doorstep walk on ISO 1.27.x: 1 intervention (R-505), STOP before publish
gates / gates (push) Successful in 17s

ISO 1.27.1 gated PASS and proven live: first-boot console Felhom-only,
pvebanner masked across a proven reboot. Hub v0.113.0 hand-over copy live
(R-497 closed). Full first hour walked again on customer tester-1 (three
disks + one disk): deploy, use, backup, removal, byte-identical restore,
power cut, typo all PASS. The tunnel gives a fresh box no routes: 12/12
503 from DooPlex (R-505); the record has no e-mail (R-508). Rows R-507,
R-508 filed; R-496/R-495 fixed/answered awaiting publish; day-0 A.1 no
longer claims the controller creates hostnames (R-506). NOT PUBLISHED.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-14 18:25:01 +02:00
parent 27e8ec860c
commit 65790672d5
69 changed files with 4110 additions and 7 deletions
@@ -0,0 +1,34 @@
# ISO release gate — felhom-installer-1.27.0 (2026-09-14)
**SUPERSEDED BY 1.27.1 — never to be published.** Its proof install (VM 331) still showed the Proxmox `:8006` block on the first boot (R-496). Built and gated; the proof installs and the first-hour walk are Phase 4 of the
doorstep task; publishing waits for the operator's yes (task Phase 5 STOP).
| | |
|---|---|
| file | `felhom-installer-1.27.0-pve9.2-1.iso` |
| sha256 | `2e2f96d30682537585612c5f277c4afa51375434a95e35a231be6d7e3d5c2ab5` |
| size | 1 705 322 496 B |
| built from | felhom.eu `6fd8c87` (manifest `repo-commit`); `HEAD` at gate time `63f29c6` changes only `manifests/hub.yaml` |
| package | `felhom-bootstrap_1.27.0_all.deb`, 13 060 B |
Every observed value and what was scanned for: `gate-run.txt` (run in `felhom-iso-assistant:trixie`
against the exact output file, stock ISO `proxmox-ve_9.2-1.iso` for the enumeration).
| criterion | result | observed |
|---|---|---|
| G1 no answer file | **PASS** | `0`; control: `/auto-installer-capable` found by the same `find` (`1`) |
| G2 no root password | **PASS** | `0` hash patterns across every added file + the package tree; no `.rootpw.txt` |
| G3 no SSH key | **PASS** | `0` |
| G4 no customer identity | **PASS (reviewed)** | 2 hits, both non-values: `Authorization: Bearer $token` (a header built from a runtime file) and the `FELHOM_RETRIEVAL_PASSPHRASE=` *parse check* string |
| G5 enumeration | **PASS** | 4 paths added (`felhomtheme/` ×3, the `.deb`), 3 removed (stock theme); content scan 0 hits, planted control `1` |
| G6 menu | **PASS** | 2 entries, `default=0`, `timeout=15`, `timeout_style=menu`; banned tokens `0`; **extra: `proxmox-start-auto-installer` in a live line `0`** (the build log's "lifted kernel line … auto-installer" is the repack's source read, not what ships) |
| G7 package | **PASS** | one `felhom-*.deb`, Version `1.27.0`, `Depends` lines `0` |
| G8 postinst | **PASS** | forbidden systemctl verbs `0`, network tools `0`, `set -e` `0`, last line `exit 0` |
| G9 payload = HEAD | **PASS** | `felhom-bootstrap.sh` `730b204b…afa6` = repo; `.service` `cf2e4678…9af3` = repo |
| G10 committed | **PASS** | `scripts/iso/` porcelain empty; `HEAD == origin/main` |
| G11 round trip | *publish-time* | — |
| G12 bucket private | *publish-time* | — |
| G13 directories | **PASS** | `./etc/felhom/`, `./usr/local/sbin/`, `./lib/systemd/system/` each `1` |
| G14 a person chooses the disk | **static half PASS** | no answer file (G1), `filter.` keys `0`; the proof-install half is the walk |
| G15 console after first boot + reboot | **static half PASS** | `systemctl mask pvebanner.service` present; issue text names `8006` `0`; the live half is the walk |
| G16 Hungarian, one name | **static half PASS** | `jelszavad` `0`; `Tulajdonosi jelmondat` `1`; negative control `isszaáll` `0`; English `printf` review list empty; GRUB titles and echo lines Hungarian |
@@ -0,0 +1,26 @@
Felhom bare-metal ISO build manifest (R-21 slice A+B+C)
built : 2026-09-14T17:28:48+02:00
iso-version-tag : v1.27.0
pve-version : 9.2-1
source-iso : proxmox-ve_9.2-1.iso
source-iso-sha256 : 4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c
assistant-version : proxmox-installer-common v9.2.7
profile : none (a release image bakes no disk selection)
fqdn : (none — interactive install)
mode : release (PUBLIC image — NO answer.toml, NO baked credential, interactive disk selection)
loader : shim (stock MS-signed chain; Secure Boot OK on compliant firmware)
grub-mkimage : unknown
boot-menu : FELHOM release menu — TWO INTERACTIVE entries ('Felhom telepítés' graphical = default, 'Felhom telepítés (szöveges mód)' = Terminal UI), timeout 15s
menu-entries : 2 (graphical default + Terminal UI; timeout 15s)
menu-removed : debug variants, Rescue Boot, memtest86+, UEFI Firmware Settings
automated-entry : NOT PRESENT — no auto-installer-mode.toml, so the stock grub.cfg does
not emit it. Disk selection is INTERACTIVE by construction.
host-install-url : https://felhom.eu/scripts/felhom-host-install.sh (default)
secret-bearing : no (PUBLIC image — carries NO credential of any kind)
root-password : NONE — not baked. The installer prompts the person installing (release gate G2).
answer-file : NONE — no answer.toml, no auto-installer-mode.toml (release gate G1)
felhom-package : felhom-bootstrap_1.27.0_all.deb sha256=0253f712c179e918d651c5447d2765cdf5039f21dff5b4ac1a5c03e748772b99
repo-commit : 6fd8c8751629d85d9a1435e338e47f868f441956
output : felhom-installer-1.27.0-pve9.2-1.iso
output-sha256 : 2e2f96d30682537585612c5f277c4afa51375434a95e35a231be6d7e3d5c2ab5
output-size-bytes : 1705322496
@@ -0,0 +1 @@
2e2f96d30682537585612c5f277c4afa51375434a95e35a231be6d7e3d5c2ab5 felhom-installer-1.27.0-pve9.2-1.iso
@@ -0,0 +1,74 @@
file: felhom-installer-1.27.0-pve9.2-1.iso sha256: 2e2f96d30682537585612c5f277c4afa51375434a95e35a231be6d7e3d5c2ab5 size: 1705322496
== G1 answer.toml / auto-installer-mode.toml at root (PASS=0)
0
control: the stock ISO's own marker '/auto-installer-capable' IS found by the same find: 1
== G5 enumeration: paths added vs stock
'/boot/grub/felhomtheme'
'/boot/grub/felhomtheme/background.png'
'/boot/grub/felhomtheme/theme.txt'
'/proxmox/packages/felhom-bootstrap_1.27.0_all.deb'
removed vs stock: 3 paths
== G2 root password / crypt hashes (PASS=0)
0
no .rootpw.txt beside the output: 0
== G3 ssh keys (PASS=0)
0
== G4 customer identity with a value (PASS=0)
/tmp/g/debx/usr/local/sbin/felhom-bootstrap.sh:493: -H "Authorization: Bearer $token" "$HUB_URL/api/v1/appliance/poll" 2>/dev/null)
/tmp/g/debx/usr/local/sbin/felhom-bootstrap.sh:511: if [[ -z "$envtext" || "$envtext" != *FELHOM_RETRIEVAL_PASSPHRASE=* ]]; then
(review: hits above must be declarations, comments or header-name use — see G4 note)
== G5 content scan (PEM keys / token= >=12 / password= / passphrase=) — hits:
(end of G5 hits)
positive control: a planted token line IS found: 1
== G6 boot menu
menuentries: 2
set timeout_style=menu
set timeout=15
set default=0
banned tokens live (PASS=0): 0
EXTRA — the automated installer token in a live line (PASS=0): 0
menuentry 'Felhom telepítés' --class felhom --class os {
linux /boot/linux26 ro ramdisk_size=16777216 rw quiet splash=silent
menuentry 'Felhom telepítés (szöveges mód)' --class felhom --class os {
linux /boot/linux26 ro ramdisk_size=16777216 rw quiet splash=silent proxtui
== G7 package
felhom debs: 1
Package: felhom-bootstrap
Version: 1.27.0
Depends lines: 0
== G8 postinst
systemctl start|daemon-reload|restart (live): 0
network tools (live): 0
set -e (live): 0
last line: exit 0
== G9 payload vs repo HEAD
bootstrap.sh pkg=730b204b87af3a2434469a6922fa03c1060988c848dd89d3ece2ab0f69ddafa6 repo=730b204b87af3a2434469a6922fa03c1060988c848dd89d3ece2ab0f69ddafa6 equal=yes
bootstrap.service pkg=cf2e4678e9ef5ab8439f7fc8522e4a61b031222243eea8916ea0efa6dca69af3 repo=cf2e4678e9ef5ab8439f7fc8522e4a61b031222243eea8916ea0efa6dca69af3 equal=yes
== G13 directories in the package
./etc/felhom/ 1
./usr/local/sbin/ 1
./lib/systemd/system/ 1
== G14 static half: filter.* keys in added text files (PASS=0): 0
== G16 static half (the packaged bootstrap)
'jelszavad' (PASS=0): 0
'Tulajdonosi jelmondat' (PASS>=1): 1
negative control 'Visszaallito kod' ascii fragment 'isszaáll' (expect 0): 0
printf lines without Hungarian letters or %s/Felhom (review list):
GRUB entry titles and echo lines:
menuentry 'Felhom telepítés' --class felhom --class os {
echo 'A Felhom telepítése indul — válassza ki a lemezt a telepítőben...'
echo 'Rendszerbetöltő betöltése...'
menuentry 'Felhom telepítés (szöveges mód)' --class felhom --class os {
echo 'A Felhom telepítése indul szöveges módban...'
echo 'Rendszerbetöltő betöltése...'
== G15 static half: bootstrap masks pvebanner and writes /etc/issue without :8006
mask line: 1 issue text lines naming 8006: 0
== G10 committed + pushed
scripts/iso porcelain: []
HEAD 63f29c6ad8e5101f750184486fda5fb61d8e4b75 origin 63f29c6ad8e5101f750184486fda5fb61d8e4b75
manifest repo-commit: repo-commit : 6fd8c8751629d85d9a1435e338e47f868f441956
@@ -0,0 +1,36 @@
# ISO release gate — felhom-installer-1.27.1 (2026-09-14)
**NOT PUBLISHED — awaiting the operator's yes.** Built and gated; the proof installs and the first-hour walk are Phase 4 of the
doorstep task; publishing waits for the operator's yes (task Phase 5 STOP).
| | |
|---|---|
| file | `felhom-installer-1.27.1-pve9.2-1.iso` |
| sha256 | `25637007d5a7120ff9faa6b5b7ead3e33c0a361ac2d67e9fd4e0ee77c034c053` |
| size | 1 705 322 496 B |
| built from | felhom.eu `27e8ec8` (manifest `repo-commit`) = `HEAD` at gate time |
| package | `felhom-bootstrap_1.27.1_all.deb` |
Every observed value and what was scanned for: `gate-run.txt` (run in `felhom-iso-assistant:trixie`
against the exact output file, stock ISO `proxmox-ve_9.2-1.iso` for the enumeration).
| criterion | result | observed |
|---|---|---|
| G1 no answer file | **PASS** | `0`; control: `/auto-installer-capable` found by the same `find` (`1`) |
| G2 no root password | **PASS** | `0` hash patterns across every added file + the package tree; no `.rootpw.txt` |
| G3 no SSH key | **PASS** | `0` |
| G4 no customer identity | **PASS (reviewed)** | 1 hit, a non-value: the `FELHOM_RETRIEVAL_PASSPHRASE=` *parse check* string (`felhom-bootstrap.sh:515`) |
| G5 enumeration | **PASS** | 4 paths added (`felhomtheme/` ×3, the `.deb`), 3 removed (stock theme); content scan 0 hits, planted control `1` |
| G6 menu | **PASS** | 2 entries, `default=0`, `timeout=15`, `timeout_style=menu`; banned tokens `0`; **extra: `proxmox-start-auto-installer` in a live line `0`** (the build log's "lifted kernel line … auto-installer" is the repack's source read, not what ships) |
| G7 package | **PASS** | one `felhom-*.deb`, Version `1.27.1`, `Depends` lines `0` |
| G8 postinst | **PASS** | forbidden systemctl verbs `0`, network tools `0`, `set -e` `0`, last line `exit 0` |
| G9 payload = HEAD | **PASS** | `felhom-bootstrap.sh` `973f0c8f…9dd6` = repo; `.service` `cf2e4678…9af3` = repo |
| G10 committed | **PASS** | `scripts/iso/` porcelain empty; `HEAD == origin/main` |
| G11 round trip | *publish-time* | — |
| G12 bucket private | *publish-time* | — |
| G13 directories | **PASS** | `./etc/felhom/`, `./usr/local/sbin/`, `./lib/systemd/system/` each `1` |
| G14 a person chooses the disk | **static half PASS** | no answer file (G1), `filter.` keys `0`; the proof-install half is the walk |
| G15 console after first boot + reboot | **PASS (live, VM 332)** — first boot Felhom-only (screen `332-b12`); proven reboot (boot 16:14:11Z > `qm reboot` 16:13:56Z); `pvebanner` `masked` → `/dev/null`; `/etc/issue` 0 × `8006`; postinst log shows both acts | `systemctl mask pvebanner.service` present; issue text names `8006` `0`; see `audits/evidence-doorstep-walk-1270-2026-09-14/G15-live-332-iso1271.txt` |
| G16 Hungarian, one name | **static half PASS** | `jelszavad` `0`; `Tulajdonosi jelmondat` `1`; negative control `isszaáll` `0`; English `printf` review list empty; GRUB titles and echo lines Hungarian |
**G14 proof half:** one disk (VM 332) and three disks (VM 331, on 1.27.0 — the installer path is identical in 1.27.1) both show the installer's own disk screen; the three-disk list is screen `331-s07`. **Graphical entry:** proven to boot, wait at the EULA with nobody at the keyboard, show the one-disk target and reach the password screen — **not driven to a full install** (R-507).
@@ -0,0 +1,26 @@
Felhom bare-metal ISO build manifest (R-21 slice A+B+C)
built : 2026-09-14T17:56:12+02:00
iso-version-tag : v1.27.1
pve-version : 9.2-1
source-iso : proxmox-ve_9.2-1.iso
source-iso-sha256 : 4e88fe416df9b527624a175f24c9aa07c714d3332afb1ee3dbf3879573ef2c6c
assistant-version : proxmox-installer-common v9.2.7
profile : none (a release image bakes no disk selection)
fqdn : (none — interactive install)
mode : release (PUBLIC image — NO answer.toml, NO baked credential, interactive disk selection)
loader : shim (stock MS-signed chain; Secure Boot OK on compliant firmware)
grub-mkimage : unknown
boot-menu : FELHOM release menu — TWO INTERACTIVE entries ('Felhom telepítés' graphical = default, 'Felhom telepítés (szöveges mód)' = Terminal UI), timeout 15s
menu-entries : 2 (graphical default + Terminal UI; timeout 15s)
menu-removed : debug variants, Rescue Boot, memtest86+, UEFI Firmware Settings
automated-entry : NOT PRESENT — no auto-installer-mode.toml, so the stock grub.cfg does
not emit it. Disk selection is INTERACTIVE by construction.
host-install-url : https://felhom.eu/scripts/felhom-host-install.sh (default)
secret-bearing : no (PUBLIC image — carries NO credential of any kind)
root-password : NONE — not baked. The installer prompts the person installing (release gate G2).
answer-file : NONE — no answer.toml, no auto-installer-mode.toml (release gate G1)
felhom-package : felhom-bootstrap_1.27.1_all.deb sha256=25d79d867aa3ae968b7f87e837fc1d73d87223a812cd198dd4a7fb502a974940
repo-commit : 27e8ec860c0f7b46c149815649c722cf362c8827
output : felhom-installer-1.27.1-pve9.2-1.iso
output-sha256 : 25637007d5a7120ff9faa6b5b7ead3e33c0a361ac2d67e9fd4e0ee77c034c053
output-size-bytes : 1705322496
@@ -0,0 +1 @@
25637007d5a7120ff9faa6b5b7ead3e33c0a361ac2d67e9fd4e0ee77c034c053 felhom-installer-1.27.1-pve9.2-1.iso
@@ -0,0 +1,78 @@
file: felhom-installer-1.27.1-pve9.2-1.iso sha256: 25637007d5a7120ff9faa6b5b7ead3e33c0a361ac2d67e9fd4e0ee77c034c053 size: 1705322496
== G1 answer.toml / auto-installer-mode.toml at root (PASS=0)
0
control: the stock ISO's own marker '/auto-installer-capable' IS found by the same find: 1
== G5 enumeration: paths added vs stock
'/boot/grub/felhomtheme'
'/boot/grub/felhomtheme/background.png'
'/boot/grub/felhomtheme/theme.txt'
'/proxmox/packages/felhom-bootstrap_1.27.1_all.deb'
removed vs stock: 3 paths
== G2 root password / crypt hashes (PASS=0)
0
no .rootpw.txt beside the output: 0
== G3 ssh keys (PASS=0)
0
== G4 customer identity with a value (PASS=0)
/tmp/g/debx/usr/local/sbin/felhom-bootstrap.sh:497: -H "Authorization: Bearer $token" "$HUB_URL/api/v1/appliance/poll" 2>/dev/null)
/tmp/g/debx/usr/local/sbin/felhom-bootstrap.sh:515: if [[ -z "$envtext" || "$envtext" != *FELHOM_RETRIEVAL_PASSPHRASE=* ]]; then
(review: hits above must be declarations, comments or header-name use — see G4 note)
== G5 content scan (PEM keys / token= >=12 / password= / passphrase=) — hits:
(end of G5 hits)
positive control: a planted token line IS found: 1
== G6 boot menu
menuentries: 2
set timeout_style=menu
set timeout=15
set default=0
banned tokens live (PASS=0): 0
EXTRA — the automated installer token in a live line (PASS=0): 0
menuentry 'Felhom telepítés' --class felhom --class os {
linux /boot/linux26 ro ramdisk_size=16777216 rw quiet splash=silent
menuentry 'Felhom telepítés (szöveges mód)' --class felhom --class os {
linux /boot/linux26 ro ramdisk_size=16777216 rw quiet splash=silent proxtui
== G7 package
felhom debs: 1
Package: felhom-bootstrap
Version: 1.27.1
Depends lines: 0
== G8 postinst
systemctl start|daemon-reload|restart (live): 0
network tools (live): 0
set -e (live): 0
last line: exit 0
== G9 payload vs repo HEAD
bootstrap.sh pkg=973f0c8f5fb04ea64f4ce5292bb792c34384b90d2800fcc1bb215f408ea59dd6 repo=973f0c8f5fb04ea64f4ce5292bb792c34384b90d2800fcc1bb215f408ea59dd6 equal=yes
bootstrap.service pkg=cf2e4678e9ef5ab8439f7fc8522e4a61b031222243eea8916ea0efa6dca69af3 repo=cf2e4678e9ef5ab8439f7fc8522e4a61b031222243eea8916ea0efa6dca69af3 equal=yes
== G13 directories in the package
./etc/felhom/ 1
./usr/local/sbin/ 1
./lib/systemd/system/ 1
== G14 static half: filter.* keys in added text files (PASS=0): 0
== G16 static half (the packaged bootstrap)
'jelszavad' (PASS=0): 0
'Tulajdonosi jelmondat' (PASS>=1): 1
negative control 'Visszaallito kod' ascii fragment 'isszaáll' (expect 0): 0
printf lines without Hungarian letters or %s/Felhom (review list):
GRUB entry titles and echo lines:
menuentry 'Felhom telepítés' --class felhom --class os {
echo 'A Felhom telepítése indul — válassza ki a lemezt a telepítőben...'
echo 'Rendszerbetöltő betöltése...'
menuentry 'Felhom telepítés (szöveges mód)' --class felhom --class os {
echo 'A Felhom telepítése indul szöveges módban...'
echo 'Rendszerbetöltő betöltése...'
== G15 static half: bootstrap masks pvebanner and writes /etc/issue without :8006
mask line: 1 issue text lines naming 8006: 0
== G15/G16 static — the POSTINST (v1.27.1)
pvebanner symlink mask line: 1
issue text in postinst == issue text in bootstrap: yes
o/u double acute in either issue text (PASS=0): 0
== G10 committed + pushed
scripts/iso porcelain: []
HEAD 27e8ec860c0f7b46c149815649c722cf362c8827 origin 27e8ec860c0f7b46c149815649c722cf362c8827
manifest repo-commit: repo-commit : 27e8ec860c0f7b46c149815649c722cf362c8827