diff --git a/CONTEXT.md b/CONTEXT.md index 623c6893..9a976d05 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -16,6 +16,13 @@ > and holds nothing of its own; this file does hold its own content, namely the standing rulings below. +> **2026-10-04 (day) — off-site closed; OS-update spike done.** Hub v0.129.0 (R-833: operator raises ONE window's cap, +> `POST /offsite/window-grant/` `max_remove=`, 1..500, consumed once, window row records its cap). Agent v0.139.0 +> (R-834: DR bring-up refuses beside a live original; restore-test measured safe), `scripts/felhom-restore-beside.sh` +> for the hand route, `07` Lane 2 rule. R-95 dated check 2026-10-12. R-726: options in STATUS (pick A). OS spike: +> `11` corrected (C1–C12, §5.4.1 wrapper draft, §7.1 answers); rows R-835..R-839; demo-hp host Debian-updated, next +> boot kernel 7.0.14-20-pve. `REPORT-backup-close-os-spike-2026-10-04.md`. + > **Rulings 2026-10-04 (day) — recorded before the work (off-site close + OS update spike).** `09` §3 decisions **75** > (the off-site topic closes first, one brief), **76** (the OS fast lane follows an approved list with a 1–2 day wait; > `unattended-upgrades` with no wait rejected) and **77** (`architecture/11-os-updates.md` added unchanged, NOT RATIFIED, diff --git a/REPORT-backup-close-os-spike-2026-10-04.md b/REPORT-backup-close-os-spike-2026-10-04.md new file mode 100644 index 00000000..b479da86 --- /dev/null +++ b/REPORT-backup-close-os-spike-2026-10-04.md @@ -0,0 +1,57 @@ +# REPORT — off-site topic closed; operating-system update spike — 2026-10-04 (day) + +Architecture read: `07-backup-architecture.md` (Lane 2, §6.1), `_recovery-inventory-2026-07-28.md`, `03-host-agent.md`, +`09` §3/§4, `11-os-updates.md`. Baselines (re-verified): felhom.eu `d07a1a904cbf` (hub 0.128.0), controller +`99a149756070` (0.290.0), agent `d766666ff8cf` (0.138.0), catalog `917a779cca67`. Register 328, highest R-834. +Rulings recorded first as `09` §3 decisions 75–77 and `11` committed verbatim (`3885640`). Evidence: +`documentation/audits/backup-close-2026-10-04/` and `documentation/audits/os-updates-spike-2026-10-04/`. + +## The Part table + +| Part | Result | Notes | +|---|---|---| +| A — restored guest safe by default (R-834) | **done** | Routes: restore-test (MEASURED safe: onboot 0 and throwaway mp8/mp9 on every poll), DR bring-up (**fixed**: refuses beside a live original — agent v0.139.0, refused live on demo-hp, nothing created), hand route (**new** `scripts/felhom-restore-beside.sh`, proven live on 9298 then destroyed), provisioning (golden, no binds). 4 tests, 2 red-proofs + 1 built-in. **Changed:** no sudoers line — the restore-test sets onboot 0 through the API, and DR refuses rather than degrades. | +| B — clean-up cannot wedge (R-833) | **done** | Hub v0.129.0 deployed. 4 red-proofs. Lab proof on a real restic 0.14.0 repo: 98 → 13 under a raised cap, default refused before, normal after. Live: 4 bad grants refused (400). **Changed:** no valid grant placed on a real customer — a demo box would consume it (brief: lab repo only). No controller change needed. | +| C — returning household (R-726) | **done** | Two options in STATUS; pick A. Nothing built. | +| D — dated check (R-95) | **done** | Due 2026-10-12, four checks named in R-95. | +| E — where we stand | **done** | 5 systems surveyed read-only (throwaway apt indexes). | +| F — exact version later | **done** | madison host + guest; DSA history 3 months; snapshot.debian.org from a throwaway container on 9202. | +| G — guest update on 9202 | **done, one deviation** | **Changed:** 9202 is on `dir` storage and cannot snapshot, so the undo was a backup + restore (73 s); the snapshot rollback is unmeasured (R-837). G3 interrupted the update straight after the undo (the "apply again" happened as G3's repair) — the same update could not be interrupted once applied. | +| H — host update on demo-hp | **done** | Debian lane 108 packages, 60 s, guests up. One-package undo: rsync gone, libpng worked. Kernel: two reboots on the operator's word — new kernel, then fallback to old. Proxmox simulated only. | +| I — design record | **done** | `11` corrected (C1–C12), wrapper draft §5.4.1, answers §7.1, sample list (157 packages) simulated on demo-felhom, Q10 price recorded. Two STATUS decisions. | + +## Claims that turned out wrong (named) + +1. **"Debian's archives keep only the newest version"** (`11` §5.3) — they keep two: the point-release one and the newest security one; intermediates are gone (C2). +2. **"Proxmox and Docker keep older ones"** — true, measured: 30–66 and 18–46 versions. +3. **"`--next-boot` falls back by itself"** (`11` §5.6) — only after a boot that reaches userspace; on GRUB it is an ordinary default; a hang keeps the new kernel (code-read). And installing a kernel alone makes it the default (C4). +4. **"The guest has no `live-restore`"** — true. But `live-restore` is the answer to Q3, and switching it off again is a trap (C5, R-835). +5. **"The agent may not run `apt` except for `dnsmasq`"** — it may also install `wireguard-tools` (C1). +6. **"The restore-test guest is safe today"** — TRUE, measured (onboot 0, no host bind). The unsafe routes were the DR bring-up and the hand route. +7. Also wrong in `11`: the slow-lane list by name (40 Proxmox packages have plain names, C3); `cloudflared` "on the host" (it is a guest container, C8); approving what ring 0 installed (C9); a fast-lane run is "a service restart at most" — libc leaves PID 1 and `lxc-start` on the old library (C11). + +## Found and handled in-session + +- My own output filter dropped every line containing "perl" — including "paperless". A false "the app vanished" was caught before acting on it; evidence files were saved unfiltered. +- `pkill -f dpkg-deb` killed my own shell during G3 (the known trap); the kill itself had landed, and the state was read in a fresh command. +- The first Docker probe counted 302/404 answers as down; re-counted from the raw probe files with "no answer" as down. +- A `pgrep` waiter matched itself and never ended (the known trap); it was harmless and killed by its timeout. + +## Rows + +Closed: **R-833, R-834**. Opened: **R-835** (live-restore off trap), **R-836** (kernel hang keeps new kernel), **R-837** +(snapshot undo unmeasured), **R-838** (cloudflared pinned since June, P2), **R-839** (boot sweep held an app whose +`HDD_PATH` names its folder). Narrowed: **R-812** (spike done), **R-95** (dated check), **R-726** (waiting on the +operator). Register **328 → 331**. + +## Teardown, three layers + +- **Machines:** scratch VMIDs 990000 (restore-test, torn down by the agent) and 9298 (destroyed); no 9297 was created. + 9202: Debian fully updated, Docker 29.8.2 / containerd 2.3.6 (golden 0.290.0's), `daemon.json` byte-identical to the + baked one, all apps healthy; its backup deleted; the `debian:trixie` probe image removed. **demo-hp host:** 108 Debian + packages + kernel `7.0.14-20-pve` installed (110 changes, `partH/H-final-host-packages-after.tsv`); **running + `7.0.2-6-pve`, next boot `7.0.14-20-pve`, no pins**; 78 Proxmox packages still pending. demo-felhom: read only (its + agent updated to 0.139.0 by signed job). Helper files removed from every host and guest. +- **Host (DooPlex):** the lab restic repo removed; scratch copies of the hub password and the DSA list shredded. Agent + 0.139.0 released (tag + package, verified by download), not vouched. +- **Hub:** v0.129.0 deployed; no grant left pending; weekly windows unchanged (ON). diff --git a/STATUS.md b/STATUS.md index 1ce73553..c5a9be61 100644 --- a/STATUS.md +++ b/STATUS.md @@ -2,8 +2,50 @@ **Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).** -**Updated 2026-10-04: off-site safety finished. Both demo boxes run controller 0.290.0 and host agent 0.138.0. Hub -0.128.0. New installs get golden 0.290.0 with agent 0.138.0; every box's floor is 0.290.0.** +**Updated 2026-10-04 (day): the off-site topic is closed; the OS-update test is done. Both demo boxes run controller +0.290.0 and host agent 0.139.0. Hub 0.129.0. New installs get golden 0.290.0; every box's floor is 0.290.0.** + +## Today (2026-10-04, day): off-site closed, operating-system updates measured + +**Two decisions for you — each has a safe default if you say nothing:** + +1. **A returning household's first night.** A new box for someone who had a box before makes no off-site copy, because + the old copy was made with a key the new box does not have. + - **A (my pick):** the new box sets the old copy aside by itself on its first night, then starts a new one. An + un-claimed box already does exactly this. Nothing is deleted; you can put the old copy back. Cost: a small box + change. A household that wanted to continue the old copy with its recovery code must do that before night one. + - **B:** ask the household on the recovery-code evening. Cost: new screens in two languages. If they skip it, the gap stays. + - **If you say nothing:** such a household has no off-site copy until someone presses "start a new off-site backup", + and you get a mail each time. Nobody is blocked today (no returning household is waiting). +2. **Approved OS updates, when Debian has already replaced the version.** Debian keeps only two versions of a package. + - **A (my pick):** the box then fetches the exact approved version from Debian's own dated archive + (snapshot.debian.org, signed by Debian). Measured: 2–3 seconds. Cost: one more outside service we rely on — but in + 3 months it would have been needed **zero** times for the packages a box has. + - **B:** the box waits for the next approval. Cost: no new service; a box can stay unpatched for one cycle. + - **If you say nothing:** nothing is blocked now; the first build step can start with B and switch later. + +**What I did:** +- **A restored box is safe by default.** The automatic restore-test was already safe (measured). The agent's disaster + restore now refuses to run next to a live original. Restores by hand use a new safe script: no start on boot, no link + to the real drives, network off. All proven live on demo-hp. New agent 0.139.0 on both demo boxes. +- **The weekly clean-up cannot get stuck any more.** You can allow one bigger clean-up for one box (hub 0.129.0). Proven on + a lab copy: 98 backups, the normal limit refused, the bigger one cleaned to 13, and the next week was normal again. +- **A dated check for 12 October** looks at the first clean-up that really deletes old backups. +- **OS updates, measured on the demo boxes (nothing built for customers):** + - The boxes are far behind: 188 updates per host, about 59 per guest. Every guest runs a different Docker version. + - A Debian update of the guest took 24 seconds. No app stopped. The undo (restore the guest) took 73 seconds. + - A Debian update of demo-hp's host took 60 seconds. The guests kept running. + - A broken (killed) update does not fix itself. Two repair commands fix it in 5 seconds. + - A Docker update restarts every app (about 30 seconds silent). A Docker setting ("live-restore") avoids that + completely — but switching it off again stopped every app and started none. Recorded as a trap. + - The new kernel booted fine, and the box fell back to the old kernel on the next restart. **But** if a new kernel + hangs, the box keeps trying it. Someone must then switch it off and on. No hardware watchdog is used. + - About 40 packages from Proxmox have ordinary names (for example the disk system ZFS and the Secure Boot loader). So + "which lane" must follow where a package comes from, not its name. + - The internet tunnel program on every box (cloudflared) is 4 months old. Nothing updates it. New row. +- **Thank you for being near the box.** demo-hp restarted twice. It now runs the old kernel and starts the new one at + its next restart. +- **Rows:** 2 closed, 5 opened. The list went from 328 to 331. ## Today (2026-10-04): off-site safety finished @@ -106,8 +148,8 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne ## What needs you -0. **Nothing new from the off-site work.** The Hetzner key change stays your call whenever you want it (3 steps, in - the list). +0. **The two decisions at the top of today's section** (a returning household's first night; approved OS updates + when Debian has moved on). Each has a safe default if you say nothing. The Hetzner key change stays your call (3 steps, in the list). 1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say nothing:** it stays hidden; nothing runs it. 2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list). diff --git a/documentation/architecture/00-capability-map.md b/documentation/architecture/00-capability-map.md index 22468f26..09d31358 100644 --- a/documentation/architecture/00-capability-map.md +++ b/documentation/architecture/00-capability-map.md @@ -232,7 +232,7 @@ likewise silent. Evidence: `audits/DRILL-r361-2026-08-22/evidence/06-part3-decis | **The hub reports LOSS OF VISIBILITY into either off-site store (not just how full it is)** | hub **v0.106.0** (R-339) | **IMPLEMENTED — deliberately NOT proven-live** | Both box checkers count consecutive failed fetch windows and emit `pbsdr_box_unreachable` / `offsite_box_unreachable` (severity `warning`) past a default 3 windows (≈30–45 min), each with a paired `*_recovered` all-clear routed via `recoveredPairedDownTypes` — required because the recoveries are severity `info`, which `severityNotifies` drops. Scopes stay customer-less (`pbsdr-box` / `pool-box`) → operator channel only. Fill logic untouched: a degraded read still drives no band transition. Evidence: `internal/monitor/box_reachability_test.go` + the cross-package wiring test in `internal/notify/`, which asserts an actual operator mail rather than a map entry. **Filed BECAUSE of a measured gap**, not a hypothesis: the 2026-08-18 ep0 outage ran 9 h 37 m with the hub silent | **The gap that remains is R-340**, and it is not small: the ep0 read is the `usage` op, which rides the LOCAL API daemon — the daemon that incident explicitly cleared — so this check would have shown GREEN for that entire outage. It closes "ep0 is unreachable as a host"; it does not close what actually happened. **No live or constructed outage has exercised the emit path**, and one cannot be manufactured against ep0 (Tier 2, protected) | | Secrets hygiene: bearer in k8s Secret, no secrets in git, single-quote credential store | hub v0.53, conventions | **IMPLEMENTED** | 07-13 closing bundle | | | Operator login password changeable from UI | hub v0.54 | **IMPLEMENTED** | 07-13 | | -| Box operating-system security updates (Proxmox host, guest Debian, Docker engine) | — | **MISSING** | `felhom-host-install.sh:2133-2136` ("No upgrades are run") | Nothing runs them after install → finding R-812, intention R-808 (added 2026-10-03). Design: `architecture/11-os-updates.md` (NOT RATIFIED, 2026-10-04) | +| Box operating-system security updates (Proxmox host, guest Debian, Docker engine) | — | **MISSING** | `felhom-host-install.sh:2133-2136` ("No upgrades are run") | Nothing runs them after install → finding R-812, intention R-808 (added 2026-10-03). Design: `architecture/11-os-updates.md` (NOT RATIFIED, 2026-10-04). **Spike done 2026-10-04** (`audits/os-updates-spike-2026-10-04/`): measured, nothing built — still MISSING | | **An ENGLISH-SPEAKING household's first hour: download, install, pair, bind, claim, two apps** | controller **v0.259.0** + hub **v0.119.0** + ISO 1.29.0 + the whole catalog | **PROVEN-LIVE on 0.258.0 with one blocker; THE BLOCKER IS FIXED AND PROVEN, THE WALK IS NOT REPEATED** | `audits/DRILL-first-hour-en-0258-2026-09-20.md` — a fresh install 2026-09-20, one intervention (R-494), stop rule not reached. Then `audits/i18n-closing-2026-09-21/live/` — the three blockers fixed and each proven on a live box or in the operator's inbox: the claim page answers English through the real cookie path; the Backup page's tier names follow the language; and the setup mail carries **four plain-ASCII English words** where the drill's carried `képző-szkítia-ásatás`, one day apart in the same inbox. | **R-596, R-597 and R-598 are CLOSED.** What this row still does NOT claim: **the fixed journey has not been walked end to end by a stranger on a fresh install.** Three fixes proven at the endpoint are not an hour proven by a person, and this project's own rule is that fixes are not a journey (see the recovery-journey row). **Also not walked:** the recovery code (needs ep0), backup/restore/remove/power-cut (proven 2026-09-14), and the two Backup-page *warnings* themselves — guest 9201 is healthy and a healthy box renders none, so they are covered by handler render tests, not live. **Verdict: nothing known now stands between an English-speaking tester and their box — and that is a different sentence from "the walk passed".** | | **A deletion of a customer's off-site history is NOTICED within a day** | hub **v0.111.0** (R-431) | **IMPLEMENTED — not yet PROVEN-LIVE** | 09-01 | `hub/internal/monitor/offsite.go` — third signal beside FILL and STALENESS. **On the hub deliberately:** a detector on the box is one the deletion can silence. Alarms when the reported count falls by more than HALF and by at least 5, guarded by `StatsKnown` (R-331), the declared `State` (R-204) and run success (R-100). **Threshold reasoned, not invented:** over 12 898 reports every decrease lands on ZERO and predates `stats_known`; in the 380-report `stats_known` window there are none. **ACCEPTANCE: 9 009 real points replayed → ZERO alarms** (`offsite_r431_test.go`, fixture committed). **What PROVEN-LIVE would need and this does NOT have:** a real drop observed on a live box producing a real mail — the live firing done at ship time was driven through the hub's own path with synthetic counts, which is an end-to-end delivery proof, not a proof that a genuine deletion is caught. | diff --git a/documentation/architecture/07-backup-architecture.md b/documentation/architecture/07-backup-architecture.md index 4f9b62e7..0e896371 100644 --- a/documentation/architecture/07-backup-architecture.md +++ b/documentation/architecture/07-backup-architecture.md @@ -143,6 +143,16 @@ work, by design and by contract**. They are not customer-facing and are not goin (`--selftest=bring-up -mode dr`), the host-loss plan builder, and the escrow-consume ceremony. Each needs root on the host or a CLI flag; none is reachable from any customer surface. +**[DESIGN + FACT, 2026-10-04, R-834] A whole-guest restore BESIDE a live original never comes up as a second box.** +A restore that does not replace the box's own guest on a replaced host ends with `onboot 0` and no host-path bind +(`mp8` = the household's drives, `mp9` = the original's bootstrap); the DR route on a replaced host keeps its binds, +because there they are right. Per route: the restore-test sets `onboot=0` at create and gives mp8/mp9 throwaway +volumes (measured live on demo-hp, every poll); the DR bring-up REFUSES when the archive's source guest, or any guest +binding the drives, is still on the host (agent v0.139.0, proven live); the hand route is +`scripts/felhom-restore-beside.sh` (proven live); provisioning restores the golden, which has no binds. Pinned by +`TestRunBringUp_DRRefusesBesideALiveOriginal`, `TestRestoreTest_NoHostPathBindBesideTheOriginal` and +`scripts/test_felhom_restore_beside.py`. `audits/backup-close-2026-10-04/partA/`. + **[FACT] What is proven in Lane 2** (INV Parts G.1, G.3): whole-guest `pct restore` from both tiers is proven with exact mount parity; the unattended restore-test is proven and currently running on both boxes; a corrupted snapshot is proven to fail cleanly. **The DR bring-up path has never been diff --git a/documentation/architecture/11-os-updates.md b/documentation/architecture/11-os-updates.md index ec017b23..33966e50 100644 --- a/documentation/architecture/11-os-updates.md +++ b/documentation/architecture/11-os-updates.md @@ -2,7 +2,7 @@ > | | | > |---|---| -> | **Status** | **NOT RATIFIED — a PROPOSAL with one operator ruling.** Ratification is Viktor's review, not an editor's. | +> | **Status** | **NOT RATIFIED — a PROPOSAL with one operator ruling, corrected by the 2026-10-04 spike (§7.1, corrections C1–C12 below).** Ratification is Viktor's review, not an editor's. | > | **Written** | 2026-10-04, by the reviewer (project Claude), before any spike. | > | **Verified against** | felhom.eu `d07a1a9` · felhom-controller `99a1497` (v0.290.0) · felhom-agent `d766666` (v0.138.0) · hub v0.128.0 | > | **Freshness** | **CURRENT** as of 2026-10-04. The spike `TASK-backup-close-and-os-updates-spike-2026-10-04` adds measurements here as `[FACT]` and corrects every claim it disproves. Mark this file STALE when it falls behind what the product does. | @@ -17,6 +17,24 @@ > **Why this file exists.** No architecture document covered operating-system updates. `00` §G marks the > capability MISSING (added 2026-10-03). The finding is **R-812**. The roadmap intention is **R-808**. > **The register carries the work. This file carries the reasoning. The source is the truth.** +> +> **Spike corrections, 2026-10-04** (`audits/os-updates-spike-2026-10-04/`). Each is made in place: the reviewer's +> text is struck (~~like this~~) and the measured text follows, labelled `[FACT]`, with its id. +> +> | Id | Where | What the spike changed | +> |---|---|---| +> | C1 | §2 | The agent may run `apt-get install` for TWO packages, not one (dnsmasq and wireguard-tools). | +> | C2 | §5.3 | Debian keeps two versions, not one; for box packages no fix was replaced within 14 days in 3 months; `snapshot.debian.org` works from a box in seconds. | +> | C3 | §5.2 | The lanes must follow the package's ORIGIN, not its name: 40 Proxmox-repository packages have ordinary names (ZFS, the Secure Boot shim, Ceph, corosync, chrony, CPU microcode). | +> | C4 | §5.6 | `--next-boot` is NOT a one-shot on these GRUB hosts. The fallback works only after a boot that reaches userspace. Installing a kernel alone makes it the default. Only a software watchdog runs. | +> | C5 | §5.6, §6 row 4 | Docker's `live-restore` keeps every container running across an engine update (measured). Turning it OFF again stops every container and starts none. | +> | C6 | §5.6 | A guest snapshot works on LVM-thin (customer guests) but not on `dir` storage; the snapshot rollback itself is unmeasured; a backup-restore undo took 73 s. | +> | C7 | §6 row 2 | A killed `apt` run does not recover by itself; the repair took ~5 s. | +> | C8 | §1, §6 row 14 | `cloudflared` is not a host package: it is a container in the guest, pinned by the controller since June. It belongs with the controller's infrastructure pins, not this file's lanes. | +> | C9 | §5.3 | The approved list must record what ring 0 RUNS healthy, not only what it installed that night. | +> | C10 | §5.5 | Restore-tests and agent updates are not windowed; the host's `apt` timers install nothing today. | +> | C11 | §5.2 | A Debian (fast-lane) update leaves PID 1, `lxc-start`, the Proxmox daemons and dockerd on the old library: its full effect needs a restart the fast lane does not do. | +> | C12 | §6 row 9 | The two demo hosts differ by 7 packages, including the CPU microcode (AMD vs Intel) and Secure Boot (on vs off). | --- @@ -50,6 +68,10 @@ boxes installed. Nobody keeps a hand-written list. alone: *"apt repo alignment skipped (byo — the owner manages repos)"* (`scripts/felhom-host-install.sh`, `align_apt_repos`). `[PROPOSAL]` On a BYO box we update the guest and Docker only, never the host. - **The Proxmox MAJOR upgrade** (PVE 9 → 10). It is a later step of its own, drilled first (R-808 item 5). +- **`cloudflared` and the other infrastructure images** (traefik, filebrowser). **[FACT] (C8)** They are containers in + the guest, pinned in the controller (`internal/infra/infra.go:26`: `cloudflare/cloudflared:2026.6.0`, since + 2026-06-11) and baked into the golden; upstream was `2026.9.3` on 2026-10-04. They move only by a controller release + — the app-image question (`09`), not an OS package. The gap is R-838. --- @@ -68,8 +90,11 @@ boxes installed. Nobody keeps a hand-written list. says *"No upgrades are run — repo alignment only"* (`felhom-host-install.sh` ~L2135). A fresh install gets the Docker engine that was current when its golden was baked, and keeps it. -**[FACT] The agent may not run `apt` today, with one exception.** Its sudoers allowlist -(`felhom-agent/configs/felhom-agent.sudoers`) holds one apt line: `apt-get install -y -q dnsmasq`. +~~**[FACT] The agent may not run `apt` today, with one exception.** Its sudoers allowlist +(`felhom-agent/configs/felhom-agent.sudoers`) holds one apt line: `apt-get install -y -q dnsmasq`.~~ +**[FACT] (C1) The agent may run `apt-get install` for two named packages:** `felhom-agent.sudoers:58` +(`apt-get install -y -q dnsmasq`, used by `internal/lanresolver/lanresolver.go:107`) and `:194` +(`apt-get install -y -q wireguard-tools`, used by `internal/wgtunnel/manager.go:628`). Nothing else. `apt` as root runs package scripts as root, so a broad `apt` grant is a full root grant. §5.4 proposes how to avoid that. @@ -128,8 +153,23 @@ has not ruled on it as such. | Urgent fix | The operator can approve a version on the same day once ring 0 has run it. | The same. | | When | The night window (§5.5) | The night window. A kernel reboot only on a night the operator scheduled. | -Which packages count as slow lane is a list the spike checks (OPEN Q7). A Debian package that restarts -something big (for example `systemd`, `libc6`, `openssh-server`) may belong in the slow lane too. +~~Which packages count as slow lane is a list the spike checks (OPEN Q7). A Debian package that restarts +something big (for example `systemd`, `libc6`, `openssh-server`) may belong in the slow lane too.~~ + +**[FACT] (C3) The lane must be decided by ORIGIN, not by name.** On demo-hp, 40 pending packages come from the +Proxmox repository under ordinary names: `zfsutils-linux`, `zfs-zed`, `libzfs7linux`…, **`shim-signed` and friends (the +Secure Boot loader)**, `ceph-common`/`librados2`…, `corosync`, `chrony`, `frr`, `amd64-microcode` +(`partH/H2-proxmox-origin-debian-names.txt`). A name rule (`pve-*`, `proxmox-*`) would have put them in the fast lane. +The fast lane is: origin `Debian` or `Debian-Security`, and nothing else. On demo-hp that selection was 108 packages +and pulled in **zero** Proxmox packages. + +**[FACT] (C11) What a fast-lane run restarts, and what it does not.** Guest (9202, 49 packages incl. libc6): the +packages' own scripts restarted postfix, journald, networkd; **dockerd, containerd, sshd, dbus, logind, cron** kept the +old libc; no container stopped (13 samples). Host (demo-hp, 108 packages): dnsmasq, postfix, journald restarted; +**systemd (PID 1), `lxc-start`, pveproxy, pvedaemon, pvestatd, pvescheduler, watchdog-mux, sshd, zed, chronyd** kept the +old libc; both guests and the agent stayed up. So the fast lane is safe to run unattended, but a libc fix is only +fully in force after a reboot (host) or a Docker restart (guest) — which are slow-lane acts. `[PROPOSAL]` the box +reports "restart needed" (processes on deleted libraries) and the slow lane's next reboot picks it up. ### 5.3 The approved list (the "tested versions" record) @@ -148,11 +188,28 @@ Nobody writes the list by hand. It fills itself: 5. Each box reports which OS release it runs, how many updates are waiting, whether it needs a reboot, and which packages it has that **no approved list covers** (see §6, edge case 9). -**OPEN Q1 is the weak point.** The design works only if a box can still download the approved version +~~**OPEN Q1 is the weak point.** The design works only if a box can still download the approved version a week later. Debian's main and security archives keep only the newest version of each package. If Debian publishes a newer fix between approval and install, the approved version is gone. Options: the box waits for the next approval; or the box uses `snapshot.debian.org` (Debian's own dated archive, -still signed by Debian); or Felhom runs a package cache. The spike measures how often this happens. +still signed by Debian); or Felhom runs a package cache. The spike measures how often this happens.~~ + +**[FACT] (C2) Q1 measured.** The live Debian archives keep **two** versions: the point-release one in `trixie` +(main) and the newest in `trixie-security`; intermediate versions are gone (openssl: installed `u1`, main `u2`, +security `u3`). Over 2026-07-04..10-04, 167 trixie security advisories; for the 517 source packages installed on a box, +**no package got a second advisory within 2, 7 or 14 days** (the 3 within 2 days were chromium and webkit2gtk, not on a +box). `snapshot.debian.org` answers a box: a dated index in **2.3–3.0 s**, a gone exact version +(`openssl 3.5.6-1~deb13u1`) downloaded in **2.0 s**, Debian-signed. Proxmox and Docker keep many old versions +(pve-manager 66, docker-ce 46). So with a 1–2 day wait the approved version is almost always still live; the rare +miss is fetched from the snapshot taken at approval time. `[PROPOSAL]` each OS release records its approval +timestamp; a box installs from its own sources, and only for a Debian package that is no longer there, from +`snapshot.debian.org/archive//`. This is the operator decision in STATUS. + +**[FACT] (C9) Approve what ring 0 RUNS, not what it installed.** In the simulation on demo-felhom +(`partI/demo-felhom-simulation.txt`), every one of the 108 host and 49 guest approved versions was installable and +downloadable — but `curl`, `libcurl*` and `libssh2` were "not covered" in the guest, only because scratch guest 9202 +ALREADY ran the newer version and so installed nothing. `[PROPOSAL]` step 1 reports the full installed +`package=version` set after the run, and approval covers every version ring 0 runs healthy. ### 5.4 Who runs it, and with what permission @@ -172,6 +229,66 @@ still signed by Debian); or Felhom runs a package cache. The spike measures how versions. A broken-into hub can choose an older version or no version. It cannot make a box install a package that the publisher did not sign. +### 5.4.1 The root wrapper's interface — DRAFT (2026-10-04, design only, nothing installed) `[PROPOSAL]` + +`felhom-os-apply` — root-owned (`0755 root:root`), installed by the installer beside `felhom-selfupdate-guarded`; +the agent's sudoers gets exactly `/usr/local/sbin/felhom-os-apply --plan /var/lib/felhom-agent/os/plan-*.json` and +`… --repair-only`. For the guest it runs on the host and enters the guest with `pct exec --` itself, so the +agent needs no `pct exec … apt` line. Built from what Parts G and H measured. + +**Input — one JSON plan file** (written by the agent, from the hub's approved OS release): + +```json +{ + "release_id": "os-2026-10-04-1", "approved_at": "2026-10-04T08:00:00Z", + "layer": "host", // "host" | "guest" + "vmid": 9201, // guest only + "snapshot": "20261004T080000Z", // the snapshot.debian.org timestamp of approval (C2) + "packages": [ {"name": "libc6", "version": "2.41-12+deb13u4", "origin": "Debian"} ], + "allow_new": ["proxmox-kernel-7.0.14-20-pve-signed"], // slow lane only, signed operator job + "lane": "fast" // "fast" | "slow" +} +``` + +**Order of work:** (1) refuse checks below; (2) **repair first** — `dpkg --configure -a` then `apt-get -f install`, +logging what it repaired (C7); (3) `apt-get -s install` of exactly `name=version` for every package that is +installed AND older; (4) refuse if the simulation would remove, downgrade, add an unlisted package, or touch a package +whose candidate origin is not the plan's; (5) download — from the box's own sources, or for a Debian version no +longer there, from `snapshot.debian.org/archive//` with a temporary sources list it deletes after +(C2); (6) install with `DEBIAN_FRONTEND=noninteractive APT_LISTCHANGES_FRONTEND=none -o Dpkg::Options::=--force-confold +-o Dpkg::Options::=--force-confdef`; (7) `apt-get clean`; (8) report. + +**Refusals** (each exits non-zero with one line `os-apply: REFUSED: ` and changes nothing): + +| # | Refuses when | +|---|---| +| R1 | the plan file is not under `/var/lib/felhom-agent/os/`, not owned by the agent, or not valid JSON | +| R2 | `lane` is `fast` and any package's origin is not `Debian` / `Debian-Security` (C3) | +| R3 | `lane` is `slow` and the plan is not carried by a verified signed operator job (R-530's mechanism) | +| R4 | the simulation removes any package | +| R5 | the simulation downgrades any package (the operator undo is a separate signed op, §5.6) | +| R6 | the simulation installs a package that is neither installed nor in `allow_new` | +| R7 | a listed version is not downloadable from the sources the installer set up or the named snapshot | +| R8 | free space on `/` (or the guest's rootfs) is below 3× the download size, minimum 500 MB (edge case 8) | +| R9 | another apt/dpkg holds the lock, or the per-guest lane lock is held (a backup, a restore-test, C10) | +| R10 | `layer` is `guest` and the vmid is not the box's own customer guest | +| R11 | the plan names a package twice, or a version that is not a Debian version string | + +**Log lines** (to the journal, tag `felhom-os-apply`, and echoed for the agent to forward to the hub): + +``` +os-apply: START release= layer= lane= packages= +os-apply: REPAIR configured= fixed= (always printed; 0 0 when nothing was half-done) +os-apply: PLAN upgrade= already= not-installed= from-snapshot= download= +os-apply: REFUSED: +os-apply: CONFFILE kept (new version saved as .dpkg-dist) +os-apply: DONE rc=0 seconds= upgraded= restarted= restart-needed= reboot-needed= +os-apply: FAILED rc= step= — dpkg state: +``` + +`restart-needed` lists processes still mapping deleted libraries (C11); `reboot-needed` is yes when that list holds +PID 1 or `lxc-start`, or a kernel was installed. + ### 5.5 When Inside the household's night window, after the backups: @@ -188,9 +305,16 @@ The OS leg starts **after the whole-guest backup has finished**, so the guest's minutes old. This is the opposite order to app updates, which run before the whole-guest backup (`07` §6.1, `09` decision 11). The reason: the whole-guest backup is the guest's undo. -**OPEN Q8:** what else runs then. The controller's self-update (default 04:30, and after any hub report +**[FACT] (C10) Q8 measured** (guest UTC; demo-hp W = 02:30): db-dump 02:30, tier-2 03:30, off-site ~04:15, +whole-guest gate [04:30, 08:30), controller self-update 04:30, offsite-integrity 06:00. Host: `apt-daily` and +`apt-daily-upgrade` run daily but install nothing (no `unattended-upgrades`, no `APT::Periodic`); `pve-daily-update` +refreshes the lists daily. **Restore-tests are NOT windowed** — they run on a cadence at any hour (demo-felhom 10:38 +daily, demo-hp 16:43 and 22:46); agent updates arrive by signed job at any hour. `[PROPOSAL]` the OS leg takes the same +per-guest lane lock the restore-test and the whole-guest backup take, rather than a clock slot. + +~~**OPEN Q8:** what else runs then. The controller's self-update (default 04:30, and after any hub report when a floor is above it, R-608), the agent's self-update, the restore-tests, and PBS jobs. The OS leg -must never overlap a backup, a restore-test or a self-update. +must never overlap a backup, a restore-test or a self-update.~~ ### 5.6 How a failed update is undone @@ -198,10 +322,10 @@ must never overlap a backup, a restore-test or a self-update. | Layer | Undo | Limit | |---|---|---| -| Guest packages | Restore the guest snapshot taken just before the update | It also undoes app data written after the snapshot. Use it only inside the health window, before apps have written much. After that, install the previous version (needs OPEN Q1). | -| Docker engine | Install the previous version (Docker's repository keeps old versions — OPEN Q2) | Every container restarts again | -| Host packages | Install the previous version | Only if the source still has it (OPEN Q1/Q2) | -| Host kernel | Boot the previous kernel. Proxmox can boot a new kernel **once** (`proxmox-boot-tool kernel pin --next-boot`). If that boot fails, the next boot uses the old kernel again. Make the new kernel permanent only after a healthy boot. | If the new kernel hangs, someone must switch the box off and on. The spike checks whether a hardware watchdog can do that (OPEN Q4). | +| Guest packages | Restore the guest snapshot taken just before the update | It also undoes app data written after the snapshot. Use it only inside the health window, before apps have written much. After that, install the previous version (needs OPEN Q1). **[FACT] (C6)** Customer guests are on LVM-thin and can snapshot; scratch 9202 (`dir` storage) cannot (`snapshot feature is not available`), so the measured undo was a whole-guest backup + restore: **73 s down**, all apps healthy, libc back. The snapshot rollback itself is unmeasured (R-837). | +| Docker engine | Install the previous version (Docker's repository keeps old versions — OPEN Q2) | Every container restarts again. **[FACT] (C5)** Docker keeps 46 `docker-ce` versions. A step (either way) without `live-restore`: 6 of 6 containers restart, the app silent **26.5–30 s**, healthy at +42–45 s. With `live-restore` on: **0 restarts, no gap**, also across a containerd step. But a restart that turns `live-restore` OFF stops every container and starts NONE (`unless-stopped` ignored) — on 9202 they stayed down until restarted by hand; `systemctl reload` turns it on but not off. | +| Host packages | Install the previous version | Only if the source still has it (OPEN Q1/Q2). **[FACT]** `rsync` back to its pre-update version: `not found`; `libpng16-16t64` back to the point-release version: worked. A Debian undo needs the snapshot archive (C2). | +| Host kernel | ~~Boot the previous kernel. Proxmox can boot a new kernel **once** (`proxmox-boot-tool kernel pin --next-boot`). If that boot fails, the next boot uses the old kernel again. Make the new kernel permanent only after a healthy boot.~~ **[FACT] (C4)** Both demo hosts boot UEFI + GRUB (no proxmox-boot-tool ESPs). **Installing a kernel makes it the GRUB default at once.** `--next-boot` on GRUB writes an ordinary `GRUB_DEFAULT` + `update-grub`; `proxmox-boot-cleanup.service` clears it only once a boot reaches userspace. Measured on demo-hp (old kernel pinned permanently FIRST, new pinned for next boot): boot 1 → `7.0.14-20-pve`, healthy, 60 s; boot 2 → back on `7.0.2-6-pve`, healthy, 76 s. **So the fallback works after a boot that succeeds; read from the code, a kernel that hangs before userspace stays the default on every power cycle.** `[PROPOSAL]` use GRUB's own one-shot (`GRUB_DEFAULT=saved` + `grub-reboot`) with the old kernel as the saved default — unmeasured (R-836). | ~~If the new kernel hangs, someone must switch the box off and on. The spike checks whether a hardware watchdog can do that (OPEN Q4).~~ **[FACT]** Only `softdog` runs (loaded by `watchdog-mux`); it cannot rescue a kernel that never boots. demo-hp has an AMD FCH whose `sp5100_tco` driver ships but is not loaded; untested. A hang still needs a person. | ### 5.7 Telling people @@ -219,19 +343,19 @@ must never overlap a backup, a restore-test or a self-update. | # | What can go wrong | What the design does | |---|---|---| | 1 | A new kernel does not boot | Boot it once (`--next-boot`); the old kernel stays the default. A hard hang needs a power cycle (OPEN Q4). | -| 2 | Power cut during an update: `dpkg` is half done | The wrapper runs `dpkg --configure -a` and `apt-get -f install` first, every time, and reports what it repaired (spike measures, Q5). | +| 2 | Power cut during an update: `dpkg` is half done | The wrapper runs `dpkg --configure -a` and `apt-get -f install` first, every time, and reports what it repaired (spike measures, Q5). **[FACT] (C7)** Killed after 15 unpacks: 5 packages `iU`, 4 triggers pending; the next ordinary `apt-get install` REFUSES (`Unmet dependencies`) — nothing repairs it by itself. The two commands repaired it in 1.4 s + 3.9 s; apps stayed up. | | 3 | An update asks a question (changed config file, service restart prompt) | Non-interactive, keep the old config, report the conflict. | -| 4 | A Docker update stops every app, and the controller | Stop the apps cleanly first, like before a backup. Measure whether `live-restore` keeps containers running (Q3). The agent drives it. | +| 4 | A Docker update stops every app, and the controller | Stop the apps cleanly first, like before a backup. Measure whether `live-restore` keeps containers running (Q3). The agent drives it. **[FACT] (C5)** `live-restore` keeps them running (0 restarts). The controller keeps running too; its `docker` calls fail for the seconds dockerd is down (logged errors, no app event). Turning `live-restore` on is a golden + fleet change — and turning it off later must not be a plain restart (R-835). | | 5 | The approved version is no longer downloadable | OPEN Q1. Until it is answered, the box waits for the next approval and reports it. | | 6 | An urgent security hole | The operator approves the same day once ring 0 has run it. | | 7 | A box was off for months | It catches up through the newest approved release. It does not install every release in between. Packages are not like app data; one `apt` step is enough. Kernel and Docker still go one approved step at a time. | | 8 | The system disk is full | Check free space before downloading; clean the package cache after; refuse and report. | -| 9 | A customer box has a package that ring 0 does not have (other hardware: firmware, CPU microcode, NIC drivers) | It is never approved, so it is never updated. The box reports it as "not covered", and the hub raises it. Fix: add matching hardware to ring 0, or approve it by hand. | +| 9 | A customer box has a package that ring 0 does not have (other hardware: firmware, CPU microcode, NIC drivers) | It is never approved, so it is never updated. The box reports it as "not covered", and the hub raises it. Fix: add matching hardware to ring 0, or approve it by hand. **[FACT] (C12)** The two demo hosts differ by 7 packages: `amd64-microcode`, `proxmox-secure-boot-support`, `felhom-bootstrap` (demo-hp) vs `intel-microcode`, `proxmox-first-boot`, `tailscale`, `tailscale-archive-keyring` (demo-felhom); Secure Boot is ON on demo-hp, OFF on demo-felhom. Ring 0 covers both CPU vendors today. | | 10 | The package source is down, or its signing key changes (Docker has done this) | The update fails cleanly and the box reports it. A key change is a slow-lane act for a person. | | 11 | A BYO host | Only the guest and Docker are updated (§1). | | 12 | Two boxes on ring 0 is a small sample | Accepted for now. When there are customers, the first tester boxes can become a second ring. | | 13 | A broken-into hub sends a harmful list | The wrapper refuses removals, downgrades and new packages, and the publishers' signatures still apply (§5.4). | -| 14 | `cloudflared` on the host | Not covered by this file yet. How it is installed and updated is OPEN Q9. It faces the internet, so it matters. | +| 14 | `cloudflared` on the host | ~~Not covered by this file yet. How it is installed and updated is OPEN Q9. It faces the internet, so it matters.~~ **[FACT] (C8)** Not on the host: a pinned container in the guest (§1). Four months behind upstream on 2026-10-04 (R-838). | | 15 | The no-subscription Proxmox repository gets less testing than the enterprise one | Ring 0 is our test. The enterprise repository costs a yearly fee per box. That is a **money** decision for the operator, later (Q10). | --- @@ -253,6 +377,27 @@ must never overlap a backup, a restore-test or a self-update. --- +### 7.1 Answers — the 2026-10-04 spike `[FACT]` + +All evidence: `audits/os-updates-spike-2026-10-04/` (its `README.md` carries every number). + +| Q | Answer in one line | Detail | +|---|---|---| +| Q1 | Usually yes: Debian keeps 2 versions; no box package was re-fixed within 14 days in 3 months; the snapshot archive serves a gone version in 2 s. | C2 | +| Q2 | Yes for Proxmox (30–66 versions) and Docker (18–46); Debian only the point-release version. | C2, §5.6 | +| Q3 | Without `live-restore`: every container restarts, ~30 s of silence. With it: none. Switching it off is a trap. | C5 | +| Q4 | `--next-boot` falls back only after a boot that succeeds (measured); a hang keeps the new kernel (code). Software watchdog only. | C4 | +| Q5 | Not by itself; `dpkg --configure -a` + `apt-get -f install` repair it in ~5 s. | C7 | +| Q6 | Hosts 188 pending each, guests 54–59; guest Debian 24 s, host Debian 60 s, kernel 47 s. Three guests, three Docker versions. | audit README | +| Q7 | Few restarts by script; libc leaves PID 1, `lxc-start`, Proxmox daemons and dockerd on the old library. Proxmox packages restart their own daemons. | C11 | +| Q8 | The backup legs are windowed; restore-tests and agent updates are not; host apt timers are inert. | C10 | +| Q9 | Not a host package: a pinned guest container, 4 months behind. | C8 | +| Q10 | €120 (Community) to €1,100 (Premium) per CPU socket per year, net; every tier includes the Enterprise Repository. Money — the operator's. | audit README | + +**Sample approved list** built from what ring 0 installed (`partI/sample-approved-list.tsv`: 108 host + 49 guest +packages, with origin) and simulated read-only on demo-felhom: **all 157 would install, exact version, downloadable**; +not covered: 79 Proxmox + 1 Tailscale on the host (slow lane / not ours), 6 Docker + 4 Debian in the guest (C9). + ## 8. Build order `[PROPOSAL]` Each step returns to the operator for go or no-go. diff --git a/documentation/audits/backup-close-2026-10-04/partA/dr-beside.log b/documentation/audits/backup-close-2026-10-04/partA/dr-beside.log new file mode 100644 index 00000000..6cd1af7d --- /dev/null +++ b/documentation/audits/backup-close-2026-10-04/partA/dr-beside.log @@ -0,0 +1,19 @@ +=== felhom-agent 0.139.0 selftest=bring-up (mode=dr vmid=9297) === + --- recover: reaping any half-built guest from a prior crashed bring-up --- + recover: examined=0 bring_up_rolled_back=0 bring_up_clean=0 scratch_destroyed=0 + bringing up local:backup/vzdump-lxc-9201-2026_10_04-04_34_55.tar.zst → vmid 9297 on nvme-scratch … + --- bring-up record --- + { + "VMID": 9297, + "AssignedMAC": "", + "Hostname": "", + "Pass": false, + "Verified": "", + "Err": {}, + "StartedAt": "2026-10-04T06:59:11.397594956Z", + "Duration": 118096279, + "StartWarnings": null, + "WarningsRecognized": false + } + [FAIL] bring-up (vmid 9297): reconcile: dr bring-up refused: the archive's source guest 9201 still exists on this host (status running) — a DR restore beside a live original would run two boxes on the same drives (R-834) +rc=1 diff --git a/documentation/audits/backup-close-2026-10-04/partB/hub-redproofs.txt b/documentation/audits/backup-close-2026-10-04/partB/hub-redproofs.txt index a05299ad..099381a7 100644 --- a/documentation/audits/backup-close-2026-10-04/partB/hub-redproofs.txt +++ b/documentation/audits/backup-close-2026-10-04/partB/hub-redproofs.txt @@ -8,3 +8,10 @@ RP3 close check uses the default cap instead of the window's own: RP4 the box API window-open sets a grant from a max_remove in its body: --- FAIL: TestOffsiteWindow_BoxCannotGrantItself — a box call left a grant (ok=true max=400) After revert: ok internal/offsitekeys, ok internal/api + +# Live on hub v0.129.0 (2026-10-04), operator Basic auth, POST /offsite/window-grant/ — every bad grant refused, nothing stored: +demo-hp-bb76ea max_remove=abc -> 400 max_remove must be a number +demo-hp-bb76ea max_remove=0 -> 400 offsitekeys: max_remove 0 is outside 1..500 +demo-hp-bb76ea max_remove=501 -> 400 offsitekeys: max_remove 501 is outside 1..500 +no-such-customer max_remove=10 -> 400 offsitekeys: no customer "no-such-customer" +A valid grant was NOT placed on a real customer: it would be consumed by that demo box's next window (the brief: lab repo only). diff --git a/documentation/audits/os-updates-spike-2026-10-04/README.md b/documentation/audits/os-updates-spike-2026-10-04/README.md new file mode 100644 index 00000000..0286e73b --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/README.md @@ -0,0 +1,84 @@ +# OS-updates spike — 2026-10-04 (answers `architecture/11-os-updates.md` §7 Q1–Q10) + +Venues: demo-hp host + its 9201 + scratch 9202 (changes: 9202 Part G, demo-hp host Part H); demo-felhom host + 9201 +(read only). Apt indexes for every read-only step went to a throwaway directory (`scripts/os-survey.sh`), so no +box's lists or sources changed. Hosts are CEST, guests UTC. + +| Folder | What | +|---|---| +| `partE/` | read-only surveys of five systems (`*-host.txt`, `*-guest.txt`), host package-set diff | +| `partF/` | `apt-cache madison` (host + guest), Debian DSA re-announcement analysis, snapshot.debian.org probe | +| `partG/` | 9202: Debian update, undo, killed update, Docker step ×3 — `SUMMARY.md` | +| `partH/` | demo-hp host: package lists before/after, Debian-lane run, one-package undo, kernel install + 2 reboots, Proxmox simulation | +| `partI/` | sample approved list (`sample-approved-list.tsv`) and its read-only simulation on demo-felhom | +| `scripts/` | every helper used, as run | + +## The answers + +**Q1 — exact Debian version a week later.** The live Debian archives keep **two** versions of a package at most: the +point-release version in `trixie` (main) and the newest in `trixie-security` — never the intermediate ones +(`partF/madison-demo-hp-host.txt`: openssl installed `u1`, main `u2`, security `u3`; `u1` is gone). DSA history, +2026-07-04..10-04 (`partF/dsa-supersede-analysis.txt`): 167 trixie advisories; a second advisory for the same package +within 2 days: **3 (1.8 %), all chromium/webkit2gtk — none of them on a box**. Restricted to the 517 source packages +installed on a box: 20 advisories over 16 packages, **0 re-announced within 2, 7 or 14 days**. `snapshot.debian.org` +is reachable from a box: a dated `apt-get update` takes **2.3–3.0 s** (10.1 MB), and the exact gone version +`openssl 3.5.6-1~deb13u1` downloads in **2.0 s** (`partF/snapshot-debian-org.md`; https needs `ca-certificates`, +present on boxes, absent in the bare `debian:trixie` image). + +**Q2 — Proxmox and Docker keep old versions.** Yes, many: `pve-manager` 66, `qemu-server` 58, `proxmox-kernel-7.0` +33, `pve-container` 32, `docker-ce` 46, `containerd.io` 18 versions listed. Debian: two at most (Q1). One host undo +measured: `rsync` back to its pre-update `3.4.1+ds1-5+deb13u2` → `E: Version … was not found`; `libpng16-16t64` back +to `1.6.48-1+deb13u5` worked because that version is the point-release one in main (`partH/H3-undo-one-package.txt`). + +**Q3 — Docker engine update.** Without `live-restore` (today's baked setting): all 6 containers restart, the app's +front door is silent **26.5–30 s**, everything healthy **+42–45 s**. With `live-restore`: **0 restarts, no gap**, +also across a containerd change. `systemctl reload` turns it ON; it does NOT turn it off; and a restart that turns it +off **stops every running container and starts none of them** (`partG/SUMMARY.md`). + +**Q4 — kernel.** Both demo hosts: UEFI, GRUB (no proxmox-boot-tool ESPs), root on LVM ext4; demo-hp has Secure Boot ON, +demo-felhom OFF (setup mode). Installing a kernel makes it the GRUB default at once (`GRUB_DEFAULT=0`, newest first). +`proxmox-boot-tool kernel pin --next-boot` on GRUB writes a normal `GRUB_DEFAULT` + `update-grub` (GRUB's own +one-shot `next_entry` stays empty); `proxmox-boot-cleanup.service` removes it **after a boot reaches userspace**. +Measured on demo-hp with the operator's word: old kernel pinned permanently first, new pinned for next boot → reboot +1 came up on `7.0.14-20-pve` (60 s, Secure Boot on, all healthy); reboot 2 came back on `7.0.2-6-pve` (76 s). **So the +fallback works after a SUCCESSFUL boot; read from the code (not measured), a kernel that hangs before userspace stays +the default.** Watchdog: only `softdog` is loaded (by `watchdog-mux`); demo-hp has an AMD FCH (SMBus 00:14.0) and the +`sp5100_tco` module ships with the kernel, not loaded. A softdog cannot rescue a kernel that never boots. + +**Q5 — interrupted apt.** Killed after 15 unpacks: 5 packages `iU`, 4 triggers pending. It does NOT recover by itself — +the next `apt-get install` refuses (`Unmet dependencies. Try 'apt --fix-broken install'`). `dpkg --configure -a` +(1.4 s) + `apt-get -f install` (3.9 s) repaired it; the rest applied in 14.1 s. Containers stayed up throughout. + +**Q6 — how far behind.** Hosts: 188 pending each (80/79 Proxmox, 66 Debian point release, 27 both, 15 security, +1 +tailscale on demo-felhom); guests: 59 (31 point, 15 both, 7 security, 6 Docker) on both 9201s, 54 on 9202. Installed: +host 746/747 packages, guest 278. Each guest runs a DIFFERENT Docker (29.7.1, 29.7.2, 29.8.0; golden 0.290.0 bakes +29.8.2). Catching up: guest Debian 24.0 s / 38.1 MB; host Debian 59.7 s / 76 MB; the kernel 47 s / 131 MB. + +**Q7 — what restarts.** Guest Debian run: postfix, journald, networkd restarted by their scripts; dockerd, containerd, +sshd, dbus, logind, cron, dhclient keep the OLD libc until restarted. Host Debian run: dnsmasq, postfix, journald +restarted; **systemd (PID 1), lxc-start, pveproxy, pvedaemon, pvestatd, pvescheduler, watchdog-mux, sshd, zed, chronyd** +keep the old libc. Proxmox packages (simulated, from their own maintainer scripts): pve-manager → pvedaemon, pveproxy, +pvestatd, pvescheduler, spiceproxy; pve-cluster → pmxcfs; corosync; chrony; qemu-server → qmeventd; pve-firewall; +pve-ha-manager → lrm, crm; zfs-zed. + +**Q8 — the night window.** Guest (UTC, demo-hp, W = 02:30): db-dump 02:30, tier-2 03:30, off-site ~04:15, whole-guest +gate [04:30, 08:30), controller self-update 04:30, offsite-integrity 06:00. Host (CEST): `apt-daily` and +`apt-daily-upgrade` timers are enabled but install nothing (no `unattended-upgrades`, no `APT::Periodic`); +`pve-daily-update` refreshes the lists daily; **restore-tests run at any hour** (demo-felhom 10:38 daily, demo-hp +16:43 and 22:46) — they are cadence-driven, not windowed; agent updates arrive by signed job at any hour. + +**Q9 — cloudflared.** Not on the host: a container in the guest, `cloudflare/cloudflared:2026.6.0`, pinned in the +controller (`internal/infra/infra.go:26`) since 2026-06-11 (v0.41.0) and baked into the golden. Upstream is at +`2026.9.3` (2026-09-24). It moves only when someone edits the pin. + +**Q10 — Proxmox enterprise repository** (proxmox.com pricing page, 2026-10-04, net, per CPU socket per year): +Community €120, Basic €370, Standard €550, Premium €1,100. Every tier includes the Enterprise Repository; Community +has no support tickets. Record only — a money decision. + +## Teardown +- 9202: Debian fully updated, Docker 29.8.2 / containerd 2.3.6 (= golden 0.290.0), `daemon.json` byte-identical to the + baked one, live-restore false, all 6 containers healthy. Its backup in `/mnt/hdd_1/dump-9202-spike` deleted. +- demo-hp host: 108 Debian packages updated + `proxmox-kernel-7.0.14-20-pve-signed` installed (110 package changes, + `partH/H-final-host-packages-after.tsv`); running `7.0.2-6-pve`, **next boot `7.0.14-20-pve`** (no pins left). + Proxmox packages NOT updated (78 pending). +- Helper files removed from both hosts and all guests; no throwaway image or container left. diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-9201-guest.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-9201-guest.txt new file mode 100644 index 00000000..3afcdd14 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-9201-guest.txt @@ -0,0 +1,156 @@ +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +### label: 9201-guest host: demo-felhom date: 2026-10-04T07:01:33Z +### os +PRETTY_NAME="Debian GNU/Linux 13 (trixie)" +VERSION_ID="13" +VERSION_CODENAME=trixie +debian_version: 13.6 +7.0.2-6-pve +### packages installed: 278 +### apt sources (URIs and suites only) +-- /etc/apt/sources.list.d/debian.sources +URIs: http://security.debian.org +Suites: trixie-security +Components: contrib main +URIs: http://deb.debian.org/debian +Suites: trixie trixie-updates +Components: contrib main +-- /etc/apt/sources.list.d/docker.list +deb [signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian trixie stable +### system apt lists age (newest *_InRelease mtime) +### apt-get update into a throwaway dir +update_rc=0 seconds=4.7 +W: Download is performed unsandboxed as root as file '/tmp/os-survey.kMaVmq/lists/partial/security.debian.org_dists_trixie-security_InRelease' couldn't be accessed by user '_apt'. - pkgAcquire::Run (13: Permission denied) +### simulate upgrade: rc=0 Inst=59 Remv=0 +### simulate dist-upgrade: rc=0 Inst=59 Remv=0 +### pending (dist-upgrade) by origin + 31 Debian:13.7/stable + 15 Debian-Security:13/stable-security, Debian:13.7/stable + 7 Debian-Security:13/stable-security + 6 Docker CE:trixie +### pending list (pkg old -> new origin) +libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +base-files 13.8+deb13u6 -> 13.8+deb13u7 [Debian:13.7/stable [amd64]] +bash 5.2.37-2+b9 -> 5.2.37-2+b10 [Debian:13.7/stable [amd64]] +bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +gzip 1.13-1 -> 1.13-1+deb13u1 [Debian:13.7/stable [amd64]] +libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [all]] +liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libblkid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libmount1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +mount 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +fdisk 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libuuid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [all]] +libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [amd64]] +libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +logsave 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +docker-ce-cli 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +containerd.io 2.2.6-1~debian.13~trixie -> 2.3.6-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-ce 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +openssl-provider-legacy 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libssl3t64 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +postfix 3.10.12-0+deb13u2 -> 3.10.13-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +python3.13 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-stdlib 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +python3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 [Debian:13.7/stable [all]] +libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +dhcpcd-base 1:10.1.0-11+deb13u3 -> 1:10.1.0-11+deb13u4 [Debian:13.7/stable [amd64]] +bind9-dnsutils 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-host 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-libs 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +libssh2-1t64 1.11.1-1+deb13u1 -> 1.11.1-1+deb13u2 [Debian:13.7/stable [amd64]] +curl 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libcurl4t64 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +docker-buildx-plugin 0.36.0-1~debian.13~trixie -> 0.37.1-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-ce-rootless-extras 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-compose-plugin 5.3.1-1~debian.13~trixie -> 5.6.0-1~debian.13~trixie [Docker CE:trixie [amd64]] +libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libcurl3t64-gnutls 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libss2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +openssl 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +### new packages pulled (not installed now) +### kernel / proxmox / docker packages installed +containerd.io 2.2.6-1~debian.13~trixie +docker-buildx-plugin 0.36.0-1~debian.13~trixie +docker-ce 5:29.7.1-1~debian.13~trixie +docker-ce-cli 5:29.7.1-1~debian.13~trixie +docker-ce-rootless-extras 5:29.7.1-1~debian.13~trixie +docker-compose-plugin 5.3.1-1~debian.13~trixie +### unattended-upgrades / needrestart +unattended-upgrades not installed +needrestart not installed +apt-listchanges 4.8 ii +unattended-upgrades.service enabled: not-found +### timers +NEXT LEFT LAST PASSED UNIT ACTIVATES +Sun 2026-10-04 08:19:13 UTC 1h 17min Sat 2026-10-03 08:19:13 UTC 22h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Sun 2026-10-04 08:39:26 UTC 1h 37min Sat 2026-10-03 06:41:13 UTC 24h ago man-db.timer man-db.service +Mon 2026-10-05 00:00:00 UTC 16h Sun 2026-10-04 00:00:38 UTC 7h ago dpkg-db-backup.timer dpkg-db-backup.service +Mon 2026-10-05 00:17:44 UTC 17h Sun 2026-10-04 00:58:38 UTC 6h ago logrotate.timer logrotate.service +Mon 2026-10-05 02:53:32 UTC 19h Sun 2026-10-04 06:34:13 UTC 27min ago apt-daily.timer apt-daily.service +Mon 2026-10-05 06:10:13 UTC 23h Sun 2026-10-04 06:51:38 UTC 10min ago apt-daily-upgrade.timer apt-daily-upgrade.service +Sun 2026-10-11 03:10:57 UTC 6 days Sun 2026-10-04 03:10:38 UTC 3h 51min ago e2scrub_all.timer e2scrub_all.service +- - - - fstrim.timer fstrim.service + +8 timers listed. +### cron +e2scrub_all +### apt periodic config +### end diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-host.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-host.txt new file mode 100644 index 00000000..1411ebe5 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-felhom-host.txt @@ -0,0 +1,309 @@ +### label: demo-felhom-host host: demo-felhom date: 2026-10-04T07:00:58Z +### os +PRETTY_NAME="Debian GNU/Linux 13 (trixie)" +VERSION_ID="13" +VERSION_CODENAME=trixie +debian_version: 13.5 +7.0.2-6-pve +### packages installed: 747 +### apt sources (URIs and suites only) +-- /etc/apt/sources.list.d/ceph.sources +URIs: https://enterprise.proxmox.com/debian/ceph-squid +Suites: trixie +Components: enterprise +Enabled: no +-- /etc/apt/sources.list.d/debian.sources +URIs: http://deb.debian.org/debian/ +Suites: trixie trixie-updates +Components: main contrib non-free-firmware +URIs: http://security.debian.org/debian-security/ +Suites: trixie-security +Components: main contrib non-free-firmware +-- /etc/apt/sources.list.d/pve-enterprise.sources +URIs: https://enterprise.proxmox.com/debian/pve +Suites: trixie +Components: pve-enterprise +Enabled: no +-- /etc/apt/sources.list.d/pve-no-subscription.sources +URIs: http://download.proxmox.com/debian/pve +Suites: trixie +Components: pve-no-subscription +-- /etc/apt/sources.list.d/tailscale.list +deb [signed-by=/usr/share/keyrings/tailscale-archive-keyring.gpg] https://pkgs.tailscale.com/stable/debian trixie main +### system apt lists age (newest *_InRelease mtime) +2026-10-04 04:12:13.000000000 +0200 /var/lib/apt/lists/deb.debian.org_debian_dists_trixie-updates_InRelease +### apt-get update into a throwaway dir +update_rc=0 seconds=3.3 +W: Download is performed unsandboxed as root as file '/tmp/os-survey.wFYNfA/lists/partial/deb.debian.org_debian_dists_trixie_InRelease' couldn't be accessed by user '_apt'. - pkgAcquire::Run (13: Permission denied) +### simulate upgrade: rc=0 Inst=184 Remv=0 +The following packages have been kept back: + proxmox-kernel-7.0 pve-firewall +The following packages will be upgraded: + base-files bash bind9-dnsutils bind9-host bind9-libs bsdextrautils bsdutils +### simulate dist-upgrade: rc=0 Inst=188 Remv=0 +### pending (dist-upgrade) by origin + 79 Proxmox Debian Repository:stable + 66 Debian:13.7/stable + 27 Debian:13.7/stable, Debian-Security:13/stable-security + 15 Debian-Security:13/stable-security + 1 Tailscale:pkgs.tailscale.com +### pending list (pkg old -> new origin) +libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +base-files 13.8+deb13u5 -> 13.8+deb13u7 [Debian:13.7/stable [amd64]] +bash 5.2.37-2+b9 -> 5.2.37-2+b10 [Debian:13.7/stable [amd64]] +bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +gzip 1.13-1 -> 1.13-1+deb13u1 [Debian:13.7/stable [amd64]] +libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [all]] +liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +eject 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +fdisk 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libblkid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libmount1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +mount 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libuuid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +util-linux 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [all]] +libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [amd64]] +sqlite3 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +logsave 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +dnsmasq-base 2.91-1+deb13u1 -> 2.91-1+deb13u2 [Debian:13.7/stable [amd64]] +dnsmasq 2.91-1+deb13u1 -> 2.91-1+deb13u2 [Debian:13.7/stable [all]] +libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libpcre2-posix3 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +frr 10.6.1-1+pve2 -> 10.6.1-1+pve3 [Proxmox Debian Repository:stable [amd64]] +libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +openssl-provider-legacy 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libssl3t64 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +postfix 3.10.5-1~deb13u1 -> 3.10.13-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +python3.13 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-stdlib 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +python3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 [Debian:13.7/stable [all]] +liblzma5 5.8.1-1 -> 5.8.1-1+deb13u1 [Debian:13.7/stable [amd64]] +rsync 3.4.1+ds1-5+deb13u2 -> 3.5.0+ds1-0+deb13u1 [Debian-Security:13/stable-security [amd64]] +openssl 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +shim-signed-common 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 [Proxmox Debian Repository:stable [all]] +shim-unsigned 16.1-1+pmx1 -> 16.1-2+pmx1 [Proxmox Debian Repository:stable [amd64]] +shim-helpers-amd64-signed 1+16.1+1+pmx1 -> 1+16.1+2+pmx1 [Proxmox Debian Repository:stable [amd64]] +shim-signed 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 [Proxmox Debian Repository:stable [amd64]] +dhcpcd-base 1:10.1.0-11+deb13u2 -> 1:10.1.0-11+deb13u4 [Debian:13.7/stable [amd64]] +libgssapi-krb5-2 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libkrb5-3 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libkrb5support0 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libk5crypto3 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2 -> 2.12.7+dfsg+really2.9.14-2.1+deb13u3 [Debian:13.7/stable [amd64]] +bind9-dnsutils 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-host 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-libs 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +krb5-locales 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +xz-utils 5.8.1-1 -> 5.8.1-1+deb13u1 [Debian:13.7/stable [amd64]] +busybox 1:1.37.0-6+b8 -> 1:1.37.0-6+b9 [Debian:13.7/stable [amd64]] +libradosstriper1 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +curl 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libssh2-1t64 1.11.1-1 -> 1.11.1-1+deb13u2 [Debian:13.7/stable [amd64]] +libcurl4t64 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +librabbitmq4 0.15.0-1 -> 0.15.0-1+deb13u2 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +librgw2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +ceph-common 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +librbd1 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +librados2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-cephfs 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +libcephfs2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-rgw 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-rados 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-ceph-argparse 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [all]] +python3-ceph-common 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [all]] +python3-rbd 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +ceph-fuse 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +chrony 4.6.1-3+deb13u1 -> 4.8-4~bpo13+2 [Proxmox Debian Repository:stable [amd64]] +libcorosync-common4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcfg7 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcmap4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcpg4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libnss3 2:3.110-1+deb13u1 -> 2:3.110-1+deb13u4 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libknet1t64 1.31-pve1 -> 1.35-pve2 [Proxmox Debian Repository:stable [amd64]] +libnozzle1t64 1.31-pve1 -> 1.35-pve2 [Proxmox Debian Repository:stable [amd64]] +libquorum5 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libvotequorum8 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +corosync 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libgcrypt20 1.11.0-7 -> 1.11.0-7+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +gpgsm 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +dirmngr 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpg 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpgconf 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpg-agent 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +frr-pythontools 10.6.1-1+pve2 -> 10.6.1-1+pve3 [Proxmox Debian Repository:stable [all]] +libasound2t64 1.2.14-1 -> 1.2.14-1+deb13u1 [Debian:13.7/stable [amd64]] +libasound2-data 1.2.14-1 -> 1.2.14-1+deb13u1 [Debian:13.7/stable [all]] +libbytes-random-secure-perl 0.29-3 -> 0.29-4~deb13u1 [Debian:13.7/stable [all]] +libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libcurl3t64-gnutls 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libevent-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libevent-core-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libgbm1 25.0.7-2 -> 25.0.7-2+deb13u1 [Debian:13.7/stable [amd64]] +mesa-libgallium 25.0.7-2 -> 25.0.7-2+deb13u1 [Debian:13.7/stable [amd64]] +libglib2.0-0t64 2.84.4-3~deb13u3 -> 2.84.4-3~deb13u5 [Debian:13.7/stable [amd64]] +libgraphite2-3 1.3.14-2+b1 -> 1.3.14-2+deb13u1 [Debian:13.7/stable [amd64]] +libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u1 -> 1.26.2-1+deb13u2 [Debian-Security:13/stable-security [amd64]] +libhtml-parser-perl 3.83-1+b2 -> 3.83-2~deb13u1 [Debian:13.7/stable [amd64]] +libhttp-daemon-perl 6.16-1 -> 6.16-1+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libjs-extjs 7.0.0-5 -> 7.0.0-7 [Proxmox Debian Repository:stable [all]] +libtalloc2 2:2.4.3+samba4.22.8+dfsg-0+deb13u1 -> 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libtevent0t64 2:0.16.2+samba4.22.8+dfsg-0+deb13u1 -> 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libsmbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +samba-common 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [all]] +smbclient 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libtdb1 2:1.4.13+samba4.22.8+dfsg-0+deb13u1 -> 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libldb2 2:2.11.0+samba4.22.8+dfsg-0+deb13u1 -> 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +samba-libs 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libwbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libnet-dns-perl 1.50-1 -> 1.56-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libnvpair3linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libpcre2-16-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libpng16-16t64 1.6.48-1+deb13u5 -> 1.6.48-1+deb13u6 [Debian-Security:13/stable-security [amd64]] +libproxmox-acme-plugins 1.7.1 -> 1.7.2 [Proxmox Debian Repository:stable [all]] +libproxmox-backup-qemu0 2.0.2 -> 2.0.3 [Proxmox Debian Repository:stable [amd64]] +libslirp0 4.8.0-1+b1 -> 4.8.0-1+deb13u1 [Debian:13.7/stable [amd64]] +pve-qemu-kvm 11.0.0-3 -> 11.0.3-4 [Proxmox Debian Repository:stable [amd64]] +libpve-notify-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +libpve-cluster-api-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +libpve-cluster-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +pve-cluster 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [amd64]] +libpve-access-control 9.1.1 -> 9.1.2 [Proxmox Debian Repository:stable [all]] +libpve-apiclient-perl 3.4.2 -> 3.4.3 [Proxmox Debian Repository:stable [all]] +librados2-perl 1.5.0 -> 1.5.1 [Proxmox Debian Repository:stable [amd64]] +libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+b2 -> 2.0207+dfsg+really+2.0134-5+deb13u1 [Debian:13.7/stable [amd64]] +proxmox-backup-client 4.2.0-1 -> 4.2.7-1 [Proxmox Debian Repository:stable [amd64]] +proxmox-backup-file-restore 4.2.0-1 -> 4.2.7-1 [Proxmox Debian Repository:stable [amd64]] +pve-manager 9.2.2 -> 9.2.21 [Proxmox Debian Repository:stable [all]] +libproxmox-acme-perl 1.7.1 -> 1.7.2 [Proxmox Debian Repository:stable [all]] +libpve-common-perl 9.1.12 -> 9.2.2 [Proxmox Debian Repository:stable [all]] +libpve-guest-common-perl 6.0.3 -> 6.0.5 [Proxmox Debian Repository:stable [all]] +qemu-server 9.1.15 -> 9.2.10 [Proxmox Debian Repository:stable [amd64]] +libpve-storage-perl 9.1.5 -> 9.1.11 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-legacy 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-ovmf 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +libpve-network-api-perl 1.6.5 -> 1.6.7 [Proxmox Debian Repository:stable [all]] +libpve-network-perl 1.6.5 -> 1.6.7 [Proxmox Debian Repository:stable [all]] +proxmox-firewall-data (new) -> 0.1 [Proxmox Debian Repository:stable [all]] +pve-firewall 6.0.4 -> 6.0.6 [Proxmox Debian Repository:stable [amd64]] +pve-container 6.1.10 -> 6.1.14 [Proxmox Debian Repository:stable [all]] +pve-ha-manager 5.2.4 -> 5.2.5 [Proxmox Debian Repository:stable [amd64]] +socat 1.8.0.3-1 -> 1.8.0.3-1+deb13u1 [Debian:13.7/stable [amd64]] +novnc-pve 1.7.0-1 -> 1.7.0-2 [Proxmox Debian Repository:stable [all]] +proxmox-enterprise-support-keyring 1.0 -> 1.1 [Proxmox Debian Repository:stable [all]] +proxmox-mini-journalreader 1.6 -> 1.7 [Proxmox Debian Repository:stable [amd64]] +proxmox-widget-toolkit 5.2.2 -> 5.2.10 [Proxmox Debian Repository:stable [all]] +pve-docs 9.2.1 -> 9.2.13 [Proxmox Debian Repository:stable [all]] +pve-i18n 3.7.4 -> 3.10.0 [Proxmox Debian Repository:stable [all]] +pve-xtermjs 6.0.0-1 -> 6.0.0-2 [Proxmox Debian Repository:stable [all]] +pve-yew-mobile-i18n 3.7.4 -> 3.10.0 [Proxmox Debian Repository:stable [all]] +pve-yew-mobile-gui 0.7.0 -> 0.8.0 [Proxmox Debian Repository:stable [amd64]] +libss2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libtasn1-6 4.20.0-2 -> 4.20.0-2+deb13u1 [Debian:13.7/stable [amd64]] +libunbound8 1.22.0-2+deb13u2 -> 1.26.1-0+deb13u1 [Debian-Security:13/stable-security [amd64]] +libuutil3linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libzfs7linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libzpool7linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +proxmox-first-boot 9.2.5 -> 9.2.8 [Proxmox Debian Repository:stable [amd64]] +pve-firmware 3.18-3 -> 3.18-6 [Proxmox Debian Repository:stable [all]] +proxmox-kernel-7.0.14-20-pve-signed (new) -> 7.0.14-20 [Proxmox Debian Repository:stable [amd64]] +proxmox-kernel-7.0 7.0.2-6 -> 7.0.14-20 [Proxmox Debian Repository:stable [amd64]] +proxmox-kernel-helper 9.1.0+fde2 -> 9.2.0 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-aarch64 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +python3-idna 3.10-1 -> 3.10-1+deb13u1 [Debian:13.7/stable [all]] +python3-urllib3 2.3.0-3+deb13u1 -> 2.3.0-3+deb13u2 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +xfsprogs 6.13.0-2+b1 -> 6.13.0-2+deb13u1 [Debian:13.7/stable [amd64]] +zfs-initramfs 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [all]] +zfsutils-linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +zfs-zed 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +tailscale 1.102.2 -> 1.102.4 [Tailscale:pkgs.tailscale.com [amd64]] +### new packages pulled (not installed now) +proxmox-firewall-data +proxmox-kernel-7.0.14-20-pve-signed +### kernel / proxmox / docker packages installed +lxc-pve 7.0.0-2 +proxmox-archive-keyring 4.0 +proxmox-backup-client 4.2.0-1 +proxmox-backup-file-restore 4.2.0-1 +proxmox-backup-restore-image 1.0.0 +proxmox-default-kernel 2.1.0 +proxmox-enterprise-support-keyring 1.0 +proxmox-firewall 1.2.3 +proxmox-first-boot 9.2.5 +proxmox-grub 2.12-9+pmx2 +proxmox-kernel-7.0 7.0.2-6 +proxmox-kernel-7.0.2-6-pve-signed 7.0.2-6 +proxmox-kernel-helper 9.1.0+fde2 +proxmox-mail-forward 1.0.3 +proxmox-mini-journalreader 1.6 +proxmox-offline-mirror-docs 0.7.4 +proxmox-offline-mirror-helper 0.7.4 +proxmox-termproxy 2.1.0 +proxmox-ve 9.2.0 +proxmox-websocket-tunnel 1.0.0 +proxmox-widget-toolkit 5.2.2 +pve-cluster 9.1.5 +pve-container 6.1.10 +pve-docs 9.2.1 +pve-edk2-firmware 4.2025.05-2 +pve-edk2-firmware-aarch64 4.2025.05-2 +pve-edk2-firmware-legacy 4.2025.05-2 +pve-edk2-firmware-ovmf 4.2025.05-2 +pve-esxi-import-tools 1.0.1 +pve-firewall 6.0.4 +pve-firmware 3.18-3 +pve-ha-manager 5.2.4 +pve-i18n 3.7.4 +pve-lxc-syscalld 2.0.2 +pve-manager 9.2.2 +pve-nvidia-vgpu-helper 0.3.1 +pve-qemu-kvm 11.0.0-3 +pve-xtermjs 6.0.0-1 +pve-yew-mobile-gui 0.7.0 +pve-yew-mobile-i18n 3.7.4 +qemu-server 9.1.15 +### unattended-upgrades / needrestart +unattended-upgrades not installed +needrestart not installed +apt-listchanges 4.8 ii +unattended-upgrades.service enabled: not-found +### timers +NEXT LEFT LAST PASSED UNIT ACTIVATES +Sun 2026-10-04 09:01:14 CEST 5s Sun 2026-10-04 09:00:14 CEST 54s ago felhom-mgmt-watchdog.timer felhom-mgmt-watchdog.service +Sun 2026-10-04 09:46:16 CEST 45min Sat 2026-10-03 09:46:16 CEST 23h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Sun 2026-10-04 11:56:35 CEST 2h 55min Sun 2026-10-04 05:29:44 CEST 3h 31min ago apt-daily.timer apt-daily.service +Mon 2026-10-05 00:00:00 CEST 14h Sun 2026-10-04 00:00:16 CEST 9h ago dpkg-db-backup.timer dpkg-db-backup.service +Mon 2026-10-05 00:01:27 CEST 15h Sun 2026-10-04 00:40:16 CEST 8h ago logrotate.timer logrotate.service +Mon 2026-10-05 00:46:18 CEST 15h Mon 2026-09-28 01:38:08 CEST 6 days ago fstrim.timer fstrim.service +Mon 2026-10-05 01:42:31 CEST 16h Sun 2026-10-04 05:54:16 CEST 3h 6min ago man-db.timer man-db.service +Mon 2026-10-05 05:36:19 CEST 20h Sun 2026-10-04 05:22:04 CEST 3h 39min ago pve-daily-update.timer pve-daily-update.service +Mon 2026-10-05 06:35:21 CEST 21h Sun 2026-10-04 06:47:16 CEST 2h 13min ago apt-daily-upgrade.timer apt-daily-upgrade.service +Sun 2026-10-11 03:10:27 CEST 6 days Sun 2026-10-04 03:10:44 CEST 5h 50min ago xfs_scrub_all.timer xfs_scrub_all.service +Sun 2026-10-11 03:10:40 CEST 6 days Sun 2026-10-04 03:10:44 CEST 5h 50min ago e2scrub_all.timer e2scrub_all.service + +11 timers listed. +### cron +e2scrub_all +vzdump +zfsutils-linux +### apt periodic config +### end diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9201-guest.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9201-guest.txt new file mode 100644 index 00000000..691cde17 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9201-guest.txt @@ -0,0 +1,156 @@ +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +### label: 9201-guest host: demo-hp date: 2026-10-04T07:01:34Z +### os +PRETTY_NAME="Debian GNU/Linux 13 (trixie)" +VERSION_ID="13" +VERSION_CODENAME=trixie +debian_version: 13.6 +7.0.2-6-pve +### packages installed: 278 +### apt sources (URIs and suites only) +-- /etc/apt/sources.list.d/debian.sources +URIs: http://security.debian.org +Suites: trixie-security +Components: contrib main +URIs: http://deb.debian.org/debian +Suites: trixie trixie-updates +Components: contrib main +-- /etc/apt/sources.list.d/docker.list +deb [signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian trixie stable +### system apt lists age (newest *_InRelease mtime) +### apt-get update into a throwaway dir +update_rc=0 seconds=4.7 +W: Download is performed unsandboxed as root as file '/tmp/os-survey.ZieNpo/lists/partial/security.debian.org_dists_trixie-security_InRelease' couldn't be accessed by user '_apt'. - pkgAcquire::Run (13: Permission denied) +### simulate upgrade: rc=0 Inst=59 Remv=0 +### simulate dist-upgrade: rc=0 Inst=59 Remv=0 +### pending (dist-upgrade) by origin + 31 Debian:13.7/stable + 15 Debian-Security:13/stable-security, Debian:13.7/stable + 7 Debian-Security:13/stable-security + 6 Docker CE:trixie +### pending list (pkg old -> new origin) +libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +base-files 13.8+deb13u6 -> 13.8+deb13u7 [Debian:13.7/stable [amd64]] +bash 5.2.37-2+b9 -> 5.2.37-2+b10 [Debian:13.7/stable [amd64]] +bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +gzip 1.13-1 -> 1.13-1+deb13u1 [Debian:13.7/stable [amd64]] +libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [all]] +liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libblkid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libmount1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +mount 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +fdisk 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libuuid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [all]] +libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [amd64]] +libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +logsave 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +docker-ce-cli 5:29.7.2-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +containerd.io 2.3.3-1~debian.13~trixie -> 2.3.6-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-ce 5:29.7.2-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +openssl-provider-legacy 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libssl3t64 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +postfix 3.10.12-0+deb13u2 -> 3.10.13-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +python3.13 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-stdlib 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +python3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 [Debian:13.7/stable [all]] +libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +dhcpcd-base 1:10.1.0-11+deb13u3 -> 1:10.1.0-11+deb13u4 [Debian:13.7/stable [amd64]] +bind9-dnsutils 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-host 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-libs 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +libssh2-1t64 1.11.1-1+deb13u1 -> 1.11.1-1+deb13u2 [Debian:13.7/stable [amd64]] +curl 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libcurl4t64 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +docker-buildx-plugin 0.36.1-1~debian.13~trixie -> 0.37.1-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-ce-rootless-extras 5:29.7.2-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-compose-plugin 5.5.0-1~debian.13~trixie -> 5.6.0-1~debian.13~trixie [Docker CE:trixie [amd64]] +libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libcurl3t64-gnutls 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libss2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +openssl 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +### new packages pulled (not installed now) +### kernel / proxmox / docker packages installed +containerd.io 2.3.3-1~debian.13~trixie +docker-buildx-plugin 0.36.1-1~debian.13~trixie +docker-ce 5:29.7.2-1~debian.13~trixie +docker-ce-cli 5:29.7.2-1~debian.13~trixie +docker-ce-rootless-extras 5:29.7.2-1~debian.13~trixie +docker-compose-plugin 5.5.0-1~debian.13~trixie +### unattended-upgrades / needrestart +unattended-upgrades not installed +needrestart not installed +apt-listchanges 4.8 ii +unattended-upgrades.service enabled: not-found +### timers +NEXT LEFT LAST PASSED UNIT ACTIVATES +Sun 2026-10-04 09:37:50 UTC 2h 36min Sat 2026-10-03 23:26:24 UTC 7h ago apt-daily.timer apt-daily.service +Sun 2026-10-04 13:56:52 UTC 6h Sat 2026-10-03 13:56:52 UTC 17h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Mon 2026-10-05 00:00:00 UTC 16h Sun 2026-10-04 00:00:03 UTC 7h ago dpkg-db-backup.timer dpkg-db-backup.service +Mon 2026-10-05 00:06:27 UTC 17h Sun 2026-10-04 02:43:52 UTC 4h 17min ago man-db.timer man-db.service +Mon 2026-10-05 00:40:18 UTC 17h Sun 2026-10-04 00:29:42 UTC 6h ago logrotate.timer logrotate.service +Mon 2026-10-05 06:46:33 UTC 23h Sun 2026-10-04 06:13:24 UTC 48min ago apt-daily-upgrade.timer apt-daily-upgrade.service +Sun 2026-10-11 03:10:18 UTC 6 days Sun 2026-10-04 03:11:24 UTC 3h 50min ago e2scrub_all.timer e2scrub_all.service +- - - - fstrim.timer fstrim.service + +8 timers listed. +### cron +e2scrub_all +### apt periodic config +### end diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9202-guest.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9202-guest.txt new file mode 100644 index 00000000..4b28555a --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-9202-guest.txt @@ -0,0 +1,153 @@ +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +trying to acquire lock... + OK +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +### label: 9202-guest host: demo-hp-scratch date: 2026-10-04T07:01:34Z +### os +PRETTY_NAME="Debian GNU/Linux 13 (trixie)" +VERSION_ID="13" +VERSION_CODENAME=trixie +debian_version: 13.6 +7.0.2-6-pve +### packages installed: 278 +### apt sources (URIs and suites only) +-- /etc/apt/sources.list.d/debian.sources +URIs: http://security.debian.org +Suites: trixie-security +Components: contrib main +URIs: http://deb.debian.org/debian +Suites: trixie trixie-updates +Components: contrib main +-- /etc/apt/sources.list.d/docker.list +deb [signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian trixie stable +### system apt lists age (newest *_InRelease mtime) +### apt-get update into a throwaway dir +update_rc=0 seconds=4.2 +W: Download is performed unsandboxed as root as file '/tmp/os-survey.Jpz4Bz/lists/partial/security.debian.org_dists_trixie-security_InRelease' couldn't be accessed by user '_apt'. - pkgAcquire::Run (13: Permission denied) +### simulate upgrade: rc=0 Inst=54 Remv=0 +### simulate dist-upgrade: rc=0 Inst=54 Remv=0 +### pending (dist-upgrade) by origin + 27 Debian:13.7/stable + 15 Debian-Security:13/stable-security, Debian:13.7/stable + 7 Debian-Security:13/stable-security + 5 Docker CE:trixie +### pending list (pkg old -> new origin) +libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +base-files 13.8+deb13u6 -> 13.8+deb13u7 [Debian:13.7/stable [amd64]] +bash 5.2.37-2+b9 -> 5.2.37-2+b10 [Debian:13.7/stable [amd64]] +bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +gzip 1.13-1 -> 1.13-1+deb13u1 [Debian:13.7/stable [amd64]] +libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [all]] +liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libblkid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libmount1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +mount 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +fdisk 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libuuid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +util-linux 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [all]] +libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [amd64]] +libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +logsave 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +docker-ce-cli 5:29.8.0-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +containerd.io 2.3.5-1~debian.13~trixie -> 2.3.6-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-ce 5:29.8.0-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +openssl-provider-legacy 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libssl3t64 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +postfix 3.10.12-0+deb13u2 -> 3.10.13-0+deb13u1 [Debian-Security:13/stable-security, Debian:13.7/stable [amd64]] +python3.13 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-stdlib 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +python3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 [Debian:13.7/stable [all]] +libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +dhcpcd-base 1:10.1.0-11+deb13u3 -> 1:10.1.0-11+deb13u4 [Debian:13.7/stable [amd64]] +bind9-dnsutils 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-host 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-libs 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +docker-ce-rootless-extras 5:29.8.0-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie [Docker CE:trixie [amd64]] +docker-compose-plugin 5.5.1-1~debian.13~trixie -> 5.6.0-1~debian.13~trixie [Docker CE:trixie [amd64]] +libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libss2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +openssl 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +### new packages pulled (not installed now) +### kernel / proxmox / docker packages installed +containerd.io 2.3.5-1~debian.13~trixie +docker-buildx-plugin 0.37.1-1~debian.13~trixie +docker-ce 5:29.8.0-1~debian.13~trixie +docker-ce-cli 5:29.8.0-1~debian.13~trixie +docker-ce-rootless-extras 5:29.8.0-1~debian.13~trixie +docker-compose-plugin 5.5.1-1~debian.13~trixie +### unattended-upgrades / needrestart +unattended-upgrades not installed +needrestart not installed +apt-listchanges 4.8 ii +unattended-upgrades.service enabled: not-found +### timers +NEXT LEFT LAST PASSED UNIT ACTIVATES +Sun 2026-10-04 10:43:27 UTC 3h 41min Sat 2026-10-03 08:50:09 UTC 22h ago man-db.timer man-db.service +Sun 2026-10-04 21:15:09 UTC 14h Sat 2026-10-03 21:15:09 UTC 9h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Mon 2026-10-05 00:00:00 UTC 16h Sun 2026-10-04 00:00:42 UTC 7h ago dpkg-db-backup.timer dpkg-db-backup.service +Mon 2026-10-05 00:58:24 UTC 17h Sun 2026-10-04 00:12:42 UTC 6h ago logrotate.timer logrotate.service +Mon 2026-10-05 02:33:39 UTC 19h Sun 2026-10-04 06:33:09 UTC 28min ago apt-daily.timer apt-daily.service +Mon 2026-10-05 06:24:43 UTC 23h Sun 2026-10-04 06:33:18 UTC 28min ago apt-daily-upgrade.timer apt-daily-upgrade.service +Sun 2026-10-11 03:10:02 UTC 6 days Sun 2026-10-04 03:10:42 UTC 3h 51min ago e2scrub_all.timer e2scrub_all.service +- - - - fstrim.timer fstrim.service + +8 timers listed. +### cron +e2scrub_all +### apt periodic config +### end diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-host.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-host.txt new file mode 100644 index 00000000..a7228519 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/demo-hp-host.txt @@ -0,0 +1,306 @@ +### label: demo-hp-host host: demo-hp date: 2026-10-04T07:00:58Z +### os +PRETTY_NAME="Debian GNU/Linux 13 (trixie)" +VERSION_ID="13" +VERSION_CODENAME=trixie +debian_version: 13.5 +7.0.2-6-pve +### packages installed: 746 +### apt sources (URIs and suites only) +-- /etc/apt/sources.list.d/ceph.sources +URIs: https://enterprise.proxmox.com/debian/ceph-squid +Suites: trixie +Components: enterprise +Enabled: no +-- /etc/apt/sources.list.d/debian.sources +URIs: http://deb.debian.org/debian/ +Suites: trixie trixie-updates +Components: main contrib non-free-firmware +URIs: http://security.debian.org/debian-security/ +Suites: trixie-security +Components: main contrib non-free-firmware +-- /etc/apt/sources.list.d/pve-enterprise.sources +URIs: https://enterprise.proxmox.com/debian/pve +Suites: trixie +Components: pve-enterprise +Enabled: no +-- /etc/apt/sources.list.d/pve-no-subscription.sources +URIs: http://download.proxmox.com/debian/pve +Suites: trixie +Components: pve-no-subscription +### system apt lists age (newest *_InRelease mtime) +2026-10-03 23:12:45.000000000 +0200 /var/lib/apt/lists/security.debian.org_debian-security_dists_trixie-security_InRelease +### apt-get update into a throwaway dir +update_rc=0 seconds=4.0 +W: Download is performed unsandboxed as root as file '/tmp/os-survey.jkb93A/lists/partial/deb.debian.org_debian_dists_trixie_InRelease' couldn't be accessed by user '_apt'. - pkgAcquire::Run (13: Permission denied) +### simulate upgrade: rc=0 Inst=184 Remv=0 +The following packages have been kept back: + proxmox-kernel-7.0 pve-firewall +The following packages will be upgraded: + amd64-microcode base-files bash bind9-dnsutils bind9-host bind9-libs +### simulate dist-upgrade: rc=0 Inst=188 Remv=0 +### pending (dist-upgrade) by origin + 80 Proxmox Debian Repository:stable + 66 Debian:13.7/stable + 27 Debian:13.7/stable, Debian-Security:13/stable-security + 15 Debian-Security:13/stable-security +### pending list (pkg old -> new origin) +libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +base-files 13.8+deb13u5 -> 13.8+deb13u7 [Debian:13.7/stable [amd64]] +bash 5.2.37-2+b9 -> 5.2.37-2+b10 [Debian:13.7/stable [amd64]] +bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +gzip 1.13-1 -> 1.13-1+deb13u1 [Debian:13.7/stable [amd64]] +libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [amd64]] +perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 [Debian:13.7/stable [all]] +liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +eject 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +fdisk 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libblkid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libmount1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +mount 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libuuid1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +util-linux 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [all]] +libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 [Debian:13.7/stable [amd64]] +sqlite3 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 [Debian:13.7/stable [amd64]] +libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [amd64]] +login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +logsave 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +dnsmasq-base 2.91-1+deb13u1 -> 2.91-1+deb13u2 [Debian:13.7/stable [amd64]] +dnsmasq 2.91-1+deb13u1 -> 2.91-1+deb13u2 [Debian:13.7/stable [all]] +libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libpcre2-posix3 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +frr 10.6.1-1+pve2 -> 10.6.1-1+pve3 [Proxmox Debian Repository:stable [amd64]] +libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +openssl-provider-legacy 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libssl3t64 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +postfix 3.10.5-1~deb13u1 -> 3.10.13-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +python3.13 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-stdlib 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +python3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +libpython3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 [Debian:13.7/stable [amd64]] +tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 [Debian:13.7/stable [all]] +liblzma5 5.8.1-1 -> 5.8.1-1+deb13u1 [Debian:13.7/stable [amd64]] +rsync 3.4.1+ds1-5+deb13u2 -> 3.5.0+ds1-0+deb13u1 [Debian-Security:13/stable-security [amd64]] +openssl 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +shim-signed-common 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 [Proxmox Debian Repository:stable [all]] +proxmox-secure-boot-support 2.0.6 -> 2.0.8 [Proxmox Debian Repository:stable [amd64]] +shim-unsigned 16.1-1+pmx1 -> 16.1-2+pmx1 [Proxmox Debian Repository:stable [amd64]] +shim-helpers-amd64-signed 1+16.1+1+pmx1 -> 1+16.1+2+pmx1 [Proxmox Debian Repository:stable [amd64]] +shim-signed 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 [Proxmox Debian Repository:stable [amd64]] +dhcpcd-base 1:10.1.0-11+deb13u2 -> 1:10.1.0-11+deb13u4 [Debian:13.7/stable [amd64]] +amd64-microcode 3.20250311.1 -> 3.20251202.1~bpo13+1 [Proxmox Debian Repository:stable [amd64]] +libgssapi-krb5-2 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libkrb5-3 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libkrb5support0 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libk5crypto3 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2 -> 2.12.7+dfsg+really2.9.14-2.1+deb13u3 [Debian:13.7/stable [amd64]] +bind9-dnsutils 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-host 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +bind9-libs 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +krb5-locales 1.21.3-5 -> 1.21.3-5+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 [Debian:13.7/stable [all]] +xz-utils 5.8.1-1 -> 5.8.1-1+deb13u1 [Debian:13.7/stable [amd64]] +busybox 1:1.37.0-6+b8 -> 1:1.37.0-6+b9 [Debian:13.7/stable [amd64]] +libradosstriper1 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +curl 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libssh2-1t64 1.11.1-1 -> 1.11.1-1+deb13u2 [Debian:13.7/stable [amd64]] +libcurl4t64 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +librabbitmq4 0.15.0-1 -> 0.15.0-1+deb13u2 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +librgw2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +ceph-common 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +librbd1 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +librados2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-cephfs 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +libcephfs2 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-rgw 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-rados 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +python3-ceph-argparse 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [all]] +python3-ceph-common 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [all]] +python3-rbd 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +ceph-fuse 19.2.3-pve4 -> 19.2.6-pve4 [Proxmox Debian Repository:stable [amd64]] +chrony 4.6.1-3+deb13u1 -> 4.8-4~bpo13+2 [Proxmox Debian Repository:stable [amd64]] +libcorosync-common4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcfg7 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcmap4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libcpg4 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libnss3 2:3.110-1+deb13u1 -> 2:3.110-1+deb13u4 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +libknet1t64 1.31-pve1 -> 1.35-pve2 [Proxmox Debian Repository:stable [amd64]] +libnozzle1t64 1.31-pve1 -> 1.35-pve2 [Proxmox Debian Repository:stable [amd64]] +libquorum5 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libvotequorum8 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +corosync 3.1.10-pve2 -> 3.1.10-pve3 [Proxmox Debian Repository:stable [amd64]] +libgcrypt20 1.11.0-7 -> 1.11.0-7+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [amd64]] +gpgsm 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +dirmngr 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpg 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpgconf 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +gpg-agent 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 [Debian:13.7/stable [amd64]] +frr-pythontools 10.6.1-1+pve2 -> 10.6.1-1+pve3 [Proxmox Debian Repository:stable [all]] +libasound2t64 1.2.14-1 -> 1.2.14-1+deb13u1 [Debian:13.7/stable [amd64]] +libasound2-data 1.2.14-1 -> 1.2.14-1+deb13u1 [Debian:13.7/stable [all]] +libbytes-random-secure-perl 0.29-3 -> 0.29-4~deb13u1 [Debian:13.7/stable [all]] +libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 [Debian:13.7/stable [amd64]] +libcurl3t64-gnutls 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 [Debian:13.7/stable [amd64]] +libevent-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libevent-core-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 [Debian-Security:13/stable-security [amd64]] +libgbm1 25.0.7-2 -> 25.0.7-2+deb13u1 [Debian:13.7/stable [amd64]] +mesa-libgallium 25.0.7-2 -> 25.0.7-2+deb13u1 [Debian:13.7/stable [amd64]] +libglib2.0-0t64 2.84.4-3~deb13u3 -> 2.84.4-3~deb13u5 [Debian:13.7/stable [amd64]] +libgraphite2-3 1.3.14-2+b1 -> 1.3.14-2+deb13u1 [Debian:13.7/stable [amd64]] +libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u1 -> 1.26.2-1+deb13u2 [Debian-Security:13/stable-security [amd64]] +libhtml-parser-perl 3.83-1+b2 -> 3.83-2~deb13u1 [Debian:13.7/stable [amd64]] +libhttp-daemon-perl 6.16-1 -> 6.16-1+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libjs-extjs 7.0.0-5 -> 7.0.0-7 [Proxmox Debian Repository:stable [all]] +libtalloc2 2:2.4.3+samba4.22.8+dfsg-0+deb13u1 -> 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libtevent0t64 2:0.16.2+samba4.22.8+dfsg-0+deb13u1 -> 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libsmbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +samba-common 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [all]] +smbclient 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libtdb1 2:1.4.13+samba4.22.8+dfsg-0+deb13u1 -> 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libldb2 2:2.11.0+samba4.22.8+dfsg-0+deb13u1 -> 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +samba-libs 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libwbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 [Debian:13.7/stable [amd64]] +libnet-dns-perl 1.50-1 -> 1.56-0+deb13u1 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +libnvpair3linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libpcre2-16-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 [Debian-Security:13/stable-security [amd64]] +libpng16-16t64 1.6.48-1+deb13u5 -> 1.6.48-1+deb13u6 [Debian-Security:13/stable-security [amd64]] +libproxmox-acme-plugins 1.7.1 -> 1.7.2 [Proxmox Debian Repository:stable [all]] +libproxmox-backup-qemu0 2.0.2 -> 2.0.3 [Proxmox Debian Repository:stable [amd64]] +libslirp0 4.8.0-1+b1 -> 4.8.0-1+deb13u1 [Debian:13.7/stable [amd64]] +pve-qemu-kvm 11.0.0-3 -> 11.0.3-4 [Proxmox Debian Repository:stable [amd64]] +libpve-notify-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +libpve-cluster-api-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +libpve-cluster-perl 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [all]] +pve-cluster 9.1.5 -> 9.1.6 [Proxmox Debian Repository:stable [amd64]] +libpve-access-control 9.1.1 -> 9.1.2 [Proxmox Debian Repository:stable [all]] +libpve-apiclient-perl 3.4.2 -> 3.4.3 [Proxmox Debian Repository:stable [all]] +librados2-perl 1.5.0 -> 1.5.1 [Proxmox Debian Repository:stable [amd64]] +libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+b2 -> 2.0207+dfsg+really+2.0134-5+deb13u1 [Debian:13.7/stable [amd64]] +proxmox-backup-client 4.2.0-1 -> 4.2.7-1 [Proxmox Debian Repository:stable [amd64]] +proxmox-backup-file-restore 4.2.0-1 -> 4.2.7-1 [Proxmox Debian Repository:stable [amd64]] +pve-manager 9.2.2 -> 9.2.21 [Proxmox Debian Repository:stable [all]] +libproxmox-acme-perl 1.7.1 -> 1.7.2 [Proxmox Debian Repository:stable [all]] +libpve-common-perl 9.1.12 -> 9.2.2 [Proxmox Debian Repository:stable [all]] +libpve-guest-common-perl 6.0.3 -> 6.0.5 [Proxmox Debian Repository:stable [all]] +qemu-server 9.1.15 -> 9.2.10 [Proxmox Debian Repository:stable [amd64]] +libpve-storage-perl 9.1.5 -> 9.1.11 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-legacy 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-ovmf 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +libpve-network-api-perl 1.6.5 -> 1.6.7 [Proxmox Debian Repository:stable [all]] +libpve-network-perl 1.6.5 -> 1.6.7 [Proxmox Debian Repository:stable [all]] +proxmox-firewall-data (new) -> 0.1 [Proxmox Debian Repository:stable [all]] +pve-firewall 6.0.4 -> 6.0.6 [Proxmox Debian Repository:stable [amd64]] +pve-container 6.1.10 -> 6.1.14 [Proxmox Debian Repository:stable [all]] +pve-ha-manager 5.2.4 -> 5.2.5 [Proxmox Debian Repository:stable [amd64]] +socat 1.8.0.3-1 -> 1.8.0.3-1+deb13u1 [Debian:13.7/stable [amd64]] +novnc-pve 1.7.0-1 -> 1.7.0-2 [Proxmox Debian Repository:stable [all]] +proxmox-enterprise-support-keyring 1.0 -> 1.1 [Proxmox Debian Repository:stable [all]] +proxmox-mini-journalreader 1.6 -> 1.7 [Proxmox Debian Repository:stable [amd64]] +proxmox-widget-toolkit 5.2.2 -> 5.2.10 [Proxmox Debian Repository:stable [all]] +pve-docs 9.2.1 -> 9.2.13 [Proxmox Debian Repository:stable [all]] +pve-i18n 3.7.4 -> 3.10.0 [Proxmox Debian Repository:stable [all]] +pve-xtermjs 6.0.0-1 -> 6.0.0-2 [Proxmox Debian Repository:stable [all]] +pve-yew-mobile-i18n 3.7.4 -> 3.10.0 [Proxmox Debian Repository:stable [all]] +pve-yew-mobile-gui 0.7.0 -> 0.8.0 [Proxmox Debian Repository:stable [amd64]] +libss2 1.47.2-3+b11 -> 1.47.2-3+b12 [Debian:13.7/stable [amd64]] +libtasn1-6 4.20.0-2 -> 4.20.0-2+deb13u1 [Debian:13.7/stable [amd64]] +libunbound8 1.22.0-2+deb13u2 -> 1.26.1-0+deb13u1 [Debian-Security:13/stable-security [amd64]] +libuutil3linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libzfs7linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +libzpool7linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +pve-firmware 3.18-3 -> 3.18-6 [Proxmox Debian Repository:stable [all]] +proxmox-kernel-7.0.14-20-pve-signed (new) -> 7.0.14-20 [Proxmox Debian Repository:stable [amd64]] +proxmox-kernel-7.0 7.0.2-6 -> 7.0.14-20 [Proxmox Debian Repository:stable [amd64]] +proxmox-kernel-helper 9.1.0+fde2 -> 9.2.0 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware-aarch64 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +pve-edk2-firmware 4.2025.05-2 -> 4.2026.08-1 [Proxmox Debian Repository:stable [all]] +python3-idna 3.10-1 -> 3.10-1+deb13u1 [Debian:13.7/stable [all]] +python3-urllib3 2.3.0-3+deb13u1 -> 2.3.0-3+deb13u2 [Debian:13.7/stable, Debian-Security:13/stable-security [all]] +xfsprogs 6.13.0-2+b1 -> 6.13.0-2+deb13u1 [Debian:13.7/stable [amd64]] +zfs-initramfs 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [all]] +zfsutils-linux 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +zfs-zed 2.4.2-pve1 -> 2.4.4-pve1 [Proxmox Debian Repository:stable [amd64]] +### new packages pulled (not installed now) +proxmox-firewall-data +proxmox-kernel-7.0.14-20-pve-signed +### kernel / proxmox / docker packages installed +lxc-pve 7.0.0-2 +proxmox-archive-keyring 4.0 +proxmox-backup-client 4.2.0-1 +proxmox-backup-file-restore 4.2.0-1 +proxmox-backup-restore-image 1.0.0 +proxmox-default-kernel 2.1.0 +proxmox-enterprise-support-keyring 1.0 +proxmox-firewall 1.2.3 +proxmox-grub 2.12-9+pmx2 +proxmox-kernel-7.0 7.0.2-6 +proxmox-kernel-7.0.2-6-pve-signed 7.0.2-6 +proxmox-kernel-helper 9.1.0+fde2 +proxmox-mail-forward 1.0.3 +proxmox-mini-journalreader 1.6 +proxmox-offline-mirror-docs 0.7.4 +proxmox-offline-mirror-helper 0.7.4 +proxmox-secure-boot-support 2.0.6 +proxmox-termproxy 2.1.0 +proxmox-ve 9.2.0 +proxmox-websocket-tunnel 1.0.0 +proxmox-widget-toolkit 5.2.2 +pve-cluster 9.1.5 +pve-container 6.1.10 +pve-docs 9.2.1 +pve-edk2-firmware 4.2025.05-2 +pve-edk2-firmware-aarch64 4.2025.05-2 +pve-edk2-firmware-legacy 4.2025.05-2 +pve-edk2-firmware-ovmf 4.2025.05-2 +pve-esxi-import-tools 1.0.1 +pve-firewall 6.0.4 +pve-firmware 3.18-3 +pve-ha-manager 5.2.4 +pve-i18n 3.7.4 +pve-lxc-syscalld 2.0.2 +pve-manager 9.2.2 +pve-nvidia-vgpu-helper 0.3.1 +pve-qemu-kvm 11.0.0-3 +pve-xtermjs 6.0.0-1 +pve-yew-mobile-gui 0.7.0 +pve-yew-mobile-i18n 3.7.4 +qemu-server 9.1.15 +### unattended-upgrades / needrestart +unattended-upgrades not installed +needrestart not installed +apt-listchanges 4.8 ii +unattended-upgrades.service enabled: not-found +### timers +NEXT LEFT LAST PASSED UNIT ACTIVATES +Sun 2026-10-04 09:01:41 CEST 27s Sun 2026-10-04 09:00:41 CEST 32s ago felhom-mgmt-watchdog.timer felhom-mgmt-watchdog.service +Sun 2026-10-04 18:03:32 CEST 9h Sat 2026-10-03 18:03:32 CEST 14h ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service +Mon 2026-10-05 00:00:00 CEST 14h Sun 2026-10-04 00:00:06 CEST 9h ago dpkg-db-backup.timer dpkg-db-backup.service +Mon 2026-10-05 00:06:44 CEST 15h Sun 2026-10-04 00:30:32 CEST 8h ago logrotate.timer logrotate.service +Mon 2026-10-05 00:13:22 CEST 15h Mon 2026-09-28 00:42:34 CEST 6 days ago fstrim.timer fstrim.service +Mon 2026-10-05 01:56:19 CEST 16h Sun 2026-10-04 06:05:32 CEST 2h 55min ago apt-daily.timer apt-daily.service +Mon 2026-10-05 02:52:32 CEST 17h Sun 2026-10-04 02:15:06 CEST 6h ago pve-daily-update.timer pve-daily-update.service +Mon 2026-10-05 04:03:50 CEST 19h Sun 2026-10-04 03:03:06 CEST 5h 58min ago man-db.timer man-db.service +Mon 2026-10-05 06:22:16 CEST 21h Sun 2026-10-04 06:56:04 CEST 2h 5min ago apt-daily-upgrade.timer apt-daily-upgrade.service +Sun 2026-10-11 03:10:28 CEST 6 days Sun 2026-10-04 03:10:32 CEST 5h 50min ago xfs_scrub_all.timer xfs_scrub_all.service +Sun 2026-10-11 03:10:43 CEST 6 days Sun 2026-10-04 03:11:04 CEST 5h 50min ago e2scrub_all.timer e2scrub_all.service + +11 timers listed. +### cron +e2scrub_all +vzdump +zfsutils-linux +### apt periodic config +### end diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/host-package-diff.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/host-package-diff.txt new file mode 100644 index 00000000..dc3f86be --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/host-package-diff.txt @@ -0,0 +1,10 @@ +# host package sets: only on demo-hp (N=3) | only on demo-felhom (N=4) +## only demo-hp: +amd64-microcode +felhom-bootstrap +proxmox-secure-boot-support +## only demo-felhom: +intel-microcode +proxmox-first-boot +tailscale +tailscale-archive-keyring diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/pk-demo-hp.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/pk-demo-hp.txt new file mode 100644 index 00000000..82b4c196 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/pk-demo-hp.txt @@ -0,0 +1,746 @@ +adduser +age +amd64-microcode +apparmor +apt +apt-listchanges +apt-utils +base-files +base-passwd +bash +bash-completion +bc +bind9-dnsutils +bind9-host +bind9-libs +binutils +binutils-common +binutils-x86-64-linux-gnu +bridge-utils +bsd-mailx +bsdextrautils +bsdutils +btrfs-progs +busybox +bzip2 +ca-certificates +ceph-common +ceph-fuse +chrony +cifs-utils +conntrack +console-setup +console-setup-linux +coreutils +corosync +cpio +criu +cron +cron-daemon-common +cstream +curl +dash +dbus +dbus-bin +dbus-daemon +dbus-session-bus-common +dbus-system-bus-common +debconf +debconf-i18n +debian-archive-keyring +debian-faq +debianutils +dhcpcd-base +diffutils +dirmngr +distro-info-data +dmeventd +dmidecode +dmsetup +dns-root-data +dnsmasq +dnsmasq-base +doc-debian +dosfstools +dpkg +dracut-install +dtach +e2fsprogs +ebtables +efibootmgr +eject +ethtool +faketime +fdisk +fdutils +felhom-bootstrap +file +findutils +fontconfig +fontconfig-config +fonts-dejavu-core +fonts-dejavu-mono +fonts-font-awesome +fonts-font-logos +frr +frr-pythontools +fuse +fuse3 +gcc-14-base +gdisk +genisoimage +gettext-base +gnupg +gnupg-l10n +gnutls-bin +golang-github-containers-common +golang-github-containers-image +gpg +gpg-agent +gpgconf +gpgsm +grep +groff-base +grub-common +grub-efi-amd64 +grub-efi-amd64-bin +grub-efi-amd64-signed +grub-efi-amd64-unsigned +grub-pc-bin +grub2-common +gzip +hdparm +hostname +ifupdown2 +inetutils-telnet +init +init-system-helpers +initramfs-tools +initramfs-tools-bin +initramfs-tools-core +iproute2 +ipset +iptables +iputils-ping +isc-dhcp-client +iso-codes +iucode-tool +kbd +keyboard-configuration +keyutils +klibc-utils +kmod +krb5-locales +ksm-control-daemon +less +libacl1 +libaio1t64 +libanyevent-http-perl +libanyevent-perl +libapparmor1 +libappconfig-perl +libapt-pkg-perl +libapt-pkg7.0 +libarchive13t64 +libasound2-data +libasound2t64 +libassuan9 +libasyncns0 +libatomic1 +libattr1 +libaudit-common +libaudit1 +libauthen-pam-perl +libavahi-client3 +libavahi-common-data +libavahi-common3 +libbabeltrace1 +libbinutils +libblas3 +libblkid1 +libbpf1 +libbrotli1 +libbsd0 +libbytes-random-secure-perl +libbz2-1.0 +libc-bin +libc-l10n +libc6 +libcairo2 +libcap-ng0 +libcap2 +libcap2-bin +libcares2 +libcbor0.10 +libcephfs2 +libcfg7 +libclass-methodmaker-perl +libclone-perl +libcmap4 +libcom-err2 +libcommon-sense-perl +libcompel1 +libconvert-asn1-perl +libcorosync-common4 +libcpg4 +libcrypt-openssl-bignum-perl +libcrypt-openssl-random-perl +libcrypt-openssl-rsa-perl +libcrypt-random-seed-perl +libcrypt-ssleay-perl +libcrypt1 +libcryptsetup12 +libctf-nobfd0 +libctf0 +libcurl3t64-gnutls +libcurl4t64 +libdatrie1 +libdb5.3t64 +libdbi1t64 +libdbus-1-3 +libdebconfclient0 +libdevel-cycle-perl +libdevmapper-event1.02.1 +libdevmapper1.02.1 +libdigest-hmac-perl +libdouble-conversion3 +libdpkg-perl +libdrm-amdgpu1 +libdrm-common +libdrm-intel1 +libdrm2 +libdw1t64 +libedit2 +libefiboot1t64 +libefivar1t64 +libelf1t64 +libencode-locale-perl +libepoxy0 +libevent-2.1-7t64 +libevent-core-2.1-7t64 +libexpat1 +libext2fs2t64 +libfaketime +libfdisk1 +libfdt1 +libffi8 +libfido2-1 +libfile-chdir-perl +libfile-listing-perl +libfile-readbackwards-perl +libfilesys-df-perl +libflac14 +libfontconfig1 +libfreetype6 +libfribidi0 +libfstrm0 +libfuse2t64 +libfuse3-4 +libgbm1 +libgcc-s1 +libgcrypt20 +libgdbm-compat4t64 +libgdbm6t64 +libglib2.0-0t64 +libgmp10 +libgnutls-dane0t64 +libgnutls30t64 +libgoogle-perftools4t64 +libgpg-error0 +libgpgme11t64 +libgprofng0 +libgraphite2-3 +libgssapi-krb5-2 +libgstreamer-plugins-base1.0-0 +libgstreamer1.0-0 +libharfbuzz0b +libhogweed6t64 +libhtml-parser-perl +libhtml-tagset-perl +libhtml-tree-perl +libhttp-cookies-perl +libhttp-daemon-perl +libhttp-date-perl +libhttp-message-perl +libhttp-negotiate-perl +libibverbs1 +libicu76 +libidn2-0 +libinih1 +libio-html-perl +libio-multiplex-perl +libio-socket-ssl-perl +libio-stringy-perl +libip4tc2 +libip6tc2 +libipset13t64 +libiscsi7 +libisns0t64 +libjansson4 +libjemalloc2 +libjpeg62-turbo +libjs-bootstrap5 +libjs-extjs +libjs-qrcodejs +libjson-c5 +libjson-glib-1.0-0 +libjson-glib-1.0-common +libjson-perl +libjson-xs-perl +libk5crypto3 +libkeyutils1 +libklibc +libkmod2 +libknet1t64 +libkrb5-3 +libkrb5support0 +libksba8 +liblastlog2-2 +libldap2 +libldb2 +liblinear4 +liblinux-inotify2-perl +libllvm19 +liblmdb0 +liblocale-gettext-perl +liblockfile-bin +liblockfile1 +liblsof0 +liblttng-ust-common1t64 +liblttng-ust-ctl5t64 +liblttng-ust1t64 +liblua5.3-0 +liblua5.4-0 +liblvm2cmd2.03 +liblwp-mediatypes-perl +liblwp-protocol-https-perl +liblz4-1 +liblzma5 +liblzo2-2 +libmagic-mgc +libmagic1t64 +libmath-random-isaac-perl +libmaxminddb0 +libmd0 +libmime-base32-perl +libmnl0 +libmount1 +libmp3lame0 +libmpg123-0t64 +libnbd0 +libncurses6 +libncursesw6 +libnet-dbus-perl +libnet-dns-perl +libnet-http-perl +libnet-ip-perl +libnet-ldap-perl +libnet-ssleay-perl +libnet-subnet-perl +libnet1 +libnetaddr-ip-perl +libnetfilter-conntrack3 +libnetfilter-log1 +libnettle8t64 +libnewt0.52 +libnfnetlink0 +libnfsidmap1 +libnftables1 +libnftnl11 +libnghttp2-14 +libnghttp3-9 +libngtcp2-16 +libngtcp2-crypto-gnutls8 +libnl-3-200 +libnl-route-3-200 +libnozzle1t64 +libnpth0t64 +libnsl2 +libnspr4 +libnss-systemd +libnss3 +libnuma1 +libnvpair3linux +liboath0t64 +libogg0 +libopeniscsiusr +libopus0 +liborc-0.4-0t64 +libp11-kit0 +libpam-modules +libpam-modules-bin +libpam-runtime +libpam-systemd +libpam-wtmpdb +libpam0g +libpango-1.0-0 +libpangocairo-1.0-0 +libpangoft2-1.0-0 +libpcap0.8t64 +libpci3 +libpciaccess0 +libpcre2-16-0 +libpcre2-8-0 +libpcre2-posix3 +libperl5.40 +libpipeline1 +libpixman-1-0 +libpng16-16t64 +libpopt0 +libposix-strptime-perl +libproc2-0 +libprotobuf-c1 +libproxmox-acme-perl +libproxmox-acme-plugins +libproxmox-backup-qemu0 +libproxmox-rs-perl +libpsl5t64 +libpulse0 +libpve-access-control +libpve-apiclient-perl +libpve-cluster-api-perl +libpve-cluster-perl +libpve-common-perl +libpve-guest-common-perl +libpve-http-server-perl +libpve-network-api-perl +libpve-network-perl +libpve-notify-perl +libpve-rs-perl +libpve-storage-perl +libpython3-stdlib +libpython3.13-minimal +libpython3.13-stdlib +libqb-tools +libqb100 +libqrencode4 +libqt5core5t64 +libqt5dbus5t64 +libqt5network5t64 +libquorum5 +librabbitmq4 +librados2 +librados2-perl +libradosstriper1 +librbd1 +librdkafka1 +librdmacm1t64 +libreadline8t64 +libreiserfscore0t64 +librgw2 +librrd8t64 +librrds-perl +librtmp1 +libsasl2-2 +libsasl2-modules-db +libseccomp2 +libselinux1 +libsemanage-common +libsemanage2 +libsensors-config +libsensors5 +libsepol2 +libsframe1 +libslang2 +libslirp0 +libsmartcols1 +libsmbclient0 +libsnappy1v5 +libsndfile1 +libsndio7.0 +libsocket6-perl +libspice-server1 +libsqlite3-0 +libss2 +libssh2-1t64 +libssl3t64 +libstatgrab10t64 +libstdc++6 +libstring-shellquote-perl +libsubid5 +libsystemd-shared +libsystemd0 +libtalloc2 +libtasn1-6 +libtcmalloc-minimal4t64 +libtdb1 +libtemplate-perl +libterm-readline-gnu-perl +libtevent0t64 +libtext-charwidth-perl +libtext-iconv-perl +libtext-wrapi18n-perl +libthai-data +libthai0 +libthrift-0.19.0t64 +libtimedate-perl +libtinfo6 +libtirpc-common +libtirpc3t64 +libtlsrpt0 +libtpms0 +libtry-tiny-perl +libtypes-serialiser-perl +libuchardet0 +libudev1 +libunbound8 +libunistring5 +libunwind8 +liburcu8t64 +liburi-perl +liburing2 +libusb-1.0-0 +libusbredirparser1t64 +libuuid-perl +libuuid1 +libuutil3linux +libuv1t64 +libva-drm2 +libva2 +libvirglrenderer1 +libvorbis0a +libvorbisenc2 +libvotequorum8 +libvulkan1 +libwayland-server0 +libwbclient0 +libwrap0 +libwtmpdb0 +libwww-perl +libwww-robotrules-perl +libx11-6 +libx11-data +libx11-xcb1 +libxau6 +libxcb-dri3-0 +libxcb-present0 +libxcb-randr0 +libxcb-render0 +libxcb-shm0 +libxcb-sync1 +libxcb-xfixes0 +libxcb1 +libxdmcp6 +libxext6 +libxkbcommon0 +libxml-libxml-perl +libxml-namespacesupport-perl +libxml-parser-perl +libxml-sax-base-perl +libxml-sax-perl +libxml-twig-perl +libxml2 +libxrender1 +libxshmfence1 +libxslt1.1 +libxtables12 +libxxhash0 +libyaml-0-2 +libyaml-libyaml-perl +libyang3 +libz3-4 +libzfs7linux +libzpool7linux +libzstd1 +linux-base +linux-sysctl-defaults +locales +login +login.defs +logrotate +logsave +lsof +lvm2 +lxc-pve +lxcfs +lzop +man-db +manpages +mawk +media-types +memtest86+ +mesa-libgallium +mokutil +mount +nano +ncurses-base +ncurses-bin +ncurses-term +netavark +netbase +netcat-traditional +nfs-common +nftables +nmap +nmap-common +node-popper2 +novnc-pve +numactl +open-iscsi +openssh-client +openssh-server +openssh-sftp-server +openssl +openssl-provider-legacy +passwd +pci.ids +pciutils +perl +perl-base +perl-modules-5.40 +perl-openssl-defaults +pinentry-curses +postfix +procmail +procps +proxmox-archive-keyring +proxmox-backup-client +proxmox-backup-file-restore +proxmox-backup-restore-image +proxmox-default-kernel +proxmox-enterprise-support-keyring +proxmox-firewall +proxmox-grub +proxmox-kernel-7.0 +proxmox-kernel-7.0.2-6-pve-signed +proxmox-kernel-helper +proxmox-mail-forward +proxmox-mini-journalreader +proxmox-offline-mirror-docs +proxmox-offline-mirror-helper +proxmox-secure-boot-support +proxmox-termproxy +proxmox-ve +proxmox-websocket-tunnel +proxmox-widget-toolkit +psmisc +pve-cluster +pve-container +pve-docs +pve-edk2-firmware +pve-edk2-firmware-aarch64 +pve-edk2-firmware-legacy +pve-edk2-firmware-ovmf +pve-esxi-import-tools +pve-firewall +pve-firmware +pve-ha-manager +pve-i18n +pve-lxc-syscalld +pve-manager +pve-nvidia-vgpu-helper +pve-qemu-kvm +pve-xtermjs +pve-yew-mobile-gui +pve-yew-mobile-i18n +python-apt-common +python3 +python3-apt +python3-autocommand +python3-bcrypt +python3-ceph-argparse +python3-ceph-common +python3-cephfs +python3-certifi +python3-cffi-backend +python3-chardet +python3-charset-normalizer +python3-cryptography +python3-dbus +python3-debconf +python3-debian +python3-debianbts +python3-idna +python3-importlib-resources +python3-inflect +python3-jaraco.context +python3-jaraco.functools +python3-jaraco.text +python3-minimal +python3-more-itertools +python3-pefile +python3-pkg-resources +python3-prettytable +python3-pyvmomi +python3-rados +python3-rbd +python3-reportbug +python3-requests +python3-rgw +python3-setuptools +python3-six +python3-systemd +python3-typeguard +python3-typing-extensions +python3-urllib3 +python3-virt-firmware +python3-wcwidth +python3-yaml +python3-zipp +python3.13 +python3.13-minimal +qemu-server +qrencode +readline-common +reportbug +rpcbind +rrdcached +rsync +runit-helper +samba-common +samba-libs +sed +sensible-utils +shared-mime-info +shim-helpers-amd64-signed +shim-signed +shim-signed-common +shim-unsigned +skopeo +smartmontools +smbclient +socat +spiceterm +sqlite3 +sqv +ssh +strace +sudo +swtpm +swtpm-libs +swtpm-tools +systemd +systemd-boot-efi +systemd-boot-tools +systemd-sysv +sysvinit-utils +tar +tcpdump +thin-provisioning-tools +time +traceroute +tzdata +ucf +udev +uidmap +usbutils +util-linux +util-linux-extra +vim-common +vim-tiny +virtiofsd +vncterm +wamerican +wget +whiptail +wireguard-tools +wtmpdb +xfsprogs +xkb-data +xsltproc +xz-utils +zfs-initramfs +zfs-zed +zfsutils-linux +zlib1g +zstd diff --git a/documentation/audits/os-updates-spike-2026-10-04/partE/pk-felhom-pve.txt b/documentation/audits/os-updates-spike-2026-10-04/partE/pk-felhom-pve.txt new file mode 100644 index 00000000..e8aef687 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partE/pk-felhom-pve.txt @@ -0,0 +1,747 @@ +adduser +age +apparmor +apt +apt-listchanges +apt-utils +base-files +base-passwd +bash +bash-completion +bc +bind9-dnsutils +bind9-host +bind9-libs +binutils +binutils-common +binutils-x86-64-linux-gnu +bridge-utils +bsd-mailx +bsdextrautils +bsdutils +btrfs-progs +busybox +bzip2 +ca-certificates +ceph-common +ceph-fuse +chrony +cifs-utils +conntrack +console-setup +console-setup-linux +coreutils +corosync +cpio +criu +cron +cron-daemon-common +cstream +curl +dash +dbus +dbus-bin +dbus-daemon +dbus-session-bus-common +dbus-system-bus-common +debconf +debconf-i18n +debian-archive-keyring +debian-faq +debianutils +dhcpcd-base +diffutils +dirmngr +distro-info-data +dmeventd +dmidecode +dmsetup +dns-root-data +dnsmasq +dnsmasq-base +doc-debian +dosfstools +dpkg +dracut-install +dtach +e2fsprogs +ebtables +efibootmgr +eject +ethtool +faketime +fdisk +fdutils +file +findutils +fontconfig +fontconfig-config +fonts-dejavu-core +fonts-dejavu-mono +fonts-font-awesome +fonts-font-logos +frr +frr-pythontools +fuse +fuse3 +gcc-14-base +gdisk +genisoimage +gettext-base +gnupg +gnupg-l10n +gnutls-bin +golang-github-containers-common +golang-github-containers-image +gpg +gpg-agent +gpgconf +gpgsm +grep +groff-base +grub-common +grub-efi-amd64 +grub-efi-amd64-bin +grub-efi-amd64-signed +grub-efi-amd64-unsigned +grub-pc-bin +grub2-common +gzip +hdparm +hostname +ifupdown2 +inetutils-telnet +init +init-system-helpers +initramfs-tools +initramfs-tools-bin +initramfs-tools-core +intel-microcode +iproute2 +ipset +iptables +iputils-ping +isc-dhcp-client +iso-codes +iucode-tool +kbd +keyboard-configuration +keyutils +klibc-utils +kmod +krb5-locales +ksm-control-daemon +less +libacl1 +libaio1t64 +libanyevent-http-perl +libanyevent-perl +libapparmor1 +libappconfig-perl +libapt-pkg-perl +libapt-pkg7.0 +libarchive13t64 +libasound2-data +libasound2t64 +libassuan9 +libasyncns0 +libatomic1 +libattr1 +libaudit-common +libaudit1 +libauthen-pam-perl +libavahi-client3 +libavahi-common-data +libavahi-common3 +libbabeltrace1 +libbinutils +libblas3 +libblkid1 +libbpf1 +libbrotli1 +libbsd0 +libbytes-random-secure-perl +libbz2-1.0 +libc-bin +libc-l10n +libc6 +libcairo2 +libcap-ng0 +libcap2 +libcap2-bin +libcares2 +libcbor0.10 +libcephfs2 +libcfg7 +libclass-methodmaker-perl +libclone-perl +libcmap4 +libcom-err2 +libcommon-sense-perl +libcompel1 +libconvert-asn1-perl +libcorosync-common4 +libcpg4 +libcrypt-openssl-bignum-perl +libcrypt-openssl-random-perl +libcrypt-openssl-rsa-perl +libcrypt-random-seed-perl +libcrypt-ssleay-perl +libcrypt1 +libcryptsetup12 +libctf-nobfd0 +libctf0 +libcurl3t64-gnutls +libcurl4t64 +libdatrie1 +libdb5.3t64 +libdbi1t64 +libdbus-1-3 +libdebconfclient0 +libdevel-cycle-perl +libdevmapper-event1.02.1 +libdevmapper1.02.1 +libdigest-hmac-perl +libdouble-conversion3 +libdpkg-perl +libdrm-amdgpu1 +libdrm-common +libdrm-intel1 +libdrm2 +libdw1t64 +libedit2 +libefiboot1t64 +libefivar1t64 +libelf1t64 +libencode-locale-perl +libepoxy0 +libevent-2.1-7t64 +libevent-core-2.1-7t64 +libexpat1 +libext2fs2t64 +libfaketime +libfdisk1 +libfdt1 +libffi8 +libfido2-1 +libfile-chdir-perl +libfile-listing-perl +libfile-readbackwards-perl +libfilesys-df-perl +libflac14 +libfontconfig1 +libfreetype6 +libfribidi0 +libfstrm0 +libfuse2t64 +libfuse3-4 +libgbm1 +libgcc-s1 +libgcrypt20 +libgdbm-compat4t64 +libgdbm6t64 +libglib2.0-0t64 +libgmp10 +libgnutls-dane0t64 +libgnutls30t64 +libgoogle-perftools4t64 +libgpg-error0 +libgpgme11t64 +libgprofng0 +libgraphite2-3 +libgssapi-krb5-2 +libgstreamer-plugins-base1.0-0 +libgstreamer1.0-0 +libharfbuzz0b +libhogweed6t64 +libhtml-parser-perl +libhtml-tagset-perl +libhtml-tree-perl +libhttp-cookies-perl +libhttp-daemon-perl +libhttp-date-perl +libhttp-message-perl +libhttp-negotiate-perl +libibverbs1 +libicu76 +libidn2-0 +libinih1 +libio-html-perl +libio-multiplex-perl +libio-socket-ssl-perl +libio-stringy-perl +libip4tc2 +libip6tc2 +libipset13t64 +libiscsi7 +libisns0t64 +libjansson4 +libjemalloc2 +libjpeg62-turbo +libjs-bootstrap5 +libjs-extjs +libjs-qrcodejs +libjson-c5 +libjson-glib-1.0-0 +libjson-glib-1.0-common +libjson-perl +libjson-xs-perl +libk5crypto3 +libkeyutils1 +libklibc +libkmod2 +libknet1t64 +libkrb5-3 +libkrb5support0 +libksba8 +liblastlog2-2 +libldap2 +libldb2 +liblinear4 +liblinux-inotify2-perl +libllvm19 +liblmdb0 +liblocale-gettext-perl +liblockfile-bin +liblockfile1 +liblsof0 +liblttng-ust-common1t64 +liblttng-ust-ctl5t64 +liblttng-ust1t64 +liblua5.3-0 +liblua5.4-0 +liblvm2cmd2.03 +liblwp-mediatypes-perl +liblwp-protocol-https-perl +liblz4-1 +liblzma5 +liblzo2-2 +libmagic-mgc +libmagic1t64 +libmath-random-isaac-perl +libmaxminddb0 +libmd0 +libmime-base32-perl +libmnl0 +libmount1 +libmp3lame0 +libmpg123-0t64 +libnbd0 +libncurses6 +libncursesw6 +libnet-dbus-perl +libnet-dns-perl +libnet-http-perl +libnet-ip-perl +libnet-ldap-perl +libnet-ssleay-perl +libnet-subnet-perl +libnet1 +libnetaddr-ip-perl +libnetfilter-conntrack3 +libnetfilter-log1 +libnettle8t64 +libnewt0.52 +libnfnetlink0 +libnfsidmap1 +libnftables1 +libnftnl11 +libnghttp2-14 +libnghttp3-9 +libngtcp2-16 +libngtcp2-crypto-gnutls8 +libnl-3-200 +libnl-route-3-200 +libnozzle1t64 +libnpth0t64 +libnsl2 +libnspr4 +libnss-systemd +libnss3 +libnuma1 +libnvpair3linux +liboath0t64 +libogg0 +libopeniscsiusr +libopus0 +liborc-0.4-0t64 +libp11-kit0 +libpam-modules +libpam-modules-bin +libpam-runtime +libpam-systemd +libpam-wtmpdb +libpam0g +libpango-1.0-0 +libpangocairo-1.0-0 +libpangoft2-1.0-0 +libpcap0.8t64 +libpci3 +libpciaccess0 +libpcre2-16-0 +libpcre2-8-0 +libpcre2-posix3 +libperl5.40 +libpipeline1 +libpixman-1-0 +libpng16-16t64 +libpopt0 +libposix-strptime-perl +libproc2-0 +libprotobuf-c1 +libproxmox-acme-perl +libproxmox-acme-plugins +libproxmox-backup-qemu0 +libproxmox-rs-perl +libpsl5t64 +libpulse0 +libpve-access-control +libpve-apiclient-perl +libpve-cluster-api-perl +libpve-cluster-perl +libpve-common-perl +libpve-guest-common-perl +libpve-http-server-perl +libpve-network-api-perl +libpve-network-perl +libpve-notify-perl +libpve-rs-perl +libpve-storage-perl +libpython3-stdlib +libpython3.13-minimal +libpython3.13-stdlib +libqb-tools +libqb100 +libqrencode4 +libqt5core5t64 +libqt5dbus5t64 +libqt5network5t64 +libquorum5 +librabbitmq4 +librados2 +librados2-perl +libradosstriper1 +librbd1 +librdkafka1 +librdmacm1t64 +libreadline8t64 +libreiserfscore0t64 +librgw2 +librrd8t64 +librrds-perl +librtmp1 +libsasl2-2 +libsasl2-modules-db +libseccomp2 +libselinux1 +libsemanage-common +libsemanage2 +libsensors-config +libsensors5 +libsepol2 +libsframe1 +libslang2 +libslirp0 +libsmartcols1 +libsmbclient0 +libsnappy1v5 +libsndfile1 +libsndio7.0 +libsocket6-perl +libspice-server1 +libsqlite3-0 +libss2 +libssh2-1t64 +libssl3t64 +libstatgrab10t64 +libstdc++6 +libstring-shellquote-perl +libsubid5 +libsystemd-shared +libsystemd0 +libtalloc2 +libtasn1-6 +libtcmalloc-minimal4t64 +libtdb1 +libtemplate-perl +libterm-readline-gnu-perl +libtevent0t64 +libtext-charwidth-perl +libtext-iconv-perl +libtext-wrapi18n-perl +libthai-data +libthai0 +libthrift-0.19.0t64 +libtimedate-perl +libtinfo6 +libtirpc-common +libtirpc3t64 +libtlsrpt0 +libtpms0 +libtry-tiny-perl +libtypes-serialiser-perl +libuchardet0 +libudev1 +libunbound8 +libunistring5 +libunwind8 +liburcu8t64 +liburi-perl +liburing2 +libusb-1.0-0 +libusbredirparser1t64 +libuuid-perl +libuuid1 +libuutil3linux +libuv1t64 +libva-drm2 +libva2 +libvirglrenderer1 +libvorbis0a +libvorbisenc2 +libvotequorum8 +libvulkan1 +libwayland-server0 +libwbclient0 +libwrap0 +libwtmpdb0 +libwww-perl +libwww-robotrules-perl +libx11-6 +libx11-data +libx11-xcb1 +libxau6 +libxcb-dri3-0 +libxcb-present0 +libxcb-randr0 +libxcb-render0 +libxcb-shm0 +libxcb-sync1 +libxcb-xfixes0 +libxcb1 +libxdmcp6 +libxext6 +libxkbcommon0 +libxml-libxml-perl +libxml-namespacesupport-perl +libxml-parser-perl +libxml-sax-base-perl +libxml-sax-perl +libxml-twig-perl +libxml2 +libxrender1 +libxshmfence1 +libxslt1.1 +libxtables12 +libxxhash0 +libyaml-0-2 +libyaml-libyaml-perl +libyang3 +libz3-4 +libzfs7linux +libzpool7linux +libzstd1 +linux-base +linux-sysctl-defaults +locales +login +login.defs +logrotate +logsave +lsof +lvm2 +lxc-pve +lxcfs +lzop +man-db +manpages +mawk +media-types +memtest86+ +mesa-libgallium +mokutil +mount +nano +ncurses-base +ncurses-bin +ncurses-term +netavark +netbase +netcat-traditional +nfs-common +nftables +nmap +nmap-common +node-popper2 +novnc-pve +numactl +open-iscsi +openssh-client +openssh-server +openssh-sftp-server +openssl +openssl-provider-legacy +passwd +pci.ids +pciutils +perl +perl-base +perl-modules-5.40 +perl-openssl-defaults +pinentry-curses +postfix +procmail +procps +proxmox-archive-keyring +proxmox-backup-client +proxmox-backup-file-restore +proxmox-backup-restore-image +proxmox-default-kernel +proxmox-enterprise-support-keyring +proxmox-firewall +proxmox-first-boot +proxmox-grub +proxmox-kernel-7.0 +proxmox-kernel-7.0.2-6-pve-signed +proxmox-kernel-helper +proxmox-mail-forward +proxmox-mini-journalreader +proxmox-offline-mirror-docs +proxmox-offline-mirror-helper +proxmox-termproxy +proxmox-ve +proxmox-websocket-tunnel +proxmox-widget-toolkit +psmisc +pve-cluster +pve-container +pve-docs +pve-edk2-firmware +pve-edk2-firmware-aarch64 +pve-edk2-firmware-legacy +pve-edk2-firmware-ovmf +pve-esxi-import-tools +pve-firewall +pve-firmware +pve-ha-manager +pve-i18n +pve-lxc-syscalld +pve-manager +pve-nvidia-vgpu-helper +pve-qemu-kvm +pve-xtermjs +pve-yew-mobile-gui +pve-yew-mobile-i18n +python-apt-common +python3 +python3-apt +python3-autocommand +python3-bcrypt +python3-ceph-argparse +python3-ceph-common +python3-cephfs +python3-certifi +python3-cffi-backend +python3-chardet +python3-charset-normalizer +python3-cryptography +python3-dbus +python3-debconf +python3-debian +python3-debianbts +python3-idna +python3-importlib-resources +python3-inflect +python3-jaraco.context +python3-jaraco.functools +python3-jaraco.text +python3-minimal +python3-more-itertools +python3-pefile +python3-pkg-resources +python3-prettytable +python3-pyvmomi +python3-rados +python3-rbd +python3-reportbug +python3-requests +python3-rgw +python3-setuptools +python3-six +python3-systemd +python3-typeguard +python3-typing-extensions +python3-urllib3 +python3-virt-firmware +python3-wcwidth +python3-yaml +python3-zipp +python3.13 +python3.13-minimal +qemu-server +qrencode +readline-common +reportbug +rpcbind +rrdcached +rsync +runit-helper +samba-common +samba-libs +sed +sensible-utils +shared-mime-info +shim-helpers-amd64-signed +shim-signed +shim-signed-common +shim-unsigned +skopeo +smartmontools +smbclient +socat +spiceterm +sqlite3 +sqv +ssh +strace +sudo +swtpm +swtpm-libs +swtpm-tools +systemd +systemd-boot-efi +systemd-boot-tools +systemd-sysv +sysvinit-utils +tailscale +tailscale-archive-keyring +tar +tcpdump +thin-provisioning-tools +time +traceroute +tzdata +ucf +udev +uidmap +usbutils +util-linux +util-linux-extra +vim-common +vim-tiny +virtiofsd +vncterm +wamerican +wget +whiptail +wireguard-tools +wtmpdb +xfsprogs +xkb-data +xsltproc +xz-utils +zfs-initramfs +zfs-zed +zfsutils-linux +zlib1g +zstd diff --git a/documentation/audits/os-updates-spike-2026-10-04/partF/dsa-supersede-analysis.txt b/documentation/audits/os-updates-spike-2026-10-04/partF/dsa-supersede-analysis.txt new file mode 100644 index 00000000..da0f8b36 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partF/dsa-supersede-analysis.txt @@ -0,0 +1,68 @@ +# Debian security advisories (DSA) for trixie, 2026-07-04 .. 2026-10-04 (92 days) +# source: salsa.debian.org/security-tracker-team/security-tracker data/DSA/list, fetched 2026-10-04 +advisories with a trixie fix: 167; source packages: 108 +packages with 2+ trixie advisories in the window: 28 + +## a second advisory for the same package within 2 day(s) of the previous: 3 (1.8% of advisories) + chromium: DSA-6482-1 2026-09-03 -> DSA-6484-1 2026-09-05 (2 d) + chromium: DSA-6506-1 2026-09-17 -> DSA-6508-1 2026-09-19 (2 d) + webkit2gtk: DSA-6534-1 2026-10-01 -> DSA-6534-2 2026-10-02 (1 d) + +## a second advisory for the same package within 7 day(s) of the previous: 18 (10.8% of advisories) + linux: DSA-6405-1 2026-07-31 -> DSA-6415-1 2026-08-06 (6 d) + linux: DSA-6466-1 2026-08-25 -> DSA-6477-1 2026-08-29 (4 d) + chromium: DSA-6378-1 2026-07-05 -> DSA-6384-1 2026-07-08 (3 d) + chromium: DSA-6384-1 2026-07-08 -> DSA-6387-1 2026-07-11 (3 d) + chromium: DSA-6387-1 2026-07-11 -> DSA-6390-1 2026-07-16 (5 d) + chromium: DSA-6390-1 2026-07-16 -> DSA-6396-1 2026-07-22 (6 d) + chromium: DSA-6422-1 2026-08-08 -> DSA-6436-1 2026-08-13 (5 d) + chromium: DSA-6436-1 2026-08-13 -> DSA-6455-1 2026-08-20 (7 d) + chromium: DSA-6455-1 2026-08-20 -> DSA-6476-1 2026-08-27 (7 d) + chromium: DSA-6476-1 2026-08-27 -> DSA-6482-1 2026-09-03 (7 d) + chromium: DSA-6482-1 2026-09-03 -> DSA-6484-1 2026-09-05 (2 d) + chromium: DSA-6506-1 2026-09-17 -> DSA-6508-1 2026-09-19 (2 d) + chromium: DSA-6508-1 2026-09-19 -> DSA-6513-1 2026-09-25 (6 d) + chromium: DSA-6513-1 2026-09-25 -> DSA-6535-1 2026-10-01 (6 d) + webkit2gtk: DSA-6534-1 2026-10-01 -> DSA-6534-2 2026-10-02 (1 d) + spip: DSA-6435-1 2026-08-12 -> DSA-6448-1 2026-08-18 (6 d) + spip: DSA-6448-1 2026-08-18 -> DSA-6456-1 2026-08-21 (3 d) + nginx: DSA-6496-1 2026-09-12 -> DSA-6496-2 2026-09-16 (4 d) + +## a second advisory for the same package within 14 day(s) of the previous: 30 (18.0% of advisories) + linux: DSA-6393-1 2026-07-21 -> DSA-6405-1 2026-07-31 (10 d) + linux: DSA-6405-1 2026-07-31 -> DSA-6415-1 2026-08-06 (6 d) + linux: DSA-6466-1 2026-08-25 -> DSA-6477-1 2026-08-29 (4 d) + chromium: DSA-6378-1 2026-07-05 -> DSA-6384-1 2026-07-08 (3 d) + chromium: DSA-6384-1 2026-07-08 -> DSA-6387-1 2026-07-11 (3 d) + chromium: DSA-6387-1 2026-07-11 -> DSA-6390-1 2026-07-16 (5 d) + chromium: DSA-6390-1 2026-07-16 -> DSA-6396-1 2026-07-22 (6 d) + chromium: DSA-6396-1 2026-07-22 -> DSA-6408-1 2026-07-31 (9 d) + chromium: DSA-6408-1 2026-07-31 -> DSA-6422-1 2026-08-08 (8 d) + chromium: DSA-6422-1 2026-08-08 -> DSA-6436-1 2026-08-13 (5 d) + chromium: DSA-6436-1 2026-08-13 -> DSA-6455-1 2026-08-20 (7 d) + chromium: DSA-6455-1 2026-08-20 -> DSA-6476-1 2026-08-27 (7 d) + chromium: DSA-6476-1 2026-08-27 -> DSA-6482-1 2026-09-03 (7 d) + chromium: DSA-6482-1 2026-09-03 -> DSA-6484-1 2026-09-05 (2 d) + chromium: DSA-6484-1 2026-09-05 -> DSA-6506-1 2026-09-17 (12 d) + chromium: DSA-6506-1 2026-09-17 -> DSA-6508-1 2026-09-19 (2 d) + chromium: DSA-6508-1 2026-09-19 -> DSA-6513-1 2026-09-25 (6 d) + chromium: DSA-6513-1 2026-09-25 -> DSA-6535-1 2026-10-01 (6 d) + firefox-esr: DSA-6451-1 2026-08-19 -> DSA-6481-1 2026-09-02 (14 d) + firefox-esr: DSA-6481-1 2026-09-02 -> DSA-6501-1 2026-09-16 (14 d) + firefox-esr: DSA-6501-1 2026-09-16 -> DSA-6533-1 2026-09-30 (14 d) + webkit2gtk: DSA-6534-1 2026-10-01 -> DSA-6534-2 2026-10-02 (1 d) + thunderbird: DSA-6461-1 2026-08-23 -> DSA-6483-1 2026-09-04 (12 d) + thunderbird: DSA-6483-1 2026-09-04 -> DSA-6503-1 2026-09-16 (12 d) + openjdk-21: DSA-6425-1 2026-08-10 -> DSA-6457-1 2026-08-21 (11 d) + openjdk-25: DSA-6431-1 2026-08-11 -> DSA-6460-1 2026-08-23 (12 d) + spip: DSA-6435-1 2026-08-12 -> DSA-6448-1 2026-08-18 (6 d) + spip: DSA-6448-1 2026-08-18 -> DSA-6456-1 2026-08-21 (3 d) + nginx: DSA-6496-1 2026-09-12 -> DSA-6496-2 2026-09-16 (4 d) + tor: DSA-6500-1 2026-09-16 -> DSA-6532-1 2026-09-30 (14 d) + +# RESTRICTED to source packages installed on a box (demo-hp host + 9201 guest + demo-felhom host, 517 source packages) +advisories touching a box package: 20 across 16 source packages: + bind9, expat, gst-plugins-base1.0, libevent, libnet-dns-perl, libpng1.6, librabbitmq, nss, openssl, pcre2, postfix, rsync, samba, unbound, util-linux, zfs-linux +## box packages re-announced within 2 d: 0 +## box packages re-announced within 7 d: 0 +## box packages re-announced within 14 d: 0 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partF/madison-9202-guest.txt b/documentation/audits/os-updates-spike-2026-10-04/partF/madison-9202-guest.txt new file mode 100644 index 00000000..1006dd3e --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partF/madison-9202-guest.txt @@ -0,0 +1,189 @@ +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +### docker-ce (installed: 5:29.8.0-1~debian.13~trixie) + 5:29.8.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.8.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.8.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.2-2~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.3.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.3.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.2.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.2.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.5-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.4.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.1.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.1.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages +### docker-ce-cli (installed: 5:29.8.0-1~debian.13~trixie) + 5:29.8.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.8.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.8.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.7.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.6.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.5.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.2-2~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.4.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.3.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.3.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.2.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.2.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.5-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.1.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:29.0.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.5.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.4.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.3.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.2.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.1.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5:28.1.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages +### containerd.io (installed: 2.3.5-1~debian.13~trixie) + 2.3.6-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.3.5-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.3.4-2~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.3.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.3.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.6-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.5-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.2.0-2~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.1.5-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 1.7.29-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 1.7.28-2~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 1.7.28-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 1.7.28-0~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 1.7.27-1 | https://download.docker.com/linux/debian trixie/stable amd64 Packages +### docker-compose-plugin (installed: 5.5.1-1~debian.13~trixie) + 5.6.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.5.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.5.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.4.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.3.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.3.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.2.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.1.4-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.1.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.1.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.1.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.1.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.0.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.0.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 5.0.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.40.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.40.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.40.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.40.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.39.4-0~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.39.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.39.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.38.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.38.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.37.3-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.36.2-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.35.1-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages + 2.35.0-1~debian.13~trixie | https://download.docker.com/linux/debian trixie/stable amd64 Packages +### openssl (installed: 3.5.6-1~deb13u2) + 3.5.7-1~deb13u3 | http://security.debian.org trixie-security/main amd64 Packages + 3.5.7-1~deb13u2 | http://deb.debian.org/debian trixie/main amd64 Packages +### libssl3t64 (installed: 3.5.6-1~deb13u2) + 3.5.7-1~deb13u3 | http://security.debian.org trixie-security/main amd64 Packages + 3.5.7-1~deb13u2 | http://deb.debian.org/debian trixie/main amd64 Packages +### libexpat1 (installed: 2.7.1-2) + 2.8.3-1~deb13u1 | http://security.debian.org trixie-security/main amd64 Packages + 2.8.3-1~deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages diff --git a/documentation/audits/os-updates-spike-2026-10-04/partF/madison-demo-hp-host.txt b/documentation/audits/os-updates-spike-2026-10-04/partF/madison-demo-hp-host.txt new file mode 100644 index 00000000..c6cc3b8b --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partF/madison-demo-hp-host.txt @@ -0,0 +1,240 @@ +### openssl (installed: 3.5.6-1~deb13u1) + 3.5.7-1~deb13u3 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 3.5.7-1~deb13u2 | http://deb.debian.org/debian trixie/main amd64 Packages +### libssl3t64 (installed: 3.5.6-1~deb13u1) + 3.5.7-1~deb13u3 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 3.5.7-1~deb13u2 | http://deb.debian.org/debian trixie/main amd64 Packages +### bind9-libs (installed: 1:9.20.21-1~deb13u1) + 1:9.20.29-1~deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 1:9.20.26-1~deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages +### libnss3 (installed: 2:3.110-1+deb13u1) + 2:3.110-1+deb13u4 | http://deb.debian.org/debian trixie/main amd64 Packages + 2:3.110-1+deb13u4 | http://security.debian.org/debian-security trixie-security/main amd64 Packages +### libpcre2-8-0 (installed: 10.46-1~deb13u1) + 10.46-1~deb13u3 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 10.46-1~deb13u2 | http://deb.debian.org/debian trixie/main amd64 Packages +### libpng16-16t64 (installed: 1.6.48-1+deb13u5) + 1.6.48-1+deb13u6 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 1.6.48-1+deb13u5 | http://deb.debian.org/debian trixie/main amd64 Packages +### rsync (installed: 3.4.1+ds1-5+deb13u2) + 3.5.0+ds1-0+deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages + 3.4.1+ds1-5+deb13u4 | http://deb.debian.org/debian trixie/main amd64 Packages +### util-linux (installed: 2.41-5) + 2.41.5-0+deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages + 2.41.5-0+deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages +### postfix (installed: 3.10.5-1~deb13u1) + 3.10.13-0+deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages + 3.10.13-0+deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages +### libexpat1 (installed: 2.7.1-2) + 2.8.3-1~deb13u1 | http://deb.debian.org/debian trixie/main amd64 Packages + 2.8.3-1~deb13u1 | http://security.debian.org/debian-security trixie-security/main amd64 Packages +### pve-manager (installed: 9.2.2) + 9.2.21 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.20 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~22 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~21 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~20 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0~8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### proxmox-kernel-7.0 (installed: 7.0.2-6) + 7.0.14-20 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.14-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.12-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.6-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.6-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.2-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-1~rc7+1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-1~rc6+1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### proxmox-default-kernel (installed: 2.1.0) + 2.1.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 2.0.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 2.0.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 2.0.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### pve-container (installed: 6.1.10) + 6.1.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.1.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### lxc-pve (installed: 7.0.0-2) + 7.0.0-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 7.0.0-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.5-4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.5-3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.5-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.5-1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 6.0.4-2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### qemu-server (installed: 9.1.15) + 9.2.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.2.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.4.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.3 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.2 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.1 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.30 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.29 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.28 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.27 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.26 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.25 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.24 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.23 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.22 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.21 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.20 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.19 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.18 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.17 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.16 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.15 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.14 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.13 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.12 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.11 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.10 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.9 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.8 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.7 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.6 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.5 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.4 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages +### proxmox-ve (installed: 9.2.0) + 9.2.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.1.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages + 9.0.0 | http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages diff --git a/documentation/audits/os-updates-spike-2026-10-04/partF/snapshot-debian-org.md b/documentation/audits/os-updates-spike-2026-10-04/partF/snapshot-debian-org.md new file mode 100644 index 00000000..2243c25f --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partF/snapshot-debian-org.md @@ -0,0 +1,12 @@ +# snapshot.debian.org from a box — 2026-10-04 (throwaway `debian:trixie` container on scratch guest 9202; no box source changed) + +- `https` from the bare `debian:trixie` image fails (no `ca-certificates` in the image). `http` is enough: apt checks + the Release signature with Debian's keyring either way. A real box has `ca-certificates`. +- Snapshot dated `20260927T000000Z` (`debian` + `debian-security`): `apt-get update` rc 0, **2.3 s** first run, 1.0 s + second. `madison openssl` → `3.5.7-1~deb13u2` in both. +- Snapshot dated `20260701T000000Z`: `apt-get update` rc 0, **3.0 s** (`Fetched 10.1 MB`); `madison openssl` → + `3.5.6-1~deb13u2` (security) and `3.5.6-1~deb13u1` (main). +- `apt-get install --download-only openssl=3.5.6-1~deb13u1` → rc 0, **2.0 s**, `Get:1 http://snapshot.debian.org/archive/debian/20260701T000000Z trixie/main amd64 openssl amd64 3.5.6-1~deb13u1 [1503 kB]`. + The same exact version is GONE from the live archives (`madison-demo-hp-host.txt`: only `3.5.7-1~deb13u2` main, + `3.5.7-1~deb13u3` security) — demo-hp's host runs it today and could not reinstall it from its own sources. +- Container removed (`--rm`), image `debian:trixie` removed from 9202. diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G0.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G0.txt new file mode 100644 index 00000000..d134368d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G0.txt @@ -0,0 +1,38 @@ +### state G0-before 2026-10-04T07:07:32Z +felhom-controller|Up 43 hours (healthy) +filebrowser|Up 2 days (healthy) +paperless-postgres|Up 7 hours (healthy) +paperless-redis|Up 7 hours (healthy) +paperless-webserver|Up 7 hours (healthy) +traefik|Up 2 days +-- container StartedAt / health +/felhom-controller started=2026-10-02T12:04:59.02402118Z health=healthy restarts=0 +/filebrowser started=2026-10-02T05:54:22.153122828Z health=healthy restarts=0 +/paperless-postgres started=2026-10-04T00:30:10.059553145Z health=healthy restarts=0 +/paperless-redis started=2026-10-04T00:30:09.859096526Z health=healthy restarts=0 +/paperless-webserver started=2026-10-04T00:30:20.251130432Z health=healthy restarts=0 +/traefik started=2026-10-01T18:43:53.50474935Z health=none restarts=0 +-- dockerd/containerd +MainPID=219 ActiveEnterTimestamp=Thu 2026-09-24 20:52:51 UTC MainPID=182 ActiveEnterTimestamp=Thu 2026-09-24 20:52:48 UTC +docker server 29.8.0 +-- services (MainPID) +12 +-- processes mapping deleted files (need a restart) + 1 postgres 560815 + 1 postgres 560750 + 1 postgres 559834 + 1 postgres 559833 + 1 postgres 559832 + 1 postgres 559830 + 1 postgres 559829 + 1 postgres 559828 + 1 postgres 559827 + 1 postgres 559826 + 1 postgres 559781 + 1 [celeryd: celer 771631 + 1 [celeryd: celer 560637 +-- disk +rootfs_used_bytes 2027982848 +279 +-- controller health via its own healthcheck +healthy diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G1-after.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G1-after.txt new file mode 100644 index 00000000..8fbd550d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G1-after.txt @@ -0,0 +1,65 @@ +### state G1-after 2026-10-04T07:10:39Z +felhom-controller|Up 43 hours (healthy) +filebrowser|Up 2 days (healthy) +paperless-postgres|Up 7 hours (healthy) +paperless-redis|Up 7 hours (healthy) +paperless-webserver|Up 7 hours (healthy) +traefik|Up 2 days +-- container StartedAt / health +/felhom-controller started=2026-10-02T12:04:59.02402118Z health=healthy restarts=0 +/filebrowser started=2026-10-02T05:54:22.153122828Z health=healthy restarts=0 +/paperless-postgres started=2026-10-04T00:30:10.059553145Z health=healthy restarts=0 +/paperless-redis started=2026-10-04T00:30:09.859096526Z health=healthy restarts=0 +/paperless-webserver started=2026-10-04T00:30:20.251130432Z health=healthy restarts=0 +/traefik started=2026-10-01T18:43:53.50474935Z health=none restarts=0 +-- dockerd/containerd +MainPID=219 ActiveEnterTimestamp=Thu 2026-09-24 20:52:51 UTC MainPID=182 ActiveEnterTimestamp=Thu 2026-09-24 20:52:48 UTC +docker server 29.8.0 +12 +-- processes mapping deleted files (need a restart) + 1 systemd-logind 160 + 1 sshd 173 + 1 postgres 560815 + 1 postgres 560750 + 1 postgres 559834 + 1 postgres 559833 + 1 postgres 559832 + 1 postgres 559830 + 1 postgres 559829 + 1 postgres 559828 + 1 postgres 559827 + 1 postgres 559826 + 1 postgres 559781 + 1 dockerd 219 + 1 docker-proxy 2917293 + 1 docker-proxy 2917286 + 1 docker-proxy 2917272 + 1 docker-proxy 2917266 + 1 dhclient 104 + 1 dbus-daemon 156 + 1 cron 155 + 1 containerd 182 + 1 agetty 172 + 1 agetty 171 + 1 agetty 170 + 1 [celeryd: celer 775036 + 1 [celeryd: celer 560637 +-- disk +rootfs_used_bytes 2227740672 +279 +-- controller health via its own healthcheck +healthy +-- services whose MainPID changed: +< postfix.service 333 +> postfix.service 777684 +< systemd-journald.service 46 +> systemd-journald.service 777499 +< systemd-networkd.service 102 +> systemd-networkd.service 777492 +-- sampler: distinct container states during the run + 13 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +13 +-- packages changed: +49 +Unpacking libc6:amd64 (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Setting up libc6:amd64 (2.41-12+deb13u4) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G1.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G1.txt new file mode 100644 index 00000000..3d27f5e4 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G1.txt @@ -0,0 +1,13 @@ +update_rc=0 +debian_packages=49 +49 upgraded, 0 newly installed, 0 to remove and 5 not upgraded. +rootfs_used_before 2215141376 +apt_cache_before 0 /var/cache/apt/archives +apt_rc=0 seconds=24.0 +Need to get 38.1 MB of archives. +Fetched 38.1 MB in 2s (21.1 MB/s) +apt_cache_after 38141568 /var/cache/apt/archives +rootfs_used_after 2267279360 +rootfs_used_after_clean 2133901312 +pending_debian_after=0 +Restarting postfix diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G2.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G2.txt new file mode 100644 index 00000000..e2fe7a82 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G2.txt @@ -0,0 +1,6 @@ +stop=5s restore=30s rc=0 start=3s +all healthy after start: 35s (healthy ) total_downtime=73s +mp8: /mnt/hdd_1/scratch-drives/scratch_hdd,mp=/mnt/felhom-drives/scratch_hdd +mp9: /var/lib/felhom-agent/guests/9202/bootstrap,mp=/etc/felhom-bootstrap,ro=1 +onboot: 1 +2.41-12+deb13u3 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G3a.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G3a.txt new file mode 100644 index 00000000..af8e2814 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G3a.txt @@ -0,0 +1,33 @@ +predownloaded_rc=0 +bash: line 8: 2586 Killed nohup apt-get install -y -q --only-upgrade -o Dpkg::Options::=--force-confold -o Dpkg::Options::=--force-confdef $pkgs > /root/apt-kill.log 2>&1 +procs-checked +killed_after_unpacking=15 setting_up=9 +Preparing to unpack .../libsmartcols1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libsmartcols1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +=== dpkg --audit +The following packages have been unpacked but not yet configured. +They must be configured using dpkg --configure or the configure +menu option in dselect for them to work: + bsdextrautils extra utilities from 4.4BSD-Lite + libperl5.40:amd64 shared Perl library + libsmartcols1:amd64 smart column output alignment library + perl Larry Wall's Practical Extraction and Report Language + perl-modules-5.40 Core Perl modules + util-linux-extra interactive login tools + +The following packages have been triggered, but the trigger processing +has not yet been done. Trigger processing can be requested using +dselect or dpkg --configure --pending (or dpkg --triggers-only): + debianutils Miscellaneous utilities specific to Debian +=== non-ii states +iU bsdextrautils 2.41.5-0+deb13u1 +it debianutils 5.23.2 +ic ifupdown 0.8.44+deb13u1 +it libc-bin 2.41-12+deb13u3 +iU libperl5.40:amd64 5.40.1-6+deb13u1 +iU libsmartcols1:amd64 2.41.5-0+deb13u1 +it man-db 2.13.1-1 +iU perl 5.40.1-6+deb13u1 +iU perl-modules-5.40 5.40.1-6+deb13u1 +it systemd 257.13-1~deb13u1 +iU util-linux-extra 2.41.5-0+deb13u1 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G3b.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G3b.txt new file mode 100644 index 00000000..abd9c787 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G3b.txt @@ -0,0 +1,18 @@ +=== a normal apt run on the half state: +E: Unmet dependencies. Try 'apt --fix-broken install' with no packages (or specify a solution). +E: The following information from --solver 3.0 may provide additional context: +=== containers still up? 6 running +dpkg --configure -a rc=0 seconds=1.4 +apt-get -f install rc=0 seconds=3.9 +The following packages will be upgraded: +5 upgraded, 0 newly installed, 0 to remove and 34 not upgraded. +=== audit after repair: '' +debian still pending after repair: 29 +apply-rest rc=0 seconds=14.1 +pending_debian_after=0 audit='' non-ii=1 +libc6 2.41-12+deb13u4 +felhom-controller running healthy started=2026-10-04T07:11:49.139954487Z +paperless-webserver running healthy started=2026-10-04T07:11:48.013778202Z +paperless-postgres running healthy started=2026-10-04T07:11:48.01752134Z +paperless-redis running healthy started=2026-10-04T07:11:47.987771038Z +filebrowser running healthy started=2026-10-04T07:11:48.006218038Z diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G4-liverestore-off-restart-dockerd.log b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-liverestore-off-restart-dockerd.log new file mode 100644 index 00000000..d744eef6 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-liverestore-off-restart-dockerd.log @@ -0,0 +1,60 @@ +Oct 04 07:19:54 demo-hp-scratch dockerd[19145]: time="2026-10-04T07:19:54.336932886Z" level=info msg="Processing signal 'terminated'" +Oct 04 07:19:54 demo-hp-scratch systemd[1]: Stopping docker.service - Docker Application Container Engine... +Oct 04 07:19:54 demo-hp-scratch dockerd[19145]: time="2026-10-04T07:19:54.338693200Z" level=info msg="Daemon shutdown complete" +Oct 04 07:19:54 demo-hp-scratch systemd[1]: docker.service: Deactivated successfully. +Oct 04 07:19:54 demo-hp-scratch systemd[1]: Stopped docker.service - Docker Application Container Engine. +Oct 04 07:19:54 demo-hp-scratch systemd[1]: docker.service: Consumed 1.323s CPU time, 46.9M memory peak. +Oct 04 07:19:54 demo-hp-scratch systemd[1]: Starting docker.service - Docker Application Container Engine... +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.413444879Z" level=info msg="Starting up" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.414672677Z" level=info msg="OTEL tracing is not configured, using no-op tracer provider" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.414780020Z" level=info msg="CDI directory does not exist, skipping" dir=/etc/cdi +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.414794006Z" level=info msg="CDI directory does not exist, skipping" dir=/var/run/cdi +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.427216451Z" level=info msg="loaded extension" extension=org.mobyproject.namesgenerator.legacy.v1 origin=builtin providers="[org.mobyproject.extension.containernamegenerator.v0 org.mobyproject.extension.servicenamegenerator.v0]" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.427759176Z" level=info msg="Creating a containerd client" address=/run/containerd/containerd.sock timeout=1m0s +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.428634258Z" level=warning msg="failed check for fsverity support" error="enable fsverity failed: operation not supported" path=/var/lib/docker/plugins/storage +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.441390293Z" level=info msg="Loading containers: start." +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.442549242Z" level=info msg="NRI is disabled" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.457828741Z" level=info msg="[graphdriver] using prior storage driver: overlay2" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.470515805Z" level=info msg="Restoring containers: start." +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.506950348Z" level=info msg="stopping restart-manager" container=364d78f29dbd0fe032ed4f518c4857bcb11b540f313aba1a827908537c161aea +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.507149384Z" level=info msg="stopping restart-manager" container=1fe604f923b72e6b21c751405ac51f036ec68f6e4722a3421574fcbb1bd14988 +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.507709932Z" level=info msg="stopping restart-manager" container=468aa784345bb2e83e1a106f6228b21b6337c4edf39e753d3d616fc7af24bc1a +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.509243848Z" level=info msg="stopping restart-manager" container=6e74bb6ff70b96fe0a9c96460a6e26fab42609e5a94a06410c9e4e066d9bcb58 +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.509258466Z" level=info msg="stopping restart-manager" container=2d6019eb004201a749ba8bc613a1ccd2e66178dba702861bebc0cf219662bb4c +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.510270206Z" level=info msg="stopping restart-manager" container=1b8dc9032f367d183dcce12bb714a9758c5857364c31eb85c9908e885db10f90 +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.573011328Z" level=info msg="received task-delete event from containerd" container=364d78f29dbd0fe032ed4f518c4857bcb11b540f313aba1a827908537c161aea module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.594911268Z" level=info msg="received task-delete event from containerd" container=1fe604f923b72e6b21c751405ac51f036ec68f6e4722a3421574fcbb1bd14988 module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.666156366Z" level=info msg="received task-delete event from containerd" container=2d6019eb004201a749ba8bc613a1ccd2e66178dba702861bebc0cf219662bb4c module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" +Oct 04 07:19:54 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:19:54.686060458Z" level=info msg="received task-delete event from containerd" container=468aa784345bb2e83e1a106f6228b21b6337c4edf39e753d3d616fc7af24bc1a module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" +Oct 04 07:20:00 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:00.834142005Z" level=info msg="received task-delete event from containerd" container=1b8dc9032f367d183dcce12bb714a9758c5857364c31eb85c9908e885db10f90 module=libcontainerd namespace=moby topic=/tasks/delete type="*events.TaskDelete" +Oct 04 07:20:00 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:00.915502984Z" level=info msg="Deleting nftables IPv4 rules" error="running nft: /dev/stdin:1:17-30: Error: Could not process rule: No such file or directory\ndelete table ip docker-bridges\n ^^^^^^^^^^^^^^\n exit status 1" +Oct 04 07:20:00 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:00.942555191Z" level=info msg="Deleting nftables IPv6 rules" error="running nft: /dev/stdin:1:18-31: Error: Could not process rule: No such file or directory\ndelete table ip6 docker-bridges\n ^^^^^^^^^^^^^^\n exit status 1" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.608426239Z" level=info msg="Removing stale sandbox" cid=364d78f29dbd isRestore=false sid=3b5209572bb3 +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.708020003Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.733439128Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.754402839Z" level=info msg="Removing stale sandbox" cid=2d6019eb0042 isRestore=false sid=5fa779737dfa +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.759713186Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.784344352Z" level=info msg="Removing stale sandbox" cid=1b8dc9032f36 isRestore=false sid=741b9879ae76 +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.789492312Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.814822488Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.837178409Z" level=info msg="Removing stale sandbox" cid=468aa784345b isRestore=false sid=be695568d5c3 +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.843704781Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.866543954Z" level=info msg="Removing stale sandbox" cid=1fe604f923b7 isRestore=false sid=d125d4df7315 +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.873248252Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.894958835Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.923232128Z" level=info msg="Removing stale sandbox" cid=6e74bb6ff70b isRestore=false sid=050407160c7c +Oct 04 07:20:01 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:01.928597067Z" level=warning msg="Failed deleting service host entries to the running container: open : no such file or directory" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091241418Z" level=warning msg="error locating sandbox id be695568d5c378c13e4d096645e6a2eecea4b11a25e834df6d49458dc74a3772: sandbox be695568d5c378c13e4d096645e6a2eecea4b11a25e834df6d49458dc74a3772 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091279229Z" level=warning msg="error locating sandbox id 050407160c7c7550ed00c1dc0b65234664b469cde7164051d24f84c22a44a158: sandbox 050407160c7c7550ed00c1dc0b65234664b469cde7164051d24f84c22a44a158 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091293847Z" level=warning msg="error locating sandbox id 5fa779737dfa9bfd46592a5308cb35b603ccc1b953b231930cc42d6e9177ad94: sandbox 5fa779737dfa9bfd46592a5308cb35b603ccc1b953b231930cc42d6e9177ad94 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091312161Z" level=warning msg="error locating sandbox id d125d4df73154d67cd6dfa6b52f7407e4cde0ed195a8b5cdecb447cb9e4c6ea7: sandbox d125d4df73154d67cd6dfa6b52f7407e4cde0ed195a8b5cdecb447cb9e4c6ea7 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091333091Z" level=warning msg="error locating sandbox id 741b9879ae76b7b24f70bbe615f00225ff731a0f417bb7b63148d64a9ba96a13: sandbox 741b9879ae76b7b24f70bbe615f00225ff731a0f417bb7b63148d64a9ba96a13 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091348700Z" level=warning msg="error locating sandbox id 3b5209572bb3696ce54dbecc13c1e08d9d695fd11705329bb080574e1daf8e55: sandbox 3b5209572bb3696ce54dbecc13c1e08d9d695fd11705329bb080574e1daf8e55 not found" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.091624882Z" level=info msg="Loading containers: done." +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.105397686Z" level=info msg="Docker daemon" commit=8af9fe3 containerd-snapshotter=false storage-driver=overlay2 version=29.8.2 +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.105466617Z" level=info msg="Initializing buildkit" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.105683486Z" level=warning msg="failed check for fsverity support" error="enable fsverity failed: operation not supported" path=/var/lib/docker/buildkit/content +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.178443926Z" level=info msg="Completed buildkit initialization" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.185872181Z" level=info msg="Daemon has completed initialization" +Oct 04 07:20:02 demo-hp-scratch dockerd[21083]: time="2026-10-04T07:20:02.186219868Z" level=info msg="API listen on /run/docker.sock" +Oct 04 07:20:02 demo-hp-scratch systemd[1]: Started docker.service - Docker Application Container Engine. diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r1.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r1.txt new file mode 100644 index 00000000..32d98143 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r1.txt @@ -0,0 +1,18 @@ +### r1-setup-down: -> docker 29.7.2 live-restore=false from 29.8.0 +apt_rc=0 apt_seconds=17.0 +all healthy at +41.9s (healthy running ) +server now 29.7.2 containerd 2.3.5-1~debian.13~trixie +paperless front door: 40.5s not-200 (first at +-3.0s, back by +0.0s); controller /api/health: 40.5s not-200 +containers restarted: 6 of 6 +controller log since step (warnings/errors/boot): +2026/10/04 07:15:09 notifier.go:1255: [WARN] notifier disabled (no hub configured): DROPPED event controller_started (severity info) — further controller_started events are logged at DEBUG only +### r1-step-nolive: -> docker 29.8.0 live-restore=false from 29.7.2 +apt_rc=0 apt_seconds=14.6 +all healthy at +44.9s (healthy running ) +server now 29.8.0 containerd 2.3.5-1~debian.13~trixie +paperless front door: 43.5s not-200 (first at +-3.0s, back by +0.0s); controller /api/health: 43.5s not-200 +containers restarted: 6 of 6 +controller log since step (warnings/errors/boot): +2026/10/04 07:15:56 notifier.go:1255: [WARN] notifier disabled (no hub configured): DROPPED event controller_started (severity info) — further controller_started events are logged at DEBUG only +r1-setup-down: paperless NO ANSWER 30.0s (from 97.8 to 0.0), controller NO ANSWER 3.0s +r1-step-nolive: paperless NO ANSWER 26.5s (from 145.2 to 177.5), controller NO ANSWER 3.0s diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r2.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r2.txt new file mode 100644 index 00000000..5c1fab2f --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r2.txt @@ -0,0 +1,31 @@ +live-restore=true +### r2-setup-down: -> docker 29.7.2 live-restore=true from 29.8.0 +apt_rc=0 apt_seconds=10.8 +all healthy at +39.6s (healthy running ) +server now 29.7.2 containerd 2.3.5-1~debian.13~trixie +paperless front door: 0.0s NO ANSWER (first at +0.0s, back by +0.0s); controller: 0.0s NO ANSWER +containers restarted: 0 of 6 +controller log since step (warnings/errors/boot): +2026/10/04 07:17:11 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:11 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: +2026/10/04 07:17:21 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:21 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: +2026/10/04 07:17:22 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:22 main.go:899: [WARN] [deadapp] OOM scan failed: exec docker inspect -f {{.Name}}|{{.State.OOMKilled}}|{{.State.StartedAt}} paperless-postgres paperless-redis paperless-webserver: exit status 1 +2026/10/04 07:17:22 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:31 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +### r2-step-live: -> docker 29.8.0 live-restore=true from 29.7.2 +apt_rc=0 apt_seconds=6.6 +all healthy at +35.7s (healthy running ) +server now 29.8.0 containerd 2.3.5-1~debian.13~trixie +paperless front door: 0.0s NO ANSWER (first at +0.0s, back by +0.0s); controller: 0.0s NO ANSWER +containers restarted: 0 of 6 +controller log since step (warnings/errors/boot): +2026/10/04 07:17:51 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1 +2026/10/04 07:17:52 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:52 scheduler.go:360: [ERROR] [scheduler] Job stack-scan failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: exit +2026/10/04 07:17:52 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:52 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: +2026/10/04 07:17:52 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:17:52 main.go:899: [WARN] [deadapp] OOM scan failed: exec docker inspect -f {{.Name}}|{{.State.OOMKilled}}|{{.State.StartedAt}} paperless-postgres paperless-redis paperless-webserver: exit status 1 +2026/10/04 07:17:52 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r3.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r3.txt new file mode 100644 index 00000000..5d483507 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/G4-r3.txt @@ -0,0 +1,15 @@ +### r3-golden-live: -> docker 29.8.2 containerd 2.3.6 live-restore=true from 29.8.0 +apt_rc=0 apt_seconds=9.2 +all healthy at +38.3s (healthy running ) +server now 29.8.2 containerd 2.3.6-1~debian.13~trixie +paperless front door: 0.0s NO ANSWER (first at +0.0s, back by +0.0s); controller: 0.0s NO ANSWER +containers restarted: 0 of 6 +controller log since step (warnings/errors/boot): +2026/10/04 07:18:51 collector.go:107: [WARN] [metrics] docker stats failed: exit status 1 +2026/10/04 07:18:51 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:18:51 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: +2026/10/04 07:18:51 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:18:51 main.go:899: [WARN] [deadapp] OOM scan failed: exec docker inspect -f {{.Name}}|{{.State.OOMKilled}}|{{.State.StartedAt}} paperless-postgres paperless-redis paperless-webserver: exit status 1 +2026/10/04 07:18:52 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:19:01 manager.go:1539: [ERROR] [stacks] execCommand failed: exit status 1 +2026/10/04 07:19:01 scheduler.go:360: [ERROR] [scheduler] Job status-refresh failed: docker ps: exec docker ps -a --format {{.Names}} {{.Image}} {{.State}} {{.Status}} {{.Label "com.docker.compose.project"}} --no-trunc: diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/SUMMARY.md b/documentation/audits/os-updates-spike-2026-10-04/partG/SUMMARY.md new file mode 100644 index 00000000..aa9643a1 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/SUMMARY.md @@ -0,0 +1,25 @@ +# Part G — a guest update end to end, on scratch guest 9202 (demo-hp), 2026-10-04 07:06–07:29 UTC + +Venue facts: 9202's disks are on `nvme-scratch` (a `dir` storage, raw images) — **`pct snapshot` refuses: "snapshot +feature is not available"**. Customer guests (9201 on both demo boxes) are on `local-lvm` (LVM-thin) and can snapshot. +So the undo here was a whole-guest backup (`vzdump --mode snapshot` fell back to `suspend`: 98 s, 1.99 GB) and a +`pct restore --force`. A snapshot rollback on LVM-thin was NOT measured (no fenced venue for it this session). + +| Step | Result | Evidence | +|---|---|---| +| G1 Debian update (49 packages, Docker CE excluded, `--force-confold --force-confdef`, non-interactive) | rc 0, **24.0 s**, `Fetched 38.1 MB`; rootfs +52 MB with the cache, **−81 MB after `apt-get clean`** vs before; no config-file prompt or conflict | `G1.txt`, `g-evidence/apt-run.log` | +| What restarted | maintainer scripts restarted **postfix, systemd-journald, systemd-networkd** (MainPID changed) | `G1-after.txt`, `g-svc-*.txt` | +| What still needs a restart | processes mapping deleted libraries after libc6 `u3→u4`: **dockerd, containerd, docker-proxy ×4, sshd, dbus-daemon, systemd-logind, cron, dhclient, agetty** (postgres/celery inside containers map deleted files from before — container-internal, unrelated) | `G1-after.txt` | +| Containers during the run | **13 samples, 2 s apart: all 6 containers up the whole time**; StartedAt unchanged; controller + every app `healthy` | `g-sampler-G1.txt` | +| G2 undo (restore the pre-update backup) | stop 5 s, **restore 30 s**, start 3 s, all healthy **35 s** after start; **73 s total downtime**; libc6 back to `u3` | `G2.txt`, `g-restore.log` | +| G3 half-done (killed after 15 `Unpacking`, 9 `Setting up`) | 5 packages `iU` (unpacked, not configured), 4 `it` (trigger pending: debianutils, libc-bin, man-db, systemd). **It does NOT recover by itself:** the next ordinary `apt-get install` refuses (`E: Unmet dependencies. Try 'apt --fix-broken install'`). Containers stayed up (6 running). | `G3a.txt`, `g-evidence/apt-kill.log` | +| G3 repair | `dpkg --configure -a` rc 0 **1.4 s**; `apt-get -f install` rc 0 **3.9 s** (5 upgraded); `dpkg --audit` empty; the remaining 29 applied in **14.1 s**; all healthy, nothing restarted | `G3b.txt`, `g-evidence/repair*.log` | +| G4 r1 Docker 29.8.0→29.7.2 (setup), **no live-restore** | apt 17.0 s; **all 6 containers restarted**; paperless front door no answer **30.0 s**; controller no answer 3.0 s; all healthy +41.9 s | `G4-r1.txt`, `g-evidence/g4-probe-r1-*.txt` | +| G4 r1 step 29.7.2→29.8.0, **no live-restore** | apt 14.6 s; **6 of 6 restarted**; paperless no answer **26.5 s**; controller 3.0 s; all healthy **+44.9 s** | same | +| G4 r2 step 29.7.2→29.8.0, **live-restore on** (set by `systemctl reload docker`, which DOES enable it) | apt 6.6 s; **0 of 6 restarted; no gap at either front door**; the controller logged `docker ps` / `docker inspect` / `docker stats` failures for the seconds dockerd was down, and raised **no** app event | `G4-r2.txt` | +| G4 r3 step to the golden's 29.8.2 **and containerd 2.3.5→2.3.6**, live-restore on | apt 9.2 s; **0 of 6 restarted; no gap**, even across the containerd restart | `G4-r3.txt` | +| **Turning live-restore OFF again** | `systemctl reload docker` with the baked `daemon.json` did **not** switch it off (`docker info` still `true`). A `systemctl restart docker` did — and the new dockerd (live-restore off) **stopped every container still running from the old one (`Exited (0)`) and restarted none of them**, although all are `unless-stopped` (`Removing stale sandbox … isRestore=false`). Nothing brought them back for 3.5 min (the host agent supervises 9201 only). `felhom-controller-bootstrap.service` restarted the controller; its boot sweep started traefik and filebrowser but **HELD paperless-ngx**: `drive /mnt/felhom-drives/scratch_hdd/userdata/paperless-ngx is not a live mountpoint` — that app's `app.yaml` `HDD_PATH` names the app's user folder, not the drive (the drive itself IS a mountpoint). Started by hand. | `G4-liverestore-off-restart-dockerd.log` | +| End state | Docker **29.8.2 / containerd 2.3.6** (= golden 0.290.0), `daemon.json` byte-identical to the baked one (`cmp`), live-restore false, Debian fully updated (`docker-compose-plugin` 5.5.1→5.6.0 left pending), all 6 containers healthy | — | + +Measurement note: the first G4 probe counted any non-200 as down; paperless answers 302 and the controller 404 (no Host +header) when up. Re-counted with **no answer (000) = down** from the raw probe files; the table uses the re-count. diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-kill.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-kill.log new file mode 100644 index 00000000..b4c04de9 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-kill.log @@ -0,0 +1,74 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + base-files bash bind9-dnsutils bind9-host bind9-libs bsdextrautils bsdutils + dhcpcd-base e2fsprogs fdisk gzip libaudit-common libaudit1 libblkid1 + libc-bin libc-l10n libc6 libcap2 libcap2-bin libcom-err2 libexpat1 + libext2fs2t64 libfdisk1 liblastlog2-2 libmount1 libpcre2-8-0 libperl5.40 + libpython3.13-minimal libpython3.13-stdlib libsmartcols1 libsqlite3-0 libss2 + libssl3t64 libuuid1 locales login logsave mount openssl + openssl-provider-legacy perl perl-base perl-modules-5.40 postfix python3.13 + python3.13-minimal tzdata util-linux util-linux-extra +apt-listchanges: Reading changelogs... +Preconfiguring packages ... +49 upgraded, 0 newly installed, 0 to remove and 5 not upgraded. +Need to get 0 B/38.1 MB of archives. +After this operation, 297 kB of additional disk space will be used. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21055 files and directories currently installed.) +Preparing to unpack .../libc6_2.41-12+deb13u4_amd64.deb ... +Unpacking libc6:amd64 (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Setting up libc6:amd64 (2.41-12+deb13u4) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21055 files and directories currently installed.) +Preparing to unpack .../base-files_13.8+deb13u7_amd64.deb ... +Unpacking base-files (13.8+deb13u7) over (13.8+deb13u6) ... +Setting up base-files (13.8+deb13u7) ... +Installing new version of config file /etc/debian_version ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../bash_5.2.37-2+b10_amd64.deb ... +Unpacking bash (5.2.37-2+b10) over (5.2.37-2+b9) ... +Setting up bash (5.2.37-2+b10) ... +update-alternatives: using /usr/share/man/man7/bash-builtins.7.gz to provide /usr/share/man/man7/builtins.7.gz (builtins.7.gz) in auto mode +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../bsdutils_1%3a2.41.5-0+deb13u1_amd64.deb ... +Unpacking bsdutils (1:2.41.5-0+deb13u1) over (1:2.41-5) ... +Setting up bsdutils (1:2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../gzip_1.13-1+deb13u1_amd64.deb ... +Unpacking gzip (1.13-1+deb13u1) over (1.13-1) ... +Setting up gzip (1.13-1+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../libperl5.40_5.40.1-6+deb13u1_amd64.deb ... +Unpacking libperl5.40:amd64 (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../perl_5.40.1-6+deb13u1_amd64.deb ... +Unpacking perl (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../perl-base_5.40.1-6+deb13u1_amd64.deb ... +Unpacking perl-base (5.40.1-6+deb13u1) over (5.40.1-6) ... +Setting up perl-base (5.40.1-6+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../perl-modules-5.40_5.40.1-6+deb13u1_all.deb ... +Unpacking perl-modules-5.40 (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../liblastlog2-2_2.41.5-0+deb13u1_amd64.deb ... +Unpacking liblastlog2-2:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up liblastlog2-2:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../bsdextrautils_2.41.5-0+deb13u1_amd64.deb ... +Unpacking bsdextrautils (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../util-linux-extra_2.41.5-0+deb13u1_amd64.deb ... +Leaving 'diversion of /sbin/ctrlaltdel to /sbin/ctrlaltdel.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/fsck.cramfs to /sbin/fsck.cramfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/fsck.minix to /sbin/fsck.minix.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.bfs to /sbin/mkfs.bfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.cramfs to /sbin/mkfs.cramfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.minix to /sbin/mkfs.minix.usr-is-merged by util-linux-extra' +Unpacking util-linux-extra (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libblkid1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libblkid1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libblkid1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../libmount1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libmount1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libmount1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../libsmartcols1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libsmartcols1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-rest.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-rest.log new file mode 100644 index 00000000..3b37b597 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/apt-rest.log @@ -0,0 +1,135 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + bind9-dnsutils bind9-host bind9-libs dhcpcd-base e2fsprogs libaudit-common + libaudit1 libc-bin libc-l10n libcap2 libcap2-bin libcom-err2 libexpat1 + libext2fs2t64 libpcre2-8-0 libpython3.13-minimal libpython3.13-stdlib + libsqlite3-0 libss2 libssl3t64 locales login logsave openssl + openssl-provider-legacy postfix python3.13 python3.13-minimal tzdata +apt-listchanges: Reading changelogs... +Preconfiguring packages ... +29 upgraded, 0 newly installed, 0 to remove and 5 not upgraded. +Need to get 0 B/21.4 MB of archives. +After this operation, 92.2 kB of additional disk space will be used. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21069 files and directories currently installed.) +Preparing to unpack .../libc-bin_2.41-12+deb13u4_amd64.deb ... +Unpacking libc-bin (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Setting up libc-bin (2.41-12+deb13u4) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21069 files and directories currently installed.) +Preparing to unpack .../libaudit-common_1%3a4.0.2-2+deb13u1_all.deb ... +Unpacking libaudit-common (1:4.0.2-2+deb13u1) over (1:4.0.2-2) ... +Setting up libaudit-common (1:4.0.2-2+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21069 files and directories currently installed.) +Preparing to unpack .../libaudit1_1%3a4.0.2-2+deb13u1_amd64.deb ... +Unpacking libaudit1:amd64 (1:4.0.2-2+deb13u1) over (1:4.0.2-2+b2) ... +Setting up libaudit1:amd64 (1:4.0.2-2+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21068 files and directories currently installed.) +Preparing to unpack .../login_1%3a4.16.0-2+really2.41.5-0+deb13u1_amd64.deb ... +Unpacking login (1:4.16.0-2+really2.41.5-0+deb13u1) over (1:4.16.0-2+really2.41-5) ... +Preparing to unpack .../logsave_1.47.2-3+b12_amd64.deb ... +Unpacking logsave (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../libext2fs2t64_1.47.2-3+b12_amd64.deb ... +Leaving 'diversion of /lib/x86_64-linux-gnu/libe2p.so.2 to /lib/x86_64-linux-gnu/libe2p.so.2.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libe2p.so.2.3 to /lib/x86_64-linux-gnu/libe2p.so.2.3.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libext2fs.so.2 to /lib/x86_64-linux-gnu/libext2fs.so.2.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libext2fs.so.2.4 to /lib/x86_64-linux-gnu/libext2fs.so.2.4.usr-is-merged by libext2fs2t64' +Unpacking libext2fs2t64:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Setting up libext2fs2t64:amd64 (1.47.2-3+b12) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../e2fsprogs_1.47.2-3+b12_amd64.deb ... +Unpacking e2fsprogs (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../libexpat1_2.8.3-1~deb13u1_amd64.deb ... +Unpacking libexpat1:amd64 (2.8.3-1~deb13u1) over (2.7.1-2) ... +Preparing to unpack .../openssl-provider-legacy_3.5.7-1~deb13u3_amd64.deb ... +Unpacking openssl-provider-legacy (3.5.7-1~deb13u3) over (3.5.6-1~deb13u2) ... +Setting up openssl-provider-legacy (3.5.7-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../libssl3t64_3.5.7-1~deb13u3_amd64.deb ... +Unpacking libssl3t64:amd64 (3.5.7-1~deb13u3) over (3.5.6-1~deb13u2) ... +Setting up libssl3t64:amd64 (3.5.7-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../0-postfix_3.10.13-0+deb13u1_amd64.deb ... +Unpacking postfix (3.10.13-0+deb13u1) over (3.10.12-0+deb13u2) ... +Preparing to unpack .../1-python3.13_3.13.5-2+deb13u5_amd64.deb ... +Unpacking python3.13 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u3) ... +Preparing to unpack .../2-libpython3.13-stdlib_3.13.5-2+deb13u5_amd64.deb ... +Unpacking libpython3.13-stdlib:amd64 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u3) ... +Preparing to unpack .../3-python3.13-minimal_3.13.5-2+deb13u5_amd64.deb ... +Unpacking python3.13-minimal (3.13.5-2+deb13u5) over (3.13.5-2+deb13u3) ... +Preparing to unpack .../4-libpython3.13-minimal_3.13.5-2+deb13u5_amd64.deb ... +Unpacking libpython3.13-minimal:amd64 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u3) ... +Preparing to unpack .../5-tzdata_2026c-0+deb13u1_all.deb ... +Unpacking tzdata (2026c-0+deb13u1) over (2026b-0+deb13u1) ... +Preparing to unpack .../6-libsqlite3-0_3.46.1-7+deb13u2_amd64.deb ... +Unpacking libsqlite3-0:amd64 (3.46.1-7+deb13u2) over (3.46.1-7+deb13u1) ... +Setting up libsqlite3-0:amd64 (3.46.1-7+deb13u2) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../libcap2_1%3a2.75-10+deb13u1+b3_amd64.deb ... +Unpacking libcap2:amd64 (1:2.75-10+deb13u1+b3) over (1:2.75-10+deb13u1+b1) ... +Setting up libcap2:amd64 (1:2.75-10+deb13u1+b3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../libpcre2-8-0_10.46-1~deb13u3_amd64.deb ... +Unpacking libpcre2-8-0:amd64 (10.46-1~deb13u3) over (10.46-1~deb13u1) ... +Setting up libpcre2-8-0:amd64 (10.46-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../0-dhcpcd-base_1%3a10.1.0-11+deb13u4_amd64.deb ... +Unpacking dhcpcd-base (1:10.1.0-11+deb13u4) over (1:10.1.0-11+deb13u3) ... +Preparing to unpack .../1-bind9-dnsutils_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-dnsutils (1:9.20.29-1~deb13u1) over (1:9.20.23-1~deb13u1) ... +Preparing to unpack .../2-bind9-host_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-host (1:9.20.29-1~deb13u1) over (1:9.20.23-1~deb13u1) ... +Preparing to unpack .../3-bind9-libs_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-libs:amd64 (1:9.20.29-1~deb13u1) over (1:9.20.23-1~deb13u1) ... +Preparing to unpack .../4-libc-l10n_2.41-12+deb13u4_all.deb ... +Unpacking libc-l10n (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Preparing to unpack .../5-locales_2.41-12+deb13u4_all.deb ... +Unpacking locales (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Preparing to unpack .../6-libcap2-bin_1%3a2.75-10+deb13u1+b3_amd64.deb ... +Unpacking libcap2-bin (1:2.75-10+deb13u1+b3) over (1:2.75-10+deb13u1+b1) ... +Preparing to unpack .../7-libcom-err2_1.47.2-3+b12_amd64.deb ... +Unpacking libcom-err2:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../8-libss2_1.47.2-3+b12_amd64.deb ... +Unpacking libss2:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../9-openssl_3.5.7-1~deb13u3_amd64.deb ... +Unpacking openssl (3.5.7-1~deb13u3) over (3.5.6-1~deb13u2) ... +Setting up libexpat1:amd64 (2.8.3-1~deb13u1) ... +Setting up libc-l10n (2.41-12+deb13u4) ... +Setting up bind9-libs:amd64 (1:9.20.29-1~deb13u1) ... +Setting up libcom-err2:amd64 (1.47.2-3+b12) ... +Setting up locales (2.41-12+deb13u4) ... +Generating locales (this might take a while)... +Generation complete. +Setting up tzdata (2026c-0+deb13u1) ... + +Current default time zone: 'Etc/UTC' +Local time is now: Sun Oct 4 07:13:37 UTC 2026. +Universal Time is now: Sun Oct 4 07:13:37 UTC 2026. +Run 'dpkg-reconfigure tzdata' if you wish to change it. + +Setting up libcap2-bin (1:2.75-10+deb13u1+b3) ... +Setting up libpython3.13-minimal:amd64 (3.13.5-2+deb13u5) ... +Setting up libss2:amd64 (1.47.2-3+b12) ... +Setting up dhcpcd-base (1:10.1.0-11+deb13u4) ... +Setting up logsave (1.47.2-3+b12) ... +Setting up postfix (3.10.13-0+deb13u1) ... + +Postfix (main.cf) configuration was not modified by debconf. If you need to +make changes, edit /etc/postfix/main.cf (and others) as needed. To view +Postfix configuration values, see postconf(1). + +After modifying main.cf, be sure to run 'systemctl reload postfix'. + +Setting up python3.13-minimal (3.13.5-2+deb13u5) ... +Setting up bind9-host (1:9.20.29-1~deb13u1) ... +Setting up openssl (3.5.7-1~deb13u3) ... +Setting up libpython3.13-stdlib:amd64 (3.13.5-2+deb13u5) ... +Setting up login (1:4.16.0-2+really2.41.5-0+deb13u1) ... +Setting up python3.13 (3.13.5-2+deb13u5) ... +Setting up e2fsprogs (1.47.2-3+b12) ... +Setting up bind9-dnsutils (1:9.20.29-1~deb13u1) ... +Processing triggers for systemd (257.13-1~deb13u1) ... +Processing triggers for man-db (2.13.1-1) ... +Processing triggers for libc-bin (2.41-12+deb13u4) ... +Processing triggers for postfix (3.10.13-0+deb13u1) ... +Restarting postfix diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-setup-down.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-setup-down.log new file mode 100644 index 00000000..bf58a6de --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-setup-down.log @@ -0,0 +1,26 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be DOWNGRADED: + docker-ce docker-ce-cli docker-ce-rootless-extras +0 upgraded, 0 newly installed, 3 downgraded, 0 to remove and 2 not upgraded. +Need to get 51.2 MB of archives. +After this operation, 4572 kB disk space will be freed. +Get:1 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-cli amd64 5:29.7.2-1~debian.13~trixie [17.0 MB] +Get:2 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce amd64 5:29.7.2-1~debian.13~trixie [24.0 MB] +Get:3 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-rootless-extras amd64 5:29.7.2-1~debian.13~trixie [10.2 MB] +Fetched 51.2 MB in 3s (16.6 MB/s) +dpkg: warning: downgrading docker-ce-cli (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../docker-ce-cli_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-cli (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +dpkg: warning: downgrading docker-ce (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +Preparing to unpack .../docker-ce_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +dpkg: warning: downgrading docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +Preparing to unpack .../docker-ce-rootless-extras_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-rootless-extras (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce-cli (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce-rootless-extras (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce (5:29.7.2-1~debian.13~trixie) ... +Processing triggers for man-db (2.13.1-1) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-step-nolive.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-step-nolive.log new file mode 100644 index 00000000..33c45528 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r1-step-nolive.log @@ -0,0 +1,24 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + docker-ce docker-ce-cli docker-ce-rootless-extras +3 upgraded, 0 newly installed, 0 to remove and 2 not upgraded. +Need to get 52.0 MB of archives. +After this operation, 4572 kB of additional disk space will be used. +Get:1 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-cli amd64 5:29.8.0-1~debian.13~trixie [17.6 MB] +Get:2 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce amd64 5:29.8.0-1~debian.13~trixie [24.3 MB] +Get:3 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-rootless-extras amd64 5:29.8.0-1~debian.13~trixie [10.2 MB] +apt-listchanges: Reading changelogs... +Fetched 52.0 MB in 1s (70.9 MB/s) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../docker-ce-cli_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-cli (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce-rootless-extras_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce-cli (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce (5:29.8.0-1~debian.13~trixie) ... +Processing triggers for man-db (2.13.1-1) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-setup-down.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-setup-down.log new file mode 100644 index 00000000..8f1b4df7 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-setup-down.log @@ -0,0 +1,22 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be DOWNGRADED: + docker-ce docker-ce-cli docker-ce-rootless-extras +0 upgraded, 0 newly installed, 3 downgraded, 0 to remove and 2 not upgraded. +Need to get 0 B/51.2 MB of archives. +After this operation, 4572 kB disk space will be freed. +dpkg: warning: downgrading docker-ce-cli (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../docker-ce-cli_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-cli (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +dpkg: warning: downgrading docker-ce (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +Preparing to unpack .../docker-ce_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +dpkg: warning: downgrading docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) to (5:29.7.2-1~debian.13~trixie) +Preparing to unpack .../docker-ce-rootless-extras_5%3a29.7.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-rootless-extras (5:29.7.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce-cli (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce-rootless-extras (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce (5:29.7.2-1~debian.13~trixie) ... +Processing triggers for man-db (2.13.1-1) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-step-live.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-step-live.log new file mode 100644 index 00000000..c71ab0bb --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r2-step-live.log @@ -0,0 +1,20 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + docker-ce docker-ce-cli docker-ce-rootless-extras +apt-listchanges: Reading changelogs... +3 upgraded, 0 newly installed, 0 to remove and 2 not upgraded. +Need to get 0 B/52.0 MB of archives. +After this operation, 4572 kB of additional disk space will be used. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../docker-ce-cli_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-cli (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce-rootless-extras_5%3a29.8.0-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) over (5:29.7.2-1~debian.13~trixie) ... +Setting up docker-ce-cli (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce-rootless-extras (5:29.8.0-1~debian.13~trixie) ... +Setting up docker-ce (5:29.8.0-1~debian.13~trixie) ... +Processing triggers for man-db (2.13.1-1) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r3-golden-live.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r3-golden-live.log new file mode 100644 index 00000000..b3465546 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-apt-r3-golden-live.log @@ -0,0 +1,28 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + containerd.io docker-ce docker-ce-cli docker-ce-rootless-extras +4 upgraded, 0 newly installed, 0 to remove and 1 not upgraded. +Need to get 75.2 MB of archives. +After this operation, 1140 kB of additional disk space will be used. +Get:1 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-cli amd64 5:29.8.2-1~debian.13~trixie [17.5 MB] +Get:2 https://download.docker.com/linux/debian trixie/stable amd64 containerd.io amd64 2.3.6-1~debian.13~trixie [23.2 MB] +Get:3 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce amd64 5:29.8.2-1~debian.13~trixie [24.3 MB] +Get:4 https://download.docker.com/linux/debian trixie/stable amd64 docker-ce-rootless-extras amd64 5:29.8.2-1~debian.13~trixie [10.2 MB] +apt-listchanges: Reading changelogs... +Fetched 75.2 MB in 1s (79.2 MB/s) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21070 files and directories currently installed.) +Preparing to unpack .../docker-ce-cli_5%3a29.8.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-cli (5:29.8.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +Preparing to unpack .../containerd.io_2.3.6-1~debian.13~trixie_amd64.deb ... +Unpacking containerd.io (2.3.6-1~debian.13~trixie) over (2.3.5-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce_5%3a29.8.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce (5:29.8.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +Preparing to unpack .../docker-ce-rootless-extras_5%3a29.8.2-1~debian.13~trixie_amd64.deb ... +Unpacking docker-ce-rootless-extras (5:29.8.2-1~debian.13~trixie) over (5:29.8.0-1~debian.13~trixie) ... +Setting up containerd.io (2.3.6-1~debian.13~trixie) ... +Setting up docker-ce-cli (5:29.8.2-1~debian.13~trixie) ... +Setting up docker-ce-rootless-extras (5:29.8.2-1~debian.13~trixie) ... +Setting up docker-ce (5:29.8.2-1~debian.13~trixie) ... +Processing triggers for man-db (2.13.1-1) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-setup-down.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-setup-down.txt new file mode 100644 index 00000000..8b6b265e --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-setup-down.txt @@ -0,0 +1,81 @@ +1791098085.594306457 302 404 +1791098086.125913590 302 404 +1791098086.657374607 302 404 +1791098087.189415699 302 404 +1791098087.720901212 302 404 +1791098088.251663430 302 404 +1791098088.785093655 302 404 +1791098089.317596128 302 404 +1791098089.851685679 302 404 +1791098090.381616827 302 404 +1791098090.912356913 302 404 +1791098091.442911348 302 404 +1791098091.973422412 302 404 +1791098092.503653807 302 404 +1791098093.034690232 302 404 +1791098093.568042230 302 404 +1791098094.100970507 302 404 +1791098094.636265874 302 404 +1791098095.168244689 302 404 +1791098095.701980962 302 404 +1791098096.238660442 302 404 +1791098097.781928753 000 000 +1791098099.310531663 000 000 +1791098100.841090617 000 000 +1791098102.372305890 000 000 +1791098103.962540438 000 000 +1791098104.489399206 000 000 +1791098105.034976256 000 404 +1791098105.565666057 000 404 +1791098106.097242311 000 404 +1791098106.628792717 000 404 +1791098107.161483436 000 404 +1791098107.695484179 000 404 +1791098108.226163399 000 404 +1791098108.757921568 000 404 +1791098109.285242999 000 404 +1791098109.817699275 000 404 +1791098110.347103509 000 404 +1791098110.877590136 000 404 +1791098111.409696161 000 404 +1791098111.942443547 000 404 +1791098112.474417422 000 404 +1791098113.007977282 000 404 +1791098113.536931035 000 404 +1791098114.063031641 000 404 +1791098114.594401456 000 404 +1791098115.125723761 000 404 +1791098115.657400706 000 404 +1791098116.189694425 000 404 +1791098116.720650108 000 404 +1791098117.251100828 000 404 +1791098117.777742956 000 404 +1791098118.309989787 000 404 +1791098118.842533628 000 404 +1791098119.373932699 000 404 +1791098119.905676209 000 404 +1791098120.437175689 000 404 +1791098120.968293778 000 404 +1791098121.500919975 000 404 +1791098122.030503477 000 404 +1791098122.564916589 000 404 +1791098123.097732093 000 404 +1791098123.631326348 000 404 +1791098124.163985116 000 404 +1791098124.696410965 000 404 +1791098125.228524895 000 404 +1791098125.761871783 000 404 +1791098126.294097073 000 404 +1791098126.826638149 000 404 +1791098127.368526073 000 404 +1791098127.902420615 000 404 +1791098128.436225578 000 404 +1791098128.970728799 000 404 +1791098129.496038953 000 404 +1791098130.043928749 000 404 +1791098130.571279105 000 404 +1791098131.098966276 000 404 +1791098131.625879767 000 404 +1791098132.152140015 000 404 +1791098132.681127341 000 404 +1791098133.208568128 000 404 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-step-nolive.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-step-nolive.txt new file mode 100644 index 00000000..53216f3d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r1-step-nolive.txt @@ -0,0 +1,87 @@ +1791098135.123601542 302 404 +1791098135.654582794 302 404 +1791098136.184301180 302 404 +1791098136.715023653 302 404 +1791098137.246593695 302 404 +1791098137.776479378 302 404 +1791098138.310435817 302 404 +1791098138.843280015 302 404 +1791098139.376493502 302 404 +1791098139.911787946 302 404 +1791098140.442806328 302 404 +1791098140.971008853 302 404 +1791098141.502373347 302 404 +1791098142.042547085 302 404 +1791098142.578846648 302 404 +1791098143.107687708 302 404 +1791098143.641441765 302 404 +1791098145.173642689 000 000 +1791098146.701547593 000 000 +1791098148.231377811 000 000 +1791098148.783666483 000 000 +1791098150.313128877 000 000 +1791098151.864089871 000 000 +1791098152.398977949 000 404 +1791098152.933323562 000 404 +1791098153.465120874 000 404 +1791098153.997228652 000 404 +1791098154.527471469 000 404 +1791098155.058109542 000 404 +1791098155.589916653 000 404 +1791098156.122079124 000 404 +1791098156.648862680 000 404 +1791098157.177440654 000 404 +1791098157.709761404 000 404 +1791098158.242651159 000 404 +1791098158.774412854 000 404 +1791098159.306626853 000 404 +1791098159.838115331 000 404 +1791098160.369368456 000 404 +1791098160.900248376 000 404 +1791098161.430164646 000 404 +1791098161.963496175 000 404 +1791098162.495479218 000 404 +1791098163.023487957 000 404 +1791098163.556660475 000 404 +1791098164.088948945 000 404 +1791098164.618500065 000 404 +1791098165.149304192 000 404 +1791098165.679817921 000 404 +1791098166.209971138 000 404 +1791098166.744387866 000 404 +1791098167.276832982 000 404 +1791098167.807520979 000 404 +1791098168.339145695 000 404 +1791098168.868862068 000 404 +1791098169.402635612 000 404 +1791098169.939731478 000 404 +1791098170.473657529 000 404 +1791098171.007658071 000 404 +1791098171.552286019 000 404 +1791098172.088640465 000 404 +1791098172.626502959 000 404 +1791098173.157506162 000 404 +1791098173.690022321 000 404 +1791098174.223807597 000 404 +1791098174.756015834 000 404 +1791098175.288765765 000 404 +1791098175.824265458 000 404 +1791098176.357639557 000 404 +1791098176.882988744 000 404 +1791098177.461871919 302 404 +1791098177.995307955 302 404 +1791098178.526249541 302 404 +1791098179.057642810 302 404 +1791098179.588330437 302 404 +1791098180.118453989 302 404 +1791098180.650427363 302 404 +1791098181.180322935 302 404 +1791098181.710638920 302 404 +1791098182.244392355 302 404 +1791098182.774409597 302 404 +1791098183.304735160 302 404 +1791098183.836709116 302 404 +1791098184.367783313 302 404 +1791098184.900043238 302 404 +1791098185.430485361 302 404 +1791098185.960964093 302 404 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-setup-down.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-setup-down.txt new file mode 100644 index 00000000..138cb251 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-setup-down.txt @@ -0,0 +1,86 @@ +1791098219.120482908 302 404 +1791098219.655102218 302 404 +1791098220.185834469 302 404 +1791098220.717232978 302 404 +1791098221.246390776 302 404 +1791098221.776633152 302 404 +1791098222.310947035 302 404 +1791098222.845133278 302 404 +1791098223.385276678 302 404 +1791098223.921073953 302 404 +1791098224.453108362 302 404 +1791098224.983755964 302 404 +1791098225.517156382 302 404 +1791098226.047217597 302 404 +1791098226.577172340 302 404 +1791098227.109193455 302 404 +1791098227.640327464 302 404 +1791098228.171857551 302 404 +1791098228.702209063 302 404 +1791098229.232541830 302 404 +1791098229.763328954 302 404 +1791098230.293034877 302 404 +1791098230.825833389 302 404 +1791098231.361963732 302 404 +1791098231.898903473 302 404 +1791098232.434363871 302 404 +1791098232.964596168 302 404 +1791098233.496742409 302 404 +1791098234.026641938 302 404 +1791098234.559474545 302 404 +1791098235.090511171 302 404 +1791098235.621497232 302 404 +1791098236.151494856 302 404 +1791098236.682266542 302 404 +1791098237.212933180 302 404 +1791098237.744273489 302 404 +1791098238.277242634 302 404 +1791098238.807497784 302 404 +1791098239.337622938 302 404 +1791098239.869966713 302 404 +1791098240.400836554 302 404 +1791098240.936480910 302 404 +1791098241.467625590 302 404 +1791098242.000819949 302 404 +1791098242.533503245 302 404 +1791098243.064315176 302 404 +1791098243.594920798 302 404 +1791098244.125037486 302 404 +1791098244.656601858 302 404 +1791098245.188215413 302 404 +1791098245.719033527 302 404 +1791098246.251268845 302 404 +1791098246.782459973 302 404 +1791098247.314941025 302 404 +1791098247.844819665 302 404 +1791098248.374617321 302 404 +1791098248.906563414 302 404 +1791098249.438782513 302 404 +1791098249.968862131 302 404 +1791098250.498787659 302 404 +1791098251.029140042 302 404 +1791098251.559461337 302 404 +1791098252.091004409 302 404 +1791098252.623426992 302 404 +1791098253.153358662 302 404 +1791098253.685360710 302 404 +1791098254.216842867 302 404 +1791098254.747111383 302 404 +1791098255.278127760 302 404 +1791098255.809203330 302 404 +1791098256.339947815 302 404 +1791098256.870014359 302 404 +1791098257.401704839 302 404 +1791098257.932596522 302 404 +1791098258.464346895 302 404 +1791098258.995820715 302 404 +1791098259.526464069 302 404 +1791098260.059306904 302 404 +1791098260.590179090 302 404 +1791098261.127586494 302 404 +1791098261.665211720 302 404 +1791098262.197780138 302 404 +1791098262.731280085 302 404 +1791098263.262629602 302 404 +1791098263.796922986 302 404 +1791098264.331778392 302 404 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-step-live.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-step-live.txt new file mode 100644 index 00000000..4bd1b8d0 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r2-step-live.txt @@ -0,0 +1,79 @@ +1791098266.322242589 302 404 +1791098266.852827722 302 404 +1791098267.384286134 302 404 +1791098267.915254391 302 404 +1791098268.448421329 302 404 +1791098268.979438007 302 404 +1791098269.512495579 302 404 +1791098270.048658313 302 404 +1791098270.588167777 302 404 +1791098271.123780633 302 404 +1791098271.658241184 302 404 +1791098272.188930463 302 404 +1791098272.720952269 302 404 +1791098273.254066448 302 404 +1791098273.788554230 302 404 +1791098274.320050553 302 404 +1791098274.854406426 302 404 +1791098275.387117644 302 404 +1791098275.918474675 302 404 +1791098276.449377718 302 404 +1791098276.982589861 302 404 +1791098277.514837683 302 404 +1791098278.045647110 302 404 +1791098278.576188090 302 404 +1791098279.105962804 302 404 +1791098279.640149948 302 404 +1791098280.174965940 302 404 +1791098280.706187224 302 404 +1791098281.240709231 302 404 +1791098281.772221014 302 404 +1791098282.303442108 302 404 +1791098282.833739077 302 404 +1791098283.366425057 302 404 +1791098283.899080780 302 404 +1791098284.429294733 302 404 +1791098284.962002143 302 404 +1791098285.493585031 302 404 +1791098286.024416649 302 404 +1791098286.554902555 302 404 +1791098287.085686073 302 404 +1791098287.616035321 302 404 +1791098288.147932282 302 404 +1791098288.679582917 302 404 +1791098289.211265301 302 404 +1791098289.743487616 302 404 +1791098290.273967270 302 404 +1791098290.806287449 302 404 +1791098291.339054212 302 404 +1791098291.873673542 302 404 +1791098292.404620869 302 404 +1791098292.939653069 302 404 +1791098293.470649660 302 404 +1791098294.000529882 302 404 +1791098294.531060603 302 404 +1791098295.062028238 302 404 +1791098295.593170233 302 404 +1791098296.125212397 302 404 +1791098296.657369049 302 404 +1791098297.189064108 302 404 +1791098297.721557153 302 404 +1791098298.253028310 302 404 +1791098298.788297398 302 404 +1791098299.319692009 302 404 +1791098299.850695864 302 404 +1791098300.381759150 302 404 +1791098300.911532860 302 404 +1791098301.443190078 302 404 +1791098301.974455466 302 404 +1791098302.506537976 302 404 +1791098303.037245972 302 404 +1791098303.568348342 302 404 +1791098304.098865808 302 404 +1791098304.628297403 302 404 +1791098305.158391920 302 404 +1791098305.690452209 302 404 +1791098306.222589983 302 404 +1791098306.754290723 302 404 +1791098307.284486762 302 404 +1791098307.815054743 302 404 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r3-golden-live.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r3-golden-live.txt new file mode 100644 index 00000000..499d4f3e --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/g4-probe-r3-golden-live.txt @@ -0,0 +1,84 @@ +1791098323.117720519 302 404 +1791098323.651585765 302 404 +1791098324.188194942 302 404 +1791098324.722935011 302 404 +1791098325.257012778 302 404 +1791098325.789157416 302 404 +1791098326.322875124 302 404 +1791098326.858560517 302 404 +1791098327.395267179 302 404 +1791098327.928122368 302 404 +1791098328.460323052 302 404 +1791098328.989672091 302 404 +1791098329.524300909 302 404 +1791098330.058903809 302 404 +1791098330.591711238 302 404 +1791098331.125726768 302 404 +1791098331.657724228 302 404 +1791098332.188431332 302 404 +1791098332.720621235 302 404 +1791098333.253156591 302 404 +1791098333.784423601 302 404 +1791098334.315512907 302 404 +1791098334.849842710 302 404 +1791098335.377175072 302 404 +1791098335.907885582 302 404 +1791098336.437656248 302 404 +1791098336.969564128 302 404 +1791098337.504143884 302 404 +1791098338.034157087 302 404 +1791098338.564712574 302 404 +1791098339.096036412 302 404 +1791098339.627606766 302 404 +1791098340.161485007 302 404 +1791098340.693393299 302 404 +1791098341.224791537 302 404 +1791098341.755038341 302 404 +1791098342.284708126 302 404 +1791098342.815264366 302 404 +1791098343.346286764 302 404 +1791098343.880452358 302 404 +1791098344.411940566 302 404 +1791098344.943659841 302 404 +1791098345.477682645 302 404 +1791098346.009521496 302 404 +1791098346.540869760 302 404 +1791098347.072943133 302 404 +1791098347.604565685 302 404 +1791098348.134935091 302 404 +1791098348.667101010 302 404 +1791098349.198466918 302 404 +1791098349.729223194 302 404 +1791098350.259496207 302 404 +1791098350.790935022 302 404 +1791098351.325636357 302 404 +1791098351.860122646 302 404 +1791098352.390780497 302 404 +1791098352.927066794 302 404 +1791098353.457129221 302 404 +1791098353.989839988 302 404 +1791098354.523227162 302 404 +1791098355.055636609 302 404 +1791098355.586862162 302 404 +1791098356.118629467 302 404 +1791098356.649535738 302 404 +1791098357.179464411 302 404 +1791098357.710449800 302 404 +1791098358.240562822 302 404 +1791098358.771715247 302 404 +1791098359.303079891 302 404 +1791098359.833160813 302 404 +1791098360.363137818 302 404 +1791098360.894719453 302 404 +1791098361.424357939 302 404 +1791098361.954485048 302 404 +1791098362.483862210 302 404 +1791098363.013551892 302 404 +1791098363.544009265 302 404 +1791098364.073547861 302 404 +1791098364.604621457 302 404 +1791098365.136177444 302 404 +1791098365.667152453 302 404 +1791098366.197811467 302 404 +1791098366.729302531 302 404 +1791098367.260064558 302 404 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair1.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair1.log new file mode 100644 index 00000000..cc382945 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair1.log @@ -0,0 +1,10 @@ +Setting up libsmartcols1:amd64 (2.41.5-0+deb13u1) ... +Setting up perl-modules-5.40 (5.40.1-6+deb13u1) ... +Setting up util-linux-extra (2.41.5-0+deb13u1) ... +Setting up bsdextrautils (2.41.5-0+deb13u1) ... +Setting up libperl5.40:amd64 (5.40.1-6+deb13u1) ... +Setting up perl (5.40.1-6+deb13u1) ... +Processing triggers for libc-bin (2.41-12+deb13u3) ... +Processing triggers for systemd (257.13-1~deb13u1) ... +Processing triggers for man-db (2.13.1-1) ... +Processing triggers for debianutils (5.23.2) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair2.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair2.log new file mode 100644 index 00000000..6cea9f94 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-evidence/repair2.log @@ -0,0 +1,33 @@ +Reading package lists... +Building dependency tree... +Reading state information... +Correcting dependencies... Done +The following additional packages will be installed: + fdisk libfdisk1 libuuid1 mount util-linux +The following packages will be upgraded: + fdisk libfdisk1 libuuid1 mount util-linux +apt-listchanges: Reading changelogs... +5 upgraded, 0 newly installed, 0 to remove and 34 not upgraded. +Need to get 0 B/1817 kB of archives. +After this operation, 30.7 kB of additional disk space will be used. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../fdisk_2.41.5-0+deb13u1_amd64.deb ... +Unpacking fdisk (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libfdisk1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libfdisk1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libuuid1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libuuid1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libuuid1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21064 files and directories currently installed.) +Preparing to unpack .../util-linux_2.41.5-0+deb13u1_amd64.deb ... +Unpacking util-linux (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up util-linux (2.41.5-0+deb13u1) ... +fstrim.service is a disabled or a static unit not running, not starting it. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 21069 files and directories currently installed.) +Preparing to unpack .../mount_2.41.5-0+deb13u1_amd64.deb ... +Unpacking mount (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libfdisk1:amd64 (2.41.5-0+deb13u1) ... +Setting up mount (2.41.5-0+deb13u1) ... +Setting up fdisk (2.41.5-0+deb13u1) ... +Processing triggers for man-db (2.13.1-1) ... +Processing triggers for libc-bin (2.41-12+deb13u3) ... diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-restore.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-restore.log new file mode 100644 index 00000000..efbddfc2 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-restore.log @@ -0,0 +1,17 @@ +recovering backed-up configuration from '/mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tar.zst' +Formatting '/mnt/hdd_1/images/9202/vm-9202-disk-2.raw', fmt=raw size=34359738368 preallocation=off +Creating filesystem with 8388608 4k blocks and 2097152 inodes +Filesystem UUID: ad667f40-a344-4432-a8db-d8bb7dc29527 +Superblock backups stored on blocks: + 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, + 4096000, 7962624 +Formatting '/mnt/hdd_1/images/9202/vm-9202-disk-3.raw', fmt=raw size=75161927680 preallocation=off +Creating filesystem with 18350080 4k blocks and 4587520 inodes +Filesystem UUID: 5283c2e7-70bb-4510-9e2b-2d93ea34fc4d +Superblock backups stored on blocks: + 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, + 4096000, 7962624, 11239424 +restoring '/mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tar.zst' now.. +extracting archive '/mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tar.zst' +Total bytes read: 6532833280 (6.1GiB, 289MiB/s) +merging backed-up and given configuration.. diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-sampler-G1.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-sampler-G1.txt new file mode 100644 index 00000000..8f3de88c --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-sampler-G1.txt @@ -0,0 +1,13 @@ +07:09:51 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:09:54 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:09:57 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:00 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:03 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:06 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:09 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:12 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:15 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:18 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:21 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:24 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days +07:10:27 felhom-controller:Up 43 hours (healthy) filebrowser:Up 2 days (healthy) paperless-postgres:Up 7 hours (healthy) paperless-redis:Up 7 hours (healthy) paperless-webserver:Up 7 hours (healthy) traefik:Up 2 days diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G0-before.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G0-before.txt new file mode 100644 index 00000000..6dde8a4a --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G0-before.txt @@ -0,0 +1,12 @@ +console-getty.service 170 +container-getty@1.service 171 +container-getty@2.service 172 +containerd.service 182 +cron.service 155 +dbus.service 156 +docker.service 219 +postfix.service 333 +ssh.service 173 +systemd-journald.service 46 +systemd-logind.service 160 +systemd-networkd.service 102 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G1-after.txt b/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G1-after.txt new file mode 100644 index 00000000..4c87027b --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-svc-G1-after.txt @@ -0,0 +1,12 @@ +console-getty.service 170 +container-getty@1.service 171 +container-getty@2.service 172 +containerd.service 182 +cron.service 155 +dbus.service 156 +docker.service 219 +postfix.service 777684 +ssh.service 173 +systemd-journald.service 777499 +systemd-logind.service 160 +systemd-networkd.service 777492 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partG/g-vzdump.log b/documentation/audits/os-updates-spike-2026-10-04/partG/g-vzdump.log new file mode 100644 index 00000000..163ec8c9 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partG/g-vzdump.log @@ -0,0 +1,32 @@ +INFO: starting new backup job: vzdump 9202 --dumpdir /mnt/hdd_1/dump-9202-spike --compress zstd --mode snapshot +INFO: Starting Backup of VM 9202 (lxc) +INFO: Backup started at 2026-10-04 09:07:57 +INFO: status = running +INFO: CT Name: demo-hp-scratch +INFO: including mount point rootfs ('/') in backup +INFO: including mount point mp0 ('/var/lib/felhom') in backup +INFO: excluding bind mount point mp8 ('/mnt/felhom-drives/scratch_hdd') from backup (not a volume) +INFO: excluding bind mount point mp9 ('/etc/felhom-bootstrap') from backup (not a volume) +INFO: mode failure - some volumes do not support snapshots +INFO: trying 'suspend' mode instead +INFO: backup mode: suspend +INFO: ionice priority: 7 +INFO: CT Name: demo-hp-scratch +INFO: including mount point rootfs ('/') in backup +INFO: including mount point mp0 ('/var/lib/felhom') in backup +INFO: excluding bind mount point mp8 ('/mnt/felhom-drives/scratch_hdd') from backup (not a volume) +INFO: excluding bind mount point mp9 ('/etc/felhom-bootstrap') from backup (not a volume) +INFO: starting first sync /proc/972848/root/ to /mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tmp +INFO: first sync finished - transferred 6.32G bytes in 40s +INFO: suspending guest +INFO: starting final sync /proc/972848/root/ to /mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tmp +INFO: final sync finished - transferred 3.97M bytes in 7s +INFO: resuming guest +INFO: guest is online again after 7 seconds +INFO: creating vzdump archive '/mnt/hdd_1/dump-9202-spike/vzdump-lxc-9202-2026_10_04-09_07_57.tar.zst' +INFO: Total bytes written: 6532833280 (6.1GiB, 145MiB/s) +INFO: archive file size: 1.99GB +INFO: Finished Backup of VM 9202 (00:01:37) +INFO: Backup finished at 2026-10-04 09:09:34 +INFO: Backup job finished successfully +INFO: notified via target `mail-to-root` diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H-final-host-packages-after.tsv b/documentation/audits/os-updates-spike-2026-10-04/partH/H-final-host-packages-after.tsv new file mode 100644 index 00000000..c671002e --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H-final-host-packages-after.tsv @@ -0,0 +1,747 @@ +ii adduser 3.152 +ii age 1.2.1-1+b5 +ii amd64-microcode 3.20250311.1 +ii apparmor 4.1.1-pmx1 +ii apt 3.0.3 +ii apt-listchanges 4.8 +ii apt-utils 3.0.3 +ii base-files 13.8+deb13u7 +ii base-passwd 3.6.7 +ii bash 5.2.37-2+b10 +ii bash-completion 1:2.16.0-7 +ii bc 1.07.1-4 +ii bind9-dnsutils 1:9.20.29-1~deb13u1 +ii bind9-host 1:9.20.29-1~deb13u1 +ii bind9-libs 1:9.20.29-1~deb13u1 +ii binutils 2.44-3 +ii binutils-common 2.44-3 +ii binutils-x86-64-linux-gnu 2.44-3 +ii bridge-utils 1.7.1-4+b1 +ii bsd-mailx 8.1.2-0.20220412cvs-1.1 +ii bsdextrautils 2.41.5-0+deb13u1 +ii bsdutils 1:2.41.5-0+deb13u1 +ii btrfs-progs 6.14-1 +ii busybox 1:1.37.0-6+b9 +ii bzip2 1.0.8-6 +ii ca-certificates 20250419 +ii ceph-common 19.2.3-pve4 +ii ceph-fuse 19.2.3-pve4 +ii chrony 4.6.1-3+deb13u1 +ii cifs-utils 2:7.4-1 +ii conntrack 1:1.4.8-2 +ii console-setup 1.242~deb13u1 +ii console-setup-linux 1.242~deb13u1 +ii coreutils 9.7-3 +ii corosync 3.1.10-pve2 +ii cpio 2.15+dfsg-2 +ii criu 4.1.1-1 +ii cron 3.0pl1-197 +ii cron-daemon-common 3.0pl1-197 +ii cstream 4.0.0-1 +ii curl 8.14.1-2+deb13u5 +ii dash 0.5.12-12 +ii dbus 1.16.2-2 +ii dbus-bin 1.16.2-2 +ii dbus-daemon 1.16.2-2 +ii dbus-session-bus-common 1.16.2-2 +ii dbus-system-bus-common 1.16.2-2 +ii debconf 1.5.91 +ii debconf-i18n 1.5.91 +ii debian-archive-keyring 2025.1 +ii debian-faq 12.2 +ii debianutils 5.23.2 +ii dhcpcd-base 1:10.1.0-11+deb13u4 +ii diffutils 1:3.10-4 +ii dirmngr 2.4.7-21+deb13u1+b5 +ii distro-info-data 0.66+deb13u2 +ii dmeventd 2:1.02.205-2+pmx1 +ii dmidecode 3.6-2 +ii dmsetup 2:1.02.205-2+pmx1 +ii dns-root-data 2025080400~deb13u1 +ii dnsmasq 2.91-1+deb13u2 +ii dnsmasq-base 2.91-1+deb13u2 +ii doc-debian 11.3+nmu1 +ii dosfstools 4.2-1.2 +ii dpkg 1.22.22 +ii dracut-install 106-6 +ii dtach 0.9-7 +ii e2fsprogs 1.47.2-3+b12 +ii ebtables 2.0.11-6 +ii efibootmgr 18-2 +ii eject 2.41.5-0+deb13u1 +ii ethtool 1:6.14.2-1 +ii faketime 0.9.10+2024-06-05+gba9ed5b2-0.6 +ii fdisk 2.41.5-0+deb13u1 +ii fdutils 5.6-4+b1 +ii felhom-bootstrap 1.26.1 +ii file 1:5.46-5 +ii findutils 4.10.0-3 +ii fontconfig 2.15.0-2.3 +ii fontconfig-config 2.15.0-2.3 +ii fonts-dejavu-core 2.37-8 +ii fonts-dejavu-mono 2.37-8 +ii fonts-font-awesome 5.0.10+really4.7.0~dfsg-4.1 +ii fonts-font-logos 1.0.1-3 +ii frr 10.6.1-1+pve2 +ii frr-pythontools 10.6.1-1+pve2 +ii fuse 3.17.2-3 +ii fuse3 3.17.2-3 +ii gcc-14-base 14.2.0-19 +ii gdisk 1.0.10-2 +ii genisoimage 9:1.1.11-4 +ii gettext-base 0.23.1-2 +ii gnupg 2.4.7-21+deb13u1 +ii gnupg-l10n 2.4.7-21+deb13u1 +ii gnutls-bin 3.8.9-3+deb13u4 +ii golang-github-containers-common 0.62.2+ds1-2 +ii golang-github-containers-image 5.34.2-1 +ii gpg 2.4.7-21+deb13u1+b5 +ii gpg-agent 2.4.7-21+deb13u1+b5 +ii gpgconf 2.4.7-21+deb13u1+b5 +ii gpgsm 2.4.7-21+deb13u1+b5 +ii grep 3.11-4 +ii groff-base 1.23.0-9 +ii grub-common 2.12-9+pmx2 +ii grub-efi-amd64 2.12-9+pmx2 +ii grub-efi-amd64-bin 2.12-9+pmx2 +ii grub-efi-amd64-signed 1+2.12+9+pmx2 +ii grub-efi-amd64-unsigned 2.12-9+pmx2 +ii grub-pc-bin 2.12-9+pmx2 +ii grub2-common 2.12-9+pmx2 +ii gzip 1.13-1+deb13u1 +ii hdparm 9.65+ds-1.1 +ii hostname 3.25 +ii ifupdown2 3.3.0-1+pmx12 +ii inetutils-telnet 2:2.6-3+deb13u3 +ii init 1.69~deb13u1 +ii init-system-helpers 1.69~deb13u1 +ii initramfs-tools 0.148.4 +ii initramfs-tools-bin 0.148.4 +ii initramfs-tools-core 0.148.4 +ii iproute2 6.15.0-1 +ii ipset 7.22-1+b1 +ii iptables 1.8.11-2 +ii iputils-ping 3:20240905-3 +ii isc-dhcp-client 4.4.3-P1-8 +ii iso-codes 4.18.0-1 +ii iucode-tool 2.3.1-3 +ii kbd 2.7.1-2 +ii keyboard-configuration 1.242~deb13u1 +ii keyutils 1.6.3-6 +ii klibc-utils 2.0.14-1 +ii kmod 34.2-2 +ii krb5-locales 1.21.3-5+deb13u1 +ii ksm-control-daemon 1.5-1 +ii less 668-1 +ii libacl1 2.3.2-2+b1 +ii libaio1t64 0.3.113-8+b1 +ii libanyevent-http-perl 2.25-2 +ii libanyevent-perl 7.170-2+b7 +ii libapparmor1 4.1.1-pmx1 +ii libappconfig-perl 1.71-2.3 +ii libapt-pkg-perl 0.1.42 +ii libapt-pkg7.0 3.0.3 +ii libarchive13t64 3.7.4-4+deb13u1 +ii libasound2-data 1.2.14-1+deb13u1 +ii libasound2t64 1.2.14-1+deb13u1 +ii libassuan9 3.0.2-2 +ii libasyncns0 0.8-6+b5 +ii libatomic1 14.2.0-19 +ii libattr1 1:2.5.2-3 +ii libaudit-common 1:4.0.2-2+deb13u1 +ii libaudit1 1:4.0.2-2+deb13u1 +ii libauthen-pam-perl 0.16-6+b4 +ii libavahi-client3 0.8-16 +ii libavahi-common-data 0.8-16 +ii libavahi-common3 0.8-16 +ii libbabeltrace1 1.5.11-4+b2 +ii libbinutils 2.44-3 +ii libblas3 3.12.1-6 +ii libblkid1 2.41.5-0+deb13u1 +ii libbpf1 1:1.5.0-3 +ii libbrotli1 1.1.0-2+b7 +ii libbsd0 0.12.2-2 +ii libbytes-random-secure-perl 0.29-4~deb13u1 +ii libbz2-1.0 1.0.8-6 +ii libc-bin 2.41-12+deb13u4 +ii libc-l10n 2.41-12+deb13u4 +ii libc6 2.41-12+deb13u4 +ii libcairo2 1.18.4-1+b1 +ii libcap-ng0 0.8.5-4+b1 +ii libcap2 1:2.75-10+deb13u1+b3 +ii libcap2-bin 1:2.75-10+deb13u1+b3 +ii libcares2 1.34.5-1+deb13u1 +ii libcbor0.10 0.10.2-2 +ii libcephfs2 19.2.3-pve4 +ii libcfg7 3.1.10-pve2 +ii libclass-methodmaker-perl 2.25-1 +ii libclone-perl 0.47-1+b1 +ii libcmap4 3.1.10-pve2 +ii libcom-err2 1.47.2-3+b12 +ii libcommon-sense-perl 3.75-3+b5 +ii libcompel1 4.1.1-1 +ii libconvert-asn1-perl 0.34-1 +ii libcorosync-common4 3.1.10-pve2 +ii libcpg4 3.1.10-pve2 +ii libcrypt-openssl-bignum-perl 0.09-2+b4 +ii libcrypt-openssl-random-perl 0.17-1+b1 +ii libcrypt-openssl-rsa-perl 0.35-1.1 +ii libcrypt-random-seed-perl 0.03-3 +ii libcrypt-ssleay-perl 0.73.06-2+b4 +ii libcrypt1 1:4.4.38-1 +ii libcryptsetup12 2:2.7.5-2 +ii libctf-nobfd0 2.44-3 +ii libctf0 2.44-3 +ii libcurl3t64-gnutls 8.14.1-2+deb13u5 +ii libcurl4t64 8.14.1-2+deb13u5 +ii libdatrie1 0.2.13-3+b1 +ii libdb5.3t64 5.3.28+dfsg2-9 +ii libdbi1t64 0.9.0-6.1+b1 +ii libdbus-1-3 1.16.2-2 +ii libdebconfclient0 0.280 +ii libdevel-cycle-perl 1.12-2 +ii libdevmapper-event1.02.1 2:1.02.205-2+pmx1 +ii libdevmapper1.02.1 2:1.02.205-2+pmx1 +ii libdigest-hmac-perl 1.05+dfsg-1 +ii libdouble-conversion3 3.3.1-1 +ii libdpkg-perl 1.22.22 +ii libdrm-amdgpu1 2.4.124-2 +ii libdrm-common 2.4.124-2 +ii libdrm-intel1 2.4.124-2 +ii libdrm2 2.4.124-2 +ii libdw1t64 0.192-4 +ii libedit2 3.1-20250104-1 +ii libefiboot1t64 38-3.1+b1 +ii libefivar1t64 38-3.1+b1 +ii libelf1t64 0.192-4 +ii libencode-locale-perl 1.05-3 +ii libepoxy0 1.5.10-2 +ii libevent-2.1-7t64 2.1.13-stable-1~deb13u1 +ii libevent-core-2.1-7t64 2.1.13-stable-1~deb13u1 +ii libexpat1 2.8.3-1~deb13u1 +ii libext2fs2t64 1.47.2-3+b12 +ii libfaketime 0.9.10+2024-06-05+gba9ed5b2-0.6 +ii libfdisk1 2.41.5-0+deb13u1 +ii libfdt1 1.7.2-2+b1 +ii libffi8 3.4.8-2 +ii libfido2-1 1.15.0-1+b1 +ii libfile-chdir-perl 0.1008-1.2 +ii libfile-listing-perl 6.16-1 +ii libfile-readbackwards-perl 1.06-2 +ii libfilesys-df-perl 0.92-7+b4 +ii libflac14 1.5.0+ds-2 +ii libfontconfig1 2.15.0-2.3 +ii libfreetype6 2.13.3+dfsg-1+deb13u1 +ii libfribidi0 1.0.16-1 +ii libfstrm0 0.6.1-1+b3 +ii libfuse2t64 2.9.9-9 +ii libfuse3-4 3.17.2-3 +ii libgbm1 25.0.7-2+deb13u1 +ii libgcc-s1 14.2.0-19 +ii libgcrypt20 1.11.0-7+deb13u1 +ii libgdbm-compat4t64 1.24-2 +ii libgdbm6t64 1.24-2 +ii libglib2.0-0t64 2.84.4-3~deb13u5 +ii libgmp10 2:6.3.0+dfsg-3 +ii libgnutls-dane0t64 3.8.9-3+deb13u4 +ii libgnutls30t64 3.8.9-3+deb13u4 +ii libgoogle-perftools4t64 2.16-1 +ii libgpg-error0 1.51-4 +ii libgpgme11t64 1.24.2-3 +ii libgprofng0 2.44-3 +ii libgraphite2-3 1.3.14-2+deb13u1 +ii libgssapi-krb5-2 1.21.3-5+deb13u1 +ii libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u2 +ii libgstreamer1.0-0 1.26.2-2 +ii libharfbuzz0b 10.2.0-1+deb13u1 +ii libhogweed6t64 3.10.1-1 +ii libhtml-parser-perl 3.83-2~deb13u1 +ii libhtml-tagset-perl 3.24-1 +ii libhtml-tree-perl 5.07-3 +ii libhttp-cookies-perl 6.11-1 +ii libhttp-daemon-perl 6.16-1+deb13u1 +ii libhttp-date-perl 6.06-1 +ii libhttp-message-perl 7.00-2 +ii libhttp-negotiate-perl 6.01-2 +ii libibverbs1 56.1-1 +ii libicu76 76.1-4 +ii libidn2-0 2.3.8-2 +ii libinih1 59-1 +ii libio-html-perl 1.004-3 +ii libio-multiplex-perl 1.16-3 +ii libio-socket-ssl-perl 2.089-1 +ii libio-stringy-perl 2.113-2 +ii libip4tc2 1.8.11-2 +ii libip6tc2 1.8.11-2 +ii libipset13t64 7.22-1+b1 +ii libiscsi7 1.20.0-4 +ii libisns0t64 0.101-1+b1 +ii libjansson4 2.14-2+b3 +ii libjemalloc2 5.3.0-3 +ii libjpeg62-turbo 1:2.1.5-4 +ii libjs-bootstrap5 5.3.5+dfsg-4 +ii libjs-extjs 7.0.0-5 +ii libjs-qrcodejs 1.20230525-pve1 +ii libjson-c5 0.18+ds-1 +ii libjson-glib-1.0-0 1.10.6+ds-2 +ii libjson-glib-1.0-common 1.10.6+ds-2 +ii libjson-perl 4.10000-1 +ii libjson-xs-perl 4.040-1~deb13u1 +ii libk5crypto3 1.21.3-5+deb13u1 +ii libkeyutils1 1.6.3-6 +ii libklibc 2.0.14-1 +ii libkmod2 34.2-2 +ii libknet1t64 1.31-pve1 +ii libkrb5-3 1.21.3-5+deb13u1 +ii libkrb5support0 1.21.3-5+deb13u1 +ii libksba8 1.6.7-2+b1 +ii liblastlog2-2 2.41.5-0+deb13u1 +ii libldap2 2.6.10+dfsg-1 +ii libldb2 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 +ii liblinear4 2.3.0+dfsg-5+b2 +ii liblinux-inotify2-perl 1:2.3-2+b3 +ii libllvm19 1:19.1.7-3+b1 +ii liblmdb0 0.9.31-1+b2 +ii liblocale-gettext-perl 1.07-7+b1 +ii liblockfile-bin 1.17-2 +ii liblockfile1 1.17-2 +ii liblsof0 4.99.4+dfsg-2 +ii liblttng-ust-common1t64 2.13.9-1 +ii liblttng-ust-ctl5t64 2.13.9-1 +ii liblttng-ust1t64 2.13.9-1 +ii liblua5.3-0 5.3.6-2+b4 +ii liblua5.4-0 5.4.7-1+b2 +ii liblvm2cmd2.03 2.03.31-2+pmx1 +ii liblwp-mediatypes-perl 6.04-2 +ii liblwp-protocol-https-perl 6.14-1 +ii liblz4-1 1.10.0-4 +ii liblzma5 5.8.1-1+deb13u1 +ii liblzo2-2 2.10-3+b1 +ii libmagic-mgc 1:5.46-5 +ii libmagic1t64 1:5.46-5 +ii libmath-random-isaac-perl 1.004-2 +ii libmaxminddb0 1.12.2-1 +ii libmd0 1.1.0-2+b1 +ii libmime-base32-perl 1.303-3 +ii libmnl0 1.0.5-3 +ii libmount1 2.41.5-0+deb13u1 +ii libmp3lame0 3.100-6+b3 +ii libmpg123-0t64 1.32.10-1+deb13u1 +ii libnbd0 1.22.2-1+b1 +ii libncurses6 6.5+20250216-2 +ii libncursesw6 6.5+20250216-2 +ii libnet-dbus-perl 1.2.0-2+b3 +ii libnet-dns-perl 1.56-0+deb13u1 +ii libnet-http-perl 6.23-1 +ii libnet-ip-perl 1.26-4 +ii libnet-ldap-perl 1:0.6800+dfsg-1 +ii libnet-ssleay-perl 1.94-3 +ii libnet-subnet-perl 1.03-2 +ii libnet1 1.3+dfsg-2 +ii libnetaddr-ip-perl 4.079+dfsg-2+b5 +ii libnetfilter-conntrack3 1.1.0-1 +ii libnetfilter-log1 1.0.2-4+b1 +ii libnettle8t64 3.10.1-1 +ii libnewt0.52 0.52.25-1 +ii libnfnetlink0 1.0.2-3 +ii libnfsidmap1 1:2.8.3-1 +ii libnftables1 1.1.3-1 +ii libnftnl11 1.2.9-1 +ii libnghttp2-14 1.64.0-1.1+deb13u1 +ii libnghttp3-9 1.8.0-1 +ii libngtcp2-16 1.11.0-1+deb13u1 +ii libngtcp2-crypto-gnutls8 1.11.0-1+deb13u1 +ii libnl-3-200 3.7.0-2 +ii libnl-route-3-200 3.7.0-2 +ii libnozzle1t64 1.31-pve1 +ii libnpth0t64 1.8-3 +ii libnsl2 1.3.0-3+b3 +ii libnspr4 2:4.36-1 +ii libnss-systemd 257.13-1~deb13u1 +ii libnss3 2:3.110-1+deb13u4 +ii libnuma1 2.0.19-1 +ii libnvpair3linux 2.4.2-pve1 +ii liboath0t64 2.6.12-1 +ii libogg0 1.3.5-3+b2 +ii libopeniscsiusr 2.1.11-1+deb13u2 +ii libopus0 1.5.2-2 +ii liborc-0.4-0t64 1:0.4.41-1 +ii libp11-kit0 0.25.5-3 +ii libpam-modules 1.7.0-5 +ii libpam-modules-bin 1.7.0-5 +ii libpam-runtime 1.7.0-5 +ii libpam-systemd 257.13-1~deb13u1 +ii libpam-wtmpdb 0.73.0-3+deb13u1 +ii libpam0g 1.7.0-5 +ii libpango-1.0-0 1.56.3-1 +ii libpangocairo-1.0-0 1.56.3-1 +ii libpangoft2-1.0-0 1.56.3-1 +ii libpcap0.8t64 1.10.5-2 +ii libpci3 1:3.13.0-2 +ii libpciaccess0 0.17-3+b3 +ii libpcre2-16-0 10.46-1~deb13u3 +ii libpcre2-8-0 10.46-1~deb13u3 +ii libpcre2-posix3 10.46-1~deb13u3 +ii libperl5.40 5.40.1-6+deb13u1 +ii libpipeline1 1.5.8-1 +ii libpixman-1-0 0.44.0-3 +ii libpng16-16t64 1.6.48-1+deb13u6 +ii libpopt0 1.19+dfsg-2 +ii libposix-strptime-perl 0.13-2+b4 +ii libproc2-0 2:4.0.4-9 +ii libprotobuf-c1 1.5.1-1 +ii libproxmox-acme-perl 1.7.1 +ii libproxmox-acme-plugins 1.7.1 +ii libproxmox-backup-qemu0 2.0.2 +ii libproxmox-rs-perl 0.4.1 +ii libpsl5t64 0.21.2-1.1+b1 +ii libpulse0 17.0+dfsg1-2+b1 +ii libpve-access-control 9.1.1 +ii libpve-apiclient-perl 3.4.2 +ii libpve-cluster-api-perl 9.1.5 +ii libpve-cluster-perl 9.1.5 +ii libpve-common-perl 9.1.12 +ii libpve-guest-common-perl 6.0.3 +ii libpve-http-server-perl 6.0.5 +ii libpve-network-api-perl 1.6.5 +ii libpve-network-perl 1.6.5 +ii libpve-notify-perl 9.1.5 +ii libpve-rs-perl 0.15.3 +ii libpve-storage-perl 9.1.5 +ii libpython3-stdlib 3.13.5-1 +ii libpython3.13-minimal 3.13.5-2+deb13u5 +ii libpython3.13-stdlib 3.13.5-2+deb13u5 +ii libqb-tools 2.0.8-2+b1 +ii libqb100 2.0.8-2+b1 +ii libqrencode4 4.1.1-2 +ii libqt5core5t64 5.15.15+dfsg-6+deb13u1 +ii libqt5dbus5t64 5.15.15+dfsg-6+deb13u1 +ii libqt5network5t64 5.15.15+dfsg-6+deb13u1 +ii libquorum5 3.1.10-pve2 +ii librabbitmq4 0.15.0-1+deb13u2 +ii librados2 19.2.3-pve4 +ii librados2-perl 1.5.0 +ii libradosstriper1 19.2.3-pve4 +ii librbd1 19.2.3-pve4 +ii librdkafka1 2.8.0-1 +ii librdmacm1t64 56.1-1 +ii libreadline8t64 8.2-6 +ii libreiserfscore0t64 1:3.6.27-9 +ii librgw2 19.2.3-pve4 +ii librrd8t64 1.7.2-4.2+pve4 +ii librrds-perl 1.7.2-4.2+pve4 +ii librtmp1 2.4+20151223.gitfa8646d.1-2+b5 +ii libsasl2-2 2.1.28+dfsg1-9 +ii libsasl2-modules-db 2.1.28+dfsg1-9 +ii libseccomp2 2.6.0-2 +ii libselinux1 3.8.1-1 +ii libsemanage-common 3.8.1-1 +ii libsemanage2 3.8.1-1 +ii libsensors-config 1:3.6.2-2 +ii libsensors5 1:3.6.2-2 +ii libsepol2 3.8.1-1 +ii libsframe1 2.44-3 +ii libslang2 2.3.3-5+b2 +ii libslirp0 4.8.0-1+deb13u1 +ii libsmartcols1 2.41.5-0+deb13u1 +ii libsmbclient0 2:4.22.11+dfsg-0+deb13u1 +ii libsnappy1v5 1.2.2-1 +ii libsndfile1 1.2.2-2+deb13u1 +ii libsndio7.0 1.10.0-0.1 +ii libsocket6-perl 0.29-3+b4 +ii libspice-server1 0.15.2-1+b1 +ii libsqlite3-0 3.46.1-7+deb13u2 +ii libss2 1.47.2-3+b12 +ii libssh2-1t64 1.11.1-1+deb13u2 +ii libssl3t64 3.5.7-1~deb13u3 +ii libstatgrab10t64 0.92.1-1.2 +ii libstdc++6 14.2.0-19 +ii libstring-shellquote-perl 1.04-3 +ii libsubid5 1:4.17.4-2 +ii libsystemd-shared 257.13-1~deb13u1 +ii libsystemd0 257.13-1~deb13u1 +ii libtalloc2 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 +ii libtasn1-6 4.20.0-2+deb13u1 +ii libtcmalloc-minimal4t64 2.16-1 +ii libtdb1 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 +ii libtemplate-perl 2.27-1+b8 +ii libterm-readline-gnu-perl 1.46-1+b3 +ii libtevent0t64 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 +ii libtext-charwidth-perl 0.04-11+b4 +ii libtext-iconv-perl 1.7-8+b4 +ii libtext-wrapi18n-perl 0.06-10 +ii libthai-data 0.1.29-2 +ii libthai0 0.1.29-2+b1 +ii libthrift-0.19.0t64 0.19.0-4+b1 +ii libtimedate-perl 2.3300-2 +ii libtinfo6 6.5+20250216-2 +ii libtirpc-common 1.3.6+ds-1 +ii libtirpc3t64 1.3.6+ds-1 +ii libtlsrpt0 0.5.0rc1-2 +ii libtpms0 0.9.7+pve2 +ii libtry-tiny-perl 0.32-1 +ii libtypes-serialiser-perl 1.01-1 +ii libuchardet0 0.0.8-1+b2 +ii libudev1 257.13-1~deb13u1 +ii libunbound8 1.26.1-0+deb13u1 +ii libunistring5 1.3-2 +ii libunwind8 1.8.1-0.1 +ii liburcu8t64 0.15.2-2 +ii liburi-perl 5.30-1 +ii liburing2 2.9-1 +ii libusb-1.0-0 2:1.0.28-1 +ii libusbredirparser1t64 0.15.0-1 +ii libuuid-perl 0.37-1 +ii libuuid1 2.41.5-0+deb13u1 +ii libuutil3linux 2.4.2-pve1 +ii libuv1t64 1.50.0-2 +ii libva-drm2 2.22.0-3 +ii libva2 2.22.0-3 +ii libvirglrenderer1 1.1.0-2 +ii libvorbis0a 1.3.7-3 +ii libvorbisenc2 1.3.7-3 +ii libvotequorum8 3.1.10-pve2 +ii libvulkan1 1.4.309.0-1 +ii libwayland-server0 1.23.1-3 +ii libwbclient0 2:4.22.11+dfsg-0+deb13u1 +ii libwrap0 7.6.q-36 +ii libwtmpdb0 0.73.0-3+deb13u1 +ii libwww-perl 6.78-1 +ii libwww-robotrules-perl 6.02-1 +ii libx11-6 2:1.8.12-1 +ii libx11-data 2:1.8.12-1 +ii libx11-xcb1 2:1.8.12-1 +ii libxau6 1:1.0.11-1 +ii libxcb-dri3-0 1.17.0-2+b1 +ii libxcb-present0 1.17.0-2+b1 +ii libxcb-randr0 1.17.0-2+b1 +ii libxcb-render0 1.17.0-2+b1 +ii libxcb-shm0 1.17.0-2+b1 +ii libxcb-sync1 1.17.0-2+b1 +ii libxcb-xfixes0 1.17.0-2+b1 +ii libxcb1 1.17.0-2+b1 +ii libxdmcp6 1:1.1.5-1 +ii libxext6 2:1.3.4-1+b3 +ii libxkbcommon0 1.7.0-2 +ii libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+deb13u1 +ii libxml-namespacesupport-perl 1.12-2 +ii libxml-parser-perl 2.47-2~deb13u1 +ii libxml-sax-base-perl 1.09-3 +ii libxml-sax-perl 1.02+dfsg-4 +ii libxml-twig-perl 1:3.52-3 +ii libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 +ii libxrender1 1:0.9.12-1 +ii libxshmfence1 1.3.3-1 +ii libxslt1.1 1.1.35-1.2+deb13u3 +ii libxtables12 1.8.11-2 +ii libxxhash0 0.8.3-2 +ii libyaml-0-2 0.2.5-2 +ii libyaml-libyaml-perl 0.903.0+ds-1 +ii libyang3 3.12.2-1 +ii libz3-4 4.13.3-1 +ii libzfs7linux 2.4.2-pve1 +ii libzpool7linux 2.4.2-pve1 +ii libzstd1 1.5.7+dfsg-1 +ii linux-base 4.12.1 +ii linux-sysctl-defaults 4.12.1 +ii locales 2.41-12+deb13u4 +ii login 1:4.16.0-2+really2.41.5-0+deb13u1 +ii login.defs 1:4.17.4-2 +ii logrotate 3.22.0-1 +ii logsave 1.47.2-3+b12 +ii lsof 4.99.4+dfsg-2 +ii lvm2 2.03.31-2+pmx1 +ii lxc-pve 7.0.0-2 +ii lxcfs 7.0.0-pve1 +ii lzop 1.04-2 +ii man-db 2.13.1-1 +ii manpages 6.9.1-1 +ii mawk 1.3.4.20250131-1 +ii media-types 13.0.0 +ii memtest86+ 7.20-1 +ii mesa-libgallium 25.0.7-2+deb13u1 +ii mokutil 0.7.2-1 +ii mount 2.41.5-0+deb13u1 +ii nano 8.4-1+deb13u1 +ii ncurses-base 6.5+20250216-2 +ii ncurses-bin 6.5+20250216-2 +ii ncurses-term 6.5+20250216-2 +ii netavark 1.14.0-2 +ii netbase 6.5 +ii netcat-traditional 1.10-50 +ii nfs-common 1:2.8.3-1 +ii nftables 1.1.3-1 +ii nmap 7.95+dfsg-3 +ii nmap-common 7.95+dfsg-3 +ii node-popper2 2.11.2-8 +ii novnc-pve 1.7.0-1 +ii numactl 2.0.19-1 +ii open-iscsi 2.1.11-1+deb13u2 +ii openssh-client 1:10.0p1-7+deb13u4 +ii openssh-server 1:10.0p1-7+deb13u4 +ii openssh-sftp-server 1:10.0p1-7+deb13u4 +ii openssl 3.5.7-1~deb13u3 +ii openssl-provider-legacy 3.5.7-1~deb13u3 +ii passwd 1:4.17.4-2 +ii pci.ids 0.0~2025.06.09-1 +ii pciutils 1:3.13.0-2 +ii perl 5.40.1-6+deb13u1 +ii perl-base 5.40.1-6+deb13u1 +ii perl-modules-5.40 5.40.1-6+deb13u1 +ii perl-openssl-defaults 7+b2 +ii pinentry-curses 1.3.1-2 +ii postfix 3.10.13-0+deb13u1 +ii procmail 3.24+really3.22-4 +ii procps 2:4.0.4-9 +ii proxmox-archive-keyring 4.0 +ii proxmox-backup-client 4.2.0-1 +ii proxmox-backup-file-restore 4.2.0-1 +ii proxmox-backup-restore-image 1.0.0 +ii proxmox-default-kernel 2.1.0 +ii proxmox-enterprise-support-keyring 1.0 +ii proxmox-firewall 1.2.3 +ii proxmox-grub 2.12-9+pmx2 +ii proxmox-kernel-7.0 7.0.14-20 +ii proxmox-kernel-7.0.14-20-pve-signed 7.0.14-20 +ii proxmox-kernel-7.0.2-6-pve-signed 7.0.2-6 +ii proxmox-kernel-helper 9.1.0+fde2 +ii proxmox-mail-forward 1.0.3 +ii proxmox-mini-journalreader 1.6 +ii proxmox-offline-mirror-docs 0.7.4 +ii proxmox-offline-mirror-helper 0.7.4 +ii proxmox-secure-boot-support 2.0.6 +ii proxmox-termproxy 2.1.0 +ii proxmox-ve 9.2.0 +ii proxmox-websocket-tunnel 1.0.0 +ii proxmox-widget-toolkit 5.2.2 +ii psmisc 23.7-2 +ii pve-cluster 9.1.5 +ii pve-container 6.1.10 +ii pve-docs 9.2.1 +ii pve-edk2-firmware 4.2025.05-2 +ii pve-edk2-firmware-aarch64 4.2025.05-2 +ii pve-edk2-firmware-legacy 4.2025.05-2 +ii pve-edk2-firmware-ovmf 4.2025.05-2 +ii pve-esxi-import-tools 1.0.1 +ii pve-firewall 6.0.4 +ii pve-firmware 3.18-3 +ii pve-ha-manager 5.2.4 +ii pve-i18n 3.7.4 +ii pve-lxc-syscalld 2.0.2 +ii pve-manager 9.2.2 +ii pve-nvidia-vgpu-helper 0.3.1 +ii pve-qemu-kvm 11.0.0-3 +ii pve-xtermjs 6.0.0-1 +ii pve-yew-mobile-gui 0.7.0 +ii pve-yew-mobile-i18n 3.7.4 +ii python-apt-common 3.0.0 +ii python3 3.13.5-1 +ii python3-apt 3.0.0 +ii python3-autocommand 2.2.2-3 +ii python3-bcrypt 4.2.0-2.1+b1 +ii python3-ceph-argparse 19.2.3-pve4 +ii python3-ceph-common 19.2.3-pve4 +ii python3-cephfs 19.2.3-pve4 +ii python3-certifi 2025.1.31+ds-1 +ii python3-cffi-backend 1.17.1-3 +ii python3-chardet 5.2.0+dfsg-2 +ii python3-charset-normalizer 3.4.2-1 +ii python3-cryptography 43.0.0-3+deb13u1 +ii python3-dbus 1.4.0-1 +ii python3-debconf 1.5.91 +ii python3-debian 1.0.1 +ii python3-debianbts 4.1.1 +ii python3-idna 3.10-1+deb13u1 +ii python3-importlib-resources 6.5.2-1 +ii python3-inflect 7.3.1-2 +ii python3-jaraco.context 6.0.1-1+deb13u1 +ii python3-jaraco.functools 4.1.0-1 +ii python3-jaraco.text 4.0.0-1 +ii python3-minimal 3.13.5-1 +ii python3-more-itertools 10.7.0-1 +ii python3-pefile 2024.8.26-2.1 +ii python3-pkg-resources 78.1.1-0.1 +ii python3-prettytable 3.15.1-1 +ii python3-pyvmomi 8.0.3.0.1-1 +ii python3-rados 19.2.3-pve4 +ii python3-rbd 19.2.3-pve4 +ii python3-reportbug 13.2.0 +ii python3-requests 2.32.3+dfsg-5+deb13u1 +ii python3-rgw 19.2.3-pve4 +ii python3-setuptools 78.1.1-0.1 +ii python3-six 1.17.0-1 +ii python3-systemd 235-1+b6 +ii python3-typeguard 4.4.2-1 +ii python3-typing-extensions 4.13.2-1 +ii python3-urllib3 2.3.0-3+deb13u2 +ii python3-virt-firmware 24.11-2 +ii python3-wcwidth 0.2.13+dfsg1-1 +ii python3-yaml 6.0.2-1+b2 +ii python3-zipp 3.21.0-1 +ii python3.13 3.13.5-2+deb13u5 +ii python3.13-minimal 3.13.5-2+deb13u5 +ii qemu-server 9.1.15 +ii qrencode 4.1.1-2 +ii readline-common 8.2-6 +ii reportbug 13.2.0 +ii rpcbind 1.2.7-1 +ii rrdcached 1.7.2-4.2+pve4 +ii rsync 3.5.0+ds1-0+deb13u1 +ii runit-helper 2.16.4 +ii samba-common 2:4.22.11+dfsg-0+deb13u1 +ii samba-libs 2:4.22.11+dfsg-0+deb13u1 +ii sed 4.9-2+deb13u1 +ii sensible-utils 0.0.25 +ii shared-mime-info 2.4-5+b2 +ii shim-helpers-amd64-signed 1+16.1+1+pmx1 +ii shim-signed 1.48+pmx1+16.1-1+pmx1 +ii shim-signed-common 1.48+pmx1+16.1-1+pmx1 +ii shim-unsigned 16.1-1+pmx1 +ii skopeo 1.18.0+ds1-1+b5 +ii smartmontools 7.5-pve2 +ii smbclient 2:4.22.11+dfsg-0+deb13u1 +ii socat 1.8.0.3-1+deb13u1 +ii spiceterm 3.4.2 +ii sqlite3 3.46.1-7+deb13u2 +ii sqv 1.3.0-3+b2 +ii ssh 1:10.0p1-7+deb13u4 +ii strace 6.13+ds-1 +ii sudo 1.9.16p2-3+deb13u2 +ii swtpm 0.8.0+pve3 +ii swtpm-libs 0.8.0+pve3 +ii swtpm-tools 0.8.0+pve3 +ii systemd 257.13-1~deb13u1 +ii systemd-boot-efi 257.13-1~deb13u1 +ii systemd-boot-tools 257.13-1~deb13u1 +ii systemd-sysv 257.13-1~deb13u1 +ii sysvinit-utils 3.14-4 +ii tar 1.35+dfsg-3.1 +ii tcpdump 4.99.5-2 +ii thin-provisioning-tools 1.1.0-4+b1 +ii time 1.9-0.2 +ii traceroute 1:2.1.6-1 +ii tzdata 2026c-0+deb13u1 +ii ucf 3.0052 +ii udev 257.13-1~deb13u1 +ii uidmap 1:4.17.4-2 +ii usbutils 1:018-2 +ii util-linux 2.41.5-0+deb13u1 +ii util-linux-extra 2.41.5-0+deb13u1 +ii vim-common 2:9.1.1230-2 +ii vim-tiny 2:9.1.1230-2 +ii virtiofsd 1.13.2-1+deb13u1 +ii vncterm 1.9.2 +ii wamerican 2020.12.07-4 +ii wget 1.25.0-2 +ii whiptail 0.52.25-1 +ii wireguard-tools 1.0.20210914-3 +ii wtmpdb 0.73.0-3+deb13u1 +ii xfsprogs 6.13.0-2+deb13u1 +ii xkb-data 2.42-1 +ii xsltproc 1.1.35-1.2+deb13u3 +ii xz-utils 5.8.1-1+deb13u1 +ii zfs-initramfs 2.4.2-pve1 +ii zfs-zed 2.4.2-pve1 +ii zfsutils-linux 2.4.2-pve1 +ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1 +ii zstd 1.5.7+dfsg-1 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H1-host-packages-before.tsv b/documentation/audits/os-updates-spike-2026-10-04/partH/H1-host-packages-before.tsv new file mode 100644 index 00000000..fa548d03 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H1-host-packages-before.tsv @@ -0,0 +1,746 @@ +ii adduser 3.152 +ii age 1.2.1-1+b5 +ii amd64-microcode 3.20250311.1 +ii apparmor 4.1.1-pmx1 +ii apt 3.0.3 +ii apt-listchanges 4.8 +ii apt-utils 3.0.3 +ii base-files 13.8+deb13u5 +ii base-passwd 3.6.7 +ii bash 5.2.37-2+b9 +ii bash-completion 1:2.16.0-7 +ii bc 1.07.1-4 +ii bind9-dnsutils 1:9.20.21-1~deb13u1 +ii bind9-host 1:9.20.21-1~deb13u1 +ii bind9-libs 1:9.20.21-1~deb13u1 +ii binutils 2.44-3 +ii binutils-common 2.44-3 +ii binutils-x86-64-linux-gnu 2.44-3 +ii bridge-utils 1.7.1-4+b1 +ii bsd-mailx 8.1.2-0.20220412cvs-1.1 +ii bsdextrautils 2.41-5 +ii bsdutils 1:2.41-5 +ii btrfs-progs 6.14-1 +ii busybox 1:1.37.0-6+b8 +ii bzip2 1.0.8-6 +ii ca-certificates 20250419 +ii ceph-common 19.2.3-pve4 +ii ceph-fuse 19.2.3-pve4 +ii chrony 4.6.1-3+deb13u1 +ii cifs-utils 2:7.4-1 +ii conntrack 1:1.4.8-2 +ii console-setup 1.242~deb13u1 +ii console-setup-linux 1.242~deb13u1 +ii coreutils 9.7-3 +ii corosync 3.1.10-pve2 +ii cpio 2.15+dfsg-2 +ii criu 4.1.1-1 +ii cron 3.0pl1-197 +ii cron-daemon-common 3.0pl1-197 +ii cstream 4.0.0-1 +ii curl 8.14.1-2+deb13u3 +ii dash 0.5.12-12 +ii dbus 1.16.2-2 +ii dbus-bin 1.16.2-2 +ii dbus-daemon 1.16.2-2 +ii dbus-session-bus-common 1.16.2-2 +ii dbus-system-bus-common 1.16.2-2 +ii debconf 1.5.91 +ii debconf-i18n 1.5.91 +ii debian-archive-keyring 2025.1 +ii debian-faq 12.2 +ii debianutils 5.23.2 +ii dhcpcd-base 1:10.1.0-11+deb13u2 +ii diffutils 1:3.10-4 +ii dirmngr 2.4.7-21+deb13u1+b3 +ii distro-info-data 0.66+deb13u2 +ii dmeventd 2:1.02.205-2+pmx1 +ii dmidecode 3.6-2 +ii dmsetup 2:1.02.205-2+pmx1 +ii dns-root-data 2025080400~deb13u1 +ii dnsmasq 2.91-1+deb13u1 +ii dnsmasq-base 2.91-1+deb13u1 +ii doc-debian 11.3+nmu1 +ii dosfstools 4.2-1.2 +ii dpkg 1.22.22 +ii dracut-install 106-6 +ii dtach 0.9-7 +ii e2fsprogs 1.47.2-3+b11 +ii ebtables 2.0.11-6 +ii efibootmgr 18-2 +ii eject 2.41-5 +ii ethtool 1:6.14.2-1 +ii faketime 0.9.10+2024-06-05+gba9ed5b2-0.6 +ii fdisk 2.41-5 +ii fdutils 5.6-4+b1 +ii felhom-bootstrap 1.26.1 +ii file 1:5.46-5 +ii findutils 4.10.0-3 +ii fontconfig 2.15.0-2.3 +ii fontconfig-config 2.15.0-2.3 +ii fonts-dejavu-core 2.37-8 +ii fonts-dejavu-mono 2.37-8 +ii fonts-font-awesome 5.0.10+really4.7.0~dfsg-4.1 +ii fonts-font-logos 1.0.1-3 +ii frr 10.6.1-1+pve2 +ii frr-pythontools 10.6.1-1+pve2 +ii fuse 3.17.2-3 +ii fuse3 3.17.2-3 +ii gcc-14-base 14.2.0-19 +ii gdisk 1.0.10-2 +ii genisoimage 9:1.1.11-4 +ii gettext-base 0.23.1-2 +ii gnupg 2.4.7-21+deb13u1 +ii gnupg-l10n 2.4.7-21+deb13u1 +ii gnutls-bin 3.8.9-3+deb13u4 +ii golang-github-containers-common 0.62.2+ds1-2 +ii golang-github-containers-image 5.34.2-1 +ii gpg 2.4.7-21+deb13u1+b3 +ii gpg-agent 2.4.7-21+deb13u1+b3 +ii gpgconf 2.4.7-21+deb13u1+b3 +ii gpgsm 2.4.7-21+deb13u1+b3 +ii grep 3.11-4 +ii groff-base 1.23.0-9 +ii grub-common 2.12-9+pmx2 +ii grub-efi-amd64 2.12-9+pmx2 +ii grub-efi-amd64-bin 2.12-9+pmx2 +ii grub-efi-amd64-signed 1+2.12+9+pmx2 +ii grub-efi-amd64-unsigned 2.12-9+pmx2 +ii grub-pc-bin 2.12-9+pmx2 +ii grub2-common 2.12-9+pmx2 +ii gzip 1.13-1 +ii hdparm 9.65+ds-1.1 +ii hostname 3.25 +ii ifupdown2 3.3.0-1+pmx12 +ii inetutils-telnet 2:2.6-3+deb13u3 +ii init 1.69~deb13u1 +ii init-system-helpers 1.69~deb13u1 +ii initramfs-tools 0.148.4 +ii initramfs-tools-bin 0.148.4 +ii initramfs-tools-core 0.148.4 +ii iproute2 6.15.0-1 +ii ipset 7.22-1+b1 +ii iptables 1.8.11-2 +ii iputils-ping 3:20240905-3 +ii isc-dhcp-client 4.4.3-P1-8 +ii iso-codes 4.18.0-1 +ii iucode-tool 2.3.1-3 +ii kbd 2.7.1-2 +ii keyboard-configuration 1.242~deb13u1 +ii keyutils 1.6.3-6 +ii klibc-utils 2.0.14-1 +ii kmod 34.2-2 +ii krb5-locales 1.21.3-5 +ii ksm-control-daemon 1.5-1 +ii less 668-1 +ii libacl1 2.3.2-2+b1 +ii libaio1t64 0.3.113-8+b1 +ii libanyevent-http-perl 2.25-2 +ii libanyevent-perl 7.170-2+b7 +ii libapparmor1 4.1.1-pmx1 +ii libappconfig-perl 1.71-2.3 +ii libapt-pkg-perl 0.1.42 +ii libapt-pkg7.0 3.0.3 +ii libarchive13t64 3.7.4-4+deb13u1 +ii libasound2-data 1.2.14-1 +ii libasound2t64 1.2.14-1 +ii libassuan9 3.0.2-2 +ii libasyncns0 0.8-6+b5 +ii libatomic1 14.2.0-19 +ii libattr1 1:2.5.2-3 +ii libaudit-common 1:4.0.2-2 +ii libaudit1 1:4.0.2-2+b2 +ii libauthen-pam-perl 0.16-6+b4 +ii libavahi-client3 0.8-16 +ii libavahi-common-data 0.8-16 +ii libavahi-common3 0.8-16 +ii libbabeltrace1 1.5.11-4+b2 +ii libbinutils 2.44-3 +ii libblas3 3.12.1-6 +ii libblkid1 2.41-5 +ii libbpf1 1:1.5.0-3 +ii libbrotli1 1.1.0-2+b7 +ii libbsd0 0.12.2-2 +ii libbytes-random-secure-perl 0.29-3 +ii libbz2-1.0 1.0.8-6 +ii libc-bin 2.41-12+deb13u3 +ii libc-l10n 2.41-12+deb13u3 +ii libc6 2.41-12+deb13u3 +ii libcairo2 1.18.4-1+b1 +ii libcap-ng0 0.8.5-4+b1 +ii libcap2 1:2.75-10+deb13u1+b1 +ii libcap2-bin 1:2.75-10+deb13u1+b1 +ii libcares2 1.34.5-1+deb13u1 +ii libcbor0.10 0.10.2-2 +ii libcephfs2 19.2.3-pve4 +ii libcfg7 3.1.10-pve2 +ii libclass-methodmaker-perl 2.25-1 +ii libclone-perl 0.47-1+b1 +ii libcmap4 3.1.10-pve2 +ii libcom-err2 1.47.2-3+b11 +ii libcommon-sense-perl 3.75-3+b5 +ii libcompel1 4.1.1-1 +ii libconvert-asn1-perl 0.34-1 +ii libcorosync-common4 3.1.10-pve2 +ii libcpg4 3.1.10-pve2 +ii libcrypt-openssl-bignum-perl 0.09-2+b4 +ii libcrypt-openssl-random-perl 0.17-1+b1 +ii libcrypt-openssl-rsa-perl 0.35-1.1 +ii libcrypt-random-seed-perl 0.03-3 +ii libcrypt-ssleay-perl 0.73.06-2+b4 +ii libcrypt1 1:4.4.38-1 +ii libcryptsetup12 2:2.7.5-2 +ii libctf-nobfd0 2.44-3 +ii libctf0 2.44-3 +ii libcurl3t64-gnutls 8.14.1-2+deb13u3 +ii libcurl4t64 8.14.1-2+deb13u3 +ii libdatrie1 0.2.13-3+b1 +ii libdb5.3t64 5.3.28+dfsg2-9 +ii libdbi1t64 0.9.0-6.1+b1 +ii libdbus-1-3 1.16.2-2 +ii libdebconfclient0 0.280 +ii libdevel-cycle-perl 1.12-2 +ii libdevmapper-event1.02.1 2:1.02.205-2+pmx1 +ii libdevmapper1.02.1 2:1.02.205-2+pmx1 +ii libdigest-hmac-perl 1.05+dfsg-1 +ii libdouble-conversion3 3.3.1-1 +ii libdpkg-perl 1.22.22 +ii libdrm-amdgpu1 2.4.124-2 +ii libdrm-common 2.4.124-2 +ii libdrm-intel1 2.4.124-2 +ii libdrm2 2.4.124-2 +ii libdw1t64 0.192-4 +ii libedit2 3.1-20250104-1 +ii libefiboot1t64 38-3.1+b1 +ii libefivar1t64 38-3.1+b1 +ii libelf1t64 0.192-4 +ii libencode-locale-perl 1.05-3 +ii libepoxy0 1.5.10-2 +ii libevent-2.1-7t64 2.1.12-stable-10+b1 +ii libevent-core-2.1-7t64 2.1.12-stable-10+b1 +ii libexpat1 2.7.1-2 +ii libext2fs2t64 1.47.2-3+b11 +ii libfaketime 0.9.10+2024-06-05+gba9ed5b2-0.6 +ii libfdisk1 2.41-5 +ii libfdt1 1.7.2-2+b1 +ii libffi8 3.4.8-2 +ii libfido2-1 1.15.0-1+b1 +ii libfile-chdir-perl 0.1008-1.2 +ii libfile-listing-perl 6.16-1 +ii libfile-readbackwards-perl 1.06-2 +ii libfilesys-df-perl 0.92-7+b4 +ii libflac14 1.5.0+ds-2 +ii libfontconfig1 2.15.0-2.3 +ii libfreetype6 2.13.3+dfsg-1+deb13u1 +ii libfribidi0 1.0.16-1 +ii libfstrm0 0.6.1-1+b3 +ii libfuse2t64 2.9.9-9 +ii libfuse3-4 3.17.2-3 +ii libgbm1 25.0.7-2 +ii libgcc-s1 14.2.0-19 +ii libgcrypt20 1.11.0-7 +ii libgdbm-compat4t64 1.24-2 +ii libgdbm6t64 1.24-2 +ii libglib2.0-0t64 2.84.4-3~deb13u3 +ii libgmp10 2:6.3.0+dfsg-3 +ii libgnutls-dane0t64 3.8.9-3+deb13u4 +ii libgnutls30t64 3.8.9-3+deb13u4 +ii libgoogle-perftools4t64 2.16-1 +ii libgpg-error0 1.51-4 +ii libgpgme11t64 1.24.2-3 +ii libgprofng0 2.44-3 +ii libgraphite2-3 1.3.14-2+b1 +ii libgssapi-krb5-2 1.21.3-5 +ii libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u1 +ii libgstreamer1.0-0 1.26.2-2 +ii libharfbuzz0b 10.2.0-1+deb13u1 +ii libhogweed6t64 3.10.1-1 +ii libhtml-parser-perl 3.83-1+b2 +ii libhtml-tagset-perl 3.24-1 +ii libhtml-tree-perl 5.07-3 +ii libhttp-cookies-perl 6.11-1 +ii libhttp-daemon-perl 6.16-1 +ii libhttp-date-perl 6.06-1 +ii libhttp-message-perl 7.00-2 +ii libhttp-negotiate-perl 6.01-2 +ii libibverbs1 56.1-1 +ii libicu76 76.1-4 +ii libidn2-0 2.3.8-2 +ii libinih1 59-1 +ii libio-html-perl 1.004-3 +ii libio-multiplex-perl 1.16-3 +ii libio-socket-ssl-perl 2.089-1 +ii libio-stringy-perl 2.113-2 +ii libip4tc2 1.8.11-2 +ii libip6tc2 1.8.11-2 +ii libipset13t64 7.22-1+b1 +ii libiscsi7 1.20.0-4 +ii libisns0t64 0.101-1+b1 +ii libjansson4 2.14-2+b3 +ii libjemalloc2 5.3.0-3 +ii libjpeg62-turbo 1:2.1.5-4 +ii libjs-bootstrap5 5.3.5+dfsg-4 +ii libjs-extjs 7.0.0-5 +ii libjs-qrcodejs 1.20230525-pve1 +ii libjson-c5 0.18+ds-1 +ii libjson-glib-1.0-0 1.10.6+ds-2 +ii libjson-glib-1.0-common 1.10.6+ds-2 +ii libjson-perl 4.10000-1 +ii libjson-xs-perl 4.040-1~deb13u1 +ii libk5crypto3 1.21.3-5 +ii libkeyutils1 1.6.3-6 +ii libklibc 2.0.14-1 +ii libkmod2 34.2-2 +ii libknet1t64 1.31-pve1 +ii libkrb5-3 1.21.3-5 +ii libkrb5support0 1.21.3-5 +ii libksba8 1.6.7-2+b1 +ii liblastlog2-2 2.41-5 +ii libldap2 2.6.10+dfsg-1 +ii libldb2 2:2.11.0+samba4.22.8+dfsg-0+deb13u1 +ii liblinear4 2.3.0+dfsg-5+b2 +ii liblinux-inotify2-perl 1:2.3-2+b3 +ii libllvm19 1:19.1.7-3+b1 +ii liblmdb0 0.9.31-1+b2 +ii liblocale-gettext-perl 1.07-7+b1 +ii liblockfile-bin 1.17-2 +ii liblockfile1 1.17-2 +ii liblsof0 4.99.4+dfsg-2 +ii liblttng-ust-common1t64 2.13.9-1 +ii liblttng-ust-ctl5t64 2.13.9-1 +ii liblttng-ust1t64 2.13.9-1 +ii liblua5.3-0 5.3.6-2+b4 +ii liblua5.4-0 5.4.7-1+b2 +ii liblvm2cmd2.03 2.03.31-2+pmx1 +ii liblwp-mediatypes-perl 6.04-2 +ii liblwp-protocol-https-perl 6.14-1 +ii liblz4-1 1.10.0-4 +ii liblzma5 5.8.1-1 +ii liblzo2-2 2.10-3+b1 +ii libmagic-mgc 1:5.46-5 +ii libmagic1t64 1:5.46-5 +ii libmath-random-isaac-perl 1.004-2 +ii libmaxminddb0 1.12.2-1 +ii libmd0 1.1.0-2+b1 +ii libmime-base32-perl 1.303-3 +ii libmnl0 1.0.5-3 +ii libmount1 2.41-5 +ii libmp3lame0 3.100-6+b3 +ii libmpg123-0t64 1.32.10-1+deb13u1 +ii libnbd0 1.22.2-1+b1 +ii libncurses6 6.5+20250216-2 +ii libncursesw6 6.5+20250216-2 +ii libnet-dbus-perl 1.2.0-2+b3 +ii libnet-dns-perl 1.50-1 +ii libnet-http-perl 6.23-1 +ii libnet-ip-perl 1.26-4 +ii libnet-ldap-perl 1:0.6800+dfsg-1 +ii libnet-ssleay-perl 1.94-3 +ii libnet-subnet-perl 1.03-2 +ii libnet1 1.3+dfsg-2 +ii libnetaddr-ip-perl 4.079+dfsg-2+b5 +ii libnetfilter-conntrack3 1.1.0-1 +ii libnetfilter-log1 1.0.2-4+b1 +ii libnettle8t64 3.10.1-1 +ii libnewt0.52 0.52.25-1 +ii libnfnetlink0 1.0.2-3 +ii libnfsidmap1 1:2.8.3-1 +ii libnftables1 1.1.3-1 +ii libnftnl11 1.2.9-1 +ii libnghttp2-14 1.64.0-1.1+deb13u1 +ii libnghttp3-9 1.8.0-1 +ii libngtcp2-16 1.11.0-1+deb13u1 +ii libngtcp2-crypto-gnutls8 1.11.0-1+deb13u1 +ii libnl-3-200 3.7.0-2 +ii libnl-route-3-200 3.7.0-2 +ii libnozzle1t64 1.31-pve1 +ii libnpth0t64 1.8-3 +ii libnsl2 1.3.0-3+b3 +ii libnspr4 2:4.36-1 +ii libnss-systemd 257.13-1~deb13u1 +ii libnss3 2:3.110-1+deb13u1 +ii libnuma1 2.0.19-1 +ii libnvpair3linux 2.4.2-pve1 +ii liboath0t64 2.6.12-1 +ii libogg0 1.3.5-3+b2 +ii libopeniscsiusr 2.1.11-1+deb13u2 +ii libopus0 1.5.2-2 +ii liborc-0.4-0t64 1:0.4.41-1 +ii libp11-kit0 0.25.5-3 +ii libpam-modules 1.7.0-5 +ii libpam-modules-bin 1.7.0-5 +ii libpam-runtime 1.7.0-5 +ii libpam-systemd 257.13-1~deb13u1 +ii libpam-wtmpdb 0.73.0-3+deb13u1 +ii libpam0g 1.7.0-5 +ii libpango-1.0-0 1.56.3-1 +ii libpangocairo-1.0-0 1.56.3-1 +ii libpangoft2-1.0-0 1.56.3-1 +ii libpcap0.8t64 1.10.5-2 +ii libpci3 1:3.13.0-2 +ii libpciaccess0 0.17-3+b3 +ii libpcre2-16-0 10.46-1~deb13u1 +ii libpcre2-8-0 10.46-1~deb13u1 +ii libpcre2-posix3 10.46-1~deb13u1 +ii libperl5.40 5.40.1-6 +ii libpipeline1 1.5.8-1 +ii libpixman-1-0 0.44.0-3 +ii libpng16-16t64 1.6.48-1+deb13u5 +ii libpopt0 1.19+dfsg-2 +ii libposix-strptime-perl 0.13-2+b4 +ii libproc2-0 2:4.0.4-9 +ii libprotobuf-c1 1.5.1-1 +ii libproxmox-acme-perl 1.7.1 +ii libproxmox-acme-plugins 1.7.1 +ii libproxmox-backup-qemu0 2.0.2 +ii libproxmox-rs-perl 0.4.1 +ii libpsl5t64 0.21.2-1.1+b1 +ii libpulse0 17.0+dfsg1-2+b1 +ii libpve-access-control 9.1.1 +ii libpve-apiclient-perl 3.4.2 +ii libpve-cluster-api-perl 9.1.5 +ii libpve-cluster-perl 9.1.5 +ii libpve-common-perl 9.1.12 +ii libpve-guest-common-perl 6.0.3 +ii libpve-http-server-perl 6.0.5 +ii libpve-network-api-perl 1.6.5 +ii libpve-network-perl 1.6.5 +ii libpve-notify-perl 9.1.5 +ii libpve-rs-perl 0.15.3 +ii libpve-storage-perl 9.1.5 +ii libpython3-stdlib 3.13.5-1 +ii libpython3.13-minimal 3.13.5-2+deb13u2 +ii libpython3.13-stdlib 3.13.5-2+deb13u2 +ii libqb-tools 2.0.8-2+b1 +ii libqb100 2.0.8-2+b1 +ii libqrencode4 4.1.1-2 +ii libqt5core5t64 5.15.15+dfsg-6+deb13u1 +ii libqt5dbus5t64 5.15.15+dfsg-6+deb13u1 +ii libqt5network5t64 5.15.15+dfsg-6+deb13u1 +ii libquorum5 3.1.10-pve2 +ii librabbitmq4 0.15.0-1 +ii librados2 19.2.3-pve4 +ii librados2-perl 1.5.0 +ii libradosstriper1 19.2.3-pve4 +ii librbd1 19.2.3-pve4 +ii librdkafka1 2.8.0-1 +ii librdmacm1t64 56.1-1 +ii libreadline8t64 8.2-6 +ii libreiserfscore0t64 1:3.6.27-9 +ii librgw2 19.2.3-pve4 +ii librrd8t64 1.7.2-4.2+pve4 +ii librrds-perl 1.7.2-4.2+pve4 +ii librtmp1 2.4+20151223.gitfa8646d.1-2+b5 +ii libsasl2-2 2.1.28+dfsg1-9 +ii libsasl2-modules-db 2.1.28+dfsg1-9 +ii libseccomp2 2.6.0-2 +ii libselinux1 3.8.1-1 +ii libsemanage-common 3.8.1-1 +ii libsemanage2 3.8.1-1 +ii libsensors-config 1:3.6.2-2 +ii libsensors5 1:3.6.2-2 +ii libsepol2 3.8.1-1 +ii libsframe1 2.44-3 +ii libslang2 2.3.3-5+b2 +ii libslirp0 4.8.0-1+b1 +ii libsmartcols1 2.41-5 +ii libsmbclient0 2:4.22.8+dfsg-0+deb13u1 +ii libsnappy1v5 1.2.2-1 +ii libsndfile1 1.2.2-2+deb13u1 +ii libsndio7.0 1.10.0-0.1 +ii libsocket6-perl 0.29-3+b4 +ii libspice-server1 0.15.2-1+b1 +ii libsqlite3-0 3.46.1-7+deb13u1 +ii libss2 1.47.2-3+b11 +ii libssh2-1t64 1.11.1-1 +ii libssl3t64 3.5.6-1~deb13u1 +ii libstatgrab10t64 0.92.1-1.2 +ii libstdc++6 14.2.0-19 +ii libstring-shellquote-perl 1.04-3 +ii libsubid5 1:4.17.4-2 +ii libsystemd-shared 257.13-1~deb13u1 +ii libsystemd0 257.13-1~deb13u1 +ii libtalloc2 2:2.4.3+samba4.22.8+dfsg-0+deb13u1 +ii libtasn1-6 4.20.0-2 +ii libtcmalloc-minimal4t64 2.16-1 +ii libtdb1 2:1.4.13+samba4.22.8+dfsg-0+deb13u1 +ii libtemplate-perl 2.27-1+b8 +ii libterm-readline-gnu-perl 1.46-1+b3 +ii libtevent0t64 2:0.16.2+samba4.22.8+dfsg-0+deb13u1 +ii libtext-charwidth-perl 0.04-11+b4 +ii libtext-iconv-perl 1.7-8+b4 +ii libtext-wrapi18n-perl 0.06-10 +ii libthai-data 0.1.29-2 +ii libthai0 0.1.29-2+b1 +ii libthrift-0.19.0t64 0.19.0-4+b1 +ii libtimedate-perl 2.3300-2 +ii libtinfo6 6.5+20250216-2 +ii libtirpc-common 1.3.6+ds-1 +ii libtirpc3t64 1.3.6+ds-1 +ii libtlsrpt0 0.5.0rc1-2 +ii libtpms0 0.9.7+pve2 +ii libtry-tiny-perl 0.32-1 +ii libtypes-serialiser-perl 1.01-1 +ii libuchardet0 0.0.8-1+b2 +ii libudev1 257.13-1~deb13u1 +ii libunbound8 1.22.0-2+deb13u2 +ii libunistring5 1.3-2 +ii libunwind8 1.8.1-0.1 +ii liburcu8t64 0.15.2-2 +ii liburi-perl 5.30-1 +ii liburing2 2.9-1 +ii libusb-1.0-0 2:1.0.28-1 +ii libusbredirparser1t64 0.15.0-1 +ii libuuid-perl 0.37-1 +ii libuuid1 2.41-5 +ii libuutil3linux 2.4.2-pve1 +ii libuv1t64 1.50.0-2 +ii libva-drm2 2.22.0-3 +ii libva2 2.22.0-3 +ii libvirglrenderer1 1.1.0-2 +ii libvorbis0a 1.3.7-3 +ii libvorbisenc2 1.3.7-3 +ii libvotequorum8 3.1.10-pve2 +ii libvulkan1 1.4.309.0-1 +ii libwayland-server0 1.23.1-3 +ii libwbclient0 2:4.22.8+dfsg-0+deb13u1 +ii libwrap0 7.6.q-36 +ii libwtmpdb0 0.73.0-3+deb13u1 +ii libwww-perl 6.78-1 +ii libwww-robotrules-perl 6.02-1 +ii libx11-6 2:1.8.12-1 +ii libx11-data 2:1.8.12-1 +ii libx11-xcb1 2:1.8.12-1 +ii libxau6 1:1.0.11-1 +ii libxcb-dri3-0 1.17.0-2+b1 +ii libxcb-present0 1.17.0-2+b1 +ii libxcb-randr0 1.17.0-2+b1 +ii libxcb-render0 1.17.0-2+b1 +ii libxcb-shm0 1.17.0-2+b1 +ii libxcb-sync1 1.17.0-2+b1 +ii libxcb-xfixes0 1.17.0-2+b1 +ii libxcb1 1.17.0-2+b1 +ii libxdmcp6 1:1.1.5-1 +ii libxext6 2:1.3.4-1+b3 +ii libxkbcommon0 1.7.0-2 +ii libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+b2 +ii libxml-namespacesupport-perl 1.12-2 +ii libxml-parser-perl 2.47-2~deb13u1 +ii libxml-sax-base-perl 1.09-3 +ii libxml-sax-perl 1.02+dfsg-4 +ii libxml-twig-perl 1:3.52-3 +ii libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2 +ii libxrender1 1:0.9.12-1 +ii libxshmfence1 1.3.3-1 +ii libxslt1.1 1.1.35-1.2+deb13u3 +ii libxtables12 1.8.11-2 +ii libxxhash0 0.8.3-2 +ii libyaml-0-2 0.2.5-2 +ii libyaml-libyaml-perl 0.903.0+ds-1 +ii libyang3 3.12.2-1 +ii libz3-4 4.13.3-1 +ii libzfs7linux 2.4.2-pve1 +ii libzpool7linux 2.4.2-pve1 +ii libzstd1 1.5.7+dfsg-1 +ii linux-base 4.12.1 +ii linux-sysctl-defaults 4.12.1 +ii locales 2.41-12+deb13u3 +ii login 1:4.16.0-2+really2.41-5 +ii login.defs 1:4.17.4-2 +ii logrotate 3.22.0-1 +ii logsave 1.47.2-3+b11 +ii lsof 4.99.4+dfsg-2 +ii lvm2 2.03.31-2+pmx1 +ii lxc-pve 7.0.0-2 +ii lxcfs 7.0.0-pve1 +ii lzop 1.04-2 +ii man-db 2.13.1-1 +ii manpages 6.9.1-1 +ii mawk 1.3.4.20250131-1 +ii media-types 13.0.0 +ii memtest86+ 7.20-1 +ii mesa-libgallium 25.0.7-2 +ii mokutil 0.7.2-1 +ii mount 2.41-5 +ii nano 8.4-1+deb13u1 +ii ncurses-base 6.5+20250216-2 +ii ncurses-bin 6.5+20250216-2 +ii ncurses-term 6.5+20250216-2 +ii netavark 1.14.0-2 +ii netbase 6.5 +ii netcat-traditional 1.10-50 +ii nfs-common 1:2.8.3-1 +ii nftables 1.1.3-1 +ii nmap 7.95+dfsg-3 +ii nmap-common 7.95+dfsg-3 +ii node-popper2 2.11.2-8 +ii novnc-pve 1.7.0-1 +ii numactl 2.0.19-1 +ii open-iscsi 2.1.11-1+deb13u2 +ii openssh-client 1:10.0p1-7+deb13u4 +ii openssh-server 1:10.0p1-7+deb13u4 +ii openssh-sftp-server 1:10.0p1-7+deb13u4 +ii openssl 3.5.6-1~deb13u1 +ii openssl-provider-legacy 3.5.6-1~deb13u1 +ii passwd 1:4.17.4-2 +ii pci.ids 0.0~2025.06.09-1 +ii pciutils 1:3.13.0-2 +ii perl 5.40.1-6 +ii perl-base 5.40.1-6 +ii perl-modules-5.40 5.40.1-6 +ii perl-openssl-defaults 7+b2 +ii pinentry-curses 1.3.1-2 +ii postfix 3.10.5-1~deb13u1 +ii procmail 3.24+really3.22-4 +ii procps 2:4.0.4-9 +ii proxmox-archive-keyring 4.0 +ii proxmox-backup-client 4.2.0-1 +ii proxmox-backup-file-restore 4.2.0-1 +ii proxmox-backup-restore-image 1.0.0 +ii proxmox-default-kernel 2.1.0 +ii proxmox-enterprise-support-keyring 1.0 +ii proxmox-firewall 1.2.3 +ii proxmox-grub 2.12-9+pmx2 +ii proxmox-kernel-7.0 7.0.2-6 +ii proxmox-kernel-7.0.2-6-pve-signed 7.0.2-6 +ii proxmox-kernel-helper 9.1.0+fde2 +ii proxmox-mail-forward 1.0.3 +ii proxmox-mini-journalreader 1.6 +ii proxmox-offline-mirror-docs 0.7.4 +ii proxmox-offline-mirror-helper 0.7.4 +ii proxmox-secure-boot-support 2.0.6 +ii proxmox-termproxy 2.1.0 +ii proxmox-ve 9.2.0 +ii proxmox-websocket-tunnel 1.0.0 +ii proxmox-widget-toolkit 5.2.2 +ii psmisc 23.7-2 +ii pve-cluster 9.1.5 +ii pve-container 6.1.10 +ii pve-docs 9.2.1 +ii pve-edk2-firmware 4.2025.05-2 +ii pve-edk2-firmware-aarch64 4.2025.05-2 +ii pve-edk2-firmware-legacy 4.2025.05-2 +ii pve-edk2-firmware-ovmf 4.2025.05-2 +ii pve-esxi-import-tools 1.0.1 +ii pve-firewall 6.0.4 +ii pve-firmware 3.18-3 +ii pve-ha-manager 5.2.4 +ii pve-i18n 3.7.4 +ii pve-lxc-syscalld 2.0.2 +ii pve-manager 9.2.2 +ii pve-nvidia-vgpu-helper 0.3.1 +ii pve-qemu-kvm 11.0.0-3 +ii pve-xtermjs 6.0.0-1 +ii pve-yew-mobile-gui 0.7.0 +ii pve-yew-mobile-i18n 3.7.4 +ii python-apt-common 3.0.0 +ii python3 3.13.5-1 +ii python3-apt 3.0.0 +ii python3-autocommand 2.2.2-3 +ii python3-bcrypt 4.2.0-2.1+b1 +ii python3-ceph-argparse 19.2.3-pve4 +ii python3-ceph-common 19.2.3-pve4 +ii python3-cephfs 19.2.3-pve4 +ii python3-certifi 2025.1.31+ds-1 +ii python3-cffi-backend 1.17.1-3 +ii python3-chardet 5.2.0+dfsg-2 +ii python3-charset-normalizer 3.4.2-1 +ii python3-cryptography 43.0.0-3+deb13u1 +ii python3-dbus 1.4.0-1 +ii python3-debconf 1.5.91 +ii python3-debian 1.0.1 +ii python3-debianbts 4.1.1 +ii python3-idna 3.10-1 +ii python3-importlib-resources 6.5.2-1 +ii python3-inflect 7.3.1-2 +ii python3-jaraco.context 6.0.1-1+deb13u1 +ii python3-jaraco.functools 4.1.0-1 +ii python3-jaraco.text 4.0.0-1 +ii python3-minimal 3.13.5-1 +ii python3-more-itertools 10.7.0-1 +ii python3-pefile 2024.8.26-2.1 +ii python3-pkg-resources 78.1.1-0.1 +ii python3-prettytable 3.15.1-1 +ii python3-pyvmomi 8.0.3.0.1-1 +ii python3-rados 19.2.3-pve4 +ii python3-rbd 19.2.3-pve4 +ii python3-reportbug 13.2.0 +ii python3-requests 2.32.3+dfsg-5+deb13u1 +ii python3-rgw 19.2.3-pve4 +ii python3-setuptools 78.1.1-0.1 +ii python3-six 1.17.0-1 +ii python3-systemd 235-1+b6 +ii python3-typeguard 4.4.2-1 +ii python3-typing-extensions 4.13.2-1 +ii python3-urllib3 2.3.0-3+deb13u1 +ii python3-virt-firmware 24.11-2 +ii python3-wcwidth 0.2.13+dfsg1-1 +ii python3-yaml 6.0.2-1+b2 +ii python3-zipp 3.21.0-1 +ii python3.13 3.13.5-2+deb13u2 +ii python3.13-minimal 3.13.5-2+deb13u2 +ii qemu-server 9.1.15 +ii qrencode 4.1.1-2 +ii readline-common 8.2-6 +ii reportbug 13.2.0 +ii rpcbind 1.2.7-1 +ii rrdcached 1.7.2-4.2+pve4 +ii rsync 3.4.1+ds1-5+deb13u2 +ii runit-helper 2.16.4 +ii samba-common 2:4.22.8+dfsg-0+deb13u1 +ii samba-libs 2:4.22.8+dfsg-0+deb13u1 +ii sed 4.9-2+deb13u1 +ii sensible-utils 0.0.25 +ii shared-mime-info 2.4-5+b2 +ii shim-helpers-amd64-signed 1+16.1+1+pmx1 +ii shim-signed 1.48+pmx1+16.1-1+pmx1 +ii shim-signed-common 1.48+pmx1+16.1-1+pmx1 +ii shim-unsigned 16.1-1+pmx1 +ii skopeo 1.18.0+ds1-1+b5 +ii smartmontools 7.5-pve2 +ii smbclient 2:4.22.8+dfsg-0+deb13u1 +ii socat 1.8.0.3-1 +ii spiceterm 3.4.2 +ii sqlite3 3.46.1-7+deb13u1 +ii sqv 1.3.0-3+b2 +ii ssh 1:10.0p1-7+deb13u4 +ii strace 6.13+ds-1 +ii sudo 1.9.16p2-3+deb13u2 +ii swtpm 0.8.0+pve3 +ii swtpm-libs 0.8.0+pve3 +ii swtpm-tools 0.8.0+pve3 +ii systemd 257.13-1~deb13u1 +ii systemd-boot-efi 257.13-1~deb13u1 +ii systemd-boot-tools 257.13-1~deb13u1 +ii systemd-sysv 257.13-1~deb13u1 +ii sysvinit-utils 3.14-4 +ii tar 1.35+dfsg-3.1 +ii tcpdump 4.99.5-2 +ii thin-provisioning-tools 1.1.0-4+b1 +ii time 1.9-0.2 +ii traceroute 1:2.1.6-1 +ii tzdata 2026b-0+deb13u1 +ii ucf 3.0052 +ii udev 257.13-1~deb13u1 +ii uidmap 1:4.17.4-2 +ii usbutils 1:018-2 +ii util-linux 2.41-5 +ii util-linux-extra 2.41-5 +ii vim-common 2:9.1.1230-2 +ii vim-tiny 2:9.1.1230-2 +ii virtiofsd 1.13.2-1+deb13u1 +ii vncterm 1.9.2 +ii wamerican 2020.12.07-4 +ii wget 1.25.0-2 +ii whiptail 0.52.25-1 +ii wireguard-tools 1.0.20210914-3 +ii wtmpdb 0.73.0-3+deb13u1 +ii xfsprogs 6.13.0-2+b1 +ii xkb-data 2.42-1 +ii xsltproc 1.1.35-1.2+deb13u3 +ii xz-utils 5.8.1-1 +ii zfs-initramfs 2.4.2-pve1 +ii zfs-zed 2.4.2-pve1 +ii zfsutils-linux 2.4.2-pve1 +ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1 +ii zstd 1.5.7+dfsg-1 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H2-plan.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-plan.txt new file mode 100644 index 00000000..fc9ad449 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-plan.txt @@ -0,0 +1,11 @@ +update_rc=0 +debian candidates: 108 +sim rc=0 +108 upgraded, 0 newly installed, 0 to remove and 78 not upgraded. +--- Proxmox-origin packages the fast-lane plan would pull in (must be none): +0 +--- new packages in the plan: +--- kept back / not upgraded: +108 upgraded, 0 newly installed, 0 to remove and 78 not upgraded. +--- big restarters in the plan: +libc6 mount util-linux login libssl3t64 postfix openssl diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H2-proxmox-origin-debian-names.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-proxmox-origin-debian-names.txt new file mode 100644 index 00000000..718c8257 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-proxmox-origin-debian-names.txt @@ -0,0 +1,40 @@ +frr +shim-signed-common +shim-unsigned +shim-helpers-amd64-signed +shim-signed +amd64-microcode +libradosstriper1 +librgw2 +ceph-common +librbd1 +librados2 +python3-cephfs +libcephfs2 +python3-rgw +python3-rados +python3-ceph-argparse +python3-ceph-common +python3-rbd +ceph-fuse +chrony +libcorosync-common4 +libcfg7 +libcmap4 +libcpg4 +libknet1t64 +libnozzle1t64 +libquorum5 +libvotequorum8 +corosync +frr-pythontools +libjs-extjs +libnvpair3linux +librados2-perl +novnc-pve +libuutil3linux +libzfs7linux +libzpool7linux +zfs-initramfs +zfsutils-linux +zfs-zed diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H2-result.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-result.txt new file mode 100644 index 00000000..7724b8fa --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H2-result.txt @@ -0,0 +1,43 @@ +apt_rc=0 seconds=59.7 +76258368 /var/cache/apt/archives +used_after 20093845504 +used_after_clean 19926065152 +used_before 19987525632 +done +-- services with a new MainPID: +dnsmasq.service postfix.service systemd-journald.service +-- guest/agent states seen during the run: + 14 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +14 +-- conffile notes: +-- host processes on deleted libs: + 38 postgres + 29 nginx + 7 apache2 + 6 php-fpm85 + 4 agetty + 4 [celeryd: celer + 3 sshd + 3 pveproxy worker + 3 pvedaemon worke + 3 mariadbd + 2 systemd-logind + 2 lxc-start + 2 dbus-daemon + 2 cron + 2 chronyd + 1 zed + 1 watchdog-mux + 1 systemd-udevd + 1 systemd-network + 1 systemd-journal + 1 systemd + 1 spiceproxy work + 1 spiceproxy + 1 smartd + 1 rrdcached + 1 rpcbind + 1 qmeventd + 1 pvestatd + 1 pvescheduler + 1 pveproxy diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H3-undo-one-package.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H3-undo-one-package.txt new file mode 100644 index 00000000..6bb57781 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H3-undo-one-package.txt @@ -0,0 +1,11 @@ +== rsync: now 3.5.0+ds1-0+deb13u1, want back the pre-update 3.4.1+ds1-5+deb13u2 +E: Version '3.4.1+ds1-5+deb13u2' for 'rsync' was not found + result: 3.5.0+ds1-0+deb13u1 +== libpng16-16t64: now 1.6.48-1+deb13u6, want back the pre-update 1.6.48-1+deb13u5 +0 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 78 not upgraded. +Get:1 http://deb.debian.org/debian trixie/main amd64 libpng16-16t64 amd64 1.6.48-1+deb13u5 [283 kB] +Setting up libpng16-16t64:amd64 (1.6.48-1+deb13u5) ... + result: 1.6.48-1+deb13u5 +== put libpng back on the security version +Setting up libpng16-16t64:amd64 (1.6.48-1+deb13u6) ... +libpng16-16t64 1.6.48-1+deb13u6 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H4-1-install-kernel.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-1-install-kernel.txt new file mode 100644 index 00000000..f2cba87a --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-1-install-kernel.txt @@ -0,0 +1,21 @@ +running: 7.0.2-6-pve +install rc=0 seconds=47 +The following packages will be upgraded: +1 upgraded, 1 newly installed, 0 to remove and 77 not upgraded. +Get:1 http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 proxmox-kernel-7.0.14-20-pve-signed amd64 7.0.14-20 [131 MB] +Get:2 http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 proxmox-kernel-7.0 amd64 7.0.14-20 [19.4 kB] +Setting up proxmox-kernel-7.0.14-20-pve-signed (7.0.14-20) ... +Setting up proxmox-kernel-7.0 (7.0.14-20) ... +/boot/vmlinuz-7.0.14-20-pve +/boot/vmlinuz-7.0.2-6-pve +Manually selected kernels: +None. + +Automatically selected kernels: +7.0.14-20-pve +7.0.2-6-pve +-- GRUB default now (no pin): +/etc/default/grub:GRUB_DEFAULT=0 +Proxmox VE GNU/Linux +Proxmox VE GNU/Linux, with Linux 7.0.14-20-pve +Proxmox VE GNU/Linux, with Linux 7.0.14-20-pve (recovery mode) diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H4-2-pins.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-2-pins.txt new file mode 100644 index 00000000..7ea8ac52 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-2-pins.txt @@ -0,0 +1,13 @@ +Adding boot menu entry for UEFI Firmware Settings ... +done +done +Pinned for next boot only. +-- pins: +7.0.2-6-pve +7.0.14-20-pve +-- grub default snippet: +GRUB_DEFAULT="gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43" +GRUB_DEFAULT="gnulinux-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43>gnulinux-7.0.14-20-pve-advanced-529c0c3d-b48e-4d01-989d-43fd5d7dbb43" + set default="${next_entry}" +enabled +07:43:06 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H4-3-boot1-new-kernel.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-3-boot1-new-kernel.txt new file mode 100644 index 00000000..e1ab52e3 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-3-boot1-new-kernel.txt @@ -0,0 +1,12 @@ +after 18s: agent=active ctl9201=healthy +VMID Status Lock Name +9201 running demo-hp +9202 running demo-hp-scratch +Oct 04 09:44:42 demo-hp systemd[1]: Started felhom-agent.service - Felhom host agent (Proxmox host tier; hub control loop + PBS verify + storage watchdog). +Oct 04 09:44:42 demo-hp felhom-agent[1872]: time=2026-10-04T09:44:42.106+02:00 level=INFO msg="felhom-agent daemon starting" version=0.139.0 host_id=demo-hp-bb76ea hub_url=https://hub.felhom.eu interv +Oct 04 09:44:42 demo-hp felhom-agent[1872]: time=2026-10-04T09:44:42.113+02:00 level=INFO msg="daemon: operator signers pinned" count=2 +[ 1.334926] RAS: Correctable Errors collector initialized. +[ 5.087323] cfg80211: failed to load regulatory.db +[ 5.269917] hp-wmi hp-wmi: Failed to apply initial fan settings: -22 +[ 6.900329] hp_bioscfg: Returned error 0x300a, "Generic/Other error" +[ 9.141444] amdgpu 0000:05:00.0: [drm] Failed to setup vendor infoframe on connector DP-1: -22 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H4-4-boot2-fallback.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-4-boot2-fallback.txt new file mode 100644 index 00000000..235d28d1 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-4-boot2-fallback.txt @@ -0,0 +1,6 @@ +kernel: 7.0.2-6-pve booted: 2026-10-04 09:46:13 +agent=active ctl9201=healthy +9201 running demo-hp +9202 running demo-hp-scratch +7.0.2-6-pve +ls: cannot access '/etc/kernel/next-boot-pin': No such file or directory diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H4-5-final-choice.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-5-final-choice.txt new file mode 100644 index 00000000..4b38e309 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H4-5-final-choice.txt @@ -0,0 +1,8 @@ +Found memtest86+ 32bit image: /boot/memtest86+ia32.bin +Adding boot menu entry for UEFI Firmware Settings ... +done +ls: cannot access '/etc/kernel/proxmox-boot-pin': No such file or directory +ls: cannot access '/etc/kernel/next-boot-pin': No such file or directory +no GRUB pin snippet +Proxmox VE GNU/Linux, with Linux 7.0.14-20-pve +running now: 7.0.2-6-pve diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/H5-proxmox-simulate.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/H5-proxmox-simulate.txt new file mode 100644 index 00000000..1bb8df0d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/H5-proxmox-simulate.txt @@ -0,0 +1,26 @@ +pending after the Debian lane + kernel: 78 (Remv 0) + 78 Proxmox Debian Repository +-- new packages: +proxmox-firewall-data +-- services the installed maintainer scripts restart or reload (per package): +pve-manager: "$UNIT" +102: deb-systemd-invoke restart "$UNIT" || true +123: # the ExecStartPre doesn't triggers on service reload, so just in case +126: deb-systemd-invoke reload-or-try-restart pvedaemon.service || true +127: deb-systemd-invoke reload-or-try-restart pvestatd.service || true +128: deb-systemd-invoke reload-or-try-restart pveproxy.service || true +129: deb-systemd-invoke reload-or-try-restart spiceproxy.service || true +130: deb-systemd-invoke reload-or-try-restart pvescheduler.service || true +146: systemctl --system daemon-reload >/dev/null || true +150: UNITS="pvedaemon.service pveproxy.service spiceproxy.service pvestatd.service pvebanner.service pvescheduler.service pve-daily-update.timer" +151: NO_RESTART_UNITS="pvenetcommit.service pve-guests.service pve-sdn-commit.service pve-firewall-commit.service" +153: for unit in ${UNITS} ${NO_RESTART_UNITS}; do +188: for unit in ${UNITS}; do +chrony: chrony.service +corosync: corosync.service +pve-cluster: pve-cluster.service +pve-manager: pvedaemon.service pveproxy.service pvescheduler.service pvestatd.service spiceproxy.service +qemu-server: pve-query-machine-capabilities.service qmeventd.service +pve-firewall: pve-firewall.service pvefw-logger.service +pve-ha-manager: pve-ha-crm.service pve-ha-lrm.service +zfs-zed: zfs-zed.service diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/h-apt-run.log b/documentation/audits/os-updates-spike-2026-10-04/partH/h-apt-run.log new file mode 100644 index 00000000..33b77041 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/h-apt-run.log @@ -0,0 +1,535 @@ +Reading package lists... +Building dependency tree... +Reading state information... +The following packages will be upgraded: + base-files bash bind9-dnsutils bind9-host bind9-libs bsdextrautils bsdutils + busybox curl dhcpcd-base dirmngr dnsmasq dnsmasq-base e2fsprogs eject fdisk + gpg gpg-agent gpgconf gpgsm gzip krb5-locales libasound2-data libasound2t64 + libaudit-common libaudit1 libblkid1 libbytes-random-secure-perl libc-bin + libc-l10n libc6 libcap2 libcap2-bin libcom-err2 libcurl3t64-gnutls + libcurl4t64 libevent-2.1-7t64 libevent-core-2.1-7t64 libexpat1 libext2fs2t64 + libfdisk1 libgbm1 libgcrypt20 libglib2.0-0t64 libgraphite2-3 + libgssapi-krb5-2 libgstreamer-plugins-base1.0-0 libhtml-parser-perl + libhttp-daemon-perl libk5crypto3 libkrb5-3 libkrb5support0 liblastlog2-2 + libldb2 liblzma5 libmount1 libnet-dns-perl libnss3 libpcre2-16-0 + libpcre2-8-0 libpcre2-posix3 libperl5.40 libpng16-16t64 + libpython3.13-minimal libpython3.13-stdlib librabbitmq4 libslirp0 + libsmartcols1 libsmbclient0 libsqlite3-0 libss2 libssh2-1t64 libssl3t64 + libtalloc2 libtasn1-6 libtdb1 libtevent0t64 libunbound8 libuuid1 + libwbclient0 libxml-libxml-perl libxml2 locales login logsave + mesa-libgallium mount openssl openssl-provider-legacy perl perl-base + perl-modules-5.40 postfix python3-idna python3-urllib3 python3.13 + python3.13-minimal rsync samba-common samba-libs smbclient socat sqlite3 + tzdata util-linux util-linux-extra xfsprogs xz-utils +108 upgraded, 0 newly installed, 0 to remove and 78 not upgraded. +Need to get 71.9 MB of archives. +After this operation, 594 kB of additional disk space will be used. +Get:1 http://security.debian.org/debian-security trixie-security/main amd64 openssl-provider-legacy amd64 3.5.7-1~deb13u3 [316 kB] +Get:2 http://deb.debian.org/debian trixie/main amd64 libc6 amd64 2.41-12+deb13u4 [2847 kB] +Get:3 http://deb.debian.org/debian trixie/main amd64 base-files amd64 13.8+deb13u7 [88.3 kB] +Get:4 http://deb.debian.org/debian trixie/main amd64 bash amd64 5.2.37-2+b10 [1501 kB] +Get:5 http://deb.debian.org/debian trixie/main amd64 bsdutils amd64 1:2.41.5-0+deb13u1 [110 kB] +Get:6 http://deb.debian.org/debian trixie/main amd64 gzip amd64 1.13-1+deb13u1 [139 kB] +Get:7 http://deb.debian.org/debian trixie/main amd64 libperl5.40 amd64 5.40.1-6+deb13u1 [4326 kB] +Get:8 http://security.debian.org/debian-security trixie-security/main amd64 libssl3t64 amd64 3.5.7-1~deb13u3 [2458 kB] +Get:9 http://deb.debian.org/debian trixie/main amd64 perl amd64 5.40.1-6+deb13u1 [268 kB] +Get:10 http://deb.debian.org/debian trixie/main amd64 perl-base amd64 5.40.1-6+deb13u1 [1666 kB] +Get:11 http://deb.debian.org/debian trixie/main amd64 perl-modules-5.40 all 5.40.1-6+deb13u1 [3014 kB] +Get:12 http://deb.debian.org/debian trixie/main amd64 liblastlog2-2 amd64 2.41.5-0+deb13u1 [28.8 kB] +Get:13 http://deb.debian.org/debian trixie/main amd64 eject amd64 2.41.5-0+deb13u1 [61.1 kB] +Get:14 http://deb.debian.org/debian trixie/main amd64 bsdextrautils amd64 2.41.5-0+deb13u1 [94.8 kB] +Get:15 http://deb.debian.org/debian trixie/main amd64 util-linux-extra amd64 2.41.5-0+deb13u1 [301 kB] +Get:16 http://deb.debian.org/debian trixie/main amd64 fdisk amd64 2.41.5-0+deb13u1 [159 kB] +Get:17 http://deb.debian.org/debian trixie/main amd64 libsmartcols1 amd64 2.41.5-0+deb13u1 [143 kB] +Get:18 http://deb.debian.org/debian trixie/main amd64 libblkid1 amd64 2.41.5-0+deb13u1 [172 kB] +Get:19 http://deb.debian.org/debian trixie/main amd64 libmount1 amd64 2.41.5-0+deb13u1 [210 kB] +Get:20 http://deb.debian.org/debian trixie/main amd64 mount amd64 2.41.5-0+deb13u1 [163 kB] +Get:21 http://deb.debian.org/debian trixie/main amd64 libuuid1 amd64 2.41.5-0+deb13u1 [37.8 kB] +Get:22 http://deb.debian.org/debian trixie/main amd64 util-linux amd64 2.41.5-0+deb13u1 [1242 kB] +Get:23 http://deb.debian.org/debian trixie/main amd64 libfdisk1 amd64 2.41.5-0+deb13u1 [215 kB] +Get:24 http://deb.debian.org/debian trixie/main amd64 libaudit-common all 1:4.0.2-2+deb13u1 [12.8 kB] +Get:25 http://deb.debian.org/debian trixie/main amd64 libaudit1 amd64 1:4.0.2-2+deb13u1 [57.7 kB] +Get:26 http://deb.debian.org/debian trixie/main amd64 sqlite3 amd64 3.46.1-7+deb13u2 [384 kB] +Get:27 http://deb.debian.org/debian trixie/main amd64 libsqlite3-0 amd64 3.46.1-7+deb13u2 [915 kB] +Get:28 http://deb.debian.org/debian trixie/main amd64 libc-bin amd64 2.41-12+deb13u4 [638 kB] +Get:29 http://deb.debian.org/debian trixie/main amd64 login amd64 1:4.16.0-2+really2.41.5-0+deb13u1 [115 kB] +Get:30 http://deb.debian.org/debian trixie/main amd64 logsave amd64 1.47.2-3+b12 [24.9 kB] +Get:31 http://deb.debian.org/debian trixie/main amd64 libext2fs2t64 amd64 1.47.2-3+b12 [213 kB] +Get:32 http://deb.debian.org/debian trixie/main amd64 e2fsprogs amd64 1.47.2-3+b12 [591 kB] +Get:33 http://deb.debian.org/debian trixie/main amd64 dnsmasq-base amd64 2.91-1+deb13u2 [507 kB] +Get:34 http://deb.debian.org/debian trixie/main amd64 dnsmasq all 2.91-1+deb13u2 [69.8 kB] +Get:35 http://deb.debian.org/debian trixie/main amd64 libexpat1 amd64 2.8.3-1~deb13u1 [123 kB] +Get:36 http://deb.debian.org/debian trixie/main amd64 postfix amd64 3.10.13-0+deb13u1 [1612 kB] +Get:37 http://deb.debian.org/debian trixie/main amd64 python3.13 amd64 3.13.5-2+deb13u5 [757 kB] +Get:38 http://deb.debian.org/debian trixie/main amd64 libpython3.13-stdlib amd64 3.13.5-2+deb13u5 [1959 kB] +Get:39 http://deb.debian.org/debian trixie/main amd64 python3.13-minimal amd64 3.13.5-2+deb13u5 [2225 kB] +Get:40 http://deb.debian.org/debian trixie/main amd64 libpython3.13-minimal amd64 3.13.5-2+deb13u5 [863 kB] +Get:41 http://deb.debian.org/debian trixie/main amd64 tzdata all 2026c-0+deb13u1 [264 kB] +Get:42 http://deb.debian.org/debian trixie/main amd64 liblzma5 amd64 5.8.1-1+deb13u1 [309 kB] +Get:43 http://deb.debian.org/debian trixie/main amd64 libcap2 amd64 1:2.75-10+deb13u1+b3 [29.0 kB] +Get:44 http://deb.debian.org/debian trixie/main amd64 dhcpcd-base amd64 1:10.1.0-11+deb13u4 [201 kB] +Get:45 http://deb.debian.org/debian trixie/main amd64 libgssapi-krb5-2 amd64 1.21.3-5+deb13u1 [138 kB] +Get:46 http://deb.debian.org/debian trixie/main amd64 libkrb5-3 amd64 1.21.3-5+deb13u1 [326 kB] +Get:47 http://deb.debian.org/debian trixie/main amd64 libkrb5support0 amd64 1.21.3-5+deb13u1 [33.1 kB] +Get:48 http://deb.debian.org/debian trixie/main amd64 libk5crypto3 amd64 1.21.3-5+deb13u1 [81.2 kB] +Get:49 http://deb.debian.org/debian trixie/main amd64 libcom-err2 amd64 1.47.2-3+b12 [25.0 kB] +Get:50 http://deb.debian.org/debian trixie/main amd64 libxml2 amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3 [700 kB] +Get:51 http://security.debian.org/debian-security trixie-security/main amd64 rsync amd64 3.5.0+ds1-0+deb13u1 [502 kB] +Get:52 http://security.debian.org/debian-security trixie-security/main amd64 libpcre2-8-0 amd64 10.46-1~deb13u3 [299 kB] +Get:53 http://deb.debian.org/debian trixie/main amd64 krb5-locales all 1.21.3-5+deb13u1 [101 kB] +Get:54 http://deb.debian.org/debian trixie/main amd64 libc-l10n all 2.41-12+deb13u4 [740 kB] +Get:55 http://deb.debian.org/debian trixie/main amd64 locales all 2.41-12+deb13u4 [3931 kB] +Get:56 http://security.debian.org/debian-security trixie-security/main amd64 bind9-dnsutils amd64 1:9.20.29-1~deb13u1 [167 kB] +Get:57 http://security.debian.org/debian-security trixie-security/main amd64 bind9-host amd64 1:9.20.29-1~deb13u1 [56.5 kB] +Get:58 http://deb.debian.org/debian trixie/main amd64 xz-utils amd64 5.8.1-1+deb13u1 [659 kB] +Get:59 http://security.debian.org/debian-security trixie-security/main amd64 bind9-libs amd64 1:9.20.29-1~deb13u1 [1248 kB] +Get:60 http://deb.debian.org/debian trixie/main amd64 busybox amd64 1:1.37.0-6+b9 [485 kB] +Get:61 http://deb.debian.org/debian trixie/main amd64 libssh2-1t64 amd64 1.11.1-1+deb13u2 [245 kB] +Get:62 http://deb.debian.org/debian trixie/main amd64 curl amd64 8.14.1-2+deb13u5 [270 kB] +Get:63 http://deb.debian.org/debian trixie/main amd64 libcurl4t64 amd64 8.14.1-2+deb13u5 [391 kB] +Get:64 http://deb.debian.org/debian trixie/main amd64 libgcrypt20 amd64 1.11.0-7+deb13u1 [843 kB] +Get:65 http://deb.debian.org/debian trixie/main amd64 gpgsm amd64 2.4.7-21+deb13u1+b5 [276 kB] +Get:66 http://deb.debian.org/debian trixie/main amd64 dirmngr amd64 2.4.7-21+deb13u1+b5 [384 kB] +Get:67 http://deb.debian.org/debian trixie/main amd64 gpg amd64 2.4.7-21+deb13u1+b5 [636 kB] +Get:68 http://deb.debian.org/debian trixie/main amd64 gpgconf amd64 2.4.7-21+deb13u1+b5 [129 kB] +Get:69 http://deb.debian.org/debian trixie/main amd64 gpg-agent amd64 2.4.7-21+deb13u1+b5 [271 kB] +Get:70 http://deb.debian.org/debian trixie/main amd64 libasound2t64 amd64 1.2.14-1+deb13u1 [381 kB] +Get:71 http://deb.debian.org/debian trixie/main amd64 libasound2-data all 1.2.14-1+deb13u1 [21.2 kB] +Get:72 http://deb.debian.org/debian trixie/main amd64 libbytes-random-secure-perl all 0.29-4~deb13u1 [30.0 kB] +Get:73 http://deb.debian.org/debian trixie/main amd64 libcap2-bin amd64 1:2.75-10+deb13u1+b3 [36.5 kB] +Get:74 http://deb.debian.org/debian trixie/main amd64 libcurl3t64-gnutls amd64 8.14.1-2+deb13u5 [384 kB] +Get:75 http://security.debian.org/debian-security trixie-security/main amd64 libevent-2.1-7t64 amd64 2.1.13-stable-1~deb13u1 [183 kB] +Get:76 http://deb.debian.org/debian trixie/main amd64 libgbm1 amd64 25.0.7-2+deb13u1 [44.6 kB] +Get:77 http://deb.debian.org/debian trixie/main amd64 mesa-libgallium amd64 25.0.7-2+deb13u1 [9630 kB] +Get:78 http://security.debian.org/debian-security trixie-security/main amd64 libevent-core-2.1-7t64 amd64 2.1.13-stable-1~deb13u1 [133 kB] +Get:79 http://security.debian.org/debian-security trixie-security/main amd64 libgstreamer-plugins-base1.0-0 amd64 1.26.2-1+deb13u2 [997 kB] +Get:80 http://deb.debian.org/debian trixie/main amd64 libglib2.0-0t64 amd64 2.84.4-3~deb13u5 [1521 kB] +Get:81 http://deb.debian.org/debian trixie/main amd64 libgraphite2-3 amd64 1.3.14-2+deb13u1 [75.2 kB] +Get:82 http://deb.debian.org/debian trixie/main amd64 libhtml-parser-perl amd64 3.83-2~deb13u1 [99.6 kB] +Get:83 http://deb.debian.org/debian trixie/main amd64 libhttp-daemon-perl all 6.16-1+deb13u1 [23.8 kB] +Get:84 http://deb.debian.org/debian trixie/main amd64 libtalloc2 amd64 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 [63.6 kB] +Get:85 http://deb.debian.org/debian trixie/main amd64 libtevent0t64 amd64 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 [78.5 kB] +Get:86 http://deb.debian.org/debian trixie/main amd64 libsmbclient0 amd64 2:4.22.11+dfsg-0+deb13u1 [99.9 kB] +Get:87 http://deb.debian.org/debian trixie/main amd64 samba-common all 2:4.22.11+dfsg-0+deb13u1 [66.3 kB] +Get:88 http://security.debian.org/debian-security trixie-security/main amd64 libpcre2-16-0 amd64 10.46-1~deb13u3 [282 kB] +Get:89 http://deb.debian.org/debian trixie/main amd64 smbclient amd64 2:4.22.11+dfsg-0+deb13u1 [504 kB] +Get:90 http://deb.debian.org/debian trixie/main amd64 libtdb1 amd64 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 [83.4 kB] +Get:91 http://deb.debian.org/debian trixie/main amd64 libldb2 amd64 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 [180 kB] +Get:92 http://deb.debian.org/debian trixie/main amd64 samba-libs amd64 2:4.22.11+dfsg-0+deb13u1 [6048 kB] +Get:93 http://security.debian.org/debian-security trixie-security/main amd64 libpcre2-posix3 amd64 10.46-1~deb13u3 [64.1 kB] +Get:94 http://security.debian.org/debian-security trixie-security/main amd64 libpng16-16t64 amd64 1.6.48-1+deb13u6 [283 kB] +Get:95 http://deb.debian.org/debian trixie/main amd64 libwbclient0 amd64 2:4.22.11+dfsg-0+deb13u1 [72.2 kB] +Get:96 http://deb.debian.org/debian trixie/main amd64 libnet-dns-perl all 1.56-0+deb13u1 [369 kB] +Get:97 http://security.debian.org/debian-security trixie-security/main amd64 libunbound8 amd64 1.26.1-0+deb13u1 [643 kB] +Get:98 http://deb.debian.org/debian trixie/main amd64 libnss3 amd64 2:3.110-1+deb13u4 [1394 kB] +Get:99 http://deb.debian.org/debian trixie/main amd64 librabbitmq4 amd64 0.15.0-1+deb13u2 [42.5 kB] +Get:100 http://deb.debian.org/debian trixie/main amd64 libslirp0 amd64 4.8.0-1+deb13u1 [66.5 kB] +Get:101 http://deb.debian.org/debian trixie/main amd64 libss2 amd64 1.47.2-3+b12 [29.7 kB] +Get:102 http://deb.debian.org/debian trixie/main amd64 libtasn1-6 amd64 4.20.0-2+deb13u1 [50.1 kB] +Get:103 http://deb.debian.org/debian trixie/main amd64 libxml-libxml-perl amd64 2.0207+dfsg+really+2.0134-5+deb13u1 [314 kB] +Get:104 http://deb.debian.org/debian trixie/main amd64 python3-idna all 3.10-1+deb13u1 [43.0 kB] +Get:105 http://deb.debian.org/debian trixie/main amd64 python3-urllib3 all 2.3.0-3+deb13u2 [115 kB] +Get:106 http://deb.debian.org/debian trixie/main amd64 socat amd64 1.8.0.3-1+deb13u1 [424 kB] +Get:107 http://security.debian.org/debian-security trixie-security/main amd64 openssl amd64 3.5.7-1~deb13u3 [1508 kB] +Get:108 http://deb.debian.org/debian trixie/main amd64 xfsprogs amd64 6.13.0-2+deb13u1 [1168 kB] +Preconfiguring packages ... +Fetched 71.9 MB in 3s (27.9 MB/s) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52612 files and directories currently installed.) +Preparing to unpack .../libc6_2.41-12+deb13u4_amd64.deb ... +Unpacking libc6:amd64 (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Setting up libc6:amd64 (2.41-12+deb13u4) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52612 files and directories currently installed.) +Preparing to unpack .../base-files_13.8+deb13u7_amd64.deb ... +Unpacking base-files (13.8+deb13u7) over (13.8+deb13u5) ... +Setting up base-files (13.8+deb13u7) ... +Installing new version of config file /etc/debian_version ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../bash_5.2.37-2+b10_amd64.deb ... +Unpacking bash (5.2.37-2+b10) over (5.2.37-2+b9) ... +Setting up bash (5.2.37-2+b10) ... +update-alternatives: using /usr/share/man/man7/bash-builtins.7.gz to provide /usr/share/man/man7/builtins.7.gz (builtins.7.gz) in auto mode +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../bsdutils_1%3a2.41.5-0+deb13u1_amd64.deb ... +Unpacking bsdutils (1:2.41.5-0+deb13u1) over (1:2.41-5) ... +Setting up bsdutils (1:2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../gzip_1.13-1+deb13u1_amd64.deb ... +Unpacking gzip (1.13-1+deb13u1) over (1.13-1) ... +Setting up gzip (1.13-1+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../libperl5.40_5.40.1-6+deb13u1_amd64.deb ... +Unpacking libperl5.40:amd64 (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../perl_5.40.1-6+deb13u1_amd64.deb ... +Unpacking perl (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../perl-base_5.40.1-6+deb13u1_amd64.deb ... +Unpacking perl-base (5.40.1-6+deb13u1) over (5.40.1-6) ... +Setting up perl-base (5.40.1-6+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../perl-modules-5.40_5.40.1-6+deb13u1_all.deb ... +Unpacking perl-modules-5.40 (5.40.1-6+deb13u1) over (5.40.1-6) ... +Preparing to unpack .../liblastlog2-2_2.41.5-0+deb13u1_amd64.deb ... +Unpacking liblastlog2-2:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up liblastlog2-2:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../eject_2.41.5-0+deb13u1_amd64.deb ... +Unpacking eject (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../bsdextrautils_2.41.5-0+deb13u1_amd64.deb ... +Unpacking bsdextrautils (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../util-linux-extra_2.41.5-0+deb13u1_amd64.deb ... +Leaving 'diversion of /sbin/ctrlaltdel to /sbin/ctrlaltdel.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/fsck.cramfs to /sbin/fsck.cramfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/fsck.minix to /sbin/fsck.minix.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.bfs to /sbin/mkfs.bfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.cramfs to /sbin/mkfs.cramfs.usr-is-merged by util-linux-extra' +Leaving 'diversion of /sbin/mkfs.minix to /sbin/mkfs.minix.usr-is-merged by util-linux-extra' +Unpacking util-linux-extra (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../fdisk_2.41.5-0+deb13u1_amd64.deb ... +Unpacking fdisk (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libsmartcols1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libsmartcols1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libsmartcols1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../libblkid1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libblkid1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libblkid1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../libmount1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libmount1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libmount1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../mount_2.41.5-0+deb13u1_amd64.deb ... +Unpacking mount (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libuuid1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libuuid1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up libuuid1:amd64 (2.41.5-0+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52621 files and directories currently installed.) +Preparing to unpack .../util-linux_2.41.5-0+deb13u1_amd64.deb ... +Unpacking util-linux (2.41.5-0+deb13u1) over (2.41-5) ... +Setting up util-linux (2.41.5-0+deb13u1) ... +fstrim.service is a disabled or a static unit not running, not starting it. +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52626 files and directories currently installed.) +Preparing to unpack .../libfdisk1_2.41.5-0+deb13u1_amd64.deb ... +Unpacking libfdisk1:amd64 (2.41.5-0+deb13u1) over (2.41-5) ... +Preparing to unpack .../libaudit-common_1%3a4.0.2-2+deb13u1_all.deb ... +Unpacking libaudit-common (1:4.0.2-2+deb13u1) over (1:4.0.2-2) ... +Setting up libaudit-common (1:4.0.2-2+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52626 files and directories currently installed.) +Preparing to unpack .../libaudit1_1%3a4.0.2-2+deb13u1_amd64.deb ... +Unpacking libaudit1:amd64 (1:4.0.2-2+deb13u1) over (1:4.0.2-2+b2) ... +Setting up libaudit1:amd64 (1:4.0.2-2+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52625 files and directories currently installed.) +Preparing to unpack .../sqlite3_3.46.1-7+deb13u2_amd64.deb ... +Unpacking sqlite3 (3.46.1-7+deb13u2) over (3.46.1-7+deb13u1) ... +Preparing to unpack .../libsqlite3-0_3.46.1-7+deb13u2_amd64.deb ... +Unpacking libsqlite3-0:amd64 (3.46.1-7+deb13u2) over (3.46.1-7+deb13u1) ... +Setting up libsqlite3-0:amd64 (3.46.1-7+deb13u2) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52625 files and directories currently installed.) +Preparing to unpack .../libc-bin_2.41-12+deb13u4_amd64.deb ... +Unpacking libc-bin (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Setting up libc-bin (2.41-12+deb13u4) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52625 files and directories currently installed.) +Preparing to unpack .../login_1%3a4.16.0-2+really2.41.5-0+deb13u1_amd64.deb ... +Unpacking login (1:4.16.0-2+really2.41.5-0+deb13u1) over (1:4.16.0-2+really2.41-5) ... +Preparing to unpack .../logsave_1.47.2-3+b12_amd64.deb ... +Unpacking logsave (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../libext2fs2t64_1.47.2-3+b12_amd64.deb ... +Leaving 'diversion of /lib/x86_64-linux-gnu/libe2p.so.2 to /lib/x86_64-linux-gnu/libe2p.so.2.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libe2p.so.2.3 to /lib/x86_64-linux-gnu/libe2p.so.2.3.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libext2fs.so.2 to /lib/x86_64-linux-gnu/libext2fs.so.2.usr-is-merged by libext2fs2t64' +Leaving 'diversion of /lib/x86_64-linux-gnu/libext2fs.so.2.4 to /lib/x86_64-linux-gnu/libext2fs.so.2.4.usr-is-merged by libext2fs2t64' +Unpacking libext2fs2t64:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Setting up libext2fs2t64:amd64 (1.47.2-3+b12) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../e2fsprogs_1.47.2-3+b12_amd64.deb ... +Unpacking e2fsprogs (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../dnsmasq-base_2.91-1+deb13u2_amd64.deb ... +Unpacking dnsmasq-base (2.91-1+deb13u2) over (2.91-1+deb13u1) ... +Preparing to unpack .../dnsmasq_2.91-1+deb13u2_all.deb ... +Unpacking dnsmasq (2.91-1+deb13u2) over (2.91-1+deb13u1) ... +Preparing to unpack .../libexpat1_2.8.3-1~deb13u1_amd64.deb ... +Unpacking libexpat1:amd64 (2.8.3-1~deb13u1) over (2.7.1-2) ... +Preparing to unpack .../openssl-provider-legacy_3.5.7-1~deb13u3_amd64.deb ... +Unpacking openssl-provider-legacy (3.5.7-1~deb13u3) over (3.5.6-1~deb13u1) ... +Setting up openssl-provider-legacy (3.5.7-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../libssl3t64_3.5.7-1~deb13u3_amd64.deb ... +Unpacking libssl3t64:amd64 (3.5.7-1~deb13u3) over (3.5.6-1~deb13u1) ... +Setting up libssl3t64:amd64 (3.5.7-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../0-postfix_3.10.13-0+deb13u1_amd64.deb ... +Unpacking postfix (3.10.13-0+deb13u1) over (3.10.5-1~deb13u1) ... +Preparing to unpack .../1-python3.13_3.13.5-2+deb13u5_amd64.deb ... +Unpacking python3.13 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u2) ... +Preparing to unpack .../2-libpython3.13-stdlib_3.13.5-2+deb13u5_amd64.deb ... +Unpacking libpython3.13-stdlib:amd64 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u2) ... +Preparing to unpack .../3-python3.13-minimal_3.13.5-2+deb13u5_amd64.deb ... +Unpacking python3.13-minimal (3.13.5-2+deb13u5) over (3.13.5-2+deb13u2) ... +Preparing to unpack .../4-libpython3.13-minimal_3.13.5-2+deb13u5_amd64.deb ... +Unpacking libpython3.13-minimal:amd64 (3.13.5-2+deb13u5) over (3.13.5-2+deb13u2) ... +Preparing to unpack .../5-tzdata_2026c-0+deb13u1_all.deb ... +Unpacking tzdata (2026c-0+deb13u1) over (2026b-0+deb13u1) ... +Preparing to unpack .../6-liblzma5_5.8.1-1+deb13u1_amd64.deb ... +Unpacking liblzma5:amd64 (5.8.1-1+deb13u1) over (5.8.1-1) ... +Setting up liblzma5:amd64 (5.8.1-1+deb13u1) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../rsync_3.5.0+ds1-0+deb13u1_amd64.deb ... +Unpacking rsync (3.5.0+ds1-0+deb13u1) over (3.4.1+ds1-5+deb13u2) ... +Preparing to unpack .../libcap2_1%3a2.75-10+deb13u1+b3_amd64.deb ... +Unpacking libcap2:amd64 (1:2.75-10+deb13u1+b3) over (1:2.75-10+deb13u1+b1) ... +Setting up libcap2:amd64 (1:2.75-10+deb13u1+b3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../libpcre2-8-0_10.46-1~deb13u3_amd64.deb ... +Unpacking libpcre2-8-0:amd64 (10.46-1~deb13u3) over (10.46-1~deb13u1) ... +Setting up libpcre2-8-0:amd64 (10.46-1~deb13u3) ... +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 52627 files and directories currently installed.) +Preparing to unpack .../00-dhcpcd-base_1%3a10.1.0-11+deb13u4_amd64.deb ... +Unpacking dhcpcd-base (1:10.1.0-11+deb13u4) over (1:10.1.0-11+deb13u2) ... +Preparing to unpack .../01-libgssapi-krb5-2_1.21.3-5+deb13u1_amd64.deb ... +Unpacking libgssapi-krb5-2:amd64 (1.21.3-5+deb13u1) over (1.21.3-5) ... +Preparing to unpack .../02-libkrb5-3_1.21.3-5+deb13u1_amd64.deb ... +Unpacking libkrb5-3:amd64 (1.21.3-5+deb13u1) over (1.21.3-5) ... +Preparing to unpack .../03-libkrb5support0_1.21.3-5+deb13u1_amd64.deb ... +Unpacking libkrb5support0:amd64 (1.21.3-5+deb13u1) over (1.21.3-5) ... +Preparing to unpack .../04-libk5crypto3_1.21.3-5+deb13u1_amd64.deb ... +Unpacking libk5crypto3:amd64 (1.21.3-5+deb13u1) over (1.21.3-5) ... +Preparing to unpack .../05-libcom-err2_1.47.2-3+b12_amd64.deb ... +Unpacking libcom-err2:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../06-libxml2_2.12.7+dfsg+really2.9.14-2.1+deb13u3_amd64.deb ... +Unpacking libxml2:amd64 (2.12.7+dfsg+really2.9.14-2.1+deb13u3) over (2.12.7+dfsg+really2.9.14-2.1+deb13u2) ... +Preparing to unpack .../07-bind9-dnsutils_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-dnsutils (1:9.20.29-1~deb13u1) over (1:9.20.21-1~deb13u1) ... +Preparing to unpack .../08-bind9-host_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-host (1:9.20.29-1~deb13u1) over (1:9.20.21-1~deb13u1) ... +Preparing to unpack .../09-bind9-libs_1%3a9.20.29-1~deb13u1_amd64.deb ... +Unpacking bind9-libs:amd64 (1:9.20.29-1~deb13u1) over (1:9.20.21-1~deb13u1) ... +Preparing to unpack .../10-krb5-locales_1.21.3-5+deb13u1_all.deb ... +Unpacking krb5-locales (1.21.3-5+deb13u1) over (1.21.3-5) ... +Preparing to unpack .../11-libc-l10n_2.41-12+deb13u4_all.deb ... +Unpacking libc-l10n (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Preparing to unpack .../12-locales_2.41-12+deb13u4_all.deb ... +Unpacking locales (2.41-12+deb13u4) over (2.41-12+deb13u3) ... +Preparing to unpack .../13-xz-utils_5.8.1-1+deb13u1_amd64.deb ... +Unpacking xz-utils (5.8.1-1+deb13u1) over (5.8.1-1) ... +Preparing to unpack .../14-busybox_1%3a1.37.0-6+b9_amd64.deb ... +Unpacking busybox (1:1.37.0-6+b9) over (1:1.37.0-6+b8) ... +Preparing to unpack .../15-libssh2-1t64_1.11.1-1+deb13u2_amd64.deb ... +Unpacking libssh2-1t64:amd64 (1.11.1-1+deb13u2) over (1.11.1-1) ... +Preparing to unpack .../16-curl_8.14.1-2+deb13u5_amd64.deb ... +Unpacking curl (8.14.1-2+deb13u5) over (8.14.1-2+deb13u3) ... +Preparing to unpack .../17-libcurl4t64_8.14.1-2+deb13u5_amd64.deb ... +Unpacking libcurl4t64:amd64 (8.14.1-2+deb13u5) over (8.14.1-2+deb13u3) ... +Preparing to unpack .../18-libgcrypt20_1.11.0-7+deb13u1_amd64.deb ... +Unpacking libgcrypt20:amd64 (1.11.0-7+deb13u1) over (1.11.0-7) ... +Preparing to unpack .../19-gpgsm_2.4.7-21+deb13u1+b5_amd64.deb ... +Unpacking gpgsm (2.4.7-21+deb13u1+b5) over (2.4.7-21+deb13u1+b3) ... +Preparing to unpack .../20-dirmngr_2.4.7-21+deb13u1+b5_amd64.deb ... +Unpacking dirmngr (2.4.7-21+deb13u1+b5) over (2.4.7-21+deb13u1+b3) ... +Preparing to unpack .../21-gpg_2.4.7-21+deb13u1+b5_amd64.deb ... +Unpacking gpg (2.4.7-21+deb13u1+b5) over (2.4.7-21+deb13u1+b3) ... +Preparing to unpack .../22-gpgconf_2.4.7-21+deb13u1+b5_amd64.deb ... +Unpacking gpgconf (2.4.7-21+deb13u1+b5) over (2.4.7-21+deb13u1+b3) ... +Preparing to unpack .../23-gpg-agent_2.4.7-21+deb13u1+b5_amd64.deb ... +Unpacking gpg-agent (2.4.7-21+deb13u1+b5) over (2.4.7-21+deb13u1+b3) ... +Preparing to unpack .../24-libasound2t64_1.2.14-1+deb13u1_amd64.deb ... +Unpacking libasound2t64:amd64 (1.2.14-1+deb13u1) over (1.2.14-1) ... +Preparing to unpack .../25-libasound2-data_1.2.14-1+deb13u1_all.deb ... +Unpacking libasound2-data (1.2.14-1+deb13u1) over (1.2.14-1) ... +Preparing to unpack .../26-libbytes-random-secure-perl_0.29-4~deb13u1_all.deb ... +Unpacking libbytes-random-secure-perl (0.29-4~deb13u1) over (0.29-3) ... +Preparing to unpack .../27-libcap2-bin_1%3a2.75-10+deb13u1+b3_amd64.deb ... +Unpacking libcap2-bin (1:2.75-10+deb13u1+b3) over (1:2.75-10+deb13u1+b1) ... +Preparing to unpack .../28-libcurl3t64-gnutls_8.14.1-2+deb13u5_amd64.deb ... +Unpacking libcurl3t64-gnutls:amd64 (8.14.1-2+deb13u5) over (8.14.1-2+deb13u3) ... +Preparing to unpack .../29-libevent-2.1-7t64_2.1.13-stable-1~deb13u1_amd64.deb ... +Unpacking libevent-2.1-7t64:amd64 (2.1.13-stable-1~deb13u1) over (2.1.12-stable-10+b1) ... +Preparing to unpack .../30-libevent-core-2.1-7t64_2.1.13-stable-1~deb13u1_amd64.deb ... +Unpacking libevent-core-2.1-7t64:amd64 (2.1.13-stable-1~deb13u1) over (2.1.12-stable-10+b1) ... +Preparing to unpack .../31-libgbm1_25.0.7-2+deb13u1_amd64.deb ... +Unpacking libgbm1:amd64 (25.0.7-2+deb13u1) over (25.0.7-2) ... +Preparing to unpack .../32-mesa-libgallium_25.0.7-2+deb13u1_amd64.deb ... +Unpacking mesa-libgallium:amd64 (25.0.7-2+deb13u1) over (25.0.7-2) ... +Preparing to unpack .../33-libglib2.0-0t64_2.84.4-3~deb13u5_amd64.deb ... +Unpacking libglib2.0-0t64:amd64 (2.84.4-3~deb13u5) over (2.84.4-3~deb13u3) ... +Preparing to unpack .../34-libgraphite2-3_1.3.14-2+deb13u1_amd64.deb ... +Unpacking libgraphite2-3:amd64 (1.3.14-2+deb13u1) over (1.3.14-2+b1) ... +Preparing to unpack .../35-libgstreamer-plugins-base1.0-0_1.26.2-1+deb13u2_amd64.deb ... +Unpacking libgstreamer-plugins-base1.0-0:amd64 (1.26.2-1+deb13u2) over (1.26.2-1+deb13u1) ... +Preparing to unpack .../36-libhtml-parser-perl_3.83-2~deb13u1_amd64.deb ... +Unpacking libhtml-parser-perl:amd64 (3.83-2~deb13u1) over (3.83-1+b2) ... +Preparing to unpack .../37-libhttp-daemon-perl_6.16-1+deb13u1_all.deb ... +Unpacking libhttp-daemon-perl (6.16-1+deb13u1) over (6.16-1) ... +Preparing to unpack .../38-libtalloc2_2%3a2.4.3+samba4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libtalloc2:amd64 (2:2.4.3+samba4.22.11+dfsg-0+deb13u1) over (2:2.4.3+samba4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../39-libtevent0t64_2%3a0.16.2+samba4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libtevent0t64:amd64 (2:0.16.2+samba4.22.11+dfsg-0+deb13u1) over (2:0.16.2+samba4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../40-libsmbclient0_2%3a4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libsmbclient0:amd64 (2:4.22.11+dfsg-0+deb13u1) over (2:4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../41-samba-common_2%3a4.22.11+dfsg-0+deb13u1_all.deb ... +Unpacking samba-common (2:4.22.11+dfsg-0+deb13u1) over (2:4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../42-smbclient_2%3a4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking smbclient (2:4.22.11+dfsg-0+deb13u1) over (2:4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../43-libtdb1_2%3a1.4.13+samba4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libtdb1:amd64 (2:1.4.13+samba4.22.11+dfsg-0+deb13u1) over (2:1.4.13+samba4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../44-libldb2_2%3a2.11.0+samba4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libldb2:amd64 (2:2.11.0+samba4.22.11+dfsg-0+deb13u1) over (2:2.11.0+samba4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../45-samba-libs_2%3a4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking samba-libs:amd64 (2:4.22.11+dfsg-0+deb13u1) over (2:4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../46-libwbclient0_2%3a4.22.11+dfsg-0+deb13u1_amd64.deb ... +Unpacking libwbclient0:amd64 (2:4.22.11+dfsg-0+deb13u1) over (2:4.22.8+dfsg-0+deb13u1) ... +Preparing to unpack .../47-libnet-dns-perl_1.56-0+deb13u1_all.deb ... +Unpacking libnet-dns-perl (1.56-0+deb13u1) over (1.50-1) ... +Preparing to unpack .../48-libnss3_2%3a3.110-1+deb13u4_amd64.deb ... +Unpacking libnss3:amd64 (2:3.110-1+deb13u4) over (2:3.110-1+deb13u1) ... +Preparing to unpack .../49-libpcre2-16-0_10.46-1~deb13u3_amd64.deb ... +Unpacking libpcre2-16-0:amd64 (10.46-1~deb13u3) over (10.46-1~deb13u1) ... +Preparing to unpack .../50-libpcre2-posix3_10.46-1~deb13u3_amd64.deb ... +Unpacking libpcre2-posix3:amd64 (10.46-1~deb13u3) over (10.46-1~deb13u1) ... +Preparing to unpack .../51-libpng16-16t64_1.6.48-1+deb13u6_amd64.deb ... +Unpacking libpng16-16t64:amd64 (1.6.48-1+deb13u6) over (1.6.48-1+deb13u5) ... +Preparing to unpack .../52-librabbitmq4_0.15.0-1+deb13u2_amd64.deb ... +Unpacking librabbitmq4:amd64 (0.15.0-1+deb13u2) over (0.15.0-1) ... +Preparing to unpack .../53-libslirp0_4.8.0-1+deb13u1_amd64.deb ... +Unpacking libslirp0:amd64 (4.8.0-1+deb13u1) over (4.8.0-1+b1) ... +Preparing to unpack .../54-libss2_1.47.2-3+b12_amd64.deb ... +Unpacking libss2:amd64 (1.47.2-3+b12) over (1.47.2-3+b11) ... +Preparing to unpack .../55-libtasn1-6_4.20.0-2+deb13u1_amd64.deb ... +Unpacking libtasn1-6:amd64 (4.20.0-2+deb13u1) over (4.20.0-2) ... +Preparing to unpack .../56-libunbound8_1.26.1-0+deb13u1_amd64.deb ... +Unpacking libunbound8:amd64 (1.26.1-0+deb13u1) over (1.22.0-2+deb13u2) ... +Preparing to unpack .../57-libxml-libxml-perl_2.0207+dfsg+really+2.0134-5+deb13u1_amd64.deb ... +update-perl-sax-parsers: Unregistering Perl SAX parser XML::LibXML::SAX::Parser with priority 50... +update-perl-sax-parsers: Unregistering Perl SAX parser XML::LibXML::SAX with priority 50... +update-perl-sax-parsers: Updating overall Perl SAX parser modules info file... +Unpacking libxml-libxml-perl (2.0207+dfsg+really+2.0134-5+deb13u1) over (2.0207+dfsg+really+2.0134-5+b2) ... +Preparing to unpack .../58-openssl_3.5.7-1~deb13u3_amd64.deb ... +Unpacking openssl (3.5.7-1~deb13u3) over (3.5.6-1~deb13u1) ... +Preparing to unpack .../59-python3-idna_3.10-1+deb13u1_all.deb ... +Unpacking python3-idna (3.10-1+deb13u1) over (3.10-1) ... +Preparing to unpack .../60-python3-urllib3_2.3.0-3+deb13u2_all.deb ... +Unpacking python3-urllib3 (2.3.0-3+deb13u2) over (2.3.0-3+deb13u1) ... +Preparing to unpack .../61-socat_1.8.0.3-1+deb13u1_amd64.deb ... +Unpacking socat (1.8.0.3-1+deb13u1) over (1.8.0.3-1) ... +Preparing to unpack .../62-xfsprogs_6.13.0-2+deb13u1_amd64.deb ... +Unpacking xfsprogs (6.13.0-2+deb13u1) over (6.13.0-2+b1) ... +Setting up libexpat1:amd64 (2.8.3-1~deb13u1) ... +Setting up libgraphite2-3:amd64 (1.3.14-2+deb13u1) ... +Setting up mesa-libgallium:amd64 (25.0.7-2+deb13u1) ... +Setting up librabbitmq4:amd64 (0.15.0-1+deb13u2) ... +Setting up libc-l10n (2.41-12+deb13u4) ... +Setting up bsdextrautils (2.41.5-0+deb13u1) ... +Setting up libgbm1:amd64 (25.0.7-2+deb13u1) ... +Setting up libtdb1:amd64 (2:1.4.13+samba4.22.11+dfsg-0+deb13u1) ... +Setting up libevent-2.1-7t64:amd64 (2.1.13-stable-1~deb13u1) ... +Setting up libgcrypt20:amd64 (1.11.0-7+deb13u1) ... +Setting up krb5-locales (1.21.3-5+deb13u1) ... +Setting up libnss3:amd64 (2:3.110-1+deb13u4) ... +Setting up libcom-err2:amd64 (1.47.2-3+b12) ... +Setting up samba-common (2:4.22.11+dfsg-0+deb13u1) ... +Setting up dnsmasq-base (2.91-1+deb13u2) ... +Setting up locales (2.41-12+deb13u4) ... +Generating locales (this might take a while)... + en_US.UTF-8... done +Generation complete. +Setting up libwbclient0:amd64 (2:4.22.11+dfsg-0+deb13u1) ... +Setting up libpcre2-16-0:amd64 (10.46-1~deb13u3) ... +Setting up libkrb5support0:amd64 (1.21.3-5+deb13u1) ... +Setting up dnsmasq (2.91-1+deb13u2) ... +Setting up tzdata (2026c-0+deb13u1) ... + +Current default time zone: 'Europe/Budapest' +Local time is now: Sun Oct 4 09:31:57 CEST 2026. +Universal Time is now: Sun Oct 4 07:31:57 UTC 2026. +Run 'dpkg-reconfigure tzdata' if you wish to change it. + +Setting up libcap2-bin (1:2.75-10+deb13u1+b3) ... +Setting up libtalloc2:amd64 (2:2.4.3+samba4.22.11+dfsg-0+deb13u1) ... +Setting up eject (2.41.5-0+deb13u1) ... +Setting up libpython3.13-minimal:amd64 (3.13.5-2+deb13u5) ... +Setting up libasound2-data (1.2.14-1+deb13u1) ... +Setting up busybox (1:1.37.0-6+b9) ... +Setting up libglib2.0-0t64:amd64 (2.84.4-3~deb13u5) ... +No schema files found: doing nothing. +Setting up libunbound8:amd64 (1.26.1-0+deb13u1) ... +Setting up libasound2t64:amd64 (1.2.14-1+deb13u1) ... +Setting up socat (1.8.0.3-1+deb13u1) ... +Setting up xz-utils (5.8.1-1+deb13u1) ... +Setting up libpng16-16t64:amd64 (1.6.48-1+deb13u6) ... +Setting up python3-idna (3.10-1+deb13u1) ... +Setting up libss2:amd64 (1.47.2-3+b12) ... +Setting up xfsprogs (6.13.0-2+deb13u1) ... +update-initramfs: deferring update (trigger activated) +Setting up dhcpcd-base (1:10.1.0-11+deb13u4) ... +Setting up libk5crypto3:amd64 (1.21.3-5+deb13u1) ... +Setting up logsave (1.47.2-3+b12) ... +Setting up python3-urllib3 (2.3.0-3+deb13u2) ... +Setting up libfdisk1:amd64 (2.41.5-0+deb13u1) ... +Setting up postfix (3.10.13-0+deb13u1) ... + +Postfix (main.cf) configuration was not modified by debconf. If you need to +make changes, edit /etc/postfix/main.cf (and others) as needed. To view +Postfix configuration values, see postconf(1). + +After modifying main.cf, be sure to run 'systemctl reload postfix'. + +Setting up libpcre2-posix3:amd64 (10.46-1~deb13u3) ... +Setting up libslirp0:amd64 (4.8.0-1+deb13u1) ... +Setting up mount (2.41.5-0+deb13u1) ... +Setting up perl-modules-5.40 (5.40.1-6+deb13u1) ... +Setting up gpgconf (2.4.7-21+deb13u1+b5) ... +Setting up libtasn1-6:amd64 (4.20.0-2+deb13u1) ... +Setting up python3.13-minimal (3.13.5-2+deb13u5) ... +Setting up libkrb5-3:amd64 (1.21.3-5+deb13u1) ... +Setting up libevent-core-2.1-7t64:amd64 (2.1.13-stable-1~deb13u1) ... +Setting up libssh2-1t64:amd64 (1.11.1-1+deb13u2) ... +Setting up openssl (3.5.7-1~deb13u3) ... +Setting up libpython3.13-stdlib:amd64 (3.13.5-2+deb13u5) ... +Setting up libxml2:amd64 (2.12.7+dfsg+really2.9.14-2.1+deb13u3) ... +Setting up sqlite3 (3.46.1-7+deb13u2) ... +Setting up gpg (2.4.7-21+deb13u1+b5) ... +Setting up libtevent0t64:amd64 (2:0.16.2+samba4.22.11+dfsg-0+deb13u1) ... +Setting up rsync (3.5.0+ds1-0+deb13u1) ... +rsync.service is a disabled or a static unit not running, not starting it. +Setting up util-linux-extra (2.41.5-0+deb13u1) ... +Setting up login (1:4.16.0-2+really2.41.5-0+deb13u1) ... +Setting up gpg-agent (2.4.7-21+deb13u1+b5) ... +Setting up python3.13 (3.13.5-2+deb13u5) ... +Setting up gpgsm (2.4.7-21+deb13u1+b5) ... +Setting up libgstreamer-plugins-base1.0-0:amd64 (1.26.2-1+deb13u2) ... +Setting up e2fsprogs (1.47.2-3+b12) ... +update-initramfs: deferring update (trigger activated) +Setting up fdisk (2.41.5-0+deb13u1) ... +Setting up libperl5.40:amd64 (5.40.1-6+deb13u1) ... +Setting up dirmngr (2.4.7-21+deb13u1+b5) ... +Setting up perl (5.40.1-6+deb13u1) ... +Setting up libgssapi-krb5-2:amd64 (1.21.3-5+deb13u1) ... +Setting up libxml-libxml-perl (2.0207+dfsg+really+2.0134-5+deb13u1) ... +update-perl-sax-parsers: Registering Perl SAX parser XML::LibXML::SAX::Parser with priority 50... +update-perl-sax-parsers: Registering Perl SAX parser XML::LibXML::SAX with priority 50... +update-perl-sax-parsers: Updating overall Perl SAX parser modules info file... +Replacing config file /etc/perl/XML/SAX/ParserDetails.ini with new version +Setting up libhttp-daemon-perl (6.16-1+deb13u1) ... +Setting up libhtml-parser-perl:amd64 (3.83-2~deb13u1) ... +Setting up libldb2:amd64 (2:2.11.0+samba4.22.11+dfsg-0+deb13u1) ... +Setting up libcurl4t64:amd64 (8.14.1-2+deb13u5) ... +Setting up bind9-libs:amd64 (1:9.20.29-1~deb13u1) ... +Setting up libcurl3t64-gnutls:amd64 (8.14.1-2+deb13u5) ... +Setting up samba-libs:amd64 (2:4.22.11+dfsg-0+deb13u1) ... +Setting up libnet-dns-perl (1.56-0+deb13u1) ... +Setting up libbytes-random-secure-perl (0.29-4~deb13u1) ... +Setting up curl (8.14.1-2+deb13u5) ... +Setting up libsmbclient0:amd64 (2:4.22.11+dfsg-0+deb13u1) ... +Setting up bind9-host (1:9.20.29-1~deb13u1) ... +Setting up smbclient (2:4.22.11+dfsg-0+deb13u1) ... +Setting up bind9-dnsutils (1:9.20.29-1~deb13u1) ... +Processing triggers for libc-bin (2.41-12+deb13u4) ... +Processing triggers for systemd (257.13-1~deb13u1) ... +Processing triggers for man-db (2.13.1-1) ... +Processing triggers for dbus (1.16.2-2) ... +Processing triggers for debianutils (5.23.2) ... +Processing triggers for initramfs-tools (0.148.4) ... +update-initramfs: Generating /boot/initrd.img-7.0.2-6-pve +Running hook script 'zz-proxmox-boot'.. +Re-executing '/etc/kernel/postinst.d/zz-proxmox-boot' in new private mount namespace.. +No /etc/kernel/proxmox-boot-uuids found, skipping ESP sync. +Processing triggers for postfix (3.10.13-0+deb13u1) ... +Restarting postfix diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/h-sampler.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/h-sampler.txt new file mode 100644 index 00000000..9de57399 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/h-sampler.txt @@ -0,0 +1,14 @@ +07:31:26 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:31 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:36 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:41 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:46 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:51 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:31:56 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:01 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:06 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:11 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:16 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:21 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:27 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active +07:32:31 9201=running 9202=running ctl9201=running/healthy agent=active pveproxy=active diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-after.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-after.txt new file mode 100644 index 00000000..fae05c9a --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-after.txt @@ -0,0 +1,38 @@ +chrony.service 892 +cron.service 1120 +dbus.service 790 +dm-event.service 360 +dnsmasq.service 573451 +felhom-agent.service 434746 +felhom-sshd.service 5162 +getty@tty1.service 975 +ksmtuned.service 802 +lxc-monitord.service 950 +lxcfs.service 826 +nfs-blkmap.service 766 +postfix.service 581574 +proxmox-firewall.service 1121 +pve-cluster.service 967 +pve-container@9201.service 3722604 +pve-container@9202.service 490507 +pve-firewall.service 1140 +pve-ha-crm.service 1179 +pve-ha-lrm.service 1315 +pve-lxc-syscalld.service 797 +pvedaemon.service 1168 +pvefw-logger.service 3019941 +pveproxy.service 1195 +pvescheduler.service 1348 +pvestatd.service 1141 +qmeventd.service 809 +rpcbind.service 679 +rrdcached.service 804 +smartmontools.service 806 +spiceproxy.service 1293 +ssh.service 969 +systemd-journald.service 574492 +systemd-logind.service 807 +systemd-udevd.service 376 +user@0.service 396762 +watchdog-mux.service 808 +zfs-zed.service 817 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-before.txt b/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-before.txt new file mode 100644 index 00000000..af39f449 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partH/h-svc-before.txt @@ -0,0 +1,38 @@ +chrony.service 892 +cron.service 1120 +dbus.service 790 +dm-event.service 360 +dnsmasq.service 3743010 +felhom-agent.service 434746 +felhom-sshd.service 5162 +getty@tty1.service 975 +ksmtuned.service 802 +lxc-monitord.service 950 +lxcfs.service 826 +nfs-blkmap.service 766 +postfix.service 1111 +proxmox-firewall.service 1121 +pve-cluster.service 967 +pve-container@9201.service 3722604 +pve-container@9202.service 490507 +pve-firewall.service 1140 +pve-ha-crm.service 1179 +pve-ha-lrm.service 1315 +pve-lxc-syscalld.service 797 +pvedaemon.service 1168 +pvefw-logger.service 3019941 +pveproxy.service 1195 +pvescheduler.service 1348 +pvestatd.service 1141 +qmeventd.service 809 +rpcbind.service 679 +rrdcached.service 804 +smartmontools.service 806 +spiceproxy.service 1293 +ssh.service 969 +systemd-journald.service 344 +systemd-logind.service 807 +systemd-udevd.service 376 +user@0.service 396762 +watchdog-mux.service 808 +zfs-zed.service 817 diff --git a/documentation/audits/os-updates-spike-2026-10-04/partI/demo-felhom-simulation.txt b/documentation/audits/os-updates-spike-2026-10-04/partI/demo-felhom-simulation.txt new file mode 100644 index 00000000..0ee523bb --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partI/demo-felhom-simulation.txt @@ -0,0 +1,261 @@ +# layer host on demo-felhom: 108 approved, 188 pending here +WOULD INSTALL (exact approved version, downloadable now): 108 + base-files 13.8+deb13u5 -> 13.8+deb13u7 + bash 5.2.37-2+b9 -> 5.2.37-2+b10 + bind9-dnsutils 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bind9-host 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bind9-libs 1:9.20.21-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 + bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 + busybox 1:1.37.0-6+b8 -> 1:1.37.0-6+b9 + curl 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 + dhcpcd-base 1:10.1.0-11+deb13u2 -> 1:10.1.0-11+deb13u4 + dirmngr 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 + dnsmasq 2.91-1+deb13u1 -> 2.91-1+deb13u2 + dnsmasq-base 2.91-1+deb13u1 -> 2.91-1+deb13u2 + e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 + eject 2.41-5 -> 2.41.5-0+deb13u1 + fdisk 2.41-5 -> 2.41.5-0+deb13u1 + gpg 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 + gpg-agent 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 + gpgconf 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 + gpgsm 2.4.7-21+deb13u1+b3 -> 2.4.7-21+deb13u1+b5 + gzip 1.13-1 -> 1.13-1+deb13u1 + krb5-locales 1.21.3-5 -> 1.21.3-5+deb13u1 + libasound2-data 1.2.14-1 -> 1.2.14-1+deb13u1 + libasound2t64 1.2.14-1 -> 1.2.14-1+deb13u1 + libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 + libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 + libblkid1 2.41-5 -> 2.41.5-0+deb13u1 + libbytes-random-secure-perl 0.29-3 -> 0.29-4~deb13u1 + libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 + libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 + libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 + libcurl3t64-gnutls 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 + libcurl4t64 8.14.1-2+deb13u3 -> 8.14.1-2+deb13u5 + libevent-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 + libevent-core-2.1-7t64 2.1.12-stable-10+b1 -> 2.1.13-stable-1~deb13u1 + libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 + libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 + libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 + libgbm1 25.0.7-2 -> 25.0.7-2+deb13u1 + libgcrypt20 1.11.0-7 -> 1.11.0-7+deb13u1 + libglib2.0-0t64 2.84.4-3~deb13u3 -> 2.84.4-3~deb13u5 + libgraphite2-3 1.3.14-2+b1 -> 1.3.14-2+deb13u1 + libgssapi-krb5-2 1.21.3-5 -> 1.21.3-5+deb13u1 + libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u1 -> 1.26.2-1+deb13u2 + libhtml-parser-perl 3.83-1+b2 -> 3.83-2~deb13u1 + libhttp-daemon-perl 6.16-1 -> 6.16-1+deb13u1 + libk5crypto3 1.21.3-5 -> 1.21.3-5+deb13u1 + libkrb5-3 1.21.3-5 -> 1.21.3-5+deb13u1 + libkrb5support0 1.21.3-5 -> 1.21.3-5+deb13u1 + liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 + libldb2 2:2.11.0+samba4.22.8+dfsg-0+deb13u1 -> 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 + liblzma5 5.8.1-1 -> 5.8.1-1+deb13u1 + libmount1 2.41-5 -> 2.41.5-0+deb13u1 + libnet-dns-perl 1.50-1 -> 1.56-0+deb13u1 + libnss3 2:3.110-1+deb13u1 -> 2:3.110-1+deb13u4 + libpcre2-16-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 + libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 + libpcre2-posix3 10.46-1~deb13u1 -> 10.46-1~deb13u3 + libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 + libpng16-16t64 1.6.48-1+deb13u5 -> 1.6.48-1+deb13u6 + libpython3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 + libpython3.13-stdlib 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 + librabbitmq4 0.15.0-1 -> 0.15.0-1+deb13u2 + libslirp0 4.8.0-1+b1 -> 4.8.0-1+deb13u1 + libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 + libsmbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 + libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 + libss2 1.47.2-3+b11 -> 1.47.2-3+b12 + libssh2-1t64 1.11.1-1 -> 1.11.1-1+deb13u2 + libssl3t64 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 + libtalloc2 2:2.4.3+samba4.22.8+dfsg-0+deb13u1 -> 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 + libtasn1-6 4.20.0-2 -> 4.20.0-2+deb13u1 + libtdb1 2:1.4.13+samba4.22.8+dfsg-0+deb13u1 -> 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 + libtevent0t64 2:0.16.2+samba4.22.8+dfsg-0+deb13u1 -> 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 + libunbound8 1.22.0-2+deb13u2 -> 1.26.1-0+deb13u1 + libuuid1 2.41-5 -> 2.41.5-0+deb13u1 + libwbclient0 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 + libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+b2 -> 2.0207+dfsg+really+2.0134-5+deb13u1 + libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2 -> 2.12.7+dfsg+really2.9.14-2.1+deb13u3 + locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 + login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 + logsave 1.47.2-3+b11 -> 1.47.2-3+b12 + mesa-libgallium 25.0.7-2 -> 25.0.7-2+deb13u1 + mount 2.41-5 -> 2.41.5-0+deb13u1 + openssl 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 + openssl-provider-legacy 3.5.6-1~deb13u1 -> 3.5.7-1~deb13u3 + perl 5.40.1-6 -> 5.40.1-6+deb13u1 + perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 + perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 + postfix 3.10.5-1~deb13u1 -> 3.10.13-0+deb13u1 + python3-idna 3.10-1 -> 3.10-1+deb13u1 + python3-urllib3 2.3.0-3+deb13u1 -> 2.3.0-3+deb13u2 + python3.13 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 + python3.13-minimal 3.13.5-2+deb13u2 -> 3.13.5-2+deb13u5 + rsync 3.4.1+ds1-5+deb13u2 -> 3.5.0+ds1-0+deb13u1 + samba-common 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 + samba-libs 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 + smbclient 2:4.22.8+dfsg-0+deb13u1 -> 2:4.22.11+dfsg-0+deb13u1 + socat 1.8.0.3-1 -> 1.8.0.3-1+deb13u1 + sqlite3 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 + tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 + util-linux 2.41-5 -> 2.41.5-0+deb13u1 + util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 + xfsprogs 6.13.0-2+b1 -> 6.13.0-2+deb13u1 + xz-utils 5.8.1-1 -> 5.8.1-1+deb13u1 +APPROVED BUT NOT DOWNLOADABLE NOW: 0 +approved, already at or above: 0 approved, not installed here: 0 +NOT COVERED (pending here, no approved entry): 80 + [Proxmox Debian Repository] 79 + ceph-common 19.2.3-pve4 -> 19.2.6-pve4 + ceph-fuse 19.2.3-pve4 -> 19.2.6-pve4 + chrony 4.6.1-3+deb13u1 -> 4.8-4~bpo13+2 + corosync 3.1.10-pve2 -> 3.1.10-pve3 + frr 10.6.1-1+pve2 -> 10.6.1-1+pve3 + frr-pythontools 10.6.1-1+pve2 -> 10.6.1-1+pve3 + libcephfs2 19.2.3-pve4 -> 19.2.6-pve4 + libcfg7 3.1.10-pve2 -> 3.1.10-pve3 + libcmap4 3.1.10-pve2 -> 3.1.10-pve3 + libcorosync-common4 3.1.10-pve2 -> 3.1.10-pve3 + libcpg4 3.1.10-pve2 -> 3.1.10-pve3 + libjs-extjs 7.0.0-5 -> 7.0.0-7 + libknet1t64 1.31-pve1 -> 1.35-pve2 + libnozzle1t64 1.31-pve1 -> 1.35-pve2 + libnvpair3linux 2.4.2-pve1 -> 2.4.4-pve1 + libproxmox-acme-perl 1.7.1 -> 1.7.2 + libproxmox-acme-plugins 1.7.1 -> 1.7.2 + libproxmox-backup-qemu0 2.0.2 -> 2.0.3 + libpve-access-control 9.1.1 -> 9.1.2 + libpve-apiclient-perl 3.4.2 -> 3.4.3 + libpve-cluster-api-perl 9.1.5 -> 9.1.6 + libpve-cluster-perl 9.1.5 -> 9.1.6 + libpve-common-perl 9.1.12 -> 9.2.2 + libpve-guest-common-perl 6.0.3 -> 6.0.5 + libpve-network-api-perl 1.6.5 -> 1.6.7 + libpve-network-perl 1.6.5 -> 1.6.7 + libpve-notify-perl 9.1.5 -> 9.1.6 + libpve-storage-perl 9.1.5 -> 9.1.11 + libquorum5 3.1.10-pve2 -> 3.1.10-pve3 + librados2 19.2.3-pve4 -> 19.2.6-pve4 + librados2-perl 1.5.0 -> 1.5.1 + libradosstriper1 19.2.3-pve4 -> 19.2.6-pve4 + librbd1 19.2.3-pve4 -> 19.2.6-pve4 + librgw2 19.2.3-pve4 -> 19.2.6-pve4 + libuutil3linux 2.4.2-pve1 -> 2.4.4-pve1 + libvotequorum8 3.1.10-pve2 -> 3.1.10-pve3 + libzfs7linux 2.4.2-pve1 -> 2.4.4-pve1 + libzpool7linux 2.4.2-pve1 -> 2.4.4-pve1 + novnc-pve 1.7.0-1 -> 1.7.0-2 + proxmox-backup-client 4.2.0-1 -> 4.2.7-1 + proxmox-backup-file-restore 4.2.0-1 -> 4.2.7-1 + proxmox-enterprise-support-keyring 1.0 -> 1.1 + proxmox-firewall-data (new) -> 0.1 + proxmox-first-boot 9.2.5 -> 9.2.8 + proxmox-kernel-7.0 7.0.2-6 -> 7.0.14-20 + proxmox-kernel-7.0.14-20-pve-signed (new) -> 7.0.14-20 + proxmox-kernel-helper 9.1.0+fde2 -> 9.2.0 + proxmox-mini-journalreader 1.6 -> 1.7 + proxmox-widget-toolkit 5.2.2 -> 5.2.10 + pve-cluster 9.1.5 -> 9.1.6 + pve-container 6.1.10 -> 6.1.14 + pve-docs 9.2.1 -> 9.2.13 + pve-edk2-firmware 4.2025.05-2 -> 4.2026.08-1 + pve-edk2-firmware-aarch64 4.2025.05-2 -> 4.2026.08-1 + pve-edk2-firmware-legacy 4.2025.05-2 -> 4.2026.08-1 + pve-edk2-firmware-ovmf 4.2025.05-2 -> 4.2026.08-1 + pve-firewall 6.0.4 -> 6.0.6 + pve-firmware 3.18-3 -> 3.18-6 + pve-ha-manager 5.2.4 -> 5.2.5 + pve-i18n 3.7.4 -> 3.10.0 + pve-manager 9.2.2 -> 9.2.21 + pve-qemu-kvm 11.0.0-3 -> 11.0.3-4 + pve-xtermjs 6.0.0-1 -> 6.0.0-2 + pve-yew-mobile-gui 0.7.0 -> 0.8.0 + pve-yew-mobile-i18n 3.7.4 -> 3.10.0 + python3-ceph-argparse 19.2.3-pve4 -> 19.2.6-pve4 + python3-ceph-common 19.2.3-pve4 -> 19.2.6-pve4 + python3-cephfs 19.2.3-pve4 -> 19.2.6-pve4 + python3-rados 19.2.3-pve4 -> 19.2.6-pve4 + python3-rbd 19.2.3-pve4 -> 19.2.6-pve4 + python3-rgw 19.2.3-pve4 -> 19.2.6-pve4 + qemu-server 9.1.15 -> 9.2.10 + shim-helpers-amd64-signed 1+16.1+1+pmx1 -> 1+16.1+2+pmx1 + shim-signed 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 + shim-signed-common 1.48+pmx1+16.1-1+pmx1 -> 1.51+pmx1+16.1-2+pmx1 + shim-unsigned 16.1-1+pmx1 -> 16.1-2+pmx1 + zfs-initramfs 2.4.2-pve1 -> 2.4.4-pve1 + zfs-zed 2.4.2-pve1 -> 2.4.4-pve1 + zfsutils-linux 2.4.2-pve1 -> 2.4.4-pve1 + [Tailscale] 1 + tailscale 1.102.2 -> 1.102.4 +# layer guest on demo-felhom: 49 approved, 59 pending here +WOULD INSTALL (exact approved version, downloadable now): 49 + base-files 13.8+deb13u6 -> 13.8+deb13u7 + bash 5.2.37-2+b9 -> 5.2.37-2+b10 + bind9-dnsutils 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bind9-host 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bind9-libs 1:9.20.23-1~deb13u1 -> 1:9.20.29-1~deb13u1 + bsdextrautils 2.41-5 -> 2.41.5-0+deb13u1 + bsdutils 1:2.41-5 -> 1:2.41.5-0+deb13u1 + dhcpcd-base 1:10.1.0-11+deb13u3 -> 1:10.1.0-11+deb13u4 + e2fsprogs 1.47.2-3+b11 -> 1.47.2-3+b12 + fdisk 2.41-5 -> 2.41.5-0+deb13u1 + gzip 1.13-1 -> 1.13-1+deb13u1 + libaudit-common 1:4.0.2-2 -> 1:4.0.2-2+deb13u1 + libaudit1 1:4.0.2-2+b2 -> 1:4.0.2-2+deb13u1 + libblkid1 2.41-5 -> 2.41.5-0+deb13u1 + libc-bin 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libc-l10n 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libc6 2.41-12+deb13u3 -> 2.41-12+deb13u4 + libcap2 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 + libcap2-bin 1:2.75-10+deb13u1+b1 -> 1:2.75-10+deb13u1+b3 + libcom-err2 1.47.2-3+b11 -> 1.47.2-3+b12 + libexpat1 2.7.1-2 -> 2.8.3-1~deb13u1 + libext2fs2t64 1.47.2-3+b11 -> 1.47.2-3+b12 + libfdisk1 2.41-5 -> 2.41.5-0+deb13u1 + liblastlog2-2 2.41-5 -> 2.41.5-0+deb13u1 + libmount1 2.41-5 -> 2.41.5-0+deb13u1 + libpcre2-8-0 10.46-1~deb13u1 -> 10.46-1~deb13u3 + libperl5.40 5.40.1-6 -> 5.40.1-6+deb13u1 + libpython3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 + libpython3.13-stdlib 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 + libsmartcols1 2.41-5 -> 2.41.5-0+deb13u1 + libsqlite3-0 3.46.1-7+deb13u1 -> 3.46.1-7+deb13u2 + libss2 1.47.2-3+b11 -> 1.47.2-3+b12 + libssl3t64 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 + libuuid1 2.41-5 -> 2.41.5-0+deb13u1 + locales 2.41-12+deb13u3 -> 2.41-12+deb13u4 + login 1:4.16.0-2+really2.41-5 -> 1:4.16.0-2+really2.41.5-0+deb13u1 + logsave 1.47.2-3+b11 -> 1.47.2-3+b12 + mount 2.41-5 -> 2.41.5-0+deb13u1 + openssl 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 + openssl-provider-legacy 3.5.6-1~deb13u2 -> 3.5.7-1~deb13u3 + perl 5.40.1-6 -> 5.40.1-6+deb13u1 + perl-base 5.40.1-6 -> 5.40.1-6+deb13u1 + perl-modules-5.40 5.40.1-6 -> 5.40.1-6+deb13u1 + postfix 3.10.12-0+deb13u2 -> 3.10.13-0+deb13u1 + python3.13 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 + python3.13-minimal 3.13.5-2+deb13u3 -> 3.13.5-2+deb13u5 + tzdata 2026b-0+deb13u1 -> 2026c-0+deb13u1 + util-linux 2.41-5 -> 2.41.5-0+deb13u1 + util-linux-extra 2.41-5 -> 2.41.5-0+deb13u1 +APPROVED BUT NOT DOWNLOADABLE NOW: 0 +approved, already at or above: 0 approved, not installed here: 0 +NOT COVERED (pending here, no approved entry): 10 + [Debian] 4 + curl 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 + libcurl3t64-gnutls 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 + libcurl4t64 8.14.1-2+deb13u4 -> 8.14.1-2+deb13u5 + libssh2-1t64 1.11.1-1+deb13u1 -> 1.11.1-1+deb13u2 + [Docker CE] 6 + containerd.io 2.2.6-1~debian.13~trixie -> 2.3.6-1~debian.13~trixie + docker-buildx-plugin 0.36.0-1~debian.13~trixie -> 0.37.1-1~debian.13~trixie + docker-ce 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie + docker-ce-cli 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie + docker-ce-rootless-extras 5:29.7.1-1~debian.13~trixie -> 5:29.8.2-1~debian.13~trixie + docker-compose-plugin 5.3.1-1~debian.13~trixie -> 5.6.0-1~debian.13~trixie diff --git a/documentation/audits/os-updates-spike-2026-10-04/partI/sample-approved-list.tsv b/documentation/audits/os-updates-spike-2026-10-04/partI/sample-approved-list.tsv new file mode 100644 index 00000000..4892695d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/partI/sample-approved-list.tsv @@ -0,0 +1,160 @@ +# Sample approved list (Part I 3) — built from what ring 0 REALLY installed on 2026-10-04: +# layer=host: demo-hp host, Debian fast lane (Part H 2, 108 packages); layer=guest: scratch guest 9202 (Part G 1, 49 packages). +# layer package version origin +host libc6 2.41-12+deb13u4 Debian:13.7/stable +host base-files 13.8+deb13u7 Debian:13.7/stable +host bash 5.2.37-2+b10 Debian:13.7/stable +host bsdutils 1:2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host gzip 1.13-1+deb13u1 Debian:13.7/stable +host libperl5.40 5.40.1-6+deb13u1 Debian:13.7/stable +host perl 5.40.1-6+deb13u1 Debian:13.7/stable +host perl-base 5.40.1-6+deb13u1 Debian:13.7/stable +host perl-modules-5.40 5.40.1-6+deb13u1 Debian:13.7/stable +host liblastlog2-2 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host eject 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host bsdextrautils 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host util-linux-extra 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host fdisk 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libsmartcols1 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libblkid1 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libmount1 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host mount 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libuuid1 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host util-linux 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libfdisk1 2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libaudit-common 1:4.0.2-2+deb13u1 Debian:13.7/stable +host libaudit1 1:4.0.2-2+deb13u1 Debian:13.7/stable +host sqlite3 3.46.1-7+deb13u2 Debian:13.7/stable +host libsqlite3-0 3.46.1-7+deb13u2 Debian:13.7/stable +host libc-bin 2.41-12+deb13u4 Debian:13.7/stable +host login 1:4.16.0-2+really2.41.5-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host logsave 1.47.2-3+b12 Debian:13.7/stable +host libext2fs2t64 1.47.2-3+b12 Debian:13.7/stable +host e2fsprogs 1.47.2-3+b12 Debian:13.7/stable +host dnsmasq-base 2.91-1+deb13u2 Debian:13.7/stable +host dnsmasq 2.91-1+deb13u2 Debian:13.7/stable +host libexpat1 2.8.3-1~deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host openssl-provider-legacy 3.5.7-1~deb13u3 Debian-Security:13/stable-security +host libssl3t64 3.5.7-1~deb13u3 Debian-Security:13/stable-security +host postfix 3.10.13-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host python3.13 3.13.5-2+deb13u5 Debian:13.7/stable +host libpython3.13-stdlib 3.13.5-2+deb13u5 Debian:13.7/stable +host python3.13-minimal 3.13.5-2+deb13u5 Debian:13.7/stable +host libpython3.13-minimal 3.13.5-2+deb13u5 Debian:13.7/stable +host tzdata 2026c-0+deb13u1 Debian:13.7/stable +host liblzma5 5.8.1-1+deb13u1 Debian:13.7/stable +host rsync 3.5.0+ds1-0+deb13u1 Debian-Security:13/stable-security +host libcap2 1:2.75-10+deb13u1+b3 Debian:13.7/stable +host libpcre2-8-0 10.46-1~deb13u3 Debian-Security:13/stable-security +host dhcpcd-base 1:10.1.0-11+deb13u4 Debian:13.7/stable +host libgssapi-krb5-2 1.21.3-5+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libkrb5-3 1.21.3-5+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libkrb5support0 1.21.3-5+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libk5crypto3 1.21.3-5+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libcom-err2 1.47.2-3+b12 Debian:13.7/stable +host libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 Debian:13.7/stable +host bind9-dnsutils 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +host bind9-host 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +host bind9-libs 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +host krb5-locales 1.21.3-5+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libc-l10n 2.41-12+deb13u4 Debian:13.7/stable +host locales 2.41-12+deb13u4 Debian:13.7/stable +host xz-utils 5.8.1-1+deb13u1 Debian:13.7/stable +host busybox 1:1.37.0-6+b9 Debian:13.7/stable +host libssh2-1t64 1.11.1-1+deb13u2 Debian:13.7/stable +host curl 8.14.1-2+deb13u5 Debian:13.7/stable +host libcurl4t64 8.14.1-2+deb13u5 Debian:13.7/stable +host libgcrypt20 1.11.0-7+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host gpgsm 2.4.7-21+deb13u1+b5 Debian:13.7/stable +host dirmngr 2.4.7-21+deb13u1+b5 Debian:13.7/stable +host gpg 2.4.7-21+deb13u1+b5 Debian:13.7/stable +host gpgconf 2.4.7-21+deb13u1+b5 Debian:13.7/stable +host gpg-agent 2.4.7-21+deb13u1+b5 Debian:13.7/stable +host libasound2t64 1.2.14-1+deb13u1 Debian:13.7/stable +host libasound2-data 1.2.14-1+deb13u1 Debian:13.7/stable +host libbytes-random-secure-perl 0.29-4~deb13u1 Debian:13.7/stable +host libcap2-bin 1:2.75-10+deb13u1+b3 Debian:13.7/stable +host libcurl3t64-gnutls 8.14.1-2+deb13u5 Debian:13.7/stable +host libevent-2.1-7t64 2.1.13-stable-1~deb13u1 Debian-Security:13/stable-security +host libevent-core-2.1-7t64 2.1.13-stable-1~deb13u1 Debian-Security:13/stable-security +host libgbm1 25.0.7-2+deb13u1 Debian:13.7/stable +host mesa-libgallium 25.0.7-2+deb13u1 Debian:13.7/stable +host libglib2.0-0t64 2.84.4-3~deb13u5 Debian:13.7/stable +host libgraphite2-3 1.3.14-2+deb13u1 Debian:13.7/stable +host libgstreamer-plugins-base1.0-0 1.26.2-1+deb13u2 Debian-Security:13/stable-security +host libhtml-parser-perl 3.83-2~deb13u1 Debian:13.7/stable +host libhttp-daemon-perl 6.16-1+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libtalloc2 2:2.4.3+samba4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libtevent0t64 2:0.16.2+samba4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libsmbclient0 2:4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host samba-common 2:4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host smbclient 2:4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libtdb1 2:1.4.13+samba4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libldb2 2:2.11.0+samba4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host samba-libs 2:4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libwbclient0 2:4.22.11+dfsg-0+deb13u1 Debian:13.7/stable +host libnet-dns-perl 1.56-0+deb13u1 Debian:13.7/stable, Debian-Security:13/stable-security +host libnss3 2:3.110-1+deb13u4 Debian:13.7/stable, Debian-Security:13/stable-security +host libpcre2-16-0 10.46-1~deb13u3 Debian-Security:13/stable-security +host libpcre2-posix3 10.46-1~deb13u3 Debian-Security:13/stable-security +host libpng16-16t64 1.6.48-1+deb13u6 Debian-Security:13/stable-security +host librabbitmq4 0.15.0-1+deb13u2 Debian:13.7/stable, Debian-Security:13/stable-security +host libslirp0 4.8.0-1+deb13u1 Debian:13.7/stable +host libss2 1.47.2-3+b12 Debian:13.7/stable +host libtasn1-6 4.20.0-2+deb13u1 Debian:13.7/stable +host libunbound8 1.26.1-0+deb13u1 Debian-Security:13/stable-security +host libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+deb13u1 Debian:13.7/stable +host openssl 3.5.7-1~deb13u3 Debian-Security:13/stable-security +host python3-idna 3.10-1+deb13u1 Debian:13.7/stable +host python3-urllib3 2.3.0-3+deb13u2 Debian:13.7/stable, Debian-Security:13/stable-security +host socat 1.8.0.3-1+deb13u1 Debian:13.7/stable +host xfsprogs 6.13.0-2+deb13u1 Debian:13.7/stable +guest base-files 13.8+deb13u7 Debian:13.7/stable +guest bash 5.2.37-2+b10 Debian:13.7/stable +guest bind9-dnsutils 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +guest bind9-host 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +guest bind9-libs 1:9.20.29-1~deb13u1 Debian-Security:13/stable-security +guest bsdextrautils 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest bsdutils 1:2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest dhcpcd-base 1:10.1.0-11+deb13u4 Debian:13.7/stable +guest e2fsprogs 1.47.2-3+b12 Debian:13.7/stable +guest fdisk 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest gzip 1.13-1+deb13u1 Debian:13.7/stable +guest libaudit-common 1:4.0.2-2+deb13u1 Debian:13.7/stable +guest libaudit1 1:4.0.2-2+deb13u1 Debian:13.7/stable +guest libblkid1 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest libc-bin 2.41-12+deb13u4 Debian:13.7/stable +guest libc-l10n 2.41-12+deb13u4 Debian:13.7/stable +guest libc6 2.41-12+deb13u4 Debian:13.7/stable +guest libcap2 1:2.75-10+deb13u1+b3 Debian:13.7/stable +guest libcap2-bin 1:2.75-10+deb13u1+b3 Debian:13.7/stable +guest libcom-err2 1.47.2-3+b12 Debian:13.7/stable +guest libexpat1 2.8.3-1~deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest libext2fs2t64 1.47.2-3+b12 Debian:13.7/stable +guest libfdisk1 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest liblastlog2-2 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest libmount1 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest libpcre2-8-0 10.46-1~deb13u3 Debian-Security:13/stable-security +guest libperl5.40 5.40.1-6+deb13u1 Debian:13.7/stable +guest libpython3.13-minimal 3.13.5-2+deb13u5 Debian:13.7/stable +guest libpython3.13-stdlib 3.13.5-2+deb13u5 Debian:13.7/stable +guest libsmartcols1 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest libsqlite3-0 3.46.1-7+deb13u2 Debian:13.7/stable +guest libss2 1.47.2-3+b12 Debian:13.7/stable +guest libssl3t64 3.5.7-1~deb13u3 Debian-Security:13/stable-security +guest libuuid1 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest locales 2.41-12+deb13u4 Debian:13.7/stable +guest login 1:4.16.0-2+really2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest logsave 1.47.2-3+b12 Debian:13.7/stable +guest mount 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest openssl 3.5.7-1~deb13u3 Debian-Security:13/stable-security +guest openssl-provider-legacy 3.5.7-1~deb13u3 Debian-Security:13/stable-security +guest perl 5.40.1-6+deb13u1 Debian:13.7/stable +guest perl-base 5.40.1-6+deb13u1 Debian:13.7/stable +guest perl-modules-5.40 5.40.1-6+deb13u1 Debian:13.7/stable +guest postfix 3.10.13-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest python3.13 3.13.5-2+deb13u5 Debian:13.7/stable +guest python3.13-minimal 3.13.5-2+deb13u5 Debian:13.7/stable +guest tzdata 2026c-0+deb13u1 Debian:13.7/stable +guest util-linux 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable +guest util-linux-extra 2.41.5-0+deb13u1 Debian-Security:13/stable-security, Debian:13.7/stable diff --git a/documentation/audits/os-updates-spike-2026-10-04/scripts/g-state.sh b/documentation/audits/os-updates-spike-2026-10-04/scripts/g-state.sh new file mode 100644 index 00000000..22842374 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/scripts/g-state.sh @@ -0,0 +1,15 @@ +#!/bin/bash +# g-state.sh — READ-ONLY state of guest 9202 for Part G (run on demo-hp as root). +export LC_ALL=C +echo "### state $1 $(date -u +%FT%TZ)" +pct exec 9202 -- docker ps -a --format '{{.Names}}|{{.Status}}' | sort +echo "-- container StartedAt / health" +for c in $(pct exec 9202 -- docker ps -aq); do pct exec 9202 -- docker inspect -f '{{.Name}} started={{.State.StartedAt}} health={{if .State.Health}}{{.State.Health.Status}}{{else}}none{{end}} restarts={{.RestartCount}}' $c; done | sort +echo "-- dockerd/containerd"; pct exec 9202 -- systemctl show -p MainPID -p ActiveEnterTimestamp docker containerd | paste -sd' ' +pct exec 9202 -- docker version --format 'docker server {{.Server.Version}}' 2>/dev/null +echo "-- services (MainPID) "; pct exec 9202 -- bash -c 'for u in $(systemctl list-units --type=service --state=running --no-legend --plain | awk "{print \$1}"); do echo "$u $(systemctl show -p MainPID --value $u)"; done' | sort > /root/g-svc-$1.txt; wc -l < /root/g-svc-$1.txt +echo "-- processes mapping deleted files (need a restart)" +pct exec 9202 -- bash -c 'for p in /proc/[0-9]*; do if grep -qE "\(deleted\)" $p/maps 2>/dev/null; then echo "$(cat $p/comm 2>/dev/null) $(basename $p)"; fi; done | sort | uniq -c | sort -rn | head -30' +echo "-- disk"; pct exec 9202 -- df -B1 --output=used / | tail -1 | sed 's/^/rootfs_used_bytes /' +pct exec 9202 -- dpkg-query -W -f='${Package} ${Version}\n' > /root/g-dpkg-$1.txt; wc -l < /root/g-dpkg-$1.txt +echo "-- controller health via its own healthcheck"; pct exec 9202 -- docker inspect -f '{{.State.Health.Status}}' felhom-controller diff --git a/documentation/audits/os-updates-spike-2026-10-04/scripts/g-update.sh b/documentation/audits/os-updates-spike-2026-10-04/scripts/g-update.sh new file mode 100644 index 00000000..636de10c --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/scripts/g-update.sh @@ -0,0 +1,28 @@ +#!/bin/bash +# g-update.sh — apply all pending DEBIAN updates (not Docker CE) in 9202, non-interactive, keep configs. +# Runs ON demo-hp as root. A sampler records the containers every 2 s while it runs. +export LC_ALL=C +TAG=$1 +( while [ ! -f /root/g-stop-$TAG ]; do echo "$(date -u +%T) $(pct exec 9202 -- docker ps --format '{{.Names}}:{{.Status}}' 2>&1 | sort | tr '\n' ' ')"; sleep 2; done ) > /root/g-sampler-$TAG.txt 2>&1 & +SP=$! +pct exec 9202 -- bash -c ' +export DEBIAN_FRONTEND=noninteractive LC_ALL=C +apt-get update -q >/dev/null 2>&1; echo update_rc=$? +pkgs=$(apt-get -s dist-upgrade | grep "^Inst " | grep -v "Docker CE" | awk "{print \$2}" | tr "\n" " ") +echo "debian_packages=$(echo $pkgs | wc -w)" +apt-get -s install --only-upgrade $pkgs 2>/dev/null | grep -E "^(Need to get|After this operation|[0-9]+ upgraded)" +df -B1 --output=used / | tail -1 | sed "s/^/rootfs_used_before /" +du -sb /var/cache/apt/archives | sed "s/^/apt_cache_before /" +s=$(date +%s.%N) +apt-get install -y -q --only-upgrade -o Dpkg::Options::=--force-confold -o Dpkg::Options::=--force-confdef $pkgs > /root/apt-run.log 2>&1 +rc=$? +echo "apt_rc=$rc seconds=$(awk -v a=$s -v b=$(date +%s.%N) "BEGIN{printf \"%.1f\", b-a}")" +grep -E "^(Fetched|Need to get)" /root/apt-run.log +grep -iE "conffile|Configuration file|dpkg-old|dpkg-dist|warning" /root/apt-run.log | head -8 +du -sb /var/cache/apt/archives | sed "s/^/apt_cache_after /" +df -B1 --output=used / | tail -1 | sed "s/^/rootfs_used_after /" +apt-get clean; df -B1 --output=used / | tail -1 | sed "s/^/rootfs_used_after_clean /" +echo "pending_debian_after=$(apt-get -s dist-upgrade | grep "^Inst " | grep -vc "Docker CE")" +grep -E "^Restarting|restart" /root/apt-run.log | head -10 +' +touch /root/g-stop-$TAG; wait $SP diff --git a/documentation/audits/os-updates-spike-2026-10-04/scripts/g3b.sh b/documentation/audits/os-updates-spike-2026-10-04/scripts/g3b.sh new file mode 100644 index 00000000..12afc06d --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/scripts/g3b.sh @@ -0,0 +1,13 @@ +export DEBIAN_FRONTEND=noninteractive LC_ALL=C +echo "=== a normal apt run on the half state:"; apt-get install -y -q curl 2>&1 | grep -E "^E:" | head -2 +echo "=== containers still up? $(docker ps -q | wc -l) running" +s=$(date +%s.%N); dpkg --configure -a --force-confold > /root/repair1.log 2>&1; echo "dpkg --configure -a rc=$? seconds=$(awk -v a=$s -v b=$(date +%s.%N) 'BEGIN{printf "%.1f", b-a}')" +s=$(date +%s.%N); apt-get -f install -y -q -o Dpkg::Options::=--force-confold > /root/repair2.log 2>&1; echo "apt-get -f install rc=$? seconds=$(awk -v a=$s -v b=$(date +%s.%N) 'BEGIN{printf "%.1f", b-a}')"; grep -E "upgraded|^E:" /root/repair2.log | head -2 +echo "=== audit after repair: '$(dpkg --audit 2>&1 | head -1)'" +pkgs=$(apt-get -s dist-upgrade | grep "^Inst " | grep -v "Docker CE" | awk '{print $2}' | tr "\n" " ") +echo "debian still pending after repair: $(echo $pkgs | wc -w)" +s=$(date +%s.%N); apt-get install -y -q --only-upgrade -o Dpkg::Options::=--force-confold -o Dpkg::Options::=--force-confdef $pkgs > /root/apt-rest.log 2>&1; echo "apply-rest rc=$? seconds=$(awk -v a=$s -v b=$(date +%s.%N) 'BEGIN{printf "%.1f", b-a}')" +echo "pending_debian_after=$(apt-get -s dist-upgrade | grep "^Inst " | grep -vc "Docker CE") audit='$(dpkg --audit 2>&1 | head -1)' non-ii=$(dpkg -l | awk 'NR>5 && $1!="ii"' | grep -vc '^rc\|ic ifupdown')" +echo "libc6 $(dpkg-query -W -f='${Version}' libc6)" +for c in felhom-controller paperless-webserver paperless-postgres paperless-redis filebrowser; do echo "$c $(docker inspect -f '{{.State.Status}} {{if .State.Health}}{{.State.Health.Status}}{{end}} started={{.State.StartedAt}}' $c)"; done +apt-get clean diff --git a/documentation/audits/os-updates-spike-2026-10-04/scripts/g4.sh b/documentation/audits/os-updates-spike-2026-10-04/scripts/g4.sh new file mode 100644 index 00000000..12848391 --- /dev/null +++ b/documentation/audits/os-updates-spike-2026-10-04/scripts/g4.sh @@ -0,0 +1,31 @@ +#!/bin/bash +# g4.sh