v0.279.0: after_install (decision 45), known default logins on the page, Part D empty-backup alarm, night chain (R-705), R-706
gates / gates (push) Successful in 27s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-28 18:38:30 +02:00
parent 2e9a948cbd
commit 0c702f834a
35 changed files with 1119 additions and 16 deletions
+27
View File
@@ -1,3 +1,30 @@
## v0.279.0 — no app goes live with a login a stranger knows (after_install); an empty backup of a running app is an alarm; the night's chain on a button; R-706 (2026-09-28)
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged; Part D rides the existing operator-only
`backup_run_failures` digest). New strings: `app_info.known_login`, `backups_apps.hollow_local`,
`backups_apps.hollow_offsite`, `debug.night_chain` (hu + en). Evidence: `felhom.eu/documentation/audits/logins-nvme-2026-09-28/`.
- **`after_install:` (`09` §3 decision 45).** A template may declare ONE command the box runs once in the app's own
container after a FRESH install (the deploy-done hook, ok=true) — to replace a known default login with a generated
`type: password` field, shown on the app page as the first password. `env:` names the deploy values filled into
`${NAME}` (an undeclared or empty one refuses — never an empty password); `success:` is a marker the output must
carry (claper's CLI exits 0 on an error). Retried while the app boots (6 × 20 s), recorded in `app.yaml`
(`after_install: {at, ok, detail}`), never logged expanded. Never on a restore or a kept-data load (R-694). The
deploy-done hook is now set on EVERY box (it was inside `if notifier != nil`, so a box with no hub would never run it).
- **The page says when a default login is in effect** (`defaultLoginInEffect`): the install dialog before the install
when nothing will replace it, the app page while it is in effect ("This app starts with a known, shared password: %s.
Change it right after the install."); the default-login card is HIDDEN once after_install replaced it.
- **Part D — a running app whose newest copy holds no data is an alarm.** At the end of the dump leg (the local unit)
and in the off-site loop (the pushed unit): an installed app that RUNS and has volumes, whose copy lists no dump and no
tar → the operator digest once per app per tier per day, and a sentence on the backup page until a later check finds
data. A held app that is stopped is not flagged. Measured before: yesterday's demo-hp nextcloud had a WARN line only.
- **R-705 (controller half):** debug action `POST /api/debug/backup/night-chain` — dump → Tier 2 → off-site → update leg,
one at a time, refused while a backup/restore op, a guarded update or another chain runs. The update leg gets its
normal length from its own start (`RunUpdateLegNow`; by day the night's W+5h has passed).
- **R-706:** a removal "with its backups" also deletes the app's off-site verification copy.
- Tests: `TestAfterInstall_*` (stacks + main.go wiring), `TestKnownLogin_*`, `TestPartD_*` (backup + page),
`TestR705_*` (web + stacks), `TestR706_*`. Red-proofs RP7–RP15, each seen failing on an assertion.
## v0.278.0 — a hold left by an earlier install no longer holds the new one (R-704) (2026-09-28)
**MinAgent: 0.131.0** (unchanged). Needs hub v0.123.0 (unchanged). New strings: none. Evidence: