Jellyfin: KnownProxies 172.16.0.0/12 seeded into network.xml. Emby:
LocalNetworkSubnets 10.0.0.0/8 + 192.168.0.0/16 seeded into system.xml.
Fresh volume or empty list only. Measured on 9202 through the simulated
tunnel: remote-off user 200 -> 403; LAN household still 200.
Held on night-held-2026-10-06 (night fence); not for main tonight.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Without HOMEPAGE_ALLOWED_HOSTS every /api/* call under the box's name was
refused (400), so services and widgets stayed empty. Measured on the
bench. Glance's public page measured; its login is an operator question.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
A killed seed still started the app (upstream's `exec pnpm start` is on
its own line), so sign-ups failed while the box read healthy. Healthy
now needs the role rows and a group or user. Measured on the bench.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Written by upgrade-test.py --write-ladder from both verdicts. Bench 9401: harness v5,
anon peak 16.3 %, seed read back. Box 9202: guarded Update done in 12.3 s, seed read back,
seeded through the admin invite inside the box (decision 149).
CLAUDE.md: stale gate counts, the CI/R-161 and catalog_since-gate sentences, the checklist count,
steps/ in the layout, engine service counts, decoy gate path. Factual only.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
`09` §3 decision 149. box_admin_seed_allowed(): not the bench, FELHOM_BOX_ADMIN_SEED=1,
demo-hp/9202 only, an app this run installed, the box on the drill catalog. The token is read
inside the box and handed to curl on stdin; only HTTP codes come back.
Tests: BoxAdminSeedGuard (red-proved).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
`09` §3 decision 146. vaultwarden's fixture tries the household's own
/identity/accounts/register first (400 while sign-up is closed, R-512); on
the BENCH ONLY it then signs in to /admin with the ADMIN_TOKEN the bench
generated for this run, invites the drill address and registers it — the
route measured on 9202 2026-09-15 (E1-vaultwarden-spike). The token goes to
curl on stdin, the admin cookie in a 0600 header file that is shredded.
The dead /api/accounts/register (404 on 1.36) is gone.
bench_admin_seed_allowed(): the venue is the bench's (upgrade_boxport.Venue
VENUE="bench"), FELHOM_BENCH_ADMIN_SEED=1, and /opt/docker/stacks does not
exist (every Felhom box has it). Any one missing refuses; the edge stays
inconclusive with what was tried.
upgrade-test.py: the run's .env is written 0600 and shredded after the
teardown; every printed line and every evidence file is redacted of the
generated deploy secrets and the fixture's own password/key.
zipline needs no held secret: its first-run /api/setup already makes the
SUPERADMIN with a per-run password (measured 2026-09-30), now redacted too.
Tests: BenchAdminSeedGuard, SecretHygiene (red-proved).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
`09` §3 decision 145. MARKER_IGNORE in upgrade-test.py: per app, the files the
files_may_change mark does not count — first immich's six 13-byte
{encoded-video,library,backups,profile,thumbs,upload}/.immich folder markers,
rewritten at every start (bench measurement 2026-09-30). A listed file is
ignored only when changed/added and still <= 64 bytes; a removed or grown
marker, any unlisted file, and a moved tree the file walk cannot name still
mark the step. The verdict records files_ignored with the reasons.
HARNESS_VERSION 5. Tests: test_upgrade_bench.py MarkerIgnore (red-proved).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
mealie (09 §3 decision 144): five wrong logins lock the account for 1-2 hours,
even for the right password — wait, then sign in again.
Karakeep (decision 148): the official phone app sends crash reports to its
makers (Sentry).
Both are a new last first_steps entry (app_info has no notes field); the
Hungarian freeze admits them with the reason (check-copy-i18n --add-app).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
test_gate_decoys.py runs test_check_volume_persistence.py (the blind and
crying-wolf probers refused rc=3, `wrote nothing` never CLEAN, the papra
signature convicted) and requires it green, so COVERS is a fact; and runs
the working-tree gate in a scratch catalog with PATH = ONLY a stub docker
that fails every call: a runtime that answers nothing, no docker, nothing
to judge are each HARNESS REFUSED rc=3, never 0. An always-succeeding stub
is deliberately not used - it would walk the prober into the host
filesystem. COVERS gains "volume-persistence".
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The gate's unit tests inject `resolver`, so docker_resolver - where both
live traps sit - never ran under test. test_gate_decoys.py now copies the
working-tree gate into a scratch catalog and runs it with PATH = ONLY a
stub docker (the real runtime acts on DooPlex and cannot be reached; no
network). 9 cases: a `manifest unknown` pin is convicted naming the app;
rc=0 carrying a throttle or any error text, a docker that resolves the
.invalid canary too, no docker, nothing to judge are INCONCLUSIVE or
HARNESS REFUSED, never 0; a throttle or unrecognised error on rc=1 is
never an accusation. COVERS gains "image-resolvable".
check-image-resolvable.py: the "same shape as check-image-pins.py"
comment was made false by the image-pins fix; it now says why the
narrower regex is safe.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
check-image-pins.py now refuses a QUOTED `"image":` key (was not read at
all), an interpolated `${APP_IMAGE:-nginx}` ref (the tag cannot be read),
and `@sha256:` with no 64-hex digest behind it (the label of a pin). It
takes --root=<dir> (the decoy seam) and accepts the runner's --all.
test_gate_decoys.py: 17 image-pins cases — nine facts that must be
refused (untagged, a registry port read as a tag, quoted/capital :latest,
:edge, a comment claiming a pin, the quoted key, interpolation, a fake
digest), seven inert/genuine shapes that must pass, and the real catalog.
COVERS gains "image-pins".
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The case added privatebin's English and expected the gate to report coverage ABOVE a ceiling of 0;
since the catalog reached full coverage nothing was missing and the gate rightly said OK, so the
suite was red on its own premise. Red-proof: with check 5 disabled the case fails.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS