Files
felhom.eu/documentation/audits/night-2026-10-04/PREDICTION.md
T

3.9 KiB
Raw Blame History

Prediction table — written 2026-10-04 ~21:45 CEST, BEFORE anything ran

All times CEST (the controller's scheduler is Europe/Budapest). Sources: each controller's "Daily job … scheduled for" lines (baseline/schedule-*.txt), the agent journals of the last 7 nights, 11 §5.5 / §8.1, 07 §6.1.

The 20-hour gap

The marker /var/lib/felhom-agent/os/last-night-run is written only by a night-trigger leg. It does not exist on either demo box (both: No such file): every OS run today was debug or signed, and the hub has no night report from either demo box (os_reports: only Tester 2's two). Prediction: the gap skips nothing tonight on either box. No marker to clear on demo-felhom — §1.2's "clear the marker" step is not needed (and no documented route exists to clear it; none was invented).

Per box

Box Leg Expected Why
demo-hp db-dump 02:30 scheduler
demo-hp tier-2 copy + fill-watch 03:30 scheduler
demo-hp metrics-prune 04:00 scheduler
demo-hp off-site 04:15 scheduler
demo-hp whole-guest backup (local) ~04:35 → ~04:40 last nights: 04:34:55 → 04:39:41
demo-hp OS leg guest → host → Docker (ring 0) ~04:40 → ~04:45, right after the backup AfterPrimaryBackup; no gap marker. Guest: pending Debian fixes if any appeared since today; host: same; Docker: select pending-docker = nothing newer than 29.8.2 expected → "nothing". The root-owned ring0_slow_lane mark is ON on both demo boxes (read 21:47: os-trust.json), so the Docker step runs unsigned and should report "nothing".
demo-hp controller 04:30 self-update no action current 0.293.0 = floor 0.293.0
demo-hp offsite-abandon-sweep / offsite-proof / offsite-integrity 05:10 / 05:30 / 06:00 scheduler
demo-felhom db-dump / tier-2 / off-site 02:30 / 03:30 / 04:15 scheduler
demo-felhom whole-guest backup (felhom-backup) ~07:45–07:55 — after the 06:30 stop last 7 nights 07:37 → 07:49, drifting +2–3 min a night
demo-felhom OS leg after ~07:50 — not watched follows the backup
Tester 1 (new box) first whole-guest backup + OS leg minutes after enrolment, not at night Tester 2 (2026-10-04): backup 14 min after enrolment, night-trigger OS leg right after (49 + 106 packages)
Tester 1 its first OS leg's package count 0 guest, 0 host — ring 1 installs only an approved release, and none is in force; it reports the pending ones (~49 guest from the golden) as "not covered" 11 §5.3, golden 0.293.0
Tester 1 night db-dump / tier-2 / off-site 02:30 / 03:30 (no 2nd drive → skipped) / 04:15 scheduler
Tester 1 off-site night one — decision 78 04:15: the orphaned old repository (earlier tester-1 boxes) is SET ASIDE, never deleted; a new repository started; one household line decision 78 (controller v0.291.0)
Tester 1 whole-guest at night not due (the install-time one is < 24 h old) cadence
Tester 1 OS leg at night none — the install-time leg wrote the marker < 20 h before the gap
Tester 2 anything offline since 18:06 UTC — nothing hub STALE

Approvals

No guest or host release is in force (today's test approvals were cancelled at 18:20 UTC). The ruled rule: 24 h since the set was first seen AND one night run on EVERY ring-0 box since then. Guest set first seen 11:07 UTC, host 12:24 UTC (if tonight's leg installs something, the set changes and the clock restarts). demo-felhom's night run comes ~07:50, so the earliest real approval is after ~11:07 UTC tomorrow, only if neither box's set changes tonight. Docker: the operator's release stays; no new set expected.

Mails expected tonight

None to a household from the demo boxes (a normal night). Tester 1: the household line for the off-site set-aside; the operator mail for it. Operator: host_stale / node_stale for Tester 2 already sent; nothing more unless it returns.