Files
felhom.eu/documentation/audits/r553-2026-09-17

R-553 + R-563 — nothing decides by reading a Hungarian word (controller v0.251.0), 2026-09-17

Method: endpoint-level inside demo-hp guest 9201 (no browser on DooPlex) — https://127.0.0.1:443 with Host: felhom.enkisfelhom.hu and a session. CSRF tokens in the saved files are <CSRF-REDACTED>.

what result
pages before (0.250.0) → after (0.251.0), Hungarian live/page-comparison.txt: /launcher and /monitoring identical; /backups/remote identical apart from the new data-status attribute and the one poll line (+23 bytes); /dashboard differs only in live numbers (CPU, load)
the deploy refusal, live POST /api/stacks/adventurelog/deploy on an ALREADY DEPLOYED app → 409 before and after, byte-identical message; the app kept running (Up 10 hours (healthy))
the 400 refusals not provoked live — a live probe starts an install (one did; it was stopped and removed the same minute, see REPORT.md). Covered by TestR553_DeployProducersCarryKindAndKeepTheirWords through the real DeployStack, and by the status table
site 2 (quota) and site 4 (stale note) not provoked live: demo-hp's off-site tier reports last_status: ok with no warning, and provoking either would mean filling a quota or clearing the selection on a live box. Red-proofed unit tests carry them
site 3 (disk warning placement) not visible live: the box has no storage warning (alert-banner blocks 0 on all three pages, before and after). The placement is unit-tested with a translated warning
site 5 (R-563) after: id="offbox-status-value" data-status="ok", poll reads v.dataset.status === 'running'; before: no attribute, poll read textContent.indexOf('Fut')
the hub wire live/hub-report-health.txt: the health block on 0.251.0 carries exactly issues, status, warnings — no kind reached the hub. warnings is [] on this box before and after (it has no warnings), so the BYTES with warnings present are pinned by TestR553_HubReportWarningsAreUnchangedOnTheWire instead
settings offbox block identical before and after; last_warning_kind absent (no warning to carry one)

Unit evidence: redproofs.txt (every site's pre-fix predicate restored and watched failing, then restored), site5-fixture-diff.txt (12 re-captured fixtures differ ONLY by the attribute and the poll line; the other 94 byte-identical), green-gate.txt.

Detector re-run (scripts/i18n_inventory.py): template compares 1 → 0; one Go compare left (offbox_handlers.go:132, the known false positive — an [INFO] log line) and one indirect compare left (handlers.go offboxStaleWarningMarker, the deliberate legacy fallback, row R-570). Decoys planted in a template and in Go were both convicted, then removed.

Teardown: machine — demo-hp guest 9201 on hu, controller 0.251.0, fleet floor unchanged (0.250.0), no golden; the password file and scripts shredded/removed; evidence pulled here. Host — transfer files removed. Hub — nothing written; the DB copy read for the report lines shredded on DooPlex. One thing was changed and put back: a first live probe of the deploy refusal used an app with no empty required field and therefore INSTALLED vaultwarden; it was stopped and removed (data volume it had just created removed with it) within two minutes, and the probe was rewritten to the 409 form.