diff --git a/documentation/audits/evidence-chaos-night-2026-09-17/ep0-snapshots-verified-present.txt b/documentation/audits/evidence-chaos-night-2026-09-17/ep0-snapshots-verified-present.txt index 923c48ff..5cb349df 100644 --- a/documentation/audits/evidence-chaos-night-2026-09-17/ep0-snapshots-verified-present.txt +++ b/documentation/audits/evidence-chaos-night-2026-09-17/ep0-snapshots-verified-present.txt @@ -39,3 +39,14 @@ repository on the Storage Box, which is orphaned and holds zero readable snapsho had a working off-site path for the WHOLE GUEST and a broken one for PER-APP restores, at the same time. Any sentence that says "off-site backup works" or "off-site backup is broken" without naming which of the two is meant would be wrong in one direction or the other. + +## MY MANIFEST PROBE WAS WORTHLESS, AND ITS SILENCE MUST NOT BE READ AS AN ANSWER +I tried to read a verify state out of index.json.blob and the client log with grep and strings. +Both returned NOTHING - and so did my negative control. That is the whole problem: with a +compressed blob, "no match" and "unreadable" look identical, and I had no POSITIVE control that +would have to appear if the probe worked at all. A probe that cannot fail visibly is not a +measurement, which is the same lesson as the empty-needle grep, the wrong-directory listing and the +invented hostname earlier tonight. +So the verify state of these snapshots is UNKNOWN, not absent. The only claim that stands is the one +already written above: the copies are PRESENT and well-formed, and their restorability was not +tested this session. diff --git a/documentation/audits/evidence-chaos-night-2026-09-17/phase2-offsite-restore-blocked.txt b/documentation/audits/evidence-chaos-night-2026-09-17/phase2-offsite-restore-blocked.txt index 2e600a53..30637628 100644 --- a/documentation/audits/evidence-chaos-night-2026-09-17/phase2-offsite-restore-blocked.txt +++ b/documentation/audits/evidence-chaos-night-2026-09-17/phase2-offsite-restore-blocked.txt @@ -40,3 +40,20 @@ The zero was the exit status of `head` at the end of my pipeline, not restic's. printed directly beneath a fatal error. restic 0.14.0 has `sftp.command`, not `sftp.args` - confirmed by asking `restic options` rather than assuming. The re-run writes restic's output to a file and reads `$?` immediately, so the status belongs to the command it is printed next to. + +## A DEFECT I ALMOST FILED, AND DID NOT - because the page does warn, in a card my probe could not see +I suspected the household was never told the repository was orphaned: `/backups/remote` is 60 KB of +HTML and the word "elarvult" appears ZERO times in it. My search was sound - negative control +"zzzznope" = 0, and two positive controls proved it finds Hungarian text ("ment" 121, "voli" 29). +It was still the wrong measurement. The page's own JavaScript does this: + fetch('/backup/offbox/status',{headers:{'Accept':'application/json'}}) +and the page carries the elements it fills in: + id="offbox-orphan-card" id="orphan-reveal" id="orphan-confirm" + id="offbox-status-value" id="i-triangle-alert" +with the word "orphan" appearing 4 times in the script. There is a dedicated ORPHAN CARD, revealed +from the very status object that says orphaned:true. It is absent from the static HTML because it is +rendered client-side - the exact case this repo's own rule warns about, and the reason there is a +standing note that endpoint-level checking cannot prove what a browser renders. +NOTHING IS FILED. The household IS told. This is the second time tonight I nearly filed a defect +that was a property of my instrument; the difference from R-550 is that this one was caught BEFORE +the row existed, by asking what the page's script does instead of trusting a grep over its HTML. diff --git a/documentation/audits/evidence-chaos-night-2026-09-17/phase2-readiness.txt b/documentation/audits/evidence-chaos-night-2026-09-17/phase2-readiness.txt index 5ddf28d4..0829aa23 100644 --- a/documentation/audits/evidence-chaos-night-2026-09-17/phase2-readiness.txt +++ b/documentation/audits/evidence-chaos-night-2026-09-17/phase2-readiness.txt @@ -27,3 +27,15 @@ the output before the real lines were ever reached. It returned an empty marker like "9202 has no containers". The fix was LC_ALL=C on the remote plus filtering the warning lines, and not truncating before the marker. Same class as every other instrument fault tonight: a probe that can drop its own result silently is not a measurement. + +## THE CATALOG BUMP: VERIFIED REVERTED, not asserted (2026-09-17T00:29Z) +The brief allowed one drill bump of one small app, reverted the same night. + working tree clean (git status --porcelain empty) + local vs origin/main 94bc5fe == 94bc5fe, 0 ahead / 0 behind + nextcloud template image: redis:7-alpine <- the ORIGINAL pin, bump gone + .felhom.yml catalog_since: "2026-07-18" <- the ORIGINAL date, bump gone + newest commit 94bc5fe, 2026-09-15 - nothing from tonight exists in this repo +The bump was prepared, refused by the catalog's own gates (image-resolvable INCONCLUSIVE and +volume-persistence INCONCLUSIVE - its own canary failed, so the verdict was UNDETERMINED, never a +pass), and reverted with `git checkout --` before any push. So there is nothing to revert now, and +that is checked rather than remembered.