From f4c5466c390ef2cea84a05b713f3a292cee1d762 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Sat, 3 Oct 2026 09:24:43 +0200 Subject: [PATCH] Backlog triage Part E: RECOMMENDATION (top 29 = every P2, five themes, pick A off-site backup safety vs B box OS updates), STATUS decision, REPORT-backlog-triage-2026-10-03 Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- REPORT-backlog-triage-2026-10-03.md | 77 ++++++++++++ STATUS.md | 20 ++- .../RECOMMENDATION.md | 115 ++++++++++++++++++ 3 files changed, 211 insertions(+), 1 deletion(-) create mode 100644 REPORT-backlog-triage-2026-10-03.md create mode 100644 documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md diff --git a/REPORT-backlog-triage-2026-10-03.md b/REPORT-backlog-triage-2026-10-03.md new file mode 100644 index 00000000..04b4a09a --- /dev/null +++ b/REPORT-backlog-triage-2026-10-03.md @@ -0,0 +1,77 @@ +# REPORT — backlog triage, 2026-10-03 + +Paperwork session. **No machine touched. No release. No golden.** Other repos read only. +Baseline: felhom.eu `main` `9305288` (verified). Commits: A `9e2786c` · B `71b8c8c` · C `9f77865` · D `33bbf8e` · +E (this commit). + +## The Part table + +| Part | Done? | Changed from the brief, and why | +|---|---|---| +| **A** — four roadmap items | **Done.** R-808 (box OS security updates), R-809 (legal + business papers), R-810 (independence, spike), R-811 (second login step). Findings filed beside two: **R-812** (no box receives OS security updates), **R-813** (website: no privacy notice, terms or imprint). `00` gained three §E/§G gap rows and a new §H "Business & legal". CONTEXT records the request first. | R-810 and R-811 got no register finding: nothing about them is false today (one password is a stated limitation, `00` §E). | +| **B** — finished rows out + gate | **Done.** 125 rows with an id and 20 without moved to `CLOSED-ITEMS.md` (one dated section, each naming `git show 9e2786c:…`). Open rows normalised to one shape. Narratives (campaign write-ups, rulings, old ranking paragraphs) moved word for word to `documentation/archive/OPEN-ITEMS-narratives-2026-10-03.md`. `closed_register_gate.py` **RULE 3**. Workflow text in `PROMPT-TEMPLATE.md` §N.7/§N.5 and `CLAUDE.md`. Loose notes: verdict per file in `backlog/README.md`. | 14 rows with an OPEN verdict were found finished and moved — each checked by me against live source (list below). 11 rows with a finished verdict **stayed open**, narrowed, because they name work no other row carries (R-451, R-579, R-610, R-618, R-621, R-635, R-691, R-707, R-719, R-723, R-738). Two loose notes stay in place (other repos link to their path). There is no "Deliverables" line in the template; §N.5's "report which rows" line gained "closed (and moved), narrowed". | +| **C** — category + severity | **Done.** Columns `| ID | Category | Sev | What | State | Blocked on | Next action | Owner |`; one section per category, severity order inside. `register_shape_gate.py` RULES 5–8. Duplicates folded: R-248 → R-246, R-580 → R-132. | A **column**, not a title tag: the gates read cells by the header's column NAME (new helper `register_table.py`), which a tag in prose cannot give reliably. Not folded (judged not duplicates): R-287/R-291, R-450/R-469, R-123/R-369 (R-123 closed anyway). Operator-owned rows: listed in `RECOMMENDATION.md`, with one line and the count in STATUS — STATUS is one screen and holds no ids. | +| **D** — clean ROADMAP | **Done.** 161 → 124 lines, 81 → 42 KB. Intentions re-sorted P2/P3/P4, each names its `00` row. 33 items + the pre-invite checklist → `ROADMAP-HISTORY.md`. UPDATE-ARC collapsed. Pre-invite list → pointer to STATUS. | R-48 was SHIPPED (controller v0.154.0) though the roadmap still listed it as an idea. Fixing `one_register_gate.py` to read suffix ids found R-50b — a finding that lived only in the roadmap; moved to the register. | +| **E** — ranking + recommendation | **Done.** `documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md` and one decision in STATUS. | The top list is 29 rows: every P2. No P1 exists, so severity alone fills the 20–30. | + +## Headline numbers + +- `OPEN-ITEMS.md`: **442 rows with an id + 22 without, 824 KB, 932 lines → 326 rows, all with an id, ≈540 KB.** +- Moved to `CLOSED-ITEMS.md`: **125 + 20**. Marked VERIFY: **11**. New rows: **11** (R-812..R-819, R-50b moved in). +- Category × severity (P2/P3/P4; **no P1**): Install 2/11/5 · Apps 0/15/21 · App updates 0/12/7 · Backup 12/24/20 · + Storage 0/7/5 · Security 3/23/3 · Box system 3/11/3 · Monitoring 2/16/6 · Hub 1/7/13 · Business 4/0/3 · + Process 0/4/83 — totals **27 / 130 / 169**. + +## Claims in the brief that turned out wrong + +1. **The row counts.** Measured at `9305288` with a split that skips pipes inside backticks: **442** id rows (not + 444) plus **22 rows with no id** the count missed. By leading verdict: **113** finished (107 CLOSED + SHIPPED 2, + FIXED 1, RULED 1, EXECUTED 1, ANSWERED 1), plus 4 DECIDED and 1 "✅ CLOSED" — 118 for the new gate; **195** + READY (not ~129); OPEN 74 + NARROWED 10; WAITING-ON-OPERATOR 15; WATCHING 15. **"~125 unreadable" was wrong:** + in those six-column tables the state is the THIRD column — the script read the last one, which is the owner. Only + **18** rows needed a person: 5 because of a pipe in prose, 13 because their state word was undefined. +2. **"Nothing updates the host or guest OS" — TRUE for boxes**, with two nuances: the installer points the host at + the no-subscription repository "so the box can pull security updates" and then says "No upgrades are run"; the + guest's Docker engine is current only on the day the golden is baked. The one `apt full-upgrade` in the project is + a by-hand step for the off-site endpoint ep0. +3. **"The website has no legal pages" — TRUE.** Worse than stated: the contact form asks for data-processing + consent and links to no notice. +4. **"No document answers the independence question" — PARTLY WRONG.** The LOST-hub half is answered + (`architecture/_recovery-inventory-2026-07-28.md` §D2.4; `07` §8 row 11b), and `01` §7 rules that the customer + owns the domain. Leaving, export and hand-over are answered nowhere — R-810 keeps those. +5. **"No gate refuses a closed row in OPEN-ITEMS" — TRUE.** One more gate had the same blind spot in another shape: + `instructions_gate.py` read the state by position and would have misread the new layout; fixed. + +## Rows found finished and moved (verified by me, evidence in each CLOSED entry) + +R-123, R-131, R-202, R-229, R-272, R-295, R-343, R-369, R-398, R-500, R-506, R-572, R-590, R-800. + +## Gates — new rules and decoys, each seen red + +- `closed_register_gate.py` RULE 3 — red on the real register before the move (118 convicted). Decoy + `finished-row-in-open` **passed the old gate**; convicts now. Genuine article (READY, prose says "closed") passes. +- `register_shape_gate.py` RULES 5–8 — five decoys (old-shape row, near-miss category, `P3-LOW` as Sev, undefined + state word, pipe outside backticks): **all five passed the old gate**; all convict now. +- `one_register_gate.py` — suffix ids and backtick-aware split; decoy `suffix-id-row` **passed the old gate**. +- Suite: `test_gate_decoys.py` 29/29; `test_instructions_gate.py` 73/73; `repo_gates.py --fast` OK at every commit. + +## Rules carried out of closed rows + +21 sentences that stated a rule and had no other home → `CONTEXT.md` ("Rules carried out of rows closed +2026-10-03"); the three decisions among them (R-245, R-303, R-312) → `07` §11 as `[DESIGN]`. + +## Observations + +1. `scripts/check_stands.py` is red and runs in no runner (2 dangling ids before today, 3 more after rows closed). + FILED: R-819. +2. `09` decision 56 and R-745 disagree about the controller self-update's roll-back target. FILED: R-817. +3. Two changelogs cite R-330/R-331 for other findings. FILED: R-818. +4. F-DIAG's six off-site failure messages have never been seen on a real failure. FILED: R-816. +5. Two July watch rows had no id and no recorded outcome (a Storage Box deletion; the first GC on the off-site + datastore). FILED: R-814, R-815. +6. One stray duplicate owner word ("operator") in R-209a's broken extra cell was dropped in normalising; every other + word of every open row is kept (checked by a token diff). NOT-A-FINDING: a duplicated cell, not content. + +## Teardown + +Provisioned nothing. diff --git a/STATUS.md b/STATUS.md index 2631540f..907ada0c 100644 --- a/STATUS.md +++ b/STATUS.md @@ -2,9 +2,23 @@ **Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).** -**Updated 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New +**Updated 2026-10-03 (the to-do list put in order). Versions unchanged since 2026-10-02 (afternoon). Both demo boxes run controller 0.288.0 and host agent 0.138.0. Hub 0.126.0. New installs get golden 0.288.0 with agent 0.138.0.** +## Today (2026-10-03): the to-do list is in order — paperwork only, no machine touched + +- **Finished items left the open list.** It went from 442 rows to 326. Nothing was deleted; each moved row names + where its full text is. +- **Every open row now has one category and one severity** (P1 now · P2 before the first paying customer · P3 + during the first customers · P4 later). **No row is P1.** 27 rows are P2. +- **Two new automatic checks** refuse a finished row left in the open list, and a new row without a category or a + severity. +- **Your four new items are on the roadmap:** security updates for the box's own system; legal pages and business + papers; "what if the household leaves Felhom"; a second login step for the dashboard. Two of them are also real + findings today: **a box never receives system security updates**, and **the website has no privacy notice, + terms or imprint.** +- The ranked list and my reasoning: the triage recommendation in the audits folder. + **Tester-2 — read only, from the hub.** The customer record exists. Tester-2's box has not registered yet. ## Today (afternoon): every app checked again @@ -41,6 +55,10 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne ## What needs you +0. **Pick the next theme.** **A — off-site backup safety** (recommended): a dated check on it turns red on + 6 October and then refuses every push until it is done; it guards the household's own files. **B — box system + security updates**: nothing patches a box today; a test on a throwaway box comes first. **If you say nothing:** + the next session starts A. 18 rows wait on you; the list is in the triage recommendation. 1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say nothing:** it stays hidden; nothing runs it. 2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list). diff --git a/documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md b/documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md new file mode 100644 index 00000000..10d1cdc2 --- /dev/null +++ b/documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md @@ -0,0 +1,115 @@ +# What to work on next — backlog triage, 2026-10-03 + +## In one screen + +- **The open list is now readable.** It went from 442 rows to 326. It went from 824 KB to about 540 KB. +- **Every open row has one category and one severity.** Two gates refuse a row without them, and refuse a + finished row left in the open list. +- **No row is P1.** Nothing in the list is harm that happens today on shipped code. 27 rows are P2 (must be done + before the first paying customer). +- **You decide one thing:** which theme starts next. Recommendation: **off-site backup safety**. The other + option: **box system security updates**. Details are in "The decision" below. + +## Headline numbers (before → after) + +| | before | after | +|---|---|---| +| rows in the open list (`OPEN-ITEMS.md`) | 442 with an id + 22 without | 326, all with an id | +| size of the open list | 824 KB, 932 lines | ≈540 KB | +| finished rows moved to `CLOSED-ITEMS.md` | — | 125 with an id + 20 without | +| rows marked VERIFY (may be finished; not proven) | — | 11 | +| rows with no severity | the reviewer counted ~182 | 0 | +| new rows filed this session | — | 11: R-812, R-813 (findings beside two roadmap items), R-814, R-815 (old July watches that had no id), R-816 to R-819 (gaps found while sorting), R-50b (a finding that lived only in the roadmap) | +| roadmap (`ROADMAP.md`) | 161 lines, 81 KB | 124 lines, 42 KB | + +**Open rows, category × severity** (no P1 anywhere): + +| Category | P2 | P3 | P4 | total | +|---|---|---|---|---| +| Install & onboarding | 2 | 11 | 5 | 18 | +| Apps & catalog | 0 | 15 | 21 | 36 | +| App updates | 0 | 12 | 7 | 19 | +| Backup & restore | 12 | 24 | 20 | 56 | +| Storage & devices | 0 | 7 | 5 | 12 | +| Security & access | 3 | 23 | 3 | 29 | +| Box system & updates | 3 | 11 | 3 | 17 | +| Monitoring & notifications | 2 | 16 | 6 | 24 | +| Hub & operator | 1 | 7 | 13 | 21 | +| Business & legal | 4 | 0 | 3 | 7 | +| Process & tooling | 0 | 4 | 83 | 87 | +| **total** | **27** | **130** | **169** | **326** | + +## The top 29 — every P2, open list and roadmap together + +Order: severity first, then "a household meets it", then cost (small first). Size: XS < S < M < L. + +| # | ID | Category | Size | Household meets it? | What is wrong or missing | +|---|---|---|---|---|---| +| 1 | R-508 | Install & onboarding | XS | yes | The hub does not warn when a customer who waits for a box has no e-mail address. | +| 2 | R-509 | Install & onboarding | XS | yes | A new box for an existing customer may not send the connect e-mail. Fix shipped; never seen live (VERIFY). | +| 3 | R-604 | Box system & updates | S | yes | A per-customer version floor can keep one box out of every fleet update, silently. | +| 4 | R-784 | Business & legal | S | yes | SparkyFitness forbids commercial use; the author's written permission is needed. | +| 5 | R-789 | Business & legal | S | yes | Tandoor's licence may forbid selling a service built on it; the authors' permission is needed. | +| 6 | R-342 | Backup & restore | S | yes | Nothing protects the off-site backup data if maintenance on that server goes wrong. | +| 7 | R-813 | Business & legal | S | yes | The website collects personal data but has no privacy notice, no terms and no imprint. | +| 8 | R-243 | Monitoring & notifications | M | yes | A box that waits for its recovery key stops off-site backups, and nobody is told. | +| 9 | R-95 | Backup & restore | M | yes | A box can delete its own off-site backups, and no older copy can be read back today. | +| 10 | R-436 | Backup & restore | M | yes | The provider's "append-only" lock (a box may add but not delete) is untested. **Its check is due 2026-10-06.** | +| 11 | R-726 | Backup & restore | M | yes | A returning customer's new box makes no off-site backup until someone presses a hidden reset. | +| 12 | R-366 | Backup & restore | M | yes | After a reinstall the box cannot read its older whole-machine backups, and it reads as a test failure. | +| 13 | R-32 | Backup & restore | M | yes | Resetting a customer leaves their old encrypted off-site data behind, unseen and uncounted. | +| 14 | R-105 | Backup & restore | M | yes | Two records a whole-box recovery needs may still be empty on the hub; not checked again. | +| 15 | R-518 | Backup & restore | M | yes | "Back up now" stops every app for minutes while a slow second backup runs. | +| 16 | R-519 | Backup & restore | M | yes | After an interrupted backup, a restore point shows a newer time than its files. | +| 17 | R-638 | Backup & restore | M | yes | Restoring a database copy from before an update can fail on top of the newer database. | +| 18 | R-528 | Monitoring & notifications | M | yes | An app killed for lack of memory is often not reported. | +| 19 | R-777 | Security & access | M | yes | Emby and Jellyfin treat internet visitors as home-network visitors and skip their remote limits. | +| 20 | R-304 | Backup & restore | L | yes | A household's correct recovery code for old backups is rejected as wrong. | +| 21 | R-812 / R-808 | Box system & updates | L | yes | Nothing ever installs operating-system security updates on a box (host, guest, Docker engine). | +| 22 | R-809 | Business & legal | M | yes | Contract, data-processing agreement, billing and invoicing do not exist yet. | +| 23 | R-135 | Security & access | S | no | The hub skips its forged-request check when no session cookie is sent. | +| 24 | R-802 | Business & legal | M | no | A lawyer must review the list of non-open-source licences. | +| 25 | R-133 | Security & access | M | no | Every copy of the hub database holds every box's root console password in readable form. | +| 26 | R-173 | Hub & operator | M | no | The hub database, which holds recovery secrets for every box, has no scheduled backup. | +| 27 | R-530 | Box system & updates | M | no | Host agents update only by a signed job per box, and nothing lists which boxes are behind. | +| 28 | R-232 | Backup & restore | L | no | The server that runs the hub keeps all its backups on itself, nothing off-site, and a failure alerts nobody. | + +(R-808 and R-812 are one item: the roadmap intention and its finding. 28 lines, 29 rows.) + +## Five work themes (about one session each) + +1. **Off-site backup safety** — R-436, R-95, R-342, R-243, R-726, R-366, R-32, R-105, R-304. The household's + files and photos sit in the tier whose credential can delete. Start with R-436's measurement (due 2026-10-06), + then the cheapest step that stops a box deleting its own history. +2. **Box system security updates** — R-812 / R-808, R-604, R-530. A spike first (what the agent may run, what a + half-done update leaves), on a throwaway box. Nothing exists today. +3. **The hub's own safety** — R-133, R-135, R-173, R-232. Operator-side; no household meets it directly, but a hub + loss or leak touches every box. R-232 is on DooPlex, which needs an operator word before anyone touches it. +4. **Honest backup and app behaviour** — R-518, R-519, R-638, R-528, R-777, R-508, R-509. Smaller items a + household meets; good for a session after theme 1. +5. **Business and legal** — R-809, R-813, R-784, R-789, R-802. **Yours**, not a CC session. CC drafts a text when + you ask. It can run beside any other theme. + +## The decision + +**Which theme does the next session start with?** + +| | A — Off-site backup safety (recommended) | B — Box system security updates | +|---|---|---| +| What it does | Measures the provider's append-only lock (R-436), then closes the biggest data risk: a box that can delete its own off-site history (R-95). | A spike on a throwaway box: what update path is safe for host, guest and Docker engine. Then a design. | +| What it costs | One session. Touches the off-site test account, never a customer's data. | One spike session plus a later build session. Touches only a Tier-0 box. | +| Why | The largest data risk the list has ranked first since July. The household's own files sit there. | Boxes stay in homes for years. Today they never receive a security patch. | +| If you decide nothing | On 2026-10-06 the dated check turns red and refuses every push to this repo until the measurement is done or the date is moved. | Boxes keep the packages they were installed with. Nothing breaks this week; the risk grows every month. | + +**My pick: A.** It has a hard date in three days, it guards the household's data, and it needs no new mechanism. +B is next. + +## Rows that wait on you (18) + +R-132 (change the hub password), R-169, R-210, R-503, R-504, R-508, R-526, R-530, R-719, R-769, R-770, R-771, R-779, +R-784, R-789, R-802, R-804, R-813. The P2 ones are in the top list above. Each row says what it needs from you. + +## Rows marked VERIFY (11) — may already be finished; nobody proved it + +R-274, R-282, R-284, R-287, R-509, R-527, R-602, R-621, R-814, R-815, R-817. Each carries, at the start of its state, +what suggests it is finished and the evidence pointer. Close one only after checking it against live source.