Shipping Notes, 27 September 2026: Wired In Is Not Working
171 commits across 20 repositories in the week to 26 September. A duplicate gate that passed everything because it read a file that is never written. A landscape screen that could never have rotated. A summary file for AI systems that said nothing. Three versions of the same failure.
Every fortnight we publish what actually shipped across the group. This edition is a week rather than a fortnight, because the volume warranted it.
171 commits across 20 repositories in the week to 26 September. The last edition was about two systems that had each been individually correct and had quietly stopped agreeing with each other. This one has a different shape, and it turned up three times in seven days in three unrelated parts of the group.
Something was built. It was wired in. It reported success. It had never been capable of doing its job.
The finding: connected is not the same as working
Start with the clearest of the three, because the others are the same mechanism wearing different clothes.
We added a check to our video publishing pipeline that refuses to upload a video that has already been uploaded. Duplicate uploads had happened before — twenty-one uploads for twelve videos on one occasion — so the check had a real job.
It was written, wired into the upload path, and deployed. It then passed every video it saw. Zero blocked.
Zero blocked is the correct result when there are no duplicates, so nothing looked wrong. But the check identified a video by reading a companion file written alongside each render — and short-form videos never write that file. For every short, the check looked for the fingerprint, found nothing, concluded it had not seen this video before, and approved it. It was not failing. It was answering a question about a file that did not exist, and answering it in the permissive direction.
The second version: a screen in one of our apps rotates to landscape. The app’s configuration declared it portrait-only. iOS refuses an orientation an app has not declared, and refuses it silently — no error, no log. The screen could never have rotated on an iPhone. Android permits runtime rotation regardless of the declaration, so on Android it worked perfectly, and Android was where it had been tested.
The third: a summary file for AI systems, sitting at the expected address on our sites, ten lines long, saying essentially nothing a machine could use. Present. Served. Returning 200. Doing nothing.
Why this class is worse than a broken thing
A broken thing announces itself. A gate that throws an error gets investigated within a day.
These three did something more expensive: they produced the appearance of coverage. A status report listing the duplicate check as active was accurate. The landscape feature was in the release notes and had been tested. The summary file existed at the correct address.
In each case the work of building the thing had been done, the connection had been made, and the only step missing was the one nobody schedules — confirming the thing can fail when it should.
★ Insight ─────────────────────────────────────
The tell in the duplicate-check case was the number zero, and it read as good news. A newly deployed check that blocks nothing is either evidence that nothing is wrong or evidence that the check cannot see. Those two states are indistinguishable from the result alone, and only one of them is safe to assume. The cheap discipline is to feed a new gate something it must reject, before trusting a pass.
─────────────────────────────────────────────────
What shipped
One forms service across five sites. Every contact and lead form on ashganda.com, g-t-s.com.au, cosmoswebtech.com.au, eawesome.com.au and cloudgeeks.com.au now posts through a single shared service. Spam protection at the browser, address verification before anything is stored, a customer record created or updated by email address rather than through a form identifier, and a confirmation email the person has to click before any follow-up is sent. Five different handlers, five spam postures and five ways of reaching the customer database became one path.
Signed publish verdicts. The record that certifies a piece of media passed its quality checks now carries a keyed signature, not just a content hash. A hash proves which bytes were checked; it cannot prove a check ran. The distinction matters more every time a step of the process is automated, and it is written up in full on ashganda.com.
Real summary files for AI systems. llms.txt and llms-full.txt across five sites, replacing the stub. Between 28 and 44 lines for the summary and 34 to 76 for the full index, each one a curated list of the pages we would actually want cited rather than a dump of everything.
Video structured data on 31 commercial pages. The pages that carry an explainer video now declare it properly, so the video is eligible to appear as a video result rather than being invisible markup on a page.
A fourth division. AI Consulting now has its own division page here and a matching service page on ashganda.com.
An iOS lifecycle adoption. iOS 27 terminates an app that has not adopted the current window lifecycle, and the framework template we generated from had not. Every launch crashed. Fixed, along with the orientation defect above.
What went wrong
A confirmation email landed in Spam. On the first site tested. The DNS records that authenticate our sending domain are not fully in place, which is the likely cause and is now the next task. Until it is fixed, the double opt-in flow has a silent failure mode: someone contacts us, never sees the confirmation, and never hears back. A line telling people to check their spam folder goes onto every form in the meantime.
A straight re-vendor was the wrong fix and we did it first. Our copy of the verdict-signing code was seventeen days behind the canonical version. The obvious repair — copy canonical over ours — dropped capabilities our copy had gained and the canonical one did not have. A cross-implementation test that had been passing 23 of 23 dropped to 21. The correct fix was a merge in both directions, after which it ran 23 of 23 again. Drift between a vendored copy and its source is rarely one-directional, and treating it as though it is turns an upgrade into a silent downgrade.
The full browser test matrix has not been run. The forms service was verified end to end, and one site’s form was tested in a real browser. Every form on every site has not been. Given the theme of this edition, we are not going to describe that as done.
The thread
Three fortnights ago: gates that never ran. Two ago: gates that ran and fired on the wrong things. Last: two systems that stopped agreeing without noticing.
This week is the next station along the same line. The gate runs. It is connected to the right place. It reports a result. And it is reading something that cannot answer the question, so its result is a well-formed statement about nothing.
The practical version, which we are adopting as a standing rule: a new check is not finished when it passes. It is finished when it has been shown to fail on something it should reject. One deliberately broken input, once, before the check is trusted. It costs minutes and it is the only thing that distinguishes a gate from a decoration.
If you have a monitor, an alert or a compliance check in your own business that has never fired, that is worth ten minutes this week. Not to fix it — to find out whether it can.
Ganda Tech Services runs web, cloud, mobile and content operations for a group of Australian brands. These notes are published every fortnight, whatever they say.