From 7d81681d6e619419c871bfab5d425a26aa1407e5 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Tue, 18 Aug 2026 13:04:37 +0200 Subject: [PATCH] =?UTF-8?q?golden=200.216.0:=20baked,=20published,=20vouch?= =?UTF-8?q?ed=20=E2=80=94=20gates=20green=20again?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Closes the two-release day-0 gap that has been convicting CI since 2026-08-14. Run against RUNBOOK-manual-build.md 4.0 + 4.1. GOLDEN_VERSION = 0.216.0 GOLDEN_SHA256 = ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b archive = 656,970,239 bytes, controller image 0.216.0 template = debian-13-standard_13.6-1_amd64.tar.zst (listed live, not reused) Baselines re-read on the machine and all four matched the sheet: controller v0.216.0, its MinAgent 0.129.0, agent v0.129.0, previous golden 0.214.0. The published agent artifact for the vouched agent_version was confirmed present in the package registry rather than inferred from a CHANGELOG, and the R-216 check passed on the machine: MinAgent is EQUAL to, not above, the newest published agent. Verified beyond the script's own claim: the artifact was downloaded back out of Gitea and hashed, and it matches GOLDEN_SHA256 exactly. A script printing a digest and the registry serving those bytes are two different claims. Pass markers (corrected post-R-233 list) all present, quoted with line numbers in pass-markers.txt; excluding/FATAL absent; there is no mp1. Token never reached a command line: copied file->file, read inside the VM by the runner. systemctl show grep = 0. Token-leak grep on the COMMITTED log run with its positive control FIRST -- seeded copy 1, real log 0 -- because a grep -c that matches nothing also returns 0. Teardown: guest destroyed and purged, token/runner/script/log shredded AFTER the log was copied out, qemu exit confirmed with ps -eo comm (not pgrep -f), disk reverted to virgin. Vouched by the operator; verified by reading the hub's own store: golden 0.216.0 / agent 0.129.0 / min_agent 0.129.0, and the hub's recorded sha256 matches the independently downloaded artifact. That check was necessary because golden_currency_gate.py says of itself that it checks the BAKE, not the vouch. repo_gates.py --fast now rc=0, all nine gates OK -- first fully green run since 2026-08-14. Capability map deliberately NOT changed: the day-0 row cites drill documents, and the map's only golden literal is a dated historical citation on the recovery-journey row which bumping would falsify. R-334 is closed in a follow-up commit quoting this push's CI run id, since closing it without one would leave the ambiguity a third time. --- REPORT-golden-0.216.0.md | 151 ++++++++ STATUS.md | 11 +- .../golden-0.216.0-2026-08-18/SUMMARY.md | 79 +++++ .../tests/golden-0.216.0-2026-08-18/bake.log | 324 ++++++++++++++++++ .../package-url-verification.txt | 8 + .../pass-markers.txt | 20 ++ .../golden-0.216.0-2026-08-18/teardown.txt | 38 ++ .../token-leak-grep.txt | 12 + 8 files changed, 641 insertions(+), 2 deletions(-) create mode 100644 REPORT-golden-0.216.0.md create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/SUMMARY.md create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/bake.log create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/package-url-verification.txt create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/pass-markers.txt create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/teardown.txt create mode 100644 documentation/tests/golden-0.216.0-2026-08-18/token-leak-grep.txt diff --git a/REPORT-golden-0.216.0.md b/REPORT-golden-0.216.0.md new file mode 100644 index 00000000..a0252c63 --- /dev/null +++ b/REPORT-golden-0.216.0.md @@ -0,0 +1,151 @@ +# REPORT — bake and vouch golden 0.216.0, closing R-334 (2026-08-18, afternoon) + +**Outcome: R-334 CLOSED.** Golden **0.216.0** baked, published, and **vouched by the operator**. +`golden_currency_gate.py` is green for the first time since 2026-08-14, and `repo_gates.py` is +**fully green — all nine gates, rc=0**. + +Run against the existing `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 + §4.1; the run sheet +pinned this run's numbers and the stop. Evidence: +`documentation/tests/golden-0.216.0-2026-08-18/`. + +--- + +## 1. Baselines, re-read on the machine + +| item | value | source | +|---|---|---| +| newest released controller | **v0.216.0** | `felhom-controller/CHANGELOG.md` head | +| its floor | **`MinAgent: 0.129.0`** | second line of that header | +| newest agent release | **v0.129.0** | `felhom-agent/CHANGELOG.md` head | +| newest golden before this run | **0.214.0** | `documentation/tests/golden-0.214.0-2026-08-12` | + +**All four match the run sheet's §1 — no disagreement to report.** All three repos were clean with +`HEAD == origin/main` before starting. + +## 2. The published agent artifact exists + +Checked against the **package registry**, not inferred from a CHANGELOG: +`generic felhom-agent 0.129.0` is published. Vouching `agent_version` at a version that was never +published would point day-0 installs at a 404. + +**The R-216 check passed on the machine rather than on the coincidence.** `MinAgent` (0.129.0) is +**equal to**, not above, the newest published agent (0.129.0). Had it read higher, hub v0.97.0 would +hold the fleet against a version nobody has. + +## 3. Identity, and a verification beyond what was asked + +``` +GOLDEN_VERSION = 0.216.0 +GOLDEN_SHA256 = ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b +URL = https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.216.0/golden.tar.zst +archive = 656,970,239 bytes (rootfs 32G + ONE data volume 24G @ /var/lib/felhom) +controller = gitea.dooplex.hu/admin/felhom-controller:0.216.0 +template = debian-13-standard_13.6-1_amd64.tar.zst (listed live per §4.1 step 2, not reused) +``` + +The URL resolves (HTTP 206 on a range request). **I did not stop at the script's printed hash**: the +artifact was downloaded back out of Gitea and hashed, and it matches `GOLDEN_SHA256` exactly. The +script reporting a digest and the registry serving those bytes are two different claims, and only the +second one is what a new install actually receives. + +## 4. Pass markers — the corrected list, quoted from the real log + +``` + 82 : docker OK (overlay2; data-root /var/lib/docker) +313 : INFO: including mount point rootfs ('/') in backup +314 : INFO: including mount point mp0 ('/var/lib/felhom') in backup +319 : [golden] pre-delete existing: HTTP 404 (404/204 expected) +320 : [golden] upload OK (HTTP 201) +``` + +`excluding` and `FATAL`: **absent**. There is no mp1 — R-165 collapsed the two data volumes into one, +which is exactly why the pre-2026-08-06 marker list could never match and why R-233 rewrote it. + +## 5. Token handling, and why the control is not ceremony + +Copied **file → file** by `scp`; the runner script inside the VM read it from `/root/.gitea-token` +itself, so the value never reached a command line or a unit's properties: + +``` +systemctl show golden-bake -p Environment -p ExecStart | grep -c -F "" = 0 +``` + +Token-leak grep on the **committed** log, positive control run **first**: + +``` +seeded throwaway copy = 1 ← proves the grep can see a token when one is present +committed bake.log = 0 ← the real measurement, now worth believing +``` + +**A `grep -c` that matches nothing returns `0`, which is indistinguishable from a clean file.** +Without the control, the `0` is an assumption wearing a number's clothes. Both figures are from the +copy that is committed to the repository, not only the one inside the VM. + +## 6. Teardown + +`pct destroy 9100 --purge` (both LVs removed, CT purged) → `shred -u` on the token, runner, +build script and log **after** the log was copied out (standing rule 5) → all four confirmed absent +→ `poweroff` → waited for qemu to exit using `ps -eo comm` (**not** `pgrep -f`, which self-matches and +reports a false "still running") → `qemu-img snapshot -a virgin`, disk reverted, snapshot list shows +the single `virgin` entry. + +**Nothing was provisioned that outlives this run.** + +## 7. The vouch, and its verification + +**Performed by the operator (Viktor)** in the hub, Configuration → Day-0 artifacts. Verified +afterwards by reading the hub's own store rather than trusting the save: + +| field | value | recorded | +|---|---|---| +| `artifact_golden_version` | **0.216.0** | 2026-08-18 11:00:59 | +| `artifact_agent_version` | **0.129.0** | 2026-08-18 11:00:59 | +| `artifact_min_agent` | **0.129.0** | 2026-08-18 11:01:00 | +| `artifact_golden_sha256` | `ac004dc9…c34b` | 2026-08-18 11:01:00 | + +The recorded sha256 **matches the artifact I downloaded and hashed independently** — so the hub is +vouching the bytes that are actually published, not merely a matching version string. + +**This separate check was necessary, and the gate says so itself.** `golden_currency_gate.py`'s own +pass line reads *"this checks the BAKE, not the vouch"*. A green gate on an unvouched bake is exactly +the "baked-but-unvouched golden is worse than none" state R-334 warned about, so the gate alone could +not have closed this row. + +## 8. Gates + +``` +golden_currency_gate.py rc=0 + newest released controller : 0.216.0 + newest golden baked : 0.216.0 + +repo_gates.py --fast rc=0 + site OK · hostinstall OK · hub-confirm OK · manifest-bearer OK · reuse-refs OK + instructions OK · golden-currency OK · wire-contract OK · hub-copy OK + all felhom.eu gates OK +``` + +**This is the first fully green gate run since 2026-08-14**, and it is the point of the run: the +CI failure mail that has been arriving since then should now stop. + +## 9. Documentation not changed, deliberately + +**`documentation/architecture/00-capability-map.md` — no change, and the reason matters.** The run +sheet said to update it *if the day-0 install row's evidence citation names the golden version*. It +does not: that row cites `DRILL-day0-vm-2026-07-12` / `DRILL-day0-take2-2026-07-12`. The only golden +version literal in the map is `tests/golden-0.205.0-2026-08-07` on the **recovery-journey** row, +which is a **dated historical citation** of what a fresh install landed on during the 2026-08-07 +walk. Bumping it to 0.216.0 would falsify a record of what happened on a specific date — `docs.md` +permits historical citations precisely because they cannot go stale. + +## 10. Observations, not acted on + +- **`min_controller_version` in the hub still reads `0.214.0`** (last touched 2026-08-12). That is a + different field from the three vouched here — it is the floor the fleet is held to, not the day-0 + golden — and it was outside this run's scope. But it is now two releases behind the golden a new + box receives, and STATUS.md's "approved pair" line describes it. Worth a decision; **not** changed + here, because widening scope past the three named fields is how a vouch goes wrong. +- **`pveam available` still offers `debian-13-standard_13.6-1_amd64.tar.zst`** — the same point + release the runbook recorded on 2026-07-31. Listed live rather than assumed, per §4.1 step 2; the + instruction stands even when the answer happens not to have moved. +- **The bake ran in ~5 minutes** (12:49 launch → 12:54:14 archive), well inside the drill VM's normal + envelope; no timeout or retry was needed. diff --git a/STATUS.md b/STATUS.md index d746c432..ada7b398 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,7 +1,7 @@ # STATUS — what works, what's broken, what's next -**Updated 2026-08-18 (midday — a listening socket that served nobody, then a rehearsal upgrade that changed nothing; off-site backups were down for -9½ hours overnight and are back).** +**Updated 2026-08-18 (afternoon — a listening socket that served nobody, a rehearsal upgrade that changed +nothing, and a new install that is finally current).** > **A view, not a source.** `documentation/backlog/OPEN-ITEMS.md` is the authority; this page restates > part of it in plain words, and **nothing may exist only here**. **Items, not paragraphs. One screen.** @@ -43,6 +43,13 @@ record with no machine** — created 13 August, no host, no backups, nothing to ## Shipped +- **A new machine installed today finally gets today's software** (R-334, closed). The pre-built image + had been two releases behind since the 14th — anyone installing would have received a version + missing last week's disk-warning fix *and* the follow-up that corrected it. A fresh image was baked + and published, and **you vouched it**, which was the half that could not be done without you. **The + build system is green again for the first time since 14 August**, so the failure mail should stop. + The running machines were not touched: this only ever affected *new* installs. + - **Last night's two backup alarms were real, and are fixed** (R-336). Both machines failed their off-site backup at 04:30; **neither machine was at fault**. The off-site box in Germany had run out of one internal resource and, while looking perfectly healthy from outside, was accepting no diff --git a/documentation/tests/golden-0.216.0-2026-08-18/SUMMARY.md b/documentation/tests/golden-0.216.0-2026-08-18/SUMMARY.md new file mode 100644 index 00000000..783e8f7f --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/SUMMARY.md @@ -0,0 +1,79 @@ +# Golden bake 0.216.0 — 2026-08-18 + +Run under `RUN SHEET — bake and vouch golden 0.216.0 (closes R-334)`, following +`documentation/runbooks/RUNBOOK-manual-build.md` §4.0 + §4.1. Closes the two-release gap +R-334 has been convicting CI on since 2026-08-14. + +## Identity + + GOLDEN_VERSION = 0.216.0 + GOLDEN_SHA256 = ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b + URL = https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.216.0/golden.tar.zst + archive = 656,970,239 bytes (rootfs 32G + ONE data volume 24G @ /var/lib/felhom) + controller = gitea.dooplex.hu/admin/felhom-controller:0.216.0 + template = debian-13-standard_13.6-1_amd64.tar.zst (listed live, not reused from the runbook) + +**The published bytes were verified, not just the script's claim:** the artifact was downloaded back +from Gitea and hashed, and its sha256 matches the value the script printed, exactly. + +## Baselines, re-read on the machine + +| item | value | source | +|---|---|---| +| newest released controller | **v0.216.0** | `felhom-controller/CHANGELOG.md` head | +| its floor | **`MinAgent: 0.129.0`** | second line of that same header | +| newest agent release | **v0.129.0** | `felhom-agent/CHANGELOG.md` head | +| newest golden before this run | **0.214.0** | `documentation/tests/golden-0.214.0-2026-08-12` | + +All four match the run sheet's §1 — no disagreement to report. The agent artifact for the vouched +`agent_version` was confirmed **published in Gitea packages** (`generic felhom-agent 0.129.0`), not +inferred from the CHANGELOG. + +**The R-216 check passed:** `MinAgent` (0.129.0) is **equal to**, not above, the newest published +agent (0.129.0). The coincidence the run sheet warned about was confirmed on the machine rather than +assumed. + +## Pass markers — the corrected list (post-2026-08-06, R-233) + + line 82 : docker OK (overlay2; data-root /var/lib/docker) + line 313 : INFO: including mount point rootfs ('/') in backup + line 314 : INFO: including mount point mp0 ('/var/lib/felhom') in backup + line 319 : [golden] pre-delete existing: HTTP 404 (404/204 expected) + line 320 : [golden] upload OK (HTTP 201) + +`excluding` and `FATAL`: **absent**. There is no mp1 — R-165 collapsed the two data volumes into one, +which is why the pre-2026-08-06 marker list could never match. + +## Token handling + +Copied **file → file** by `scp`; never on a command line. The runner script inside the VM read it +from `/root/.gitea-token` itself. + + systemctl show golden-bake -p Environment -p ExecStart | grep -c -F "" = 0 + +Token-leak grep on the **committed** log, with its positive control run FIRST: + + seeded throwaway copy = 1 (proves the grep can see the token) + committed bake.log = 0 (the real measurement, now trustworthy) + +The control is not ceremony: a `grep -c` that silently matches nothing returns `0`, which is +indistinguishable from a clean file. Full transcript in `token-leak-grep.txt`. + +## Teardown + +- `pct destroy 9100 --purge` — both logical volumes removed, CT purged from related configs. +- `shred -u` on `/root/.gitea-token`, `/root/bake-run.sh`, `/root/build-golden.sh`, `/root/bake.log` + — **after** `bake.log` was copied out to this directory (standing rule 5). +- All four confirmed absent by `ls` afterwards. +- `poweroff`, waited for qemu to exit (`ps -eo comm`, **not** `pgrep -f`, which self-matches). +- `qemu-img snapshot -a virgin` — disk reverted; snapshot list shows the single `virgin` entry. + +Nothing was provisioned that outlives this run. + +## Files + + bake.log the real bake log, token-grepped (0, with control) + pass-markers.txt the markers quoted from that log with line numbers + token-leak-grep.txt control=1 / real=0 transcript + package-url-verification.txt URL resolution + downloaded-sha256 match + teardown.txt destroy, shred, qemu exit, revert diff --git a/documentation/tests/golden-0.216.0-2026-08-18/bake.log b/documentation/tests/golden-0.216.0-2026-08-18/bake.log new file mode 100644 index 00000000..cb37fb58 --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/bake.log @@ -0,0 +1,324 @@ +[golden] build-golden.sh v3.0.0 — baking controller gitea.dooplex.hu/admin/felhom-controller:0.216.0 +[golden] creating build LXC 9100 (nesting=1,keyctl=1, unprivileged; rootfs 32G + ONE data volume 24G @ /var/lib/felhom, backup=1) … + Logical volume "vm-9100-disk-0" created. + Logical volume pve/vm-9100-disk-0 changed. +Creating filesystem with 8388608 4k blocks and 2097152 inodes +Filesystem UUID: 04b6626c-cbce-49f2-b370-642a325029df +Superblock backups stored on blocks: + 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, + 4096000, 7962624 + Logical volume "vm-9100-disk-1" created. + Logical volume pve/vm-9100-disk-1 changed. +Creating filesystem with 6291456 4k blocks and 1572864 inodes +Filesystem UUID: 77e27bed-bdca-4436-aca7-42fd4f4db9e0 +Superblock backups stored on blocks: + 32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208, +extracting archive '/var/lib/vz/template/cache/debian-13-standard_13.6-1_amd64.tar.zst' +Total bytes read: 553512960 (528MiB, 173MiB/s) +Detected container architecture: amd64 +Creating SSH host key 'ssh_host_ecdsa_key' - this may take some time ... +done: SHA256:0U6qROh3MR0dZ936k1KUiGYhd4BEcaQlMKGzTYgi7kY root@felhom-golden +Creating SSH host key 'ssh_host_rsa_key' - this may take some time ... +done: SHA256:tYitIywg5r71mqw1sMLS1UxQyf00iRDV/xRhGhCj6BM root@felhom-golden +Creating SSH host key 'ssh_host_ed25519_key' - this may take some time ... +done: SHA256:ZdV26t00BfeuIwbEi52UJH40Lps/128W1nuDl5HJ1Wg root@felhom-golden +[golden] starting + installing Docker (official repo, trixie channel) … +apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct! +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = (unset), + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to the standard locale ("C"). +locale: Cannot set LC_CTYPE to default locale: No such file or directory +locale: Cannot set LC_MESSAGES to default locale: No such file or directory +locale: Cannot set LC_ALL to default locale: No such file or directory +apt-listchanges: Can't set locale; make sure $LC_* and $LANG are correct! +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = (unset), + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to the standard locale ("C"). +locale: Cannot set LC_CTYPE to default locale: No such file or directory +locale: Cannot set LC_MESSAGES to default locale: No such file or directory +locale: Cannot set LC_ALL to default locale: No such file or directory +[golden] baking daemon.json: classic overlay2 driver (containerd-snapshotter OFF) + log rotation … +[golden] wiring the single data volume (R-165 variant V-c): /var/lib/felhom/{docker,sys_drive} -> binds … +[golden] verifying Docker works in the build guest (storage driver should be overlay2 on the ext4 data volume) … +Unable to find image 'hello-world:latest' locally +latest: Pulling from library/hello-world +4f55086f7dd0: Pulling fs layer +4f55086f7dd0: Download complete +4f55086f7dd0: Pull complete +Digest: sha256:5dd0d3e6e255913fc30f90b9f2b1d359cc2cbdb48090cc4b65f1676e203243cc +Status: Downloaded newer image for hello-world:latest + docker OK (overlay2; data-root /var/lib/docker) + /var/lib/docker is a real mount: /dev/mapper/pve-vm--9100--disk--1[/docker] ext4 + /mnt/sys_drive is a real mount: /dev/mapper/pve-vm--9100--disk--1[/sys_drive] ext4 + both paths are ONE filesystem: /dev/mapper/pve-vm--9100--disk--1 23317576 +[golden] baking the in-guest controller image gitea.dooplex.hu/admin/felhom-controller:0.216.0 (no registry cred at deploy) … + +WARNING! Your credentials are stored unencrypted in '/root/.docker/config.json'. +Configure a credential helper to remove this warning. See +https://docs.docker.com/go/credential-store/ + +0.216.0: Pulling from admin/felhom-controller +039e6f9f9752: Pulling fs layer +0094c3ac0914: Pulling fs layer +deca1dac7403: Pulling fs layer +11c19a33d1b8: Pulling fs layer +44e9e14e4e05: Pulling fs layer +7d8b3a282cc4: Pulling fs layer +11c19a33d1b8: Waiting +44e9e14e4e05: Waiting +7d8b3a282cc4: Waiting +deca1dac7403: Verifying Checksum +deca1dac7403: Download complete +11c19a33d1b8: Verifying Checksum +11c19a33d1b8: Download complete +44e9e14e4e05: Verifying Checksum +44e9e14e4e05: Download complete +7d8b3a282cc4: Verifying Checksum +7d8b3a282cc4: Download complete +039e6f9f9752: Verifying Checksum +039e6f9f9752: Download complete +0094c3ac0914: Verifying Checksum +0094c3ac0914: Download complete +039e6f9f9752: Pull complete +0094c3ac0914: Pull complete +deca1dac7403: Pull complete +11c19a33d1b8: Pull complete +44e9e14e4e05: Pull complete +7d8b3a282cc4: Pull complete +Digest: sha256:2d9551b8a67112a19738a3943a346737d323cf772d1e50acbc799c0a5cc64673 +Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-controller:0.216.0 +gitea.dooplex.hu/admin/felhom-controller:0.216.0 +[golden] asking the controller which infra images it manages … +[golden] baking infra images (4): traefik:v3.6.7 cloudflare/cloudflared:2026.6.0 gtstef/filebrowser:1.3.3-stable gitea.dooplex.hu/admin/felhom-samba:1.1.0 … +v3.6.7: Pulling from library/traefik +589002ba0eae: Pulling fs layer +ef63511ea6cc: Pulling fs layer +0738e5cb835e: Pulling fs layer +3e6813f70c64: Pulling fs layer +3e6813f70c64: Waiting +ef63511ea6cc: Verifying Checksum +ef63511ea6cc: Download complete +589002ba0eae: Download complete +3e6813f70c64: Verifying Checksum +3e6813f70c64: Download complete +0738e5cb835e: Verifying Checksum +0738e5cb835e: Download complete +589002ba0eae: Pull complete +ef63511ea6cc: Pull complete +0738e5cb835e: Pull complete +3e6813f70c64: Pull complete +Digest: sha256:a9890c898f379c1905ee5b28342f6b408dc863f08db2dab20e46c267d1ff463a +Status: Downloaded newer image for traefik:v3.6.7 +docker.io/library/traefik:v3.6.7 +2026.6.0: Pulling from cloudflare/cloudflared +47de5dd0b812: Pulling fs layer +c172f21841df: Pulling fs layer +99515e7b4d35: Pulling fs layer +99ba982a9142: Pulling fs layer +d6b1b89eccac: Pulling fs layer +2780920e5dbf: Pulling fs layer +7c12895b777b: Pulling fs layer +3214acf345c0: Pulling fs layer +52630fc75a18: Pulling fs layer +dd64bf2dd177: Pulling fs layer +b839dfae01f6: Pulling fs layer +ebddc55facdc: Pulling fs layer +bdfd7f7e5bf6: Pulling fs layer +2d4d7adf6272: Pulling fs layer +40008157d8d2: Pulling fs layer +bd8962e29291: Pulling fs layer +cac2ae0193cb: Pulling fs layer +74d1dac84ecc: Pulling fs layer +99ba982a9142: Waiting +d6b1b89eccac: Waiting +2780920e5dbf: Waiting +7c12895b777b: Waiting +3214acf345c0: Waiting +52630fc75a18: Waiting +dd64bf2dd177: Waiting +b839dfae01f6: Waiting +ebddc55facdc: Waiting +bdfd7f7e5bf6: Waiting +2d4d7adf6272: Waiting +40008157d8d2: Waiting +bd8962e29291: Waiting +cac2ae0193cb: Waiting +74d1dac84ecc: Waiting +47de5dd0b812: Verifying Checksum +47de5dd0b812: Download complete +99515e7b4d35: Verifying Checksum +99515e7b4d35: Download complete +c172f21841df: Verifying Checksum +c172f21841df: Download complete +99ba982a9142: Download complete +47de5dd0b812: Pull complete +d6b1b89eccac: Verifying Checksum +d6b1b89eccac: Download complete +2780920e5dbf: Verifying Checksum +2780920e5dbf: Download complete +7c12895b777b: Download complete +3214acf345c0: Download complete +52630fc75a18: Verifying Checksum +52630fc75a18: Download complete +dd64bf2dd177: Verifying Checksum +dd64bf2dd177: Download complete +b839dfae01f6: Verifying Checksum +b839dfae01f6: Download complete +ebddc55facdc: Verifying Checksum +ebddc55facdc: Download complete +bdfd7f7e5bf6: Verifying Checksum +bdfd7f7e5bf6: Download complete +c172f21841df: Pull complete +2d4d7adf6272: Verifying Checksum +2d4d7adf6272: Download complete +40008157d8d2: Verifying Checksum +40008157d8d2: Download complete +bd8962e29291: Verifying Checksum +bd8962e29291: Download complete +cac2ae0193cb: Verifying Checksum +cac2ae0193cb: Download complete +74d1dac84ecc: Verifying Checksum +74d1dac84ecc: Download complete +99515e7b4d35: Pull complete +99ba982a9142: Pull complete +d6b1b89eccac: Pull complete +2780920e5dbf: Pull complete +7c12895b777b: Pull complete +3214acf345c0: Pull complete +52630fc75a18: Pull complete +dd64bf2dd177: Pull complete +b839dfae01f6: Pull complete +ebddc55facdc: Pull complete +bdfd7f7e5bf6: Pull complete +2d4d7adf6272: Pull complete +40008157d8d2: Pull complete +bd8962e29291: Pull complete +cac2ae0193cb: Pull complete +74d1dac84ecc: Pull complete +Digest: sha256:ba461b8aa9c042156dbd39c38657fe7431bafa063220eab8d5330a523863da9f +Status: Downloaded newer image for cloudflare/cloudflared:2026.6.0 +docker.io/cloudflare/cloudflared:2026.6.0 +1.3.3-stable: Pulling from gtstef/filebrowser +6a0ac1617861: Pulling fs layer +ef8806083e82: Pulling fs layer +b74107c861c7: Pulling fs layer +adc935def003: Pulling fs layer +4f4fb700ef54: Pulling fs layer +18695ccc900a: Pulling fs layer +45d119d5c397: Pulling fs layer +dac52db4fc51: Pulling fs layer +6d598f86b2f2: Pulling fs layer +8aa349c8396c: Pulling fs layer +45d119d5c397: Waiting +dac52db4fc51: Waiting +6d598f86b2f2: Waiting +8aa349c8396c: Waiting +adc935def003: Waiting +4f4fb700ef54: Waiting +18695ccc900a: Waiting +6a0ac1617861: Verifying Checksum +6a0ac1617861: Download complete +b74107c861c7: Verifying Checksum +b74107c861c7: Download complete +4f4fb700ef54: Verifying Checksum +4f4fb700ef54: Download complete +6a0ac1617861: Pull complete +ef8806083e82: Verifying Checksum +ef8806083e82: Download complete +adc935def003: Verifying Checksum +adc935def003: Download complete +18695ccc900a: Verifying Checksum +18695ccc900a: Download complete +45d119d5c397: Verifying Checksum +45d119d5c397: Download complete +dac52db4fc51: Verifying Checksum +dac52db4fc51: Download complete +6d598f86b2f2: Verifying Checksum +6d598f86b2f2: Download complete +8aa349c8396c: Verifying Checksum +8aa349c8396c: Download complete +ef8806083e82: Pull complete +b74107c861c7: Pull complete +adc935def003: Pull complete +4f4fb700ef54: Pull complete +18695ccc900a: Pull complete +45d119d5c397: Pull complete +dac52db4fc51: Pull complete +6d598f86b2f2: Pull complete +8aa349c8396c: Pull complete +Digest: sha256:eb3733681db8757412632c61a99ad656f0d94ed6781bb2ea114b4d70babab78c +Status: Downloaded newer image for gtstef/filebrowser:1.3.3-stable +docker.io/gtstef/filebrowser:1.3.3-stable +1.1.0: Pulling from admin/felhom-samba +897d797d2723: Pulling fs layer +3051591aa250: Pulling fs layer +ce57a3f93416: Pulling fs layer +fb94eeec2fe1: Pulling fs layer +fb94eeec2fe1: Waiting +ce57a3f93416: Verifying Checksum +ce57a3f93416: Download complete +fb94eeec2fe1: Verifying Checksum +fb94eeec2fe1: Download complete +897d797d2723: Verifying Checksum +897d797d2723: Download complete +3051591aa250: Verifying Checksum +3051591aa250: Download complete +897d797d2723: Pull complete +3051591aa250: Pull complete +ce57a3f93416: Pull complete +fb94eeec2fe1: Pull complete +Digest: sha256:1c17c09422bec0366d7cf0e0fcfc1486ba6c90334a0a5d5c851073a9342f8f10 +Status: Downloaded newer image for gitea.dooplex.hu/admin/felhom-samba:1.1.0 +gitea.dooplex.hu/admin/felhom-samba:1.1.0 +[golden] baking the controller-bootstrap unit (deploys the BAKED controller from the config mount) … +Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.service' → '/etc/systemd/system/felhom-controller-bootstrap.service'. +[golden] baking the controller-bootstrap PATH unit (starts the service on bootstrap-mount hot-plug — B1) … +Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-controller-bootstrap.path' → '/etc/systemd/system/felhom-controller-bootstrap.path'. +[golden] baking the first-boot SSH host-key regeneration unit (F3) … +Created symlink '/etc/systemd/system/multi-user.target.wants/felhom-regen-hostkeys.service' → '/etc/systemd/system/felhom-regen-hostkeys.service'. +[golden] identity-clean + minimize … +[golden] stop + archive … +INFO: including mount point rootfs ('/') in backup +INFO: including mount point mp0 ('/var/lib/felhom') in backup +INFO: archive file size: 626MB +INFO: Finished Backup of VM 9100 (00:00:43) +[golden] DONE. golden archive volid: local:backup/vzdump-lxc-9100-2026_08_18-12_54_14.tar.zst (rootfs 32G + ONE data volume 24G @ /var/lib/felhom, all in the archive) +[golden] publishing golden (656970239 bytes, sha256 ac004dc90d8cefcc…) → https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.216.0/golden.tar.zst +[golden] pre-delete existing: HTTP 404 (404/204 expected) +[golden] upload OK (HTTP 201) +GOLDEN_VERSION=0.216.0 +GOLDEN_SHA256=ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b +[golden] Record in the hub operator UI (Configs → Day-0 artifacts): golden 0.216.0 / ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b +[golden] (the build guest 9100 is stopped; destroy it with: pct destroy 9100 --purge) diff --git a/documentation/tests/golden-0.216.0-2026-08-18/package-url-verification.txt b/documentation/tests/golden-0.216.0-2026-08-18/package-url-verification.txt new file mode 100644 index 00000000..18671a82 --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/package-url-verification.txt @@ -0,0 +1,8 @@ +PACKAGE URL RESOLUTION +URL: https://gitea.dooplex.hu/api/packages/admin/generic/felhom-golden/0.216.0/golden.tar.zst + HTTP=206 size=1 bytes + (expected: 200/206 and NOT 404; log reported 656970239 bytes) + +SHA256 verification — download and hash, rather than trusting the script's own print: + downloaded sha256 = ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b + script reported = ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b diff --git a/documentation/tests/golden-0.216.0-2026-08-18/pass-markers.txt b/documentation/tests/golden-0.216.0-2026-08-18/pass-markers.txt new file mode 100644 index 00000000..553c5f7b --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/pass-markers.txt @@ -0,0 +1,20 @@ +PASS MARKERS — the CORRECTED list (RUNBOOK-manual-build.md §4.1, post-2026-08-06 R-233) +quoted from the real log: /mnt/5_hdd/felhom.eu/git/felhom.eu/documentation/tests/golden-0.216.0-2026-08-18/bake.log + +1) storage driver — literal 'docker OK (overlay2' +82: docker OK (overlay2; data-root /var/lib/docker) + +2) 'including mount point' for rootfs AND mp0 (there is NO mp1) +313:INFO: including mount point rootfs ('/') in backup +314:INFO: including mount point mp0 ('/var/lib/felhom') in backup + +3) negative markers — 'excluding' and 'FATAL' must NOT appear + none present OK + +4) 'upload OK (HTTP 201)' +320:[golden] upload OK (HTTP 201) + +5) published identity +319:[golden] pre-delete existing: HTTP 404 (404/204 expected) +321:GOLDEN_VERSION=0.216.0 +322:GOLDEN_SHA256=ac004dc90d8cefccc5448377892f9cff3a4c3e1e27d0e11129120e38ac31c34b diff --git a/documentation/tests/golden-0.216.0-2026-08-18/teardown.txt b/documentation/tests/golden-0.216.0-2026-08-18/teardown.txt new file mode 100644 index 00000000..2b52e946 --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/teardown.txt @@ -0,0 +1,38 @@ +### destroy build guest 9100 + Logical volume "vm-9100-disk-0" successfully removed. + Logical volume "vm-9100-disk-1" successfully removed. +purging CT 9100 from related configurations.. +### guest list after destroy (9100 must be gone) +perl: warning: Setting locale failed. +perl: warning: Please check that your locale settings: + LANGUAGE = (unset), + LC_ALL = (unset), + LC_CTYPE = "UTF-8", + LC_NUMERIC = (unset), + LC_COLLATE = (unset), + LC_TIME = (unset), + LC_MESSAGES = (unset), + LC_MONETARY = (unset), + LC_ADDRESS = (unset), + LC_IDENTIFICATION = (unset), + LC_MEASUREMENT = (unset), + LC_PAPER = (unset), + LC_TELEPHONE = (unset), + LC_NAME = (unset), + LANG = "en_US.UTF-8" + are supported and installed on your system. +perl: warning: Falling back to a fallback locale ("en_US.UTF-8"). +### shred token, runner, script, log (log already copied out) +### confirm gone +ls: cannot access '/root/.gitea-token': No such file or directory +ls: cannot access '/root/bake-run.sh': No such file or directory +ls: cannot access '/root/build-golden.sh': No such file or directory +ls: cannot access '/root/bake.log': No such file or directory +### qemu liveness after poweroff (ps -eo comm, NOT pgrep -f) + none — qemu exited +### revert disk to virgin + revert OK +### snapshot list +Snapshot list: +ID TAG VM_SIZE DATE VM_CLOCK ICOUNT +1 virgin 0 B 2026-07-03 14:12:15 0000:00:00.000 0 diff --git a/documentation/tests/golden-0.216.0-2026-08-18/token-leak-grep.txt b/documentation/tests/golden-0.216.0-2026-08-18/token-leak-grep.txt new file mode 100644 index 00000000..5d166187 --- /dev/null +++ b/documentation/tests/golden-0.216.0-2026-08-18/token-leak-grep.txt @@ -0,0 +1,12 @@ +TOKEN-LEAK GREP — on the COMMITTED log, with a positive control first. +Target: /mnt/5_hdd/felhom.eu/git/felhom.eu/documentation/tests/golden-0.216.0-2026-08-18/bake.log +Method: grep -c -F against the LITERAL token value (a broad [a-f0-9]{40} pattern false-hits image shas). + +-- POSITIVE CONTROL: seed a throwaway copy with the token, prove the grep can find it -- + seeded copy match count = 1 (MUST be 1 — otherwise the instrument is blind) + seeded copy shredded + +-- THE REAL MEASUREMENT, now that the grep is shown to work -- + committed log match count = 0 (MUST be 0) + +VERDICT: PASS — the grep works AND the committed log is clean.