the backup promise is kept: photos deleted and returned byte-identical
gates / gates (push) Successful in 20s

The capability map's journey row now carries the half it could never finish: five
photos in, deleted the way a child would, the old route refusing and touching
nothing, the off-site restore returning them, and them opening — sha256 identical,
5 of 5, with a negative control.

Stated with it, because both are true: the bind needed ZERO operator presses (the
box registered itself and used the mail the hub sent itself), but the PBS cascade
needed ONE — the Re-issue press R-511 documents, which then succeeded because of
this morning's ep0 grant.

R-543 (P1) is the honest caveat: off-site ON by default is not off-site WORKING on
day one — a fresh box waits at „Kulcsletétre vár" until the household creates its
recovery code, and nothing asks them to, while the tier-1 row already promises that
copy. R-544 records a log line that says „escrow deleted" where the effect is
demotion to retained custody.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 20:24:50 +02:00
parent c18efc0610
commit 3f7ac8ee6e
5 changed files with 177 additions and 69 deletions
+37
View File
@@ -1,5 +1,41 @@
# STATUS — what works, what's broken, what's next
**Updated 2026-09-16 (evening) — the photos come back, and they open.**
> **Ready for a volunteer: almost — one thing stands in the way, and it is small.** A brand-new box now
> protects the household's own files: I put five photos in, deleted them the way a child would, and got
> them back byte-for-byte from the off-site copy. The old route that used to lie now refuses politely
> and points at the one that works. What is missing: on a new box the off-site copy is switched on but
> **paused** until the household creates their recovery code, and nothing asks them to do it.
**What changed today.** The backup page stops claiming it holds files it does not hold. A restore that
cannot bring your files back now refuses instead of reporting success — and it no longer wipes the app's
own wastebasket on the way. „Alkalmazás telepítve" now means installed, not merely started. Every new
customer gets the off-site copy by default, 100 GB. The off-site server got the one permission it was
missing, so a rebuilt customer's box can be set up again without hand-work.
**What I proved on a box that installed itself this evening.** It installed from the new image, showed
Felhom's own screen with no Proxmox address, registered itself, and **bound with nothing pressed on your
side** — the connect e-mail it used was the one the system sent itself. It landed on today's golden.
Then: five photos in, the local backup, the recovery-code ceremony, the off-site copy, the deletion, the
refusal, the restore, and five photos that open — identical to the originals.
**Decisions I took.** None under the unattended rule.
**Needs you.**
1. **Say yes or no to publishing the new installer image (1.28.0).** It is built and passed every check,
and it fixes the screen that kept showing the pairing code after the box was connected. Nothing is
published without your word. If you do nothing: new volunteers keep getting the older image, which
works but shows that stale screen.
2. **One small fix before a volunteer: tell the household to create their recovery code.** Until they do,
the off-site copy is paused — so „your files are protected" is a promise with a delay in it. I can
add the prompt and make the sentence state the real state.
3. **The slow-crash-loop counter** (yesterday's ruling) is still owed, and is a job for the nightly.
---
## Previous note
**Updated 2026-09-16 (drill on a fresh box) — the fixes hold; the backup promise does not.**
> **Ready for a volunteer: NO — one reason, and it is new.** On a brand-new box with one drive, the
@@ -786,3 +822,4 @@ off. **`peti-felhom` is a real machine we have not heard from since 15 July** an
The 2026-08-09 batch (R-279 … R-292), still untriaged; the three remaining R-264 readers; R-317 (one
line in the agent); R-327 (decide the naming claim's status); R-359 (nothing reads the off-site store).