From 41590f8ee618c84ce47830714037de139f9090a8 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sun, 13 Sep 2026 23:06:21 +0200 Subject: [PATCH] second night: scratch guest 9202 built (R-481 CLOSED, persists); controller v0.242.0 delivered (R-487 R-491 R-490 R-476 R-456 CLOSED, R-489 re-scoped); R-492 filed; rotation restarted from bentopdf; morning note Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CONTEXT.md | 11 +++ REPORT.md | 66 +++++++------- STATUS.md | 42 +++++++++ .../architecture/01-topology-and-trust.md | 8 ++ .../architecture/07-backup-architecture.md | 2 +- .../14-scratch-guest-built.txt | 17 ++++ .../15-bentopdf-walk.txt | 60 +++++++++++++ .../v0242-2026-09-14/16-floor-0.242.0.txt | 54 +++++++++++ .../v0242-2026-09-14/17-v0242-live-9202.txt | 90 +++++++++++++++++++ .../18-v0242-live-9202-pass2.txt | 75 ++++++++++++++++ .../audits/v0242-2026-09-14/19-R489-cause.txt | 19 ++++ .../rp-v242-R476-manifest-date.txt | 11 +++ .../rp-v242-R487-list-inert.txt | 20 +++++ .../rp-v242-R487-picker-404.txt | 12 +++ .../rp-v242-R487-picker-not-rendered.txt | 11 +++ .../rp-v242-R487-restore-wrong-dir.txt | 16 ++++ .../rp-v242-R487-row-not-built.txt | 15 ++++ .../rp-v242-R487-row-not-rendered.txt | 11 +++ .../rp-v242-R489-null-again.txt | 15 ++++ .../rp-v242-R490-mount-removed.txt | 11 +++ .../rp-v242-R490-no-fallback.txt | 11 +++ .../rp-v242-R491-hold-not-cleared.txt | 11 +++ documentation/backlog/CLOSED-ITEMS.md | 6 ++ documentation/backlog/OPEN-ITEMS.md | 9 +- documentation/operations/nodes.md | 19 ++++ documentation/runbooks/nightly-rotation.md | 10 +-- 26 files changed, 586 insertions(+), 46 deletions(-) create mode 100644 documentation/audits/nightly-2026-09-13b-bentopdf/14-scratch-guest-built.txt create mode 100644 documentation/audits/nightly-2026-09-13b-bentopdf/15-bentopdf-walk.txt create mode 100644 documentation/audits/v0242-2026-09-14/16-floor-0.242.0.txt create mode 100644 documentation/audits/v0242-2026-09-14/17-v0242-live-9202.txt create mode 100644 documentation/audits/v0242-2026-09-14/18-v0242-live-9202-pass2.txt create mode 100644 documentation/audits/v0242-2026-09-14/19-R489-cause.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R476-manifest-date.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-list-inert.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-404.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-not-rendered.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-restore-wrong-dir.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-row-not-built.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R487-row-not-rendered.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R489-null-again.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R490-mount-removed.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R490-no-fallback.txt create mode 100644 documentation/audits/v0242-2026-09-14/rp-v242-R491-hold-not-cleared.txt diff --git a/CONTEXT.md b/CONTEXT.md index d9a71687..98594e4a 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -40,6 +40,17 @@ on demo-hp — `documentation/audits/slice4-2026-09-13/`, design `09-update-arch - **One host, one customer** (schema: `hosts.host_id` PK, one `customer_id`; one agent per box). A scratch guest "enrolled as its own customer" on a box that already belongs to a customer is not something the product can do (R-481, 2026-09-13); a second guest of the same customer is. +- **The scratch guest is LXC 9202 on demo-hp and it persists** (operator ruling option 1, built + 2026-09-13 night, R-481 CLOSED). A second guest of the demo-hp customer, restored from the vouched + golden onto the NVMe `dir` storage at `/mnt/hdd_1`, hub OFF, tunnel OFF, agent OFF, off-site OFF, + self-update OFF — so the floor does not reach it and its controller image is set by hand in + `/etc/felhom-controller-image` (the one place hand-setting is allowed). Never bind the real data + drive into it; never start cloudflared there (a second connector would serve the public domain). + Two choices were CC's and are reversible — decided by CC unattended, operator may reverse: no + data-drive bind, no tunnel. Reach, shape and rebuild recipe: `operations/nodes.md`. +- **The local backup lists are keyed on the DRIVES, not on what is deployed** (controller v0.242.0, + R-487 — the same rule R-237 set for the off-site list). A removed app whose unit was kept is listed + with its restore; a unit on a data drive is opened where it sits. - **A release reaches the fleet by floor between golden bakes when its MinAgent is declared with the floor** (ruling 2026-09-13, hub v0.112.0, R-472 CLOSED). An undeclared floor above the golden is still held, and the forms refuse it. v0.239.0 arrived on both demo boxes this way in ~15 s. Never hand-deploy diff --git a/REPORT.md b/REPORT.md index 210678e5..c6288f2e 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,45 +1,45 @@ -# REPORT — the four evening items before the second night (2026-09-13) +# REPORT — the second night: scratch guest built, controller v0.242.0, rotation restarted (2026-09-13/14) -*Overwritten each session. The night's own report (adventurelog rotation, v0.240.0) is preserved as -`audits/nightly-2026-09-13-adventurelog/` and the register; the controller report is -`felhom-controller/REPORT.md`, the catalog's `app-catalog-felhom.eu/REPORT.md`.* +*Overwritten each session. Evidence: `documentation/audits/nightly-2026-09-13b-bentopdf/` (the guest +build and the bentopdf walk) and `documentation/audits/v0242-2026-09-14/` (red-proofs, floor, three +live passes). Controller detail: `felhom-controller/REPORT.md`.* -## 1. The rules file +**Rules:** `.claude/rules/unprompted-work.md`. **Architecture named:** `01-topology-and-trust.md` §2 +(the scratch guest is a second guest of the same customer), `07-backup-architecture.md` §6.3 and the +R-237 store-keyed list rule, `09-update-architecture.md` (holds). **Baselines:** felhom.eu `72ee053`, +controller `3e81330` (v0.241.0), catalog `6d6eec3`. -`.claude/rules/unprompted-work.md` copied byte-identical into `felhom-controller`, `felhom.eu` and -`app-catalog-felhom.eu` (documents-only pushes). `instructions_gate.py` refused the first push: a rule -file needs `paths:` or `unconditional: true`; all four copies (root included) now start with the -three-line `unconditional: true` frontmatter — sha256 `d1aa3af83ae3b220…` everywhere. +## Step 0 — R-481, operator ruling option 1 → LXC 9202 on demo-hp, persists -## 2. R-481 — the scratch guest (ruled; NOT built, and why) +Restored from the vouched golden 0.236.0 onto a `dir` storage re-added at `/mnt/hdd_1` +(`nvme-scratch`), sized like 9201, unprivileged; the demo-hp customer seeded with hub OFF, tunnel OFF, +agent OFF, off-site OFF, self-update OFF; image set by hand (the one place allowed). Disposition in +the guest, on the host and on the hub side (`operations/nodes.md`, the register). Two CC decisions, +tagged in `CONTEXT.md` and `01-topology-and-trust.md`: no real-data-drive bind, no cloudflared. -The ruling ("a second enrolled LXC … enrolled as a scratch customer") collides with the model: the hub -keys a host to one customer (`hosts.host_id` PK) and the box runs one agent with one host identity; -re-running the installer with another customer-id would rewrite demo-hp's enrolment. Options and a -recommendation are in the row and STATUS; 9201's shape and the disk placement (`pct move-volume` -onto a `dir` storage at `/mnt/hdd_1`) are recorded for whichever is chosen. +## Step 1–3 — controller v0.242.0 (`d698ce3`, docs `406755f`), one release, floor-delivered -## 3. R-483 — photos (re-ranked P2, catalog) +R-487 (removed app listed with its restore; the lists are keyed on the drives), R-491 (removal +clears the update hold), R-490 (`/api/system/info` reachable + fallback), R-489 (`volumes_removed` +difference — **half: a restore-recreated volume has no compose label and is missed; row kept open, +measured**), R-476 (Tier-2 copy dated by its data), R-456 (rule pinned). Red-proofs ×11, full gate +green, floor 0.242.0 with MinAgent 0.129.0: demo-hp +16 s, demo-felhom +17 s. Live on 9202 with an +opengist throwaway through the endpoints the UI invokes (no browser on DooPlex); the first pass was +refused 409 (a running app must be stopped before removal) and repeated. -Diffed against `homelab-manifests` `adventurelog-system/adventurelog.yaml`: the k3s ingress sends -`/media`, `/static`, `/admin`, `/accounts` to the backend **service port 80**; the catalog sent -everything to the frontend. Two catalog cuts (`3172258`, `ed62cfd`): a backend traefik router for the -four prefixes, then port 80 instead of 8000 — the backend image runs nginx in front of gunicorn and -Django serves a photo by `X-Accel-Redirect`, so port 8000 returned 200 with an empty body. Applied to -the operator's own instance through the guarded Update; proven without a browser -(`audits/nightly-2026-09-13-adventurelog/11-R483-repro.txt`): `GET /media/images/.webp` with a -session → 200 `image/webp`, RIFF/WEBP magic; anonymous 403 (the app's rule). **Confirmed by the operator in a browser at 21:49 — closed.** The frontend's 500 on scripted multipart uploads is upstream and -recorded in the row; browser uploads work. +## Step 2 — rotation reset to bentopdf on 9202: clean -## 4. R-479 — tier order for bind-data apps (ruled; controller v0.241.0) +Front door, use (browser-side tool, no data route — recorded, not faked), backup + second copy, +remove-with-data keep-backups, Tier-2 unit restore, guarded update (same pin; backed up first because +the restore rewrote `deployed_at`, R-478), remove-everything. No new rows from the walk. -Ruling 9 in `09-update-architecture.md` §3. Built, tested, red-proofed; delivered by the floor and -live-checked on a nextcloud throwaway — see `felhom-controller/REPORT.md` and -`audits/v0241-2026-09-13/`. +## Register -## Observations +210 open / 194 closed → **205 / 200**. Closed: R-481, R-487, R-491, R-490, R-476, R-456. Re-scoped: +R-489. Opened: R-492 (delete `cfg.Paths.HDDPath`). Security note: demo-hp's retrieval passphrase +appeared once in a tool output on DooPlex during the guest build (redaction list missed the key). -0. **A removed app keeps its update hold; a reinstall would start held.** FILED: R-491 +## Teardown, three layers -1. **The controller's evening release rides the same session as the night's — two releases in one calendar day, one per session.** NOT-A-FINDING: the rule is per session; both are recorded with their MinAgent lines. -2. **`homelab-manifests` is not in the workspace; its manifests were read from Gitea's API.** NOT-A-FINDING: the workspace CLAUDE.md says non-felhom repos are unrelated; a read-only fetch was enough. +Machine: throwaways (opengist, bentopdf) removed with data and backups; 9202 persists on purpose. +Host: the `nvme-scratch` storage and 9202 stay (disposition recorded). Hub: floor raised; nothing else. diff --git a/STATUS.md b/STATUS.md index e79687ed..4e797d58 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,5 +1,47 @@ # STATUS — what works, what's broken, what's next +**Updated 2026-09-14 (morning note, the second night) — the scratch guest is built, one controller release, the rotation restarted.** + +**Decisions I took.** (1) The scratch guest on the HP was built as you ruled: a second guest under +the HP's own customer, on the fast internal disk, sized like the main one, kept on purpose and written +up in all three places. Two properties of it were my call and you may reverse them: it never sees your +real data drive, and it never starts the public tunnel — a second connector would serve the public +domain from a throwaway. (2) A finding I had already listed as fixed turned out half-fixed when +measured live, and the rule is one release per night, so I kept the line open with the exact measurement +instead of shipping a second release. (3) The removed-app listing was a medium-priority line, but it +needed no ruling, touched no customer data and was the rotation's own finding, so I took it into +tonight's release. + +**What I exercised.** The rotation restarted from its first standing app on the scratch guest: front +door, use, backup, second copy, remove-with-data, full restore from the second copy, the guarded +update, remove-everything — all clean. Then a throwaway app for the release proof. + +**What broke, and whether I fixed it.** Six lines fixed and shipped in one controller release, +delivered by the floor in 16 and 17 seconds, proven on the scratch guest: an app you removed while +keeping its backup now shows on the backup pages with a button that reinstalls it (before, the way +back existed only as a hidden endpoint, and a backup kept on a data drive could not be found at all); +a removal now clears the "held after a failed update" mark; the memory card on the monitoring page can +render; the second copy is dated by its data rather than by a file that only moves when the app's +definition changes; and a boot rule is now pinned by a test. Half-fixed: the removal's list of +deleted volumes is right for a freshly installed app and empty for one that came back from a restore, +because the restore recreates the volume without the label the list looks for. Measured, kept open. +One security slip to know about: while building the scratch guest, the HP's retrieval passphrase was +printed once into a tool output here on DooPlex. Nothing left the machine. + +**Rows.** Opened 1 (delete the empty drive-path setting nothing reads any more). Closed 6 (the +scratch guest, the removed-app listing, the hold left behind, the monitoring card, the second-copy +date, the boot rule). Re-scoped 1 (deleted-volume list). Register: 210 open / 194 closed before, +205 open / 200 closed after. + +**Needs you.** (1) Open the backup page once in a browser after removing a throwaway app with its +backup kept, and press the new button — strict screen coverage is yours. **If you do nothing:** the +feature stays proven at the endpoint level only. (2) The passphrase slip: re-issue the HP's retrieval +passphrase from the hub when convenient. **If you do nothing:** the old one stays valid; the exposure +is one line in this session's local record. (3) The scratch guest stays up and idle. **If you do +nothing:** it costs the HP about one and a half gigabytes of memory and nothing else. + +--- + **Updated 2026-09-13 (evening, before the night) — your four items.** **Decisions I took.** (1) The rules file now sits in the workspace root and all three repos, diff --git a/documentation/architecture/01-topology-and-trust.md b/documentation/architecture/01-topology-and-trust.md index 74303a5c..31eb7020 100644 --- a/documentation/architecture/01-topology-and-trust.md +++ b/documentation/architecture/01-topology-and-trust.md @@ -64,6 +64,14 @@ customer box. one host (a company environment) is **not precluded** — the agent manages a *set* of guests. The only multi-tenant-specific work deferred to "if it becomes real" is resource fairness (per-guest disk/RAM/CPU quotas). +- **A scratch guest is a second guest of the SAME customer, unenrolled** (operator ruling + 2026-09-13, R-481; built as LXC 9202 on demo-hp, persists). The hub ties one host to one + customer, so a second enrolled customer on a box is not a thing the product does. The scratch + guest runs with the hub, the tunnel, the agent link, off-site and self-update all off, and its + controller image is set by hand — the one place that is allowed. Two of its properties were + *decided by CC unattended — operator may reverse*: **it never binds the customer's real data + drive** (a throwaway must not be able to reach real data) and **it never starts cloudflared** + (a second connector would serve the public domain from a scratch box). --- diff --git a/documentation/architecture/07-backup-architecture.md b/documentation/architecture/07-backup-architecture.md index 72e8e6a2..92501d82 100644 --- a/documentation/architecture/07-backup-architecture.md +++ b/documentation/architecture/07-backup-architecture.md @@ -277,7 +277,7 @@ what the unit holds** — for an app whose data is a bind mount that is the defi (R-479). **Removal and the tiers (controller v0.240.0):** removing an app with its backups KEPT keeps the unit, the Tier-2 mirror AND the Tier-2 record, so „Teljes visszaállítás" still works afterwards (R-486); „Mentési adatok törlése" deletes the unit, every mirror and the app's backup preferences, and -never touches off-site snapshots (R-474). A removed app is listed on neither backup page (R-487, open). **For a bind-data app the update's tier order is second drive → off-site → own unit (R-479, v0.241.0), because the unit does not hold the files.** +never touches off-site snapshots (R-474). A removed app whose unit was kept is listed on both local backup pages with its restore since controller v0.242.0 (R-487): **the local lists are keyed on the drives, not on what is deployed** — the rule R-237 set for the off-site list — and the restore opens the unit where it sits, a data drive included. **For a bind-data app the update's tier order is second drive → off-site → own unit (R-479, v0.241.0), because the unit does not hold the files.** ### 6.1 The four tiers, as configured on the live fleet diff --git a/documentation/audits/nightly-2026-09-13b-bentopdf/14-scratch-guest-built.txt b/documentation/audits/nightly-2026-09-13b-bentopdf/14-scratch-guest-built.txt new file mode 100644 index 00000000..76c29220 --- /dev/null +++ b/documentation/audits/nightly-2026-09-13b-bentopdf/14-scratch-guest-built.txt @@ -0,0 +1,17 @@ +=== scratch guest 9202 — first contact 2026-09-13T20:24:41Z === +HTTP 200 +{"ok":true,"data":[{"name":"actualbudget","meta":{"display_name":"ActualBudget","description":"Személyes pénzügyek és költségvetés kezelése","category":"finance","subdomain":"budget", +--- sync the catalog --- +HTTP 200 +{"ok":true,"data":{"ok":true,"message":"Sablonok naprakészek — nincs változás"},"message":"Sablonok naprakészek — nincs változás"} + + +stacks known: 55 | deployed: [] +--- guest facts --- +VMID Status Lock Name +9201 running demo-hp +9202 running demo-hp-scratch +felhom-controller filebrowser traefik +0 +SCRATCH GUEST — R-481, operator ruling 2026-09-13 (option 1) +The nightly rotation throwaway host under the demo-hp customer. Hub OFF, tunnel OFF, agent OFF, off-site OFF. diff --git a/documentation/audits/nightly-2026-09-13b-bentopdf/15-bentopdf-walk.txt b/documentation/audits/nightly-2026-09-13b-bentopdf/15-bentopdf-walk.txt new file mode 100644 index 00000000..aff2ed98 --- /dev/null +++ b/documentation/audits/nightly-2026-09-13b-bentopdf/15-bentopdf-walk.txt @@ -0,0 +1,60 @@ +=== NIGHT 2 — bentopdf as a customer on the SCRATCH guest 9202 — 2026-09-13T20:25:37Z === +controller: gitea.dooplex.hu/admin/felhom-controller:0.241.0 | catalog pin: image: ghcr.io/alam00000/bentopdf:v2.8.6 +--- install --- +HTTP 202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} +after: state=running updating=False phase=None err='' hold='' | ghcr.io/alam00000/bentopdf:v2.8.6 Up 14 seconds (healthy) +--- front door: GET / and the app's assets through traefik --- +GET / -> 200 text/html 72677 +GET /index.html -> 301 text/html 169 +USE: BentoPDF is a browser-side toolbox — every PDF is processed in the browser and never sent to the server. There is no data route and no API; nothing to put in and nothing to read back. Recorded, not faked. +--- backup through the backups page: backup now, then the 2nd copy --- +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +idle after 5 s +HTTP 200 {"ok":true,"message":"2. mentés elindítva"} +/mnt/sys_drive/felhom-data/backups/primary/bentopdf: + 2026-09-13T20:26 1864 compose/.felhom.yml + 2026-09-13T20:26 291 compose/app.yaml + 2026-09-13T20:26 1109 compose/docker-compose.yml + 2026-09-13T20:26 1009 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/bentopdf: + 2026-09-13T20:26 1864 recovery-unit/compose/.felhom.yml + 2026-09-13T20:26 1109 recovery-unit/compose/docker-compose.yml + 2026-09-13T20:26 291 recovery-unit/compose/app.yaml + 2026-09-13T20:26 1009 recovery-unit/manifest.json + 2026-09-13T20:26 1 .felhom-tier2-layout +card: {"ok":true,"data":{"stack":"bentopdf","backup_paths":[{"path":"/mnt/sys_drive/felhom-data/backups/primary/bentopdf","size_bytes":12465,"size_human":"24K","exists":true},{"path":"/mnt/felhom-drives/scratch_hdd/backups/secondary/bentopdf","size_bytes":16562,"size_human":"32K","exists":true}],"has_back +--- disaster: remove with data, keep backups; the way back: Teljes visszaállítás (Tier 2) --- +HTTP 200 {"ok":true,"data":{"removed":"bentopdf","volumes_removed":null,"hdd_paths_removed":[],"hdd_paths_preserved":[],"hdd_note":"Az alkalmazás nem tárolt saját adatot külső meghajtón, így ott nem volt mit törölni."},"message":"Stack bentopdf removed"} +removed: state=not_deployed updating=False phase=None err='' hold='' | front door now: 404 text/plain; charset=utf-8 19 +HTTP/2 302 +location: /backups/apps?flash=Teljes+vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl. + +restore-status: {"running": false, "op": "tier2-unit-restore", "stack": "bentopdf", "started_at": "2026-09-13T20:26:23.141536724Z", "last": {"op": "tier2-unit-restore", "stack": "bentopdf", "ok": true, "message": "A(z) bentopdf: a beállítások visszaálltak — az alkalmazás újraindult. FIGYELEM: ez a mentés csak a beállításokat tartalmazta, adatot nem. Az alkalmazás adatai NEM álltak vissza ebből a mentésből. A viss +after restore: state=running updating=False phase=None err='' hold='' | front door: 200 text/html 72677 +--- guarded Update (same pin: no edge in the catalog) --- +--- POST /api/stacks/bentopdf/update at 2026-09-13T20:26:34Z --- +HTTP 202 +{"ok":true,"data":{"accepted":true,"completed":false},"message":"Frissítés elindult – az állapot a kártyán követhető"} + + 0s phase backing-up + + 3s phase done +end (2026-09-13T20:26:38Z, +3s): state=running updating=False phase=done err='' hold='' +2026/09/13 20:26:35 update.go:391: [INFO] [stacks] update bentopdf: accepted — guarded update started +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase checking +2026/09/13 20:26:35 update.go:508: [INFO] [stacks] update bentopdf: no usable copy on any tier — younger than 24h0m0s and not older than this install's deploy (2026-09-13T20:26:23Z) (found: Tier 2 (second drive) at 2026-09-13T20:26:13Z (0s old); Tier 1 (own recovery unit) at 2026-09-13T20:26:07Z ( +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase backing-up +2026/09/13 20:26:35 update.go:523: [INFO] [stacks] update bentopdf: precondition met after the backup — Tier 2 (second drive) copy from 2026-09-13T20:26:35Z +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase safety-dump +2026/09/13 20:26:35 update.go:538: [INFO] [stacks] update bentopdf: safety dump done (0 file(s)) [] +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase pinning +2026/09/13 20:26:35 pin.go:362: [INFO] [stacks] update bentopdf: pin advanced to the catalog's current definition (bentopdf=ghcr.io/alam00000/bentopdf:v2.8.6) +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase pulling +2026/09/13 20:26:35 update.go:820: [INFO] [stacks] update bentopdf: phase starting +2026/09/13 20:26:36 update.go:820: [INFO] [stacks] update bentopdf: phase verifying +2026/09/13 20:26:36 update.go:614: [INFO] [stacks] update bentopdf: healthy after 0s (the app's health check passed) +2026/09/13 20:26:36 update.go:620: [INFO] [stacks] update bentopdf: DONE in 1s +--- remove with data AND backups; drive clean? --- +HTTP 200 {"ok":true,"data":{"removed":"bentopdf","volumes_removed":null,"hdd_paths_removed":[],"hdd_paths_preserved":[],"hdd_note":"Az alkalmazás nem tárolt saját adatot külső meghajtón, így ott nem volt mit törölni.","backup_paths_removed":["/mnt/sys_drive/felhom-data/backups/primary/bentopdf (24K)","/mnt/felhom-drives/scratch_hdd/backups/secondary/bentopdf (16.2 KB)"]},"message":"Stack bentopdf removed"} +/mnt/sys_drive/felhom-data/backups/primary/bentopdf: ABSENT +/mnt/felhom-drives/scratch_hdd/backups/secondary/bentopdf: ABSENT +containers: 0 | prefs: None None | card: state=not_deployed updating=False phase=done err='' hold='' +=== done 2026-09-13T20:26:46Z === diff --git a/documentation/audits/v0242-2026-09-14/16-floor-0.242.0.txt b/documentation/audits/v0242-2026-09-14/16-floor-0.242.0.txt new file mode 100644 index 00000000..3ae77cda --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/16-floor-0.242.0.txt @@ -0,0 +1,54 @@ +=== FLOOR RAISE: 0.242.0 with min_agent 0.129.0 (R-487 R-491 R-490 R-489 R-476) === +T0 POST at 2026-09-13T20:51:13Z +HTTP/1.1 303 See Other +Location: /configuration?flash=floor_set +DB floor + declared: id="global-floor-input" name="min_controller_version" value="0.242.0" | name="min_agent" value="0.129.0" placeholder="MinAgent from | +demo-hp on 0.242.0 at 2026-09-13T20:51:30Z (+16s): gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 7 seconds (healthy) +demo-felhom on 0.242.0 at 2026-09-13T20:51:31Z (+17s): gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 10 seconds (healthy) +--- hub log since T0 (managed floor) --- +2026/09/13 22:51:14 [INFO] Global controller-version floor set to "0.242.0" (declared MinAgent "0.129.0") +2026/09/13 22:51:16 [INFO] managed floor SERVED for demo-felhom: floor 0.242.0, agent requirement "0.129.0" from declared (golden 0.236.0) +2026/09/13 22:51:17 [INFO] managed floor SERVED for demo-hp: floor 0.242.0, agent requirement "0.129.0" from declared (golden 0.236.0) + +--- demo-hp: controller log (SetFloor / self-update / version) --- +2026/09/13 20:51:23 updater.go:96: [DEBUG] [selfupdate] VerifyStartup: checking update state in /opt/docker/felhom-controller/data +2026/09/13 20:51:23 updater.go:96: [DEBUG] [selfupdate] VerifyStartup: pending update found — target=0.242.0 previous=0.241.0 +2026/09/13 20:51:23 updater.go:809: [INFO] [selfupdate] Post-update startup: update successful (0.241.0 → 0.242.0) +2026/09/13 20:51:23 main.go:655: [INFO] Self-update enabled (check every 6h, auto-update: false, auto-update time: 04:30) +2026/09/13 20:51:23 scheduler.go:102: [INFO] [scheduler] Registered periodic job: selfupdate-check (every 6h0m0s) +2026/09/13 20:51:23 scheduler.go:67: [DEBUG] [scheduler] periodic job registered: name="selfupdate-check" interval=6h0m0s totalJobs=18 +2026/09/13 20:51:23 offsiteapply.go:151: [INFO] [offsite-apply] settle-gate: awaiting floor knowledge (first report ACK) before offsite apply +2026/09/13 20:51:24 client.go:67: [DEBUG] [agentapi] agent version seen: 0.130.0 (was "") +2026/09/13 20:51:28 builder.go:40: [DEBUG] [report] BuildReport: starting — version=0.242.0, storagePaths=1 +2026/09/13 20:51:29 updater.go:96: [DEBUG] [selfupdate] SetFloor: floor "" → "0.242.0" +2026/09/13 20:51:29 updater.go:96: [DEBUG] [selfupdate] maybeAutoUpdate: current 0.242.0 >= floor 0.242.0 — no action +2026/09/13 20:51:33 offsiteapply.go:151: [INFO] [offsite-apply] settle-gate: GO — at/above floor 0.242.0 (we are 0.242.0), no managed update running + +--- demo-hp: bootstrap service journal --- +Sep 13 20:51:22 demo-hp systemd[1]: felhom-controller-bootstrap.service: Deactivated successfully. +Sep 13 20:51:22 demo-hp systemd[1]: Stopped felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount). +Sep 13 20:51:22 demo-hp systemd[1]: Stopping felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount)... +Sep 13 20:51:22 demo-hp systemd[1]: Starting felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount)... +Sep 13 20:51:22 demo-hp felhom-controller-bootstrap.sh[2438508]: [ctrl-bootstrap] deploying gitea.dooplex.hu/admin/felhom-controller:0.242.0 from /etc/felhom-bootstrap/bootstrap.json (hostname=demo-hp) +Sep 13 20:51:22 demo-hp felhom-controller-bootstrap.sh[2438582]: 9e9e3a9987db6cab7c7d8d413a64ce73695fe5b9f090f554022ab02520ebe0b7 +Sep 13 20:51:23 demo-hp felhom-controller-bootstrap.sh[2438508]: [ctrl-bootstrap] controller started +Sep 13 20:51:23 demo-hp systemd[1]: Finished felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount). + +--- demo-felhom: controller log (SetFloor / self-update / version) --- +2026/09/13 20:51:22 [INFO] [selfupdate] Post-update startup: update successful (0.241.0 → 0.242.0) +2026/09/13 20:51:22 [INFO] Self-update enabled (check every 6h, auto-update: false, auto-update time: 04:30) +2026/09/13 20:51:22 [INFO] [scheduler] Registered periodic job: selfupdate-check (every 6h0m0s) +2026/09/13 20:51:22 [INFO] [offsite-apply] settle-gate: awaiting floor knowledge (first report ACK) before offsite apply +2026/09/13 20:51:32 [INFO] [offsite-apply] settle-gate: GO — at/above floor 0.242.0 (we are 0.242.0), no managed update running + +--- demo-felhom: bootstrap service journal --- +Sep 13 20:51:21 demo-felhom systemd[1]: felhom-controller-bootstrap.service: Deactivated successfully. +Sep 13 20:51:21 demo-felhom systemd[1]: Stopped felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount). +Sep 13 20:51:21 demo-felhom systemd[1]: Stopping felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount)... +Sep 13 20:51:21 demo-felhom systemd[1]: Starting felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount)... +Sep 13 20:51:21 demo-felhom felhom-controller-bootstrap.sh[3573553]: [ctrl-bootstrap] deploying gitea.dooplex.hu/admin/felhom-controller:0.242.0 from /etc/felhom-bootstrap/bootstrap.json (hostname=demo-felhom) +Sep 13 20:51:21 demo-felhom felhom-controller-bootstrap.sh[3573602]: eaa532876b7d3df1f2ab46965d08245f2b3eaff97f8ba9b4f6d93e799876a38f +Sep 13 20:51:21 demo-felhom felhom-controller-bootstrap.sh[3573553]: [ctrl-bootstrap] controller started +Sep 13 20:51:21 demo-felhom systemd[1]: Finished felhom-controller-bootstrap.service - Felhom controller bootstrap (deploy the baked controller from the agent-populated config mount). + +SUMMARY T0=2026-09-13T20:51:13Z {'demo-hp': ('2026-09-13T20:51:30Z', 16), 'demo-felhom': ('2026-09-13T20:51:31Z', 17)} not done: [] diff --git a/documentation/audits/v0242-2026-09-14/17-v0242-live-9202.txt b/documentation/audits/v0242-2026-09-14/17-v0242-live-9202.txt new file mode 100644 index 00000000..eccd7ec2 --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/17-v0242-live-9202.txt @@ -0,0 +1,90 @@ +=== v0.242.0 LIVE on the scratch guest 9202 — 2026-09-13T20:52:22Z === +controller: gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 35 seconds (healthy) + +--- R-490: GET /api/system/info (the monitoring card's fetch) --- +HTTP HTTP 200 | hdd_configured=True hdd_total_gb=937.8 used_mem_mb=0 + +--- install opengist (throwaway) --- +HTTP 202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} +after: state=running updating=False phase=None err='' hold='' | front door: 302 0 + +--- backup now → the primary unit --- +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +idle after 5 s +/mnt/sys_drive/felhom-data/backups/primary/opengist: + 2026-09-13T20:52 1941 compose/.felhom.yml + 2026-09-13T20:52 292 compose/app.yaml + 2026-09-13T20:52 1260 compose/docker-compose.yml + 2026-09-13T20:52 181248 volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: ABSENT + +--- R-491: seed an UPDATE hold (settings file edit on the scratch guest + controller restart; the hold's origin is not what is under test) --- + +positive control — held: state=running updating=False phase=None err='' hold='A(z) opengist frissítése 2026-09-13 22:52-kor nem sikerült, és az alkalmazás nem indult el az új verzióval. Az alkalmazás biztonsági okból leállítva marad, hogy az adatai ne sérüljenek. Visszaállítható a Mentések oldalon ebből a biztonsági mentésből: saját meghajtó, 2026-09-13 22:52 — ez a másolat a' +settings has hold: True + +--- R-489 + R-491: remove with data, KEEP backups --- +HTTP HTTP 409 +volumes_removed=None backup_paths_removed=None hdd_paths_removed=None +log: +after removal: state=running updating=False phase=None err='' hold='A(z) opengist frissítése 2026-09-13 22:52-kor nem sikerült, és az alkalmazás nem indult el az új verzióval. Az alkalmazás biztonsági okból leállítva marad, hogy az adatai ne sérüljenek. Visszaállítható a Mentések oldalon ebből a biztonsági mentésből: saját meghajtó, 2026-09-13 22:52 — ez a másolat a' | settings still has hold: True +docker volume ls: opengist_opengist_data + +--- R-487: the removed app on the two pages and the picker API --- +/backups/apps has the row: False | Megtartva badge: False | restore form: False +row says last backup: None +GET /api/backup/snapshots → HTTP 200 {"ok":true,"data":[{"time":"2026-09-13T20:52:42Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}]} +/backups/restore picker lists it: False + +--- R-487: Visszaállítás a mentésből (POST /backup/restore, the row's button) --- +HTTP/2 302 +location: /backups/restore?flash=Vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl. + +restore-status: {"running": false, "op": "restore", "stack": "opengist", "started_at": "2026-09-13T20:53:18.897214019Z", "last": {"op": "restore", "stack": "opengist", "ok": true, "message": "A(z) opengist: 1 adatkötet visszaállítva — az alkalmazás újraindult.", "finished_at": "2026-09-13T20:53:28.201829063Z"}, "last_recent": true} +after restore: state=running updating=False phase=None err='' hold='' | front door: 302 0 +log: 2026/09/13 20:53:28 handlers.go:1542: [INFO] [web] Restore completed (async): stack=opengist in 9.304495819s (volumes 1/1, dbs 0/0) + +--- R-476: two captures, one definition → the Tier-2 date must be the DATA's --- +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +capture A manifest +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +capture B manifest (same = definition unchanged) +newest dump: -rw-r--r-- 1 root root 181248 2026-09-13T20:54Z opengist_opengist_data.tar +HTTP 200 {"ok":true,"message":"2. mentés elindítva"} +/mnt/sys_drive/felhom-data/backups/primary/opengist: + 2026-09-13T20:52 1941 compose/.felhom.yml + 2026-09-13T20:52 292 compose/app.yaml + 2026-09-13T20:52 1260 compose/docker-compose.yml + 2026-09-13T20:54 181248 volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: + 2026-09-13T20:52 1941 recovery-unit/compose/.felhom.yml + 2026-09-13T20:52 1260 recovery-unit/compose/docker-compose.yml + 2026-09-13T20:52 292 recovery-unit/compose/app.yaml + 2026-09-13T20:54 181248 recovery-unit/volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 recovery-unit/manifest.json + 2026-09-13T20:54 1 .felhom-tier2-layout +Tier-2 unit confirm sentences on the page: [] + +--- teardown: remove with data AND backups --- +HTTP HTTP 409 +volumes_removed=None backup_paths_removed=None +/mnt/sys_drive/felhom-data/backups/primary/opengist: + 2026-09-13T20:52 1941 compose/.felhom.yml + 2026-09-13T20:52 292 compose/app.yaml + 2026-09-13T20:52 1260 compose/docker-compose.yml + 2026-09-13T20:54 181248 volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: + 2026-09-13T20:52 1941 recovery-unit/compose/.felhom.yml + 2026-09-13T20:52 1260 recovery-unit/compose/docker-compose.yml + 2026-09-13T20:52 292 recovery-unit/compose/app.yaml + 2026-09-13T20:54 181248 recovery-unit/volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 recovery-unit/manifest.json + 2026-09-13T20:54 1 .felhom-tier2-layout +volumes left: opengist_opengist_data +/backups/apps still lists it: True | Megtartva anywhere: False +settings restore_holds: none +=== done 2026-09-13T20:55:01Z === +live-rc=0 diff --git a/documentation/audits/v0242-2026-09-14/18-v0242-live-9202-pass2.txt b/documentation/audits/v0242-2026-09-14/18-v0242-live-9202-pass2.txt new file mode 100644 index 00000000..447e63ad --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/18-v0242-live-9202-pass2.txt @@ -0,0 +1,75 @@ +=== v0.242.0 LIVE on 9202, second pass (the first was refused 409: a running app must be stopped before removal) — 2026-09-13T20:56:25Z === +controller: gitea.dooplex.hu/admin/felhom-controller:0.242.0 Up 3 minutes (healthy) | state=running updating=False phase=None err='' hold='' + +--- R-491: seed an UPDATE hold (settings file edit + controller restart; the hold's ORIGIN is not what is under test) --- +positive control — held: A(z) opengist frissítése 2026-09-13 22:56-kor nem sikerült, és az alkalmazás nem indult el az új verzióval. Az alkalmazá | settings has hold: True + +--- R-489 + R-491: stop, then remove with data, KEEP backups --- +stop: HTTP 200 {"ok":true,"message":"Stack opengist stop completed"} +HTTP 200 +volumes_removed=[] backup_paths_removed=None hdd_paths_removed=[] +log: 2026/09/13 20:56:57 router.go:916: [INFO] [api] remove opengist: its update hold is cleared with it (R-491) +after removal: state=not_deployed updating=False phase=None err='' hold='' | settings still has hold: False +docker volume ls: none +/mnt/sys_drive/felhom-data/backups/primary/opengist: + 2026-09-13T20:52 1941 compose/.felhom.yml + 2026-09-13T20:52 292 compose/app.yaml + 2026-09-13T20:52 1260 compose/docker-compose.yml + 2026-09-13T20:54 181248 volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: + 2026-09-13T20:52 1941 recovery-unit/compose/.felhom.yml + 2026-09-13T20:52 1260 recovery-unit/compose/docker-compose.yml + 2026-09-13T20:52 292 recovery-unit/compose/app.yaml + 2026-09-13T20:54 181248 recovery-unit/volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 recovery-unit/manifest.json + 2026-09-13T20:54 1 .felhom-tier2-layout + +--- R-487: the removed app on the two pages and the picker API --- +/backups/apps row: True | Megtartva badge: True | restore form: True +row says last backup: 2026-09-13 22:54 +GET /api/backup/snapshots → HTTP 200 {"ok":true,"data":[{"time":"2026-09-13T20:54:42Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}]} +/backups/restore picker lists it: True + +--- R-487: Visszaállítás a mentésből (the row's button = POST /backup/restore) --- +HTTP/2 302 +location: /backups/restore?flash=Vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl. + +restore-status: {"op": "restore", "stack": "opengist", "ok": true, "message": "A(z) opengist: 1 adatkötet visszaállítva — az alkalmazás újraindult.", "finished_at": "2026-09-13T20:57:13.803999331Z"} +after restore: state=running updating=False phase=None err='' hold='' | front door: 302 0 +log: 2026/09/13 20:57:13 handlers.go:1542: [INFO] [web] Restore completed (async): stack=opengist in 9.118788015s (volumes 1/1, dbs 0/0) +row is a normal deployed row again (no Megtartva): True + +--- R-476: two captures under one definition → the Tier-2 date must be the DATA's --- +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +capture A manifest "created_at": "2026-09-13T20:52:42Z" at 2026-09-13T20:57:22Z +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +capture B manifest "created_at": "2026-09-13T20:52:42Z" at 2026-09-13T20:58:34Z (same = definition unchanged) +newest dump: -rw-r--r-- 1 root root 181248 2026-09-13T20:58:28Z opengist_opengist_data.tar +HTTP 200 {"ok":true,"message":"2. mentés elindítva"} +/mnt/sys_drive/felhom-data/backups/primary/opengist: + 2026-09-13T20:52 1941 compose/.felhom.yml + 2026-09-13T20:52 292 compose/app.yaml + 2026-09-13T20:52 1260 compose/docker-compose.yml + 2026-09-13T20:58 181248 volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 manifest.json +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: + 2026-09-13T20:52 1941 recovery-unit/compose/.felhom.yml + 2026-09-13T20:52 1260 recovery-unit/compose/docker-compose.yml + 2026-09-13T20:52 292 recovery-unit/compose/app.yaml + 2026-09-13T20:58 181248 recovery-unit/volume-dumps/opengist_opengist_data.tar + 2026-09-13T20:52 1041 recovery-unit/manifest.json + 2026-09-13T20:58 1 .felhom-tier2-layout +Tier-2 unit confirm for opengist: második meghajtón lévő másolattal. Ami a másolat óta keletkezett, elveszik. A másolat kelte: 2026-09-13 22:58. A mellette lévő „Fájlok visszaállítása” ezzel szemben csak a hiányzó fájlokat pótolja, és semmit nem ír felül. Az alkalmazás a művelet idejére leáll. + +--- teardown: stop, remove with data AND backups --- +stop: HTTP 200 {"ok":true,"message":"Stack opengist stop completed"} +HTTP 200 +volumes_removed=[] backup_paths_removed=['/mnt/sys_drive/felhom-data/backups/primary/opengist (208K)', '/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist (197.4 KB)'] +/mnt/sys_drive/felhom-data/backups/primary/opengist: ABSENT +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: ABSENT +volumes left: none +/backups/apps still lists it: False | Megtartva anywhere: False +settings restore_holds: none +docker ps: felhom-controller filebrowser traefik +=== done 2026-09-13T20:58:52Z === diff --git a/documentation/audits/v0242-2026-09-14/19-R489-cause.txt b/documentation/audits/v0242-2026-09-14/19-R489-cause.txt new file mode 100644 index 00000000..4e141d6a --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/19-R489-cause.txt @@ -0,0 +1,19 @@ +=== R-489 cause on 9202 — 2026-09-13T21:01:40Z === +A) fresh compose-created volume +HTTP 202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} +labels: {"com.docker.compose.config-hash":"5f89c3baba6dff6769fa699a804f2c56a643af979b55241e2af324dfde6be51c","com.docker.compose.project":"opengist","com.docker.compose.version":"5.5.0","com.docker.compose.volume":"opengist_data"} +remove-all → HTTP 200 ["opengist_opengist_data"] +left: none +B) volume recreated by a unit restore +HTTP 202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} +HTTP 200 {"ok":true,"message":"Mentés elindítva"} +HTTP/2 302 +location: /backups/restore?flash=Vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl. + +restore: A(z) opengist: 1 adatkötet visszaállítva — az alkalmazás újraindult. +labels: null +remove-all → HTTP 200 [] +left: none +units: /mnt/sys_drive/felhom-data/backups/primary/opengist: ABSENT +/mnt/felhom-drives/scratch_hdd/backups/secondary/opengist: ABSENT +=== done 2026-09-13T21:02:40Z === diff --git a/documentation/audits/v0242-2026-09-14/rp-v242-R476-manifest-date.txt b/documentation/audits/v0242-2026-09-14/rp-v242-R476-manifest-date.txt new file mode 100644 index 00000000..f2a68499 --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/rp-v242-R476-manifest-date.txt @@ -0,0 +1,11 @@ +MUTATION in internal/backup/tier2_restore.go: + - if !c.UnitLegPreserved && c.UnitDataDate != "" && c.UnitDataDate > c.UnitPackageDate { + + if false && !c.UnitLegPreserved && c.UnitDataDate != "" && c.UnitDataDate > c.UnitPackageDate { + +=== RUN TestR476_UnitRestoreDateNamesTheDataTimeWhenTheLegWasRefreshed + r476_unit_data_date_test.go:13: refreshed leg: got "2026-09-12T02:15:29Z" preserved=false, want the dump's time +--- FAIL: TestR476_UnitRestoreDateNamesTheDataTimeWhenTheLegWasRefreshed (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-controller/internal/backup 0.005s +FAIL +exit=1 diff --git a/documentation/audits/v0242-2026-09-14/rp-v242-R487-list-inert.txt b/documentation/audits/v0242-2026-09-14/rp-v242-R487-list-inert.txt new file mode 100644 index 00000000..74bbd511 --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/rp-v242-R487-list-inert.txt @@ -0,0 +1,20 @@ +MUTATION in internal/backup/removed_units.go: + - if m.stackProvider == nil { + return nil + } + deployed + + if m.stackProvider == nil || true { + return nil + } + deployed + +=== RUN TestR487_ListRemovedAppUnits_ListsKeptUnitsOfUndeployedApps +[INFO] [settings] No settings.json found, using defaults +[INFO] [settings] Added storage path: /tmp/TestR487_ListRemovedAppUnits_ListsKeptUnitsOfUndeployedApps3160582406/004 +[INFO] [settings] Settings saved + r487_removed_units_test.go:88: want [drive-app gone-app], got [] +--- FAIL: TestR487_ListRemovedAppUnits_ListsKeptUnitsOfUndeployedApps (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-controller/internal/backup 0.007s +FAIL +exit=1 diff --git a/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-404.txt b/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-404.txt new file mode 100644 index 00000000..63d01dba --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-404.txt @@ -0,0 +1,12 @@ +MUTATION in internal/backup/restore_points.go: + - if u, found := m.RemovedAppUnitFor(stackName); found { + + if u, found := m.RemovedAppUnitFor(stackName); found && false { + +=== RUN TestR487_ListRestorePointsFindsARemovedAppsUnit +[INFO] [settings] No settings.json found, using defaults + r487_removed_units_test.go:112: want found with one point, got found=false pts=[] +--- FAIL: TestR487_ListRestorePointsFindsARemovedAppsUnit (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-controller/internal/backup 0.006s +FAIL +exit=1 diff --git a/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-not-rendered.txt b/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-not-rendered.txt new file mode 100644 index 00000000..6215aa7b --- /dev/null +++ b/documentation/audits/v0242-2026-09-14/rp-v242-R487-picker-not-rendered.txt @@ -0,0 +1,11 @@ +MUTATION in internal/web/templates/backups_restore.html: + -