Backlog row daily-health-digest-contract-missing-20260925. The digest has been
dispatched on a schedule with NO contract file at all - no *daily*.prose.md,
absent from contract-registry.yaml, the only reference anywhere being the CT100
cron line. That absence is why the choice of execution copy was silently the
operator's, and how a stale clone could run the check unnoticed.
New daily-health-digest.prose.md states:
* the PINNED execution path /root/abiba-workspace/projects/prose-contracts/
scripts/daily-infra-report.py and the pinned clone - the cron's FM_HOME clone,
the only stable non-ephemeral copy; the treehouse clone is a per-agent working
copy and must NOT be pinned;
* the output shape (all 18 top-level --json keys) and what a healthy run is;
* the exit-code semantics AS THEY ACTUALLY BEHAVE, verified case by case:
missing PVE_TOKEN or an unreachable probe exits 1 and raises an alert, while
a missing EMAIL credential is a deliberate DEGRADED leg that still exits 0 and
still produces the report. PROBE_FAILURES and DEGRADED_LEGS are separate lists
on purpose and must not be merged;
* the email-delivery dependency, that EMAIL_PASSWORD must be a Google app
password, that it is failing with 534 5.7.9 as of 2026-09-25, and that a
delivery failure is a credential dependency rather than a code defect;
* what counts as a failure versus degraded.
Registered in contract-registry.yaml (contracts entry plus index.by_category
.monitoring and index.by_domain.infrastructure). Verified: YAML parses, 31
contracts, exactly one daily-health-digest entry.