Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,24 @@
|
||||
## v0.139.0 — a DR restore never lands beside a live original (2026-10-04, R-834)
|
||||
|
||||
> **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.139.0` (`475bdce`), sha256
|
||||
> `8534a9be368a6d24d8065db77436e86900443c5c6554c71f6fe91c2bdb9d0b9c`, verified by download. **Not vouched.**
|
||||
|
||||
**MinAgent impact:** none required by any controller.
|
||||
|
||||
- The DR bring-up (`--selftest=bring-up -mode dr`) keeps the archive's `onboot: 1`, binds the host's REAL drives
|
||||
(`mp8 /mnt/felhom-drives`) and STARTS the guest — right on a replaced host, wrong beside a live original (a second
|
||||
controller for the same household on the same drives). It now REFUSES, before any restore, when the archive's
|
||||
source guest still exists on the host, when any guest binds the drives parent, or when a guest's config cannot be
|
||||
read (fail closed). On a replaced host it proceeds and keeps its binds, unchanged.
|
||||
- The restore-test was MEASURED safe live on demo-hp (onboot 0 and throwaway stand-ins for mp8/mp9 from the first
|
||||
config read to teardown); a test now pins its "no host path" half beside the existing onboot test.
|
||||
- No sudoers change: the restore-test sets onboot 0 through the API create call, and DR refuses rather than degrade,
|
||||
so no `-onboot 0` line is needed.
|
||||
- Tests: `TestRunBringUp_DRRefusesBesideALiveOriginal` (source guest present / drives bind on another guest / an
|
||||
unreadable config refuse; a replaced host proceeds and keeps the drives bind), `TestRunBringUp_ProvisionNotBlockedByADrivesBind`,
|
||||
`TestArchiveSourceVMID`, `TestRestoreTest_NoHostPathBindBesideTheOriginal`. Red-proofs: the DR check returning ""
|
||||
→ three refusal cases restore and START; the restore-test's mp8 override set to the host path → fails.
|
||||
|
||||
## v0.138.0 — the restore test takes only THIS box's archives (2026-09-30, R-727, `09` §3 decision 51)
|
||||
|
||||
> **RELEASED 2026-09-30** by `scripts/release-agent.sh` — tag `v0.138.0` (`e1b8269`), sha256
|
||||
|
||||
@@ -1,12 +1,10 @@
|
||||
# REPORT — 2026-09-30: v0.138.0 (R-727)
|
||||
# REPORT — 2026-10-04: v0.139.0 (R-834)
|
||||
|
||||
Full session report: `felhom.eu/REPORT-fixes-first-tester-2026-09-30.md`.
|
||||
Full session report: `felhom.eu/REPORT-backup-close-os-spike-2026-10-04.md`.
|
||||
|
||||
- **Measured:** a PBS archive carries its key FINGERPRINT (PVE content `encrypted`), not a host id; the storage
|
||||
carries its own (`GET /storage` → `encryption-key`). The restore test now skips an archive written with another
|
||||
key and logs it by name; an unencrypted storage is not filtered; a failed storage read is UNKNOWN.
|
||||
- Tests `TestR727_*`; red-proof RP39 (the skip removed → the 2026-09-16 archive of an earlier box is picked).
|
||||
- Released by `release-agent.sh` (tag `v0.138.0`, sha256 `55916026…8195`, verified by download); **not vouched**.
|
||||
Delivered by signed `agent_update` jobs to `demo-hp-bb76ea` and `demo-felhom-8363b5` (both committed within 340 s);
|
||||
`-selftest=restore-test-due` on both reads each tier normally on 0.138.0.
|
||||
- ep0 (decision 51): the three drill archives in `tester-1`'s namespace removed; other namespaces byte-identical.
|
||||
- **Measured** on demo-hp: the scheduled restore-test's scratch guest has `onboot: 0` and throwaway stand-ins for
|
||||
mp8/mp9 on every config read until teardown — it was already safe. Evidence `felhom.eu/documentation/audits/backup-close-2026-10-04/partA/`.
|
||||
- **Fixed:** the DR bring-up refuses beside a live original (source guest present, a drives bind on another guest,
|
||||
or an unreadable config). On a replaced host it is unchanged.
|
||||
- Tests `TestRunBringUp_DRRefusesBesideALiveOriginal`, `TestRestoreTest_NoHostPathBindBesideTheOriginal` and two
|
||||
more; both rules red-proved. No sudoers change (said why in the CHANGELOG).
|
||||
|
||||
Reference in New Issue
Block a user