diff --git a/REPORT-i18n-closing.md b/REPORT-i18n-closing.md index 487c07e0..616402ea 100644 --- a/REPORT-i18n-closing.md +++ b/REPORT-i18n-closing.md @@ -59,7 +59,7 @@ after the fix), with seven decoys; `05-hub-architecture.md` §15.6; `10-localisa 4. The engine reverted to `RandomPassphrase(3)` → the wiring test convicted on the word count **and** on the non-ASCII code. **Live, on real systems:** -- Claim page, guest 9201, through the **`felhom_lang` cookie** — `en`: "Invalid form — reload the page.", "Too many attempts — try again in 15 minutes."; `hu`: the byte-identical Hungarian. +- Claim page, guest 9201, through the **`felhom_lang` cookie** — `en`: **"Wrong or expired code"** (the drill's own screen), "Invalid form — reload the page.", "Too many attempts — try again in 15 minutes."; `hu`: the byte-identical Hungarian for each. - The **lockout proved itself unasked**: Hungarian attempts locked out the English request from the same source, demonstrating live that the counter is per source, not per language. - Backups page: `Local storage (felhom-backup)` / `Backup server – separate hardware (PBS)` against the Hungarian. - **The setup mail, one day apart in the same inbox**: 2026-09-20 `képző-szkítia-ásatás` → 2026-09-21 four plain-ASCII English words. @@ -76,7 +76,7 @@ after the fix), with seven decoys; `05-hub-architecture.md` §15.6; `10-localisa setting to stage a test, and rewriting its password hash (this repo records a session that did exactly that and lost the original bytes), buys little: the acceptance path is untouched by this release and is pinned by `TestClaimAcceptsAnEnglishWordCode`. The refusals — which is what R-596 - was about — were walked live in both languages. + was about — were walked live in both languages, including the wrong-code answer that stopped the drill. - **The two Backup-page warnings were not walked live.** Guest 9201 is healthy and a healthy box renders none, by design. Producing either state means un-assigning a live backup target. They are covered by render tests through the real handler. diff --git a/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md b/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md index b28459aa..78a89ba4 100644 --- a/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md +++ b/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md @@ -43,9 +43,25 @@ The claim/reset page's rate limiter was left locked for **15 minutes** from the Tier 0). It clears itself; nothing was configured, no password was changed, no code was consumed. The dashboard password is **unchanged** — the probe never submitted a valid code. -## What was NOT walked here +## C — the drill's own screen, walked after the window reopened -The **wrong-code answer in English** ("Wrong or expired code") — the drill's own screen — was -pre-empted by the lockout above. It is covered by `TestClaimAnswersFollowTheReadersLanguage`, which -asserts both that the English sentence is present and that the Hungarian one is gone, and which was -red-proofed by restoring the literal. See the second live run below once the window reopens. +The first pass could not see the wrong-code answer in English, because its own Hungarian attempts had +tripped the lockout. The window was **waited out** rather than cleared by restarting the controller — +restarting to make a probe pass would have measured a box nobody runs. One wrong code per language, +**English first** so the Hungarian pass could not pre-lock it: + +| cookie | one wrong code | answer | +|---|---|---| +| `felhom_lang=en` | `this-is-not-the-code` | **"Wrong or expired code"** | +| `felhom_lang=hu` | `this-is-not-the-code` | „Hibás vagy lejárt kód" | + +**That is the exact screen the 2026-09-20 drill stopped on**, and it is now in the reader's language. +It is also the sentence `VOLUNTEER-first-hour.en.md` §13 quotes, and `guide_quote_gate.py` now fails +the push if the guide and the bundle ever disagree about it. + +## The box afterwards + +The claim/reset rate limiter was exercised and has since cleared. **Nothing was configured, no code +was consumed, no password was changed** — every attempt used a deliberately wrong code, so none of +them could reach the password-setting branch. The dashboard password is the one in the operator's +credentials file, unchanged, and was used to sign in for the backups capture after all of this.