Files
felhom.eu/documentation/audits/update-arc-gaps-2026-09-21/02-seeding.txt
T
admin c85262111c
gates / gates (push) Successful in 23s
The update arc's two missing measurements, the lock, and the floor to 0.260.0
Part 0 — floor raised to 0.260.0, MinAgent 0.131.0 declared. 3 boxes below, all
down or blocked; both demo boxes SERVED.

Part 1 (R-610) — the DANGEROUS power cut, measured three times with three apps and
two cut mechanisms. All ended honest: resumed, completed, and pinned/installed/live
compose/docker inspect all agreed. vikunja's 2.6.0 migration had ALREADY run 0.64 s
after the cut decision and the seeded data read back intact — so the branch that is
one step from old-binary-on-migrated-database is now evidence, not argument.
Instrument limit stated: `starting` lasts under a second; all three landed in
`verifying`, which RecoverUpdates handles in the same branch.

Part 3 (R-611) — the night the previous session skipped without saying so. An app
updated with nobody pressing anything; a terminally-refused app was pressed exactly
once and never again over three passes. The unattended HOLD was NOT produced: the
within-a-major rule correctly refused the broken edge before it was attempted, so
Q4 still rests on the attended hold from slice 4. Said plainly rather than implied.

Rows: closed R-608/609/610/611; opened R-612 (P1 wishlist unusable on a fresh
install, and its error is a lie), R-613 (uptime-kuma healthy on its setup wizard),
R-614 (stale update phase survives a redeploy). R-520's pointer corrected.

Catalog: two drill pairs, both reverted; every image line byte-identical to
ff9717d3. The alpine:3.20 negative control a security review flagged is cleared.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 15:00:09 +02:00

38 lines
2.1 KiB
Plaintext

# 02 — seeding each app through its own front door, BEFORE any bump
# guest 9202, 2026-09-21T12:24:42Z
## vikunja — seeded via its REST API (/api/v1/register, /login, PUT /projects, PUT /projects/2/tasks)
vikunja version: v2.3.0
TASK 1 'SEED-VIKUNJA-CANARY-9f3c1e-20260921' desc= 'power-cut drill canary'
POSITIVE CONTROL: seed present = True
NEGATIVE CONTROL: absent string present = False
## uptime-kuma — seeded via its own socket.io front door (the same API the browser uses)
# NOTE: uptime-kuma 2.4.0 first boot sits in the SETUP-DATABASE wizard ('Waiting for user action').
# The controller reported the app running + healthy anyway. The wizard was passed through its own
# front door: POST /setup-database {"dbConfig":{"type":"sqlite"}} -> {"ok":true}.
MONITORS: ["SEED-KUMA-CANARY-4a91c7-20260921"]
POSITIVE CONTROL: seed present = true
NEGATIVE CONTROL: absent name present = false
read-back finished
## wishlist — seeded via POST /signup then POST /lists/<id>/create-item
# NOTE: on first boot the image's own 'pnpm prisma db seed' was OOM-Killed at mem_limit 128M,
# so the Role/Group rows were missing and EVERY signup failed with a misleading
# 'User with username or email already exists' (real cause: FOREIGN KEY constraint).
# Repaired by running the image's own seed once (docker update --memory 512m, run seed, back to 128m).
wishlist version banner: 308
list page code=200
POSITIVE CONTROL occurrences of seed name: 2
NEGATIVE CONTROL occurrences of absent name: 0
context: '-[--><!--[-1--><div data-scope="dialog" data-part="title" id="dialog:s11:title" class="truncate text-xl font-bold text-wrap wrap-break-word md:text-2xl"><!---->SEED-WISHLIST-CANARY-7b2d44-20260921<!----></div><!--]--><!--]--> <!--[--><!--[-1--><button data-scope="dialog" data-par'
## glance — no user data
glance has NO user data (catalog app_info declares none; the only persistent state is the
first-boot seeded /app/config/glance.yml). Observable recorded instead:
d9104faa1890d25cd77ed62eb2271da5 /app/config/glance.yml
1
glance HTTP 200 size=7842
POSITIVE CONTROL (ASCII fragment "Kezd" on the page): 4
NEGATIVE CONTROL: 0