the off-site tier works on the fresh box, and the photos are deleted for the test
gates / gates (push) Successful in 20s

The escrow ceremony ran (start re-authenticates, phase done, uploaded, sealed) and
the one-time recovery code was captured into a 0600 file at the moment it appeared —
it is shown once, the box stores it nowhere, and it appears in no committed file.

Tier 3 then reported „Sikeres restic → …your-storagebox.de · Helyreállítási egység,
titkosítva", and „Kulcsletétre vár" is gone. The restore wizard renders for Nextcloud,
which it only does for an app the store can actually restore — checked BEFORE
deleting anything, because deleting with an unproven copy is the harm itself.

Then the child's action: DELETE /Fotok -> 204, the folder 404s, the photo 404s.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 19:45:17 +02:00
parent a73abf04db
commit c5df1a372b
@@ -94,3 +94,133 @@
## So the chain stops at the APPLY step, because the agent's PBS-DR capabilities are switched off by
## configuration — not because ep0 refused anything. This morning's grant (R-534) is therefore still
## unproven end-to-end: nothing has yet asked ep0 to do the thing the grant allows.
## 2026-09-16T17:27:21Z THE ESCROW CEREMONY — the customer action that unpauses the off-site tier
POST /api/escrow/start -> 401 {"data":null,"error":"Hibás jelszó.","ok":false}
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
status: none False
POST /api/escrow/claim -> 404
fields returned: [] | ok= False | error= Nincs aktív helyreállítási folyamat — előbb indítsa el a kódkészítést.
## 2026-09-16T17:26:19Z THE ADOPT UNBLOCKED THE CEREMONY — escrow preflight, all six green:
## pbs_storage_id ok — „felhom-pbs"
## dr_tier ok — „DR tier applied"
## age_binary ok — /usr/bin/age
## hub_upload ok — hub upload target configured
## staged_secret ok — staged secret present
## sudo_grant ok — sudo grant listed (list-mode)
## Thirty-eight seconds after „pbsdr ADOPTED", the two red prerequisites went green on the box.
## escrow_state still „pending" — that is the ceremony not yet performed, which is the next step.
## THE CEREMONY RE-AUTHENTICATES, and that is right: `POST /api/escrow/start` with an empty body is
## refused 401 „Hibás jelszó." The one action that mints the last key to a household's backups asks
## for the dashboard password again, even inside an authenticated session. Recorded as a property,
## not a defect — my empty body was the error.
## 2026-09-16T17:33:09Z escrow ceremony, with the call the page itself makes (form-encoded password)
POST /api/escrow/start -> http=200 {"data":{"job_id":"escrow-1789579989860205159","phase":"running"},"error":"","ok":true}
phase=done claimable=True uploaded=True sealed=True
POST /api/escrow/claim -> http=200
claim fields: ['recovery_code']
RECOVERY CODE captured from 'recovery_code' into a 0600 file: 70 chars — value NOT printed
## THE CALL SHAPE, read from the page's own script so the next session does not guess it three times:
## POST /api/escrow/start
## Content-Type: application/x-www-form-urlencoded
## body: password=<the dashboard password> (the re-auth field is `reauth-password` in the UI)
## headers: X-CSRF-Token from the page's meta tag
## then poll GET /api/escrow/status until `claimable:true`, then POST /api/escrow/claim.
## (My first attempt sent an empty JSON body and was correctly refused 401 „Hibás jelszó.")
## 2026-09-16T17:33:41Z TIER-3 LEG, now that the key is escrowed
POST /backup/offbox/run -> 302
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:33:55Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
## 2026-09-16T17:33Z THE CEREMONY RAN, and the household now holds the last key to its backups:
## POST /api/escrow/start -> 200 {"job_id":"escrow-1789579989860205159","phase":"running"}
## status: phase=done · claimable=true · uploaded=true · restic_pw_sealed=true
## POST /api/escrow/claim -> 200, field `recovery_code`, 70 characters.
## The code was captured straight into a 0600 file at the moment it appeared. It is shown ONCE, the
## box stores it nowhere and Felhom does not know it — so the capture had to be right first time,
## and the off-site restore later in this phase depends on it. It appears in no committed file.
## ELAPSED: the whole chain — adopt (19:25:36 CEST) → descriptor applied on the box (19:26:19) →
## ceremony done (19:33) — took under eight minutes once the ep0 grant existed.
snapshots for nextcloud: {"ok":true,"data":[{"time":"2026-09-16T17:34:02Z","short_id":"helyi","tier":1,"drive_label":"Adatlemez"}]}
## 2026-09-16T17:4xZ THE OFF-SITE TIER IS WORKING ON THIS BOX — the app-backup page, verbatim:
## „Nextcloud · Adatlemez · 65.1 MB"
## „1. mentés Auto helyi Utolsó: 9 perce DB + Konfig"
## „Az alkalmazás fájljait a távoli másolat (és a második meghajtó) védi — …"
## „2. mentés … Nincs 2. (off-drive) másolat"
## „3. mentés Sikeres restic → u629488-sub4.your-storagebox.de Utolsó: 8 perce
## Helyreállítási egység, titkosítva"
## „Kulcsletétre vár" is GONE. So the chain that R-543 describes — off-site on by default, paused
## until the ceremony — completes the moment the ceremony is performed, and the sentence under the
## tier-1 row becomes true. What R-543 still records is that nothing ASKS the household to perform it.
## 2026-09-16T17:44:35Z F10 ON THE FRESH BOX — a child deletes the photo folder
before: GET nyaralas-1.jpg -> 200 (200 = the photo opens)
2026-09-16T17:44:36Z the child deletes the folder: DELETE /Fotok -> 204
after: PROPFIND /Fotok -> 404 (404 = gone)
after: GET nyaralas-1.jpg -> 404
trash right after the delete: 1
## THE OFF-SITE COPY EXISTS — checked BEFORE deleting anything, which is the whole point:
## GET /backups/restore/app?name=nextcloud -> 200, the wizard renders („Előkészítés · Megerősítés ·
## Végrehajtás · Eredmény"), and it renders ONLY for an app the store can actually restore
## (`resolveOffsiteRestoreApp` requires a restorable row — R-237's rule). Its two forms post to
## `/backup/offbox/restore` with `app` and `mode`.
## Local snapshots endpoint at the same moment: exactly one tier-1 point („helyi", 17:34:02Z) —
## it does not list tier 3, which is why the wizard, not that endpoint, is the check that matters.
## 2026-09-16T17:44:59Z THE OLD ROUTE (tier-1 restore) — it must REFUSE and touch nothing
app state BEFORE: nextcloud=running
redirect carried this message:
Ez a mentés nem tartalmazza az alkalmazás fájljait, ezért nem állítjuk vissza az adatbázist föléjük — a fájlok így a helyükön maradnak. A fájlok a távoli másolatból állíthatók vissza: Biztonsági mentés → Visszaállítás, „Teljes visszaállítás (fájlok + adatbázis)”.
app state AFTER (must be unchanged): nextcloud=running
trash still intact after the refusal (entries incl. root): 1