diff --git a/documentation/audits/evidence-bignight-2026-09-14/journal.md b/documentation/audits/evidence-bignight-2026-09-14/journal.md index 2ff3e5a8..3cdbb32f 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/journal.md +++ b/documentation/audits/evidence-bignight-2026-09-14/journal.md @@ -650,3 +650,20 @@ a power-cycle, and the night moves to Phase 6. the boot reconciler); **homebox `running`, `deploying false`, `deployed true`, „Fut · Naprakész" — the interrupted deploy is not stuck**. Hub: `controller_started (info)` 22:10:32Z, `node_recovered` 22:10:43Z — **mail suppressed by cooldown**. So a reboot heals it; nothing short of a reboot does, and no screen tells a household to reboot. + +## Phase 6 — the morning after (`phase6/`) + +**Every app healthy? Every label true?** (`phase6/morning-after-check.txt`, 22:13:14Z): all 12 apps `running`, no +container down or unhealthy. Labels: 11 × „Fut · Naprakész" with installed == catalog — true. **privatebin: „Frissítés +elérhető — ma" while installed 2.0.6 and catalog 2.0.5** (after the Phase 4 revert) — **false: the offered Update is a +downgrade** → **R-524 (P2)**. (The check script's own „label true" verdict for privatebin was wrong — it compared for +difference, exactly as the product does.) + +**Every backup page honest?** (`phase6/backups-overview-morning.txt`): „DB mentések 6 fájl" ✓; „Távoli rendszermentés — +nincs beállítva" ✓ (honest again after the reboot); whole-system tile „– · Utolsó teljes mentés – · Méret / cél · +**Naprakész**" — no backup shown, labelled current (R-517); „Következő mentés — 3 órája" (R-500 class); +„Pillanatkép-mód: … csak néhány másodpercre" (R-518). `/backups/restore` lists 13 apps incl. Homebox ✓. + +**Restore from off-site onto 9202: not walked** — no off-site copy exists on this record (see the pre-note). Instead a +DB-backed app (BookStack, MariaDB) is restored from its local copy on the box through `POST /backup/restore`, after a +page is deleted and the recycle bin emptied (below). diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase6/backups-overview-morning.txt b/documentation/audits/evidence-bignight-2026-09-14/phase6/backups-overview-morning.txt new file mode 100644 index 00000000..f5bab2de --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase6/backups-overview-morning.txt @@ -0,0 +1 @@ +↗ | Biztonsági mentés | enkicsifelhom.hu | A rendszermentés jelenleg ugyanazon a lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem. Csatlakoztass egy második meghajtót a teljes védelemhez. | Ezt a meghajtót kijelölheted a rendszermentés helyéül — így egy lemezhiba után is vissza tudod állítani a rendszert. | Adatlemez | Kijelölöm | Tárhely áttekintés | Rendszer (/) | 23.2 GB / 68.7 GB (34%) | Adatlemez | 3.47 GB / 97.9 GB (4%) | DB mentések | 6 fájl | Rendszermentés (teljes mentés) | A teljes szerver — alkalmazások, beállítások és adatbázisok együtt — időszakos mentése, amelyből az egész készülék visszaállítható. Ezt a host-ügynök készíti és kezeli. | – | Utolsó teljes mentés | – | Méret / cél | Naprakész | Következő mentés | 3 órája — a mentési ablakon belül | – | Visszaállítás ellenőrizve | Még nem futott | Mentés most | Pillanatkép-mód: az alkalmazások csak néhány másodpercre állnak le. | Mentési időablak | A mentések egymás után futnak: adatbázis-mentés, helyi másolat, távoli mentés, majd a teljes rendszermentés. | Mentési időablak kezdete | Mentés | Adatbázis-mentés: | 02:30 | Helyi másolat: | 03:30 | Távoli mentés: | 04:15 | Teljes rendszermentés: kb. | 04:30–08:30 | között | ✓ | Adatmentés aktív | – | Távoli rendszermentés | nincs beállítva | 6 | Adatbázis mentve diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase6/local-restore-bookstack.txt b/documentation/audits/evidence-bignight-2026-09-14/phase6/local-restore-bookstack.txt new file mode 100644 index 00000000..e020ff85 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase6/local-restore-bookstack.txt @@ -0,0 +1,11 @@ +22:14:36 BEFORE accident pages {'toltott-kaposzta': 200, 'wifi-jelszo-helye': 200, 'kutya-oltasi-naptar': 200, 'nyaralas-balaton-2026': 200, 'auto-szerviz': 200} attachments(status,sha equal) {'nagymama-recept.bin': (200, True), 'garancia-jegy.bin': (200, True)} wifi text 2 +22:14:36 --- the accident: someone deletes „Wifi jelszó helye" and empties the recycle bin +22:14:36 delete page 302 +22:14:36 empty recycle bin 404 +22:14:37 AFTER accident pages {'toltott-kaposzta': 200, 'wifi-jelszo-helye': 404, 'kutya-oltasi-naptar': 200, 'nyaralas-balaton-2026': 200, 'auto-szerviz': 200} attachments(status,sha equal) {'nagymama-recept.bin': (200, True), 'garancia-jegy.bin': (200, True)} wifi text 0 +22:14:37 points for bookstack: {"ok":true,"data":[{"time":"2026-09-14T20:59:20Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}]} + +22:14:37 --- restore through the page call: POST /backup/restore stack_name=bookstack snapshot_id=helyi +22:14:37 restore POST -> ['HTTP/2 302 ', 'location: /backups/restore?flash=Vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl.'] +22:14:37 restore-status {"ok":true,"data":{"running":true,"op":"restore","stack":"bookstack","started_at":"2026-09-14T22:14:37.276259266Z"}} + diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase6/morning-after-check.txt b/documentation/audits/evidence-bignight-2026-09-14/phase6/morning-after-check.txt new file mode 100644 index 00000000..f803498f --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase6/morning-after-check.txt @@ -0,0 +1,20 @@ +=== apps 22:13:14 +bookstack state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +docmost state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +privatebin state running | tags ['Fut', 'Frissítés elérhető — ma'] | installed==catalog False | label true | unhealthy/down containers [] +gokapi state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +nextcloud state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +immich state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +vaultwarden state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +paperless-ngx state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +jellyfin state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +mealie state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +uptime-kuma state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +adventurelog state running | tags ['Fut', 'Naprakész'] | installed==catalog True | label true | unhealthy/down containers [] +=== backup pages +/backups :: ↗ | Biztonsági mentés | enkicsifelhom.hu | A rendszermentés jelenleg ugyanazon a lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem. Csatlakoztass egy második meghajtót a teljes védelemhez. | Ezt a meghajtót kijelölheted a rendszermentés helyéül — így egy lemezhiba után is vissza tudod állítani a rendszert. | Adatlemez | Kijelölöm | Tárhely áttekintés | Rendszer (/) | 23.2 GB / 68.7 GB (34%) | Adatlemez | 3.47 GB / 97.9 GB (4%) | DB mentések | 6 fájl | Rendszermentés (teljes mentés) | A teljes szerver — alkalmazások, beállítások és adatbázisok együtt — időszakos mentése, amelyből az egész készülék visszaállítható. Ezt a host-ügynök készíti és kezeli. | – | Utolsó teljes mentés | – | Méret / cél | Naprakész | Következő mentés | 3 órája — a mentési ablakon belül | – | Visszaállítás ellenőrizve | Még nem futott | Mentés most | Pillanatkép-mód: az alkalmazások csak néhány másodpercre állnak le. | Mentési időablak | A mentések egymás után futnak: adatbázis-mentés, helyi másolat, távoli mentés, majd a teljes rendszermentés. | Mentési időablak kezdete | Mentés | Adatbázis-mentés: | 02:30 | Helyi másolat: | 03:30 | Távoli mentés: | 04:15 | Teljes rendszermentés: kb. | 04:30–08:30 | között | ✓ | Adatmentés aktív | – | Távoli rendszermentés | nincs beállítva | 6 | Adatbázis mentve + +/backups/apps :: ↗ | Biztonsági mentés — Alkalmazások | enkicsifelhom.hu | Alkalmazás-mentések (adatbázis + konfiguráció) | Az egyes alkalmazások részletes, granulált mentése — adatbázis-kiírások, beállítások és alkalmazás-fájlok. A fenti teljes mentéstől függetlenül, alkalmazásonként visszaállítható. | Ütemezés | Adatbázis mentés | 02:30 | Következő: ma 02:30 | Utolsó adatbázis mentés: | 2026-09-14 22:59 (1 órája) | Mentés most | Adatbázisok | Alkalmazás | Típus | Méret | Utolsó | Érvényesítés | Állapot | adventurelog | PostgreSQL | 153.0 KB | 09-14 22:59 | 47 tábla | OK | bookstack | MariaDB | 66.6 KB | 09-14 22:59 | 41 tábla | OK | docmost | PostgreSQL | 139.9 KB | 09-14 22:59 | 42 tábla | OK | immich | PostgreSQL | 51.0 MB | 09-14 22:59 | 66 tábla | OK | nextcloud | MariaDB | 1.4 MB | 09-14 22:59 | 131 tábla | OK | paperless-ngx | PostgreSQL | 320.3 KB | 09-14 22:59 | 72 tábla | OK | Alkalmazások mentési állapota | AdventureLog | Konfig + DB + Adatok | ▶ | 1. mentés | Auto | helyi | Utolsó: 1 órája | DB + Konfig + Adatok | 2. mentés | rsync | → hdd_1 | Naponta | Utolsó sikeres: 3 órája | Sikeres | 112.2 MB | DB + Konfig + Adatok | Fájlok visszaállítása | Teljes visszaállítás a másolatból | Beállítás | 3. mentés | Nincs beállítva | távoli (offsite) | Nincs távoli mentési cél beállítva | Beállítás | BookStack | Konfig + DB + Adatok | ▶ | 1. mentés | Auto | helyi | Utolsó: 1 órája | DB + Konfig + Adatok | 2. mentés | rsync | → hdd_1 | Naponta | Utolsó sikeres: 3 órája | Sikeres | 154.9 MB | DB + Konfig + Adatok | Fájlok visszaállítása | Teljes visszaállítás a másolatból | Beállítás | 3. me + +/backups/restore :: ↗ | Biztonsági mentés — Visszaállítás | enkicsifelhom.hu | Visszaállítás | Alkalmazás: | — Válasszon — | AdventureLog | BookStack | Docmost | Gokapi | Homebox | Immich | Jellyfin | Mealie | Nextcloud | Paperless-ngx | PrivateBin | Uptime Kuma | Vaultwarden | Pillanatkép: | — Válasszon alkalmazást — | Még nincs mentés felhasználói adattal. | A visszaállítás felülírja az alkalmazás jelenlegi adatait a kiválasztott mentés állapotával. | Az alkalmazás a folyamat során automatikusan leáll és újraindul. | Megértettem, visszaállítás indítása. | Visszaállítás indítása | Importálás mentett csomagból (.fab) | Hordozható mentéscsomag (.fab) | Hordozható pillanatfelvétel — bárhol tárolhatod, és bármikor visszatöltheted egy meghajtóról. A folyamatos védelmet az 1–3. szintű mentés adja. | Jelszavas titkosítás (opcionális) | Üresen hagyva a csomag titkosítás nélkül készül. | AdventureLog | Letöltés (.fab) | BookStack | Letöltés (.fab) | Docmost | Letöltés (.fab) | Gokapi | Letöltés (.fab) | Homebox | Letöltés (.fab) | Immich | Letöltés (.fab) | Jellyfin | Letöltés (.fab) | Mealie | Letöltés (.fab) | Nextcloud | Letöltés (.fab) | Paperless-ngx | Letöltés (.fab) | PrivateBin | Letöltés (.fab) | Uptime Kuma | Letöltés (.fab) | Vaultwarden | Letöltés (.fab) | Összes letöltése (egyenként) | A csomagok egyenként készülnek és töltődnek le — pillanatfelvétel a mostani állapotról. + diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase6/privatebin-label.txt b/documentation/audits/evidence-bignight-2026-09-14/phase6/privatebin-label.txt new file mode 100644 index 00000000..2e0fa1ca --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase6/privatebin-label.txt @@ -0,0 +1,9 @@ +=== 22:13:37 +installed(template) {'privatebin': 'privatebin/pdo:2.0.6'} catalog {'privatebin': 'privatebin/pdo:2.0.5'} since 2026-09-14 +class="tag tag-warn" title="Újabb változat érhető el ehhez az alkalmazáshoz. A frissítés indításához nyomd meg a Frissítés gombot.">Frissítés elérhető — ma +installed_images: + privatebin: + ref: privatebin/pdo:2.0.6 + digest: sha256:4c141b2326f8b353598ce9ce7507a9cfecf2dad5c60a39fea903d430e296d8f5 + image: privatebin/pdo:2.0.6 +privatebin/pdo:2.0.6 diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index 1a6873f2..ec1b1c35 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -727,6 +727,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-521** | **[P3-LOW] One unplugged drive sends the operator five e-mails and the household none.** MEASURED 2026-09-14 (BIGNIGHT F4, VM 333): `storage_disconnected (error)` at 21:58:02 CEST plus `app_start_failed (warning)` for each of the four apps the drive carries at 21:58:15, each with its own operator mail (hub log: five `Operator email sent`). The customer's mailbox (`tester1@felhom.eu`, read through the connector) received nothing; the household learns of it only on the dashboard, which is honest and says what to do. The apps' stop is a consequence of the drive event, so the four warnings add no information. **Fix shape:** suppress `app_start_failed` for apps stopped by a `storage_disconnected` (the dead-app check already knows the reason — „Hiányzó tárhely"), and decide whether a household gets a mail for a lost drive. **F6, 40 min later, the opposite failure:** a second, separate drive loss (20:38:33Z) produced `storage_disconnected (error)` and four `app_start_failed`, and the hub logged `Operator email suppressed … cooldown` for all five — **no mail at all for the second unplug**; only `health_degraded (warning)` mailed. A per-key cooldown that outlives the recovery (`storage_reconnected` came between them) silences a new incident. **F7:** the system disk at 95 % produced only `health_degraded (warning)`, whose operator mail was **suppressed by the cooldown** left by F6's `health_degraded` 15 minutes earlier; no disk-specific event reached the hub at all — the operator was not told the disk was nearly full. | **READY — rank P3-LOW; owner: CC (controller) · operator (customer mail policy)** | | **R-522** | **[P3-LOW] While the box has no internet, the dashboard's „Cloudflare Tunnel" tile keeps saying „Fut", and no page tells the household the box is offline.** MEASURED 2026-09-14 (BIGNIGHT F8, VM 333): VM 333's traffic off the LAN and to the hub was dropped at demo-hp's bridge 21:08:36 → 21:26:07Z. Throughout, the LAN dashboard (probed every 26 s from demo-hp) answered 200 and, polled every 2 min, showed no banner and the tile „Cloudflare Tunnel — Biztonságos internetkapcsolat — a szerver portnyitás nélkül érhető el kívülről. · **Fut** · Védett"; meanwhile cloudflared logged ≈ 20 errors every 2 minutes, the public name answered 530, and the controller logged `[report] Push failed … context deadline exceeded` and `Job hub-report failed: hub push failed after 3 attempts`. The tile reports the container, not the connection. A household whose remote access is gone sees „Fut". **Fix shape:** the tile reads the tunnel's connection state (cloudflared's registered connections or the report push result) and says „Nincs internetkapcsolat" when either fails. | **READY — rank P3-LOW; owner: CC (controller)** | | **R-523** | **[P1-HIGH] If the controller container is killed, nothing restarts it: the household's dashboard is gone and no screen can bring it back — the big night's stop rule.** MEASURED 2026-09-14 (BIGNIGHT F9, VM 333, controller 0.242.0): `docker kill felhom-controller` at 21:34:39Z, 4 s into a deploy. The container stays `Exited (137)` with `restart=unless-stopped` (Docker does not restart a container stopped by kill); the in-guest `felhom-controller-bootstrap` unit is a one-shot (`active (exited)` since boot) and does not watch it; the host agent does not either. The dashboard answered **502** for 33 min until the harness power-cycled the box. The app being deployed came up by itself (`homebox … (healthy)`). The hub raised `node_stale` at 22:04:43Z (30 min after the last report, which reached it 3 s before the kill) and **suppressed the operator mail by cooldown** (F8's `node_stale` 39 min earlier) — so for over half an hour neither the household nor the operator was told. Recovery by power-cycle (`qm reset` 22:08:17Z): the bootstrap started the controller at boot (22:10:23Z), dashboard 200 at +131 s, all 12 apps running at +229 s, the deployed homebox `running · deploying false · deployed true` — „Fut · Naprakész", **not stuck**. Hub `controller_started (info)` 22:10:32Z, `node_recovered` 22:10:43Z with its mail **also suppressed by cooldown**. `docker kill` is the brief's injection; the same state follows any stop that Docker records as deliberate (an operator's `docker stop`, a failed self-update that stops the old container). Memory note „controller DOES auto-recover — test with kill -9/OOM, never docker kill" describes the mechanism, not the consequence: nothing watches for a controller that is simply not running. **Fix shape:** a systemd watchdog (or the agent) that starts `felhom-controller` whenever it is not running and the operator has not parked it; restart policy `always`. | **READY — rank P1-HIGH; owner: CC (controller bootstrap / agent)** | +| **R-524** | **[P2-MEDIUM] When the catalog moves an app back to an older version, a box that already updated shows „Frissítés elérhető" — and the offered Update is a downgrade.** MEASURED 2026-09-15 (BIGNIGHT Phase 6, VM 333): privatebin was updated 2.0.5 → 2.0.6 through the guarded Update after the drill bump; the catalog was then reverted to 2.0.5 (`a161ccb`). At 22:13:37Z the box reads `installed privatebin/pdo:2.0.6`, `catalog privatebin/pdo:2.0.5`, `catalog_since 2026-09-14`, and the app page tag „**Frissítés elérhető — ma**" with the title „Újabb változat érhető el ehhez az alkalmazáshoz. A frissítés indításához nyomd meg a Frissítés gombot." The label compares for *difference*, not for *newer* (`09-update-architecture.md` §5.4 render table); the guarded Update would advance the pin „to the catalog's current definition" — 2.0.6 → 2.0.5. The same state follows any real upstream yank. **Not pressed tonight.** **Fix shape:** compare versions (or `catalog_since` against the installed record) and render „Naprakész" / „a katalógusnál újabb" when the box is ahead; refuse a pin move to an older tag without an operator word. | **READY — rank P2-MEDIUM; owner: CC (controller)** |