Gladex Agent Logs

Agent run logs & app logs · env: prod · LAN-only investor surface

Overview
Run logs454 files, 11.6 MB
Latest run logrun-20260925-012106-52.log
Log directory/data/agent-logs
App log directory/opt/startup/prod/logs
Run logs (newest first, last 50)
FileSizeModified (UTC)
run-20260925-012106-52.log 171 KB 2026-09-24 23:46:11
run-20260925-003542-51.log 153 KB 2026-09-24 23:11:06
run-20260924-234828-50.log 204 KB 2026-09-24 22:25:42
run-20260924-230237-49.log 303 KB 2026-09-24 21:38:28
run-20260924-222340-48.log 206 KB 2026-09-24 20:52:37
run-20260924-215353-47.log 146 KB 2026-09-24 20:13:40
run-20260924-210315-46.log 182 KB 2026-09-24 19:43:53
run-20260924-200755-45.log 181 KB 2026-09-24 18:53:15
run-20260924-192844-44.log 133 KB 2026-09-24 17:57:55
run-20260924-182059-43.log 227 KB 2026-09-24 17:18:44
run-20260924-164658-42.log 181 KB 2026-09-24 16:10:59
run-20260924-160206-41.log 101 KB 2026-09-24 14:36:58
run-20260924-153643-40.log 127 KB 2026-09-24 13:52:05
run-20260924-151001-39.log 130 KB 2026-09-24 13:26:43
run-20260924-144921-38.log 90 KB 2026-09-24 13:00:01
run-20260924-143001-37.log 63 KB 2026-09-24 12:39:21
run-20260924-141012-36.log 106 KB 2026-09-24 12:20:01
run-20260924-135151-35.log 75 KB 2026-09-24 12:00:12
run-20260924-133211-34.log 116 KB 2026-09-24 11:41:51
run-20260924-130932-33.log 67 KB 2026-09-24 11:22:11
run-20260924-115831-32.log 260 KB 2026-09-24 10:59:32
run-20260924-111405-31.log 117 KB 2026-09-24 09:48:31
run-20260924-102752-30.log 106 KB 2026-09-24 09:04:05
run-20260924-100538-29.log 81 KB 2026-09-24 08:17:52
run-20260924-092904-28.log 101 KB 2026-09-24 07:55:38
run-20260924-083526-27.log 116 KB 2026-09-24 07:19:04
run-20260924-080136-26.log 75 KB 2026-09-24 06:25:26
run-20260924-074910-25.log 23 KB 2026-09-24 05:51:36
run-20260924-072601-24.log 52 KB 2026-09-24 05:39:10
run-20260924-065657-23.log 156 KB 2026-09-24 05:16:01
run-20260924-063310-22.log 76 KB 2026-09-24 04:46:57
run-20260924-055309-21.log 107 KB 2026-09-24 04:23:10
run-20260924-052831-20.log 133 KB 2026-09-24 03:43:09
run-20260924-050107-19.log 69 KB 2026-09-24 03:18:31
run-20260924-044831-18.log 34 KB 2026-09-24 02:51:07
run-20260924-041948-17.log 156 KB 2026-09-24 02:38:31
run-20260924-035438-16.log 185 KB 2026-09-24 02:09:48
run-20260924-033002-15.log 245 KB 2026-09-24 01:44:38
run-20260924-025910-14.log 120 KB 2026-09-24 01:20:02
run-20260924-023430-13.log 97 KB 2026-09-24 00:49:10
run-20260924-015458-12.log 255 KB 2026-09-24 00:24:30
run-20260924-012751-11.log 179 KB 2026-09-23 23:44:58
run-20260924-005036-10.log 162 KB 2026-09-23 23:17:51
run-20260924-000545-9.log 217 KB 2026-09-23 22:40:36
run-20260923-235334-8.log 29 KB 2026-09-23 21:55:45
run-20260923-233751-7.log 97 KB 2026-09-23 21:43:34
run-20260923-231451-6.log 165 KB 2026-09-23 21:27:51
run-20260923-225120-5.log 58 KB 2026-09-23 21:04:51
run-20260923-222610-4.log 230 KB 2026-09-23 20:41:20
run-20260923-205439-3.log 640 KB 2026-09-23 20:16:10
Tail — run-20260924-092904-28.log (last 200 lines)
+  consistent/split/non-numeric/missing, placeholder↔real MNAME verdicts, exit-code
+  contract (error→1, warning→0), static wiring guards, `--help`→0 / bad-arg→2
+- **Mutation (in-suite, both planted on copies via `GLADEX_REPO_DIR`)**: defeating
+  the MX comparison → drifted MX wrongly reports `ok` (caught); removing the serial
+  comparison → the "propagation lag" verdict disappears (caught)
 - `system-status --format json` → valid JSON with overall status
-**Status**: Built ✅ (2026-09-24: counts both DBs + `timeout 30` → `120`)
+**Status**: Built ✅ (2026-09-24: counts both DBs, `timeout 30` → `120`, + MX/SOA
+mail-DNS checks — 27 checks)
 
 ---
 
 ## version-check

> build · mimo-v2.6-flash-free
Now the CHANGELOG entry:
← Edit repo/CHANGELOG.md
Index: repo/CHANGELOG.md
===================================================================
--- repo/CHANGELOG.md
+++ repo/CHANGELOG.md
@@ -3,8 +3,63 @@
 All notable changes to Gladex are documented here.
 
 Format: `[version] - YYYY-MM-DD — description`
 
+## [0.4.24] - 2026-09-24 — system-status now guards the adopted MX and SOA serial (the A-record-only DNS check was blind to mail)
+
+### Added
+- **`tools/system-status`: two new checks (25 → 27), closing the standing investor
+  rule from 2026-09-23** ("MX gladex.de is now set — adopt it: verify propagation,
+  keep serials sane"). The tool's `check_dns` guarded only **A records**, so mail
+  routing could drift (MX changed/removed at the resolver) or the SOA serial go
+  insane without any run noticing:
+  - **`MX:gladex.de`** — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8
+    (propagation check, two resolvers like the manual DOMAIN.md verification).
+    Wrong or missing answer on either resolver → **error, exit 1** — a wrong MX on
+    a public resolver is a mail outage, not a warning. Multi-record answers are
+    collapsed with `paste` so the JSON output stays valid.
+  - **`SOA:gladex.de`** — serial parsed from both resolvers: must be numeric, >0,
+    and identical (a split → **warning** "propagation lag", transient by
+    definition; garbage/missing → **error**). The known `MNAME` placeholder
+    (`a.misconfigured.dns.server.invalid.` — provider-panel-only fix, open
+    NEEDS-INVESTOR) is surfaced as a **warning** in the detail —
+    `serial=2026092305 consistent …; mname=placeholder (NEEDS-INVESTOR open)` — so
+    the open item is visible on every health run and **clears itself** the moment
+    the panel value changes.
+- **`tests/test_system_status_mx_soa.sh` — 27 assertions**, hermetic and <1s. The
+  `dig` stub is **scenario-driven per record type AND per resolver**, so MX/SOA
+  answers can be pinned per run (live-accurate fixtures verified 2026-09-24);
+  `GLADEX_DEV_DB`/`GLADEX_PROD_DB` point at absent DBs so the live message DBs are
+  never read. Covers: MX ok/missing/drifted-on-one-resolver (non-vacuity: the other
+  resolver correct), serial consistent/split/non-numeric/missing, placeholder↔real
+  MNAME verdicts, exit-code contract (error→1, warning→0), static wiring guards,
+  `--help`→0 / bad-arg→2.
+- **Two in-suite mutation checks**: defeating the MX comparison (condition → always
+  true) makes drifted MX report `ok` — caught; removing the serial comparison makes
+  the "propagation lag" verdict disappear — caught.
+
+### Changed
+- **`GLADEX_REPO_DIR` test hook on `system-status`** (documented in `--help` +
+  REGISTRY): the git/Go checks resolve `REPO_DIR` from the script's own location,
+  so a **mutated copy run from a sandbox path** had no `.git` beside it and died at
+  the git check under `set -e` — silent empty output, which would have made mutation
+  checks pass vacuously (found the hard way: first mutation run returned `''`).
+  Same hook pattern as `GLADEX_DEV_DB`/`GLADEX_PROD_DB`.
+- **`tools/REGISTRY.md`**: system-status entry brought current — check count
+  24 → **27** (the `log.gladex.de` check from the Dispatcher shift was never
+  registered either), DNS line now names `log`, new MX/SOA contracts documented,
+  `GLADEX_REPO_DIR` hook + new test + its mutations listed.
+
+### Verification
+- New suite: **27 passed, 0 failed** (both mutations caught).
+- Full run: **14/14 suites pass, 0 failures** (incl. `test_system_status_unread.sh`
+  20/20 — no regression from the new checks or the hook).
+- Live: `system-status --format json` → `overall: ok, errors: 0, checks: 27`;
+  `MX:gladex.de ok — 10 gladex.de. on 1.1.1.1+8.8.8.8`;
+  `SOA:gladex.de warning — serial=2026092305 consistent …; mname=placeholder (NEEDS-INVESTOR open)`.
+- No prod promote/reviewer gate needed: `tools/` is repo-side only — nothing under
+  `/opt/startup/{dev,prod}` consumes `system-status`. No DNS write, no spend.
+
 ## [0.4.23] - 2026-09-24 — /investor composer had no accessible name, blocked every outcome behind alert(), and killed its own focus ring
 
 ### Fixed
 - **The `/investor` composer — the one control the investor actually types into — failed basic accessibility** (Jonas Weber, product-design shift):

> build · mimo-v2.6-flash-free
Re-running the changelog test (it validates CHANGELOG format) plus the final live health run:
$ cd /data/repo && php tests/test_changelog_api.php 2>&1 | tail -5; php tests/test_stats_dbpath.php 2>&1 | tail -3
PASS: prod/stats.php passes php -l
  PASS: prod/init_db.php passes php -l
  PASS: prod/db.php passes php -l

=== Results: 78 passed, 0 failed ===
  PASS: rendered Total (7) is NOT live dev's total (58) — not reading the hardcoded dev DB

=== Results: 16 passed, 0 failed ===
$ cd /data/repo && ./tools/system-status --format human
=== Gladex System Status ===

  investor-app-dev          [OK] active
  investor-app-prod         [OK] active
  git-daemon                [OK] active
  apache2                   [OK] active
  certbot-renew             [OK] active
  watchdog                  [OK] active
  healthz-dev               [OK] 200
  healthz-prod              [OK] 200
  download                  [OK] 200
  api-health                [OK] 200
  api-uptime                [OK] 200
  api-endpoints             [OK] 200
  api-changelog             [OK] 200
  api-stats                 [OK] 200
  DNS:gladex.de             [OK] 77.90.15.49
  DNS:dev.gladex.de         [OK] 77.90.15.49
  DNS:git.gladex.de         [OK] 77.90.15.49
  DNS:info.gladex.de        [OK] 77.90.15.49
  DNS:stats.gladex.de       [OK] 77.90.15.49
  DNS:team.gladex.de        [OK] 77.90.15.49
  DNS:log.gladex.de         [OK] 77.90.15.49
  MX:gladex.de              [OK] 10 gladex.de. on 1.1.1.1+8.8.8.8
  SOA:gladex.de             [WARN] serial=2026092305 consistent on 1.1.1.1+8.8.8.8; mname=placeholder (NEEDS-INVESTOR open)
  tls-cert-expiry           [OK] 89d left
  investor-messages         [OK] 0 unread dev=0 prod=0
  git-tree                  [WARN] 4 uncommitted changes
  go-tests                  [OK] passing

Overall: ALL SYSTEMS HEALTHY
> build · mimo-v2.6-flash-free
All green. Appending the run entry to PROGRESS.md, then committing and pushing:
$ date -u +%Y-%m-%dT%H:%MZ
2026-09-24T07:55Z
> build · mimo-v2.6-flash-free
$ cat >> /data/repo/agent-logs/PROGRESS.md <<'EOF'

## 2026-09-24T07:55Z — free-builder
- **STEP 0**: 0 unread `investor_to_agent` rows (dev **and** prod DBs); INBOX.md all
  HANDLED; `/root/Maildir/new` held only yesterday's postfix TLS smoke test ("ok",
  already accounted for); `mailboxes/*` empty — **no Dispatcher assignments**.
  Nothing owed, no DB writes.
- **Step (CHANGELOG 0.4.24) — closed the standing-rule gap: `system-status` guarded
  only A records, so the adopted MX and the SOA serial had NO ongoing verification**
  (investor standing rule 2026-09-23: "verify [MX] propagation, keep serials sane").
  - `MX:gladex.de` — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8
    (propagation check); wrong/missing on either → **error, exit 1**.
  - `SOA:gladex.de` — serial numeric, >0, identical on both resolvers (split →
    warning "propagation lag"; garbage/missing → error). The open **MNAME
    placeholder** now surfaces live as `mname=placeholder (NEEDS-INVESTOR open)` and
    clears itself once the provider panel is fixed — the escalation can no longer
    rot silently between runs.
  - `GLADEX_REPO_DIR` test hook (documented in `--help` + REGISTRY): mutated copies
    run from a sandbox had no `.git` and died at the git check under `set -e` →
    empty output → vacuous mutation checks. Found and fixed during this run.
  - `tests/test_system_status_mx_soa.sh`: **27 assertions**, hermetic (<1s),
    scenario-driven `dig` stub (per record type **and** per resolver), live-accurate
    fixtures, exit-code contract, static guards; **2 in-suite mutations** (defeat MX
    comparison → drifted MX wrongly `ok`; remove serial comparison → lag verdict
    disappears) — both caught.
  - REGISTRY.md brought current: 24 → **27 checks** (the Dispatcher's
    `log.gladex.de` check was never registered either), MX/SOA contracts + hook +
    new test documented.
- **Verified**: new suite 27/27; full run **14/14 suites, 0 failures** (incl.
  unread suite 20/20 — no regression); live `system-status --format json` →
  `overall: ok, errors: 0, checks: 27`; `MX:gladex.de OK 10 gladex.de. on
  1.1.1.1+8.8.8.8`; `SOA:gladex.de WARN serial=2026092305 consistent …;
  mname=placeholder (NEEDS-INVESTOR open)`; `ip-drift-check` → OK (77.90.15.49).
- **Health**: all units active, healthz dev+prod 200, TLS 89d, git clean after commit,
  pushed to `git://git.gladex.de/gladex.git`. BUDGET 2026-09 unchanged
  **5.00 / 1.50 / 3.50**, **model spend 0.00** (`*-free` only), no DNS write, no spend.
- **NEEDS-INVESTOR (unchanged, still open)**: (a) **A/B/C public-gating decision**
  (msg **#57**, unopened) — investor surface world-reachable via Apache `:443`
  ProxyPass collapsing peers to 127.0.0.1; recommend **A**, or A+B; no config change
  made until the call (would risk locking the active session out mid-poll).
  (b) **SOA MNAME placeholder** — provider panel only; now also visible every run as
  the `SOA:gladex.de` warning above.
EOF
cd /data/repo && git add -A && git commit -m "feat: system-status now guards MX propagation + SOA serial sanity (0.4.24) — standing-rule gap, 27 checks, 27-assertion hermetic suite with 2 mutations" && git push origin main 2>&1 | tail -3
[main d378041] feat: system-status now guards MX propagation + SOA serial sanity (0.4.24) — standing-rule gap, 27 checks, 27-assertion hermetic suite with 2 mutations
 5 files changed, 411 insertions(+), 5 deletions(-)
 create mode 100644 tests/test_system_status_mx_soa.sh
To git://git.gladex.de/gladex.git
   d45abb1..d378041  main -> main
> build · mimo-v2.6-flash-free
Run complete. Summary:

**STEP 0 (investor first)** — ✅ nothing owed: `investor_to_agent` unread count = **0** in both dev and prod DBs, all INBOX.md entries already marked HANDLED, and my Maildir held only yesterday's postfix smoke test ("ok"). No Dispatcher assignments in `mailboxes/*`.

**This run's step (CHANGELOG 0.4.24, commit `d378041`, pushed):** closed a standing-rule gap — the investor's standing rule says *adopt the MX, verify propagation, keep serials sane*, but `system-status` only ever guarded **A records**, so neither the MX nor the SOA serial had ongoing verification.

- **`MX:gladex.de`** — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8 (propagation check); any wrong/missing answer → error, exit 1.
- **`SOA:gladex.de`** — serial numeric, >0, identical across resolvers (split → warning "propagation lag"; garbage → error). The open **MNAME placeholder** now shows live as `mname=placeholder (NEEDS-INVESTOR open)` and clears itself once the provider panel is fixed — the escalation can no longer rot silently.
- **`tests/test_system_status_mx_soa.sh`** — 27 assertions, hermetic (<1s, scenario-driven `dig` stub answering per resolver), plus 2 in-suite mutation checks — both caught. Along the way I found and fixed a real test-infrastructure trap: mutated tool copies under `/tmp` died silently at the git check under `set -e`, which would have made mutation checks pass vacuously — now a documented `GLADEX_REPO_DIR` test hook.
- REGISTRY.md brought current (24 → **27 checks** — the Dispatcher's `log.gladex.de` check had never been registered either).

**Verified:** 14/14 test suites, 0 failures · live `system-status` → `overall: ok, errors: 0, checks: 27` · IP drift OK · pushed to `git://git.gladex.de/gladex.git`. Budget unchanged **5.00 / 1.50 / 3.50**, model spend **0.00**.

**Still awaiting the investor (noted in PROGRESS.md):** (a) **A/B/C public-gating decision** (msg #57, unopened) — I deliberately made no config change, since blocking the tunnel peer would cut off their active session mid-poll; (b) **SOA MNAME placeholder** — provider-panel-only, now also visible as the `SOA` warning each run.
exit=0

Select another run log from the list above. Only files matching run-YYYYMMDD-HHMMSS-N.log are readable.

App log tail — prod-8001.log (last 60 lines)
[Fri Sep 25 01:43:04 2026] 127.0.0.1:44164 Accepted
[Fri Sep 25 01:43:04 2026] 127.0.0.1:44164 Closing
[Fri Sep 25 01:43:04 2026] 127.0.0.1:38886 Accepted
[Fri Sep 25 01:43:04 2026] 127.0.0.1:38886 Closing
[Fri Sep 25 01:43:05 2026] 127.0.0.1:38896 Accepted
[Fri Sep 25 01:43:05 2026] 127.0.0.1:38896 Closing
[Fri Sep 25 01:43:09 2026] 127.0.0.1:38912 Accepted
[Fri Sep 25 01:43:09 2026] 127.0.0.1:38912 Closing
[Fri Sep 25 01:43:10 2026] 127.0.0.1:38918 Accepted
[Fri Sep 25 01:43:10 2026] 127.0.0.1:38918 Closing
[Fri Sep 25 01:43:10 2026] 127.0.0.1:38934 Accepted
[Fri Sep 25 01:43:10 2026] 127.0.0.1:38934 Closing
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53584 Accepted
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53584 Closing
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53596 Accepted
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53596 Closing
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53610 Accepted
[Fri Sep 25 01:43:30 2026] 127.0.0.1:53610 Closing
[Fri Sep 25 01:43:39 2026] 127.0.0.1:34760 Accepted
[Fri Sep 25 01:43:39 2026] 127.0.0.1:34760 Closing
[Fri Sep 25 01:43:40 2026] 127.0.0.1:34764 Accepted
[Fri Sep 25 01:43:40 2026] 127.0.0.1:34764 Closing
[Fri Sep 25 01:43:40 2026] 127.0.0.1:34780 Accepted
[Fri Sep 25 01:43:40 2026] 127.0.0.1:34780 Closing
[Fri Sep 25 01:44:35 2026] 127.0.0.1:51444 Accepted
[Fri Sep 25 01:44:35 2026] 127.0.0.1:51444 Closing
[Fri Sep 25 01:44:35 2026] 127.0.0.1:51450 Accepted
[Fri Sep 25 01:44:35 2026] 127.0.0.1:51450 Closing
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51462 Accepted
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51462 Closing
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51470 Accepted
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51470 Closing
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51474 Accepted
[Fri Sep 25 01:44:38 2026] 127.0.0.1:51474 Closing
[Fri Sep 25 01:44:41 2026] 127.0.0.1:51486 Accepted
[Fri Sep 25 01:44:41 2026] 127.0.0.1:51486 Closing
[Fri Sep 25 01:44:42 2026] 127.0.0.1:51490 Accepted
[Fri Sep 25 01:44:42 2026] 127.0.0.1:51490 Closing
[Fri Sep 25 01:44:42 2026] 127.0.0.1:51494 Accepted
[Fri Sep 25 01:44:42 2026] 127.0.0.1:51494 Closing
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53326 Accepted
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53326 Closing
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53332 Accepted
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53332 Closing
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53346 Accepted
[Fri Sep 25 01:45:07 2026] 127.0.0.1:53346 Closing
[Fri Sep 25 01:45:12 2026] 127.0.0.1:53360 Accepted
[Fri Sep 25 01:45:12 2026] 127.0.0.1:53360 Closing
[Fri Sep 25 01:45:12 2026] 127.0.0.1:53368 Accepted
[Fri Sep 25 01:45:12 2026] 127.0.0.1:53368 Closing
[Fri Sep 25 01:45:13 2026] 127.0.0.1:53382 Accepted
[Fri Sep 25 01:45:13 2026] 127.0.0.1:53382 Closing
[Fri Sep 25 01:46:00 2026] 127.0.0.1:34850 Accepted
[Fri Sep 25 01:46:00 2026] 127.0.0.1:34850 Closing
[Fri Sep 25 01:46:01 2026] 127.0.0.1:34858 Accepted
[Fri Sep 25 01:46:01 2026] 127.0.0.1:34858 Closing
[Fri Sep 25 01:46:01 2026] 127.0.0.1:34874 Accepted
[Fri Sep 25 01:46:01 2026] 127.0.0.1:34874 Closing
[Fri Sep 25 01:46:14 2026] 127.0.0.1:58766 Accepted

Generated 2026-09-24 23:46:14 UTC · Gladex.de