Files
felhom.eu/REPORT-calibre-name-and-prune-2026-10-01.md
T

5.7 KiB
Raw Permalink Blame History

REPORT — rulings 61 (calibre-web's generated login name) and 62 (the registry prune rule) — 2026-10-01 late afternoon

Evidence: documentation/audits/calibre-name-and-prune-2026-10-01/ (A, B, T); tools in audits/lockouts-2026-10-01/tools/ (a_calibre_name.py, lk.py, walk.py, repoint.py). Read: 09 §3 decisions 45, 57–60; FIRST-ADMIN.md; rows R-752, R-750, R-753; audits/lockouts-2026-10-01/ B1, C1; homelab-manifests HM-024. Baselines (~12:55 CEST): controller c1b123c64955, felhom.eu 8dab40c7a786, catalog ed6df4b46b93 — matched. Register 390; highest R-755; last decision 60 → the rulings are 61 and 62.

The Part table

Part done / not done / changed why
Rulings 61, 62 done — recorded first (09 §3, CONTEXT) numbered 61/62: 58–60 were taken by the lockouts session
A1 measure done — hex:N + type: secret already exist; calibre-web has no rename command —
A2 build done — catalog e9f50b5 (template, hu + en copy, the freeze for those 5 strings, FIRST-ADMIN) no controller change
A3 proof on 9202 done —
A4 installed apps done — and a defect found (R-757); demo-hp renamed TWICE the box invented a name for the installed app
B prune rule done — admin/misc-scripts c9d5ed5; test red-proofed; live dry-run the running hub added to "in use" (a version in use the ruling did not name)
B4 runbook line done — RUNBOOK-manual-build.md §4.1a HM-024 lives in homelab-manifests (outside the felhom fence)
C release / golden not needed A1 needed no controller change

Claims in the brief that turned out wrong (or right)

  1. "The controller can generate a login name" — right: generate: "hex:N" (deploy.go:1187) gives lowercase a–f and digits; type: secret is filled when empty and shown behind „Megjelenítés".
  2. "calibre-web can rename a user" — no command does: cps/cli.py offers only -s user:password (ub.py:1350 password_change). Its admin page renames by setting user.name (admin.py:2789, column ub.py:264, unique). So after_install updates that column itself, then uses Calibre-Web's own -s for the password.
  3. "The OPDS door uses the same name" — right: OPDS is limited per name (cps/main.py:75, request_username); a stranger's tries on admin never touch the real name (measured: OPDS with the real name ok after 40 tries on admin).
  4. Where the prune script lives — in a repo already: Gitea admin/misc-scripts (~/git/misc-scripts). The August run is in its own log: 2026-08-22T16:02:20Z RUN action=prune … apply=true keep='7'.
  5. "A template change reaches an installed calibre-web only through an Update" — wrong in a way that matters: the template reached demo-hp at the next sync (images equal), and the box then INVENTED the new field's value (InjectMissingFields, R-757). My own first CHANGELOG line said "frozen until an Update" — also wrong.

Part A — calibre-web

9202 (drill catalog 4e18b3a, identical to live e9f50b5) — A/A1-9202-calibre-generated-name.txt: install hold before the first start, opened by after_install at 11:02:17; a stranger polling admin/admin123 from the deploy press got in 0 of 31 times; after_install record ok: true; the name 10 lowercase hex characters (read through the page's reveal); app.db: 2 users, 0 named admin; name + password: form ok, OPDS ok; admin + the right password refused; 40 wrong tries on admin at 3/min (11:02–11:16) → the household at once: form ok, OPDS ok; a wrong password on the real name refused. Removed (drive data kept: R-756).

demo-hp — A/A2-demo-hp-rename.txt: renamed by the same method (values through stdin, never printed); a real login over its traefik: name ok (form, OPDS), admin wrong. Then the box's sync injected a DIFFERENT ADMIN_USER into its app.yaml (R-757, A/A3…); renamed again to the box's recorded value; verified (the earlier name and admin refused). The name is in ~/.config/credentials as DEMO_HP_CALIBRE_USER (backup credentials.bak-20261001-calibre); never in a repo.

What any other installed calibre-web gets, and when: at the next catalog sync (≤ 15 min) its .felhom.yml gains the field and the box invents an ADMIN_USER for it; its login stays admin (after_install runs only after a fresh install). No other box has calibre-web today (the N100 does not; Tester-2 has not registered).

Part B — the prune rule

tests/test-prune-plan.sh: 7 checks pass (an in-use version older than the newest 20 is kept, with its reason; --keep defaults to 20; dry-run; an unreadable in-use list → exit 3). Red-proofs: the same plan with an empty in-use list deletes 0.262.0; the in-use check removed from is_protected → 3 checks fail (B/B1-test-and-red-proof.txt). Live dry-run (B/B2-live-dry-run.txt): in use — controller 0.285.0 (floor, golden's, baked), golden 0.285.0, agent 0.138.0 and 0.131.0, hub 0.126.0, felhom-samba 1.1.0. Would delete: felhom-controller 70, felhom-hub 8; every other package nothing. No --apply. No token or password in any output (grepped for each value).

Rows

390 → 392. Closed R-750, R-752. Opened R-756 (9202 remove-with-data refused), R-757 (the box invents a new secret field's value for installed apps).

Teardown

  • Machine: 9202 back on the live catalog (repo_url read back), the same six containers; calibre-web removed through the product (drive data kept, R-756). demo-hp: calibre-web's user renamed (the only change there).
  • Host: nothing. Hub: read only (the Configuration page, for the dry-run). Gitea: read only; one repo push (misc-scripts). Drill catalog reset to live (e9f50b5).