37 Commits

Author SHA1 Message Date
admin 8e873ee4a0 night fixes 2026-10-05: System page read after demo-hp's facts caught up (R-853 delay, ~17 min)
gates / gates (push) Successful in 34s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 08:31:49 +02:00
admin 5fd2656021 night fixes 2026-10-05: R-867/R-95/R-863..R-869 closed, R-870..R-876 opened (R-876 P2: repair misses dpkg's journal); Part E crash record; Part F spike; golden 0.294.0; rulings 100-103, CC decisions 104-108; STATUS
gates / gates (push) Successful in 32s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 08:26:23 +02:00
admin 7221ee5cd6 night 2026-10-04: Tester 2 read 06:20 local
gates / gates (push) Successful in 41s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 06:20:28 +02:00
admin d1d56cb0ad night 2026-10-04: last Tester 2 read (still down)
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 05:22:32 +02:00
admin 51ac1cb4ff night 2026-10-04/05: morning note, accidents, decision 78 proven, R-867..R-869; STATUS
gates / gates (push) Successful in 34s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 05:20:57 +02:00
admin 76ff0654ea night 2026-10-04: the guest undo runbook (proven 48 s), R-866, A3 in progress
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 22:37:25 +02:00
admin a1a32bbd74 night 2026-10-04: baseline, prediction, Tester 1 fresh box (installer 1.31.0 + bundle live), the ruled undo proven (48 s), A2, A4; rows R-863..R-865
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 22:25:38 +02:00
admin 9d3e0f558d Tester 2 offline since 18:06 UTC: act 1 queued, not delivered (report, STATUS)
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 20:52:18 +02:00
admin 79f07a7f10 R-840/R-859/R-860 records: 11 §5.3.1 + §5.4.2, 03, 04, 00; runbooks config-bundle + os-updates-test-waits; register 333→334 (R-840/859/860 closed, R-861/862 opened); STATUS; report; evidence
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 20:40:08 +02:00
admin c01d48f457 manifests: installer 1.31.0 (scripts sync ref)
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 20:21:52 +02:00
admin 877e89ee2a manifests: hub 0.133.0
gates / gates (push) Successful in 36s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 20:19:40 +02:00
admin ff1db11db4 hub v0.133.0 (R-859 test approvals end with the test; R-840 bundle on the System page, manifest, alarm); installer 1.31.0 (root files from the config bundle); bundle bootstrap script; golden 0.293.0 evidence; rulings 96–99; drill-r50 removed (evidence)
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 20:18:37 +02:00
admin 6b820143f8 R-858 closed (agent v0.142.1, ruling 95): the Docker step restarts the socket users; incident evidence; STATUS; report addendum
gates / gates (push) Successful in 34s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 18:35:40 +02:00
admin 242f0a15d5 R-858 filed (P2): a Docker engine step leaves the controller and traefik on the old docker socket; demo-felhom repaired by restarting the two containers; incident evidence
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:57:54 +02:00
admin 9291ae255a REPORT-os-docker-crash-2026-10-04: CI line
gates / gates (push) Successful in 32s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:51:09 +02:00
admin 21986d03b5 golden 0.292.0 re-vouched (re-bake: live-restore + approved Docker set) with agent 0.142.0; R-857 filed; STATUS; REPORT-os-docker-crash-2026-10-04
gates / gates (push) Successful in 32s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:49:30 +02:00
admin 208d21d18f golden 0.292.0 re-bake evidence: build-golden.sh 3.1.0, pinned Docker set, live-restore on
gates / gates (push) Successful in 37s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:39:28 +02:00
admin c9052264f7 manifests: publish installer 1.30.0 (both git-sync refs)
gates / gates (push) Successful in 34s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:36:21 +02:00
admin 0c55336fba docs: 11 §5.7 System page, §5.8 Docker slow lane BUILT, §5.9 crash restart; 00/03/07/08; decisions 90-94 (CC unattended); runbooks docker-undo + crash-guard; register R-852 R-835 R-848 R-849 R-851 R-854 closed, R-853 R-855 R-856 opened, R-812 R-840 narrowed (334 -> 332); live evidence
gates / gates (push) Successful in 33s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 17:36:10 +02:00
admin 245886ee92 manifests: revert the TEST-ONLY Docker approval wait (ruled 2 nights)
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 16:28:52 +02:00
admin 30cfdc1dc5 manifests: TEST-ONLY Docker approval wait 0 nights (os-docker-crash Part B; reverted in the same session)
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 16:27:19 +02:00
admin 3de64b138d manifests: hub 0.132.0
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 16:17:23 +02:00
admin b1b5c7e7e1 installer 1.30.0 (not yet tagged): the crash guard units + config, the root-owned slow-lane trust files (os-trust.json, operator-signers), their removal on uninstall
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 16:16:24 +02:00
admin 175ecfcdd2 hub v0.132.0: the System page (versions + OS updates with the ring/switch/approve buttons, R-852), the Hosts Proxmox/kernel column, the operator-approved Docker engine release (2 healthy ring-0 nights), the crash-guard events (R-851); evidence audits/os-docker-crash-2026-10-04
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 16:16:02 +02:00
admin bee277ffad rulings 87-89 recorded before the work (live-restore ON; crash restart with a limit; versions visible in the hub); R-852 filed (versions shown nowhere)
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 15:26:41 +02:00
admin 5efe6daec3 golden 0.292.0 vouched with agent 0.141.1; golden waiver deleted (newest controller has its golden); REPORT-os-host-lane-2026-10-04 with the Part table; STATUS/CONTEXT
gates / gates (push) Successful in 33s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 14:53:50 +02:00
admin f93738dc49 golden 0.292.0: bake + publish evidence (RUNBOOK-manual-build §4.0/§4.1 steps 1-4; not vouched, no floor change)
gates / gates (push) Successful in 36s
GOLDEN_SHA256=d6cf8b33ad58e5cfbf9566558044b2e1df692ef29d5353a40e39117794d16671, round trip MATCH;
drill VM 9100 destroyed, VM reverted to virgin.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 14:51:35 +02:00
admin 31bdb4b549 docs: OS updates steps 3+4 BUILT (11 §8.2/§8.3, §5.6 kernel facts, §5.8 Docker slow lane design), 00/03/07/08 updated, decisions 84-86 (CC unattended), host undo runbook (proved), register: R-841 R-845 R-846 R-850 closed, R-848 R-849 R-851 opened, R-836 R-812 narrowed (332 -> 333); STATUS; live evidence
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 14:47:21 +02:00
admin 0e970ba384 manifests: revert the TEST-ONLY OS approval wait (ruled 24h + 1 night)
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 14:41:35 +02:00
admin a73f728a55 manifests: TEST-ONLY OS approval wait 2m / 0 nights (os-host-lane Part B ring-1 proof; reverted in the same session)
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 14:38:17 +02:00
admin 771e12445c manifests: hub 0.131.1
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 13:40:46 +02:00
admin fd1f98547e hub v0.131.1: a scanned host pass (reboot_scanned, agent 0.141.1) clears 'reboot needed', so the 14-day alarm does not fire after a reboot; live evidence partB/partD/partG
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 13:39:48 +02:00
admin 693f3b45aa manifests: hub 0.131.0
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 13:05:59 +02:00
admin 88b0a2e761 hub v0.131.0: the tunnel status is true (R-841: three states, tunnel_down after two not_running reports, unknown never alarms); OS updates per layer (guest/host separate approved sets, host candidate leaves out kernel/boot/firmware, host_release in the box block), the fleet view and four hourly operator alarms (11 §8 steps 3+4); red-proofs in audits/os-host-lane-2026-10-04
gates / gates (push) Successful in 30s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 13:05:00 +02:00
admin 0ed2e8de4c docs: rulings 2026-10-04 ~12:20 (decisions 81-83); R-842 closed (A); R-840 ruling recorded
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 12:24:07 +02:00
admin e78726314e OS updates guest fast lane: records — 11 §8.1 BUILT, 03 cloudflared corrected, 07 §6.1 OS leg, 00 PARTIAL, monthly runbook infra pins, golden 0.291.0 record + vouch, register 331 -> 333 (R-837/838/726/843 closed; R-840/841/842/844/845 opened), STATUS, report
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 11:41:50 +02:00
admin e55b2ceb63 manifests: serve the installer from installer-v1.29.0
gates / gates (push) Successful in 29s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-04 11:40:40 +02:00
338 changed files with 21318 additions and 212 deletions
+70
View File
@@ -16,6 +16,76 @@
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
> **2026-10-05 (day) — the night's fixes (controller v0.294.0, agent v0.144.0 + v0.144.1, golden 0.294.0 vouched with agent
> 0.144.1, min_agent 0.131.0).** Rulings 100–103 (`09` §3: Tester 1's CF tokens NOT rotated → R-870; A1 by day on demo-hp
> only, with the operator's go; Tester 2 is a laptop off at night; re-sign Tester 2 only if online — it never was).
> CC decisions 104–108, *operator may reverse*: guard "young" = keep-daily CALENDAR days (`offbox_window.go`, built from
> `keepDaily`/`keepWeekly`/`keepMonthly`); `dockerexec.BeginImageWork`/`TryImageCleanup` for every pulling compose verb;
> the wrapper's kept report copy (`report-<run>-<layer>-apply.json`) + `Leg.SendUnsentLoop` (5 min) + `pass.lock`; the
> selftest's saved block (`os-update-block.json`); a second agent release. Closed R-95, R-863..R-869. Opened R-870..R-876
> (R-871 the operator's decision: a box off at night; **R-876 P2: after a mid-update crash the wrapper's repair misses
> dpkg's update journal — fix next**). Floors: demo-hp, demo-felhom, tester-1 at 0.294.0 (MinAgent 0.131.0); global
> unchanged. Report: `REPORT-night-fixes-2026-10-05.md`.
> **2026-10-04 (night) — R-840 BUILT (agent v0.143.0, hub v0.133.0, installer 1.31.0), R-859 + R-860 FIXED (hub v0.133.0,
> controller v0.293.0), golden 0.293.0 vouched, drill-r50 removed.** The config bundle (`11` §5.4.2): one table of 22
> root paths in `felhom-os-apply`; signed `agent_config_update`; the trust root never a bundle path; installer installs the
> same bundle; a pre-0.143.0 box needs `scripts/felhom-bundle-bootstrap.sh` once (demo boxes done; Tester 2 = R-862,
> operator). Test approvals (`11` §5.3.1): marked, cancelled at a start without the override (4 cancelled 18:20 UTC; the
> operator's Docker approval kept — CC decision). Docker socket self-heal: controller exits after 60 s of refusals.
> Floors: demo customers 0.293.0, global 0.292.0 (Tester 2 not moved). Tester 2: signed agent_update to 0.143.0 queued.
> R-861 opened (the agent sudoers is root-equivalent). Report: `REPORT-r840-config-bundle-2026-10-04.md`.
> **2026-10-04 (~18:49) — rulings 96–99 (the R-840 / Tester 2 brief), recorded before the work.** `09` §3: **96** build
> R-840 now (option A, a signed config bundle; replaces 82); **97** Tester 2 may receive only the signed agent update,
> the bundle by the route and the one-time live-restore reload (~19:05: the operator will install the bootstrap file by
> hand through his tunnel — the route cannot reach a root side that predates it); **98** drill-r50 removed from the hub,
> ep0 touch allowed (~19:05); tester-1 stays; **99** the operator's cause with the reviewer's correction.
> **2026-10-04 (~18:00) — R-858 incident + ruling 95.** The operator saw demo-felhom DOWN: the 14:13 UTC Docker step
> left `felhom-controller` and `traefik` on the OLD socket (live-restore kept them running; their bind-mounted socket
> file was recreated). Repaired by restarting the two (15:57 UTC). `09` §3 decision **95**: the wrapper restarts the
> socket users after a step + the health rule checks the controller reaches Docker (agent v0.142.1). Demo ring-0 Docker
> marks OFF until released.
> **2026-10-04 (evening) — the System page, the Docker engine slow lane and the crash guard BUILT.** Agent v0.142.0,
> hub v0.132.0, installer 1.30.0, `build-golden.sh` 3.1.0. **Decided by CC unattended — operator may reverse:** `09` §3
> decisions **90** (crash signal = a clean-shutdown marker; pstore saved nothing), **91** (`panic_on_oops` stays 0; an
> oops is reported), **92** (the 3rd unclean stop in 60 min leaves the box off; 10 s / 24 h), **93** (the wrapper
> verifies Docker authority against root-owned files), **94** (page colours = alarm thresholds). Live: live-restore on by
> reload with the same ids (9202 6/6, demo-hp 24/24, demo-felhom 5/5); Docker 29.7 → 29.8.2 on both demo boxes, ids kept;
> the operator's button approved `os-docker-20261004-142842` (TEST 0-night wait, reverted); a signed undo to 29.7.2 on
> demo-hp and back; demo-felhom as ring 1 by a signed job; a replay refused; crash 1–2 restarted in 54/53 s, the guard
> tripped, crash 3 stayed off, the hub mailed the trip, re-armed. `REPORT-os-docker-crash-2026-10-04.md`.
> **Rulings 2026-10-04 (~15:17) — recorded before the work (System page + Docker lane + crash restart brief).** `09` §3
> decisions **87** (Docker `live-restore` ON fleet-wide, never off by a plain restart), **88** (a crashed host restarts by
> itself, with a limit — R-851) and **89** (the operator sees the boxes' OS / Proxmox versions in the hub — R-852).
> **2026-10-04 (late afternoon) — OS updates: host fast lane + fleet view + alarms BUILT (`11` §8.2–§8.3); the tunnel
> status is true (R-841).** Agent v0.141.0 → v0.141.1, hub v0.131.0 → v0.131.1, controller v0.292.0 (cloudflared
> readiness health check). **Decided by CC unattended — operator may reverse:** `09` §3 decisions **84** (appliance proof
> = the root-owned install record), **85** (alarm numbers 7/14/7/14 days, configuration), **86** (a same-session patch
> release of agent and hub for the host "reboot needed" defect, R-846). Live: `tunnel_down`/`tunnel_recovered` on
> demo-hp; ring 0 host pass on demo-felhom (108 Debian packages); a 605-package host release; ring 1 exact install;
> by-hand host undo proved; leg 23–32 s with nothing to install. Kernel spike (R-836, narrowed): GRUB's one-shot is not
> a one-shot on LVM `/boot`; Secure Boot fine; `kernel.panic = 0` (R-851); `sp5100_tco` answers. demo-hp now runs and
> defaults to kernel 7.0.14-20. Docker slow lane designed (`11` §5.8). Golden 0.292.0 baked + vouched with agent 0.141.1 (min_agent
> 0.131.0); the golden waiver deleted (not needed). `REPORT-os-host-lane-2026-10-04.md`.
> **Rulings 2026-10-04 (~12:20) — recorded before the work (host fast lane brief).** `09` §3 decisions **81** (R-842 A:
> the undo is the whole-guest backup by hand; R-842 closed), **82** (R-840 not built now — "There are no older boxes";
> row kept open with the reviewer's note) and **83** (next: R-841, the host fast lane, OS-update improvements).
> **2026-10-04 (afternoon) — OS updates, guest fast lane BUILT (`11` §8.1).** Agent v0.140.0: `configs/felhom-os-apply`
> (R1–R13, repair first, snapshot.debian.org fallback; FELHOM_OSAPPLY sudoers), `internal/osupdate` (the leg after a
> successful primary backup, under the heavy-op gate; health baseline = start of the leg), `--selftest=os-update`.
> Hub v0.130.0: `internal/osupdates` (rings, switch default ON, candidate = what ALL ring-0 boxes run, approval 24 h +
> 1 night via `OS_APPROVE_AFTER` / `OS_APPROVE_NIGHTS`, `os_update` desired block, `POST /hosts/{id}/os-report`,
> operator `/os/*`). Controller v0.291.0: decision 78 (R-726), infra pins raised (R-838) + `scripts/check-infra-pins.py`.
> Installer 1.29.0 installs the wrapper. **No automatic undo** (R-837 measured → R-842). **Existing boxes need the
> wrapper + sudoers by hand** (R-840 — the demo boxes got them by hand). `REPORT-os-guest-lane-2026-10-04.md`.
> **Rulings 2026-10-04 (~10:17) — recorded before the work (guest fast lane build).** `09` §3 decisions **78** (R-726
> option A: a returning household's box sets the old off-site copy aside on night one), **79** (`snapshot.debian.org`
> fallback for a replaced approved version — option A; the reviewer had picked B) and **80** (next build: the guest
+81
View File
@@ -0,0 +1,81 @@
# REPORT — the night's fixes, the power cut by day, a box that is off at night (2026-10-05)
Brief: "fix what the 2026-10-04 night found …" (operator, 2026-10-05). Evidence: `documentation/audits/night-fixes-2026-10-05/`.
Architecture read before the claims: `07-backup-architecture.md` (§6.1, the Tier-3 row), `11-os-updates.md` (§5.4.1, §8),
`09` §3 (decisions 53, 68–74, 81, 86), `audits/offsite-append-only-2026-10-03/DESIGN.md`.
## 1. The Part table
| Part | State | Note |
|---|---|---|
| §1 rulings recorded first | **done** | `09` decisions 100–103; R-870 (tokens, like R-831); Tester 2's page in `runbooks/target-selection.md` |
| A — clean-up guard (R-867) | **done** | controller v0.294.0; tests run restic 0.14.0's policy (proven identical to the binary); 5 red-proofs; live windows on both demo boxes with counts; R-867 and R-95 closed (DUE-CHECKS entry removed) |
| B — image clean-up race (R-863, R-864) | **done** | one lock for every pulling compose verb; the night's shape reproduced in a test and live on 9202 (fired at minute 3, skipped, install OK first time) |
| C — R8 real download (R-865) | **changed** | fix + tests + red-proof done. Live: the INSTALLED wrapper's measure read 12 802 456 B on demo-hp. **No R8 refusal line was produced**: it needs < 500 MB free on demo-hp's guest = 28.5 GB written into a thin pool with 18.7 GB free — it would have stopped every guest |
| D — R-868, R-869, R-866 | **done, with a second agent release** | R-868's first fix (v0.144.0) was measured NOT to work live (broken stderr pipe); v0.144.1 fixed it and the A5 shape then delivered one `applied` report. R-866 live with the hub blackholed. R-869 test + red-proof |
| E — power cut mid-update (A1 by day) | **done** | operator's go; crash 06:13:55 UTC, back by itself in 37 s; **the next pass failed** → R-876 (P2); by-hand repair; demo-hp left with every package current |
| F — a box off at night (spike) | **done** | read only; `partF/FINDINGS.md`; no architecture covers it → R-871; R-872..R-874; STATUS decision A/B |
| G — releases, golden, records | **done** | controller v0.294.0; agent v0.144.0 + v0.144.1 (decision 108); golden 0.294.0 baked + vouched (gate OK); `07`, `11`, `00`, `09` updated |
## 2. Claims in the brief that turned out wrong (or only partly true)
1. **"The policy's constants can drive the guard's line"** — true, and done — but with a cost the brief did not name: a
line derived from keep-daily (calendar days) can no longer catch a past-dated gap-fill that steers a 7–8-day-old
keep, which the 8-day line caught while refusing every honest window. Past-dated fakes can never make the policy drop
a snapshot inside the last keep-daily calendar days, so the line now catches only the skew-window shape. The rest is
R-822's residual, bounded by the cap and the hub's count check (decision 104).
2. **"The same race exists in the update and restore paths"** — the update path: NO, it was already guarded (no pass
while any app is updating, since v0.284). The restore and undo paths: exposed in principle (they pull inside
`compose up`), not measured; they now hold the same lock.
3. **"Dropping `-s` downloads nothing"** — TRUE, measured on 9202 (archive cache 10 → 10 files, versions unchanged).
4. **"A box off at W runs nothing when it comes back"** — mostly true: the database dumps, second copy, off-site copy and
app updates never catch up; but the whole-guest backup DOES catch up (48 h safety valve, about every 2 days for an
evening-only box), and the OS leg follows it by day under the `night` label.
5. **"The night A5 showed the wrapper finished"** (R-868's premise, and v0.144.0's design) — the packages were installed,
but the wrapper process itself died on its first log line after the agent's death. Found only by running it live.
6. Part E: "the next pass must repair dpkg first and finish" — it does NOT (R-876).
## 3. What was proven, with numbers
- **Part A.** Tests: the measured shape (7 d + 5 s → allowed), 60 nights × 3 apps with two same-day manual runs across a
month boundary (never refused, ≥ 45 removed), weekly windows, the skew-window fake (refused), the lab's 13 future fakes
(refused). Red-proofs: 8-day line back → 3 fail; each refusal dropped → its test fails. Lab: restic 0.14.0 binary vs
the test simulation over 92 snapshots: identical 72 removals. **Live:** demo-felhom 15 snapshots, predicted removals
`92e49f62`, `343d57a5` → window 5 removed exactly those (16 → 14 incl. the run's new one); demo-hp 136 snapshots,
predicted 18 → window 6 removed exactly those (145 → 127). Hub rows `pruned`, no event, no mail, key audit 0 findings.
- **Part B.** Live on 9202: controller start 05:28:35, install 05:31:15, clean-up 05:31:36 "skipped — … pulling images
now", BookStack deployed 05:31:54 (35.5 s), retry 05:33:36 ran (0 deleted). Teardown through the product verified.
- **Part C.** `download_bytes = 12802456 B` from the installed wrapper on demo-hp (was 0).
- **Part D.** R-866: `block=SAVED(2026-10-05T05:23:26Z; hub unreachable: … connect: invalid argument)`. R-868 (v0.144.1):
killed 06:04:00, wrapper `DONE upgraded=13`, kept copy, hub report id 63 `applied` (13) at 06:09:05, once.
- **Part E.** See `11` §8.4: back in 37 s; apps healthy within 4 min; household saw one timeline line; one operator mail
`os_update_failed` (true); next pass FAILED (R-876); after `dpkg --configure -a` the pass installed 12; the guest's
package list equals the pre-test one (279 lines). The first crash attempt did not fire (my watcher's pattern missed
apt's dpkg call; the pass installed normally) — rolled back again and repeated.
- **Part F.** `audits/night-fixes-2026-10-05/partF/FINDINGS.md`; two claims re-checked in source by me.
## 4. Rows
Register before **341**, after **340**. Closed (8): R-95, R-863, R-864, R-865, R-866, R-867, R-868, R-869. Opened (7):
R-870 (tokens, operator), R-871 (a box off at night — the operator's decision), R-872 (P2, no missed-backup alarm for a
box down at 05:00), R-873 (nightly "cannot be reached" mail), R-874 (restore-test never runs on short sessions),
R-875 (P4, kept-report reason text), **R-876 (P2, the repair misses dpkg's update journal)**. STATUS updated.
`unproven.py --summary`: unchanged — 55 claims, 35 not walked (no number moved).
## 5. Teardown, three layers
- **Machines:** 9202: BookStack removed through the product (no container, stack dir, volume); controller 0.294.0 (set by
hand, allowed there). demo-hp 9201: every package current, list identical to before; my scripts and logs in `/root`
removed after copying. The bake VM: CT 9100 destroyed, token shredded, reverted to `virgin`, qemu gone.
- **Hosts:** the blackhole routes on felhom-pve removed (in the same script). Nothing provisioned.
- **Hub:** two one-shot clean-up grants (consumed); floors for demo-hp, demo-felhom, tester-1 → 0.294.0; artifacts
vouched (agent 0.144.1, golden 0.294.0, min_agent 0.131.0); 12 signed jobs (3× agent 0.144.0, 3× bundle 0.144.0,
3× agent 0.144.1, 3× bundle 0.144.1). Tester 2: read only, nothing sent (offline all session).
- Scratch secrets (hub password, hub key, controller password, deploy secrets) shredded at the end.
## 6. Notes
- The hub pod log prints a customer's e-mail address in "Customer email sent to …" lines (seen by the Part F helper; not
recorded anywhere).
- demo-hp's System page read "no running customer guest" / "unknown" for several minutes after the crash although the
guest ran — R-853 (facts late after a boot), not a new defect.
+99
View File
@@ -0,0 +1,99 @@
# REPORT — System page, Docker slow lane, crash restart (2026-10-04, late afternoon–evening)
Brief: "OS updates — a System page …; the Docker engine slow lane built (live-restore ON, decision); a crashed host
restarts by itself, with a limit (decision)". Architecture read first: `documentation/architecture/11-os-updates.md`
(owner; §5.6, §5.8, §8.1–8.3), `05-hub-architecture.md`, `03-host-agent.md`, `08-alarm-ladder.md`, `07` §6.1. Rulings
recorded before the work: `09` §3 decisions 87–89. Evidence for every claim: `documentation/audits/os-docker-crash-2026-10-04/`.
## Part table
| Part | What | Result | Evidence |
|---|---|---|---|
| A | System page + version report (R-852) | **DONE.** The box reports Proxmox + kernel (API) and the wrapper's read-only facts (host Debian, next-boot kernel, held packages, taint, `kernel.panic`, crash guard; guest Debian, Docker, containerd, live-restore); unreadable = `unknown`. Hub: **System** tab on every page — per box ring + switch with buttons, tunnel, host, guest, Docker, last leg; releases per layer; what ring 0 runs; "Approve now" (confirm) and "Approve Docker set" (only when allowed). Hosts gets a Proxmox / kernel column. R-849: guest scanned every pass. Rendered with real data from both demo boxes. | `partA/` (`live/system-page.html`, `hosts-page.html`, facts) |
| B | Docker engine slow lane (`11` §5.8) | **DONE.** live-restore on by RELOAD: same ids on 9202 (6/6, by hand — R10 refuses a scratch guest by design), demo-hp (24/24, 7.5 s), demo-felhom (5/5). Ring 0 on both: 29.7.x → **29.8.2**, every id kept (122 s / 99 s whole pass). Approval with the page button under a TEST 0-night wait (logged, reverted): `os-docker-20261004-142842`. **Signed undo** on demo-hp → 29.7.2 (wrapper `authority=signed UNDO`, 24/24 ids, 41 s) and back to 29.8.2 by its ring-0 pass. **demo-felhom as ring 1**: its night pass skips Docker; a signed job with the approved set verified by the wrapper (already current → nothing); the **replayed** job refused ("nonce already seen"); back to ring 0. | `partB/` |
| C | Crash restart with a limit (R-851) | **DONE.** Spike (your word before each crash): `kernel.panic=10` + `echo c` → back by itself in 54 s, same kernel; pstore saved nothing; no oops history. Guard built (decision 88, 90–92). Live: crash 1 → 54 s, crash 2 → 53 s and the guard **tripped**, crash 3 → **stayed off** (184 s watched) until you switched it on; the hub mailed `host_crash_guard_tripped` (+3 restart events, 3 household lines); System page red; re-armed by `felhom-crash-guard rearm`. | `partC/` |
| D | Releases, golden, records | Agent **v0.142.0** (signed to both demo boxes), hub **v0.132.0**, installer **1.30.0** (tagged, public, verified), `build-golden.sh` 3.1.0. Golden: see below. Records: `11` §5.7/§5.8/§5.9, `00`, `03`, `07`, `08`, decisions 90–94, two runbooks. | `partD/`, git |
## Claims in the brief that turned out wrong (or half right)
- **"No box reports its versions"** — half right: every box already sent `pveversion` and `kversion` inside the Proxmox
API answer the agent reads each report (`NodeStatus`); nothing stored or showed them. Debian, the next-boot kernel and
everything Docker were truly not reported.
- **"A reload turns live-restore on with no container restart, on the demo boxes too"** — TRUE, measured: 24/24 and 5/5
ids kept. But "prove on 9202 first" could not use the product path: 9202 binds a scratch folder, not the drives, so the
wrapper refuses it (R10, by design); proved there by hand with the same two steps.
- **"A crash boot can be told apart from a clean one"** — only from a CLEAN one. Not from a power cut or a hard reset:
`efi_pstore` is on, yet a real panic saved nothing on demo-hp. The guard counts every unclean stop (decision 90).
- **"`echo c` crashes the host and `kernel.panic` brings it back"** — TRUE (54 s, 53 s). But `sysctl -w` does not survive
the restart (back to 0), so it must be set at every boot — the guard does that.
- **The guard's count** — the brief said both "at 3 … the next crash leaves the box off" (the 4th) and "crashes 3 times
within one hour, it stays off" (the 3rd). Built per your words: the 3rd (decision 92).
## Decisions taken by CC unattended (operator may reverse) — `09` §3
90 crash signal = clean-stop marker · 91 `panic_on_oops` stays 0, an oops is mailed · 92 the 3rd unclean stop in 60 min
stays off; 10 s; 24 h · 93 the wrapper verifies Docker authority against root-owned files · 94 page colours = alarm
thresholds.
## Releases and what was copied by hand
- **Agent v0.142.0** (`b1746c2`, sha256 `7beb3222…de6`): signed `agent_update` to both demo boxes, both COMPLETED.
- **Hub v0.132.0** (`175ecfc`): image tag verified on the pod; ArgoCD Synced/Healthy.
- **Installer 1.30.0**: tag `installer-v1.30.0`, both git-sync refs; `https://felhom.eu/scripts/felhom-host-install.sh`
serves `SCRIPT_VERSION="1.30.0"`.
- **By hand on both demo hosts** (R-840; `partD/copied-by-hand-*.txt`, hashes equal to tag v0.142.0):
`/usr/local/sbin/felhom-os-apply`, `/usr/local/sbin/felhom-crash-guard`, `/etc/systemd/system/felhom-crash-guard.service`,
`…/felhom-crash-guard-check.service`, `…/felhom-crash-guard-check.timer`, `/etc/felhom/crash-guard.conf`,
`/etc/felhom/operator-signers`, `/etc/felhom/os-trust.json` (with `ring0_slow_lane: true` — the demo boxes only);
units enabled. Previous wrapper kept as `/root/felhom-os-apply.bak-0.141.1`. A test binary (`felhom-agent-0.142.0-rc1`)
ran the debug actions before the release and was removed after.
## Golden
- **Re-baked golden 0.292.0** with `build-golden.sh` 3.1.0 (by a helper agent, RUNBOOK-manual-build §4.0/§4.1; the
documented publish replaces the same version: pre-delete 204, upload 201). The log shows "Docker engine set PINNED",
the six approved versions (docker-ce 5:29.8.2, containerd.io 2.3.6, buildx 0.37.1, compose 5.6.0, …) and
"live-restore: on". New sha256 `79a1dce3…d43a`, re-hashed by download in the main session: match. Drill VM destroyed,
drill disk back to `virgin`. Evidence `documentation/tests/golden-0.292.0-2026-10-04-rebake/` (commit `208d21d`).
- **Re-vouched:** agent 0.142.0 + golden 0.292.0 (new sha), `min_agent` 0.131.0 → `artifacts_set` (17:48). Between the
re-bake upload and the re-vouch the hub vouched the old sha — a fresh install would have failed closed; none ran (R-857).
- The crash guard is NOT in the golden (it is a host program): the installer 1.30.0 installs it.
- The golden waiver stays deleted: the newest controller (0.292.0) has its golden.
## Register
Open rows **334 → 333** (333 at the start + R-852 filed first). Closed: **R-852, R-835, R-848, R-849, R-851**; filed and
closed: **R-854**. Opened: **R-853** (facts reach the hub ~15 min late after a boot), **R-855** (cosmetic TEST log line),
**R-856** (after a crash the household also gets app mails — your choice later), **R-857** (a same-version golden
re-bake: the gate shows the first sha; a window until the re-vouch). Narrowed: **R-812** (Docker lane built;
kernel left), **R-840** (by hand again). `unproven.py`: unchanged (35 of 55 not walked).
## Teardown — three layers
- **Machine:** demo-hp and demo-felhom customer guests running, live-restore on, Docker 29.8.2, all apps up. 9202
running, live-restore on (its old daemon.json kept as `/root/daemon.json.bak-2026-10-04` in the guest).
- **Host:** both hosts run agent 0.142.0, the crash guard ARMED (`kernel.panic = 10`), ring 0, switch ON; the test
binary and the id lists removed. demo-hp booted 3 extra times today (the crash test); kernel unchanged (7.0.14-20).
- **Hub:** the TEST Docker wait reverted (log: 2 nights); the approval `os-docker-20261004-142842` stays (a real
approval of what ring 0 runs). The crash and trip mails for demo-hp were sent on purpose. The hub password copy in
the scratchpad shredded at the end. The hub announced the re-arm (`host_crash_guard_rearmed`, 17:47).
## CI
Checked by `head_sha` over every page of the Gitea `jobs` endpoint: felhom.eu — all 10 commits from `bee277f` (rulings)
to `21986d0` (re-vouch records) **success** (incl. hub `175ecfc` 1265→, installer, manifests, docs); felhom-agent —
`b1746c2` (1273, 1274), `f24dce5` (1275), `42af3ab` (1281) **success**. This report's own commit: checked after the push
(see the session's final message).
## Addendum (~18:30) — R-858, found by the operator
The N100 showed DOWN from 14:18 UTC. Cause: v0.142.0's Docker step restarted dockerd (14:13); live-restore kept the
containers running, but `felhom-controller` and `traefik` bind-mount the socket FILE and kept the deleted inode, so the
controller could not reach Docker. My Docker health rule passed it (the controller's own check said healthy) — the rule
checked the mechanism, not the consequence. Repaired by restarting the two containers (15:57 UTC). Ruling 95: agent
**v0.142.1** (`4950030`, sha256 `003f882a…62bd`) restarts only the socket users after a step and fails health when the
controller cannot reach Docker. Proven live on demo-hp before the release (signed undo, then forward): `applied, healthy`,
guest / controller / traefik on the same socket inode both times. Ring-0 marks were OFF during the fix, back ON after.
Both boxes on 0.142.1; vouched for new installs (golden unchanged). Red-proofs 4/4. Register: R-858 opened and closed
(still **333** open). Evidence `partE-incident/`. Not touched: Tester 1 shows DOWN for 4 days on the dashboard — a
fenced tester box, outside this brief.
+60
View File
@@ -0,0 +1,60 @@
# REPORT — OS updates build step 1: the guest's Debian fast lane; decision 78; the infrastructure images — 2026-10-04
Architecture read: `11-os-updates.md` (with C1–C12, §5.4.1, §7.1 — the design; it won wherever it differed from the
brief, see below), `03-host-agent.md`, `07` §6.1, `09` §3 decisions 11/12/15/18, `08`. Baselines (re-verified):
felhom.eu `1b74ddc0c9` (hub 0.129.0), agent `596238cc2e` (0.139.0), controller `99a1497560` (0.290.0), catalog
`917a779cca`. Register 331, highest R-839. Rulings recorded first: `09` §3 decisions 78–80 (`6ed79cd`). Evidence: `documentation/audits/os-guest-lane-2026-10-04/` (parts A–G).
## The Part table
| Part | Result | Notes |
|---|---|---|
| A — the snapshot undo first (R-837) | **done — and it FAILED: no snapshot is possible** | PVE refuses any snapshot not named `vzdump` of a guest with host-path binds (mp8/mp9), as the agent's token (which has `VM.Snapshot` + `VM.Snapshot.Rollback`) and as root. By the brief's rule: **no automatic undo built**; the decision is in STATUS (R-842). Steps 2–5 (apply, roll back, re-apply) had nothing to roll back to; 9201 was brought current by the product's own leg in Part G. Thin pool unchanged. |
| B — the wrapper | **done** | `felhom-os-apply` (Python 3 stdlib), R1–R13, repair first, snapshot.debian.org fallback, log lines; host layer and slow lane refused. 35 tests; **every refusal red-proved** (13/13). `visudo -cf` OK. **Changed:** Python not shell (a JSON plan cannot be parsed safely in sh — so "shellcheck clean" became `ast`/compile-checked + the suite); one sudoers entry with a plan `mode` instead of a separate `--repair-only`. **The route for existing boxes: none exists** (R-840, with a proposal). |
| C — the agent's leg | **done** | After a successful primary whole-guest backup, under the heavy-op gate (red-proved: the gate is held), once per 20 h, 90 s settle. Health rule written and pinned (`HealthVerdict`). Report: full installed set with origins, pending, not covered, restart-needed. Debug action `--selftest=os-update`. 7 leg red-proofs + 2 hook red-proofs. |
| D — the hub | **done** — hub v0.130.0 | Rings, per-box switch (default ON), the candidate/approval rule (24 h + 1 night, config), approve-now, events, fleet JSON. 5 approval red-proofs; the `os_update` wire golden byte-identical in both repos. |
| E — household line + decision 78 | **done** | Line = hub customer event `os_update_applied` (info: on the household's timeline, not mailed; hu/en in the bundle). **Changed:** there is no box-side event surface, so the hub event is it (R-844). Decision 78 built in controller v0.291.0, red-proved both ways. |
| F — infrastructure images (R-838) | **done** | traefik v3.7.13, cloudflared 2026.9.3, filebrowser 1.5.6-stable; breaking changes named (none we use). A release moves all three (9202: ≤ 1.9 s / ≤ 1.5 s; demo boxes: public gap ≤ 19.6 s / ≤ 14.7 s incl. the controller restart). `scripts/check-infra-pins.py` + runbook section. **Changed:** the standing brief `claude/MONTHLY-security-retest.md` lives in the claude.ai project, not the repo — the repo half is the runbook; the project file is the operator's to update. `03` corrected (3 lines). |
| G — live proof | **done, one part changed** | Ring 0 on both boxes (53 packages each, healthy); approval with a 2-minute TEST wait (272 packages, auto), then the ruled values back; ring 1 on demo-felhom (exactly the 3 approved versions, nothing newer); a failed health check → `health_failed`, operator mail, household line. **Changed:** "show the rollback" — there is none (Part A). Teardown: no snapshot, no plan files, test config gone, demo-felhom back to ring 0. |
| H — release, golden, records | **done** (see Teardown for the golden) | Agent 0.140.0 (signed per box, both demo boxes on it), hub 0.130.0, controller 0.291.0 (floor 0.291.0, MinAgent 0.131.0 declared), installer 1.29.0. `11` §8.1, `00`, `07` §6.1, `03` updated. |
## Claims in the brief that turned out wrong (named)
1. **"The agent's token can snapshot and roll back"** — it HAS the rights, but no snapshot of a customer guest is
possible at all (bind mounts). Neither the token nor root can.
2. **"A snapshot rollback leaves the thin pool clean"** — unmeasurable: there was no snapshot.
3. **"A new sudoers line can reach an installed box through the product"** — false. Only the installer writes it;
the signed agent update replaces the binary only (R-840). The demo boxes got the wrapper + sudoers BY HAND.
4. **"A controller release moves the infrastructure containers"** — TRUE for all three. (I first wrote the opposite
for the file browser and corrected it the same hour: its start-up mount sync renders the new image.)
5. **"An agent event can reach the household's timeline"** — only through the hub (a hub customer event); the box has
no timeline of its own (R-844).
6. **"Before each guest update, the box takes a snapshot"** (the one-page summary) — impossible (Part A).
7. `11` vs the brief: `11` §5.4.1's `--repair-only` flag was folded into the plan; `11`'s "a missed night waits" holds.
## Found and fixed live (before the release)
- `--selftest=os-update` was refused by the flag's allow-list — and so was `--selftest=wgtunnel`, since S3 (R-843,
opened and closed; a new test pins every dispatched mode).
- The wrapper logged an UPDATED conffile as "kept" (dpkg's two message shapes; fixed + tested).
- An app stopped between the inventory and the apply escaped the health check; the baseline is now the start of the
leg (fixed + red-proved).
- My stopped-app test also made the box mail one `app_start_failed` (a second one was held by the cooldown).
## Rows
Closed: **R-837** (measured), **R-838**, **R-726**, **R-843** (opened and closed). Opened: **R-840** (no product route
to installed boxes, P2), **R-841** (the agent's cloudflared probe reads a host unit that does not exist, P3), **R-842**
(the undo decision, waiting on the operator), **R-844** (household line only on the hub, P4), **R-845** (a pass takes
3–4 min, P4). Narrowed: **R-812**. Register **331 → 333**.
## Teardown, three layers
- **Machines:** no snapshot on either 9201; no plan files; privatebin restarted and healthy; demo-felhom back to ring 0;
both 9201s fully Debian-current (openssl at the approved u3). 9202 runs controller 0.291.0 (from Part F).
**Kept on purpose:** the wrapper + sudoers on both demo hosts (installed by hand; the old sudoers saved as
`/root/felhom-agent.sudoers.bak-pre-osapply`); agent 0.140.0 (signed update).
- **Host (DooPlex):** helper scripts in the scratchpad only; the hub password copy shredded at the end.
- **Hub:** v0.130.0 at the ruled 24 h + 1 night (the TEST override reverted and the start log shows no override);
both demo boxes ring 0, ON; release `os-20261004-091417` approved (it was approved under the TEST wait — ring 1 boxes
will install it; every version in it already runs on both demo boxes). Floor 0.291.0.
+90
View File
@@ -0,0 +1,90 @@
# REPORT — OS updates, build steps 3 + 4 (2026-10-04, afternoon–evening)
Brief: "OS updates, build step 3 + 4" (Parts A–G). Architecture read first: `documentation/architecture/11-os-updates.md`
(owner), `08-alarm-ladder.md`, `03-host-agent.md`, `07-backup-architecture.md` §6.1. Evidence for every claim:
`documentation/audits/os-host-lane-2026-10-04/` (partA … partG).
## Part table
| Part | What | Result | Evidence |
|---|---|---|---|
| A | The tunnel status is true (R-841) | **DONE.** Three states from the guest container + controller v0.292.0's readiness check; `unknown` never alarms; `tunnel_down` after two `not_running` reports. Live on demo-hp: port 7844 blocked → `tunnel_down` mailed 11:52 UTC (2nd report); unblocked → `tunnel_recovered` 12:07 UTC. No new sudoers line. | `partA/` (red-proofs agent/hub/controller, `live/`) |
| B | Host fast lane (`11` §8 step 3) | **DONE.** R12 lifted for lane fast / layer host on an appliance only (root-owned install record); R14 refuses kernel/boot/firmware; host step after a healthy guest step; host health rule in `11` §8.2; reboot-needed with first date, never reboots; separate per-layer approved sets. Live: demo-felhom ring 0 → 108 Debian host packages (all Debian origin, checked against apt), healthy; demo-hp ring 0 (nothing pending); 605-package host release approved under a TEST wait (2 m / 0 nights, logged, reverted); demo-felhom as ring 1 installed exactly the 1 version it lacked; back to ring 0 and the ruled 24 h + 1 night. Host undo runbook proved on demo-hp (`tzdata`). | `partB/` (`live/`, `ring1/`, `undo/`, red-proofs) |
| C | Fleet view + four alarms (`11` §8 step 4) | **DONE.** `GET /os/fleet`: one line per box, ring, switch, tunnel, per layer release/pending/not-covered/last good leg/reboot-since. Alarms `os_update_stale`, `os_reboot_needed`, `os_ring0_stalled`, `os_not_covered`, hourly, operator-only, each red-proved (9 mutations caught). Numbers in `11` §8.3 / `09` decision 85 as CC-decided. | `partC/` |
| D | The leg is fast (R-845) | **DONE.** Nothing to install, both layers: **23.3 s** (demo-felhom), **31.5 s** (demo-hp). Before (agent 0.140.0, guest only, nothing to install): 14.0 s. A 108-package host pass: 70 s. | `partD/`, `partB/live/` |
| E | Kernel one-shot spike on demo-hp (R-836), operator's word before each reboot | **DONE (measured).** Secure Boot ON boots the new kernel fine; **`grub-reboot` is NOT a one-shot here** — `/boot` on LVM, GRUB cannot clear `next_entry`, reboot 2 (no command) came back on the NEW kernel. `kernel.panic = 0`. `sp5100_tco` loads and answers (sysfs only, never armed, unloaded). No kernel installed (7.0.14-20 was already there). Left: runs 7.0.14-20, saved default 7.0.14-20, both kernels installed, `GRUB_DEFAULT=saved`. | `partE/` |
| F | Docker slow lane design | **DONE (design only).** `11` §5.8. One STATUS decision: `live-restore` on, fleet-wide. | `11` §5.8, STATUS |
| G | Releases, golden, records | See below. Agent **v0.141.0 + v0.141.1**, hub **v0.131.0 + v0.131.1** (decision 86 — a second release in each, for a live-found defect), controller **v0.292.0**. Installer: **no new release** (see below). | `partG/` |
## Claims in the brief that turned out wrong (or only half right)
- **cloudflared readiness** — it EXISTS (`/ready`, 200 only with a connection), but nothing exposed it: the metrics
port was random and there was no health check. A container state alone lies (wrong token: `running`, `/ready` 503).
Controller v0.292.0 adds the fixed port + Docker health check; the agent reads it with its existing sudoers line.
- **"Find where the install mode is known"** — known in TWO places, and only one is trustworthy: `agent.json`
`deployment_mode` (the agent can write it) and the installer's root-owned `state.json` `mode`. The wrapper trusts
only the second (decision 84).
- **`grub-reboot` with Secure Boot** — Secure Boot was not the problem (it booted fine). The one-shot itself fails on
these boxes because GRUB cannot write its state on LVM `/boot`.
- **Panic auto-restart** — there is none: `kernel.panic = 0`; a panicked host stays down (R-851).
- **Under 60 s** — met (23–32 s). But the leg was ALREADY under 60 s with nothing to install (14 s, guest only); the
3–4-minute passes of R-845 were passes that installed something.
## Releases
- **Agent v0.141.0** (`cfba0d0`, sha256 `6eaad980…`) and **v0.141.1** (`a6bc3f1`, sha256 `b712f577…`) — signed
`agent_update` jobs to both demo boxes (both COMPLETED). v0.141.1 fixes R-846 (host "reboot needed" hid `lxc-start`,
and a reboot never cleared it).
- **Hub v0.131.0** (`88b0a2e`) and **v0.131.1** (`fd1f985`) — deployed via ArgoCD; image tag verified on the pod.
- **Controller v0.292.0** (`09e634d`) — floor raised (`min_controller_version` 0.292.0, `min_agent` 0.131.0); both demo
boxes run it; cloudflared recreated once, `healthy`.
- **Installer — no new release, deliberately** (recommendation not followed, one line why): the installer fetches
`configs/felhom-os-apply` from the VOUCHED agent's tag, the file name did not change and the sudoers line did not
change, so vouching agent 0.141.1 delivers the new wrapper to every fresh install with no installer change.
- **Copied by hand to both demo hosts** (`partG/wrapper-copied-by-hand.txt`): `/usr/local/sbin/felhom-os-apply` only —
first from v0.141.0 (sha `4729769c…`), then from v0.141.1 (sha `51e100ad…`), installed `0755 root:root`, the old
file kept as `/root/felhom-os-apply.bak-0.140.0`. `/etc/sudoers.d/felhom-agent` was NOT copied: it already equals the
repo's (`02df92d7…` on both).
## Golden
- **Golden 0.292.0 baked** (by a helper agent, RUNBOOK-manual-build §4.0/§4.1, same `build-golden.sh` bytes as
0.291.0; drill VM 9100 destroyed, drill disk back to `virgin`): sha256 `d6cf8b33…16671`, re-hashed by download in the
main session — match. Evidence `documentation/tests/golden-0.292.0-2026-10-04/` (commit `f93738d`).
- **Vouched:** agent 0.141.1 + golden 0.292.0, `min_agent` 0.131.0 → `artifacts_set` (`05-vouch.txt`). Fresh installs
now get agent 0.141.1, its wrapper, and controller 0.292.0.
- **Waiver REMOVED** (`documentation/tests/golden-waiver.yml` deleted): the newest controller (0.292.0) now has its
golden, so `golden_currency_gate.py` passes without it. Golden 0.291.0 alone could NOT have retired it — this session
released controller 0.292.0, which put 0.291.0 behind.
## Decisions taken by CC unattended (operator may reverse) — `09` §3
- **84** — the appliance proof is the root-owned install record.
- **85** — alarm numbers 7 / 14 / 7 / 14 days, all configuration.
- **86** — a second same-session release of agent and hub (R-846).
## Register
Open rows **332 → 333**. Closed: **R-841**, **R-845**; filed and closed the same day: **R-846**, **R-850**. Opened:
**R-848** (a held host package is invisible to the hub), **R-849** (the guest "reboot needed since" never clears),
**R-851** (a panicked host stays down — operator). Narrowed: **R-836** (GRUB one-shot measured: not a one-shot),
**R-812** (host lane built). `unproven.py`: unchanged (35 of 55 not walked).
## Teardown — three layers
- **Machine:** demo-hp guest 9201 — the port-7844 block removed (`DOCKER-USER` empty, verified); cloudflared
`healthy`. demo-hp host — `tzdata` back on 2026c, no holds, no snapshot source left; `sp5100_tco` unloaded; GRUB:
`GRUB_DEFAULT=saved`, saved default 7.0.14-20, `next_entry` cleared, `/etc/default/grub` backup at
`/root/grub.default.bak-2026-10-04`. demo-felhom host — `tzdata` 2026c (re-installed by its ring-1 run), no snapshot
source left.
- **Host:** both demo hosts run agent 0.141.1 + wrapper `51e100ad…`; both ring 0, switch ON.
- **Hub:** the TEST approval wait reverted (log: 24 h and 1 night); the TEST releases `os-guest-20261004-123933` and
`os-host-20261004-124034` stay (they are real approvals of what ring 0 runs). The operator mails `tunnel_down` /
`tunnel_recovered` for demo-hp were sent on purpose (Part A). The hub password copy in the scratchpad was shredded.
## CI
Checked by `head_sha` over every page of the Gitea `jobs` endpoint (felhom.eu `CLAUDE.md` recipe):
agent `cfba0d0` (jobs 1259, 1260), `3bf77c3` (1261), `a6bc3f1` (1262, 1263), `2e2e8f5` (1264) — all **success**;
controller `09e634d` (1258) **success**; felhom.eu `88b0a2e` (1256), `fd1f985` (1265) **success**. The last docs pushes
(`31bdb4b` and this report's commit): see the session's final message — checked after the push.
+137
View File
@@ -0,0 +1,137 @@
# REPORT — the config bundle (R-840), test approvals (R-859), the Docker-socket self-heal (R-860), Tester 2, drill-r50
2026-10-04, evening–night. Brief: "a signed route that brings an installed box's root-owned parts up to date (R-840)…".
Architecture read first: `11-os-updates.md` (§5.3, §5.4, §5.8, §5.9, §8), `03-host-agent.md` (§3, §4, §11),
`04-control-plane-authorization.md` (§3), `07-backup-architecture.md` (§6.4). Evidence: `documentation/audits/r840-config-bundle-2026-10-04/`.
## The Part table
| Part | Result | Why / what changed |
|---|---|---|
| A — what Tester 2 has | **done (read through the hub; no route to the box)** | The brief's timestamp reasoning was wrong (UTC vs local). Tester 2 has installer 1.30.0, agent 0.142.0, the crash guard armed, `live-restore` on, Docker 29.8.2, the re-made golden. It lacks only the R-858 wrapper fix. |
| A — the `felhom-pbs` warning | **done: not a fault** | By design (R-723): a new box's first-hour tier skip is recorded, never mailed; the tier came 7 min later and backed up at 16:31 UTC. No row. |
| B — the bundle route | **done, live on both demo boxes** | Agent 0.143.0 (bundle mode in `felhom-os-apply`, signed `agent_config_update`), hub 0.133.0, installer 1.31.0. Changed: the installer is NOT the self-update wrapper (it cannot do it); a one-time bootstrap is needed on older boxes. |
| C — Tester 2 | **act 1 sent, NOT delivered (box offline since 18:06 UTC); act 2 waits for the operator; act 3 not needed** | Act 1: queued 18:35 UTC — see "Part C" below. Act 2 needs the one by-hand bootstrap (R-862, the operator's tunnel). Act 3: `live-restore` is already on. |
| D — test approvals end | **done, live** | Hub 0.133.0 cancelled the 4 test approvals of 2026-10-04 at start (18:20 UTC). Changed: the operator's own Docker button approval was not backfilled (CC decision). |
| E — self-heal after any Docker restart | **done, live (9202 + demo-hp)** | Controller 0.293.0. Changed: only a `docker.socket` restart breaks it; a dockerd crash or `systemctl restart docker` does not. |
| F — new installs start with the approved fixes | **built; tonight's golden carries none** | `build-golden.sh` 3.2.0 `GOLDEN_GUEST_PKGS`. No guest release is in force tonight (the test one was cancelled), so the golden keeps the template (49 Debian updates pending for the next real approval). |
| G — drill-r50 | **done** | Deleted through the product (operator's yes: it touched ep0). On ep0: its PBS namespace did not exist; its WireGuard peer left (5 → 4 peers pushed). |
| H — release, golden, records | **done** | Agent 0.143.0, controller 0.293.0, hub 0.133.0, installer 1.31.0, golden 0.293.0 baked + vouched. Floor 0.293.0 for the two demo customers only (Tester 2 untouched). |
## Claims in the brief that turned out wrong
1. **The timestamp reasoning about Tester 2 (§1).** Tester 2 was bound at **16:06 UTC = 18:06 local**; the releases were
compared in local time. At 18:06 local, installer 1.30.0 (17:36), agent 0.142.0 (vouched ~17:49) and the re-made golden
(17:48) were all current. Measured (hub records): agent **0.142.0**, crash guard **armed** (`kernel.panic` 10), `live-restore`
**on**, Docker **29.8.2**; the wrapper reports a facts mode (so it is not "old"). Only agent 0.142.1's R-858 wrapper fix is
missing — and the root files of 0.142.0 equal 0.143.0's in every file but `felhom-os-apply`.
2. **"The felhom-pbs warning is a fault."** It is the designed first-hour behaviour (R-723): recorded, not mailed.
3. **"The self-update wrapper can install a bundle safely."** It cannot: it is a fixed sh script that swaps one binary. The
bundle is installed by `felhom-os-apply` (already reachable through the agent's sudoers line). And **no** existing root
helper can install the first bundle on an older box — one by-hand bootstrap per older box (done on both demo boxes).
4. **"A restart of an existing container picks up the new socket."** True — measured twice (controller exit → restart policy;
`docker restart traefik`): both came back on the current inode, same container ids.
5. **"dockerd restarts on its own … the box shows DOWN until a person acts."** Only when the socket FILE is re-created
(`docker.socket` restart, i.e. a docker-ce upgrade or by hand). A dockerd crash or `systemctl restart docker` keeps it (measured).
6. **Act 3 for Tester 2 (`live-restore` reload)** is not needed: it is already on (from the golden).
## Part A — Tester 2, read back (hub records; CC has no route to the box)
| Item | Brief expected | Measured | Source |
|---|---|---|---|
| bound / enrolled | 16:06 (read as local) | 16:06:27 UTC bind, 16:07:04 UTC host | `appliance_registrations`, `hosts` |
| installer | 1.29.0 | **1.30.0** (the crash guard is installed — only 1.30.0 does that) | host report `system.facts.host.crash_guard` |
| agent | 0.141.1 | **0.142.0** | `/hosts` |
| PBS wrapper sha | — | `104db0a4…` = every release's | host report `wrapper_sha256` |
| `felhom-os-apply` | old (no facts, no Docker) | 0.142.0's (it answers the facts mode) | facts present |
| sudoers | — | not readable from the hub; 0.142.0's file equals 0.143.0's (tag diff); capability probe all ok | `/hosts/Tester-2-be8404` |
| crash guard / `kernel.panic` | absent / 0 | **armed / 10** | facts |
| operator-signers | absent | not readable from the hub; installer 1.30.0 writes it | inference |
| `live-restore` / Docker | off / unpinned | **on / 29.8.2** | facts |
| golden | first 0.292.0 bake | the re-bake (live-restore + 29.8.2) | facts |
| OS releases installed | TEST-approved | guest `os-guest-20261004-123933` (49 pkgs, 16:24) and host `os-host-20261004-124133` (106, 16:25), both approved "auto" 1.5 h after first seen = the TEST wait | `os_reports`, `os_releases` |
## Part C — Tester 2, what happened
- **Act 1** (signed `agent_update` to 0.143.0): queued 18:35 UTC, **not delivered** — Tester 2 stopped reporting at
18:06 UTC (host 18:05:48, controller 18:06:24). It was also silent 17:13–18:05 UTC, and its controller started at
18:06:20 UTC, so the box restarted or was switched on in between. CC sent Tester 2 nothing before 18:35 UTC; the cause
is outside this work (power, network, or the tester). The job expires 19:20 UTC; if Tester 2 returns later, it is
refused as expired (harmless) and must be re-signed.
- **Act 2** (bundle): waits for the operator's one-time bootstrap (R-862).
- **Act 3** (`live-restore`): not needed — already on.
- No Docker step, no reboot, no app change was sent. Read-back of the System page line: still agent 0.142.0, Root files
`unknown`, guard armed, `live-restore` on (last report 18:05 UTC).
## Part B — the bundle
Shape, checks, trust rule, bootstrap: `11` §5.4.2; runbook `runbooks/config-bundle.md`. Red-proofs: 22 of 22 wrapper rules
(`partB/redproof.txt`), hub 6 of 6 (`partB/hub-bundle-redproof.txt`), Go executor tests. Live:
| Step | Box | Result |
|---|---|---|
| read the box's files vs the bundle | both | 21 of 22 identical; only `felhom-os-apply` differed (`b1`) |
| bootstrap, wrong sha | demo-hp | `STOP`, nothing changed (`b2`) |
| bootstrap | both | the new `felhom-os-apply`, self-check ok (`b2`, `b3`) |
| job A, wrong sha | demo-hp | refused by the agent, nothing changed (`b4`) |
| job B, the 0.143.0 bundle | both | written 0, same 21, kept 1, self-check ok, probe 71/71 (`b4`) |
| a bundle with one deliberate change | demo-hp | written 1 (that file), self-check ok (`b6`) |
| its undo (the 0.143.0 bundle again) | demo-hp | written 1, the release file back (sha `b71d8698…`), probe 71/71 (`b6`) |
| replay of job B | demo-hp | `REJECTED … replay (nonce already seen)` (`b6`) |
| the installer's new path | demo-felhom | written 0, record `installer`, services active (`b5`) |
## Part D — test approvals
Marked, cancelled at start, amber, operator event, ring-1 bump; red-proofs 6 of 6 (`partD/d-redproof.txt`). Live at the
18:20 UTC start: `os-guest-20261004-123933`, `os-20261004-091417`, `os-host-20261004-124133`, `os-host-20261004-124034`
cancelled; one mail (three held by the cooldown); the System page lists them; the Docker release stays (`partD/d2`). The
2026-10-04 fact and why the risk was small: `runbooks/os-updates-test-waits.md`.
## Part E — the measured heal
| Box | Break | Controller back | traefik back | Container ids |
|---|---|---|---|---|
| 9202 (controller 0.291.0, before the fix) | `systemctl restart docker.socket` | never by itself (blind 2+ min, health "healthy") | never | same |
| 9202 (0.293.0) | same | +73 s | +104 s | same (`e7`) |
| demo-hp 9201 (0.293.0) | same | +88 s | +120 s | 21 of 21 same (`e8`) |
`systemctl restart docker` and `kill -9 dockerd`: socket inode unchanged, nothing to heal (`e1`, `e2`). Red-proof 9 of 9 (`e6`).
## Part F — the first-night count
Golden 0.293.0 (`documentation/tests/golden-0.293.0-2026-10-04/`): no guest release in force → template versions kept;
**49** Debian updates pending in the baked guest, which the next REAL approval (tomorrow, after 24 h + a night) will bring.
A ring-1 box from this golden installs **0** on its first night until then. The host: the agent's first leg already runs
right after the first whole-guest backup (Tester 2: 17 min after enrolment, 106 host packages in 44 s) — an installer pass
would cost ~45 s and run before any backup exists; not built.
## Part G — drill-r50
What the product delete touched (read first, `partG/g1`): hub rows (host, guest, reports 185, telemetry 185, the recovery
credential, the DR recipe, the claim, an appliance registration, the WireGuard peer 10.77.0.4), ep0's PBS tenancy
(`tenantsync.Deprovision`, namespace `drill-r50`), ep0's WireGuard peer list. No Storage Box (no off-site tier), no mail
(no address). Asked the operator (ep0); yes. Result: `deprovision ok (existed=false)` — nothing destroyed on ep0; the peer
left ep0 at the next push (5 → 4); `/hosts` without drill-r50; the delete preview 404s (`partG/`).
## Rows
Before **333**, after **334**. Closed: **R-840** (built), **R-859** (opened and closed), **R-860** (opened and closed).
Opened: **R-861** (P2 — the agent's sudoers is root-equivalent; read, not exploited), **R-862** (P3 — Tester 2's bootstrap,
operator). R-857 not fixed: avoided by baking under a new controller version.
## Decisions taken by CC (operator may reverse)
1. The one-time backfill marks only the AUTOMATIC test approvals; your Docker button approval of 2026-10-04 stays in force.
2. The bundle alarm fires after 7 days behind (`OS_ALARM_BUNDLE_BEHIND_AFTER`).
3. The bundle lives inside `felhom-os-apply` (no new sudoers line), not in a new tool.
4. The controller fixes Part E (it reaches every box by the floor), not the agent (that would need a sudoers change).
5. The demo customers' floor is 0.293.0; the global floor stays 0.292.0 so Tester 2's controller does not move this session.
## Teardown
- Machines: 9202 left on controller 0.293.0, working (all apps up). demo-hp and demo-felhom: agent 0.143.0, bundle 0.143.0,
controller 0.293.0; the test line removed again on demo-hp. Drill VM off and at `virgin`.
- Hosts: the bootstrap script, the installer harness and the test script removed from `/root` on both demo hosts. The
bundles' previous copies stay in `/var/lib/felhom-os-apply/bundle-prev/` by design.
- Hub: the registry's test version `0.143.0-r840test` deleted (204, then 404); drill-r50 removed; the scratchpad copy of
the hub DB deleted at the end.
+208 -5
View File
@@ -1,9 +1,212 @@
# STATUS — what works, what's broken, what's next
**Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).**
**Ready for the first real tester (Tester-2): yes. Tester 2 is a laptop that is switched off at night (your word,
2026-10-05) — it was offline all session; nothing was sent to it.**
**Updated 2026-10-04 (day): the off-site topic is closed; the OS-update test is done. Both demo boxes run controller
0.290.0 and host agent 0.139.0. Hub 0.129.0. New installs get golden 0.290.0; every box's floor is 0.290.0.**
**Updated 2026-10-05 (day, the night's fixes): every box of ours healthy. Fixed and proven live: the off-site clean-up
now deletes old copies (both demo boxes), a new box's first app install, the update's disk-space check, a killed
update's lost report. The power cut in the middle of an update was tested on demo-hp with your go: the box came back by
itself in 37 s, but the next update failed until I ran one command by hand — filed (R-876), fix next session.
One decision for you below (a box that is off at night). Report: `REPORT-night-fixes-2026-10-05.md`.**
## Today (2026-10-05, day): the night's fixes, the power cut by day, a box that is off at night
**Decisions I took myself (you may reverse each — `09` decisions 104–108):**
- The off-site clean-up's safety line is now "the last 7 calendar days" — the same number the clean-up keeps — not
"8 days old". It can never block an honest clean-up again.
- The image clean-up now waits while ANY app install, update, restore or undo is downloading — not only installs.
- A killed update keeps its report on the box until the hub has it; the agent looks for such reports every 5 minutes.
- **A second agent release today (0.144.1)**, against "one release per repo": the first fix for the lost report was
proven NOT to work on demo-hp, and shipping it as it was would have been worse.
**What works now (proven live):**
- **The weekly off-site clean-up really deletes old backups.** One clean-up each by hand: demo-felhom 16 → 14, demo-hp
145 → 127 — exactly the backups I predicted. No error mail, the hub's count check quiet, the key files clean.
This also closes R-95 (the box can no longer delete its own off-site history, and clean-up now works).
- **A new box's first app install works the first time:** the image clean-up met an install at minute 3 on the scratch
box, waited, and BookStack installed first try. A failed install now logs its real reason.
- **The update's disk-space check counts the real download** (12.8 MB for 13 packages; it counted 0 before).
- **A killed update still reports to the hub** (5 minutes later, once). The debug update runs with the hub away.
- Controller 0.294.0 on demo-hp, demo-felhom and Tester 1 (floor per customer; Tester 2 not moved). Agent 0.144.1
and its root files on all three. New-install image 0.294.0 baked and approved.
**Found today (filed, not fixed):**
- **After a power cut in the middle of an update, every later update fails until someone runs one command on the box**
(R-876, P2). The box itself comes back fine. Until the fix: `runbooks/crash-guard.md` has the command. I fix it next.
- A box that is off at night (below): no catch-up, no missed-backup alarm (R-872), a "server cannot be reached" mail to
the household every night (R-873), restore-tests never run (R-874).
**Needs you:**
1. **A box that is off every night (Tester 2) — what does the product promise?** Today such a box never gets its
nightly database backups, second copy or off-site copy; the whole-box backup runs only about every 2 days; no
alarm says so; the household is mailed "your server cannot be reached" every night. No design document covers it
(R-871).
- **A (my pick): a missed night runs once when the box comes back.** The database backups, the second copy and
the off-site copy run a few minutes after the box is on again (they take seconds to minutes; whether
any of them pauses an app is to be measured in the design — the whole-box backup, which does pause apps, already
has its own catch-up). App and system updates still
wait for a night. Costs: a design section and one controller release; the household may notice a busy disk for a
few minutes after switching on.
- **B: say plainly that the box must stay on at night.** The setup guide and the box's backup page say it; the
missed-night alarm fires after 2 nights off. Costs: wording + one alarm; a laptop household gets an alarm it
cannot fix except by changing habits.
- **If you do nothing:** Tester 2 keeps having no database or off-site backup, nobody is told, and the household
keeps getting the nightly "cannot be reached" mail. A restore-test alarm will fire around 2026-10-11.
2. **Tester 2's one-time step** — unchanged from yesterday (below). If you wait, it keeps working; it just cannot get
new root files.
**Recorded, not decisions:** Tester 1's Cloudflare tokens are NOT rotated (your ruling; R-870 has the steps).
## Today (2026-10-04, night): root files for installed boxes, test approvals, Docker self-repair
**Decisions I took myself (you may reverse each):**
- The hub cancelled only the AUTOMATIC test approvals of today (guest and host fixes). Your own "Approve Docker set"
press stays in force. From now on every approval made during a test wait gets the test mark, button or not.
- A box whose root files are behind the approved ones for 7 days sends you a mail.
- The demo boxes' controller floor is 0.293.0; the fleet floor stays 0.292.0, so Tester 2's controller did not move.
**What I did:**
- **Root files for installed boxes (your ruling):** a box's root-owned files (permissions list, helper scripts, crash
guard) now travel as one signed package. The box checks your signature, every file and itself; on any problem it
puts the old files back. Proven on both demo boxes: a wrong package refused, a package with one changed line
installed and undone, a copied old job refused. New installs use the same package.
- **One catch:** a box installed before tonight cannot take the FIRST package by itself; it needs one small step by
hand. I did it on both demo boxes. **Tester 2 needs it from you** (below).
- **Tester 2 was not as old as the brief thought:** it was installed at 18:06 local, after the crash guard and the new
image. It already has the crash guard, live-restore and Docker 29.8.2. It lacks only tonight's Docker-update fix. I
sent it the signed agent update.
- **Test approvals end with the test:** the hub cancelled today's 4 test approvals at its restart (you got one mail).
Tester 2 keeps what it installed; no further box installs them. The same fixes get a real approval after 24 h + a night.
- **Docker self-repair:** if Docker's socket is re-created, the controller now restarts itself and the web router within
about 2 minutes. Proven on the scratch box and on demo-hp, no app restarted.
- **drill-r50 is gone** from the hub. On ep0 nothing was destroyed (it had no backups there); its tunnel entry left.
- The "felhom-pbs skipped" line on Tester 2 is normal for a new box's first hour (no mail was sent).
- New-install image 0.293.0 baked and approved.
**Needs you (nothing breaks if you wait):**
- **Tester 2 is offline** since 20:06 local (and was off 19:13–20:05 local; it restarted in between). I sent it nothing
before 20:35. My agent update for it is queued but expires at 21:20 local; when the box is back I re-send it.
Worth asking the tester whether the box was switched off.
- **Tester 2's one-time step** (5 minutes): connect your tunnel, `ssh -p 8822 felhom-op@10.77.0.5`, reveal the root
password in the hub (Hosts → Tester-2 → Console access; this writes one line on Tester 2's timeline), `su -`, then
run the three commands in `documentation/runbooks/config-bundle.md` ("Tester 2"). Tell me when done; I send the package.
If you wait: Tester 2 keeps working; it just cannot get new root files until then.
- **Found, not fixed:** the agent's permission list is wider than "minimal": a broken-into agent could become root on
its own box. Worth fixing before the first paying customer.
## Today (2026-10-04, ~18:30): you found a bug — the Docker update blinded the box's controller
- **What happened:** the Docker update on the N100 restarted Docker itself. The apps kept running (as designed), but
the controller and the web router kept a connection to the OLD Docker, so the controller could not see anything:
the hub showed the N100 DOWN from 14:18 to 15:57. demo-hp had the same fault; the crash test happened to heal it.
- **Fixed (your choice):** after a Docker update the box now restarts just those two (about 10 seconds, apps untouched),
and the update's health check now asks "can the controller really reach Docker?". Released as host agent 0.142.1,
proven twice on demo-hp, on both demo boxes now, and approved for new installs.
## Today (2026-10-04, late evening): the System page, Docker updates, the crash restart
**Decisions I took myself (you may reverse each):**
- The box knows a crash only as "it did not shut down cleanly" (the crash memory chip saved nothing). So a power cut
also counts as a crash.
- An "oops" (a kernel error the box survives) does not restart the box; you get a mail instead.
- Your words win where the brief disagreed: the **3rd** crash within one hour leaves the box off. Restart after 10 s,
re-arm after 24 h. All settings.
- Only the box itself decides whether a Docker update is allowed: it checks your signature with a key file only root
can change (not the agent's own settings, which the agent could change).
- The System page uses the alarm limits for its colours (red = an alarm would fire).
**No decision needed from you today.**
**What I did:**
- **The System tab** in the hub: per box the Proxmox, kernel (now and next boot), Debian and Docker versions, what is
waiting, held packages, "restart needed", the crash guard and the last update run — with buttons for ring, on/off,
"Approve now" and "Approve Docker set". The Hosts page shows Proxmox and kernel too.
- **Docker updates:** "live-restore" is on in every box (no app restarted: 24 of 24 and 5 of 5 containers kept running).
Both demo boxes moved to Docker 29.8.2, every app kept running. I approved that set with the new button (a 0-night
test wait, then back to 2 nights). An undo signed by your key put demo-hp back one version and forward again, apps
running throughout. A copied (replayed) signed job was refused.
- **Crash restart (your 3 crashes on demo-hp):** crash 1 and 2 — back by itself in under a minute; crash 3 — it stayed
off until you switched it on. You got the "guard tripped" mail. I re-armed it.
- **Found:** the hub learns about a crash up to 15 minutes late (nothing lost). After a crash, the household can also get
an "app stopped" mail besides "restarted after a crash" — whether to calm that is a later choice for you.
- **New-install image re-made** with live-restore on and the approved Docker version, and approved in the hub with host
agent 0.142.0. New boxes also get the crash guard (installer 1.30.0).
- **Rows:** 6 closed, 1 opened-and-closed the same day, 5 opened. The list went from 334 to 333.
**Needs you later (nothing breaks if you wait):**
- Installed boxes still get new root files only by hand (the long-standing gap; there are no other boxes today).
- Kernel updates are still not built (a hung new kernel would stay — needs a fix first).
## Today (2026-10-04, evening): host fixes, the fleet view, a true tunnel status
**Decisions I took myself (you may reverse each):**
- Only a box the installer itself recorded as "appliance" gets host updates (a record the agent cannot change).
- The four alarm times: no update run for 7 days; "reboot needed" for 14 days; the demo boxes approve nothing for 7
days; a box has fixes nobody approved for 14 days. All four are settings.
- I released the host agent and the hub a second time today. The first release said "reboot needed" wrongly; the new
14-day alarm would then have mailed you about boxes you had already rebooted.
**One decision for you (a safe default if you say nothing) — the Docker engine updates (designed, not built):**
1. **Turn on Docker's "live-restore" on every box.** With it, a Docker engine update restarts no app (measured: 0
restarts). Without it, every app stops for about 30 seconds per engine update.
- **A (my pick):** turn it on — in the new-install image and once on existing boxes. It goes on without restarting
anything. Cost: it must never be turned off by a plain restart again (that stops every app and starts none).
- **B:** leave it off. Every Docker update then means ~30 seconds of every app being down, at night.
- **If you say nothing:** nothing changes; Docker updates stay unbuilt.
**What I did:**
- **The host's Debian fixes now install themselves**, after the guest's, on the same night run, only on appliances,
never a kernel or boot package, never a reboot. Proven: demo-felhom installed 108 host fixes and stayed healthy; all
108 came from Debian. A box made "ring 1" for a test installed exactly the one approved host version it lacked.
- **A way to put one host package back by hand** is written and proven on demo-hp (and the test taught it two fixes).
- **The fleet view** in the hub: one line per box with its updates, "reboot needed since", and the tunnel.
- **The tunnel status is now true:** running, not running, or unknown. I blocked demo-hp's tunnel: after two reports
(about 30 minutes) you got a "tunnel down" mail; when I unblocked it, "recovered". A simply stopped tunnel heals
itself within 5 minutes, before the hub can even see it.
- **The night run is fast:** 23–32 seconds when there is nothing to install (target was under 60).
- **The kernel test on demo-hp (your two reboots):** Secure Boot works with it, but GRUB's "boot once" does not work
on our boxes: the second plain reboot came up on the NEW kernel again. So a new kernel that hangs would stay. That
must be solved before kernel updates. demo-hp now runs the newer kernel, healthy. A watchdog chip exists on demo-hp.
- **Found and fixed during the live test:** "reboot needed" was wrong in two ways (fixed in the second release).
- **New-install image baked and vouched** (0.292.0 with host agent 0.141.1). The golden waiver is gone: not needed.
- **Rows:** 2 closed, 2 opened-and-closed the same day, 3 opened. The list went from 332 to 333.
**Needs you later (nothing breaks if you wait):**
- **A host that crashes does not restart by itself** (Linux's "panic" setting is off). Changing it changes how every
box behaves, so it is your call, together with kernel updates.
## Today (2026-10-04, afternoon): the guest's security fixes install themselves
**One decision for you (a safe default if you say nothing):**
1. **Undo for a guest update that goes wrong.** I tested it first, as you asked: Proxmox cannot take a snapshot of a
customer box at all (the box is linked to the household's drives, and Proxmox refuses). So there is no automatic undo.
Today a failed check stops, mails you, and last night's whole-box backup (minutes old) is the undo, by hand.
- **A (my pick):** keep it so. Nothing new to build. A restore takes about 1–3 minutes plus losing what apps wrote
since the backup.
- **B:** build our own disk snapshot under Proxmox. Automatic, but a new mechanism nobody has tested, with a risk to
the disk pool.
- **If you say nothing:** A stays.
**What I did:**
- **Your two choices are built.** A returning household's new box sets the old off-site copy aside on night one and
starts a new one (nothing deleted). An approved version that Debian already replaced comes from Debian's dated archive.
- **Guest security fixes now install themselves.** Each night, after the whole-box backup, the demo boxes install
Debian's fixes. When both demo boxes run the same versions healthy for 24 hours and one night, the hub approves that
set; every other box then installs exactly those versions. Docker, the host and the kernel are not touched.
- Proven live: each demo box installed 53 fixes and stayed healthy. With a 2-minute test wait the hub approved the
set; then I put back 24 hours. demo-felhom, made "ring 1" for the test, installed exactly the 3 approved versions it
lacked and nothing newer. A run where I stopped an app failed its check and mailed you (you got that mail).
- You can switch OS updates off per box in the hub. They are ON by default. The household sees one line in its
timeline: "System security fixes installed".
- **The tunnel and two other built-in programs are current** (cloudflared was 4 months old). A new monthly check
catches them falling behind. The tunnel came back by itself on both demo boxes within 20 seconds.
- **Three bugs found and fixed during the live test**, before release.
- **Two gaps found, now rows:** existing boxes cannot receive the new update tool through the product (only new
installs, or by hand — the demo boxes got it by hand); and the hub's "tunnel status" for every box always reads
"inactive" because it checks the wrong place.
- **Rows:** 4 closed (one opened and closed the same day), 5 opened. The list went from 331 to 333.
## Today (2026-10-04, day): off-site closed, operating-system updates measured
@@ -148,8 +351,8 @@ Your licence decisions are recorded: Emby, Plex and n8n stay. recipe-importer ne
## What needs you
0. **The two decisions at the top of today's section** (a returning household's first night; approved OS updates
when Debian has moved on). Each has a safe default if you say nothing. The Hetzner key change stays your call (3 steps, in the list).
0. **The undo choice at the top of today's section** (A: keep the backup as the undo; B: build our own snapshot).
If you say nothing, A stays. Earlier today's two decisions are built. The Hetzner key change stays your call.
1. **plant-it:** keep the hidden template as it is, or remove it entirely (its image no longer exists). **If you say
nothing:** it stays hidden; nothing runs it.
2. **Send the SparkyFitness request, and ask the Tandoor authors** (the "Before the first paying customer" list).
@@ -232,7 +232,7 @@ likewise silent. Evidence: `audits/DRILL-r361-2026-08-22/evidence/06-part3-decis
| **The hub reports LOSS OF VISIBILITY into either off-site store (not just how full it is)** | hub **v0.106.0** (R-339) | **IMPLEMENTED — deliberately NOT proven-live** | Both box checkers count consecutive failed fetch windows and emit `pbsdr_box_unreachable` / `offsite_box_unreachable` (severity `warning`) past a default 3 windows (≈30–45 min), each with a paired `*_recovered` all-clear routed via `recoveredPairedDownTypes` — required because the recoveries are severity `info`, which `severityNotifies` drops. Scopes stay customer-less (`pbsdr-box` / `pool-box`) → operator channel only. Fill logic untouched: a degraded read still drives no band transition. Evidence: `internal/monitor/box_reachability_test.go` + the cross-package wiring test in `internal/notify/`, which asserts an actual operator mail rather than a map entry. **Filed BECAUSE of a measured gap**, not a hypothesis: the 2026-08-18 ep0 outage ran 9 h 37 m with the hub silent | **The gap that remains is R-340**, and it is not small: the ep0 read is the `usage` op, which rides the LOCAL API daemon — the daemon that incident explicitly cleared — so this check would have shown GREEN for that entire outage. It closes "ep0 is unreachable as a host"; it does not close what actually happened. **No live or constructed outage has exercised the emit path**, and one cannot be manufactured against ep0 (Tier 2, protected) |
| Secrets hygiene: bearer in k8s Secret, no secrets in git, single-quote credential store | hub v0.53, conventions | **IMPLEMENTED** | 07-13 closing bundle | |
| Operator login password changeable from UI | hub v0.54 | **IMPLEMENTED** | 07-13 | |
| Box operating-system security updates (Proxmox host, guest Debian, Docker engine) | — | **MISSING** | `felhom-host-install.sh:2133-2136` ("No upgrades are run") | Nothing runs them after install → finding R-812, intention R-808 (added 2026-10-03). Design: `architecture/11-os-updates.md` (NOT RATIFIED, 2026-10-04). **Spike done 2026-10-04** (`audits/os-updates-spike-2026-10-04/`): measured, nothing built — still MISSING |
| Box operating-system security updates (Proxmox host, guest Debian, Docker engine) | agent v0.143.0, hub v0.133.0 | **PARTIAL — the GUEST and HOST Debian fast lanes and the DOCKER engine slow lane are PROVEN-LIVE (2026-10-04), with the System page, the fleet view and the alarms; the KERNEL lane is MISSING** | Guest: `audits/os-guest-lane-2026-10-04/`. Host + fleet + alarms: `audits/os-host-lane-2026-10-04/`. Docker + System page + crash guard: `audits/os-docker-crash-2026-10-04/` — live-restore on with the same container ids on every box; Docker 29.8.2 on both demo boxes; operator-approved Docker release; a signed undo and a signed ring-1 step; a replay refused; the crash guard restarted demo-hp twice and kept it off the third time. Design `architecture/11-os-updates.md` §5.8, §5.9, §8 | **No automatic undo** (guest: last night's backup; host: by-hand runbook; Docker: a signed undo job); existing boxes get root-owned files by the signed config bundle since 2026-10-04 (R-840 CLOSED; a box from before agent 0.143.0 needs one by-hand bootstrap — Tester 2: R-862; `audits/r840-config-bundle-2026-10-04/`); test approvals now end with the test (R-859); the agent's sudoers is root-equivalent (R-861); the kernel lane (R-836); facts reach the hub late after a boot (R-853). **2026-10-05 (agent v0.144.1):** R8 measures the real download (R-865); a killed pass still reports (R-868, live); the debug pass runs with the hub away (R-866, live); **a power cut mid-update was proven by day on demo-hp — the box came back by itself in 37 s, but the next pass fails until `dpkg --configure -a` is run by hand (R-876, P2, open)** — `audits/night-fixes-2026-10-05/` |
| **An ENGLISH-SPEAKING household's first hour: download, install, pair, bind, claim, two apps** | controller **v0.259.0** + hub **v0.119.0** + ISO 1.29.0 + the whole catalog | **PROVEN-LIVE on 0.258.0 with one blocker; THE BLOCKER IS FIXED AND PROVEN, THE WALK IS NOT REPEATED** | `audits/DRILL-first-hour-en-0258-2026-09-20.md` — a fresh install 2026-09-20, one intervention (R-494), stop rule not reached. Then `audits/i18n-closing-2026-09-21/live/` — the three blockers fixed and each proven on a live box or in the operator's inbox: the claim page answers English through the real cookie path; the Backup page's tier names follow the language; and the setup mail carries **four plain-ASCII English words** where the drill's carried `képző-szkítia-ásatás`, one day apart in the same inbox. | **R-596, R-597 and R-598 are CLOSED.** What this row still does NOT claim: **the fixed journey has not been walked end to end by a stranger on a fresh install.** Three fixes proven at the endpoint are not an hour proven by a person, and this project's own rule is that fixes are not a journey (see the recovery-journey row). **Also not walked:** the recovery code (needs ep0), backup/restore/remove/power-cut (proven 2026-09-14), and the two Backup-page *warnings* themselves — guest 9201 is healthy and a healthy box renders none, so they are covered by handler render tests, not live. **Verdict: nothing known now stands between an English-speaking tester and their box — and that is a different sentence from "the walk passed".** |
| **A deletion of a customer's off-site history is NOTICED within a day** | hub **v0.111.0** (R-431) | **IMPLEMENTED — not yet PROVEN-LIVE** | 09-01 | `hub/internal/monitor/offsite.go` — third signal beside FILL and STALENESS. **On the hub deliberately:** a detector on the box is one the deletion can silence. Alarms when the reported count falls by more than HALF and by at least 5, guarded by `StatsKnown` (R-331), the declared `State` (R-204) and run success (R-100). **Threshold reasoned, not invented:** over 12 898 reports every decrease lands on ZERO and predates `stats_known`; in the 380-report `stats_known` window there are none. **ACCEPTANCE: 9 009 real points replayed → ZERO alarms** (`offsite_r431_test.go`, fixture committed). **What PROVEN-LIVE would need and this does NOT have:** a real drop observed on a live box producing a real mail — the live firing done at ship time was driven through the hub's own path with synthetic counts, which is an end-to-end delivery proof, not a proof that a genuine deletion is caught. |
+26 -3
View File
@@ -47,7 +47,13 @@ Owns:
1. **Proxmox lifecycle** — create/start/stop/destroy guests, snapshots, storage allocation. Via a scoped Proxmox API token (the **`FelhomAgent` operator role** — `proxmox-platform.md` §3.6, validated Phase 3 B3) for everything the API covers; raw host ops only where unavoidable.
2. **Storage management** — attach/classify targets, reconcile the storage manifest, mount USB-by-UUID, present mounts into guests.
3. **Backup/restore orchestration** — vzdump to the tiers, PBS, snapshot management, and the **self-restore-test**.
4. **Host & tunnel monitoring** — host metrics, guest up/down, storage-target status, and `cloudflared` health; reports the host domain to the hub.
4. **Host & tunnel monitoring** — host metrics, guest up/down, storage-target status, and `cloudflared` health; reports the host domain to the hub. **[FACT, 2026-10-04] The "cloudflared health" leg reads a host unit that does not exist:** `internal/hub/cloudflared.go` runs `systemctl is-active cloudflared` on the HOST, but cloudflared is a container in the guest (below), so every box reports `inactive` (`Unit cloudflared.service could not be found`, demo-hp). R-841. **[FACT, FIXED agent v0.141.0 / controller v0.292.0, R-841 CLOSED]** The agent now reads the guest's `cloudflared` container through the existing `pct exec [0-9]* -- docker inspect -f *` sudoers line: state, exit code and the Docker health status of a check the controller adds (`cloudflared tunnel --metrics localhost:20241 ready` → cloudflared's own `/ready`, 200 only with a connection). Three states: `running` (healthy), `not_running` (stopped, absent, or running but NOT connected), `unknown` (could not ask, or the check is still starting) — `unknown` never alarms. No new sudoers line. **[FACT, agent v0.142.0, R-852]** The host report gains `system`: the Proxmox version and kernel from the
Proxmox API, plus the OS wrapper's read-only `facts` (host Debian, next-boot kernel, held packages, taint, the crash
guard; guest Debian, Docker engine, containerd, live-restore), at most every 10 min. **Still no new sudoers line** — the
facts, `live-restore-on` and the Docker layer all ride `FELHOM_OSAPPLY`. New ROOT-owned files instead (installer 1.30.0;
by hand on installed boxes, R-840): `/etc/felhom/os-trust.json`, `/etc/felhom/operator-signers` (the wrapper verifies
Docker authority against them, never against the agent-writable config — `09` decision 93), and the crash guard
(`/usr/local/sbin/felhom-crash-guard`, its units, `/etc/felhom/crash-guard.conf`).
5. **Provisioning** — provision a guest **by restoring the golden base image** (§9), deploy the controller into it, hand it its bootstrap config; also **build and refresh the golden base image** itself.
6. **Hub control loop** — poll for desired state + signed jobs, reconcile, execute, report, heartbeat.
7. **Local API** — the per-guest authorization gate the controller calls.
@@ -64,7 +70,7 @@ Explicitly does **not**:
- **Native Go binary, systemd service** on the host: boot-start, `Restart=always`, systemd watchdog (kill+restart on hang), journald logging, resource limits.
- **Root-minimized (boundary settled — Phase 3 B3).** The agent runs as a **non-root** service user with the scoped `FelhomAgent` token for all API-covered work + a **narrow `sudoers` allowlist** for true host ops. Per Phase 3 (B3) the boundary is settled: the entire per-customer guest lifecycle — provision (by restore, §9), config, start/stop, snapshot, backup, **restore**, destroy — is token-covered. Genuine OS-root is confined to: (1) building/refreshing the **golden base image** (`keyctl` create is `root@pam`-only — one-time at enrollment + a maintenance cadence, §9); (2) **host mounts** (USB mount-by-UUID, systemd mount units / fstab); (3) **SMART / hardware sensors**. Root therefore never sits on the per-customer path. See `proxmox-platform.md` §3.6 for the role + boundary table.
- **`cloudflared` is a separate systemd service**, not embedded in the agent. This is what makes the data path survive control-plane death by construction. The agent **manages and health-watches** it (see §5) but the tunnel does not live or die with the agent process.
- ~~**`cloudflared` is a separate systemd service**, not embedded in the agent. … The agent **manages and health-watches** it (see §5) but the tunnel does not live or die with the agent process.~~ **[FACT, corrected 2026-10-04 — `11-os-updates.md` C8, R-838]** `cloudflared` is a **container in the customer guest** (`cloudflare/cloudflared:<pin>`), rendered and kept up by the in-guest controller (`felhom-controller/controller/internal/infra/infra.go`, `internal/stacks/infra.go`) and baked into the golden; there is no host systemd unit. It is still NOT embedded in the agent, so the data path survives the agent's death — and the agent does not manage it; it READS its health (R-841, agent v0.141.0). Its version moves only by a controller release (the pin), on the monthly re-test (`runbooks/monthly-floating-retest.md` "Infrastructure pins").
## 4. Control model — reconcile + signed destructive ops
@@ -143,7 +149,7 @@ notification) is the control.
**Box-initiated poll.** The hub never connects inbound. Each poll cycle exchanges:
- **Up:** heartbeat + a host-domain state report — host CPU/RAM/disk, per-guest up/down + spec, storage-target status (USB connected? NFS/CIFS reachable? PBS reachable?), last backup per target, last restore-test result, `cloudflared` health, agent + controller versions, audit-log tail.
- **Up:** heartbeat + a host-domain state report — host CPU/RAM/disk, per-guest up/down + spec, storage-target status (USB connected? NFS/CIFS reachable? PBS reachable?), last backup per target, last restore-test result, `cloudflared` health (`running` / `not_running` / `unknown` from the guest container's readiness check — R-841), agent + controller versions, audit-log tail.
- **Down:** the current desired state, any pending signed one-shot jobs, and config (poll interval, update window, policy changes).
**Dead-man's-switch (essential, not optional).** In a box-initiated model the heartbeat
@@ -633,6 +639,23 @@ buildable until then; recorded here so the front-half built in slice 7 lands rea
never — the binary is what flips. Report field `selfupdate_pending` surfaces a runs-but-never-commits
binary. v1 scope-outs: no hub-floor auto-update, no failed-update auto-retry (the operator re-signs),
no pending-timeout auto-rollback.
- **OS updates, guest fast lane (agent v0.140.0, `11-os-updates.md` §8.1).** A second root-owned wrapper,
`/usr/local/sbin/felhom-os-apply`, behind ONE sudoers entry (`FELHOM_OSAPPLY`: `felhom-os-apply --plan
/var/lib/felhom-agent/os/plan-*.json`). The agent has no `apt` grant of its own for this; every rule (no removal,
no downgrade, no new or unlisted package, Debian origin only, the box's own customer guest only) is in the wrapper,
red-proved per rule. The leg runs after a successful primary whole-guest backup, under the heavy-op gate.
~~**[FACT] The signed agent update does NOT carry the wrapper or the sudoers line** — only the installer installs
them (R-840).~~ **[FACT, 2026-10-04, agent v0.143.0] The config bundle does:** a signed `agent_config_update` brings
every root-owned file (sudoers, wrappers, units) as one checked unit; `felhom-os-apply` verifies it itself, keeps the
previous copies and undoes on a failed self-check; the trust root (`/etc/felhom/operator-signers`, `os-trust.json`) is
never a bundle path. The installer installs the same bundle. A box from before 0.143.0 needs one by-hand bootstrap.
Design: `11` §5.4.2; runbook `runbooks/config-bundle.md`.
- **[FACT, 2026-10-04 — R-861] "Root-minimized" overstates it.** Read from `configs/felhom-agent.sudoers`: the agent user
can already reach root without the operator key — `FELHOM_GUESTHOOK` installs a hookscript from `/tmp` that Proxmox
runs as root at guest start (and `pct reboot` is granted); `FELHOM_INTERMEDIARY` installs a script and a systemd unit
that run as root at boot; `FELHOM_ESCROW` runs the agent binary as root, and `FELHOM_SELFUPDATE apply` accepts a sha
the agent itself passes. So a compromised agent PROCESS is root on its host; the root-owned trust files (decision 93,
the bundle's R17) are defence in depth, not a boundary, until R-861 narrows these grants.
- **Controller (the easy case — it's a guest).** The agent owns the controller's lifecycle,
so the **agent updates the controller**: snapshot-before-update (free rollback, because the
controller *is* a snapshottable guest) → pull new image → redeploy → health-check → rollback
@@ -113,6 +113,16 @@ Proven twice: `demo-hp-bb76ea` 2026-09-15, `demo-felhom-8363b5` 2026-09-16. **Re
sale** — at that point the key belongs behind the operator (or a hardware key, §7), and a fleet
rollout step still has to be designed (R-530).
**Who may sign a config bundle (`agent_config_update`, R-840, decision 96, 2026-10-04).** The same operational key
(`felhom-op-1`) and the same custody: CC may sign it under the ruling above (per box, until the first paying
customer). It is destructive-class (the agent's gate requires the operational key) AND the box's root wrapper verifies
the signature itself against the ROOT-OWNED `/etc/felhom/operator-signers` — not the agent's config. The recovery key
does not sign bundles. **A bundle can never change who may sign:** the signers file and `os-trust.json` are not bundle
paths (R17); on a box with no signers file, only a job signed by the installer's pinned `felhom-op-1` is accepted, and
the file is created with exactly that key. **Rotating a signer** (adding `felhom-op-2`, removing `felhom-op-1`) is a
separate act, not built: it needs its own op, signed by the key being replaced (or the recovery key), with its own
design (`11` §5.4.2).
## 4. Rotation & compromise recovery
The agents pin the operator public keys. The danger: rotation must **not** flow as plain hub config,
File diff suppressed because one or more lines are too long
@@ -310,6 +310,36 @@ message, not a wider cooldown.
---
## 6.3 Box alarms outside the app ladder: the tunnel and OS updates [DESIGN, hub v0.131.0, 2026-10-04]
These are **operator-only** (the household can act on none of them — except `host_restarted_after_crash`, the household's
one info line beside `host_crash_restart`; `operatorOnlyEvents`, pinned by
`TestOSUpdateEvents_OperatorOnlyExceptApplied`). They go through the same dispatcher and severity contract (§6.1):
`info` is recorded and never mailed; `warning` and `error` are mailed.
| Event | Severity | Raised when | Cleared | Pinned by |
|---|---|---|---|---|
| `tunnel_down` | error | the box's two newest host reports say the tunnel is `not_running` (more than one report cycle, 15 min) and the one before did not | the first `running` after it → `tunnel_recovered` (info) | `api/tunnel_test.go` |
| `os_update_stale` | warning | no successful OS leg for **7 days** while the switch is ON (agents that can run the leg only); the mail names the likely reason (box not reporting / the last leg's failure / no good night backup) | a successful leg | `TestAlarm_StaleLeg`, `TestAlarm_StaleNamesTheReason` |
| `os_reboot_needed` | warning | the host has needed a reboot for **14 days** (from the FIRST scanned report that said so) | a scanned pass that finds nothing (agent ≥ 0.141.1 scans the host every pass) | `TestAlarm_RebootNeeded`, `TestRebootNeeded_ClearedByAScannedPass` |
| `os_ring0_stalled` | error | ring 0 approved nothing for **7 days** in a layer while it has pending FAST-lane updates (a pending kernel does not count) | a new release | `TestAlarm_Ring0Stalled` |
| `os_not_covered` | warning | a ring-1 box has had fast-lane packages no approved release names for **14 days** | the packages are covered or gone | `TestAlarm_NotCovered` |
| `host_crash_restart` | warning | the box's crash guard reports a NEW unclean boot (a crash, a power cut or a hard reset; hub v0.132.0) | — (one per boot) | `api/crash_test.go` |
| `host_crash_guard_tripped` | error | the guard tripped: the next crash leaves the box OFF | the re-arm → `host_crash_guard_rearmed` (info) | `api/crash_test.go` |
| `host_kernel_oops` | warning | a kernel oops this boot (taint D) — the box keeps running | — (once per boot) | `api/crash_test.go` |
- **`unknown` never alarms** (R-96 rule 3): a probe that could not ask is neither up nor down. An `unknown` report
breaks a `not_running` run.
- **A stopped cloudflared heals itself before the hub can see it** (measured 2026-10-04): the controller's
protected-container check recreates it within 5 minutes, and the host reports every 15. So `tunnel_down` catches
what the box cannot heal — a running container with no connection (wrong token, blocked network).
- The OS alarms are checked **hourly**, re-sent at most **once a week** while true, and forgotten when false, so the
next occurrence is announced again. The four numbers are configuration (`OS_ALARM_STALE_AFTER`,
`OS_ALARM_REBOOT_AFTER`, `OS_ALARM_RING0_STALL_AFTER`, `OS_ALARM_NOT_COVERED_AFTER`) — *decided by CC unattended,
operator may reverse* (`11` §8.3).
---
## 7. The intent test [DESIGN, R-386 — CLOSED controller v0.223.0]
**"The customer stopped this" is asked of the FIELD THAT RECORDS IT, never inferred from the state.**
@@ -741,6 +741,12 @@ its length, and both fixes cost something the household would notice — operato
days from the box's request (R-823)**; the household (a recovery on the box) or the operator can cancel in that
time; the hub deletes only `<repo>.orphaned-<…>`, never the live repository; every request, cancel and deletion is
an operator event. *Operator brief 2026-10-04 (Part E).* Built hub v0.128.0 + controller v0.290.0.
**Note 2026-10-05 (R-867, controller v0.294.0):** the clean-up windows that feed this deletion path now remove
honest old copies: the guard's "young" line is keep-daily CALENDAR days (decision 104), not a fixed 8-day age that
sat inside the keep window. Proven live by hand the same morning: demo-felhom window 5 (16 → 14, the 2 snapshots
predicted), demo-hp window 6 (145 → 127, the 18 predicted); hub count check quiet, key files clean, no mail.
The reviewer's own error is recorded: the 2026-10-04 brief set the 8-day line and said real deletion would start
around 11 October; it would not have. `audits/night-fixes-2026-10-05/partA/`.
### 2026-10-04 (day) — three operator rulings (recorded before the work)
@@ -765,6 +771,141 @@ its length, and both fixes cost something the household would notice — operato
80. **Next build: the guest fast lane** (`11` §8 step 2), with R-837 (the snapshot undo) measured first and R-838 (the
infrastructure images) in the same session. *Operator ruling 2026-10-04 ~10:17.*
### 2026-10-04 (~12:20) — three operator rulings (recorded before the work)
81. **The undo for a failed OS update is the whole-guest backup, restored by hand (R-842, option A).** Nothing new is
built. **Rejected:** a home-made LVM-thin snapshot behind Proxmox's back (unmeasured; thin-pool risk).
*Operator ruling 2026-10-04 ~12:20.*
82. **R-840 (a route for wrappers/sudoers to installed boxes) is not built now** — *"There are no older boxes."* No
installed box exists outside the two demo boxes, and they take wrapper changes by hand. The row stays open, not
re-ranked. *Reviewer's note, recorded as written:* the ruling is right for today, but every box installed from now on
becomes an "older box" the first time the wrapper or the sudoers line changes again; R-840 must be solved before the
first box that cannot be reached by hand. *Operator ruling 2026-10-04 ~12:20.*
83. **Next: the tunnel status (R-841), the host fast lane (`11` §8 step 3), and other OS-update improvements.**
*Operator ruling 2026-10-04 ~12:20.*
### 2026-10-04 (~18:00) — operator ruling after the R-858 incident
95. **A Docker engine step restarts the containers that mount the Docker socket** (R-858): after every step that
installed something, the wrapper restarts ONLY those containers (today `felhom-controller` and `traefik`, ~10 s;
apps untouched, the engine untouched), and the health rule checks that the controller reaches Docker from inside its
container. **Rejected:** mounting a socket folder instead of the file (cleaner, but it changes Docker's config, the
controller templates and the golden on every box). Until the fix is released, the demo boxes' root-owned ring-0
Docker mark is OFF (no unsigned step). *Operator ruling 2026-10-04 ~18:00.*
### 2026-10-04 (~18:49) — four operator rulings (recorded before the work; the R-840 / Tester 2 brief)
96. **R-840: build the route now, option A** (a signed `agent_config_update` op pinning the agent tag and the sha256 of
a config bundle; the root side installs it after its own checks), and use it on Tester 2. Every later box needs it.
**This replaces decision 82.** *Operator ruling 2026-10-04 ~18:49.*
97. **Tester 2 may receive, in this session only:** the signed agent update to the vouched agent; the config bundle
through the new route; the one-time `live-restore` reload through the wrapper (a reload, never a restart). Nothing
else: no Docker engine step, no reboot, no crash test, no app change. *Operator ruling 2026-10-04 ~18:49.*
**Added ~19:05, the operator's answer:** the first bundle cannot reach Tester 2 by the route (its root side predates
the route — see `11` §5.4.2); the operator will try to reach Tester 2 through his own WireGuard tunnel and install the
one bootstrap file by hand, with CC's written steps.
98. **drill-r50 is removed from the hub. tester-1 stays** (CC's disposable test box, a VM on the HP box, down when not
used). **Added ~19:05, the operator's answer:** the product delete may touch ep0 — it destroys drill-r50's PBS
namespace and token there and removes its WireGuard peer. *Operator ruling 2026-10-04 ~18:49 / ~19:05.*
99. **The operator's cause, with the reviewer's correction:** *"we didn't bake a new golden before he joined."* Partly:
the golden carries `live-restore` and the Docker version; the crash guard and the operator-signers file come from the
INSTALLER; the wrapper comes from the agent tag the installer pins. A newer golden alone would not have fixed it, and
with perfect timing the next wrapper change would still leave Tester 2 behind — that is R-840. **CC's measurement
(same evening) corrects the premise further:** Tester 2 was bound at 16:06 **UTC** (18:06 local), after installer
1.30.0, agent 0.142.0 and the re-made golden; it lacks only agent 0.142.1's wrapper fix (R-858). *Operator ruling
2026-10-04 ~18:49.*
### 2026-10-05 (06:49) — four operator rulings (recorded before the work; the night-fixes brief)
100. **Tester 1's Cloudflare tokens, shown in the 2026-10-04 night session's output, are NOT rotated** (option B) —
filed like R-831: R-870 holds what was shown, where, and the rotation steps. *Operator ruling 2026-10-05.*
101. **The power cut in the middle of an OS update (night A1) runs by day, on demo-hp only**, while the operator is
awake to switch the box on. The crash command is allowed for demo-hp only; CC asks the operator before the crash.
*Operator ruling 2026-10-05.*
102. **Tester 2's box is a laptop that is switched off at night.** It is not broken; its absence every night is the
input to the "box off at night" spike (R-871). Recorded on its page in `runbooks/target-selection.md`.
*Operator ruling 2026-10-05.*
103. **If Tester 2 is online during the session, CC re-signs its agent update to the vouched agent** (act 1 of
decision 97) and reads it back. Nothing else on Tester 2; its one-time bundle step stays with the operator
(R-862). *Operator ruling 2026-10-05.*
### 2026-10-05 (day) — decided by CC — operator may reverse (night-fixes brief)
104. **What "young" means in the off-site guard (R-867).** Options: (a) an age in hours derived from keep-daily
(7 × 24 h minus a margin) — the margin is a guess and DST/clock shapes move it; (b) CALENDAR days, as restic
itself buckets a snapshot's day, compared with keep-daily — exactly the policy's own boundary. **Chosen (b)**:
it is the only line that provably never refuses the honest policy (the newest snapshot of any of the last N
calendar days is always kept by keep-daily N). Cost, recorded: the line no longer catches past-dated gap-fills
that steer a 7–8-day-old keep (the 8-day line did, while refusing every honest window) — that shape is R-822's
residual, bounded by the cap and the hub's count check. Controller v0.294.0.
105. **Which commands hold off the image clean-up (R-863).** Options: (a) only the deploy path (the measured case);
(b) every compose command that can pull — `up`, `pull`, `create`, `run` — through one lock in `dockerexec`.
**Chosen (b)**: a restore, an undo and the FileBrowser sync pull the same way, and one lock is one place to
keep right. The one-time clean-up is retried every 2 minutes (at most 30 times) instead of waiting for the
next start, and writes its marker only after a pass that ran. Controller v0.294.0.
106. **Where a killed pass's report waits (R-868).** Options: (a) the agent writes a "pass started" record and
reconstructs the outcome from the journal — brittle; (b) the ROOT wrapper writes its own report beside the plan
before printing it, and the agent deletes it once sent. **Chosen (b)**, with the root write hardened (the
directory opened O_NOFOLLOW and checked to be the agent's own, the file created O_EXCL|O_NOFOLLOW) and a
cross-process pass lock so a sender never takes a running pass's copy. Agent v0.144.0.
107. **The debug OS pass with the hub away (R-866).** Options: (a) the selftest falls back to the block the daemon
saved, and says so; (b) a documented way to trigger the daemon's own leg. **Chosen (a).** The DAEMON does not
load the saved block at its own start (one line why: that would change what a box does after a restart with
the hub away — today it reports only, the safe direction — and no brief asked for it). Agent v0.144.0.
108. **A second agent release in one session (v0.144.1), against "one release per repo".** Options: (a) keep
v0.144.0 and leave R-868 open — its fix was MEASURED not to work live (the wrapper died on a broken stderr pipe
before saving the report); (b) release v0.144.1 with the two live findings fixed and red-proofed. **Chosen (b)**:
shipping a fix proven not to work is worse than a second release; precedent decision 86. Cost: a second signed
agent update and bundle per box.
### 2026-10-04 (evening) — decided by CC unattended — operator may reverse (System page / Docker / crash-restart brief)
90. **How does a box tell a crash boot from a clean one?** Options: (a) `pstore` — measured on demo-hp: `efi_pstore` is on,
yet a real panic saved NOTHING; (b) the previous boot's journal ends without shutdown lines — readable only after
the journal is up, and slow; (c) a marker written by an ExecStop at every orderly shutdown. **Chosen (c):** cheap,
early, measured to work; cost: a power cut and a hard reset count as a crash too (they cannot be told apart on these
boxes). `11` §5.9.
91. **`kernel.panic_on_oops`?** Options: set it (an oops becomes a restart, which may loop on a bad driver) or leave it
0 and REPORT an oops (taint bit D) to the operator. **Chosen: leave 0, report** — a box with an oops usually keeps
serving the household; the hub mails `host_kernel_oops`. `11` §5.9.
92. **The guard numbers.** The brief said both "at 3 it sets panic=0 so the next crash leaves the box off" (= the 4th)
and "if it crashes 3 times within one hour, it stays off" (= the 3rd, the operator's own page). **Chosen: the
operator's words** — the 3rd unclean stop within 60 minutes leaves the box off (the guard trips at the 2nd crash
boot); `kernel.panic` 10 s; re-arm after 24 h of normal running. All four are `/etc/felhom/crash-guard.conf`.
93. **Who may authorize a Docker step on the box itself?** Options: the agent's word (its config is agent-writable);
the wrapper verifying the signed job against ROOT-owned files. **Chosen: the wrapper verifies** — `ssh-keygen -Y
verify` against `/etc/felhom/operator-signers`, bound to `/etc/felhom/os-trust.json` `host_id`, a root-owned nonce
record; an unsigned ring-0 step only with that file's `ring0_slow_lane: true`, set by hand on the demo boxes only.
Cost: two more root files per box (the installer writes them; R-840 for installed boxes). `11` §5.8.
94. **The System page colours** use the alarm thresholds themselves (red = an `08` alarm would fire; amber = worth a
look; `unknown` = amber with its reason). No second set of numbers. `11` §5.7.
### 2026-10-04 (~15:17) — three operator rulings (recorded before the work)
87. **Docker `live-restore` is ON for every box** (`11` §5.8, option A). It is turned on once — by the golden and by a
one-time step on each installed box — and never turned off by a plain restart (R-835). *Operator ruling 2026-10-04
~15:17.*
88. **A crashed host restarts by itself, with a limit** (R-851): *"Yes, but maybe not indefinitely."* After a limit of
crashes in a short time the box stays off and the operator is told. *Operator ruling 2026-10-04 ~15:17.*
89. **The operator must see the boxes' OS and Proxmox versions in the hub** (*"Where should I be able to see the
OS/Proxmox versions of the boxes?"* — today: nowhere; R-852). *Operator ruling 2026-10-04 ~15:17.*
### 2026-10-04 (afternoon) — decided by CC unattended — operator may reverse (host fast lane brief)
84. **Which record proves a box is an appliance, for the host fast lane?** Options: (a) `agent.json`
`deployment_mode` — the agent can write it, so a compromised agent could claim "appliance" and unlock host
updates; (b) the installer's ROOT-owned `/var/lib/felhom-install/state.json` `mode` — written once, as root, at
install. **Chosen (b):** the wrapper is the root fence and must not trust a file the agent can change. Cost: a box
whose install record is missing gets no host step (fails closed). `11` §8.2.
85. **The four OS alarm thresholds.** Options: shorter (3/7 days — noisy: a weekend away alarms) or longer (14/30 —
a stopped box goes unseen for weeks). **Chosen:** no OS leg 7 days, reboot needed 14, ring 0 stalled 7, not covered
14; all four are configuration. Cost: a real stop is seen after a week, not a night. `11` §8.3, `08` §6.3.
86. **A second release of the agent (v0.141.1) and the hub (v0.131.1) in the same session**, against "one release per
repo". Options: (a) keep v0.141.0 / v0.131.0 and file the defect — the host "reboot needed" stays wrong (it hid
`lxc-start`, and a reboot never cleared it), so the new 14-day alarm would fire on rebooted hosts; (b) patch now.
**Chosen (b):** a known-false operator alarm is worse than an extra release; both patches are small and red-proved.
R-846.
### 2026-09-30 (day) — operator notes, recorded before the work
- **The day brief runs by day.** Every backup and automatic-update test is started by hand — the night chain's debug
+235 -8
View File
@@ -2,7 +2,7 @@
> | | |
> |---|---|
> | **Status** | **NOT RATIFIED — a PROPOSAL with one operator ruling, corrected by the 2026-10-04 spike (§7.1, corrections C1–C12 below).** Ratification is Viktor's review, not an editor's. |
> | **Status** | **NOT RATIFIED — a PROPOSAL with operator rulings, corrected by the 2026-10-04 spike (§7.1, C1–C12); §8 step 2 BUILT 2026-10-04 (§8.1).** Ratification is Viktor's review, not an editor's. |
> | **Written** | 2026-10-04, by the reviewer (project Claude), before any spike. |
> | **Verified against** | felhom.eu `d07a1a9` · felhom-controller `99a1497` (v0.290.0) · felhom-agent `d766666` (v0.138.0) · hub v0.128.0 |
> | **Freshness** | **CURRENT** as of 2026-10-04. The spike `TASK-backup-close-and-os-updates-spike-2026-10-04` adds measurements here as `[FACT]` and corrects every claim it disproves. Mark this file STALE when it falls behind what the product does. |
@@ -211,6 +211,17 @@ downloadable — but `curl`, `libcurl*` and `libssh2` were "not covered" in the
ALREADY ran the newer version and so installed nothing. `[PROPOSAL]` step 1 reports the full installed
`package=version` set after the run, and approval covers every version ring 0 runs healthy.
### 5.3.1 Test approvals end with the test — BUILT 2026-10-04 (hub v0.133.0, R-859) `[FACT]`
An approval made while a TEST override (`OS_APPROVE_AFTER`, `OS_APPROVE_NIGHTS`, `OS_DOCKER_APPROVE_NIGHTS`) is active
carries a `test` mark (amber on the System page). At every hub start WITHOUT an override, every test approval that no
real approval has superseded is cancelled: never served again, ring-1 boxes bumped, one operator event
`os_release_cancelled` each; what boxes installed stays; the ruled wait approves the same set again as a real release.
A one-time backfill marked the AUTOMATIC approvals made under 24 h after first seen; the 2026-10-04 guest and host test
approvals (which Tester 2 installed on its first night) were cancelled at 18:20 UTC. The operator's Docker button
approval of that day stays in force (decided by CC unattended — operator may reverse). Runbook:
`runbooks/os-updates-test-waits.md`. Evidence: `audits/r840-config-bundle-2026-10-04/partD/`.
### 5.4 Who runs it, and with what permission
- **The agent runs every OS update**, for the host and for the guest (`pct exec`). The controller does
@@ -269,7 +280,7 @@ longer there, from `snapshot.debian.org/archive/<archive>/<snapshot>` with a tem
| R5 | the simulation downgrades any package (the operator undo is a separate signed op, §5.6) |
| R6 | the simulation installs a package that is neither installed nor in `allow_new` |
| R7 | a listed version is not downloadable from the sources the installer set up or the named snapshot |
| R8 | free space on `/` (or the guest's rootfs) is below 3× the download size, minimum 500 MB (edge case 8) |
| R8 | free space on `/` (or the guest's rootfs) is below 3× the download size, minimum 500 MB (edge case 8). The download size is the `--print-uris` total WITHOUT `-s` (R-865, agent v0.144.0 — with `-s` it read 0 B) |
| R9 | another apt/dpkg holds the lock, or the per-guest lane lock is held (a backup, a restore-test, C10) |
| R10 | `layer` is `guest` and the vmid is not the box's own customer guest |
| R11 | the plan names a package twice, or a version that is not a Debian version string |
@@ -289,6 +300,46 @@ os-apply: FAILED rc=<n> step=<download|install> — dpkg state: <dpkg --audit fi
`restart-needed` lists processes still mapping deleted libraries (C11); `reboot-needed` is yes when that list holds
PID 1 or `lxc-start`, or a kernel was installed.
### 5.4.2 The config bundle: a box's root-owned files by a signed job — BUILT 2026-10-04 (agent v0.143.0, hub v0.133.0, installer 1.31.0, R-840) `[FACT]`
Decision 96. Before it, the signed `agent_update` replaced only the binary; wrappers, units and sudoers lines reached
an installed box by reinstall or by hand.
- **One source of truth.** `BUNDLE_FILES` in `felhom-os-apply` is the ONE table of root-owned paths (22: sudoers ×2, the
five wrappers, the crash guard and its units + config, the agent and rollback units, the start-limit drop-in, the mgmt
watchdog and its tmpfiles/units, the OOB belt's four files). `scripts/build-config-bundle.py` builds the bundle from it
reproducibly; `release-agent.sh` publishes it beside the binary; the hub vouches its sha with the agent (exact-name
lookup); the installer (1.31.0) installs it through the same code (`--install-bundle`, root only, refused through
sudo). A test fails on a root path the installer names that the bundle lacks.
- **The route.** Signed `agent_config_update` {agent_version, bundle_sha256}. The agent is a courier; the root wrapper
re-verifies the signature against the root-owned signers file, the host binding (`os-trust.json`), the window and its
own nonce, then the sha, every path (R16) and every content check before the first write: `visudo -cf`, `sh/bash -n`,
Python compile, unit sections, no `RuntimeDirectory=` (G1), `User=felhom-agent`, `nft -c`, and that the route
survives (the sudoers keeps the `--plan` line; the new wrapper keeps the bundle mode). Policies: replace / if-absent
(`crash-guard.conf`, an operator setting) / oob (only on a box with the belt). Atomic per file, sudoers last,
previous copies kept (last 3). Self-check: `visudo -c`, `sudo -l -U felhom-agent` lists the route, the new wrapper's
`--self-check`, the self-update wrapper's usage, the crash guard's status equals `kernel.panic`; any failure puts
every previous copy back. A newly installed crash guard is started (`enable --now`): `kernel.panic` for this boot, no
reboot. Record `/etc/felhom/config-bundle.json`; the agent reports it (`system.config_bundle`, "none" when absent);
the facts mode adds drift (files changed by hand).
- **The trust root is not changed by a bundle** (R17, tested). A missing signers file is created only with the
installer's pinned key, only after a job that key signed (pinned equal to the installer by a test). Signer rotation is
a later, separate act (`04` §3).
- **Bootstrap (corrects the brief).** The self-update wrapper cannot install a bundle (fixed sh, binary-only), and no
signed job can write a root file on a box whose `felhom-os-apply` predates 0.143.0. Such a box needs ONE by-hand step
(`scripts/felhom-bundle-bootstrap.sh`: only the new `felhom-os-apply`). Done on both demo boxes; Tester 2 needs the
operator (`runbooks/config-bundle.md`).
- **Visibility.** System page "Root files" column; alarm `os_config_bundle_behind` after 7 days
(`OS_ALARM_BUNDLE_BEHIND_AFTER`; decided by CC unattended — operator may reverse).
- **Measured live** (`audits/r840-config-bundle-2026-10-04/partB/`): both demo boxes had every file equal to the release
except `felhom-os-apply`; after the bootstrap the signed bundle wrote 0 of 22 (21 same, 1 setting kept), self-check
ok, capability probe 71/71. demo-hp: a wrong-sha job refused (nothing changed); a bundle with one deliberate change
wrote exactly that file; the 0.143.0 bundle undid it; a replayed job was rejected. The installer path on demo-felhom:
0 written, services active. 22 of 22 wrapper rules red-proved.
- **Not a boundary yet — R-861.** The agent's sudoers already lets the agent user reach root without the operator key
(a hookscript, a boot unit, the escrow self-test run as root, the self-update of its own binary). The trust-root rule
is defence in depth until R-861 is closed.
### 5.5 When
Inside the household's night window, after the backups:
@@ -324,18 +375,81 @@ must never overlap a backup, a restore-test or a self-update.~~
|---|---|---|
| Guest packages | Restore the guest snapshot taken just before the update | It also undoes app data written after the snapshot. Use it only inside the health window, before apps have written much. After that, install the previous version (needs OPEN Q1). **[FACT] (C6)** Customer guests are on LVM-thin and can snapshot; scratch 9202 (`dir` storage) cannot (`snapshot feature is not available`), so the measured undo was a whole-guest backup + restore: **73 s down**, all apps healthy, libc back. The snapshot rollback itself is unmeasured (R-837). |
| Docker engine | Install the previous version (Docker's repository keeps old versions — OPEN Q2) | Every container restarts again. **[FACT] (C5)** Docker keeps 46 `docker-ce` versions. A step (either way) without `live-restore`: 6 of 6 containers restart, the app silent **26.5–30 s**, healthy at +42–45 s. With `live-restore` on: **0 restarts, no gap**, also across a containerd step. But a restart that turns `live-restore` OFF stops every container and starts NONE (`unless-stopped` ignored) — on 9202 they stayed down until restarted by hand; `systemctl reload` turns it on but not off. |
| Host packages | Install the previous version | Only if the source still has it (OPEN Q1/Q2). **[FACT]** `rsync` back to its pre-update version: `not found`; `libpng16-16t64` back to the point-release version: worked. A Debian undo needs the snapshot archive (C2). |
| Host kernel | ~~Boot the previous kernel. Proxmox can boot a new kernel **once** (`proxmox-boot-tool kernel pin <ver> --next-boot`). If that boot fails, the next boot uses the old kernel again. Make the new kernel permanent only after a healthy boot.~~ **[FACT] (C4)** Both demo hosts boot UEFI + GRUB (no proxmox-boot-tool ESPs). **Installing a kernel makes it the GRUB default at once.** `--next-boot` on GRUB writes an ordinary `GRUB_DEFAULT` + `update-grub`; `proxmox-boot-cleanup.service` clears it only once a boot reaches userspace. Measured on demo-hp (old kernel pinned permanently FIRST, new pinned for next boot): boot 1 → `7.0.14-20-pve`, healthy, 60 s; boot 2 → back on `7.0.2-6-pve`, healthy, 76 s. **So the fallback works after a boot that succeeds; read from the code, a kernel that hangs before userspace stays the default on every power cycle.** `[PROPOSAL]` use GRUB's own one-shot (`GRUB_DEFAULT=saved` + `grub-reboot`) with the old kernel as the saved default — unmeasured (R-836). | ~~If the new kernel hangs, someone must switch the box off and on. The spike checks whether a hardware watchdog can do that (OPEN Q4).~~ **[FACT]** Only `softdog` runs (loaded by `watchdog-mux`); it cannot rescue a kernel that never boots. demo-hp has an AMD FCH whose `sp5100_tco` driver ships but is not loaded; untested. A hang still needs a person. |
| Host packages | Install the previous version | Only if the source still has it (OPEN Q1/Q2). **[FACT]** `rsync` back to its pre-update version: `not found`; `libpng16-16t64` back to the point-release version: worked. A Debian undo needs the snapshot archive (C2). **[FACT, 2026-10-04]** Proved by hand: `runbooks/os-updates-host-undo.md` (demo-hp, `tzdata` back one version from `snapshot.debian.org`, held, released). Use the NEW version's `first_seen` as the timestamp when there is no previous host release; a package that pins its siblings (`eject` → `libmount1 =`) goes back only with them. |
| Host kernel | ~~Boot the previous kernel. Proxmox can boot a new kernel **once** (`proxmox-boot-tool kernel pin <ver> --next-boot`). If that boot fails, the next boot uses the old kernel again. Make the new kernel permanent only after a healthy boot.~~ **[FACT] (C4)** Both demo hosts boot UEFI + GRUB (no proxmox-boot-tool ESPs). **Installing a kernel makes it the GRUB default at once.** `--next-boot` on GRUB writes an ordinary `GRUB_DEFAULT` + `update-grub`; `proxmox-boot-cleanup.service` clears it only once a boot reaches userspace. Measured on demo-hp (old kernel pinned permanently FIRST, new pinned for next boot): boot 1 → `7.0.14-20-pve`, healthy, 60 s; boot 2 → back on `7.0.2-6-pve`, healthy, 76 s. **So the fallback works after a boot that succeeds; read from the code, a kernel that hangs before userspace stays the default on every power cycle.** ~~`[PROPOSAL]` use GRUB's own one-shot (`GRUB_DEFAULT=saved` + `grub-reboot`) with the old kernel as the saved default — unmeasured (R-836).~~ **[FACT, 2026-10-04, demo-hp, operator's word before each reboot] GRUB's one-shot is NOT a one-shot here either.** With `GRUB_DEFAULT=saved` (old 7.0.2-6 saved) and `grub-reboot` 7.0.14-20: boot 1 → 7.0.14-20, **Secure Boot ON, booted fine** (signed kernel, shim → GRUB); but `/boot` is ext4 on LVM, GRUB cannot write its environment block there (`grub-reboot` warns so itself), `next_entry` was never cleared, and boot 2 with no command → **7.0.14-20 again**. A kernel lane needs a writable env block (the ESP) or a userspace "boot good" step — R-836. demo-hp left on 7.0.14-20, saved default 7.0.14-20, both kernels installed (`audits/os-host-lane-2026-10-04/partE/`). | ~~If the new kernel hangs, someone must switch the box off and on. The spike checks whether a hardware watchdog can do that (OPEN Q4).~~ **[FACT]** Only `softdog` runs (loaded by `watchdog-mux`); it cannot rescue a kernel that never boots. demo-hp has an AMD FCH whose `sp5100_tco` driver ships but is not loaded; untested. A hang still needs a person. **[FACT, 2026-10-04]** `sp5100_tco` is blacklisted by the Proxmox kernel package; loaded by hand it answers (`SP5100 TCO timer`, 60 s, inactive, nowayout 0 — read from sysfs, never opened, so never armed; unloaded). `kernel.panic = 0`: a panic leaves the host stopped (R-851). |
### 5.7 Telling people
- **Operator:** a hub event for each update and each failure; a fleet view showing each box's OS release,
how far behind it is, and whether it needs a reboot. A box that is more than N days behind the newest
approved release raises an alarm (`08`).
- **[FACT, hub v0.132.0] The System page** (`/system`, R-852, decision 89): one row per box — ring and switch with
buttons, the tunnel, host Proxmox / running and next-boot kernel / Debian / release / pending / not covered / held /
reboot needed / `kernel.panic` / oops / crash restarts / the guard, guest Debian / release / pending / restart needed,
Docker engine / containerd / live-restore / release, the last leg — and above it the releases, what ring 0 runs, "Approve
now" and "Approve Docker set". Colours are the alarm thresholds (decision 94). Hosts shows Proxmox / kernel too.
- **Household:** one line on the timeline in both languages, informal voice: what was updated and
whether the box restarted. Telling households in advance that the box may restart at night is a
**promise to users**. That is the operator's decision when the slow lane is built.
### 5.8 The Docker engine slow lane — BUILT 2026-10-04 (agent v0.142.0, hub v0.132.0) `[FACT]`
**As built** (evidence `audits/os-docker-crash-2026-10-04/partB/`; decisions 87, 93):
- **live-restore ON**: the golden bakes it (`build-golden.sh` 3.1.0, fail-closed assertion); an installed box gets it once
by the wrapper's `live-restore-on` (merge into daemon.json + `systemctl reload docker`). Measured: the same container ids
after (9202 6/6 by hand — R10 refuses a scratch guest by design —, demo-hp 24/24, demo-felhom 5/5).
- **The step** runs in the night leg after a healthy guest and host step, **ring 0 only**, `select pending-docker`,
allowed by the wrapper only with the root-owned `ring0_slow_lane` mark. **Ring 1 and every undo** only through a signed
`os_docker_step` the wrapper re-verifies itself (decision 93). Measured: 29.7.x → 29.8.2 on both demo boxes, every id
kept; a signed undo to 29.7.2 on demo-hp (41 s, ids kept) and back; demo-felhom as ring 1 by a signed job; a replayed
job refused by the agent (nonce).
- **Approval**: the hub never approves a Docker set automatically; the System page's button works after every ring-0 box
ran the set in 2 healthy night Docker steps (`OS_DOCKER_APPROVE_NIGHTS` TEST override, logged). An approval nudges no
box. Undo: `runbooks/os-updates-docker-undo.md`.
**The design as written before the build:**
Built from C5 (measured) and R-835. **The one decision it needs is in STATUS: `live-restore` on, fleet-wide.**
- **What moves:** `docker-ce`, `docker-ce-cli`, `containerd.io`, `docker-buildx-plugin`, `docker-compose-plugin`,
`docker-ce-rootless-extras` in the customer guest — today the six "not covered" packages on every box. One
approved **engine set** at a time, like a controller floor: the operator approves it (slow lane, §5.2), after ring 0
has run it for at least 2 nights healthy. Never two steps in one night.
- **Precondition: `live-restore` ON.** Without it an engine step restarts every container — 26.5–30 s of silence,
healthy at +42–45 s (C5). With it: 0 restarts, no gap, also across a containerd step. Turning it ON is safe
(`systemctl reload docker` applies it without a restart, C5); turning it OFF later by a plain restart stops every
container and starts none (R-835) — so it is turned on once, by the golden and by a one-time fleet step, and never
turned off by the lane.
- **Who and when:** the agent, through the same wrapper (`lane: slow`, refusal R3: only inside a verified signed
operator job, R-530's mechanism), in the guest, after the guest and host fast-lane steps, under the same heavy-op
gate, on a night the operator scheduled. Debian origin rule replaced by "origin `Docker CE`, exactly these names".
- **Health:** the guest rule (§8.1) plus `docker version` reports the approved engine, and every container running
at the start is running with the SAME container id (proof that `live-restore` held). A changed id is
`health_failed` even if the app is healthy — it means the households' apps restarted when they should not have.
- **Undo:** install the previous engine set (Docker's repository keeps 46 versions, C2) — by an operator job, with
`live-restore` still on, so the undo is also restart-free.
- **Not covered here:** the golden's own engine (baked weekly; a new golden carries the approved set), and BYO hosts
(the guest is ours on both, so the lane applies there too).
### 5.9 A crashed host restarts, with a limit — BUILT 2026-10-04 (agent v0.142.0, installer 1.30.0) `[FACT]`
Decision 88 (R-851): *"Yes, but maybe not indefinitely."* Evidence `audits/os-docker-crash-2026-10-04/partC/`.
- **Measured first (demo-hp, the operator's word before each crash):** `kernel.panic = 10` + `echo c >
/proc/sysrq-trigger` → the box restarted by itself in 54 s, on the same kernel (the saved default), the agent up 18 s
after the boot. `kernel.panic` set by `sysctl -w` is gone after the restart (back to 0) — it must be set at every boot.
- **The crash signal** (decision 90): `efi_pstore` is on, yet a real panic saved NOTHING; the journal and `last` show
only "no shutdown". The guard uses a **clean-stop marker** (the unit's ExecStop at every orderly shutdown); a boot
without it followed a crash, a power cut or a hard reset — counted alike.
- **The guard** (`felhom-crash-guard`, early boot unit + hourly re-arm timer): armed → `kernel.panic = 10`; the 2nd
unclean boot within 60 minutes TRIPS it (`kernel.panic = 0`), so **the 3rd crash within the hour leaves the box off**
(decision 92 — the operator's words); re-arms after 24 h of normal running or `felhom-crash-guard rearm`. A crash before
the unit runs (very early boot) leaves the box off: the safe side. `panic_on_oops` stays 0; an oops is reported
(decision 91).
- **Telling people:** each unclean boot = an operator mail (`host_crash_restart`) + the household's line; the trip = an
alarm (`host_crash_guard_tripped`); re-arm and oops announced once (`08` §6.3). The System page shows the guard.
- **Measured live:** crash 1 → back in 54 s; crash 2 → back in 53 s, guard tripped; crash 3 → **stayed off** until the
operator switched it on; the hub mailed the trip (15 min after the boot — R-853); re-armed by hand.
---
## 6. Risks and edge cases
@@ -403,15 +517,128 @@ not covered: 79 Proxmox + 1 Tailscale on the host (slow lane / not ours), 6 Dock
Each step returns to the operator for go or no-go.
1. **Spike** (measure Q1–Q10; no product code).
2. **Guest Debian, fast lane.** Lowest risk: a snapshot undo exists.
3. **Host Debian, fast lane** (no kernel, no Proxmox packages).
4. **Fleet view and alarms** (§5.7).
5. **Slow lane: Docker engine.**
2. **Guest Debian, fast lane.** ~~Lowest risk: a snapshot undo exists.~~ **BUILT 2026-10-04** — agent v0.140.0, hub
v0.130.0, installer 1.29.0; §8.1. **There is no snapshot undo** (R-837, measured).
3. **Host Debian, fast lane** (no kernel, no Proxmox packages). **BUILT 2026-10-04** — agent v0.141.1, hub v0.131.1;
§8.2.
4. **Fleet view and alarms** (§5.7). **BUILT 2026-10-04** — hub v0.131.0/v0.131.1; §8.3.
5. **Slow lane: Docker engine.** **BUILT 2026-10-04** — agent v0.142.0, hub v0.132.0; §5.8.
**Root files to installed boxes (R-840): BUILT 2026-10-04** — agent v0.143.0, hub v0.133.0, installer 1.31.0; §5.4.2.
**Test approvals end with the test (R-859): BUILT** — hub v0.133.0; §5.3.1. **The golden carries the approved guest
release** (`build-golden.sh` 3.2.0 `GOLDEN_GUEST_PKGS`; golden 0.293.0 baked with none in force — 49 Debian updates
pending for the next real approval; the host stays with its first night's OS leg). **A host pass at install time is
not needed:** measured on Tester 2, the agent's first OS leg ran right after the box's FIRST whole-guest backup, 17 min
after enrolment (16:24/16:25 UTC: 49 guest + 106 host packages, 110 s + 44 s, healthy). An installer pass would cost
~45 s and run BEFORE any whole-guest backup exists (no undo) — not built.
6. **Slow lane: host kernel and Proxmox packages, with the reboot.**
7. **Later:** the Proxmox major upgrade (PVE 9 → 10), drilled on ring 0 first.
---
### 8.1 Step 2 as BUILT (2026-10-04) `[FACT]`
Evidence: `audits/os-guest-lane-2026-10-04/` (parts A–G). Brief: guest fast lane, decisions 78–80 (`09` §3).
- **The undo (R-837, measured first): none automatic.** PVE refuses ANY snapshot of a customer guest —
`PVE/AbstractConfig.pm:755-757` skips non-snapshot mounts only for a snapshot named `vzdump`, and every customer
guest carries the host-path binds mp8/mp9. As the agent's token and as root: `snapshot feature is not available`.
The token's role HAS `VM.Snapshot` / `VM.Snapshot.Rollback`. So §5.6's first row does not exist: a failed health
check stops, reports `health_failed`, and the hub mails the operator; the whole-guest backup taken minutes earlier
is the undo, by hand. The choice of a real undo is in STATUS (R-842).
- **The wrapper** `felhom-os-apply` (agent repo `configs/`), Python 3 stdlib, per §5.4.1 with refusals R1–R13 (R12:
the host layer; R13: dpkg still broken after the repair). **Changed from the draft** *(decided by CC unattended —
operator may reverse)*: one sudoers entry (`--plan <file>`); the plan's `mode` field (`inventory` / `apply` /
`health`) replaces a separate `--repair-only` (the repair runs first on every apply); Python, because a JSON plan
cannot be parsed safely in sh. The box's own customer guest is "the guest that binds `/mnt/felhom-drives`" (R10).
- **The leg** (agent `internal/osupdate`): after a SUCCESSFUL primary whole-guest backup, inside the backup's
goroutine before the host-wide heavy-op gate is released (so never beside a backup or a restore-test, C10), 90 s
after the backup, at most once per 20 h. *Decided by CC unattended — operator may reverse:* the 90 s settle and the
20 h gap; the controller's own self-update (04:30) is not detected — the 5-minute health wait absorbs a restart.
- **The health rule** (`HealthVerdict`, pinned): docker answers, the guest resolves `deb.debian.org`, the controller's
health check is `healthy`, and every container running at the START of the leg runs again (healthy if it was). The
baseline merges the inventory's reading with the apply's own — found live: an app stopped between them escaped the
first rule. Wait 5 min, poll 15 s.
- **Rings and the switch** (hub, per box): ring 0 = demo-hp + demo-felhom, everything else ring 1; switch ON by
default; OFF → the box reports, installs nothing. A box with no `os_update` block (older hub) = ring 1, ON, no
release.
- **The approval rule (the ruled "1–2 day wait")**: every Debian / Debian-Security package=version that ALL ring-0
boxes having it agree on; approved when, since that set was first seen, **24 h** passed with every ring-0 report
healthy and every ring-0 box completed **1** post-backup night run (`OS_APPROVE_AFTER`, `OS_APPROVE_NIGHTS`; an
override is logged as a TEST configuration). The approval time is the snapshot.debian.org timestamp (decision 79).
"Approve now" is an operator event. *The 24 h / 1 night numbers: decided by CC unattended within the ruled 1–2 days.*
- **The household's line**: hub event `os_update_applied` (info: on the household's hub timeline, never mailed;
hu/en in the bundle). There is no surface on the box itself (R-844).
- **Measured live**: ring 0 — 53 Debian packages on each demo box (18.7–31.7 s inside the wrapper; 174–226 s for the
whole leg incl. the inventory), healthy, 6 Docker updates "not covered"; approval — with a 2-minute TEST wait, a
272-package release approved automatically, then the ruled values restored; ring 1 — demo-felhom installed exactly
the 3 approved versions it lacked (269 already current) and left the newer Docker packages alone; a deliberately
stopped app → `health_failed` after 5 min, the operator mailed, the household line recorded.
- **Not delivered to existing boxes by the product**: the wrapper and the sudoers line reach a box only through the
installer; the signed agent update replaces the binary only (R-840). The demo boxes got them BY HAND.
### 8.2 Step 3 as BUILT (2026-10-04) `[FACT]`
Evidence: `audits/os-host-lane-2026-10-04/` (parts A–G).
- **Where it runs:** appliances only. The proof is the ROOT-owned install record `/var/lib/felhom-install/state.json`
`mode: appliance` (written by the installer as root); the agent-writable `agent.json` `deployment_mode` is not
trusted for this. A BYO host gets no host step (wrapper refusal **R12**, now lifted only for lane fast / layer host
on an appliance). *Decided by CC unattended — operator may reverse.*
- **What:** origin `Debian` / `Debian-Security` only, and never a kernel, boot or firmware package (name pattern
`HOST_SLOW_RE` — `linux-*`, `proxmox-kernel*`, `pve-kernel*`, `pve-firmware`, `firmware-*`, `grub*`, `shim*`,
`systemd-boot*`, `*-microcode`, `efibootmgr`; refusal **R14**). The hub leaves the same names out of the host
candidate.
- **When:** in the same leg, after the guest step, under the same heavy-op gate. A failed or unhealthy guest step
skips the host step.
- **The host health rule** (`HostHealthVerdict`, pinned in `internal/osupdate`): `felhom-agent`, `pveproxy`,
`pvedaemon`, `pvestatd` and `pve-cluster` are `active`; the customer guest runs; the guest health rule (§8.1)
passes; the tunnel is `running` — an `unknown` tunnel does not fail it, `not_running` does. Same 5-minute wait.
- **Separate approved sets:** host and guest releases are separate (`os-host-…`, `os-guest-…`), each by the same rule
(24 h, 1 night of THAT layer, every ring-0 box). Ring 1 receives `host_release` beside `release`.
- **Reboot needed:** reported when PID 1 or `lxc-start` maps a replaced file, with the date of the first scanned
report that said so. **Never reboots.** The host is scanned on every pass, so a reboot clears it (v0.141.1 — v0.141.0
hid `lxc-start` and never cleared, R-846).
- **Undo:** by hand, `runbooks/os-updates-host-undo.md` (proved). No automatic undo.
- **Speed (R-845):** one call per layer; both steps with nothing to install 23–32 s; a 108-package host pass 70 s.
- **Measured live:** demo-felhom ring 0 installed 108 Debian host packages, all Debian origin (checked against apt),
healthy; a 605-package host release approved (TEST wait 2 min / 0 nights, logged, reverted to 24 h + 1 night);
demo-felhom as ring 1 installed exactly the one version it lacked (604 already current).
### 8.3 Step 4 as BUILT (2026-10-04) `[FACT]`
- **The fleet view** (`GET /os/fleet`, operator): one line per box — ring, switch, the tunnel, and per layer: the
release, the last outcome, the last successful leg, pending, not covered, restart needed, reboot needed since, the
wrapper's own seconds.
- **The four alarms** (`08` §6.3), operator-only, hourly, at most weekly while true: no successful OS leg for
**7 days** while the switch is ON (naming the likely reason); reboot needed for **14 days**; ring 0 approved nothing
for **7 days** while it has pending fast-lane updates; not-covered fast-lane packages for **14 days**. The four
numbers are configuration (`OS_ALARM_*`). *Decided by CC unattended — operator may reverse:* 7 days = a week of
missed nights is past any normal hiccup (a box off for a weekend does not alarm); 14 days for reboot and coverage =
two weekly golden cycles, both need a person anyway.
- **The tunnel** (R-841): `running` / `not_running` / `unknown`; `tunnel_down` after two `not_running` reports.
### 8.4 The night's fixes as BUILT (2026-10-05) `[FACT]`
Agent v0.144.0 + v0.144.1 (wrapper and agent; `09` decisions 106–108). Evidence `audits/night-fixes-2026-10-05/`.
- **R8 measures the real download** (R-865): `--print-uris` without `-s`; the installed wrapper read 12 802 456 B for 13
pending guest upgrades on demo-hp (it read 0 B before). `--print-uris` alone downloads nothing (measured on 9202).
- **A killed pass still reports** (R-868): the wrapper writes `report-<run>-<layer>-apply.json` beside the plan before it
prints the report, and it survives a dead reader (a killed agent closes the stderr pipe — v0.144.0 died there,
measured); the agent sends a kept copy at start and every 5 minutes, then deletes it. Live: the A5 shape on demo-hp →
ONE `applied` report (13 packages) reached the hub 5 minutes later. A pass lock (flock) keeps the sender off a running
pass, also across the daemon and a selftest.
- **The debug pass with the hub away** (R-866): the daemon saves the hub's block (`os-update-block.json`); the selftest
uses it when the hub is unreachable and says `block=SAVED(…)` in its header. The daemon itself does not load the saved
block at start (decision 107).
- **A power cut in the middle of an update (night A1, run by day on demo-hp, decision 101):** crash at 06:13:55 UTC while
dpkg ran; the crash guard brought the host back in 37 s (1 unclean boot, still armed); every app healthy again within
4 minutes; dpkg `--audit` clean, the 13 packages split 1 new / 12 old, all `ii`. **The next pass FAILED** (`E: dpkg was
interrupted, you must manually run 'dpkg --configure -a'`): the repair step runs only on a non-clean `--audit`, and a
crash can leave only dpkg's update journal behind — **R-876 (P2, open)**. By hand: `dpkg --configure -a` in the guest
(runbook `crash-guard.md`), then the next pass installed the 12. Operator mail `os_update_failed` (true); no
household mail; the household's timeline showed "Controller elindult".
## 9. Where the rest lives
- The finding: **R-812** (`backlog/OPEN-ITEMS.md`). The intention: **R-808** (`backlog/ROADMAP.md`).
@@ -0,0 +1,63 @@
# The accidents — five lines each (household saw · box did by itself · time to steady · alarm fired, true? · alarm owed, missing?)
All times UTC. Evidence beside this file in `accidents/`.
## A2 — Docker's socket re-created during a whole-guest backup (demo-felhom, 20:16)
"Mentés most" (`POST /api/guest-backup/trigger`) at 20:16:12; the app stop began 20:16:16; `systemctl restart docker.socket`
in the guest at 20:16:23 (socket inode 151 → 646).
- **Household saw:** opengist (the one app stopped for the backup) down 20:16:16 → 20:17:50 (94 s); the dashboard briefly
unable to show app states; the timeline "Controller elindult" once. No mail.
- **Box did by itself:** the `felhom-backup` copy finished honestly (`backup: completed`, 20:16:43 — vzdump does not use
the socket). The unquiesce could not restart opengist (`exit code 1`: the controller was blind). The controller's
socket watch exited it at 20:17:33 after 60 s of refusals (R-860), Docker restarted it on the new socket, boot
reconciliation restarted opengist at 20:17:50, and the controller restarted traefik onto the new socket at 20:18:05.
The `felhom-pbs` tier answered BUSY (the agent's heavy-op gate was held) and was deferred 15 min, as designed. Then the
`night` OS leg ran (20:18–20:18:56: guest, host, Docker all "nothing").
- **Time to steady:** 102 s (20:16:23 → 20:18:05).
- **Alarms fired:** none. True: nothing stayed broken.
- **Alarms owed and missing:** none — the box healed within two minutes. (The failed restart at unquiesce left no event;
acceptable because boot reconciliation repaired it 64 s later.)
## A3 — the hub out of reach (Tester 1 box, 20:26:09 → 20:56:10, 30 min)
Blackhole route to the hub's address on the host and in the guest.
- **Household saw:** nothing (the dashboard and apps go through the tunnel, not the hub).
- **Box did by itself:** two host reports failed (22:40:49, 22:55:49 local — `hub: report failed; keeping current
interval`); the next one after the unblock arrived on time (21:10:49 UTC); the controller's report went through at
20:57:04. Missed host reports are snapshots and are not replayed — the next one replaces them. **The debug OS pass could
not run at all** (it fetches its plan from the hub — R-866); the daemon's own leg would use its saved plan, but the
20-hour gap held it back (this box's leg ran at 19:49).
- **Time to steady:** at the first report after the unblock, 14 min 39 s (the report interval).
- **Alarms fired:** none. True: 30 min is under the 45 min stale threshold.
- **Alarms owed and missing:** none. The 7-day OS alarms stayed quiet.
## A4 — the system disk nearly full (Tester 1 box guest, 20:24)
The guest's `/` filled to 400 MB free; a one-package-set plan (bind9 ×3, Debian-Security) handed to the wrapper as the
agent writes it.
- **Household saw:** nothing (the disk was freed 3 minutes later; the apps live on the data volume).
- **Box did by itself:** the wrapper refused BEFORE downloading: `REFUSED: R8 free space 419430400 B is below max(500 MB,
3 x download 0 B)`, exit 2, nothing installed (bind9 stayed at the old version). **But the download was measured as
0 B** — `apt-get -s --print-uris` prints no URIs (R-865), so only the 500 MB floor ever applies.
- **Time to steady:** immediate (a refusal changes nothing).
- **Alarms fired:** none (a refused debug plan reports nothing to the hub). True.
- **Alarms owed and missing:** none for a debug run; a NIGHT leg refused by R8 reports `refused` and the stale alarm
fires after 7 days — not exercised.
## A5 — the agent killed in the middle of a pass (demo-hp, 02:57 UTC)
Six guest packages rolled back (simulated first: 0 removals); a debug pass started; when `apt-get` ran, the pass and the
agent daemon were `kill -9`-ed (02:57:18).
- **Household saw:** nothing.
- **Box did by itself:** the root wrapper (its own process under sudo) finished all six packages; `dpkg --audit` clean;
systemd restarted the daemon in < 20 s (`NRestarts` 1; the self-update rollback did nothing — no pending update).
- **Time to steady:** < 20 s.
- **Alarms fired:** none. True.
- **Alarms owed and missing:** none — but the killed pass's report never reached the hub (R-868); no duplicate report.
## A1 — a power cut in the middle of an OS update (demo-hp) — NOT RUN
The host crash (`echo c > /proc/sysrq-trigger` while dpkg ran) was refused by this session's permission check
("interfere with workloads"). Not attempted another way. The six rolled-back packages were brought forward by a normal
debug pass (applied, healthy); dpkg clean; demo-hp's guest package list equals the 21:47 baseline. Operator decision 2.
@@ -0,0 +1,105 @@
# Morning note — the OS-update night, 2026-10-04/05
## 1. Is any box off or broken right now?
**No box of ours is off or broken.** At 05:20 local: demo-hp 21 of 21 apps healthy, demo-felhom 5 of 5, scratch box 9202
6 of 6, the new Tester 1 box 9 of 9; every crash guard armed. Nothing for you to do on them.
**Tester 2 is still offline** — since 20:06 local yesterday, before anything of tonight. I read it every 15–30 minutes; it
never came back, so I sent it nothing. Worth asking the tester whether the box is switched off.
**One test I could not do: A1 (a power cut in the middle of an update).** The crash command for demo-hp was refused by
this session's permission check. I did not look for another way. demo-hp is clean (the rolled-back packages were brought
forward again; its package list equals the evening's). Decision 2 below.
## Decisions I took myself (you may reverse each)
- **The undo test and accident A2 ran on demo-felhom in the evening, not after its night.** Its whole-guest backup runs
at ~07:45 local, after my 06:30 stop. A2's "backup now" counted as its night run (the update step ran right after it:
nothing to install), so the real approval of the fixes is not delayed.
- **A5 (the agent killed mid-update) ran on demo-hp, not demo-felhom**, inside A1's allowed rollback.
- **The new Tester 1 box stays running** (it is the returning-household box; it costs demo-hp 8 GB of memory).
## Slips of mine you should know
- **On demo-felhom I rolled back 8 packages by hand for A5, which tonight's rules did not allow — and apt removed 18
others with them, including Python and the guest's network tool.** I put every one back within a minute, before any
restart; the package list equals the evening's, line by line. From then on I simulated every downgrade first.
- **My first database query printed Tester 1's Cloudflare tokens into my own session output** (not into any file).
Tester 1 is the test customer. Decision 1 below.
- I did not pull the "USB stick" at the end of the Tester 1 install (the guide says to), so the box started the
installer again; I pulled it and it booted normally.
## 2. The prediction table, with the real times (local time)
| Box | Step | Predicted | Real | |
|---|---|---|---|---|
| all 3 | database dump | 02:30 | 02:30 (demo-hp 1 m 30 s, Tester 1 40 s, demo-felhom 1 s) | ✓ |
| all 3 | second copy | 03:30 | 03:30 (demo-felhom: no second drive, said so) | ✓ |
| all 3 | off-site | 04:15 | demo-hp 04:15–04:17 OK; demo-felhom 04:15 OK **+ an error mail (below)**; **Tester 1 skipped** | ✗ Tester 1 |
| demo-hp | whole-guest backup | ~04:35–04:40 | 04:35:24–04:40:16 | ✓ |
| demo-hp | update step (guest, host, Docker) | right after, nothing to install | 04:41:46–04:42:46, nothing in all three | ✓ |
| demo-hp | controller self-update 04:30 | no action | no action; no overlap with the update step | ✓ |
| demo-felhom | whole-guest backup + update step | ~07:50 | **moved: 22:16 / 22:18 by A2's "backup now"**, nothing to install | changed (my test) |
| Tester 1 | first backup + update step | minutes after install | 21:47 backup, 21:49 update step: **0 installed** (nothing approved) | ✓ |
| — | the 20-hour gap | skips nothing | nothing was skipped by it | ✓ |
**Surprise:** Tester 1's off-site copy waited for the household's recovery code, which I had not made (a first-hour step
I skipped). I made it at 05:07 and pressed "run now" — see 3.
## 3. Decision 78 on the fresh Tester 1 box — PROVEN (by a "run now" at 05:08, not the night run)
The box found the old off-site copy of earlier Tester 1 boxes (made with a key it does not have), moved it aside
(`…felhom-repo.orphaned-20261005`, nothing deleted), started a fresh copy and saved all 3 apps in 54 s. The household's
timeline got two lines ("orphaned", then "reset — old history kept"); you got one mail. The old copy is untouched.
## 4. The ruled undo — PROVEN on demo-felhom: 48 seconds down
Three packages rolled back, a whole-guest backup, an update pass forward, then the backup restored over the live guest:
down 22:12:54 → every app healthy 22:13:42 (48 s); the three packages back at the "before" versions; no mail; the hub kept
the box. A pass then brought them forward. There was no written way to do this — the guide is written now.
## 5. The accidents
- **A1 power cut mid-update (demo-hp): NOT RUN** — the crash was refused by the permission check (decision 2).
- **A2 Docker socket re-created during a backup (demo-felhom):** the household saw one app down 94 s, nothing else.
The box healed itself: the backup finished honestly, the controller restarted itself after 60 s, restarted the app and
the web router. Steady in 102 s. No alarm, none owed.
- **A3 the hub out of reach for 30 min (Tester 1):** the household saw nothing. Two reports failed, the next arrived on
time after the block. No alarm (right: under the 45-min limit). The debug update pass cannot run without the hub
(a gap, filed).
- **A4 the disk nearly full (Tester 1):** refused at once with a clear reason, nothing installed. But the free-space rule
measures every download as 0 bytes, so only its 500 MB floor ever works (filed).
- **A5 the agent killed mid-update (demo-hp):** the install finished anyway (the root helper runs on its own), the agent
restarted in under 20 s, packages clean. The hub never got that pass's report (filed). No duplicate.
## 6. Every mail of the night
| Mail | To | True? |
|---|---|---|
| Bind link, setup code (Tester 1 install) | household | true |
| demo-felhom "off-site clean-up refused" (error, 04:15) | you | **true fact, wrong alarm** — a defect: the clean-up's guard refuses normal 7-day retention, so every weekly clean-up will refuse and mail you (filed P2) |
| Tester 1 "off-site repository orphaned" (05:08) | you | true, expected for a returning household |
No household mail besides the two install mails.
## 7. Rows
Register before **334**, after **341**. Opened, each before I moved on:
- **P2** — a new box's first app install can fail: the box's one-time image clean-up deletes the image the install is
downloading (BookStack on Tester 1; the second press worked).
- **P2** — the off-site clean-up guard refuses normal 7-day retention and mails an error every week; nothing is pruned.
- **P3** — the update free-space rule always measures the download as 0 bytes.
- **P4** ×4 — a failed install logs the start of the error and cuts the error itself; the debug update pass needs the
hub; a killed pass's report is lost; the move-aside log line prints an empty destination.
## 8. Decisions for you
1. **Rotate Tester 1's Cloudflare tokens?** They appeared in my session output (not in a file).
- **A (my pick): rotate them** — Tester 1 is our test customer; it costs a few minutes in Cloudflare.
- **B: leave them.** If you do nothing: nothing changes; the risk is that session log.
2. **A1, the power cut mid-update — how to run it?**
- **A (my pick): allow it once** for demo-hp in this kind of night (a permission rule for the crash command on demo-hp
only), and I run it next night.
- **B: you press the crash yourself** next time while I watch.
If you do nothing: A1 stays untested; the crash guard itself was proven on 2026-10-04 by day.
@@ -0,0 +1,48 @@
# Prediction table — written 2026-10-04 ~21:45 CEST, BEFORE anything ran
All times CEST (the controller's scheduler is Europe/Budapest). Sources: each controller's "Daily job … scheduled for"
lines (`baseline/schedule-*.txt`), the agent journals of the last 7 nights, `11` §5.5 / §8.1, `07` §6.1.
## The 20-hour gap
The marker `/var/lib/felhom-agent/os/last-night-run` is written only by a `night`-trigger leg. **It does not exist on
either demo box** (both: `No such file`): every OS run today was `debug` or signed, and the hub has no `night` report from
either demo box (`os_reports`: only Tester 2's two). **Prediction: the gap skips nothing tonight on either box.** No
marker to clear on demo-felhom — §1.2's "clear the marker" step is not needed (and no documented route exists to clear
it; none was invented).
## Per box
| Box | Leg | Expected | Why |
|---|---|---|---|
| demo-hp | db-dump | 02:30 | scheduler |
| demo-hp | tier-2 copy + fill-watch | 03:30 | scheduler |
| demo-hp | metrics-prune | 04:00 | scheduler |
| demo-hp | off-site | 04:15 | scheduler |
| demo-hp | whole-guest backup (`local`) | ~04:35 → ~04:40 | last nights: 04:34:55 → 04:39:41 |
| demo-hp | OS leg guest → host → Docker (ring 0) | ~04:40 → ~04:45, right after the backup | `AfterPrimaryBackup`; no gap marker. Guest: pending Debian fixes if any appeared since today; host: same; Docker: `select pending-docker` = nothing newer than 29.8.2 expected → "nothing". The root-owned `ring0_slow_lane` mark is ON on both demo boxes (read 21:47: `os-trust.json`), so the Docker step runs unsigned and should report "nothing". |
| demo-hp | controller 04:30 self-update | no action | current 0.293.0 = floor 0.293.0 |
| demo-hp | offsite-abandon-sweep / offsite-proof / offsite-integrity | 05:10 / 05:30 / 06:00 | scheduler |
| demo-felhom | db-dump / tier-2 / off-site | 02:30 / 03:30 / 04:15 | scheduler |
| demo-felhom | whole-guest backup (`felhom-backup`) | **~07:45–07:55** — after the 06:30 stop | last 7 nights 07:37 → 07:49, drifting +2–3 min a night |
| demo-felhom | OS leg | after ~07:50 — **not watched** | follows the backup |
| Tester 1 (new box) | first whole-guest backup + OS leg | **minutes after enrolment**, not at night | Tester 2 (2026-10-04): backup 14 min after enrolment, `night`-trigger OS leg right after (49 + 106 packages) |
| Tester 1 | its first OS leg's package count | **0 guest, 0 host** — ring 1 installs only an approved release, and none is in force; it reports the pending ones (~49 guest from the golden) as "not covered" | `11` §5.3, golden 0.293.0 |
| Tester 1 | night db-dump / tier-2 / off-site | 02:30 / 03:30 (no 2nd drive → skipped) / 04:15 | scheduler |
| Tester 1 | off-site night one — decision 78 | 04:15: the orphaned old repository (earlier tester-1 boxes) is SET ASIDE, never deleted; a new repository started; one household line | decision 78 (controller v0.291.0) |
| Tester 1 | whole-guest at night | not due (the install-time one is < 24 h old) | cadence |
| Tester 1 | OS leg at night | none — the install-time leg wrote the marker < 20 h before | the gap |
| Tester 2 | anything | offline since 18:06 UTC — nothing | hub `STALE` |
## Approvals
No guest or host release is in force (today's test approvals were cancelled at 18:20 UTC). The ruled rule: 24 h since
the set was first seen AND one `night` run on EVERY ring-0 box since then. Guest set first seen 11:07 UTC, host 12:24 UTC
(if tonight's leg installs something, the set changes and the clock restarts). demo-felhom's night run comes ~07:50, so
**the earliest real approval is after ~11:07 UTC tomorrow**, only if neither box's set changes tonight. Docker: the
operator's release stays; no new set expected.
## Mails expected tonight
None to a household from the demo boxes (a normal night). Tester 1: the household line for the off-site set-aside; the
operator mail for it. Operator: `host_stale` / `node_stale` for Tester 2 already sent; nothing more unless it returns.
@@ -0,0 +1,15 @@
02:58:42
"healthy": true,
"outcome": "applied",
"healthy": true,
"outcome": "nothing",
"healthy": true,
"outcome": "nothing",
audit_rc=0
bind9-dnsutils 1:9.20.29-1~deb13u1
bind9-host 1:9.20.29-1~deb13u1
bind9-libs:amd64 1:9.20.29-1~deb13u1
libpcre2-8-0:amd64 10.46-1~deb13u3
libssh2-1t64:amd64 1.11.1-1+deb13u2
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3
demo-hp guest IDENTICAL to the 21:47 baseline
@@ -0,0 +1,7 @@
0 upgraded, 0 newly installed, 6 downgraded, 0 to remove and 0 not upgraded.
Inst libpcre2-8-0 [10.46-1~deb13u3] (10.46-1~deb13u2 Debian:13.7/stable [amd64])
Inst libxml2 [2.12.7+dfsg+really2.9.14-2.1+deb13u3] (2.12.7+dfsg+really2.9.14-2.1+deb13u1 Debian-Security:13/stable-security [amd64])
Inst bind9-host [1:9.20.29-1~deb13u1] (1:9.20.26-1~deb13u1 Debian:13.7/stable [amd64]) []
Inst bind9-dnsutils [1:9.20.29-1~deb13u1] (1:9.20.26-1~deb13u1 Debian:13.7/stable [amd64]) []
Inst bind9-libs [1:9.20.29-1~deb13u1] (1:9.20.26-1~deb13u1 Debian:13.7/stable [amd64])
Inst libssh2-1t64 [1.11.1-1+deb13u2] (1.11.1-1+deb13u1 Debian-Security:13/stable-security [amd64])
@@ -0,0 +1,6 @@
0 upgraded, 0 newly installed, 6 downgraded, 0 to remove and 0 not upgraded.
0 upgraded, 0 newly installed, 6 downgraded, 0 to remove and 0 not upgraded.
Oct 05 04:57:23 demo-hp systemd[1]: Started felhom-agent.service - Felhom host agent (Proxmox host tier; hub control loop + PBS verify + storage watchdog).
Oct 05 04:57:23 demo-hp felhom-agent[2031788]: time=2026-10-05T04:57:23.746+02:00 level=INFO msg="felhom-agent daemon starting" version=0.143.0 host_id=demo-hp-bb76ea hub_url=https://hub.felhom.eu int
Oct 05 04:57:25 demo-hp felhom-agent[2031788]: time=2026-10-05T04:57:25.550+02:00 level=INFO msg="controller-supervisor: started" interval=30s confirm_sweeps=2 crashloop_max=3 crashloop_window=15m0s s
21
@@ -0,0 +1,34 @@
cloudflared bdbd524f10b0 Up 7 minutes (healthy)
felhom-controller 6fed831a7b6b Up 3 minutes (healthy)
filebrowser 6bda22106919 Up 7 minutes (healthy)
opengist 17fc57389b52 Up 3 minutes (healthy)
traefik ddc8abb0ce45 Up 3 minutes
2026/10/04 20:16:14 [INFO] [web] manual whole-guest backup triggered (quiesce loop)
2026/10/04 20:16:14 [INFO] [quiesce] manual backup requested — quiescing now
2026/10/04 20:16:16 [INFO] [quiesce] backup due on 2 tier(s) — quiescing 1 stack(s): [opengist]
2026/10/04 20:16:16 [INFO] [stacks] Stopping stack: opengist
2026/10/04 20:16:16 [INFO] [quiesce] tier felhom-backup: backup job backup-9201-1791144976590222481 started — polling
2026/10/04 20:16:33 [WARN] [sockheal] Docker refuses the socket (dial unix /var/run/docker.sock: connect: connection refused) — exiting after 1m0s of refusals so Docker restarts this controller on the current socket (R-860)
2026/10/04 20:16:46 [INFO] [quiesce] tier felhom-backup: backup job backup-9201-1791144976590222481 done — next tier may start (app still quiesced)
2026/10/04 20:16:46 [INFO] [quiesce] tier felhom-pbs is BUSY — the agent refused the backup because a concurrent heavy operation holds it. This is contention, NOT a failure: the tier stays due and retries in 15m0s (contended for
2026/10/04 20:16:46 [INFO] [quiesce] unquiescing (last tier is busy — deferring to a later cycle): restarting 1 stack(s)
2026/10/04 20:16:46 [INFO] [stacks] Starting stack: opengist
2026/10/04 20:16:46 [ERROR] [quiesce] restart opengist: starting stack opengist: exit code 1
2026/10/04 20:17:33 [ERROR] [sockheal] Docker has refused the socket for 1m0s (dial unix /var/run/docker.sock: connect: connection refused) — the socket file was re-created and this container holds the old one; EXITING (code 75)
2026/10/04 20:17:35 [INFO] [quiesce] loop started (poll 5m0s, max-quiesce 30m0s)
2026/10/04 20:17:35 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-10-05 03:30 CEST
2026/10/04 20:17:50 [INFO] [bootrecon] boot window: fleet settled after 10s (3 identical samples 5s apart) — sweeping
2026/10/04 20:17:50 [INFO] [bootrecon] Boot reconciliation: 1 boot-orphaned app(s) found: [opengist] — up to 2 attempt(s)
2026/10/04 20:17:50 [INFO] [stacks] Starting stack: opengist
2026/10/04 20:17:50 [INFO] [bootrecon] Boot reconciliation attempt 1/2: started "opengist" (took 0.5s)
2026/10/04 20:17:50 [INFO] [bootrecon] Boot reconciliation complete: 1 app(s) recovered in 1 attempt(s): [opengist]
2026/10/04 20:18:05 [WARN] [sockheal] traefik holds an old docker socket (inode 151, current 646) — restarting it (R-860)
2026/10/04 20:18:05 [INFO] [sockheal] traefik restarted onto the current docker socket
Oct 04 22:16:43 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:16:43.062+02:00 level=INFO msg="backup: completed" vmid=9201 target=felhom-backup archive=felhom-backup:backup/vzdump-lxc-9201-202
Oct 04 22:16:43 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:16:43.062+02:00 level=INFO msg="local-api: backup job complete" vmid=9201 target=felhom-backup job=backup-9201-1791144976590222481
Oct 04 22:18:13 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:13.063+02:00 level=INFO msg="osupdate: START" run=20261004T201813Z layer=guest vmid=9201 ring=0 trigger=night enabled=true rele
Oct 04 22:18:26 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:26.519+02:00 level=INFO msg="osupdate: DONE" run=20261004T201813Z layer=guest vmid=9201 ring=0 trigger=night outcome=nothing he
Oct 04 22:18:26 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:26.609+02:00 level=INFO msg="osupdate: START" run=20261004T201813Z layer=host vmid=9201 ring=0 trigger=night enabled=true relea
Oct 04 22:18:39 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:39.682+02:00 level=INFO msg="osupdate: DONE" run=20261004T201813Z layer=host vmid=9201 ring=0 trigger=night outcome=nothing hea
Oct 04 22:18:41 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:41.341+02:00 level=INFO msg="osupdate: START" run=20261004T201813Z layer=docker vmid=9201 ring=0 trigger=night enabled=true rel
Oct 04 22:18:56 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:18:56.175+02:00 level=INFO msg="osupdate: DONE" run=20261004T201813Z layer=docker vmid=9201 ring=0 trigger=night outcome=nothing h
@@ -0,0 +1,5 @@
cloudflared bdbd524f10b0 Up 2 minutes (healthy)
felhom-controller 6fed831a7b6b Up 2 minutes (healthy)
filebrowser 6bda22106919 Up 2 minutes (healthy)
opengist 2b84350e01a3 Up 2 minutes (healthy)
traefik ddc8abb0ce45 Up 2 minutes
@@ -0,0 +1,30 @@
20:16:12
{"data":{"started":true},"ok":true}
HTTP 200
app-stop seen 20:16:17
docker.socket restarted 20:16:23 inode=646
20:16:41 controller_started=20:13:31 running=4
20:16:53 controller_started=20:13:31 running=4
20:17:04 controller_started=20:13:31 running=4
20:17:16 controller_started=20:13:31 running=4
20:17:27 controller_started=20:13:31 running=4
20:17:39 controller_started=20:17:33 running=4
20:17:51 controller_started=20:17:33 running=5
20:18:02 controller_started=20:17:33 running=5
20:18:14 controller_started=20:17:33 running=5
20:18:25 controller_started=20:17:33 running=5
20:18:37 controller_started=20:17:33 running=5
20:18:49 controller_started=20:17:33 running=5
20:19:00 controller_started=20:17:33 running=5
20:19:12 controller_started=20:17:33 running=5
20:19:23 controller_started=20:17:33 running=5
20:19:35 controller_started=20:17:33 running=5
20:19:46 controller_started=20:17:33 running=5
20:19:58 controller_started=20:17:33 running=5
20:20:09 controller_started=20:17:33 running=5
20:20:21 controller_started=20:17:33 running=5
20:20:32 controller_started=20:17:33 running=5
20:20:44 controller_started=20:17:33 running=5
20:20:55 controller_started=20:17:33 running=5
20:21:07 controller_started=20:17:33 running=5
@@ -0,0 +1,17 @@
BLOCK 20:26:09
host: 000blocked
guest: 000blocked
PASS 20:26:10
selftest=os-update: desired state: hub: transport error: Get "https://hub.felhom.eu/api/v1/hosts/tester-1-d70be4/desired-state": dial tcp 192.168.0.192:443: connect: invalid argument
PASS-END 20:26:11
tester-1-d70be4 Tester 1 0.143.0 9.2.2 7.0.2-6-pve ONLINE 1/1
Last Report 30 min ago
UNBLOCK 20:56:10
Oct 04 22:40:49 felhom felhom-agent[2492]: time=2026-10-04T22:40:49.055+02:00 level=WARN msg="hub: report failed; keeping current interval" err="hub: transport error: Post \"https://hub.felhom.eu/api/
Oct 04 22:55:49 felhom felhom-agent[2492]: time=2026-10-04T22:55:49.082+02:00 level=WARN msg="hub: report failed; keeping current interval" err="hub: transport error: Post \"https://hub.felhom.eu/api/
== 21:12:07
Last Report 1 min ago
2026/10/04 20:57:04 [INFO] [scheduler] Running job: hub-report
2026/10/04 20:57:05 [INFO] [scheduler] Job hub-report completed (took 759ms)
2026/10/04 21:12:04 [INFO] [scheduler] Running job: hub-report
2026/10/04 21:12:05 [INFO] [scheduler] Job hub-report completed (took 841ms)
@@ -0,0 +1,9 @@
20:24:20
/dev/mapper/pve-vm--9201--disk--0 32G 30G 400M 99% /
os-apply: START release=a4-diskfull layer=guest:9201 lane=fast mode=apply select=listed packages=3
os-apply: REPAIR configured=0 fixed=0
os-apply: PLAN upgrade=3 already=0 not-installed=0 from-snapshot=0
os-apply: REFUSED: R8 free space 419430400 B is below max(500 MB, 3 x download 0 B)
OSAPPLY-REPORT {"health_before": {"containers": {"bookstack": {"health": "healthy", "id": "b2c5a47cecf243d921f300f2d61b634f8fab5b9f84bf0f43b7de9255c10c174f", "state": "running"}, "bookstack-db": {"health": "healthy", "id": "7ed4dde2643bf9834b33bdb4696c22604faf045bbbba67666acdb282138b7ea3", "state":
rc=2
bind9-libs:amd64 1:9.20.23-1~deb13u1
@@ -0,0 +1,4 @@
--- as the wrapper (with -s):
0
--- without -s:
3 uris, 1471812 bytes
@@ -0,0 +1,4 @@
66a67
> iso-codes=4.18.0-1
211a213
> lsb-release=12.1-1
@@ -0,0 +1,20 @@
daemon pid before 447632
pass pid 2030197 start 02:56:59.583
KILLED at 02:57:18.480: the pass + the daemon (apt-get was running)
/root/a5.sh: line 11: 2030197 Killed nohup sudo -u felhom-agent /usr/local/bin/felhom-agent --config /etc/felhom-agent/agent.json --selftest=os-update -vmid 9201 > /root/a5-pass1.log 2>&1
dpkg running after kill: 0
1015 41981 /usr/sbin/dnsmasq -x /run/dnsmasq/dnsmasq.pid -u dnsmasq -7 /etc/dnsmasq.d,.dpkg-dist,.dpkg-old,.dpkg-new --local-service --trust-anchor=.,20326,8,2,E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D --trust-anchor=.,38696,8,2,683D2D0ACB8C9B712A1948B27F741219298D0A450D612C483AF444A4C0FB2B16
2030216 20 sudo -n /usr/local/sbin/felhom-os-apply --plan /var/lib/felhom-agent/os/plan-20261005T025659Z-guest-apply.json
2030219 20 /usr/bin/python3 /usr/local/sbin/felhom-os-apply --plan /var/lib/felhom-agent/os/plan-20261005T025659Z-guest-apply.json
2031523 2 lxc-attach -n 9201 --keep-env -- env DEBIAN_FRONTEND=noninteractive APT_LISTCHANGES_FRONTEND=none NEEDRESTART_MODE=l LC_ALL=C apt-get -y -q -o Dpkg::Options::=--force-confold -o Dpkg::Options::=--force-confdef install --only-upgrade --no-install-recommends libpcre2-8-0=10.46-1~deb13u3 libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3 bind9-host=1:9.20.29-1~deb13u1 bind9-dnsutils=1:9.20.29-1~deb13u1 bind9-libs=1:9.20.29-1~deb13u1 libssh2-1t64=1.11.1-1+deb13u2
2031555 1 apt-get -y -q -o Dpkg::Options::=--force-confold -o Dpkg::Options::=--force-confdef install --only-upgrade --no-install-recommends libpcre2-8-0=10.46-1~deb13u3 libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3 bind9-host=1:9.20.29-1~deb13u1 bind9-dnsutils=1:9.20.29-1~deb13u1 bind9-libs=1:9.20.29-1~deb13u1 libssh2-1t64=1.11.1-1+deb13u2
daemon pid after 2031788 state active restarts 1
audit rc=0
bind9-dnsutils 1:9.20.29-1~deb13u1
bind9-host 1:9.20.29-1~deb13u1
bind9-libs:amd64 1:9.20.29-1~deb13u1
libpcre2-8-0:amd64 10.46-1~deb13u3
libssh2-1t64:amd64 1.11.1-1+deb13u2
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3
=== felhom-agent 0.143.0 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
time=2026-10-05T04:56:59.730+02:00 level=INFO msg="osupdate: START" run=20261005T025659Z layer=guest vmid=9201 ring=0 trigger=debug enabled=true release=ring0-20261005T025659Z
@@ -0,0 +1,281 @@
adduser=3.152
apparmor=4.1.0-1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
bzip2=1.0.8-6
ca-certificates=20250419
containerd.io=2.3.6-1~debian.13~trixie
coreutils=9.7-3
cpio=2.15+dfsg-2
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus-user-session=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
distro-info-data=0.66+deb13u2
dmidecode=3.6-2
doc-debian=11.3+nmu1
docker-buildx-plugin=0.37.1-1~debian.13~trixie
docker-ce-cli=5:29.8.2-1~debian.13~trixie
docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie
docker-ce=5:29.8.2-1~debian.13~trixie
docker-compose-plugin=5.6.0-1~debian.13~trixie
dpkg=1.22.22
e2fsprogs=1.47.2-3+b12
fdisk=2.41.5-0+deb13u1
file=1:5.46-5
findutils=4.10.0-3
gcc-14-base=14.2.0-19
gettext-base=0.23.1-2
git-man=1:2.47.3-0+deb13u1
git=1:2.47.3-0+deb13u1
grep=3.11-4
groff-base=1.23.0-9
gzip=1.13-1+deb13u1
hostname=3.25
ifupdown2=3.0.0-1.3
ifupdown=0.8.44+deb13u1
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
iproute2=6.15.0-1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
iso-codes=4.18.0-1
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
less=668-1
libacl1=2.3.2-2+b1
libapparmor1=4.1.0-1
libapt-pkg7.0=3.0.3
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcbor0.10=0.10.2-2
libcom-err2=1.47.2-3+b12
libcrypt1=1:4.4.38-1
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdb5.3t64=5.3.28+dfsg2-9
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libedit2=3.1-20250104-1
libelf1t64=0.192-4
liberror-perl=0.17030-1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfdisk1=2.41.5-0+deb13u1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfstrm0=0.6.1-1+b3
libgcc-s1=14.2.0-19
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libgmp10=2:6.3.0+dfsg-3
libgnutls30t64=3.8.9-3+deb13u4
libgssapi-krb5-2=1.21.3-5+deb13u1
libhogweed6t64=3.10.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjson-c5=0.18+ds-1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libkmod2=34.2-2
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
liblastlog2-2=2.41.5-0+deb13u1
libldap-common=2.6.10+dfsg-1
libldap2=2.6.10+dfsg-1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblsof0=4.99.4+dfsg-2
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libncursesw6=6.5+20250216-2
libnetfilter-conntrack3=1.1.0-1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnsl2=1.3.0-3+b3
libnss-systemd=257.13-1~deb13u1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpcre2-8-0=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpopt0=1.19+dfsg-2
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libpsl5t64=0.21.2-1.1+b1
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libreadline8t64=8.2-6
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsepol2=3.8.1-1
libslang2=2.3.3-5+b2
libsmartcols1=2.41.5-0+deb13u1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstdc++6=14.2.0-19
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunistring5=1.3-2
liburcu8t64=0.15.2-2
libuuid1=2.41.5-0+deb13u1
libuv1t64=1.50.0-2
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libzstd1=1.5.7+dfsg-1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsb-release=12.1-1
lsof=4.99.4+dfsg-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netbase=6.5
netcat-traditional=1.10-50
nftables=1.1.3-1
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
patch=2.8-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl=5.40.1-6+deb13u1
pigz=2.8-1
postfix=3.10.13-0+deb13u1
procps=2:4.0.4-9
python-apt-common=3.0.0
python3-apt=3.0.0
python3-certifi=2025.1.31+ds-1
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-minimal=3.13.5-1
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-urllib3=2.3.0-3+deb13u2
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
readline-common=8.2-6
reportbug=13.2.0
runit-helper=2.16.4
sed=4.9-2+deb13u1
sensible-utils=0.0.25
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
systemd-sysv=257.13-1~deb13u1
systemd-timesyncd=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tar=1.35+dfsg-3.1
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wtmpdb=0.73.0-3+deb13u1
xz-utils=5.8.1-1+deb13u1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
@@ -0,0 +1,279 @@
adduser=3.152
apparmor=4.1.0-1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
bzip2=1.0.8-6
ca-certificates=20250419
containerd.io=2.3.6-1~debian.13~trixie
coreutils=9.7-3
cpio=2.15+dfsg-2
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus-user-session=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
distro-info-data=0.66+deb13u2
dmidecode=3.6-2
doc-debian=11.3+nmu1
docker-buildx-plugin=0.37.1-1~debian.13~trixie
docker-ce-cli=5:29.8.2-1~debian.13~trixie
docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie
docker-ce=5:29.8.2-1~debian.13~trixie
docker-compose-plugin=5.6.0-1~debian.13~trixie
dpkg=1.22.22
e2fsprogs=1.47.2-3+b12
fdisk=2.41.5-0+deb13u1
file=1:5.46-5
findutils=4.10.0-3
gcc-14-base=14.2.0-19
gettext-base=0.23.1-2
git-man=1:2.47.3-0+deb13u1
git=1:2.47.3-0+deb13u1
grep=3.11-4
groff-base=1.23.0-9
gzip=1.13-1+deb13u1
hostname=3.25
ifupdown2=3.0.0-1.3
ifupdown=0.8.44+deb13u1
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
iproute2=6.15.0-1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
less=668-1
libacl1=2.3.2-2+b1
libapparmor1=4.1.0-1
libapt-pkg7.0=3.0.3
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcbor0.10=0.10.2-2
libcom-err2=1.47.2-3+b12
libcrypt1=1:4.4.38-1
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdb5.3t64=5.3.28+dfsg2-9
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libedit2=3.1-20250104-1
libelf1t64=0.192-4
liberror-perl=0.17030-1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfdisk1=2.41.5-0+deb13u1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfstrm0=0.6.1-1+b3
libgcc-s1=14.2.0-19
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libgmp10=2:6.3.0+dfsg-3
libgnutls30t64=3.8.9-3+deb13u4
libgssapi-krb5-2=1.21.3-5+deb13u1
libhogweed6t64=3.10.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjson-c5=0.18+ds-1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libkmod2=34.2-2
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
liblastlog2-2=2.41.5-0+deb13u1
libldap-common=2.6.10+dfsg-1
libldap2=2.6.10+dfsg-1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblsof0=4.99.4+dfsg-2
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libncursesw6=6.5+20250216-2
libnetfilter-conntrack3=1.1.0-1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnsl2=1.3.0-3+b3
libnss-systemd=257.13-1~deb13u1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpcre2-8-0=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpopt0=1.19+dfsg-2
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libpsl5t64=0.21.2-1.1+b1
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libreadline8t64=8.2-6
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsepol2=3.8.1-1
libslang2=2.3.3-5+b2
libsmartcols1=2.41.5-0+deb13u1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstdc++6=14.2.0-19
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunistring5=1.3-2
liburcu8t64=0.15.2-2
libuuid1=2.41.5-0+deb13u1
libuv1t64=1.50.0-2
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libzstd1=1.5.7+dfsg-1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsof=4.99.4+dfsg-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netbase=6.5
netcat-traditional=1.10-50
nftables=1.1.3-1
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
patch=2.8-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl=5.40.1-6+deb13u1
pigz=2.8-1
postfix=3.10.13-0+deb13u1
procps=2:4.0.4-9
python-apt-common=3.0.0
python3-apt=3.0.0
python3-certifi=2025.1.31+ds-1
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-minimal=3.13.5-1
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-urllib3=2.3.0-3+deb13u2
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
readline-common=8.2-6
reportbug=13.2.0
runit-helper=2.16.4
sed=4.9-2+deb13u1
sensible-utils=0.0.25
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
systemd-sysv=257.13-1~deb13u1
systemd-timesyncd=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tar=1.35+dfsg-3.1
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wtmpdb=0.73.0-3+deb13u1
xz-utils=5.8.1-1+deb13u1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
@@ -0,0 +1,18 @@
2026-10-04 20:22:16 remove apt-listchanges:all 4.8 <none>
2026-10-04 20:22:16 remove ifupdown2:all 3.0.0-1.3 <none>
2026-10-04 20:22:16 remove reportbug:all 13.2.0 <none>
2026-10-04 20:22:16 remove python3-reportbug:all 13.2.0 <none>
2026-10-04 20:22:17 remove python3-requests:all 2.32.3+dfsg-5+deb13u1 <none>
2026-10-04 20:22:17 remove python3-debian:all 1.0.1 <none>
2026-10-04 20:22:17 remove python3-charset-normalizer:amd64 3.4.2-1 <none>
2026-10-04 20:22:17 remove python3-idna:all 3.10-1+deb13u1 <none>
2026-10-04 20:22:17 remove python3-apt:amd64 3.0.0 <none>
2026-10-04 20:22:17 remove python3-debianbts:all 4.1.1 <none>
2026-10-04 20:22:17 remove python3-certifi:all 2025.1.31+ds-1 <none>
2026-10-04 20:22:17 remove python3-chardet:all 5.2.0+dfsg-2 <none>
2026-10-04 20:22:17 remove python3-debconf:all 1.5.91 <none>
2026-10-04 20:22:17 remove python3-urllib3:all 2.3.0-3+deb13u2 <none>
2026-10-04 20:22:18 remove python3:amd64 3.13.5-1 <none>
2026-10-04 20:22:18 remove python3-minimal:amd64 3.13.5-1 <none>
2026-10-04 20:22:18 remove python3.13:amd64 3.13.5-2+deb13u5 <none>
2026-10-04 20:22:18 remove python3.13-minimal:amd64 3.13.5-2+deb13u5 <none>
@@ -0,0 +1,7 @@
20:22:46
The following packages will be upgraded:
8 upgraded, 20 newly installed, 0 to remove and 0 not upgraded.
20:22:56
280
Reading state information...
IDENTICAL to the 21:47 baseline
@@ -0,0 +1 @@
0 upgraded, 0 newly installed, 8 downgraded, 18 to remove and 0 not upgraded.
@@ -0,0 +1,3 @@
02:56:41
0 upgraded, 0 newly installed, 6 downgraded, 0 to remove and 0 not upgraded.
guard armed True in_window 0
@@ -0,0 +1,4 @@
(4616, 'demo-felhom', 'os_update_applied', 'info', 'System security fixes installed on the box (3 package(s)).', 'hub', '2026-10-04 20:12:09')
(4617, 'demo-felhom', 'controller_started', 'info', 'Controller elindult (0.293.0)', 'controller', '2026-10-04 20:13:38')
(4618, 'demo-felhom', 'os_update_applied', 'info', 'System security fixes installed on the box (3 package(s)).', 'hub', '2026-10-04 20:14:18')
(4619, 'demo-felhom', 'controller_started', 'info', 'Controller elindult (0.293.0)', 'controller', '2026-10-04 20:17:40')
@@ -0,0 +1,11 @@
('os-20261004-091417', 'guest', '2026-10-04 09:14:17', 'auto', 1, '2026-10-04 18:20:02')
('os-guest-20261004-123933', 'guest', '2026-10-04 12:39:33', 'auto', 1, '2026-10-04 18:20:02')
('os-host-20261004-124034', 'host', '2026-10-04 12:40:34', 'auto', 1, '2026-10-04 18:20:02')
('os-host-20261004-124133', 'host', '2026-10-04 12:41:33', 'auto', 1, '2026-10-04 18:20:02')
('os-docker-20261004-142842', 'docker', '2026-10-04 14:28:42', 'operator', 0, '')
('e196eb8652b9b11e', '2026-10-04 14:28:42')
('1bdef9bcf1bd39e3', '2026-10-04 14:14:57')
('777f842b71239d88', '2026-10-04 12:38:19')
('7708d5e0f37a2796', '2026-10-04 12:24:19')
('6c18a3e193e79f5b', '2026-10-04 11:07:23')
('e0c5dac127834c78', '2026-10-04 09:12:07')
@@ -0,0 +1,279 @@
adduser=3.152
apparmor=4.1.0-1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
bzip2=1.0.8-6
ca-certificates=20250419
containerd.io=2.3.6-1~debian.13~trixie
coreutils=9.7-3
cpio=2.15+dfsg-2
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus-user-session=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
distro-info-data=0.66+deb13u2
dmidecode=3.6-2
doc-debian=11.3+nmu1
docker-buildx-plugin=0.37.1-1~debian.13~trixie
docker-ce-cli=5:29.8.2-1~debian.13~trixie
docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie
docker-ce=5:29.8.2-1~debian.13~trixie
docker-compose-plugin=5.6.0-1~debian.13~trixie
dpkg=1.22.22
e2fsprogs=1.47.2-3+b12
fdisk=2.41.5-0+deb13u1
file=1:5.46-5
findutils=4.10.0-3
gcc-14-base=14.2.0-19
gettext-base=0.23.1-2
git-man=1:2.47.3-0+deb13u1
git=1:2.47.3-0+deb13u1
grep=3.11-4
groff-base=1.23.0-9
gzip=1.13-1+deb13u1
hostname=3.25
ifupdown2=3.0.0-1.3
ifupdown=0.8.44+deb13u1
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
iproute2=6.15.0-1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
less=668-1
libacl1=2.3.2-2+b1
libapparmor1=4.1.0-1
libapt-pkg7.0=3.0.3
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcbor0.10=0.10.2-2
libcom-err2=1.47.2-3+b12
libcrypt1=1:4.4.38-1
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdb5.3t64=5.3.28+dfsg2-9
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libedit2=3.1-20250104-1
libelf1t64=0.192-4
liberror-perl=0.17030-1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfdisk1=2.41.5-0+deb13u1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfstrm0=0.6.1-1+b3
libgcc-s1=14.2.0-19
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libgmp10=2:6.3.0+dfsg-3
libgnutls30t64=3.8.9-3+deb13u4
libgssapi-krb5-2=1.21.3-5+deb13u1
libhogweed6t64=3.10.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjson-c5=0.18+ds-1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libkmod2=34.2-2
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
liblastlog2-2=2.41.5-0+deb13u1
libldap-common=2.6.10+dfsg-1
libldap2=2.6.10+dfsg-1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblsof0=4.99.4+dfsg-2
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libncursesw6=6.5+20250216-2
libnetfilter-conntrack3=1.1.0-1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnsl2=1.3.0-3+b3
libnss-systemd=257.13-1~deb13u1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpcre2-8-0=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpopt0=1.19+dfsg-2
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libpsl5t64=0.21.2-1.1+b1
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libreadline8t64=8.2-6
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsepol2=3.8.1-1
libslang2=2.3.3-5+b2
libsmartcols1=2.41.5-0+deb13u1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstdc++6=14.2.0-19
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunistring5=1.3-2
liburcu8t64=0.15.2-2
libuuid1=2.41.5-0+deb13u1
libuv1t64=1.50.0-2
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libzstd1=1.5.7+dfsg-1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsof=4.99.4+dfsg-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netbase=6.5
netcat-traditional=1.10-50
nftables=1.1.3-1
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
patch=2.8-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl=5.40.1-6+deb13u1
pigz=2.8-1
postfix=3.10.13-0+deb13u1
procps=2:4.0.4-9
python-apt-common=3.0.0
python3-apt=3.0.0
python3-certifi=2025.1.31+ds-1
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-minimal=3.13.5-1
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-urllib3=2.3.0-3+deb13u2
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
readline-common=8.2-6
reportbug=13.2.0
runit-helper=2.16.4
sed=4.9-2+deb13u1
sensible-utils=0.0.25
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
systemd-sysv=257.13-1~deb13u1
systemd-timesyncd=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tar=1.35+dfsg-3.1
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wtmpdb=0.73.0-3+deb13u1
xz-utils=5.8.1-1+deb13u1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
@@ -0,0 +1,279 @@
adduser=3.152
apparmor=4.1.0-1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
bzip2=1.0.8-6
ca-certificates=20250419
containerd.io=2.3.6-1~debian.13~trixie
coreutils=9.7-3
cpio=2.15+dfsg-2
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus-user-session=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
distro-info-data=0.66+deb13u2
dmidecode=3.6-2
doc-debian=11.3+nmu1
docker-buildx-plugin=0.37.1-1~debian.13~trixie
docker-ce-cli=5:29.8.2-1~debian.13~trixie
docker-ce-rootless-extras=5:29.8.2-1~debian.13~trixie
docker-ce=5:29.8.2-1~debian.13~trixie
docker-compose-plugin=5.6.0-1~debian.13~trixie
dpkg=1.22.22
e2fsprogs=1.47.2-3+b12
fdisk=2.41.5-0+deb13u1
file=1:5.46-5
findutils=4.10.0-3
gcc-14-base=14.2.0-19
gettext-base=0.23.1-2
git-man=1:2.47.3-0+deb13u1
git=1:2.47.3-0+deb13u1
grep=3.11-4
groff-base=1.23.0-9
gzip=1.13-1+deb13u1
hostname=3.25
ifupdown2=3.0.0-1.3
ifupdown=0.8.44+deb13u1
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
iproute2=6.15.0-1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
less=668-1
libacl1=2.3.2-2+b1
libapparmor1=4.1.0-1
libapt-pkg7.0=3.0.3
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcbor0.10=0.10.2-2
libcom-err2=1.47.2-3+b12
libcrypt1=1:4.4.38-1
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdb5.3t64=5.3.28+dfsg2-9
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libedit2=3.1-20250104-1
libelf1t64=0.192-4
liberror-perl=0.17030-1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfdisk1=2.41.5-0+deb13u1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfstrm0=0.6.1-1+b3
libgcc-s1=14.2.0-19
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libgmp10=2:6.3.0+dfsg-3
libgnutls30t64=3.8.9-3+deb13u4
libgssapi-krb5-2=1.21.3-5+deb13u1
libhogweed6t64=3.10.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjson-c5=0.18+ds-1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libkmod2=34.2-2
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
liblastlog2-2=2.41.5-0+deb13u1
libldap-common=2.6.10+dfsg-1
libldap2=2.6.10+dfsg-1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblsof0=4.99.4+dfsg-2
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libncursesw6=6.5+20250216-2
libnetfilter-conntrack3=1.1.0-1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnsl2=1.3.0-3+b3
libnss-systemd=257.13-1~deb13u1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpcre2-8-0=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpopt0=1.19+dfsg-2
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libpsl5t64=0.21.2-1.1+b1
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libreadline8t64=8.2-6
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsepol2=3.8.1-1
libslang2=2.3.3-5+b2
libsmartcols1=2.41.5-0+deb13u1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstdc++6=14.2.0-19
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunistring5=1.3-2
liburcu8t64=0.15.2-2
libuuid1=2.41.5-0+deb13u1
libuv1t64=1.50.0-2
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libzstd1=1.5.7+dfsg-1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsof=4.99.4+dfsg-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netbase=6.5
netcat-traditional=1.10-50
nftables=1.1.3-1
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
patch=2.8-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl=5.40.1-6+deb13u1
pigz=2.8-1
postfix=3.10.13-0+deb13u1
procps=2:4.0.4-9
python-apt-common=3.0.0
python3-apt=3.0.0
python3-certifi=2025.1.31+ds-1
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-minimal=3.13.5-1
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-urllib3=2.3.0-3+deb13u2
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
readline-common=8.2-6
reportbug=13.2.0
runit-helper=2.16.4
sed=4.9-2+deb13u1
sensible-utils=0.0.25
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
systemd-sysv=257.13-1~deb13u1
systemd-timesyncd=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tar=1.35+dfsg-3.1
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wtmpdb=0.73.0-3+deb13u1
xz-utils=5.8.1-1+deb13u1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
@@ -0,0 +1,747 @@
adduser=3.152
age=1.2.1-1+b5
amd64-microcode=3.20250311.1
apparmor=4.1.1-pmx1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bc=1.07.1-4
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
binutils-common=2.44-3
binutils-x86-64-linux-gnu=2.44-3
binutils=2.44-3
bridge-utils=1.7.1-4+b1
bsd-mailx=8.1.2-0.20220412cvs-1.1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
btrfs-progs=6.14-1
busybox=1:1.37.0-6+b9
bzip2=1.0.8-6
ca-certificates=20250419
ceph-common=19.2.3-pve4
ceph-fuse=19.2.3-pve4
chrony=4.6.1-3+deb13u1
cifs-utils=2:7.4-1
conntrack=1:1.4.8-2
console-setup-linux=1.242~deb13u1
console-setup=1.242~deb13u1
coreutils=9.7-3
corosync=3.1.10-pve2
cpio=2.15+dfsg-2
criu=4.1.1-1
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
cstream=4.0.0-1
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
dirmngr=2.4.7-21+deb13u1+b5
distro-info-data=0.66+deb13u2
dmeventd=2:1.02.205-2+pmx1
dmidecode=3.6-2
dmsetup=2:1.02.205-2+pmx1
dns-root-data=2025080400~deb13u1
dnsmasq-base=2.91-1+deb13u2
dnsmasq=2.91-1+deb13u2
doc-debian=11.3+nmu1
dosfstools=4.2-1.2
dpkg=1.22.22
dracut-install=106-6
dtach=0.9-7
e2fsprogs=1.47.2-3+b12
ebtables=2.0.11-6
efibootmgr=18-2
eject=2.41.5-0+deb13u1
ethtool=1:6.14.2-1
faketime=0.9.10+2024-06-05+gba9ed5b2-0.6
fdisk=2.41.5-0+deb13u1
fdutils=5.6-4+b1
felhom-bootstrap=1.26.1
file=1:5.46-5
findutils=4.10.0-3
fontconfig-config=2.15.0-2.3
fontconfig=2.15.0-2.3
fonts-dejavu-core=2.37-8
fonts-dejavu-mono=2.37-8
fonts-font-awesome=5.0.10+really4.7.0~dfsg-4.1
fonts-font-logos=1.0.1-3
frr-pythontools=10.6.1-1+pve2
frr=10.6.1-1+pve2
fuse3=3.17.2-3
fuse=3.17.2-3
gcc-14-base=14.2.0-19
gdisk=1.0.10-2
genisoimage=9:1.1.11-4
gettext-base=0.23.1-2
gnupg-l10n=2.4.7-21+deb13u1
gnupg=2.4.7-21+deb13u1
gnutls-bin=3.8.9-3+deb13u4
golang-github-containers-common=0.62.2+ds1-2
golang-github-containers-image=5.34.2-1
gpg-agent=2.4.7-21+deb13u1+b5
gpg=2.4.7-21+deb13u1+b5
gpgconf=2.4.7-21+deb13u1+b5
gpgsm=2.4.7-21+deb13u1+b5
grep=3.11-4
groff-base=1.23.0-9
grub-common=2.12-9+pmx2
grub-efi-amd64-bin=2.12-9+pmx2
grub-efi-amd64-signed=1+2.12+9+pmx2
grub-efi-amd64-unsigned=2.12-9+pmx2
grub-efi-amd64=2.12-9+pmx2
grub-pc-bin=2.12-9+pmx2
grub2-common=2.12-9+pmx2
gzip=1.13-1+deb13u1
hdparm=9.65+ds-1.1
hostname=3.25
ifupdown2=3.3.0-1+pmx12
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
initramfs-tools-bin=0.148.4
initramfs-tools-core=0.148.4
initramfs-tools=0.148.4
iproute2=6.15.0-1
ipset=7.22-1+b1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
iso-codes=4.18.0-1
iucode-tool=2.3.1-3
kbd=2.7.1-2
keyboard-configuration=1.242~deb13u1
keyutils=1.6.3-6
klibc-utils=2.0.14-1
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
ksm-control-daemon=1.5-1
less=668-1
libacl1=2.3.2-2+b1
libaio1t64=0.3.113-8+b1
libanyevent-http-perl=2.25-2
libanyevent-perl=7.170-2+b7
libapparmor1=4.1.1-pmx1
libappconfig-perl=1.71-2.3
libapt-pkg-perl=0.1.42
libapt-pkg7.0=3.0.3
libarchive13t64=3.7.4-4+deb13u1
libasound2-data=1.2.14-1+deb13u1
libasound2t64=1.2.14-1+deb13u1
libassuan9=3.0.2-2
libasyncns0=0.8-6+b5
libatomic1=14.2.0-19
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libauthen-pam-perl=0.16-6+b4
libavahi-client3=0.8-16
libavahi-common-data=0.8-16
libavahi-common3=0.8-16
libbabeltrace1=1.5.11-4+b2
libbinutils=2.44-3
libblas3=3.12.1-6
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbytes-random-secure-perl=0.29-4~deb13u1
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcairo2=1.18.4-1+b1
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcares2=1.34.5-1+deb13u1
libcbor0.10=0.10.2-2
libcephfs2=19.2.3-pve4
libcfg7=3.1.10-pve2
libclass-methodmaker-perl=2.25-1
libclone-perl=0.47-1+b1
libcmap4=3.1.10-pve2
libcom-err2=1.47.2-3+b12
libcommon-sense-perl=3.75-3+b5
libcompel1=4.1.1-1
libconvert-asn1-perl=0.34-1
libcorosync-common4=3.1.10-pve2
libcpg4=3.1.10-pve2
libcrypt-openssl-bignum-perl=0.09-2+b4
libcrypt-openssl-random-perl=0.17-1+b1
libcrypt-openssl-rsa-perl=0.35-1.1
libcrypt-random-seed-perl=0.03-3
libcrypt-ssleay-perl=0.73.06-2+b4
libcrypt1=1:4.4.38-1
libcryptsetup12=2:2.7.5-2
libctf-nobfd0=2.44-3
libctf0=2.44-3
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdatrie1=0.2.13-3+b1
libdb5.3t64=5.3.28+dfsg2-9
libdbi1t64=0.9.0-6.1+b1
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libdevel-cycle-perl=1.12-2
libdevmapper-event1.02.1=2:1.02.205-2+pmx1
libdevmapper1.02.1=2:1.02.205-2+pmx1
libdigest-hmac-perl=1.05+dfsg-1
libdouble-conversion3=3.3.1-1
libdpkg-perl=1.22.22
libdrm-amdgpu1=2.4.124-2
libdrm-common=2.4.124-2
libdrm-intel1=2.4.124-2
libdrm2=2.4.124-2
libdw1t64=0.192-4
libedit2=3.1-20250104-1
libefiboot1t64=38-3.1+b1
libefivar1t64=38-3.1+b1
libelf1t64=0.192-4
libencode-locale-perl=1.05-3
libepoxy0=1.5.10-2
libevent-2.1-7t64=2.1.13-stable-1~deb13u1
libevent-core-2.1-7t64=2.1.13-stable-1~deb13u1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfaketime=0.9.10+2024-06-05+gba9ed5b2-0.6
libfdisk1=2.41.5-0+deb13u1
libfdt1=1.7.2-2+b1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfile-chdir-perl=0.1008-1.2
libfile-listing-perl=6.16-1
libfile-readbackwards-perl=1.06-2
libfilesys-df-perl=0.92-7+b4
libflac14=1.5.0+ds-2
libfontconfig1=2.15.0-2.3
libfreetype6=2.13.3+dfsg-1+deb13u1
libfribidi0=1.0.16-1
libfstrm0=0.6.1-1+b3
libfuse2t64=2.9.9-9
libfuse3-4=3.17.2-3
libgbm1=25.0.7-2+deb13u1
libgcc-s1=14.2.0-19
libgcrypt20=1.11.0-7+deb13u1
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libglib2.0-0t64=2.84.4-3~deb13u5
libgmp10=2:6.3.0+dfsg-3
libgnutls-dane0t64=3.8.9-3+deb13u4
libgnutls30t64=3.8.9-3+deb13u4
libgoogle-perftools4t64=2.16-1
libgpg-error0=1.51-4
libgpgme11t64=1.24.2-3
libgprofng0=2.44-3
libgraphite2-3=1.3.14-2+deb13u1
libgssapi-krb5-2=1.21.3-5+deb13u1
libgstreamer-plugins-base1.0-0=1.26.2-1+deb13u2
libgstreamer1.0-0=1.26.2-2
libharfbuzz0b=10.2.0-1+deb13u1
libhogweed6t64=3.10.1-1
libhtml-parser-perl=3.83-2~deb13u1
libhtml-tagset-perl=3.24-1
libhtml-tree-perl=5.07-3
libhttp-cookies-perl=6.11-1
libhttp-daemon-perl=6.16-1+deb13u1
libhttp-date-perl=6.06-1
libhttp-message-perl=7.00-2
libhttp-negotiate-perl=6.01-2
libibverbs1=56.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libinih1=59-1
libio-html-perl=1.004-3
libio-multiplex-perl=1.16-3
libio-socket-ssl-perl=2.089-1
libio-stringy-perl=2.113-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libipset13t64=7.22-1+b1
libiscsi7=1.20.0-4
libisns0t64=0.101-1+b1
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjpeg62-turbo=1:2.1.5-4
libjs-bootstrap5=5.3.5+dfsg-4
libjs-extjs=7.0.0-5
libjs-qrcodejs=1.20230525-pve1
libjson-c5=0.18+ds-1
libjson-glib-1.0-0=1.10.6+ds-2
libjson-glib-1.0-common=1.10.6+ds-2
libjson-perl=4.10000-1
libjson-xs-perl=4.040-1~deb13u1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libklibc=2.0.14-1
libkmod2=34.2-2
libknet1t64=1.31-pve1
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
libksba8=1.6.7-2+b1
liblastlog2-2=2.41.5-0+deb13u1
libldap2=2.6.10+dfsg-1
libldb2=2:2.11.0+samba4.22.11+dfsg-0+deb13u1
liblinear4=2.3.0+dfsg-5+b2
liblinux-inotify2-perl=1:2.3-2+b3
libllvm19=1:19.1.7-3+b1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblockfile1=1.17-2
liblsof0=4.99.4+dfsg-2
liblttng-ust-common1t64=2.13.9-1
liblttng-ust-ctl5t64=2.13.9-1
liblttng-ust1t64=2.13.9-1
liblua5.3-0=5.3.6-2+b4
liblua5.4-0=5.4.7-1+b2
liblvm2cmd2.03=2.03.31-2+pmx1
liblwp-mediatypes-perl=6.04-2
liblwp-protocol-https-perl=6.14-1
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
liblzo2-2=2.10-3+b1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmath-random-isaac-perl=1.004-2
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmime-base32-perl=1.303-3
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libmp3lame0=3.100-6+b3
libmpg123-0t64=1.32.10-1+deb13u1
libnbd0=1.22.2-1+b1
libncurses6=6.5+20250216-2
libncursesw6=6.5+20250216-2
libnet-dbus-perl=1.2.0-2+b3
libnet-dns-perl=1.56-0+deb13u1
libnet-http-perl=6.23-1
libnet-ip-perl=1.26-4
libnet-ldap-perl=1:0.6800+dfsg-1
libnet-ssleay-perl=1.94-3
libnet-subnet-perl=1.03-2
libnet1=1.3+dfsg-2
libnetaddr-ip-perl=4.079+dfsg-2+b5
libnetfilter-conntrack3=1.1.0-1
libnetfilter-log1=1.0.2-4+b1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnfsidmap1=1:2.8.3-1
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnl-3-200=3.7.0-2
libnl-route-3-200=3.7.0-2
libnozzle1t64=1.31-pve1
libnpth0t64=1.8-3
libnsl2=1.3.0-3+b3
libnspr4=2:4.36-1
libnss-systemd=257.13-1~deb13u1
libnss3=2:3.110-1+deb13u4
libnuma1=2.0.19-1
libnvpair3linux=2.4.2-pve1
liboath0t64=2.6.12-1
libogg0=1.3.5-3+b2
libopeniscsiusr=2.1.11-1+deb13u2
libopus0=1.5.2-2
liborc-0.4-0t64=1:0.4.41-1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpango-1.0-0=1.56.3-1
libpangocairo-1.0-0=1.56.3-1
libpangoft2-1.0-0=1.56.3-1
libpcap0.8t64=1.10.5-2
libpci3=1:3.13.0-2
libpciaccess0=0.17-3+b3
libpcre2-16-0=10.46-1~deb13u3
libpcre2-8-0=10.46-1~deb13u3
libpcre2-posix3=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpixman-1-0=0.44.0-3
libpng16-16t64=1.6.48-1+deb13u6
libpopt0=1.19+dfsg-2
libposix-strptime-perl=0.13-2+b4
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libproxmox-acme-perl=1.7.1
libproxmox-acme-plugins=1.7.1
libproxmox-backup-qemu0=2.0.2
libproxmox-rs-perl=0.4.1
libpsl5t64=0.21.2-1.1+b1
libpulse0=17.0+dfsg1-2+b1
libpve-access-control=9.1.1
libpve-apiclient-perl=3.4.2
libpve-cluster-api-perl=9.1.5
libpve-cluster-perl=9.1.5
libpve-common-perl=9.1.12
libpve-guest-common-perl=6.0.3
libpve-http-server-perl=6.0.5
libpve-network-api-perl=1.6.5
libpve-network-perl=1.6.5
libpve-notify-perl=9.1.5
libpve-rs-perl=0.15.3
libpve-storage-perl=9.1.5
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libqb-tools=2.0.8-2+b1
libqb100=2.0.8-2+b1
libqrencode4=4.1.1-2
libqt5core5t64=5.15.15+dfsg-6+deb13u1
libqt5dbus5t64=5.15.15+dfsg-6+deb13u1
libqt5network5t64=5.15.15+dfsg-6+deb13u1
libquorum5=3.1.10-pve2
librabbitmq4=0.15.0-1+deb13u2
librados2-perl=1.5.0
librados2=19.2.3-pve4
libradosstriper1=19.2.3-pve4
librbd1=19.2.3-pve4
librdkafka1=2.8.0-1
librdmacm1t64=56.1-1
libreadline8t64=8.2-6
libreiserfscore0t64=1:3.6.27-9
librgw2=19.2.3-pve4
librrd8t64=1.7.2-4.2+pve4
librrds-perl=1.7.2-4.2+pve4
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsensors-config=1:3.6.2-2
libsensors5=1:3.6.2-2
libsepol2=3.8.1-1
libsframe1=2.44-3
libslang2=2.3.3-5+b2
libslirp0=4.8.0-1+deb13u1
libsmartcols1=2.41.5-0+deb13u1
libsmbclient0=2:4.22.11+dfsg-0+deb13u1
libsnappy1v5=1.2.2-1
libsndfile1=1.2.2-2+deb13u1
libsndio7.0=1.10.0-0.1
libsocket6-perl=0.29-3+b4
libspice-server1=0.15.2-1+b1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstatgrab10t64=0.92.1-1.2
libstdc++6=14.2.0-19
libstring-shellquote-perl=1.04-3
libsubid5=1:4.17.4-2
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtalloc2=2:2.4.3+samba4.22.11+dfsg-0+deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtcmalloc-minimal4t64=2.16-1
libtdb1=2:1.4.13+samba4.22.11+dfsg-0+deb13u1
libtemplate-perl=2.27-1+b8
libterm-readline-gnu-perl=1.46-1+b3
libtevent0t64=2:0.16.2+samba4.22.11+dfsg-0+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libthai-data=0.1.29-2
libthai0=0.1.29-2+b1
libthrift-0.19.0t64=0.19.0-4+b1
libtimedate-perl=2.3300-2
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libtpms0=0.9.7+pve2
libtry-tiny-perl=0.32-1
libtypes-serialiser-perl=1.01-1
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunbound8=1.26.1-0+deb13u1
libunistring5=1.3-2
libunwind8=1.8.1-0.1
liburcu8t64=0.15.2-2
liburi-perl=5.30-1
liburing2=2.9-1
libusb-1.0-0=2:1.0.28-1
libusbredirparser1t64=0.15.0-1
libuuid-perl=0.37-1
libuuid1=2.41.5-0+deb13u1
libuutil3linux=2.4.2-pve1
libuv1t64=1.50.0-2
libva-drm2=2.22.0-3
libva2=2.22.0-3
libvirglrenderer1=1.1.0-2
libvorbis0a=1.3.7-3
libvorbisenc2=1.3.7-3
libvotequorum8=3.1.10-pve2
libvulkan1=1.4.309.0-1
libwayland-server0=1.23.1-3
libwbclient0=2:4.22.11+dfsg-0+deb13u1
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libwww-perl=6.78-1
libwww-robotrules-perl=6.02-1
libx11-6=2:1.8.12-1
libx11-data=2:1.8.12-1
libx11-xcb1=2:1.8.12-1
libxau6=1:1.0.11-1
libxcb-dri3-0=1.17.0-2+b1
libxcb-present0=1.17.0-2+b1
libxcb-randr0=1.17.0-2+b1
libxcb-render0=1.17.0-2+b1
libxcb-shm0=1.17.0-2+b1
libxcb-sync1=1.17.0-2+b1
libxcb-xfixes0=1.17.0-2+b1
libxcb1=1.17.0-2+b1
libxdmcp6=1:1.1.5-1
libxext6=2:1.3.4-1+b3
libxkbcommon0=1.7.0-2
libxml-libxml-perl=2.0207+dfsg+really+2.0134-5+deb13u1
libxml-namespacesupport-perl=1.12-2
libxml-parser-perl=2.47-2~deb13u1
libxml-sax-base-perl=1.09-3
libxml-sax-perl=1.02+dfsg-4
libxml-twig-perl=1:3.52-3
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxrender1=1:0.9.12-1
libxshmfence1=1.3.3-1
libxslt1.1=1.1.35-1.2+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libyaml-0-2=0.2.5-2
libyaml-libyaml-perl=0.903.0+ds-1
libyang3=3.12.2-1
libz3-4=4.13.3-1
libzfs7linux=2.4.2-pve1
libzpool7linux=2.4.2-pve1
libzstd1=1.5.7+dfsg-1
linux-base=4.12.1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsof=4.99.4+dfsg-2
lvm2=2.03.31-2+pmx1
lxc-pve=7.0.0-2
lxcfs=7.0.0-pve1
lzop=1.04-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
memtest86+=7.20-1
mesa-libgallium=25.0.7-2+deb13u1
mokutil=0.7.2-1
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netavark=1.14.0-2
netbase=6.5
netcat-traditional=1.10-50
nfs-common=1:2.8.3-1
nftables=1.1.3-1
nmap-common=7.95+dfsg-3
nmap=7.95+dfsg-3
node-popper2=2.11.2-8
novnc-pve=1.7.0-1
numactl=2.0.19-1
open-iscsi=2.1.11-1+deb13u2
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
pci.ids=0.0~2025.06.09-1
pciutils=1:3.13.0-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl-openssl-defaults=7+b2
perl=5.40.1-6+deb13u1
pinentry-curses=1.3.1-2
postfix=3.10.13-0+deb13u1
procmail=3.24+really3.22-4
procps=2:4.0.4-9
proxmox-archive-keyring=4.0
proxmox-backup-client=4.2.0-1
proxmox-backup-file-restore=4.2.0-1
proxmox-backup-restore-image=1.0.0
proxmox-default-kernel=2.1.0
proxmox-enterprise-support-keyring=1.0
proxmox-firewall=1.2.3
proxmox-grub=2.12-9+pmx2
proxmox-kernel-7.0.14-20-pve-signed=7.0.14-20
proxmox-kernel-7.0.2-6-pve-signed=7.0.2-6
proxmox-kernel-7.0=7.0.14-20
proxmox-kernel-helper=9.1.0+fde2
proxmox-mail-forward=1.0.3
proxmox-mini-journalreader=1.6
proxmox-offline-mirror-docs=0.7.4
proxmox-offline-mirror-helper=0.7.4
proxmox-secure-boot-support=2.0.6
proxmox-termproxy=2.1.0
proxmox-ve=9.2.0
proxmox-websocket-tunnel=1.0.0
proxmox-widget-toolkit=5.2.2
psmisc=23.7-2
pve-cluster=9.1.5
pve-container=6.1.10
pve-docs=9.2.1
pve-edk2-firmware-aarch64=4.2025.05-2
pve-edk2-firmware-legacy=4.2025.05-2
pve-edk2-firmware-ovmf=4.2025.05-2
pve-edk2-firmware=4.2025.05-2
pve-esxi-import-tools=1.0.1
pve-firewall=6.0.4
pve-firmware=3.18-3
pve-ha-manager=5.2.4
pve-i18n=3.7.4
pve-lxc-syscalld=2.0.2
pve-manager=9.2.2
pve-nvidia-vgpu-helper=0.3.1
pve-qemu-kvm=11.0.0-3
pve-xtermjs=6.0.0-1
pve-yew-mobile-gui=0.7.0
pve-yew-mobile-i18n=3.7.4
python-apt-common=3.0.0
python3-apt=3.0.0
python3-autocommand=2.2.2-3
python3-bcrypt=4.2.0-2.1+b1
python3-ceph-argparse=19.2.3-pve4
python3-ceph-common=19.2.3-pve4
python3-cephfs=19.2.3-pve4
python3-certifi=2025.1.31+ds-1
python3-cffi-backend=1.17.1-3
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-cryptography=43.0.0-3+deb13u1
python3-dbus=1.4.0-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-importlib-resources=6.5.2-1
python3-inflect=7.3.1-2
python3-jaraco.context=6.0.1-1+deb13u1
python3-jaraco.functools=4.1.0-1
python3-jaraco.text=4.0.0-1
python3-minimal=3.13.5-1
python3-more-itertools=10.7.0-1
python3-pefile=2024.8.26-2.1
python3-pkg-resources=78.1.1-0.1
python3-prettytable=3.15.1-1
python3-pyvmomi=8.0.3.0.1-1
python3-rados=19.2.3-pve4
python3-rbd=19.2.3-pve4
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-rgw=19.2.3-pve4
python3-setuptools=78.1.1-0.1
python3-six=1.17.0-1
python3-systemd=235-1+b6
python3-typeguard=4.4.2-1
python3-typing-extensions=4.13.2-1
python3-urllib3=2.3.0-3+deb13u2
python3-virt-firmware=24.11-2
python3-wcwidth=0.2.13+dfsg1-1
python3-yaml=6.0.2-1+b2
python3-zipp=3.21.0-1
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
qemu-server=9.1.15
qrencode=4.1.1-2
readline-common=8.2-6
reportbug=13.2.0
rpcbind=1.2.7-1
rrdcached=1.7.2-4.2+pve4
rsync=3.5.0+ds1-0+deb13u1
runit-helper=2.16.4
samba-common=2:4.22.11+dfsg-0+deb13u1
samba-libs=2:4.22.11+dfsg-0+deb13u1
sed=4.9-2+deb13u1
sensible-utils=0.0.25
shared-mime-info=2.4-5+b2
shim-helpers-amd64-signed=1+16.1+1+pmx1
shim-signed-common=1.48+pmx1+16.1-1+pmx1
shim-signed=1.48+pmx1+16.1-1+pmx1
shim-unsigned=16.1-1+pmx1
skopeo=1.18.0+ds1-1+b5
smartmontools=7.5-pve2
smbclient=2:4.22.11+dfsg-0+deb13u1
socat=1.8.0.3-1+deb13u1
spiceterm=3.4.2
sqlite3=3.46.1-7+deb13u2
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
strace=6.13+ds-1
sudo=1.9.16p2-3+deb13u2
swtpm-libs=0.8.0+pve3
swtpm-tools=0.8.0+pve3
swtpm=0.8.0+pve3
systemd-boot-efi=257.13-1~deb13u1
systemd-boot-tools=257.13-1~deb13u1
systemd-sysv=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tar=1.35+dfsg-3.1
tcpdump=4.99.5-2
thin-provisioning-tools=1.1.0-4+b1
time=1.9-0.2
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
uidmap=1:4.17.4-2
usbutils=1:018-2
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
virtiofsd=1.13.2-1+deb13u1
vncterm=1.9.2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wireguard-tools=1.0.20210914-3
wtmpdb=0.73.0-3+deb13u1
xfsprogs=6.13.0-2+deb13u1
xkb-data=2.42-1
xsltproc=1.1.35-1.2+deb13u3
xz-utils=5.8.1-1+deb13u1
zfs-initramfs=2.4.2-pve1
zfs-zed=2.4.2-pve1
zfsutils-linux=2.4.2-pve1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
zstd=1.5.7+dfsg-1
@@ -0,0 +1,747 @@
adduser=3.152
age=1.2.1-1+b5
apparmor=4.1.1-pmx1
apt-listchanges=4.8
apt-utils=3.0.3
apt=3.0.3
base-files=13.8+deb13u7
base-passwd=3.6.7
bash-completion=1:2.16.0-7
bash=5.2.37-2+b10
bc=1.07.1-4
bind9-dnsutils=1:9.20.29-1~deb13u1
bind9-host=1:9.20.29-1~deb13u1
bind9-libs=1:9.20.29-1~deb13u1
binutils-common=2.44-3
binutils-x86-64-linux-gnu=2.44-3
binutils=2.44-3
bridge-utils=1.7.1-4+b1
bsd-mailx=8.1.2-0.20220412cvs-1.1
bsdextrautils=2.41.5-0+deb13u1
bsdutils=1:2.41.5-0+deb13u1
btrfs-progs=6.14-1
busybox=1:1.37.0-6+b9
bzip2=1.0.8-6
ca-certificates=20250419
ceph-common=19.2.3-pve4
ceph-fuse=19.2.3-pve4
chrony=4.6.1-3+deb13u1
cifs-utils=2:7.4-1
conntrack=1:1.4.8-2
console-setup-linux=1.242~deb13u1
console-setup=1.242~deb13u1
coreutils=9.7-3
corosync=3.1.10-pve2
cpio=2.15+dfsg-2
criu=4.1.1-1
cron-daemon-common=3.0pl1-197
cron=3.0pl1-197
cstream=4.0.0-1
curl=8.14.1-2+deb13u5
dash=0.5.12-12
dbus-bin=1.16.2-2
dbus-daemon=1.16.2-2
dbus-session-bus-common=1.16.2-2
dbus-system-bus-common=1.16.2-2
dbus=1.16.2-2
debconf-i18n=1.5.91
debconf=1.5.91
debian-archive-keyring=2025.1
debian-faq=12.2
debianutils=5.23.2
dhcpcd-base=1:10.1.0-11+deb13u4
diffutils=1:3.10-4
dirmngr=2.4.7-21+deb13u1+b5
distro-info-data=0.66+deb13u2
dmeventd=2:1.02.205-2+pmx1
dmidecode=3.6-2
dmsetup=2:1.02.205-2+pmx1
dns-root-data=2025080400~deb13u1
dnsmasq-base=2.91-1+deb13u2
dnsmasq=2.91-1+deb13u2
doc-debian=11.3+nmu1
dosfstools=4.2-1.2
dpkg=1.22.22
dracut-install=106-6
dtach=0.9-7
e2fsprogs=1.47.2-3+b12
ebtables=2.0.11-6
efibootmgr=18-2
eject=2.41.5-0+deb13u1
ethtool=1:6.14.2-1
faketime=0.9.10+2024-06-05+gba9ed5b2-0.6
fdisk=2.41.5-0+deb13u1
fdutils=5.6-4+b1
file=1:5.46-5
findutils=4.10.0-3
fontconfig-config=2.15.0-2.3
fontconfig=2.15.0-2.3
fonts-dejavu-core=2.37-8
fonts-dejavu-mono=2.37-8
fonts-font-awesome=5.0.10+really4.7.0~dfsg-4.1
fonts-font-logos=1.0.1-3
frr-pythontools=10.6.1-1+pve2
frr=10.6.1-1+pve2
fuse3=3.17.2-3
fuse=3.17.2-3
gcc-14-base=14.2.0-19
gdisk=1.0.10-2
genisoimage=9:1.1.11-4
gettext-base=0.23.1-2
gnupg-l10n=2.4.7-21+deb13u1
gnupg=2.4.7-21+deb13u1
gnutls-bin=3.8.9-3+deb13u4
golang-github-containers-common=0.62.2+ds1-2
golang-github-containers-image=5.34.2-1
gpg-agent=2.4.7-21+deb13u1+b5
gpg=2.4.7-21+deb13u1+b5
gpgconf=2.4.7-21+deb13u1+b5
gpgsm=2.4.7-21+deb13u1+b5
grep=3.11-4
groff-base=1.23.0-9
grub-common=2.12-9+pmx2
grub-efi-amd64-bin=2.12-9+pmx2
grub-efi-amd64-signed=1+2.12+9+pmx2
grub-efi-amd64-unsigned=2.12-9+pmx2
grub-efi-amd64=2.12-9+pmx2
grub-pc-bin=2.12-9+pmx2
grub2-common=2.12-9+pmx2
gzip=1.13-1+deb13u1
hdparm=9.65+ds-1.1
hostname=3.25
ifupdown2=3.3.0-1+pmx12
inetutils-telnet=2:2.6-3+deb13u3
init-system-helpers=1.69~deb13u1
init=1.69~deb13u1
initramfs-tools-bin=0.148.4
initramfs-tools-core=0.148.4
initramfs-tools=0.148.4
intel-microcode=3.20251111.1~deb13u1
iproute2=6.15.0-1
ipset=7.22-1+b1
iptables=1.8.11-2
iputils-ping=3:20240905-3
isc-dhcp-client=4.4.3-P1-8
iso-codes=4.18.0-1
iucode-tool=2.3.1-3
kbd=2.7.1-2
keyboard-configuration=1.242~deb13u1
keyutils=1.6.3-6
klibc-utils=2.0.14-1
kmod=34.2-2
krb5-locales=1.21.3-5+deb13u1
ksm-control-daemon=1.5-1
less=668-1
libacl1=2.3.2-2+b1
libaio1t64=0.3.113-8+b1
libanyevent-http-perl=2.25-2
libanyevent-perl=7.170-2+b7
libapparmor1=4.1.1-pmx1
libappconfig-perl=1.71-2.3
libapt-pkg-perl=0.1.42
libapt-pkg7.0=3.0.3
libarchive13t64=3.7.4-4+deb13u1
libasound2-data=1.2.14-1+deb13u1
libasound2t64=1.2.14-1+deb13u1
libassuan9=3.0.2-2
libasyncns0=0.8-6+b5
libatomic1=14.2.0-19
libattr1=1:2.5.2-3
libaudit-common=1:4.0.2-2+deb13u1
libaudit1=1:4.0.2-2+deb13u1
libauthen-pam-perl=0.16-6+b4
libavahi-client3=0.8-16
libavahi-common-data=0.8-16
libavahi-common3=0.8-16
libbabeltrace1=1.5.11-4+b2
libbinutils=2.44-3
libblas3=3.12.1-6
libblkid1=2.41.5-0+deb13u1
libbpf1=1:1.5.0-3
libbrotli1=1.1.0-2+b7
libbsd0=0.12.2-2
libbytes-random-secure-perl=0.29-4~deb13u1
libbz2-1.0=1.0.8-6
libc-bin=2.41-12+deb13u4
libc-l10n=2.41-12+deb13u4
libc6=2.41-12+deb13u4
libcairo2=1.18.4-1+b1
libcap-ng0=0.8.5-4+b1
libcap2-bin=1:2.75-10+deb13u1+b3
libcap2=1:2.75-10+deb13u1+b3
libcares2=1.34.5-1+deb13u1
libcbor0.10=0.10.2-2
libcephfs2=19.2.3-pve4
libcfg7=3.1.10-pve2
libclass-methodmaker-perl=2.25-1
libclone-perl=0.47-1+b1
libcmap4=3.1.10-pve2
libcom-err2=1.47.2-3+b12
libcommon-sense-perl=3.75-3+b5
libcompel1=4.1.1-1
libconvert-asn1-perl=0.34-1
libcorosync-common4=3.1.10-pve2
libcpg4=3.1.10-pve2
libcrypt-openssl-bignum-perl=0.09-2+b4
libcrypt-openssl-random-perl=0.17-1+b1
libcrypt-openssl-rsa-perl=0.35-1.1
libcrypt-random-seed-perl=0.03-3
libcrypt-ssleay-perl=0.73.06-2+b4
libcrypt1=1:4.4.38-1
libcryptsetup12=2:2.7.5-2
libctf-nobfd0=2.44-3
libctf0=2.44-3
libcurl3t64-gnutls=8.14.1-2+deb13u5
libcurl4t64=8.14.1-2+deb13u5
libdatrie1=0.2.13-3+b1
libdb5.3t64=5.3.28+dfsg2-9
libdbi1t64=0.9.0-6.1+b1
libdbus-1-3=1.16.2-2
libdebconfclient0=0.280
libdevel-cycle-perl=1.12-2
libdevmapper-event1.02.1=2:1.02.205-2+pmx1
libdevmapper1.02.1=2:1.02.205-2+pmx1
libdigest-hmac-perl=1.05+dfsg-1
libdouble-conversion3=3.3.1-1
libdpkg-perl=1.22.22
libdrm-amdgpu1=2.4.124-2
libdrm-common=2.4.124-2
libdrm-intel1=2.4.124-2
libdrm2=2.4.124-2
libdw1t64=0.192-4
libedit2=3.1-20250104-1
libefiboot1t64=38-3.1+b1
libefivar1t64=38-3.1+b1
libelf1t64=0.192-4
libencode-locale-perl=1.05-3
libepoxy0=1.5.10-2
libevent-2.1-7t64=2.1.13-stable-1~deb13u1
libevent-core-2.1-7t64=2.1.13-stable-1~deb13u1
libexpat1=2.8.3-1~deb13u1
libext2fs2t64=1.47.2-3+b12
libfaketime=0.9.10+2024-06-05+gba9ed5b2-0.6
libfdisk1=2.41.5-0+deb13u1
libfdt1=1.7.2-2+b1
libffi8=3.4.8-2
libfido2-1=1.15.0-1+b1
libfile-chdir-perl=0.1008-1.2
libfile-listing-perl=6.16-1
libfile-readbackwards-perl=1.06-2
libfilesys-df-perl=0.92-7+b4
libflac14=1.5.0+ds-2
libfontconfig1=2.15.0-2.3
libfreetype6=2.13.3+dfsg-1+deb13u1
libfribidi0=1.0.16-1
libfstrm0=0.6.1-1+b3
libfuse2t64=2.9.9-9
libfuse3-4=3.17.2-3
libgbm1=25.0.7-2+deb13u1
libgcc-s1=14.2.0-19
libgcrypt20=1.11.0-7+deb13u1
libgdbm-compat4t64=1.24-2
libgdbm6t64=1.24-2
libglib2.0-0t64=2.84.4-3~deb13u5
libgmp10=2:6.3.0+dfsg-3
libgnutls-dane0t64=3.8.9-3+deb13u4
libgnutls30t64=3.8.9-3+deb13u4
libgoogle-perftools4t64=2.16-1
libgpg-error0=1.51-4
libgpgme11t64=1.24.2-3
libgprofng0=2.44-3
libgraphite2-3=1.3.14-2+deb13u1
libgssapi-krb5-2=1.21.3-5+deb13u1
libgstreamer-plugins-base1.0-0=1.26.2-1+deb13u2
libgstreamer1.0-0=1.26.2-2
libharfbuzz0b=10.2.0-1+deb13u1
libhogweed6t64=3.10.1-1
libhtml-parser-perl=3.83-2~deb13u1
libhtml-tagset-perl=3.24-1
libhtml-tree-perl=5.07-3
libhttp-cookies-perl=6.11-1
libhttp-daemon-perl=6.16-1+deb13u1
libhttp-date-perl=6.06-1
libhttp-message-perl=7.00-2
libhttp-negotiate-perl=6.01-2
libibverbs1=56.1-1
libicu76=76.1-4
libidn2-0=2.3.8-2
libinih1=59-1
libio-html-perl=1.004-3
libio-multiplex-perl=1.16-3
libio-socket-ssl-perl=2.089-1
libio-stringy-perl=2.113-2
libip4tc2=1.8.11-2
libip6tc2=1.8.11-2
libipset13t64=7.22-1+b1
libiscsi7=1.20.0-4
libisns0t64=0.101-1+b1
libjansson4=2.14-2+b3
libjemalloc2=5.3.0-3
libjpeg62-turbo=1:2.1.5-4
libjs-bootstrap5=5.3.5+dfsg-4
libjs-extjs=7.0.0-5
libjs-qrcodejs=1.20230525-pve1
libjson-c5=0.18+ds-1
libjson-glib-1.0-0=1.10.6+ds-2
libjson-glib-1.0-common=1.10.6+ds-2
libjson-perl=4.10000-1
libjson-xs-perl=4.040-1~deb13u1
libk5crypto3=1.21.3-5+deb13u1
libkeyutils1=1.6.3-6
libklibc=2.0.14-1
libkmod2=34.2-2
libknet1t64=1.31-pve1
libkrb5-3=1.21.3-5+deb13u1
libkrb5support0=1.21.3-5+deb13u1
libksba8=1.6.7-2+b1
liblastlog2-2=2.41.5-0+deb13u1
libldap2=2.6.10+dfsg-1
libldb2=2:2.11.0+samba4.22.11+dfsg-0+deb13u1
liblinear4=2.3.0+dfsg-5+b2
liblinux-inotify2-perl=1:2.3-2+b3
libllvm19=1:19.1.7-3+b1
liblmdb0=0.9.31-1+b2
liblocale-gettext-perl=1.07-7+b1
liblockfile-bin=1.17-2
liblockfile1=1.17-2
liblsof0=4.99.4+dfsg-2
liblttng-ust-common1t64=2.13.9-1
liblttng-ust-ctl5t64=2.13.9-1
liblttng-ust1t64=2.13.9-1
liblua5.3-0=5.3.6-2+b4
liblua5.4-0=5.4.7-1+b2
liblvm2cmd2.03=2.03.31-2+pmx1
liblwp-mediatypes-perl=6.04-2
liblwp-protocol-https-perl=6.14-1
liblz4-1=1.10.0-4
liblzma5=5.8.1-1+deb13u1
liblzo2-2=2.10-3+b1
libmagic-mgc=1:5.46-5
libmagic1t64=1:5.46-5
libmath-random-isaac-perl=1.004-2
libmaxminddb0=1.12.2-1
libmd0=1.1.0-2+b1
libmime-base32-perl=1.303-3
libmnl0=1.0.5-3
libmount1=2.41.5-0+deb13u1
libmp3lame0=3.100-6+b3
libmpg123-0t64=1.32.10-1+deb13u1
libnbd0=1.22.2-1+b1
libncurses6=6.5+20250216-2
libncursesw6=6.5+20250216-2
libnet-dbus-perl=1.2.0-2+b3
libnet-dns-perl=1.56-0+deb13u1
libnet-http-perl=6.23-1
libnet-ip-perl=1.26-4
libnet-ldap-perl=1:0.6800+dfsg-1
libnet-ssleay-perl=1.94-3
libnet-subnet-perl=1.03-2
libnet1=1.3+dfsg-2
libnetaddr-ip-perl=4.079+dfsg-2+b5
libnetfilter-conntrack3=1.1.0-1
libnetfilter-log1=1.0.2-4+b1
libnettle8t64=3.10.1-1
libnewt0.52=0.52.25-1
libnfnetlink0=1.0.2-3
libnfsidmap1=1:2.8.3-1
libnftables1=1.1.3-1
libnftnl11=1.2.9-1
libnghttp2-14=1.64.0-1.1+deb13u1
libnghttp3-9=1.8.0-1
libngtcp2-16=1.11.0-1+deb13u1
libngtcp2-crypto-gnutls8=1.11.0-1+deb13u1
libnl-3-200=3.7.0-2
libnl-route-3-200=3.7.0-2
libnozzle1t64=1.31-pve1
libnpth0t64=1.8-3
libnsl2=1.3.0-3+b3
libnspr4=2:4.36-1
libnss-systemd=257.13-1~deb13u1
libnss3=2:3.110-1+deb13u4
libnuma1=2.0.19-1
libnvpair3linux=2.4.2-pve1
liboath0t64=2.6.12-1
libogg0=1.3.5-3+b2
libopeniscsiusr=2.1.11-1+deb13u2
libopus0=1.5.2-2
liborc-0.4-0t64=1:0.4.41-1
libp11-kit0=0.25.5-3
libpam-modules-bin=1.7.0-5
libpam-modules=1.7.0-5
libpam-runtime=1.7.0-5
libpam-systemd=257.13-1~deb13u1
libpam-wtmpdb=0.73.0-3+deb13u1
libpam0g=1.7.0-5
libpango-1.0-0=1.56.3-1
libpangocairo-1.0-0=1.56.3-1
libpangoft2-1.0-0=1.56.3-1
libpcap0.8t64=1.10.5-2
libpci3=1:3.13.0-2
libpciaccess0=0.17-3+b3
libpcre2-16-0=10.46-1~deb13u3
libpcre2-8-0=10.46-1~deb13u3
libpcre2-posix3=10.46-1~deb13u3
libperl5.40=5.40.1-6+deb13u1
libpipeline1=1.5.8-1
libpixman-1-0=0.44.0-3
libpng16-16t64=1.6.48-1+deb13u6
libpopt0=1.19+dfsg-2
libposix-strptime-perl=0.13-2+b4
libproc2-0=2:4.0.4-9
libprotobuf-c1=1.5.1-1
libproxmox-acme-perl=1.7.1
libproxmox-acme-plugins=1.7.1
libproxmox-backup-qemu0=2.0.2
libproxmox-rs-perl=0.4.1
libpsl5t64=0.21.2-1.1+b1
libpulse0=17.0+dfsg1-2+b1
libpve-access-control=9.1.1
libpve-apiclient-perl=3.4.2
libpve-cluster-api-perl=9.1.5
libpve-cluster-perl=9.1.5
libpve-common-perl=9.1.12
libpve-guest-common-perl=6.0.3
libpve-http-server-perl=6.0.5
libpve-network-api-perl=1.6.5
libpve-network-perl=1.6.5
libpve-notify-perl=9.1.5
libpve-rs-perl=0.15.3
libpve-storage-perl=9.1.5
libpython3-stdlib=3.13.5-1
libpython3.13-minimal=3.13.5-2+deb13u5
libpython3.13-stdlib=3.13.5-2+deb13u5
libqb-tools=2.0.8-2+b1
libqb100=2.0.8-2+b1
libqrencode4=4.1.1-2
libqt5core5t64=5.15.15+dfsg-6+deb13u1
libqt5dbus5t64=5.15.15+dfsg-6+deb13u1
libqt5network5t64=5.15.15+dfsg-6+deb13u1
libquorum5=3.1.10-pve2
librabbitmq4=0.15.0-1+deb13u2
librados2-perl=1.5.0
librados2=19.2.3-pve4
libradosstriper1=19.2.3-pve4
librbd1=19.2.3-pve4
librdkafka1=2.8.0-1
librdmacm1t64=56.1-1
libreadline8t64=8.2-6
libreiserfscore0t64=1:3.6.27-9
librgw2=19.2.3-pve4
librrd8t64=1.7.2-4.2+pve4
librrds-perl=1.7.2-4.2+pve4
librtmp1=2.4+20151223.gitfa8646d.1-2+b5
libsasl2-2=2.1.28+dfsg1-9
libsasl2-modules-db=2.1.28+dfsg1-9
libseccomp2=2.6.0-2
libselinux1=3.8.1-1
libsemanage-common=3.8.1-1
libsemanage2=3.8.1-1
libsensors-config=1:3.6.2-2
libsensors5=1:3.6.2-2
libsepol2=3.8.1-1
libsframe1=2.44-3
libslang2=2.3.3-5+b2
libslirp0=4.8.0-1+deb13u1
libsmartcols1=2.41.5-0+deb13u1
libsmbclient0=2:4.22.11+dfsg-0+deb13u1
libsnappy1v5=1.2.2-1
libsndfile1=1.2.2-2+deb13u1
libsndio7.0=1.10.0-0.1
libsocket6-perl=0.29-3+b4
libspice-server1=0.15.2-1+b1
libsqlite3-0=3.46.1-7+deb13u2
libss2=1.47.2-3+b12
libssh2-1t64=1.11.1-1+deb13u2
libssl3t64=3.5.7-1~deb13u3
libstatgrab10t64=0.92.1-1.2
libstdc++6=14.2.0-19
libstring-shellquote-perl=1.04-3
libsubid5=1:4.17.4-2
libsystemd-shared=257.13-1~deb13u1
libsystemd0=257.13-1~deb13u1
libtalloc2=2:2.4.3+samba4.22.11+dfsg-0+deb13u1
libtasn1-6=4.20.0-2+deb13u1
libtcmalloc-minimal4t64=2.16-1
libtdb1=2:1.4.13+samba4.22.11+dfsg-0+deb13u1
libtemplate-perl=2.27-1+b8
libterm-readline-gnu-perl=1.46-1+b3
libtevent0t64=2:0.16.2+samba4.22.11+dfsg-0+deb13u1
libtext-charwidth-perl=0.04-11+b4
libtext-iconv-perl=1.7-8+b4
libtext-wrapi18n-perl=0.06-10
libthai-data=0.1.29-2
libthai0=0.1.29-2+b1
libthrift-0.19.0t64=0.19.0-4+b1
libtimedate-perl=2.3300-2
libtinfo6=6.5+20250216-2
libtirpc-common=1.3.6+ds-1
libtirpc3t64=1.3.6+ds-1
libtlsrpt0=0.5.0rc1-2
libtpms0=0.9.7+pve2
libtry-tiny-perl=0.32-1
libtypes-serialiser-perl=1.01-1
libuchardet0=0.0.8-1+b2
libudev1=257.13-1~deb13u1
libunbound8=1.26.1-0+deb13u1
libunistring5=1.3-2
libunwind8=1.8.1-0.1
liburcu8t64=0.15.2-2
liburi-perl=5.30-1
liburing2=2.9-1
libusb-1.0-0=2:1.0.28-1
libusbredirparser1t64=0.15.0-1
libuuid-perl=0.37-1
libuuid1=2.41.5-0+deb13u1
libuutil3linux=2.4.2-pve1
libuv1t64=1.50.0-2
libva-drm2=2.22.0-3
libva2=2.22.0-3
libvirglrenderer1=1.1.0-2
libvorbis0a=1.3.7-3
libvorbisenc2=1.3.7-3
libvotequorum8=3.1.10-pve2
libvulkan1=1.4.309.0-1
libwayland-server0=1.23.1-3
libwbclient0=2:4.22.11+dfsg-0+deb13u1
libwrap0=7.6.q-36
libwtmpdb0=0.73.0-3+deb13u1
libwww-perl=6.78-1
libwww-robotrules-perl=6.02-1
libx11-6=2:1.8.12-1
libx11-data=2:1.8.12-1
libx11-xcb1=2:1.8.12-1
libxau6=1:1.0.11-1
libxcb-dri3-0=1.17.0-2+b1
libxcb-present0=1.17.0-2+b1
libxcb-randr0=1.17.0-2+b1
libxcb-render0=1.17.0-2+b1
libxcb-shm0=1.17.0-2+b1
libxcb-sync1=1.17.0-2+b1
libxcb-xfixes0=1.17.0-2+b1
libxcb1=1.17.0-2+b1
libxdmcp6=1:1.1.5-1
libxext6=2:1.3.4-1+b3
libxkbcommon0=1.7.0-2
libxml-libxml-perl=2.0207+dfsg+really+2.0134-5+deb13u1
libxml-namespacesupport-perl=1.12-2
libxml-parser-perl=2.47-2~deb13u1
libxml-sax-base-perl=1.09-3
libxml-sax-perl=1.02+dfsg-4
libxml-twig-perl=1:3.52-3
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u3
libxrender1=1:0.9.12-1
libxshmfence1=1.3.3-1
libxslt1.1=1.1.35-1.2+deb13u3
libxtables12=1.8.11-2
libxxhash0=0.8.3-2
libyaml-0-2=0.2.5-2
libyaml-libyaml-perl=0.903.0+ds-1
libyang3=3.12.2-1
libz3-4=4.13.3-1
libzfs7linux=2.4.2-pve1
libzpool7linux=2.4.2-pve1
libzstd1=1.5.7+dfsg-1
linux-base=4.12.1
linux-sysctl-defaults=4.12.1
locales=2.41-12+deb13u4
login.defs=1:4.17.4-2
login=1:4.16.0-2+really2.41.5-0+deb13u1
logrotate=3.22.0-1
logsave=1.47.2-3+b12
lsof=4.99.4+dfsg-2
lvm2=2.03.31-2+pmx1
lxc-pve=7.0.0-2
lxcfs=7.0.0-pve1
lzop=1.04-2
man-db=2.13.1-1
manpages=6.9.1-1
mawk=1.3.4.20250131-1
media-types=13.0.0
memtest86+=7.20-1
mesa-libgallium=25.0.7-2+deb13u1
mokutil=0.7.2-1
mount=2.41.5-0+deb13u1
nano=8.4-1+deb13u1
ncurses-base=6.5+20250216-2
ncurses-bin=6.5+20250216-2
ncurses-term=6.5+20250216-2
netavark=1.14.0-2
netbase=6.5
netcat-traditional=1.10-50
nfs-common=1:2.8.3-1
nftables=1.1.3-1
nmap-common=7.95+dfsg-3
nmap=7.95+dfsg-3
node-popper2=2.11.2-8
novnc-pve=1.7.0-1
numactl=2.0.19-1
open-iscsi=2.1.11-1+deb13u2
openssh-client=1:10.0p1-7+deb13u4
openssh-server=1:10.0p1-7+deb13u4
openssh-sftp-server=1:10.0p1-7+deb13u4
openssl-provider-legacy=3.5.7-1~deb13u3
openssl=3.5.7-1~deb13u3
passwd=1:4.17.4-2
pci.ids=0.0~2025.06.09-1
pciutils=1:3.13.0-2
perl-base=5.40.1-6+deb13u1
perl-modules-5.40=5.40.1-6+deb13u1
perl-openssl-defaults=7+b2
perl=5.40.1-6+deb13u1
pinentry-curses=1.3.1-2
postfix=3.10.13-0+deb13u1
procmail=3.24+really3.22-4
procps=2:4.0.4-9
proxmox-archive-keyring=4.0
proxmox-backup-client=4.2.0-1
proxmox-backup-file-restore=4.2.0-1
proxmox-backup-restore-image=1.0.0
proxmox-default-kernel=2.1.0
proxmox-enterprise-support-keyring=1.0
proxmox-firewall=1.2.3
proxmox-first-boot=9.2.5
proxmox-grub=2.12-9+pmx2
proxmox-kernel-7.0.2-6-pve-signed=7.0.2-6
proxmox-kernel-7.0=7.0.2-6
proxmox-kernel-helper=9.1.0+fde2
proxmox-mail-forward=1.0.3
proxmox-mini-journalreader=1.6
proxmox-offline-mirror-docs=0.7.4
proxmox-offline-mirror-helper=0.7.4
proxmox-termproxy=2.1.0
proxmox-ve=9.2.0
proxmox-websocket-tunnel=1.0.0
proxmox-widget-toolkit=5.2.2
psmisc=23.7-2
pve-cluster=9.1.5
pve-container=6.1.10
pve-docs=9.2.1
pve-edk2-firmware-aarch64=4.2025.05-2
pve-edk2-firmware-legacy=4.2025.05-2
pve-edk2-firmware-ovmf=4.2025.05-2
pve-edk2-firmware=4.2025.05-2
pve-esxi-import-tools=1.0.1
pve-firewall=6.0.4
pve-firmware=3.18-3
pve-ha-manager=5.2.4
pve-i18n=3.7.4
pve-lxc-syscalld=2.0.2
pve-manager=9.2.2
pve-nvidia-vgpu-helper=0.3.1
pve-qemu-kvm=11.0.0-3
pve-xtermjs=6.0.0-1
pve-yew-mobile-gui=0.7.0
pve-yew-mobile-i18n=3.7.4
python-apt-common=3.0.0
python3-apt=3.0.0
python3-autocommand=2.2.2-3
python3-bcrypt=4.2.0-2.1+b1
python3-ceph-argparse=19.2.3-pve4
python3-ceph-common=19.2.3-pve4
python3-cephfs=19.2.3-pve4
python3-certifi=2025.1.31+ds-1
python3-cffi-backend=1.17.1-3
python3-chardet=5.2.0+dfsg-2
python3-charset-normalizer=3.4.2-1
python3-cryptography=43.0.0-3+deb13u1
python3-dbus=1.4.0-1
python3-debconf=1.5.91
python3-debian=1.0.1
python3-debianbts=4.1.1
python3-idna=3.10-1+deb13u1
python3-importlib-resources=6.5.2-1
python3-inflect=7.3.1-2
python3-jaraco.context=6.0.1-1+deb13u1
python3-jaraco.functools=4.1.0-1
python3-jaraco.text=4.0.0-1
python3-minimal=3.13.5-1
python3-more-itertools=10.7.0-1
python3-pefile=2024.8.26-2.1
python3-pkg-resources=78.1.1-0.1
python3-prettytable=3.15.1-1
python3-pyvmomi=8.0.3.0.1-1
python3-rados=19.2.3-pve4
python3-rbd=19.2.3-pve4
python3-reportbug=13.2.0
python3-requests=2.32.3+dfsg-5+deb13u1
python3-rgw=19.2.3-pve4
python3-setuptools=78.1.1-0.1
python3-six=1.17.0-1
python3-systemd=235-1+b6
python3-typeguard=4.4.2-1
python3-typing-extensions=4.13.2-1
python3-urllib3=2.3.0-3+deb13u2
python3-virt-firmware=24.11-2
python3-wcwidth=0.2.13+dfsg1-1
python3-yaml=6.0.2-1+b2
python3-zipp=3.21.0-1
python3.13-minimal=3.13.5-2+deb13u5
python3.13=3.13.5-2+deb13u5
python3=3.13.5-1
qemu-server=9.1.15
qrencode=4.1.1-2
readline-common=8.2-6
reportbug=13.2.0
rpcbind=1.2.7-1
rrdcached=1.7.2-4.2+pve4
rsync=3.5.0+ds1-0+deb13u1
runit-helper=2.16.4
samba-common=2:4.22.11+dfsg-0+deb13u1
samba-libs=2:4.22.11+dfsg-0+deb13u1
sed=4.9-2+deb13u1
sensible-utils=0.0.25
shared-mime-info=2.4-5+b2
shim-helpers-amd64-signed=1+16.1+1+pmx1
shim-signed-common=1.48+pmx1+16.1-1+pmx1
shim-signed=1.48+pmx1+16.1-1+pmx1
shim-unsigned=16.1-1+pmx1
skopeo=1.18.0+ds1-1+b5
smartmontools=7.5-pve2
smbclient=2:4.22.11+dfsg-0+deb13u1
socat=1.8.0.3-1+deb13u1
spiceterm=3.4.2
sqlite3=3.46.1-7+deb13u2
sqv=1.3.0-3+b2
ssh=1:10.0p1-7+deb13u4
strace=6.13+ds-1
sudo=1.9.16p2-3+deb13u2
swtpm-libs=0.8.0+pve3
swtpm-tools=0.8.0+pve3
swtpm=0.8.0+pve3
systemd-boot-efi=257.13-1~deb13u1
systemd-boot-tools=257.13-1~deb13u1
systemd-sysv=257.13-1~deb13u1
systemd=257.13-1~deb13u1
sysvinit-utils=3.14-4
tailscale-archive-keyring=1.35.181
tailscale=1.102.2
tar=1.35+dfsg-3.1
tcpdump=4.99.5-2
thin-provisioning-tools=1.1.0-4+b1
time=1.9-0.2
traceroute=1:2.1.6-1
tzdata=2026c-0+deb13u1
ucf=3.0052
udev=257.13-1~deb13u1
uidmap=1:4.17.4-2
usbutils=1:018-2
util-linux-extra=2.41.5-0+deb13u1
util-linux=2.41.5-0+deb13u1
vim-common=2:9.1.1230-2
vim-tiny=2:9.1.1230-2
virtiofsd=1.13.2-1+deb13u1
vncterm=1.9.2
wamerican=2020.12.07-4
wget=1.25.0-2
whiptail=0.52.25-1
wireguard-tools=1.0.20210914-3
wtmpdb=0.73.0-3+deb13u1
xfsprogs=6.13.0-2+deb13u1
xkb-data=2.42-1
xsltproc=1.1.35-1.2+deb13u3
xz-utils=5.8.1-1+deb13u1
zfs-initramfs=2.4.2-pve1
zfs-zed=2.4.2-pve1
zfsutils-linux=2.4.2-pve1
zlib1g=1:1.3.dfsg+really1.3.1-1+b1
zstd=1.5.7+dfsg-1
@@ -0,0 +1,24 @@
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job db-dump scheduled for 2026-10-05 02:30 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-10-05 03:30 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-10-05 04:15 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-10-05 05:10 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-10-05 06:00 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-10-05 05:30 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-10-05 04:00 CEST
2026/10/04 17:52:28 scheduler.go:132: [INFO] [scheduler] Daily job fill-watch scheduled for 2026-10-05 03:30 CEST
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for adventurelog → /mnt/sys_drive/felhom-data/backups/primary/adventurelog (images=3, secrets-referenced=2, data_keys=1, portable-carried=2/2, withheld=0)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for bentopdf → /mnt/sys_drive/felhom-data/backups/primary/bentopdf (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for bookstack → /mnt/sys_drive/felhom-data/backups/primary/bookstack (images=2, secrets-referenced=3, data_keys=0, portable-carried=2/2, withheld=1)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for calibre-web → /mnt/felhom-drives/hdd_1/backups/primary/calibre-web (images=1, secrets-referenced=2, data_keys=0, portable-carried=1/1, withheld=1)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for docmost → /mnt/sys_drive/felhom-data/backups/primary/docmost (images=3, secrets-referenced=2, data_keys=0, portable-carried=2/2, withheld=0)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for kimai → /mnt/sys_drive/felhom-data/backups/primary/kimai (images=2, secrets-referenced=2, data_keys=0, portable-carried=1/1, withheld=1)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for opengist → /mnt/sys_drive/felhom-data/backups/primary/opengist (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
2026/10/04 17:52:28 recovery_unit.go:289: [INFO] [backup] Recovery unit captured for privatebin → /mnt/sys_drive/felhom-data/backups/primary/privatebin (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job db-dump scheduled for 2026-10-05 02:30 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-10-05 03:30 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-10-05 04:15 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-10-05 05:10 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-10-05 06:00 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-10-05 05:30 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-10-05 04:00 CEST
2026/10/04 18:24:59 scheduler.go:132: [INFO] [scheduler] Daily job fill-watch scheduled for 2026-10-05 03:30 CEST
@@ -0,0 +1,9 @@
2026/10/04 17:52:26 [INFO] [scheduler] Daily job db-dump scheduled for 2026-10-05 02:30 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job tier2-backup scheduled for 2026-10-05 03:30 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-10-05 04:15 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job offsite-abandon-sweep scheduled for 2026-10-05 05:10 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job offsite-integrity scheduled for 2026-10-05 06:00 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job offsite-proof scheduled for 2026-10-05 05:30 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job metrics-prune scheduled for 2026-10-05 04:00 CEST
2026/10/04 17:52:26 [INFO] [scheduler] Daily job fill-watch scheduled for 2026-10-05 03:30 CEST
2026/10/04 17:52:26 [INFO] [backup] Recovery unit captured for opengist → /mnt/sys_drive/felhom-data/backups/primary/opengist (images=1, secrets-referenced=0, data_keys=0, portable-carried=0/0, withheld=0)
@@ -0,0 +1,2 @@
0.143.0 signed
guard armed True panic 10
@@ -0,0 +1,2 @@
0.143.0 installer
guard armed True panic 10
@@ -0,0 +1,254 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>System — Felhom Hub</title>
<link rel="stylesheet" href="/style.css?v=0.133.0">
<style>
.sys td, .sys th { white-space: nowrap; font-size: 0.82em; vertical-align: top; }
.sys .grp { border-left: 2px solid var(--border, #444); }
.c-warn { color: var(--warn); font-weight: 600; }
.c-bad { color: var(--danger, #e5534b); font-weight: 700; }
.sys form { display: inline; }
.rel-grid { display: grid; grid-template-columns: repeat(auto-fit, minmax(16rem, 1fr)); gap: 0.75rem; }
</style>
</head>
<body>
<svg xmlns="http://www.w3.org/2000/svg" style="display:none" aria-hidden="true">
<symbol id="i-triangle-alert" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3" /> <path d="M12 9v4" /> <path d="M12 17h.01" /></symbol>
<symbol id="i-check" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M20 6 9 17l-5-5" /></symbol>
<symbol id="i-server" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><rect width="20" height="8" x="2" y="2" rx="2" ry="2" /> <rect width="20" height="8" x="2" y="14" rx="2" ry="2" /> <line x1="6" x2="6.01" y1="6" y2="6" /> <line x1="6" x2="6.01" y1="18" y2="18" /></symbol>
<symbol id="i-settings" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M9.671 4.136a2.34 2.34 0 0 1 4.659 0 2.34 2.34 0 0 0 3.319 1.915 2.34 2.34 0 0 1 2.33 4.033 2.34 2.34 0 0 0 0 3.831 2.34 2.34 0 0 1-2.33 4.033 2.34 2.34 0 0 0-3.319 1.915 2.34 2.34 0 0 1-4.659 0 2.34 2.34 0 0 0-3.32-1.915 2.34 2.34 0 0 1-2.33-4.033 2.34 2.34 0 0 0 0-3.831A2.34 2.34 0 0 1 6.35 6.051a2.34 2.34 0 0 0 3.319-1.915" /> <circle cx="12" cy="12" r="3" /></symbol>
<symbol id="i-x" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M18 6 6 18" /> <path d="m6 6 12 12" /></symbol>
<symbol id="i-info" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10" /> <path d="M12 16v-4" /> <path d="M12 8h.01" /></symbol>
<symbol id="i-hard-drive" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M10 16h.01" /> <path d="M2.212 11.577a2 2 0 0 0-.212.896V18a2 2 0 0 0 2 2h16a2 2 0 0 0 2-2v-5.527a2 2 0 0 0-.212-.896L18.55 5.11A2 2 0 0 0 16.76 4H7.24a2 2 0 0 0-1.79 1.11z" /> <path d="M21.946 12.013H2.054" /> <path d="M6 16h.01" /></symbol>
<symbol id="i-cpu" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M12 20v2" /> <path d="M12 2v2" /> <path d="M17 20v2" /> <path d="M17 2v2" /> <path d="M2 12h2" /> <path d="M2 17h2" /> <path d="M2 7h2" /> <path d="M20 12h2" /> <path d="M20 17h2" /> <path d="M20 7h2" /> <path d="M7 20v2" /> <path d="M7 2v2" /> <rect x="4" y="4" width="16" height="16" rx="2" /> <rect x="8" y="8" width="8" height="8" rx="1" /></symbol>
<symbol id="i-clock" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><circle cx="12" cy="12" r="10" /> <path d="M12 6v6l4 2" /></symbol>
<symbol id="i-boxes" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M2.97 12.92A2 2 0 0 0 2 14.63v3.24a2 2 0 0 0 .97 1.71l3 1.8a2 2 0 0 0 2.06 0L12 19v-5.5l-5-3-4.03 2.42Z" /> <path d="m7 16.5-4.74-2.85" /> <path d="m7 16.5 5-3" /> <path d="M7 16.5v5.17" /> <path d="M12 13.5V19l3.97 2.38a2 2 0 0 0 2.06 0l3-1.8a2 2 0 0 0 .97-1.71v-3.24a2 2 0 0 0-.97-1.71L17 10.5l-5 3Z" /> <path d="m17 16.5-5-3" /> <path d="m17 16.5 4.74-2.85" /> <path d="M17 16.5v5.17" /> <path d="M7.97 4.42A2 2 0 0 0 7 6.13v4.37l5 3 5-3V6.13a2 2 0 0 0-.97-1.71l-3-1.8a2 2 0 0 0-2.06 0l-3 1.8Z" /> <path d="M12 8 7.26 5.15" /> <path d="m12 8 4.74-2.85" /> <path d="M12 13.5V8" /></symbol>
<symbol id="i-users" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M16 21v-2a4 4 0 0 0-4-4H6a4 4 0 0 0-4 4v2" /> <path d="M16 3.128a4 4 0 0 1 0 7.744" /> <path d="M22 21v-2a4 4 0 0 0-3-3.87" /> <circle cx="9" cy="7" r="4" /></symbol>
</svg>
<script>
function felhomConfirm(el,question,onYes){
if(!el||el.dataset.fcOpen)return;
el.dataset.fcOpen='1';
var wrap=document.createElement('span');wrap.className='inline-confirm';
var q=document.createElement('span');q.className='inline-confirm-q';q.textContent=question;
var yes=document.createElement('button');yes.type='button';yes.className='btn btn-sm btn-danger';yes.textContent='Igen';
var no=document.createElement('button');no.type='button';no.className='btn btn-sm btn-outline';no.textContent='Mégse';
wrap.appendChild(q);wrap.appendChild(yes);wrap.appendChild(no);
el.style.display='none';el.parentNode.insertBefore(wrap,el.nextSibling);
function close(){wrap.remove();el.style.display='';delete el.dataset.fcOpen;}
no.addEventListener('click',close);
yes.addEventListener('click',function(){close();onYes();});
}
document.addEventListener('click',function(e){
var btn=e.target.closest?e.target.closest('[data-confirm]'):null;
if(!btn)return;
e.preventDefault();
felhomConfirm(btn,btn.getAttribute('data-confirm'),function(){
var form=btn.closest('form');
if(form){if(form.requestSubmit)form.requestSubmit(btn);else form.submit();}
});
});
</script>
<div class="container">
<header>
<h1>Felhom <span>Hub</span></h1>
<nav class="nav-links">
<a href="/" class="nav-link">Dashboard</a>
<a href="/configs" class="nav-link">Customers</a>
<a href="/apps" class="nav-link">Apps</a>
<a href="/hosts" class="nav-link">Hosts</a>
<a href="/system" class="nav-link active">System</a>
<a href="/offsite" class="nav-link">Offsite</a>
<a href="/configuration" class="nav-link">Configuration</a>
</nav>
</header>
<h2 style="margin-bottom: 1rem;">System — versions and OS updates</h2>
<section class="card" style="margin-bottom: 1.5rem;">
<h3 style="margin-top: 0;">Approved releases</h3>
<div class="rel-grid">
<div><strong>docker</strong>: <code>os-docker-20261004-142842</code><br>
<span class="text-muted">6 packages · 2026-10-04 14:28 UTC · by operator</span>
</div>
</div>
<h3>Cancelled approvals (last 7 days)</h3>
<div class="rel-grid">
<div><strong>host</strong>: <code>os-host-20261004-124133</code><br>
<span class="c-warn">cancelled 2026-10-04 18:20:02 UTC — a TEST approval</span><br>
<span class="text-muted">no further box installs it; boxes that installed it keep it</span></div>
<div><strong>host</strong>: <code>os-host-20261004-124034</code><br>
<span class="c-warn">cancelled 2026-10-04 18:20:02 UTC — a TEST approval</span><br>
<span class="text-muted">no further box installs it; boxes that installed it keep it</span></div>
<div><strong>guest</strong>: <code>os-guest-20261004-123933</code><br>
<span class="c-warn">cancelled 2026-10-04 18:20:02 UTC — a TEST approval</span><br>
<span class="text-muted">no further box installs it; boxes that installed it keep it</span></div>
<div><strong>guest</strong>: <code>os-20261004-091417</code><br>
<span class="c-warn">cancelled 2026-10-04 18:20:02 UTC — a TEST approval</span><br>
<span class="text-muted">no further box installs it; boxes that installed it keep it</span></div>
</div>
<h3>What ring 0 runs now</h3>
<div class="rel-grid">
<div><strong>guest</strong>:
272 packages, first seen 2026-10-04 11:07 UTC<br>
<span class="text-muted">healthy for 8h17m0s of 24h0m0s</span>
</div>
<div><strong>host</strong>:
607 packages, first seen 2026-10-04 12:24 UTC<br>
<span class="text-muted">healthy for 7h0m0s of 24h0m0s</span>
</div>
<div><strong>docker</strong>:
6 packages, first seen 2026-10-04 14:28 UTC<br>
<span class="text-muted">approved as os-docker-20261004-142842</span>
</div>
</div>
<form method="POST" action="/os/approve-now" style="margin-top: 0.8rem;">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<button type="submit" class="btn btn-sm btn-danger" data-confirm="Approve the guest and host sets ring 0 runs NOW, without the 24 h + 1 night wait? Every ring-1 box installs them at its next night run.">Approve now (guest + host)</button>
<span class="text-muted" style="font-size: 0.85em;">An urgent fix only — normally the hub approves after 24 h and one night.</span>
</form>
</section>
<section class="card" style="padding: 0; overflow-x: auto;">
<table class="data-table sys">
<thead>
<tr>
<th>Box</th><th>Ring / updates</th><th>Tunnel</th>
<th class="grp">Proxmox</th><th>Kernel (running)</th><th>Kernel (next boot)</th><th>Debian</th><th>Felhom release</th><th>Pending</th><th>Not covered</th><th>Held</th><th>Reboot needed</th><th>kernel.panic</th><th>Oops</th><th>Crash restarts 24 h</th><th>Crash guard</th><th title="The root-owned config bundle: sudoers, wrappers, units (R-840)">Root files</th>
<th class="grp">Guest Debian</th><th>Felhom release</th><th>Pending</th><th>Restart needed</th>
<th class="grp">Docker</th><th>containerd</th><th>live-restore</th><th>Docker release</th>
<th class="grp">Last OS leg</th>
</tr>
<tr class="text-muted"><th></th><th></th><th></th><th class="grp" colspan="14">host</th><th class="grp" colspan="4">guest</th><th class="grp" colspan="4">Docker engine</th><th class="grp"></th></tr>
</thead>
<tbody>
<tr>
<td><a href="/hosts/Tester-2-be8404">Tester-2-be8404</a><br><span class="text-muted">Tester 2</span>
</td>
<td>
ring 1
<form method="POST" action="/os/ring/Tester-2-be8404">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="ring" value="0"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Make Tester-2-be8404 a DEMO (ring 0) box? It then installs every new fix first and takes unsigned Docker steps if its root-owned ring-0 mark allows.">→ demo</button>
</form><br>
updates <strong>ON</strong>
<form method="POST" action="/os/enabled/Tester-2-be8404">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="on" value="0"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Switch OS updates OFF for Tester-2-be8404? It keeps reporting and installs nothing.">switch off</button>
</form>
</td>
<td>running</td>
<td class="grp ">9.2.2</td>
<td>7.0.2-6-pve</td><td>7.0.2-6-pve</td><td>13.7</td>
<td>os-host-20261004-124133</td><td>78</td><td>0</td>
<td>none</td><td class="c-warn">since 2026-10-04</td><td>10 s</td><td>no</td>
<td>0</td><td>armed</td><td class="c-warn" title="the box could not read it (agent older than v0.142.0, or the guest is down)">unknown</td>
<td class="grp ">13.7</td>
<td>os-guest-20261004-123933</td><td>0</td><td>7</td>
<td class="grp ">29.8.2</td>
<td>2.3.6-1~debian.13~trixie</td><td>on</td><td>—</td>
<td class="grp " title="last successful leg: 2 h ago">2 h ago · applied · 44 s</td>
</tr>
<tr>
<td><a href="/hosts/demo-felhom-8363b5">demo-felhom-8363b5</a><br><span class="text-muted">Demo Ügyfél</span>
</td>
<td>
ring 0
<form method="POST" action="/os/ring/demo-felhom-8363b5">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="ring" value="1"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Make demo-felhom-8363b5 a normal (ring 1) box? It then installs only approved releases.">→ normal</button>
</form><br>
updates <strong>ON</strong>
<form method="POST" action="/os/enabled/demo-felhom-8363b5">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="on" value="0"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Switch OS updates OFF for demo-felhom-8363b5? It keeps reporting and installs nothing.">switch off</button>
</form>
</td>
<td>running</td>
<td class="grp ">9.2.2</td>
<td>7.0.2-6-pve</td><td>7.0.2-6-pve</td><td>13.7</td>
<td>os-host-20261004-124133</td><td>80</td><td>0</td>
<td>none</td><td class="c-warn">since 2026-10-04</td><td>10 s</td><td>no</td>
<td>0</td><td>armed</td><td>0.143.0</td>
<td class="grp ">13.7</td>
<td>os-guest-20261004-123933</td><td>0</td><td>10</td>
<td class="grp ">29.8.2</td>
<td>2.3.6-1~debian.13~trixie</td><td>on</td><td>os-docker-20261004-142842</td>
<td class="grp " title="last successful leg: 4 h ago">4 h ago · nothing · 12 s</td>
</tr>
<tr>
<td><a href="/hosts/demo-hp-bb76ea">demo-hp-bb76ea</a><br><span class="text-muted">Demo HP</span>
</td>
<td>
ring 0
<form method="POST" action="/os/ring/demo-hp-bb76ea">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="ring" value="1"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Make demo-hp-bb76ea a normal (ring 1) box? It then installs only approved releases.">→ normal</button>
</form><br>
updates <strong>ON</strong>
<form method="POST" action="/os/enabled/demo-hp-bb76ea">
<input type="hidden" name="_csrf" value=""><input type="hidden" name="return" value="/system">
<input type="hidden" name="on" value="0"><button type="submit" class="btn btn-sm btn-outline" data-confirm="Switch OS updates OFF for demo-hp-bb76ea? It keeps reporting and installs nothing.">switch off</button>
</form>
</td>
<td>running</td>
<td class="grp ">9.2.2</td>
<td>7.0.14-20-pve</td><td>7.0.14-20-pve</td><td>13.7</td>
<td>ring0-20261004T144238Z</td><td>78</td><td>0</td>
<td>none</td><td>no</td><td>10 s</td><td>no</td>
<td class="c-warn">3</td><td>armed</td><td>0.143.0</td>
<td class="grp ">13.7</td>
<td>ring0-20261004T144238Z</td><td>6</td><td>1</td>
<td class="grp ">29.8.2</td>
<td>2.3.6-1~debian.13~trixie</td><td>on</td><td>r858-proof-forward</td>
<td class="grp " title="last successful leg: 4 h ago">2 h ago · applied · 69 s</td>
</tr>
</tbody>
</table>
</section>
<p class="text-muted" style="font-size: 0.85em;">Amber: worth a look. Red: an operator alarm fires (`08` §6.3). "unknown": the box could not read the value — never a guess.</p>
<footer style="margin-top: 2rem; color: var(--text-muted); font-size: 0.8rem; text-align: center;">
Felhom Hub <span style="font-family: var(--font-mono)">0.133.0</span>
</footer>
</div>
</body>
</html>
@@ -0,0 +1,96 @@
System — Felhom Hub
Felhom Hub
Dashboard
Customers
Apps
Hosts
System
Offsite
Configuration
System — versions and OS updates
Approved releases
docker : os-docker-20261004-142842
6 packages · 2026-10-04 14:28 UTC · by operator
Cancelled approvals (last 7 days)
host : os-host-20261004-124133
cancelled 2026-10-04 18:20:02 UTC — a TEST approval
no further box installs it; boxes that installed it keep it
host : os-host-20261004-124034
cancelled 2026-10-04 18:20:02 UTC — a TEST approval
no further box installs it; boxes that installed it keep it
guest : os-guest-20261004-123933
cancelled 2026-10-04 18:20:02 UTC — a TEST approval
no further box installs it; boxes that installed it keep it
guest : os-20261004-091417
cancelled 2026-10-04 18:20:02 UTC — a TEST approval
no further box installs it; boxes that installed it keep it
What ring 0 runs now
guest :
272 packages, first seen 2026-10-04 11:07 UTC
healthy for 8h17m0s of 24h0m0s
host :
607 packages, first seen 2026-10-04 12:24 UTC
healthy for 7h0m0s of 24h0m0s
docker :
6 packages, first seen 2026-10-04 14:28 UTC
approved as os-docker-20261004-142842
Approve now (guest + host)
An urgent fix only — normally the hub approves after 24 h and one night.
Box Ring / updates Tunnel
Proxmox Kernel (running) Kernel (next boot) Debian Felhom release Pending Not covered Held Reboot needed kernel.panic Oops Crash restarts 24 h Crash guard Root files
Guest Debian Felhom release Pending Restart needed
Docker containerd live-restore Docker release
Last OS leg
host guest Docker engine
Tester-2-be8404 Tester 2
ring 1
→ demo
updates ON
switch off
running
9.2.2
7.0.2-6-pve 7.0.2-6-pve 13.7
os-host-20261004-124133 78 0
none since 2026-10-04 10 s no
0 armed unknown
13.7
os-guest-20261004-123933 0 7
29.8.2
2.3.6-1~debian.13~trixie on —
2 h ago · applied · 44 s
demo-felhom-8363b5 Demo Ügyfél
ring 0
→ normal
updates ON
switch off
running
9.2.2
7.0.2-6-pve 7.0.2-6-pve 13.7
os-host-20261004-124133 80 0
none since 2026-10-04 10 s no
0 armed 0.143.0
13.7
os-guest-20261004-123933 0 10
29.8.2
2.3.6-1~debian.13~trixie on os-docker-20261004-142842
4 h ago · nothing · 12 s
demo-hp-bb76ea Demo HP
ring 0
→ normal
updates ON
switch off
running
9.2.2
7.0.14-20-pve 7.0.14-20-pve 13.7
ring0-20261004T144238Z 78 0
none no 10 s no
3 armed 0.143.0
13.7
ring0-20261004T144238Z 6 1
29.8.2
2.3.6-1~debian.13~trixie on r858-proof-forward
2 h ago · applied · 69 s
Amber: worth a look. Red: an operator alarm fires (`08` §6.3). "unknown": the box could not read the value — never a guess.
Felhom Hub 0.133.0
@@ -0,0 +1,6 @@
03:19:45
Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1 -- demo-felhom-8363b5 Demo Ügyfél 0.143.0 9.2.2 7.0.2-6-pve ONLINE 1/2 -- demo-hp-bb76ea Demo HP 0.143.0 9.2.2 7.0.14-20-pve ONLINE 1/2 -- tester-1-d70be4 Tester 1 0.143.0 9.2.2 7.0.2-6-pve ONLINE 1/1
demo-hp: 0 not-healthy of 21 containers; guard 10
felhom-pve: 0 not-healthy of 5 containers; guard 10
9202: 6 containers, controller Up 9 hours (healthy)
tester1: 9 healthy containers
@@ -0,0 +1,12 @@
2026/10/05 00:30:00 scheduler.go:346: [INFO] [scheduler] Running job: db-dump
2026/10/05 00:31:29 scheduler.go:363: [INFO] [scheduler] Job db-dump completed (took 1m29.61s)
2026/10/05 01:30:00 scheduler.go:346: [INFO] [scheduler] Running job: tier2-backup
2026/10/05 01:30:00 scheduler.go:346: [INFO] [scheduler] Running job: fill-watch
2026/10/05 01:30:00 fillwatch.go:267: [INFO] [fillwatch] checked 3 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok
2026/10/05 01:30:00 scheduler.go:363: [INFO] [scheduler] Job fill-watch completed (took 0s)
2026/10/05 01:30:01 tier2.go:425: [INFO] [backup] Tier 2 copied adventurelog → /mnt/felhom-drives/hdd_1/backups/secondary/adventurelog (336.4 MB, 0 leg(s), 2s)
2026/10/05 01:30:01 tier2.go:425: [INFO] [backup] Tier 2 copied bentopdf → /mnt/felhom-drives/hdd_1/backups/secondary/bentopdf (13.6 KB, 0 leg(s), 0s)
2026/10/05 01:30:02 tier2.go:425: [INFO] [backup] Tier 2 copied bookstack → /mnt/felhom-drives/hdd_1/backups/secondary/bookstack (159.4 MB, 0 leg(s), 1s)
2026/10/05 01:30:02 tier2.go:425: [INFO] [backup] Tier 2 copied calibre-web → /mnt/sys_drive/felhom-data/backups/secondary/calibre-web (5.6 MB, 1 leg(s), 0s) [SSD: state-only]
2026/10/05 01:30:02 tier2.go:425: [INFO] [backup] Tier 2 copied docmost → /mnt/felhom-drives/hdd_1/backups/secondary/docmost (83.5 MB, 0 leg(s), 0s)
2026/10/05 01:30:03 tier2.go:425: [INFO] [backup] Tier 2 copied kimai → /mnt/felhom-drives/hdd_1/backups/secondary/kimai (173.0 MB, 0 leg(s), 1s)
@@ -0,0 +1,9 @@
2026/10/05 00:30:00 [INFO] [scheduler] Running job: db-dump
2026/10/05 00:30:00 [INFO] [scheduler] Job db-dump completed (took 998ms)
2026/10/05 01:30:00 [INFO] [scheduler] Running job: tier2-backup
2026/10/05 01:30:00 [INFO] [scheduler] Running job: fill-watch
2026/10/05 01:30:00 [INFO] [fillwatch] checked 2 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok
2026/10/05 01:30:00 [INFO] [scheduler] Job fill-watch completed (took 0s)
2026/10/05 01:30:00 [INFO] [backup] Tier 2 for opengist: no off-drive target — nincs másik fizikai meghajtó — a 2. mentéshez 2. meghajtó szükséges
2026/10/05 01:30:00 [INFO] [backup] Tier 2 run complete: 1 app(s) processed (incl. volume-only — F6)
2026/10/05 01:30:00 [INFO] [scheduler] Job tier2-backup completed (took 6ms)
@@ -0,0 +1,9 @@
2026/10/05 00:30:00 [INFO] [scheduler] Running job: db-dump
2026/10/05 00:30:39 [INFO] [scheduler] Job db-dump completed (took 39.504s)
2026/10/05 01:30:00 [INFO] [fillwatch] checked 3 filesystem(s), 0 unreadable/skipped, 0 notification(s); bands: all ok
2026/10/05 01:30:00 [INFO] [scheduler] Running job: tier2-backup
2026/10/05 01:30:00 [INFO] [backup] Tier 2 copied bookstack → /mnt/felhom-drives/adatlemez/backups/secondary/bookstack (154.2 MB, 0 leg(s), 1s)
2026/10/05 01:30:00 [INFO] [backup] Tier 2 copied paperless-ngx → /mnt/sys_drive/felhom-data/backups/secondary/paperless-ngx (69.8 MB, 1 leg(s), 0s) [SSD: state-only]
2026/10/05 01:30:01 [INFO] [backup] Tier 2 copied privatebin → /mnt/felhom-drives/adatlemez/backups/secondary/privatebin (28.3 KB, 0 leg(s), 0s)
2026/10/05 01:30:01 [INFO] [backup] Tier 2 run complete: 3 app(s) processed (incl. volume-only — F6)
2026/10/05 01:30:01 [INFO] [scheduler] Job tier2-backup completed (took 1.303s)
@@ -0,0 +1,34 @@
2026/10/05 02:14:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:14:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:15:00 scheduler.go:346: [INFO] [scheduler] Running job: offbox-backup
2026/10/05 02:15:00 offbox.go:1001: [INFO] [offbox] backup run started (9 app(s) toggled)
2026/10/05 02:16:20 offbox.go:1048: [INFO] [offbox] pre-push dump leg completed in 1m20.405s — snapshot pair is coherent
2026/10/05 02:16:27 offbox.go:1479: [INFO] [offbox] backed up opengist (/mnt/sys_drive/felhom-data/backups/primary/opengist, 0 mandatory path(s))
2026/10/05 02:16:28 offbox.go:1479: [INFO] [offbox] backed up privatebin (/mnt/sys_drive/felhom-data/backups/primary/privatebin, 0 mandatory path(s))
2026/10/05 02:16:30 offbox.go:1479: [INFO] [offbox] backed up romm (/mnt/felhom-drives/hdd_1/backups/primary/romm, 0 mandatory path(s))
2026/10/05 02:16:33 offbox.go:1479: [INFO] [offbox] backed up bookstack (/mnt/sys_drive/felhom-data/backups/primary/bookstack, 0 mandatory path(s))
2026/10/05 02:16:35 offbox.go:1479: [INFO] [offbox] backed up docmost (/mnt/sys_drive/felhom-data/backups/primary/docmost, 0 mandatory path(s))
2026/10/05 02:16:38 offbox.go:1479: [INFO] [offbox] backed up kimai (/mnt/sys_drive/felhom-data/backups/primary/kimai, 0 mandatory path(s))
2026/10/05 02:16:44 offbox.go:1476: [WARN] [offbox] backed up bentopdf (/mnt/sys_drive/felhom-data/backups/primary/bentopdf, 0 mandatory path(s)) — but the recovery unit carried NO database dump and NO volume tar, so this snapshot holds none of the app's data; the next run with a dump leg will replace it
2026/10/05 02:16:46 offbox.go:1479: [INFO] [offbox] backed up calibre-web (/mnt/felhom-drives/hdd_1/backups/primary/calibre-web, 1 mandatory path(s))
2026/10/05 02:16:48 offbox_window.go:206: [INFO] [offbox] retention skipped (after-run): no clean-up window now (not due (last window 2026-10-04T05:36:14Z)) — nothing deleted (decision 68)
2026/10/05 02:16:53 offbox.go:1244: [INFO] [offbox] backup OK: 9 app(s) backed up, 136 snapshot(s), 1m48s
2026/10/05 02:16:53 unattended.go:270: [INFO] [update-leg] started (after-offsite): window 02:30, no step starts at or after 07:30
2026/10/05 02:16:53 unattended.go:248: [INFO] [update-leg] update leg (after-offsite): done=0 undone=0 held=0 failed=0 skipped=1 in 0s [skipped: romm=held]
2026/10/05 02:16:53 scheduler.go:363: [INFO] [scheduler] Job offbox-backup completed (took 1m53.096s)
2026/10/05 02:19:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:19:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:24:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:24:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:29:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:29:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:34:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:34:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:39:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:39:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 1ms)
2026/10/05 02:44:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:44:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:49:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:49:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:54:59 scheduler.go:346: [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:54:59 scheduler.go:363: [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
@@ -0,0 +1,27 @@
2026/10/05 02:12:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:12:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:15:00 [INFO] [scheduler] Running job: offbox-backup
2026/10/05 02:15:00 [INFO] [offbox] backup run started (1 app(s) toggled)
2026/10/05 02:15:00 [INFO] [offbox] pre-push dump leg completed in 894ms — snapshot pair is coherent
2026/10/05 02:15:05 [INFO] [offbox] backed up opengist (/mnt/sys_drive/felhom-data/backups/primary/opengist, 0 mandatory path(s))
2026/10/05 02:15:10 [ERROR] [offbox] clean-up window 3: the fake-snapshot guard REFUSED — nothing deleted: the policy would remove snapshot 343d57a5 from 2026-09-28T02:15:05Z — younger than 8 days and not superseded the same day, which honest retention never does (R-822)
2026/10/05 02:15:15 [INFO] [offbox] backup OK: 1 app(s) backed up, 15 snapshot(s), 12s
2026/10/05 02:15:15 [INFO] [update-leg] started (after-offsite): window 02:30, no step starts at or after 07:30
2026/10/05 02:15:15 [INFO] [update-leg] update leg (after-offsite): done=0 undone=0 held=0 failed=0 skipped=0 in 0s [skipped: ]
2026/10/05 02:15:15 [INFO] [scheduler] Job offbox-backup completed (took 15.079s)
2026/10/05 02:17:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:17:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:22:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:22:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:27:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:27:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:32:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:32:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:37:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:37:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:42:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:42:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:47:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:47:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:52:35 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:52:35 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
@@ -0,0 +1,23 @@
2026/10/05 02:12:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:12:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:15:00 [INFO] [scheduler] Running job: offbox-backup
2026/10/05 02:15:00 [INFO] [offbox] skipped — pending key escrow (no offsite run until the repo password is escrowed under R)
2026/10/05 02:15:00 [INFO] [update-leg] started (after-offsite): window 02:30, no step starts at or after 07:30
2026/10/05 02:15:00 [INFO] [update-leg] update leg (after-offsite): done=0 undone=0 held=0 failed=0 skipped=0 in 0s [skipped: ]
2026/10/05 02:15:00 [INFO] [scheduler] Job offbox-backup completed (took 107ms)
2026/10/05 02:17:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:17:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:22:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:22:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:27:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:27:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:32:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:32:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:37:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:37:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:42:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:42:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:47:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:47:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
2026/10/05 02:52:04 [INFO] [scheduler] Running job: offsite-credential-retry
2026/10/05 02:52:04 [INFO] [scheduler] Job offsite-credential-retry completed (took 0s)
@@ -0,0 +1,32 @@
Oct 05 04:39:24 demo-hp felhom-agent[447632]: time=2026-10-05T04:39:24.344+02:00 level=INFO msg="janitor: stale-lock sweep deferred — a heavy operation is in flight" busy=backup:local
Oct 05 04:40:16 demo-hp felhom-agent[447632]: time=2026-10-05T04:40:16.647+02:00 level=INFO msg="backup: completed" vmid=9201 target=local archive=local:backup/vzdump-lxc-9201-2026_10_05-04_35_24.tar.zst size_bytes=4882309520 uncovered_volumes=2
Oct 05 04:40:16 demo-hp felhom-agent[447632]: time=2026-10-05T04:40:16.647+02:00 level=INFO msg="local-api: backup job complete" vmid=9201 target=local job=backup-9201-1791167723831350602 archive=local:backup/vzdump-lxc-9201-2026_10_05-04_35_24.tar.zst
Oct 05 04:41:46 demo-hp felhom-agent[447632]: time=2026-10-05T04:41:46.648+02:00 level=INFO msg="osupdate: START" run=20261005T024146Z layer=guest vmid=9201 ring=0 trigger=night enabled=true release=ring0-20261005T024146Z
Oct 05 04:41:47 demo-hp felhom-os-apply[1985513]: os-apply: START release=ring0-20261005T024146Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0
Oct 05 04:41:57 demo-hp felhom-os-apply[1985958]: os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0
Oct 05 04:41:57 demo-hp felhom-os-apply[1985959]: os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)
Oct 05 04:42:04 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:04.983+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261005T024146Z layer=guest:9201 lane=fast mode=apply select=pending-fast packages=0"
Oct 05 04:42:04 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:04.983+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
Oct 05 04:42:04 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:04.983+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
Oct 05 04:42:04 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:04.983+02:00 level=INFO msg="osupdate: DONE" run=20261005T024146Z layer=guest vmid=9201 ring=0 trigger=night outcome=nothing healthy=true reason="" upgraded=0 pending=0 not_covered=0 restart_n
Oct 05 04:42:05 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:05.036+02:00 level=INFO msg="osupdate: START" run=20261005T024146Z layer=host vmid=9201 ring=0 trigger=night enabled=true release=ring0-20261005T024146Z
Oct 05 04:42:06 demo-hp felhom-os-apply[1986777]: os-apply: START release=ring0-20261005T024146Z layer=host lane=fast mode=apply select=pending-fast packages=0
Oct 05 04:42:14 demo-hp felhom-os-apply[1987237]: os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0
Oct 05 04:42:14 demo-hp felhom-os-apply[1987238]: os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)
Oct 05 04:42:22 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:22.500+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261005T024146Z layer=host lane=fast mode=apply select=pending-fast packages=0"
Oct 05 04:42:22 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:22.500+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
Oct 05 04:42:22 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:22.500+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
Oct 05 04:42:23 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:23.580+02:00 level=INFO msg="osupdate: DONE" run=20261005T024146Z layer=host vmid=9201 ring=0 trigger=night outcome=nothing healthy=true reason="" upgraded=0 pending=78 not_covered=78 restart_
Oct 05 04:42:25 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:25.734+02:00 level=INFO msg="osupdate: START" run=20261005T024146Z layer=docker vmid=9201 ring=0 trigger=night enabled=true release=ring0-20261005T024146Z
Oct 05 04:42:27 demo-hp felhom-os-apply[1988603]: os-apply: START release=ring0-20261005T024146Z layer=docker:9201 lane=slow mode=apply select=pending-docker packages=0 authority=ring0
Oct 05 04:42:37 demo-hp felhom-os-apply[1989188]: os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0
Oct 05 04:42:37 demo-hp felhom-os-apply[1989189]: os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)
Oct 05 04:42:46 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:46.151+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: START release=ring0-20261005T024146Z layer=docker:9201 lane=slow mode=apply select=pending-docker packages=0 authority=ring0"
Oct 05 04:42:46 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:46.151+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: PLAN upgrade=0 already=0 not-installed=0 from-snapshot=0"
Oct 05 04:42:46 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:46.151+02:00 level=INFO msg="osupdate: wrapper" line="os-apply: DONE rc=0 seconds=0 upgraded=0 (nothing to do)"
Oct 05 04:42:46 demo-hp felhom-agent[447632]: time=2026-10-05T04:42:46.152+02:00 level=INFO msg="osupdate: DONE" run=20261005T024146Z layer=docker vmid=9201 ring=0 trigger=night outcome=nothing healthy=true reason="" upgraded=0 pending=0 not_covered=0 restart_
2026/10/05 02:35:02 quiesce.go:505: [INFO] [quiesce] backup due on 1 tier(s) — quiescing 9 stack(s): [adventurelog bentopdf bookstack calibre-web docmost kimai opengist paperless-ngx privatebin]
2026/10/05 02:35:23 quiesce.go:554: [INFO] [quiesce] tier local: backup job backup-9201-1791167723831350602 started — polling
2026/10/05 02:35:33 quiesce.go:623: [INFO] [quiesce] tier local: job backup-9201-1791167723831350602 snapshotted — resuming app early (8B.2)
2026/10/05 02:35:33 quiesce.go:492: [INFO] [quiesce] unquiescing (snapshotted (early resume, last tier)): restarting 9 stack(s)
2026/10/05 02:40:21 quiesce.go:628: [INFO] [quiesce] tier local: backup job backup-9201-1791167723831350602 done
@@ -0,0 +1,2 @@
2026/10/05 02:15:10 [ERROR] [offbox] clean-up window 3: the fake-snapshot guard REFUSED — nothing deleted: the policy would remove snapshot 343d57a5 from 2026-09-28T02:15:05Z — younger than 8 days and not superseded the same day, which honest retention never does (R-822)
2026/10/05 02:15:15 [INFO] [update-leg] started (after-offsite): window 02:30, no step starts at or after 07:30
@@ -0,0 +1,3 @@
('demo-felhom', 'offsite_prune_guard_refused', 'sent', 'operator', '', '2026-10-05 02:15:11')
('demo-felhom', 'offsite_prune_guard_refused', 'skipped', 'customer', 'operator_only', '2026-10-05 02:15:11')
('tester-1', 'offbox_repo_orphaned', 'sent', 'operator', '', '2026-10-05 03:08:58')
Binary file not shown.

After

Width:  |  Height:  |  Size: 157 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 137 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 131 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 131 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 134 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 134 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 150 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 150 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 157 KiB

@@ -0,0 +1,3 @@
2026-10-04T19:26:07Z
HTTP/1.1 303 See Other
Location: /customers/tester-1?flash=selfbind-sent#tab=setup
@@ -0,0 +1,28 @@
Formatting '/mnt/hdd_1/images/341/vm-341-disk-0.raw', fmt=raw size=540672 preallocation=off
transferred 0.0 B of 528.0 KiB (0.00%)
transferred 528.0 KiB of 528.0 KiB (100.00%)
transferred 528.0 KiB of 528.0 KiB (100.00%)
efidisk0: successfully created disk 'nvme-scratch:341/vm-341-disk-0.raw,efitype=4m,pre-enrolled-keys=0,size=528K'
Formatting '/mnt/hdd_1/images/341/vm-341-disk-1.raw', fmt=raw size=214748364800 preallocation=off
scsi0: successfully created disk 'nvme-scratch:341/vm-341-disk-1.raw,size=200G'
Formatting '/mnt/hdd_1/images/341/vm-341-disk-2.raw', fmt=raw size=53687091200 preallocation=off
scsi1: successfully created disk 'nvme-scratch:341/vm-341-disk-2.raw,size=50G'
update VM 341: -boot order=ide2;scsi0
bios: ovmf
boot: order=ide2;scsi0
cores: 4
cpu: host
efidisk0: nvme-scratch:341/vm-341-disk-0.raw,efitype=4m,pre-enrolled-keys=0,size=528K
ide2: local:iso/felhom-installer-1.29.0-pve9.2-1.iso,media=cdrom,size=1665356K
machine: q35
memory: 8192
meta: creation-qemu=11.0.0,ctime=1791141969
name: night1004-tester1
net0: virtio=BC:24:11:AC:E3:F9,bridge=vmbr0
ostype: l26
scsi0: nvme-scratch:341/vm-341-disk-1.raw,size=200G
scsi1: nvme-scratch:341/vm-341-disk-2.raw,size=50G
scsihw: virtio-scsi-single
smbios1: uuid=451c8d94-abf2-46e4-a278-b579a9f315b5
vga: std
vmgenid: acdf89db-a810-445c-9d88-7bccd688d3c1
@@ -0,0 +1,7 @@
Oct 04 21:48:28 felhom felhom-agent[2492]: time=2026-10-04T21:48:28.339+02:00 level=INFO msg="backup: completed" vmid=9201 target=local archive=local:backup/vzdump-lxc-9201-2026_10_04-21_47_12.tar.zst size_bytes=1378818894 uncovered_volumes=2
Oct 04 21:49:58 felhom felhom-agent[2492]: time=2026-10-04T21:49:58.341+02:00 level=INFO msg="osupdate: START" run=20261004T194958Z layer=guest vmid=9201 ring=1 trigger=night enabled=true release=""
Oct 04 21:50:19 felhom felhom-agent[2492]: time=2026-10-04T21:50:19.590+02:00 level=INFO msg="osupdate: DONE" run=20261004T194958Z layer=guest vmid=9201 ring=1 trigger=night outcome=nothing healthy=true reason="" upgraded=0 pending=49 not_covered=49 restart_needed=0 reboot_needed=false wrapper_seconds=21.2
Oct 04 21:50:19 felhom felhom-agent[2492]: time=2026-10-04T21:50:19.629+02:00 level=INFO msg="osupdate: START" run=20261004T194958Z layer=host vmid=9201 ring=1 trigger=night enabled=true release=""
Oct 04 21:50:36 felhom felhom-agent[2492]: time=2026-10-04T21:50:36.213+02:00 level=INFO msg="osupdate: DONE" run=20261004T194958Z layer=host vmid=9201 ring=1 trigger=night outcome=nothing healthy=true reason="" upgraded=0 pending=185 not_covered=185 restart_needed=0 reboot_needed=false wrapper_seconds=15.5
Oct 04 21:50:36 felhom felhom-agent[2492]: time=2026-10-04T21:50:36.239+02:00 level=INFO msg="osupdate: docker step skipped — ring 1 takes an engine set only inside a signed operator job (`11` §5.8)" run=20261004T194958Z vmid=9201 trigger=night ring=1 enabled=true
Oct 04 22:00:05 felhom felhom-agent[2492]: time=2026-10-04T22:00:05.529+02:00 level=INFO msg="backup: completed" vmid=9201 target=felhom-pbs archive=felhom-pbs:backup/ct/9201/2026-10-04T19:57:18Z size_bytes=4913374023 uncovered_volumes=2
@@ -0,0 +1 @@
tester-1-d70be4 Tester 1 ring 1 → demo updates ON switch off running 9.2.2 7.0.2-6-pve 7.0.2-6-pve 13.5 — 185 106 none no 10 s no 0 armed 0.143.0 13.6 — 49 0 29.8.2 2.3.6-1~debian.13~trixie on — 18 min ago · nothing · 16 s Amber: worth a look. Red: an operator alarm fires (`08` §6.3). "unknown": the box could not read the value — never a guess. Felhom Hub 0.133.0
@@ -0,0 +1,4 @@
10
armed True
live-restore=true engine=29.8.2
gitea.dooplex.hu/admin/felhom-controller:0.293.0
@@ -0,0 +1,7 @@
03:07:37
{"data":{"job_id":"escrow-1791169657458544213","phase":"running"},"error":"","ok":true}
{'claimable': True, 'detail': '', 'entropy_bits': 129.24070185585344, 'phase': 'done', 'restic_pw_sealed': True, 'uploaded': True}
03:07:42
claim ok True keys ['recovery_code'] err
escrow_state pending
escrow_state=escrowed 03:08:15
@@ -0,0 +1,14 @@
2026/10/05 03:08:23 [INFO] [offbox] backup run started (3 app(s) toggled)
2026/10/05 03:08:56 [INFO] [offbox] pre-push dump leg completed in 32.838s — snapshot pair is coherent
2026/10/05 03:08:58 [INFO] [offbox] orphaned repo, auto (returning household — this box never made an off-site copy; decision 78) — setting the old copy aside (move-aside + re-init, nothing deleted)
2026/10/05 03:08:58 [WARN] [offbox] resetting orphaned repo (auto (returning household — this box never made an off-site copy; decision 78)): asking the hub to set /home/felhom-repo aside, then re-init
2026/10/05 03:08:58 [INFO] Event pushed: offbox_repo_orphaned (warning) [hu-only] — A távoli mentési tároló elárvult: a benne lévő mentések egy korábbi, már nem elérhető kulccsal készültek (újratelepítés). Új mentés a tároló visszaállításáig nem készül.
2026/10/05 03:08:58 [INFO] [offbox] the hub set the orphaned repo aside: /home/felhom-repo -> (nothing deleted)
2026/10/05 03:09:02 [INFO] [offbox] orphaned repo reset complete — old history set aside at /home/felhom-repo.orphaned-20261005 (move-aside, not deleted); fresh repo initialized
2026/10/05 03:09:02 [INFO] Event pushed: offbox_repo_reset (info) [hu-only] — A távoli mentési tároló visszaállítva: a régi előzmény félretéve (nem törölve), és egy üres, új tároló jött létre a mostani kulccsal.
2026/10/05 03:09:05 [INFO] [offbox] backed up privatebin (/mnt/sys_drive/felhom-data/backups/primary/privatebin, 0 mandatory path(s))
2026/10/05 03:09:09 [INFO] [offbox] backed up paperless-ngx (/mnt/felhom-drives/adatlemez/backups/primary/paperless-ngx, 1 mandatory path(s))
2026/10/05 03:09:12 [INFO] [offbox] backed up bookstack (/mnt/sys_drive/felhom-data/backups/primary/bookstack, 0 mandatory path(s))
2026/10/05 03:09:16 [INFO] [offbox] clean-up window 4: the policy removes nothing
2026/10/05 03:09:21 [INFO] [offbox] backup OK: 3 app(s) backed up, 3 snapshot(s), 54s
2026/10/05 03:09:21 [INFO] [offbox] manual run progress reporting ended after 57s
@@ -0,0 +1 @@
19:31:30
@@ -0,0 +1 @@
19:37:42
@@ -0,0 +1 @@
Felhom — Doboz összekötése Felhom doboz összekötése Sikeres összekötés. A doboz kb. egy percen belül folytatja a telepítést. Ezt az oldalt bezárhatod — a beállítás a háttérben befejeződik, és a vezérlőpultod hamarosan elérhető lesz. Felhom.eu
@@ -0,0 +1,4 @@
19:42:15
HTTP/2 302
location: /
launcher 200
@@ -0,0 +1,3 @@
19:44:08
{"data":{"phase":"formatting","started":true},"ok":true}
{"data":{"device":"/dev/sdb","durable_id":"","error":"","opsign":"","phase":"done","reason":"","started_at":"2026-10-04T19:44:08.674482321Z","updated_at":"2026-10-04T19:44:10.414201508Z","where":"/mnt/felhom-drives/adatlemez"},"ok":true}
@@ -0,0 +1,18 @@
19:44:38
privatebin fields sent: ['DOMAIN', 'SUBDOMAIN'] {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"}
HTTP 202
bookstack fields sent: ['ADMIN_PASSWORD', 'APP_KEY', 'DB_PASSWORD', 'DOMAIN', 'SUBDOMAIN'] {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"}
HTTP 202
paperless-ngx fields sent: ['DB_PASSWORD', 'DOMAIN', 'HDD_PATH', 'PAPERLESS_ADMIN_PASSWORD', 'PAPERLESS_ADMIN_USER', 'PAPERLESS_OCR_LANGUAGE', 'PAPERLESS_SECRET_KEY', 'SUBDOMAIN'] {"ok":false,"error":"path \"/mnt/felhom-drives/adatlemez/appdata/paperless-ngx\" does not exist for field \"Adattárolási útvonal\""}
HTTP 400
paperless-ngx fields sent: ['DB_PASSWORD', 'DOMAIN', 'HDD_PATH', 'PAPERLESS_ADMIN_PASSWORD', 'PAPERLESS_ADMIN_USER', 'PAPERLESS_OCR_LANGUAGE', 'PAPERLESS_SECRET_KEY', 'SUBDOMAIN'] {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"}
HTTP 202
19:55:59
bookstack fields sent: ['ADMIN_PASSWORD', 'APP_KEY', 'DB_PASSWORD', 'DOMAIN', 'SUBDOMAIN'] {"ok":true,"message":"Telepítés elindítva – az állapot a kártyán követhető"}
HTTP 202
bookstack running True
@@ -0,0 +1,20 @@
2026/10/04 19:44:39 [INFO] [api] Deploy requested for stack: bookstack
2026/10/04 19:44:39 [INFO] [stacks] bookstack: install HOLD before the first start — only the household reaches [wiki.enkicsifelhom.hu] until the known first login is replaced
2026/10/04 19:44:39 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 5 env vars, 3 encrypted, 3 sensitive fields
2026/10/04 19:44:39 [INFO] [stacks] Deploying stack bookstack with 5 env vars: [DOMAIN, SUBDOMAIN, APP_KEY, DB_PASSWORD, ADMIN_PASSWORD]
2026/10/04 19:44:39 [INFO] [stacks] SaveAppConfig: saved config for bookstack
2026/10/04 19:44:44 [INFO] [stacks] Stack privatebin deployed successfully (took 5.3s)
2026/10/04 19:45:04 [INFO] [stacks] image retention (one-time clean-up): deleted [mariadb:<none>] (dfff46ef3f9d, 334MB) — no container, installed app or undo names it (decision 53)
2026/10/04 19:45:04 [INFO] [stacks] image retention (one-time clean-up): pass over 8 image(s) of [actualbudget/actual-server calcom/cal.com codewithcj/sparkyfitness codewithcj/sparkyfitness_server crocodilestick/calibre-web-automated deluan/navidrome docmost/docmost emby/embyserver f0rc3/gokapi fallenbagel/jellyseerr flomp/wanderer-db flomp/wanderer-web freikin/dawarich getmeili/meilisearch ghcr.io/advplyr/audiobookshelf ghcr.io/alam00000/bentopdf ghcr.io/alexta69/metube ghcr.io/claperco/claper ghcr.io/cmintey/wishlist ghcr.io/diced/zipline ghcr.io/gethomepage/homepage ghcr.io/gramps-project/grampsweb ghcr.io/grimmory-tools/grimmory ghcr.io/home-assistant/home-assistant ghcr.io/immich-app/immich-machine-learning ghcr.io/immich-app/immich-server ghcr.io/immich-app/postgres ghcr.io/karakeep-app/karakeep ghcr.io/karakeep-app/karakeep-chrome ghcr.io/kozea/radicale ghcr.io/lukegus/termix ghcr.io/mealie-recipes/mealie ghcr.io/paperless-ngx/paperless-ngx ghcr.io/papra-hq/papra ghcr.io/seanmorley15/adventurelog-backend ghcr.io/seanmorley15/adventurelog-frontend ghcr.io/sysadminsmedia/homebox ghcr.io/tandoorrecipes/recipes ghcr.io/thomiceli/opengist ghost gitea.dooplex.hu/admin/recipe-importer gitea/gitea glanceapp/glance gotson/komga grafana/grafana jellyfin/jellyfin kimai/kimai2 louislam/uptime-kuma lscr.io/linuxserver/bookstack lscr.io/linuxserver/code-server lscr.io/linuxserver/radarr lscr.io/linuxserver/sonarr lukevella/rallly mariadb msdeluise/plant-it n8nio/n8n nextcloud onlyoffice/documentserver outlinewiki/outline plexinc/pms-docker postgis/postgis postgres privatebin/pdo redis registry.gitlab.com/crafty-controller/crafty-4 rommapp/romm vaultwarden/server vikunja/vikunja wger/server] — 1 candidate(s), 1 deleted, the rest kept
2026/10/04 19:45:04 [INFO] [stacks] image retention (one-time): deleted 1 image(s). docker disk before: Images 1.364GB 436.4MB (31%) | after: Images 1.031GB 102.6MB (9%)
2026/10/04 19:45:05 [INFO] [stacks] controller image retention: pass over 1 controller image(s) — running 0.293.0, previous "" (), 0 candidate(s), 0 deleted, the rest kept
2026/10/04 19:45:05 [ERROR] [stacks] Command failed: docker compose up -d (in /opt/docker/stacks/bookstack) — exit code 1 (took 25.6s)
2026/10/04 19:45:05 [ERROR] [stacks] stderr: Image lscr.io/linuxserver/bookstack:26.09.1@sha256:99cd1f5707c1911afad213adec5c9739763b76f843d1477142231834ecdcb6f7 Pulling
2026/10/04 19:45:05 [ERROR] [stacks] Stack bookstack deploy failed after 25.6s: exit code 1
stderr: Image lscr.io/linuxserver/bookstack:26.09.1@sha256:99cd1f5707c1911afad213adec5c9739763b76f843d1477142231834ecdcb6f7 Pulling
2026/10/04 19:45:05 [INFO] [stacks] Stack bookstack: the failed deploy's containers were removed (volumes kept) — R-649
2026/10/04 19:45:05 [DEBUG] [stacks] SaveAppConfig: saving /opt/docker/stacks/bookstack — 5 env vars, 3 encrypted, 3 sensitive fields
2026/10/04 19:45:05 [INFO] [stacks] SaveAppConfig: saved config for bookstack
stderr: Image lscr.io/linuxserver/bookstack:26.09.1@sha256:99cd1f5707c1911afad213adec5c9739763b76f843d1477142231834ecdcb6f7 Pulling
2026/10/04 19:45:24 [INFO] [stacks] bookstack: removed an install-hold file for an app that is not held
2026/10/04 19:45:36 [INFO] [stacks] Stack paperless-ngx deployed successfully (took 47.3s)
@@ -0,0 +1,2 @@
book: https://wiki.enkicsifelhom.hu/books/csaladi-receptek
page: location: https://wiki.enkicsifelhom.hu/books/csaladi-receptek/page/turos-csusza
@@ -0,0 +1,2 @@
upload: "5cb7a425-a645-4822-bbec-d31f3aaea6f9"
HTTP 200
@@ -0,0 +1 @@
status 0 id 3f5172ad798b9377 url /?3f5172ad798b9377
@@ -0,0 +1,13 @@
== 21:12:40 Tester 2
Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 21:13:33 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 21:43:34 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 22:13:34 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 22:43:34 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 23:13:42 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 23:28:43 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 23:43:44 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 23:58:44 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 00:13:45 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 03:22:27 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
== 04:20:28 Tester-2-be8404 Tester 2 0.142.0 9.2.2 7.0.2-6-pve DOWN 1/1
@@ -0,0 +1,15 @@
2026-10-04T20:10:41Z
cores: 3
hookscript: local:snippets/felhom-guest-hook.sh
memory: 12288
mp0: local-lvm:vm-9201-disk-1,mp=/var/lib/felhom,backup=1,size=250G
mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
mp9: /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1
onboot: 1
rootfs: local-lvm:vm-9201-disk-0,size=32G
felhom-backup:backup/vzdump-lxc-9201-2026_10_02-07_45_20.tar.zst tar.zst backup 734719733 9201
felhom-backup:backup/vzdump-lxc-9201-2026_10_03-07_48_06.tar.zst tar.zst backup 736103026 9201
felhom-backup:backup/vzdump-lxc-9201-2026_10_04-07_49_00.tar.zst tar.zst backup 735936533 9201
libpcre2-8-0:amd64 10.46-1~deb13u3
libssh2-1t64:amd64 1.11.1-1+deb13u2
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3
@@ -0,0 +1,11 @@
local dir active 98497780 28882564 64565668 29.32%
0 upgraded, 0 newly installed, 3 downgraded, 0 to remove and 0 not upgraded.
Unpacking libpcre2-8-0:amd64 (10.46-1~deb13u2) over (10.46-1~deb13u3) ...
Setting up libpcre2-8-0:amd64 (10.46-1~deb13u2) ...
Unpacking libssh2-1t64:amd64 (1.11.1-1+deb13u1) over (1.11.1-1+deb13u2) ...
Unpacking libxml2:amd64 (2.12.7+dfsg+really2.9.14-2.1+deb13u1) over (2.12.7+dfsg+really2.9.14-2.1+deb13u3) ...
Setting up libssh2-1t64:amd64 (1.11.1-1+deb13u1) ...
Setting up libxml2:amd64 (2.12.7+dfsg+really2.9.14-2.1+deb13u1) ...
libpcre2-8-0:amd64 10.46-1~deb13u2
libssh2-1t64:amd64 1.11.1-1+deb13u1
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u1
@@ -0,0 +1,11 @@
20:11:04
INFO: Starting Backup of VM 9201 (lxc)
INFO: including mount point rootfs ('/') in backup
INFO: including mount point mp0 ('/var/lib/felhom') in backup
INFO: excluding bind mount point mp8 ('/mnt/felhom-drives') from backup (not a volume)
INFO: excluding bind mount point mp9 ('/etc/felhom-bootstrap') from backup (not a volume)
INFO: creating vzdump archive '/var/lib/vz/dump/vzdump-lxc-9201-2026_10_04-22_11_05.tar.zst'
INFO: archive file size: 899MB
INFO: Finished Backup of VM 9201 (00:00:31)
20:11:36
/var/lib/vz/dump/vzdump-lxc-9201-2026_10_04-22_11_05.log
@@ -0,0 +1,27 @@
20:11:43
=== felhom-agent 0.143.0 selftest=os-update vmid=9201 ring=0 enabled=true guest-release=false host-release=false appliance=true ===
"health_reason": "",
"healthy": true,
"outcome": "applied",
"refused": null,
"upgraded": [
"name": "libpcre2-8-0",
"version": "10.46-1~deb13u3",
"name": "libssh2-1t64",
"version": "1.11.1-1+deb13u2",
"name": "libxml2",
"version": "2.12.7+dfsg+really2.9.14-2.1+deb13u3",
"health_reason": "",
"healthy": true,
"outcome": "nothing",
"refused": null,
"upgraded": [],
"health_reason": "",
"healthy": true,
"outcome": "nothing",
"refused": null,
"upgraded": [],
20:12:39
libpcre2-8-0:amd64 10.46-1~deb13u3
libssh2-1t64:amd64 1.11.1-1+deb13u2
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3
@@ -0,0 +1,25 @@
cloudflared Up 9 hours (healthy)
felhom-controller Up 2 hours (healthy)
filebrowser Up 11 hours (healthy)
opengist Up 14 hours (healthy)
traefik Up 4 hours
DOWN-FROM 20:12:54
stopped 20:13:07
Logical volume "vm-9201-disk-2" created.
Logical volume pve/vm-9201-disk-2 changed.
WARNING: You have not turned on protection against thin pools running out of space.
WARNING: Set activation/thin_pool_autoextend_threshold below 100 to trigger automatic extension of thin pools before they get full.
Logical volume "vm-9201-disk-3" created.
WARNING: Sum of all thin volume sizes (564.00 GiB) exceeds the size of thin pool pve/data and the size of whole volume group (<475.94 GiB).
Logical volume pve/vm-9201-disk-3 changed.
Logical volume "vm-9201-disk-0" successfully removed.
Logical volume "vm-9201-disk-1" successfully removed.
extracting archive '/var/lib/vz/dump/vzdump-lxc-9201-2026_10_04-22_11_05.tar.zst'
restored 20:13:23
hookscript: local:snippets/felhom-guest-hook.sh
mp0: local-lvm:vm-9201-disk-3,mp=/var/lib/felhom,backup=1,size=250G
mp8: /mnt/felhom-drives,mp=/mnt/felhom-drives
mp9: /var/lib/felhom-agent/guests/9201/bootstrap,mp=/etc/felhom-bootstrap,ro=1
onboot: 1
rootfs: local-lvm:vm-9201-disk-2,size=32G
started 20:13:27
@@ -0,0 +1,9 @@
ALL-HEALTHY 20:13:42
cloudflared Up 11 seconds (healthy)
felhom-controller Up 10 seconds (healthy)
filebrowser Up 11 seconds (healthy)
opengist Up 11 seconds (healthy)
traefik Up 11 seconds
libpcre2-8-0:amd64 10.46-1~deb13u2
libssh2-1t64:amd64 1.11.1-1+deb13u1
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u1
@@ -0,0 +1,11 @@
20:13:55
"healthy": true,
"outcome": "applied",
"healthy": true,
"outcome": "nothing",
"healthy": true,
"outcome": "nothing",
libpcre2-8-0:amd64 10.46-1~deb13u3
libssh2-1t64:amd64 1.11.1-1+deb13u2
libxml2:amd64 2.12.7+dfsg+really2.9.14-2.1+deb13u3
Oct 04 22:13:10 demo-felhom felhom-agent[3166444]: time=2026-10-04T22:13:10.553+02:00 level=INFO msg="guest-power: guest is stopped but LOCKED — leaving it to the stale-lock path" vmid=9201 lock=create
@@ -0,0 +1,142 @@
[
{
"id": "6ea854132efc6053ee5f7ca900a2db6f767dd3d89250efeb52fa30e319598ed1",
"short_id": "6ea85413",
"time": "2026-08-12T15:15:33.030477238Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"drill-retained-key-20260812"
]
},
{
"id": "b4d7cb79502a6c3f772254bc79463ec726f722f185a1c10571c389516e31746d",
"short_id": "b4d7cb79",
"time": "2026-08-31T02:15:04.935400697Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "6ce44d9de433625eff342dc0234d526a11336fb9b813aaa49cd737682c07387a",
"short_id": "6ce44d9d",
"time": "2026-09-20T02:15:05.018256188Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "c7000d7de36008707347c3b6dec9c79166feeae2a517137daa2c47004221e7ef",
"short_id": "c7000d7d",
"time": "2026-09-27T02:15:05.066652132Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "8ccc027e486d4f2e1b5415e2e602e29e8acbf0001a1596ec08b00c43b148ea68",
"short_id": "8ccc027e",
"time": "2026-09-29T02:15:05.16680869Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "40826801b49bdb9a249d0d0e7576081d5c96ea2bc7d4503d9a1bce6bfb19cb60",
"short_id": "40826801",
"time": "2026-09-30T02:15:05.173694815Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "c3a3b13b9832ba3d98cc3dc047b01b376ced2c824506e8f06001d8a3a7c5660e",
"short_id": "c3a3b13b",
"time": "2026-10-01T02:15:05.016873278Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "b2606da6d28cb24ce8d5c0616ced769b1a7f7b3d0b2923fca23b4364262b7a31",
"short_id": "b2606da6",
"time": "2026-10-02T02:15:05.138940278Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "64129ff5dcb75ea1ff766605e1a0b4dc36e6a4441a0be9433fe2519e5ddd16e0",
"short_id": "64129ff5",
"time": "2026-10-03T02:15:05.108133602Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "2bb8fb60447e6387d374d98d196807dd9e32187695ddab5df85ff2a1ac856404",
"short_id": "2bb8fb60",
"time": "2026-10-03T15:05:39.219021268Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "5dd1f0b99e8ed22d7fdcc9005501e880ddd600341fe35bd6897174acdd943857",
"short_id": "5dd1f0b9",
"time": "2026-10-03T15:17:27.992813997Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "89df02373ec2ffbe4a6b02d622c30c6f5001b922fc692bb1e1b84dfb0b8d2971",
"short_id": "89df0237",
"time": "2026-10-04T02:15:03.833138622Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "4e7867af43f024c8f712417bce982c5c8085524b51e7f37040c665d0dc1146de",
"short_id": "4e7867af",
"time": "2026-10-05T02:15:03.941403075Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "47bad696fe89450b2f5db11bfbc3a958edf2796a60d851dd9d92585eb36d53fc",
"short_id": "47bad696",
"time": "2026-10-05T05:21:04.032874428Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
}
]
@@ -0,0 +1,152 @@
[
{
"id": "6ea854132efc6053ee5f7ca900a2db6f767dd3d89250efeb52fa30e319598ed1",
"short_id": "6ea85413",
"time": "2026-08-12T15:15:33.030477238Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"drill-retained-key-20260812"
]
},
{
"id": "b4d7cb79502a6c3f772254bc79463ec726f722f185a1c10571c389516e31746d",
"short_id": "b4d7cb79",
"time": "2026-08-31T02:15:04.935400697Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "92e49f62c017e103cf7a1f73f8982a7faa39d77eb9c7fd129b3910cc5734a262",
"short_id": "92e49f62",
"time": "2026-09-13T02:15:05.107149713Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "6ce44d9de433625eff342dc0234d526a11336fb9b813aaa49cd737682c07387a",
"short_id": "6ce44d9d",
"time": "2026-09-20T02:15:05.018256188Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "c7000d7de36008707347c3b6dec9c79166feeae2a517137daa2c47004221e7ef",
"short_id": "c7000d7d",
"time": "2026-09-27T02:15:05.066652132Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "343d57a5614f88b80a18b129b52753740c8391581073f406fe9878bf40716381",
"short_id": "343d57a5",
"time": "2026-09-28T02:15:05.279260454Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "8ccc027e486d4f2e1b5415e2e602e29e8acbf0001a1596ec08b00c43b148ea68",
"short_id": "8ccc027e",
"time": "2026-09-29T02:15:05.16680869Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "40826801b49bdb9a249d0d0e7576081d5c96ea2bc7d4503d9a1bce6bfb19cb60",
"short_id": "40826801",
"time": "2026-09-30T02:15:05.173694815Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "c3a3b13b9832ba3d98cc3dc047b01b376ced2c824506e8f06001d8a3a7c5660e",
"short_id": "c3a3b13b",
"time": "2026-10-01T02:15:05.016873278Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "b2606da6d28cb24ce8d5c0616ced769b1a7f7b3d0b2923fca23b4364262b7a31",
"short_id": "b2606da6",
"time": "2026-10-02T02:15:05.138940278Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "64129ff5dcb75ea1ff766605e1a0b4dc36e6a4441a0be9433fe2519e5ddd16e0",
"short_id": "64129ff5",
"time": "2026-10-03T02:15:05.108133602Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "2bb8fb60447e6387d374d98d196807dd9e32187695ddab5df85ff2a1ac856404",
"short_id": "2bb8fb60",
"time": "2026-10-03T15:05:39.219021268Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "5dd1f0b99e8ed22d7fdcc9005501e880ddd600341fe35bd6897174acdd943857",
"short_id": "5dd1f0b9",
"time": "2026-10-03T15:17:27.992813997Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "89df02373ec2ffbe4a6b02d622c30c6f5001b922fc692bb1e1b84dfb0b8d2971",
"short_id": "89df0237",
"time": "2026-10-04T02:15:03.833138622Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
},
{
"id": "4e7867af43f024c8f712417bce982c5c8085524b51e7f37040c665d0dc1146de",
"short_id": "4e7867af",
"time": "2026-10-05T02:15:03.941403075Z",
"hostname": "demo-felhom",
"tags": [
"felhom-offbox",
"opengist"
]
}
]
@@ -0,0 +1,26 @@
2026-10-05T05:20:57Z
grant HTTP 200
HTTP 302
before 15 after 14
removed: [('343d57a5', '2026-09-28T02:15:05'), ('92e49f62', '2026-09-13T02:15:05')]
added by the run: [('47bad696', '2026-10-05T05:21:04')]
2026/10/05 05:16:20 [INFO] [scheduler] Daily job offbox-backup scheduled for 2026-10-06 04:15 CEST
2026/10/05 05:16:35 [INFO] [bootrecon] boot window: fleet settled after 10s (3 identical samples 5s apart) — sweeping
2026/10/05 05:21:00 [INFO] [offbox] backup run started (1 app(s) toggled)
2026/10/05 05:21:01 [INFO] [offbox] pre-push dump leg completed in 892ms — snapshot pair is coherent
2026/10/05 05:21:06 [INFO] [offbox] backed up opengist (/mnt/sys_drive/felhom-data/backups/primary/opengist, 0 mandatory path(s))
2026/10/05 05:21:14 [INFO] [offbox] clean-up window 5 (after-run): 2 of 5 planned snapshot(s) removed, 16 -> 14, in 6s
2026/10/05 05:21:18 [INFO] [offbox] backup OK: 1 app(s) backed up, 14 snapshot(s), 15s
2026/10/05 05:21:18 [INFO] [offbox] manual run progress reporting ended after 18s
Traceback (most recent call last):
File "<stdin>", line 3, in <module>
sqlite3.OperationalError: no such column: removed
Traceback (most recent call last):
File "<stdin>", line 3, in <module>
sqlite3.OperationalError: no such column: box_reason
--- hub offsite_windows (demo-felhom, newest 3)
(5, '2026-10-05 05:21:08', '2026-10-05 05:21:15', 16, 14, 8, 'pruned', 'box')
(3, '2026-10-05 02:15:08', '2026-10-05 02:15:11', 15, 15, 7, 'guard-refused', 'box')
--- hub events since 05:20 UTC
--- hub notification_log since 05:20 UTC
@@ -0,0 +1,46 @@
PLAN 80ebd0d6 2026-09-13T02:16:27Z [felhom-offbox bentopdf]
PLAN 29516b0c 2026-09-13T02:16:31Z [felhom-offbox bookstack]
PLAN 21efaca4 2026-09-13T02:16:35Z [felhom-offbox calibre-web]
PLAN c8562d68 2026-09-13T02:16:39Z [felhom-offbox docmost]
PLAN b4350226 2026-09-13T02:16:44Z [felhom-offbox kimai]
PLAN 1ebc8069 2026-09-13T02:16:54Z [felhom-offbox paperless-ngx]
PLAN 6fac4ba8 2026-09-13T02:17:01Z [felhom-offbox romm]
PLAN 8cda9681 2026-09-13T02:17:08Z [felhom-offbox opengist]
PLAN 605bf9c7 2026-09-13T02:17:11Z [felhom-offbox privatebin]
PLAN 9efec80f 2026-09-28T13:42:12Z [felhom-offbox docmost]
PLAN ef800224 2026-09-28T13:42:20Z [felhom-offbox opengist]
PLAN c9c2414d 2026-09-28T13:42:24Z [felhom-offbox bentopdf]
PLAN 14981ce0 2026-09-28T13:42:27Z [felhom-offbox bookstack]
PLAN 693c93e1 2026-09-28T13:42:31Z [felhom-offbox calibre-web]
PLAN 90da3064 2026-09-28T13:42:36Z [felhom-offbox kimai]
PLAN 7db18829 2026-09-28T13:43:46Z [felhom-offbox paperless-ngx]
PLAN 57191440 2026-09-28T13:43:52Z [felhom-offbox privatebin]
PLAN 0febfb1d 2026-09-28T13:43:55Z [felhom-offbox romm]
PLAN b522e2f4 2026-10-03T02:16:49Z [felhom-offbox bentopdf]
PLAN c974cffe 2026-10-03T02:16:56Z [felhom-offbox calibre-web]
PLAN 0bffcb8f 2026-10-03T02:17:00Z [felhom-offbox paperless-ngx]
PLAN b5d27227 2026-10-03T02:17:08Z [felhom-offbox bookstack]
PLAN 5d1830e6 2026-10-03T02:17:13Z [felhom-offbox docmost]
PLAN 4a3c71f5 2026-10-03T02:17:19Z [felhom-offbox kimai]
PLAN 0a155533 2026-10-03T02:17:26Z [felhom-offbox opengist]
PLAN a5822405 2026-10-03T02:17:29Z [felhom-offbox privatebin]
PLAN 2cd36d95 2026-10-03T02:17:32Z [felhom-offbox romm]
PLAN bea276a7 2026-10-03T15:24:46Z [felhom-offbox bentopdf]
PLAN 59717090 2026-10-03T15:24:49Z [felhom-offbox calibre-web]
PLAN c6b5c67b 2026-10-03T15:24:51Z [felhom-offbox docmost]
PLAN cb83c862 2026-10-03T15:24:54Z [felhom-offbox paperless-ngx]
PLAN 38fbd3bc 2026-10-03T15:24:57Z [felhom-offbox privatebin]
PLAN 4ce84465 2026-10-03T15:24:59Z [felhom-offbox romm]
PLAN 2f72df90 2026-10-03T15:25:02Z [felhom-offbox bookstack]
PLAN 2c0385d3 2026-10-03T15:25:04Z [felhom-offbox kimai]
PLAN c43f2d0e 2026-10-03T15:25:07Z [felhom-offbox opengist]
PLAN 2d412cd5 2026-10-04T02:16:44Z [felhom-offbox bentopdf]
PLAN 93a66c3e 2026-10-04T02:16:46Z [felhom-offbox calibre-web]
PLAN 6dbbceac 2026-10-04T02:16:48Z [felhom-offbox docmost]
PLAN 84559526 2026-10-04T02:16:51Z [felhom-offbox paperless-ngx]
PLAN 2abceaa3 2026-10-04T02:16:54Z [felhom-offbox privatebin]
PLAN a86c8d7f 2026-10-04T02:16:56Z [felhom-offbox romm]
PLAN 40328365 2026-10-04T02:16:59Z [felhom-offbox bookstack]
PLAN f6c41de0 2026-10-04T02:17:01Z [felhom-offbox kimai]
PLAN d2b6725f 2026-10-04T02:17:04Z [felhom-offbox opengist]
GUARD at 2026-10-05T05:23:43Z: removes 18 [80ebd0d6 29516b0c 21efaca4 c8562d68 b4350226 1ebc8069 6fac4ba8 8cda9681 605bf9c7 9efec80f ef800224 c9c2414d 14981ce0 693c93e1 90da3064 7db18829 57191440 0febfb1d] refusal=""
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,33 @@
2026-10-05T05:23:54Z
grant HTTP 200
HTTP 302
2026/10/05 05:26:03 offbox_window.go:273: [INFO] [offbox] clean-up window 6 (after-run): 18 of 54 planned snapshot(s) removed, 145 -> 127, in 10s
2026/10/05 05:26:08 offbox.go:1244: [INFO] [offbox] backup OK: 9 app(s) backed up, 127 snapshot(s), 2m7s
before 136 after 127 removed 18 added by the run 9
removed == predicted: True
removed 80ebd0d6 2026-09-13T02:16:27 ['bentopdf']
removed 29516b0c 2026-09-13T02:16:31 ['bookstack']
removed 21efaca4 2026-09-13T02:16:35 ['calibre-web']
removed c8562d68 2026-09-13T02:16:39 ['docmost']
removed b4350226 2026-09-13T02:16:44 ['kimai']
removed 1ebc8069 2026-09-13T02:16:54 ['paperless-ngx']
removed 6fac4ba8 2026-09-13T02:17:01 ['romm']
removed 8cda9681 2026-09-13T02:17:08 ['opengist']
removed 605bf9c7 2026-09-13T02:17:11 ['privatebin']
removed 9efec80f 2026-09-28T13:42:12 ['docmost']
removed ef800224 2026-09-28T13:42:20 ['opengist']
removed c9c2414d 2026-09-28T13:42:24 ['bentopdf']
removed 14981ce0 2026-09-28T13:42:27 ['bookstack']
removed 693c93e1 2026-09-28T13:42:31 ['calibre-web']
removed 90da3064 2026-09-28T13:42:36 ['kimai']
removed 7db18829 2026-09-28T13:43:46 ['paperless-ngx']
removed 57191440 2026-09-28T13:43:52 ['privatebin']
removed 0febfb1d 2026-09-28T13:43:55 ['romm']
--- hub offsite_windows (demo-hp, newest 2)
(6, '2026-10-05 05:25:53', '2026-10-05 05:26:04', 145, 127, 72, 'pruned', 'box')
(2, '2026-10-04 05:36:14', '2026-10-04 05:36:17', 127, 127, None, 'nothing', 'box')
--- hub events since 05:23 UTC
--- notification_log since 05:23 UTC
--- key audit
[{"customer":"Tester-2","lines":1,"pinned":1,"findings":null},{"customer":"demo-felhom","lines":1,"pinned":1,"findings":null},{"customer":"demo-hp","lines":1,"pinned":1,"findings":null},{"customer":"tester-1","lines":1,"pinned":1,"findings":null}]
@@ -0,0 +1 @@
[{"customer":"Tester-2","lines":1,"pinned":1,"findings":null},{"customer":"demo-felhom","lines":1,"pinned":1,"findings":null},{"customer":"demo-hp","lines":1,"pinned":1,"findings":null},{"customer":"tester-1","lines":1,"pinned":1,"findings":null}]

Some files were not shown because too many files have changed in this diff Show More