Files
felhom.eu/documentation/audits/r553-2026-09-17/green-gate.txt
T
admin 2bd6fbfac9
gates / gates (push) Successful in 24s
R-553 + R-563 CLOSED (controller v0.251.0): evidence, 10 §9 rewritten, R-569..R-571, slice-2 dependency
- audits/r553-2026-09-17/: live before/after on demo-hp (CSRF redacted), the 409 refusal, the hub
  health block, red-proofs for all five sites, the site-5 fixture diff, gates.
- 10-localisation.md §9: the five decisions with what each reads now; the rule (a text signature may
  remain only where the text is not ours); the one legacy exception and its end date.
- Register: R-553 and R-563 closed to CLOSED-ITEMS; R-569 (four API handlers match English words),
  R-570 (the legacy stale-note fallback + the slice-2 fence), R-571 (classifier and alert placement
  documented nowhere). R-557 carries the R-570 dependency. 263 -> 264 open.
- STATUS, including the live probe that installed an app and was removed the same minute.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-17 21:11:31 +02:00

206 lines
15 KiB
Plaintext

controller_gates — 16 gate(s) [--fast]
==============================================================================
== gate: template-id (template_id_gate.py)
==============================================================================
integrity gate OK — every JS element-ID reference resolves within its own template
==============================================================================
== gate: emoji (emoji_gate.py)
==============================================================================
emoji gate OK — no emoji in web/setup templates
==============================================================================
== gate: native-confirm (native_confirm_gate.py)
==============================================================================
native-confirm gate OK — no native confirm()/prompt()/alert() in templates
==============================================================================
== gate: offbox-rename (offbox_rename_gate.py)
==============================================================================
offbox rename gate OK — Tier-3 is 'Tavoli mentes' everywhere customer-facing
==============================================================================
== gate: app-row-dedup (app_row_dedup_gate.py)
==============================================================================
app_row_dedup_gate: OK (row markup single-sourced in app_row.html; 36 templates scanned)
==============================================================================
== gate: mojibake (mojibake_gate.py)
==============================================================================
mojibake_gate: OK (777 files clean — no double-encoding signatures)
==============================================================================
== gate: docker-v (docker_run_volume_path_gate.py)
==============================================================================
docker -v gate OK — every volume mount is named-volume or proven host-visible
==============================================================================
== gate: secret-markup (secret_in_markup_gate.py)
==============================================================================
secret-in-markup gate OK — 36 templates, no secret-named expression rendered
(NAME-BASED: blind to a secret arriving under a neutral PAGE-DATA key — see the docstring)
==============================================================================
== gate: retrieval-promise (retrieval_promise_gate.py)
==============================================================================
retrieval-promise gate OK — 37 surface(s) incl. 1 Go handler file(s), 11 registered claim(s) + 16 English, none unregistered
(BLIND SPOT: it registers WHERE the claim is made, not whether each conditional is wired
to a true predicate — that is what the R-302 render tests are for.)
==============================================================================
== gate: debug-routes (debug_route_gate.py)
==============================================================================
debug route gate OK - 19 referenced address(es), all dispatched, none orphaned
==============================================================================
== gate: reuse-refs (reuse_refs_check.py /mnt/5_hdd/felhom.eu/git/felhom-controller)
==============================================================================
note [felhom-controller] line 15: backup/appbackup_bridge.go (resolved by suffix → controller/internal/backup/appbackup_bridge.go)
note [felhom-controller] line 19: appbackup/userdata.go (resolved by suffix → controller/internal/appbackup/userdata.go)
note [felhom-controller] line 19: stacks/skeleton_derive.go (resolved by suffix → controller/internal/stacks/skeleton_derive.go)
note [felhom-controller] line 47: internal/report/builder.go (resolved by suffix → controller/internal/report/builder.go)
note [felhom-controller] line 76: stacks/deploy.go (resolved by suffix → controller/internal/stacks/deploy.go)
note [felhom-controller] line 129: cmd/controller/main.go (resolved by suffix → controller/cmd/controller/main.go)
note [felhom-controller] line 152: appbackup/appdata.go (resolved by suffix → controller/internal/appbackup/appdata.go)
note [felhom-controller] line 174: scripts/secret_in_markup_gate.py (resolved by suffix → controller/scripts/secret_in_markup_gate.py)
note [felhom-controller] line 216: hub/internal/api/handler.go (cross-repo → felhom.eu/hub/internal/api/handler.go)
note [felhom-controller] line 216: hub/internal/notify/dispatcher.go (cross-repo → felhom.eu/hub/internal/notify/dispatcher.go)
note [felhom-controller] line 229: monitor/deadline.go (cross-repo (suffix) → felhom.eu/hub/internal/monitor/deadline.go)
note [felhom-controller] line 267: wgsync/reconciler.go (cross-repo (suffix) → felhom.eu/hub/internal/wgsync/reconciler.go)
note [felhom-controller] line 301: api/router.go (resolved by suffix → controller/internal/api/router.go)
note [felhom-controller] line 323: web/netprobe.go (resolved by suffix → controller/internal/web/netprobe.go)
note [felhom-controller] line 323: web/server.go (resolved by suffix → controller/internal/web/server.go)
note [felhom-controller] line 347: felhom.eu/scripts/golden_currency_gate.py (cross-repo → felhom.eu/scripts/golden_currency_gate.py)
OK [felhom-controller]: 174 cited paths — exact 158, suffix 11, ambiguous 0, cross-repo 5, FAILED 0 (siblings searched: app-catalog-felhom.eu, felhom-agent, felhom.eu)
==============================================================================
== gate: instructions (instructions_gate.py /mnt/5_hdd/felhom.eu/git/felhom-controller)
==============================================================================
instructions_gate: /mnt/5_hdd/felhom.eu/git/felhom-controller
CLAUDE.md effective lines : 92 (ceiling 200)
version literals : 0
TEMPORARY blocks : 0
rule files : 5 (4 path-scoped)
workspace file : SYMLINK -> felhom.eu/documentation/runbooks/workspace-CLAUDE.md (resolves to the versioned copy)
memory index : 181 lines (ceiling 200), 25554 bytes (ceiling 25600)
memory index content : 39 version literal(s), 5 host address(es), 0 expired statement(s) [WARN only]
memory topic files : 148 indexed, 0 orphaned, 40 archived
register citations : 13 cited, 533 register items known
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:19: version literal '0.112.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- **[A floor above the golden needs a DECLARED MinAgent](floor-held-above-golden.md)** — h
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:21: version literal '0.236.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- **["Delete my data too" was INERT until ctrl 0.236.0 (R-442)](r442-remove-reads-per-app-
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:24: version literal '0.14.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- **[restic 0.14.0 `--verify` is size+mtime, NOT content](restic-0140-verify-and-lock-sema
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:35: version literal '1.25.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [ISO train v1.25.0](iso-train-v1.25.0-2026-07-23.md) — R-71 build-gate (golden≥floor), r
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:59: version literal '1.2.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [Offsite pool-box aggregate](offsite-pool-box-aggregate-2026-07-17.md) — R-5 hub 0.64/0.
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:63: version literal '0.90.0' — the fleet is not uniform, so it is stale within a day. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [Guest RAM resize + fast-tick](guest-ram-resize-fasttick-2026-07-17.md) — R-24 controlle
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md: ... and 33 more version literal(s) — full list from the tally counts above.
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:39: host address '192.168.0.192' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [hub.felhom.eu resolves to the LAN here](hub-resolves-to-lan-on-dooplex-network.md) — 19
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:54: host address '192.168.0.0' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [Tailscale N100 location-independent](tailscale-n100-location-independent-2026-07-19.md)
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:58: host address '167.233.158.164' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [Offsite PBS box RAM ceiling](offsite-pbs-box-ram-ceiling-2026-07-27.md) — **root SSH =
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:58: host address '10.77.0.1' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- [Offsite PBS box RAM ceiling](offsite-pbs-box-ram-ceiling-2026-07-27.md) — **root SSH =
WARNING: /mnt/5_hdd/felhom.eu/git/.claude-memory/MEMORY.md:162: host address '192.168.0.180' — operations/nodes.md is the single home for these. Not a failure: Claude writes this file between sessions, so this warning is aimed at the model that will next edit it, not at whoever is pushing.
- **CC runs ON DooPlex** (192.168.0.180) — repos `/mnt/5_hdd/felhom.eu/git/felhom-*`, buil
instructions_gate: OK (12 warning(s))
==============================================================================
== gate: observations (observations_gate.py /mnt/5_hdd/felhom.eu/git/felhom-controller)
==============================================================================
report : /mnt/5_hdd/felhom.eu/git/felhom-controller/REPORT.md
section : ## Observations
observation items : 9
OK 1. FILED R-563
OK 2. FILED R-564
OK 3. FILED R-565
OK 4. FILED R-566
OK 5. FILED R-567
OK 6. FILED R-568
OK 7. FILED R-516
OK 8. NOT-A-FINDING
OK 9. NOT-A-FINDING
observations gate OK — every observation is either filed or explicitly declared
==============================================================================
== gate: minagent-header (minagent_header_gate.py)
==============================================================================
minagent header gate OK — v0.250.0 declares MinAgent 0.131.0
==============================================================================
== gate: i18n (i18n_missing_gate.py)
==============================================================================
i18n: 1875 markers in 36 templates; hu 1588 keys, en 1591 keys
i18n: English missing 0 (ceiling 0); Hungarian formal forms 16 (ceiling 16, R-516)
formal: launcher.olvassa_be_telefonnal_a_gyors (olvassa be)
formal: launcher.biztosan_kikapcsolja_a_megosztast_a (biztosan kikapcsolja)
formal: layout.ha_ujratelepiti_az_alkalmazast_az (ujratelepiti az)
formal: layout.ha_ujratelepiti_az_alkalmazast_az (importalnia)
formal: backups_shared.empty_body (kerjuk)
formal: backups_shared.empty_body (vegye fel)
formal: app_import.fab_csomag_feltoltese_huzza_ide (valassza ki)
formal: app_import.a_feltoltes_megszakadt_ellenorizze_a (ellenorizze)
formal: deploy.a_kontener_leallt_ellenorizze_a (ellenorizze)
formal: settings_system.ezek_az_ertekek_a_helyi (kerjuk)
formal: backups_remote.a_megerosites_nem_erkezett_meg (ellenorizze)
formal: backups_escrow.a_megadott_szavak_nem_egyeznek (ellenorizze)
formal: storage.nincs_regisztralt_adattarolo_adjon_hozza (adjon hozza)
formal: storage_init.valassza_ki_a_formazando_felhasznaloi (valassza ki)
formal: storage_attach.valassza_ki_a_mar_fajlrendszerrel (valassza ki)
formal: debug.kattintson_a_gombra_a_telemetria (kattintson)
i18n gate OK
==============================================================================
== gate: golden-notice (golden_notice.py /mnt/5_hdd/felhom.eu/git/felhom-controller)
==============================================================================
==============================================================================
NOTICE — v0.250.0 OWES A GOLDEN. (this NEVER blocks; see the docstring)
==============================================================================
newest released controller : 0.250.0 (this repo's CHANGELOG.md)
newest golden baked : 0.246.0 (felhom.eu documentation/tests/)
A machine installed right now would receive 0.246.0, not 0.250.0.
This is a REMINDER AT THE ONE MOMENT IT IS USEFUL — you are in the repo where the
release happens. It does not block, and must not: at the moment a release is
committed the golden cannot exist yet.
WHAT CLEARS IT: bake a golden (felhom.eu documentation/runbooks/RUNBOOK-manual-build.md
section 4.1), then vouch it — a THREE-field change: golden_version + agent_version +
min_agent. The bake record lands in felhom.eu documentation/tests/golden-<ver>-<date>/.
If this release deliberately needs no golden, record a waiver row in
felhom.eu documentation/backlog/OPEN-ITEMS.md — never a habit of bypassing.
==============================================================================
==============================================================================
== summary
==============================================================================
template-id OK (exit 0)
emoji OK (exit 0)
native-confirm OK (exit 0)
offbox-rename OK (exit 0)
app-row-dedup OK (exit 0)
mojibake OK (exit 0)
docker-v OK (exit 0)
secret-markup OK (exit 0)
retrieval-promise OK (exit 0)
debug-routes OK (exit 0)
reuse-refs OK (exit 0)
instructions OK (exit 0)
observations OK (exit 0)
minagent-header OK (exit 0)
i18n OK (exit 0)
golden-notice ADVISORY (exit 0, advisory)
all controller gates OK