Files
felhom.eu/documentation/audits/backup-close-2026-10-04/partB/lab-proof.md
T
2026-10-04 08:56:56 +02:00

1.4 KiB

R-833 lab proof — 2026-10-04 (a lab repo on DooPlex scratch, not a demo box's)

restic 0.14.0 from the controller image felhom-controller:0.290.0 (docker run --rm --entrypoint sh), a local repo, password lab-only-password (a lab value). 98 daily snapshots, --host demo-lab --tag felhom-offsite, dated 97..0 days back — the shape of a box whose windows were off for three months.

The box's own guard (offsiteGuard, controller v0.290.0 source) was run on the repo's REAL snapshots --json and the policy's REAL forget --dry-run --json by offbox_window_lab_test.go.txt (copy it into controller/internal/backup/ and set OFFSITE_LAB_DIR to rerun; it skips without it, so it is not committed).

Step Result
Honest plan 98 snapshots, the policy removes 85
Default cap (hub MaxRemove = half) 49 → REFUSED: the plan would remove 85 snapshots, more than one week's retention may (49)
Operator-raised cap 90 (one window) 85 ids, no refusal
restic forget <those 85 ids> --prune rc 0; 98 → 13; restic check rc 0
Next window, default cap again (6) plan 0, no refusal — the cap only needed raising once

The hub half (the grant is one-shot, the next window has the default cap, the close check uses the window's own cap, a box cannot grant itself) is in hub-redproofs.txt and the hub suite.