Four paper debts and one fact given a reader. Hub-only — nothing to bake. A4 — the entry about "the tester's machine" named a risk correctly and labelled it in a way that invited deleting it. Established from the hub's own store: `peti-felhom` is a REAL machine (482 reports, 2026-02-27 → 2026-07-15, a named person's own box) and the 3.6 GB with no key and no backup is real. `david` → `tester-1` is a DIFFERENT record with no host, no escrow and no report, ever — deleted 07:55:49 and re-created 07:56:47 this morning. The prompt's premise conflated the two; the register now says which is which. A1 — R-312/R-313/R-303 recorded as DECIDED with their re-open triggers, and moved out of STATUS's "Waiting on you", which is now empty. A3 — day0-install §C.1 said pushing the installer publishes it. It has not since R-110. Corrected, with the two manifest pins named and an outside-verification command; the one copy that repeated it (a dated audit, true when written) carries a superseded note. A5 — standing rule 5: evidence comes off the machine at the end of the phase that produced it, before any revert. Earned twice in three days on the same box at the same point (R-320). Four homes, plus what to do when it is already gone. R-295 hub half — „Beállító kód" everywhere; „Visszaállító kód" retired. New `reenroll` mail kind so the mail names the page a REBUILT box actually shows („A szerver beállítása"), not the „Elfelejtett jelszó" page it has no login screen to reach. Naming only; the acceptance pin proves the secret is untouched. R-319 — the hub models `guest_net` after 23 days of receiving and discarding it. The signal is `heals_last_hour`, not `state`: a guest the watchdog keeps repairing reads healthy between repairs. `heal_succeeded` decoded too (R-260's lesson). Unknown is never drawn as healthy — three absences, three sentences. No alarm, deliberately. Three red-proofs, mutations asserted applied. Wire-gate checked tags 182 → 190. B1 — the operator's 2026-08-12 dispositions were NOT in the register; they are now. Third allowlist kind for the five ruled "no reader wanted"; `reporting_disabled` reclassified redundant. 8 read · 5 deliberately unread · 1 redundant · 6 still owed. Also filed: R-321 (a deliberately-silent box still alarms stale/down — the checker is age-only, and decoding the flag would not have fixed it), R-322 (the claim guard has never scanned the hub; a hand scan returns zero, so it is a scope gap, not a defect).
5.5 KiB
STATUS — what works, what's broken, what's next
Updated 2026-08-13 (evening — the small debts, and one fact given a reader).
A view, not a source.
documentation/backlog/OPEN-ITEMS.mdis the authority; this page restates part of it in plain words, and nothing may exist only here. Items, not paragraphs. One screen. If it does not fit, it belongs in the register instead.
Waiting on you
Nothing. All three questions that stood here were answered on 12–13 August and have moved to Decided below. A decided question left in the deciding list is how a person loses track of what is actually waiting.
Decided — and what would reopen each
A decision with no trigger becomes a permanent silence, so each one names what would make us look again.
- Getting old backups back yourself: NOT BUILT, deliberately. A customer in that position is a support conversation, and we can do it by hand. Reopens if: a real customer actually asks — one request from a person who is not us. (register: R-312)
- The unopenable old copy on
demo-felhom: KEPT, as a test fixture. Not for sentiment: it is the only state in existence where a set-aside store is present and cannot be opened, which is the case any future handling of lost backups has to face honestly. Delete it when: that work ships, or is abandoned. Until then it is a fixture, not an accumulation. (register: R-313) - A machine in two kinds of trouble says both things: LEFT AS IT IS. Its real-world likelihood is unknown, and hiding one card risks hiding a real second failure. Reopens if: it is observed happening outside a constructed test. (register: R-303)
What works
Both demo machines are home, healthy and reporting on the approved pair — controller 0.214.0, agent
0.129.0, delivered by the floor rather than by hand. Off-site is credentialed on demo-hp and its
repository still opens with the machine's own key. drill-r50 is reverted to virgin, powered off.
What the fleet actually is, because two summaries have now been misread: the hub holds five
customer records and three machines. The machines are demo-felhom and demo-hp (both ours, both
disposable) and drill-r50 (a nested drill VM on DooPlex, reverted and powered off). peti-felhom
is a real machine we have not heard from since 15 July and has no host record. tester-1 is a
record with no machine — created 13 August, no host, no backups, nothing to lose.
Shipped
- The removal now genuinely reverses the installation (R-316,
installer-v1.28.0published). The second reinstall used to hit our own leftover; it was watched failing on the cycle that actually fails, then watched passing. - A correct recovery code is no longer called wrong (R-311, three components). If a customer types the code for an older set of backups, the machine now checks the packages we kept, recognises it, and says so: your code is correct, it belongs to an earlier package, we kept it, your current backups are fine, write to us. It deliberately promises no restore, because there is no button yet.
- The drive can be re-attached after a reinstall (R-280), and the orphan card and the countdown banner stop promising retrieval they cannot see is still true (R-294, R-299, R-302).
- One name per secret — now both halves (R-295). The dashboard code is „Beállító kód" everywhere, on the machine and in the hub's emails; „Visszaállító kód" is retired. It collided with the escrow „Helyreállítási kód" and cost a real code.
- The hub can see whether a machine's guest still has working networking (R-319, first reader built against R-264). A machine quietly repairing its own network over and over is now visible instead of being a green tick; a machine that does not report it is drawn as unknown, never as healthy.
- The countdown on
demo-felhomis cancelled on your ruling (R-307). Nothing was deleted.
Broken, or knowingly incomplete
- Peti's machine has no recovery route at all — see the
PETIrow. This is a real machine belonging to a real person, not one of ours and not a record: it reported to the hub for four and a half months and has been silent since 15 July, when its host record was deleted. There is no key, no off-site copy and no local backup. If that drive fails, everything on it is lost. First act of the visit: copy the ~3.6 GB off before anything is reinstalled — it is currently the only copy in existence. Whether it stays parked is your call and is deliberately left open. - Kept backups can be opened — but still only by us (R-304 partly closed, R-312 decided-not-built). Today the honest answer is "your code is right, write to us" — and we can.
- The agent picks dnsmasq by looking at a file another package owns (R-317). The box installs fine; only LAN name resolution goes missing, and quietly. One line, deliberately not taken tonight.
- The storage page has its own separate reason for showing an empty list (R-298), untouched.
- Three more facts the machines send still have no reader (R-264): a staged-but-unapplied agent update, how deep a restore test actually went, and the two backup-integrity timestamps. Five others are now recorded as deliberately unread, which is honest rather than fixed.
Working on next
The three remaining R-264 readers, now that one has been built and we know what one costs; then R-317 (one line in the agent); then the 2026-08-09 batch (R-279 … R-292), still untriaged against everything since.