hub v0.104.0: the guest network gets a reader (R-319), and the hub half of the naming (R-295)
gates / gates (push) Successful in 14s

Four paper debts and one fact given a reader. Hub-only — nothing to bake.

A4 — the entry about "the tester's machine" named a risk correctly and labelled it
in a way that invited deleting it. Established from the hub's own store: `peti-felhom`
is a REAL machine (482 reports, 2026-02-27 → 2026-07-15, a named person's own box) and
the 3.6 GB with no key and no backup is real. `david` → `tester-1` is a DIFFERENT record
with no host, no escrow and no report, ever — deleted 07:55:49 and re-created 07:56:47
this morning. The prompt's premise conflated the two; the register now says which is which.

A1 — R-312/R-313/R-303 recorded as DECIDED with their re-open triggers, and moved out
of STATUS's "Waiting on you", which is now empty.

A3 — day0-install §C.1 said pushing the installer publishes it. It has not since
R-110. Corrected, with the two manifest pins named and an outside-verification command;
the one copy that repeated it (a dated audit, true when written) carries a superseded note.

A5 — standing rule 5: evidence comes off the machine at the end of the phase that
produced it, before any revert. Earned twice in three days on the same box at the same
point (R-320). Four homes, plus what to do when it is already gone.

R-295 hub half — „Beállító kód" everywhere; „Visszaállító kód" retired. New `reenroll`
mail kind so the mail names the page a REBUILT box actually shows („A szerver
beállítása"), not the „Elfelejtett jelszó" page it has no login screen to reach.
Naming only; the acceptance pin proves the secret is untouched.

R-319 — the hub models `guest_net` after 23 days of receiving and discarding it. The
signal is `heals_last_hour`, not `state`: a guest the watchdog keeps repairing reads
healthy between repairs. `heal_succeeded` decoded too (R-260's lesson). Unknown is never
drawn as healthy — three absences, three sentences. No alarm, deliberately.
Three red-proofs, mutations asserted applied. Wire-gate checked tags 182 → 190.

B1 — the operator's 2026-08-12 dispositions were NOT in the register; they are now.
Third allowlist kind for the five ruled "no reader wanted"; `reporting_disabled`
reclassified redundant. 8 read · 5 deliberately unread · 1 redundant · 6 still owed.

Also filed: R-321 (a deliberately-silent box still alarms stale/down — the checker is
age-only, and decoding the flag would not have fixed it), R-322 (the claim guard has
never scanned the hub; a hand scan returns zero, so it is a scope gap, not a defect).
This commit is contained in:
2026-08-13 10:50:12 +02:00
parent 2d05b29b82
commit 4d6ec7c7bb
22 changed files with 1253 additions and 115 deletions
+51 -73
View File
@@ -1,6 +1,6 @@
# STATUS — what works, what's broken, what's next
**Updated 2026-08-12 (night — the door, part one).**
**Updated 2026-08-13 (evening — the small debts, and one fact given a reader).**
> **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority; this page restates
> part of it in plain words, and **nothing may exist only here**. **Items, not paragraphs. One screen.**
@@ -8,44 +8,25 @@
## Waiting on you
*Three decisions. Each says what it would cost to leave alone, because two of them quietly choose an
outcome if you do not answer. The register row is the detail, not the decision.*
*Nothing. All three questions that stood here were answered on 1213 August and have moved to
**Decided** below. A decided question left in the deciding list is how a person loses track of what is
actually waiting.*
### Should a customer be able to get their old backups back themselves, or is that a phone call?
## Decided — and what would reopen each
Since Tuesday a machine recognises an older recovery code and says so honestly, but it cannot hand the
files over — it tells the person to write to us, and we can do it by hand.
*A decision with no trigger becomes a permanent silence, so each one names what would make us look
again.*
- **Build it:** the restore code has to accept a second location and password instead of only its own.
Contained — three functions and a screen — plus one genuine design question: what a customer sees
when they have several old sets and must pick one.
- **Leave it:** nothing breaks. Every customer in this position becomes a support conversation, and we
keep a promise we can only keep manually.
**If you do nothing:** the honest message stays and the work never gets scheduled. Nobody is blocked;
this is the one decision here with no deadline of any kind. *(register: R-312)*
### The old copy on the demo machine cannot be opened by anyone. Keep paying to store it, or delete it?
You told me to keep it, and I did. Then I found out what it is: 36 backups and a single key, and that
key was destroyed by the bug we fixed on 4 August. **No recovery code in existence opens it.**
- **Keep it:** pennies of storage, and it stays as the one physical example of what that bug cost.
- **Delete it:** irreversible, and the example goes with it.
**If you do nothing:** it stays forever and stops being a decision — which is how five scratch
customers accumulated. Nobody is blocked. *(register: R-313)*
### When a machine is in two kinds of trouble at once, should it say both things?
A machine can count down to deleting its old backups while also reporting that it cannot open its new
ones. Both cards are true; together they are bewildering.
- **Leave it:** two true statements, confusing side by side. Nobody has been hurt by it.
- **Hide the older card during a countdown:** tidier, and it risks hiding a real second failure — which
is why I have not done it.
**If you do nothing:** both keep showing. Ranked low on purpose. *(register: R-303)*
- **Getting old backups back yourself: NOT BUILT, deliberately.** A customer in that position is a
support conversation, and we can do it by hand. **Reopens if:** a real customer actually asks —
one request from a person who is not us. *(register: R-312)*
- **The unopenable old copy on `demo-felhom`: KEPT, as a test fixture.** Not for sentiment: it is the
only state in existence where a set-aside store is present and cannot be opened, which is the case
any future handling of lost backups has to face honestly. **Delete it when:** that work ships, or is
abandoned. Until then it is a fixture, not an accumulation. *(register: R-313)*
- **A machine in two kinds of trouble says both things: LEFT AS IT IS.** Its real-world likelihood is
unknown, and hiding one card risks hiding a real second failure. **Reopens if:** it is observed
happening outside a constructed test. *(register: R-303)*
## What works
@@ -53,53 +34,50 @@ Both demo machines are home, healthy and reporting on the approved pair — **co
0.129.0**, delivered by the floor rather than by hand. Off-site is credentialed on `demo-hp` and its
repository still opens with the machine's own key. `drill-r50` is reverted to `virgin`, powered off.
**What the fleet actually is, because two summaries have now been misread:** the hub holds **five
customer records and three machines**. The machines are `demo-felhom` and `demo-hp` (both ours, both
disposable) and `drill-r50` (a nested drill VM on DooPlex, reverted and powered off). **`peti-felhom`
is a real machine we have not heard from since 15 July** and has no host record. **`tester-1` is a
record with no machine** — created 13 August, no host, no backups, nothing to lose.
## Shipped
- **The drive can be re-attached after a reinstall** (R-280). The restore page said *"this is two
clicks"* over an empty list; it was zero clicks and needed an internal path no customer could produce.
- **The orphan card stops promising** that set-aside off-site copies can be reopened — twice over
(R-294, then **R-299**, which was the same claim in the plural, in the *always-visible* half, missed
because the guard matched one inflection of a Hungarian verb).
- **The countdown banner stops promising retrieval it cannot see is still true** (R-302). The promise
is now conditional on the hub still holding the package it held when the customer decided — pinned
then, compared now. A sweep found the same claim in five places; a fourth was fixed with it and a
fifth deliberately left, because it is true where it renders.
- **One name per secret, box side** (R-295): the dashboard code is „Beállító kód" everywhere;
„Visszaállító kód" is retired. It collided with the escrow „Helyreállítási kód" and cost a real code.
- **The removal now genuinely reverses the installation** (R-316, `installer-v1.28.0` published). The
second reinstall used to hit our own leftover; it was watched failing on the cycle that actually
fails, then watched passing.
- **A correct recovery code is no longer called wrong** (R-311, three components). If a customer types
the code for an older set of backups, the machine now checks the packages we kept, recognises it, and
says so: *your code is correct, it belongs to an earlier package, we kept it, your current backups are
fine, write to us*. It deliberately promises no restore, because there is no button yet.
- **The countdown on `demo-felhom` is cancelled** on your ruling (R-307). Nothing was deleted; the
24 August deadline is gone. See R-313 for what that copy turns out to be.
- **Vouched and delivered 2026-08-12**: golden 0.214.0, agent 0.129.0, floor 0.214.0 — both machines
took it themselves. The version guard was watched working on the way: `demo-hp` was **held** back
while its agent was older, and updated 6 seconds after the agent caught up. That guard exists because
a machine once ran ahead of its agent and a customer was told a correct code was wrong; first sighting.
- **Both installer fixes are now PUBLISHED** as `installer-v1.27.0` (R-297 + R-300). Each fault was
watched happening first, on a machine reset to factory state: the old installer really did build a
machine on a base image from July, and our own uninstall really did block our own next install.
- **The drive can be re-attached after a reinstall** (R-280), and **the orphan card and the countdown
banner stop promising retrieval they cannot see is still true** (R-294, R-299, R-302).
- **One name per secret — now both halves** (R-295). The dashboard code is „Beállító kód" everywhere,
on the machine *and* in the hub's emails; „Visszaállító kód" is retired. It collided with the escrow
„Helyreállítási kód" and cost a real code.
- **The hub can see whether a machine's guest still has working networking** (R-319, first reader built
against R-264). A machine quietly repairing its own network over and over is now visible instead of
being a green tick; a machine that does not report it is drawn as unknown, never as healthy.
- **The countdown on `demo-felhom` is cancelled** on your ruling (R-307). Nothing was deleted.
## Broken, or knowingly incomplete
- **The tester's machine has no recovery route at all** — see the `PETI` row. Its host record was
deleted on 15 July; there is no key, no off-site copy and no local backup. **If that drive fails,
everything on it is lost.** First act of the visit: copy the ~3.6 GB off before anything is
reinstalled — it is currently the only copy in existence. Whether it stays parked is your call and is
deliberately left open.
- **Kept backups can be opened — but still only by us** (R-304 partly closed, R-312 open). The machine
now recognises an older code and says so plainly instead of hedging. What it still cannot do is hand
the customer their old files: that needs the restore code to accept a second location, which is real
work rather than wiring. Today the honest answer is "your code is right, write to us" — and we can.
- **The dnsmasq fix helps a machine once** (R-305). On a machine that never had Felhom it works. On the
second reinstall the leftover comes back, because the package is never removed — so the machine looks,
to our own installer, as if the household had installed it. Watched happening the same afternoon.
- **The hub half of the naming is undone** (R-295 PARTIAL): the emails still use the retired name and
send people to a page a rebuilt machine does not show.
- **Peti's machine has no recovery route at all** — see the `PETI` row. **This is a real machine
belonging to a real person**, not one of ours and not a record: it reported to the hub for four and a
half months and has been silent since 15 July, when its host record was deleted. There is no key, no
off-site copy and no local backup. **If that drive fails, everything on it is lost.** First act of the
visit: copy the ~3.6 GB off before anything is reinstalled — it is currently the only copy in
existence. Whether it stays parked is your call and is deliberately left open.
- **Kept backups can be opened — but still only by us** (R-304 partly closed, R-312 decided-not-built).
Today the honest answer is "your code is right, write to us" — and we can.
- **The agent picks dnsmasq by looking at a file another package owns** (R-317). The box installs fine;
only LAN name resolution goes missing, and quietly. One line, deliberately not taken tonight.
- **The storage page has its own separate reason for showing an empty list** (R-298), untouched.
- **Three more facts the machines send still have no reader** (R-264): a staged-but-unapplied agent
update, how deep a restore test actually went, and the two backup-integrity timestamps. Five others
are now recorded as deliberately unread, which is honest rather than fixed.
## Working on next
R-312's shape (the button, or deliberately no button); then R-305, because the tester's second
reinstall still hits the dnsmasq wall; then the hub naming; then the 2026-08-09 batch
(R-279 … R-292), still untriaged against everything since.
The three remaining R-264 readers, now that one has been built and we know what one costs; then R-317
(one line in the agent); then the 2026-08-09 batch (R-279 … R-292), still untriaged against everything
since.