Files
felhom.eu/REPORT-mailer-source.md
T

4.1 KiB
Raw Blame History

REPORT — the contact mailer's lost source (R-902), 2026-10-08

NOT FOUND. Searched read-only on DooPlex, in the web editor, in all Gitea repositories and in Docker's build records. The running binary is now kept in git; a replacement plan is written (Part D).

REPORT-mailer-source.md, not REPORT.md: another session has uncommitted work in this repo.

Part A — the program's clues (documentation/audits/mailer-source-2026-10-08/)

  • go version -m: module github.com/felhom/contact-mailer (devel), go1.23.12, CGO_ENABLED=0, -ldflags="-w -s". No vcs.revision/vcs.time/vcs.modified.
  • Build paths in the binary: /build/main.go only — one source file, built in a container folder.
  • Image (containerd, k3s ctr content get): built 2026-02-05 10:40 +01:00 by BuildKit, two stages (builder at /build; alpine 3.20.9, user 1000, WORKDIR /app, COPY /build/contact-mailer .). The SLSA provenance blob the index names is not present in containerd.

Part B — places searched, each with its positive control

Place Found Control that proves the search worked
/build (from Part A) does not exist on DooPlex —
Web editor storage + its file history (through the running pod) only felhom.eu/manifests/contact-mailer.yaml func main found in agent code and in 2 History copies
All 10 Gitea repos, full history (-G sendViaResend|buildEmailHTML|felhom/contact-mailer) manifests only (homelab-manifests c9648cd 2026-02-05; felhom.eu 0b144a4d) the manifests are found by the same search
DooPlex disks, 55,548 *.go/go.mod/Dockerfile* files + name search, no depth limit only hub/cmd/hub/main.go (×2, for RESEND_API_KEY) and the pod's logs RESEND_API_KEY in the hub's main.go
Docker build cache (337 records) and build history oldest record 2026-09-28; history 7 days today's builds are listed

Excluded by name: kernel/runtime folders, Docker/containerd/k3s/kubelet/Longhorn/PBS stores, media folders — listed in SEARCH.md. Not reachable: the operator's Windows workstation.

Side finding: homelab-manifests history (c9648cd) holds an old Resend key literal. Compared by hash only, it is not today's key (rotated 2026-06-29, felhom.eu feea0606). Whether the old key was also revoked at Resend is not visible from here. No row.

Part D — the plan

documentation/audits/mailer-source-2026-10-08/PLAN-replacement.md: endpoints (/api/contact, /healthz, /debug/test), env, one mail per form with Reply-To, the limits read from the binary (5 files, 10 MB each, 20 MB total, name ≤ 200, message ≤ 10 000, rate limit, honeypot), a stdlib-only replacement with a version-tagged image, proof steps, switch-over and roll-back.

The binary is committed (contact-mailer.bin, sha256 775a23d5…30bb0, no key inside — searched): a DooPlex rebuild no longer loses the program.

Fixed without a row: the decoy suite now runs one at a time

During this task the gates ran in this session and in Felhom.eu session 1 at the same moment. scripts/test_gate_decoys.py edits real files and restores them from a copy taken when it plants; two runs at once left a planted fault behind — website/en/apps.html lost its Radicale logo line, twice, in the local copy (never pushed; the live page was checked: logo present). Restored from HEAD both times. The suite now takes an exclusive lock (.git/decoy-suite.lock) at start, so a second run waits; two runs of mine started 2 s apart both finished, one after the other (the waiting one: „all 73 decoys behaved"). The other session could not be messaged (not reachable from here).

Register

Rows before 130, after 130, opened 0, closed 0. R-902 stays open, NARROWED (search done; owner operator).

One decision for you

Is the February contact-mailer folder on your Windows workstation (for example under e:\DooPlex Server\)?

  • Pick: look there first. If it is there, I commit it as it is and only a tagged rebuild is left.
  • If you do nothing: the replacement is written from the plan in a later, attended task. The form keeps working.