Files
felhom.eu/documentation/audits/update-night-2026-09-21/13-probe-sweep-sharpened.txt
T
admin da20722e76
gates / gates (push) Successful in 27s
Update night 2026-09-21: Phase 0 and Phase 1 evidence, the drill method, and two instrument fixes
INTERIM CHECKPOINT — evidence off the machine at the end of the phase that produced it (R-320),
not at the end of the session. Phases 2-5 follow in a later commit.

Phase 0, all three mechanisms proven with their controls:
- the fleet floor to 0.261.0 with its declared MinAgent — both demo boxes in 13 s, the hub
  logging `managed floor SERVED ... from declared (golden 0.258.0)`.
- a PRIVATE DRILL CATALOG (admin/app-catalog-drill), so that broken, dummy, cross-repo and
  engine-major edges can be measured without the live catalog ever carrying one. Positive
  control quoted, and two negative controls: the live catalog's main and both real boxes'
  caches unchanged.
- a throwaway image store on the scratch guest, which is what makes an UNATTENDED HOLD
  measurable at all: an edge that PASSES the within-a-major test and still fails.
  CompareImageRefs was proven to order host:port/ references by RUNNING it (4 positive cases
  + 1 negative control), not by reading it.

Phase 1: real within-a-major upstream edges walked on guest 9202 through the product's own
guarded Update, each app seeded and read back through its OWN front door (R-156), with a
per-edge verdict record in 09's shape. `inconclusive` is never collapsed into `failed`.

TWO INSTRUMENT FIXES, both in this repo's own evidence code:
- 00-api-recipe.md said the app page is /app/<n>; it is /apps/<n>, and every call it described
  404s. Corrected, with the session-expiry note that cost the same time.
- unattended-caller.py's follow() read update_phase/updating off the API ENVELOPE, so both were
  always None and EVERY followed update ran to its 900 s timeout and was then recorded
  `timeout` and never-press-again. Fixed before B1 relied on it. R-623.

No controller, agent or hub code was written. The live catalog carries no broken reference.

Gates: repo_gates.py --fast — all 15 OK, exit 0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 21:17:46 +02:00

78 lines
5.6 KiB
Plaintext

PROBE SWEEP 3 — the SHARPENED rule, read from healthprobe.go rather than assumed
catalog f5f6a152b513, 2026-09-21, controller v0.261.0
type: http -> ANY response is healthy. ONLY THE PORT MATTERS.
type: api with NO expect block -> same as http (healthprobe.go:265). ONLY THE PORT.
type: api WITH expect.status -> the PORT, the PATH and the STATUS all matter.
So a probe/compose PATH difference is only a candidate when the type is `api` WITH expect.
actualbudget type=http port=5006 path=None ok
adventurelog type=api port=8000 path=/api/ PATH /api/ not in compose ['/api/\\'] (and expect={'status': 200}) <<< CANDIDATE
audiobookshelf type=api port=80 path=/healthcheck ok
bentopdf type=http port=8080 path=None ok
bookstack type=http port=80 path=None ok
calcom type=api port=3000 path=/api/auth/providers ok
calibre-web type=http port=8083 path=None ok
claper type=http port=4000 path=None ok
code-server type=api port=8443 path=/healthz ok
crafty-controller type=tcp port=8443 path=None ok
docmost type=http port=3000 path=None ok
emby type=api port=8096 path=/emby/system/ping ok
ghost type=http port=2368 path=None ok
gitea type=api port=3000 path=/api/healthz ok
glance type=http port=8080 path=None ok
gokapi type=http port=53842 path=None ok
grafana type=api port=3000 path=/api/health ok
gramps-web type=http port=5000 path=None ok
home-assistant type=api port=8123 path=/api/ ok
homebox type=api port=7745 path=/api/v1/status ok
homepage type=http port=3000 path=None ok
immich type=api port=2283 path=/api/server/ping ok
jellyfin type=api port=8096 path=/health ok
kimai type=http port=8001 path=None ok
komga type=api port=25600 path=/actuator/health ok
mealie type=tcp port=9000 path=None ok
n8n type=api port=5678 path=/healthz ok
navidrome type=api port=4533 path=/ping ok
nextcloud type=api port=80 path=/status.php ok
onlyoffice type=api port=80 path=/healthcheck ok
opengist type=api port=6157 path=/healthcheck ok
outline type=api port=3000 path=/_health ok
paperless-ngx type=http port=8000 path=None ok
papra type=http port=1221 path=None ok
plant-it type=api port=8080 path=/api/info ok
plex type=api port=32400 path=/identity ok
privatebin type=http port=8080 path=None ok
radarr type=api port=7878 path=/ping ok
rallly type=http port=3000 path=None ok
recipe-importer type=api port=8000 path=/health ok
romm type=http port=8080 path=None ok
seerr type=api port=5055 path=/api/v1/status ok
sonarr type=api port=8989 path=/ping ok
sparkyfitness type=http port=80 path=None ok
tandoor type=http port=8080 path=/accounts/login/ PORT 8080 not in compose ['80'] <<< CANDIDATE
termix type=http port=8080 path=None ok
uptime-kuma type=http port=3001 path=None ok
vaultwarden type=api port=80 path=/alive ok
vikunja type=api port=3456 path=/api/v1/info ok
wanderer type=http port=3000 path=None ok
wger type=http port=80 path=None PORT 80 not in compose ['8000'] <<< CANDIDATE
wishlist type=http port=3000 path=None ok
zipline type=api port=3000 path=/api/health PATH /api/health not in compose ['/api/healthcheck'] (and expect={'status': 200}) <<< CANDIDATE
CANDIDATES: 4 -> ['adventurelog', 'tandoor', 'wger', 'zipline']
LIVE RESULTS 2026-09-21 on guest 9202:
tandoor CONFIRMED DEFECT probe type http port 8080; the container listens on 80 ONLY.
Connection refused every time -> the box reads `unhealthy` while the app serves 200.
zipline CONFIRMED DEFECT probe type api + expect 200 on /api/health; zipline 4.6.1
answers 404 there. The COMPOSE healthcheck in the same file uses /api/healthcheck
and is green. The box reads `unhealthy` while /dashboard answers 200.
wger SUSPECTED, NOT MEASURED. type http, port 80; wger/server serves 8000 and the
template's own traefik label says 8000. Not deployed tonight.
home-assistant NOT a defect, MEASURED: type api with NO expect block, so any response passes —
/api/ answers 401 without a token and that is healthy. Edge PROVEN tonight.
adventurelog NOT a defect, MEASURED: type api + expect 200 on /api/ port 8000, reads `running`.