burn-down Part A: 24 rows closed as fixed by later work, 2 duplicates merged, R-376/R-817/R-818 done (335 -> 306); Part A table
gates / gates (push) Failing after 1m16s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 16:53:02 +02:00
parent 58ce696e16
commit f5a0aeb0b8
8 changed files with 714 additions and 38 deletions
+29
View File
@@ -33,6 +33,35 @@ The full text of every row below: `git show ab2b3049:documentation/backlog/OPEN-
| Row | What | Closed | Evidence |
|---|---|---|---|
| **R-885** | **The Python tests under `felhom.eu/scripts/` did not run in CI (P4).** New gate `script-tests` (`scripts/script_tests_gate.py`) walks `scripts/` and runs every `test_*.py` on every push (13 suites, ~20 s); a suite's verdict is its exit code; finding none fails; nested runs step aside. The hub-DB script tests use a Python-sqlite3 stand-in when the CI runner has no `sqlite3` CLI (said out loud). Decoys (5) declared in `test_gate_decoys.py`; red-proofs R885-a/b convict. | CLOSED 2026-10-05 — FIXED (gate) | `scripts/script_tests_gate.py`; `scripts/test_script_tests_gate.py`; `audits/burndown-2026-10-05/r885-red-proof.txt` |
| **R-184** | **Nothing prevents the hub from vouching an agent version that was never released.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Fixed by felhom.eu b55fc17d "hub v0.102.0 — refuse to vouch a version that cannot be installed (R-273)" — exactly shape (b), validate at vouch time in the hub. felhom.eu/hub/internal/web/configs.go:1358 `res := s.gitea.PackageDownloadable(ctx, t.pkg, t.version, t.file)` and :1365 `s.logger.Printf("[WARN] artifact vouch REFUSED: %s package %s is NOT downloadable (R-287)", ...)`; tag leg at :1343 TagServesFile; unreachable registry also refuses. |
| **R-207** | **`DRY_RUN=1` on `node-housekeeping.sh` is NOT non-mutating — it destroys the metric history it is supposed to let you inspect** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Fixed by homelab-manifests fc9fbb8 "node_housekeeping: guard DRY_RUN, correct the expired Docker rationale, pin container log rotation". /home/kisfenyo/git/homelab-manifests/homelab-ansible/roles/node_housekeeping/templates/node-housekeeping.sh.j2:137 `if [[ "${DRY_RUN}" == "1" ]]; then` inside write_metrics, :138 logs "file left untouched". |
| **R-287** | **`felhom-agent` CI is red for a TRUE reason, and the diagnosis it was filed under is wrong in every particular.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Deleter established 2026-08-10 (R-267 newest-10 prune, recorded in the row itself); CI fixed by felhom-agent 53d047a "Two guards, one number: bound the published check to the retention it must live with" (R-291). felhom-agent@e06ed97 scripts/check-published-versions.py:101 `RETENTION_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), "retention-policy.json")`, :213 `keep = retention_kept()`; scripts/retention-policy.json:37 `"generic_versions_kept": 10,`. Follow-up row R-291 is open (OPEN-ITEMS.md:439). |
| **R-289** | **R-182's register row describes a defect the code no longer has — an OPEN row that is a false alarm.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | R-182 was closed by felhom.eu ef6ac6fe (2026-08-22, register compression): documentation/backlog/CLOSED-ITEMS.md:474 `/ **R-182** / ... / **CLOSED — SHIPPED** (controller v0.194.0 + hub v0.90.0/.1, 2026-08-03) /`. The residue (digest never seen delivering) was since observed: documentation/audits/DRILL-chaos-night-2026-09-17.md:181 `backup_run_failures` „1 of 12 apps failed to back up in this nightly run: nextcloud" listed as an alarm that fired and was true. |
| **R-373** | **`SysDataGrowGB` is the intended lever for the system-data volume, it works, and nothing sets it.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Premise (20G/50G two-volume mismatch, 'nothing sets SysDataGrowGB') was retired by agent v0.120.0 one-data-volume work, commit cd6e267 'v0.120.0 — one data volume (R-165...)'. felhom-agent/internal/reconcile/bringup.go:191 '// SysDataGrowGB is a COMPATIBILITY INPUT since agent v0.120.0 (R-165). There is no longer a second' and :437 'growGB := spec.DataVolGrowGB + spec.SysDataGrowGB'; installer passes it (felhom-host-install.sh:3140 '-sysdata-grow "$SYSDATA_GROW"') and records the sizing at :2041-2058. Note: cd6e267 predates the row's filing date; the row quoted an older audit. |
| **R-390** | **The golden-bake runbook omits `pveam update`, and the failure it produces names the wrong cause.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Commit 2344589a ('... runbook pveam note'); felhom.eu/documentation/runbooks/RUNBOOK-manual-build.md:154 '2. Run **`pveam update` first** — the `virgin` snapshot's template INDEX is stale too, and a stale index fails as a bogus'. |
| **R-427** | **`closed_register_gate.py` checks ONE direction only: an open word in a CLOSED row. The mirror — a CLOSED verdict on a row still sitting in `OPEN-ITEMS.md` — is unchecked, and there are TWELVE.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Commit 71b8c8c6 (Backlog triage Part B: '... closed_register_gate RULE 3 refuses a finished row in OPEN-ITEMS'); felhom.eu/scripts/closed_register_gate.py:10 'RULE 3 — (2026-10-03) no row in `OPEN-ITEMS.md` may carry a CLOSED-family word (CLOSED, SHIPPED,'. Of the 12 named rows, R-385/387/341/378/405/88a/88b/123 are now only in CLOSED-ITEMS.md; R-190 and R-352 remain open (partly-closed, as the row predicted). |
| **R-437** | **The register compression sweep is OWED, and it was deliberately NOT run inside the 2026-09-01 beta-line session — this row is the record of that choice, not a note.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu 71b8c8c6 'Backlog triage Part B: 125 finished rows + 20 id-less rows moved to CLOSED-ITEMS ... closed_register_gate RULE 3 refuses a finished row in OPEN-ITEMS (decoys, seen red) ... register 444 -> 325'. felhom.eu/scripts/closed_register_gate.py:10 'RULE 3 — (2026-10-03) no row in `OPEN-ITEMS.md` may carry a CLOSED-family word'. Gate run today: 'closed-register gate OK — no open work filed as closed, no id in both registers.' (456 closed / 336 open, 0 convicted). |
| **R-464** | **[P3-LOW] MariaDB's entrypoint prints `MariaDB upgrade not required` on an UNSUPPORTED DOWNGRADE, so that line cannot be used as a soundness signal.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Lesson homed and harness uses the correct probe. app-catalog-felhom.eu b7ef0c4 'upgrade-test.py: record the engine's own view of its datadir'; app-catalog-felhom.eu/scripts/upgrade-test.py:278 '"mariadb-upgrade --check-if-upgrade-is-needed --user=root "'. felhom.eu d6837d98 (SPIKE R-459); felhom.eu/documentation/architecture/09-update-architecture.md:1647 '1. **Ask the engine, not the log.** MariaDB's entrypoint prints `MariaDB upgrade not required` on an' (cites R-464). |
| **R-501** | **[P3-LOW] The documented "confirm your CI run" recipe reads only the LAST page of the jobs list, and that list is not in id order — so it can report a run as missing that exists and passed.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu a4993272 'CLAUDE.md: the CI-check recipe was wrong in two ways, both measured today'. felhom.eu/CLAUDE.md:176 'rows — a run can sit several pages earlier. **Scan every page** and match on `head_sha`; with a'; recipe at CLAUDE.md:166-168 loops every page. |
| **R-602** | **[P3-LOW] The language a signed-in page uses is NOT the language a cookie asks for, and a live probe that forgets this reports a fixed defect as unfixed.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu e02bc038 'hub v0.119.0 — ... R-596/R-598 closed' added the finding; felhom.eu/documentation/architecture/10-localisation.md:809-812 'the `felhom_lang` cookie and got the **Hungarian** page for `en`. ... The cookie is the right instrument for the anonymous claim page and the **wrong**' and :509 '`langFor`'s order is fixed: `?lang=` → **the household's setting when a session exists**'. Only the optional pointer from the workspace live-validation rules is absent (grep ?lang=/felhom_lang in CLAUDE.md files and .claude/rules: none) — a 5-minute add if wanted. |
| **R-617** | **[P3-LOW] The Gitea API token this project uses for pushes cannot create a repository through the documented endpoint, but CAN through `repos/migrate` — so "the token cannot do it" was nearly recorded as a fact when the truth was "one endpoint refuses it".** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu@462ab4a5 (2026-09-22) documentation/architecture/09-update-architecture.md:1969 "`POST /api/v1/repos/migrate` is the route that works (the project's Gitea tokens carry" - continues at :1970 "`write:repository` but not `write:user`, so `POST /user/repos` answers 403"; recipe at :1979. The one-line note the row asked for exists (in the architecture doc rather than operations/). The optional operator-scoped token is a separate wish, not the defect. |
| **R-705** | **[P3-LOW] There is no way to run the night's chain now — only its pieces.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | The remaining half (manual whole-guest backup) EXISTS and predates the row: felhom-controller bbed5af (v0.47.0, 2026-06-12) 'backups page — whole-guest backup visibility + manual trigger'. Live source @7690c27: controller/internal/web/backup_handlers.go:324 `case r.URL.Path == "/api/guest-backup/trigger" && r.Method == http.MethodPost:`; :340 `if err := s.backupTrigger.TriggerNow(); err != nil {`; quiesce.go:427 "manual backup requested — quiescing now" (bypasses due-ness, all tiers); wired cmd/controller/main.go:2099 and the page button backups.html:229. Agent side: felhom-agent internal/localapi/server.go:514 `mux.HandleFunc("POST /backup", ...)`. The controller half was built v0.279.0 (night-chain, handler_debug.go:79). The row's 'no manual trigger' claim was not true at writing; it is not chained into night-chain, which the row did not require. |
| **R-766** | **[P3-LOW] A new app's logo and screenshots reach the boxes only with the next HUB release — the website alone is not enough.** (P4) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Hub releases after the assets push (felhom.eu 40f07429, 2026-10-01): hub v0.131.0 (2026-10-04) .. v0.136.0 (d4be9f6f, 2026-10-05). The build copies website assets: felhom.eu scripts/build-hub.sh:98 `cp "${WEBSITE_ASSETS_DIR}"/*-logo.svg "${BUILD_DIR}/assets/" 2>/dev/null // true`, and the hub build workspace /mnt/5_hdd/felhom.eu/build/felhom-hub/workspace/assets/ holds radicale-logo.svg + 3 screenshots (also karakeep, dawarich) dated Oct 5 14:28; hub/Dockerfile:27 `COPY assets/ /usr/share/felhom/assets-seed/`. Not checked: what a live box shows (no machine access). Checked 2026-10-05: the live hub image (v0.136.0) `/usr/share/felhom/assets-seed/` holds radicale-, karakeep- and dawarich-logo.svg + screenshots. |
| **R-50b** | **[P2] A root-owned privileged host artifact is delivered unversioned from `main` — "which wrapper is on this host?" is unanswerable.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | Claim 'fetched via fetch_raw from raw/branch/main — no tag, no pin' no longer true: bee68484 (installer v1.23.0, R-110/R-183) pinned fetch_raw to the vouched agent tag — felhom.eu scripts/felhom-host-install.sh:533 '"$GITEA_BASE/$GITEA_OWNER/$AGENT_REPO/raw/tag/v$ART_AGENT_VER/$path" \' (leg b). Leg (c)-like signed delivery: felhom-agent c9fa2e7 (R-840 config bundle) and configs/test_felhom_config_bundle.py:264 covers /usr/local/sbin/felhom-pbs-apply. Residual worth one line if kept: the 0440 sudoers drift visibility note. |
| **R-121** | **A BOX's installed agent can sit releases behind the vouched one and nothing notices — the R-120 gate does not cover it.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | 3d7a2761 (hub v0.135.0, R-530/R-604 'boxes left behind listed and alarmed'): felhom.eu hub/internal/osupdates/service.go:79 'EventAgentBehind = "agent_behind" // warning, operator' with :180 'AgentBehindAfter: a box runs an agent older than the vouched one this long → an operator alarm' (7 d window, the staleness window the row asked for). |
| **R-200** | **The DR password-injection seam has a handler, a route and tests — and no form.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | The remaining half (customer-facing recovery-code form: yell → R form → preview) shipped as the recovery screen: felhom-controller 636c51e 'R-193: the recovery screen — unlocking, and only unlocking (v0.200.0)'; controller/internal/web/templates/recovery.html:82 '<form id="unlock-form" method="POST" action="/recovery/unlock" autocomplete="off">', routed at internal/web/server.go:602. Plumbing half was 1b1366b (v0.196.0). The 64-hex inject-password route (server.go:783) stays a deliberate DR fallback with no form. |
| **R-450** | **[P2-MEDIUM] UPDATE ARC SLICE 6 — a version sequence: automatic WITHIN a major, never ACROSS one, and an engine change gets its OWN edge.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | The row's only remainder was 'the other ten PostgreSQL apps need two-venue proof'. R-463 CLOSED 2026-09-30 by felhom.eu 25cb3eb9 ('The last six PostgreSQL apps decided'): 8 of 11 moved by the box's own conversion, 3 (zipline, adventurelog, immich) stay by decision 42; CLOSED-ITEMS.md:223. Source proof: app-catalog templates/docmost/docker-compose.yml:62 'image: postgres:18-alpine' (also rallly:67, outline:64, paperless-ngx:101). The per-app engine gate stays as the permanent rule (catalog CLAUDE.md:115-122). |
| **R-489** | **[P3-LOW] `POST /api/stacks/{name}/remove` reports `volumes_removed: null` over named volumes it DID remove.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | The residual (a unit-restore-recreated volume has no compose label, so the remove answered []) was fixed in felhom-controller 206b035 (v0.268.0, R-658). controller/internal/stacks/delete.go:1089-1090: '// appVolumeSet is every volume the removal accounts for: the ones carrying the project label AND the // ones the app's definition declares that Docker holds by name (R-658, v0.268.0).' delete.go:703 'resp.VolumesRemoved = removedVolumes(volsBefore, m.appVolumeSet(name, stackDir))'. |
| **R-573** | **[P3-LOW] The agent-channel and endpoint-drift banners reach the dashboard as finished Hungarian, so they stay Hungarian on an English page.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom-controller 7c4a33b (v0.258.0, 'the last four Hungarian things an English household met ... R-573 the two channel banners'). controller/internal/web/alerts.go:113 'func (am *AlertManager) SetAgentChannelAlert(down bool, msgKey, msg string) {' and :136 'func (am *AlertManager) SetEndpointDriftAlert(drift bool, msgKey, msg string) {'. Both set MessageKey with msg only as a fail-open fallback. |
| **R-622** | **[P2-MEDIUM] `adventurelog v0.13.0` migrates the customer's database and then does not serve — the edge must NOT be promoted, and it is the first real-catalog candidate this project has measured as unsafe.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | adventurelog v0.13.0 was diagnosed, fixed and promoted with a two-venue test record in app-catalog-felhom.eu 06ea7da (2026-09-27, 'adventurelog: v0.12.1 -> v0.13.0 with its health and world-data fixes in the same commit (R-655, 09 decision 41)'; bench healthy in 217 s, box 9202 through the guarded Update in 204 s). templates/adventurelog/docker-compose.yml:13 ' image: ghcr.io/seanmorley15/adventurelog-backend:v0.13.0'. The proven step is recorded at templates/adventurelog/.felhom.yml:132 (update_ladder entry from v0.12.1). |
| **R-635** | **[P1-HIGH] `romm 5.3.0` does not fit the memory the template gives it, and the guarded Update called that a success — the app has been OOM-crash-looping on demo-hp for six hours at ~500% CPU.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | The open remainder (app_oom fires once per container run, no escalation) was built in felhom-controller 0054d4b (v0.265.0, 'OOM storm alarm', R-636). controller/internal/notify/notifier.go:746 '\t\tn.emit("app_oom_storm", "error",' fires once per run when 20 or more kills land in 30 min (:754-764, oomStormKills=20, oomStormWindowMin=30; pinned by TestR636_*). The 79 % headroom and the method lesson are carried by R-462 (per the row). |
| **R-235** | **The appliance console keeps telling an already-paired box to go and pair itself.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu c033b3b6 'ISO 1.28.0 source: the console stops showing the pairing code once bound (R-535)'. scripts/iso/felhom-bootstrap.sh:538: `print_bound_banner # R-535: replace the pairing code on the console with the truth`. Same defect already CLOSED twice in CLOSED-ITEMS.md as R-535 (line 232) and R-214 (line 200, 'proven on a fresh install'). |
| **R-282** | **One secret, three different Hungarian names, and the email sends the customer to a page their box is not showing.** (P3) | CLOSED 2026-10-05 — FIXED BY LATER WORK (burn-down Part A) | felhom.eu 4d6ec7c 'hub v0.104.0: ... the hub half of the naming (R-295)' + controller v0.211.0 (R-295 CLOSED, CLOSED-ITEMS.md:207) + R-323 hub v0.105.0. hub/internal/notify/templates.go:204: '// R-295, HUB HALF (2026-08-13). ONE NAME PER SECRET, and it is „Beállító kód".'; hub/internal/claim/engine.go:51 `EmailReenroll EmailKind = "reenroll"` (mail names the setup page a rebuilt box shows). |
| **R-376** | **The placement decision that cost four mis-filed defect reports was never recorded as a decision anywhere, and the architecture folder's own marker convention lives in one document of eight.** (P4) | CLOSED 2026-10-05 — DONE | The legend reached the three documents written after the 2026-08-22 pass (`08`, `09`, `11`); all eleven numbered architecture documents now carry it (`grep -c "not yet classified"` = 1 each; `07` is the original home). The hot/bulk decision was given its home on 2026-08-22 (`01` [DESIGN] + CONTEXT). Marking every statement stays a practice of each session that touches a document, not a defect. |
| **R-817** | **`09` decision 56 and R-745 disagree about what the controller self-update rolls back to.** (P4) | CLOSED 2026-10-05 — CLARIFIED (no contradiction) | `felhom-agent internal/localapi/controllerswap.go:236-240` records the image running when a swap starts as `Previous`; `:289` writes it back on failure. After a good swap that is „the one before" the running image — decision 56 and R-745 name the same image. A dated clarification sits under decision 56 in `09`; the ruling text is unchanged. |
| **R-818** | **Two changelogs cite register ids for other findings.** (P4) | CLOSED 2026-10-05 — CORRECTED | Dated correction notes under hub v0.109.0 (`hub/CHANGELOG.md`) and controller v0.224.0 + v0.225.0 (`felhom-controller/CHANGELOG.md`): those two findings never had register rows of their own — the triage's „the real ids are in CLOSED-ITEMS" was itself wrong (no closed row names hub v0.109.0 or controller v0.224.0/v0.225.0). Nothing renumbered. |
| **R-755** | **[P3-LOW] wger runs Django's DEVELOPMENT server in production: `manage.py runserver`, because the template does not set `WGER_USE_GUNICORN=True`.** (P3) | CLOSED 2026-10-05 — DUPLICATE of R-762 (its unique fact moved there) | Still true: templates/wger/docker-compose.yml has no WGER_USE_GUNICORN (grep empty). R-762 (open, read) states 'Owner decides together with R-755 (same server question)' and its fix names 'the gunicorn switch of R-755'. |
| **R-446** | **[P2-MEDIUM] „Naprakész" can be FALSE, and the badge that says it cannot tell.** (P3) | CLOSED 2026-10-05 — DUPLICATE of R-440 (its unique fact moved there) | felhom-controller/controller/internal/stacks/updateorder.go:96: `if len(s.CatalogDigests) == 0 // s.CatalogTestedAt.IsZero() { return false }` — blind only for apps with no ladder entry, i.e. the same 15 templates R-440 lists (app-catalog has no update_ladder for them). Both rows close by the same act: each app's first proven ladder step (R-462). |
---
File diff suppressed because one or more lines are too long