box_walk: a target table (9202, 9201, tester-1 via a jump through the HP box); the Tester 1 guest is a test box for the admin seed (R-892, decision 158)
gates / gates (push) Successful in 5s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 19:04:57 +02:00
parent a5a5b51c77
commit d63ea3591e
4 changed files with 101 additions and 12 deletions
+35 -6
View File
@@ -28,12 +28,41 @@ from datetime import datetime, timezone
SC = os.environ.get('SC', os.path.expanduser('~/.felhom-retest'))
EV = os.environ.get('EV', os.path.join(SC, 'evidence'))
DRILL = "/mnt/5_hdd/felhom.eu/drill/app-catalog-drill"
# GUEST=9201 selects demo-hp's hub-enabled guest (the mail proof); default 9202, the scratch guest.
GUEST = os.environ.get("GUEST", "9202")
BASE = os.environ.get("BASE") or {"9202": "https://192.168.0.114", "9201": "https://192.168.0.155"}[GUEST]
DOMAIN = os.environ.get("DOMAIN", "enkisfelhom.hu")
# THE TARGETS (R-892, 2026-10-06): one row per box the walk may drive. `hp` is the box's NAME for the guards
# (upgrade_fixtures_box.BOX_ADMIN_SEED_GUESTS keys on (hp, guest)); `ssh` is how its Proxmox host is reached, with an
# optional `jump` (never an edit of DooPlex's ~/.ssh/config); `guest` the customer LXC; `base` and `domain` its dashboard.
# TARGET=9202 (default) scratch guest 9202 on demo-hp
# TARGET=9201 demo-hp's hub-enabled guest (the mail proof) — household-shaped, never seeded through an admin
# TARGET=tester-1 the Tester 1 box: VM 341 on the HP box (`09` §3 decision 158), its node `felhom` at
# 192.168.0.154, guest 9201 at 192.168.0.101 for felhom.enkicsifelhom.hu (identity matched
# 2026-10-06: the agent's report `host.node=felhom` = the VM's certificate; the guest answers
# that domain, the other one 404 — `felhom.eu/documentation/audits/readback-2026-10-07/`)
# GUEST=<vmid> still selects a demo-hp row (the old switch), unless TARGET is set.
TARGETS = {
"9202": {"hp": "demo-hp", "ssh": "demo-hp", "jump": None, "guest": "9202",
"base": "https://192.168.0.114", "domain": "enkisfelhom.hu"},
"9201": {"hp": "demo-hp", "ssh": "demo-hp", "jump": None, "guest": "9201",
"base": "https://192.168.0.155", "domain": "enkisfelhom.hu"},
"tester-1": {"hp": "tester-1", "ssh": "root@192.168.0.154", "jump": "demo-hp", "guest": "9201",
"base": "https://192.168.0.101", "domain": "enkicsifelhom.hu"},
}
TARGET = os.environ.get("TARGET") or os.environ.get("GUEST", "9202")
if TARGET not in TARGETS:
raise SystemExit(f"box_walk: unknown TARGET {TARGET!r} — one of {sorted(TARGETS)}")
_T = TARGETS[TARGET]
GUEST = _T["guest"]
BASE = os.environ.get("BASE") or _T["base"]
DOMAIN = os.environ.get("DOMAIN") or _T["domain"]
HOSTHDR = f"Host: felhom.{DOMAIN}"
HP = "demo-hp"
HP = _T["hp"]
def ssh_args():
"""The ssh argv prefix that reaches the target's Proxmox host (a jump when the row names one)."""
a = ["ssh", "-o", "ConnectTimeout=20", "-o", "StrictHostKeyChecking=accept-new"]
if _T["jump"]:
a += ["-J", _T["jump"]]
return a + [_T["ssh"]]
LOG = []
@@ -58,7 +87,7 @@ def guest(script, timeout=600):
# two concurrent walks (memory: guest-helper-shares-one-tmp-file).
import secrets as _s
t = f"/tmp/w{GUEST}-{os.getpid()}-{_s.token_hex(4)}.sh"
r = sh(["ssh", "-o", "ConnectTimeout=20", "-o", "StrictHostKeyChecking=accept-new", HP,
r = sh(ssh_args() + [
f"export LC_ALL=C; cat > {t}; pct push {GUEST} {t} {t} >/dev/null 2>&1; "
f"pct exec {GUEST} -- bash {t}; pct exec {GUEST} -- rm -f {t}; rm -f {t}"],
timeout=timeout, inp=script)