diff --git a/documentation/audits/evidence-bignight-2026-09-14/journal.md b/documentation/audits/evidence-bignight-2026-09-14/journal.md index b366430f..33941d79 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/journal.md +++ b/documentation/audits/evidence-bignight-2026-09-14/journal.md @@ -340,3 +340,21 @@ customer a FileBrowser login.** A customer's first guess, `admin` / `admin`, **w 401. With it, both sources list (Adatlemez → `documents`, …; Beolvasás → `paperless`). The same login works on demo-hp's **9201** and **9202**, and 9201's login page answers **200 through Cloudflare from the internet** (GET only, no login attempted remotely). Filed R-513 before anything else; nothing changed on any box. + +**immich** (cont.) ML queues empty at 18:32:09Z (≈ 6 min after upload); asset 42 original read back **sha equal**. + +**paperless-ngx** 18:27:xx deploy → running. Token with the deploy-generated admin password (the app card's +„admin / admin" is not what was set — the form generates a 16-char password). Tags Számla / Garancia / Adó (201 ×3); +**20 PDFs posted 18:29:57Z → 0 documents**. Kernel: the container's cgroup OOM-killed `gs` and the celery worker at +18:31:22Z; tasks 11 FAILURE (WorkerLostError) · 1 STARTED · 8 PENDING, unchanged at 18:44Z. App still „Fut". **R-514 (P2).** + +**jellyfin** 18:29:34 → running **50 s**. Startup wizard through its REST calls (Hungarian UI culture, user „anna"), +login 200; libraries none; the container sees `/media/{audiobooks,books,comics,movies,music,photos,podcasts,tv}` +(the drive's `userdata/media`, read-only). + +**mealie** → running **85 s**. The card's default login `changeme@example.com / MyPassword` works (200); password +changed (old now 401); 5 Hungarian recipes with ingredients + steps (201/200 ×5); meal plan 15–19 Sept (201 ×5) reads +back all five; Gulyásleves reads back its accents. + +**uptime-kuma** → running **50 s**. Its socket.io endpoint answers the polling transport with the SPA page (websocket +only); DooPlex has no websocket library — a raw client is written next. diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-adventurelog.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-adventurelog.txt new file mode 100644 index 00000000..cab391cb --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-adventurelog.txt @@ -0,0 +1,6 @@ +adventurelog: fields ['DB_PASSWORD', 'SECRET_KEY', 'SUBDOMAIN']; secrets in /tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/a23ddbf6-6c9b-4b80-8fa9-69a2a962eeb6/scratchpad/apps/adventurelog.json: ['SECRET_KEY', 'DB_PASSWORD'] +POST 18:45:42 + -> {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + + +5s not_deployed + +10s deploying diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-mealie.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-mealie.txt new file mode 100644 index 00000000..d45b39b3 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-mealie.txt @@ -0,0 +1,8 @@ +mealie: fields ['SUBDOMAIN']; secrets in /tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/a23ddbf6-6c9b-4b80-8fa9-69a2a962eeb6/scratchpad/apps/mealie.json: [] +POST 18:32:17 + -> {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + + +5s deploying + +65s starting + +85s running +mealie: final running after 85s diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-uptime-kuma.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-uptime-kuma.txt new file mode 100644 index 00000000..e4ac8acb --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/deploy-uptime-kuma.txt @@ -0,0 +1,9 @@ +uptime-kuma: fields ['SUBDOMAIN']; secrets in /tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/a23ddbf6-6c9b-4b80-8fa9-69a2a962eeb6/scratchpad/apps/uptime-kuma.json: [] +POST 18:42:53 + -> {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + + +5s not_deployed + +10s deploying + +40s starting + +50s running +uptime-kuma: final running after 50s diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-logs.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-logs.txt new file mode 100644 index 00000000..5c1de28e --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-logs.txt @@ -0,0 +1,30 @@ +[2026-09-14 20:31:22,888] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/process.py", line 110, in run +[2026-09-14 20:31:22,889] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 290, in __call__ +[2026-09-14 20:31:22,891] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/celery/concurrency/asynpool.py", line 250, in on_loop_start +[2026-09-14 20:31:22,891] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/queues.py", line 366, in put +[2026-09-14 20:31:22,892] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/queues.py", line 358, in send_payload +[2026-09-14 20:31:22,892] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/connection.py", line 224, in send_bytes +[2026-09-14 20:31:22,893] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/connection.py", line 450, in _send_bytes +[2026-09-14 20:31:22,894] [WARNING] [celery.redirected] File "/usr/local/lib/python3.12/site-packages/billiard/connection.py", line 403, in _send +[2026-09-14 20:31:22,894] [WARNING] [celery.redirected] BrokenPipeError: [Errno 32] Broken pipe +-- ******* ---- .> task events: ON +[tasks] + . documents.tasks.bulk_update_documents + . documents.tasks.check_scheduled_workflows + . documents.tasks.consume_file + . documents.tasks.empty_trash + . documents.tasks.index_optimize + . documents.tasks.sanity_check + . documents.tasks.train_classifier + . documents.tasks.update_document_content_maybe_archive_file + . paperless_mail.mail.error_callback + . paperless_mail.tasks.process_mail_accounts +[2026-09-14 20:31:34,920] [INFO] [celery.beat] Scheduler: Sending due task Check all e-mail accounts (paperless_mail.tasks.process_mail_accounts) +[2026-09-14 20:31:35,217] [INFO] [celery.worker.consumer.connection] Connected to redis://paperless-redis:6379// +[2026-09-14 20:31:35,308] [INFO] [celery.worker.strategy] Task paperless_mail.tasks.process_mail_accounts[a7c631ca-8b2d-413b-a542-70ab656365ae] received +[2026-09-14 20:31:35,319] [INFO] [celery.worker.strategy] Task paperless_mail.tasks.process_mail_accounts[78bf7d54-48d5-4eff-b20f-53923a5118a9] received +[2026-09-14 20:31:35,411] [INFO] [celery.app.trace] Task paperless_mail.tasks.process_mail_accounts[a7c631ca-8b2d-413b-a542-70ab656365ae] succeeded in 0.09534799400034899s: 'No new documents were added.' +[2026-09-14 20:31:40,598] [INFO] [celery.app.trace] Task paperless_mail.tasks.process_mail_accounts[78bf7d54-48d5-4eff-b20f-53923a5118a9] succeeded in 0.0797082050003155s: 'No new documents were added.' +[2026-09-14 20:40:00,000] [INFO] [celery.beat] Scheduler: Sending due task Check all e-mail accounts (paperless_mail.tasks.process_mail_accounts) +[2026-09-14 20:40:00,005] [INFO] [celery.worker.strategy] Task paperless_mail.tasks.process_mail_accounts[653878d3-25f8-4f07-b554-d08c587311dc] received +[2026-09-14 20:40:00,091] [INFO] [celery.app.trace] Task paperless_mail.tasks.process_mail_accounts[653878d3-25f8-4f07-b554-d08c587311dc] succeeded in 0.08074803699992117s: 'No new documents were added.' diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-oom-check.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-oom-check.txt new file mode 100644 index 00000000..e5dfce7b --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-oom-check.txt @@ -0,0 +1,46 @@ +--- VM kernel OOM lines since 20:25 CEST +Sep 14 20:31:22 felhom kernel: [celeryd: celer invoked oom-killer: gfp_mask=0xcc0(GFP_KERNEL), order=0, oom_score_adj=0 +Sep 14 20:31:22 felhom kernel: oom-kill:constraint=CONSTRAINT_MEMCG,nodemask=(null),cpuset=docker-53dcb98902831673ff4f9b5b9ee4b9be2193c2fb41a6424a0c477b579b16de8d.scope,mems_allowed=0,oom_memcg=/lxc/9201/ns/system.slice/docker-53dcb98902831 +Sep 14 20:31:22 felhom kernel: Memory cgroup out of memory: Killed process 52659 (gs) total-vm:201648kB, anon-rss:157440kB, file-rss:15204kB, shmem-rss:0kB, UID:101000 pgtables:432kB oom_score_adj:0 +Sep 14 20:31:22 felhom kernel: [celeryd: celer invoked oom-killer: gfp_mask=0xcc0(GFP_KERNEL), order=0, oom_score_adj=0 +Sep 14 20:31:22 felhom kernel: oom-kill:constraint=CONSTRAINT_MEMCG,nodemask=(null),cpuset=docker-53dcb98902831673ff4f9b5b9ee4b9be2193c2fb41a6424a0c477b579b16de8d.scope,mems_allowed=0,oom_memcg=/lxc/9201/ns/system.slice/docker-53dcb98902831 +Sep 14 20:31:22 felhom kernel: Memory cgroup out of memory: Killed process 52685 (gs) total-vm:201648kB, anon-rss:157444kB, file-rss:15000kB, shmem-rss:0kB, UID:101000 pgtables:436kB oom_score_adj:0 +Sep 14 20:31:22 felhom kernel: [celeryd: celer invoked oom-killer: gfp_mask=0xcc0(GFP_KERNEL), order=0, oom_score_adj=0 +Sep 14 20:31:22 felhom kernel: oom-kill:constraint=CONSTRAINT_MEMCG,nodemask=(null),cpuset=docker-53dcb98902831673ff4f9b5b9ee4b9be2193c2fb41a6424a0c477b579b16de8d.scope,mems_allowed=0,oom_memcg=/lxc/9201/ns/system.slice/docker-53dcb98902831 +Sep 14 20:31:22 felhom kernel: Memory cgroup out of memory: Killed process 45078 ([celeryd: celer) total-vm:275476kB, anon-rss:118284kB, file-rss:34744kB, shmem-rss:0kB, UID:101000 pgtables:416kB oom_score_adj:0 +Sep 14 20:31:22 felhom kernel: [celeryd: celer invoked oom-killer: gfp_mask=0xcc0(GFP_KERNEL), order=0, oom_score_adj=0 +Sep 14 20:31:22 felhom kernel: oom-kill:constraint=CONSTRAINT_MEMCG,nodemask=(null),cpuset=docker-53dcb98902831673ff4f9b5b9ee4b9be2193c2fb41a6424a0c477b579b16de8d.scope,mems_allowed=0,oom_memcg=/lxc/9201/ns/system.slice/docker-53dcb98902831 +Sep 14 20:31:22 felhom kernel: Memory cgroup out of memory: Killed process 45083 ([celery beat] -) total-vm:348532kB, anon-rss:96712kB, file-rss:34368kB, shmem-rss:0kB, UID:101000 pgtables:412kB oom_score_adj:0 +--- inspect +/paperless-webserver mem=805306368 restarts=0 oomkilled=true started=2026-09-14T18:27:32.784793017Z +/paperless-postgres mem=268435456 restarts=0 oomkilled=false started=2026-09-14T18:27:22.319110781Z +/paperless-redis mem=134217728 restarts=0 oomkilled=false started=2026-09-14T18:27:22.31484663Z +--- stats +bookstack 59.21MiB / 512MiB +bookstack-db 72.11MiB / 256MiB +cloudflared 18.03MiB / 11.55GiB +docmost 264.2MiB / 384MiB +docmost-postgres 45.13MiB / 256MiB +docmost-redis 6.062MiB / 128MiB +felhom-controller 87.46MiB / 11.55GiB +filebrowser 14.37MiB / 256MiB +gokapi 8.969MiB / 128MiB +immich-machine-learning 196.1MiB / 1.5GiB +immich-postgres 352.5MiB / 512MiB +immich-redis 5.824MiB / 128MiB +immich-server 807.6MiB / 2GiB +jellyfin 176.4MiB / 2GiB +mealie 273.3MiB / 1000MiB +nextcloud 228.3MiB / 1GiB +nextcloud-db 85.95MiB / 512MiB +nextcloud-redis 4.191MiB / 128MiB +paperless-postgres 66.88MiB / 256MiB +paperless-redis 8.629MiB / 128MiB +paperless-webserver 609.9MiB / 768MiB +privatebin 22.47MiB / 128MiB +traefik 53.66MiB / 11.55GiB +uptime-kuma 102.8MiB / 256MiB +vaultwarden 44.22MiB / 256MiB +--- free + total used free shared buff/cache available +Mem: 11828 3520 104 401 8603 8307 diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-tasks.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-tasks.txt new file mode 100644 index 00000000..e3e81803 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/paperless-tasks.txt @@ -0,0 +1,43 @@ +tasks 20 {'PENDING': 8, 'STARTED': 1, 'FAILURE': 11} +szamla-00.pdf FAILURE 2026-09-14T20:29:52.966540+02:00 2026-09-14T20:30:12.827429+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-01.pdf FAILURE 2026-09-14T20:29:53.858373+02:00 2026-09-14T20:30:12.879255+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-02.pdf FAILURE 2026-09-14T20:29:54.042812+02:00 2026-09-14T20:30:16.856645+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-03.pdf FAILURE 2026-09-14T20:29:54.441824+02:00 2026-09-14T20:30:16.901908+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-04.pdf FAILURE 2026-09-14T20:29:54.702199+02:00 2026-09-14T20:30:36.422907+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-05.pdf FAILURE 2026-09-14T20:29:54.981092+02:00 2026-09-14T20:30:36.480605+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-06.pdf FAILURE 2026-09-14T20:29:55.341903+02:00 2026-09-14T20:30:50.950202+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-07.pdf FAILURE 2026-09-14T20:29:55.474933+02:00 2026-09-14T20:30:51.007984+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-08.pdf FAILURE 2026-09-14T20:29:55.677026+02:00 2026-09-14T20:31:04.088026+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-09.pdf FAILURE 2026-09-14T20:29:55.800004+02:00 2026-09-14T20:31:04.306670+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-10.pdf FAILURE 2026-09-14T20:29:56.005346+02:00 2026-09-14T20:31:21.714985+02:00 Traceback (most recent call last): + File "/usr/local/lib/python3.12/site-packages/billiard/pool.py", line 1265, in mark_as_worker_lost + raise WorkerLostErro +szamla-11.pdf STARTED 2026-09-14T20:29:56.125431+02:00 None None +szamla-12.pdf PENDING 2026-09-14T20:29:56.232396+02:00 None None +szamla-13.pdf PENDING 2026-09-14T20:29:56.392096+02:00 None None +szamla-14.pdf PENDING 2026-09-14T20:29:56.505880+02:00 None None +szamla-15.pdf PENDING 2026-09-14T20:29:56.768077+02:00 None None +szamla-16.pdf PENDING 2026-09-14T20:29:56.934349+02:00 None None +szamla-17.pdf PENDING 2026-09-14T20:29:57.094106+02:00 None None +szamla-18.pdf PENDING 2026-09-14T20:29:57.309719+02:00 None None +szamla-19.pdf PENDING 2026-09-14T20:29:57.480055+02:00 None None diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-immich.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-immich.txt index 2be71fa1..5fa34a25 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-immich.txt +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-immich.txt @@ -15,3 +15,5 @@ 18:30:39 jobs pending {'faceDetection': (2, 16), 'ocr': (1, 118)} 18:31:09 jobs pending {'ocr': (1, 94)} 18:31:39 jobs pending {'ocr': (1, 57)} +18:32:09 jobs pending {} +18:32:09 readback asset 42 200 True diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-mealie.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-mealie.txt new file mode 100644 index 00000000..77380837 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-mealie.txt @@ -0,0 +1,22 @@ +18:42:50 default login (the app card) 200 +18:42:50 self 200 changeme@example.com +18:42:50 change password 200 {"message":"Password updated","error":false} +18:42:51 old default password now 401 +18:42:51 new password 200 +18:42:52 create Gulyásleves 201 gulyasleves +18:42:52 fill 200 +18:42:52 create Túrós csusza 201 turos-csusza +18:42:52 fill 200 +18:42:52 create Lecsó 201 lecso +18:42:52 fill 200 +18:42:53 create Rakott krumpli 201 rakott-krumpli +18:42:53 fill 200 +18:42:53 create Somlói galuska 201 somloi-galuska +18:42:53 fill 200 +18:42:53 mealplan Gulyásleves 201 +18:42:53 mealplan Túrós csusza 201 +18:42:53 mealplan Lecsó 201 +18:42:53 mealplan Rakott krumpli 201 +18:42:53 mealplan Somlói galuska 201 +18:42:53 plan readback 200 ['Somlói galuska', 'Rakott krumpli', 'Lecsó', 'Túrós csusza', 'Gulyásleves'] +18:42:53 readback gulyas ['1 kg marhalábszár', '2 fej vöröshagyma', 'pirospaprika', 'burgonya'] BIGNIGHT-RECEPT árvíztűrő diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-paperless.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-paperless.txt index 980e2d1a..f2826903 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-paperless.txt +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-paperless.txt @@ -33,3 +33,52 @@ Traceback (most recent call last): File "/usr/lib/python3/dist-packages/requests/models.py", line 971, in json raise RequestsJSONDecodeError(e.msg, e.doc, e.pos) requests.exceptions.JSONDecodeError: Expecting value: line 1 column 1 (char 0) +18:32:40 (re-run of the read-back; the first run crashed on /api/tasks/ returning non-JSON) +18:32:40 tasks endpoint 200 application/json [{"id":20,"task_id":"9975d1ff-f06e-4545-b611-95102cd090f2","task_name":"consume_ +18:32:40 documents 0 +18:32:55 documents 0 +18:33:10 documents 0 +18:33:25 documents 0 +18:33:40 documents 0 +18:33:55 documents 0 +18:34:11 documents 0 +18:34:26 documents 0 +18:34:41 documents 0 +18:34:56 documents 0 +18:35:11 documents 0 +18:35:26 documents 0 +18:35:41 documents 0 +18:35:56 documents 0 +18:36:11 documents 0 +18:36:26 documents 0 +18:36:41 documents 0 +18:36:56 documents 0 +18:37:11 documents 0 +18:37:26 documents 0 +18:37:42 documents 0 +18:37:57 documents 0 +18:38:12 documents 0 +18:38:27 documents 0 +18:38:42 documents 0 +18:38:57 documents 0 +18:39:12 documents 0 +18:39:27 documents 0 +18:39:42 documents 0 +18:39:57 documents 0 +18:40:12 documents 0 +18:40:27 documents 0 +18:40:42 documents 0 +18:40:57 documents 0 +18:41:12 documents 0 +18:41:28 documents 0 +18:41:43 documents 0 +18:41:58 documents 0 +18:42:13 documents 0 +18:42:28 documents 0 +18:42:43 tag Számla docs 0 +18:42:43 tag Garancia docs 0 +18:42:43 tag Adó docs 0 +18:42:43 full-text "BIGNIGHT" 0 | negative "XYZZYQ" 0 +Traceback (most recent call last): + File "", line 17, in +IndexError: list index out of range diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-uptime-kuma.txt b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-uptime-kuma.txt new file mode 100644 index 00000000..f87400e2 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase3/seed-uptime-kuma.txt @@ -0,0 +1,15 @@ +Traceback (most recent call last): + File "/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/a23ddbf6-6c9b-4b80-8fa9-69a2a962eeb6/scratchpad/seed_kuma.py", line 7, in + k=Kuma(B); log('socket.io connected, events so far',[p[:40] for p in k.buf][:4]) + File "/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/a23ddbf6-6c9b-4b80-8fa9-69a2a962eeb6/scratchpad/kuma.py", line 9, in __init__ + self.sid=json.loads(r.text[1:r.text.index('}')+1])['sid'] + ~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + File "/usr/lib/python3.13/json/__init__.py", line 346, in loads + return _default_decoder.decode(s) + ~~~~~~~~~~~~~~~~~~~~~~~^^^ + File "/usr/lib/python3.13/json/decoder.py", line 345, in decode + obj, end = self.raw_decode(s, idx=_w(s, 0).end()) + ~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^ + File "/usr/lib/python3.13/json/decoder.py", line 363, in raw_decode + raise JSONDecodeError("Expecting value", s, err.value) from None +json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0) diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index a20e8245..b3f6f381 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -717,6 +717,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-511** | **[P2-MEDIUM] A customer whose box is rebuilt keeps its ep0 PBS token, and then the DR tier can be neither provisioned nor re-issued: the hub's error advises the one action that refuses.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, `tester-1`, DR tier ticked): on the new box's WireGuard registration the hub logged `[ERROR] pbsdr auto-provision for tester-1 (WG-registration hook): the endpoint already holds a PBS token for tester-1 but the hub has no descriptor — use the explicit "Re-issue PBS credentials" action — save the customer config to retry`. The operator's `POST /configs/tester-1/pbsdr-reissue` → **400 `No provisioned PBS DR tier for this customer`** (`hub/internal/web/pbsdr.go` ~411). The token was left by the doorstep walk's host delete (a host delete does not deprovision tenancy; only RESET does, which also removes the tunnel). So a box rebuilt for an existing customer — the reinstall journey — has no whole-guest off-site tier and no button that restores it. **Fix shape:** let re-issue adopt an existing endpoint token when the descriptor is absent (the message already assumes it does), or have host delete offer to drop the PBS token. | **READY — rank P2-MEDIUM; owner: CC (hub)** | | **R-512** | **[P2-MEDIUM] Vaultwarden is installed with open registration, and the one control the page tells the customer to use to close it is read-only.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, controller 0.242.0, catalog vaultwarden 1.36.0-alpine): the deploy form sends `SIGNUPS_ALLOWED=true` (catalog default); after install, „Vaultwarden — Beállítások" says „Ez az alkalmazás már telepítve van. **Az alábbi beállítások csak olvashatók.**" and, below it, „Regisztráció engedélyezése — Igen / Nem — Új fiókok regisztrálásának engedélyezése. **Az első fiók létrehozása után állítsd 'Nem'-re.**" At 18:27:20Z a stranger with no invite and no login registered `idegen.probe@example.com` → **200** (`phase3/vaultwarden-stranger-signup.txt`). Once the dashboard is reachable through the tunnel, anyone who guesses `vault.` can open an account on the household's password server. A route does exist (the Vaultwarden admin panel's own setting, token under „Megjelenítés"), and no screen names it. **Fix shape:** default `SIGNUPS_ALLOWED=false` with an invite-first first step, or make that one field editable after install; the page must not instruct an act it forbids. | **READY — rank P2-MEDIUM; owner: CC (catalog + controller)** | | **R-513** | **[P1-HIGH — SECURITY] Every box's file manager (FileBrowser, `files.`, a launcher tile) accepts the login `admin` / `admin`, and on demo-hp that login page is on the public internet.** MEASURED 2026-09-14 (BIGNIGHT): `POST /api/auth/login?username=admin` with `X-Password: admin` → **200 + a session token** on VM 333 (fresh ISO 1.27.1 install, controller 0.242.0) and on demo-hp guests **9201 and 9202** (loopback, `Host: files.enkisfelhom.hu`); negative control `admin` / wrong → **401** on all three. On VM 333 that token lists both sources — „Adatlemez" (the data drive's `userdata`: documents, media, photos…) and „Beolvasás" (with `paperless`) — `GET /api/users?id=self` 200. **Public exposure, measured by GET only:** `https://files.enkisfelhom.hu/` from DooPlex through Cloudflare → 200, FileBrowser Quantum, `passwordAvailable:true, noAuth:false` (`phase3/filebrowser-public-reachability-demo-hp.txt`); no login was attempted over the internet. The generated `config.yaml` sets no admin credential (FileBrowser's own default applies); no screen shows the customer any FileBrowser login. Geo-restriction narrows who can reach it, it does not authenticate. **Not changed tonight** (9201's standing state is fenced; no product code). **Fix shape:** the controller sets a generated admin password (or proxy auth behind the dashboard session) at stack creation and on every existing box, and shows it where the customer finds app credentials. | **READY — rank P1-HIGH; owner: CC (controller) · operator (rotate on live boxes first)** | +| **R-514** | **[P2-MEDIUM] Paperless-ngx dies silently when a family uploads 20 documents at once: its worker is OOM-killed inside the catalog's 768 MB cap, 11 uploads fail, 8 wait forever, and the app still reads „Fut".** MEASURED 2026-09-14 (BIGNIGHT, VM 333, catalog paperless-ngx 2.20.15, `paperless-webserver` limit 805 306 368 B): 20 small 3-page PDFs posted through `/api/documents/post_document/` at 18:29:57Z. At 18:31:22Z the VM kernel logged `Memory cgroup out of memory: Killed process … (gs)` ×2, `([celeryd: celer)`, `([celery beat] -)` — constraint MEMCG of that container; `docker inspect` → `oomkilled=true restarts=0`. Paperless's own task list: **11 FAILURE (`WorkerLostError`), 1 STARTED, 8 PENDING**, unchanged 13 minutes later; **0 documents**. The controller shows the app running and healthy; no event, no alarm (`phase3/paperless-tasks.txt`, `paperless-oom-check.txt`). A household scanning a drawer of bills sees nothing arrive and no reason. **Fix shape:** raise the cap or set `PAPERLESS_TASK_WORKERS=1` / `PAPERLESS_THREADS_PER_WORKER=1` in the template, and let the dead-app/health check see an OOM-killed worker. | **READY — rank P2-MEDIUM; owner: CC (catalog)** |