PHASE 3 RESULT — the failure path (docmost, Postgres)

CORRUPTION METHOD: the prepared scratch's db-dumps/docmost-postgres.sql was TRUNCATED from
141 364 B to 62 000 B, landing mid-statement at "COPY public.felhom_r356b_discriminator ".
sha256 30e84d2c0d0bcf3e7043459a0d135e96cdb65947f4138f181837b1ee35d2e087.
Scratch only. Store and live unit untouched.

DOES THE CUSTOMER SEE A FAILURE?  YES.
  Rendered in an `alert alert-error` block under the heading "Eredmény", beginning
  "A teljes visszaállítás sikertelen:". Not a warning beside a success.

DOES THE MESSAGE NAME THE UNDO COPY?  YES.
  "... — a korábbi állapot mentése megvan: pre-restore-20260822T140924Z-docmost-postgres.sql"

IS THE APP RUNNING AFTERWARDS?  NO — it crash-loops.
  `docmost | Restarting (1)`; docmost-postgres and docmost-redis stay healthy. Login through
  traefik returns 404 because there is no healthy backend.
  This is recorded as HONEST rather than as a defect: the app is visibly broken, not falsely
  green. An earlier reading in this session said "reports healthy" — that was wrong, taken from
  a "health: starting" line during the restart, and is corrected here.

WHAT STATE IS THE DATA IN?  EMPTY, and that is inherent to the mechanism.
  The truncated dump ran its DROP/CREATE sequence and died partway through the data:
    tables in public schema : 43   (schema intact)
    pages                   :  0   (was 4)
    users                   :  0   (was 1 — the workspace owner)
    spaces                  :  0
    felhom_r356b_discriminator: 0  (was 1)

IS THE UNDO COPY VALID AND SUFFICIENT?  YES — proven by using it.
  141 363 B, proper pg_dump header, 43 COPY blocks.
  Its pages block holds 4 rows, its users block 1 row, and it contains the accented title.
  Applied BY HAND (docker cp + psql -v ON_ERROR_STOP=1): pages 4, users 1,
  discriminator ALTERED-VALUE-B — exactly the pre-restore state.

THE GAP — and it is the finding of this phase:
  NOTHING IN THE PRODUCT CAN APPLY THAT UNDO COPY.
  - The filename appears ONLY inside the error text. There is no button, no list entry, no route.
  - `preRestoreDumpPrefix` ("pre-restore-") is explicitly SKIPPED at three places so these files
    are never offered as a restore source:
        internal/backup/restore_unit.go:125
        internal/backup/offbox_reconstitute.go:489
        internal/backup/offbox_reconstitute.go:539
  - So a customer whose off-site dump is corrupt is left with a crash-looping app, an emptied
    database, and a filename they cannot act on. The data is recoverable — by us, by hand.

SECOND FINDING — the message leaks raw engine internals at a Hungarian customer.
  407 bytes, of which the middle ~250 are untranslated English psql output including a caret
  diagram and "exit status 3":
    "importing postgres dump for docmost: postgres import into docmost-postgres failed:
     ERROR:  syntax error at end of input
     LINE 1: COPY public.felhom_r356b_discriminator
                                                   ^ — exit status 3"
