# REPORT — rulings 61 (calibre-web's generated login name) and 62 (the registry prune rule) — 2026-10-01 late afternoon Evidence: `documentation/audits/calibre-name-and-prune-2026-10-01/` (A, B, T); tools in `audits/lockouts-2026-10-01/tools/` (`a_calibre_name.py`, `lk.py`, `walk.py`, `repoint.py`). Read: `09` §3 decisions 45, 57–60; `FIRST-ADMIN.md`; rows R-752, R-750, R-753; `audits/lockouts-2026-10-01/` B1, C1; homelab-manifests HM-024. Baselines (~12:55 CEST): controller `c1b123c64955`, felhom.eu `8dab40c7a786`, catalog `ed6df4b46b93` — matched. Register 390; highest R-755; last decision 60 → the rulings are **61 and 62**. ## The Part table | Part | done / not done / changed | why | |---|---|---| | Rulings 61, 62 | **done** — recorded first (`09` §3, CONTEXT) | numbered 61/62: 58–60 were taken by the lockouts session | | **A1 measure** | **done** — `hex:N` + `type: secret` already exist; calibre-web has no rename command | — | | **A2 build** | **done** — catalog `e9f50b5` (template, hu + en copy, the freeze for those 5 strings, FIRST-ADMIN) | no controller change | | **A3 proof on 9202** | **done** | — | | **A4 installed apps** | **done — and a defect found** (R-757); demo-hp renamed TWICE | the box invented a name for the installed app | | **B prune rule** | **done** — `admin/misc-scripts` `c9d5ed5`; test red-proofed; live dry-run | the running hub added to "in use" (a version in use the ruling did not name) | | B4 runbook line | **done** — `RUNBOOK-manual-build.md` §4.1a | HM-024 lives in homelab-manifests (outside the felhom fence) | | **C release / golden** | **not needed** | A1 needed no controller change | ## Claims in the brief that turned out wrong (or right) 1. **"The controller can generate a login name"** — right: `generate: "hex:N"` (deploy.go:1187) gives lowercase a–f and digits; `type: secret` is filled when empty and shown behind „Megjelenítés". 2. **"calibre-web can rename a user"** — **no command does**: `cps/cli.py` offers only `-s user:password` (`ub.py:1350 password_change`). Its admin page renames by setting `user.name` (`admin.py:2789`, column `ub.py:264`, unique). So `after_install` updates that column itself, then uses Calibre-Web's own `-s` for the password. 3. **"The OPDS door uses the same name"** — right: OPDS is limited per name (`cps/main.py:75`, `request_username`); a stranger's tries on `admin` never touch the real name (measured: OPDS with the real name ok after 40 tries on `admin`). 4. **Where the prune script lives** — in a repo already: Gitea `admin/misc-scripts` (`~/git/misc-scripts`). The August run is in its own log: `2026-08-22T16:02:20Z RUN action=prune … apply=true keep='7'`. 5. **"A template change reaches an installed calibre-web only through an Update"** — wrong in a way that matters: the template reached demo-hp at the next sync (images equal), and the box then INVENTED the new field's value (`InjectMissingFields`, R-757). My own first CHANGELOG line said "frozen until an Update" — also wrong. ## Part A — calibre-web **9202 (drill catalog `4e18b3a`, identical to live `e9f50b5`)** — `A/A1-9202-calibre-generated-name.txt`: install hold before the first start, opened by `after_install` at 11:02:17; a stranger polling `admin/admin123` from the deploy press got in **0 of 31** times; `after_install` record `ok: true`; the name 10 lowercase hex characters (read through the page's reveal); app.db: 2 users, 0 named `admin`; name + password: form ok, OPDS ok; `admin` + the right password refused; **40 wrong tries on `admin` at 3/min (11:02–11:16) → the household at once: form ok, OPDS ok**; a wrong password on the real name refused. Removed (drive data kept: R-756). **demo-hp** — `A/A2-demo-hp-rename.txt`: renamed by the same method (values through stdin, never printed); a real login over its traefik: name ok (form, OPDS), `admin` wrong. Then the box's sync injected a DIFFERENT `ADMIN_USER` into its app.yaml (R-757, `A/A3…`); renamed again to the box's recorded value; verified (the earlier name and `admin` refused). **The name is in `~/.config/credentials` as `DEMO_HP_CALIBRE_USER`** (backup `credentials.bak-20261001-calibre`); never in a repo. **What any other installed calibre-web gets, and when:** at the next catalog sync (≤ 15 min) its `.felhom.yml` gains the field and the box invents an `ADMIN_USER` for it; its login stays `admin` (after_install runs only after a fresh install). No other box has calibre-web today (the N100 does not; Tester-2 has not registered). ## Part B — the prune rule `tests/test-prune-plan.sh`: 7 checks pass (an in-use version older than the newest 20 is kept, with its reason; `--keep` defaults to 20; dry-run; an unreadable in-use list → exit 3). Red-proofs: the same plan with an empty in-use list deletes 0.262.0; the in-use check removed from `is_protected` → 3 checks fail (`B/B1-test-and-red-proof.txt`). Live dry-run (`B/B2-live-dry-run.txt`): in use — controller 0.285.0 (floor, golden's, baked), golden 0.285.0, agent 0.138.0 and 0.131.0, hub 0.126.0, felhom-samba 1.1.0. Would delete: felhom-controller 70, felhom-hub 8; every other package nothing. **No `--apply`.** No token or password in any output (grepped for each value). ## Rows **390 → 392.** Closed R-750, R-752. Opened R-756 (9202 remove-with-data refused), R-757 (the box invents a new secret field's value for installed apps). ## Teardown - **Machine:** 9202 back on the live catalog (`repo_url` read back), the same six containers; calibre-web removed through the product (drive data kept, R-756). demo-hp: calibre-web's user renamed (the only change there). - **Host:** nothing. **Hub:** read only (the Configuration page, for the dry-run). **Gitea:** read only; one repo push (`misc-scripts`). Drill catalog reset to live (`e9f50b5`).