Family gate built + licence read: evidence (9202, bench, floor), licence table + SparkyFitness request draft (not sent), 01 §5 family gate, 09 decision 64 built, capability map, register 422 -> 436 (R-767/R-780/R-787 closed; R-775/R-784 updated; R-788..R-801 opened), CONTEXT
gates / gates (push) Successful in 28s
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -878,7 +878,7 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server`
|
||||
| **R-764** | **[P3-LOW] wger sends no mail: its mail backend is the console, so a password-reset mail never leaves the box, and the template maps no SMTP.** READ 2026-10-01 inside the app on 9202 (checklist row 7.1): `EMAIL_BACKEND django.core.mail.backends.console.EmailBackend`; the settings read `ENABLE_EMAIL`, `EMAIL_HOST`, `EMAIL_PORT`, `FROM_EMAIL` …; the template carries no `smtp_mapping`. The household's admin can reset another member's password in the app; a member who forgets theirs and asks wger by e-mail gets nothing, and the page does not say so. Not measured: what wger shows after a reset request. **Needs:** an `smtp_mapping` (vaultwarden's shape, a fresh install with mail OFF booting — REUSE.md §2), or the page saying mail is not available. `audits/new-app-checklist-2026-10-01/C/C2-static-reads.txt` | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-765** | **[P2-MEDIUM] A new app that builds its login from a `type: password` value at EVERY start loses the household's login on a restore after a remove — found on Radicale's first template, fixed before publishing.** MEASURED 2026-10-01 on 9202 (drill catalog): Radicale's start command rewrote its login file from `RADICALE_PASSWORD` at every start. Remove (keeping backups) + the household's restore → the right password answered 401. Cause, read in the controller: a restore carries only `type: secret` values (`stacks.PortableSecretEnvVars`, the D5 ruling — a `type: password` is an internet-reachable login and stays out of the drive's backup) and makes a NEW password when the guest's own copy is gone (`restore_unit.go:538`, „generated replacement … the page will not show the new value as the password”), expecting the app's login to come back WITH ITS DATA. Fix (catalog, same session): the login file is written on the FIRST start only and lives on the data volume; re-measured: remove + restore → the original login reads the event back. The checklist row that caught it is 2.5 (restore round trip); 1.9 names the shape. `audits/new-apps-2026-10-01/box/radicale-attempt1/restore.txt`, `box/radicale/restore.txt` | **CLOSED 2026-10-01 — Radicale's template, before publishing** |
|
||||
| **R-766** | **[P3-LOW] A new app's logo and screenshots reach the boxes only with the next HUB release — the website alone is not enough.** READ 2026-10-01: the box's asset syncer reads the hub's `/api/v1/assets/manifest` (`felhom-controller internal/assets/syncer.go`); the hub serves its PVC, seeded at start from `/usr/share/felhom/assets-seed/` baked into the hub IMAGE (`hub/Dockerfile:27`; the hub build copies `website/assets/*-logo.{svg,png}` and `*-screenshot-*.webp`, `hub/README.md`). So Radicale's assets (pushed `40f0742`) answer 200 on felhom.eu, and a box shows an app card without a logo until a hub build carries them. Today's fence kept the hub untouched. **Needs:** the next hub release (any) carries them — say so in its report; or a ruling that the hub reseeds from the website without a release. `audits/new-apps-2026-10-01/S/S3-assets.txt` | **READY — rank P3-LOW; owner: CC (next hub release)** |
|
||||
| **R-767** | **[P3-LOW] MeTube has no login at all, by design, and the box has no permanent household-only door — so it is not built.** READ 2026-10-01 (fit table): upstream „MeTube deliberately has no login system … use HTTP basic auth, Authelia, or your proxy” (wiki, Reverse-proxy-configurations). Published on the household's subdomain, anyone who finds it can make the box download through the household's IP and use uploaded YouTube cookies. The box offers `setup_gate` (until setup) and `signup_block` only. **Two routes:** (a) a login-proxy sidecar inside the template (basic auth from a generated password, catalog-only — measure the phone/browser experience); (b) a controller feature: a permanent household-only door. Also owed before any build: the operator's word on the YouTube sentence (STATUS). `audits/new-apps-2026-10-01/FIT.md` | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator (route), CC builds** |
|
||||
| **R-767** | **[P3-LOW] MeTube has no login at all, by design, and the box has no permanent household-only door — so it is not built.** READ 2026-10-01 (fit table): upstream „MeTube deliberately has no login system … use HTTP basic auth, Authelia, or your proxy” (wiki, Reverse-proxy-configurations). Published on the household's subdomain, anyone who finds it can make the box download through the household's IP and use uploaded YouTube cookies. The box offers `setup_gate` (until setup) and `signup_block` only. **Two routes:** (a) a login-proxy sidecar inside the template (basic auth from a generated password, catalog-only — measure the phone/browser experience); (b) a controller feature: a permanent household-only door. Also owed before any build: the operator's word on the YouTube sentence (STATUS). `audits/new-apps-2026-10-01/FIT.md` **UPDATE 2026-10-02 — CLOSED by route (b):** the operator said GO (`09` §3 decision 64); controller 0.287.0 has the family gate and MeTube is published behind it with NO exception (every path, the websocket included, measured on 9202: `audits/family-gate-2026-10-02/A/items.txt`, `audits/family-gate-2026-10-02/B/box/metube-fresh.txt`); the own-use sentence is on the page in both languages; `onboarding/metube.md`. | **CLOSED 2026-10-02 — controller v0.287.0 + catalog (MeTube published)** |
|
||||
| **R-768** | **[P3-LOW] Grimoire is not built: upstream rules out public exposure and publishes no image for its current line.** READ 2026-10-01: SECURITY.md „Public-network exposure is not a supported Grimoire mode”; docs/06-remote-access.md „General REST routes remain loopback-only and tokenless”; v1.x has no published image (the compose builds from source; Docker Hub is the old 0.x). Karakeep covers the bookmark need. **Reopens if** upstream publishes an image and supports authenticated remote use. `audits/new-apps-2026-10-01/FIT.md` | **WATCHING — rank P3-LOW; owner: CC (re-read at the next catalog campaign)** |
|
||||
| **R-769** | **[P3-LOW] Pinchflat is not built: upstream is paused (no release in 2026, last push 2025-12-16) and its last release has no image tag.** READ 2026-10-01: ghcr's newest version tag `v2025.6.6`, `latest` amd64 only; runs as root by default; an unanswered 30 GB yt-dlp memory report (#866); third parties call it unmaintained (community-scripts #15968). Forks with images exist (Pinchflat-NGX, MorganKryze). **Needs:** the operator's word on a fork (a new upstream), after the YouTube sentence (R-767). `audits/new-apps-2026-10-01/FIT.md` | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator** |
|
||||
| **R-770** | **[P3-LOW] Invidious — fit check only; the recommendation is not to build it.** READ 2026-10-01: playback needs `invidious-companion` (rolling `latest`, no version tags); PostgreSQL 14 (EOL 2026-11); `registration_enabled: true` by default; upstream: a bot check means „your IP is blocked from YouTube”, a 429 can last 24 h, triggered by „someone on your network” — on our boxes that IP is the household's. One bad period in 2026 (March, ~2 weeks). No report found of a family's other devices being bot-checked (inference). **Needs:** the operator's go / no-go. `audits/new-apps-2026-10-01/FIT.md` | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator** |
|
||||
@@ -886,19 +886,33 @@ class (an image `VOLUME` at an unmounted path) is still live — `immich-server`
|
||||
| **R-772** | **[P3-LOW] A health probe that finds NO container to probe records `healthy: true` — and the next check is 5 minutes away.** MEASURED 2026-10-01 on 9202 (controller 0.285.0, Karakeep): with the app container stopped, the probe's record read `{type: none, target: karakeep, healthy: true, message_key: health.no_probe_container}` and stayed so 4+ minutes (`RunHealthProbes: skipping karakeep — last check …, effective interval 5m0s, healthy=true`). The app's STATE did read `degraded` within 10 s, so the household saw it; the probe record alone says healthy about a check that did not run (the presence-is-not-success shape). Not checked: which readers use `health_probe.healthy` (the guarded Update's `verifying`? the hub report?). **Needs:** a not-run probe recorded as not-healthy (or `unknown`), with a test that pins it. `audits/new-apps-2026-10-01/box/karakeep-768M/neg-and-crawl.txt` **-- FIXED controller v0.286.1:** a not-run probe records `healthy: false, not_checked: true`, is looked at on the next tick (0.286.0 still waited out the last healthy record's 5-minute interval — found live, fixed in .1), the state stays the containers' (R-630 holds), the app page says so. Readers checked: `health_probe` feeds only the state override and the API/page; the hub gets container states, never the probe record. **Live on 9202 (0.286.1):** paperless-webserver stopped 19:48:33 → `healthy false, not_checked true` at 19:48:47; started 19:49:05 → healthy at 19:49:47. Red-proofs RP-D1, RP-D1b. `audits/visitors-2026-10-01/D/`. | **CLOSED 2026-10-01 — controller v0.286.1** |
|
||||
| **R-773** | **[P3-LOW] After a remove + restore, an app's sign-up route block (decision 47) is gone; only the app's own switch still refuses.** MEASURED 2026-10-01 on 9202 (Karakeep): before — `/signup` 403 and tRPC `users.create` 403; after the household removed the app (keeping backups) and pressed restore — `/signup` answers 200, `users.create` still 403 (the restored env keeps `DISABLE_SIGNUPS=true`). For an app with NO own switch (opengist, wishlist: block only) a remove + restore would reopen sign-up entirely — not measured. **Needs:** the restore re-applies the lock record's block (or the gate) for an app whose template has `signup_block`, with a test; then measured on a block-only app. `audits/new-apps-2026-10-01/box/karakeep/restore.txt` **-- FIXED controller v0.286.0:** a REMOVED app restored from its backup gets the lock record (`opened_by: restore`) and the block written before anything starts; the loop sets the app's own switch; an installed app the household never closed keeps what it had (decision 49). **Live on 9202:** Karakeep — before: `/signup` 403, `users.create` 403; removed keeping backups; restored → record `opened_by: restore`, `native_lock: applied`, block file present, a stranger's `/signup` 403 and `users.create` 403, the bookmark read back. Red-proof RP-D2. Block-only apps (opengist, wishlist) share the code path, not measured. `audits/visitors-2026-10-01/D/r773-live.txt`. | **CLOSED 2026-10-01 — controller v0.286.0** |
|
||||
| **R-774** | **[P3-LOW] Two things the new apps' pages do not show yet: Karakeep's mail-ON path is unproven, and its official phone app reports crashes to its makers.** READ/MEASURED 2026-10-01: Karakeep's `smtp_mapping` (plaintext :2526, as Cal.com) was proven only with mail OFF (a fresh install boots) — 9202 has no hub, so the relay cannot be exercised there; the official mobile app ships Sentry crash reporting with a hard-coded DSN (`apps/mobile/app/_layout.tsx`, FIT.md). **Needs:** one password-reset mail from Karakeep on a hub-enabled box (demo-hp 9201, a throwaway install); and a sentence on the page about the phone app (copy, freeze). `audits/new-apps-2026-10-01/bench/karakeep-mail-off-boot.txt` | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-775** | **[P2-MEDIUM] Grimmory: a stranger's 5 wrong sign-ins lock EVERY visitor out of the web login for 15 minutes — so Grimmory was not published.** MEASURED 2026-10-01 on 9202 (drill catalog, v3.4.1, through traefik): after 5 wrong tries for `admin` every further sign-in answered 429 — the household's right password AND a different name — and stayed 429 for 10+ minutes of retries. Read in the jar: `AuthRateLimitService` — Caffeine `expireAfterWrite(ofMinutes(15))`, `MAX_ATTEMPTS 5`, keys `login:ip:` and `login:user:`; Spring `forward-headers-strategy: native` takes the address from X-Forwarded-For, and behind the tunnel every visitor is the tunnel container's address (R-753) — the wger shape (R-752), with no setting to change it. Everything else in the checklist passed (bench + box step v3.4.1 → v3.5.0, gate by its own probe, OPDS through traefik); two smaller findings for the publishing session: on a reinstall over the first install's kept books, a new upload was saved to the drive but not added to the library (`box/grimmory/reinstall-c1.txt`, not investigated); and the remove + restore round trip (2.5) cannot be shown on 9202 for a drive app — its backup lives on the scratch drive, which is not a registered drive (R-756). The template waits in `audits/new-apps-2026-10-01/wip/grimmory/`. **Needs (operator):** (A) publish with a sentence on the page that wrong guesses by others can lock the login for 15 minutes (MEASURED: during the lock an e-reader's OPDS feed still answered 200 with its own login, wrong 401 — `box/grimmory/opds-under-lock.txt`), or (B) wait until the box passes each visitor's real address (R-753). `audits/new-apps-2026-10-01/box/grimmory/throttle.txt` **-- 2026-10-01 (evening):** option B's precondition SHIPPED (controller v0.286.1, R-753): Grimmory's Tomcat RemoteIpValve walks from the right and counts `172.16.0.0/12` as a proxy (READ in source, Spring Boot 4.1.1 — not yet measured with Grimmory's own lock), so `login:ip:` becomes per visitor; `login:user:` still lets a stranger lock the public name `admin` 15 min. A third route was spiked and passed: Grimmory behind the permanent family gate with its e-reader paths excepted (R-780). Recommendation: publish behind the family gate if R-780 is built; otherwise B with a measured 3.6. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (A / B / behind R-780), CC publishes** |
|
||||
| **R-775** | **[P2-MEDIUM] Grimmory: a stranger's 5 wrong sign-ins lock EVERY visitor out of the web login for 15 minutes — so Grimmory was not published.** MEASURED 2026-10-01 on 9202 (drill catalog, v3.4.1, through traefik): after 5 wrong tries for `admin` every further sign-in answered 429 — the household's right password AND a different name — and stayed 429 for 10+ minutes of retries. Read in the jar: `AuthRateLimitService` — Caffeine `expireAfterWrite(ofMinutes(15))`, `MAX_ATTEMPTS 5`, keys `login:ip:` and `login:user:`; Spring `forward-headers-strategy: native` takes the address from X-Forwarded-For, and behind the tunnel every visitor is the tunnel container's address (R-753) — the wger shape (R-752), with no setting to change it. Everything else in the checklist passed (bench + box step v3.4.1 → v3.5.0, gate by its own probe, OPDS through traefik); two smaller findings for the publishing session: on a reinstall over the first install's kept books, a new upload was saved to the drive but not added to the library (`box/grimmory/reinstall-c1.txt`, not investigated); and the remove + restore round trip (2.5) cannot be shown on 9202 for a drive app — its backup lives on the scratch drive, which is not a registered drive (R-756). The template waits in `audits/new-apps-2026-10-01/wip/grimmory/`. **Needs (operator):** (A) publish with a sentence on the page that wrong guesses by others can lock the login for 15 minutes (MEASURED: during the lock an e-reader's OPDS feed still answered 200 with its own login, wrong 401 — `box/grimmory/opds-under-lock.txt`), or (B) wait until the box passes each visitor's real address (R-753). `audits/new-apps-2026-10-01/box/grimmory/throttle.txt` **-- 2026-10-01 (evening):** option B's precondition SHIPPED (controller v0.286.1, R-753): Grimmory's Tomcat RemoteIpValve walks from the right and counts `172.16.0.0/12` as a proxy (READ in source, Spring Boot 4.1.1 — not yet measured with Grimmory's own lock), so `login:ip:` becomes per visitor; `login:user:` still lets a stranger lock the public name `admin` 15 min. A third route was spiked and passed: Grimmory behind the permanent family gate with its e-reader paths excepted (R-780). Recommendation: publish behind the family gate if R-780 is built; otherwise B with a measured 3.6. **UPDATE 2026-10-02 — NARROWED, Grimmory PUBLISHED behind the family gate:** a stranger cannot reach Grimmory's web sign-in at all (6 tries through the simulated tunnel: the gate's 401, then the household signs in 200 — `audits/family-gate-2026-10-02/A/items.txt`), and the e-reader exceptions keep Grimmory's own login. The 2.5 round trip now WORKS on 9202 (`audits/family-gate-2026-10-02/B/box/life.txt`). **What is left:** a family member past the gate can still lock a NAME (the admin's) for 15 minutes with 5 wrong tries — hard-coded in Grimmory; and the reinstall-over-kept-books finding (`new-apps-2026-10-01/box/grimmory/reinstall-c1.txt`) is still not investigated. | **WATCHING — rank P3-LOW; owner: CC** |
|
||||
| **R-776** | **[P3-LOW] Right-walking catalog apps need ONE setting to see each visitor since v0.286 (R-753); without it they keep the tunnel's one address (a stranger can still trip their per-address limits for everyone).** READ in source (`audits/visitors-2026-10-01/A/sweep/`): kimai `TRUSTED_PROXIES=127.0.0.1,172.16.0.0/12`; zipline `CORE_TRUST_PROXY=true` + `CORE_TRUSTED_PROXIES=172.16.0.0/12`; vikunja `VIKUNJA_SERVICE_IPEXTRACTIONMETHOD=xff`; nextcloud `TRUSTED_PROXIES=172.16.0.0/12`; n8n `N8N_PROXY_HOPS=2` (optional). BookStack `APP_PROXIES` measured this session (see its catalog commit). **Needs:** per app, the setting + checklist 3.6 re-measured on 9202 through the simulated tunnel (the BookStack shape, `audits/visitors-2026-10-01/tools/bookstack_36.py`). Count readers (calibre-web, tandoor, wger) stay as they are — a fixed count is wrong for one of the two paths. | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-777** | **[P2-MEDIUM] Emby and Jellyfin treat every internet visitor as being on the LAN — users with "remote access" off can sign in from the internet, IP filters and remote limits are skipped.** READ in source (`audits/visitors-2026-10-01/A/sweep/sweep-1.md`, `sweep-2.md`), not measured live: Jellyfin with `KnownProxies` empty uses the TCP peer (traefik, private) → "LAN"; Emby reads the leftmost XFF (its chain is now removed by the R-753 reset, so it sees cloudflared's private address → "LAN", as before). True before R-753 too; R-753 neither caused nor fixed it. **Needs:** measure on 9202 (a user with remote access off, through the simulated tunnel); Jellyfin: `KnownProxies` `172.16.0.0/12` in `network.xml` (no env — an `after_install` or a seed file); Emby: no setting fixes it (its `LocalNetworkSubnets` still counts private ranges) — a page sentence or a decision. | **READY — rank P2-MEDIUM; owner: CC (measure), operator (Emby route)** |
|
||||
| **R-778** | **[P3-LOW] A box that rolls back to a controller ≤ 0.285 after v0.286 keeps the new traefik (an old controller never rewrites a running traefik) — and the old `clientIP` believes the LEFTMOST X-Forwarded-For, which a stranger then writes: the dashboard's login counter becomes dodgeable until the box moves forward again.** Reasoned from the code (old `claim.go` clientIP + v0.286 traefik trust), not measured. The floor never moves back; the window is the self-update's crash roll-back. **Needs:** decide whether that window matters (it closes at the next floor); if it does, a 0.285.x patch that reads the rightmost hop, or the self-update refusing to roll back across v0.286. | **OPEN — rank P3-LOW; owner: CC** |
|
||||
| **R-779** | **[P3-LOW] Part A's "two outside addresses seen as two" is proven through the simulated tunnel only; on the REAL tunnel the second outside address (ep0, one request allowed) was refused by Cloudflare's edge with 403 and never reached the box.** Measured 2026-10-01 19:51 UTC (`audits/visitors-2026-10-01/A/L2-demo-hp-real-tunnel.txt`): no log line on demo-hp; demo-hp's box has no geo restriction in its settings, so a Cloudflare ZONE rule (country or bot, not read) refused a German datacenter address. DooPlex's own address on the real tunnel was seen as itself. **Needs:** one sign-in from a second Hungarian address (the operator's phone off wifi) while DooPlex is locked out — 2 minutes; and say which Cloudflare rule refused ep0. | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator (a phone), CC reads the logs** |
|
||||
| **R-780** | **[P2-MEDIUM] A permanent household gate with family accounts — the spike PASSED; the build waits for the operator's go (`09` §3 decision 63).** Measured on 9202 2026-10-01 (`audits/permanent-gate-2026-10-01/VERDICT.md`, exit test committed before): a stranger reached nothing of Grimmory or MeTube (36 requests incl. websockets); family members with their own logins got in for 30 days, logout worked; a stranger's guesses locked only the stranger; Grimmory's OPDS/Kobo/KOReader worked through anchored path exceptions with the app's own login; the family login never opened the dashboard; +0.4 ms per request; the gate down → apps refuse (500). **Build requirement F1:** exceptions must be anchored (`PathPrefix(/api/v1/opds)` also matched `/api/v1/opdsx`). **Cost:** 2 sessions (controller release; catalog — Grimmory and MeTube published behind it). If nothing is decided: Grimmory stays held (R-775) and MeTube unpublished (R-767). | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (go/no-go), CC builds** |
|
||||
| **R-780** | **[P2-MEDIUM] A permanent household gate with family accounts — the spike PASSED; the build waits for the operator's go (`09` §3 decision 63).** Measured on 9202 2026-10-01 (`audits/permanent-gate-2026-10-01/VERDICT.md`, exit test committed before): a stranger reached nothing of Grimmory or MeTube (36 requests incl. websockets); family members with their own logins got in for 30 days, logout worked; a stranger's guesses locked only the stranger; Grimmory's OPDS/Kobo/KOReader worked through anchored path exceptions with the app's own login; the family login never opened the dashboard; +0.4 ms per request; the gate down → apps refuse (500). **Build requirement F1:** exceptions must be anchored (`PathPrefix(/api/v1/opds)` also matched `/api/v1/opdsx`). **Cost:** 2 sessions (controller release; catalog — Grimmory and MeTube published behind it). If nothing is decided: Grimmory stays held (R-775) and MeTube unpublished (R-767). **UPDATE 2026-10-02 — BUILT (decision 64):** controller v0.287.0 — `internal/family` (own name + password per member, bcrypt, sessions asked on every request), the Család card, `family_gate:` / `family_gate_except:` (anchored, F1) / `min_controller:` in the template, the catalog gate `check-family-gate.py`. Exit items 1-5 proven live on 9202 through the product (`audits/family-gate-2026-10-02/A/items.txt`); both demo boxes on 0.287.0 by the floor (`audits/family-gate-2026-10-02/E/floor.txt`); Grimmory and MeTube published behind it. | **CLOSED 2026-10-02 — controller v0.287.0** |
|
||||
| **R-781** | **[P3-LOW] The catalog's `scripts/test_gate_decoys.py` fails 4 of its own "genuine" onboarding cases — on the untouched tree.** Measured 2026-10-01 (same 4 FAIL lines before and after this session's checklist edit): the harness copies the catalog into a temp tree with a fake sibling `felhom.eu`, and the REAL published records (radicale, karakeep, dawarich) name evidence that the fake sibling lacks, so a complete record reads incomplete. The gate itself (`onboarding`) is green on the real tree. **Needs:** the genuine cases build their own records, or the fake sibling mirrors the cited evidence. | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-782** | **[P3-LOW] Two side observations of the R-753 sweep, inferred, not measured:** glance's seeded `glance.yml` has no `auth:` block (the dashboard is public to anyone with the address), and homepage's `/api/*` refuses a Host not in `HOMEPAGE_ALLOWED_HOSTS`, which the template does not set (widgets may 400). **Needs:** measure both on 9202; glance: decide whether a public link dashboard is intended (the setup gate does not cover it after setup). | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-783** | **[P3-LOW] SparkyFitness: three wrong sign-ins by anyone shut EVERY visitor out of sign-in for ~10 s — a stranger retrying every 10 s keeps the household out.** MEASURED 2026-10-01 on 9202 through the simulated tunnel (`audits/visitors-2026-10-01/C/box/sparky-box.txt`): better-auth's sign-in limit (3 per 10 s) is keyed on one address — it reads the LEFTMOST X-Forwarded-For, whose chain the R-753 router reset removes, so its frontend nginx hands it traefik's address; the household from another address got 429 at 3 s and 10 s, in at 16 s. Not forgeable (a rotating forged address did not escape). better-auth's header setting is not exposed as an env by SparkyFitness. **Needs:** accept (10 s), or an upstream setting for better-auth's `ipAddressHeaders` + a right-walking reader. | **OPEN — rank P3-LOW; owner: CC** |
|
||||
| **R-784** | **[P2-MEDIUM] SparkyFitness's licence forbids commercial use: "may not be used, directly or indirectly, in any product, service … intended for … commercial advantage … without prior written permission from the author" — and Felhom is a paid service that offers it in its catalog.** READ 2026-10-01 (`audits/visitors-2026-10-01/C/C0-license.txt`): a custom licence (GitHub: NOASSERTION), the same at the pinned tag v0.17.3 and at `main`; termination clause 7 ("cease all use"). SparkyFitness was named as wger's replacement for fitness. **Needs (operator):** (A) hide it from new installs (`lifecycle: hidden`) until the author gives written permission, and ask; (B) ask first and keep it offered meanwhile; (C) keep it. Recommended A. If nothing is decided it stays offered. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator** |
|
||||
| **R-784** | **[P2-MEDIUM] SparkyFitness's licence forbids commercial use: "may not be used, directly or indirectly, in any product, service … intended for … commercial advantage … without prior written permission from the author" — and Felhom is a paid service that offers it in its catalog.** READ 2026-10-01 (`audits/visitors-2026-10-01/C/C0-license.txt`): a custom licence (GitHub: NOASSERTION), the same at the pinned tag v0.17.3 and at `main`; termination clause 7 ("cease all use"). SparkyFitness was named as wger's replacement for fitness. **Needs (operator):** (A) hide it from new installs (`lifecycle: hidden`) until the author gives written permission, and ask; (B) ask first and keep it offered meanwhile; (C) keep it. Recommended A. If nothing is decided it stays offered. **UPDATE 2026-10-02 — DECIDED (`09` §3 decision 65, option B):** SparkyFitness stays offered; the operator asks the author. The request is drafted (NOT sent): `audits/licences-2026-10-02/EMAIL-DRAFT-sparkyfitness.md` — the author publishes no e-mail; the routes are the project's Discord (private, recommended) or a GitHub Discussion. **Trigger:** no written permission before the first paying customer → `lifecycle: hidden` (a STATUS standing item). | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (send the request; the answer)** |
|
||||
| **R-785** | **[P3-LOW] SparkyFitness is pinned 11 releases and a major behind upstream (v0.17.3; upstream v1.7.3, v1.6.0 dated 2026-07-24).** READ 2026-10-01 (`audits/visitors-2026-10-01/C/bench/C1-previous-tag.txt`). **Needs:** an update walk 0.17 → 1.x through the ladder (bench + box), after R-784 is decided. | **OPEN — rank P3-LOW; owner: CC (after R-784)** |
|
||||
| **R-786** | **[P3-LOW] SparkyFitness's onboarding record has six open rows** (`app-catalog-felhom.eu/onboarding/sparkyfitness.md`): 0.5 runtime internet (food search providers), 0.7 the phone app's sign-in route through traefik, 1.6 the env names the server reads, 1.7 the entrypoint read, 5.4 a second memory watch at another limit, 8.3 no logo/screenshots on felhom.eu (404). Everything else measured this session (bench + 9202). **Needs:** each row measured, or n/a with a reason. | **READY — rank P3-LOW; owner: CC (catalog)** |
|
||||
| **R-787** | **[P2-MEDIUM] No catalog app's LICENCE has been checked against Felhom being a paid service; the first look (SparkyFitness, R-784) found a non-commercial-only licence.** The new-app checklist row 0.1 binds apps opened from 2026-10-01; the 53 exempt apps were never read. **Needs:** a read of every template's licence at its pinned tag (SPDX + any custom terms), one table, and the non-open ones to the operator. | **READY — rank P2-MEDIUM; owner: CC (read), operator (decisions)** |
|
||||
| **R-787** | **[P2-MEDIUM] No catalog app's LICENCE has been checked against Felhom being a paid service; the first look (SparkyFitness, R-784) found a non-commercial-only licence.** The new-app checklist row 0.1 binds apps opened from 2026-10-01; the 53 exempt apps were never read. **Needs:** a read of every template's licence at its pinned tag (SPDX + any custom terms), one table, and the non-open ones to the operator. **UPDATE 2026-10-02 — READ:** all 58 templates (56 published + Grimmory + MeTube), every image, at the pinned tag — one table: `audits/licences-2026-10-02/TABLE.md` (method in `read-1.md`, `read-2.md`). OSI-approved: all but the rows below. Not OSI / limiting, each now its own row: Tandoor (Commons Clause, R-789), Emby (R-790), n8n (R-791), Plex (R-792), the EE/BUSL parts of Cal.com, Docmost, Outline and meilisearch (R-793), redis 7.4 in seven apps (R-794), recipe-importer has no licence file (R-795); SparkyFitness is R-784. Nothing was hidden or changed because of the read (the brief's rule). New apps carry their licence in record row 0.1. | **CLOSED 2026-10-02 — the read (decisions are R-784, R-789..R-795)** |
|
||||
| **R-788** | **[P3-LOW] The volume-persistence gate reads an EMPTY declared volume as CLEAN — MeTube's `/state` passed while the app had written nothing there.** MEASURED 2026-10-02 on the bench (`audits/family-gate-2026-10-02/C-metube-bench/C2-volume-persistence-metube.txt`): "declared volume /state is EMPTY" → exit 0. The catalog's CLAUDE.md says an app that wrote nothing is UNDETERMINED (exit 2), never a pass. MeTube's real proof came from elsewhere (the history read back after a recreate and after a restore). **Needs:** the gate treats an empty declared volume as undecided, or the app gets an exerciser (MeTube: one `POST /add`); a decoy that is an app writing nothing. **UPDATE 2026-10-02:** part of the cause was R-801 (no port → no exercise at all); the catalog now also has `APP_EXERCISE` (MeTube: one `POST /add`). The empty-volume → CLEAN path itself is still to be checked. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-789** | **[P2-MEDIUM] Tandoor's licence is AGPL-3.0 WITH the Commons Clause: it forbids selling "a product or service whose value derives, entirely or substantially, from the functionality of the Software" — fees for hosting or support included.** READ 2026-10-02 at 2.6.15 (`audits/licences-2026-10-02/TABLE.md`). Felhom charges for installing and caring for the household's apps; whether that value comes "substantially" from Tandoor is the question. **Needs (operator):** keep (the fee is for the box, not Tandoor), hide for new installs, or ask the authors. Nothing changed meanwhile. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator** |
|
||||
| **R-790** | **[P2-MEDIUM] Emby is proprietary: a personal, non-commercial, non-transferable licence.** READ 2026-10-02 (emby.media/terms.html; `audits/licences-2026-10-02/TABLE.md`). The household's private use fits; Felhom installs the official image from Emby (no copy distributed) as part of a paid service, a context the licence does not cover. Jellyfin (GPL) offers the same. **Needs (operator):** keep, hide, or ask Emby. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator** |
|
||||
| **R-791** | **[P3-LOW] n8n's Sustainable Use License allows own internal or personal use, and distribution only free of charge for non-commercial purposes.** READ 2026-10-02 at 2.42.1 (`audits/licences-2026-10-02/TABLE.md`). The household's own use is allowed; Felhom pulling the unchanged official image onto the household's box is arguably not distributing — a grey zone. **Needs (operator):** keep (recommended reading) or ask n8n. | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator** |
|
||||
| **R-792** | **[P3-LOW] Plex is proprietary (Plex Terms of Service): the HOUSEHOLD is the licensee under its own Plex account.** READ 2026-10-02 (the ToS page answered 403; quoted from a search snippet — `audits/licences-2026-10-02/TABLE.md`). Felhom gets no right and installs it as the household's agent; selling Plex or Plex Pass is not covered. **Needs (operator):** keep as is, or a page sentence that the Plex account is the household's own. | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator** |
|
||||
| **R-793** | **[P3-LOW] Enterprise / BUSL code ships inside four open images — Cal.com and Docmost (EE folders, off without a key), Outline (BUSL-1.1: no commercial "Document Service"), meilisearch v1.36 in Wanderer (EE modules).** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`). Each is fine as the catalog runs them: no EE key, the household's own Outline is not a Document Service, Wanderer uses plain search. **Watch:** never turn on an EE feature, never switch Karakeep's/Wanderer's meilisearch to the `-enterprise` image, and re-read on each major. | **WATCHING — rank P3-LOW; owner: CC** |
|
||||
| **R-794** | **[P3-LOW] redis 7.4 (RSALv2 / SSPL, not OSI) runs as a private cache in seven apps: dawarich, docmost, immich, nextcloud, outline, paperless-ngx, romm.** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`). Read as permitted (a private cache only its app uses is not Redis offered as a service — inferred). Valkey (BSD-3) or redis 8 (AGPL option) removes the question. **Needs:** a ladder step per app to valkey or redis 8, through the harness — no hurry. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-795** | **[P3-LOW] recipe-importer, Felhom's own image, has no licence file.** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`): all rights reserved by default; its dependencies are permissive (inferred from requirements.txt). **Needs (operator):** pick a licence (or none, on purpose) and add the file. | **WAITING-ON-OPERATOR — rank P3-LOW; owner: operator** |
|
||||
| **R-796** | **[P3-LOW] MeTube's "send to MeTube" helpers (browser extensions, bookmarklets, phone apps) cannot work behind the family gate.** READ 2026-10-02 (`audits/family-gate-2026-10-02/B/metube-reads/reads-2026.09.29.txt`): they call `/add` from another site and carry no family login; the template sets no CORS origin and MeTube has NO exception by design (an exception on an app with no login would be an open door). The household pastes links in the page (first_steps). **Needs:** nothing unless households ask; a way would be a per-member token the gate accepts on `/add` only — a design question, not a fix. | **WATCHING — rank P3-LOW; owner: CC** |
|
||||
| **R-797** | **[P3-LOW] `check-family-gate.py` rule 3 (a family_gate template needs a baked golden ≥ 0.287.0) is checked only where the felhom.eu sibling exists — CI's single clone cannot.** MEASURED 2026-10-02 (`audits/family-gate-2026-10-02/C-metube-bench/C3b-family-gate-with-sibling.txt`): without the sibling the gate printed NOT CHECKED and its summary read OK. The summary line now says "rule 3 … NOT CHECKED here". The pre-push hook (with the sibling) is where it bites. **Needs:** nothing more unless CI gets the sibling. | **WATCHING — rank P3-LOW; owner: CC** |
|
||||
| **R-798** | **[P3-LOW] Grimmory's template sets `SWAGGER_ENABLED=false`, which v3.5.0 does not read (it reads `API_DOCS_ENABLED`, default false).** READ 2026-10-02 (`audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt`). Harmless today — the API docs are off by default. **Needs:** remove the dead line or set the right name, on the next Grimmory step. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-799** | **[P3-LOW] The MeTube fixture's `POST /add` leaves out `download_type`, which upstream's validator lists as required.** MEASURED 2026-10-02 (`audits/family-gate-2026-10-02/C-metube-bench/`): both 2026.09.28 and .29 answered 200 and downloaded anyway. Fragile if a later tag enforces it. **Needs:** add `download_type: video` to the fixture with the next MeTube step. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-800** | **[P3-LOW] Removing MeTube "keeping data" answers `hdd_paths_preserved: []` although its downloads stay on the drive.** MEASURED 2026-10-02 on 9202 (`audits/family-gate-2026-10-02/B/box/life.txt`, `audits/family-gate-2026-10-02/B/box/final.txt`): the remove parses MeTube's compose as "0 HDD mounts" — its only drive mount is `${USERDATA_PATH}`, not `${HDD_PATH}` — so the result lists nothing kept; the files WERE kept and the restore used them. Other userdata-only apps (jellyfin, komga, …) have the same shape. **Needs:** check what the household's remove dialog says for such an app; list userdata mounts as kept. | **READY — rank P3-LOW; owner: CC** |
|
||||
| **R-801** | **[P2-MEDIUM] The volume-persistence gate never sent a request to ANY app: it read the routed port from label VALUES while `docker compose config --format json` puts the port in the label NAME.** MEASURED 2026-10-02 on the bench (`audits/family-gate-2026-10-02/B/volume-persistence-metube-exerciser-diag.txt`: `"ports": []`, `"exercise": []` for MeTube; the label shape read on Compose 2.26.1). So every verdict since the gate exists came only from what an app writes at start by itself; the GET exercise and the deep second pass never ran. **Fixed in the catalog** (`routed_ports()`, key=value; unit tests, red-proofed: `audits/family-gate-2026-10-02/B/RP-R801-routed-ports.txt`). **Still owed:** a full re-sweep of all 58 templates on the bench with the fixed gate — an app whose data path is written only on a request may now read differently. | **READY — rank P2-MEDIUM; owner: CC (the re-sweep)** |
|
||||
|
||||
<!-- DUE-CHECKS-BEGIN — machine-readable. Parsed by scripts/due_checks_gate.py.
|
||||
One row per dated check. The R-number must have a row above. Dates are UTC.
|
||||
|
||||
Reference in New Issue
Block a user