diff --git a/CHANGELOG.md b/CHANGELOG.md index 585a244..186923b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,24 @@ +## v0.139.0 — a DR restore never lands beside a live original (2026-10-04, R-834) + +> **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.139.0` (`475bdce`), sha256 +> `8534a9be368a6d24d8065db77436e86900443c5c6554c71f6fe91c2bdb9d0b9c`, verified by download. **Not vouched.** + +**MinAgent impact:** none required by any controller. + +- The DR bring-up (`--selftest=bring-up -mode dr`) keeps the archive's `onboot: 1`, binds the host's REAL drives + (`mp8 /mnt/felhom-drives`) and STARTS the guest — right on a replaced host, wrong beside a live original (a second + controller for the same household on the same drives). It now REFUSES, before any restore, when the archive's + source guest still exists on the host, when any guest binds the drives parent, or when a guest's config cannot be + read (fail closed). On a replaced host it proceeds and keeps its binds, unchanged. +- The restore-test was MEASURED safe live on demo-hp (onboot 0 and throwaway stand-ins for mp8/mp9 from the first + config read to teardown); a test now pins its "no host path" half beside the existing onboot test. +- No sudoers change: the restore-test sets onboot 0 through the API create call, and DR refuses rather than degrade, + so no `-onboot 0` line is needed. +- Tests: `TestRunBringUp_DRRefusesBesideALiveOriginal` (source guest present / drives bind on another guest / an + unreadable config refuse; a replaced host proceeds and keeps the drives bind), `TestRunBringUp_ProvisionNotBlockedByADrivesBind`, + `TestArchiveSourceVMID`, `TestRestoreTest_NoHostPathBindBesideTheOriginal`. Red-proofs: the DR check returning "" + → three refusal cases restore and START; the restore-test's mp8 override set to the host path → fails. + ## v0.138.0 — the restore test takes only THIS box's archives (2026-09-30, R-727, `09` §3 decision 51) > **RELEASED 2026-09-30** by `scripts/release-agent.sh` — tag `v0.138.0` (`e1b8269`), sha256 diff --git a/REPORT.md b/REPORT.md index 7afb100..10c3c3c 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,12 +1,10 @@ -# REPORT — 2026-09-30: v0.138.0 (R-727) +# REPORT — 2026-10-04: v0.139.0 (R-834) -Full session report: `felhom.eu/REPORT-fixes-first-tester-2026-09-30.md`. +Full session report: `felhom.eu/REPORT-backup-close-os-spike-2026-10-04.md`. -- **Measured:** a PBS archive carries its key FINGERPRINT (PVE content `encrypted`), not a host id; the storage - carries its own (`GET /storage` → `encryption-key`). The restore test now skips an archive written with another - key and logs it by name; an unencrypted storage is not filtered; a failed storage read is UNKNOWN. -- Tests `TestR727_*`; red-proof RP39 (the skip removed → the 2026-09-16 archive of an earlier box is picked). -- Released by `release-agent.sh` (tag `v0.138.0`, sha256 `55916026…8195`, verified by download); **not vouched**. - Delivered by signed `agent_update` jobs to `demo-hp-bb76ea` and `demo-felhom-8363b5` (both committed within 340 s); - `-selftest=restore-test-due` on both reads each tier normally on 0.138.0. -- ep0 (decision 51): the three drill archives in `tester-1`'s namespace removed; other namespaces byte-identical. +- **Measured** on demo-hp: the scheduled restore-test's scratch guest has `onboot: 0` and throwaway stand-ins for + mp8/mp9 on every config read until teardown — it was already safe. Evidence `felhom.eu/documentation/audits/backup-close-2026-10-04/partA/`. +- **Fixed:** the DR bring-up refuses beside a live original (source guest present, a drives bind on another guest, + or an unreadable config). On a replaced host it is unchanged. +- Tests `TestRunBringUp_DRRefusesBesideALiveOriginal`, `TestRestoreTest_NoHostPathBindBesideTheOriginal` and two + more; both rules red-proved. No sudoers change (said why in the CHANGELOG).