Files
felhom.eu/documentation/audits/evidence-recovery-code-2026-09-16/phaseA-redproofs.txt
T
admin d124c77e17
gates / gates (push) Successful in 21s
R-543 closed: the household is asked for the recovery code (controller v0.245.0)
The tier-3 pause is the zero-knowledge escrow design and is untouched. What was
missing was the ASK, while the backup page promised the copy that had never run.

- VOLUNTEER-first-hour.md: a new step 6, right after the dashboard password and
  before the first app - what the code is, where, write it on PAPER, and that
  Felhom cannot get it back for them. Sections 6..12 renumbered to 7..13.
- day0-install.md A.2b: the operator step for a REBUILT box, which was missing.
  Acknowledged delete -> the hub re-issues by itself; otherwise ONE press of
  "Re-issue PBS credentials" (F-14 ruling 2026-07-13, hub/internal/web/pbsdr.go).
  This is the correction to last night's "zero presses" note.
- 07-backup-architecture.md: 6.1 records tier-3's paused state as a DESIGN, and
  2 records that the household is asked from first login.
- capability map: the first-hour row's last gap closed, with what it still does
  not claim (no volunteer has walked the ask from the written guide).
- register: R-543 CLOSED with the live measurements; R-545 filed (nothing
  un-configures an off-site target). R-511 was already closed yesterday.
- STATUS: the answered publish question removed (1.28.0 is live), readiness yes.
- evidence: red-proofs, the two-box live validation, teardown on three layers,
  and both of my own mistakes in this session.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-16 21:20:51 +02:00

49 lines
3.8 KiB
Plaintext

## R-543 red-proofs — controller v0.245.0, 2026-09-16, DooPlex
## Each fix was BROKEN first and the test was watched convicting it. A test never seen failing has
## not been shown to test anything.
### RED-PROOF 1 — the reminder bar
Break: delete `s.addEscrowBanner(data, r)` from executeTemplate (internal/web/server.go).
That is the whole wiring: the bar hangs off the single render choke point, so removing one line
returns the product to the measured 2026-09-16 state (a paused off-site tier, and silence).
--- FAIL: TestR543_A_PausedBoxAsksOnEveryPage (0.20s)
r543_escrow_banner_test.go:72: R-543: /dashboard does not tell the household the off-site copy is PAUSED. The tier is on, nothing is running, and the page is silent about it
r543_escrow_banner_test.go:76: R-543: /dashboard states the pause but names no route to end it — a reminder without its door is the shape that left a fresh box waiting indefinitely
r543_escrow_banner_test.go:72: R-543: /launcher does not tell the household the off-site copy is PAUSED. The tier is on, nothing is running, and the page is silent about it
r543_escrow_banner_test.go:76: R-543: /launcher states the pause but names no route to end it — a reminder without its door is the shape that left a fresh box waiting indefinitely
FAIL gitea.dooplex.hu/admin/felhom-controller/internal/web 0.208s
Note BOTH pages fail. That is the point of the hook placement: a per-handler helper would have
covered the three pages someone remembered, which is the seam-built-but-never-wired shape.
### RED-PROOF 2 — the tier-1 sentence
Break: return the v0.244.0 wording from driveFilesNoteFor before the state switch, i.e. compute the
sentence from the app's shape alone, exactly as v0.244.0 shipped it.
--- FAIL: TestR543_Tier1Sentence_PausedStateDoesNotPromise (0.00s)
r543_tier1_sentence_test.go:38: R-543: the sentence claims the files ARE protected while the copy is paused for the recovery code. This is the exact promise a fresh box read for its whole first day: "Az alkalmazás fájljait a távoli másolat (és a második meghajtó) védi — ez a helyi mentés a beállításokat és az adatbázist tartalmazza."
r543_tier1_sentence_test.go:42: R-543: the paused sentence must say the copy WOULD protect them and that it is waiting; got "Az alkalmazás fájljait a távoli másolat (és a második meghajtó) védi — ez a helyi mentés a beállításokat és az adatbázist tartalmazza."
r543_tier1_sentence_test.go:46: R-543: the paused sentence names no route out (link="" text="")
FAIL gitea.dooplex.hu/admin/felhom-controller/internal/web 0.007s
### RESTORED
go test ./internal/web/ -run 'R543'
ok gitea.dooplex.hu/admin/felhom-controller/internal/web 0.895s
### The filter was proven to match (the `-run` trap: a pattern matching nothing prints `ok`, exit 0)
=== RUN TestR543_A_PausedBoxAsksOnEveryPage --- PASS (0.29s)
=== RUN TestR543_B_EscrowedBoxIsNotNagged --- PASS (0.19s)
=== RUN TestR543_C_UnconfiguredBoxIsNotNagged --- PASS (0.20s)
=== RUN TestR543_D_DismissIsForThisVisitOnly --- PASS (0.28s)
=== RUN TestR543_Tier1Sentence_ActiveStateKeepsThePromise --- PASS
=== RUN TestR543_Tier1Sentence_PausedStateDoesNotPromise --- PASS
=== RUN TestR543_Tier1Sentence_NoCopyAtAllSaysSo --- PASS
=== RUN TestR543_Tier1Sentence_SecondDriveCounts --- PASS
=== RUN TestR543_Tier1Sentence_NoFileLegsNoSentence --- PASS
### Fixture validity (an instrument that can lose its precondition measures nothing)
escrowServer asserts backupMgr.OffboxConfigured() itself before any assertion runs: the target is
enabled and valid AND the ssh_key + repo_password files exist on disk. A fixture that silently fell
back to "not configured" would make every one of these tests pass for the wrong reason.