# What to work on next — backlog triage, 2026-10-03 ## In one screen - **The open list is now readable.** It went from 442 rows to 326. It went from 824 KB to about 540 KB. - **Every open row has one category and one severity.** Two gates refuse a row without them, and refuse a finished row left in the open list. - **No row is P1.** Nothing in the list is harm that happens today on shipped code. 27 rows are P2 (must be done before the first paying customer). - **You decide one thing:** which theme starts next. Recommendation: **off-site backup safety**. The other option: **box system security updates**. Details are in "The decision" below. ## Headline numbers (before → after) | | before | after | |---|---|---| | rows in the open list (`OPEN-ITEMS.md`) | 442 with an id + 22 without | 326, all with an id | | size of the open list | 824 KB, 932 lines | ≈540 KB | | finished rows moved to `CLOSED-ITEMS.md` | — | 125 with an id + 20 without | | rows marked VERIFY (may be finished; not proven) | — | 11 | | rows with no severity | the reviewer counted ~182 | 0 | | new rows filed this session | — | 11: R-812, R-813 (findings beside two roadmap items), R-814, R-815 (old July watches that had no id), R-816 to R-819 (gaps found while sorting), R-50b (a finding that lived only in the roadmap) | | roadmap (`ROADMAP.md`) | 161 lines, 81 KB | 124 lines, 42 KB | **Open rows, category × severity** (no P1 anywhere): | Category | P2 | P3 | P4 | total | |---|---|---|---|---| | Install & onboarding | 2 | 11 | 5 | 18 | | Apps & catalog | 0 | 15 | 21 | 36 | | App updates | 0 | 12 | 7 | 19 | | Backup & restore | 12 | 24 | 20 | 56 | | Storage & devices | 0 | 7 | 5 | 12 | | Security & access | 3 | 23 | 3 | 29 | | Box system & updates | 3 | 11 | 3 | 17 | | Monitoring & notifications | 2 | 16 | 6 | 24 | | Hub & operator | 1 | 7 | 13 | 21 | | Business & legal | 4 | 0 | 3 | 7 | | Process & tooling | 0 | 4 | 83 | 87 | | **total** | **27** | **130** | **169** | **326** | ## The top 29 — every P2, open list and roadmap together Order: severity first, then "a household meets it", then cost (small first). Size: XS < S < M < L. | # | ID | Category | Size | Household meets it? | What is wrong or missing | |---|---|---|---|---|---| | 1 | R-508 | Install & onboarding | XS | yes | The hub does not warn when a customer who waits for a box has no e-mail address. | | 2 | R-509 | Install & onboarding | XS | yes | A new box for an existing customer may not send the connect e-mail. Fix shipped; never seen live (VERIFY). | | 3 | R-604 | Box system & updates | S | yes | A per-customer version floor can keep one box out of every fleet update, silently. | | 4 | R-784 | Business & legal | S | yes | SparkyFitness forbids commercial use; the author's written permission is needed. | | 5 | R-789 | Business & legal | S | yes | Tandoor's licence may forbid selling a service built on it; the authors' permission is needed. | | 6 | R-342 | Backup & restore | S | yes | Nothing protects the off-site backup data if maintenance on that server goes wrong. | | 7 | R-813 | Business & legal | S | yes | The website collects personal data but has no privacy notice, no terms and no imprint. | | 8 | R-243 | Monitoring & notifications | M | yes | A box that waits for its recovery key stops off-site backups, and nobody is told. | | 9 | R-95 | Backup & restore | M | yes | A box can delete its own off-site backups, and no older copy can be read back today. | | 10 | R-436 | Backup & restore | M | yes | The provider's "append-only" lock (a box may add but not delete) is untested. **Its check is due 2026-10-06.** | | 11 | R-726 | Backup & restore | M | yes | A returning customer's new box makes no off-site backup until someone presses a hidden reset. | | 12 | R-366 | Backup & restore | M | yes | After a reinstall the box cannot read its older whole-machine backups, and it reads as a test failure. | | 13 | R-32 | Backup & restore | M | yes | Resetting a customer leaves their old encrypted off-site data behind, unseen and uncounted. | | 14 | R-105 | Backup & restore | M | yes | Two records a whole-box recovery needs may still be empty on the hub; not checked again. | | 15 | R-518 | Backup & restore | M | yes | "Back up now" stops every app for minutes while a slow second backup runs. | | 16 | R-519 | Backup & restore | M | yes | After an interrupted backup, a restore point shows a newer time than its files. | | 17 | R-638 | Backup & restore | M | yes | Restoring a database copy from before an update can fail on top of the newer database. | | 18 | R-528 | Monitoring & notifications | M | yes | An app killed for lack of memory is often not reported. | | 19 | R-777 | Security & access | M | yes | Emby and Jellyfin treat internet visitors as home-network visitors and skip their remote limits. | | 20 | R-304 | Backup & restore | L | yes | A household's correct recovery code for old backups is rejected as wrong. | | 21 | R-812 / R-808 | Box system & updates | L | yes | Nothing ever installs operating-system security updates on a box (host, guest, Docker engine). | | 22 | R-809 | Business & legal | M | yes | Contract, data-processing agreement, billing and invoicing do not exist yet. | | 23 | R-135 | Security & access | S | no | The hub skips its forged-request check when no session cookie is sent. | | 24 | R-802 | Business & legal | M | no | A lawyer must review the list of non-open-source licences. | | 25 | R-133 | Security & access | M | no | Every copy of the hub database holds every box's root console password in readable form. | | 26 | R-173 | Hub & operator | M | no | The hub database, which holds recovery secrets for every box, has no scheduled backup. | | 27 | R-530 | Box system & updates | M | no | Host agents update only by a signed job per box, and nothing lists which boxes are behind. | | 28 | R-232 | Backup & restore | L | no | The server that runs the hub keeps all its backups on itself, nothing off-site, and a failure alerts nobody. | (R-808 and R-812 are one item: the roadmap intention and its finding. 28 lines, 29 rows.) ## Five work themes (about one session each) 1. **Off-site backup safety** — R-436, R-95, R-342, R-243, R-726, R-366, R-32, R-105, R-304. The household's files and photos sit in the tier whose credential can delete. Start with R-436's measurement (due 2026-10-06), then the cheapest step that stops a box deleting its own history. 2. **Box system security updates** — R-812 / R-808, R-604, R-530. A spike first (what the agent may run, what a half-done update leaves), on a throwaway box. Nothing exists today. 3. **The hub's own safety** — R-133, R-135, R-173, R-232. Operator-side; no household meets it directly, but a hub loss or leak touches every box. R-232 is on DooPlex, which needs an operator word before anyone touches it. 4. **Honest backup and app behaviour** — R-518, R-519, R-638, R-528, R-777, R-508, R-509. Smaller items a household meets; good for a session after theme 1. 5. **Business and legal** — R-809, R-813, R-784, R-789, R-802. **Yours**, not a CC session. CC drafts a text when you ask. It can run beside any other theme. ## The decision **Which theme does the next session start with?** | | A — Off-site backup safety (recommended) | B — Box system security updates | |---|---|---| | What it does | Measures the provider's append-only lock (R-436), then closes the biggest data risk: a box that can delete its own off-site history (R-95). | A spike on a throwaway box: what update path is safe for host, guest and Docker engine. Then a design. | | What it costs | One session. Touches the off-site test account, never a customer's data. | One spike session plus a later build session. Touches only a Tier-0 box. | | Why | The largest data risk the list has ranked first since July. The household's own files sit there. | Boxes stay in homes for years. Today they never receive a security patch. | | If you decide nothing | On 2026-10-06 the dated check turns red and refuses every push to this repo until the measurement is done or the date is moved. | Boxes keep the packages they were installed with. Nothing breaks this week; the risk grows every month. | **My pick: A.** It has a hard date in three days, it guards the household's data, and it needs no new mechanism. B is next. ## Rows that wait on you (18) R-132 (change the hub password), R-169, R-210, R-503, R-504, R-508, R-526, R-530, R-719, R-769, R-770, R-771, R-779, R-784, R-789, R-802, R-804, R-813. The P2 ones are in the top list above. Each row says what it needs from you. ## Rows marked VERIFY (11) — may already be finished; nobody proved it R-274, R-282, R-284, R-287, R-509, R-527, R-602, R-621, R-814, R-815, R-817. Each carries, at the start of its state, what suggests it is finished and the evidence pointer. Close one only after checking it against live source.