diff --git a/documentation/audits/evidence-bignight-2026-09-14/journal.md b/documentation/audits/evidence-bignight-2026-09-14/journal.md index a9102b19..39ad4ee6 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/journal.md +++ b/documentation/audits/evidence-bignight-2026-09-14/journal.md @@ -500,3 +500,14 @@ target=felhom-pbs … storage 'felhom-pbs' does not exist`), no operator mail fo | should have fired, did not | none — a 61 s outage is under the hub's 30-minute staleness threshold, by design | Verdict **PASS**. Jellyfin's health probe answered 503 / refused for ≈ 45 s after its start (WARN lines), then healthy. + +### F2 — power cut during the nightly backup (`phase5/F2-power-cut-during-backup.txt`, `phase5/F2/`) + +| | | +|---|---| +| how | `POST /api/backup/run` 19:40:03Z; the harness waited for the first „Stopping … for safe volume dump" (adventurelog, 19:40:07Z) and cut power at **19:40:08Z**; 33 s off; `qm start` 19:40:41Z | +| what the customer saw | every app down ≈ 3½ min, as F1. Afterwards `/backups/apps`: „Utolsó adatbázis mentés **2026-09-14 21:40 (5 perce)**", six databases „21:40 · OK", every app „Utolsó: 5 perce"; `/backups` and `/dashboard`: **no word of an interruption**; dashboard tile „Utolsó mentés: 2026-09-14 **19:40**" (UTC beside local times — R-500); whole-system tile „– · Naprakész" with no backup listed (added to R-517) | +| what the box did alone | controller 19:42:48Z: `[appstop] crash recovery: an app-data backup (volume dump) … was interrupted and left 1 app(s) stopped — restarting them: [adventurelog]` → restarted 19:42:52Z — **the app-stop guard restarted what it stopped** ✓. All 12 running on the same images at **+245 s**. AdventureLog's trip read back intact (3 places, visits). | +| torn copy | on disk the adventurelog and bookstack units hold a **19:40:07 SQL dump beside 19:00 volume tars and a 19:02:34 manifest**; both restore points are dated 19:40:07Z → **R-519 (P2)** | +| alarms fired | `backup_failed (error) — an app-data backup (volume dump) was interrupted by a controller restart — 1 app(s) were left stopped and have been restarted` + **operator e-mail** — **true**; `controller_started (info)` — true. No false dead-app alarm at +10 min | +| should have fired, did not | a customer-side notice on the backups page (R-519) | diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2-power-cut-during-backup.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2-power-cut-during-backup.txt new file mode 100644 index 00000000..990e2aab --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2-power-cut-during-backup.txt @@ -0,0 +1,22 @@ +F2 POST /api/backup/run 19:40:03 +{"ok":true,"message":"Mentés elindítva"} + +stack stopped for dump: 2026/09/14 19:40:07 [INFO] [backup] Stopping adventurelog for safe volume dump +F2 qm stop at 19:40:08 (+5 s into the backup) +status: stopped +F2 qm start at 19:40:41 +status: running +F2 + 135s dashboard /api/health 200 +F2 + 137s privatebin running same images +F2 + 137s gokapi running same images +F2 + 138s vaultwarden running same images +F2 + 138s jellyfin running same images +F2 + 144s nextcloud running same images +F2 + 149s bookstack running same images +F2 + 155s uptime-kuma running same images +F2 + 184s mealie running same images +F2 + 189s docmost running same images +F2 + 204s immich running same images +F2 + 205s adventurelog running same images +F2 + 245s paperless-ngx running same images +F2 + 245s ALL 12 running diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/adventurelog-readback.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/adventurelog-readback.txt new file mode 100644 index 00000000..b506209b --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/adventurelog-readback.txt @@ -0,0 +1 @@ +19:45:14 adventurelog after F2 200 [('Badacsony', 4.0, 1), ('Keszthely', 5.0, 1), ('Tihany', 5.0, 1)] diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/backup-honesty.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/backup-honesty.txt new file mode 100644 index 00000000..ed31be9a --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/backup-honesty.txt @@ -0,0 +1,10 @@ +=== 19:45:09 /api/backup/status +{"ok":true,"data":{"enabled":true,"running":false}} + +=== /backups/apps +Ütemezés | Adatbázis mentés | 02:30 | Következő: holnap 02:30 | Utolsó adatbázis mentés: | 2026-09-14 21:40 (5 perce) | Mentés most | Adatbázisok | Alkalmazás | Típus | Méret | Utolsó | Érvényesítés | Állapot | immich | PostgreSQL | 51.0 MB | 21:40 | 66 tábla | OK | nextcloud | MariaDB | 1.4 MB | 21:40 | 131 tábla | OK | paperless-ngx | PostgreSQL | 317.6 KB | 21:40 | 72 tábla | OK | adventurelog | PostgreSQL | 152.6 KB | 21:40 | 47 tábla | OK | bookstack | MariaDB | 66.4 KB | 21:40 | 41 tábla | OK | docmost | PostgreSQL | 139.9 KB | 21:40 | 42 tábla | OK | Alkalmazások mentési állapota | AdventureLog | Konfig + DB + Adatok | ▶ | 1. mentés | Auto | helyi | Utolsó: 5 perce | DB + Konfig + Adatok | 2. mentés | rsync | → hdd_1 | Naponta | Utolsó sikeres: 42 perce | Sikeres | 112.2 MB | DB + Konfig + Adatok | Fájlok visszaállítása | Teljes visszaállítás a másolatból | Beállítás | 3. mentés | Nincs beállítva | távoli (offsite) | Nincs távoli mentési cél beállítva | Beállítás | BookStack | Konfig + DB + Adatok | ▶ | 1. mentés | Auto | helyi | Utolsó: 5 perce | DB + Konfig + Adatok | 2. mentés | rsync | → hdd_1 | Naponta | Utolsó sikeres: 42 perce | Sikeres | 154.9 MB | DB + Konfig + Adatok | Fájlok visszaállítása | Teljes visszaállítás a másolatból | Beállítás | 3. mentés | Nincs beállítva | távoli (offsite) | Nincs távoli mentési cél beállítva | Beállítás | Docmost | Konfig + DB + A +=== restore points adventurelog / bookstack +{"ok":true,"data":[{"time":"2026-09-14T19:40:07Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}]} + +{"ok":true,"data":[{"time":"2026-09-14T19:40:07Z","short_id":"helyi","tier":1,"drive_label":"Belső SSD (rendszer)"}]} + diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/controller-backup-lines.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/controller-backup-lines.txt new file mode 100644 index 00000000..f710aa69 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/controller-backup-lines.txt @@ -0,0 +1,16 @@ +2026/09/14 19:42:48 [INFO] local-api: mount mp8 → /mnt/felhom-drives (storage=/mnt/felhom-drives, class=, backup=false) +2026/09/14 19:42:48 [INFO] local-api: mount mp9 → /etc/felhom-bootstrap (storage=/var/lib/felhom-agent/guests/9201/bootstrap, class=, backup=false) +2026/09/14 19:42:48 [INFO] local-api: mount mp0 → /var/lib/felhom (storage=local-lvm, class=, backup=true) +2026/09/14 19:42:48 [WARN] [appstop] crash recovery: an app-data backup (volume dump) (op "volume-dump:adventurelog") was interrupted and left 1 app(s) stopped — restarting them: [adventurelog] +2026/09/14 19:42:52 [INFO] [appstop] crash recovery: restarted adventurelog after the interrupted an app-data backup (volume dump) +2026/09/14 19:42:52 [INFO] [scheduler] Daily job db-dump scheduled for 2026-09-15 02:30 CEST +2026/09/14 19:42:52 [INFO] [scheduler] Registered periodic job: backup-cache (every 5m0s) +2026/09/14 19:42:52 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-09-15 03:30 CEST +2026/09/14 19:42:52 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-09-15 04:15 CEST +2026/09/14 19:42:53 [INFO] Event pushed: backup_failed (error) — an app-data backup (volume dump) was interrupted by a controller restart — 1 app(s) were left stopped and have been restarted +2026/09/14 19:42:57 [INFO] [backup] Found 6 DB dump files across drives +2026/09/14 19:42:58 [INFO] [backup] Discovered 5 databases +2026/09/14 19:42:58 [INFO] [backup] Discovered app data: 12 apps +2026/09/14 19:42:59 [INFO] [backup] Backup status cache refreshed +2026/09/14 19:43:48 [INFO] [bootrecon] boot window: budget 50s exhausted while the fleet was still changing — sweeping anyway +2026/09/14 19:43:48 [INFO] [bootrecon] Boot reconciliation: no boot-orphaned apps (nothing to start) diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/overview-after.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/overview-after.txt new file mode 100644 index 00000000..e73110c9 --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/overview-after.txt @@ -0,0 +1,18 @@ +=== /backups 19:45:41 + fragment 'megszakad' 0 + fragment 'sikertelen' 0 + fragment 'hiba' 2 + fragment 'Hiba' 0 + fragment 'nem sikerült' 0 + fragment 'interrupt' 0 + fragment 'failed' 0 +↗ | Biztonsági mentés | enkicsifelhom.hu | A rendszermentés jelenleg ugyanazon a lemezen van, mint a rendszer — így hibás fájlok ellen véd, lemezhiba ellen nem. Csatlakoztass egy második meghajtót a teljes védelemhez. | Ezt a meghajtót kijelölheted a rendszermentés helyéül — így egy lemezhiba után is vissza tudod állítani a rendszert. | Adatlemez | Kijelölöm | Tárhely áttekintés | Rendszer (/) | 23.0 GB / 68.7 GB (34%) | Adatlemez | 3.52 GB / 97.9 GB (4%) | DB mentések | 6 fájl | Rendszermentés (teljes mentés) | A teljes szerver — alkalmazások, beállítások és adatbázisok együtt — időszakos mentése, amelyből az egész készülék visszaállítható. Ezt a host-ügynök készíti és kezeli. | – | Utolsó teljes mentés | – | Méret / cél | Naprakész | Következő mentés | 0 órája — a mentési ablakon belül | – | Visszaállítás ellenőrizve | Még nem futott | Mentés most | Pillanatkép-mód: az alkalmazások csa +=== /dashboard 19:45:42 + fragment 'megszakad' 0 + fragment 'sikertelen' 0 + fragment 'hiba' 0 + fragment 'Hiba' 0 + fragment 'nem sikerült' 0 + fragment 'interrupt' 0 + fragment 'failed' 0 +↗ | Vezérlőpult | enkicsifelhom.hu | 16 | Futó alkalmazás | 0 | Leállítva | 57 | Összes alkalmazás | Memória | 3.8 GB / 12 GB (33%) | CPU | 15% | Load: 2.45 / 2.69 / 1.18 | Rendszer (/) | 23.0 GB / 68.7 GB (34%) | Adatlemez | 3.52 GB / 97.9 GB (4%) | Lemezek állapota | QEMU QEMU HARDDISK | Nincs adat | 0 °C | QEMU QEMU HARDDISK | Nincs adat | 0 °C | Biztonsági mentés | Utolsó mentés: | 2026-09-14 19:40 | Adatbázisok: | 6 mentve | Telepített alkalmazások | AdventureLog | Utazási napló és kalandtervező | Fut | Megnyitás | Napló | BookStack | Egyszerű, könyv-szerű wiki és dokumentáció platform | Fut | Megnyitás | Napló | Cloudflare Tunnel | Biztonságos internetkapcsolat — a szerver portnyitás nélkül érhető el kívülről. | Fut | Védett | Docmost | Modern wiki és dokumentáció platform (Notion-szerű) | Fut | Megnyitás | Napló | FileBrowser | Fájlkezelő — a tárhely fájljainak böngészése a böngés diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/units-on-disk.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/units-on-disk.txt new file mode 100644 index 00000000..85f580fc --- /dev/null +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/F2/units-on-disk.txt @@ -0,0 +1,37 @@ +== adventurelog +/mnt/sys_drive/felhom-data/backups/primary/adventurelog: +drwxr-xr-x 2 root root 4096 19:02:34 compose +drwxr-xr-x 2 root root 4096 19:40:07 db-dumps +-rw-r--r-- 1 root root 1385 19:02:34 manifest.json +drwxr-xr-x 2 root root 4096 19:00:35 volume-dumps + +/mnt/sys_drive/felhom-data/backups/primary/adventurelog/db-dumps: +-rw-r--r-- 1 root root 156311 19:40:07 adventurelog-postgres.sql + +/mnt/sys_drive/felhom-data/backups/primary/adventurelog/volume-dumps: +-rw-r--r-- 1 root root 2048 19:00:34 adventurelog_adventurelog_media.tar +-rw-r--r-- 1 root root 117450752 19:00:35 adventurelog_adventurelog_postgres_data.tar +"created_at": "2026-09-14T19:02:34Z" +== bookstack +/mnt/sys_drive/felhom-data/backups/primary/bookstack: +drwxr-xr-x 2 root root 4096 19:02:34 compose +drwxr-xr-x 2 root root 4096 19:40:07 db-dumps +-rw-r--r-- 1 root root 1247 19:02:34 manifest.json +drwxr-xr-x 2 root root 4096 19:00:48 volume-dumps + +/mnt/sys_drive/felhom-data/backups/primary/bookstack/db-dumps: +-rw-r--r-- 1 root root 67958 19:40:07 bookstack-mariadb.sql + +/mnt/sys_drive/felhom-data/backups/primary/bookstack/volume-dumps: +-rw-r--r-- 1 root root 1461248 19:00:47 bookstack_bookstack_config.tar +-rw-r--r-- 1 root root 160836096 19:00:48 bookstack_bookstack_db_data.tar +"created_at": "2026-09-14T19:02:34Z" +== vaultwarden +/mnt/sys_drive/felhom-data/backups/primary/vaultwarden: +drwxr-xr-x 2 root root 4096 19:02:34 compose +-rw-r--r-- 1 root root 1073 19:02:34 manifest.json +drwxr-xr-x 2 root root 4096 19:02:33 volume-dumps + +/mnt/sys_drive/felhom-data/backups/primary/vaultwarden/volume-dumps: +-rw-r--r-- 1 root root 756736 19:02:33 vaultwarden_vaultwarden_data.tar +"created_at": "2026-09-14T19:02:34Z" diff --git a/documentation/audits/evidence-bignight-2026-09-14/phase5/family-activity-F1.txt b/documentation/audits/evidence-bignight-2026-09-14/phase5/family-activity-F1.txt index 1445c164..22016ef0 100644 --- a/documentation/audits/evidence-bignight-2026-09-14/phase5/family-activity-F1.txt +++ b/documentation/audits/evidence-bignight-2026-09-14/phase5/family-activity-F1.txt @@ -253,3 +253,48 @@ 19:39:47 bookstack:ok5/fail0 mealie:ok5/fail0 nextcloud:ok1/fail0 19:39:52 bookstack:ok4/fail0 mealie:ok5/fail0 nextcloud:ok2/fail0 19:39:57 bookstack:ok5/fail0 mealie:ok5/fail0 nextcloud:ok2/fail0 +19:40:02 bookstack:ok5/fail0 mealie:ok5/fail0 nextcloud:ok2/fail0 +19:40:07 bookstack:ok4/fail0 mealie:ok4/fail0 nextcloud:ok2/fail0 +19:40:12 bookstack:ok3/fail0 mealie:ok3/fail0 nextcloud:ok1/fail0 +19:40:17 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail0 +19:40:22 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:40:27 bookstack:ok0/fail0 mealie:ok0/fail0 nextcloud:ok0/fail0 +19:40:32 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:40:37 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail0 +19:40:42 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:40:47 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:40:52 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:40:57 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:02 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:07 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:12 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:41:17 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:22 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:27 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:32 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:41:37 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:42 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:47 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:41:52 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:41:57 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:02 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:07 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:12 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:17 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:42:22 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:27 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:32 bookstack:ok0/fail1 mealie:ok0/fail1 nextcloud:ok0/fail1 +19:42:37 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail2 +19:42:42 bookstack:ok0/fail2 mealie:ok0/fail2 nextcloud:ok0/fail1 +19:42:47 bookstack:ok0/fail5 mealie:ok0/fail5 nextcloud:ok0/fail3 +19:42:52 bookstack:ok0/fail5 mealie:ok0/fail5 nextcloud:ok0/fail2 +19:42:57 bookstack:ok0/fail4 mealie:ok0/fail4 nextcloud:ok0/fail3 +19:43:02 bookstack:ok0/fail5 mealie:ok0/fail5 nextcloud:ok0/fail2 +19:43:07 bookstack:ok0/fail4 mealie:ok0/fail5 nextcloud:ok0/fail1 +19:43:12 bookstack:ok4/fail0 mealie:ok0/fail4 nextcloud:ok1/fail0 +19:43:17 bookstack:ok4/fail0 mealie:ok0/fail5 nextcloud:ok1/fail0 +19:43:22 bookstack:ok4/fail0 mealie:ok0/fail5 nextcloud:ok1/fail0 +19:43:27 bookstack:ok4/fail0 mealie:ok0/fail4 nextcloud:ok1/fail0 +19:43:32 bookstack:ok5/fail0 mealie:ok0/fail5 nextcloud:ok0/fail0 +19:43:37 bookstack:ok4/fail0 mealie:ok0/fail5 nextcloud:ok0/fail2 +19:43:42 bookstack:ok5/fail0 mealie:ok0/fail5 nextcloud:ok0/fail2 diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index e144757d..d8819c99 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -720,8 +720,9 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-514** | **[P2-MEDIUM] Paperless-ngx dies silently when a family uploads 20 documents at once: its worker is OOM-killed inside the catalog's 768 MB cap, 11 uploads fail, 8 wait forever, and the app still reads „Fut".** MEASURED 2026-09-14 (BIGNIGHT, VM 333, catalog paperless-ngx 2.20.15, `paperless-webserver` limit 805 306 368 B): 20 small 3-page PDFs posted through `/api/documents/post_document/` at 18:29:57Z. At 18:31:22Z the VM kernel logged `Memory cgroup out of memory: Killed process … (gs)` ×2, `([celeryd: celer)`, `([celery beat] -)` — constraint MEMCG of that container; `docker inspect` → `oomkilled=true restarts=0`. Paperless's own task list: **11 FAILURE (`WorkerLostError`), 1 STARTED, 8 PENDING**, unchanged 13 minutes later; **0 documents**. The controller shows the app running and healthy; no event, no alarm (`phase3/paperless-tasks.txt`, `paperless-oom-check.txt`). A household scanning a drawer of bills sees nothing arrive and no reason. **Fix shape:** raise the cap or set `PAPERLESS_TASK_WORKERS=1` / `PAPERLESS_THREADS_PER_WORKER=1` in the template, and let the dead-app/health check see an OOM-killed worker. | **READY — rank P2-MEDIUM; owner: CC (catalog)** | | **R-515** | **[P3-LOW] The Paperless-ngx app page tells the customer to log in with `admin / admin`, and that login does not exist: the deploy form generates the admin password.** MEASURED 2026-09-14 (BIGNIGHT, VM 333): `/apps/paperless-ngx` „Első lépések — Jelentkezz be: admin / admin" and „Alapértelmezett belépés admin / admin"; the catalog template generates `PAPERLESS_ADMIN_PASSWORD` (`password:16`) and the token call with the generated value succeeded (`phase3/seed-paperless.txt`). A household following the page is refused at its first login. Same card also sends documents to „FileBrowser … import/paperless" — the FileBrowser login is R-513. **Fix:** the card points at „Beállítások → Automatikusan generált értékek" as gokapi's does. | **READY — rank P3-LOW; owner: CC (catalog)** | | **R-516** | **[P3-LOW] English a customer meets on a fresh box and its apps' first screens — enumerated by the big night.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1, controller 0.242.0). Felhom-owned: (1) the dashboard menu item **„Debug"**; (2) the dashboard CPU tile **„Load: 0.29 / 0.39 / 0.37"**; (3) the launcher tile **„Filebrowser"** opens a login in English with no Felhom text (R-513); (4) the storage page mixes formal „Adjon hozzá / Csatlakoztasson" with the product's „te". App first screens a household meets before any Felhom text helps: (5) **Uptime Kuma 2.4 opens on „Which database would you like to use?"** (SQLite / Embedded MariaDB, „Next") — the app card's „Első lépések" does not mention it; (6) PrivateBin, Gokapi, AdventureLog and FileBrowser UIs are English (the apps' own). Already rows: the Proxmox installer screens (R-495, answered by the guide), `wiki.DOMAIN` (R-498). **Fix shape:** rename „Debug"/„Load" (controller); add the Uptime Kuma database step to its card, or pre-seed `db-config.json` for SQLite in the template (catalog). | **READY — rank P3-LOW; owner: CC (controller + catalog)** | -| **R-517** | **[P1-HIGH] After a failed off-site whole-system backup, „Biztonsági mentés" tells the customer the full backup is current and that a remote copy on separate hardware exists — neither is true.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, controller 0.242.0, customer `tester-1` with the DR tier ticked but never provisioned — R-511): „Mentés most" at 19:03:23Z; the local tier succeeded (8 877 619 753 B, 362 s); the `felhom-pbs` tier then failed — agent: `could not activate storage 'felhom-pbs': storage 'felhom-pbs' does not exist`; `pvesm status` lists only `local` and `local-lvm`. At 19:15:36Z `/backups` read: „✗ · **Utolsó teljes mentés 2026-09-14 21:09 (5 perce) · 0 B · Biztonsági szerver – külön hardver (PBS) · Naprakész**" and „✓ **Távoli rendszermentés — külön hardveren (PBS)**" (`phase4/backup-pages-after.txt`). The successful 8.9 GB local backup is no longer shown; a 0-byte failed attempt is labelled up to date; the remote tier is ticked as present. The CLAUDE.md rule „presence is not success" in page form: an attempt's timestamp stands in for a result. The hub did raise a true `whole_guest_backup_failed (error)` to the operator; the customer's page says the opposite. **Fix shape:** the tile shows the newest SUCCESSFUL backup per tier, a failed tier as failed, and a tier whose storage does not exist as „nincs beállítva". | **READY — rank P1-HIGH; owner: CC (controller)** | +| **R-517** | **[P1-HIGH] After a failed off-site whole-system backup, „Biztonsági mentés" tells the customer the full backup is current and that a remote copy on separate hardware exists — neither is true.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, controller 0.242.0, customer `tester-1` with the DR tier ticked but never provisioned — R-511): „Mentés most" at 19:03:23Z; the local tier succeeded (8 877 619 753 B, 362 s); the `felhom-pbs` tier then failed — agent: `could not activate storage 'felhom-pbs': storage 'felhom-pbs' does not exist`; `pvesm status` lists only `local` and `local-lvm`. At 19:15:36Z `/backups` read: „✗ · **Utolsó teljes mentés 2026-09-14 21:09 (5 perce) · 0 B · Biztonsági szerver – külön hardver (PBS) · Naprakész**" and „✓ **Távoli rendszermentés — külön hardveren (PBS)**" (`phase4/backup-pages-after.txt`). The successful 8.9 GB local backup is no longer shown; a 0-byte failed attempt is labelled up to date; the remote tier is ticked as present. The CLAUDE.md rule „presence is not success" in page form: an attempt's timestamp stands in for a result. The hub did raise a true `whole_guest_backup_failed (error)` to the operator; the customer's page says the opposite. **Fix shape:** the tile shows the newest SUCCESSFUL backup per tier, a failed tier as failed, and a tier whose storage does not exist as „nincs beállítva". **Also measured after F2's reboot (19:45:41Z):** the whole-system tile read „– · Utolsó teljes mentés – · Méret / cél · **Naprakész**" — no backup listed at all, still labelled up to date (the 21:03 CEST local success no longer shown). | **READY — rank P1-HIGH; owner: CC (controller)** | | **R-518** | **[P2-MEDIUM] „Mentés most" on the whole-system backup stops every app for about eight minutes while the page promises „csak néhány másodpercre".** MEASURED 2026-09-14 (BIGNIGHT, VM 333, 12 apps): the button's call quiesced all 12 stacks at 19:03:23Z (first stopped 19:03:27Z); the local vzdump ran 19:03:49 → 19:09:59Z; the controller then kept the apps stopped for the second (PBS) tier and restarted them at 19:10:09Z after it failed, the last started 19:11:12Z (`phase4/guest-backup-quiesce-log.txt`) — **≈ 7 m 45 s** with every app answering 404. The page under the button: „Pillanatkép-mód: az alkalmazások csak néhány másodpercre állnak le." A household pressing it at dinner loses every app for the length of the dump, and longer on a bigger box. **Fix shape:** state the real expected downtime (it scales with data), or quiesce per tier and not across a second tier's attempt; do not start a tier whose storage is absent (see R-517). | **READY — rank P2-MEDIUM; owner: CC (controller)** | +| **R-519** | **[P2-MEDIUM] After a backup torn by a power cut, an app's restore point carries the new database dump's time while its files are from the previous run — and no customer screen says the run was interrupted.** MEASURED 2026-09-14 (BIGNIGHT F2, VM 333): „Mentés most" 19:40:03Z; the power was cut 19:40:08Z while adventurelog was stopped for its volume dump. On disk afterwards, `backups/primary/adventurelog`: `db-dumps/adventurelog-postgres.sql` **19:40:07**, `volume-dumps/*.tar` **19:00:35**, `manifest.json created_at 19:02:34Z`; bookstack the same shape (sql 19:40:07, tars 19:00:48). `GET /api/backup/snapshots` for both → `time 2026-09-14T19:40:07Z, helyi` (`phase5/F2/units-on-disk.txt`, `backup-honesty.txt`). `/backups/apps` shows „Utolsó adatbázis mentés 2026-09-14 21:40 · … OK" and every app „Utolsó: 5 perce"; `/backups` and `/dashboard` contain no word of an interruption (fragments `megszakad|sikertelen|nem sikerült` = 0; control „hiba" appears in the standing warning text). The controller itself knew: `[appstop] crash recovery: an app-data backup (volume dump) … was interrupted … restarting them: [adventurelog]` and pushed `backup_failed (error)` to the hub. A household restoring „the 21:40 backup" gets 21:00 files for BookStack's uploads. **Fix shape:** date a point by the oldest part it contains (or mark it partial) and show the interrupted run on the backups page until the next complete one. | **READY — rank P2-MEDIUM; owner: CC (controller)** |