diff --git a/documentation/audits/night-burndown-2026-10-05/hub-docker-firstseen-red-proof.txt b/documentation/audits/night-burndown-2026-10-05/hub-docker-firstseen-red-proof.txt new file mode 100644 index 00000000..e2709a16 --- /dev/null +++ b/documentation/audits/night-burndown-2026-10-05/hub-docker-firstseen-red-proof.txt @@ -0,0 +1,7 @@ +[INFO] [store] app-update event types added to 0 household(s)' notification prefs (one-time, add-only): [] +[INFO] [store] app_stopped_unhealthy added to 0 household(s)' notification prefs (one-time, add-only): [] +--- FAIL: TestEvaluate_StampsDockerFirstSeenWithoutAPageView (0.05s) + docker_firstseen_test.go:33: two healthy nights after the set was first seen on the tick, yet: "hp has 0 of 2 healthy night Docker step(s) with this set" (first seen 2026-10-06 13:01:00 +0000 UTC) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/osupdates 0.052s +FAIL diff --git a/hub/CHANGELOG.md b/hub/CHANGELOG.md index 41d9e4c2..194cc1cf 100644 --- a/hub/CHANGELOG.md +++ b/hub/CHANGELOG.md @@ -25,6 +25,10 @@ first:** `felhom-hub -unseal-box-secrets` in the running pod (see R-879 below an hashes. Empty hash (older agent) = unknown, never drift. - **R-276 (hub half):** deleting a host asks the WireGuard peer sync for an immediate full-list push (as the customer delete does since R-600), so the off-site endpoint drops the removed box's peer at once instead of on the next tick. +- **Fixed without a row:** the Docker engine set's „first seen" is stamped by the evaluate tick like the other layers + — it was stamped only when someone opened the System page, so healthy nights before that view did not count (found + through a flaky `TestSystemPage_DockerButtonOnlyWhenReady`, which now runs on a fixed clock). Test + `TestEvaluate_StampsDockerFirstSeenWithoutAPageView`; red-proved (without the call: „0 of 2 healthy night"). - **scripts:** `wire_contract_gate.py` checks the mirrored escrow roots field by field and prints each root's check (R-315); `hub_copy_gate.py` accepts the controller gate importing the shared vocabulary (R-325, felhom.eu half); `reuse_refs_check.py` checks `.md` citations (R-422); the instructions gate's decoy is in the suite, exemptions 20 → 16 diff --git a/hub/internal/osupdates/docker_firstseen_test.go b/hub/internal/osupdates/docker_firstseen_test.go new file mode 100644 index 00000000..db59409d --- /dev/null +++ b/hub/internal/osupdates/docker_firstseen_test.go @@ -0,0 +1,38 @@ +package osupdates + +import ( + "testing" + "time" +) + +// The Docker set's "first seen" is stamped by the evaluate tick, not by a page view: two healthy night Docker steps that +// happen while nobody opens the System page count. Before 2026-10-05 the stamp was taken only by DockerStatus on the +// page, so nights before the first view were lost (and the page test flaked on a second boundary). +// Red-proof: drop the DockerStatus call from Evaluate — the final status still waits ("0 of 2" / "1 of 2"). +func TestEvaluate_StampsDockerFirstSeenWithoutAPageView(t *testing.T) { + f := newFix(t) + f.s.DockerNights = 2 + set := []Package{{Name: "docker-ce", Version: "5:29.8.2-1", Origin: "Docker"}} + f.reportL(t, "hp", LayerDocker, "debug", true, set...) + f.reportL(t, "n100", LayerDocker, "debug", true, set...) + f.now = f.now.Add(time.Minute) + if _, err := f.s.Evaluate(); err != nil { // the tick: no page view anywhere in this test + t.Fatal(err) + } + for i := 0; i < 2; i++ { + f.now = f.now.Add(24 * time.Hour) + f.reportL(t, "hp", LayerDocker, "night", true, set...) + f.reportL(t, "n100", LayerDocker, "night", true, set...) + } + f.now = f.now.Add(time.Hour) + st, err := f.s.DockerStatus() // the operator opens the page for the first time only now + if err != nil { + t.Fatal(err) + } + if st.Waiting != "" { + t.Fatalf("two healthy nights after the set was first seen on the tick, yet: %q (first seen %s)", st.Waiting, st.FirstSeen) + } + if st.FirstSeen.IsZero() { + t.Fatalf("no first-seen stamp: %+v", st) + } +} diff --git a/hub/internal/osupdates/service.go b/hub/internal/osupdates/service.go index a5c21b45..a28cc2c1 100644 --- a/hub/internal/osupdates/service.go +++ b/hub/internal/osupdates/service.go @@ -392,6 +392,13 @@ func (s *Service) Evaluate() ([]Status, error) { } out = append(out, st) } + // The Docker set approves only by the operator's button, but its "first seen" must still be stamped on the tick + // like the other layers: otherwise it was stamped only when someone opened the System page, and the healthy + // nights before that view did not count (found 2026-10-05, a flaky TestSystemPage_DockerButtonOnlyWhenReady). + // Pinned by TestEvaluate_StampsDockerFirstSeenWithoutAPageView. + if _, err := s.DockerStatus(); err != nil { + return out, err + } return out, nil } diff --git a/hub/internal/web/system_test.go b/hub/internal/web/system_test.go index a1b8016f..53d95a1b 100644 --- a/hub/internal/web/system_test.go +++ b/hub/internal/web/system_test.go @@ -76,6 +76,10 @@ func TestSystemPage_DockerButtonOnlyWhenReady(t *testing.T) { t.Fatal("button shown with no Docker candidate") } _ = st.SetOSRing("full-1", 0) + // A fixed clock: on the real one the page's first-seen stamp could fall one second after the first night's report + // and drop it (the flake seen 2026-10-05 under full-suite load). + clock := time.Date(2026, 10, 5, 3, 0, 0, 0, time.UTC) + svc.Now = func() time.Time { return clock } night := func() { if err := svc.Ingest("full-1", osupdates.Report{RunID: time.Now().String(), Layer: "docker", Trigger: "night", Mode: "apply", Outcome: "nothing", Healthy: true, Installed: []osupdates.Package{{Name: "docker-ce", Version: "5:29.8.2-1", Origin: "Docker"}}}); err != nil {