doorstep: console is Felhom's (ISO 1.27.0 source), passphrase hand-over copy (hub 0.113.0 source), rulings
gates / gates (push) Successful in 19s
gates / gates (push) Successful in 19s
Phase 0: the public ISO never auto-installs by construction (no answer.toml, G1); the operator re-affirmed the interactive installer 2026-09-14. - felhom-bootstrap.sh: mask pvebanner.service, write a Hungarian /etc/issue (no :8006 admin URL); pairing banner names the Tulajdonosi jelmondat and paints through the CONSOLE_DEV seam (R-496). Harness: 8 checks, red first; fake hub now sends a pairing code (the banner was never tested, R-502). - hub: created flash + Credentials block tell the operator to hand the phrase over; the self-bind mail names the operator (R-497). Tests red first. - iso-release-gate G14-G16; domain ruling in 01-topology + CONTEXT; R-494 narrowed to P3; R-502..R-504 filed; volunteer guide and day-0 A.2 aligned. ISO_VERSION 1.27.0 (not built, not published). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -97,7 +97,9 @@ exit 0
|
||||
HI
|
||||
exit 0 ;;
|
||||
*"/appliance/register")
|
||||
echo '{"appliance_token":"TESTTOKEN123456","poll_interval_sec":30}'
|
||||
# pairing_code (R-27): without it print_pairing_banner returns early and the banner is never
|
||||
# painted — which is how the banner went untested until v1.27.0 (R-496).
|
||||
echo '{"appliance_token":"TESTTOKEN123456","poll_interval_sec":30,"pairing_code":"TST-CDE"}'
|
||||
exit 0 ;;
|
||||
*"/appliance/poll")
|
||||
if [ "$mode" = "200" ]; then
|
||||
@@ -113,15 +115,15 @@ exit 0
|
||||
CURL
|
||||
chmod +x "$FAKE/curl"
|
||||
|
||||
# fake systemctl (disable is a no-op)
|
||||
printf '#!/bin/bash\nexit 0\n' > "$FAKE/systemctl"; chmod +x "$FAKE/systemctl"
|
||||
# fake systemctl (disable is a no-op); logs every call so R-496's pvebanner mask is observable
|
||||
printf '#!/bin/bash\necho "$*" >> /work/systemctl.log\nexit 0\n' > "$FAKE/systemctl"; chmod +x "$FAKE/systemctl"
|
||||
|
||||
reset_state() {
|
||||
rm -rf /etc/felhom /run/felhom-bootstrap-pass /var/lib/felhom-install "$CALLS" /work/hostinstall.log \
|
||||
/work/poll-mode /work/sleep.count /work/sleep.flip /work/sleep.abort \
|
||||
/work/ip.log /work/ifreload.log /work/dhclient.log /work/hub-mode /work/dhcp-mode \
|
||||
/work/sys /work/interfaces /work/interfaces.felhom-bak /work/console.out \
|
||||
/run/felhom-interfaces.orig /work/run.log
|
||||
/run/felhom-interfaces.orig /work/run.log /work/issue /work/systemctl.log
|
||||
mkdir -p /etc/felhom
|
||||
}
|
||||
|
||||
@@ -150,7 +152,7 @@ iface nicB inet manual
|
||||
source /etc/network/interfaces.d/*
|
||||
IFACES
|
||||
}
|
||||
GATE_ENV="FELHOM_NET_SYS=/work/sys FELHOM_INTERFACES_FILE=/work/interfaces FELHOM_CONSOLE_DEV=/work/console.out"
|
||||
GATE_ENV="FELHOM_NET_SYS=/work/sys FELHOM_INTERFACES_FILE=/work/interfaces FELHOM_CONSOLE_DEV=/work/console.out FELHOM_ISSUE_FILE=/work/issue"
|
||||
|
||||
# ============================ Scenario D — direct mode, zero appliance calls =========================
|
||||
# Runs WITH the gate fixture (NICs + fallback-shaped interfaces) and the hub reachable: the G1
|
||||
@@ -179,6 +181,13 @@ check "G1: gate made zero ifreload calls" "[ ! -f /work/ifreload.log ]"
|
||||
check "G1: gate made zero dhclient calls" "[ ! -f /work/dhclient.log ]"
|
||||
check "G1: gate consumed zero sleeps" "[ ! -f /work/sleep.count ]"
|
||||
check "G1: interfaces fixture untouched" "grep -q 'bridge-ports nicA' /work/interfaces && grep -q '192.168.100.2' /work/interfaces"
|
||||
# R-496 (v1.27.0): the console's login banner is Felhom's, not Proxmox's — and it survives a reboot,
|
||||
# because pvebanner.service (which rewrites /etc/issue on EVERY boot) is masked, not merely overwritten.
|
||||
check "R-496: /etc/issue written" "[ -s /work/issue ]"
|
||||
check "R-496: /etc/issue is the Felhom text" "grep -q 'Felhom otthoni szerver' /work/issue"
|
||||
check "R-496: /etc/issue carries no admin URL (:8006)" "! grep -q '8006' /work/issue"
|
||||
check "R-496: /etc/issue does not say Proxmox" "! grep -qi 'proxmox' /work/issue"
|
||||
check "R-496: pvebanner.service masked" "grep -q 'mask pvebanner.service' /work/systemctl.log"
|
||||
|
||||
# ============ P: pairing loop (v1.21.0) — register, wait unbound INSIDE one invocation, deliver =====
|
||||
say "P: pairing env -> register + in-script 204 wait -> 200 delivery -> host-install, ONE invocation"
|
||||
@@ -188,7 +197,12 @@ FELHOM_HUB_URL=https://hub.example
|
||||
ENV
|
||||
echo 204 > /work/poll-mode
|
||||
echo 3 > /work/sleep.flip # after 3 in-script waits the hub "binds" (poll flips to 200)
|
||||
bash "$BSTRAP"; rc=$?
|
||||
rm -f /work/console.out
|
||||
env FELHOM_CONSOLE_DEV=/work/console.out FELHOM_ISSUE_FILE=/work/issue bash "$BSTRAP"; rc=$?
|
||||
# R-496: the pairing banner names the secret the way the self-bind mail and page do (R-323).
|
||||
check "R-496: banner painted to the console seam" "grep -q 'Párosító kód' /work/console.out"
|
||||
check "R-496: banner names the Tulajdonosi jelmondat" "grep -q 'Tulajdonosi jelmondat' /work/console.out"
|
||||
check "R-496: banner no longer says 'jelszavad'" "! grep -q 'jelszavad' /work/console.out"
|
||||
check "single invocation ran to done (exit 0)" "[ $rc -eq 0 ]"
|
||||
check "POSTed /appliance/register" "grep -q '/appliance/register' $CALLS"
|
||||
check "appliance token persisted 0600" "[ -f /etc/felhom/.bootstrap-done ] || { [ -f /etc/felhom/appliance-token ] && [ \"\$(stat -c %a /etc/felhom/appliance-token)\" = 600 ]; }"
|
||||
|
||||
Reference in New Issue
Block a user