hub v0.119.0 — English households get English words for their codes (R-597); R-596/R-598 closed
gates / gates (push) Successful in 24s

The setup code and the owner passphrase now follow the household's language,
one word longer in English so the entropy never drops (setup 3 hu / 4 en,
passphrase 5 hu / 6 en). List and count are chosen together so a caller cannot
pair an English list with a Hungarian count. Hungarian is byte-unchanged.

Three claims in the row were wrong and are recorded as such:
  - the RECOVERY CODE is minted by felhom-agent from the EFF list and has
    always been English; the hub does not own it and no row was added.
  - no claim mail states a word count; the only count wording was the bind
    page's passphrase hint, whose English half is now count-free.
  - the proposed phone-safe filter removes 68% of the list (5270 of 7772
    words) and was measured, then declined, with the reason in source.

Also: guide_quote_gate binds the English volunteer guide's three quoted
messages to the controller's English bundle — nothing did, so the guide would
have gone on quoting Hungarian after the fix. Seven decoys, all convicting,
including the name-for-fact one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-21 07:56:56 +02:00
parent a499327236
commit e02bc03819
18 changed files with 8859 additions and 50 deletions
@@ -0,0 +1,45 @@
# Live proof — the Backup page's Go-composed copy follows the language (R-598)
**Box:** guest 9201 (`demo-felhom`) on `felhom-pve`, controller **0.259.0**, 2026-09-21.
**Method:** endpoint-level; signed in as the household, then `GET /backups` in both languages.
## What was proven live
| | `hu` | `en` |
|---|---|---|
| page title | `Biztonsági mentés — Felhom.eu` | `Backup — Felhom.eu` |
| primary tier label | „Helyi tároló (felhom-backup)" | **"Local storage (felhom-backup)"** |
| offsite tier label | „Biztonsági szerver – külön hardver (PBS)" | **"Backup server – separate hardware (PBS)"** |
| page size | 46 384 bytes | 45 728 bytes |
Those two labels are `backupTargetLabel` / `buildTierViews` — **Go-composed strings handed to the
page as struct fields**, which is the whole defect class. Before 0.259.0 the English column read
exactly like the Hungarian one.
## A finding about the method, worth more than the result
The first run used the **`felhom_lang` cookie** and got the **Hungarian page for `en`**. That is
correct behaviour, not a defect: `langFor` step 2 says a request **with a session** is the
household's own, so their saved setting wins and the visitor cookie is deliberately not read — a
signed-in family must never see a language a previous visitor picked on the sign-in page of the same
browser. The cookie is the right instrument for the anonymous claim page and the **wrong** one for a
signed-in page. `?lang=` — the documented testing override — is the right one here.
**This is worth writing down because the mistake is invisible:** a session that had only run the
cookie probe would have concluded R-598 was not fixed, and "fixed" it a second time.
## What was NOT proven live, and why
The **degraded** and **absent-drive** warnings did not render, because this box is **healthy** — it
has a real backup drive (`felhom-backup`), and a working configuration is designed to render nothing
at all (E-2 Scenario E). Producing either state live would mean un-assigning a real box's backup
target, which the task fences forbid and which is not worth doing to read a sentence.
They are covered instead by tests that drive the **real page handler** with the agent seams set to
the two states and read the returned HTML — `TestBackupWarningsFollowLanguage`,
`TestAbsentDriveWarningFollowsLanguageAndKeepsThePromise`. Those assert both that the English
appears and that the Hungarian is **gone**, and the English absent-drive copy is asserted to carry
the FACT, the CONSEQUENCE and the REMEDY, matching the Hungarian.
**Stated plainly: the two warnings the drill actually saw are proven by a handler-level render test,
not by a live box.** The next full English walk on a one-drive machine is what closes that.
@@ -0,0 +1,51 @@
# Live proof — the claim page answers in the reader's language (R-596)
**Box:** guest 9201 (`demo-felhom`) on `felhom-pve`, controller **0.259.0**, 2026-09-21.
**Method:** endpoint-level (no browser on DooPlex). The exact URL the page's own form POSTs to,
reached at the controller container's address with the `Host` header the router requires, carrying
the **`felhom_lang` cookie the language globe sets** — i.e. the real path a household takes, not the
`?lang=` testing override.
> **The box is CLAIMED, so `/claim` is the RESET-code entry.** That is the venue the task named, and
> it is the same handler, the same page and the same nine messages as a first claim.
## A — through the cookie (the household's path)
| cookie | screen | answer |
|---|---|---|
| `felhom_lang=hu` | page title | `Jelszó visszaállítása — Felhom` |
| `felhom_lang=hu` | wrong code | „Hibás vagy lejárt kód" |
| `felhom_lang=hu` | invalid form | „Érvénytelen űrlap — töltsd újra az oldalt." |
| `felhom_lang=en` | page title | `Reset password — Felhom` |
| `felhom_lang=en` | invalid form | **"Invalid form — reload the page."** |
| `felhom_lang=en` | after 5 wrong codes | **"Too many attempts — try again in 15 minutes."** |
Both Hungarian answers are byte-identical to what the box said at 0.258.0.
## B — the lockout proved itself, unasked
The probe sent two wrong codes per language. By the English run the **per-source lockout had already
tripped from the Hungarian ones**, so English received the lockout answer instead of the wrong-code
one. That is a stronger result than the one planned:
1. The **English lockout message** is proven live, which was not otherwise going to be walked.
2. The **lockout is language-blind** — the counter is per source, not per language. Attempts made
with `felhom_lang=hu` locked out the `felhom_lang=en` request from the same address. A guesser
cannot buy extra attempts by switching the cookie. `TestClaimLockoutAnswersInEnglishAndCountsTheSame`
asserts this on the counter; here the live box demonstrated it by accident.
The `?lang=hu` override then returned „Túl sok próbálkozás — próbáld újra 15 perc múlva." — the same
lockout, in Hungarian, from the same tripped counter.
## What this did to the box
The claim/reset page's rate limiter was left locked for **15 minutes** from the probe (a demo box,
Tier 0). It clears itself; nothing was configured, no password was changed, no code was consumed.
The dashboard password is **unchanged** — the probe never submitted a valid code.
## What was NOT walked here
The **wrong-code answer in English** ("Wrong or expired code") — the drill's own screen — was
pre-empted by the lockout above. It is covered by `TestClaimAnswersFollowTheReadersLanguage`, which
asserts both that the English sentence is present and that the Hungarian one is gone, and which was
red-proofed by restoring the literal. See the second live run below once the window reopens.