Files
felhom.eu/documentation/audits/backlog-triage-2026-10-03/RECOMMENDATION.md
T

8.7 KiB
Raw Blame History

What to work on next — backlog triage, 2026-10-03

In one screen

  • The open list is now readable. It went from 442 rows to 326. It went from 824 KB to about 540 KB.
  • Every open row has one category and one severity. Two gates refuse a row without them, and refuse a finished row left in the open list.
  • No row is P1. Nothing in the list is harm that happens today on shipped code. 27 rows are P2 (must be done before the first paying customer).
  • You decide one thing: which theme starts next. Recommendation: off-site backup safety. The other option: box system security updates. Details are in "The decision" below.

Headline numbers (before → after)

before after
rows in the open list (OPEN-ITEMS.md) 442 with an id + 22 without 326, all with an id
size of the open list 824 KB, 932 lines ≈540 KB
finished rows moved to CLOSED-ITEMS.md — 125 with an id + 20 without
rows marked VERIFY (may be finished; not proven) — 11
rows with no severity the reviewer counted ~182 0
new rows filed this session — 11: R-812, R-813 (findings beside two roadmap items), R-814, R-815 (old July watches that had no id), R-816 to R-819 (gaps found while sorting), R-50b (a finding that lived only in the roadmap)
roadmap (ROADMAP.md) 161 lines, 81 KB 124 lines, 42 KB

Open rows, category × severity (no P1 anywhere):

Category P2 P3 P4 total
Install & onboarding 2 11 5 18
Apps & catalog 0 15 21 36
App updates 0 12 7 19
Backup & restore 12 24 20 56
Storage & devices 0 7 5 12
Security & access 3 23 3 29
Box system & updates 3 11 3 17
Monitoring & notifications 2 16 6 24
Hub & operator 1 7 13 21
Business & legal 4 0 3 7
Process & tooling 0 4 83 87
total 27 130 169 326

The top 29 — every P2, open list and roadmap together

Order: severity first, then "a household meets it", then cost (small first). Size: XS < S < M < L.

# ID Category Size Household meets it? What is wrong or missing
1 R-508 Install & onboarding XS yes The hub does not warn when a customer who waits for a box has no e-mail address.
2 R-509 Install & onboarding XS yes A new box for an existing customer may not send the connect e-mail. Fix shipped; never seen live (VERIFY).
3 R-604 Box system & updates S yes A per-customer version floor can keep one box out of every fleet update, silently.
4 R-784 Business & legal S yes SparkyFitness forbids commercial use; the author's written permission is needed.
5 R-789 Business & legal S yes Tandoor's licence may forbid selling a service built on it; the authors' permission is needed.
6 R-342 Backup & restore S yes Nothing protects the off-site backup data if maintenance on that server goes wrong.
7 R-813 Business & legal S yes The website collects personal data but has no privacy notice, no terms and no imprint.
8 R-243 Monitoring & notifications M yes A box that waits for its recovery key stops off-site backups, and nobody is told.
9 R-95 Backup & restore M yes A box can delete its own off-site backups, and no older copy can be read back today.
10 R-436 Backup & restore M yes The provider's "append-only" lock (a box may add but not delete) is untested. Its check is due 2026-10-06.
11 R-726 Backup & restore M yes A returning customer's new box makes no off-site backup until someone presses a hidden reset.
12 R-366 Backup & restore M yes After a reinstall the box cannot read its older whole-machine backups, and it reads as a test failure.
13 R-32 Backup & restore M yes Resetting a customer leaves their old encrypted off-site data behind, unseen and uncounted.
14 R-105 Backup & restore M yes Two records a whole-box recovery needs may still be empty on the hub; not checked again.
15 R-518 Backup & restore M yes "Back up now" stops every app for minutes while a slow second backup runs.
16 R-519 Backup & restore M yes After an interrupted backup, a restore point shows a newer time than its files.
17 R-638 Backup & restore M yes Restoring a database copy from before an update can fail on top of the newer database.
18 R-528 Monitoring & notifications M yes An app killed for lack of memory is often not reported.
19 R-777 Security & access M yes Emby and Jellyfin treat internet visitors as home-network visitors and skip their remote limits.
20 R-304 Backup & restore L yes A household's correct recovery code for old backups is rejected as wrong.
21 R-812 / R-808 Box system & updates L yes Nothing ever installs operating-system security updates on a box (host, guest, Docker engine).
22 R-809 Business & legal M yes Contract, data-processing agreement, billing and invoicing do not exist yet.
23 R-135 Security & access S no The hub skips its forged-request check when no session cookie is sent.
24 R-802 Business & legal M no A lawyer must review the list of non-open-source licences.
25 R-133 Security & access M no Every copy of the hub database holds every box's root console password in readable form.
26 R-173 Hub & operator M no The hub database, which holds recovery secrets for every box, has no scheduled backup.
27 R-530 Box system & updates M no Host agents update only by a signed job per box, and nothing lists which boxes are behind.
28 R-232 Backup & restore L no The server that runs the hub keeps all its backups on itself, nothing off-site, and a failure alerts nobody.

(R-808 and R-812 are one item: the roadmap intention and its finding. 28 lines, 29 rows.)

Five work themes (about one session each)

  1. Off-site backup safety — R-436, R-95, R-342, R-243, R-726, R-366, R-32, R-105, R-304. The household's files and photos sit in the tier whose credential can delete. Start with R-436's measurement (due 2026-10-06), then the cheapest step that stops a box deleting its own history.
  2. Box system security updates — R-812 / R-808, R-604, R-530. A spike first (what the agent may run, what a half-done update leaves), on a throwaway box. Nothing exists today.
  3. The hub's own safety — R-133, R-135, R-173, R-232. Operator-side; no household meets it directly, but a hub loss or leak touches every box. R-232 is on DooPlex, which needs an operator word before anyone touches it.
  4. Honest backup and app behaviour — R-518, R-519, R-638, R-528, R-777, R-508, R-509. Smaller items a household meets; good for a session after theme 1.
  5. Business and legal — R-809, R-813, R-784, R-789, R-802. Yours, not a CC session. CC drafts a text when you ask. It can run beside any other theme.

The decision

Which theme does the next session start with?

A — Off-site backup safety (recommended) B — Box system security updates
What it does Measures the provider's append-only lock (R-436), then closes the biggest data risk: a box that can delete its own off-site history (R-95). A spike on a throwaway box: what update path is safe for host, guest and Docker engine. Then a design.
What it costs One session. Touches the off-site test account, never a customer's data. One spike session plus a later build session. Touches only a Tier-0 box.
Why The largest data risk the list has ranked first since July. The household's own files sit there. Boxes stay in homes for years. Today they never receive a security patch.
If you decide nothing On 2026-10-06 the dated check turns red and refuses every push to this repo until the measurement is done or the date is moved. Boxes keep the packages they were installed with. Nothing breaks this week; the risk grows every month.

My pick: A. It has a hard date in three days, it guards the household's data, and it needs no new mechanism. B is next.

Rows that wait on you (18)

R-132 (change the hub password), R-169, R-210, R-503, R-504, R-508, R-526, R-530, R-719, R-769, R-770, R-771, R-779, R-784, R-789, R-802, R-804, R-813. The P2 ones are in the top list above. Each row says what it needs from you.

Rows marked VERIFY (11) — may already be finished; nobody proved it

R-274, R-282, R-284, R-287, R-509, R-527, R-602, R-621, R-814, R-815, R-817. Each carries, at the start of its state, what suggests it is finished and the evidence pointer. Close one only after checking it against live source.