v0.243.0: FileBrowser generated admin password (R-513); per-tier whole-guest backup truth (R-517); skip absent-storage tiers (R-518); OOM-killed worker visible (R-514)
gates / gates (push) Successful in 14s

MinAgent: 0.131.0

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-15 10:12:08 +02:00
parent 406755fa8f
commit 843b319f35
23 changed files with 1095 additions and 8 deletions
+43
View File
@@ -1,3 +1,46 @@
## v0.243.0 — the file manager gets a real password, the backup page tells the truth per tier, an absent tier stops no app, an OOM-killed worker is seen (2026-09-15, R-513 / R-517 / R-518 / R-514)
**MinAgent: 0.131.0** (the per-tier backup status and tier storage presence are agent v0.131.0; the controller supervisor rides the same release)
- **R-513 (P1, SECURITY) — FileBrowser no longer accepts `admin` / `admin`.** Measured first
(2026-09-15, `gtstef/filebrowser:1.3.3-stable`, `felhom.eu/documentation/audits/evidence-p1fixes-2026-09-15/B1`):
the config key `auth.adminPassword` / env `FILEBROWSER_ADMIN_PASSWORD` sets the password on a fresh
and an existing database — but RE-APPLIES IT ON EVERY START, overwriting a password set by hand; the
API (`PUT /api/users?id=<id>` with `X-Password: <current>`) changes it once and it sticks. So ONE
mechanism for fresh and existing boxes, the API: every base-stack tick until decided,
`Manager.EnsureFileBrowserAdminPassword` logs in as admin/admin against `http://filebrowser:80`;
**200** → generates `password:16`, sets it, verifies new=200 AND admin=401, stores it AES-encrypted in
settings (`filebrowser_admin_state: generated`); **401** → records `operator` and never touches it
(the HP and the N100 were changed by hand on 2026-09-15). Unreachable → nothing recorded, retried.
The FileBrowser app page shows „Kezdeti belépési adatok": user `admin` and the password behind
„Megjelenítés" (the R-254 reveal: POST, no-store, logged, never in the page), or „az üzemeltető
állította be". Cost, stated: on a brand-new box admin/admin works from FileBrowser's first start until
the next tick. Red-proofs: without the PUT, admin/admin still logs in; without the operator branch, the
page does not say who set it.
- **R-517 (P1) — „Rendszermentés" speaks per tier.** The tile read the agent's single LATEST record, so
a failed 0-byte PBS attempt on absent storage became „✗ · 0 B · PBS · Naprakész" and ticked
„Távoli rendszermentés — külön hardveren". With agent ≥ 0.131.0 the page shows, per tier, the newest
SUCCESSFUL backup (date, size — unknown when read back from storage after a restart), a failed attempt
✗ „sikertelen" UNDER it, and a tier whose storage does not exist as „nincs beállítva". „Naprakész" is
computed from successes (a set-up tier whose newest success is older than 1.5 × its cadence is
„Esedékes"); the remote tick needs a current PBS SUCCESS. An older agent renders exactly as before.
Red-proof: reading a tier's success from its last attempt loses the local backup's size.
- **R-518 (cheap half) — a tier whose storage does not exist is not attempted, and no app is stopped for
it.** `quiesce.skipAbsentTiers` drops tiers the agent reports `storage: absent` from the manual and the
scheduled run (unknown/legacy never skipped), logs every skip and pushes `backup_tier_skipped`
(warning, operator-only, once per absence). Button copy now tells the truth: „A mentés alatt az
alkalmazások leállnak — általában néhány perc, nagyobb adatnál több." Per-tier quiesce (the other half)
stays open. Red-proof: without the skip, the manual run starts felhom-pbs and the scheduled run stops an
app for it.
- **R-514 — an OOM-killed worker inside a running container is visible.** BIGNIGHT: Paperless's worker
was killed by the memory limit, the container ran on, the app read „Fut". The 30 s dead-app check reads
`State.OOMKilled` for running app containers in one `docker inspect`; the dashboard row shows „Memória
elfogyott" (with a what-to-do title) and the hub gets `app_oom` (warning, operator-only), once per
container run. **The task named the tag „memória elfogyott — újraindítva"; the controller does NOT
restart the app** (an automatic restart is an unmeasured mechanism that could cut a household's
upload), so the tag does not claim it. Red-proof: skipping the `true` lines hides the killed worker.
- Hub ≥ v0.114.0 registers `backup_tier_skipped` and `app_oom`; deploy the hub first.
## v0.242.0 — a removed app is listed with its kept backup, and five small ones (2026-09-13/14, R-487 / R-491 / R-490 / R-489 / R-476 / R-456)
**MinAgent: 0.129.0** (unchanged)