Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| dd7cdc09e7 | |||
| 7b0a8b234b | |||
| ce1a4b4758 | |||
| ac90169a5d | |||
| 154d6dcaa9 | |||
| 2f7072050f | |||
| 85e799f360 |
@@ -23,7 +23,8 @@ unconditional: true
|
|||||||
customer data; anything that changes a promise the product makes to a customer; anything that
|
customer data; anything that changes a promise the product makes to a customer; anything that
|
||||||
reverses a documented design decision (`documentation/architecture/` — a design decision is not a
|
reverses a documented design decision (`documentation/architecture/` — a design decision is not a
|
||||||
defect, R-370); anything on DooPlex or ep0; baking or vouching a golden; promoting a
|
defect, R-370); anything on DooPlex or ep0; baking or vouching a golden; promoting a
|
||||||
catalog version; a new external dependency.
|
catalog version; a new external dependency; **a hub image build or hub deploy in a session the operator does not
|
||||||
|
attend** (operator ruling 2026-10-07, `09` §3 decision 162).
|
||||||
|
|
||||||
## 2. When you may decide instead of ask (operator grant, 2026-09-14)
|
## 2. When you may decide instead of ask (operator grant, 2026-09-14)
|
||||||
|
|
||||||
|
|||||||
+47
-4
@@ -1,4 +1,47 @@
|
|||||||
## Unreleased (2026-10-06 night, later) — after a restart the agent remembers the last backup per tier (R-894); three more SMART counters on the wire (R-330)
|
## Unreleased (2026-10-07) — the agent can no longer hand the guest any image; felhom-op's pct lines are exact (R-861 (a) A1, (b) B2; `09` §3 decision 165)
|
||||||
|
|
||||||
|
**Delivery order: agent binary FIRST, then the config bundle.** The new sudoers drops the agent's in-guest `tee`
|
||||||
|
grant; an older binary still calls `tee`, so a bundle that lands before the binary would stop managed controller
|
||||||
|
updates (and the old binary's capability probe would read `controllerswap-write` degraded). No bundle path is added
|
||||||
|
(`felhom-priv-apply` and `/etc/sudoers.d/felhom-op` are already bundle files), so no step bundle.
|
||||||
|
|
||||||
|
- `configs/felhom-priv-apply`: new verb `controller-image <vmid>` — reads the ref on stdin (≤ 256 bytes, ASCII, one
|
||||||
|
optional trailing newline), requires `^gitea\.dooplex\.hu/admin/felhom-controller:[0-9]+\.[0-9]+\.[0-9]+$` (the agent's
|
||||||
|
own `controllerImageRe`), then runs `pct exec <vmid> -- tee /etc/felhom-controller-image` AS ROOT; refusal rule `I1`
|
||||||
|
(rc 3), a bad vmid `A1` (rc 2); listed in `--self-check`.
|
||||||
|
- `configs/felhom-agent.sudoers` `FELHOM_CONTROLLERSWAP`: `pct ^exec [0-9]+ -- tee /etc/felhom-controller-image$`
|
||||||
|
REMOVED; `/usr/local/sbin/felhom-priv-apply ^controller-image [0-9]+$` added.
|
||||||
|
- `internal/localapi`: `GuestExecutor.GuestExecStdin` replaced by `WriteControllerImage`; `GuestBinder.WriteControllerImage`
|
||||||
|
pipes `ref\n` to the verb through the fenced runner; the swap's `writeImage` calls it. Capability `controllerswap-write`
|
||||||
|
now probes the verb.
|
||||||
|
- `configs/felhom-op.sudoers` (B2, hygiene): `pct start|stop|unlock [0-9]*` → `pct ^start [0-9]+$` etc. (the glob's `*`
|
||||||
|
matched spaces: `pct stop 9201 --skiplock 1` passed).
|
||||||
|
- Tests: `ControllerImage` (5, `configs/test_felhom_priv_apply.py`), `TestSudoersRefusesTheR861Injections` (+3 lines),
|
||||||
|
`TestSudoersAllowsTheControllerImageVerb`, `TestFelhomOpSudoersPctIsExact`, `TestR861_WriteControllerImageUsesTheRootVerb`,
|
||||||
|
`TestControllerSwap_WriteViaRootVerb_NoShell`. Red-proofs: `felhom.eu/documentation/audits/day-2026-10-07/C/`.
|
||||||
|
- `README.md`: the controller-swap paragraph described the removed `tee` path — corrected.
|
||||||
|
## Unreleased (2026-10-07) — the Proxmox package lane (R-812 option A, `09` §3 decision 163)
|
||||||
|
|
||||||
|
**MinAgent impact: none** (a new layer; an older hub ignores the pve report). **The bundle carries the new
|
||||||
|
`felhom-os-apply` — deliver it with the binary** (signed `agent_update`, then signed `agent_config_update`).
|
||||||
|
|
||||||
|
- `configs/felhom-os-apply`: new layer `pve`, lane `slow` only — the host's Proxmox USERSPACE packages: origin `Proxmox Debian Repository` only (R2), never a kernel / boot / firmware / microcode name (R14, `HOST_SLOW_RE` — the kernel is R-836's lane), no removal (R4), no undo (R5), a new package only from `PVE_NEW_ALLOW` (`proxmox-firewall-data`, measured on demo-felhom; R6 otherwise), an appliance only (R12), authority = a signed `os_pve_step` or the root-owned ring-0 mark (R3). Select `pending-pve` (ring 0): installed Proxmox-origin packages with a pending upgrade. The report carries `pve_manager` (pveversion after the step).
|
||||||
|
- `internal/pvegate` (new): the agent's own writes to /etc/pve wait while a pve step runs (pmxcfs restarts); the step waits for writes in flight (bounded, 2 min — then it fails and does not run). Wired at `proxmox.Client.doBody` (every non-GET) and `ExecRunner.RunStdin` (`WritesEtcPVE`: pct config verbs, pvesm, pveum, felhom-pbs-apply create/reconcile).
|
||||||
|
- `internal/osupdate`: `LayerPVE`; the night leg runs the pve step in ring 0 after a healthy host step (an appliance; ring 1 never in the night leg); `PVEHealthVerdict` = the host rule + every running container keeps its id + pveversion reads the installed pve-manager; the pve report carries Proxmox userspace only (the hub's candidate set). `PVEStepExecutor` (signed `os_pve_step`, ring 1, under the heavy-op gate and the /etc/pve gate); `reconcile.ClassOSPVEStep` (destructive-class); `felhom-opsign -op os_pve_step` (params by `-params`).
|
||||||
|
- Tests: wrapper `PVELane` (17; red first — the `pve-manager` plan was refused R12 on the old code), `pvegate` (5), `TestPVEGate_*` + `TestWritesEtcPVE`, `TestPVE_*`, `TestPVEHealthVerdict`, `TestPVEStepExecutor_*`. Red-proofs: `felhom.eu/documentation/audits/day-2026-10-07/B/`.
|
||||||
|
## Unreleased (2026-10-07)
|
||||||
|
|
||||||
|
- R-366 slice 2 (`09` §3 decision 168): the restore-test pick records, per tier, the archives it skipped as written with another key (count, oldest, newest — no key material) in a `ForeignKeyLedger`; the host report carries it as `foreign_key_archives.tiers` (the stanza absent until a tier was evaluated since start, `tiers: []` when none — no null on the wire, the report contract forbids it). The hub turns a change into one operator line. Tests `TestR366_PickRecordsArchivesWrittenWithAnotherKey`, `TestR366_EvaluatedWithNoneIsAnEmptyList` (red-proved, `felhom.eu/documentation/audits/day-2026-10-07/E/`).
|
||||||
|
- R-105 option A (`09` §3 decision 169): the `--selftest=escrow-create -directive <file>` flag and the escrow upload's `directive` field are removed — nothing read the directive; the DR path reads the recipe, tenantsync and the escrow blob. The hub ignores a `directive` from an older agent.
|
||||||
|
|
||||||
|
## v0.150.0 — the Docker step proves the engine reports a memory kill; after a restart the agent remembers the last backup per tier; three more SMART counters on the wire (R-528, R-894, R-330; `09` §3 decisions 157, 161) (2026-10-07)
|
||||||
|
|
||||||
|
Released by `scripts/release-agent.sh`: binary sha256 `a23d1c9085bc7fd4fc48fe0327f6504aa83e6331510fb4a3d23e042dddb26f9c`
|
||||||
|
config bundle sha256 `88456b386d9b1027bd22861cac8c23df004bf9fd9f67644d6595bfca8c94498e` (tag `v0.150.0` = `3a72a48`).
|
||||||
|
**The bundle carries the new `felhom-os-apply` (the memory-kill check) — deliver it with the binary:** signed
|
||||||
|
`agent_update`, then signed `agent_config_update`. No path added (26 → 26), so no step bundle.
|
||||||
|
|
||||||
|
### Part of v0.150.0 (2026-10-06 night, later) — after a restart the agent remembers the last backup per tier (R-894); three more SMART counters on the wire (R-330)
|
||||||
|
|
||||||
Ships with the memory-kill check below as v0.150.0, AFTER the 2026-10-07 night read-back. Nothing delivered tonight.
|
Ships with the memory-kill check below as v0.150.0, AFTER the 2026-10-07 night read-back. Nothing delivered tonight.
|
||||||
|
|
||||||
@@ -9,7 +52,7 @@ Ships with the memory-kill check below as v0.150.0, AFTER the 2026-10-07 night r
|
|||||||
- Tests: `TestBackupDue_R894_*` (restart = a new server and a new state from the same file; fresh / old / none / storage answers / failed backup not saved), `TestBackupSuccessState_*`, `TestR894_LastKnownBackupsIsWiredIntoTheDaemon` (AST). Four red-proofs observed (`felhom.eu/documentation/audits/night-burndown-2026-10-06/s4/`).
|
- Tests: `TestBackupDue_R894_*` (restart = a new server and a new state from the same file; fresh / old / none / storage answers / failed backup not saved), `TestBackupSuccessState_*`, `TestR894_LastKnownBackupsIsWiredIntoTheDaemon` (AST). Four red-proofs observed (`felhom.eu/documentation/audits/night-burndown-2026-10-06/s4/`).
|
||||||
- **R-330 (disk health Phase 2, the wire only):** the SMART summary carries three more SATA raw counters — `reported_uncorrect` (187), `command_timeout` (188, carried as the vendor reports it; some pack several counters), `udma_crc_errors` (199). Pointer + omitempty: an attribute the drive does not report is OMITTED (unknown), never 0. No verdict reads them yet. Tests `TestParseSMART_R330_*` (two red-proofs, `felhom.eu/documentation/audits/night-burndown-2026-10-06/r330/`).
|
- **R-330 (disk health Phase 2, the wire only):** the SMART summary carries three more SATA raw counters — `reported_uncorrect` (187), `command_timeout` (188, carried as the vendor reports it; some pack several counters), `udma_crc_errors` (199). Pointer + omitempty: an attribute the drive does not report is OMITTED (unknown), never 0. No verdict reads them yet. Tests `TestParseSMART_R330_*` (two red-proofs, `felhom.eu/documentation/audits/night-burndown-2026-10-06/r330/`).
|
||||||
|
|
||||||
## Unreleased (2026-10-06 night) — the Docker step proves the engine reports a memory kill (`09` §3 decision 157, R-528)
|
### Part of v0.150.0 (2026-10-06 night) — the Docker step proves the engine reports a memory kill (`09` §3 decision 157, R-528)
|
||||||
|
|
||||||
To be released as v0.150.0 with its config bundle AFTER the 2026-10-07 night read-back (the night of 2026-10-06 runs v0.149.0 on purpose).
|
To be released as v0.150.0 with its config bundle AFTER the 2026-10-07 night read-back (the night of 2026-10-06 runs v0.149.0 on purpose).
|
||||||
|
|
||||||
@@ -18,11 +61,11 @@ To be released as v0.150.0 with its config bundle AFTER the 2026-10-07 night rea
|
|||||||
- `configs/test_felhom_os_apply.py`: its `unittest.main()` sat in the middle of the file, so 11 tests (UnsentReport, SaveReportOnDisk, AgentDiesMidPass, CrashLeftTheJournal) never ran — moved to the end; all pass.
|
- `configs/test_felhom_os_apply.py`: its `unittest.main()` sat in the middle of the file, so 11 tests (UnsentReport, SaveReportOnDisk, AgentDiesMidPass, CrashLeftTheJournal) never ran — moved to the end; all pass.
|
||||||
- Tests: the OOMCheck class (pass, OOMKilled=false, no event, unreadable image, removal on an inspect error, not on other layers or in health mode, the events window after the settle wait, mode oom-check alone and its refusals); TestDocker_OOMCheckReachesTheHubUnchanged, TestR868_KeptCopyCarriesTheOOMCheck. 12 red-proofs in `felhom.eu/documentation/audits/readback-2026-10-07/F/`.
|
- Tests: the OOMCheck class (pass, OOMKilled=false, no event, unreadable image, removal on an inspect error, not on other layers or in health mode, the events window after the settle wait, mode oom-check alone and its refusals); TestDocker_OOMCheckReachesTheHubUnchanged, TestR868_KeptCopyCarriesTheOOMCheck. 12 red-proofs in `felhom.eu/documentation/audits/readback-2026-10-07/F/`.
|
||||||
|
|
||||||
## Unreleased (2026-10-06 evening) — the shared rule file (`09` §3 decision 152); no code change
|
### Part of v0.150.0 (2026-10-06 evening) — the shared rule file (`09` §3 decision 152); no code change
|
||||||
|
|
||||||
- `.claude/rules/unprompted-work.md` added, byte-identical to the copies in felhom.eu, felhom-controller, app-catalog-felhom.eu and the workspace root (checked with `diff` against the controller's copy and one md5 across all five). Its copies line names five copies.
|
- `.claude/rules/unprompted-work.md` added, byte-identical to the copies in felhom.eu, felhom-controller, app-catalog-felhom.eu and the workspace root (checked with `diff` against the controller's copy and one md5 across all five). Its copies line names five copies.
|
||||||
|
|
||||||
## Unreleased (2026-10-06 afternoon) — instruction files kept true (`09` §3 decision 150); no code change
|
### Part of v0.150.0 (2026-10-06 afternoon) — instruction files kept true (`09` §3 decision 150); no code change
|
||||||
|
|
||||||
- `CLAUDE.md` „Gates — ONE entry point": the runner runs every gate in its `GATES` table (five: three shared, `published`, `release-complete`); `--fast` skips `published` (network). It said two gates and „all of them".
|
- `CLAUDE.md` „Gates — ONE entry point": the runner runs every gate in its `GATES` table (five: three shared, `published`, `release-complete`); `--fast` skips `published` (network). It said two gates and „all of them".
|
||||||
- `CLAUDE.md`: the decoy gate and its audit are named with their `felhom.eu/` prefix (they do not exist in this repo).
|
- `CLAUDE.md`: the decoy gate and its audit are named with their `felhom.eu/` prefix (they do not exist in this repo).
|
||||||
|
|||||||
@@ -44,13 +44,14 @@ unnoticed until a user hit them. `internal/capability` makes that loud:
|
|||||||
(`HostCapabilityChecker`) alerts the operator on a Critical capability going degraded. Serve-degraded
|
(`HostCapabilityChecker`) alerts the operator on a Critical capability going degraded. Serve-degraded
|
||||||
— the probe never blocks startup. (Next self-health slice: the controller↔agent channel check.)
|
— the probe never blocks startup. (Next self-health slice: the controller↔agent channel check.)
|
||||||
|
|
||||||
**Controller-swap under non-root (v0.45.0).** The agent-owned controller image swap
|
**Controller-swap under non-root (v0.45.0; the write since R-861 (a) A1).** The agent-owned controller image swap
|
||||||
(`internal/localapi/controllerswap.go`) no longer shells out: `writeImage` pipes the image ref on
|
(`internal/localapi/controllerswap.go`) no longer shells out. The write goes on **stdin** to the ROOT verb
|
||||||
**stdin** into an in-guest `tee /etc/felhom-controller-image` (via `GuestExecStdin` →
|
`felhom-priv-apply controller-image <vmid>` (`GuestBinder.WriteControllerImage` → `Runner.RunStdin`, the same fenced
|
||||||
`Runner.RunStdin`, the same fenced `sudo -n` runner) — no `bash -c`, no interpolation. Its 5 narrow
|
`sudo -n` runner), which re-checks the ref against our registry + repository + an x.y.z tag and writes
|
||||||
grants live in the `FELHOM_CONTROLLERSWAP` sudoers alias (all read-only or fixed-target; the `tee`
|
`/etc/felhom-controller-image` inside the guest itself; the agent has no in-guest `tee` grant any more (before, a
|
||||||
target is the FIXED image path, content stdin-fed) and in the capability manifest (Critical), so a
|
compromised agent could feed any image — sudo cannot see stdin). Its grants live in the `FELHOM_CONTROLLERSWAP` sudoers
|
||||||
dropped grant is a build failure + a live degraded signal. No general `pct exec` is granted.
|
alias (read-only or fixed-target) and in the capability manifest (Critical), so a dropped grant is a build failure + a
|
||||||
|
live degraded signal. No general `pct exec` is granted.
|
||||||
|
|
||||||
## The `storage` package — observe + watchdog (slice 5)
|
## The `storage` package — observe + watchdog (slice 5)
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,8 @@
|
|||||||
# REPORT — the second burn-down night (2026-10-06 → 07): R-894 and the R-330 wire half, on main, unreleased
|
# REPORT — v0.150.0 released and delivered (2026-10-07)
|
||||||
|
|
||||||
Nothing was released or delivered (brief fence). Both changes ship with the memory-kill check as **v0.150.0**, after the
|
On the operator's word (`09` §3 decision 161). `scripts/release-agent.sh 0.150.0`: sha `a23d1c90…`, bundle `88456b38…`,
|
||||||
2026-10-07 night read-back. Session report: `felhom.eu/REPORT-night-burndown-2026-10-06.md`; night log
|
tag `v0.150.0` = `3a72a48`, verified by download. Vouched with golden 0.301.0 and MinAgent 0.131.0 (unchanged). No bundle
|
||||||
`felhom.eu/documentation/audits/night-burndown-2026-10-06/NIGHT-LOG.md`.
|
path added (26 → 26), so no step bundle. Signed `agent_update` → demo-hp, demo-felhom, Tester 1 on 0.150.0 (07:06–07:07Z);
|
||||||
|
signed `agent_config_update` → `BUNDLE DONE written=1 same=24 self-check=ok`, capability probe 68/68 on all three
|
||||||
- **R-894** (`74b5eae`): the newest successful backup per tier is kept on disk (`backup-success-state.json` in the OOB
|
(07:21Z). Tester 2 not touched. Carries R-528 (the memory-kill check), R-894 (the last backup per tier on disk), R-330
|
||||||
state dir) and read by `/backup/due` **only when the tier's storage cannot be read**: fresh → not due, older than the
|
(SMART counters on the wire). Evidence: `felhom.eu/documentation/audits/readback-2026-10-07/delivery/`.
|
||||||
cadence → due, none → due with age unknown (as before). A storage that answers stays the ground truth. Tests
|
|
||||||
`TestBackupDue_R894_*`, `TestBackupSuccessState_*`, `TestR894_LastKnownBackupsIsWiredIntoTheDaemon`; four red-proofs
|
|
||||||
`felhom.eu/documentation/audits/night-burndown-2026-10-06/s4/`. Architecture: `07` §6.1 updated.
|
|
||||||
- **R-330, wire only** (`adaf86a`): the host report's SMART summary carries 187 `reported_uncorrect`, 188
|
|
||||||
`command_timeout`, 199 `udma_crc_errors` (pointers, omitted when unknown). No verdict reads them.
|
|
||||||
- Suite `go test ./...` rc 0; `scripts/agent_gates.py` (full) all OK; CI green on each push (runs 1451, 1467).
|
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
| `SudoHostOps.run` | internal/storage/hostops.go | `run(ctx, name, args...) error` | allowlisted exec with stderr-wrapped error | Every arg pre-validated via validate.go before this is called |
|
| `SudoHostOps.run` | internal/storage/hostops.go | `run(ctx, name, args...) error` | allowlisted exec with stderr-wrapped error | Every arg pre-validated via validate.go before this is called |
|
||||||
| `Prober.Probe` | internal/capability/probe.go | `Probe(ctx) []Status` | live sudo-policy capability check (`sudo -n -l --`) | Needs a DIRECT runner (never the sudo-prefixing one — double-sudo); never executes probed cmds. v0.86.0: config-gated caps (`Capability.GatedBy` + `Prober.GateActive`) report `inactive`/"disabled by configuration" ONLY when healthy — broken plumbing stays degraded; the pbsdr-* gate answers from `pbsdr.Manager.DRConfigured` (marker-backed across restarts) |
|
| `Prober.Probe` | internal/capability/probe.go | `Probe(ctx) []Status` | live sudo-policy capability check (`sudo -n -l --`) | Needs a DIRECT runner (never the sudo-prefixing one — double-sudo); never executes probed cmds. v0.86.0: config-gated caps (`Capability.GatedBy` + `Prober.GateActive`) report `inactive`/"disabled by configuration" ONLY when healthy — broken plumbing stays degraded; the pbsdr-* gate answers from `pbsdr.Manager.DRConfigured` (marker-backed across restarts) |
|
||||||
| ~~`stageTemp`~~ (REMOVED v0.146.0, R-861) | — | — | — | Nothing the agent writes is `install`ed where root reads it any more: use `felhom-priv-apply` (below) or ship a fixed file in the bundle |
|
| ~~`stageTemp`~~ (REMOVED v0.146.0, R-861) | — | — | — | Nothing the agent writes is `install`ed where root reads it any more: use `felhom-priv-apply` (below) or ship a fixed file in the bundle |
|
||||||
| `felhom-priv-apply` (v0.146.0, R-861) | configs/felhom-priv-apply | `felhom-priv-apply unit <name> \| dnsmasq <tmp> <name> \| wg \| sshd-config \| sshd-key` | ANY agent-rendered file a root program reads (systemd unit, dnsmasq drop-in, wg-quick conf, OOB sshd) — fixed source + destination, CONTENT checked against the agent's own renderers | A new renderer needs a verb + a contract test (`internal/privapplytest.Check`) feeding its REAL output; never a new `install` sudoers line |
|
| `felhom-priv-apply` (v0.146.0, R-861) | configs/felhom-priv-apply | `felhom-priv-apply unit <name> \| dnsmasq <tmp> <name> \| wg \| sshd-config \| sshd-key \| controller-image <vmid>` (the last reads the ref on stdin, R-861 (a) A1) | ANY agent-rendered file a root program reads (systemd unit, dnsmasq drop-in, wg-quick conf, OOB sshd) — fixed source + destination, CONTENT checked against the agent's own renderers | A new renderer needs a verb + a contract test (`internal/privapplytest.Check`) feeding its REAL output; never a new `install` sudoers line |
|
||||||
| `privapplytest.Check` | internal/privapplytest/check.go | `Check(t, verb, name, content) string` | the Go↔root-checker contract: a renderer's real output must read `OK` | Skips without python3; one call per rendered shape + one refused control |
|
| `privapplytest.Check` | internal/privapplytest/check.go | `Check(t, verb, name, content) string` | the Go↔root-checker contract: a renderer's real output must read `OK` | Skips without python3; one call per rendered shape + one refused control |
|
||||||
| `BUNDLE_FILES` + `Bundle` (mode `bundle`, `--install-bundle`; mode `agent_update` v0.146.0, R-861) | configs/felhom-os-apply | the ONE table of root-owned paths + the installer of them | ANY new root-owned file the installer writes (sudoers line, wrapper, unit) — add it to the table, never a new installer fetch (R-840) | The builder (`scripts/build-config-bundle.py`) and the installer read the same table; `test_every_root_file_the_installer_writes_is_in_the_bundle` fails on a path the bundle lacks. Trust files (`/etc/felhom/os-trust.json`, `operator-signers`) are NEVER bundle paths (R17) |
|
| `BUNDLE_FILES` + `Bundle` (mode `bundle`, `--install-bundle`; mode `agent_update` v0.146.0, R-861) | configs/felhom-os-apply | the ONE table of root-owned paths + the installer of them | ANY new root-owned file the installer writes (sudoers line, wrapper, unit) — add it to the table, never a new installer fetch (R-840) | The builder (`scripts/build-config-bundle.py`) and the installer read the same table; `test_every_root_file_the_installer_writes_is_in_the_bundle` fails on a path the bundle lacks. Trust files (`/etc/felhom/os-trust.json`, `operator-signers`) are NEVER bundle paths (R17) |
|
||||||
| `osupdate.ConfigUpdateExecutor` | internal/osupdate/bundle.go | signed op `agent_config_update` {agent_version, bundle_sha256} | delivering the bundle to an installed box | a courier only: the root wrapper re-verifies signature, host, nonce and sha itself |
|
| `osupdate.ConfigUpdateExecutor` | internal/osupdate/bundle.go | signed op `agent_config_update` {agent_version, bundle_sha256} | delivering the bundle to an installed box | a courier only: the root wrapper re-verifies signature, host, nonce and sha itself |
|
||||||
@@ -88,6 +88,7 @@
|
|||||||
|
|
||||||
| Symbol | File | Short signature | Use for | Gotchas |
|
| Symbol | File | Short signature | Use for | Gotchas |
|
||||||
|---|---|---|---|---|
|
|---|---|---|---|---|
|
||||||
|
| `pvegate.Write` / `pvegate.Step` | internal/pvegate/pvegate.go | `Write(ctx) (release, waited, err)` / `Step(ctx) (end, err)` | R-812 option A: keep the agent's own /etc/pve writes out of a Proxmox package step (pmxcfs restarts) | Already wired at the two chokepoints — `Client.doBody` (every non-GET) and `ExecRunner.RunStdin` (`WritesEtcPVE`: pct config verbs, pvesm, pveum, felhom-pbs-apply create/reconcile). A new root CLI that writes /etc/pve goes into `WritesEtcPVE`, never its own lock. Never take `Step` around anything but the wrapper call (`Leg.runPVE`) — a `Write` inside a `Step` deadlocks until its context ends. |
|
||||||
| `Client.WaitTask` | internal/proxmox/task.go | `WaitTask(ctx, upid, opts) (TaskStatus, error)` | asserting EVERY mutating op | POST 200 ≠ success; authz can fail at task exec; `AllowWarnings` opt-in |
|
| `Client.WaitTask` | internal/proxmox/task.go | `WaitTask(ctx, upid, opts) (TaskStatus, error)` | asserting EVERY mutating op | POST 200 ≠ success; authz can fail at task exec; `AllowWarnings` opt-in |
|
||||||
| `Client.Pool` | internal/proxmox/query.go | `Pool(ctx, name) (PoolInfo, error)` | felhom-pool membership (the ownership registry, A1) | Needs `Pool.Audit` at `/pool/<name>` (host-install v1.9.0+); `Pool.Allocate` does NOT satisfy the read; members can be storages (type `storage`, vmid 0) — filter them |
|
| `Client.Pool` | internal/proxmox/query.go | `Pool(ctx, name) (PoolInfo, error)` | felhom-pool membership (the ownership registry, A1) | Needs `Pool.Audit` at `/pool/<name>` (host-install v1.9.0+); `Pool.Allocate` does NOT satisfy the read; members can be storages (type `storage`, vmid 0) — filter them |
|
||||||
| `Client` mutate wrappers (`RestoreLXC/Vzdump/DestroyLXC/Snapshot/Rollback/SetConfig/ResizeLXC/Start/Stop`) | internal/proxmox/mutate.go | return `(upid, error)` | all API mutations | Async → always pair with WaitTask; route via gate/queue, not ad-hoc |
|
| `Client` mutate wrappers (`RestoreLXC/Vzdump/DestroyLXC/Snapshot/Rollback/SetConfig/ResizeLXC/Start/Stop`) | internal/proxmox/mutate.go | return `(upid, error)` | all API mutations | Async → always pair with WaitTask; route via gate/queue, not ad-hoc |
|
||||||
@@ -168,7 +169,7 @@
|
|||||||
| `backup.SpecBuilder` / `backup.TierPicker` / `(*BackupRunner).PickSettledRestoreCandidateOn` | internal/backup/schedule.go, runner.go | `func(ctx,archive) RestoreTestSpec`; `func(ctx,target,notAfter) (archive,landed,error)` | The per-run restore-test spec + per-tier **settled** candidate lookup (R-85, widened by R-86) | The spec is built **PER RUN**, never frozen at construction — the pre-R-85 immediately-invoked value made the offsite tier unschedulable AND went stale on any config change. `SourceTier` comes from **the archive**, never the configured target (the v0.100.0 rule). A tier with no archive returns `("", zero, nil)` — **`""` is NOT an error**, or every fresh box looks broken for its first week. **R-86: `notAfter` is the settle cutoff** (zero = no cutoff, which is what keeps `PickRestoreCandidateOn` a one-line call into it), and the picker now skips entries failing `archivePlausiblyComplete` — under per-archive due-ness an incomplete phantom would be picked forever, fail forever, never earn proof, and make the tier due at EVERY evaluation. |
|
| `backup.SpecBuilder` / `backup.TierPicker` / `(*BackupRunner).PickSettledRestoreCandidateOn` | internal/backup/schedule.go, runner.go | `func(ctx,archive) RestoreTestSpec`; `func(ctx,target,notAfter) (archive,landed,error)` | The per-run restore-test spec + per-tier **settled** candidate lookup (R-85, widened by R-86) | The spec is built **PER RUN**, never frozen at construction — the pre-R-85 immediately-invoked value made the offsite tier unschedulable AND went stale on any config change. `SourceTier` comes from **the archive**, never the configured target (the v0.100.0 rule). A tier with no archive returns `("", zero, nil)` — **`""` is NOT an error**, or every fresh box looks broken for its first week. **R-86: `notAfter` is the settle cutoff** (zero = no cutoff, which is what keeps `PickRestoreCandidateOn` a one-line call into it), and the picker now skips entries failing `archivePlausiblyComplete` — under per-archive due-ness an incomplete phantom would be picked forever, fail forever, never earn proof, and make the tier due at EVERY evaluation. |
|
||||||
| `localapi.BackupTier` + `normalizeBackupTiers` / `config.BackupConfig.BackupTiers` | internal/localapi/backup_tiers.go, internal/config/config.go | `normalizeBackupTiers(tiers, legacy, cadence) []BackupTier`; `BackupTiers() ([]BackupTier, []string)` | THE R-82 multi-tier resolution — one runner per tier, primary first | **The untargeted local-API contract is FROZEN**: no `?target=` ⇒ primary tier ⇒ pre-R-82 response BYTES (Target is `omitempty` and stays empty). Never default a missing cadence — reject it and log the warning at ERROR. Never share one retention knob between tiers. Jobs are keyed by (vmid,target). |
|
| `localapi.BackupTier` + `normalizeBackupTiers` / `config.BackupConfig.BackupTiers` | internal/localapi/backup_tiers.go, internal/config/config.go | `normalizeBackupTiers(tiers, legacy, cadence) []BackupTier`; `BackupTiers() ([]BackupTier, []string)` | THE R-82 multi-tier resolution — one runner per tier, primary first | **The untargeted local-API contract is FROZEN**: no `?target=` ⇒ primary tier ⇒ pre-R-82 response BYTES (Target is `omitempty` and stays empty). Never default a missing cadence — reject it and log the warning at ERROR. Never share one retention knob between tiers. Jobs are keyed by (vmid,target). |
|
||||||
| `localapi.StaleLockController` | internal/localapi/stalelock.go | `*staleLockController` (Client + Runner + pool) | `fakeStaleLock` (Server-level) stalelock_test.go; `fakeStaleLockAPI` (controller-level, tests the A1 pool intersect) stalelock_pool_test.go |
|
| `localapi.StaleLockController` | internal/localapi/stalelock.go | `*staleLockController` (Client + Runner + pool) | `fakeStaleLock` (Server-level) stalelock_test.go; `fakeStaleLockAPI` (controller-level, tests the A1 pool intersect) stalelock_pool_test.go |
|
||||||
| `localapi.GuestExecutor` | internal/localapi/controllerswap.go | `*GuestBinder` (pct exec) | `fakeGuestExec` internal/localapi/controllerswap_test.go |
|
| `localapi.GuestExecutor` | internal/localapi/controllerswap.go | `*GuestBinder` (pct exec; the image write via `felhom-priv-apply controller-image`) | `fakeGuestExec` internal/localapi/controllerswap_test.go |
|
||||||
| `guestnet.Runner` / `guestnet.GuestSource` (R-54, v0.92.0) | internal/guestnet/{probe,watchdog}.go | `*proxmox.ExecRunner`; the POOL-VERIFIED `localapi.StaleLockController.Guests` (ListLXC ∩ felhom pool, audit A1) | `scriptedRunner` + `fakeGuests` internal/guestnet/watchdog_test.go. **Never wire a bare `ListLXC` here** — under a broad token that would run dhclient inside a co-tenant's container. Every assertion is an exec COUNT, and the load-bearing ones are the negatives: a static guest, an unprobeable guest, a boot-race guest and an unproven guest list must record **zero** heal calls |
|
| `guestnet.Runner` / `guestnet.GuestSource` (R-54, v0.92.0) | internal/guestnet/{probe,watchdog}.go | `*proxmox.ExecRunner`; the POOL-VERIFIED `localapi.StaleLockController.Guests` (ListLXC ∩ felhom pool, audit A1) | `scriptedRunner` + `fakeGuests` internal/guestnet/watchdog_test.go. **Never wire a bare `ListLXC` here** — under a broad token that would run dhclient inside a co-tenant's container. Every assertion is an exec COUNT, and the load-bearing ones are the negatives: a static guest, an unprobeable guest, a boot-race guest and an unproven guest list must record **zero** heal calls |
|
||||||
| `guestnet.Watchdog.SetDampers` / `now` (clock seam) | internal/guestnet/watchdog.go | config `guest_net.*`; `now` defaults to `time.Now` | tests advance a manual clock (the storage-watchdog pattern) and assert the heal ceilings EXACTLY — ≥10 min apart, ≤3/hour, and ≤30 over a scripted 10 hours of permanent failure. A damper with no test is a comment |
|
| `guestnet.Watchdog.SetDampers` / `now` (clock seam) | internal/guestnet/watchdog.go | config `guest_net.*`; `now` defaults to `time.Now` | tests advance a manual clock (the storage-watchdog pattern) and assert the heal ceilings EXACTLY — ≥10 min apart, ≤3/hour, and ≤30 over a scripted 10 hours of permanent failure. A damper with no test is a comment |
|
||||||
| `hub.GuestNetReporter` (R-54) | internal/hub/collect.go | `*guestnet.Watchdog` (`GuestNetStatus`) | internal/hub/collect_guestnet_test.go asserts the stanza through the PRODUCTION `Collect` path AND that the `guest_net` key is ABSENT from the wire when no reporter is wired — an always-present empty stanza would make "not wired" and "found nothing" the same signal, which is the shape v0.91.0 hid behind |
|
| `hub.GuestNetReporter` (R-54) | internal/hub/collect.go | `*guestnet.Watchdog` (`GuestNetStatus`) | internal/hub/collect_guestnet_test.go asserts the stanza through the PRODUCTION `Collect` path AND that the `guest_net` key is ABSENT from the wire when no reporter is wired — an always-present empty stanza would make "not wired" and "found nothing" the same signal, which is the shape v0.91.0 hid behind |
|
||||||
|
|||||||
+63
-59
@@ -135,39 +135,38 @@ func main() {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
var (
|
var (
|
||||||
cfgPath string
|
cfgPath string
|
||||||
selftest selftestFlag
|
selftest selftestFlag
|
||||||
vmid int
|
vmid int
|
||||||
watch time.Duration
|
watch time.Duration
|
||||||
archive string
|
archive string
|
||||||
mode string
|
mode string
|
||||||
hostname string
|
hostname string
|
||||||
keep bool
|
keep bool
|
||||||
rootfsGrow int
|
rootfsGrow int
|
||||||
dataVolGrow int
|
dataVolGrow int
|
||||||
dataVolMount string
|
dataVolMount string
|
||||||
sysDataGrow int
|
sysDataGrow int
|
||||||
sysDataMount string
|
sysDataMount string
|
||||||
cores int
|
cores int
|
||||||
memoryMB int
|
memoryMB int
|
||||||
pbsStorage string
|
pbsStorage string
|
||||||
paperkey bool
|
paperkey bool
|
||||||
offline bool
|
offline bool
|
||||||
upload bool
|
upload bool
|
||||||
custID string
|
custID string
|
||||||
custDomain string
|
custDomain string
|
||||||
custName string
|
custName string
|
||||||
custEmail string
|
custEmail string
|
||||||
hubPassword string
|
hubPassword string
|
||||||
blobPath string
|
blobPath string
|
||||||
expectedFP string
|
expectedFP string
|
||||||
keyDest string
|
keyDest string
|
||||||
installWGKey bool
|
installWGKey bool
|
||||||
idBundlePath string
|
idBundlePath string
|
||||||
directivePath string
|
swapImage string
|
||||||
swapImage string
|
outputMode string
|
||||||
outputMode string
|
showVersion bool
|
||||||
showVersion bool
|
|
||||||
)
|
)
|
||||||
flag.StringVar(&cfgPath, "config", envOr("FELHOM_AGENT_CONFIG", "/etc/felhom-agent/agent.json"), "path to the agent config file (JSON)")
|
flag.StringVar(&cfgPath, "config", envOr("FELHOM_AGENT_CONFIG", "/etc/felhom-agent/agent.json"), "path to the agent config file (JSON)")
|
||||||
flag.Var(&selftest, "selftest", "run a self-test and exit: bare/`read` = read-only queries; `task` = reversible mutating exercise (needs -vmid); `hub` = one collect+report; `storage` = observe storage (+ -watch); `backup` = one-shot backup of -vmid; `restore-test` = restore→boot→verify→teardown of -archive (or newest backup); `restore-test-due` = READ-ONLY: print the per-tier due verdict the scheduler would act on, with its cost; `pbs-verify` = trigger a PBS verify + print snapshot records; `bring-up` = restore→reset identity→size→start link-up of -archive into -vmid (needs -mode/-archive/-vmid; optional -cores/-memory cap; tears down unless -keep); `provision` = full slice-8A chain: bring-up provision + mint token + populate bootstrap config mount (needs -archive/-vmid/-customer-id/-hub-password; optional -rootfs-grow/-datavol-grow/-cores/-memory (-sysdata-grow is deprecated: folded into -datavol-grow); keeps the guest)")
|
flag.Var(&selftest, "selftest", "run a self-test and exit: bare/`read` = read-only queries; `task` = reversible mutating exercise (needs -vmid); `hub` = one collect+report; `storage` = observe storage (+ -watch); `backup` = one-shot backup of -vmid; `restore-test` = restore→boot→verify→teardown of -archive (or newest backup); `restore-test-due` = READ-ONLY: print the per-tier due verdict the scheduler would act on, with its cost; `pbs-verify` = trigger a PBS verify + print snapshot records; `bring-up` = restore→reset identity→size→start link-up of -archive into -vmid (needs -mode/-archive/-vmid; optional -cores/-memory cap; tears down unless -keep); `provision` = full slice-8A chain: bring-up provision + mint token + populate bootstrap config mount (needs -archive/-vmid/-customer-id/-hub-password; optional -rootfs-grow/-datavol-grow/-cores/-memory (-sysdata-grow is deprecated: folded into -datavol-grow); keeps the guest)")
|
||||||
@@ -198,7 +197,6 @@ func main() {
|
|||||||
flag.StringVar(&keyDest, "keydest", "", "for --selftest=escrow-consume: where to install the recovered key (0600)")
|
flag.StringVar(&keyDest, "keydest", "", "for --selftest=escrow-consume: where to install the recovered key (0600)")
|
||||||
flag.BoolVar(&installWGKey, "install-wg-key", false, "for --selftest=identity-consume: ALSO install the recovered wg_private_key into wgtunnel's key file (S5 DR; create-only, refuses to overwrite)")
|
flag.BoolVar(&installWGKey, "install-wg-key", false, "for --selftest=identity-consume: ALSO install the recovered wg_private_key into wgtunnel's key file (S5 DR; create-only, refuses to overwrite)")
|
||||||
flag.StringVar(&idBundlePath, "identity-bundle", "", "for --selftest=escrow-create: a 0600 JSON file {tunnel_token,pbs_token} to ALSO escrow under R (10D)")
|
flag.StringVar(&idBundlePath, "identity-bundle", "", "for --selftest=escrow-create: a 0600 JSON file {tunnel_token,pbs_token} to ALSO escrow under R (10D)")
|
||||||
flag.StringVar(&directivePath, "directive", "", "for --selftest=escrow-create: a JSON file with the non-secret DR directive (pbs repo/ns, expected fingerprint, tunnel id)")
|
|
||||||
flag.StringVar(&custID, "customer-id", "", "for --selftest=provision: the customer id — the hub config-pull target, baked into the guest's bootstrap")
|
flag.StringVar(&custID, "customer-id", "", "for --selftest=provision: the customer id — the hub config-pull target, baked into the guest's bootstrap")
|
||||||
flag.StringVar(&hubPassword, "hub-password", "", "for --selftest=provision: the customer's hub RETRIEVAL PASSPHRASE (SECRET) — baked into bootstrap.json so the controller pulls its config (and the customer-scoped hub key) from the hub. The customer must already exist in the hub.")
|
flag.StringVar(&hubPassword, "hub-password", "", "for --selftest=provision: the customer's hub RETRIEVAL PASSPHRASE (SECRET) — baked into bootstrap.json so the controller pulls its config (and the customer-scoped hub key) from the hub. The customer must already exist in the hub.")
|
||||||
flag.StringVar(&swapImage, "image", "", "for --selftest=controller-swap: the target controller image ref (gitea.dooplex.hu/admin/felhom-controller:<semver>) — must already be pulled in the guest")
|
flag.StringVar(&swapImage, "image", "", "for --selftest=controller-swap: the target controller image ref (gitea.dooplex.hu/admin/felhom-controller:<semver>) — must already be pulled in the guest")
|
||||||
@@ -269,7 +267,7 @@ func main() {
|
|||||||
SysDataGrowGB: sysDataGrow, SysDataMount: sysDataMount, Cores: cores, MemoryMB: memoryMB},
|
SysDataGrowGB: sysDataGrow, SysDataMount: sysDataMount, Cores: cores, MemoryMB: memoryMB},
|
||||||
}))
|
}))
|
||||||
case "escrow-create":
|
case "escrow-create":
|
||||||
os.Exit(runSelftestEscrowCreate(context.Background(), cfg, logger, pbsStorage, paperkey, offline, upload, idBundlePath, directivePath, outputMode))
|
os.Exit(runSelftestEscrowCreate(context.Background(), cfg, logger, pbsStorage, paperkey, offline, upload, idBundlePath, outputMode))
|
||||||
case "escrow-consume":
|
case "escrow-consume":
|
||||||
os.Exit(runSelftestEscrowConsume(context.Background(), logger, blobPath, expectedFP, keyDest))
|
os.Exit(runSelftestEscrowConsume(context.Background(), logger, blobPath, expectedFP, keyDest))
|
||||||
case "identity-consume":
|
case "identity-consume":
|
||||||
@@ -792,6 +790,9 @@ func runDaemon(cfg config.Config, logger *slog.Logger, logRing *applog.Ring) int
|
|||||||
pbsTargets := pbsTargetsFromPVE(cfg, px, logger)
|
pbsTargets := pbsTargetsFromPVE(cfg, px, logger)
|
||||||
pbsReporter := pbs.NewLiveSnapshotReporter(pbsTargets, pbsStore, pbs.DefaultLiveSnapshotTimeout, logger)
|
pbsReporter := pbs.NewLiveSnapshotReporter(pbsTargets, pbsStore, pbs.DefaultLiveSnapshotTimeout, logger)
|
||||||
collector := hub.NewCollector(px, newTunnelProber(cfg, px), observer, backupStore, backupStore, pbsReporter, cfg.Hub.HostID, version, logger)
|
collector := hub.NewCollector(px, newTunnelProber(cfg, px), observer, backupStore, backupStore, pbsReporter, cfg.Hub.HostID, version, logger)
|
||||||
|
// R-366 slice 2: the restore-test's ledger of archives written with another key → the host report.
|
||||||
|
foreignKeys := backup.NewForeignKeyLedger()
|
||||||
|
collector.SetForeignKeyArchiveReporter(foreignKeys)
|
||||||
collector.SetBackupTargetResolver(primaryBackupTargetOf(cfg)) // R-109: the recipe names the live target
|
collector.SetBackupTargetResolver(primaryBackupTargetOf(cfg)) // R-109: the recipe names the live target
|
||||||
// Privileged-capability self-check (v0.44.0): probe the sudoers grants the non-root agent
|
// Privileged-capability self-check (v0.44.0): probe the sudoers grants the non-root agent
|
||||||
// depends on. The probe runs `sudo -n -l` LITERALLY (a policy LIST, never executing the
|
// depends on. The probe runs `sudo -n -l` LITERALLY (a policy LIST, never executing the
|
||||||
@@ -1017,7 +1018,7 @@ func runDaemon(cfg config.Config, logger *slog.Logger, logRing *applog.Ring) int
|
|||||||
// with the local API so a backup and a restore-test can never run together.
|
// with the local API so a backup and a restore-test can never run together.
|
||||||
rtState := backup.NewRestoreTestState(filepath.Join(cfg.OOB.WithDefaults().StateDir, "restore-test-state.json"))
|
rtState := backup.NewRestoreTestState(filepath.Join(cfg.OOB.WithDefaults().StateDir, "restore-test-state.json"))
|
||||||
heavyOps := &backup.InFlight{}
|
heavyOps := &backup.InFlight{}
|
||||||
scheduler := buildRestoreTestScheduler(cfg, px, engine, backupStore, rtState, heavyOps, logger)
|
scheduler := buildRestoreTestScheduler(cfg, px, engine, backupStore, rtState, heavyOps, foreignKeys, logger)
|
||||||
// R-189: the host report's restore_tests[] must survive an agent restart. The in-memory store
|
// R-189: the host report's restore_tests[] must survive an agent restart. The in-memory store
|
||||||
// holds only this process's latest run, and under per-archive due-ness the agent will not
|
// holds only this process's latest run, and under per-archive due-ness the agent will not
|
||||||
// re-test an archive it has already proven — so without this the hub can report a tier unproven
|
// re-test an archive it has already proven — so without this the hub can report a tier unproven
|
||||||
@@ -1109,6 +1110,15 @@ func runDaemon(cfg config.Config, logger *slog.Logger, logRing *applog.Ring) int
|
|||||||
}
|
}
|
||||||
return release, nil
|
return release, nil
|
||||||
}}
|
}}
|
||||||
|
// R-812 option A: a signed Proxmox package step (`11` §5.10) — ring 1; under the heavy-op gate and the /etc/pve gate.
|
||||||
|
pveExec := osupdate.PVEStepExecutor{Leg: osLeg, Guest: firstGuest(px),
|
||||||
|
Gate: func(ctx context.Context) (func(), error) {
|
||||||
|
release, busy, ok := heavyOps.TryAcquire("os-pve-step")
|
||||||
|
if !ok {
|
||||||
|
return nil, fmt.Errorf("busy: %s", busy)
|
||||||
|
}
|
||||||
|
return release, nil
|
||||||
|
}}
|
||||||
// Agent v0.143.0 (R-840): the config bundle — the box's root-owned files by a signed job; the wrapper verifies it.
|
// Agent v0.143.0 (R-840): the config bundle — the box's root-owned files by a signed job; the wrapper verifies it.
|
||||||
bundleExec := osupdate.ConfigUpdateExecutor{Leg: osLeg, URLTemplate: suCfg.URLTemplate, Username: suCfg.Username, Token: suCfg.Token,
|
bundleExec := osupdate.ConfigUpdateExecutor{Leg: osLeg, URLTemplate: suCfg.URLTemplate, Username: suCfg.Username, Token: suCfg.Token,
|
||||||
// The capability probe confirms from the agent's side: `sudo -l` lists every command the new sudoers grants.
|
// The capability probe confirms from the agent's side: `sudo -l` lists every command the new sudoers grants.
|
||||||
@@ -1120,7 +1130,7 @@ func runDaemon(cfg config.Config, logger *slog.Logger, logRing *applog.Ring) int
|
|||||||
}
|
}
|
||||||
logger.Warn("osupdate: capability probe after the config bundle", "ok", ok, "total", total, "degraded", strings.Join(names, ","))
|
logger.Warn("osupdate: capability probe after the config bundle", "ok", ok, "total", total, "degraded", strings.Join(names, ","))
|
||||||
}}
|
}}
|
||||||
jobsRunner := signedjobs.NewRunner(client, gate, signedjobs.ExecutorChain{wipeExec, decommExec, updateExec, dockerExec, bundleExec}, cfg.Hub.HostID, logger)
|
jobsRunner := signedjobs.NewRunner(client, gate, signedjobs.ExecutorChain{wipeExec, decommExec, updateExec, dockerExec, pveExec, bundleExec}, cfg.Hub.HostID, logger)
|
||||||
loop.SetEnvelopeObserver(hub.MultiObserver(desiredSyncer, jobsRunner))
|
loop.SetEnvelopeObserver(hub.MultiObserver(desiredSyncer, jobsRunner))
|
||||||
|
|
||||||
// Controller-driven escrow ceremony (v0.88.0): static config facts + the LATE-BOUND DR gate —
|
// Controller-driven escrow ceremony (v0.88.0): static config facts + the LATE-BOUND DR gate —
|
||||||
@@ -1700,7 +1710,7 @@ func primaryBackupTargetOf(cfg config.Config) func() hub.ConfiguredBackupTarget
|
|||||||
// disables the cadence (returns a scheduler that just waits) when the cadence is off or the
|
// disables the cadence (returns a scheduler that just waits) when the cadence is off or the
|
||||||
// scratch band / restore storage is invalid — a misconfig must not crash the daemon, and the
|
// scratch band / restore storage is invalid — a misconfig must not crash the daemon, and the
|
||||||
// machinery still works on-demand via --selftest=restore-test.
|
// machinery still works on-demand via --selftest=restore-test.
|
||||||
func buildRestoreTestScheduler(cfg config.Config, px *proxmox.Client, engine *reconcile.Engine, store *backup.Store, rtState *backup.RestoreTestState, inFlight *backup.InFlight, logger *slog.Logger) *backup.Scheduler {
|
func buildRestoreTestScheduler(cfg config.Config, px *proxmox.Client, engine *reconcile.Engine, store *backup.Store, rtState *backup.RestoreTestState, inFlight *backup.InFlight, foreign *backup.ForeignKeyLedger, logger *slog.Logger) *backup.Scheduler {
|
||||||
// R-86: this is the EVALUATION interval, not the trigger. What decides a test happens is the
|
// R-86: this is the EVALUATION interval, not the trigger. What decides a test happens is the
|
||||||
// per-archive due-check in internal/backup/restoretest_due.go.
|
// per-archive due-check in internal/backup/restoretest_due.go.
|
||||||
cadence := cfg.Backup.RestoreTestEvalInterval()
|
cadence := cfg.Backup.RestoreTestEvalInterval()
|
||||||
@@ -1719,6 +1729,9 @@ func buildRestoreTestScheduler(cfg config.Config, px *proxmox.Client, engine *re
|
|||||||
min, max := cfg.Backup.ScratchBand()
|
min, max := cfg.Backup.ScratchBand()
|
||||||
target := cfg.Backup.BackupTarget()
|
target := cfg.Backup.BackupTarget()
|
||||||
runner := backup.NewBackupRunner(px, target, "", "felhom restore-test", "", logger)
|
runner := backup.NewBackupRunner(px, target, "", "felhom restore-test", "", logger)
|
||||||
|
if foreign != nil {
|
||||||
|
runner.SetForeignKeyLedger(foreign) // R-366 slice 2: the pick records archives written with another key
|
||||||
|
}
|
||||||
// Every configured tier is a rotation candidate, not just the primary.
|
// Every configured tier is a rotation candidate, not just the primary.
|
||||||
cfgTiers, _ := cfg.Backup.BackupTiers() // warnings already logged where the tiers are armed
|
cfgTiers, _ := cfg.Backup.BackupTiers() // warnings already logged where the tiers are armed
|
||||||
tierIDs := make([]string, 0, len(cfgTiers))
|
tierIDs := make([]string, 0, len(cfgTiers))
|
||||||
@@ -2264,7 +2277,7 @@ func runSelftestRestoreTestDue(ctx context.Context, cfg config.Config, logger *s
|
|||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
rtState := backup.NewRestoreTestState(filepath.Join(cfg.OOB.WithDefaults().StateDir, "restore-test-state.json"))
|
rtState := backup.NewRestoreTestState(filepath.Join(cfg.OOB.WithDefaults().StateDir, "restore-test-state.json"))
|
||||||
sched := buildRestoreTestScheduler(cfg, px, nil, backup.NewStore(), rtState, &backup.InFlight{}, logger)
|
sched := buildRestoreTestScheduler(cfg, px, nil, backup.NewStore(), rtState, &backup.InFlight{}, nil, logger)
|
||||||
|
|
||||||
fmt.Printf("eval_interval=%s settle=%s\n", cfg.Backup.RestoreTestEvalInterval(), cfg.Backup.RestoreTestSettle())
|
fmt.Printf("eval_interval=%s settle=%s\n", cfg.Backup.RestoreTestEvalInterval(), cfg.Backup.RestoreTestSettle())
|
||||||
start := time.Now()
|
start := time.Now()
|
||||||
@@ -2690,7 +2703,6 @@ type escrowCeremonyOpts struct {
|
|||||||
offline bool
|
offline bool
|
||||||
upload bool
|
upload bool
|
||||||
identityBundlePath string
|
identityBundlePath string
|
||||||
directivePath string
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// escrowCeremonyOutcome is the shared core's result. R is the ONLY secret; Sum mirrors the
|
// escrowCeremonyOutcome is the shared core's result. R is the ONLY secret; Sum mirrors the
|
||||||
@@ -2749,11 +2761,10 @@ func escrowCeremony(ctx context.Context, cfg config.Config, logger *slog.Logger,
|
|||||||
return out, &escrowCeremonyErr{kind: "setup", err: fmt.Errorf("PBS key for %q not found (%s): %v", storage, keyPath, err)}
|
return out, &escrowCeremonyErr{kind: "setup", err: fmt.Errorf("PBS key for %q not found (%s): %v", storage, keyPath, err)}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Slice 10D.1: optionally ALSO wrap the identity bundle under the same R, and carry the non-secret
|
// Slice 10D.1: optionally ALSO wrap the identity bundle under the same R. The bundle file is a 0600 secret
|
||||||
// directive for the hub. The bundle file is a 0600 secret (tunnel/pbs tokens); the directive is
|
// (tunnel/pbs tokens). The non-secret "directive" that used to ride along is retired (R-105, `09` §3 decision 169:
|
||||||
// non-secret (pbs repo/ns, expected fingerprint, tunnel id).
|
// nothing read it; the DR path reads the recipe, tenantsync and the escrow blob).
|
||||||
var identity *escrow.IdentityBundle
|
var identity *escrow.IdentityBundle
|
||||||
var directive json.RawMessage
|
|
||||||
if opts.identityBundlePath != "" {
|
if opts.identityBundlePath != "" {
|
||||||
raw, err := os.ReadFile(opts.identityBundlePath)
|
raw, err := os.ReadFile(opts.identityBundlePath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -2764,11 +2775,6 @@ func escrowCeremony(ctx context.Context, cfg config.Config, logger *slog.Logger,
|
|||||||
return out, &escrowCeremonyErr{kind: "setup", err: fmt.Errorf("identity bundle is not valid JSON {tunnel_token,pbs_token}: %v", err)}
|
return out, &escrowCeremonyErr{kind: "setup", err: fmt.Errorf("identity bundle is not valid JSON {tunnel_token,pbs_token}: %v", err)}
|
||||||
}
|
}
|
||||||
identity = &b
|
identity = &b
|
||||||
if opts.directivePath != "" {
|
|
||||||
if d, err := os.ReadFile(opts.directivePath); err == nil && json.Valid(d) {
|
|
||||||
directive = d
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
// S3: auto-inject the offsite WG private key into the escrowed identity when the key file
|
// S3: auto-inject the offsite WG private key into the escrowed identity when the key file
|
||||||
// exists — a NEW escrow run should always capture the live tunnel identity. Field NAME only
|
// exists — a NEW escrow run should always capture the live tunnel identity. Field NAME only
|
||||||
@@ -2847,7 +2853,7 @@ func escrowCeremony(ctx context.Context, cfg config.Config, logger *slog.Logger,
|
|||||||
ResticPwSealed: resticStaged,
|
ResticPwSealed: resticStaged,
|
||||||
}
|
}
|
||||||
if opts.upload {
|
if opts.upload {
|
||||||
if err := uploadEscrowBlob(ctx, cfg, res, directive, resticPwSHA256); err != nil {
|
if err := uploadEscrowBlob(ctx, cfg, res, resticPwSHA256); err != nil {
|
||||||
// R is minted and the blob self-verified — only the hub leg failed. kind "upload" lets
|
// R is minted and the blob self-verified — only the hub leg failed. kind "upload" lets
|
||||||
// the text shell keep the pre-extraction order (R surfaced, THEN the failure).
|
// the text shell keep the pre-extraction order (R surfaced, THEN the failure).
|
||||||
return out, &escrowCeremonyErr{kind: "upload", err: err}
|
return out, &escrowCeremonyErr{kind: "upload", err: err}
|
||||||
@@ -2904,7 +2910,7 @@ func printEscrowTextRBlock(out *escrowCeremonyOutcome) {
|
|||||||
// NOTHING else there; every human/info line goes to stderr; failures exit non-zero with no
|
// NOTHING else there; every human/info line goes to stderr; failures exit non-zero with no
|
||||||
// partial JSON. This is the controller-driven ceremony's parse surface (spike §2.3: the text
|
// partial JSON. This is the controller-driven ceremony's parse surface (spike §2.3: the text
|
||||||
// banner is positionally brittle).
|
// banner is positionally brittle).
|
||||||
func runSelftestEscrowCreate(ctx context.Context, cfg config.Config, logger *slog.Logger, storage string, paperkey, offline, upload bool, identityBundlePath, directivePath, outputMode string) int {
|
func runSelftestEscrowCreate(ctx context.Context, cfg config.Config, logger *slog.Logger, storage string, paperkey, offline, upload bool, identityBundlePath, outputMode string) int {
|
||||||
switch outputMode {
|
switch outputMode {
|
||||||
case "", "text", "json":
|
case "", "text", "json":
|
||||||
default:
|
default:
|
||||||
@@ -2922,7 +2928,7 @@ func runSelftestEscrowCreate(ctx context.Context, cfg config.Config, logger *slo
|
|||||||
|
|
||||||
out, cerr := escrowCeremony(ctx, cfg, logger, escrowCeremonyOpts{
|
out, cerr := escrowCeremony(ctx, cfg, logger, escrowCeremonyOpts{
|
||||||
storage: storage, paperkey: paperkey, offline: offline, upload: upload,
|
storage: storage, paperkey: paperkey, offline: offline, upload: upload,
|
||||||
identityBundlePath: identityBundlePath, directivePath: directivePath,
|
identityBundlePath: identityBundlePath,
|
||||||
})
|
})
|
||||||
if cerr != nil {
|
if cerr != nil {
|
||||||
switch cerr.kind {
|
switch cerr.kind {
|
||||||
@@ -3105,20 +3111,19 @@ type escrowUploadRequest struct {
|
|||||||
BlobB64 string `json:"blob_b64"` // base64 of the opaque R-wrapped blob (ciphertext)
|
BlobB64 string `json:"blob_b64"` // base64 of the opaque R-wrapped blob (ciphertext)
|
||||||
KeyFingerprint string `json:"key_fingerprint"` // for operator display only
|
KeyFingerprint string `json:"key_fingerprint"` // for operator display only
|
||||||
Posture string `json:"posture"` // e.g. "zero_knowledge"
|
Posture string `json:"posture"` // e.g. "zero_knowledge"
|
||||||
// Slice 10D.1 — optional DR bundle (identity escrow + non-secret directive). Omitted in slice-7.
|
// Slice 10D.1 — optional identity escrow. Omitted in slice-7. (The `directive` is retired — R-105.)
|
||||||
IdentityBlobB64 string `json:"identity_blob_b64,omitempty"`
|
IdentityBlobB64 string `json:"identity_blob_b64,omitempty"`
|
||||||
DirectiveJSON json.RawMessage `json:"directive,omitempty"`
|
CreatedAt string `json:"created_at"` // RFC3339
|
||||||
CreatedAt string `json:"created_at"` // RFC3339
|
|
||||||
// SLICE 3 — sha256 hex of the offsite restic repo password sealed in the identity blob (present only
|
// SLICE 3 — sha256 hex of the offsite restic repo password sealed in the identity blob (present only
|
||||||
// when a staged password was folded in). Non-reversible hash of a 256-bit random secret — safe to
|
// when a staged password was folded in). Non-reversible hash of a 256-bit random secret — safe to
|
||||||
// store/serve; lets the controller VERIFY "the escrow covers the CURRENT key" and auto-confirm.
|
// store/serve; lets the controller VERIFY "the escrow covers the CURRENT key" and auto-confirm.
|
||||||
ResticPwSHA256 string `json:"restic_pw_sha256,omitempty"`
|
ResticPwSHA256 string `json:"restic_pw_sha256,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// uploadEscrowBlob PUTs the opaque blob (and, for 10D, the identity blob + non-secret directive) to
|
// uploadEscrowBlob PUTs the opaque blob (and, for 10D, the identity blob) to
|
||||||
// the hub, authed with the per-host key. The hub stores ciphertext + non-secret fields; no usable
|
// the hub, authed with the per-host key. The hub stores ciphertext + non-secret fields; no usable
|
||||||
// secret leaves the agent.
|
// secret leaves the agent.
|
||||||
func uploadEscrowBlob(ctx context.Context, cfg config.Config, res escrow.CreateResult, directive json.RawMessage, resticPwSHA256 string) error {
|
func uploadEscrowBlob(ctx context.Context, cfg config.Config, res escrow.CreateResult, resticPwSHA256 string) error {
|
||||||
if cfg.Hub.URL == "" || cfg.Hub.HostID == "" || cfg.Hub.APIKey == "" {
|
if cfg.Hub.URL == "" || cfg.Hub.HostID == "" || cfg.Hub.APIKey == "" {
|
||||||
return fmt.Errorf("hub not configured (url/host_id/api_key)")
|
return fmt.Errorf("hub not configured (url/host_id/api_key)")
|
||||||
}
|
}
|
||||||
@@ -3131,7 +3136,6 @@ func uploadEscrowBlob(ctx context.Context, cfg config.Config, res escrow.CreateR
|
|||||||
}
|
}
|
||||||
if len(res.IdentityBlob) > 0 {
|
if len(res.IdentityBlob) > 0 {
|
||||||
upReq.IdentityBlobB64 = base64.StdEncoding.EncodeToString(res.IdentityBlob)
|
upReq.IdentityBlobB64 = base64.StdEncoding.EncodeToString(res.IdentityBlob)
|
||||||
upReq.DirectiveJSON = directive
|
|
||||||
}
|
}
|
||||||
body, _ := json.Marshal(upReq)
|
body, _ := json.Marshal(upReq)
|
||||||
url := strings.TrimRight(cfg.Hub.URL, "/") + "/api/v1/hosts/" + cfg.Hub.HostID + "/escrow"
|
url := strings.TrimRight(cfg.Hub.URL, "/") + "/api/v1/hosts/" + cfg.Hub.HostID + "/escrow"
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ func main() {
|
|||||||
|
|
||||||
func run() error {
|
func run() error {
|
||||||
var (
|
var (
|
||||||
op = flag.String("op", "", "op class to sign, e.g. storage_wipe | guest_destroy | decommission | agent_update | os_docker_step | agent_config_update")
|
op = flag.String("op", "", "op class to sign, e.g. storage_wipe | guest_destroy | decommission | agent_update | os_docker_step | os_pve_step | agent_config_update")
|
||||||
host = flag.String("host", "", "target host_id (anti-retarget — the op runs ONLY on this host)")
|
host = flag.String("host", "", "target host_id (anti-retarget — the op runs ONLY on this host)")
|
||||||
guest = flag.String("guest", "", "target guest_id (\"\" = host-scoped op)")
|
guest = flag.String("guest", "", "target guest_id (\"\" = host-scoped op)")
|
||||||
keyID = flag.String("key-id", "", "key id of the signing key (must match a pinned agent signer)")
|
keyID = flag.String("key-id", "", "key id of the signing key (must match a pinned agent signer)")
|
||||||
|
|||||||
@@ -111,15 +111,17 @@ Cmnd_Alias FELHOM_INTERMEDIARY = \
|
|||||||
# docker inspect -f * — container running/health/image (read-only; `*` spans the -f template
|
# docker inspect -f * — container running/health/image (read-only; `*` spans the -f template
|
||||||
# + container across spaces, spike-confirmed)
|
# + container across spaces, spike-confirmed)
|
||||||
# systemctl restart <fixed unit> — re-run the golden's bootstrap (the only state change)
|
# systemctl restart <fixed unit> — re-run the golden's bootstrap (the only state change)
|
||||||
# tee <FIXED image file> — WRITE the ref; content is fed on STDIN (no shell, no interpolation),
|
# felhom-priv-apply controller-image <vmid> — WRITE the ref (R-861 (a) A1, `09` §3 decision 165): the ref goes on
|
||||||
# the agent strict-validates the ref (controllerImageRe) before the write.
|
# STDIN to the ROOT wrapper, which requires our registry + repository + an x.y.z tag
|
||||||
|
# and writes the guest file itself. The agent's own `tee` grant is GONE: before, a
|
||||||
|
# compromised agent could hand the guest's bootstrap ANY image (sudo cannot see stdin).
|
||||||
# Validated GO: felhom.eu/documentation/audits/SPIKE-controllerswap-narrow-grants-2026-06-29.md.
|
# Validated GO: felhom.eu/documentation/audits/SPIKE-controllerswap-narrow-grants-2026-06-29.md.
|
||||||
Cmnd_Alias FELHOM_CONTROLLERSWAP = \
|
Cmnd_Alias FELHOM_CONTROLLERSWAP = \
|
||||||
/usr/sbin/pct ^exec [0-9]+ -- cat /etc/felhom-controller-image$, \
|
/usr/sbin/pct ^exec [0-9]+ -- cat /etc/felhom-controller-image$, \
|
||||||
/usr/sbin/pct ^exec [0-9]+ -- docker image inspect gitea\.dooplex\.hu/admin/felhom-controller\:[0-9]+\.[0-9]+\.[0-9]+$, \
|
/usr/sbin/pct ^exec [0-9]+ -- docker image inspect gitea\.dooplex\.hu/admin/felhom-controller\:[0-9]+\.[0-9]+\.[0-9]+$, \
|
||||||
/usr/sbin/pct ^exec [0-9]+ -- docker inspect -f .+ (felhom-controller|cloudflared)$, \
|
/usr/sbin/pct ^exec [0-9]+ -- docker inspect -f .+ (felhom-controller|cloudflared)$, \
|
||||||
/usr/sbin/pct ^exec [0-9]+ -- systemctl restart felhom-controller-bootstrap\.service$, \
|
/usr/sbin/pct ^exec [0-9]+ -- systemctl restart felhom-controller-bootstrap\.service$, \
|
||||||
/usr/sbin/pct ^exec [0-9]+ -- tee /etc/felhom-controller-image$
|
/usr/local/sbin/felhom-priv-apply ^controller-image [0-9]+$
|
||||||
|
|
||||||
# Stale-lock recovery (F2-b, v0.49.0). A host reboot DURING a vzdump backup leaves the guest with a
|
# Stale-lock recovery (F2-b, v0.49.0). A host reboot DURING a vzdump backup leaves the guest with a
|
||||||
# `snapshot-delete`/`backup` lock + `onboot:1` then can't start it → the customer box stays DOWN. The
|
# `snapshot-delete`/`backup` lock + `onboot:1` then can't start it → the customer box stays DOWN. The
|
||||||
|
|||||||
@@ -16,8 +16,10 @@ Cmnd_Alias FELHOM_OP_REPAIR = \
|
|||||||
/usr/bin/systemctl reset-failed felhom-sshd, \
|
/usr/bin/systemctl reset-failed felhom-sshd, \
|
||||||
/usr/bin/systemctl restart felhom-sshd, \
|
/usr/bin/systemctl restart felhom-sshd, \
|
||||||
/usr/sbin/pct list, \
|
/usr/sbin/pct list, \
|
||||||
/usr/sbin/pct start [0-9]*, \
|
/usr/sbin/pct ^start [0-9]+$, \
|
||||||
/usr/sbin/pct stop [0-9]*, \
|
/usr/sbin/pct ^stop [0-9]+$, \
|
||||||
/usr/sbin/pct unlock [0-9]*
|
/usr/sbin/pct ^unlock [0-9]+$
|
||||||
|
|
||||||
|
# R-861 (b) B2 (`09` §3 decision 165, hygiene): one numeric vmid per pct verb, anchored — the old glob `[0-9]*` also
|
||||||
|
# matched spaces, so `pct stop 9201 --skiplock 1` passed. Pinned by TestFelhomOpSudoersPctIsExact.
|
||||||
felhom-op ALL=(root) NOPASSWD: FELHOM_OP_REPAIR
|
felhom-op ALL=(root) NOPASSWD: FELHOM_OP_REPAIR
|
||||||
|
|||||||
+66
-16
@@ -21,6 +21,11 @@
|
|||||||
# or, for an unsigned ring-0 step, the root-owned TRUST_FILE saying `"ring0_slow_lane": true` (set by hand on the demo
|
# or, for an unsigned ring-0 step, the root-owned TRUST_FILE saying `"ring0_slow_lane": true` (set by hand on the demo
|
||||||
# boxes only). The agent's own config is NOT trusted for either: the agent can write it. A Docker step also needs
|
# boxes only). The agent's own config is NOT trusted for either: the agent can write it. A Docker step also needs
|
||||||
# `live-restore` ON (R15) — without it every container restarts.
|
# `live-restore` ON (R15) — without it every container restarts.
|
||||||
|
# Agent v0.151.0 (R-812 option A, `09` §3 decision 163) adds the layer "pve": the HOST's Proxmox USERSPACE packages,
|
||||||
|
# lane "slow" only, origin "Proxmox Debian Repository" only, never a kernel / boot / firmware / microcode name (R14 —
|
||||||
|
# the kernel is R-836's lane), no removal, no undo, a NEW package only from PVE_NEW_ALLOW, an appliance only (R12), and
|
||||||
|
# the same authority as the Docker step (R3: a signed `os_pve_step`, or the root-owned ring-0 mark). Select
|
||||||
|
# "pending-pve" (ring 0): every installed Proxmox-origin package with a pending upgrade, minus HOST_SLOW_RE.
|
||||||
#
|
#
|
||||||
# Modes (plan field "mode"):
|
# Modes (plan field "mode"):
|
||||||
# inventory `apt-get update`, then report what is installed (with origin), what is pending, and health.
|
# inventory `apt-get update`, then report what is installed (with origin), what is pending, and health.
|
||||||
@@ -100,6 +105,12 @@ HOST_SERVICES = ["pveproxy", "pvedaemon", "pvestatd", "pve-cluster", "felhom-age
|
|||||||
DOCKER_NAMES = ("containerd.io", "docker-buildx-plugin", "docker-ce", "docker-ce-cli", "docker-ce-rootless-extras",
|
DOCKER_NAMES = ("containerd.io", "docker-buildx-plugin", "docker-ce", "docker-ce-cli", "docker-ce-rootless-extras",
|
||||||
"docker-compose-plugin")
|
"docker-compose-plugin")
|
||||||
DOCKER_ORIGIN = "Docker CE"
|
DOCKER_ORIGIN = "Docker CE"
|
||||||
|
# The Proxmox package lane (R-812 option A): the origin apt prints for download.proxmox.com, and the ONLY new packages
|
||||||
|
# a pve step may add (measured on demo-felhom 2026-10-07: a full upgrade adds proxmox-firewall-data and the kernel;
|
||||||
|
# the kernel is refused by R14 whatever this list says).
|
||||||
|
PVE_ORIGIN = "Proxmox Debian Repository"
|
||||||
|
PVE_NEW_ALLOW = ("proxmox-firewall-data",)
|
||||||
|
PVE_SIGNED_OP = "os_pve_step"
|
||||||
# ROOT-OWNED trust anchors (the installer writes them; the demo boxes got them by hand, R-840). Never the agent's config.
|
# ROOT-OWNED trust anchors (the installer writes them; the demo boxes got them by hand, R-840). Never the agent's config.
|
||||||
TRUST_FILE = "/etc/felhom/os-trust.json" # {"host_id": "...", "ring0_slow_lane": false}
|
TRUST_FILE = "/etc/felhom/os-trust.json" # {"host_id": "...", "ring0_slow_lane": false}
|
||||||
TRUST_SIGNERS = "/etc/felhom/operator-signers" # ssh allowed_signers: <key_id> namespaces="felhom-op-v1" <key>
|
TRUST_SIGNERS = "/etc/felhom/operator-signers" # ssh allowed_signers: <key_id> namespaces="felhom-op-v1" <key>
|
||||||
@@ -434,12 +445,14 @@ class Apply:
|
|||||||
raise Refused("R11", "bundle is a host-layer mode")
|
raise Refused("R11", "bundle is a host-layer mode")
|
||||||
return mode, "host", 0, "bundle"
|
return mode, "host", 0, "bundle"
|
||||||
layer = plan.get("layer")
|
layer = plan.get("layer")
|
||||||
if layer not in ("guest", "host", "docker"):
|
if layer not in ("guest", "host", "docker", "pve"):
|
||||||
raise Refused("R12", f"layer {layer!r} is not guest, host or docker")
|
raise Refused("R12", f"layer {layer!r} is not guest, host, docker or pve")
|
||||||
lane = plan.get("lane", "fast")
|
lane = plan.get("lane", "fast")
|
||||||
if layer == "docker" and lane != "slow":
|
if layer == "docker" and lane != "slow":
|
||||||
raise Refused("R3", "the Docker engine is the slow lane (`11` §5.8); a fast-lane Docker plan is refused")
|
raise Refused("R3", "the Docker engine is the slow lane (`11` §5.8); a fast-lane Docker plan is refused")
|
||||||
if layer != "docker" and lane != "fast":
|
if layer == "pve" and lane != "slow":
|
||||||
|
raise Refused("R3", "the Proxmox packages are the slow lane (`11` §5.10); a fast-lane pve plan is refused")
|
||||||
|
if layer not in ("docker", "pve") and lane != "fast":
|
||||||
raise Refused("R3", f"the {layer} layer has no slow lane in this release (kernel, Proxmox: `11` §8 step 6)")
|
raise Refused("R3", f"the {layer} layer has no slow lane in this release (kernel, Proxmox: `11` §8 step 6)")
|
||||||
if mode == "facts" and layer != "host":
|
if mode == "facts" and layer != "host":
|
||||||
raise Refused("R11", "facts is a host-layer mode (it reads the host and the guest)")
|
raise Refused("R11", "facts is a host-layer mode (it reads the host and the guest)")
|
||||||
@@ -447,7 +460,7 @@ class Apply:
|
|||||||
raise Refused("R11", "live-restore-on is a guest-layer mode")
|
raise Refused("R11", "live-restore-on is a guest-layer mode")
|
||||||
if mode == "oom-check" and layer != "docker":
|
if mode == "oom-check" and layer != "docker":
|
||||||
raise Refused("R11", "oom-check is a docker-layer mode (it checks the guest's Docker engine)")
|
raise Refused("R11", "oom-check is a docker-layer mode (it checks the guest's Docker engine)")
|
||||||
if plan.get("undo") and layer != "docker":
|
if plan.get("undo") and layer != "docker": # the pve layer has no undo in this release (R-812 option A)
|
||||||
raise Refused("R5", "an undo (downgrade) exists only for the Docker layer, inside a signed job")
|
raise Refused("R5", "an undo (downgrade) exists only for the Docker layer, inside a signed job")
|
||||||
vmid = plan.get("vmid")
|
vmid = plan.get("vmid")
|
||||||
if not isinstance(vmid, int) or isinstance(vmid, bool) or vmid <= 0:
|
if not isinstance(vmid, int) or isinstance(vmid, bool) or vmid <= 0:
|
||||||
@@ -458,17 +471,19 @@ class Apply:
|
|||||||
if plan.get("allow_new"):
|
if plan.get("allow_new"):
|
||||||
raise Refused("R6", "allow_new is a slow-lane field; the fast lane never adds a package")
|
raise Refused("R6", "allow_new is a slow-lane field; the fast lane never adds a package")
|
||||||
select = plan.get("select", "listed")
|
select = plan.get("select", "listed")
|
||||||
if select not in ("listed", "pending-fast", "pending-docker"):
|
if select not in ("listed", "pending-fast", "pending-docker", "pending-pve"):
|
||||||
raise Refused("R11", f"unknown select {select!r}")
|
raise Refused("R11", f"unknown select {select!r}")
|
||||||
if (select == "pending-docker") != (layer == "docker" and select != "listed"):
|
if (select == "pending-docker") != (layer == "docker" and select != "listed"):
|
||||||
if select == "pending-docker" or layer == "docker":
|
if select == "pending-docker" or layer == "docker":
|
||||||
raise Refused("R11", f"select {select!r} does not fit layer {layer!r}")
|
raise Refused("R11", f"select {select!r} does not fit layer {layer!r}")
|
||||||
|
if (select == "pending-pve") != (layer == "pve" and select != "listed"):
|
||||||
|
raise Refused("R11", f"select {select!r} does not fit layer {layer!r}")
|
||||||
pk = plan.get("packages", [])
|
pk = plan.get("packages", [])
|
||||||
if not isinstance(pk, list):
|
if not isinstance(pk, list):
|
||||||
raise Refused("R11", "packages must be a list")
|
raise Refused("R11", "packages must be a list")
|
||||||
if mode == "apply" and select == "listed" and not pk:
|
if mode == "apply" and select == "listed" and not pk:
|
||||||
raise Refused("R11", "packages must be a non-empty list in apply mode (select listed)")
|
raise Refused("R11", "packages must be a non-empty list in apply mode (select listed)")
|
||||||
if select in ("pending-fast", "pending-docker") and pk:
|
if select in ("pending-fast", "pending-docker", "pending-pve") and pk:
|
||||||
raise Refused("R11", f"select {select} takes no package list")
|
raise Refused("R11", f"select {select} takes no package list")
|
||||||
seen = set()
|
seen = set()
|
||||||
for e in pk:
|
for e in pk:
|
||||||
@@ -488,6 +503,12 @@ class Apply:
|
|||||||
continue
|
continue
|
||||||
if n in DOCKER_NAMES:
|
if n in DOCKER_NAMES:
|
||||||
raise Refused("R2", f"{n} is a Docker package — the slow lane (`11` §5.8), never in a {layer} plan")
|
raise Refused("R2", f"{n} is a Docker package — the slow lane (`11` §5.8), never in a {layer} plan")
|
||||||
|
if layer == "pve":
|
||||||
|
if o != PVE_ORIGIN:
|
||||||
|
raise Refused("R2", f"{n}: origin {o!r} is not {PVE_ORIGIN!r} (the pve layer)")
|
||||||
|
if HOST_SLOW_RE.match(n):
|
||||||
|
raise Refused("R14", f"{n} is a kernel / boot / firmware package — never the pve lane (R-836)")
|
||||||
|
continue
|
||||||
if o not in FAST_ORIGINS:
|
if o not in FAST_ORIGINS:
|
||||||
raise Refused("R2", f"{n}: origin {o!r} is not Debian / Debian-Security (the fast lane, `11` C3)")
|
raise Refused("R2", f"{n}: origin {o!r} is not Debian / Debian-Security (the fast lane, `11` C3)")
|
||||||
if layer == "host" and HOST_SLOW_RE.match(n):
|
if layer == "host" and HOST_SLOW_RE.match(n):
|
||||||
@@ -630,12 +651,13 @@ class Apply:
|
|||||||
now = self.r.now()
|
now = self.r.now()
|
||||||
self.r.write_nonces({k: v for k, v in seen.items() if v > now})
|
self.r.write_nonces({k: v for k, v in seen.items() if v > now})
|
||||||
|
|
||||||
def docker_authority(self, plan):
|
def docker_authority(self, plan, op_name=SIGNED_OP):
|
||||||
"""R3 for the docker layer: returns (who, undo). A signed job binds the EXACT package list and the undo flag."""
|
"""R3 for the docker (and, op_name os_pve_step, the pve) layer: returns (who, undo). A signed job binds the EXACT
|
||||||
|
package list and the undo flag."""
|
||||||
trust = self.load_trust()
|
trust = self.load_trust()
|
||||||
signed = plan.get("signed")
|
signed = plan.get("signed")
|
||||||
if signed:
|
if signed:
|
||||||
params = self.verify_signed(signed, trust)
|
params = self.verify_signed(signed, trust, op_name=op_name)
|
||||||
want = sorted(f"{e.get('name')}={e.get('version')}" for e in params.get("packages") or [])
|
want = sorted(f"{e.get('name')}={e.get('version')}" for e in params.get("packages") or [])
|
||||||
got = sorted(f"{e['name']}={e['version']}" for e in plan.get("packages", []))
|
got = sorted(f"{e['name']}={e['version']}" for e in plan.get("packages", []))
|
||||||
if not want or want != got:
|
if not want or want != got:
|
||||||
@@ -649,7 +671,7 @@ class Apply:
|
|||||||
raise Refused("R3", "an undo (downgrade) needs a signed operator job")
|
raise Refused("R3", "an undo (downgrade) needs a signed operator job")
|
||||||
if trust.get("ring0_slow_lane") is True:
|
if trust.get("ring0_slow_lane") is True:
|
||||||
return "ring0", False
|
return "ring0", False
|
||||||
raise Refused("R3", "a Docker step needs a signed operator job (ring 1) or this box's root-owned ring-0 mark")
|
raise Refused("R3", f"a {self.layer} slow-lane step needs a signed operator job (ring 1) or this box's root-owned ring-0 mark")
|
||||||
|
|
||||||
def live_restore(self):
|
def live_restore(self):
|
||||||
rc, out, _ = self.g(["docker", "info", "--format", "{{.LiveRestoreEnabled}}"], timeout=60)
|
rc, out, _ = self.g(["docker", "info", "--format", "{{.LiveRestoreEnabled}}"], timeout=60)
|
||||||
@@ -795,8 +817,8 @@ class Apply:
|
|||||||
|
|
||||||
# ---------- target helpers ----------
|
# ---------- target helpers ----------
|
||||||
def x(self, argv, timeout=1800):
|
def x(self, argv, timeout=1800):
|
||||||
"""Run in the TARGET layer: the guest via pct exec, or the host directly."""
|
"""Run in the TARGET layer: the guest via pct exec, or the host directly (host and pve)."""
|
||||||
if self.layer == "host":
|
if self.layer in ("host", "pve"):
|
||||||
return self.r.host(argv, timeout)
|
return self.r.host(argv, timeout)
|
||||||
return self.r.guest(self.vmid, argv, timeout) # guest and docker both live in the customer guest
|
return self.r.guest(self.vmid, argv, timeout) # guest and docker both live in the customer guest
|
||||||
|
|
||||||
@@ -891,7 +913,7 @@ class Apply:
|
|||||||
def restart_needed(self):
|
def restart_needed(self):
|
||||||
"""Processes still mapping deleted files, OUTSIDE containers (C11). Guest: outside docker; host: outside the
|
"""Processes still mapping deleted files, OUTSIDE containers (C11). Guest: outside docker; host: outside the
|
||||||
LXC guests (the host's /proc shows guest processes too)."""
|
LXC guests (the host's /proc shows guest processes too)."""
|
||||||
skip = RESTART_SKIP_CGROUP["host" if self.layer == "host" else "guest"]
|
skip = RESTART_SKIP_CGROUP["host" if self.layer in ("host", "pve") else "guest"]
|
||||||
script = ('for p in /proc/[0-9]*; do grep -q "(deleted)" $p/maps 2>/dev/null || continue; '
|
script = ('for p in /proc/[0-9]*; do grep -q "(deleted)" $p/maps 2>/dev/null || continue; '
|
||||||
'grep -q "%s" $p/cgroup 2>/dev/null && continue; echo "${p#/proc/} $(cat $p/comm 2>/dev/null)"; done' % skip)
|
'grep -q "%s" $p/cgroup 2>/dev/null && continue; echo "${p#/proc/} $(cat $p/comm 2>/dev/null)"; done' % skip)
|
||||||
rc, out, _ = self.x(["sh", "-c", script], timeout=120)
|
rc, out, _ = self.x(["sh", "-c", script], timeout=120)
|
||||||
@@ -965,7 +987,7 @@ class Apply:
|
|||||||
return Bundle(self).from_plan(plan)
|
return Bundle(self).from_plan(plan)
|
||||||
if self.mode == "agent_update":
|
if self.mode == "agent_update":
|
||||||
return self.agent_update(plan)
|
return self.agent_update(plan)
|
||||||
if self.layer == "host":
|
if self.layer in ("host", "pve"):
|
||||||
self.check_appliance()
|
self.check_appliance()
|
||||||
self.check_guest(self.vmid)
|
self.check_guest(self.vmid)
|
||||||
log = self.r.log
|
log = self.r.log
|
||||||
@@ -976,6 +998,9 @@ class Apply:
|
|||||||
self.report["oom_check"] = self.oom_check()
|
self.report["oom_check"] = self.oom_check()
|
||||||
return 0
|
return 0
|
||||||
self.who, self.allow_downgrade = ("fast", False)
|
self.who, self.allow_downgrade = ("fast", False)
|
||||||
|
if self.layer == "pve" and self.mode == "apply":
|
||||||
|
self.who, self.allow_downgrade = self.docker_authority(plan, op_name=PVE_SIGNED_OP)
|
||||||
|
self.report["authority"] = self.who
|
||||||
if self.layer == "docker" and self.mode == "apply":
|
if self.layer == "docker" and self.mode == "apply":
|
||||||
self.who, self.allow_downgrade = self.docker_authority(plan)
|
self.who, self.allow_downgrade = self.docker_authority(plan)
|
||||||
if self.live_restore() != "true":
|
if self.live_restore() != "true":
|
||||||
@@ -988,7 +1013,7 @@ class Apply:
|
|||||||
log(f"os-apply: START release={plan.get('release_id')} layer={self.layer}" +
|
log(f"os-apply: START release={plan.get('release_id')} layer={self.layer}" +
|
||||||
(f":{self.vmid}" if self.layer != "host" else "") +
|
(f":{self.vmid}" if self.layer != "host" else "") +
|
||||||
f" lane={plan.get('lane', 'fast')} mode={self.mode} select={self.select} packages={len(plan.get('packages', []))}" +
|
f" lane={plan.get('lane', 'fast')} mode={self.mode} select={self.select} packages={len(plan.get('packages', []))}" +
|
||||||
(f" authority={self.who}{' UNDO' if self.allow_downgrade else ''}" if self.layer == "docker" else ""))
|
(f" authority={self.who}{' UNDO' if self.allow_downgrade else ''}" if self.layer in ("docker", "pve") else ""))
|
||||||
if self.apt_lock_held():
|
if self.apt_lock_held():
|
||||||
raise Refused("R9", f"another apt/dpkg holds the lock on the {self.layer}")
|
raise Refused("R9", f"another apt/dpkg holds the lock on the {self.layer}")
|
||||||
self.report["health_before"] = self.health()
|
self.report["health_before"] = self.health()
|
||||||
@@ -1012,6 +1037,8 @@ class Apply:
|
|||||||
if self.layer == "docker":
|
if self.layer == "docker":
|
||||||
rc_v, out_v, _ = self.g(["docker", "version", "--format", "{{.Server.Version}}"], timeout=60)
|
rc_v, out_v, _ = self.g(["docker", "version", "--format", "{{.Server.Version}}"], timeout=60)
|
||||||
self.report["docker_engine"] = out_v.strip() if rc_v == 0 and out_v.strip() else "unknown"
|
self.report["docker_engine"] = out_v.strip() if rc_v == 0 and out_v.strip() else "unknown"
|
||||||
|
if self.layer == "pve":
|
||||||
|
self.report["pve_manager"] = self.pve_manager()
|
||||||
self.report["reboot_scanned"] = "reboot_needed" in self.report
|
self.report["reboot_scanned"] = "reboot_needed" in self.report
|
||||||
self.report["health_after"] = self.health()
|
self.report["health_after"] = self.health()
|
||||||
if self.layer == "docker" and self.mode == "apply":
|
if self.layer == "docker" and self.mode == "apply":
|
||||||
@@ -1161,10 +1188,26 @@ class Apply:
|
|||||||
return [{"name": p["name"], "version": p["to"], "origin": DOCKER_ORIGIN} for p in pend
|
return [{"name": p["name"], "version": p["to"], "origin": DOCKER_ORIGIN} for p in pend
|
||||||
if p["from"] is not None and p["name"] in DOCKER_NAMES and self.origin_name(p["origin"]) == {DOCKER_ORIGIN}]
|
if p["from"] is not None and p["name"] in DOCKER_NAMES and self.origin_name(p["origin"]) == {DOCKER_ORIGIN}]
|
||||||
|
|
||||||
|
def pending_pve(self):
|
||||||
|
"""Ring 0 (select pending-pve): the newest pending version of each INSTALLED Proxmox-origin package, never a
|
||||||
|
kernel / boot / firmware / microcode name (HOST_SLOW_RE, R-836's lane), never another origin."""
|
||||||
|
rc, pend, remv, _ = self.simulate(["dist-upgrade"])
|
||||||
|
return [{"name": p["name"], "version": p["to"], "origin": PVE_ORIGIN} for p in pend
|
||||||
|
if p["from"] is not None and not HOST_SLOW_RE.match(p["name"]) and p["name"] not in DOCKER_NAMES
|
||||||
|
and self.origin_name(p["origin"]) == {PVE_ORIGIN}]
|
||||||
|
|
||||||
|
def pve_manager(self):
|
||||||
|
"""pveversion's pve-manager version ("unknown" when it cannot be read)."""
|
||||||
|
rc, out, _ = self.r.host(["pveversion"], 60)
|
||||||
|
m = re.match(r"^pve-manager/([^/\s]+)", out.strip()) if rc == 0 else None
|
||||||
|
return m.group(1) if m else "unknown"
|
||||||
|
|
||||||
def origin_ok(self, origin):
|
def origin_ok(self, origin):
|
||||||
o = self.origin_name(origin)
|
o = self.origin_name(origin)
|
||||||
if self.layer == "docker":
|
if self.layer == "docker":
|
||||||
return o == {DOCKER_ORIGIN}
|
return o == {DOCKER_ORIGIN}
|
||||||
|
if self.layer == "pve":
|
||||||
|
return o == {PVE_ORIGIN}
|
||||||
return bool(o & set(FAST_ORIGINS))
|
return bool(o & set(FAST_ORIGINS))
|
||||||
|
|
||||||
def apply(self, plan):
|
def apply(self, plan):
|
||||||
@@ -1173,6 +1216,8 @@ class Apply:
|
|||||||
packages = plan["packages"]
|
packages = plan["packages"]
|
||||||
elif self.select == "pending-docker":
|
elif self.select == "pending-docker":
|
||||||
packages = self.pending_docker()
|
packages = self.pending_docker()
|
||||||
|
elif self.select == "pending-pve":
|
||||||
|
packages = self.pending_pve()
|
||||||
else:
|
else:
|
||||||
packages = self.pending_fast()
|
packages = self.pending_fast()
|
||||||
cmp_op = "ne" if self.allow_downgrade else "gt"
|
cmp_op = "ne" if self.allow_downgrade else "gt"
|
||||||
@@ -1221,6 +1266,11 @@ class Apply:
|
|||||||
raise Refused("R4", f"the plan would remove {', '.join(remv[:5])}")
|
raise Refused("R4", f"the plan would remove {', '.join(remv[:5])}")
|
||||||
want = dict(upgrade)
|
want = dict(upgrade)
|
||||||
for p in sim:
|
for p in sim:
|
||||||
|
if p["from"] is None and self.layer == "pve" and p["name"] in PVE_NEW_ALLOW and self.origin_ok(p["origin"]) \
|
||||||
|
and not HOST_SLOW_RE.match(p["name"]):
|
||||||
|
self.r.log(f"os-apply: NEW {p['name']}={p['to']} (on the pve lane's allow-list)")
|
||||||
|
self.report.setdefault("added", []).append({"name": p["name"], "version": p["to"]})
|
||||||
|
continue
|
||||||
if p["from"] is None:
|
if p["from"] is None:
|
||||||
raise Refused("R6", f"the plan would add a package that is not installed: {p['name']}")
|
raise Refused("R6", f"the plan would add a package that is not installed: {p['name']}")
|
||||||
if p["name"] not in want:
|
if p["name"] not in want:
|
||||||
@@ -1231,7 +1281,7 @@ class Apply:
|
|||||||
raise Refused("R5", f"{p['name']} would be downgraded {p['from']} -> {p['to']}")
|
raise Refused("R5", f"{p['name']} would be downgraded {p['from']} -> {p['to']}")
|
||||||
if not self.origin_ok(p["origin"]):
|
if not self.origin_ok(p["origin"]):
|
||||||
raise Refused("R2", f"{p['name']} would come from {p['origin']}, not the {self.layer} layer's origin")
|
raise Refused("R2", f"{p['name']} would come from {p['origin']}, not the {self.layer} layer's origin")
|
||||||
if self.layer == "host" and HOST_SLOW_RE.match(p["name"]):
|
if self.layer in ("host", "pve") and HOST_SLOW_RE.match(p["name"]):
|
||||||
raise Refused("R14", f"{p['name']} is a kernel / boot / firmware package — the host's slow lane")
|
raise Refused("R14", f"{p['name']} is a kernel / boot / firmware package — the host's slow lane")
|
||||||
need = self.download_bytes(args)
|
need = self.download_bytes(args)
|
||||||
free = self.free_bytes()
|
free = self.free_bytes()
|
||||||
|
|||||||
@@ -17,6 +17,8 @@ Verbs (each one sudoers line, exact-match pattern):
|
|||||||
wg /var/lib/felhom-agent/wg/wg-felhom.conf -> /etc/wireguard/wg-felhom.conf (0600)
|
wg /var/lib/felhom-agent/wg/wg-felhom.conf -> /etc/wireguard/wg-felhom.conf (0600)
|
||||||
sshd-config /var/lib/felhom-agent/felhom-sshd/sshd_config -> /etc/felhom-sshd/sshd_config
|
sshd-config /var/lib/felhom-agent/felhom-sshd/sshd_config -> /etc/felhom-sshd/sshd_config
|
||||||
sshd-key /var/lib/felhom-agent/felhom-sshd/authorized_keys.felhom-op -> /etc/felhom-sshd/authorized_keys/felhom-op
|
sshd-key /var/lib/felhom-agent/felhom-sshd/authorized_keys.felhom-op -> /etc/felhom-sshd/authorized_keys/felhom-op
|
||||||
|
controller-image <vmid> the ref on STDIN -> /etc/felhom-controller-image INSIDE guest <vmid> (R-861 (a) A1): only
|
||||||
|
our registry + our repository + an x.y.z tag; the agent no longer has a `tee` grant
|
||||||
--self-check prints "felhom-priv-apply ok verbs=..." (the bundle's self-check)
|
--self-check prints "felhom-priv-apply ok verbs=..." (the bundle's self-check)
|
||||||
|
|
||||||
Exit codes: 0 installed (or already identical), 2 usage, 3 refused (content or source), 4 install failed.
|
Exit codes: 0 installed (or already identical), 2 usage, 3 refused (content or source), 4 install failed.
|
||||||
@@ -39,7 +41,14 @@ WG_SRC, WG_DEST = STATE + "/wg/wg-felhom.conf", "/etc/wireguard/wg-felhom.conf"
|
|||||||
SSHD_SRC, SSHD_DEST = STATE + "/felhom-sshd/sshd_config", "/etc/felhom-sshd/sshd_config"
|
SSHD_SRC, SSHD_DEST = STATE + "/felhom-sshd/sshd_config", "/etc/felhom-sshd/sshd_config"
|
||||||
KEY_SRC, KEY_DEST = STATE + "/felhom-sshd/authorized_keys.felhom-op", "/etc/felhom-sshd/authorized_keys/felhom-op"
|
KEY_SRC, KEY_DEST = STATE + "/felhom-sshd/authorized_keys.felhom-op", "/etc/felhom-sshd/authorized_keys/felhom-op"
|
||||||
MAX_BYTES = 64 * 1024
|
MAX_BYTES = 64 * 1024
|
||||||
VERBS = ("unit", "dnsmasq", "wg", "sshd-config", "sshd-key")
|
VERBS = ("unit", "dnsmasq", "wg", "sshd-config", "sshd-key", "controller-image")
|
||||||
|
# R-861 (a) A1 (`09` §3 decision 165): the SAME pattern as the agent's controllerImageRe (internal/localapi/
|
||||||
|
# controllerswap.go) — a compromised agent cannot hand the guest's bootstrap any other image. Pinned by
|
||||||
|
# configs/test_felhom_priv_apply.py ControllerImage.
|
||||||
|
CONTROLLER_IMAGE_RE = re.compile(r"^gitea\.dooplex\.hu/admin/felhom-controller:[0-9]+\.[0-9]+\.[0-9]+$")
|
||||||
|
CONTROLLER_IMAGE_FILE = "/etc/felhom-controller-image"
|
||||||
|
CONTROLLER_IMAGE_MAX = 256
|
||||||
|
VMID_RE = re.compile(r"^[0-9]{1,9}$")
|
||||||
|
|
||||||
UNIT_NAME_RE = re.compile(r"^mnt-[A-Za-z0-9_.\\-]+\.(mount|automount)$")
|
UNIT_NAME_RE = re.compile(r"^mnt-[A-Za-z0-9_.\\-]+\.(mount|automount)$")
|
||||||
DNSMASQ_TMP_RE = re.compile(r"^/tmp/felhom-resolver-[0-9]+\.conf$")
|
DNSMASQ_TMP_RE = re.compile(r"^/tmp/felhom-resolver-[0-9]+\.conf$")
|
||||||
@@ -123,6 +132,16 @@ class Host:
|
|||||||
pass
|
pass
|
||||||
raise
|
raise
|
||||||
|
|
||||||
|
def read_stdin(self, limit):
|
||||||
|
return sys.stdin.buffer.read(limit + 1)
|
||||||
|
|
||||||
|
def write_guest_image(self, vmid, data):
|
||||||
|
"""As root: `pct exec <vmid> -- tee <the fixed file>` with the checked ref on stdin (no shell)."""
|
||||||
|
r = subprocess.run(["/usr/sbin/pct", "exec", str(vmid), "--", "tee", CONTROLLER_IMAGE_FILE],
|
||||||
|
input=data, stdout=subprocess.DEVNULL, stderr=subprocess.PIPE, timeout=60)
|
||||||
|
if r.returncode != 0:
|
||||||
|
raise OSError(f"pct exec {vmid} tee exited {r.returncode}: {r.stderr.decode(errors='replace').strip()[:200]}")
|
||||||
|
|
||||||
def log(self, line):
|
def log(self, line):
|
||||||
print(line, file=sys.stderr)
|
print(line, file=sys.stderr)
|
||||||
try:
|
try:
|
||||||
@@ -377,6 +396,34 @@ def plan(argv):
|
|||||||
raise Refused("A1", f"wrong arguments for {v}")
|
raise Refused("A1", f"wrong arguments for {v}")
|
||||||
|
|
||||||
|
|
||||||
|
def controller_image(rest, host):
|
||||||
|
"""R-861 (a) A1: read the ref on stdin, check it, write it INSIDE the guest as root."""
|
||||||
|
try:
|
||||||
|
if len(rest) != 1 or not VMID_RE.match(rest[0]):
|
||||||
|
raise Refused("A1", "usage: felhom-priv-apply controller-image <vmid> (the ref on stdin)")
|
||||||
|
raw = host.read_stdin(CONTROLLER_IMAGE_MAX)
|
||||||
|
if len(raw) > CONTROLLER_IMAGE_MAX:
|
||||||
|
raise Refused("I1", f"the image ref is longer than {CONTROLLER_IMAGE_MAX} bytes")
|
||||||
|
try:
|
||||||
|
text = raw.decode("ascii")
|
||||||
|
except UnicodeDecodeError:
|
||||||
|
raise Refused("I1", "the image ref is not ASCII")
|
||||||
|
ref = text[:-1] if text.endswith("\n") else text
|
||||||
|
if not CONTROLLER_IMAGE_RE.match(ref) or "\n" in ref:
|
||||||
|
raise Refused("I1", "the image ref is not gitea.dooplex.hu/admin/felhom-controller:<x.y.z>")
|
||||||
|
except Refused as e:
|
||||||
|
host.log(f"felhom-priv-apply: REFUSED [{e.rule}] controller-image {' '.join(rest)[:40]}: {e.reason}")
|
||||||
|
return 2 if e.rule == "A1" else 3
|
||||||
|
vmid = int(rest[0])
|
||||||
|
try:
|
||||||
|
host.write_guest_image(vmid, (ref + "\n").encode())
|
||||||
|
except (OSError, subprocess.SubprocessError) as e:
|
||||||
|
host.log(f"felhom-priv-apply: FAILED controller-image {vmid}: {e}")
|
||||||
|
return 4
|
||||||
|
host.log(f"felhom-priv-apply: WROTE controller-image {vmid} {ref}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
def main(argv, host=None):
|
def main(argv, host=None):
|
||||||
host = host or Host()
|
host = host or Host()
|
||||||
if argv == ["--self-check"]:
|
if argv == ["--self-check"]:
|
||||||
@@ -396,6 +443,8 @@ def main(argv, host=None):
|
|||||||
return 3
|
return 3
|
||||||
print("OK")
|
print("OK")
|
||||||
return 0
|
return 0
|
||||||
|
if argv and argv[0] == "controller-image":
|
||||||
|
return controller_image(argv[1:], host)
|
||||||
try:
|
try:
|
||||||
verb, src, dest, mode, checker = plan(argv)
|
verb, src, dest, mode, checker = plan(argv)
|
||||||
data = host.read_source(src)
|
data = host.read_source(src)
|
||||||
|
|||||||
@@ -232,6 +232,8 @@ class Fake:
|
|||||||
return (0, self.daemon_json, "") if self.daemon_json is not None else (1, "", "No such file")
|
return (0, self.daemon_json, "") if self.daemon_json is not None else (1, "", "No such file")
|
||||||
if cmd == "cat" and a[1] == "/etc/debian_version":
|
if cmd == "cat" and a[1] == "/etc/debian_version":
|
||||||
return 0, "13.7\n", ""
|
return 0, "13.7\n", ""
|
||||||
|
if cmd == "pveversion":
|
||||||
|
return 0, f"pve-manager/{self.installed.get('pve-manager', '9.2.2')}/abcdef (running kernel: 7.0.14-20-pve)\n", ""
|
||||||
if cmd == "uname":
|
if cmd == "uname":
|
||||||
return 0, "7.0.14-20-pve\n", ""
|
return 0, "7.0.14-20-pve\n", ""
|
||||||
if cmd == "apt-mark":
|
if cmd == "apt-mark":
|
||||||
@@ -284,7 +286,7 @@ class Fake:
|
|||||||
n, v = x.split("=", 1)
|
n, v = x.split("=", 1)
|
||||||
if v not in self.avail(n):
|
if v not in self.avail(n):
|
||||||
return 100, "", f"E: Version '{v}' for '{n}' was not found"
|
return 100, "", f"E: Version '{v}' for '{n}' was not found"
|
||||||
origin = "Docker CE:trixie" if n in osapply.DOCKER_NAMES else SEC if n == "openssl" else DEB
|
origin = getattr(self, "origins", {}).get(n) or ("Docker CE:trixie" if n in osapply.DOCKER_NAMES else SEC if n == "openssl" else DEB)
|
||||||
out += f"Inst {n} [{self.installed[n]}] ({v} {origin} [amd64])\n"
|
out += f"Inst {n} [{self.installed[n]}] ({v} {origin} [amd64])\n"
|
||||||
out += "".join(l + "\n" for l in self.extra_sim)
|
out += "".join(l + "\n" for l in self.extra_sim)
|
||||||
return 0, out, ""
|
return 0, out, ""
|
||||||
@@ -1324,5 +1326,155 @@ class OOMCheck(unittest.TestCase):
|
|||||||
self.assertEqual((rc, rep["refused"]["code"]), (2, "R11"), rep)
|
self.assertEqual((rc, rep["refused"]["code"]), (2, "R11"), rep)
|
||||||
|
|
||||||
|
|
||||||
|
PVE = "Proxmox Debian Repository:stable"
|
||||||
|
PVE_SET = [{"name": "pve-manager", "version": "9.2.21", "origin": "Proxmox Debian Repository"},
|
||||||
|
{"name": "libpve-common-perl", "version": "9.1.9", "origin": "Proxmox Debian Repository"}]
|
||||||
|
|
||||||
|
|
||||||
|
def pve_fake(signed=None, ring0=False):
|
||||||
|
f = Fake()
|
||||||
|
f.installed.update({"pve-manager": "9.2.2", "libpve-common-perl": "9.1.1", "proxmox-kernel-helper": "9.0.4"})
|
||||||
|
f.live["pve-manager"] = {"9.2.21", "9.2.2"}
|
||||||
|
f.live["libpve-common-perl"] = {"9.1.9", "9.1.1"}
|
||||||
|
f.origins = {"pve-manager": PVE, "libpve-common-perl": PVE, "proxmox-kernel-helper": PVE, "shim-signed": PVE,
|
||||||
|
"proxmox-firewall-data": PVE}
|
||||||
|
f.plan = {"release_id": "os-pve-t1", "layer": "pve", "lane": "slow", "vmid": 9201, "mode": "apply",
|
||||||
|
"packages": [dict(p) for p in PVE_SET]}
|
||||||
|
if ring0:
|
||||||
|
f.files[osapply.TRUST_FILE] = json.dumps({"host_id": "demo-hp-bb76ea", "ring0_slow_lane": True})
|
||||||
|
if signed is not None:
|
||||||
|
f.plan["signed"] = signed
|
||||||
|
return f
|
||||||
|
|
||||||
|
|
||||||
|
class PVELane(unittest.TestCase):
|
||||||
|
"""R-812 option A (`09` §3 decision 163): the host's Proxmox USERSPACE packages, slow lane, no kernel / boot /
|
||||||
|
firmware / microcode (R14), no removal, a new package only from PVE_NEW_ALLOW. Red-proof: audits/day-2026-10-07/B/."""
|
||||||
|
|
||||||
|
def refused(self, f, code):
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual(rc, 2, rep)
|
||||||
|
self.assertEqual(rep["refused"]["code"], code, rep)
|
||||||
|
self.assertEqual(f.installed["pve-manager"], "9.2.2", "nothing may be installed on a refusal")
|
||||||
|
return rep
|
||||||
|
|
||||||
|
# THE RED TEST (design-R-812 §5): before the pve layer existed this plan was refused R12.
|
||||||
|
def test_pve_manager_plan_is_installed_on_the_host(self):
|
||||||
|
f = pve_fake(signed=signed_job(packages=PVE_SET, op="os_pve_step"))
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual(rc, 0, rep)
|
||||||
|
self.assertEqual(f.installed["pve-manager"], "9.2.21")
|
||||||
|
self.assertEqual(rep["authority"], "signed")
|
||||||
|
self.assertEqual(rep["pve_manager"], "9.2.21", "pveversion after the step is reported")
|
||||||
|
inst = [c for c in f.calls if c[0] == "host" and "install" in c[1] and "-s" not in c[1] and "-f" not in c[1]
|
||||||
|
and "--print-uris" not in c[1]]
|
||||||
|
self.assertTrue(inst, "the pve layer installs on the HOST")
|
||||||
|
self.assertFalse([c for c in f.calls if c[0] == "guest" and "install" in c[2]], "nothing installed in the guest")
|
||||||
|
self.assertEqual(sorted(rep["health_after"]["host_services"]), sorted(osapply.HOST_SERVICES))
|
||||||
|
|
||||||
|
def test_kernel_in_a_pve_plan_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["packages"].append({"name": "proxmox-kernel-7.0", "version": "7.0.14-20", "origin": "Proxmox Debian Repository"})
|
||||||
|
self.refused(f, "R14")
|
||||||
|
|
||||||
|
def test_shim_in_a_pve_plan_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["packages"].append({"name": "shim-signed", "version": "1.47+pmx1", "origin": "Proxmox Debian Repository"})
|
||||||
|
self.refused(f, "R14")
|
||||||
|
|
||||||
|
def test_kernel_pulled_in_by_the_simulation_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.installed["proxmox-kernel-helper"] = "9.0.4"
|
||||||
|
f.extra_sim = ["Inst proxmox-kernel-helper [9.0.4] (9.0.6 Proxmox Debian Repository:stable [all])"]
|
||||||
|
self.refused(f, "R6") # not in the plan — refused before the name check; R14 below when it IS in the plan
|
||||||
|
g = pve_fake(ring0=True)
|
||||||
|
g.live["proxmox-kernel-helper"] = {"9.0.6"}
|
||||||
|
g.plan["packages"] = [dict(PVE_SET[0])]
|
||||||
|
g.extra_sim = ["Inst proxmox-kernel-helper [9.0.4] (9.0.6 Proxmox Debian Repository:stable [all])"]
|
||||||
|
# a kernel-helper the plan did not name is R6; the R14 name check covers a listed one (test above)
|
||||||
|
self.refused(g, "R6")
|
||||||
|
|
||||||
|
def test_debian_package_in_a_pve_plan_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["packages"].append({"name": "libc6", "version": "2.41-12+deb13u4", "origin": "Debian"})
|
||||||
|
self.refused(f, "R2")
|
||||||
|
|
||||||
|
def test_debian_origin_in_the_pve_simulation_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.origins["libpve-common-perl"] = DEB
|
||||||
|
self.refused(f, "R2")
|
||||||
|
|
||||||
|
def test_docker_package_in_a_pve_plan_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["packages"].append({"name": "docker-ce", "version": "5:29.8.2-1~debian.13~trixie", "origin": "Proxmox Debian Repository"})
|
||||||
|
self.refused(f, "R2")
|
||||||
|
|
||||||
|
def test_pve_in_the_fast_lane_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["lane"] = "fast"
|
||||||
|
self.refused(f, "R3")
|
||||||
|
|
||||||
|
def test_no_authority_is_refused(self):
|
||||||
|
self.refused(pve_fake(), "R3")
|
||||||
|
|
||||||
|
def test_docker_signed_op_does_not_authorize_a_pve_step(self):
|
||||||
|
self.refused(pve_fake(signed=signed_job(packages=PVE_SET, op="os_docker_step")), "R3")
|
||||||
|
|
||||||
|
def test_pve_on_a_byo_box_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.files[osapply.INSTALL_STATE] = json.dumps({"mode": "byo"})
|
||||||
|
self.refused(f, "R12")
|
||||||
|
|
||||||
|
def test_unlisted_new_package_is_refused(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.extra_sim = ["Inst proxmox-new-thing (1.0 Proxmox Debian Repository:stable [all])"]
|
||||||
|
self.refused(f, "R6")
|
||||||
|
|
||||||
|
def test_allow_listed_new_package_is_accepted(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.extra_sim = ["Inst proxmox-firewall-data (0.1 Proxmox Debian Repository:stable [all])"]
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual(rc, 0, rep)
|
||||||
|
self.assertEqual(f.installed["pve-manager"], "9.2.21")
|
||||||
|
|
||||||
|
def test_allow_new_is_never_an_open_door_in_the_fast_lane(self):
|
||||||
|
f = Fake()
|
||||||
|
f.plan["layer"] = "host"
|
||||||
|
f.extra_sim = ["Inst proxmox-firewall-data (0.1 Proxmox Debian Repository:stable [all])"]
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual((rc, rep["refused"]["code"]), (2, "R6"), rep)
|
||||||
|
|
||||||
|
def test_undo_is_refused(self):
|
||||||
|
f = pve_fake(signed=signed_job(packages=PVE_SET, op="os_pve_step"))
|
||||||
|
f.plan["undo"] = True
|
||||||
|
self.refused(f, "R5")
|
||||||
|
|
||||||
|
def test_ring0_pending_pve_takes_only_installed_proxmox_userspace(self):
|
||||||
|
f = pve_fake(ring0=True)
|
||||||
|
f.plan["select"], f.plan["packages"] = "pending-pve", []
|
||||||
|
f.installed.update({"linux-image-amd64": "6.12.1", "tailscale": "1.102.2"})
|
||||||
|
f.pending_sim = [
|
||||||
|
"Inst pve-manager [9.2.2] (9.2.21 Proxmox Debian Repository:stable [amd64])",
|
||||||
|
"Inst libpve-common-perl [9.1.1] (9.1.9 Proxmox Debian Repository:stable [all])",
|
||||||
|
"Inst proxmox-kernel-helper [9.0.4] (9.0.6 Proxmox Debian Repository:stable [all])",
|
||||||
|
"Inst proxmox-kernel-7.0.14-20-pve-signed (7.0.14-20 Proxmox Debian Repository:stable [amd64])",
|
||||||
|
"Inst proxmox-firewall-data (0.1 Proxmox Debian Repository:stable [all])",
|
||||||
|
"Inst libc6 [2.41-12+deb13u3] (2.41-12+deb13u4 Debian:13.7/stable [amd64])",
|
||||||
|
"Inst tailscale [1.102.2] (1.102.5 Tailscale:pkgs.tailscale.com [amd64])",
|
||||||
|
]
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual(rc, 0, rep)
|
||||||
|
self.assertEqual(rep["authority"], "ring0")
|
||||||
|
self.assertEqual(sorted(u["name"] for u in rep["upgraded"]), ["libpve-common-perl", "pve-manager"],
|
||||||
|
"pending-pve: installed, Proxmox-origin, never kernel/boot/firmware, never Debian or other origins")
|
||||||
|
self.assertEqual(f.installed["libc6"], "2.41-12+deb13u3")
|
||||||
|
|
||||||
|
def test_select_pending_pve_needs_the_pve_layer(self):
|
||||||
|
f = Fake()
|
||||||
|
f.plan["layer"], f.plan["select"], f.plan["packages"] = "host", "pending-pve", []
|
||||||
|
rc, rep = run(f)
|
||||||
|
self.assertEqual((rc, rep["refused"]["code"]), (2, "R11"), rep)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
unittest.main()
|
unittest.main()
|
||||||
|
|||||||
@@ -56,6 +56,18 @@ class FakeHost:
|
|||||||
def log(self, line):
|
def log(self, line):
|
||||||
self.logs.append(line)
|
self.logs.append(line)
|
||||||
|
|
||||||
|
# controller-image (R-861 (a) A1): the ref arrives on stdin and is written INSIDE the guest by root.
|
||||||
|
stdin = b""
|
||||||
|
guest_writes = None
|
||||||
|
|
||||||
|
def read_stdin(self, limit):
|
||||||
|
return self.stdin[:limit + 1]
|
||||||
|
|
||||||
|
def write_guest_image(self, vmid, data):
|
||||||
|
if self.guest_writes is None:
|
||||||
|
self.guest_writes = []
|
||||||
|
self.guest_writes.append((vmid, data))
|
||||||
|
|
||||||
|
|
||||||
LOCAL_UNIT = """# Managed by felhom-agent — do not edit by hand.
|
LOCAL_UNIT = """# Managed by felhom-agent — do not edit by hand.
|
||||||
[Unit]
|
[Unit]
|
||||||
@@ -316,5 +328,53 @@ class Refuses(unittest.TestCase):
|
|||||||
self.refused(h, ["wg", "/etc/shadow"], "A1")
|
self.refused(h, ["wg", "/etc/shadow"], "A1")
|
||||||
|
|
||||||
|
|
||||||
|
class ControllerImage(unittest.TestCase):
|
||||||
|
"""R-861 (a) A1 (`09` §3 decision 165): the agent can no longer `tee` any image ref into the guest. The root verb
|
||||||
|
reads the ref on stdin, requires our registry + our repository + an x.y.z tag, and writes the guest file itself.
|
||||||
|
RED-PROOF: on the pre-A1 wrapper `controller-image` is not a verb (A1 usage, rc 2) — the accepted case fails."""
|
||||||
|
|
||||||
|
def go(self, ref, *argv):
|
||||||
|
h = FakeHost()
|
||||||
|
h.stdin = ref.encode() if isinstance(ref, str) else ref
|
||||||
|
return h, run(h, *(argv or ("controller-image", "9201")))
|
||||||
|
|
||||||
|
def test_our_controller_ref_is_written_in_the_guest(self):
|
||||||
|
h, rc = self.go("gitea.dooplex.hu/admin/felhom-controller:0.301.0\n")
|
||||||
|
self.assertEqual(rc, 0, h.logs)
|
||||||
|
self.assertEqual(h.guest_writes, [(9201, b"gitea.dooplex.hu/admin/felhom-controller:0.301.0\n")])
|
||||||
|
|
||||||
|
def test_a_foreign_image_is_refused(self):
|
||||||
|
for ref in ("docker.io/library/alpine:latest\n", "alpine\n",
|
||||||
|
"gitea.dooplex.hu/admin/felhom-controller:latest\n",
|
||||||
|
"gitea.dooplex.hu/admin/other:0.1.0\n",
|
||||||
|
"evil.example/admin/felhom-controller:0.301.0\n",
|
||||||
|
"gitea.dooplex.hu/admin/felhom-controller:0.301.0\nalpine\n",
|
||||||
|
"gitea.dooplex.hu/admin/felhom-controller:0.301.0 x\n",
|
||||||
|
"", "\n"):
|
||||||
|
h, rc = self.go(ref)
|
||||||
|
self.assertEqual(rc, 3, f"{ref!r} was accepted")
|
||||||
|
self.assertFalse(h.guest_writes, f"{ref!r} wrote the guest file")
|
||||||
|
self.assertTrue(any("[I1]" in l for l in h.logs), h.logs)
|
||||||
|
|
||||||
|
def test_oversize_stdin_is_refused(self):
|
||||||
|
h, rc = self.go("gitea.dooplex.hu/admin/felhom-controller:0.301.0" + " " * 300)
|
||||||
|
self.assertEqual(rc, 3)
|
||||||
|
self.assertFalse(h.guest_writes)
|
||||||
|
|
||||||
|
def test_vmid_must_be_numeric(self):
|
||||||
|
for argv in (("controller-image", "9201;id"), ("controller-image", "-1"), ("controller-image",),
|
||||||
|
("controller-image", "9201", "9202")):
|
||||||
|
h, rc = self.go("gitea.dooplex.hu/admin/felhom-controller:0.301.0\n", *argv)
|
||||||
|
self.assertIn(rc, (2, 3), argv)
|
||||||
|
self.assertFalse(h.guest_writes, argv)
|
||||||
|
|
||||||
|
def test_self_check_names_the_verb(self):
|
||||||
|
import io, contextlib
|
||||||
|
buf = io.StringIO()
|
||||||
|
with contextlib.redirect_stdout(buf):
|
||||||
|
pa.main(["--self-check"])
|
||||||
|
self.assertIn("controller-image", buf.getvalue())
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
unittest.main(verbosity=2)
|
unittest.main(verbosity=2)
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
package backup
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"sort"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
||||||
|
)
|
||||||
|
|
||||||
|
// ForeignKeyLedger (R-366 slice 2, `09` §3 decision 168) holds, per backup tier, the whole-guest archives the
|
||||||
|
// restore-test pick skipped because another key wrote them (R-727 — an earlier install of this box). Since R-727 the
|
||||||
|
// skip was one INFO log line per archive and nothing else, so after a reinstall the operator was never told that the
|
||||||
|
// box's older whole-guest copies are unreadable to it. The host report carries this ledger; the hub raises ONE
|
||||||
|
// operator event when it changes.
|
||||||
|
//
|
||||||
|
// It reports nil until a tier has been evaluated since the agent started, so a restart does not read as "the set
|
||||||
|
// changed to empty" (the hub keeps its last state for an absent field).
|
||||||
|
type ForeignKeyLedger struct {
|
||||||
|
mu sync.Mutex
|
||||||
|
byTarget map[string]hub.ForeignKeyArchives
|
||||||
|
}
|
||||||
|
|
||||||
|
// NewForeignKeyLedger builds an empty ledger.
|
||||||
|
func NewForeignKeyLedger() *ForeignKeyLedger {
|
||||||
|
return &ForeignKeyLedger{}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (l *ForeignKeyLedger) set(target string, n int, oldest, newest int64) {
|
||||||
|
l.mu.Lock()
|
||||||
|
defer l.mu.Unlock()
|
||||||
|
if l.byTarget == nil {
|
||||||
|
l.byTarget = map[string]hub.ForeignKeyArchives{}
|
||||||
|
}
|
||||||
|
e := hub.ForeignKeyArchives{Target: target, Count: n}
|
||||||
|
if n > 0 {
|
||||||
|
e.Oldest = time.Unix(oldest, 0).UTC().Format(time.RFC3339)
|
||||||
|
e.Newest = time.Unix(newest, 0).UTC().Format(time.RFC3339)
|
||||||
|
}
|
||||||
|
l.byTarget[target] = e
|
||||||
|
}
|
||||||
|
|
||||||
|
// ForeignKeyArchives implements hub.ForeignKeyArchiveReporter: nil before any evaluation; otherwise the tiers that
|
||||||
|
// hold such archives (`Tiers` empty, never nil, when none do), sorted by tier.
|
||||||
|
func (l *ForeignKeyLedger) ForeignKeyArchives(context.Context) *hub.ForeignKeyArchivesStanza {
|
||||||
|
l.mu.Lock()
|
||||||
|
defer l.mu.Unlock()
|
||||||
|
if l.byTarget == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
out := []hub.ForeignKeyArchives{}
|
||||||
|
for _, e := range l.byTarget {
|
||||||
|
if e.Count > 0 {
|
||||||
|
out = append(out, e)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort.Slice(out, func(i, j int) bool { return out[i].Target < out[j].Target })
|
||||||
|
return &hub.ForeignKeyArchivesStanza{Tiers: out}
|
||||||
|
}
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
package backup
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/proxmox"
|
||||||
|
)
|
||||||
|
|
||||||
|
// R-366 slice 2 (`09` §3 decision 168) — the restore-test's skip of an archive written with another key stops being
|
||||||
|
// silent: the pick records, per tier, how many it skipped and their time range, and the host report carries it.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): remove the `r.foreign.set(...)` call from PickSettledRestoreCandidateOn → this fails
|
||||||
|
// with "after one evaluation the ledger must report felhom-pbs: 2 archives …; got []". Restored.
|
||||||
|
func TestR366_PickRecordsArchivesWrittenWithAnotherKey(t *testing.T) {
|
||||||
|
api := &fakeBackupAPI{
|
||||||
|
storages: []proxmox.Storage{{Storage: "felhom-pbs", Type: "pbs", EncryptionKey: thisBoxKey}},
|
||||||
|
content: []proxmox.StorageContent{
|
||||||
|
{VolID: "felhom-pbs:backup/ct/9201/2026-09-16T17:27:32Z", Content: "backup", VMID: 9201, Size: 4774114206, CTime: 1789579652, Encrypted: earlierBox2},
|
||||||
|
{VolID: "felhom-pbs:backup/ct/9201/2026-09-16T21:59:54Z", Content: "backup", VMID: 9201, Size: 20811501236, CTime: 1789595994, Encrypted: earlierBox1},
|
||||||
|
{VolID: "felhom-pbs:backup/ct/9201/2026-09-29T19:37:07Z", Content: "backup", VMID: 9201, Size: 3490689830, CTime: 1790710627, Encrypted: thisBoxKey},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
r := NewBackupRunner(api, "local", proxmox.ModeSnapshot, "", "keep-last=1", quiet())
|
||||||
|
l := NewForeignKeyLedger()
|
||||||
|
r.SetForeignKeyLedger(l)
|
||||||
|
|
||||||
|
if got := l.ForeignKeyArchives(context.Background()); got != nil {
|
||||||
|
t.Fatalf("before any evaluation the ledger must be nil (the hub keeps its state); got %v", got)
|
||||||
|
}
|
||||||
|
if _, _, err := r.PickSettledRestoreCandidateOn(context.Background(), "felhom-pbs", time.Time{}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
st := l.ForeignKeyArchives(context.Background())
|
||||||
|
want := hub.ForeignKeyArchives{Target: "felhom-pbs", Count: 2, Oldest: "2026-09-16T17:27:32Z", Newest: "2026-09-16T21:59:54Z"}
|
||||||
|
var got []hub.ForeignKeyArchives
|
||||||
|
if st != nil {
|
||||||
|
got = st.Tiers
|
||||||
|
}
|
||||||
|
if len(got) != 1 || got[0] != want {
|
||||||
|
t.Fatalf("after one evaluation the ledger must report felhom-pbs: 2 archives 2026-09-16T17:27:32Z…21:59:54Z; got %v", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Evaluated and none found → the stanza with `tiers: []`; not evaluated → no stanza at all. Never a null on the wire.
|
||||||
|
func TestR366_EvaluatedWithNoneIsAnEmptyList(t *testing.T) {
|
||||||
|
api := &fakeBackupAPI{
|
||||||
|
storages: []proxmox.Storage{{Storage: "felhom-pbs", Type: "pbs", EncryptionKey: thisBoxKey}},
|
||||||
|
content: []proxmox.StorageContent{{VolID: "felhom-pbs:backup/ct/9201/2026-09-29T19:37:07Z", Content: "backup", VMID: 9201, Size: 3490689830, CTime: 1790710627, Encrypted: thisBoxKey}},
|
||||||
|
}
|
||||||
|
r := NewBackupRunner(api, "local", proxmox.ModeSnapshot, "", "keep-last=1", quiet())
|
||||||
|
l := NewForeignKeyLedger()
|
||||||
|
r.SetForeignKeyLedger(l)
|
||||||
|
b, _ := json.Marshal(hub.HostReport{ForeignKeyArchives: l.ForeignKeyArchives(context.Background())})
|
||||||
|
if strings.Contains(string(b), "foreign_key_archives") {
|
||||||
|
t.Fatalf("not evaluated must omit the stanza; got %s", b)
|
||||||
|
}
|
||||||
|
if _, _, err := r.PickSettledRestoreCandidateOn(context.Background(), "felhom-pbs", time.Time{}); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
b, _ = json.Marshal(hub.HostReport{ForeignKeyArchives: l.ForeignKeyArchives(context.Background())})
|
||||||
|
if !strings.Contains(string(b), `"foreign_key_archives":{"tiers":[]}`) {
|
||||||
|
t.Fatalf("evaluated with none must report tiers: []; got %s", b)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -66,8 +66,13 @@ type BackupRunner struct {
|
|||||||
// due-check is served from the local-API handler goroutines.
|
// due-check is served from the local-API handler goroutines.
|
||||||
rejectedMu sync.Mutex
|
rejectedMu sync.Mutex
|
||||||
rejected map[string]struct{}
|
rejected map[string]struct{}
|
||||||
|
// foreign (R-366 slice 2) records, per tier, the archives the pick skipped as another key's. nil = not wired.
|
||||||
|
foreign *ForeignKeyLedger
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SetForeignKeyLedger wires the R-366 slice-2 ledger the host report reads.
|
||||||
|
func (r *BackupRunner) SetForeignKeyLedger(l *ForeignKeyLedger) { r.foreign = l }
|
||||||
|
|
||||||
// NewBackupRunner builds a runner. mode defaults to snapshot (works for a stopped guest and
|
// NewBackupRunner builds a runner. mode defaults to snapshot (works for a stopped guest and
|
||||||
// for lvm-thin); the caller may pass ModeStop for storages without snapshot support. retention is the
|
// for lvm-thin); the caller may pass ModeStop for storages without snapshot support. retention is the
|
||||||
// per-run prune spec ("keep-last=N", or "" to never prune) — only the periodic local backup sets it.
|
// per-run prune spec ("keep-last=N", or "" to never prune) — only the periodic local backup sets it.
|
||||||
@@ -370,6 +375,8 @@ func (r *BackupRunner) PickSettledRestoreCandidateOn(ctx context.Context, target
|
|||||||
var best string
|
var best string
|
||||||
var bestCTime int64 = -1
|
var bestCTime int64 = -1
|
||||||
known := map[int]bool{} // vmid → the guest exists on this node (asked once per vmid per pick)
|
known := map[int]bool{} // vmid → the guest exists on this node (asked once per vmid per pick)
|
||||||
|
var foreignN int // R-366 slice 2: archives skipped as another key's, and their time range
|
||||||
|
var foreignMin, foreignMax int64
|
||||||
for _, e := range contents {
|
for _, e := range contents {
|
||||||
if e.Content != "backup" {
|
if e.Content != "backup" {
|
||||||
continue
|
continue
|
||||||
@@ -384,6 +391,13 @@ func (r *BackupRunner) PickSettledRestoreCandidateOn(ctx context.Context, target
|
|||||||
}
|
}
|
||||||
if ownKey != "" && !strings.EqualFold(e.Encrypted, ownKey) {
|
if ownKey != "" && !strings.EqualFold(e.Encrypted, ownKey) {
|
||||||
r.noteNotAGuestBackupOnce(e, fmt.Sprintf("written by another box (key %s, this box's key %s) — not this box's proof", shortFP(e.Encrypted), shortFP(ownKey)))
|
r.noteNotAGuestBackupOnce(e, fmt.Sprintf("written by another box (key %s, this box's key %s) — not this box's proof", shortFP(e.Encrypted), shortFP(ownKey)))
|
||||||
|
foreignN++
|
||||||
|
if foreignMin == 0 || e.CTime < foreignMin {
|
||||||
|
foreignMin = e.CTime
|
||||||
|
}
|
||||||
|
if e.CTime > foreignMax {
|
||||||
|
foreignMax = e.CTime
|
||||||
|
}
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
// R-689 (v0.136.0): … OF A GUEST THAT STILL EXISTS here. Measured on demo-hp 2026-09-27 right after
|
// R-689 (v0.136.0): … OF A GUEST THAT STILL EXISTS here. Measured on demo-hp 2026-09-27 right after
|
||||||
@@ -420,6 +434,9 @@ func (r *BackupRunner) PickSettledRestoreCandidateOn(ctx context.Context, target
|
|||||||
bestCTime, best = e.CTime, e.VolID
|
bestCTime, best = e.CTime, e.VolID
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if r.foreign != nil {
|
||||||
|
r.foreign.set(target, foreignN, foreignMin, foreignMax)
|
||||||
|
}
|
||||||
if best == "" {
|
if best == "" {
|
||||||
return "", time.Time{}, nil
|
return "", time.Time{}, nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -145,7 +145,8 @@ var manifest = []Capability{
|
|||||||
{"controllerswap-image-inspect", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "docker", "image", "inspect", "gitea.dooplex.hu/admin/felhom-controller:0.0.0"}, true, ""},
|
{"controllerswap-image-inspect", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "docker", "image", "inspect", "gitea.dooplex.hu/admin/felhom-controller:0.0.0"}, true, ""},
|
||||||
{"controllerswap-inspect", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "docker", "inspect", "-f", "{{.State.Running}}", "felhom-controller"}, true, ""},
|
{"controllerswap-inspect", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "docker", "inspect", "-f", "{{.State.Running}}", "felhom-controller"}, true, ""},
|
||||||
{"controllerswap-restart", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "systemctl", "restart", "felhom-controller-bootstrap.service"}, true, ""},
|
{"controllerswap-restart", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "systemctl", "restart", "felhom-controller-bootstrap.service"}, true, ""},
|
||||||
{"controllerswap-write", "controller-swap / managed auto-update", "/usr/sbin/pct", []string{"exec", "9201", "--", "tee", "/etc/felhom-controller-image"}, true, ""},
|
// R-861 (a) A1 (decision 165): the write goes through the ROOT verb that checks the ref; the agent has no `tee` grant.
|
||||||
|
{"controllerswap-write", "controller-swap / managed auto-update", "/usr/local/sbin/felhom-priv-apply", []string{"controller-image", "9201"}, true, ""},
|
||||||
|
|
||||||
// ---- Stale-lock recovery (FELHOM_STALELOCK, v0.49.0; Critical: a guest stuck behind a stale
|
// ---- Stale-lock recovery (FELHOM_STALELOCK, v0.49.0; Critical: a guest stuck behind a stale
|
||||||
// reboot-during-backup lock can't start → the customer box stays DOWN until this clears it) ----
|
// reboot-during-backup lock can't start → the customer box stays DOWN until this clears it) ----
|
||||||
|
|||||||
@@ -200,7 +200,8 @@ func TestRedProof_DroppedGrantFailsCheck(t *testing.T) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// TestRedProof_DroppedControllerSwapTeeFailsCheck is the companion red-proof for the v0.45.0
|
// TestRedProof_DroppedControllerSwapTeeFailsCheck is the companion red-proof for the v0.45.0
|
||||||
// FELHOM_CONTROLLERSWAP grants: with the `tee /etc/felhom-controller-image` line removed, the
|
// FELHOM_CONTROLLERSWAP grants: with the write grant removed (since R-861 (a) A1 the `felhom-priv-apply controller-image`
|
||||||
|
// line; before it, an agent `tee /etc/felhom-controller-image`), the
|
||||||
// controllerswap-write capability MUST be reported uncovered. Proves the build gate watches the new
|
// controllerswap-write capability MUST be reported uncovered. Proves the build gate watches the new
|
||||||
// swap write grant (so dropping it can't ship a non-root agent that silently can't auto-update).
|
// swap write grant (so dropping it can't ship a non-root agent that silently can't auto-update).
|
||||||
func TestRedProof_DroppedControllerSwapTeeFailsCheck(t *testing.T) {
|
func TestRedProof_DroppedControllerSwapTeeFailsCheck(t *testing.T) {
|
||||||
@@ -210,7 +211,7 @@ func TestRedProof_DroppedControllerSwapTeeFailsCheck(t *testing.T) {
|
|||||||
}
|
}
|
||||||
var kept []string
|
var kept []string
|
||||||
for _, ln := range strings.Split(string(data), "\n") {
|
for _, ln := range strings.Split(string(data), "\n") {
|
||||||
if strings.Contains(ln, "tee /etc/felhom-controller-image") {
|
if strings.Contains(ln, "felhom-priv-apply ^controller-image") { // R-861 (a) A1: the write's grant
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
kept = append(kept, ln)
|
kept = append(kept, ln)
|
||||||
@@ -229,7 +230,7 @@ func TestRedProof_DroppedControllerSwapTeeFailsCheck(t *testing.T) {
|
|||||||
}
|
}
|
||||||
cmdline := write.Binary + " " + strings.Join(write.ReprArgs, " ")
|
cmdline := write.Binary + " " + strings.Join(write.ReprArgs, " ")
|
||||||
if matchesAny(cmdline, entries) {
|
if matchesAny(cmdline, entries) {
|
||||||
t.Errorf("red-proof FAILED: controllerswap-write still matches after dropping the tee grant")
|
t.Errorf("red-proof FAILED: controllerswap-write still matches after dropping its grant")
|
||||||
}
|
}
|
||||||
if full := parseSudoersEntries(t, string(data)); !matchesAny(cmdline, full) {
|
if full := parseSudoersEntries(t, string(data)); !matchesAny(cmdline, full) {
|
||||||
t.Errorf("controllerswap-write should be covered by the real sudoers")
|
t.Errorf("controllerswap-write should be covered by the real sudoers")
|
||||||
|
|||||||
@@ -49,6 +49,10 @@ var r861Injections = []string{
|
|||||||
"/usr/local/sbin/felhom-priv-apply unit ../../etc/x.mount",
|
"/usr/local/sbin/felhom-priv-apply unit ../../etc/x.mount",
|
||||||
"/usr/local/sbin/felhom-priv-apply dnsmasq /etc/shadow felhom-x.conf",
|
"/usr/local/sbin/felhom-priv-apply dnsmasq /etc/shadow felhom-x.conf",
|
||||||
"/usr/local/sbin/felhom-priv-apply wg /etc/shadow",
|
"/usr/local/sbin/felhom-priv-apply wg /etc/shadow",
|
||||||
|
// R-861 (a) A1 (decision 165): the agent wrote ANY image ref into the guest by `tee` — now only the root verb may
|
||||||
|
"/usr/sbin/pct exec 9201 -- tee /etc/felhom-controller-image",
|
||||||
|
"/usr/local/sbin/felhom-priv-apply controller-image 9201 9202",
|
||||||
|
"/usr/local/sbin/felhom-priv-apply controller-image 9201;id",
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestSudoersRefusesTheR861Injections(t *testing.T) {
|
func TestSudoersRefusesTheR861Injections(t *testing.T) {
|
||||||
@@ -93,3 +97,42 @@ func TestSudoersFstrimRuleIsExact(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// R-861 (a) A1: the managed controller update still has its route — the root verb, one numeric vmid.
|
||||||
|
func TestSudoersAllowsTheControllerImageVerb(t *testing.T) {
|
||||||
|
data, err := os.ReadFile(sudoersPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if !matchesAny("/usr/local/sbin/felhom-priv-apply controller-image 9201", parseSudoersEntries(t, string(data))) {
|
||||||
|
t.Fatal("the sudoers does not allow `felhom-priv-apply controller-image 9201` — a managed controller update cannot write its image")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// R-861 (b) B2 (decision 165, hygiene): felhom-op's `pct start|stop|unlock` grants are ONE numeric vmid each. The old
|
||||||
|
// glob `[0-9]*` eats spaces, so `pct stop 9201 --skiplock 1` and two vmids matched.
|
||||||
|
// RED-PROOF: on the pre-B2 felhom-op.sudoers (`/usr/sbin/pct stop [0-9]*`) the decoys match.
|
||||||
|
func TestFelhomOpSudoersPctIsExact(t *testing.T) {
|
||||||
|
data, err := os.ReadFile("../../configs/felhom-op.sudoers")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
entries := parseSudoersEntries(t, string(data))
|
||||||
|
for _, ok := range []string{"/usr/sbin/pct start 9201", "/usr/sbin/pct stop 9201", "/usr/sbin/pct unlock 9201", "/usr/sbin/pct list"} {
|
||||||
|
if !matchesAny(ok, entries) {
|
||||||
|
t.Errorf("felhom-op lost a repair verb: %s", ok)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for _, bad := range []string{
|
||||||
|
"/usr/sbin/pct stop 9201 --skiplock 1",
|
||||||
|
"/usr/sbin/pct start 9201 9202",
|
||||||
|
"/usr/sbin/pct unlock 9201 --whatever",
|
||||||
|
"/usr/sbin/pct start 92a1",
|
||||||
|
"/usr/sbin/pct stop ",
|
||||||
|
"/usr/sbin/pct destroy 9201",
|
||||||
|
} {
|
||||||
|
if matchesAny(bad, entries) {
|
||||||
|
t.Errorf("felhom-op's sudoers allows %q", bad)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -115,6 +115,7 @@ type Collector struct {
|
|||||||
ctrlSup ControllerSupervisorReporter // R-523: in-guest controller supervisor (nil → stanza omitted)
|
ctrlSup ControllerSupervisorReporter // R-523: in-guest controller supervisor (nil → stanza omitted)
|
||||||
guestNet GuestNetReporter // R-54: per-guest network watchdog (nil → stanza omitted)
|
guestNet GuestNetReporter // R-54: per-guest network watchdog (nil → stanza omitted)
|
||||||
diskTrim GuestDiskTrimReporter // R-444: weekly guest disk trim (nil → stanza omitted)
|
diskTrim GuestDiskTrimReporter // R-444: weekly guest disk trim (nil → stanza omitted)
|
||||||
|
foreignKey ForeignKeyArchiveReporter // R-366 slice 2 (nil → omitted)
|
||||||
selfUpdate SelfUpdateReporter // D1: agent self-update pending status (nil → false)
|
selfUpdate SelfUpdateReporter // D1: agent self-update pending status (nil → false)
|
||||||
mgmtPlane MgmtPlaneReporter // G1: management-plane health (nil → stanza omitted)
|
mgmtPlane MgmtPlaneReporter // G1: management-plane health (nil → stanza omitted)
|
||||||
oob OOBReporter // H1: operator-access health (nil → stanza omitted)
|
oob OOBReporter // H1: operator-access health (nil → stanza omitted)
|
||||||
@@ -228,6 +229,18 @@ func (c *Collector) SetGuestNetReporter(g GuestNetReporter) *Collector {
|
|||||||
return c
|
return c
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ForeignKeyArchiveReporter is the R-366 slice-2 seam: the restore-test's ledger of archives written with another
|
||||||
|
// key. nil = not evaluated yet (the stanza is omitted and the hub keeps its state).
|
||||||
|
type ForeignKeyArchiveReporter interface {
|
||||||
|
ForeignKeyArchives(ctx context.Context) *ForeignKeyArchivesStanza
|
||||||
|
}
|
||||||
|
|
||||||
|
// SetForeignKeyArchiveReporter wires the restore-test's foreign-key ledger (R-366 slice 2; nil-safe → omitted).
|
||||||
|
func (c *Collector) SetForeignKeyArchiveReporter(r ForeignKeyArchiveReporter) *Collector {
|
||||||
|
c.foreignKey = r
|
||||||
|
return c
|
||||||
|
}
|
||||||
|
|
||||||
// SetGuestDiskTrimReporter wires the R-444 weekly trim job as a report source (nil-safe → stanza omitted).
|
// SetGuestDiskTrimReporter wires the R-444 weekly trim job as a report source (nil-safe → stanza omitted).
|
||||||
func (c *Collector) SetGuestDiskTrimReporter(r GuestDiskTrimReporter) *Collector {
|
func (c *Collector) SetGuestDiskTrimReporter(r GuestDiskTrimReporter) *Collector {
|
||||||
c.diskTrim = r
|
c.diskTrim = r
|
||||||
@@ -394,6 +407,10 @@ func (c *Collector) Collect(ctx context.Context) (*HostReport, error) {
|
|||||||
if c.diskTrim != nil {
|
if c.diskTrim != nil {
|
||||||
report.GuestDiskTrim = c.diskTrim.GuestDiskTrimStatus(ctx)
|
report.GuestDiskTrim = c.diskTrim.GuestDiskTrimStatus(ctx)
|
||||||
}
|
}
|
||||||
|
// R-366 slice 2: archives the restore-test skipped as another key's (nil → not evaluated yet → omitted).
|
||||||
|
if c.foreignKey != nil {
|
||||||
|
report.ForeignKeyArchives = c.foreignKey.ForeignKeyArchives(ctx)
|
||||||
|
}
|
||||||
// D1: agent self-update pending status (nil reporter → pending=false, the steady state).
|
// D1: agent self-update pending status (nil reporter → pending=false, the steady state).
|
||||||
if c.selfUpdate != nil {
|
if c.selfUpdate != nil {
|
||||||
report.SelfUpdatePending, report.SelfUpdatePendingVersion = c.selfUpdate.SelfUpdatePending()
|
report.SelfUpdatePending, report.SelfUpdatePendingVersion = c.selfUpdate.SelfUpdatePending()
|
||||||
|
|||||||
@@ -129,6 +129,12 @@ type HostReport struct {
|
|||||||
// wired; an empty `guests` list means the job runs and no guest has been trimmed yet. No secret.
|
// wired; an empty `guests` list means the job runs and no guest has been trimmed yet. No secret.
|
||||||
GuestDiskTrim *GuestDiskTrimStatus `json:"guest_disk_trim,omitempty"`
|
GuestDiskTrim *GuestDiskTrimStatus `json:"guest_disk_trim,omitempty"`
|
||||||
|
|
||||||
|
// ForeignKeyArchives (R-366 slice 2, `09` §3 decision 168): per backup tier, the whole-guest archives the
|
||||||
|
// restore-test SKIPPED because they were written with another key (an earlier install of this box). This box
|
||||||
|
// cannot open them; the hub turns a CHANGE of this list into one operator event. Absent = not evaluated yet since
|
||||||
|
// the agent started (the hub keeps its last state); `tiers: []` = evaluated, none found.
|
||||||
|
ForeignKeyArchives *ForeignKeyArchivesStanza `json:"foreign_key_archives,omitempty"`
|
||||||
|
|
||||||
// LogTail is the agent's on-demand debug-ring tail (v0.83.0 observability) — the agent
|
// LogTail is the agent's on-demand debug-ring tail (v0.83.0 observability) — the agent
|
||||||
// mirror of the controller's report log_tails channel. Present ONLY on the heartbeat
|
// mirror of the controller's report log_tails channel. Present ONLY on the heartbeat
|
||||||
// right after the control envelope requested it (log_tail_requested); consume-once on
|
// right after the control envelope requested it (log_tail_requested); consume-once on
|
||||||
@@ -726,3 +732,18 @@ type WireRestoreDirective struct {
|
|||||||
Archive string `json:"archive,omitempty"` // source archive/snapshot to restore from
|
Archive string `json:"archive,omitempty"` // source archive/snapshot to restore from
|
||||||
VMID int `json:"vmid,omitempty"`
|
VMID int `json:"vmid,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ForeignKeyArchivesStanza wraps the per-tier list so "evaluated, none" (`tiers: []`) differs from "not evaluated"
|
||||||
|
// (the stanza absent) without a null on the wire.
|
||||||
|
type ForeignKeyArchivesStanza struct {
|
||||||
|
Tiers []ForeignKeyArchives `json:"tiers"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// ForeignKeyArchives is one tier's count of archives written with another key (R-366 slice 2): the count and the
|
||||||
|
// newest/oldest archive time (RFC3339, UTC). No key material — the fingerprints stay on the box.
|
||||||
|
type ForeignKeyArchives struct {
|
||||||
|
Target string `json:"target"`
|
||||||
|
Count int `json:"count"`
|
||||||
|
Oldest string `json:"oldest"`
|
||||||
|
Newest string `json:"newest"`
|
||||||
|
}
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"errors"
|
"errors"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
@@ -54,8 +53,8 @@ func (f *supExec) GuestExec(_ context.Context, vmid int, args ...string) (string
|
|||||||
}
|
}
|
||||||
return "", errors.New("supExec: unexpected args")
|
return "", errors.New("supExec: unexpected args")
|
||||||
}
|
}
|
||||||
func (f *supExec) GuestExecStdin(context.Context, int, io.Reader, ...string) (string, error) {
|
func (f *supExec) WriteControllerImage(context.Context, int, string) error {
|
||||||
return "", errors.New("supExec: no stdin exec expected")
|
return errors.New("supExec: no image write expected")
|
||||||
}
|
}
|
||||||
func (f *supExec) count(vmid int) int {
|
func (f *supExec) count(vmid int) int {
|
||||||
f.mu.Lock()
|
f.mu.Lock()
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"os"
|
"os"
|
||||||
@@ -41,9 +40,10 @@ func ValidControllerImage(ref string) bool { return controllerImageRe.MatchStrin
|
|||||||
// faked in tests. The single seam the swap composes over (no hand-rolled pct).
|
// faked in tests. The single seam the swap composes over (no hand-rolled pct).
|
||||||
type GuestExecutor interface {
|
type GuestExecutor interface {
|
||||||
GuestExec(ctx context.Context, vmid int, args ...string) (string, error)
|
GuestExec(ctx context.Context, vmid int, args ...string) (string, error)
|
||||||
// GuestExecStdin is GuestExec with the command's stdin fed from stdin — the swap write pipes the
|
// WriteControllerImage writes the image ref into the guest's /etc/felhom-controller-image through the ROOT
|
||||||
// image ref into an in-guest `tee` (no shell vector).
|
// verb `felhom-priv-apply controller-image <vmid>` (R-861 (a) A1, `09` §3 decision 165), which re-checks the
|
||||||
GuestExecStdin(ctx context.Context, vmid int, stdin io.Reader, args ...string) (string, error)
|
// ref against our registry + repository + x.y.z. The agent no longer holds a `tee` grant into the guest.
|
||||||
|
WriteControllerImage(ctx context.Context, vmid int, image string) error
|
||||||
}
|
}
|
||||||
|
|
||||||
// ControllerSwapState is the durable record of a swap (crash-safety + status). Written before the swap
|
// ControllerSwapState is the durable record of a swap (crash-safety + status). Written before the swap
|
||||||
@@ -141,14 +141,11 @@ func (c *ControllerSwapper) imagePresent(ctx context.Context, vmid int, image st
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (c *ControllerSwapper) writeImage(ctx context.Context, vmid int, image string) error {
|
func (c *ControllerSwapper) writeImage(ctx context.Context, vmid int, image string) error {
|
||||||
// Non-root path: pipe the image ref into an in-guest `tee` over stdin — no shell, no
|
// R-861 (a) A1: the ROOT verb writes the file (it re-checks the ref — a compromised agent cannot hand the guest's
|
||||||
// interpolation, no `bash -c` (the only swap vector that would have needed an arbitrary-exec
|
// bootstrap another image). The bytes are `image\n`, byte-identical to the golden's `printf '%s\n'`; the bootstrap
|
||||||
// grant). The trailing "\n" makes the on-disk bytes byte-identical to the golden's
|
// reads `IMAGE=$(cat …)` so the newline is stripped on read. image is also strict-validated (controllerImageRe)
|
||||||
// `printf '%s\n'`; the bootstrap reads `IMAGE=$(cat …)` so the newline is stripped on read
|
// upstream in Swap.
|
||||||
// (spike SPIKE-controllerswap-narrow-grants-2026-06-29). image is strict-validated
|
return c.exec.WriteControllerImage(ctx, vmid, image)
|
||||||
// (controllerImageRe) upstream in Swap; defence-in-depth, the stdin path can't smuggle anyway.
|
|
||||||
_, err := c.exec.GuestExecStdin(ctx, vmid, strings.NewReader(image+"\n"), "tee", controllerImageFile)
|
|
||||||
return err
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *ControllerSwapper) restartBootstrap(ctx context.Context, vmid int) error {
|
func (c *ControllerSwapper) restartBootstrap(ctx context.Context, vmid int) error {
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ type fakeGuestExec struct {
|
|||||||
present map[string]bool // images pulled into the guest
|
present map[string]bool // images pulled into the guest
|
||||||
good map[string]bool // images that report healthy when running
|
good map[string]bool // images that report healthy when running
|
||||||
containerImg string // image the running container currently has
|
containerImg string // image the running container currently has
|
||||||
teeStdin []string // raw bytes piped into each `tee` write (the swap's write vector)
|
teeStdin []string // image refs handed to WriteControllerImage (the root verb, R-861 (a) A1)
|
||||||
failRestart bool
|
failRestart bool
|
||||||
noHealthBlock bool // if set, .State.Health is absent ("none")
|
noHealthBlock bool // if set, .State.Health is absent ("none")
|
||||||
restartCount int // F1: .RestartCount reported by docker inspect (a crash-looper has >0)
|
restartCount int // F1: .RestartCount reported by docker inspect (a crash-looper has >0)
|
||||||
@@ -75,20 +75,15 @@ func (f *fakeGuestExec) GuestExec(_ context.Context, _ int, args ...string) (str
|
|||||||
return "", fmt.Errorf("fake: unexpected exec %v", args)
|
return "", fmt.Errorf("fake: unexpected exec %v", args)
|
||||||
}
|
}
|
||||||
|
|
||||||
// GuestExecStdin models the swap's write vector: `tee /etc/felhom-controller-image` with the image
|
// WriteControllerImage models the swap's write: the root verb `felhom-priv-apply controller-image <vmid>` (R-861
|
||||||
// piped on stdin. It records the raw stdin bytes and sets the modeled file content (newline-stripped,
|
// (a) A1). It records the ref and sets the modeled file content, as the bootstrap's `IMAGE=$(cat …)` would read it.
|
||||||
// as the bootstrap's `IMAGE=$(cat …)` read would see it).
|
func (f *fakeGuestExec) WriteControllerImage(_ context.Context, _ int, image string) error {
|
||||||
func (f *fakeGuestExec) GuestExecStdin(_ context.Context, _ int, stdin io.Reader, args ...string) (string, error) {
|
|
||||||
f.mu.Lock()
|
f.mu.Lock()
|
||||||
defer f.mu.Unlock()
|
defer f.mu.Unlock()
|
||||||
f.calls = append(f.calls, args)
|
f.calls = append(f.calls, []string{"felhom-priv-apply", "controller-image", image})
|
||||||
b, _ := io.ReadAll(stdin)
|
f.teeStdin = append(f.teeStdin, image+"\n")
|
||||||
if len(args) >= 2 && args[0] == "tee" && args[1] == controllerImageFile {
|
f.imageFile = image
|
||||||
f.teeStdin = append(f.teeStdin, string(b))
|
return nil
|
||||||
f.imageFile = strings.TrimSpace(string(b))
|
|
||||||
return string(b), nil // tee echoes stdin to stdout
|
|
||||||
}
|
|
||||||
return "", fmt.Errorf("fake: unexpected exec-stdin args=%v stdin=%q", args, string(b))
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// wrote reports whether the image was written via the stdin `tee` vector with the exact `image\n`
|
// wrote reports whether the image was written via the stdin `tee` vector with the exact `image\n`
|
||||||
@@ -162,7 +157,7 @@ func TestControllerSwap_Happy(t *testing.T) {
|
|||||||
|
|
||||||
// The write vector must be the stdin `tee` with byte-identical `image\n` and NO shell — the
|
// The write vector must be the stdin `tee` with byte-identical `image\n` and NO shell — the
|
||||||
// controllerswap.go writeImage rewrite. This would FAIL on the pre-change `bash -c "printf … >"` impl.
|
// controllerswap.go writeImage rewrite. This would FAIL on the pre-change `bash -c "printf … >"` impl.
|
||||||
func TestControllerSwap_WriteViaStdinTee_NoShell(t *testing.T) {
|
func TestControllerSwap_WriteViaRootVerb_NoShell(t *testing.T) {
|
||||||
fe := &fakeGuestExec{
|
fe := &fakeGuestExec{
|
||||||
imageFile: prevImg,
|
imageFile: prevImg,
|
||||||
present: map[string]bool{newImg: true},
|
present: map[string]bool{newImg: true},
|
||||||
@@ -173,22 +168,15 @@ func TestControllerSwap_WriteViaStdinTee_NoShell(t *testing.T) {
|
|||||||
t.Fatalf("state = %q, want done", st.State)
|
t.Fatalf("state = %q, want done", st.State)
|
||||||
}
|
}
|
||||||
if !fe.wrote(newImg) {
|
if !fe.wrote(newImg) {
|
||||||
t.Errorf("expected a tee write of %q+\\n; teeStdin=%q", newImg, fe.teeStdin)
|
t.Errorf("expected the root verb to write %q; writes=%q", newImg, fe.teeStdin)
|
||||||
}
|
}
|
||||||
sawTee := false
|
|
||||||
for _, c := range fe.calls {
|
for _, c := range fe.calls {
|
||||||
if len(c) >= 2 && c[0] == "tee" {
|
if len(c) >= 1 && c[0] == "tee" {
|
||||||
sawTee = true
|
t.Errorf("the swap still uses an in-guest tee (R-861 (a) A1 removed that grant): %v", c)
|
||||||
if c[1] != controllerImageFile {
|
|
||||||
t.Errorf("tee target = %q, want fixed %q", c[1], controllerImageFile)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if !sawTee {
|
|
||||||
t.Error("no tee call recorded — writeImage did not use the stdin tee vector")
|
|
||||||
}
|
|
||||||
if fe.usedShell() {
|
if fe.usedShell() {
|
||||||
t.Errorf("swap used a shell vector (bash/-c/printf) — must be stdin tee only; calls=%v", fe.calls)
|
t.Errorf("swap used a shell vector (bash/-c/printf); calls=%v", fe.calls)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -300,9 +288,7 @@ func (s *inspectScript) GuestExec(_ context.Context, _ int, args ...string) (str
|
|||||||
}
|
}
|
||||||
return "", nil
|
return "", nil
|
||||||
}
|
}
|
||||||
func (s *inspectScript) GuestExecStdin(_ context.Context, _ int, _ io.Reader, _ ...string) (string, error) {
|
func (s *inspectScript) WriteControllerImage(context.Context, int, string) error { return nil }
|
||||||
return "", nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func fastSwapper(exec GuestExecutor) *ControllerSwapper {
|
func fastSwapper(exec GuestExecutor) *ControllerSwapper {
|
||||||
s := NewControllerSwapper(exec, "", discardLogger())
|
s := NewControllerSwapper(exec, "", discardLogger())
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ package localapi
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
@@ -126,14 +125,16 @@ func (b *GuestBinder) GuestExec(ctx context.Context, vmid int, args ...string) (
|
|||||||
return string(out), nil
|
return string(out), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// GuestExecStdin is GuestExec with the in-guest command's stdin fed from stdin. The controller-swap
|
// privApplyBin is the root content checker (R-861); its `controller-image` verb writes the guest's image file.
|
||||||
// write uses it to pipe the image ref into an in-guest `tee` (no shell vector, no interpolation),
|
const privApplyBin = "/usr/local/sbin/felhom-priv-apply"
|
||||||
// through the same fenced runner so the `sudo -n` prefix stays in one place.
|
|
||||||
func (b *GuestBinder) GuestExecStdin(ctx context.Context, vmid int, stdin io.Reader, args ...string) (string, error) {
|
// WriteControllerImage pipes `image\n` to `felhom-priv-apply controller-image <vmid>` through the same fenced runner
|
||||||
pctArgs := append([]string{"exec", strconv.Itoa(vmid), "--"}, args...)
|
// (the `sudo -n` prefix stays in one place). The verb checks the ref as root and writes the guest file itself
|
||||||
out, stderr, err := b.runner.RunStdin(ctx, stdin, "pct", pctArgs...)
|
// (R-861 (a) A1, `09` §3 decision 165). Pinned by TestR861_WriteControllerImageUsesTheRootVerb.
|
||||||
|
func (b *GuestBinder) WriteControllerImage(ctx context.Context, vmid int, image string) error {
|
||||||
|
_, stderr, err := b.runner.RunStdin(ctx, strings.NewReader(image+"\n"), privApplyBin, "controller-image", strconv.Itoa(vmid))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return string(out), fmt.Errorf("pct exec %d %v: %w: %s", vmid, args, err, strings.TrimSpace(string(stderr)))
|
return fmt.Errorf("felhom-priv-apply controller-image %d: %w: %s", vmid, err, strings.TrimSpace(string(stderr)))
|
||||||
}
|
}
|
||||||
return string(out), nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,48 @@
|
|||||||
|
package localapi
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"io"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// stdinRecorder is a proxmox.Runner that records each call and the stdin it was handed.
|
||||||
|
type stdinRecorder struct {
|
||||||
|
name string
|
||||||
|
args []string
|
||||||
|
stdin string
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *stdinRecorder) Run(_ context.Context, name string, args ...string) ([]byte, []byte, error) {
|
||||||
|
r.name, r.args = name, args
|
||||||
|
return nil, nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *stdinRecorder) RunStdin(_ context.Context, stdin io.Reader, name string, args ...string) ([]byte, []byte, error) {
|
||||||
|
b, _ := io.ReadAll(stdin)
|
||||||
|
r.name, r.args, r.stdin = name, args, string(b)
|
||||||
|
return nil, nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// R-861 (a) A1 (`09` §3 decision 165): the managed controller update writes the guest's image file through the ROOT
|
||||||
|
// verb, never through an in-guest `tee` the agent could feed any image.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): restore the pre-A1 body (`b.runner.RunStdin(ctx, …, "pct", "exec", vmid, "--",
|
||||||
|
// "tee", controllerImageFile)`) → this fails with "the image write ran pct …, want felhom-priv-apply". Restored.
|
||||||
|
func TestR861_WriteControllerImageUsesTheRootVerb(t *testing.T) {
|
||||||
|
rec := &stdinRecorder{}
|
||||||
|
b := NewGuestBinder(rec, discardLogger())
|
||||||
|
const img = "gitea.dooplex.hu/admin/felhom-controller:0.302.0"
|
||||||
|
if err := b.WriteControllerImage(context.Background(), 9201, img); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if rec.name != privApplyBin {
|
||||||
|
t.Fatalf("the image write ran %s %v, want felhom-priv-apply", rec.name, rec.args)
|
||||||
|
}
|
||||||
|
if len(rec.args) != 2 || rec.args[0] != "controller-image" || rec.args[1] != "9201" {
|
||||||
|
t.Fatalf("argv = %v, want [controller-image 9201] (the sudoers line `^controller-image [0-9]+$`)", rec.args)
|
||||||
|
}
|
||||||
|
if rec.stdin != img+"\n" {
|
||||||
|
t.Fatalf("stdin = %q, want the ref plus one newline", rec.stdin)
|
||||||
|
}
|
||||||
|
}
|
||||||
+131
-6
@@ -20,6 +20,7 @@ import (
|
|||||||
"log/slog"
|
"log/slog"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
|
"regexp"
|
||||||
"sort"
|
"sort"
|
||||||
"strings"
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
@@ -27,6 +28,7 @@ import (
|
|||||||
|
|
||||||
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
||||||
"gitea.dooplex.hu/admin/felhom-agent/internal/proxmox"
|
"gitea.dooplex.hu/admin/felhom-agent/internal/proxmox"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
)
|
)
|
||||||
|
|
||||||
// WrapperPath is the pinned sudoers vector (configs/felhom-agent.sudoers FELHOM_OSAPPLY).
|
// WrapperPath is the pinned sudoers vector (configs/felhom-agent.sudoers FELHOM_OSAPPLY).
|
||||||
@@ -40,8 +42,21 @@ const (
|
|||||||
LayerGuest = "guest"
|
LayerGuest = "guest"
|
||||||
LayerHost = "host"
|
LayerHost = "host"
|
||||||
LayerDocker = "docker" // the guest's Docker engine set — slow lane (`11` §5.8)
|
LayerDocker = "docker" // the guest's Docker engine set — slow lane (`11` §5.8)
|
||||||
|
// LayerPVE is the HOST's Proxmox userspace packages — slow lane (R-812 option A, `09` §3 decision 163, `11` §5.10):
|
||||||
|
// ring 0 in the night leg after a healthy host step, ring 1 only inside a signed os_pve_step. Never a kernel.
|
||||||
|
LayerPVE = "pve"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// PVEOrigin is the origin apt prints for download.proxmox.com (the wrapper's PVE_ORIGIN); InstalledPVEOrigin is how
|
||||||
|
// the wrapper's inventory names the same source.
|
||||||
|
const (
|
||||||
|
PVEOrigin = "Proxmox Debian Repository"
|
||||||
|
InstalledPVEOrigin = "Proxmox"
|
||||||
|
)
|
||||||
|
|
||||||
|
// hostSlowRE mirrors the wrapper's HOST_SLOW_RE: kernel, boot, firmware and microcode names never ride the pve lane.
|
||||||
|
var hostSlowRE = regexp.MustCompile(`^(linux-(image|headers|kbuild|modules|base)|proxmox-kernel|proxmox-default-kernel|pve-kernel|pve-firmware|firmware-|grub|shim|systemd-boot|intel-microcode|amd64-microcode|efibootmgr)`)
|
||||||
|
|
||||||
// DockerNames are the six packages of the Docker engine set (the wrapper's DOCKER_NAMES).
|
// DockerNames are the six packages of the Docker engine set (the wrapper's DOCKER_NAMES).
|
||||||
var DockerNames = map[string]bool{"containerd.io": true, "docker-buildx-plugin": true, "docker-ce": true,
|
var DockerNames = map[string]bool{"containerd.io": true, "docker-buildx-plugin": true, "docker-ce": true,
|
||||||
"docker-ce-cli": true, "docker-ce-rootless-extras": true, "docker-compose-plugin": true}
|
"docker-ce-cli": true, "docker-ce-rootless-extras": true, "docker-compose-plugin": true}
|
||||||
@@ -109,6 +124,8 @@ type WrapperReport struct {
|
|||||||
// OOMCheck (R-528, `09` decision 157): the docker layer's memory-kill check, {result, oom_killed, oom_event,
|
// OOMCheck (R-528, `09` decision 157): the docker layer's memory-kill check, {result, oom_killed, oom_event,
|
||||||
// exit_code, image, detail}. Carried to the hub UNCHANGED; the agent never reads it.
|
// exit_code, image, detail}. Carried to the hub UNCHANGED; the agent never reads it.
|
||||||
OOMCheck json.RawMessage `json:"oom_check"`
|
OOMCheck json.RawMessage `json:"oom_check"`
|
||||||
|
// PVEManager: the pve layer — pveversion's pve-manager version after the step ("unknown" = unreadable).
|
||||||
|
PVEManager string `json:"pve_manager"`
|
||||||
// R-868 (v0.144.0): the agent's ids, echoed from the plan, so a report kept on disk can be sent without the
|
// R-868 (v0.144.0): the agent's ids, echoed from the plan, so a report kept on disk can be sent without the
|
||||||
// agent process that started the pass. ReleaseID / VMID were always in the report.
|
// agent process that started the pass. ReleaseID / VMID were always in the report.
|
||||||
RunID string `json:"run_id"`
|
RunID string `json:"run_id"`
|
||||||
@@ -149,6 +166,8 @@ type Report struct {
|
|||||||
// OOMCheck: docker layer — the wrapper's oom_check object, byte-for-byte (R-528; the hub decides approval on it).
|
// OOMCheck: docker layer — the wrapper's oom_check object, byte-for-byte (R-528; the hub decides approval on it).
|
||||||
// Pinned by TestDocker_OOMCheckReachesTheHubUnchanged and TestR868_KeptCopyCarriesTheOOMCheck.
|
// Pinned by TestDocker_OOMCheckReachesTheHubUnchanged and TestR868_KeptCopyCarriesTheOOMCheck.
|
||||||
OOMCheck json.RawMessage `json:"oom_check,omitempty"`
|
OOMCheck json.RawMessage `json:"oom_check,omitempty"`
|
||||||
|
// PVEManager: pve layer — pve-manager's version after the step (the hub's System page; R-812 option A).
|
||||||
|
PVEManager string `json:"pve_manager,omitempty"`
|
||||||
|
|
||||||
unsent string // R-868: the wrapper's kept copy of this pass's report — deleted once the hub has it
|
unsent string // R-868: the wrapper's kept copy of this pass's report — deleted once the hub has it
|
||||||
}
|
}
|
||||||
@@ -386,6 +405,36 @@ func EngineOf(pkgVersion string) string {
|
|||||||
return v
|
return v
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// PVEHealthVerdict is THE Proxmox-package-step health rule (R-812 option A; pinned by TestPVEHealthVerdict): the host
|
||||||
|
// rule (every host service active, the guest running and healthy, the tunnel running), plus every container running at
|
||||||
|
// the start still runs as the SAME container (a Proxmox step must not restart the household's apps), plus pveversion
|
||||||
|
// now reports the pve-manager the step installed (wantPVE "" = pve-manager was not in the step).
|
||||||
|
func PVEHealthVerdict(before, after *Health, tunnel, wantPVE, gotPVE string) (bool, string) {
|
||||||
|
if ok, why := HostHealthVerdict(before, after, tunnel); !ok {
|
||||||
|
return false, why
|
||||||
|
}
|
||||||
|
if before != nil && before.Guest != nil && after.Guest != nil {
|
||||||
|
names := make([]string, 0, len(before.Guest.Containers))
|
||||||
|
for n := range before.Guest.Containers {
|
||||||
|
names = append(names, n)
|
||||||
|
}
|
||||||
|
sort.Strings(names)
|
||||||
|
for _, n := range names {
|
||||||
|
b := before.Guest.Containers[n]
|
||||||
|
if b.State != "running" || b.ID == "" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if a := after.Guest.Containers[n]; a.ID != b.ID {
|
||||||
|
return false, n + " is a new container (id changed) — the Proxmox step restarted the household's app"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if wantPVE != "" && gotPVE != wantPVE {
|
||||||
|
return false, "pveversion reads pve-manager " + gotPVE + ", not " + wantPVE
|
||||||
|
}
|
||||||
|
return true, ""
|
||||||
|
}
|
||||||
|
|
||||||
// DockerHealthVerdict is THE Docker-step health rule (`11` §5.8; pinned by TestDockerHealthVerdict): the guest rule,
|
// DockerHealthVerdict is THE Docker-step health rule (`11` §5.8; pinned by TestDockerHealthVerdict): the guest rule,
|
||||||
// plus every container running at the start still runs as the SAME container (same id — a changed id means the
|
// plus every container running at the start still runs as the SAME container (same id — a changed id means the
|
||||||
// household's apps restarted, which `live-restore` exists to prevent), plus the engine now reports the version the step
|
// household's apps restarted, which `live-restore` exists to prevent), plus the engine now reports the version the step
|
||||||
@@ -451,7 +500,7 @@ func (l *Leg) call(ctx context.Context, runID string, plan map[string]any) (Wrap
|
|||||||
|
|
||||||
// Pass is one leg's reports; an empty Layer means the step did not run.
|
// Pass is one leg's reports; an empty Layer means the step did not run.
|
||||||
type Pass struct {
|
type Pass struct {
|
||||||
Guest, Host, Docker Report
|
Guest, Host, Docker, PVE Report
|
||||||
}
|
}
|
||||||
|
|
||||||
// Run is one pass: the guest layer, then (on an appliance, after a good guest step) the host layer, then (ring 0
|
// Run is one pass: the guest layer, then (on an appliance, after a good guest step) the host layer, then (ring 0
|
||||||
@@ -479,13 +528,44 @@ func (l *Leg) Run(ctx context.Context, vmid int, trigger string) Pass {
|
|||||||
if err := l.EnsureLiveRestore(ctx, g.RunID, vmid); err != nil {
|
if err := l.EnsureLiveRestore(ctx, g.RunID, vmid); err != nil {
|
||||||
p.Docker = l.finish(ctx, lg, Report{RunID: g.RunID, Layer: LayerDocker, Trigger: trigger, Ring: 0, VMID: vmid,
|
p.Docker = l.finish(ctx, lg, Report{RunID: g.RunID, Layer: LayerDocker, Trigger: trigger, Ring: 0, VMID: vmid,
|
||||||
Mode: "apply", Outcome: "failed", HealthReason: "live-restore could not be turned on: " + err.Error()})
|
Mode: "apply", Outcome: "failed", HealthReason: "live-restore could not be turned on: " + err.Error()})
|
||||||
return p
|
} else {
|
||||||
|
p.Docker = l.runLayer(ctx, g.RunID, LayerDocker, vmid, trigger, blk, dockerOpts{})
|
||||||
}
|
}
|
||||||
p.Docker = l.runLayer(ctx, g.RunID, LayerDocker, vmid, trigger, blk, dockerOpts{})
|
}
|
||||||
|
// R-812 option A: the Proxmox package step — ring 0, an appliance, after a HEALTHY host step (it is a host change).
|
||||||
|
// A Docker step's outcome does not gate it (the Docker set lives in the guest). Pinned by TestPVE_*.
|
||||||
|
switch {
|
||||||
|
case blk.Ring != 0 || !blk.Enabled:
|
||||||
|
lg.Info("osupdate: pve step skipped — ring 1 takes a Proxmox set only inside a signed operator job (`11` §5.10)", "ring", blk.Ring, "enabled", blk.Enabled)
|
||||||
|
case !l.Appliance || h.Layer == "" || !okStep(h):
|
||||||
|
lg.Info("osupdate: pve step skipped — no healthy host step this pass (an appliance only)", "appliance", l.Appliance, "host_outcome", h.Outcome)
|
||||||
|
default:
|
||||||
|
p.PVE = l.runPVE(ctx, g.RunID, vmid, trigger, blk, dockerOpts{})
|
||||||
}
|
}
|
||||||
return p
|
return p
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// pveDrainWait bounds how long a pve step waits for the agent's own /etc/pve writes in flight (pvegate).
|
||||||
|
var pveDrainWait = 2 * time.Minute
|
||||||
|
|
||||||
|
// runPVE runs the pve layer while holding pvegate: the agent's own /etc/pve writes wait until it ends.
|
||||||
|
func (l *Leg) runPVE(ctx context.Context, runID string, vmid int, trigger string, blk hub.WireOSUpdate, do dockerOpts) Report {
|
||||||
|
lg := l.log().With("run", runID, "layer", LayerPVE, "vmid", vmid, "trigger", trigger)
|
||||||
|
dctx, cancel := context.WithTimeout(ctx, pveDrainWait)
|
||||||
|
end, err := pvegate.Step(dctx)
|
||||||
|
cancel()
|
||||||
|
if err != nil {
|
||||||
|
return l.finish(ctx, lg, Report{RunID: runID, Layer: LayerPVE, Trigger: trigger, Ring: blk.Ring, VMID: vmid, Mode: "apply",
|
||||||
|
ReleaseID: do.releaseID, Outcome: "failed", HealthReason: "an agent write to /etc/pve did not finish in time (pvegate): " + err.Error()})
|
||||||
|
}
|
||||||
|
lg.Info("osupdate: pve step holds the /etc/pve write gate — the agent's own writes wait until it ends")
|
||||||
|
defer func() {
|
||||||
|
end()
|
||||||
|
lg.Info("osupdate: pve step released the /etc/pve write gate")
|
||||||
|
}()
|
||||||
|
return l.runLayer(ctx, runID, LayerPVE, vmid, trigger, blk, do)
|
||||||
|
}
|
||||||
|
|
||||||
// dockerOpts is a signed Docker step (DockerStepExecutor); the zero value is ring 0's unsigned "pending-docker".
|
// dockerOpts is a signed Docker step (DockerStepExecutor); the zero value is ring 0's unsigned "pending-docker".
|
||||||
type dockerOpts struct {
|
type dockerOpts struct {
|
||||||
releaseID string
|
releaseID string
|
||||||
@@ -571,7 +651,7 @@ func (l *Leg) runLayer(ctx context.Context, runID, layer string, vmid int, trigg
|
|||||||
wire = blk.HostRelease
|
wire = blk.HostRelease
|
||||||
}
|
}
|
||||||
lane := "fast"
|
lane := "fast"
|
||||||
if layer == LayerDocker {
|
if layer == LayerDocker || layer == LayerPVE {
|
||||||
lane = "slow"
|
lane = "slow"
|
||||||
if do.signed != nil {
|
if do.signed != nil {
|
||||||
rel = hub.WireOSRelease{ID: do.releaseID}
|
rel = hub.WireOSRelease{ID: do.releaseID}
|
||||||
@@ -604,6 +684,13 @@ func (l *Leg) runLayer(ctx context.Context, runID, layer string, vmid int, trigg
|
|||||||
}
|
}
|
||||||
case layer == LayerDocker:
|
case layer == LayerDocker:
|
||||||
plan["select"] = "pending-docker" // ring 0: the wrapper checks the box's ROOT-OWNED ring-0 mark itself
|
plan["select"] = "pending-docker" // ring 0: the wrapper checks the box's ROOT-OWNED ring-0 mark itself
|
||||||
|
case layer == LayerPVE && do.signed != nil:
|
||||||
|
plan["packages"], plan["signed"] = do.packages, do.signed
|
||||||
|
for _, p := range do.packages {
|
||||||
|
planned[p.Name] = true
|
||||||
|
}
|
||||||
|
case layer == LayerPVE:
|
||||||
|
plan["select"] = "pending-pve" // ring 0: the same root-owned mark; the wrapper picks installed Proxmox userspace
|
||||||
case !blk.Enabled:
|
case !blk.Enabled:
|
||||||
plan["mode"] = "inventory"
|
plan["mode"] = "inventory"
|
||||||
lg.Info("osupdate: switched OFF for this box — reporting only")
|
lg.Info("osupdate: switched OFF for this box — reporting only")
|
||||||
@@ -637,6 +724,7 @@ func (l *Leg) runLayer(ctx context.Context, runID, layer string, vmid int, trigg
|
|||||||
rep.Upgraded, rep.PassSeconds = wr.Upgraded, wr.PassSeconds
|
rep.Upgraded, rep.PassSeconds = wr.Upgraded, wr.PassSeconds
|
||||||
rep.DockerEngine, rep.Authority, rep.Undo = wr.DockerEngine, wr.Authority, wr.Undo
|
rep.DockerEngine, rep.Authority, rep.Undo = wr.DockerEngine, wr.Authority, wr.Undo
|
||||||
rep.OOMCheck = rawOrNil(wr.OOMCheck)
|
rep.OOMCheck = rawOrNil(wr.OOMCheck)
|
||||||
|
rep.PVEManager = wr.PVEManager
|
||||||
if rep.Outcome == "" {
|
if rep.Outcome == "" {
|
||||||
switch {
|
switch {
|
||||||
case rep.Mode == "inventory" && !blk.Enabled:
|
case rep.Mode == "inventory" && !blk.Enabled:
|
||||||
@@ -654,21 +742,27 @@ func (l *Leg) runLayer(ctx context.Context, runID, layer string, vmid int, trigg
|
|||||||
}
|
}
|
||||||
// Health: compare with the start of the pass; give restarted services time (only after an install).
|
// Health: compare with the start of the pass; give restarted services time (only after an install).
|
||||||
cur := wr.HealthAfter
|
cur := wr.HealthAfter
|
||||||
wantEngine := ""
|
wantEngine, wantPVE := "", ""
|
||||||
for _, u := range wr.Upgraded {
|
for _, u := range wr.Upgraded {
|
||||||
if u.Name == "docker-ce" {
|
if u.Name == "docker-ce" {
|
||||||
wantEngine = EngineOf(u.Version)
|
wantEngine = EngineOf(u.Version)
|
||||||
}
|
}
|
||||||
|
if u.Name == "pve-manager" {
|
||||||
|
wantPVE = u.Version
|
||||||
|
}
|
||||||
}
|
}
|
||||||
verdict := func(h *Health) (bool, string) {
|
verdict := func(h *Health) (bool, string) {
|
||||||
if layer == LayerDocker {
|
if layer == LayerDocker {
|
||||||
return DockerHealthVerdict(wr.HealthBefore, h, wantEngine, wr.DockerEngine)
|
return DockerHealthVerdict(wr.HealthBefore, h, wantEngine, wr.DockerEngine)
|
||||||
}
|
}
|
||||||
if layer == LayerHost {
|
if layer == LayerHost || layer == LayerPVE {
|
||||||
t := hub.TunnelUnknown
|
t := hub.TunnelUnknown
|
||||||
if l.Tunnel != nil {
|
if l.Tunnel != nil {
|
||||||
t, _ = l.Tunnel.Status(ctx)
|
t, _ = l.Tunnel.Status(ctx)
|
||||||
}
|
}
|
||||||
|
if layer == LayerPVE {
|
||||||
|
return PVEHealthVerdict(wr.HealthBefore, h, t, wantPVE, wr.PVEManager)
|
||||||
|
}
|
||||||
return HostHealthVerdict(wr.HealthBefore, h, t)
|
return HostHealthVerdict(wr.HealthBefore, h, t)
|
||||||
}
|
}
|
||||||
return HealthVerdict(wr.HealthBefore, h)
|
return HealthVerdict(wr.HealthBefore, h)
|
||||||
@@ -708,6 +802,10 @@ func (l *Leg) runLayer(ctx context.Context, runID, layer string, vmid int, trigg
|
|||||||
// the docker report carries the engine set only (the guest report already carries the Debian packages)
|
// the docker report carries the engine set only (the guest report already carries the Debian packages)
|
||||||
rep.Installed, rep.Pending = onlyDocker(wr.Installed), onlyDockerPending(wr.Pending)
|
rep.Installed, rep.Pending = onlyDocker(wr.Installed), onlyDockerPending(wr.Pending)
|
||||||
rep.NotCovered = nil
|
rep.NotCovered = nil
|
||||||
|
} else if layer == LayerPVE {
|
||||||
|
// the pve report carries the Proxmox userspace set only — the hub's candidate is built from it
|
||||||
|
rep.Installed, rep.Pending = onlyPVE(wr.Installed), onlyPVEPending(wr.Pending)
|
||||||
|
rep.NotCovered = nil
|
||||||
} else {
|
} else {
|
||||||
rep.NotCovered = notCovered(wr.Pending, blk.Ring, planned)
|
rep.NotCovered = notCovered(wr.Pending, blk.Ring, planned)
|
||||||
}
|
}
|
||||||
@@ -732,6 +830,33 @@ func onlyDocker(in []Package) []Package {
|
|||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// onlyPVE keeps the installed Proxmox-origin packages the pve lane may touch (never a kernel / boot / firmware name).
|
||||||
|
func onlyPVE(in []Package) []Package {
|
||||||
|
var out []Package
|
||||||
|
for _, p := range in {
|
||||||
|
if (p.Origin == InstalledPVEOrigin || p.Origin == PVEOrigin) && !hostSlowRE.MatchString(p.Name) && !DockerNames[p.Name] {
|
||||||
|
out = append(out, p)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
func onlyPVEPending(in []Pending) []Pending {
|
||||||
|
var out []Pending
|
||||||
|
for _, p := range in {
|
||||||
|
if p.From == "" || hostSlowRE.MatchString(p.Name) || DockerNames[p.Name] {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
for _, o := range p.Origin {
|
||||||
|
if o == PVEOrigin {
|
||||||
|
out = append(out, p)
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
func onlyDockerPending(in []Pending) []Pending {
|
func onlyDockerPending(in []Pending) []Pending {
|
||||||
var out []Pending
|
var out []Pending
|
||||||
for _, p := range in {
|
for _, p := range in {
|
||||||
|
|||||||
@@ -13,16 +13,18 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
)
|
)
|
||||||
|
|
||||||
// fakeWrapper plays /usr/local/sbin/felhom-os-apply: it reads the plan the leg wrote and answers per layer and mode.
|
// fakeWrapper plays /usr/local/sbin/felhom-os-apply: it reads the plan the leg wrote and answers per layer and mode.
|
||||||
type fakeWrapper struct {
|
type fakeWrapper struct {
|
||||||
t *testing.T
|
t *testing.T
|
||||||
pending []Pending
|
pending []Pending
|
||||||
applyRep map[string]WrapperReport // per layer
|
applyRep map[string]WrapperReport // per layer
|
||||||
healthSeq map[string][]*Health // per layer: answers to successive "health" calls
|
healthSeq map[string][]*Health // per layer: answers to successive "health" calls
|
||||||
plans []map[string]any
|
plans []map[string]any
|
||||||
keep bool // R-868: like the real wrapper, keep an apply report beside the plan
|
keep bool // R-868: like the real wrapper, keep an apply report beside the plan
|
||||||
|
pveGateHeld bool
|
||||||
}
|
}
|
||||||
|
|
||||||
func yes() *bool { b := true; return &b }
|
func yes() *bool { b := true; return &b }
|
||||||
@@ -50,9 +52,12 @@ func (f *fakeWrapper) Run(_ context.Context, name string, args ...string) ([]byt
|
|||||||
f.plans = append(f.plans, plan)
|
f.plans = append(f.plans, plan)
|
||||||
layer := plan["layer"].(string)
|
layer := plan["layer"].(string)
|
||||||
ok := guestOK()
|
ok := guestOK()
|
||||||
if layer == LayerHost {
|
if layer == LayerHost || layer == LayerPVE {
|
||||||
ok = hostOK()
|
ok = hostOK()
|
||||||
}
|
}
|
||||||
|
if layer == LayerPVE && plan["mode"] == "apply" {
|
||||||
|
f.pveGateHeld = pvegate.Stepping() // R-812: the /etc/pve write gate must be held while the pve step runs
|
||||||
|
}
|
||||||
var rep WrapperReport
|
var rep WrapperReport
|
||||||
switch plan["mode"] {
|
switch plan["mode"] {
|
||||||
case "inventory":
|
case "inventory":
|
||||||
@@ -160,8 +165,8 @@ func TestRing0_OneCallPerLayer(t *testing.T) {
|
|||||||
if g.Outcome != "applied" || !g.Healthy || ho.Outcome != "applied" || !ho.Healthy {
|
if g.Outcome != "applied" || !g.Healthy || ho.Outcome != "applied" || !ho.Healthy {
|
||||||
t.Fatalf("guest %+v\nhost %+v", g, ho)
|
t.Fatalf("guest %+v\nhost %+v", g, ho)
|
||||||
}
|
}
|
||||||
if calls(w) != "guest:apply,host:apply,guest:live-restore-on,docker:apply" {
|
if calls(w) != "guest:apply,host:apply,guest:live-restore-on,docker:apply,pve:apply" {
|
||||||
t.Fatalf("calls = %s, want one apply per layer, guest first, then live-restore and the ring-0 docker step", calls(w))
|
t.Fatalf("calls = %s, want one apply per layer, guest first, then live-restore, the ring-0 docker step and the pve step", calls(w))
|
||||||
}
|
}
|
||||||
for _, p := range w.plans[:2] {
|
for _, p := range w.plans[:2] {
|
||||||
if p["select"] != "pending-fast" || p["snapshot"] != "" || len(p["packages"].([]any)) != 0 {
|
if p["select"] != "pending-fast" || p["snapshot"] != "" || len(p["packages"].([]any)) != 0 {
|
||||||
@@ -171,7 +176,7 @@ func TestRing0_OneCallPerLayer(t *testing.T) {
|
|||||||
if len(g.NotCovered) != 1 || g.NotCovered[0] != "docker-ce" {
|
if len(g.NotCovered) != 1 || g.NotCovered[0] != "docker-ce" {
|
||||||
t.Fatalf("not covered = %v", g.NotCovered)
|
t.Fatalf("not covered = %v", g.NotCovered)
|
||||||
}
|
}
|
||||||
if len(h.reports) != 3 || h.reports[0].Layer != LayerGuest || h.reports[1].Layer != LayerHost || h.reports[2].Layer != LayerDocker {
|
if len(h.reports) != 4 || h.reports[0].Layer != LayerGuest || h.reports[1].Layer != LayerHost || h.reports[2].Layer != LayerDocker || h.reports[3].Layer != LayerPVE {
|
||||||
t.Fatalf("hub got %+v", h.reports)
|
t.Fatalf("hub got %+v", h.reports)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -389,7 +394,7 @@ func TestHostReport_CarriesRebootScanned(t *testing.T) {
|
|||||||
}}
|
}}
|
||||||
l, h := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
l, h := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
run2(l, "night")
|
run2(l, "night")
|
||||||
if len(h.reports) != 3 || !h.reports[1].RebootScanned || !h.reports[1].RebootNeeded || h.reports[0].RebootScanned {
|
if len(h.reports) != 4 || !h.reports[1].RebootScanned || !h.reports[1].RebootNeeded || h.reports[0].RebootScanned {
|
||||||
t.Fatalf("hub got %+v", h.reports)
|
t.Fatalf("hub got %+v", h.reports)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -436,7 +441,12 @@ func TestDocker_Ring0PlanAndReport(t *testing.T) {
|
|||||||
DockerEngine: "29.8.2", Authority: "ring0"}}}
|
DockerEngine: "29.8.2", Authority: "ring0"}}}
|
||||||
l, _ := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
l, _ := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
p := l.Run(context.Background(), 9201, "night")
|
p := l.Run(context.Background(), 9201, "night")
|
||||||
dp := w.plans[len(w.plans)-1]
|
var dp map[string]any
|
||||||
|
for _, x := range w.plans {
|
||||||
|
if x["layer"] == "docker" {
|
||||||
|
dp = x
|
||||||
|
}
|
||||||
|
}
|
||||||
if dp["layer"] != "docker" || dp["lane"] != "slow" || dp["select"] != "pending-docker" {
|
if dp["layer"] != "docker" || dp["lane"] != "slow" || dp["select"] != "pending-docker" {
|
||||||
t.Fatalf("docker plan = %v", dp)
|
t.Fatalf("docker plan = %v", dp)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,152 @@
|
|||||||
|
package osupdate
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/hub"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/reconcile"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/signedjobs"
|
||||||
|
)
|
||||||
|
|
||||||
|
// ---- the Proxmox package step (R-812 option A, `09` §3 decision 163, `11` §5.10) ----
|
||||||
|
|
||||||
|
// Ring 0: after a healthy host step the leg runs the pve layer — slow lane, select pending-pve — while holding the
|
||||||
|
// /etc/pve write gate; the report carries only Proxmox userspace packages and pve-manager's version.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): call runLayer instead of runPVE in Run → "the /etc/pve write gate was not held".
|
||||||
|
func TestPVE_Ring0PlanGateAndReport(t *testing.T) {
|
||||||
|
w := &fakeWrapper{t: t, applyRep: map[string]WrapperReport{LayerPVE: {
|
||||||
|
Upgraded: []Package{{Name: "pve-manager", Version: "9.2.21"}},
|
||||||
|
Installed: []Package{{Name: "pve-manager", Version: "9.2.21", Origin: "Proxmox"},
|
||||||
|
{Name: "proxmox-kernel-helper", Version: "9.0.4", Origin: "Proxmox"}, {Name: "libc6", Version: "u4", Origin: "Debian"}},
|
||||||
|
Pending: []Pending{{Name: "qemu-server", From: "9.0.1", To: "9.0.9", Origin: []string{PVEOrigin}},
|
||||||
|
{Name: "proxmox-kernel-7.0", From: "7.0.2", To: "7.0.14", Origin: []string{PVEOrigin}},
|
||||||
|
{Name: "libc6", From: "u3", To: "u4", Origin: []string{"Debian"}}},
|
||||||
|
PVEManager: "9.2.21", Authority: "ring0"}}}
|
||||||
|
l, h := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
|
p := l.Run(context.Background(), 9201, "night")
|
||||||
|
var pp map[string]any
|
||||||
|
for _, x := range w.plans {
|
||||||
|
if x["layer"] == LayerPVE {
|
||||||
|
pp = x
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if pp == nil || pp["lane"] != "slow" || pp["select"] != "pending-pve" {
|
||||||
|
t.Fatalf("pve plan = %v (calls %s)", pp, calls(w))
|
||||||
|
}
|
||||||
|
if !w.pveGateHeld {
|
||||||
|
t.Fatal("the /etc/pve write gate was not held while the pve step ran")
|
||||||
|
}
|
||||||
|
if pvegate.Stepping() {
|
||||||
|
t.Fatal("the gate must be released after the step")
|
||||||
|
}
|
||||||
|
r := p.PVE
|
||||||
|
if r.Outcome != "applied" || !r.Healthy || r.PVEManager != "9.2.21" {
|
||||||
|
t.Fatalf("pve report = %+v", r)
|
||||||
|
}
|
||||||
|
if len(r.Installed) != 1 || r.Installed[0].Name != "pve-manager" || len(r.Pending) != 1 || r.Pending[0].Name != "qemu-server" {
|
||||||
|
t.Fatalf("the pve report must carry Proxmox userspace only: installed=%v pending=%v", r.Installed, r.Pending)
|
||||||
|
}
|
||||||
|
if h.reports[len(h.reports)-1].Layer != LayerPVE {
|
||||||
|
t.Fatalf("the hub must get the pve report: %+v", h.reports)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Ring 1 never takes a Proxmox step in the night leg.
|
||||||
|
func TestPVE_Ring1NightLegNeverSteps(t *testing.T) {
|
||||||
|
w := &fakeWrapper{t: t}
|
||||||
|
l, _ := newLeg(t, w, &hub.WireOSUpdate{Ring: 1, Enabled: true})
|
||||||
|
if p := l.Run(context.Background(), 9201, "night"); p.PVE.Layer != "" || strings.Contains(calls(w), "pve") {
|
||||||
|
t.Fatalf("ring 1 took a pve step: %s", calls(w))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// No healthy host step (a BYO box, or an unhealthy host step) → no pve step.
|
||||||
|
func TestPVE_SkippedWithoutAHealthyHostStep(t *testing.T) {
|
||||||
|
w := &fakeWrapper{t: t}
|
||||||
|
l, _ := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
|
l.Appliance = false
|
||||||
|
if p := l.Run(context.Background(), 9201, "night"); p.PVE.Layer != "" || strings.Contains(calls(w), "pve") {
|
||||||
|
t.Fatalf("a BYO box took a pve step: %s", calls(w))
|
||||||
|
}
|
||||||
|
w2 := &fakeWrapper{t: t}
|
||||||
|
l2, _ := newLeg(t, w2, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
|
l2.Tunnel = fakeTunnel{"stopped"} // the host step reads unhealthy
|
||||||
|
w2.applyRep = map[string]WrapperReport{LayerHost: {Upgraded: []Package{{Name: "libc6", Version: "u4"}}}}
|
||||||
|
if p := l2.Run(context.Background(), 9201, "night"); p.PVE.Layer != "" || strings.Contains(calls(w2), "pve") {
|
||||||
|
t.Fatalf("a pve step ran after an unhealthy host step: %s", calls(w2))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A write in flight that never finishes makes the pve step give up (failed), never run without the gate.
|
||||||
|
func TestPVE_GivesUpWhenAWriteDoesNotFinish(t *testing.T) {
|
||||||
|
old := pveDrainWait
|
||||||
|
pveDrainWait = 50_000_000 // 50 ms
|
||||||
|
defer func() { pveDrainWait = old }()
|
||||||
|
rel, _, _ := pvegate.Write(context.Background())
|
||||||
|
defer rel()
|
||||||
|
w := &fakeWrapper{t: t}
|
||||||
|
l, _ := newLeg(t, w, &hub.WireOSUpdate{Ring: 0, Enabled: true})
|
||||||
|
p := l.Run(context.Background(), 9201, "night")
|
||||||
|
if p.PVE.Outcome != "failed" || strings.Contains(calls(w), "pve") {
|
||||||
|
t.Fatalf("the pve step must fail without a wrapper call: %+v calls=%s", p.PVE, calls(w))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// THE pve health rule. COMPANION RED-PROOF (observed): drop the container-id loop or the pve-manager check in
|
||||||
|
// PVEHealthVerdict → the matching case below fails.
|
||||||
|
func TestPVEHealthVerdict(t *testing.T) {
|
||||||
|
before, after := hostOK(), hostOK()
|
||||||
|
before.Guest.Containers["app"] = Container{State: "running", Health: "healthy", ID: "a1"}
|
||||||
|
after.Guest.Containers["app"] = Container{State: "running", Health: "healthy", ID: "a1"}
|
||||||
|
if ok, why := PVEHealthVerdict(before, after, hub.TunnelRunning, "9.2.21", "9.2.21"); !ok {
|
||||||
|
t.Fatalf("healthy step read unhealthy: %s", why)
|
||||||
|
}
|
||||||
|
if ok, _ := PVEHealthVerdict(before, after, hub.TunnelRunning, "9.2.21", "9.2.2"); ok {
|
||||||
|
t.Fatal("pveversion still on the old pve-manager must fail")
|
||||||
|
}
|
||||||
|
after.Guest.Containers["app"] = Container{State: "running", Health: "healthy", ID: "b2"}
|
||||||
|
if ok, why := PVEHealthVerdict(before, after, hub.TunnelRunning, "", "9.2.2"); ok || !strings.Contains(why, "id changed") {
|
||||||
|
t.Fatalf("an app restarted by the Proxmox step must fail, got ok=%v %q", ok, why)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The signed executor hands the RAW envelope and the exact list to the wrapper's pve layer.
|
||||||
|
func TestPVEStepExecutor_PassesTheSignedEnvelope(t *testing.T) {
|
||||||
|
w := &fakeWrapper{t: t, applyRep: map[string]WrapperReport{LayerPVE: {
|
||||||
|
Upgraded: []Package{{Name: "pve-manager", Version: "9.2.21"}}, PVEManager: "9.2.21", Authority: "signed"}}}
|
||||||
|
l, h := newLeg(t, w, &hub.WireOSUpdate{Ring: 1, Enabled: true})
|
||||||
|
e := PVEStepExecutor{Leg: l, Guest: func(context.Context) (int, error) { return 9201, nil }}
|
||||||
|
params, _ := json.Marshal(PVEStepParams{ReleaseID: "os-pve-1", Packages: []Package{{Name: "pve-manager", Version: "9.2.21", Origin: PVEOrigin}}})
|
||||||
|
ctx := signedjobs.WithSignedOp(context.Background(), &reconcile.SignedOp{Blob: []byte(`{"op":"os_pve_step"}`), Sig: []byte("SIG")})
|
||||||
|
if err := e.Execute(ctx, OpPVEStep, params); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
pp := w.plans[len(w.plans)-1]
|
||||||
|
sg, _ := pp["signed"].(map[string]any)
|
||||||
|
if pp["layer"] != LayerPVE || pp["lane"] != "slow" || pp["release_id"] != "os-pve-1" || sg == nil ||
|
||||||
|
sg["blob_b64"] != base64.StdEncoding.EncodeToString([]byte(`{"op":"os_pve_step"}`)) || sg["sig"] != "SIG" {
|
||||||
|
t.Fatalf("pve plan = %v", pp)
|
||||||
|
}
|
||||||
|
if !w.pveGateHeld || calls(w) != "pve:apply" || len(h.reports) != 1 || h.reports[0].Trigger != "signed" {
|
||||||
|
t.Fatalf("gate=%v calls=%s reports=%+v", w.pveGateHeld, calls(w), h.reports)
|
||||||
|
}
|
||||||
|
if err := e.Execute(context.Background(), OpPVEStep, params); err == nil {
|
||||||
|
t.Fatal("no envelope must refuse")
|
||||||
|
}
|
||||||
|
if err := e.Execute(context.Background(), OpDockerStep, params); err != signedjobs.ErrNoExecutor {
|
||||||
|
t.Fatalf("another op must pass through the chain: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// os_pve_step is never benign.
|
||||||
|
func TestPVEStep_IsDestructiveClass(t *testing.T) {
|
||||||
|
if reconcile.Classify(reconcile.ClassOSPVEStep, reconcile.Provenance{}) != reconcile.Destructive {
|
||||||
|
t.Fatal("os_pve_step must be destructive-class (signed, operational key)")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,85 @@
|
|||||||
|
package osupdate
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/json"
|
||||||
|
"fmt"
|
||||||
|
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/signedjobs"
|
||||||
|
)
|
||||||
|
|
||||||
|
// OpPVEStep is the signed op class of a Proxmox package step (R-812 option A, `11` §5.10): a ring-1 box takes an
|
||||||
|
// approved Proxmox set only through it. No undo in this release. CC may sign it until the first paying customer.
|
||||||
|
const OpPVEStep = "os_pve_step"
|
||||||
|
|
||||||
|
// PVEStepParams are the signed params. The wrapper compares Packages with the plan byte-for-byte.
|
||||||
|
type PVEStepParams struct {
|
||||||
|
ReleaseID string `json:"release_id"`
|
||||||
|
Packages []Package `json:"packages"`
|
||||||
|
VMID int `json:"vmid,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// PVEStepExecutor runs a verified os_pve_step (signedjobs.Executor) under the host-wide heavy-op gate (Gate) and the
|
||||||
|
// /etc/pve write gate (inside runPVE).
|
||||||
|
type PVEStepExecutor struct {
|
||||||
|
Leg *Leg
|
||||||
|
Guest func(ctx context.Context) (int, error)
|
||||||
|
Gate func(ctx context.Context) (release func(), err error)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Execute implements signedjobs.Executor.
|
||||||
|
func (e PVEStepExecutor) Execute(ctx context.Context, op string, params json.RawMessage) error {
|
||||||
|
if op != OpPVEStep {
|
||||||
|
return signedjobs.ErrNoExecutor
|
||||||
|
}
|
||||||
|
so, ok := signedjobs.SignedOpFrom(ctx)
|
||||||
|
if !ok {
|
||||||
|
return fmt.Errorf("os_pve_step: no signed envelope in the context — the wrapper could not verify it")
|
||||||
|
}
|
||||||
|
var p PVEStepParams
|
||||||
|
if err := json.Unmarshal(params, &p); err != nil || len(p.Packages) == 0 {
|
||||||
|
return fmt.Errorf("os_pve_step: params must name the Proxmox set: %v", err)
|
||||||
|
}
|
||||||
|
vmid := p.VMID
|
||||||
|
if vmid == 0 {
|
||||||
|
if e.Guest == nil {
|
||||||
|
return fmt.Errorf("os_pve_step: no vmid and no guest finder")
|
||||||
|
}
|
||||||
|
v, err := e.Guest(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("os_pve_step: find the customer guest: %w", err)
|
||||||
|
}
|
||||||
|
vmid = v
|
||||||
|
}
|
||||||
|
if e.Gate != nil {
|
||||||
|
release, err := e.Gate(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("os_pve_step: heavy-op gate busy (a backup or restore-test runs): %w", err)
|
||||||
|
}
|
||||||
|
defer release()
|
||||||
|
}
|
||||||
|
rep := e.Leg.RunPVESigned(ctx, vmid, p, so.Blob, string(so.Sig))
|
||||||
|
switch rep.Outcome {
|
||||||
|
case "applied", "nothing":
|
||||||
|
if rep.Healthy {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return fmt.Errorf("os_pve_step: %s (%s) %s", rep.Outcome, rep.HealthReason, string(rep.Refused))
|
||||||
|
}
|
||||||
|
|
||||||
|
// RunPVESigned is one signed Proxmox step (ring 1): the pve layer with the signed envelope, which the wrapper verifies
|
||||||
|
// itself, holding the /etc/pve write gate.
|
||||||
|
func (l *Leg) RunPVESigned(ctx context.Context, vmid int, p PVEStepParams, blob []byte, sig string) Report {
|
||||||
|
unlock := l.lockPass(true)
|
||||||
|
defer unlock()
|
||||||
|
l.sendUnsentLocked(ctx) // R-868
|
||||||
|
runID := l.now().UTC().Format("20060102T150405Z")
|
||||||
|
rid := p.ReleaseID
|
||||||
|
if rid == "" {
|
||||||
|
rid = "signed-" + runID
|
||||||
|
}
|
||||||
|
return l.runPVE(ctx, runID, vmid, "signed", l.Block(), dockerOpts{releaseID: rid, packages: p.Packages,
|
||||||
|
signed: map[string]string{"blob_b64": base64.StdEncoding.EncodeToString(blob), "sig": sig}})
|
||||||
|
}
|
||||||
@@ -145,21 +145,28 @@ func (l *Leg) reportFromKept(ctx context.Context, wr WrapperReport, path string)
|
|||||||
rep.Upgraded, rep.PassSeconds = wr.Upgraded, wr.PassSeconds
|
rep.Upgraded, rep.PassSeconds = wr.Upgraded, wr.PassSeconds
|
||||||
rep.DockerEngine, rep.Authority, rep.Undo = wr.DockerEngine, wr.Authority, wr.Undo
|
rep.DockerEngine, rep.Authority, rep.Undo = wr.DockerEngine, wr.Authority, wr.Undo
|
||||||
rep.OOMCheck = rawOrNil(wr.OOMCheck)
|
rep.OOMCheck = rawOrNil(wr.OOMCheck)
|
||||||
wantEngine := ""
|
rep.PVEManager = wr.PVEManager
|
||||||
|
wantEngine, wantPVE := "", ""
|
||||||
for _, u := range wr.Upgraded {
|
for _, u := range wr.Upgraded {
|
||||||
if u.Name == "docker-ce" {
|
if u.Name == "docker-ce" {
|
||||||
wantEngine = EngineOf(u.Version)
|
wantEngine = EngineOf(u.Version)
|
||||||
}
|
}
|
||||||
|
if u.Name == "pve-manager" {
|
||||||
|
wantPVE = u.Version
|
||||||
|
}
|
||||||
}
|
}
|
||||||
verdict := func(h *Health) (bool, string) {
|
verdict := func(h *Health) (bool, string) {
|
||||||
switch wr.Layer {
|
switch wr.Layer {
|
||||||
case LayerDocker:
|
case LayerDocker:
|
||||||
return DockerHealthVerdict(wr.HealthBefore, h, wantEngine, wr.DockerEngine)
|
return DockerHealthVerdict(wr.HealthBefore, h, wantEngine, wr.DockerEngine)
|
||||||
case LayerHost:
|
case LayerHost, LayerPVE:
|
||||||
t := hub.TunnelUnknown
|
t := hub.TunnelUnknown
|
||||||
if l.Tunnel != nil {
|
if l.Tunnel != nil {
|
||||||
t, _ = l.Tunnel.Status(ctx)
|
t, _ = l.Tunnel.Status(ctx)
|
||||||
}
|
}
|
||||||
|
if wr.Layer == LayerPVE {
|
||||||
|
return PVEHealthVerdict(wr.HealthBefore, h, t, wantPVE, wr.PVEManager)
|
||||||
|
}
|
||||||
return HostHealthVerdict(wr.HealthBefore, h, t)
|
return HostHealthVerdict(wr.HealthBefore, h, t)
|
||||||
}
|
}
|
||||||
return HealthVerdict(wr.HealthBefore, h)
|
return HealthVerdict(wr.HealthBefore, h)
|
||||||
@@ -167,7 +174,7 @@ func (l *Leg) reportFromKept(ctx context.Context, wr WrapperReport, path string)
|
|||||||
ok, why := verdict(wr.HealthAfter)
|
ok, why := verdict(wr.HealthAfter)
|
||||||
if !ok && len(wr.Upgraded) > 0 && wr.VMID > 0 {
|
if !ok && len(wr.Upgraded) > 0 && wr.VMID > 0 {
|
||||||
lane := "fast"
|
lane := "fast"
|
||||||
if wr.Layer == LayerDocker {
|
if wr.Layer == LayerDocker || wr.Layer == LayerPVE {
|
||||||
lane = "slow"
|
lane = "slow"
|
||||||
}
|
}
|
||||||
if hr, err := l.call(ctx, "kept-"+runID, map[string]any{"release_id": "kept", "layer": wr.Layer, "lane": lane,
|
if hr, err := l.call(ctx, "kept-"+runID, map[string]any{"release_id": "kept", "layer": wr.Layer, "lane": lane,
|
||||||
@@ -187,6 +194,8 @@ func (l *Leg) reportFromKept(ctx context.Context, wr WrapperReport, path string)
|
|||||||
rep.RebootScanned = wr.RebootScanned
|
rep.RebootScanned = wr.RebootScanned
|
||||||
if wr.Layer == LayerDocker {
|
if wr.Layer == LayerDocker {
|
||||||
rep.Installed, rep.Pending = onlyDocker(wr.Installed), onlyDockerPending(wr.Pending)
|
rep.Installed, rep.Pending = onlyDocker(wr.Installed), onlyDockerPending(wr.Pending)
|
||||||
|
} else if wr.Layer == LayerPVE {
|
||||||
|
rep.Installed, rep.Pending = onlyPVE(wr.Installed), onlyPVEPending(wr.Pending)
|
||||||
} else {
|
} else {
|
||||||
planned := map[string]bool{}
|
planned := map[string]bool{}
|
||||||
for _, u := range wr.Upgraded {
|
for _, u := range wr.Upgraded {
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/url"
|
"net/url"
|
||||||
@@ -105,6 +106,15 @@ func (c *Client) do(ctx context.Context, method, path string, body io.Reader, ou
|
|||||||
// doBody is the single HTTP chokepoint: builds the request, sets auth, executes,
|
// doBody is the single HTTP chokepoint: builds the request, sets auth, executes,
|
||||||
// maps non-2xx to APIError, and decodes the data envelope.
|
// maps non-2xx to APIError, and decodes the data envelope.
|
||||||
func (c *Client) doBody(ctx context.Context, method, path string, body io.Reader, contentType string, out any) error {
|
func (c *Client) doBody(ctx context.Context, method, path string, body io.Reader, contentType string, out any) error {
|
||||||
|
// R-812 option A: every non-GET call may write /etc/pve — it waits while a Proxmox package step restarts pmxcfs
|
||||||
|
// (pvegate). Pinned by TestPVEGate_ClientWriteWaitsGetDoesNot.
|
||||||
|
if method != http.MethodGet {
|
||||||
|
release, _, gerr := pvegate.Write(ctx)
|
||||||
|
if gerr != nil {
|
||||||
|
return fmt.Errorf("proxmox: %s %s held back by a Proxmox package step: %w", method, path, gerr)
|
||||||
|
}
|
||||||
|
defer release()
|
||||||
|
}
|
||||||
req, err := http.NewRequestWithContext(ctx, method, c.base+path, body)
|
req, err := http.NewRequestWithContext(ctx, method, c.base+path, body)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("proxmox: building request: %w", err)
|
return fmt.Errorf("proxmox: building request: %w", err)
|
||||||
|
|||||||
@@ -4,8 +4,10 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
"io"
|
"io"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
"strconv"
|
"strconv"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -59,6 +61,15 @@ func (r *ExecRunner) Run(ctx context.Context, name string, args ...string) ([]by
|
|||||||
// RunStdin is Run with the process stdin fed from stdin (nil = no stdin). The sudo-prefix/mode
|
// RunStdin is Run with the process stdin fed from stdin (nil = no stdin). The sudo-prefix/mode
|
||||||
// handling is identical to Run — kept here so both paths share one place.
|
// handling is identical to Run — kept here so both paths share one place.
|
||||||
func (r *ExecRunner) RunStdin(ctx context.Context, stdin io.Reader, name string, args ...string) ([]byte, []byte, error) {
|
func (r *ExecRunner) RunStdin(ctx context.Context, stdin io.Reader, name string, args ...string) ([]byte, []byte, error) {
|
||||||
|
// R-812 option A: a root CLI that writes /etc/pve waits while a Proxmox package step runs (pvegate).
|
||||||
|
// Pinned by TestPVEGate_ExecRunnerPctSetWaits / TestWritesEtcPVE.
|
||||||
|
if WritesEtcPVE(name, args) {
|
||||||
|
release, _, gerr := pvegate.Write(ctx)
|
||||||
|
if gerr != nil {
|
||||||
|
return nil, nil, fmt.Errorf("proxmox: %s held back by a Proxmox package step: %w", name, gerr)
|
||||||
|
}
|
||||||
|
defer release()
|
||||||
|
}
|
||||||
var cmd *exec.Cmd
|
var cmd *exec.Cmd
|
||||||
if r.Mode == RunnerSudo {
|
if r.Mode == RunnerSudo {
|
||||||
sudo := r.SudoPath
|
sudo := r.SudoPath
|
||||||
@@ -77,6 +88,28 @@ func (r *ExecRunner) RunStdin(ctx context.Context, stdin io.Reader, name string,
|
|||||||
return stdout.b, stderr.b, err
|
return stdout.b, stderr.b, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// WritesEtcPVE reports whether a root command writes /etc/pve: `pct` with a config-changing verb, `pvesm`, `pveum`,
|
||||||
|
// and the PBS storage wrapper's create / reconcile verbs. `pct exec|status|list|config` and every other command do not
|
||||||
|
// (the os-update wrapper itself must never wait on the gate its own step holds). Pinned by TestWritesEtcPVE.
|
||||||
|
func WritesEtcPVE(name string, args []string) bool {
|
||||||
|
base := filepath.Base(name)
|
||||||
|
switch base {
|
||||||
|
case "pvesm", "pveum":
|
||||||
|
return true
|
||||||
|
case "pct":
|
||||||
|
if len(args) == 0 {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
switch args[0] {
|
||||||
|
case "set", "create", "destroy", "restore", "unlock", "resize", "snapshot", "delsnapshot", "rollback", "move-volume", "start", "stop", "reboot", "shutdown":
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
case "felhom-pbs-apply":
|
||||||
|
return len(args) > 0 && (args[0] == "create" || args[0] == "reconcile")
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
// Privileged is the root-CLI backend.
|
// Privileged is the root-CLI backend.
|
||||||
type Privileged struct {
|
type Privileged struct {
|
||||||
runner Runner
|
runner Runner
|
||||||
|
|||||||
@@ -0,0 +1,92 @@
|
|||||||
|
package proxmox
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"net/http"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
||||||
|
)
|
||||||
|
|
||||||
|
// R-812 option A: while a Proxmox package step holds the gate, a non-GET API call waits and a GET does not.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): delete the pvegate.Write block in doBody → this fails with "a PUT reached the API
|
||||||
|
// while the Proxmox step held the gate". Restored. (audits/day-2026-10-07/B/red-pvegate-chokepoints.txt)
|
||||||
|
func TestPVEGate_ClientWriteWaitsGetDoesNot(t *testing.T) {
|
||||||
|
d := &mockDoer{fn: func(*http.Request) (*http.Response, error) { return jsonResp(200, `{"data":null}`), nil }}
|
||||||
|
c := newTestClient(d)
|
||||||
|
end, err := pvegate.Step(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if err := c.get(context.Background(), "/nodes", nil); err != nil {
|
||||||
|
t.Fatalf("a GET must not wait on the gate: %v", err)
|
||||||
|
}
|
||||||
|
if d.calls != 1 {
|
||||||
|
t.Fatalf("the GET must reach the API, calls=%d", d.calls)
|
||||||
|
}
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
||||||
|
defer cancel()
|
||||||
|
err = c.postForm(ctx, http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil)
|
||||||
|
if d.calls != 1 {
|
||||||
|
end()
|
||||||
|
t.Fatal("a PUT reached the API while the Proxmox step held the gate")
|
||||||
|
}
|
||||||
|
if err == nil {
|
||||||
|
end()
|
||||||
|
t.Fatal("a PUT held back past its deadline must fail")
|
||||||
|
}
|
||||||
|
end()
|
||||||
|
if err := c.postForm(context.Background(), http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil); err != nil || d.calls != 2 {
|
||||||
|
t.Fatalf("after the step the PUT must go through (err=%v calls=%d)", err, d.calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A root `pct set` waits on the gate; `pct exec` does not.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): delete the WritesEtcPVE block in RunStdin → this fails with "pct set ran while the
|
||||||
|
// Proxmox step held the gate". Restored.
|
||||||
|
func TestPVEGate_ExecRunnerPctSetWaits(t *testing.T) {
|
||||||
|
r := &ExecRunner{Mode: RunnerDirect}
|
||||||
|
end, err := pvegate.Step(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
defer end()
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
||||||
|
defer cancel()
|
||||||
|
start := time.Now()
|
||||||
|
_, _, err = r.Run(ctx, "/nonexistent/pct", "set", "9201", "-mp8", "/x")
|
||||||
|
if err == nil || time.Since(start) < 90*time.Millisecond {
|
||||||
|
t.Fatalf("pct set ran while the Proxmox step held the gate (err=%v after %s)", err, time.Since(start))
|
||||||
|
}
|
||||||
|
start = time.Now()
|
||||||
|
_, _, _ = r.Run(context.Background(), "/nonexistent/pct", "exec", "9201", "--", "true")
|
||||||
|
if time.Since(start) > 80*time.Millisecond {
|
||||||
|
t.Fatal("pct exec must not wait on the gate")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestWritesEtcPVE(t *testing.T) {
|
||||||
|
for _, c := range []struct {
|
||||||
|
name string
|
||||||
|
args []string
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
{"pct", []string{"set", "9201", "-mp8", "x"}, true},
|
||||||
|
{"/usr/sbin/pct", []string{"create", "9201"}, true},
|
||||||
|
{"pct", []string{"exec", "9201", "--", "true"}, false},
|
||||||
|
{"pct", []string{"status", "9201"}, false},
|
||||||
|
{"pvesm", []string{"add", "dir", "x"}, true},
|
||||||
|
{"pveum", []string{"acl", "modify"}, true},
|
||||||
|
{"/usr/local/sbin/felhom-pbs-apply", []string{"reconcile"}, true},
|
||||||
|
{"/usr/local/sbin/felhom-pbs-apply", []string{"read"}, false},
|
||||||
|
{"/usr/local/sbin/felhom-os-apply", []string{"--plan", "x"}, false},
|
||||||
|
{"pct", nil, false},
|
||||||
|
} {
|
||||||
|
if got := WritesEtcPVE(c.name, c.args); got != c.want {
|
||||||
|
t.Errorf("WritesEtcPVE(%s %v) = %v, want %v", c.name, c.args, got, c.want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,104 @@
|
|||||||
|
// Package pvegate keeps the agent's own writes to /etc/pve out of the way of a Proxmox package step (R-812 option A,
|
||||||
|
// `09` §3 decision 163, `11` §5.10).
|
||||||
|
//
|
||||||
|
// WHY. A `pve` step upgrades pve-cluster / pve-manager / qemu-server / pve-container; their postinst scripts restart
|
||||||
|
// pmxcfs (the FUSE filesystem behind /etc/pve) and the API daemons. A write that lands while pmxcfs restarts fails or,
|
||||||
|
// worse, half-lands (design-R-812 §3 A, "can go wrong"). Backups and restore-tests are already kept out by the
|
||||||
|
// host-wide heavy-op gate; this gate covers everything else the agent writes: every non-GET Proxmox API call
|
||||||
|
// (proxmox.Client.doBody) and every root CLI that writes /etc/pve (proxmox.ExecRunner — `pct set|create|…`, `pvesm`,
|
||||||
|
// `pveum`, `felhom-pbs-apply create|reconcile`).
|
||||||
|
//
|
||||||
|
// THE RULE. Write waits while a step runs (bounded by its own context). Step marks the step and then waits until every
|
||||||
|
// write already in flight has finished; it never waits forever (its context bounds it, and the caller gives up and
|
||||||
|
// does not run the step). One step at a time. Pinned by pvegate_test.go and, at the two chokepoints, by
|
||||||
|
// proxmox TestPVEGate_*.
|
||||||
|
package pvegate
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
var (
|
||||||
|
mu sync.Mutex
|
||||||
|
inFlight int
|
||||||
|
stepping bool
|
||||||
|
stepDone chan struct{}
|
||||||
|
)
|
||||||
|
|
||||||
|
// ErrStepRunning is returned by Step when another step already holds the gate.
|
||||||
|
var ErrStepRunning = errors.New("pvegate: a Proxmox package step is already running")
|
||||||
|
|
||||||
|
// Write marks one /etc/pve write in flight, first waiting while a Proxmox package step runs. The returned release must
|
||||||
|
// be called when the write has finished. waited reports how long the write was held back.
|
||||||
|
func Write(ctx context.Context) (release func(), waited time.Duration, err error) {
|
||||||
|
start := time.Now()
|
||||||
|
for {
|
||||||
|
mu.Lock()
|
||||||
|
if !stepping {
|
||||||
|
inFlight++
|
||||||
|
mu.Unlock()
|
||||||
|
var once sync.Once
|
||||||
|
return func() {
|
||||||
|
once.Do(func() {
|
||||||
|
mu.Lock()
|
||||||
|
inFlight--
|
||||||
|
mu.Unlock()
|
||||||
|
})
|
||||||
|
}, time.Since(start), nil
|
||||||
|
}
|
||||||
|
ch := stepDone
|
||||||
|
mu.Unlock()
|
||||||
|
select {
|
||||||
|
case <-ch:
|
||||||
|
case <-ctx.Done():
|
||||||
|
return nil, time.Since(start), ctx.Err()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Step marks a Proxmox package step and waits until every /etc/pve write already in flight has finished. On error the
|
||||||
|
// gate is released again and the step must not run. end releases the gate and lets the held-back writes go.
|
||||||
|
func Step(ctx context.Context) (end func(), err error) {
|
||||||
|
mu.Lock()
|
||||||
|
if stepping {
|
||||||
|
mu.Unlock()
|
||||||
|
return nil, ErrStepRunning
|
||||||
|
}
|
||||||
|
stepping = true
|
||||||
|
done := make(chan struct{})
|
||||||
|
stepDone = done
|
||||||
|
mu.Unlock()
|
||||||
|
var once sync.Once
|
||||||
|
end = func() {
|
||||||
|
once.Do(func() {
|
||||||
|
mu.Lock()
|
||||||
|
stepping = false
|
||||||
|
close(done)
|
||||||
|
mu.Unlock()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
for {
|
||||||
|
mu.Lock()
|
||||||
|
n := inFlight
|
||||||
|
mu.Unlock()
|
||||||
|
if n == 0 {
|
||||||
|
return end, nil
|
||||||
|
}
|
||||||
|
select {
|
||||||
|
case <-ctx.Done():
|
||||||
|
end()
|
||||||
|
return nil, ctx.Err()
|
||||||
|
case <-time.After(50 * time.Millisecond):
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Stepping reports whether a Proxmox package step holds the gate (for logs).
|
||||||
|
func Stepping() bool {
|
||||||
|
mu.Lock()
|
||||||
|
defer mu.Unlock()
|
||||||
|
return stepping
|
||||||
|
}
|
||||||
@@ -0,0 +1,104 @@
|
|||||||
|
package pvegate
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// A write that starts while a step runs waits until the step ends.
|
||||||
|
//
|
||||||
|
// COMPANION RED-PROOF (observed): make Write ignore `stepping` → this fails with "the write went through while the
|
||||||
|
// Proxmox step held the gate". Restored. (audits/day-2026-10-07/B/red-pvegate.txt)
|
||||||
|
func TestWrite_WaitsWhileAStepRuns(t *testing.T) {
|
||||||
|
end, err := Step(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
got := make(chan time.Time, 1)
|
||||||
|
go func() {
|
||||||
|
rel, _, err := Write(context.Background())
|
||||||
|
if err == nil {
|
||||||
|
rel()
|
||||||
|
}
|
||||||
|
got <- time.Now()
|
||||||
|
}()
|
||||||
|
select {
|
||||||
|
case <-got:
|
||||||
|
end()
|
||||||
|
t.Fatal("the write went through while the Proxmox step held the gate")
|
||||||
|
case <-time.After(150 * time.Millisecond):
|
||||||
|
}
|
||||||
|
ended := time.Now()
|
||||||
|
end()
|
||||||
|
select {
|
||||||
|
case at := <-got:
|
||||||
|
if at.Before(ended) {
|
||||||
|
t.Fatal("the write finished before the step ended")
|
||||||
|
}
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
t.Fatal("the write never went through after the step ended")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A step waits for a write already in flight before it starts.
|
||||||
|
func TestStep_WaitsForAWriteInFlight(t *testing.T) {
|
||||||
|
rel, _, err := Write(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
started := make(chan struct{})
|
||||||
|
go func() {
|
||||||
|
end, err := Step(context.Background())
|
||||||
|
if err == nil {
|
||||||
|
close(started)
|
||||||
|
end()
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
select {
|
||||||
|
case <-started:
|
||||||
|
rel()
|
||||||
|
t.Fatal("the step started while a write was in flight")
|
||||||
|
case <-time.After(150 * time.Millisecond):
|
||||||
|
}
|
||||||
|
rel()
|
||||||
|
select {
|
||||||
|
case <-started:
|
||||||
|
case <-time.After(2 * time.Second):
|
||||||
|
t.Fatal("the step never started after the write finished")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A step that cannot drain the writes in time gives up and releases the gate (it never waits forever).
|
||||||
|
func TestStep_GivesUpAndReleases(t *testing.T) {
|
||||||
|
rel, _, _ := Write(context.Background())
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
||||||
|
defer cancel()
|
||||||
|
if _, err := Step(ctx); err == nil {
|
||||||
|
t.Fatal("the step must give up while a write is in flight past its deadline")
|
||||||
|
}
|
||||||
|
if Stepping() {
|
||||||
|
t.Fatal("a step that gave up must release the gate")
|
||||||
|
}
|
||||||
|
rel()
|
||||||
|
}
|
||||||
|
|
||||||
|
// A write held back past its own deadline returns the context's error.
|
||||||
|
func TestWrite_HonoursItsContext(t *testing.T) {
|
||||||
|
end, _ := Step(context.Background())
|
||||||
|
defer end()
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
|
||||||
|
defer cancel()
|
||||||
|
if _, _, err := Write(ctx); err == nil {
|
||||||
|
t.Fatal("a write held back past its deadline must fail")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// One step at a time.
|
||||||
|
func TestStep_OneAtATime(t *testing.T) {
|
||||||
|
end, _ := Step(context.Background())
|
||||||
|
defer end()
|
||||||
|
if _, err := Step(context.Background()); err != ErrStepRunning {
|
||||||
|
t.Fatalf("a second step must be refused, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -52,6 +52,10 @@ const (
|
|||||||
// (signed, operational key) like agent_update; the root wrapper re-verifies the same signature itself.
|
// (signed, operational key) like agent_update; the root wrapper re-verifies the same signature itself.
|
||||||
ClassOSDockerStep OpClass = "os_docker_step"
|
ClassOSDockerStep OpClass = "os_docker_step"
|
||||||
|
|
||||||
|
// A Proxmox package step on the host (R-812 option A, `11` §5.10) — ring 1. Destructive-class (signed, operational
|
||||||
|
// key) like os_docker_step; the root wrapper re-verifies the same signature itself.
|
||||||
|
ClassOSPVEStep OpClass = "os_pve_step"
|
||||||
|
|
||||||
// The config bundle (agent v0.143.0, R-840, `11` §5.4.2): the box's ROOT-OWNED files (sudoers, wrappers, units).
|
// The config bundle (agent v0.143.0, R-840, `11` §5.4.2): the box's ROOT-OWNED files (sudoers, wrappers, units).
|
||||||
// Destructive-class (signed, operational key) like agent_update; the root wrapper re-verifies the signature itself.
|
// Destructive-class (signed, operational key) like agent_update; the root wrapper re-verifies the signature itself.
|
||||||
ClassAgentConfigUpdate OpClass = "agent_config_update"
|
ClassAgentConfigUpdate OpClass = "agent_config_update"
|
||||||
@@ -123,7 +127,7 @@ func Classify(class OpClass, prov Provenance) Disposition {
|
|||||||
return Destructive
|
return Destructive
|
||||||
case ClassKeyRotation:
|
case ClassKeyRotation:
|
||||||
return Destructive
|
return Destructive
|
||||||
case ClassAgentUpdate, ClassOSDockerStep, ClassAgentConfigUpdate:
|
case ClassAgentUpdate, ClassOSDockerStep, ClassOSPVEStep, ClassAgentConfigUpdate:
|
||||||
// Never benign — no agent-internal provenance can make replacing the agent binary
|
// Never benign — no agent-internal provenance can make replacing the agent binary
|
||||||
// unsigned-safe (a compromised process must not be able to self-bless an update).
|
// unsigned-safe (a compromised process must not be able to self-bless an update).
|
||||||
return Destructive
|
return Destructive
|
||||||
|
|||||||
Reference in New Issue
Block a user