ten answers: golden 0.300.0 baked (pinned), delivery evidence; R-645 R-856 R-747 R-774 R-734 R-624 R-502 R-99 closed; R-890/R-891 filed; 03 gains FELHOM_FSTRIM and GET /host/crash-guard (149 -> 143)
gates / gates (push) Successful in 2m47s

CI 1423 (929e59e8) was red on golden-currency: it read controller v0.300.0 before this commit recorded its golden.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 12:24:43 +02:00
parent 929e59e8f4
commit bfdea83204
12 changed files with 453 additions and 8 deletions
+15
View File
@@ -26,6 +26,21 @@
---
## 2026-10-06 (midday) — the operator's ten answers built
The full text of every row below: `git show 929e59e8:documentation/backlog/OPEN-ITEMS.md`.
| Row | What | Closed | Evidence |
|---|---|---|---|
| **R-774** | **[P3-LOW] Two things the new apps' pages do not show yet: Karakeep's mail-ON path is unproven, and its official phone app reports crashes to its makers.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 148): Karakeep's page says its phone app sends crash reports | catalog `ec72c9d` (live `1938921`): hu + en. The row's other half — one password-reset mail from Karakeep on a hub-enabled box — is NOT covered by this ruling; it is not built. |
| **R-734** | **[P3-LOW] The harness marks immich `files_may_change` because immich rewrites six 13-byte `.immich` folder markers at every start.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 145): the update test ignores listed marker files, each with a reason | catalog `b0939cf`: `scripts/upgrade-test.py` per-app list, immich's six `.immich` markers first; a listed file is ignored only when changed/added and ≤ 64 bytes; verdict records `files_ignored`; harness v5. `MarkerIgnore` tests on the measured immich lists; red-proof: an ignore-all mutant fails two tests. |
| **R-645** | **[P3-LOW] Lifting an update hold by the operator CLI lets the recovery unit be re-captured with the FAILED new definition within seconds — the copy the hold sentence names is overwritten.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 142): the night backup skips an app that runs another version than it saved | controller `2d63714` (v0.300.0): every night leg (DB dump, volume dump, unit capture, Tier 2) skips an app whose pin is not what it runs; one amber line on the backups page (`backup.status.version_skip`, hu + en); unknown never skips. `TestR645_HandLiftedHoldKeepsTheGoodUnit` runs the night + Tier 2 on the hand-lift shape (unit checksum unchanged); red-proof: without the skip the unit was rewritten with `docmost:0.96.0`. Delivered 10:22Z to the three boxes. **Residual, stated:** after the lift the boot reconciler may START the app on the new version, and then pin = running — the ruling's predicate protects the window between the lift and that start (the measured overwrite came 3 s after the restart); covering the started-new-version case is a design question, not built. |
| **R-99** | Server-side prune **never removes** a phantom snapshot. Confirmed it does NOT count them toward `keep-last` (dry-run kept 2 real + the phantom) so there is **no retention/data-loss bug** — but one acc (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 140): phantom leftovers are deleted by a runbook — none exist today | `runbooks/pbs-phantom-cleanup.md` + `pbs-phantom-list.py`; read-only listing of ep0 2026-10-06: 9 snapshots in 5 namespaces, all ≥ 369,808,250 B, all verification `ok`, every directory has its manifest — **no phantom, nothing deleted**, real counts unchanged (`audits/ten-answers-2026-10-06/r99-ep0-listing.txt`). The agent's WARN for a phantom now names the runbook (agent `be398f9`, v0.149.0, `TestRejectedArchiveWarnNamesTheCleanupRunbook`). |
| **R-747** | **[P3-LOW] A stranger can lock the household out of mealie with five wrong logins.** (P3) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 144): mealie's page says five wrong logins lock the account for 1–2 hours | catalog `ec72c9d` (live `1938921`): a new last first step, hu + en, informal. The 1–2 h is true where mealie runs with the one-hour lock setting; an already-installed mealie gets it when its compose is rendered again (still unmeasured, as the row said). |
| **R-856** | **A crash restart reaches the household twice: the hub's "restarted after an unexpected stop" line AND the controller's app mails.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 143): app mails wait ~15 minutes after a crash boot | controller `c393d85` (v0.300.0, `internal/crashboot`) + agent `f277e61` route `GET /host/crash-guard` (v0.149.0). Tests + red-proofs both halves (crash boot holds the mails at +3m30s; a normal boot keeps 90 s; an agent 404 = normal). **Live, through the real route (`audits/ten-answers-2026-10-06/delivery/controller-and-bundle.txt`):** demo-hp logged „boot grace 1m30s: the host's last unclean boot (2026-10-05T07:56:41Z) is not the one this start followed", demo-felhom „… the host's last boot was clean". The crash branch itself was not shown live (no crash allowed by the brief). |
| **R-502** | **[P3-LOW] The bootstrap regression harness is run by NO gate and NO CI — and it had never exercised the pairing banner.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 147): the ISO first-boot test is a gate, full runs only | felhom.eu `9d39faab`: `scripts/iso_bootstrap_gate.py`, fast=False (CI and the pre-push hook call --fast, so never), NOT CHECKED (exit 2) without docker or the image; a built-in decoy every full run; 9 docker-free decoy tests. **First real full run on DooPlex 2026-10-06** (after building `felhom-iso-assistant:trixie`): 73 harness checks green, the built-in decoy convicted (`audits/ten-answers-2026-10-06/r502-first-full-run.txt`). |
| **R-624** | **[P3-LOW] Three of the catalog's apps cannot be seeded by ANY headless route, and for two of them that is a deliberate security decision — so the upgrade harness has a permanent ceiling nobody has written down.** (P4) | CLOSED 2026-10-06 — BUILT AND DELIVERED (operator ruling, `09` §3 decision 146): the bench may seed vaultwarden through its admin route, bench only | catalog `aed80ee`. **Proven on the recreated bench 9401 (2026-10-06):** admin sign-in 200, invite 200, invited registration 200, seed read back before AND after the move; `.env` shredded, 64-hex grep 0 (control 1), `VW_ADMIN=` 0; WITHOUT the run flag the admin route is not tried and the verdict is `inconclusive` (`audits/ten-answers-2026-10-06/r624-bench/`). The move used (1.36.0-alpine → 1.36.0) failed on health — the non-alpine image fails the alpine health check; that is the test target, not the seed. Zipline needs no held secret (its `/api/setup`); its redaction is covered by `SecretHygiene`. **New question filed as R-890:** the ladder writer needs both venues, so a vaultwarden step still cannot be written. |
## 2026-10-06 (midday) — the ten answers
The full text of every row below: `git show 8c65ff0c:documentation/backlog/OPEN-ITEMS.md`.
File diff suppressed because one or more lines are too long