# felhom.eu burndown2 red-proofs, 2026-10-05 (fix undone -> test fails; fix restored -> test passes)

### R-277 (offsite row bytes)
$ (cd . && go test ./internal/web -run 'TestOffsiteRow_SmallRepoNotZeroGB' -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestOffsiteRow_SmallRepoNotZeroGB
    r277_r92_bytes_test.go:27: 162 KB repo rendered as "0.0 GB", want "162.0 KB"
--- FAIL: TestOffsiteRow_SmallRepoNotZeroGB (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.062s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestOffsiteRow_SmallRepoNotZeroGB
--- PASS: TestOffsiteRow_SmallRepoNotZeroGB (0.04s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.064s

### R-92 (PBS DR exact bytes)
$ (cd . && go test ./internal/web -run 'TestPBSDRPanel_ExactBytesShowsSmallDelta' -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestPBSDRPanel_ExactBytesShowsSmallDelta
    r277_r92_bytes_test.go:55: PBS DR panel must show exact bytes:
        PBS DR datastore</h3>
                    
                    <table class="detail-table">
                        <tr><th style="width: 12rem;">Datastore</th><td><code>felhom-offsite</code> (ep0)</td></tr>
                        <tr><th>Capacity</th><td>40.0 GB</td></tr>
                        <tr><th>Used</th><td>8.0 GB &middot; 20% full</td></tr>
                    </table>
                    <div class="bar" style="margin: 0.4rem 0 0.9rem;"><div class="bar-fill bar-ok" style="width: 20%;"></div></div>
                    <table class="detail-table">
                        <tr><th style="width: 12rem;">Polled</th><td>just now</td></tr>
                    </table>
                    
                </section>
        
                <p class="text-muted" style="margin: 0 0 1rem; font-size: 0.85em;">
                    The endpoint below IS the PBS DR host. Peer allocation and endpoint sync currently use the
                    lowest endpoint id (ep0); per-endpoint allocation is a future work item.
                </p>
        
                
                <section class="card" style="margin-bottom: 1.5rem;">
                    <h3>Endpoint</h3>
                    <p class="text-muted">Not configured. Add one below (or via <code>PUT /api/v1/admin/wg/endpoint</code>, runbook: offsite-endpoint.md).</p>
                </section>
                
        
                
                <section class="card" style="margin-bottom: 1.5rem;">
                    <h3 id="ep-form-title">Add endpoint</h3>
                    <form method="POST" action="/offsite/endpoints" id="ep-form" onsubmit="return epFormSubmitCheck()"
                          style="display: grid; grid-template-columns: auto 1fr; gap: 0.5rem; align-items: center; max-width: 44em; margin-top: 0.75rem;">
                        <input type="hidden" name="_csrf" value="">
                        <label style="font-size: 0.9em;">Endpoint id</label>
                        <input type="text" name="endpoint_id" id="ep-id" placeholder="ep1" style="padding: 0.3em 0.5em;">
                        <label style="font-size: 0.9em;">DNS name</label>
                        <input type="text" name="dns_name" id="ep-dns" placeholder="ep1.felhom.eu" style="padding: 0.3em 0.5em;">
                        <label style="font-size: 0.9em;">WG port</label>
                        <input type="number" name="wg_port" id="ep-port" min="1" max="65535" placeholder="443" style="padding: 0.3em 0.5em;">
--- fix RESTORED (rc=0):
=== RUN   TestPBSDRPanel_ExactBytesShowsSmallDelta
--- PASS: TestPBSDRPanel_ExactBytesShowsSmallDelta (0.07s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.093s


### R-581 (newest report tie-break)
$ (cd . && go test ./internal/store -run TestGetCustomers_SameSecondReportsOneRowNewestWins -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestGetCustomers_SameSecondReportsOneRowNewestWins
    r581_newest_report_test.go:32: GetCustomers returned 2 rows for one customer, want exactly 1
--- FAIL: TestGetCustomers_SameSecondReportsOneRowNewestWins (0.03s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/store	0.040s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestGetCustomers_SameSecondReportsOneRowNewestWins
--- PASS: TestGetCustomers_SameSecondReportsOneRowNewestWins (0.03s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/store	0.040s

### R-600 (delete cascade WG peer push + honest COMPLETE line)
$ (cd . && go test ./internal/web -run 'TestDeleteCascade_TriggersWGPeerPushAndSaysSo' -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestDeleteCascade_TriggersWGPeerPushAndSaysSo
    customer_delete_test.go:642: WG peer-sync triggers = 0, want exactly 1 (the endpoint must drop the peer now, not on the next tick)
--- FAIL: TestDeleteCascade_TriggersWGPeerPushAndSaysSo (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.070s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestDeleteCascade_TriggersWGPeerPushAndSaysSo
--- PASS: TestDeleteCascade_TriggersWGPeerPushAndSaysSo (0.05s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.072s

### R-600 (main wiring of SetWGPeerSync)
$ (cd . && go test ./cmd/hub -run TestR600_MainWiresWGPeerSyncIntoWeb -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestR600_MainWiresWGPeerSyncIntoWeb
    r600_wiring_test.go:32: cmd/hub/main.go never calls webServer.SetWGPeerSync(<reconciler>.Trigger) — the delete cascade cannot push the peer removal
--- FAIL: TestR600_MainWiresWGPeerSyncIntoWeb (0.00s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/cmd/hub	0.024s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestR600_MainWiresWGPeerSyncIntoWeb
--- PASS: TestR600_MainWiresWGPeerSyncIntoWeb (0.00s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/cmd/hub	0.025s

### R-599 (ONLINE 409 says when deletion opens; host + cascade)
$ (cd . && go test ./internal/web -run TestHostDelete_OnlineRefusalSaysWhenItOpens -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestHostDelete_OnlineRefusalSaysWhenItOpens
    r544_r599_host_delete_test.go:74: host-delete 409 body missing "min ago":
        Host is ONLINE — deletion is refused (a live agent would receive 401s permanently).
    r544_r599_host_delete_test.go:74: host-delete 409 body missing "deletion opens at 17:42 UTC":
        Host is ONLINE — deletion is refused (a live agent would receive 401s permanently).
    r544_r599_host_delete_test.go:74: host-delete 409 body missing "45m0s":
        Host is ONLINE — deletion is refused (a live agent would receive 401s permanently).
    r544_r599_host_delete_test.go:84: cascade ONLINE refusal = 409 "Delete refused: host gone-vm is ONLINE. Decommission the box first — the cascade never deletes a live host.\n", want 409 naming the opening time
--- FAIL: TestHostDelete_OnlineRefusalSaysWhenItOpens (0.05s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.066s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestHostDelete_OnlineRefusalSaysWhenItOpens
--- PASS: TestHostDelete_OnlineRefusalSaysWhenItOpens (0.04s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.065s

### R-544 (host-delete log states demotion)
$ (cd . && go test ./internal/web -run TestHostDelete_LogSaysEscrowDemotedNotDeleted -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestHostDelete_LogSaysEscrowDemotedNotDeleted
    r544_r599_host_delete_test.go:32: log still says the escrow was deleted:
        [INFO] host deleted: esc-host (escrow deleted: true)
    r544_r599_host_delete_test.go:35: log must state the demotion:
        [INFO] host deleted: esc-host (escrow deleted: true)
--- FAIL: TestHostDelete_LogSaysEscrowDemotedNotDeleted (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.064s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestHostDelete_LogSaysEscrowDemotedNotDeleted
--- PASS: TestHostDelete_LogSaysEscrowDemotedNotDeleted (0.04s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.063s

### R-855 (start log prints effective Docker nights)
$ (cd . && go test ./cmd/hub ./internal/osupdates -run 'TestR855_StartLogPrintsEffectiveDockerNights|TestDockerNightsEffective' -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestR855_StartLogPrintsEffectiveDockerNights
    r855_docker_nights_log_test.go:41: the Docker approval-nights start log must print osSvc.DockerNightsEffective(), not the raw field
--- FAIL: TestR855_StartLogPrintsEffectiveDockerNights (0.00s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/cmd/hub	0.022s
=== RUN   TestDockerNightsEffective
--- PASS: TestDockerNightsEffective (0.00s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/osupdates	0.005s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestR855_StartLogPrintsEffectiveDockerNights
--- PASS: TestR855_StartLogPrintsEffectiveDockerNights (0.00s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/cmd/hub	0.022s
=== RUN   TestDockerNightsEffective
--- PASS: TestDockerNightsEffective (0.00s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/osupdates	0.006s

### R-134 (zone candidates strip progressively; red = the old one-label parentDomain)
$ (cd . && go test ./internal/cloudflare -run TestZoneCandidates -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestZoneCandidates
    unblock_test.go:24: zoneCandidates("a.b.felhom.eu") = [a.b.felhom.eu b.felhom.eu], want [a.b.felhom.eu b.felhom.eu felhom.eu]
    unblock_test.go:24: zoneCandidates("x.y.z.example.co") = [x.y.z.example.co y.z.example.co], want [x.y.z.example.co y.z.example.co z.example.co example.co]
--- FAIL: TestZoneCandidates (0.00s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/cloudflare	0.006s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestZoneCandidates
--- PASS: TestZoneCandidates (0.00s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/cloudflare	0.006s


### R-292 (artifact sha flash names the cause; red = every failure -> artifact_sha_invalid, the old single flash)
$ (cd . && go test ./internal/web -run 'TestArtifactSave_FlashNamesTheCause' -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestArtifactSave_FlashNamesTheCause
=== RUN   TestArtifactSave_FlashNamesTheCause/version_not_found
    r292_artifact_flash_test.go:57: flash = "artifact_sha_invalid", want "artifact_version_missing"
=== RUN   TestArtifactSave_FlashNamesTheCause/registry_failing
    r292_artifact_flash_test.go:57: flash = "artifact_sha_invalid", want "artifact_unverifiable"
=== RUN   TestArtifactSave_FlashNamesTheCause/no_sha_listed
    r292_artifact_flash_test.go:57: flash = "artifact_sha_invalid", want "artifact_sha_missing"
=== RUN   TestArtifactSave_FlashNamesTheCause/healthy
--- FAIL: TestArtifactSave_FlashNamesTheCause (0.24s)
    --- FAIL: TestArtifactSave_FlashNamesTheCause/version_not_found (0.06s)
    --- FAIL: TestArtifactSave_FlashNamesTheCause/registry_failing (0.07s)
    --- FAIL: TestArtifactSave_FlashNamesTheCause/no_sha_listed (0.07s)
    --- PASS: TestArtifactSave_FlashNamesTheCause/healthy (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.264s
--- fix RESTORED (rc=0):
=== RUN   TestArtifactSave_FlashNamesTheCause
=== RUN   TestArtifactSave_FlashNamesTheCause/version_not_found
=== RUN   TestArtifactSave_FlashNamesTheCause/registry_failing
=== RUN   TestArtifactSave_FlashNamesTheCause/no_sha_listed
=== RUN   TestArtifactSave_FlashNamesTheCause/healthy
--- PASS: TestArtifactSave_FlashNamesTheCause (0.17s)
    --- PASS: TestArtifactSave_FlashNamesTheCause/version_not_found (0.04s)
    --- PASS: TestArtifactSave_FlashNamesTheCause/registry_failing (0.04s)
    --- PASS: TestArtifactSave_FlashNamesTheCause/no_sha_listed (0.04s)
    --- PASS: TestArtifactSave_FlashNamesTheCause/healthy (0.04s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.188s

### R-725 (expired bind page points at the button)
$ (cd . && go test ./internal/web -run TestBindExpiredPage_PointsAtTheButton -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestBindExpiredPage_PointsAtTheButton
    r725_bind_expired_copy_test.go:28: the expired page with a button does not carry the sentence that points at it
    r725_bind_expired_copy_test.go:31: the expired page with a button still sends the household to support
--- FAIL: TestBindExpiredPage_PointsAtTheButton (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.065s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestBindExpiredPage_PointsAtTheButton
--- PASS: TestBindExpiredPage_PointsAtTheButton (0.04s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.057s

### R-725 (console banner glyph; red = the check mark restored in script + golden)
$ (cd . && python3 scripts/iso/test/test_console_glyphs.py)
--- fix UNDONE (rc=1):
FAIL: console glyphs the Latin-2 font cannot draw (R-725):
--- fix RESTORED (rc=0):
OK: 58 printf literals + 3 goldens use only console-safe glyphs

### R-728 (in-flight create guard; red = guard removed, seam kept)
$ (cd . && go test ./internal/web -run TestConfigCreate_ConcurrentSubmitCreatesOnce -v -count=1)
--- fix UNDONE (rc=1):
=== RUN   TestConfigCreate_ConcurrentSubmitCreatesOnce
    r728_create_once_test.go:57: customer created 2 times for one press, want exactly 1:
        [INFO] Customer config created: tester-2
        [INFO] self-bind link NOT auto-minted for tester-2 on customer creation: no mailer configured on this hub
        [INFO] Customer config created: tester-2
        [INFO] self-bind link NOT auto-minted for tester-2 on customer creation: no mailer configured on this hub
--- FAIL: TestConfigCreate_ConcurrentSubmitCreatesOnce (0.04s)
FAIL
FAIL	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.064s
FAIL
--- fix RESTORED (rc=0):
=== RUN   TestConfigCreate_ConcurrentSubmitCreatesOnce
--- PASS: TestConfigCreate_ConcurrentSubmitCreatesOnce (0.05s)
PASS
ok  	gitea.dooplex.hu/admin/felhom-hub/internal/web	0.065s

### R-208 hub half (Dockerfile ARG order; red = ARGs back above go mod download)
$ (cd . && python3 scripts/test_dockerfile_arg_order.py)
--- fix UNDONE (rc=1):
FAIL: hub/Dockerfile (R-208):
--- fix RESTORED (rc=0):
OK: hub/Dockerfile declares its per-build ARGs below the module download


### R-819 (check_stands accepts CLOSED rows; red = rule 3 reads OPEN-ITEMS.md only)
$ (cd . && python3 scripts/check_stands.py)
--- fix UNDONE (rc=1):
CONVICTED — 34 problem(s):
--- fix RESTORED (rc=0):
check_stands: OK — every claim cites a source, every citation resolves, and every 'walked' cites a walk.

### R-819 decoy suite (the genuine closed-row stand must pass; red = OPEN-only rule 3)
$ (cd . && python3 scripts/test_gate_decoys.py)
--- fix UNDONE (rc=1):
  ok  hub-confirm/subdir   decoy rejected
  ok  manifest-bearer/subdir decoy rejected
  ok  observations/R-419   decoy rejected
  ok  observations/genuine-FILED genuine accepted
  ok  observations/genuine-NAF genuine accepted
  ok  reuse-refs/missing-go decoy rejected
  ok  reuse-refs/missing-md (KNOWN HOLE R-422) genuine accepted
  ok  golden-currency      empty dir rejected AND named
  ok  closed-register/body-word (BY DESIGN) genuine accepted
  ok  closed-register/verdict-word decoy rejected
  ok  closed-register/unreadable-row decoy rejected
  ok  closed-register/duplicate-closed-id decoy rejected
  ok  closed-register/finished-row-in-open decoy rejected
  ok  closed-register/open-row-closed-word (BY DESIGN) genuine accepted
  ok  one-register/suffix-id-row decoy rejected
--- fix RESTORED (rc=0):
  ok  hub-confirm/subdir   decoy rejected
  ok  manifest-bearer/subdir decoy rejected
  ok  observations/R-419   decoy rejected
  ok  observations/genuine-FILED genuine accepted
  ok  observations/genuine-NAF genuine accepted
  ok  reuse-refs/missing-go decoy rejected
  ok  reuse-refs/missing-md (KNOWN HOLE R-422) genuine accepted
  ok  golden-currency      empty dir rejected AND named
  ok  closed-register/body-word (BY DESIGN) genuine accepted
  ok  closed-register/verdict-word decoy rejected
  ok  closed-register/unreadable-row decoy rejected
  ok  closed-register/duplicate-closed-id decoy rejected
  ok  closed-register/finished-row-in-open decoy rejected
  ok  closed-register/open-row-closed-word (BY DESIGN) genuine accepted
  ok  one-register/suffix-id-row decoy rejected

### R-857 (golden gate reads the re-bake; red = the old regex + version-only sort)
$ (cd . && python3 scripts/test_golden_currency_gate.py)
--- fix UNDONE (rc=1):
CASE 17 ok (R-857): a later-dated bake of the same version wins
FAIL: CASE 16 (R-857): two bakes of one version — the gate did not report the RE-BAKE's sha
golden currency gate OK — the newest released controller has a golden (NOTE: this checks the BAKE, not the vouch — see the module docstring)
--- fix RESTORED (rc=0):
CASE 16 ok (R-857): of two bakes of one version, the re-bake's sha is the one reported
CASE 17 ok (R-857): a later-dated bake of the same version wins
golden-currency gate self-test OK — a directory name alone cannot satisfy it (R-410), and the waiver is judged on its dates, its row and its direction (2026-09-13)


### R-555 (wire-contract strips comments; red = whole-file tokenising as before)
$ (cd . && python3 scripts/test_gate_decoys.py > /tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/ea20e5ca-a93a-4939-bd73-dd472bcf0590/scratchpad/d.out 2>&1; rc=$?; grep -E 'FAIL: wire|ok  wire|behaved|exposed a hole' /tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/ea20e5ca-a93a-4939-bd73-dd472bcf0590/scratchpad/d.out; exit $rc)
--- fix UNDONE (rc=1):
  ok  wire-contract/genuine genuine accepted
FAIL: wire-contract/comment: rc=0, want 10 (10 = the comment-only tag convicted, 0 = passed)
--- fix RESTORED (rc=0):
  ok  wire-contract/comment decoy rejected
  ok  wire-contract/genuine genuine accepted


### R-364 (hu_grep refuses an untested zero; red = the anchor check disabled; no bytecode cache)
$ (cd . && PYTHONDONTWRITEBYTECODE=1 python3 -B scripts/test_hu_grep.py)
--- fix UNDONE (rc=1):
ok  present accented string counted    rc=0 1 line(s)
ok  octal-escaped pattern REFUSED      rc=2 REFUSED: the pattern arrived TRANSFORMED ('k\\303\\251rj') — octal esc
ok  U+FFFD pattern REFUSED             rc=2 REFUSED: the pattern arrived TRANSFORMED ('k�rj') — octal escapes or U
ok  no anchor given REFUSED            rc=2 REFUSED: an accented pattern needs --anchor with ASCII text known to b
ok  NFD file, NFC pattern REFUSED      rc=2 REFUSED: 0 for the pattern as typed, but 1 line(s) hold its NFD form —
ok  tested zero is a zero              rc=1 0 line(s) — a TESTED zero: anchor 'Felhom' found on 1 line(s), negativ
ok  ascii pattern plain zero           rc=1 0 line(s)
FAIL:
  blind instrument REFUSED: rc=1 msg="0 line(s) — a TESTED zero: anchor 'NotInTheFile' found on 0 line(s), negative control 0, other normal form 0", want rc=2 containing 'anchor'
--- fix RESTORED (rc=0):
ok  present accented string counted    rc=0 1 line(s)
ok  octal-escaped pattern REFUSED      rc=2 REFUSED: the pattern arrived TRANSFORMED ('k\\303\\251rj') — octal esc
ok  U+FFFD pattern REFUSED             rc=2 REFUSED: the pattern arrived TRANSFORMED ('k�rj') — octal escapes or U
ok  blind instrument REFUSED           rc=2 REFUSED: the anchor 'NotInTheFile' was not found either — the instrume
ok  no anchor given REFUSED            rc=2 REFUSED: an accented pattern needs --anchor with ASCII text known to b
ok  NFD file, NFC pattern REFUSED      rc=2 REFUSED: 0 for the pattern as typed, but 1 line(s) hold its NFD form —
ok  tested zero is a zero              rc=1 0 line(s) — a TESTED zero: anchor 'Felhom' found on 1 line(s), negativ
ok  ascii pattern plain zero           rc=1 0 line(s)
hu_grep: OK — no untested zero for an accented pattern

### R-587 (release build refuses a stray *.rootpw.txt; red = the guard body emptied; run under BusyBox PATH too)
$ (cd . && PATH=/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/ea20e5ca-a93a-4939-bd73-dd472bcf0590/scratchpad/bb python3 scripts/iso/test/test_rootpw_guard.py)
--- fix UNDONE (rc=1):
FAIL (R-587):
--- fix RESTORED (rc=0):
OK: a release build refuses a *.rootpw.txt in its out dir; a clean dir and a non-release build proceed
