Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
5.7 KiB
REPORT — rulings 61 (calibre-web's generated login name) and 62 (the registry prune rule) — 2026-10-01 late afternoon
Evidence: documentation/audits/calibre-name-and-prune-2026-10-01/ (A, B, T); tools in audits/lockouts-2026-10-01/tools/
(a_calibre_name.py, lk.py, walk.py, repoint.py).
Read: 09 §3 decisions 45, 57–60; FIRST-ADMIN.md; rows R-752, R-750, R-753; audits/lockouts-2026-10-01/ B1, C1;
homelab-manifests HM-024. Baselines (~12:55 CEST): controller c1b123c64955, felhom.eu 8dab40c7a786, catalog
ed6df4b46b93 — matched. Register 390; highest R-755; last decision 60 → the rulings are 61 and 62.
The Part table
| Part | done / not done / changed | why |
|---|---|---|
| Rulings 61, 62 | done — recorded first (09 §3, CONTEXT) |
numbered 61/62: 58–60 were taken by the lockouts session |
| A1 measure | done — hex:N + type: secret already exist; calibre-web has no rename command |
— |
| A2 build | done — catalog e9f50b5 (template, hu + en copy, the freeze for those 5 strings, FIRST-ADMIN) |
no controller change |
| A3 proof on 9202 | done | — |
| A4 installed apps | done — and a defect found (R-757); demo-hp renamed TWICE | the box invented a name for the installed app |
| B prune rule | done — admin/misc-scripts c9d5ed5; test red-proofed; live dry-run |
the running hub added to "in use" (a version in use the ruling did not name) |
| B4 runbook line | done — RUNBOOK-manual-build.md §4.1a |
HM-024 lives in homelab-manifests (outside the felhom fence) |
| C release / golden | not needed | A1 needed no controller change |
Claims in the brief that turned out wrong (or right)
- "The controller can generate a login name" — right:
generate: "hex:N"(deploy.go:1187) gives lowercase a–f and digits;type: secretis filled when empty and shown behind „Megjelenítés". - "calibre-web can rename a user" — no command does:
cps/cli.pyoffers only-s user:password(ub.py:1350 password_change). Its admin page renames by settinguser.name(admin.py:2789, columnub.py:264, unique). Soafter_installupdates that column itself, then uses Calibre-Web's own-sfor the password. - "The OPDS door uses the same name" — right: OPDS is limited per name (
cps/main.py:75,request_username); a stranger's tries onadminnever touch the real name (measured: OPDS with the real name ok after 40 tries onadmin). - Where the prune script lives — in a repo already: Gitea
admin/misc-scripts(~/git/misc-scripts). The August run is in its own log:2026-08-22T16:02:20Z RUN action=prune … apply=true keep='7'. - "A template change reaches an installed calibre-web only through an Update" — wrong in a way that matters: the
template reached demo-hp at the next sync (images equal), and the box then INVENTED the new field's value
(
InjectMissingFields, R-757). My own first CHANGELOG line said "frozen until an Update" — also wrong.
Part A — calibre-web
9202 (drill catalog 4e18b3a, identical to live e9f50b5) — A/A1-9202-calibre-generated-name.txt:
install hold before the first start, opened by after_install at 11:02:17; a stranger polling admin/admin123 from the
deploy press got in 0 of 31 times; after_install record ok: true; the name 10 lowercase hex characters (read
through the page's reveal); app.db: 2 users, 0 named admin; name + password: form ok, OPDS ok; admin + the right
password refused; 40 wrong tries on admin at 3/min (11:02–11:16) → the household at once: form ok, OPDS ok; a wrong
password on the real name refused. Removed (drive data kept: R-756).
demo-hp — A/A2-demo-hp-rename.txt: renamed by the same method (values through stdin, never printed); a real login
over its traefik: name ok (form, OPDS), admin wrong. Then the box's sync injected a DIFFERENT ADMIN_USER into its
app.yaml (R-757, A/A3…); renamed again to the box's recorded value; verified (the earlier name and admin refused).
The name is in ~/.config/credentials as DEMO_HP_CALIBRE_USER (backup credentials.bak-20261001-calibre); never in a repo.
What any other installed calibre-web gets, and when: at the next catalog sync (≤ 15 min) its .felhom.yml gains the
field and the box invents an ADMIN_USER for it; its login stays admin (after_install runs only after a fresh install).
No other box has calibre-web today (the N100 does not; Tester-2 has not registered).
Part B — the prune rule
tests/test-prune-plan.sh: 7 checks pass (an in-use version older than the newest 20 is kept, with its reason; --keep
defaults to 20; dry-run; an unreadable in-use list → exit 3). Red-proofs: the same plan with an empty in-use list deletes
0.262.0; the in-use check removed from is_protected → 3 checks fail (B/B1-test-and-red-proof.txt).
Live dry-run (B/B2-live-dry-run.txt): in use — controller 0.285.0 (floor, golden's, baked), golden 0.285.0, agent
0.138.0 and 0.131.0, hub 0.126.0, felhom-samba 1.1.0. Would delete: felhom-controller 70, felhom-hub 8; every other
package nothing. No --apply. No token or password in any output (grepped for each value).
Rows
390 → 392. Closed R-750, R-752. Opened R-756 (9202 remove-with-data refused), R-757 (the box invents a new secret field's value for installed apps).
Teardown
- Machine: 9202 back on the live catalog (
repo_urlread back), the same six containers; calibre-web removed through the product (drive data kept, R-756). demo-hp: calibre-web's user renamed (the only change there). - Host: nothing. Hub: read only (the Configuration page, for the dry-run). Gitea: read only; one repo push
(
misc-scripts). Drill catalog reset to live (e9f50b5).