Agent run logs & app logs · env: prod · LAN-only investor surface
| Run logs | 454 files, 11.6 MB |
| Latest run log | run-20260925-012106-52.log |
| Log directory | /data/agent-logs |
| App log directory | /opt/startup/prod/logs |
| File | Size | Modified (UTC) |
|---|---|---|
| run-20260925-012106-52.log | 171 KB | 2026-09-24 23:46:11 |
| run-20260925-003542-51.log | 153 KB | 2026-09-24 23:11:06 |
| run-20260924-234828-50.log | 204 KB | 2026-09-24 22:25:42 |
| run-20260924-230237-49.log | 303 KB | 2026-09-24 21:38:28 |
| run-20260924-222340-48.log | 206 KB | 2026-09-24 20:52:37 |
| run-20260924-215353-47.log | 146 KB | 2026-09-24 20:13:40 |
| run-20260924-210315-46.log | 182 KB | 2026-09-24 19:43:53 |
| run-20260924-200755-45.log | 181 KB | 2026-09-24 18:53:15 |
| run-20260924-192844-44.log | 133 KB | 2026-09-24 17:57:55 |
| run-20260924-182059-43.log | 227 KB | 2026-09-24 17:18:44 |
| run-20260924-164658-42.log | 181 KB | 2026-09-24 16:10:59 |
| run-20260924-160206-41.log | 101 KB | 2026-09-24 14:36:58 |
| run-20260924-153643-40.log | 127 KB | 2026-09-24 13:52:05 |
| run-20260924-151001-39.log | 130 KB | 2026-09-24 13:26:43 |
| run-20260924-144921-38.log | 90 KB | 2026-09-24 13:00:01 |
| run-20260924-143001-37.log | 63 KB | 2026-09-24 12:39:21 |
| run-20260924-141012-36.log | 106 KB | 2026-09-24 12:20:01 |
| run-20260924-135151-35.log | 75 KB | 2026-09-24 12:00:12 |
| run-20260924-133211-34.log | 116 KB | 2026-09-24 11:41:51 |
| run-20260924-130932-33.log | 67 KB | 2026-09-24 11:22:11 |
| run-20260924-115831-32.log | 260 KB | 2026-09-24 10:59:32 |
| run-20260924-111405-31.log | 117 KB | 2026-09-24 09:48:31 |
| run-20260924-102752-30.log | 106 KB | 2026-09-24 09:04:05 |
| run-20260924-100538-29.log | 81 KB | 2026-09-24 08:17:52 |
| run-20260924-092904-28.log | 101 KB | 2026-09-24 07:55:38 |
| run-20260924-083526-27.log | 116 KB | 2026-09-24 07:19:04 |
| run-20260924-080136-26.log | 75 KB | 2026-09-24 06:25:26 |
| run-20260924-074910-25.log | 23 KB | 2026-09-24 05:51:36 |
| run-20260924-072601-24.log | 52 KB | 2026-09-24 05:39:10 |
| run-20260924-065657-23.log | 156 KB | 2026-09-24 05:16:01 |
| run-20260924-063310-22.log | 76 KB | 2026-09-24 04:46:57 |
| run-20260924-055309-21.log | 107 KB | 2026-09-24 04:23:10 |
| run-20260924-052831-20.log | 133 KB | 2026-09-24 03:43:09 |
| run-20260924-050107-19.log | 69 KB | 2026-09-24 03:18:31 |
| run-20260924-044831-18.log | 34 KB | 2026-09-24 02:51:07 |
| run-20260924-041948-17.log | 156 KB | 2026-09-24 02:38:31 |
| run-20260924-035438-16.log | 185 KB | 2026-09-24 02:09:48 |
| run-20260924-033002-15.log | 245 KB | 2026-09-24 01:44:38 |
| run-20260924-025910-14.log | 120 KB | 2026-09-24 01:20:02 |
| run-20260924-023430-13.log | 97 KB | 2026-09-24 00:49:10 |
| run-20260924-015458-12.log | 255 KB | 2026-09-24 00:24:30 |
| run-20260924-012751-11.log | 179 KB | 2026-09-23 23:44:58 |
| run-20260924-005036-10.log | 162 KB | 2026-09-23 23:17:51 |
| run-20260924-000545-9.log | 217 KB | 2026-09-23 22:40:36 |
| run-20260923-235334-8.log | 29 KB | 2026-09-23 21:55:45 |
| run-20260923-233751-7.log | 97 KB | 2026-09-23 21:43:34 |
| run-20260923-231451-6.log | 165 KB | 2026-09-23 21:27:51 |
| run-20260923-225120-5.log | 58 KB | 2026-09-23 21:04:51 |
| run-20260923-222610-4.log | 230 KB | 2026-09-23 20:41:20 |
| run-20260923-205439-3.log | 640 KB | 2026-09-23 20:16:10 |
+ consistent/split/non-numeric/missing, placeholder↔real MNAME verdicts, exit-code
+ contract (error→1, warning→0), static wiring guards, `--help`→0 / bad-arg→2
+- **Mutation (in-suite, both planted on copies via `GLADEX_REPO_DIR`)**: defeating
+ the MX comparison → drifted MX wrongly reports `ok` (caught); removing the serial
+ comparison → the "propagation lag" verdict disappears (caught)
- `system-status --format json` → valid JSON with overall status
-**Status**: Built ✅ (2026-09-24: counts both DBs + `timeout 30` → `120`)
+**Status**: Built ✅ (2026-09-24: counts both DBs, `timeout 30` → `120`, + MX/SOA
+mail-DNS checks — 27 checks)
---
## version-check
> build · mimo-v2.6-flash-free
Now the CHANGELOG entry:
[0m← [0mEdit repo/CHANGELOG.md
Index: repo/CHANGELOG.md
===================================================================
--- repo/CHANGELOG.md
+++ repo/CHANGELOG.md
@@ -3,8 +3,63 @@
All notable changes to Gladex are documented here.
Format: `[version] - YYYY-MM-DD — description`
+## [0.4.24] - 2026-09-24 — system-status now guards the adopted MX and SOA serial (the A-record-only DNS check was blind to mail)
+
+### Added
+- **`tools/system-status`: two new checks (25 → 27), closing the standing investor
+ rule from 2026-09-23** ("MX gladex.de is now set — adopt it: verify propagation,
+ keep serials sane"). The tool's `check_dns` guarded only **A records**, so mail
+ routing could drift (MX changed/removed at the resolver) or the SOA serial go
+ insane without any run noticing:
+ - **`MX:gladex.de`** — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8
+ (propagation check, two resolvers like the manual DOMAIN.md verification).
+ Wrong or missing answer on either resolver → **error, exit 1** — a wrong MX on
+ a public resolver is a mail outage, not a warning. Multi-record answers are
+ collapsed with `paste` so the JSON output stays valid.
+ - **`SOA:gladex.de`** — serial parsed from both resolvers: must be numeric, >0,
+ and identical (a split → **warning** "propagation lag", transient by
+ definition; garbage/missing → **error**). The known `MNAME` placeholder
+ (`a.misconfigured.dns.server.invalid.` — provider-panel-only fix, open
+ NEEDS-INVESTOR) is surfaced as a **warning** in the detail —
+ `serial=2026092305 consistent …; mname=placeholder (NEEDS-INVESTOR open)` — so
+ the open item is visible on every health run and **clears itself** the moment
+ the panel value changes.
+- **`tests/test_system_status_mx_soa.sh` — 27 assertions**, hermetic and <1s. The
+ `dig` stub is **scenario-driven per record type AND per resolver**, so MX/SOA
+ answers can be pinned per run (live-accurate fixtures verified 2026-09-24);
+ `GLADEX_DEV_DB`/`GLADEX_PROD_DB` point at absent DBs so the live message DBs are
+ never read. Covers: MX ok/missing/drifted-on-one-resolver (non-vacuity: the other
+ resolver correct), serial consistent/split/non-numeric/missing, placeholder↔real
+ MNAME verdicts, exit-code contract (error→1, warning→0), static wiring guards,
+ `--help`→0 / bad-arg→2.
+- **Two in-suite mutation checks**: defeating the MX comparison (condition → always
+ true) makes drifted MX report `ok` — caught; removing the serial comparison makes
+ the "propagation lag" verdict disappear — caught.
+
+### Changed
+- **`GLADEX_REPO_DIR` test hook on `system-status`** (documented in `--help` +
+ REGISTRY): the git/Go checks resolve `REPO_DIR` from the script's own location,
+ so a **mutated copy run from a sandbox path** had no `.git` beside it and died at
+ the git check under `set -e` — silent empty output, which would have made mutation
+ checks pass vacuously (found the hard way: first mutation run returned `''`).
+ Same hook pattern as `GLADEX_DEV_DB`/`GLADEX_PROD_DB`.
+- **`tools/REGISTRY.md`**: system-status entry brought current — check count
+ 24 → **27** (the `log.gladex.de` check from the Dispatcher shift was never
+ registered either), DNS line now names `log`, new MX/SOA contracts documented,
+ `GLADEX_REPO_DIR` hook + new test + its mutations listed.
+
+### Verification
+- New suite: **27 passed, 0 failed** (both mutations caught).
+- Full run: **14/14 suites pass, 0 failures** (incl. `test_system_status_unread.sh`
+ 20/20 — no regression from the new checks or the hook).
+- Live: `system-status --format json` → `overall: ok, errors: 0, checks: 27`;
+ `MX:gladex.de ok — 10 gladex.de. on 1.1.1.1+8.8.8.8`;
+ `SOA:gladex.de warning — serial=2026092305 consistent …; mname=placeholder (NEEDS-INVESTOR open)`.
+- No prod promote/reviewer gate needed: `tools/` is repo-side only — nothing under
+ `/opt/startup/{dev,prod}` consumes `system-status`. No DNS write, no spend.
+
## [0.4.23] - 2026-09-24 — /investor composer had no accessible name, blocked every outcome behind alert(), and killed its own focus ring
### Fixed
- **The `/investor` composer — the one control the investor actually types into — failed basic accessibility** (Jonas Weber, product-design shift):
> build · mimo-v2.6-flash-free
Re-running the changelog test (it validates CHANGELOG format) plus the final live health run:
[0m$ [0mcd /data/repo && php tests/test_changelog_api.php 2>&1 | tail -5; php tests/test_stats_dbpath.php 2>&1 | tail -3
PASS: prod/stats.php passes php -l
PASS: prod/init_db.php passes php -l
PASS: prod/db.php passes php -l
=== Results: 78 passed, 0 failed ===
PASS: rendered Total (7) is NOT live dev's total (58) — not reading the hardcoded dev DB
=== Results: 16 passed, 0 failed ===
[0m$ [0mcd /data/repo && ./tools/system-status --format human
=== Gladex System Status ===
investor-app-dev [OK] active
investor-app-prod [OK] active
git-daemon [OK] active
apache2 [OK] active
certbot-renew [OK] active
watchdog [OK] active
healthz-dev [OK] 200
healthz-prod [OK] 200
download [OK] 200
api-health [OK] 200
api-uptime [OK] 200
api-endpoints [OK] 200
api-changelog [OK] 200
api-stats [OK] 200
DNS:gladex.de [OK] 77.90.15.49
DNS:dev.gladex.de [OK] 77.90.15.49
DNS:git.gladex.de [OK] 77.90.15.49
DNS:info.gladex.de [OK] 77.90.15.49
DNS:stats.gladex.de [OK] 77.90.15.49
DNS:team.gladex.de [OK] 77.90.15.49
DNS:log.gladex.de [OK] 77.90.15.49
MX:gladex.de [OK] 10 gladex.de. on 1.1.1.1+8.8.8.8
SOA:gladex.de [WARN] serial=2026092305 consistent on 1.1.1.1+8.8.8.8; mname=placeholder (NEEDS-INVESTOR open)
tls-cert-expiry [OK] 89d left
investor-messages [OK] 0 unread dev=0 prod=0
git-tree [WARN] 4 uncommitted changes
go-tests [OK] passing
Overall: ALL SYSTEMS HEALTHY
> build · mimo-v2.6-flash-free
All green. Appending the run entry to PROGRESS.md, then committing and pushing:
[0m$ [0mdate -u +%Y-%m-%dT%H:%MZ
2026-09-24T07:55Z
> build · mimo-v2.6-flash-free
[0m$ [0mcat >> /data/repo/agent-logs/PROGRESS.md <<'EOF'
## 2026-09-24T07:55Z — free-builder
- **STEP 0**: 0 unread `investor_to_agent` rows (dev **and** prod DBs); INBOX.md all
HANDLED; `/root/Maildir/new` held only yesterday's postfix TLS smoke test ("ok",
already accounted for); `mailboxes/*` empty — **no Dispatcher assignments**.
Nothing owed, no DB writes.
- **Step (CHANGELOG 0.4.24) — closed the standing-rule gap: `system-status` guarded
only A records, so the adopted MX and the SOA serial had NO ongoing verification**
(investor standing rule 2026-09-23: "verify [MX] propagation, keep serials sane").
- `MX:gladex.de` — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8
(propagation check); wrong/missing on either → **error, exit 1**.
- `SOA:gladex.de` — serial numeric, >0, identical on both resolvers (split →
warning "propagation lag"; garbage/missing → error). The open **MNAME
placeholder** now surfaces live as `mname=placeholder (NEEDS-INVESTOR open)` and
clears itself once the provider panel is fixed — the escalation can no longer
rot silently between runs.
- `GLADEX_REPO_DIR` test hook (documented in `--help` + REGISTRY): mutated copies
run from a sandbox had no `.git` and died at the git check under `set -e` →
empty output → vacuous mutation checks. Found and fixed during this run.
- `tests/test_system_status_mx_soa.sh`: **27 assertions**, hermetic (<1s),
scenario-driven `dig` stub (per record type **and** per resolver), live-accurate
fixtures, exit-code contract, static guards; **2 in-suite mutations** (defeat MX
comparison → drifted MX wrongly `ok`; remove serial comparison → lag verdict
disappears) — both caught.
- REGISTRY.md brought current: 24 → **27 checks** (the Dispatcher's
`log.gladex.de` check was never registered either), MX/SOA contracts + hook +
new test documented.
- **Verified**: new suite 27/27; full run **14/14 suites, 0 failures** (incl.
unread suite 20/20 — no regression); live `system-status --format json` →
`overall: ok, errors: 0, checks: 27`; `MX:gladex.de OK 10 gladex.de. on
1.1.1.1+8.8.8.8`; `SOA:gladex.de WARN serial=2026092305 consistent …;
mname=placeholder (NEEDS-INVESTOR open)`; `ip-drift-check` → OK (77.90.15.49).
- **Health**: all units active, healthz dev+prod 200, TLS 89d, git clean after commit,
pushed to `git://git.gladex.de/gladex.git`. BUDGET 2026-09 unchanged
**5.00 / 1.50 / 3.50**, **model spend 0.00** (`*-free` only), no DNS write, no spend.
- **NEEDS-INVESTOR (unchanged, still open)**: (a) **A/B/C public-gating decision**
(msg **#57**, unopened) — investor surface world-reachable via Apache `:443`
ProxyPass collapsing peers to 127.0.0.1; recommend **A**, or A+B; no config change
made until the call (would risk locking the active session out mid-poll).
(b) **SOA MNAME placeholder** — provider panel only; now also visible every run as
the `SOA:gladex.de` warning above.
EOF
cd /data/repo && git add -A && git commit -m "feat: system-status now guards MX propagation + SOA serial sanity (0.4.24) — standing-rule gap, 27 checks, 27-assertion hermetic suite with 2 mutations" && git push origin main 2>&1 | tail -3
[main d378041] feat: system-status now guards MX propagation + SOA serial sanity (0.4.24) — standing-rule gap, 27 checks, 27-assertion hermetic suite with 2 mutations
5 files changed, 411 insertions(+), 5 deletions(-)
create mode 100644 tests/test_system_status_mx_soa.sh
To git://git.gladex.de/gladex.git
d45abb1..d378041 main -> main
> build · mimo-v2.6-flash-free
Run complete. Summary:
**STEP 0 (investor first)** — ✅ nothing owed: `investor_to_agent` unread count = **0** in both dev and prod DBs, all INBOX.md entries already marked HANDLED, and my Maildir held only yesterday's postfix smoke test ("ok"). No Dispatcher assignments in `mailboxes/*`.
**This run's step (CHANGELOG 0.4.24, commit `d378041`, pushed):** closed a standing-rule gap — the investor's standing rule says *adopt the MX, verify propagation, keep serials sane*, but `system-status` only ever guarded **A records**, so neither the MX nor the SOA serial had ongoing verification.
- **`MX:gladex.de`** — must be `10 gladex.de.` on **both** 1.1.1.1 and 8.8.8.8 (propagation check); any wrong/missing answer → error, exit 1.
- **`SOA:gladex.de`** — serial numeric, >0, identical across resolvers (split → warning "propagation lag"; garbage → error). The open **MNAME placeholder** now shows live as `mname=placeholder (NEEDS-INVESTOR open)` and clears itself once the provider panel is fixed — the escalation can no longer rot silently.
- **`tests/test_system_status_mx_soa.sh`** — 27 assertions, hermetic (<1s, scenario-driven `dig` stub answering per resolver), plus 2 in-suite mutation checks — both caught. Along the way I found and fixed a real test-infrastructure trap: mutated tool copies under `/tmp` died silently at the git check under `set -e`, which would have made mutation checks pass vacuously — now a documented `GLADEX_REPO_DIR` test hook.
- REGISTRY.md brought current (24 → **27 checks** — the Dispatcher's `log.gladex.de` check had never been registered either).
**Verified:** 14/14 test suites, 0 failures · live `system-status` → `overall: ok, errors: 0, checks: 27` · IP drift OK · pushed to `git://git.gladex.de/gladex.git`. Budget unchanged **5.00 / 1.50 / 3.50**, model spend **0.00**.
**Still awaiting the investor (noted in PROGRESS.md):** (a) **A/B/C public-gating decision** (msg #57, unopened) — I deliberately made no config change, since blocking the tunnel peer would cut off their active session mid-poll; (b) **SOA MNAME placeholder** — provider-panel-only, now also visible as the `SOA` warning each run.
exit=0
Select another run log from the list above. Only files matching run-YYYYMMDD-HHMMSS-N.log are readable.
[Fri Sep 25 01:43:04 2026] 127.0.0.1:44164 Accepted [Fri Sep 25 01:43:04 2026] 127.0.0.1:44164 Closing [Fri Sep 25 01:43:04 2026] 127.0.0.1:38886 Accepted [Fri Sep 25 01:43:04 2026] 127.0.0.1:38886 Closing [Fri Sep 25 01:43:05 2026] 127.0.0.1:38896 Accepted [Fri Sep 25 01:43:05 2026] 127.0.0.1:38896 Closing [Fri Sep 25 01:43:09 2026] 127.0.0.1:38912 Accepted [Fri Sep 25 01:43:09 2026] 127.0.0.1:38912 Closing [Fri Sep 25 01:43:10 2026] 127.0.0.1:38918 Accepted [Fri Sep 25 01:43:10 2026] 127.0.0.1:38918 Closing [Fri Sep 25 01:43:10 2026] 127.0.0.1:38934 Accepted [Fri Sep 25 01:43:10 2026] 127.0.0.1:38934 Closing [Fri Sep 25 01:43:30 2026] 127.0.0.1:53584 Accepted [Fri Sep 25 01:43:30 2026] 127.0.0.1:53584 Closing [Fri Sep 25 01:43:30 2026] 127.0.0.1:53596 Accepted [Fri Sep 25 01:43:30 2026] 127.0.0.1:53596 Closing [Fri Sep 25 01:43:30 2026] 127.0.0.1:53610 Accepted [Fri Sep 25 01:43:30 2026] 127.0.0.1:53610 Closing [Fri Sep 25 01:43:39 2026] 127.0.0.1:34760 Accepted [Fri Sep 25 01:43:39 2026] 127.0.0.1:34760 Closing [Fri Sep 25 01:43:40 2026] 127.0.0.1:34764 Accepted [Fri Sep 25 01:43:40 2026] 127.0.0.1:34764 Closing [Fri Sep 25 01:43:40 2026] 127.0.0.1:34780 Accepted [Fri Sep 25 01:43:40 2026] 127.0.0.1:34780 Closing [Fri Sep 25 01:44:35 2026] 127.0.0.1:51444 Accepted [Fri Sep 25 01:44:35 2026] 127.0.0.1:51444 Closing [Fri Sep 25 01:44:35 2026] 127.0.0.1:51450 Accepted [Fri Sep 25 01:44:35 2026] 127.0.0.1:51450 Closing [Fri Sep 25 01:44:38 2026] 127.0.0.1:51462 Accepted [Fri Sep 25 01:44:38 2026] 127.0.0.1:51462 Closing [Fri Sep 25 01:44:38 2026] 127.0.0.1:51470 Accepted [Fri Sep 25 01:44:38 2026] 127.0.0.1:51470 Closing [Fri Sep 25 01:44:38 2026] 127.0.0.1:51474 Accepted [Fri Sep 25 01:44:38 2026] 127.0.0.1:51474 Closing [Fri Sep 25 01:44:41 2026] 127.0.0.1:51486 Accepted [Fri Sep 25 01:44:41 2026] 127.0.0.1:51486 Closing [Fri Sep 25 01:44:42 2026] 127.0.0.1:51490 Accepted [Fri Sep 25 01:44:42 2026] 127.0.0.1:51490 Closing [Fri Sep 25 01:44:42 2026] 127.0.0.1:51494 Accepted [Fri Sep 25 01:44:42 2026] 127.0.0.1:51494 Closing [Fri Sep 25 01:45:07 2026] 127.0.0.1:53326 Accepted [Fri Sep 25 01:45:07 2026] 127.0.0.1:53326 Closing [Fri Sep 25 01:45:07 2026] 127.0.0.1:53332 Accepted [Fri Sep 25 01:45:07 2026] 127.0.0.1:53332 Closing [Fri Sep 25 01:45:07 2026] 127.0.0.1:53346 Accepted [Fri Sep 25 01:45:07 2026] 127.0.0.1:53346 Closing [Fri Sep 25 01:45:12 2026] 127.0.0.1:53360 Accepted [Fri Sep 25 01:45:12 2026] 127.0.0.1:53360 Closing [Fri Sep 25 01:45:12 2026] 127.0.0.1:53368 Accepted [Fri Sep 25 01:45:12 2026] 127.0.0.1:53368 Closing [Fri Sep 25 01:45:13 2026] 127.0.0.1:53382 Accepted [Fri Sep 25 01:45:13 2026] 127.0.0.1:53382 Closing [Fri Sep 25 01:46:00 2026] 127.0.0.1:34850 Accepted [Fri Sep 25 01:46:00 2026] 127.0.0.1:34850 Closing [Fri Sep 25 01:46:01 2026] 127.0.0.1:34858 Accepted [Fri Sep 25 01:46:01 2026] 127.0.0.1:34858 Closing [Fri Sep 25 01:46:01 2026] 127.0.0.1:34874 Accepted [Fri Sep 25 01:46:01 2026] 127.0.0.1:34874 Closing [Fri Sep 25 01:46:14 2026] 127.0.0.1:58766 Accepted
Generated 2026-09-24 23:46:14 UTC · Gladex.de