drill report: customer-claim arc resolution + post-claim-arc snapshot + follow-up observations

Claude-Session: https://claude.ai/code/session_01NptTCFtu7dz2Ru89qHRagN
This commit is contained in:
2026-07-12 19:20:39 +02:00
parent 8ded485a58
commit 6040c7b93d
@@ -167,6 +167,20 @@ non-HU geo-block verification (needs a non-HU vantage).
| `pre-day0-clean` | 15:12 | PVE 9.2.2 + keys, nothing Felhom — the universal re-drill zero |
| `post-install` | 15:35 | Day-0 SUCCESS + ActualBudget + guests-dir chown |
| `post-drill` | 17:11 | full drill end state (WG + PBS-DR + escrowed + geo HU + dashboard OPEN per F-4) |
| `post-claim-arc` | 19:08 | customer-claim arc: ctrl 0.122.0, demo-vm-felhom CLAIMED (customer-set password), gate proven |
## 10. F-4/F-5 resolution — customer-claim arc (2026-07-12, same day)
Shipped **hub v0.50.0 + controller v0.122.0** (both LIVE): the dashboard password is customer-owned,
set via a one-time claim code the hub emails to the registered address. An unclaimed box serves only
the claim page — F-4's open-dashboard exposure and F-5's unauthenticated geo toggle are both closed.
Live-proven on this drill box (gate ON via the real edge; Viktor claimed it, code generation consumed,
box now password-gated) and on the live demo after the floor raise (0.121→0.122 → claim-gated). Two
follow-up observations for the backlog: (a) the hub issues a claim code to EVERY reporting customer on
first report (peti + demo also emailed) — benign for pre-0.122 boxes (no gate, ACK ignored), but a
real customer on an old controller gets an unusable "beállító kód" email; consider gating issuance on
reported controller version ≥ 0.122. (b) the drill's reset flow (Scenario C) was deferred by the
operator — worth one supervised pass before Peti onboarding.
Blast radius honored: guest demo 9201 on felhom-pve, Peti's hub entry, and the demo offbox were
never touched. Drill leftovers to tidy at teardown (deliberately kept for re-drills now): hub