diff --git a/documentation/audits/DRILL-prove-fixes-0243-2026-09-16.md b/documentation/audits/DRILL-prove-fixes-0243-2026-09-16.md index 477aab92..54bcafb1 100644 --- a/documentation/audits/DRILL-prove-fixes-0243-2026-09-16.md +++ b/documentation/audits/DRILL-prove-fixes-0243-2026-09-16.md @@ -39,7 +39,23 @@ Re-run with the amd64 template: `GOLDEN_VERSION=0.243.0`, Vouched as a three-field change — golden 0.243.0 + agent 0.131.0 + min agent 0.131.0 — hub logged `Artifact manifest set: agent=0.131.0 golden=0.243.0 min_agent="0.131.0" wrapper_sha=true`. -## Phase 1 — the walk +## Phase 1 — the walk, as a volunteer -_(in progress)_ +| # | step | what happened | time (UTC) | +|---|---|---|---| +| 1 | download from `felhom.eu/letoltes` | the page names `felhom-installer-1.27.1-pve9.2-1.iso`, 1 705 322 496 B, sha256 `25637007…c053`; the downloaded file matched **byte-for-byte** | 08:55–08:56 | +| 2 | install | boot menu default is the **graphical** entry (15 s). It IS drivable by keyboard (Tab moves focus, Enter presses), but each step needs a screenshot to see where focus is, so the walk switched to the **text-mode** entry — the other entry a volunteer is offered — and says so. Screens: EULA (English Proxmox), disk target **`/dev/sda 32 GiB` only** (the 100 GB data disk is never offered as the target), Hungary/Europe-Budapest/Hungarian prefilled (the keyboard was set to U.S. English **for typing only**), password + `mail@example.invalid` prefilled, host name prefilled `pve.example.invalid` (replaced with `tester1.enkicsifelhom.hu`), DHCP `192.168.0.128/24`, summary with **[X] Automatically reboot after successful installation** | 09:00–09:12 start | +| 2b | the reboot trap, measured | the automatic reboot **re-entered the installer**: a guest reboot reuses the running process's boot order, so a disk-first change made during the install does not apply. A volunteer with the stick still in sees the installer again. Cold stop + remove the stick + start → boots the installed system | 09:57 | +| 3 | first console screen | **Felhom-only, Hungarian, no admin URL** (`8006` 0 occurrences): „Felhom otthoni szerver … Ezen a gépen most nincs dolgod … Párosító kód: 37S-NFE … Nyisd meg az e-mailben kapott linket". The hub's Hosts page lists the same box as an unclaimed appliance with the same code | 09:58 | +| 4 | the connect mail + bind | **O1 (pre-declared, not counted):** the operator's „Send self-bind link" pressed once — the customer was already waiting when the automatic trigger shipped. Mail arrived at **09:59:56Z** to `tester1@felhom.eu`, subject „Kösd össze a Felhom dobozodat", naming the two things to enter and the 7-day / 5-attempt limits. The bind page took the pairing code + owner passphrase and answered **„Sikeres összekötés."** | 09:59:55 → 10:01:14 | + +| 5 | „ready" | the hub served **agent 0.131.0 / golden 0.243.0** (this run's own bake) at 09:01:59Z; the guest came up and the controller announced itself: `controller_started (0.243.0)` at 10:03:30Z. The box's first host-report carrying a guest: 10:17:16Z (1 guest, 2 storage targets, 1 backup) | 10:01–10:17 | +| 6 | **the tunnel from outside** (R-510) | three GETs from DooPlex to `https://felhom.enkicsifelhom.hu` → **302 ×3 (cloudflare)**, following → **200** on „A szerver beállítása" — no 502, no 530. **R-510 CLOSED** | 10:04:19–25 | +| 6b | claim | the setup-code mail („Új beállító kód — újratelepült a szervered", 10:01:57Z, 72 h) + a new dashboard password → **302 → /**. First try refused with „Érvénytelen űrlap": the field names are `code` / `new_password` / `confirm_password` | 10:06:18 | +| 7 | **the off-site tier** (R-511 → **R-534**) | the WG hook refused exactly as R-511 describes; **O2 pressed** → hub v0.114.0's ADOPT path ran and the ENDPOINT refused: `status 255 … missing Datastore.Modify on /datastore/felhom-offsite` → 502, nothing written (fail-closed). So the adopt fix is sound and **inert until the ep0 grant is fixed** — new row **R-534 (P1)**. The box therefore has **no** whole-guest off-site tier | 10:02:15 / 10:03:29 | +| 8 | **the file manager** (R-513 on a FRESH box) | the app page shows „Kezdeti belépési adatok — Felhasználónév admin … A jelszót a Felhom állította be ezen a gépen"; reveal → 200, 16 chars; through the tunnel `files.enkicsifelhom.hu`: revealed **200**, `admin`/`admin` **401**, wrong **401** — and admin/admin was already 401 on a probe taken BEFORE any dashboard action | 10:06:43 | +| 8b | the data drive | „Nincs regisztrált adattároló" on arrival; the wizard formatted and registered `/dev/sdb` as „Adatlemez" (`/mnt/felhom-drives/adatlemez`, default, 97.9 GB) in ~2 s. **Two refusals worth recording:** the mount name rejects accented letters („érvénytelen csatlakoztatási név"), which is the first thing a Hungarian volunteer types, and the API needs `mount_name`, not `label` | 10:20 | +| 11 | **the backup page** (R-517 on a FRESH box) | per tier: „Helyi tároló (local) ✓ Utolsó sikeres mentés: 2026-09-16 12:08 · 624.3 MB · Naprakész"; „Biztonsági szerver – külön hardver (PBS) **nincs beállítva**"; the remote tile „Távoli rendszermentés **nincs beállítva**" (not ticked); the button says „A mentés alatt az alkalmazások leállnak — általában néhány perc, nagyobb adatnál több." | 10:22 | + +_(steps 9–12 continue: the four apps, their cards, the manual backup)_ diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-apps.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-apps.txt new file mode 100644 index 00000000..dac2aaa5 --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-apps.txt @@ -0,0 +1,6 @@ +## 2026-09-16T10:21:17Z deploying four apps on the fresh box (HDD_PATH=/mnt/felhom-drives/adatlemez) + 2026-09-16T10:21:17Z privatebin deploy http=202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + 2026-09-16T10:21:38Z vaultwarden deploy http=202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + 2026-09-16T10:21:58Z paperless-ngx deploy http=202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + 2026-09-16T10:22:18Z nextcloud deploy http=202 {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"} + 2026-09-16T10:23:29Z nextcloud=starting paperless-ngx=starting privatebin=running vaultwarden=running diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-backups.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-backups.txt new file mode 100644 index 00000000..9ffc45e8 --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-backups.txt @@ -0,0 +1,3 @@ +## whole-system section (fresh box, off-site NOT provisioned — R-534): +Rendszermentés (teljes mentés) A teljes szerver — alkalmazások, beállítások és adatbázisok együtt — időszakos mentése, amelyből az egész készülék visszaállítható. Ezt a host-ügynök készíti és kezeli. ✓ Utolsó teljes mentés 2026-09-16 12:08 (14 perce) 624.3 MB Helyi tároló (local) Naprakész Következő mentés 0 órája — a mentési ablakon belül – Visszaállítás ellenőrizve Még nem futott Helyi tároló (local) ✓ Utolsó sikeres mentés: 2026-09-16 12:08 (14 perce) · 624.3 MB Naprakész Biztonsági szerver – külön hardver (PBS) nincs beállítva Mentés most A mentés alatt az alkalmazások leállnak — általában néhány perc, nagyobb adatnál több. +## remote tile: s – Távoli rendszermentés nincs beállítva diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-filebrowser.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-filebrowser.txt new file mode 100644 index 00000000..ba2b931e --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-filebrowser.txt @@ -0,0 +1,3 @@ +## 2026-09-16T10:06:43Z public file-manager probe BEFORE any dashboard action (control): + X-Password=admin -> 401 + X-Password=wrong-pw-x -> 401 diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-install.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-install.txt index 947274ab..67c554f6 100644 --- a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-install.txt +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-install.txt @@ -5,3 +5,24 @@ ide2: local:iso/felhom-installer-1.27.1-pve9.2-1.iso,media=cdrom,size=1665354K ## 2026-09-16T09:12:16Z INSTALL started (text mode, summary as captured in screens/24) ## 2026-09-16T09:12:50Z box answers on 192.168.0.128 (installed and booted) ## CORRECTION 2026-09-16T09:13:39Z: the '09:12:50Z box answers on 192.168.0.128' line is WRONG — the INSTALLER's live system already holds that address, so the ping proved nothing about the install. Install progress is read from the console instead. +## 2026-09-16T09:57:39Z FINDING: after the install's automatic reboot the VM re-entered the INSTALLER — a guest reboot reuses the running QEMU process's boot order (ide2 first), so the disk-first change made mid-install did not apply. The install itself had completed. Cold stop + CD detach + start follows. +update VM 334: -delete ide2 +update VM 334: -boot order=scsi0 +boot: order=scsi0 +status: running +## First-boot console, verbatim (screens/30-first-boot.png), 2026-09-16 ~09:58Z — Felhom-only, Hungarian, no admin URL: + Felhom otthoni szerver + Ezen a gépen most nincs dolgod, és bejelentkezni sem kell. + A beállításhoz kövesd a Felhomtól kapott útmutatót. + tester1 login: + ================================================== + Felhom — a doboz készen áll, és a párosításra vár. + Párosító kód: 37S-NFE + Nyisd meg az e-mailben kapott linket, és add meg + ezt a kódot és a Tulajdonosi jelmondatodat + (az 5 szót a Felhom üzemeltetőjétől kaptad). + Ez a képernyő magától frissül — nincs teendő a + doboznál, és nyugodtan itt hagyhatod bekapcsolva. + ================================================== + ASCII-fragment checks: "8006" 0 occurrences (no Proxmox admin URL); "Tulajdonosi jelmondat" present; negative control "Visszaallito" 0. +## Hub Hosts page, same moment: "Unclaimed appliances … Appliance d7fc0d50-f6ad-43c8-a2e8-8c6941335908 | Pairing code 37S-NFE | MAC bc:24:11:bf:69:6d | Standard PC (i440FX + PIIX, 199…" diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-pbsdr.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-pbsdr.txt new file mode 100644 index 00000000..2b99fea1 --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-pbsdr.txt @@ -0,0 +1,9 @@ +## 2026-09-16T10:03:28Z O2 (pre-declared, NOT counted): the WG hook refused and advised it — pressing 'Re-issue PBS credentials' for tester-1 (R-511 live test) +HTTP/1.1 502 Bad Gateway +2026/09/16 12:02:15 [ERROR] pbsdr auto-provision for tester-1 (WG-registration hook): the endpoint already holds a PBS token for tester-1 but the hub has no descriptor — use the explicit "Re-issue PBS credentials" action — save the customer config to retry +2026/09/16 12:03:29 [ERROR] pbsdr adopt for tester-1: endpoint re-issue: tenantsync: remote op failed: Process exited with status 255 (stderr: Error: permission check failed +2026/09/16 12:03:29 [ERROR] pbsdr adopt for tester-1: endpoint re-issue: tenantsync: remote op failed: Process exited with status 255 (stderr: Error: permission check failed +Error: permission check failed - missing Datastore.Modify on /datastore/felhom-offsite) +2026/09/16 12:03:30 [INFO] Event from tester-1: controller_started (info) — Controller elindult (0.243.0) +2026/09/16 12:03:30 [INFO] DR-recipe app-half stored for customer tester-1 (v1) +2026/09/16 12:03:30 [INFO] Received report from tester-1 (2261 bytes) diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-provision.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-provision.txt new file mode 100644 index 00000000..fe0946da --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-provision.txt @@ -0,0 +1,31 @@ +## 2026-09-16T10:01:44Z bind done; watching the box set itself up +## 2026-09-16T10:02:10Z inside the box (operator path, root password from the install): +Permission denied, please try again. +## 2026-09-16T10:02:14Z host record on the hub: tester-1-652049 +2026/09/16 12:01:56 [INFO] host enrolled: tester-1-652049 (customer tester-1) +2026/09/16 12:01:56 [INFO] claim reenroll email sent to the registered address of tester-1 +2026/09/16 12:01:56 [INFO] [claim] reenroll code (gen 3) emailed to the registered address of tester-1 +2026/09/16 12:01:56 [INFO] [claim] reset code re-issued (gen 3) for tester-1 on box re-enrollment (clean-slate reinstall) +2026/09/16 12:02:14 [INFO] wg registered: host=tester-1-652049 pubkey=8Eaq0bPjRBLDfdtHzaVD8trl4NxeJ8toCQshtcDhbkA= ip=10.77.0.5/32 changed=true gen=1 sync=ok +## 2026-09-16T10:02:49Z OBSERVATION: root SSH with the password typed during the install is REFUSED after the bind ("Permission denied") — consistent with the universal-ISO flow rotating the box credential once the hub claims it. The volunteer path needs no SSH; operator shell access is the hub-vaulted break-glass credential. +## 2026-09-16T10:03:05Z hub lines for tester-1 (WG + pbsdr + claim + floor): +2026/09/16 12:01:20 [INFO] appliance credentials DELIVERED once to appliance 29 (customer=tester-1 mode=appliance; passphrase withheld) +2026/09/16 12:01:28 [INFO] Config downloaded for customer tester-1 +2026/09/16 12:01:56 [INFO] host enrolled: tester-1-652049 (customer tester-1) +2026/09/16 12:01:56 [INFO] claim reenroll email sent to the registered address of tester-1 +2026/09/16 12:01:56 [INFO] [claim] reenroll code (gen 3) emailed to the registered address of tester-1 +2026/09/16 12:01:56 [INFO] [claim] reset code re-issued (gen 3) for tester-1 on box re-enrollment (clean-slate reinstall) +2026/09/16 12:01:57 [INFO] vaulted break-glass recovery credential for host tester-1-652049 (user=root@pam, secret 32 chars) +2026/09/16 12:01:59 [INFO] Artifact manifest served for customer tester-1 (agent=0.131.0 golden=0.243.0) +2026/09/16 12:01:59 [INFO] Config downloaded for customer tester-1 +2026/09/16 12:02:14 [INFO] wg registered: host=tester-1-652049 pubkey=8Eaq0bPjRBLDfdtHzaVD8trl4NxeJ8toCQshtcDhbkA= ip=10.77.0.5/32 changed=true gen=1 sync=ok +2026/09/16 12:02:14 [INFO] host-report from tester-1-652049 (0 guests, 2 storage targets, 0 backups, 0 restore-tests, 0 pbs-snapshots, 10228 bytes) +2026/09/16 12:02:14 [INFO] DR-recipe host-half stored for customer tester-1 (host tester-1-652049, v1) +2026/09/16 12:02:15 [ERROR] pbsdr auto-provision for tester-1 (WG-registration hook): the endpoint already holds a PBS token for tester-1 but the hub has no descriptor — use the explicit "Re-issue PBS credentials" action — save the customer config to retry +2026/09/16 12:02:15 [INFO] Config downloaded for customer tester-1 +2026/09/16 12:03:04 [INFO] restore-test staleness: tester-1 local tier: not restore-proven yet, but only watching for 0s (grace 168h0m0s since first contact 2026-09-16T10:02:14Z) — newborn, not a fault +[Controller] …s Hosts Offsite Configuration ← All Customers Tester 1 Last report: 1 min ago · Controller 0.243.0 Auto-refresh (paused) Tester 1 ok Controller 0.243.0 Last report 1 min ago Containers 0/0 Overview Applications Setup Edit Backup & DR Events… +[Guests] …d Generation 1 Vitals CPU 0% Memory 20% Disk (root fs) 31% Cloudflared inactive Guests 0/0 running Guests No guests reported on this host. Storage Targets Name Role Type State Fill Thin Pool SMART Temp Wear local — local attached 31% — UNKN… +[0.243.0] …site Configuration ← All Customers Tester 1 Last report: 1 min ago · Controller 0.243.0 Auto-refresh (paused) Tester 1 ok Controller 0.243.0 Last report 1 min ago Containers 0/0 Overview Applications Setup Edit Backup & DR Events Notificati… +[Agent] …ter-1-652049 → tester-1-652049 ONLINE Host ID tester-1-652049 Customer Tester 1 Agent Version 0.131.0 PBS wrapper matches vouched 104db0a4401f… Enrolled 3 min ago Last Report 2 min ago Desired Generation 1 Vitals CPU 0% Memory 20% Disk (roo… +## 2026-09-16T10:17:40Z 2026/09/16 12:17:16 [INFO] host-report from tester-1-652049 (1 guests, 2 storage targets, 1 backups, 0 restore-tests, 0 pbs-snapshots, 11172 bytes) diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-selfbind.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-selfbind.txt new file mode 100644 index 00000000..ff04557d --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-selfbind.txt @@ -0,0 +1,16 @@ +## 2026-09-16T09:59:55Z O1 (pre-declared, NOT counted): pressing 'Send self-bind link' for tester-1 +HTTP/1.1 303 See Other +Location: /customers/tester-1?flash=selfbind-sent#tab=setup +2026/09/16 11:59:55 [INFO] self-bind link emailed to the registered address of tester-1 +2026/09/16 11:59:55 [INFO] self-bind link (hash 64147e55…, valid 7 days) emailed to the registered address of tester-1 +## 2026-09-16T10:01:14Z bind POST: HTTP/2 200 +Sikeres összekötés. +## MISTAKE, stated (2026-09-16): while looking for the owner passphrase's markup, a masking pass that only covered +## element TEXT printed the hub operator page's `data-secret="…"` ATTRIBUTE into the session transcript — i.e. the +## `tester-1` owner passphrase was echoed once. It was not written to any file here and is not in this repo. The +## passphrase is a TESTER record's, not a paying customer's. Standing rule reaffirmed: mask attributes too, and read +## secrets file→file (scripts/read_credential.py) rather than by grepping a page. +## The connect mail (redacted), 2026-09-16 09:59:56Z, to tester1@felhom.eu, subject "[Felhom] Kösd össze a Felhom dobozodat": +## "Elkészült a Felhom dobozod, és készen áll az összekötésre. … https://hub.felhom.eu/bind/ … +## 1. A párosító kódot, amely a doboz képernyőjén (a monitoron) látható. +## 2. A tulajdonosi jelmondatodat (az 5 szóból álló kifejezést) … A hivatkozás 7 napig érvényes. … 5 sikertelen próbálkozás után zárolódik" diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-storage.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-storage.txt new file mode 100644 index 00000000..14553d07 --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-storage.txt @@ -0,0 +1,22 @@ +[Meghajt] …d(c);document.body.appendChild(o);} Indítópult Vezérlőpult Alkalmazások Tárhely Meghajtók Hálózati tárhely Biztonsági mentés Áttekintés Távoli mentés Alkalmazások Visszaállítás Megosztás Hálózati megosztás Rendszermonitor Debug Beállítások Rendszer Értesítések Biztonság és hozzáférés 0.243.0 Kijelentkezés ↗ Tárhely — Meghajtók Adattárolók… +[Tárhely] … Tárhely — Felhom.eu document.documentElement.className=document.documentElement.className.replace('no-js','js'); function csrfHeaders(){var el=document.querySelector('meta[name="csrf-token"]');return el?{'X-CSRF-Token':el.content}:{};} function felhomConfirm(e… +[Nincs] … — Meghajtók Adattárolók Külső meghajtók kezelése alkalmazásadatok tárolásához. Nincs regisztrált adattároló. Adjon hozzá egyet az alábbi űrlappal. Adatok áthelyezése … function migFmtGB(b){ return (Number(b||0)/1e9).toFixed(1)+' GB'; } function migRender(job){ var names={stop:'Alkalmazások leállítása',copy:'Adatok másolása',verify:'Ellen… +[Csatlakoztat] …lementById('storage-actions-' + path); if (actionsDiv) actionsDiv.innerHTML = ' Csatlakoztatás... '; fetch('/api/storage/reconnect', { method: 'POST', headers: Object.assign({'Content-Type': 'application/json'}, csrfHeaders()), body: JSON.stringify({where: path}) }).then(function(r) { return r.json(); }).then(function(data) { if (data.ok)… +## 2026-09-16 ~10:07Z, fresh box, before the volunteer adds a drive: +## Tárhely → Meghajtók: "Nincs regisztrált adattároló. Adjon hozzá egyet az alábbi űrlappal." +## (note the formal „Adjon hozzá" — the product's voice elsewhere is „te"; already filed as R-516 item 4) +## Dashboard nav renders Hungarian; the controller version badge reads 0.243.0. +status: {"data":{"phase":"idle"},"ok":true} +## 2026-09-16T10:19:30Z drive init, second attempt with an ASCII name: + init http=400 +{"error":"érvénytelen csatlakoztatási név (csak betűk, számok, _ és - engedélyezett)","ok":false} + + final status: {"data":{"phase":"idle"},"ok":true} + drives now: [] +## 2026-09-16T10:20:37Z drive init with the page's own body keys (mount_name/label/set_default): + init http=200 +{"data":{"phase":"formatting","started":true},"ok":true} + + status: {"data":{"device":"/dev/sdb","durable_id":"","error":"","opsign":"","phase":"done","reason":"","started_at":"2026-09-16T10:20:38.042865651Z","updated_at":"2026-09-16T10:20:39.78961511Z","where":"/mnt/felhom-drives/adatle + drive: eb40c1dd-1276-4a5a-967a-f9515cfa9d3d usb attached /mnt/adatlemez 105.1 GB + storage page: zzáférés 0.243.0 Kijelentkezés ↗ Tárhely — Meghajtók Adattárolók Külső meghajtók kezelése alkalmazásadatok tárolásához. Adatlemez /mnt/felhom-drives/adatlemez Alapértelmezett Aktív 0.0 GB / 97.9 GB ext4 · /dev/sdb[/felhom-data] · QEMU HARDDISK Nincs alkalmazás ezen a tárolón Új telepítések letiltása Végleges leszerelés Adatok áthelyezése diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/phase1-tunnel.txt b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-tunnel.txt new file mode 100644 index 00000000..86510cb2 --- /dev/null +++ b/documentation/audits/evidence-drill-0243-2026-09-16/phase1-tunnel.txt @@ -0,0 +1,18 @@ +## 2026-09-16T10:04:19Z R-510 — three GETs from DooPlex to the customer's own address, with a box connected: + 2026-09-16T10:04:19Z http=302 server=cloudflare bytes=29 + 2026-09-16T10:04:22Z http=302 server=cloudflare bytes=29 + 2026-09-16T10:04:25Z http=302 server=cloudflare bytes=29 + body fragments: claim +## 2026-09-16T10:04:53Z following the redirect (the volunteer's landing page): + final http=200 bytes=2525 url_path=https://felhom.enkicsifelhom.hu/claim + page text (first 500 chars): + A szerver beállítása — Felhom A szerver beállítása Tester 1 Add meg az e-mailben kapott beállító kódot, majd válassz saját jelszót a vezérlőpult védelméhez. Beállító kód Új jelszó (min. 12 karakter) Új jelszó megerősítése Beállítás és belépés Nem kaptad meg a kódot? Új kód kérése Felhom — Otthoni szerver kezelés felhom.eu + ASCII-fragment checks: "Beall" = 2 | "kod" = 4 | negative control "Visszaallito" = 0 +## 2026-09-16T10:05:20Z claim POST: HTTP/2 200 location= + body: A szerver beállítása — Felhom A szerver beállítása Tester 1 Érvénytelen űrlap — töltsd újra az oldalt. Add meg az e-mailben kapott beállító kódot, majd válassz saját jelszót a vezérlőpult védelméhez. Beállító kód Új jelszó (min. 12 karakter) Új jelszó megerősítése Beállítás és belépés Nem kaptad meg +## 2026-09-16T10:06:18Z claim POST (correct field names): HTTP/2 302 location: / + body: +## Claim (the volunteer's step 5), 2026-09-16 10:06:18Z: POST /claim with the setup code from the mail +## („Új beállító kód — újratelepült a szervered", 10:01:57Z, 72 h TTL) + a new dashboard password → **302 → /**. +## First attempt failed with „Érvénytelen űrlap" because the field names were guessed (claim_code/password); +## the real names are code / new_password / confirm_password. Recorded so the next session does not repeat it. diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/screens/29-boot-watch.png b/documentation/audits/evidence-drill-0243-2026-09-16/screens/29-boot-watch.png new file mode 100644 index 00000000..3df9cdc9 Binary files /dev/null and b/documentation/audits/evidence-drill-0243-2026-09-16/screens/29-boot-watch.png differ diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/screens/30-first-boot.png b/documentation/audits/evidence-drill-0243-2026-09-16/screens/30-first-boot.png new file mode 100644 index 00000000..cc9c4d15 Binary files /dev/null and b/documentation/audits/evidence-drill-0243-2026-09-16/screens/30-first-boot.png differ diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/screens/31-after-bind.png b/documentation/audits/evidence-drill-0243-2026-09-16/screens/31-after-bind.png new file mode 100644 index 00000000..fc543320 Binary files /dev/null and b/documentation/audits/evidence-drill-0243-2026-09-16/screens/31-after-bind.png differ diff --git a/documentation/audits/evidence-drill-0243-2026-09-16/screens/32-setup-progress.png b/documentation/audits/evidence-drill-0243-2026-09-16/screens/32-setup-progress.png new file mode 100644 index 00000000..50ecb2b6 Binary files /dev/null and b/documentation/audits/evidence-drill-0243-2026-09-16/screens/32-setup-progress.png differ diff --git a/documentation/backlog/CLOSED-ITEMS.md b/documentation/backlog/CLOSED-ITEMS.md index b409ea5c..7340d364 100644 --- a/documentation/backlog/CLOSED-ITEMS.md +++ b/documentation/backlog/CLOSED-ITEMS.md @@ -26,6 +26,12 @@ --- +## 2026-09-16 — the drill: the tunnel answers from outside + +| ID | Title | Shipped | Evidence | +|---|---|---|---| +| **R-510** | [P1-HIGH] `tester-1`'s tunnel now has its route, and still gives a fresh box 502: the route sends traffic to `https://traefik` WITH certificate checking, and traefik answers the name `traefik` with its default certificate. | operator ticked „No TLS Verify" 2026-09-15; proven with a box connected 2026-09-16 | three GETs from DooPlex to `https://felhom.enkicsifelhom.hu` at 10:04:19/22/25Z → **302 ×3 (server: cloudflare)**, following it → **200** on the Hungarian claim page „A szerver beállítása … Add meg az e-mailben kapott beállító kódot" (no 502, no 530). `audits/evidence-drill-0243-2026-09-16/phase1-tunnel.txt` | + ## 2026-09-16 — the drill's Phase 0 (hub v0.115.0, golden 0.243.0, the signing ruling) Two rows closed. **Full original text: `git show ^ -- documentation/backlog/OPEN-ITEMS.md`.** diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index e3a1cf60..e21d1008 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -710,7 +710,6 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-507** | **[P3-LOW] The proof-install harness cannot drive the graphical installer, so a release's graphical entry is proven only up to its password screen.** MEASURED 2026-09-14 on VM 332 (ISO 1.27.0): `qm sendkey 332 tab` did not move focus (both password copies landed in one field), `mouse_move 1237 772` + `mouse_button 1` did not move the cursor or press Next, while `alt-n` did advance a page. The TUI entry is fully drivable. The gate's "proof install on BOTH menu entries" was met for 1.26.1 (by a person) and not for 1.27.x. **Fix shape:** measure QEMU `input-send-event` with absolute coordinates, or a VNC client on DooPlex; until then a release's graphical proof is an operator click-through. | **READY — rank P3-LOW; owner: CC** | | **R-508** | **[P2-MEDIUM] Customer `tester-1` has no registered e-mail, so neither the self-bind link nor the setup code can reach a volunteer.** MEASURED 2026-09-14: the edit form's `email` value is empty; on bind the hub logged `[ERROR] [claim] claim code generated (gen 1) but customer tester-1 has NO registered email — deliver via resend after setting one`. A volunteer onboarded on this record would sit at „A szerver beállítása" with no code. **What it needs:** the operator sets the volunteer's address on the record before sending the guide (day-0 A.2). The hub's customer page could warn when a record with an unclaimed box has no e-mail — the log line exists, the page says nothing. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (record), CC (page warning)** | | **R-509** | **[P1-HIGH] A box installed for an EXISTING customer never gets the self-bind e-mail the console tells the volunteer to open.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1): customer `tester-1` now has `tester1@felhom.eu` registered; the box registered as appliance 28 at 17:44:53Z and its console says „Nyisd meg az e-mailben kapott linket"; **ten minutes later the mailbox (read through the Gmail connector) held 0 messages to that address.** Cause, from source: the hub auto-sends the link only at customer creation (`hub/internal/web/configs.go:725`) and at RESET completion (`customer_reset.go:162`); a customer whose e-mail was added later, or whose previous box was destroyed, never receives one unless the operator presses „Send self-bind link". The volunteer guide's operator prerequisites do not list that press. Intervention **I1** of the big night (the operator's button pressed). **Fix shape (for the operator to choose):** send the link when an unclaimed appliance registers and a customer with no host is waiting, or add the press to the guide's operator prerequisites (day-0 A.2). **SHIPPED hub v0.114.0 (2026-09-15), NOT YET PROVEN BY A REAL MAIL:** triggers added — e-mail set/changed on a customer with no box, and host delete — each re-checking no bound host; every send recorded as `selfbind_link_sent` and shown on the Setup tab. Unit-proven with a red-proof (`TestSelfBind_EmailSetOnWaitingCustomerSendsLink`). The live check with the Gmail-read mailbox was NOT run: it needs a throwaway customer, and deleting one runs the RESET cascade (ep0 `deprovision` + Cloudflare), which is fenced without the operator's word. **Closes on:** one real mail from either trigger. | **READY — rank P1-HIGH; owner: CC (hub fix) · operator (which fix shape)** | -| **R-510** | **[P1-HIGH] `tester-1`'s tunnel now has its route, and still gives a fresh box 502: the route sends traffic to `https://traefik` WITH certificate checking, and traefik answers the name `traefik` with its default certificate.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1, controller 0.242.0), after the operator's R-505 fix: from DooPlex `https://felhom.enkicsifelhom.hu` → **502 ×3** (18:07:48Z, `server: cloudflare`). The box's `cloudflared` logs `Request failed … tls: failed to verify certificate: x509: certificate is valid for 544346c4….traefik.default, not traefik … ingressRule=0 originService=https://traefik`. Traefik itself holds a valid Let's Encrypt `CN=*.enkicsifelhom.hu` (openssl on 127.0.0.1:443 with SNI). **Control:** demo-hp's working tunnel config reads `{"hostname":"*.enkisfelhom.hu", "originRequest":{"noTLSVerify":true}, "service":"https://traefik"}` — the same route WITH `noTLSVerify`. So the Cloudflare-side public hostname for `*.enkicsifelhom.hu` lacks „No TLS Verify" (or an origin server name). The Cloudflare side is not visible to the session; the inference rests on the log line and the control. Intervention **I2** of the big night: the claim and every dashboard request go to the guest's LAN address with the name forced. **Fix:** operator ticks „No TLS Verify" on that public hostname, then day-0 A.1 names the setting beside the route. **2026-09-15, after the operator's tick:** three GETs from DooPlex 08:09:07–08:09:14Z → **530 ×3** (`server: cloudflare`) — no tunnel is connected, because tester-1 has no box since the BIGNIGHT teardown. The fix cannot be observed until a box exists. `day0-install.md` A.1 now names „No TLS Verify" beside the route, marked unproven. **Closes on:** 200 or the claim page through the tunnel on the next tester-1 box. | **WAITING-ON-OPERATOR — rank P1-HIGH; owner: operator (Cloudflare route), CC (day-0 A.1 wording after)** | | **R-511** | **[P2-MEDIUM] A customer whose box is rebuilt keeps its ep0 PBS token, and then the DR tier can be neither provisioned nor re-issued: the hub's error advises the one action that refuses.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, `tester-1`, DR tier ticked): on the new box's WireGuard registration the hub logged `[ERROR] pbsdr auto-provision for tester-1 (WG-registration hook): the endpoint already holds a PBS token for tester-1 but the hub has no descriptor — use the explicit "Re-issue PBS credentials" action — save the customer config to retry`. The operator's `POST /configs/tester-1/pbsdr-reissue` → **400 `No provisioned PBS DR tier for this customer`** (`hub/internal/web/pbsdr.go` ~411). The token was left by the doorstep walk's host delete (a host delete does not deprovision tenancy; only RESET does, which also removes the tunnel). So a box rebuilt for an existing customer — the reinstall journey — has no whole-guest off-site tier and no button that restores it. **Fix shape:** let re-issue adopt an existing endpoint token when the descriptor is absent (the message already assumes it does), or have host delete offer to drop the PBS token. **SHIPPED hub v0.114.0 (2026-09-15):** re-issue ADOPTS the endpoint token when the descriptor is absent and the DR flag is on (re-key + descriptor rebuilt from the endpoint + `pbsdr_adopted` audit row); DR flag off still refuses, endpoint untouched (both pinned, red-proofed). **NOT proven on tester-1's real state:** re-issue needs an enrolled host and tester-1 has none. **ep0 cleanup DONE on the operator's yes (2026-09-15 08:33Z):** the one doorstep snapshot `ns tester-1 / ct/9201/2026-09-14T16:04:53Z` (logical 1 928 820 672 B) forgotten via the local PBS API; namespace lists empty; token `felhom@pbs!tester-1` kept; nothing outside tester-1 read or touched (`D3-*` in `audits/evidence-p1fixes-2026-09-15/`). The token-only release on host delete was NOT built → R-526. **Closes on:** adopt ending in a descriptor the next tester-1 box consumes. | **READY — rank P2-MEDIUM; owner: CC (hub)** | | **R-516** | **[P3-LOW] English a customer meets on a fresh box and its apps' first screens — enumerated by the big night.** MEASURED 2026-09-14 (BIGNIGHT, VM 333, ISO 1.27.1, controller 0.242.0). Felhom-owned: (1) the dashboard menu item **„Debug"**; (2) the dashboard CPU tile **„Load: 0.29 / 0.39 / 0.37"**; (3) the launcher tile **„Filebrowser"** opens a login in English with no Felhom text (R-513); (4) the storage page mixes formal „Adjon hozzá / Csatlakoztasson" with the product's „te". App first screens a household meets before any Felhom text helps: (5) **Uptime Kuma 2.4 opens on „Which database would you like to use?"** (SQLite / Embedded MariaDB, „Next") — the app card's „Első lépések" does not mention it; (6) PrivateBin, Gokapi, AdventureLog and FileBrowser UIs are English (the apps' own). Already rows: the Proxmox installer screens (R-495, answered by the guide), `wiki.DOMAIN` (R-498). **Fix shape:** rename „Debug"/„Load" (controller); add the Uptime Kuma database step to its card, or pre-seed `db-config.json` for SQLite in the template (catalog). **Added by F4 (20:04:54Z):** (7) the storage page prints the disconnect time as a raw ISO UTC string „Leválasztva: 2026-09-14T19:58:02Z"; (8) the „Meghajtó leválasztva" banner appears twice on every page; (9) „4 telepített alkalmazás nem fut — nézze meg a rendszermonitort" uses the formal form. **Added by F7 (20:50–21:00Z, system disk at 95 %):** (10) a banner on every page in English, „**SSD disk usage high: 90%**"; (11) the dashboard tile reads „Rendszer (/) 61.8 GB / 68.7 GB (**90%**)" while `df` reports **95 %** (reserved blocks ignored), and „(/)" labels the data volume `/mnt/sys_drive`; the deploy page says nothing about free disk. | **READY — rank P3-LOW; owner: CC (controller + catalog)** | | **R-518** | **[P2-MEDIUM] „Mentés most" on the whole-system backup stops every app for about eight minutes while the page promises „csak néhány másodpercre".** MEASURED 2026-09-14 (BIGNIGHT, VM 333, 12 apps): the button's call quiesced all 12 stacks at 19:03:23Z (first stopped 19:03:27Z); the local vzdump ran 19:03:49 → 19:09:59Z; the controller then kept the apps stopped for the second (PBS) tier and restarted them at 19:10:09Z after it failed, the last started 19:11:12Z (`phase4/guest-backup-quiesce-log.txt`) — **≈ 7 m 45 s** with every app answering 404. The page under the button: „Pillanatkép-mód: az alkalmazások csak néhány másodpercre állnak le." A household pressing it at dinner loses every app for the length of the dump, and longer on a bigger box. **Fix shape:** state the real expected downtime (it scales with data), or quiesce per tier and not across a second tier's attempt; do not start a tier whose storage is absent (see R-517). **NARROWED 2026-09-15 (controller v0.243.0 + agent v0.131.0):** a tier whose storage the agent reports absent is skipped before anything stops (`backup_tier_skipped`, once per absence; unknown never skipped), and the button copy now says „általában néhány perc, nagyobb adatnál több". Unit-proven with red-proofs. **Still open:** quiesce per tier, so a slow second tier does not keep every app down. | **READY — rank P2-MEDIUM; owner: CC (controller)** | @@ -719,6 +718,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server` | **R-521** | **[P3-LOW] One unplugged drive sends the operator five e-mails and the household none.** MEASURED 2026-09-14 (BIGNIGHT F4, VM 333): `storage_disconnected (error)` at 21:58:02 CEST plus `app_start_failed (warning)` for each of the four apps the drive carries at 21:58:15, each with its own operator mail (hub log: five `Operator email sent`). The customer's mailbox (`tester1@felhom.eu`, read through the connector) received nothing; the household learns of it only on the dashboard, which is honest and says what to do. The apps' stop is a consequence of the drive event, so the four warnings add no information. **Fix shape:** suppress `app_start_failed` for apps stopped by a `storage_disconnected` (the dead-app check already knows the reason — „Hiányzó tárhely"), and decide whether a household gets a mail for a lost drive. **F6, 40 min later, the opposite failure:** a second, separate drive loss (20:38:33Z) produced `storage_disconnected (error)` and four `app_start_failed`, and the hub logged `Operator email suppressed … cooldown` for all five — **no mail at all for the second unplug**; only `health_degraded (warning)` mailed. A per-key cooldown that outlives the recovery (`storage_reconnected` came between them) silences a new incident. **F7:** the system disk at 95 % produced only `health_degraded (warning)`, whose operator mail was **suppressed by the cooldown** left by F6's `health_degraded` 15 minutes earlier; no disk-specific event reached the hub at all — the operator was not told the disk was nearly full. | **READY — rank P3-LOW; owner: CC (controller) · operator (customer mail policy)** | | **R-522** | **[P3-LOW] While the box has no internet, the dashboard's „Cloudflare Tunnel" tile keeps saying „Fut", and no page tells the household the box is offline.** MEASURED 2026-09-14 (BIGNIGHT F8, VM 333): VM 333's traffic off the LAN and to the hub was dropped at demo-hp's bridge 21:08:36 → 21:26:07Z. Throughout, the LAN dashboard (probed every 26 s from demo-hp) answered 200 and, polled every 2 min, showed no banner and the tile „Cloudflare Tunnel — Biztonságos internetkapcsolat — a szerver portnyitás nélkül érhető el kívülről. · **Fut** · Védett"; meanwhile cloudflared logged ≈ 20 errors every 2 minutes, the public name answered 530, and the controller logged `[report] Push failed … context deadline exceeded` and `Job hub-report failed: hub push failed after 3 attempts`. The tile reports the container, not the connection. A household whose remote access is gone sees „Fut". **Fix shape:** the tile reads the tunnel's connection state (cloudflared's registered connections or the report push result) and says „Nincs internetkapcsolat" when either fails. | **READY — rank P3-LOW; owner: CC (controller)** | | **R-524** | **[P2-MEDIUM] When the catalog moves an app back to an older version, a box that already updated shows „Frissítés elérhető" — and the offered Update is a downgrade.** MEASURED 2026-09-15 (BIGNIGHT Phase 6, VM 333): privatebin was updated 2.0.5 → 2.0.6 through the guarded Update after the drill bump; the catalog was then reverted to 2.0.5 (`a161ccb`). At 22:13:37Z the box reads `installed privatebin/pdo:2.0.6`, `catalog privatebin/pdo:2.0.5`, `catalog_since 2026-09-14`, and the app page tag „**Frissítés elérhető — ma**" with the title „Újabb változat érhető el ehhez az alkalmazáshoz. A frissítés indításához nyomd meg a Frissítés gombot." The label compares for *difference*, not for *newer* (`09-update-architecture.md` §5.4 render table); the guarded Update would advance the pin „to the catalog's current definition" — 2.0.6 → 2.0.5. The same state follows any real upstream yank. **Not pressed tonight.** **Fix shape:** compare versions (or `catalog_since` against the installed record) and render „Naprakész" / „a katalógusnál újabb" when the box is ahead; refuse a pin move to an older tag without an operator word. | **READY — rank P2-MEDIUM; owner: CC (controller)** | +| **R-534** | **[P1-HIGH] The off-site tier cannot be provisioned or adopted for a rebuilt box: the hub's endpoint token lacks `Datastore.Modify`, so every re-issue fails.** MEASURED 2026-09-16 on the drill box (`tester-1-652049`, fresh install from published ISO 1.27.1): the WG-registration hook refused as R-511 describes („the endpoint already holds a PBS token … use the explicit Re-issue PBS credentials action"); the operator pressed exactly that, hub v0.114.0's ADOPT path ran, and the endpoint answered **`Process exited with status 255 (stderr: Error: permission check failed - missing Datastore.Modify on /datastore/felhom-offsite)`** → HTTP 502, no descriptor written, no secret stored (fail-closed, correct). So the code fix of 2026-09-15 is sound and INERT: a rebuilt box has no whole-guest off-site tier, and the customer's „Távoli rendszermentés" stays absent. **Not run by hand on ep0** (fenced). **Fix shape (operator):** grant the hub's tenantsync user `Datastore.Modify` on `/datastore/felhom-offsite` (it already holds the create/delete grants the provision path uses), or give the script a token-only re-key op that needs no Modify. Evidence: `audits/evidence-drill-0243-2026-09-16/phase1-pbsdr.txt`. | **WAITING-ON-OPERATOR — rank P1-HIGH; owner: operator (ep0 grant) · CC (verify after)** | | **R-525** | **[P3-LOW] FileBrowser has its own login; putting it behind the dashboard session (traefik forwardAuth or Quantum proxy auth) is a new mechanism nobody has measured.** Filed 2026-09-15 by the P1-fixes task (B.5). R-513 closed the default-password hole with a generated password; a household still has two logins. **What it needs:** a spike on a scratch guest — forwardAuth to the controller session, and what FileBrowser Quantum does with a trusted header. | **READY — rank P3-LOW; owner: CC (spike)** | | **R-526** | **[P3-LOW] A host delete cannot release only the customer's ep0 PBS token: the endpoint's one removal op destroys every backup group too.** MEASURED 2026-09-15 from source: `tenantsync.Deprovision` „DESTROYS the customer's PBS namespace, all its backup groups, and its token". The task asked for „PBS token elengedése" on host delete; building it needs a new token-only op in the ep0 tenantsync script — a new operation on a protected box. Not built. R-511's adopt path makes the kept token usable instead. | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator (new ep0 op yes/no), CC (build)** | | **R-527** | **[P3-LOW] The catalog flag `locked_after_deploy` is read by no controller code — every setting is read-only after install whatever the catalog says.** FOUND 2026-09-15: `stacks/metadata.go` parses it; `grep -rn LockedAfterDeploy` finds no reader; `deploy.html` renders „Az alábbi beállítások csak olvashatók" for every field. Recorded as the design in `02-controller-module-map.md`; the flag is a seam never wired. **Fix shape:** remove the flag from the catalog, or wire an editable-after-install allow-list (a bigger change). | **READY — rank P3-LOW; owner: CC** |