The live proof: the box's own "send test notification" button pressed twice, 74 seconds apart, on demo-hp. Reporting `en` it produced "[Felhom] Test notification / Dear Customer, ..."; switched to `hu` it produced "[Felhom] Teszt értesítés / Kedves Ügyfél! ...", byte-for-byte the v0.117.0 literal. The operator's copy is identical in both, which is the half worth stating. R-583 (closed, hub v0.118.1): the test mail was the one customer mail that did not follow the language, and it is the mail an operator would use to CHECK that the language works. The surface you would use to check a feature is the one most worth checking first. R-584 (open, P2): five probe scripts from slice 2's releases B/C/D were still in the guest's /tmp carrying the controller password INLINE. The rule to delete them exists, was loaded, and was not followed three times running - so the rule is not the mechanism. All shredded; whether to rotate the shared demo password is the operator's call. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Slice 3 Part A — hub v0.118.0 / v0.118.1, live evidence (2026-09-18)
Method: endpoint-level, plus one real e-mail read in the operator's own inbox. No browser on DooPlex. Nothing was installed, nothing removed; the deploy endpoint was never touched.
1. The wire already worked — measured BEFORE writing any code
Read-only copy of the live hub.db (+ -wal, or it is hours stale):
demo-felhom 14:12 UTC language='hu' controller 0.255.0
demo-hp 14:09 UTC language='en' controller 0.255.0
drill-r50 / peti-felhom / tester-1 language=<ABSENT> (0.213.0 / 0.115.0 / 0.245.0)
The positive and the negative control in one read: every box on ≥ 0.247.0 publishes the field, every older one sends nothing at all — which is the case the empty default exists for.
2. The migration applied
reports.language present: True
customer_configs.language present: True
customer_configs.language = 'hu' for all five customers (the default backfill)
The first reports written by the NEW hub, minutes after the sync, carry the denormalised value:
demo-felhom id=25717 14:22:59 language='hu'
demo-hp id=25718 14:23:00 language='en'
Rollback, written before the sync: revert the manifest tag to 0.117.0 and sync. The two columns stay and need no undo — v0.117.0 neither reads nor writes them and both carry a DEFAULT, so every INSERT the old binary performs still succeeds. Rolling back the image is the whole rollback.
3. One real e-mail, both directions, 74 seconds apart
The path is the product's own: sign in to the box, press Send test notification on the
notifications page (POST /settings/notifications/test) — which is what a customer's own click does.
The box POSTs event_type=test to the hub, and the hub composes the mail.
Box reporting en — 14:30:43 UTC, to the household address drill@felhom.eu:
Subject: [Felhom] Test notification
Dear Customer,
This is a test notification from the Felhom monitoring system.
Notifications are working correctly.
Best regards,
Felhom.eu monitoring
The same button, box switched to hu — 14:31:57 UTC, same address:
Subject: [Felhom] Teszt értesítés
Kedves Ügyfél! Ez egy teszt értesítés a Felhom monitoring rendszerből.
Az értesítések megfelelően működnek. Üdvözlettel, Felhom.eu monitoring
The Hungarian is byte-for-byte the literal that shipped in v0.117.0 — it was extracted into the bundle by script, never retyped.
The operator's copy is identical in both, to admin@felhom.eu:
[Felhom] ✅ demo-hp: teszt / operator channel OK. That is the half worth stating: the household's
language changed twice and nothing the operator reads moved.
4. What this did NOT prove
message_customerhas no live proof yet. No box sends it until controller v0.256.0 (Part B). The hub half is covered by tests only.- The
testmail bypassesFormatCustomerEmail, so this proof exercises the bundle and the language resolution, not the event-mail wrapper. The wrapper's live proof waits for Part B. - Nobody looked at these mails in a mail CLIENT. They are plain text; the bytes above are what was sent.
5. A lapse, recorded
Earlier in this same session (slice 2 releases B/C/D) I left five probe scripts in the guest's
/tmp — probeB.sh, probeB2.sh, probeB3.sh, probeC.sh, probeD.sh — and they carried the
controller password inline. The standing rule says a credential-bearing helper is deleted from
/tmp on both host and guest when done; they sat there for hours instead. Found while cleaning up
after this proof, by grepping my own litter for secret-shaped strings before deleting it. All are
now shredded, along with this run's password file on the host, the guest and DooPlex. This run
used a file→file password (never an inline literal), which is why its own scripts were clean.
6. State at the end
Hub 0.118.1, Synced/Healthy, clean startup log. demo-hp back on Hungarian. Nothing
installed, nothing removed, no floor change, no golden. Guest /tmp clean.