docs: §13.2 wizard leg COMPLETE (offered/enrolled/formatted via operator UI + GO; pipeline-level teardown, boxes as found) + Day-0 manifest vouched 0.87.0; cross-ref the two controller bugs the leg surfaced (0.126.3/0.126.4)

This commit is contained in:
2026-07-13 14:15:02 +02:00
parent 4e6171442f
commit adf7882f7d
2 changed files with 21 additions and 8 deletions
+17 -6
View File
@@ -80,13 +80,24 @@ Full suite: `go test ./...` green (all packages; recovery-code flake did not fir
(creds from the 180 docker-config, out-of-band). felhom.eu disposition note:
`documentation/audits/DISPOSITION-ia-finding2-systemdisks-2026-07-13.md` (commit `74fa61c`).
## STOPPED for Viktor (per the task's STOP)
## §13.2 wizard live leg — COMPLETE (operator session + GO; finished same day)
1. **13.2 wizard live leg** — hot-add the 5 GB scsi scratch disk to the drill PVE VM (qm 300 on
felhom-pve), then through YOUR logged-in dashboard session (no gate-lift): wizard OFFERS the
disk → enroll + format (GO required before format) → unenroll/detach, leave as found.
2. **Day-0 manifest bump** to agent 0.87.0 (hub operator UI, password-gated) + the IA audit doc
finding-2 disposition line (felhom.eu).
- Wizard **OFFERED** the hot-added 5 GB disk (Üres — formázható) on the legacy-boot drill box —
the exact pre-fix dead end. Operator enrolled + formatted through the REAL UI flow
(mount name enroll-test, ext4, default): "A meghajtó sikeresen inicializálva és regisztrálva:
/mnt/felhom-drives/enroll-test"; storage page showed the drive Active/Default, role
Felhasználói adat, uuid durable-id. (First attempt hit the controller-side CSRF bug on
claimed-box wizard pages → fixed as controller v0.126.3, unrelated to the agent.)
- **Teardown (leave as found):** decommission attempted through the UI → correctly REFUSED by
the controller's M1 guard (last usable drive; the refusal surfaced badly → controller
v0.126.4 fixed the 502-through-Cloudflare + native-alert classes). Teardown completed at
pipeline level: agent `/disks/decommission` (guest token) → ok (logical retire per design;
the raw mount/unit intentionally stays for re-enroll — removed manually as the "physical
removal" step), controller registry entry removed (0 storage paths — the pre-enroll state),
mount unit stopped + file removed, `qm disk unlink 300 --idlist scsi1 --force` (LV
vm-300-disk-1 destroyed). Verified: /proc/mounts clean, candidates empty, drill gate back ON.
- **Day-0 manifest**: vouched by the operator — agent **0.87.0**, sha `2447d4a3…dc7a`
(hub Configuration screenshot; golden 0.120.0 + MinAgent 0.81.0 unchanged).
## Observations