# REPORT — 2026-09-28 evening: v0.279.0 Architecture: `09` §3 decision 45 (new), `07` §6 (Part D), `01` §5. Brief: "no app goes live with a login a stranger knows…". | change | test (red-proof) | live | |---|---|---| | `after_install:` — one command after a FRESH install, generated values filled in, `success:` marker required, recorded in app.yaml; the deploy-done hook now set on every box | `TestAfterInstall_ReplacesTheDefaultLoginOnceAndRecordsIt` (RP13 marker, RP14 empty value), `TestAfterInstall_IsWiredToEveryFreshInstall` | 9202: claper and bookstack — default fails, generated works, wrong fails; claper after a restore keeps it | | the page's default-login rule (`defaultLoginInEffect`, `app_info.known_login`) | `TestKnownLogin_InEffectOnlyUntilReplaced` (RP15) | demo-hp: bookstack, calibre-web, romm pages warn; docmost (no default) does not; claper page hides the card after the fix | | Part D — running app, copy with no data → digest once/app/tier/day + backup-page sentence | `TestPartD_ARunningAppWithAnEmptyCopyIsAnAlarm` (RP11), `TestPartD_TheBackupPageSaysARunningAppHasNoData` (RP12) | 9202: no false alarm over a full chain | | R-705 — `POST /api/debug/backup/night-chain`; `RunUpdateLegNow` | `TestR705_NightChainRunsTheLegsInOrderAndRefusesWhenBusy` (RP8, RP9), `TestR705_TheManualLegRunsByDay` (RP10) | 9202: 44 s, second press 409, leg deadline 22:00 | | R-706 — removal with backups deletes the verification copy | `TestR706_RemovalWithBackupsDeletesTheVerificationCopy` (RP7) | not seen live | Red-proofs: `felhom.eu/documentation/audits/logins-nvme-2026-09-28/redproofs/` — RP13 first failed to COMPILE (not a proof); rewritten, and the test gained the exit-0-without-marker case, which is claper's real failure shape. Suite green; `controller_gates.py` green (go-parity keys listed, the debug button added, the debug page fixture regenerated — diff = the two button lines). Floor 0.279.0 (MinAgent 0.131.0), both demo boxes healthy.