night fixes 2026-10-05: R-867/R-95/R-863..R-869 closed, R-870..R-876 opened (R-876 P2: repair misses dpkg's journal); Part E crash record; Part F spike; golden 0.294.0; rulings 100-103, CC decisions 104-108; STATUS
gates / gates (push) Successful in 32s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 08:26:23 +02:00
parent 7221ee5cd6
commit 5fd2656021
55 changed files with 4856 additions and 23 deletions
+15
View File
@@ -17,3 +17,18 @@ normal running.
4. **Check:** `sysctl kernel.panic` = 10; the System page shows "armed".
The numbers live in `/etc/felhom/crash-guard.conf` (LIMIT, WINDOW_MINUTES, PANIC_SECONDS, REARM_HOURS).
## After a crash in the middle of an OS update (R-876 — until the wrapper repairs this itself)
Measured 2026-10-05 on demo-hp (`audits/night-fixes-2026-10-05/partE/`): after the crash `dpkg --audit` is clean, but
`/var/lib/dpkg/updates/` holds files, and every OS pass fails with `E: dpkg was interrupted, you must manually run
'sudo dpkg --configure -a'` (operator mail `os_update_failed`). On the box's host, as root:
```bash
pct exec 9201 -- ls /var/lib/dpkg/updates/ # non-empty = this case
pct exec 9201 -- env DEBIAN_FRONTEND=noninteractive dpkg --configure -a --force-confold # rc 0
pct exec 9201 -- dpkg --audit # empty
```
The next pass (the night's, or `--selftest=os-update -vmid 9201` as `felhom-agent`) then installs the rest. The same
applies to the host layer (run the commands on the host itself).
@@ -170,6 +170,17 @@ return. Its hub customer, Storage Box sub-account (`u629488-sub2`, which never h
removed through the hub's own customer delete; ep0 held nothing of it. The audit trail stays (events, the
deletion and reset tombstones). Record: `audits/RETIRE-peti-2026-09-25.md`.
### `Tester 2` (`Tester-2-be8404`, hub customer `Tester-2`) — **Tier 2, a volunteer household** (operator rulings 2026-10-04, 2026-10-05)
- **What it is:** a volunteer household's box. **It is a LAPTOP that is switched OFF at night** (operator,
2026-10-05) — it is not broken. Its absence every night is expected; a night of `DOWN` / stale on the hub is
the normal state, not an incident. What such a box misses is the subject of `audits/night-fixes-2026-10-05/partF/`.
- **Freely:** read its hub records.
- **Care:** only the acts the operator ruled: the signed agent update to the vouched agent, the config bundle by the
signed route (after the operator's one-time bootstrap, R-862), the live-restore reload.
- **Forbidden:** any crash, reboot or package change; any drill. **Because it is a real household's machine.**
CC has no route to it (its door admits only the operator's WireGuard peer).
### `ep0` (`felhom-hetzner`, `ep0.felhom.eu`) + the Hetzner Storage Boxes — **Tier 2, PROTECTED** (operator ruling 2026-08-03)
Reads are fine. It is the **offsite of last resort** (PBS-DR datastore, WireGuard hub, operator OOB