HEX
Server: LiteSpeed
System: Linux houston.panomity.com 6.8.0-100-generic #100-Ubuntu SMP PREEMPT_DYNAMIC Tue Jan 13 16:40:06 UTC 2026 x86_64
User: nudepix (1011)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: //proc/self/root/workspace/rollout/rollback-mission-control-fix.md
# Mission Control rollout rollback

## Purpose

Rollback the LiteSpeed carve-out if the public `/mc` worker/API exposure behaves unexpectedly after the live rollout.

## Scope

This rollback restores the previous LiteSpeed vhost config from the backup created by `apply-mission-control-fix.sh` and reloads LiteSpeed.

It does **not** revert the frontend files in the repo. That is intentional:

- the frontend proxy fix was already validated on the alternate runtime
- the higher-risk live change is the public LiteSpeed carve-out
- restoring the vhost backup is the fastest way to re-protect `/mc` at the public edge

## Command

```bash
cd rollout
I_UNDERSTAND_THIS_RELOADS_SERVICES=YES ./rollback-mission-control-fix.sh /usr/local/lsws/conf/vhosts/altaira.panomity.com/vhost.conf.bak.TIMESTAMP
```

Use the exact backup path printed by `apply-mission-control-fix.sh` during rollout.

## Expected result

After reload, the public `/mc` worker/API carve-outs should be gone again and the protected UI boundary should behave as before.