From 7942fb67132a4a317ea92db9bfd1d37b01cbdb96 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 7 Oct 2026 10:22:59 +0200 Subject: [PATCH] day 2026-10-07: red-proofs for Parts B, C, D1, E, F Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .../audits/day-2026-10-07/B/red-agent-go.txt | 35 +++ .../day-2026-10-07/B/red-hub-pve-before.txt | 5 + .../B/red-hub-pve-mutations.txt | 19 ++ .../B/red-wrapper-pve-before.txt | 204 ++++++++++++++++++ .../B/red-wrapper-pve-mutations.txt | 10 + .../audits/day-2026-10-07/C/C-red-before.txt | 25 +++ .../audits/day-2026-10-07/C/C-red-go-tee.txt | 7 + .../audits/day-2026-10-07/D/red1-no-purge.txt | 13 ++ .../day-2026-10-07/D/red2-error-ignored.txt | 11 + .../day-2026-10-07/D/red3-no-filter.txt | 11 + .../day-2026-10-07/E/red-agent-ledger.txt | 10 + .../audits/day-2026-10-07/E/red-hub-event.txt | 14 ++ .../audits/day-2026-10-07/F/red-r105.txt | 13 ++ 13 files changed, 377 insertions(+) create mode 100644 documentation/audits/day-2026-10-07/B/red-agent-go.txt create mode 100644 documentation/audits/day-2026-10-07/B/red-hub-pve-before.txt create mode 100644 documentation/audits/day-2026-10-07/B/red-hub-pve-mutations.txt create mode 100644 documentation/audits/day-2026-10-07/B/red-wrapper-pve-before.txt create mode 100644 documentation/audits/day-2026-10-07/B/red-wrapper-pve-mutations.txt create mode 100644 documentation/audits/day-2026-10-07/C/C-red-before.txt create mode 100644 documentation/audits/day-2026-10-07/C/C-red-go-tee.txt create mode 100644 documentation/audits/day-2026-10-07/D/red1-no-purge.txt create mode 100644 documentation/audits/day-2026-10-07/D/red2-error-ignored.txt create mode 100644 documentation/audits/day-2026-10-07/D/red3-no-filter.txt create mode 100644 documentation/audits/day-2026-10-07/E/red-agent-ledger.txt create mode 100644 documentation/audits/day-2026-10-07/E/red-hub-event.txt create mode 100644 documentation/audits/day-2026-10-07/F/red-r105.txt diff --git a/documentation/audits/day-2026-10-07/B/red-agent-go.txt b/documentation/audits/day-2026-10-07/B/red-agent-go.txt new file mode 100644 index 00000000..e82d9dcd --- /dev/null +++ b/documentation/audits/day-2026-10-07/B/red-agent-go.txt @@ -0,0 +1,35 @@ +## RED G1: pvegate.Write ignores the step +--- FAIL: TestWrite_WaitsWhileAStepRuns (0.00s) + pvegate_test.go:29: the write went through while the Proxmox step held the gate +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/pvegate 0.003s + +## RED G2: doBody without the gate +--- FAIL: TestPVEGate_ClientWriteWaitsGetDoesNot (0.00s) + pvegate_test.go:34: a PUT reached the API while the Proxmox step held the gate +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/proxmox 0.006s + +## RED G3: RunStdin without the gate +--- FAIL: TestPVEGate_ExecRunnerPctSetWaits (0.00s) + pvegate_test.go:62: pct set ran while the Proxmox step held the gate (err=fork/exec /nonexistent/pct: no such file or directory after 472.608µs) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/proxmox 0.006s + +## RED L1: the night leg runs the pve layer without the gate (runLayer instead of runPVE) +--- FAIL: TestPVE_Ring0PlanGateAndReport (0.00s) + pve_test.go:43: the /etc/pve write gate was not held while the pve step ran +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.010s + +## RED L2: PVEHealthVerdict without the container-id loop +--- FAIL: TestPVEHealthVerdict (0.00s) + pve_test.go:115: an app restarted by the Proxmox step must fail, got ok=true "" +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.011s + +## RED L3: ring 1 allowed in the night leg +--- FAIL: TestPVE_Ring1NightLegNeverSteps (0.00s) + pve_test.go:65: ring 1 took a pve step: guest:inventory,host:inventory,pve:apply +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.010s diff --git a/documentation/audits/day-2026-10-07/B/red-hub-pve-before.txt b/documentation/audits/day-2026-10-07/B/red-hub-pve-before.txt new file mode 100644 index 00000000..06451535 --- /dev/null +++ b/documentation/audits/day-2026-10-07/B/red-hub-pve-before.txt @@ -0,0 +1,5 @@ +# gitea.dooplex.hu/admin/felhom-hub/internal/osupdates [gitea.dooplex.hu/admin/felhom-hub/internal/osupdates.test] +internal/osupdates/pve_test.go:22:34: undefined: LayerPVE +internal/osupdates/pve_test.go:35:41: undefined: LayerPVE +internal/osupdates/pve_test.go:48:19: f.s.ApprovePVE undefined (type *Service has no field or method ApprovePVE) +internal/osupdates/pve_test.go:54:17: f.s.ApprovePVE undefined (type *Service has no field or method ApprovePVE) diff --git a/documentation/audits/day-2026-10-07/B/red-hub-pve-mutations.txt b/documentation/audits/day-2026-10-07/B/red-hub-pve-mutations.txt new file mode 100644 index 00000000..3a350009 --- /dev/null +++ b/documentation/audits/day-2026-10-07/B/red-hub-pve-mutations.txt @@ -0,0 +1,19 @@ +## RED H1: LayerPVE added to the auto-approved Layers +--- FAIL: TestPVE_NeverAutoApproved (0.04s) + pve_test.go:36: a Proxmox set was auto-approved: &{ID:os-pve-20261006-140000 Layer:pve Fingerprint:22251aeab002291b ApprovedAt:2026-10-06 14:00:00 +0000 UTC ApprovedBy:auto PackagesJSON:[{"name":"pve-manager","version":"9.2.21","origin":"Proxmox"},{"name":"qemu-server","version":"9.0.9","origin":"Proxmox"}] Test:false CancelledAt: CancelReason:} +FAIL + +## RED H2: the pve candidate keeps kernel names +--- FAIL: TestPVE_ApproveNeedsTwoHealthyNightsOnEveryRing0Box (0.04s) + pve_test.go:61: release &{ID:os-pve-20261005-120000 Layer:pve Fingerprint:f3d69aa6894cd1d9 ApprovedAt:2026-10-05 12:00:00 +0000 UTC ApprovedBy:operator PackagesJSON:[{"name":"proxmox-kernel-helper","version":"9.0.6","origin":"Proxmox"},{"name":"pve-manager","version":"9.2.21","origin":"Proxmox"},{"name":"qemu-server","version":"9.0.9","origin":"Proxmox"}] Test:false CancelledAt: CancelReason:} +FAIL + +## RED H3: the pve button without the Waiting condition +--- FAIL: TestSystemPage_PVEButtonOnlyWhenReady (0.06s) + system_test.go:209: button shown after ONE night +FAIL + +## RED H4: a pve approval bumps ring-1 boxes +--- FAIL: TestPVE_ApproveNeedsTwoHealthyNightsOnEveryRing0Box (0.04s) + pve_test.go:64: a Proxmox approval must nudge no box (ring 1 takes it by a signed job): [cust1] +FAIL diff --git a/documentation/audits/day-2026-10-07/B/red-wrapper-pve-before.txt b/documentation/audits/day-2026-10-07/B/red-wrapper-pve-before.txt new file mode 100644 index 00000000..ade5dc71 --- /dev/null +++ b/documentation/audits/day-2026-10-07/B/red-wrapper-pve-before.txt @@ -0,0 +1,204 @@ +F.FFFFFFFFF.F.FFF +====================================================================== +FAIL: test_allow_listed_new_package_is_accepted (configs.test_felhom_os_apply.PVELane.test_allow_listed_new_package_is_accepted) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1437, in test_allow_listed_new_package_is_accepted + self.assertEqual(rc, 0, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^ +AssertionError: 2 != 0 : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_debian_origin_in_the_pve_simulation_is_refused (configs.test_felhom_os_apply.PVELane.test_debian_origin_in_the_pve_simulation_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1405, in test_debian_origin_in_the_pve_simulation_is_refused + self.refused(f, "R2") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R2' +- R12 +? - ++ R2 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_debian_package_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_debian_package_in_a_pve_plan_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1400, in test_debian_package_in_a_pve_plan_is_refused + self.refused(f, "R2") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R2' +- R12 +? - ++ R2 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_docker_package_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_docker_package_in_a_pve_plan_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1410, in test_docker_package_in_a_pve_plan_is_refused + self.refused(f, "R2") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R2' +- R12 +? - ++ R2 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_docker_signed_op_does_not_authorize_a_pve_step (configs.test_felhom_os_apply.PVELane.test_docker_signed_op_does_not_authorize_a_pve_step) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1421, in test_docker_signed_op_does_not_authorize_a_pve_step + self.refused(pve_fake(signed=signed_job(packages=PVE_SET, op="os_docker_step")), "R3") + ~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R3' +- R12 ++ R3 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_kernel_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_kernel_in_a_pve_plan_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1378, in test_kernel_in_a_pve_plan_is_refused + self.refused(f, "R14") + ~~~~~~~~~~~~^^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R14' +- R12 +? ^ ++ R14 +? ^ + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_kernel_pulled_in_by_the_simulation_is_refused (configs.test_felhom_os_apply.PVELane.test_kernel_pulled_in_by_the_simulation_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1389, in test_kernel_pulled_in_by_the_simulation_is_refused + self.refused(f, "R6") # not in the plan — refused before the name check; R14 below when it IS in the plan + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R6' +- R12 ++ R6 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_no_authority_is_refused (configs.test_felhom_os_apply.PVELane.test_no_authority_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1418, in test_no_authority_is_refused + self.refused(pve_fake(), "R3") + ~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R3' +- R12 ++ R3 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_pve_in_the_fast_lane_is_refused (configs.test_felhom_os_apply.PVELane.test_pve_in_the_fast_lane_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1415, in test_pve_in_the_fast_lane_is_refused + self.refused(f, "R3") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R3' +- R12 ++ R3 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_pve_manager_plan_is_installed_on_the_host (configs.test_felhom_os_apply.PVELane.test_pve_manager_plan_is_installed_on_the_host) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1365, in test_pve_manager_plan_is_installed_on_the_host + self.assertEqual(rc, 0, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^ +AssertionError: 2 != 0 : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_ring0_pending_pve_takes_only_installed_proxmox_userspace (configs.test_felhom_os_apply.PVELane.test_ring0_pending_pve_takes_only_installed_proxmox_userspace) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1466, in test_ring0_pending_pve_takes_only_installed_proxmox_userspace + self.assertEqual(rc, 0, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^ +AssertionError: 2 != 0 : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_shim_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_shim_in_a_pve_plan_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1383, in test_shim_in_a_pve_plan_is_refused + self.refused(f, "R14") + ~~~~~~~~~~~~^^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R14' +- R12 +? ^ ++ R14 +? ^ + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_undo_is_refused (configs.test_felhom_os_apply.PVELane.test_undo_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1450, in test_undo_is_refused + self.refused(f, "R5") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R5' +- R12 ++ R5 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +====================================================================== +FAIL: test_unlisted_new_package_is_refused (configs.test_felhom_os_apply.PVELane.test_unlisted_new_package_is_refused) +---------------------------------------------------------------------- +Traceback (most recent call last): + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1431, in test_unlisted_new_package_is_refused + self.refused(f, "R6") + ~~~~~~~~~~~~^^^^^^^^^ + File "/mnt/5_hdd/felhom.eu/wt/pb/felhom-agent/configs/test_felhom_os_apply.py", line 1357, in refused + self.assertEqual(rep["refused"]["code"], code, rep) + ~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'R12' != 'R6' +- R12 ++ R6 + : {'mode': None, 'pass_seconds': 0.0, 'refused': {'code': 'R12', 'reason': "layer 'pve' is not guest, host or docker"}} + +---------------------------------------------------------------------- +Ran 17 tests in 0.023s + +FAILED (failures=14) diff --git a/documentation/audits/day-2026-10-07/B/red-wrapper-pve-mutations.txt b/documentation/audits/day-2026-10-07/B/red-wrapper-pve-mutations.txt new file mode 100644 index 00000000..9483d6ad --- /dev/null +++ b/documentation/audits/day-2026-10-07/B/red-wrapper-pve-mutations.txt @@ -0,0 +1,10 @@ +## RED W1: the pve branch's R14 name check removed (plan names a kernel / shim) +FAIL: test_kernel_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_kernel_in_a_pve_plan_is_refused) +FAIL: test_shim_in_a_pve_plan_is_refused (configs.test_felhom_os_apply.PVELane.test_shim_in_a_pve_plan_is_refused) +Ran 17 tests in 0.085s +FAILED (failures=2) + +## RED W2: origin_ok accepts any origin on the pve layer +FAIL: test_debian_origin_in_the_pve_simulation_is_refused (configs.test_felhom_os_apply.PVELane.test_debian_origin_in_the_pve_simulation_is_refused) +Ran 17 tests in 0.071s +FAILED (failures=1) diff --git a/documentation/audits/day-2026-10-07/C/C-red-before.txt b/documentation/audits/day-2026-10-07/C/C-red-before.txt new file mode 100644 index 00000000..b638d419 --- /dev/null +++ b/documentation/audits/day-2026-10-07/C/C-red-before.txt @@ -0,0 +1,25 @@ +## RED (before the fix): python3 configs/test_felhom_priv_apply.py ControllerImage + self.assertIn("controller-image", buf.getvalue()) + ~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ +AssertionError: 'controller-image' not found in 'felhom-priv-apply ok verbs=unit,dnsmasq,wg,sshd-config,sshd-key\n' + +---------------------------------------------------------------------- +Ran 5 tests in 0.002s + +FAILED (failures=4) +## RED: go test ./internal/capability -run 'R861|ControllerImageVerb|FelhomOp' +=== RUN TestSudoersRefusesTheR861Injections + r861_injection_test.go:66: the sudoers still allows: /usr/sbin/pct exec 9201 -- tee /etc/felhom-controller-image +--- FAIL: TestSudoersRefusesTheR861Injections (0.09s) +=== RUN TestSudoersAllowsTheControllerImageVerb + r861_injection_test.go:108: the sudoers does not allow `felhom-priv-apply controller-image 9201` — a managed controller update cannot write its image +--- FAIL: TestSudoersAllowsTheControllerImageVerb (0.00s) +=== RUN TestFelhomOpSudoersPctIsExact + r861_injection_test.go:135: felhom-op's sudoers allows "/usr/sbin/pct stop 9201 --skiplock 1" + r861_injection_test.go:135: felhom-op's sudoers allows "/usr/sbin/pct start 9201 9202" + r861_injection_test.go:135: felhom-op's sudoers allows "/usr/sbin/pct unlock 9201 --whatever" + r861_injection_test.go:135: felhom-op's sudoers allows "/usr/sbin/pct start 92a1" +--- FAIL: TestFelhomOpSudoersPctIsExact (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/capability 0.099s +FAIL diff --git a/documentation/audits/day-2026-10-07/C/C-red-go-tee.txt b/documentation/audits/day-2026-10-07/C/C-red-go-tee.txt new file mode 100644 index 00000000..c1488104 --- /dev/null +++ b/documentation/audits/day-2026-10-07/C/C-red-go-tee.txt @@ -0,0 +1,7 @@ +## RED (Go): WriteControllerImage restored to the pre-A1 in-guest tee +=== RUN TestR861_WriteControllerImageUsesTheRootVerb + r861_controller_image_test.go:40: the image write ran pct [exec 9201 -- tee /etc/felhom-controller-image], want felhom-priv-apply +--- FAIL: TestR861_WriteControllerImageUsesTheRootVerb (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/localapi 0.009s +FAIL diff --git a/documentation/audits/day-2026-10-07/D/red1-no-purge.txt b/documentation/audits/day-2026-10-07/D/red1-no-purge.txt new file mode 100644 index 00000000..172facf3 --- /dev/null +++ b/documentation/audits/day-2026-10-07/D/red1-no-purge.txt @@ -0,0 +1,13 @@ +## RED 1 — today's Deprovision (no purge before the delete) +=== RUN TestDeprovision_R32_PurgesFolderBeforeDeletingSubaccount + r32_purge_test.go:39: the folder must be purged before the sub-account is deleted; order [delete-subaccount] +--- FAIL: TestDeprovision_R32_PurgesFolderBeforeDeletingSubaccount (0.03s) +=== RUN TestDeprovision_R32_FailedPurgeKeepsSubaccount + r32_purge_test.go:54: a failed purge must fail Deprovision +--- FAIL: TestDeprovision_R32_FailedPurgeKeepsSubaccount (0.03s) +=== RUN TestDeprovision_R32_NoPurgeRouteRefuses + r32_purge_test.go:68: no purge route must refuse and keep the sub-account; err= deleted=1 +--- FAIL: TestDeprovision_R32_NoPurgeRouteRefuses (0.03s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/offsite 0.103s +FAIL diff --git a/documentation/audits/day-2026-10-07/D/red2-error-ignored.txt b/documentation/audits/day-2026-10-07/D/red2-error-ignored.txt new file mode 100644 index 00000000..24755c1a --- /dev/null +++ b/documentation/audits/day-2026-10-07/D/red2-error-ignored.txt @@ -0,0 +1,11 @@ +## RED 2 — the purge error ignored +=== RUN TestDeprovision_R32_PurgesFolderBeforeDeletingSubaccount +--- PASS: TestDeprovision_R32_PurgesFolderBeforeDeletingSubaccount (0.03s) +=== RUN TestDeprovision_R32_FailedPurgeKeepsSubaccount + r32_purge_test.go:54: a failed purge must fail Deprovision +--- FAIL: TestDeprovision_R32_FailedPurgeKeepsSubaccount (0.03s) +=== RUN TestDeprovision_R32_NoPurgeRouteRefuses +--- PASS: TestDeprovision_R32_NoPurgeRouteRefuses (0.03s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/offsite 0.105s +FAIL diff --git a/documentation/audits/day-2026-10-07/D/red3-no-filter.txt b/documentation/audits/day-2026-10-07/D/red3-no-filter.txt new file mode 100644 index 00000000..04bec718 --- /dev/null +++ b/documentation/audits/day-2026-10-07/D/red3-no-filter.txt @@ -0,0 +1,11 @@ +## RED 3 — the repository/set-aside filter removed +=== RUN TestPurgeRepos_R32_RemovesRepoAndSetAsidesOnly + r32_purge_test.go:58: want the repo + 2 set-asides removed, got [/home/felhom-repo /home/felhom-repo-notes /home/felhom-repo.orphaned-20260721 /home/felhom-repo.orphaned-20260721-2 /home/other] +--- FAIL: TestPurgeRepos_R32_RemovesRepoAndSetAsidesOnly (0.00s) +=== RUN TestPurgeRepos_R32_SurvivorFails +--- PASS: TestPurgeRepos_R32_SurvivorFails (0.00s) +=== RUN TestPurgeRepos_R32_EmptyIsSuccess +--- PASS: TestPurgeRepos_R32_EmptyIsSuccess (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/offsitekeys 0.008s +FAIL diff --git a/documentation/audits/day-2026-10-07/E/red-agent-ledger.txt b/documentation/audits/day-2026-10-07/E/red-agent-ledger.txt new file mode 100644 index 00000000..589f8192 --- /dev/null +++ b/documentation/audits/day-2026-10-07/E/red-agent-ledger.txt @@ -0,0 +1,10 @@ +## RED (agent, stanza shape) — the pick never writes the ledger +=== RUN TestR366_PickRecordsArchivesWrittenWithAnotherKey + r366_foreign_key_ledger_test.go:45: after one evaluation the ledger must report felhom-pbs: 2 archives 2026-09-16T17:27:32Z…21:59:54Z; got [] +--- FAIL: TestR366_PickRecordsArchivesWrittenWithAnotherKey (0.00s) +=== RUN TestR366_EvaluatedWithNoneIsAnEmptyList + r366_foreign_key_ledger_test.go:67: evaluated with none must report tiers: []; got {"host_id":"","reported_at":"","agent_version":"","host":{"node":"","cpu_percent":0,"memory_total_bytes":0,"memory_used_bytes":0,"memory_percent":0,"disk_total_bytes":0,"disk_used_bytes":0,"disk_percent":0,"loadavg":null,"uptime_seconds":0,"cpu_temp_c":null},"guests":null,"storage_targets":null,"backups":null,"restore_tests":null,"pbs_snapshots":null,"cloudflared":{"status":""},"audit_tail":null,"capabilities":null,"leaf_fingerprint":"","addresses":null,"dr_recipe":null} +--- FAIL: TestR366_EvaluatedWithNoneIsAnEmptyList (0.00s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-agent/internal/backup 0.009s +FAIL diff --git a/documentation/audits/day-2026-10-07/E/red-hub-event.txt b/documentation/audits/day-2026-10-07/E/red-hub-event.txt new file mode 100644 index 00000000..bea3a2f2 --- /dev/null +++ b/documentation/audits/day-2026-10-07/E/red-hub-event.txt @@ -0,0 +1,14 @@ +## RED (hub, stanza shape) — the host report does not note the set +=== RUN TestR366_ForeignKeyArchivesOneEventPerChange + r366_foreign_key_archives_test.go:45: a new set of other-key archives must record exactly one operator event; got 0 +--- FAIL: TestR366_ForeignKeyArchivesOneEventPerChange (0.04s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/api 0.059s +FAIL +## RED (hub) — no edge trigger (every report records) +=== RUN TestR366_ForeignKeyArchivesOneEventPerChange + r366_foreign_key_archives_test.go:45: a new set of other-key archives must record exactly one operator event; got 3 +--- FAIL: TestR366_ForeignKeyArchivesOneEventPerChange (0.04s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/api 0.060s +FAIL diff --git a/documentation/audits/day-2026-10-07/F/red-r105.txt b/documentation/audits/day-2026-10-07/F/red-r105.txt new file mode 100644 index 00000000..6ca1d24e --- /dev/null +++ b/documentation/audits/day-2026-10-07/F/red-r105.txt @@ -0,0 +1,13 @@ +## RED on today's code (felhom.eu 5ba1702f + the test, old 3-arg call) +=== RUN TestR105_IdentitySaveLeavesDirectiveColumnAlone + r105_retired_fields_test.go:35: the identity-blob save must leave directive_json alone; got {} +--- FAIL: TestR105_IdentitySaveLeavesDirectiveColumnAlone (0.04s) +=== RUN TestR105_RetiredColumnsHaveNoReader + r105_retired_fields_test.go:56: dr_record_json is still read or written in store.go outside its schema statement + r105_retired_fields_test.go:56: directive_json is still read or written in store.go outside its schema statement + r105_retired_fields_test.go:56: DRRecordJSON is still read or written in store.go outside its schema statement + r105_retired_fields_test.go:56: DirectiveJSON is still read or written in store.go outside its schema statement +--- FAIL: TestR105_RetiredColumnsHaveNoReader (0.05s) +FAIL +FAIL gitea.dooplex.hu/admin/felhom-hub/internal/store 0.097s +FAIL