burn-down round 2: controller v0.297.0 rows closed (23), golden 0.297.0 evidence, delivery evidence, 23-row unchecked table, STATUS/CONTEXT/REPORT (292 -> 199; 1 opened, 94 closed)
gates / gates (push) Successful in 1m59s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 20:41:50 +02:00
parent d75ad0fdf3
commit 30650cad6e
13 changed files with 640 additions and 37 deletions
+23
View File
@@ -103,6 +103,29 @@ The full text of every row below: `git show e8c56c44:documentation/backlog/OPEN-
| **R-269** | **A rotated-out per-guest local-API token still authorises, and the test that appears to pin the opposite passes only because of its lookup ORDER.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-agent v0.147.0 (delivered): token store reloads on growth before answering; `TestTokenStore_RotatedOutTokenRejectedFirst`; red-proof agent-red-proofs.txt |
| **R-317** | **The agent decides whether to install dnsmasq by stat-ing a file the OTHER package owns.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-agent v0.147.0 (delivered): dnsmasq install probed by its service unit; `TestEnsureDnsmasq_*`; red-proof agent-red-proofs.txt |
| **R-350** | **SECURITY — the hub operator password was printed in cleartext into a session transcript by CC, 2026-08-20. Rotation recommended.** (P3) | CLOSED 2026-10-05 — DUPLICATE of R-132 (its unique facts moved there) | Same credential (hub operator password HUB_PW), same mechanism (curl -w '%{redirect_url}' re-renders Basic-auth into the URL), same single action (operator decides to rotate). R-132 already folded R-580 (third occurrence 2026-09-18) on 2026-10-03; R-350 is the 2026-08-20 occurrence. |
| **R-591** | **[P3-LOW] `Stack.Copy()` is a deep copy with one shallow field, and the field is new.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: `deepCopyStack` copies every reference in Meta (i18n overlay and 11 more found by `TestDeepCopyStackMetaSharesNoReference`); `TestDeepCopyStackI18nIsNotShared` |
| **R-568** | **[P3-LOW] The dashboard's drive-health rows swap order between visits — the same two disks, listed in a different order a minute apart.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: disk-health rows sorted by durable id; `TestDiskHealthRows_OrderIsStable` |
| **R-567** | **[P3-LOW] The two drive wizard pages (/storage/init, /storage/attach) do not highlight the Tárhely menu group — the sidebar reads as if the household left the storage section.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: storage wizard pages open the Storage nav group; `TestStorageWizardPages_OpenTheStorageNavGroup`; two parity fixtures re-captured (nav only) |
| **R-363** | **The fill watcher runs once a day, so a filesystem that fills at 03:31 goes unannounced for ~24 h while the backup is already refusing apps.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: fill-watch also every 10 min (`sched.Every`), daily + start-up kept; `TestFillWatchRunsOnAnInterval` |
| **R-547** | **[P3-LOW] A disk that fills and empties between sweeps is never mentioned to anyone: `disk_critical` is defined at ≥95 % used, but the fill-watch runs once a day.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: same change as R-363 (the interval watch); `TestFillWatchRunsOnAnInterval` |
| **R-10** | T-6E-1: DB-dump dir-fsync asymmetry (LOW, confirmed in 6E) **MIGRATED FROM `ROADMAP.md` 2026-08-22 (R-369) — originally filed 2026-07-15, size XS, roadmap state `idea`.** Moved verbatim; nothing added (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: dump directory fsynced after the rename; `TestDumpOneTo_SyncsTheDumpDirectoryAfterRename` |
| **R-552** | **[P3-LOW] An interrupted-restore notice for an app that is then REMOVED stays on the restore page for ever.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: remove clears the interrupted-restore notice (`ClearInterruptedRestore`, wired in the remove path); `TestR552_RemoveClearsTheInterruptedRestoreNotice` |
| **R-251** | **The recovery listing renders one row per restic TAG, so the customer is shown an "app" they never installed and their data counted twice.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: off-site marker tag not listed as an app; `TestR251_MarkerTagIsNotAnApp` |
| **R-104** | **An interrupted offsite run leaves an exclusive restic lock the existing self-heal cannot reach.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: a lock surviving the self-heal is classed `locked` with its own cause line; `TestR104_SurvivingLockIsNamed` |
| **R-619** | **[P3-LOW] A `type: password` deploy field is MANDATORY however `required` reads, and the `deploy-fields` contract says the opposite — so any caller that trusts it is refused.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: password deploy fields served as required by the API (fresh metadata per call); `TestR619_PasswordFieldIsServedAsRequired` |
| **R-362** | **A data drive detached mid-restore is reported as „permission denied".** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: a restore onto a detached drive names the drive; `TestR362_DetachedDriveIsNamed` |
| **R-675** | **[P3-LOW] The unit-only restore's refusal for a file app still points to „Fájlok visszaállítása" instead of the second drive's whole restore.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: files-restore refusal names the second drive's whole copy (and is in both languages now); `TestR675_RefusalNamesTheWholeCopy` |
| **R-256** | **C2 — „A mentéskezelő nem elérhető." names no route at all.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: `flash.offbox.mgr_unavailable/_unreachable` name a route (hu+en); `TestR256_R257_OffboxRefusalsNameARoute` |
| **R-257** | **C2 — „Az offsite tároló nincs elárvult állapotban." puts an English loanword and an internal state name in front of a Hungarian household customer, and names no route.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: `flash.offbox.not_orphaned` reworded (hu+en); `TestR256_R257_OffboxRefusalsNameARoute` |
| **R-240** | **A backup that covered nothing calls itself „Sikeres".** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: a zero-selection run no longer says „Sikeres"; `TestR240_ZeroSelectionRunDoesNotSaySuccess` |
| **R-365** | **An overdue abandonment countdown renders its past due-date in the future tense.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: a 0-day deletion countdown says it is due — page AND top bar (`TestR365_OverdueCountdownIsNotFutureTense`, `TestR365_BannerSaysDueAtZeroDays`) |
| **R-425** | **`offbox_rename_gate.py` scans a fixed three-entry `FILES` list.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: offbox rename gate finds files by pattern and judges the bundle; 3 decoys |
| **R-565** | **[P3-LOW] The English page test sees only ACCENTED Hungarian: an ASCII-only Hungarian word left in a template passes it on the English page.** (P3) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: English-page test knows ASCII Hungarian words; a real `mp` leak became a key; `TestI18nEnglishPages` |
| **R-564** | **[P3-LOW] The retrieval-promise gate's Hungarian stems cannot see a SPLIT verb — „csak akkor állíthatók vissza", „hozod vissza" — so those Hungarian sentences were never scanned; the English translation exposed them.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: retrieval-promise gate knows split-verb Hungarian; 7 occurrences registered; 2 decoys |
| **R-603** | **[P3-LOW] An English string containing an apostrophe silently never matches on a rendered page, and a `strings.Contains` assertion reads exactly like a missing sentence.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: Go-side check for HTML-escapable values; `TestR603_GoNamedValuesDoNotHideBehindHTMLEscaping` |
| **R-454** | **[P3-LOW] Five `internal/web` test files have been `gofmt`-unclean for an unknown length of time, and nothing notices.** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: `scripts/gofmt_gate.py` (NOT CHECKED out loud on the Go-less CI runner, INCONCLUSIVE elsewhere; 3 decoys); 12 files formatted |
| **R-208** | **Every Felhom Go build re-downloads its modules because `ARG VERSION` sits ABOVE the module-download layer — ~440 MB of dead cache per build, 90.5 GB of the 157 GB** (P4) | CLOSED 2026-10-05 — FIXED (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: controller and hub Dockerfiles: `ARG VERSION…` just above `go build`; `TestR208_DockerfileVersionArgsSitBelowModuleDownload`, felhom.eu `scripts/test_dockerfile_arg_order.py` (hub v0.137.0 deployed) |
| **R-457** | **[P3-LOW] A test that hardcodes a date AND asserts an age derived from it is green on the day it is written and red the next morning — one instance PROVEN, six candidate files named.** (P4) | CLOSED 2026-10-05 — CHECKED, NOTHING LEFT (burn-down round 2) | felhom-controller v0.297.0 (`1453cfc` + CI fix `6f1ba1f`, CI run 1372 success; image `felhom-controller:0.297.0`; golden 0.297.0 vouched; delivered to demo-hp, demo-felhom, tester-1 — `audits/burndown2-2026-10-05/delivery/controller-delivery.txt`); red-proofs `audits/burndown2-2026-10-05/controller-red-proofs.txt`: swept: none of the six candidate files has a date literal feeding an assertion against the real clock (identity/format/ordering checks only) — nothing to change; the faked-future-date CI idea is a separate, larger job |
---
File diff suppressed because one or more lines are too long