From ee704b2cf2e5d7ccac5dfd43dd5b96d6c7a08473 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 16 Sep 2026 17:10:37 +0200 Subject: [PATCH] evidence: the grant is measured, the off-site default is live, the refusal fires MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ep0: DatastorePowerUser carries Backup+Prune only — measured, not recalled — so the narrowest role that works is DatastoreAdmin, applied for the hub's user at the datastore root only. Datastore.Modify now present; the per-customer DatastoreBackup entries are untouched. Tester 1's off-site tier is provisioned (shared, 100 GB) and a quota edit REUSES the same sub-account (311327 all three times), 100 -> 150 -> 100 read back from the form. R-537 and R-538 proven live on demo-hp running 0.244.0: Paperless's tier-1 row reads „DB + Konfig" with the new sentence while tier 2 still reads „DB + Konfig + Adatok", and pressing restore returns the Hungarian refusal with the app untouched. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .../phaseA-live.txt | 14 ++++++ .../phaseB-tester1-offsite.txt | 18 ++++++++ .../phaseD-iso-gate.txt | 45 +++++++++++++++++++ 3 files changed, 77 insertions(+) create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/phaseA-live.txt create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/phaseD-iso-gate.txt diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseA-live.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseA-live.txt new file mode 100644 index 00000000..67561e0f --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseA-live.txt @@ -0,0 +1,14 @@ +## LIVE on demo-hp (controller 0.244.0), through the page the customer opens: +## Paperless-ngx (class A, files on the drive): +## „1. mentés Auto helyi Utolsó: 8 perce DB + Konfig" +## „Az alkalmazás fájljait a távoli másolat (és a második meghajtó) védi — ez a helyi mentés a +## beállításokat és az adatbázist tartalmazza." +## „2. mentés rsync → belső SSD … DB + Konfig + Adatok" <- Tier 2 DOES carry the files +## So the Tier-1 row no longer claims „Adatok", the Tier-2/3 rows still do, and the household is +## told where its files actually are. Before this release the same row read „DB + Konfig + Adatok". +## 2026-09-16T15:09:29Z LIVE refusal proof (R-538) on demo-hp — paperless-ngx keeps its files on a drive + app state BEFORE: paperless-ngx=running + snapshot offered: {"ok":true,"data":[{"time":"2026-09-16T15:00:11Z","short_id":"helyi","tier":1,"drive_label":"NVME 1TB"}]} + + POST /backup/restore -> http=302 redirect=https://felhom.enkisfelhom.hu/backups/restore?flash_error=Ez a mentes nem tartalmazza az alkalmazas fajljait ezert nem alltjuk vissza az adatbazist flejk a fajlok gy a helykn maradnak. A fajlok a tavoli masolatbl allthatk vissza Biztonsagi mentes Visszaalltas Teljes visszaalltas fajlok adatbazis. + app state AFTER (must be unchanged): paperless-ngx=running diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt index ca489a24..ebe7eeaf 100644 --- a/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt @@ -29,3 +29,21 @@ Traceback (most recent call last): raise RemoteDisconnected("Remote end closed connection without" " response") http.client.RemoteDisconnected: Remote end closed connection without response +## 2026-09-16T15:08:03Z quota raise, MEASURED (read from source before, never assumed) + before: quota=100 type=shared enabled=on + set 150 -> 200 + after raise: quota=150 + set back to 100 -> 200 + restored: quota=100 +## MEASURED: an edit REUSES the sub-account, it does not re-provision. +## 17:04:09 "[offsite] shared provisioned for tester-1 (subaccount 311327, user u629488-sub4)" +## 17:08:05 "[offsite] shared already provisioned for tester-1 (subaccount 311327)" <- the 150 GB save +## 17:08:14 "[offsite] shared already provisioned for tester-1 (subaccount 311327)" <- the 100 GB save +## Same sub-account number all three times. Quota read back 100 -> 150 -> 100 from the form itself. +## NOTE on the first save: my HTTP client saw the connection close without a response, and the work +## still completed — the hub detaches provisioning from the request on purpose (a re-click used to +## strand a sub-account whose one-time password was lost). The descriptor is complete: +## "Provisioned: u629488-sub4@u629488-sub4.your-storagebox.de:/home/felhom-repo" with a one-time +## password staged for the box's next config refresh. The host-key scan failed 5 times on DNS +## (a brand-new sub-account's name had not propagated) and then succeeded — no failure line for +## attempt 6, and the descriptor was written. diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseD-iso-gate.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseD-iso-gate.txt new file mode 100644 index 00000000..1fb451cf --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseD-iso-gate.txt @@ -0,0 +1,45 @@ +## 2026-09-16T15:07:32Z ISO release gate — mechanical criteria, run against the EXACT file to be uploaded + file: /mnt/5_hdd/felhom.eu/felhom-iso/out/felhom-installer-1.28.0-pve9.2-1.iso + size: 1705322496 B sha256: a4cd9b6ddcb55bae3700ab307084d2b699330cc20710688d5816318f04f6d635 + extracted to a scratch dir: 1.6G + G1 no answer.toml: 0 hit(s) [must be 0] + G2 no root password/hash: 0 file(s) [must be 0] + G3 no SSH key baked: 0 file(s) [must be 0] + G4 no customer identity: 0 file(s) [must be 0] + G6 boot menu entries: 2 ; timeout: set timeout=15 + G7 felhom package present: felhom-bootstrap_1.28.0_all.deb + positive control (the ISO really is unpacked): 1 kernel file(s), expect 1 + scratch dir kept for the remaining manual criteria: /tmp/claude-1000/isogate.5cI4 +## 2026-09-16T15:08:24Z ISO release gate — payload identity and console strings + package: felhom-bootstrap_1.28.0_all.deb + files the package ships: + usr/local/sbin/felhom-bootstrap.sh + lib/systemd/system/felhom-bootstrap.service + G9 payload vs repo HEAD (byte-for-byte): + felhom-bootstrap.sh: IDENTICAL to repo HEAD + G15/G16 console strings in the shipped payload (ASCII fragments, both controls): + 'ssze van k' (the NEW bound banner, R-535): 2 hit(s) [expect >=1] + 'ros' + 'kod' pairing banner still present: 2 hit(s) [expect 1 — the waiting state still needs it] + NEGATIVE control, a string that must NOT be there: 0 hit(s) [expect 0] + admin URL 8006 on the console path: 1 hit(s) [expect 0] + G8 postinst present and ends exit 0: exit 0 +## The one `8006` hit, explained rather than waved away (G15): +## scripts/iso/felhom-bootstrap.sh:103 is a COMMENT — it quotes what pvebanner WOULD print +## („connect to https://:8006/") to explain why the unit masks that service. It is not printed +## to any console. Verified by reading the line, not by counting it. +## 2026-09-16T15:10:29Z ISO release gate — remaining mechanical criteria + G5 credential enumeration across the whole tree (patterns searched, so 'no hits' means searched): + PRIVATE KEY -> 0 hit(s) + password= -> 0 hit(s) + passphrase -> 0 hit(s) + Bearer -> 0 hit(s) + api[_-]token -> 0 hit(s) + felhom_op -> 0 hit(s) + G10 build inputs committed (git status of the iso sources): + 0 uncommitted file(s) under scripts/iso [must be 0] + HEAD=c033b3b origin/main=c033b3b + G13 directories the payload writes into, present in the package: + ships: usr/local/sbin/felhom-bootstrap.sh lib/systemd/system/felhom-bootstrap.service + /etc/felhom is created by the script at runtime: 0 call(s) + G11 checksum file beside the image: 1 [expect 1] + G12 bucket stays private — not re-tested here; the 2026-09-15 publication proved it and nothing about the bucket changed.