Files
felhom.eu/documentation/audits/CAMPAIGN-6C-2026-07-14-PROMPT.md
T
admin 671bd3fd91 CAMPAIGN-6B: note credential fully reverted at cleanup
Break-glass credential undone — original customer-claimed hash restored on the
demo controller; box back to pre-6B credential state.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A45Qop8YY8tS94bz63LFne
2026-07-14 13:32:14 +02:00

5.0 KiB

CAMPAIGN-6C — supervised browser planes + deep backup tiers + the C6B-F1 fix-verify

Class: Continuation of CAMPAIGN-6B. The three split buckets below need either a supervised browser (6B was unattended; the browser-select step blocks with no human) or deliberate deep setup budget 6B preserved for its wrap. Findings only unless a TASK/RUNBOOK says otherwise. Output: felhom.eu/documentation/audits/CAMPAIGN-6C-<date>.md (same structure). Continue the ledger

  • evidence at 180:~/campaign6/. Record a new seed.

Pre-existing state (verify at P0, don't trust)

  • controller 0.129.0 both guests · agent 0.88.0 both hosts (caps 63/63) · hub 0.54.0.
  • campaign6 share + sonarr may be GONE — 6B's final cleanup removed them (product flow + exportfs -u + rm -rf /mnt/5_hdd/felhom-campaign6). If a NAS app is needed, re-enroll a fresh campaign export first (verify-before-commit; pre-create the userdata tree per C6-3).
  • Credential: 6B REVERTED the demo controller to its pre-6B customer-claimed credential (break-glass undone; the settings.json.c6b-bak backup was removed). A fresh CC session will NOT know the plaintext — re-establish a known credential via break-glass (write a bcrypt hash to settings.json password_hash, back up the original first, revert at cleanup) or the reset flow, and ledger it. Viktor rotates the customer-claimed credential independently.
  • Access unchanged: SSH=/c/Windows/System32/OpenSSH/ssh.exe; 180=DooPlex, felhom-pve=demo, root@192.168.0.152=drill. Controllers via docker exec felhom-controller curl 127.0.0.1:8080 OR claude-in-chrome (session started AFTER the bridge connected).

The one thing to watch above all: C6B-F1 (CRITICAL, from 6B)

.fab export produces hollow, data-free bundles for ${USERDATA_PATH} needs_hdd apps (12/13 media apps). Root cause + fix direction are in CAMPAIGN-6B-2026-07-14.md. If project Claude ships a fix, 6C must red-proof it live: deploy a ${USERDATA_PATH} app with ≥1 GiB varied data → export → the bundle must now contain the userdata AND named volumes → download → delete → upload → import → byte-compare every file vs a pre-export sha256 manifest = zero mismatches. This is the full-circle byte-compare 6B could not run (blocked-by-bug). Until then, re-confirm the bug still reproduces.

PHASE 3 — browser planes (claude-in-chrome; supervised)

Session started AFTER the bridge connected; the operator picks the browser at the select prompt.

  • 3A escrow wizard, full browser pass (drill): preflight all-green + Hungarian details (no raw English leak), warnings, re-auth, run, reveal, typed-back with the two highlighted words (read from screen), manual hide/show toggle, finish → auto-confirm flips + hub row hash matches (server-side check via 180). Then re-claim → 410 UI; unclaimed → TTL → unclaimed_void screen; F-C live (phase:none claim → clean 4xx UI, not 502); out-of-band CLI ceremony w/o staged secret → stale card fires → wizard clears it. (Drill R scratch + uncommitted.)
  • 3B live session/CSRF UX (both boxes): session expiry mid-wizard and mid-upload → JSON 401 on /api/, redirect on pages (6B proved the codes via curl; 6C proves the UX); zero-toggle honesty + inline two-step confirms visible. (Native-alert sweep already PASS in 6B — spot-check only.)
  • 3C hub 8-tab customer-detail ring (hub credential = campaign credential): hash-nav across all 8 tabs; auto-refresh scoped to live tabs; dirty-form suppression (start editing → refresh holds); events tab under volume; no stale-host deletion against real hosts (synthetic row only).

PHASE 4-deep — backup tiers depth (needs setup budget)

  • F7 LIVE precise cut: 6B code-confirmed the atomic .tar.tmp→rename guarantee but could not time a live 6 s cut (no app had a >6 s NAS volume dump). Fabricate one: a NAS app with a large docker named volume (or inject ≥1 GiB into one), POST /api/backup/run, exportfs -u at T+~6 s, confirm the last-good .tar survives, no 0-byte artifact, success:false is the only signal, then re-export → recovers.
  • restic stale-lock self-heal (kill controller mid-offsite-run → next run self-heals the lock); Tier-3 "Távoli mentés most" additive + quota bar; tier-1 replace-semantics; offsite restore-to-verify to a scratch campaign app → byte-identical; volume-only app gets its tier-2 secondary (F6 fix); per-app toggles round-trip; snapshot coherence across the four sub-pages.

PHASE 5-rest — regression

  • Dead-app alert + email on a killed campaign container (cooldown math vs the run's emails).
  • Re-confirm F1/F2 residue is still clean if any campaign share was re-enrolled + removed in 6C.

Wrap — same completeness gate as 6A/6B

Checklist table (PASS/FAIL/FINDING/→6D); verdict; ranked findings + repros; timings; deviations; box state; morning recovery; evidence index. Commit the doc + overwrite felhom.eu/REPORT.md. No credential, no R, no blob committed. Final: leave the campaign credential for Viktor to rotate, or rotate it if this is the last leg.