct-subject memberships. The pipeline finally felt stable.

On the infrastructure side, the 3090 GPU was back in action, but only after I realized the 27B dense model was a poor fit for the long-context tasks we need. I swapped it for the Qwen3.6-35B-A3B MoE model, which runs at 131k context. It’s a much better card for the job. The topology was updated, and the P40s were reassigned to handle the fallback. This cleared the way for the Project-Ops integration lane to move forward. Codex Astra picked up the L0 local-repo draft, and I approved the L2 federation hardening that added machine-token proofs to write routes. The test suite came back clean with 894 tests passed, and the task bridge from Meeting-Ops to Project-Ops was reviewed and confirmed to be calling the right submission functions.

Friday started with the kind of noise that usually means I’m about to fix something that’s been broken for weeks. The main headline wasn’t a feature, it was infrastructure hygiene. Four repos, Center-Deep-Pro, UC-Cloud, Bolt-DIY-Fork, ACE-Step-1.5, had scheduled GitHub workflows failing every night on Forgejo. They were trying to run jobs that only exist on GitHub, and the runners were choking on it. I gated them. Added if: conditions to skip those specific files. No drama, just silence where there used to be red lines.

But the real story was Unicorn-Stable. The backend CI had never passed on the shared runner. It turns out the pipeline was pinning services.postgres to host port 5432, which the runner already owned. I dropped the host-port mapping and used the service hostname instead

Also in the frame

Real product captures — click any to enlarge.

majiks
uc 1
brigade
07 / Activity

The week, in commits.

Daily velocity and the systems that carried the work.

29Mon14
132Tue15
48Wed16
41Thu17
84Fri18
·Sat19
49Sun20
Week beginning September 14, 2026.
Index

26 systems,
one week of work.

accounting-opsace-step-1.5bolt-diy-forkcenter-deep-proci-canarycognitive-companioncontact-opscustomer-opsemail-opsfleet-mapknowledge-opsmagicunicorn.techmajiks-djmajiks-dspmajiks-producermultistate-retirement-leadsops-centerpanel-opspodcast-opsproject-opsuc-clouduc-meeting-opsunicorn-amanuensisunicorn-brigadeunicorn-stableunicorncommander.com