From c91c1377bc9e13290535adb3613ec8f6634befec Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 16 Sep 2026 19:50:05 +0200 Subject: [PATCH] =?UTF-8?q?THE=20PHOTOS=20OPEN=20=E2=80=94=20the=20backup?= =?UTF-8?q?=20promise=20is=20true=20on=20a=20box=20that=20installed=20itse?= =?UTF-8?q?lf=20today?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Five photos in, deleted the way a child would, and back again: HTTP 200 with bytes 200000/400000/600000/800000/1000000 and sha256 identical to the originals, five of five, with a negative control. Controls at the same moment: status.php 200, WebDAV 207. The two halves that make it honest: - the OLD route refused and touched nothing („a fájlok így a helyükön maradnak"), naming the route that could help; the app was running before and after; - the off-site restore ran in two steps — a verification copy that states „A meglévő adatok változatlanok", then a reconstitution whose message counts „5 fájl és 3 adatkötet és az adatbázis". This morning the same deletion ended with five photos listed, none of them openable, and a success message over the top. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .../phaseE-photos.txt | 81 +++++++++++++++++++ 1 file changed, 81 insertions(+) diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseE-photos.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseE-photos.txt index 6312241b..98891689 100644 --- a/documentation/audits/evidence-backup-promise-2026-09-16/phaseE-photos.txt +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseE-photos.txt @@ -224,3 +224,84 @@ Ez a mentés nem tartalmazza az alkalmazás fájljait, ezért nem állítjuk vissza az adatbázist föléjük — a fájlok így a helyükön maradnak. A fájlok a távoli másolatból állíthatók vissza: Biztonsági mentés → Visszaállítás, „Teljes visszaállítás (fájlok + adatbázis)”. app state AFTER (must be unchanged): nextcloud=running trash still intact after the refusal (entries incl. root): 1 +## 2026-09-16T17:45:46Z THE OFF-SITE FULL RESTORE — step 1: prepare (the wizard's own form) + POST /backup/offbox/restore mode=full confirm=1 -> 302 https://felhom.enkicsifelhom.hu/backups/restore/app?name=nextcloud&flash=A+t%C3%A1voli+vissza%C3%A1ll%C3%ADt%C3%A1s+elindult+%E2%80%94+az+%C3%A1llapot+itt+friss%C3%BCl. + {"ok":true,"data":{"running":false,"op":"offbox-restore","stack":"nextcloud","started_at":"2026-09-16T17:45:52.739901902Z","last":{"op":"offbox-restore","stack":"nextcloud","ok":true,"message":"A(z) nextcloud teljes mentése visszaállítva +## THE REFUSAL, ON A BOX WHERE THE OFF-SITE COPY EXISTS (2026-09-16T17:44:59Z) — and it points there: +## „Ez a mentés nem tartalmazza az alkalmazás fájljait, ezért nem állítjuk vissza az adatbázist +## föléjük — a fájlok így a helyükön maradnak. A fájlok a távoli másolatból állíthatók vissza: +## Biztonsági mentés → Visszaállítás, „Teljes visszaállítás (fájlok + adatbázis)"." +## app state BEFORE: nextcloud=running · AFTER: nextcloud=running — nothing was stopped. +## The wastebasket listing is unchanged by the refusal (1 href = the trash root, i.e. untouched). +## COMPARE WITH THIS MORNING, same app class, same action, before v0.244.0: +## „A(z) nextcloud: 3 adatkötet és az adatbázis visszaállítva — az alkalmazás újraindult." +## …after which the folder listed five photos and NONE of them opened, and the trash had become +## unreachable. The refusal is the whole difference between those two outcomes. +## 2026-09-16T17:46:33Z do the photos open? + controls first: status.php -> 200; WebDAV root -> 207 + folder: PROPFIND /Fotok -> 404 + GET nyaralas-1.jpg -> http=404 bytes=249 (expected 200000) + GET nyaralas-2.jpg -> http=404 bytes=249 (expected 400000) + GET nyaralas-3.jpg -> http=404 bytes=249 (expected 600000) + GET nyaralas-4.jpg -> http=404 bytes=249 (expected 800000) + GET nyaralas-5.jpg -> http=404 bytes=249 (expected 1000000) +## 2026-09-16T17:46:56Z THE OFF-SITE FULL RESTORE — step 2: reconstitute (put the files back) + POST /backup/offbox/reconstitute -> http=302 + still running… + still running… + op: offbox-reconstitute ok: True + message: A(z) nextcloud: 5 fájl és 3 adatkötet és az adatbázis visszaállítva (mentés: 2026-09-16 19:33) — az alkalmazás újraindult. + finished_at: 2026-09-16T17:47:46.353608527Z +## STEP 1 OF THE OFF-SITE RESTORE did exactly what it says and nothing more (17:46:12Z): +## „A(z) nextcloud teljes mentése visszaállítva ellenőrző mappába: +## /mnt/felhom-drives/adatlemez/backups/offsite-restore/nextcloud — a saját fájljaiddal együtt. +## A meglévő adatok változatlanok." +## Checked immediately after, with controls: status.php 200, WebDAV root 207 (so the app and the +## login work), /Fotok still 404 and every photo still 404 — i.e. the verification copy is on the +## drive and the LIVE app is untouched, which is precisely what „ellenőrző mappába" promises. +## A restore that silently changed the live app here would be the same class of lie R-538 fixed. +## 2026-09-16T17:49:02Z THE QUESTION THIS WHOLE TASK EXISTS FOR — do the photos open? + controls first: status.php -> 200; WebDAV root -> 207 + folder: PROPFIND /Fotok -> 207 + GET nyaralas-1.jpg -> http=200 bytes=200000 (expected 200000) + GET nyaralas-2.jpg -> http=200 bytes=400000 (expected 400000) + GET nyaralas-3.jpg -> http=200 bytes=600000 (expected 600000) + GET nyaralas-4.jpg -> http=200 bytes=800000 (expected 800000) + GET nyaralas-5.jpg -> http=200 bytes=1000000 (expected 1000000) +## STEP 2, THE RECONSTITUTION (17:47:46Z) — and note what the sentence now counts: +## „A(z) nextcloud: 5 fájl és 3 adatkötet és az adatbázis visszaállítva +## (mentés: 2026-09-16 19:33) — az alkalmazás újraindult." +## FIVE FILES — the customer's own photos — named in the outcome, beside the volumes and the +## database, and with the backup's own timestamp. This morning's local-tier message counted only +## „3 adatkötet és az adatbázis" and was true about the volumes while the photos were gone. +## 2026-09-16T17:49:27Z BYTE-IDENTITY — the downloaded photos against the ones that were uploaded + nyaralas-1.jpg IDENTICAL sha256 e2931047cf3244b3… + nyaralas-2.jpg IDENTICAL sha256 74dd287612e73136… + nyaralas-3.jpg IDENTICAL sha256 a25b0462dbed45f9… + nyaralas-4.jpg IDENTICAL sha256 91c135ab0df0774c… + nyaralas-5.jpg IDENTICAL sha256 eeb51f27a2586e7d… + identical: 5 of 5, differing: 0 + negative control (a file that must NOT match): e2931047cf3244b3 vs 74dd287612e73136 — different, as they must be + +## ============================================================================ +## THE WALK, END TO END, ON A BOX THAT INSTALLED ITSELF TODAY (2026-09-16) +## ============================================================================ +## 1. Five photos into Nextcloud through the app's own interface — 3 000 000 B, all PUT 201. +## 2. The tier-1 (local) leg ran; the tier-3 (off-site) leg was PAUSED at „Kulcsletétre vár" — the +## day-one gap R-543 records: off-site on by default is not yet off-site working. +## 3. The PBS-DR cascade completed only after the explicit „Re-issue PBS credentials" — the refusal +## R-511 describes, reproduced by itself, and the adopt then SUCCEEDED thanks to this morning's +## ep0 grant (R-534). Descriptor applied on the box 38 s later. +## 4. The household performed the escrow ceremony (re-auth required; code shown once, 70 chars, +## captured out-of-band). Tier 3 went „Sikeres — restic → …your-storagebox.de". +## 5. A child deleted the photo folder: DELETE 204, folder 404, photo 404. +## 6. THE OLD ROUTE REFUSED and touched nothing: „Ez a mentés nem tartalmazza az alkalmazás +## fájljait… a fájlok így a helyükön maradnak. A fájlok a távoli másolatból állíthatók vissza…" +## app running before AND after; the wastebasket unchanged. +## 7. The off-site restore, two steps: a verification copy („A meglévő adatok változatlanok"), then +## the reconstitution — „5 fájl és 3 adatkötet és az adatbázis visszaállítva". +## 8. THE PHOTOS OPEN: five GETs, http=200, bytes 200000/400000/600000/800000/1000000 — the exact +## sizes uploaded — with status.php 200 and WebDAV 207 as controls, and byte-identity checked +## against the originals above. +## THIS IS THE SENTENCE THE TASK EXISTED TO MAKE TRUE. This morning the same deletion ended with +## five photos listed and none of them openable, and a success message over the top of it.