b9073e8fb6
gates / gates (push) Failing after 11m54s
You saw the cover uncropped signed out, after R-919 said the sides are cut. Both are true; my first measurement was one view generalised to "the phone". SIGNED IN, confirmed on your real phone (Chrome/Android, 1080 px): the crop is real. The cover band is 708 px tall across 1080 = 1.525:1 against the file's 2.628:1, and solving the laptop frame's left edge against that scale puts the window at x 351..1298 where the emulated Pixel 9 said 351..1289 -- the left edge to the pixel. R-919 is confirmed on hardware, not replaced. SIGNED OUT, measured from your screenshot: the box is 412x132 = 3.121:1, WIDER than the file, so the height is cut, not the width -- and the file's blue top rule is still visible at the top edge, which puts the cut at the BOTTOM: the top 525 px of 624 survives. The circle is far bigger and higher: x 486..1150 from y 232, 41% of the width. So the sides are cut for one visitor and the bottom for the other. build.py now carries both views; SAFE is their intersection, (391,40)-(1249,485). Two changes made that workable rather than merely safe: - the circles are modelled as DISCS, not rectangles running to the bottom. Near its top a disc is a few pixels wide; the rectangle was discarding most of the lower cover for nothing, which is much of why the frame looked empty. - TWO LAYERS. The READ layer (catchphrase, wordmark) must survive every view and the check fails on it. The DECOR layer may be cropped or covered, and the build REPORTS the cost instead of forbidding it (B 39%, C 62%). Before the split one check governed both, so no laptop big enough to read could ever pass. Red-proof again: the two-view geometry convicted all three covers as they stood -- A 908 content px under a circle (its wordmark sat inside the signed-out circle), B 1715 plus content past the cut bottom, C 1962. control_old_window still convicts the pre-R-919 layout, so there are two controls now. Covers redrawn: C is your laptop idea -- catchphrase and wordmark left, the dashboard at 640 px (was 370) running off the right edge, readable at last. B's home motif grew the same way. A lifted into the tighter band. Capitals 48/45/43 against the 25 px floor. Profile pictures untouched, not in the diff. Still VERIFY: three views measured, all disagreeing with each other and with Meta's help page, and the Facebook APP is still the one nobody has measured.
Felhom — Documentation
Felhom is a managed home-server service for Hungarian households, built on a three-component model over Proxmox:
- Hub — operator backend on k3s (
hub.felhom.eu). Repo:felhom.eu/hub/. - Host agent — one per Proxmox host; operator-tier; owns all Proxmox interaction. Repo:
felhom-agent/. - In-guest controller — one per customer LXC; Docker-only; manages the customer's apps. Repo:
felhom-controller/.
This directory is the central, code-verified documentation home for all three components plus the platform and the security-audit record.
Sections
Controller (in-guest) — controller/
The Docker-only app-domain controller. Full per-area docs grounded in current source (v0.59.0).
→ controller/README.md: module map, deploy & stack lifecycle, backup
architecture, storage/monitoring/metrics, auth/hub/sync/integrations.
Where we stand — architecture/where-felhom-stands.*
The operator's one-page picture of what is proven, built, partial and missing.
architecture/where-felhom-stands.html— generated; do not hand-editarchitecture/where-felhom-stands.yaml— the data behind it; every claim cites its source. Gate:scripts/check_stands.py; regenerate withscripts/render_stands.pyarchitecture/where-felhom-stands-2026-08-09-snapshot.html— a dated snapshot, NOT maintained. The original React bundle, kept for the record; its statuses are those of 2026-08-09 before the verification pass
Host agent & platform — architecture/, proxmox-platform.md
The operator-tier agent and the Proxmox platform.
architecture/01-topology-and-trust.md— topology & trust modelarchitecture/03-host-agent.md— the host agent (Go; v0.29.1)architecture/04-control-plane-authorization.md— signing, escrow, authzarchitecture/02-controller-module-map.md— historical v0.33 planning map; the live map iscontroller/module-map.mdproxmox-platform.md— Proxmox platform referencearchitecture/11-os-updates.md— operating-system updates: host, guest, Docker engine (NOT RATIFIED, 2026-10-04)
Hub (operator backend) — architecture/05
architecture/05-hub-architecture.md— hub architecture (v0.11.0)
Security audits & remediation — audits/
audits/deep-sweep-2026-06-13.md— cross-repo deep audit (controller + agent) with remediation statusaudits/bughunt-reconcile-2026-06-13.md— reconciliation of the v0.30.3 BUGHUNT against current code + merged fix list
Spike & test findings — tests/
Per-slice spike/validation findings (phases 0–5, slices 7–10). See tests/.
Conventions
- Code-verified, not memory-derived. Architectural claims here are checked against the actual current source; if a claim can't be verified it is omitted and flagged, not guessed.
- Per-repo operational working files (
CLAUDE.md,CONTEXT.md,CHANGELOG.md,BUGHUNT.md,REPORT.md,TASK.md) live in their own repos — they are operational, not published docs. - Authoritative versions at last refresh: controller v0.59.0, agent v0.29.1, hub v0.11.0.