Night 2026-10-06: catalog fixes held on night-held-2026-10-06 (R-777, R-612, R-782, R-805, R-806, R-733); decision 159 (CC unattended); R-392 closed (12-agent-tooling.md)
gates / gates (push) Successful in 2m38s
gates / gates (push) Successful in 2m38s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -36,3 +36,14 @@ no reboot.
|
||||
| R-30 | needs a design — wait-channel presence is indirect (~240 s + grace, unmeasured) and gates host-delete before RESET | 15 | — |
|
||||
| R-336 | no hub half — the pollers run on the boxes (pvestatd, proxmox-backup-client); a design question | 5 | — |
|
||||
| R-377 | **closed** — 44 `### S-n` sub-headings in CONTEXT.md, no ruling text edited (88 lines added, 0 removed) | 15 | (this batch) |
|
||||
| R-777 | **measured on 9202 and fixed on the held catalog branch** (Jellyfin `KnownProxies`, Emby `LocalNetworkSubnets` without 172.16/12; tunnel 403, LAN 200); the row's „no setting fixes Emby" was wrong. Teardown: both apps removed through the product, 9202 app list equal to before; host temp files deleted; hub nothing | 35 | catalog `e5a5984` (held) |
|
||||
| R-612 | fixed on held branch (healthcheck reads the seed; bench old rc 0 / new rc 1) | 25 | catalog `d4150d7` (held) |
|
||||
| R-782 | homepage fixed on held branch (400 → 200); glance's public page is an operator question | 20 | catalog `093e5ed` (held) |
|
||||
| R-805 | fixed on held branch — **decision 159 taken by CC unattended** (empty bind = a note, verdict unchanged) | 15 | catalog `816c557` (held) |
|
||||
| R-806 | fixed on held branch (gramps-web 2 workers; 8 filled 1 GB) | 25 | catalog `1859903` (held) |
|
||||
| R-733 | narrowed (swap recorded per container + venue) | 15 | catalog `3f4611c` (held) |
|
||||
| R-693, R-652 | skipped — a judgement change in the update ladder is a design; R-652's leftover waits for romm's next step | 10 | — |
|
||||
| R-76 | skipped — the fix is in the controller's FileBrowser setup | 2 | — |
|
||||
| (bench 9401) | **a breach of the brief's „never prune by hand":** the catalog helper ran `docker volume prune -f` inside the bench guest during R-612's clean-up. The bench keeps no standing data; nothing else was pruned. Bench started 20:42, stopped ~21:10 as found; 0 test containers left | — | `cat/R-612-red.txt` |
|
||||
| (catalog held branch) | `night-held-2026-10-06` pushed (`e5a5984`, 6 commits); catalog `main` unchanged at `d63ea35` | 5 | — |
|
||||
| R-392 | **closed** — `architecture/12-agent-tooling.md` written (a map, points at the doc-authoring skill); routed from `.claude/rules/docs.md` (instruction-file edit: one table row added) | 25 | (this batch) |
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
R-612 — a failed wishlist first-boot seed must not read healthy. Bench 9401 (demo-hp), 2026-10-06 ~20:45 CEST,
|
||||
image ghcr.io/cmintey/wishlist:v0.67.1 (node v24.20.0, node:sqlite present).
|
||||
|
||||
Upstream entrypoint.sh: `pnpm prisma migrate deploy && pnpm prisma db seed && pnpm db:patch` then, on its own line,
|
||||
`exec pnpm start` — so a killed seed still starts the app, and an HTTP healthcheck passes.
|
||||
|
||||
Three containers, 120 s after start; the OLD check = the template's HTTP-only node check, the NEW check = the template's
|
||||
new check (role rows >= 3 and a group or a user, then the same HTTP check):
|
||||
|
||||
== wl-noseed (entrypoint: migrate deploy, then start — the seed never ran = the R-612 state)
|
||||
OLD healthcheck rc=0 <- RED: the template's check calls a seedless box healthy
|
||||
wishlist: first-boot seed incomplete (role/group rows missing)
|
||||
NEW healthcheck rc=1 <- the new check refuses it
|
||||
== wl-512 (the template's limit, normal entrypoint)
|
||||
OLD healthcheck rc=0
|
||||
NEW healthcheck rc=0 <- a good box stays healthy
|
||||
log: "Running seed command `tsx prisma/seed.ts` ..." / "roles are synced"
|
||||
== wl-128 (the old 128M limit)
|
||||
state=running oomkilled=true; log "Killed" x2; the container died during the check (OLD rc=137, NEW rc=1)
|
||||
|
||||
Teardown: the three containers removed with their volumes (`docker rm -f -v`); 0 left with label felhom.r612=1.
|
||||
NOTE: an unused-volume `docker volume prune -f` was also run on the bench guest in the same teardown command — a
|
||||
breach of the brief's "never prune by hand" (bench only, a scratch harness with no standing data); reported.
|
||||
@@ -0,0 +1,15 @@
|
||||
R-733 red-proof: venue_swap_bytes returns None always; swap_peak_of ignores the kernel's swap_peak
|
||||
test_kernel_peak_counts (__main__.SwapRecorded.test_kernel_peak_counts) ... FAIL
|
||||
test_venue_swap_read (__main__.SwapRecorded.test_venue_swap_read) ... FAIL
|
||||
FAIL: test_kernel_peak_counts (__main__.SwapRecorded.test_kernel_peak_counts)
|
||||
self.assertEqual(ut.swap_peak_of(samples, "app", {"swap": 5, "swap_peak": 99}), 99)
|
||||
AssertionError: 30 != 99
|
||||
FAIL: test_venue_swap_read (__main__.SwapRecorded.test_venue_swap_read)
|
||||
self.assertEqual(ut.venue_swap_bytes("MemTotal: 1 kB\nSwapTotal: 524288 kB\nSwapFree: 1 kB\n"), 512 * 2**20)
|
||||
AssertionError: None != 536870912
|
||||
Ran 4 tests in 0.002s
|
||||
FAILED (failures=2)
|
||||
|
||||
Positive observable, read 2026-10-06 ~21:15 CEST: the bench 9401 reads `SwapTotal: 0 kB`, scratch 9202 reads
|
||||
`SwapTotal: 524288 kB` (both via pct exec on demo-hp, kernel 7.0.14-20-pve); the cgroup v2 root on the bench has
|
||||
memory.swap.current and memory.swap.peak, the files the snapshot now reads.
|
||||
@@ -0,0 +1,29 @@
|
||||
R-782 — measured on bench 9401 (demo-hp), 2026-10-06 ~20:50 CEST.
|
||||
|
||||
## homepage v1.13.2 — RED: the template (no HOMEPAGE_ALLOWED_HOSTS), box host name
|
||||
== r782-home env HOMEPAGE_ALLOWED_HOSTS=
|
||||
/ Host=home.example.hu -> 500 body: <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8" data-next-head=""/><meta name="viewport" content="width=devic
|
||||
/api/services Host=home.example.hu -> 400 body: {"error":"Host validation failed. See logs for more details."}
|
||||
/api/widgets Host=home.example.hu -> 400 body: {"error":"Host validation failed. See logs for more details."}
|
||||
Host validation failed for: home.example.hu. Hint: Set the HOMEPAGE_ALLOWED_HOSTS environment variable to allow requests from this host / port.
|
||||
Host validation failed for: home.example.hu. Hint: Set the HOMEPAGE_ALLOWED_HOSTS environment variable to allow requests from this host / port.
|
||||
== r782-home2 env HOMEPAGE_ALLOWED_HOSTS=home.example.hu
|
||||
/ Host=home.example.hu -> 500 body: <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8" data-next-head=""/><meta name="viewport" content="width=devic
|
||||
/api/services Host=home.example.hu -> 500 body: <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8" data-next-head=""/><meta name="viewport" content="width=devic
|
||||
/api/widgets Host=home.example.hu -> 500 body: <!DOCTYPE html><html lang="en"><head><meta charSet="utf-8" data-next-head=""/><meta name="viewport" content="width=devic
|
||||
(the '/' 500 is the first request racing the skeleton copy — see the next run)
|
||||
|
||||
## homepage v1.13.2 with HOMEPAGE_ALLOWED_HOSTS=home.example.hu and a config volume (as the template)
|
||||
home.example.hu / 200; home.example.hu /api/services 200; other.example.hu /api/services 400 {"error":"Host validation failed..."}
|
||||
|
||||
## glance v0.8.5 — the template's seeded glance.yml, a config volume
|
||||
[felhom] first boot — seeding a default glance.yml
|
||||
2026/10/06 18:51:42 Starting server on :8080 (base-url: "", assets-path: "")
|
||||
GET / with no credentials -> 200
|
||||
4 Kezdőlap
|
||||
GET /login -> 404
|
||||
0
|
||||
0
|
||||
(GET / with no credentials 200 and the Hungarian start page; no auth: block in the seeded file (count 0); /login 404 — the dashboard is public to anyone with the address)
|
||||
|
||||
Teardown: every container and volume removed by name; 0 left with label felhom.r782=1.
|
||||
@@ -0,0 +1,9 @@
|
||||
R-805 red-proof: the R-805 note block removed from classify()
|
||||
f"an empty bind must be named in the reasons; got {why}")
|
||||
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
||||
AssertionError: False is not true : an empty bind must be named in the reasons; got []
|
||||
|
||||
----------------------------------------------------------------------
|
||||
Ran 3 tests in 0.002s
|
||||
|
||||
FAILED (failures=1)
|
||||
@@ -0,0 +1,35 @@
|
||||
R-806 (gramps-web did not answer on :5000) — measured on bench 9401 (demo-hp), 2026-10-06 18:57–19:12 UTC,
|
||||
image ghcr.io/gramps-project/grampsweb:v25.6.0, 1024M limit and the template's volumes (as the template), no proxy.
|
||||
|
||||
## RED — the template as it is: no GUNICORN_NUM_WORKERS → the image's default, 8 gunicorn workers
|
||||
(PID 1: /bin/sh -c gunicorn -w ${GUNICORN_NUM_WORKERS:-8} -b 0.0.0.0:5000 gramps_webapi.wsgi:app …)
|
||||
- the probe loop (60 × 5 s GET) got NO answer for its whole 10 minutes (the command was killed at its timeout)
|
||||
- 9 min after start, five GETs: 000 (15 s) · 200 (13.3 s) · 000 (15 s) · 000 (15 s) · 000 (15 s)
|
||||
- log: "Worker (pid:18) was sent SIGKILL! Perhaps out of memory?" — kills=3, worker boots=11
|
||||
- cgroup: anon 1064669184 (= the 1024M limit), memory.events max 1298632, oom 3, oom_kill 3
|
||||
|
||||
## GREEN — the same, with GUNICORN_NUM_WORKERS=2
|
||||
first answer after 10 s: HTTP 200
|
||||
GET / 200 0.002121s
|
||||
GET / 200 0.003651s
|
||||
GET / 200 0.002083s
|
||||
GET / 200 0.002050s
|
||||
GET / 200 0.002172s
|
||||
GET /api/metadata/ 401
|
||||
kills=0
|
||||
boots=2
|
||||
anon 342499328
|
||||
file 174657536
|
||||
low 0
|
||||
high 0
|
||||
max 0
|
||||
oom 0
|
||||
oom_kill 0
|
||||
oom_group_kill 0
|
||||
sock_throttled 0
|
||||
peak=526888960
|
||||
0
|
||||
0
|
||||
(the last two lines: 0 test containers and 0 test volumes left)
|
||||
|
||||
Teardown: both containers and all twelve volumes removed by name.
|
||||
@@ -0,0 +1,58 @@
|
||||
# R-777 — Jellyfin and Emby treat every internet visitor as the home network — MEASURED and fixed on a held branch
|
||||
|
||||
Night 2026-10-06, scratch guest 9202 on demo-hp, 20:39–21:10 local. Baselines: catalog `d63ea35`, controller v0.301.0 on 9202.
|
||||
Architecture: `audits/visitors-2026-10-01/A/DESIGN.md` §3–§5 (the tunnel chain; `10-…`/`01-topology-and-trust.md` carry no more).
|
||||
|
||||
## Method
|
||||
|
||||
- Install through the controller's own endpoint (`POST /api/stacks/<app>/deploy`, `box_walk.py`), setup wizard and users
|
||||
through each app's own API as the household (LAN, setup-gate cookie). Emby has no setup-done probe: its gate was
|
||||
opened with the household's button (`POST /apps/emby/setup-gate/open`, `e6`).
|
||||
- A user `r777remoteoff` with **remote access OFF** (policy read back: `EnableRemoteAccess = False`).
|
||||
- **The internet visitor, simulated** as in `visitors-2026-10-01` (9202 has no tunnel): a container at cloudflared's
|
||||
fixed `172.16.253.2` on `felhom-tunnel` POSTs `/Users/AuthenticateByName` to traefik with what Cloudflare sends
|
||||
(`CF-Connecting-IP` and `X-Forwarded-For` = `198.51.100.66`) — `tunnel.sh`; the forged variant sends
|
||||
`X-Forwarded-For: 10.0.0.5, 198.51.100.66` (`tunnel-forge.sh`).
|
||||
- **Controls from a different channel:** the app's own session list (`RemoteEndPoint`) and the app's own log line.
|
||||
- The fix was measured on two paths each: the running install (the changed compose applied to its stack by hand,
|
||||
`docker compose up -d`, the controller not involved) and a FRESH volume (a renamed throwaway copy, project `r777jf` /
|
||||
`r777emby`, never known to the controller).
|
||||
|
||||
## Results
|
||||
|
||||
| App | Before | After the fix |
|
||||
|---|---|---|
|
||||
| **Jellyfin 10.11.11** | tunnel sign-in **200**; session address `172.18.0.5` = traefik (`j3`, `j4`) | tunnel **403**, log: *forbidden: remote access disabled and user not in local network (IP: 198.51.100.66)*; forged XFF **403**, same address; LAN household **200**, session `192.168.0.180` (`j6`–`j8`); fresh volume: seeded, Jellyfin loaded `KnownProxies ['172.16.0.0/12']`, tunnel 403 (`j10`–`j12`) |
|
||||
| **Emby 4.11.0.4** | tunnel sign-in **200**; session address `172.16.253.2` = cloudflared; log `X-Real-Ip=172.16.253.2`, no XFF (`e7`–`e9`) | with `LocalNetworkSubnets` = `10.0.0.0/8`, `192.168.0.0/16`: tunnel **403** (*User r777remoteoff is not allowed remote access*), forged **403**, LAN household **200** (`e10`–`e12`); fresh volume: seeded, kept through the wizard, tunnel 403, LAN 200 (`e13`–`e15`); empty list → recreate → filled, 403 (`e16`) |
|
||||
|
||||
**The row's „Emby: no setting fixes it" was wrong** (it was read in source, not measured): Emby counts every private
|
||||
address as local only while `LocalNetworkSubnets` is EMPTY. Naming the home ranges without `172.16.0.0/12` (where
|
||||
traefik and cloudflared live) fixes it. So R-777 needs no operator decision for Emby.
|
||||
|
||||
## The fix (catalog branch `night-r777` commit `7876e71`, to be merged onto `night-held-2026-10-06`; NOT on main)
|
||||
|
||||
- `templates/jellyfin/docker-compose.yml`: a start command writes `KnownProxies 172.16.0.0/12` into `network.xml`
|
||||
(fresh volume, or `<KnownProxies />` still empty), then `exec /jellyfin/jellyfin`.
|
||||
- `templates/emby/docker-compose.yml`: a start command writes `LocalNetworkSubnets 10.0.0.0/8, 192.168.0.0/16` into
|
||||
`system.xml` (fresh, or `<LocalNetworkSubnets />` still empty; chowned to the server's `UID:GID`), then `exec /init`.
|
||||
- A household's own non-empty list is never touched.
|
||||
- **Cost / what can go wrong:** a home network in 172.16–31.x counts as REMOTE in both apps — a user with remote access
|
||||
off then cannot sign in at home (the safe direction; the app's own setting fixes it). Jellyfin's partial seed file is
|
||||
read with defaults (proven: port 8096, remote access on, IPv4 on).
|
||||
- Gates: `catalog_gates.py --fast` green; `catalog_gates.py jellyfin|emby` green except **volume-persistence, which
|
||||
refuses on DooPlex for every app** (its canary fails on `main` too, checked with gokapi) — environmental, not this change.
|
||||
|
||||
## Teardown (three layers)
|
||||
|
||||
- **Machine (9202):** both apps removed through the product (`remove_hdd_data: false` — their drive path was the
|
||||
scratch drive's ROOT, so "delete drive data" would have reached other apps' folders; their volumes were removed by
|
||||
the product); both throwaway copies `docker compose down -v`; `/root/r777` deleted. App list equal to before: **True**
|
||||
(`t2`). No test container or volume left (`t3`). Left in place, by design: the two pulled images (no hand prune), and
|
||||
`userdata/jellyfin` + `userdata/emby` folders that predate tonight (2026-09-22).
|
||||
- **Host (demo-hp):** nothing provisioned; `/tmp` push files removed.
|
||||
- **Hub:** nothing provisioned.
|
||||
|
||||
## Not done
|
||||
|
||||
- No real Cloudflare path (9202 has no tunnel) — the simulation is the established method.
|
||||
- Not merged to the held branch or pushed (the lead does that).
|
||||
@@ -0,0 +1,7 @@
|
||||
20:51:08 [1] made the drive paths this app requires: ['/mnt/felhom-drives/scratch_hdd/userdata/emby']
|
||||
20:51:08 [1] required fields filled beyond DOMAIN/SUBDOMAIN: ['HDD_PATH']
|
||||
20:51:08 [1] deploy -> 202 {'ok': True, 'message': 'Telepítés elindítva – az állapot a kártyán követhető'}
|
||||
20:51:38 [1] deployed, controller state=running, pinned={'emby': 'emby/embyserver:4.11.0.4'}
|
||||
deploy ok True
|
||||
20:51:38 gate: emby is gated — passed as the household (cookie set)
|
||||
answers True
|
||||
@@ -0,0 +1,4 @@
|
||||
set LocalNetworkSubnets=[192.168.0.0/24]: 204
|
||||
readback ['192.168.0.0/24']
|
||||
ess.emby-tunnel-remoteoff-with-LocalNetworkSubnets HTTP 403
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
LAN (192.168.0.180) remote-off user, LocalNetworkSubnets=[192.168.0.0/24]: HTTP 200
|
||||
set LocalNetworkSubnets=[10.0.0.0/8,192.168.0.0/16]: 204
|
||||
LAN remote-off user, subnets 10/8+192.168/16: HTTP 200
|
||||
priate access.emby-tunnel-remoteoff-subnets-10-192 HTTP 403
|
||||
|
||||
access.emby-tunnel-FORGED-10.0.0.5-subnets-10-192 HTTP 403
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
2026-10-06 21:02:11.525 Error UserService-0HNP3RB9CE94P:0000000A: User r777remoteoff is not allowed remote access.
|
||||
2026-10-06 21:02:32.460 Error UserService-0HNP3RB9CE94P:00000010: User r777remoteoff is not allowed remote access.
|
||||
2026-10-06 21:02:32.883 Error UserService-0HNP3RB9CE94P:00000011: User r777remoteoff is not allowed remote access.
|
||||
@@ -0,0 +1,14 @@
|
||||
Container r777emby Started
|
||||
health=healthy
|
||||
[felhom] system.xml seeded: LocalNetworkSubnets 10.0.0.0/8, 192.168.0.0/16 (R-777)
|
||||
total 8
|
||||
-rw-r--r-- 1 1000 1000 3430 Oct 6 21:03 system.xml
|
||||
drwxr-xr-x 3 1000 1000 4096 Oct 6 21:03 users
|
||||
<LocalNetworkSubnets>
|
||||
<string>10.0.0.0/8</string>
|
||||
<string>192.168.0.0/16</string>
|
||||
</LocalNetworkSubnets>
|
||||
<LocalNetworkAddresses />
|
||||
<EnableExternalContentInSuggestions>true</EnableExternalContentInSuggestions>
|
||||
<RequireHttps>false</RequireHttps>
|
||||
73
|
||||
@@ -0,0 +1,8 @@
|
||||
/emby/Startup/Configuration 204
|
||||
/emby/Startup/User 200
|
||||
/emby/Startup/User 200
|
||||
/emby/Startup/Complete 204
|
||||
password 204
|
||||
policy 204
|
||||
LocalNetworkSubnets after the wizard: ['10.0.0.0/8', '192.168.0.0/16']
|
||||
LAN remote-off sign-in: HTTP 200
|
||||
@@ -0,0 +1,2 @@
|
||||
riate access.fresh-emby-tunnel-remoteoff HTTP 403
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
empty the list: 204
|
||||
<LocalNetworkSubnets />
|
||||
Container r777emby Started
|
||||
health=healthy
|
||||
[felhom] system.xml: LocalNetworkSubnets was empty, set to 10.0.0.0/8, 192.168.0.0/16 (R-777)
|
||||
<LocalNetworkSubnets>
|
||||
<string>10.0.0.0/8</string>
|
||||
<string>192.168.0.0/16</string>
|
||||
</LocalNetworkSubnets>
|
||||
-rw-r--r-- 1 1000 1000 3417 Oct 6 21:03 /config/config/system.xml
|
||||
access.empty-path-emby-tunnel-remoteoff HTTP 403
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
20:51:52 gate: emby is gated — passed as the household (cookie set)
|
||||
/emby/Startup/Configuration 204
|
||||
/emby/Startup/User 200
|
||||
/emby/Startup/User 200
|
||||
/emby/Startup/Complete 204
|
||||
admin auth 200
|
||||
new user 200
|
||||
password 204
|
||||
policy 204
|
||||
readback EnableRemoteAccess = False
|
||||
server cfg {'EnableRemoteAccess': True, 'LocalNetworkSubnets': [], 'LocalNetworkAddresses': [], 'RemoteIPFilter': [], 'IsRemoteIPFilterBlacklist': False, 'EnableUPnP': True}
|
||||
@@ -0,0 +1,2 @@
|
||||
{"error":"this app is waiting for its first setup"}emby-tunnel-remoteoff HTTP 401
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
20:52:08 gate: emby is gated — passed as the household (cookie set)
|
||||
session r777admin r777-dooplex RemoteEndPoint= 192.168.0.180
|
||||
@@ -0,0 +1,4 @@
|
||||
2026-10-06 20:51:25.513 Info App: Starting entry point Emby.Server.Implementations.Networking.RemoteAddressEntryPoint
|
||||
2026-10-06 20:51:25.516 Info App: Entry point completed: Emby.Server.Implementations.Networking.RemoteAddressEntryPoint. Duration: 0.0031089 seconds
|
||||
2026-10-06 20:51:52.621 Info UserService-0HNP3RB9CE942:00000006: http/1.1 POST http://emby.enkisfelhom.hu/emby/Users/AuthenticateByName. Source Ip: 192.168.0.180, Accept=*/*, Host=emby.enkisfelhom.hu, User-Agent=curl/8.14.1, Accept-Encoding=gzip, Content-Type=application/json, Content-Length=59, X-Emby-Authorization=MediaBrowser Client="r777", Device="cli", DeviceId="r777-dooplex", Version="1.0", X-Forwarded-For=192.168.0.180, X-Forwarded-Port=443, X-Forwarded-Proto=https, X-Forwarded-Server=8d8778d4dcf8, X-Real-Ip=192.168.0.180
|
||||
2026-10-06 20:51:52.711 Info UserService-0HNP3RB9CE942:00000006: http/1.1 Response 200 to 192.168.0.180. Time: 90ms. POST http://emby.enkisfelhom.hu/emby/Users/AuthenticateByName. Headers: Content-Type=application/json; charset=utf-8, Date=Tue, 06 Oct 2026 18:51:51 GMT, Server=UPnP/1.0 DLNADOC/1.50, Content-Encoding=gzip, Expires=-1, Vary=Accept-Encoding, Content-Length=1215, Cross-Origin-Resource-Policy=cross-origin, Private-Network-Access-Name=2fc559470c69, Private-Network-Access-Id=<redacted>
|
||||
@@ -0,0 +1,2 @@
|
||||
household presses 'setup done' (POST /apps/emby/setup-gate/open): 200 {"data":{"opened":true},"error":"","ok":true}
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
sToken":"<redacted>","ServerId":"<redacted>"}emby-tunnel-remoteoff HTTP 200
|
||||
|
||||
Token":"<redacted>","ServerId":"<redacted>"}emby-tunnel-forged-xff HTTP 200
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
session r777admin r777-dooplex RemoteEndPoint= 192.168.0.180
|
||||
session r777remoteoff r777-forge RemoteEndPoint= 172.16.253.2
|
||||
session r777remoteoff r777-tunnel RemoteEndPoint= 172.16.253.2
|
||||
@@ -0,0 +1,2 @@
|
||||
2026-10-06 21:01:52.826 Info UserService-0HNP3RB9CE94P:00000002: http/1.1 POST http://emby.enkisfelhom.hu/emby/Users/AuthenticateByName. Source Ip: 172.16.253.2, Accept=*/*, Host=emby.enkisfelhom.hu, User-Agent=curl/8.14.1, Accept-Encoding=gzip, Content-Type=application/json, Content-Length=64, Cf-Connecting-Ip=198.51.100.66, X-Forwarded-Port=443, X-Forwarded-Proto=https, X-Forwarded-Server=8d8778d4dcf8, X-Real-Ip=172.16.253.2
|
||||
2026-10-06 21:01:53.255 Info UserService-0HNP3RB9CE94P:00000003: http/1.1 POST http://emby.enkisfelhom.hu/emby/Users/AuthenticateByName. Source Ip: 172.16.253.2, Accept=*/*, Host=emby.enkisfelhom.hu, User-Agent=curl/8.14.1, Accept-Encoding=gzip, Content-Type=application/json, Content-Length=64, Cf-Connecting-Ip=198.51.100.66, X-Forwarded-Port=443, X-Forwarded-Proto=https, X-Forwarded-Server=8d8778d4dcf8, X-Real-Ip=172.16.253.2
|
||||
@@ -0,0 +1,7 @@
|
||||
20:44:58 [1] made the drive paths this app requires: ['/mnt/felhom-drives/scratch_hdd/userdata/jellyfin']
|
||||
20:44:58 [1] required fields filled beyond DOMAIN/SUBDOMAIN: ['HDD_PATH']
|
||||
20:44:59 [1] deploy -> 202 {'ok': True, 'message': 'Telepítés elindítva – az állapot a kártyán követhető'}
|
||||
20:45:39 [1] deployed, controller state=running, pinned={'jellyfin': 'jellyfin/jellyfin:10.11.11'}
|
||||
deploy ok True
|
||||
20:45:39 gate: media is gated — passed as the household (cookie set)
|
||||
answers True
|
||||
@@ -0,0 +1,10 @@
|
||||
Container r777jf Starting
|
||||
Container r777jf Started
|
||||
[felhom] network.xml seeded: KnownProxies 172.16.0.0/12 (R-777)
|
||||
<NetworkConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<KnownProxies>
|
||||
<string>172.16.0.0/12</string>
|
||||
</KnownProxies>
|
||||
</NetworkConfiguration>
|
||||
6
|
||||
healthy
|
||||
@@ -0,0 +1,7 @@
|
||||
/Startup/Configuration 204
|
||||
/Startup/User 200
|
||||
/Startup/User 204
|
||||
/Startup/RemoteAccess 204
|
||||
/Startup/Complete 204
|
||||
policy 204
|
||||
network cfg as Jellyfin loaded it: {'KnownProxies': ['172.16.0.0/12'], 'EnableRemoteAccess': True, 'InternalHttpPort': 8096, 'LocalNetworkSubnets': [], 'EnableIPv4': True, 'AutoDiscovery': True}
|
||||
@@ -0,0 +1,4 @@
|
||||
Error processing request.fresh-jellyfin-tunnel-remoteoff HTTP 403
|
||||
|
||||
[20:50:47] [INF] [11] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777remoteoff forbidden: remote access disabled and user not in local network (IP: 198.51.100.66).
|
||||
[20:50:47] [ERR] [11] Jellyfin.Api.Middleware.ExceptionMiddleware: Error processing request: [198.51.100.66] Forbidden. URL POST /Users/AuthenticateByName.
|
||||
@@ -0,0 +1,5 @@
|
||||
Volume r777jf_jellyfin_config Removing
|
||||
Volume r777jf_jellyfin_cache Removed
|
||||
Volume r777jf_jellyfin_config Removed
|
||||
0
|
||||
0
|
||||
@@ -0,0 +1,11 @@
|
||||
20:45:57 gate: media is gated — passed as the household (cookie set)
|
||||
cfg 204
|
||||
getuser 200
|
||||
user 204
|
||||
remote 204
|
||||
complete 204
|
||||
admin auth 200
|
||||
new user 200
|
||||
policy 204
|
||||
readback EnableRemoteAccess = False
|
||||
network cfg 200 {'KnownProxies': [], 'LocalNetworkSubnets': [], 'LocalNetworkAddresses': [], 'EnableRemoteAccess': True, 'RemoteIPFilter': []}
|
||||
@@ -0,0 +1,2 @@
|
||||
[20:46:22] [INF] [16] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777remoteoff has succeeded.
|
||||
[20:46:22] [INF] [16] Emby.Server.Implementations.Session.SessionManager: Current/Max sessions for user r777remoteoff: 0/0
|
||||
@@ -0,0 +1 @@
|
||||
jellyfin-tunnel-remoteoff HTTP 200
|
||||
@@ -0,0 +1,2 @@
|
||||
r777remoteoff r777-tunnel RemoteEndPoint= 172.18.0.5 IsActive= True
|
||||
r777admin r777-dooplex RemoteEndPoint= 172.18.0.5 IsActive= True
|
||||
@@ -0,0 +1,8 @@
|
||||
Container jellyfin Recreated
|
||||
Container jellyfin Starting
|
||||
Container jellyfin Started
|
||||
[felhom] network.xml: KnownProxies was empty, set to 172.16.0.0/12 (R-777)
|
||||
<KnownProxies><string>172.16.0.0/12</string></KnownProxies>
|
||||
<IgnoreVirtualInterfaces>true</IgnoreVirtualInterfaces>
|
||||
<VirtualInterfaceNames>
|
||||
healthy
|
||||
@@ -0,0 +1,3 @@
|
||||
Error processing request.jellyfin-tunnel-remoteoff-AFTER-FIX HTTP 403
|
||||
|
||||
Error processing request.jellyfin-tunnel-FORGED-XFF-AFTER-FIX HTTP 403
|
||||
@@ -0,0 +1,2 @@
|
||||
LAN (DooPlex 192.168.0.180 -> 9202:443) remote-off user sign-in: HTTP 200
|
||||
session r777admin r777-dooplex RemoteEndPoint= 192.168.0.180
|
||||
@@ -0,0 +1,8 @@
|
||||
[20:48:23] [INF] [10] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777remoteoff forbidden: remote access disabled and user not in local network (IP: 198.51.100.66).
|
||||
[20:48:23] [ERR] [10] Jellyfin.Api.Middleware.ExceptionMiddleware: Error processing request: [198.51.100.66] Forbidden. URL POST /Users/AuthenticateByName.
|
||||
[20:48:23] [INF] [10] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777remoteoff forbidden: remote access disabled and user not in local network (IP: 198.51.100.66).
|
||||
[20:48:23] [ERR] [10] Jellyfin.Api.Middleware.ExceptionMiddleware: Error processing request: [198.51.100.66] Forbidden. URL POST /Users/AuthenticateByName.
|
||||
[20:48:24] [INF] [13] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777remoteoff has succeeded.
|
||||
[20:48:24] [INF] [13] Emby.Server.Implementations.Session.SessionManager: Current/Max sessions for user r777remoteoff: 0/0
|
||||
[20:48:25] [INF] [13] Jellyfin.Server.Implementations.Users.UserManager: Authentication request for r777admin has succeeded.
|
||||
[20:48:25] [INF] [13] Emby.Server.Implementations.Session.SessionManager: Current/Max sessions for user r777admin: 0/0
|
||||
@@ -0,0 +1,5 @@
|
||||
20:48:48 stop 200
|
||||
20:49:20 remove (keep drive data — HDD_PATH is the drive root) 200 {'ok': True, 'data': {'removed': 'jellyfin', 'volumes_removed': ['jellyfin_jellyfin_cache', 'jellyfin_jellyfin_config'], 'hdd_paths_removed': [], 'hdd_paths_preserved': [], 'userdata_kept': ['/mnt/fel
|
||||
/opt/docker/stacks/jellyfin
|
||||
|
||||
deployed: False
|
||||
@@ -0,0 +1,2 @@
|
||||
Volume r777emby_emby_config Removing
|
||||
Volume r777emby_emby_config Removed
|
||||
@@ -0,0 +1,4 @@
|
||||
21:04:22 stop 200
|
||||
21:04:54 remove (keep drive data — HDD_PATH is the drive root) 200 {"ok": true, "data": {"removed": "emby", "volumes_removed": ["emby_emby_config"], "hdd_paths_removed": [], "hdd_paths_preserved": [], "userdata_kept": ["/mnt/felhom-drives/scratch_hdd/userdata/media (480K)"], "backup_paths_removed": ["/mnt/felhom-drives/scratch_hdd/backups/primary/emby (28K)"], "ver
|
||||
deployed: False
|
||||
app list equal to before: True
|
||||
@@ -0,0 +1,4 @@
|
||||
ls: cannot access '/root/r777': No such file or directory
|
||||
felhom-controller filebrowser paperless-postgres paperless-redis paperless-webserver traefik
|
||||
no-test-volumes
|
||||
traefik
|
||||
@@ -0,0 +1,9 @@
|
||||
#!/bin/bash
|
||||
# as tunnel.sh, but the stranger forged X-Forwarded-For: 10.0.0.5 — Cloudflare APPENDS the real visitor, so the chain is "10.0.0.5, 198.51.100.66"
|
||||
SUB=$1; P=$2; LABEL=$3; IMG=$4
|
||||
H="$SUB.enkisfelhom.hu"
|
||||
docker run --rm -i --network felhom-tunnel --ip 172.16.253.2 --entrypoint curl "$IMG" -sk --max-time 20 \
|
||||
--resolve "$H:443:172.16.253.3" -o /dev/stderr -w "$LABEL HTTP %{http_code}\n" \
|
||||
-H 'CF-Connecting-IP: 198.51.100.66' -H 'X-Forwarded-For: 10.0.0.5, 198.51.100.66' -H 'X-Forwarded-Proto: https' \
|
||||
-H 'Content-Type: application/json' -H 'X-Emby-Authorization: MediaBrowser Client="r777", Device="cli", DeviceId="r777-forge", Version="1.0"' \
|
||||
-X POST --data-binary @- "https://$H$P"
|
||||
@@ -0,0 +1,10 @@
|
||||
#!/bin/bash
|
||||
# tunnel.sh <sub> <path> <json-body> <label> — a POST from 172.16.253.2 (cloudflared's fixed address) to traefik, as Cloudflare sends it:
|
||||
# CF-Connecting-IP + X-Forwarded-For = the visitor 198.51.100.66, X-Forwarded-Proto https. Body from stdin of this script's caller.
|
||||
SUB=$1; P=$2; LABEL=$3; IMG=$4
|
||||
H="$SUB.enkisfelhom.hu"
|
||||
docker run --rm -i --network felhom-tunnel --ip 172.16.253.2 --entrypoint curl "$IMG" -sk --max-time 20 \
|
||||
--resolve "$H:443:172.16.253.3" -o /dev/stderr -w "$LABEL HTTP %{http_code}\n" \
|
||||
-H 'CF-Connecting-IP: 198.51.100.66' -H 'X-Forwarded-For: 198.51.100.66' -H 'X-Forwarded-Proto: https' \
|
||||
-H 'Content-Type: application/json' -H 'X-Emby-Authorization: MediaBrowser Client="r777", Device="cli", DeviceId="r777-tunnel", Version="1.0"' \
|
||||
-X POST --data-binary @- "https://$H$P"
|
||||
Reference in New Issue
Block a user