Files
felhom.eu/documentation/audits/DRILL-soak-2026-08-31/phase5-mutated-cycle/04-tier2-r403-guard.txt
T
admin ab8b884763
gates / gates (push) Failing after 18s
soak phase 5: R-403 guard PROVEN live; R-412 CORRECTED down after measuring the mechanism
R-403 MIRROR GUARD - PASS, forced after the natural test evaporated. privatebin was
injected hollow at 23:34 to meet the 03:30 mirror; the 02:30 db-dump re-made its tar, so
by 03:30 the primary was complete and the guard had nothing to refuse. Forced instead on
calibre-web through the real Tier-2 path: the guard fired and named itself -
"unit leg SKIPPED ... The copy was PRESERVED rather than replaced with an empty one
(R-403). The other legs continue." Secondary byte-identical, 23 files, tar sha d7e7f422.

R-412 CORRECTED, AND I OVERSTATED IT WHEN I FILED IT. The first wording claimed the hollow
unit sits in the store for a whole cycle because the volume-dump leg runs only on the
backup schedule. That is WRONG. The 04:15 off-site run has its OWN pre-push dump leg -
"Stopping calibre-web for safe volume dump", "Volume dump: ... -> 877.5 KB" - so a unit
that is hollow when a run starts is REPAIRED before it is pushed. Measured twice: opengist
and calibre-web both went in hollow and came out complete, and the snapshot pulled back
from the store (6fee3b5a) holds the volume tar and all 17 userdata files.

What remains real is narrower: the one hollow snapshot that DID reach the store was created
when the unit was destroyed INSIDE a run that had already completed that app's dump leg.
The race is real and was observed, and "backed up opengist (... 0 mandatory path(s))" is a
success line over a backup holding none of the app's data either way. Severity HIGH -> LOW,
with the correction stated in the row rather than quietly rewritten.

Phase 6 interim: the observer is clean so far - db-dump 674ms, tier2-backup 3ms (a no-op,
cause to be established not assumed), zero ERROR/WARN since 23:00.

Also recorded: two of Phase 5's four injections were NOT performed, with the reasons
established rather than asserted - there is no endpoint that reaches SetDisconnected and a
hand-set flag would be reverted by the live monitor before 04:15; and a corrupted manifest
provably never reaches the store because the capture rewrites it first.
2026-09-01 04:21:15 +02:00

18 lines
1.1 KiB
Plaintext

=== THE DECISIVE MEASUREMENT: did the hollow primary overwrite the good secondary? ===
primary : 5 files, 2122928 bytes
primary manifest: db_dumps=[] volume_dumps=['privatebin_privatebin_data.tar'] HOLLOW=False
secondary: 6 files, 2122929 bytes
(was 6 files, 2123007 bytes before injection)
secondary tar sha: c3ea1bae0731bcc3082d6c94
(was c3ea1bae0731bcc3082d6c94)
=== did the R-403 guard say anything? ===
RunHealthProbes: skipping privatebin — last check 3m50s ago, effective interval 5m0s, healthy=true
RunHealthProbes: collected 0 targets (8 skipped not due, 1 skipped no container)
RunHealthProbes: skipping privatebin — last check 4m0s ago, effective interval 5m0s, healthy=true
RunHealthProbes: collected 0 targets (8 skipped not due, 1 skipped no container)
RunHealthProbes: skipping privatebin — last check 4m10s ago, effective interval 5m0s, healthy=true
RunHealthProbes: collected 0 targets (8 skipped not due, 1 skipped no container)
RunHealthProbes: skipping privatebin — last check 4m20s ago, effective interval 5m0s, healthy=true
RunHealthProbes: collected 0 targets (8 skipped not due, 1 skipped no container)