evidence: R-502 first full run (73 checks, decoy convicted), R-624 bench (vaultwarden admin seed + guard)
gates / gates (push) Successful in 2m35s
gates / gates (push) Successful in 2m35s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,108 @@
|
||||
TEST: D: direct env -> run_direct, NO appliance calls
|
||||
felhom-bootstrap: console: pvebanner.service masked (it would rewrite /work/issue with the Proxmox admin URL on every boot)
|
||||
felhom-bootstrap: console: /work/issue is the Felhom text (no admin URL)
|
||||
felhom-bootstrap: fetching host-install: https://felhom.eu/scripts/felhom-host-install.sh
|
||||
felhom-bootstrap: running host-install (customer=acme mode=appliance hub=https://hub.example)
|
||||
felhom-bootstrap: host-install SUCCESS — writing done-flag, disabling unit, scrubbing secrets
|
||||
ok: run_direct exited 0 (host-install stub succeeded)
|
||||
ok: host-install was invoked
|
||||
ok: ZERO /appliance/register calls
|
||||
ok: ZERO /appliance/poll calls
|
||||
ok: done-flag written
|
||||
ok: env shredded on success
|
||||
ok: G1: gate made zero ip calls
|
||||
ok: G1: gate made zero ifreload calls
|
||||
ok: G1: gate made zero dhclient calls
|
||||
ok: G1: gate consumed zero sleeps
|
||||
ok: G1: interfaces fixture untouched
|
||||
ok: R-496: /etc/issue written
|
||||
ok: R-496: /etc/issue is the Felhom text
|
||||
ok: R-496: /etc/issue carries no admin URL (:8006)
|
||||
ok: R-496: /etc/issue does not say Proxmox
|
||||
ok: R-496: pvebanner.service masked
|
||||
ok: R-496: /etc/issue carries no ő/ű (the boot font lacks them)
|
||||
TEST: P: pairing env -> register + in-script 204 wait -> 200 delivery -> host-install, ONE invocation
|
||||
felhom-bootstrap: console: pvebanner.service masked (it would rewrite /work/issue with the Proxmox admin URL on every boot)
|
||||
felhom-bootstrap: console: /work/issue is the Felhom text (no admin URL)
|
||||
felhom-bootstrap: PAIRING mode (generic ISO, no baked customer/passphrase) — hub=https://hub.example
|
||||
felhom-bootstrap: registering unclaimed appliance at the hub
|
||||
felhom-bootstrap: registered — appliance token stored (0600); waiting for the operator or a customer self-bind
|
||||
felhom-bootstrap: not bound yet — polling every 30s until the operator or a customer self-bind lands (this is the normal waiting state, not an error)
|
||||
felhom-bootstrap: bind DELIVERED — writing credentials to the env and switching to direct install
|
||||
felhom-bootstrap: fetching host-install: https://felhom.eu/scripts/felhom-host-install.sh
|
||||
felhom-bootstrap: running host-install (customer=drill mode=appliance hub=https://hub.example)
|
||||
felhom-bootstrap: host-install SUCCESS — writing done-flag, disabling unit, scrubbing secrets
|
||||
ok: R-496: banner painted to the console seam
|
||||
ok: R-496: banner names the Tulajdonosi jelmondat
|
||||
ok: R-496: banner no longer says 'jelszavad'
|
||||
ok: R-559: the pairing banner's Hungarian block is byte-identical to the golden
|
||||
ok: R-559: the pairing English block exists
|
||||
ok: R-559: the pairing English block has no Hungarian letter
|
||||
ok: R-559: CONTROL — the pairing Hungarian block does have one
|
||||
ok: R-559: every pairing line fits 80 columns
|
||||
ok: R-559: the bound banner's Hungarian block is byte-identical to the golden
|
||||
ok: R-559: the bound English block exists
|
||||
ok: R-559: the bound English block has no Hungarian letter
|
||||
ok: R-559: CONTROL — the bound Hungarian block does have one
|
||||
ok: R-559: every bound line fits 80 columns
|
||||
ok: R-559: the pairing code appears in BOTH blocks
|
||||
ok: R-559: the pairing banner fits a 25-row console (it is 24)
|
||||
ok: R-559: the bound banner fits a 25-row console (it is 18)
|
||||
ok: R-559: the bound banner carries no pairing code
|
||||
ok: R-559: /etc/issue still opens with the golden Hungarian
|
||||
ok: R-559: /etc/issue has an English half
|
||||
ok: R-559: /etc/issue English half has no Hungarian letter
|
||||
ok: R-559: /etc/issue names no admin URL
|
||||
ok: single invocation ran to done (exit 0)
|
||||
ok: POSTed /appliance/register
|
||||
ok: appliance token persisted 0600
|
||||
ok: polled more than once (the wait lived in-script, not in systemd restarts)
|
||||
ok: waited between polls (fake sleep called >=3x)
|
||||
ok: host-install invoked after delivery
|
||||
ok: done-flag written
|
||||
ok: env shredded on success
|
||||
TEST: 410: consumed delivery + no env -> exit non-zero so systemd restarts clean
|
||||
felhom-bootstrap: console: pvebanner.service masked (it would rewrite /etc/issue with the Proxmox admin URL on every boot)
|
||||
felhom-bootstrap: console: /etc/issue is the Felhom text (no admin URL)
|
||||
felhom-bootstrap: PAIRING mode (generic ISO, no baked customer/passphrase) — hub=https://hub.example
|
||||
felhom-bootstrap: registering unclaimed appliance at the hub
|
||||
felhom-bootstrap: registered — appliance token stored (0600); waiting for the operator or a customer self-bind
|
||||
felhom-bootstrap: ERROR: delivery already consumed but no local env — exiting so the unit restarts (rare crash-window)
|
||||
ok: 410 poll exits non-zero
|
||||
ok: host-install NOT run
|
||||
TEST: G2: hub down + no state.json -> sweep finds nicB, persists (bak kept), proceeds to pairing
|
||||
ok: sweep re-pointed vmbr0 to nicB
|
||||
ok: winner persisted with DHCP addressing
|
||||
ok: fallback static address dropped
|
||||
ok: original saved as interfaces.felhom-bak
|
||||
ok: self-heal logged loudly
|
||||
ok: proceeded to pairing after the heal
|
||||
ok: sweep exercised ifreload
|
||||
TEST: G3: hub down everywhere -> console screen painted, interfaces byte-identical, no bak
|
||||
Terminated
|
||||
ok: console screen painted (header)
|
||||
ok: screen lists the NICs
|
||||
ok: screen names the fallback signature
|
||||
ok: screen carries the remedy line
|
||||
ok: interfaces BYTE-IDENTICAL after failed sweep
|
||||
ok: no .felhom-bak on failure (success-only persist)
|
||||
ok: host-install never ran
|
||||
TEST: G4: hub down + state.json present -> screen + retry, sweep NEVER invoked, interfaces untouched
|
||||
Terminated
|
||||
ok: sweep NEVER invoked: zero ifreload calls
|
||||
ok: sweep NEVER invoked: zero dhclient calls
|
||||
ok: interfaces untouched
|
||||
ok: console screen still painted
|
||||
ok: no-sweep branch logged
|
||||
TEST: PI: postinst configure -> pvebanner masked by symlink, /etc/issue is Felhom's, exit 0
|
||||
ok: PI: postinst exits 0
|
||||
ok: PI: pvebanner.service -> /dev/null (masked by file)
|
||||
ok: PI: /etc/issue is the Felhom text
|
||||
ok: PI: /etc/issue carries no admin URL
|
||||
ok: PI: /etc/issue carries no ő/ű
|
||||
ok: PI: postinst and bootstrap write the SAME issue text
|
||||
==================================================
|
||||
ALL BOOTSTRAP-MODE TESTS PASSED
|
||||
|
||||
iso-bootstrap: built-in decoy convicted (a banner that never paints -> harness exit 1)
|
||||
iso-bootstrap gate OK — 73 harness checks green in felhom-iso-assistant:trixie
|
||||
Binary file not shown.
Binary file not shown.
Reference in New Issue
Block a user