D4 build week: the table turns green
420-302-VA · WEEK 14 · FALL 2026

Stage 6 of 6 · The exit · three days of deliberate stillness

The freeze

Engineering has a standard name for what Monday evening begins: a freeze, the point after which the rules for changing the system tighten, kept by every team that ships to a date. The logic is not superstition about touching things; it is arithmetic about a shrinking window. This page gives the argument once, so the rules read as conclusions, then the rules, then the three-day runway they protect.

Why freeze: the risk argument

Every change to a working system carries some probability of breaking something distant, through the shared contracts Week 12 counted; that probability never reaches zero, which is why regression re-runs exist. During the build week that risk was a good trade: a break had days of runway to be noticed and repaired, and the change bought a new green. After D4 both sides of the trade collapse at once. The upside drops to near zero, the table is submitted and no cell improves, and the downside grows without bound as the recovery window shrinks toward Thursday, 14:30 or whenever the announcement sets the demo. The standard formulation (see freeze, software engineering): a freeze exists so that the portion of the system known to work keeps working, precisely because any change may have unintended consequences.

A chart with time from Monday December 7 to Thursday December 10 on the horizontal axis and the expected cost of one more change on the vertical axis. A curve rises slowly across the build region, then sweeps steeply upward after the freeze line, a vertical dashed line at Monday evening labelled freeze called. The region left of the line is tinted green and labelled build: a break has days of runway, the change buys a green. The region right of the line is tinted gray and labelled frozen: a break may not be found before the demo, and the change buys nothing. A note on the curve near Thursday reads: same probability of breaking, vanishing time to notice and repair. build a break has runway; the change buys a green frozen a break may meet the demo first; the change buys nothing freeze called · Mon evening same P(break), vanishing repair window Mon 7Tue 8Wed 9Thu 10 expected cost of one more change → The curve is why "one small improvement" is a different proposition on Wednesday than it was last Tuesday, with identical code.
The trade inverts at the line. Risk per change is roughly constant; what explodes is the cost of the bad draw, because the next guaranteed full exercise of the system is the public demo itself. Freezing is not caution winning over courage; it is the same expected-value reasoning that ranked the rungs, applied to a week where the product is now trust.

The rules: allowed and banned

Allowed on the runwayBanned until after D5
Restoring green: the smallest fix for anything that breaks, followed by the full regression lap, because the freeze protects "known working", and a break has already left that stateNew rungs, however small, however tempting, however "basically done" one already is
Configuration and environment: demo-room Wi-Fi details, a fresh SD card from the stranger-test recipe, battery and cable logisticsRefactors and cleanups: every DEBT line in the journal stays exactly as journaled; January exists
Documentation: README polish, the D5 one-pager, demo notes; words cannot break the loop"One small improvement": the banned phrase in full; if it changes behaviour, it is a change, and the curve above does not ask how small
Rehearsal: running the system, as many times as you like; exercising is not changingDependency and tool updates: the versions that passed D4 are the versions that demo

The tie-breaker question

Unsure which column something belongs to? Ask: if this goes wrong, does the demo get worse than it is right now? Fixing a real break passes (the demo is already worse; you are restoring). Everything else that touches code fails, by the curve. Two people both answering, out loud, is the pair catching what one tired judgment misses.

The runway: two rehearsals and a drill

Three boxes along an arrow from the freeze to the demo. Tuesday December 8, rehearsal one: the full demonstration, timed, out loud, every stumble written down; fixes to words and order, not code. Wednesday December 9, rehearsal two plus the failure drill: a clean run, then on purpose pull the node's power mid-demo and practise the recovery sentence while the status topic and service restart tell the story. Thursday December 10: perform. A note: rehearsing twice is the cheapest grade improvement left this term. Tue 8 · rehearsal 1 Wed 9 · rehearsal 2 + drill Thu 10 · perform full run, timed, out loud; every stumble written down; fix words and order, not code clean run, then pull the node's power on purpose: practise the recovery sentence, LWT narrating D5 · 10 % the frozen system, shown in public Two rehearsals on a frozen system are the cheapest grade improvement left this term: zero risk, by construction.
The runway has a schedule, not a mood. Rehearsal 1 finds the demo's rough edges while there is a day to smooth the performance; the Wednesday drill makes the scariest moment, hardware dying in public, a practised scene with the status topic and the restarting service as narrators. Week 15 carries the performance craft; the evaluation page's slot protocol is the script being rehearsed.

What the drill is really buying: Week 12 built a system that survives failure (services restart, LWT reports, the broker holds), and Week 13's clinic showed you can read its signatures. The drill converts that machinery into composure, because the pair that has already watched the node die and come back, twice, narrates Thursday's worst case as a feature demonstration. Graceful degradation was designed in; rehearsal makes it visible under pressure.

Checklist for this stage

Check yourself

Tuesday night, rehearsal 1 reveals the chart label says "light (%)" but the demo script says "brightness". Your partner reaches for the HTML. Apply the freeze's own machinery.
Run the tie-breaker: if the change goes wrong, does the demo get worse than it is right now? The label is cosmetic; the demo works as-is, so a bad draw (a typo that breaks the template, a cached file confusing the fetch) makes things strictly worse for zero behavioural gain, and the risk curve is already steep on Tuesday. The freeze-consistent fix is to change the script: say "light level" on stage, one word in a document, zero risk. If the pair judges the label genuinely misleading rather than cosmetic, that is a judgment to make out loud, both partners, with the full regression lap priced in after the one-line edit; the point of the rules is that this becomes a deliberate, two-person exception, not a reflex.
Why schedule the failure drill on Wednesday rather than keep the clean run as the last memory before Thursday? Argue from how the system and the graders both work.
From the system's side: the drill is the only runway item that exercises the full resilience stack end to end, LWT firing, the status topic flipping, systemd restarting, the dashboard's staleness showing honestly, and if any link of that stack rusted since Week 12, Wednesday is the last day to discover it as a fix-to-restore-green rather than live. From the graders' and performers' side: D5 rewards composure under the exact failure the drill rehearses, and rehearsal converts startle into procedure (the same logic as any emergency drill); meanwhile a clean run also happens Wednesday, so the last memory is "we recovered, on purpose, and it looked good", which is a stronger Thursday asset than unbroken luck. Ending on the drill is choosing confidence built on evidence over confidence built on not looking.

Next week

Week 15 · Thu Dec 10

D5: the public demonstration

10 %: the frozen, twice-rehearsed system performed live. Cause the disturbance, let the dashboard narrate, answer anything. The course ends the way it was built: running.

Already written

The demo-slot protocol

Setup, frame, live run, proof, questions: the five-part slot the rehearsals are practising, with the three questions every milestone answers. It has been the target since the project hub opened.