Skip to content

Release validation: complete real-lab scenarios 26–40 and endurance gates #61

Description

@vladimirperovic

Why this remains open

The code/CI candidate is heavily validated, but the repository does not yet contain current real-Proxmox evidence for the repaired scenarios 26–30 or committed result artifacts for scenarios 31–40. This is a release-evidence gap, not a reason to claim those conditions already passed.

Required isolated-lab reruns

  • 26 ENOSPC: dynamic root fill reaches the intended low-space condition; save fails cleanly; firewall/LAN/DNS/Internet remain safe; recovery save converges after cleanup.
  • 27 live LAN interface move: deliberate API rejection is observed with no disruption.
  • 28 live LAN subnet move: deliberate API rejection is observed with no disruption.
  • 29 Squid: authenticated LAN client fetch succeeds through the proxy after the output-chain reply-direction fix; disable returns to clean state.
  • 30 DDNS: unreachable provider causes the one-shot provider verification to reject the save and roll back cleanly.
  • 31 encrypted backup/restore onto a fresh VM/appliance instance.
  • 32 inode exhaustion fail-closed behavior and recovery.
  • 33 read-only-rootfs behavior and recovery.
  • 34 external/WAN port scan proving the expected exposure surface.
  • 35 sustained throughput/latency/loss/thermal soak with recorded measurements.
  • 36 corrupt metadata recovery/fail-closed behavior.
  • 37 snapshot/restore convergence.
  • 38 WireGuard peer rotation and recovery.
  • 39 DNS rebinding protections.
  • 40 WAN IP change with DDNS/tunnel recovery as applicable.

Endurance / production-adjacent gates

  • Repeated cold boots with stable interface identity and no stale DHCP/networking delay.
  • Repeated real PPPoE reconnect/reboot cycles with the target ISP.
  • WireGuard recovery across PPPoE reconnect and reboot.
  • At least 7 days of unattended stable operation with no unexplained service restarts, transaction divergence, or thermal/resource drift.
  • Independent signed install/recovery-media test and independent security review before calling the appliance an unattended pfSense/OpenWrt replacement.

Evidence rule

For each scenario, commit result.txt plus the relevant evidence artifact/log under scripts/lab/scenarios/results/; update docs/CURRENT_VALIDATION.md only after the real run passes. Do not convert missing evidence into a documentation-only PASS.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions