@@ 21,7 21,10 @@ This hits two upload paths in production:
**Fix.** Set both `RequestChecksumCalculation` and `ResponseChecksumValidation` to `WhenRequired`, so the SDK only checksums when the protocol mandates it. This restores pre-SDK-v1.30 behavior and is the workaround Amazon documents for non-AWS S3 backends (Garage/Ceph/Minio) where strict checksum negotiation is also unreliable.
-**Status.** Applied in phoebe-lab production; **not upstreamed yet**. Also lives as commit `c2c2f3848fa9a88d96952ff08f886483f8b9d1f7` on `master` of the fork `git.srht.bigb.es/~bigbes/core-go` (branched from upstream `71b2787`), pinned via a `replace` directive in the `go.bigb.es/sourcehut-compare` service.
+**Status.** Applied in phoebe-lab production; **not upstreamed yet**. It reaches production two ways, both from the copy in `~/data/home/phoebe-lab/srht/patches/`:
+
+- **Baked into the fork** `sourcecraft.dev/bigbes/sr-ht-core` (upstream core-go + this patch), consumed by the three custom Go services (`sr-ht-compare`, `sr-ht-dolt`, `sr-ht-spec`) as a normal pinned `go.mod` dependency — *not* via a `replace` directive.
+- **`git apply`d at image-build time** by the two stack services built from source against upstream core-go: `Dockerfile.pages` and `Dockerfile.builds-worker` each `git clone` core-go (at `SRHT_PAGES_COREGO_REV` / `SRHT_BUILDS_COREGO_REV`), `git apply` this patch, then `go mod edit -replace` onto the patched tree. The `srht-build-1` worker binary reapplies it the same way via `update-worker`. The apk-packaged `builds.sr.ht` api/web is stock (unpatched) — it never uploads to S3, so it doesn't need it.
**Verify it still applies cleanly:**