Machine: VM 330 destroyed with its disks. Host: ISO and scratch removed, ~8.5 GiB returned on nvme-scratch. Hub: customer drill0242 DELETED via the cascade (journal #17), pages 404; its ep0 WireGuard peer dropped at the next full-list push. Evidence pulled before the destroy. R-501: the documented CI-check recipe reads only the last jobs page, which is not in id order. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -480,3 +480,17 @@ the lock is honest about its length and lifts on time. Two properties recorded,
|
||||
household out for 15 minutes, by design against guessing; and the lockout e-mail went to the
|
||||
**operator only** (`Operator email sent for drill0242/claim_lockout`), while the screen tells the
|
||||
customer.
|
||||
|
||||
## Teardown — three layers (`teardown-before.txt`, `teardown-layer1.txt`, `teardown-layer2.txt`, `teardown-layer3-hub.txt`)
|
||||
|
||||
Evidence was copied off the box **before** the destroy (`box-logs-final/`, 14:16, secret sweep 0).
|
||||
|
||||
| layer | UTC | result |
|
||||
|---|---|---|
|
||||
| **1. machine** | 14:16:23 | `qm destroy 330 --purge` → `qm list` empty; `/mnt/hdd_1/images/330` gone; `images/9202` untouched |
|
||||
| **2. host** | 14:16:27 | ISO removed (0 left); `/root/drill0242` shredded, removed; `nvme-scratch` used **19 059 372 → 10 130 532 KiB**; `local` **24 768 200 → 23 013 832 KiB**; `local-lvm` 44.17 % before and after; 9201 and 9202 running; `vmbr9` pre-existed |
|
||||
| **3. hub** | 14:35:15 | host stale at 14:34:45 (true `host_stale` operator mail); **customer DELETE cascade COMPLETE** (journal #17); customer and host pages 404; lists 0 (control 1) |
|
||||
| 3b. ep0 peer | 14:40:00 | `10.77.0.5/32` removed at the 14:39:30 periodic push (5 → 4 peers); 4 m 14 s after the delete; control peer present |
|
||||
|
||||
**Disposition of `drill0242`: DELETED.** The hub's event stream and the three operator mails
|
||||
(`claim_lockout`, `host_stale`, and the bind/enrol log lines) are append-only and stay, by design.
|
||||
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
=== LAYER 3 — the hub 2026-09-14T14:35:15Z
|
||||
ep0 WG peer for 10.77.0.5 BEFORE: 1
|
||||
delete POST: HTTP/1.1 303 See Other Location: /configs?flash=deleted
|
||||
|
||||
customer page: 404
|
||||
host page: 404
|
||||
configs list mentions drill0242: 0 (control, a live customer 'enkisfelhom': 1)
|
||||
hosts list mentions drill0242: 0
|
||||
ep0 WG peer for 10.77.0.5 AFTER: 1 (control, demo-hp 10.77.0.3: 1)
|
||||
--- hub log
|
||||
2026/09/14 16:34:45 [INFO] Host staleness: drill0242-3f4b42 ok → stale (host_stale)
|
||||
2026/09/14 16:34:46 [INFO] Operator email sent for drill0242/host_stale
|
||||
2026/09/14 16:35:16 [INFO] customer DELETE cascade started for drill0242 (journal #17, 1 host(s))
|
||||
2026/09/14 16:35:16 [INFO] delete drill0242: host drill0242-3f4b42 deleted (escrow DEMOTED to retained custody)
|
||||
2026/09/14 16:35:17 [INFO] tenantsync: deprovision ok for drill0242 (ns=drill0242, existed=false)
|
||||
2026/09/14 16:35:17 [INFO] reset drill0242: PBS tenancy deprovisioned
|
||||
2026/09/14 16:35:17 [INFO] [claim] reset to unclaimed for drill0242 (customer RESET) — next onboarding mints a fresh code
|
||||
2026/09/14 16:35:17 [INFO] delete drill0242: residue purged (reports=9 app_telemetry=16 app_log_tails=0 log_tail_requests=0 notif_prefs=1 selfbind_tokens=1 appliance_registrations=1)
|
||||
2026/09/14 16:35:17 [INFO] customer DELETE cascade COMPLETE for drill0242 (journal #17) — full teardown
|
||||
=== ep0 re-check 14:37:21
|
||||
peer 10.77.0.5: 1 control 10.77.0.3: 1
|
||||
peer config files naming 10.77.0.5: 1
|
||||
--- hub log wg lines
|
||||
2026/09/14 16:29:30 [INFO] wgsync: pushed 5 peers to 167.233.158.164:22
|
||||
2026/09/14 16:34:30 [INFO] wgsync: pushed 5 peers to 167.233.158.164:22
|
||||
=== ep0 re-check after the next wgsync push 14:40:00
|
||||
peer 10.77.0.5: 0 control 10.77.0.3: 1
|
||||
config files naming 10.77.0.5: 0
|
||||
2026/09/14 16:39:30 [INFO] wgsync: pushed 4 peers to 167.233.158.164:22
|
||||
@@ -704,6 +704,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server`
|
||||
| **R-498** | **[P3-LOW] The „Első lépések" on 52 of 53 app pages tell a customer to open a literal `wiki.DOMAIN` — the placeholder is never filled in.** MEASURED 2026-09-14 on a fresh 0.242.0 box (drill step 5): BookStack's app page renders „Nyisd meg a **wiki.DOMAIN** címet a böngészőben", PrivateBin's „Nyisd meg a **paste.DOMAIN** címet". `grep -rl '\.DOMAIN c[íi]m' app-catalog-felhom.eu/templates/*/.felhom.yml` → **52 of 53** templates carry it in `first_steps`; the controller renders the string as text (`internal/stacks/metadata.go`). A stranger reading their first instruction meets a word that is not an address. **Fix shape:** substitute the stack's real `SUBDOMAIN.DOMAIN` at render time (one place in the controller), with a render test per template that fails on a literal `DOMAIN`. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-499** | **[P2-MEDIUM] Every app without a data drive is told its data is „already in the full system backup (PBS)" and there is „nothing to do" — on a box with no PBS, whose only whole-box copy sits on the same disk.** MEASURED 2026-09-14 on a fresh 0.242.0 box with the DR tier off (drill step 7): `GET /stacks/bookstack/backup` renders „Ennek az alkalmazásnak az adatai a belső rendszerlemezen vannak, amelyek **már szerepelnek a teljes rendszermentésben (PBS)** … ehhez az alkalmazáshoz nincs külön teendő." The sentence sits under `{{if not .IsHDDApp}}` in `controller/internal/web/templates/tier2_config.html:20-26` and consults nothing about where the whole-guest backup goes. On the same box `/backups` says, correctly, „Helyi tároló (local)" and „A rendszermentés jelenleg ugyanazon a lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem." **Two pages of one product contradict each other, and the reassuring one is the false one.** **Fix shape:** branch the sentence on the box's actual whole-guest target (PBS vs local, same-disk flag the overview already computes); a render test per branch. | **READY — rank P2-MEDIUM; owner: CC** |
|
||||
| **R-500** | **[P3-LOW] The dashboard shows the last backup in UTC while every backup page shows it in local time — two different clock times for one backup.** MEASURED 2026-09-14 on a fresh 0.242.0 box (drill step 12): the same backup (`last_run 2026-09-14T13:41:37Z`) reads „Utolsó mentés: **2026-09-14 13:41**" on `/dashboard` and „Utolsó adatbázis mentés: **2026-09-14 15:41** (most)" on `/backups/apps`. Cause, from source: `controller/internal/web/templates/dashboard.html:154` renders `{{.BackupStatus.LastRun.Format "2006-01-02 15:04"}}` with no conversion to the box's zone, while the backup pages go through the zone-aware helpers in `funcmap.go`. A household comparing the two screens sees a backup two hours apart from itself. **Fix shape:** format through the same zone-aware helper; a render test that pins a non-UTC zone and asserts the local hour. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-501** | **[P3-LOW] The documented "confirm your CI run" recipe reads only the LAST page of the jobs list, and that list is not in id order — so it can report a run as missing that exists and passed.** MEASURED 2026-09-14 for felhom.eu commit `38848ff`: `actions/jobs?limit=1` → `total_count 335`; the recipe's page `T/50+1` = page 7 held ids 473…570 and **no match for 8 minutes**; a scan of all seven pages found the job on **page 6** (ids 380…581): `job id=581 name=gates status=completed conclusion=success completed_at 2026-09-14T14:18:23Z`. Pages are not sorted (page 1 ids 1…273, page 2 84…208). `actions/tasks` listed the same run first (`id 582, run_number 335, success`). **Fix shape:** the recipe in `felhom.eu/CLAUDE.md` (end-of-session checklist) scans every page and matches `head_sha`; say so in the same sentence that warns about the id offset (R-417). | **READY — rank P3-LOW; owner: CC** |
|
||||
|
||||
<!-- DUE-CHECKS-BEGIN — machine-readable. Parsed by scripts/due_checks_gate.py.
|
||||
One row per dated check. The R-number must have a row above. Dates are UTC.
|
||||
|
||||
Reference in New Issue
Block a user