Files
felhom.eu/documentation/audits/offsite-append-only-2026-10-03/lab/A5-locks.txt
T
admin 9268d9933b
gates / gates (push) Successful in 29s
R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed,
authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820,
R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions.
Register 326 -> 327.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 13:40:35 +02:00

71 lines
3.5 KiB
Plaintext

## A5: kill a backup mid-run through the FORCED key (docker kill -s KILL on the client = a crash)
killing r436-cli-2801178 at 09:12:15
locks on server after the crash:
-rw-r--r-- 1 sub sub 141 09:12:12 b70bc18cbb4e907bc81308a463dd0a86839ef7200eb74c8ba8baf20d51f74fca
## next BACKUP (shared lock) from a NEW container (new hostname — as after a controller recreate)
$ c.sh forced spike-repo backup /d/tree --host labbox --tag app1
using parent snapshot 066a039d
Files: 0 new, 0 changed, 4 unmodified
Dirs: 0 new, 1 changed, 2 unmodified
Added to the repository: 325 B (274 B stored)
processed 4 files, 585.948 KiB in 0:00
snapshot 16f27a03 saved
[rc=0]
## next EXCLUSIVE op (check) — does the stale lock wedge it?
$ c.sh forced spike-repo check
using temporary cache in /tmp/restic-check-cache-108793622
create exclusive lock for repository
unable to create lock in backend: repository is already locked by PID 1 on 6999b25ca937 by root (UID 0, GID 0)
lock was created at 2026-10-03 09:12:12 (9.203992203s ago)
storage ID b70bc18c
the `unlock` command can be used to remove stale locks
[rc=1]
## plain unlock (stale-only)
$ c.sh forced spike-repo unlock
successfully removed locks
[rc=0]
locks:
-rw-r--r-- 1 sub sub 141 09:12:12 b70bc18cbb4e907bc81308a463dd0a86839ef7200eb74c8ba8baf20d51f74fca
## unlock --remove-all
$ c.sh forced spike-repo unlock --remove-all
successfully removed locks
[rc=0]
locks:
## check again
$ c.sh forced spike-repo check
using temporary cache in /tmp/restic-check-cache-3364593304
create exclusive lock for repository
load indexes
check all packs
pack 1a9dd015f3b76fd43ed4f4019bb15d024a36763d2e52f1a9216284a53f9be971: not referenced in any index
pack 8184618eaa974e3094796144f9b466468113f9e2bcd82194f9ca58f959d0f822: not referenced in any index
pack 63e40e54bedfc638a55e9fe5225231edebc84bb7263b4e4ca25b5933188ebb1c: not referenced in any index
pack 97b9da6b48256ec083071902fea61ef56ea5a18f3af869f7ec6eb2ead7772674: not referenced in any index
pack b213484fe31fd640b6b519a5ddbe486bfeed32688fea8a0185ff98dcf7165eb3: not referenced in any index
pack 5ccfd475d12254508662e5940c923ae132dc0a63b48ba65ff8e3970925f264fb: not referenced in any index
pack 0b27c44a9453ac56fb8c171447927d6a45b30ad9233aaa71e4dd9db9a3102b43: not referenced in any index
pack af691cecf756d65918ffd1430d8bebdfb720b657ba1ab24c37fd42e1506185ca: not referenced in any index
pack 14883d87a878ea91e66a471e892eb1a2f17cc916dcf3be3f6f32f9eb353b755c: not referenced in any index
pack 70c49c3190eba6522d6b493b2c35009bd8a562edd5fb706a0ef29a865c56d52a: not referenced in any index
pack fa2445b724ba511629fb1dadc75a86f6ae413a61147f7152e50d58effba4ea88: not referenced in any index
pack 3902d8453121f05f590775ff617782e0da7027553edcc81305a5629abf6bcde9: not referenced in any index
pack f86e1c71608c4ddcde8ad66ada62c42a0459b798f4ce4bc1f8a76a4728a85b1d: not referenced in any index
pack 4a080216c5d17e9f2b5eb91cc797901d7f858b86f97cbedb20192e6a90160599: not referenced in any index
pack 10a1dfa78d932c22e68f4bf59fde5e5fdb997d79711d67b8029285ab4c9ae934: not referenced in any index
pack 70fb6c036df351cc2f9f46ad69ecc8d234f635b4deee44fbc711e7f81174ea62: not referenced in any index
pack c7d8a4a140ac753cb9e9232a014e521b5d419c5c29cb29f4713e7b8b71cd0e47: not referenced in any index
17 additional files were found in the repo, which likely contain duplicate data.
This is non-critical, you can run `restic prune` to correct this.
check snapshots, trees and blobs
[0:00] 100.00% 3 / 3 snapshots
no errors were found
[rc=0]