diff --git a/scripts/iso/build-felhom-iso.sh b/scripts/iso/build-felhom-iso.sh index f6534f9..4a041ef 100755 --- a/scripts/iso/build-felhom-iso.sh +++ b/scripts/iso/build-felhom-iso.sh @@ -463,6 +463,7 @@ echo "$OUT_SHA $(basename "$OUT_ISO")" > "$OUT_ISO.sha256" LOADER_NOTE="shim (stock MS-signed chain; Secure Boot OK on compliant firmware)" [[ "$LOADER" == "mkimage" ]] && LOADER_NOTE="mkimage (monolithic grub-mkimage UEFI loader, F1 fix — UNSIGNED; target board MUST have Secure Boot OFF)" BRAND_NOTE="FELHOM (single entry 'Felhom telepítés', default, 5s; stock installer entries not emitted)" +$RELEASE && BRAND_NOTE="FELHOM release menu — TWO INTERACTIVE entries ('Felhom telepítés' graphical = default, 'Felhom telepítés (szöveges mód)' = Terminal UI), timeout 15s" $BRAND || BRAND_NOTE="STOCK PVE menu (--no-brand; DEBUG BUILD — manual installer reachable, do not ship)" MODE_NOTE="direct (env-baked customer-id + retrieval passphrase; secret-bearing)" $PAIRING && MODE_NOTE="pairing (GENERIC secret-free universal ISO — box self-registers, operator binds, hub delivers once)" @@ -475,15 +476,22 @@ pve-version : ${PVE_VERSION} source-iso : ${ISO_BASE} source-iso-sha256 : ${ISO_SHA256} assistant-version : ${ASSISTANT_VER} -profile : ${PROFILE_NAME} +profile : $( $RELEASE && echo 'none (a release image bakes no disk selection)' || echo "${PROFILE_NAME}" ) fqdn : ${FELHOM_FQDN} mode : ${MODE_NOTE} loader : ${LOADER_NOTE} grub-mkimage : ${GRUB_VERSION:-n/a (shim mode; loader unchanged)} boot-menu : ${BRAND_NOTE} -$( $BRAND && cat "$WORK/brand-report.txt" 2>/dev/null || true ) +$( if $RELEASE; then + echo "menu-entries : 2 (graphical default + Terminal UI; timeout 15s)" + echo "menu-removed : debug variants, Rescue Boot, memtest86+, UEFI Firmware Settings" + echo "automated-entry : NOT PRESENT — no auto-installer-mode.toml, so the stock grub.cfg does" + echo " not emit it. Disk selection is INTERACTIVE by construction." + else + $BRAND && cat "$WORK/brand-report.txt" 2>/dev/null || true + fi ) host-install-url : $(grep -oE 'FELHOM_INSTALL_URL=[^ ]*' "$BOOTSTRAP_ENV" 2>/dev/null || echo 'https://felhom.eu/scripts/felhom-host-install.sh (default)') -secret-bearing : ${SECRET_BEARING}$( $PAIRING && echo ' (GENERIC ISO — carries NO customer secret)' || echo ' (embeds the customer retrieval passphrase — supervised/single-use, delete after the run)') +secret-bearing : ${SECRET_BEARING}$( $RELEASE && echo ' (PUBLIC image — carries NO credential of any kind)' || { $PAIRING && echo ' (GENERIC ISO — carries NO customer secret)' || echo ' (embeds the customer retrieval passphrase — supervised/single-use, delete after the run)'; } ) root-password : $( $RELEASE && echo 'NONE — not baked. The installer prompts the person installing (release gate G2).' || echo "see $(basename "$OUT_ISO").rootpw.txt (operator-only; NEVER commit or paste into REPORTs)" ) answer-file : $( $RELEASE && echo 'NONE — no answer.toml, no auto-installer-mode.toml (release gate G1)' || echo 'baked (/answer.toml)' ) felhom-package : $( [[ -n "$RELEASE_DEB" ]] && echo "$(basename "$RELEASE_DEB") sha256=$(sha256sum "$RELEASE_DEB" | cut -d\ -f1)" || echo 'n/a (day-0 rides the answer file first-boot hook)' )