R-275, R-276, R-881: the uninstall removes every copy of the agent config, the WireGuard tunnel and felhom-priv-apply

- R-275: the agent's own config dir is purged as a directory (the .bak* glob missed all five
  demo-hp copies); a custom config path loses agent.json + every agent.json.* sibling only.
  Sudoers dotted copies go too. At install, a freshly created service user cannot read what an old
  install left in /etc/felhom-agent (sealed root 0600, named, never deleted). vmbr9 and the ISO
  first-boot files are now NAMED under KEPT.
- R-276: wg-quick@wg-felhom is disabled --now and its conf removed, then observed down; the hub-side
  peer is named under KEPT (removing it is the hub's job).
- R-881: /usr/local/sbin/felhom-priv-apply is removed; the disclosure says it and the guest hook
  come from the config bundle.
- scripts/test_hostinstall.py: lifts the functions verbatim and runs them with PATH stubs (13 tests,
  BusyBox-safe); harness GL4-D here-string (SIGPIPE false miss), GL8-F1 follows the new purge.
- SCRIPT_VERSION 1.32.0 (not published; no tag).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:14:19 +02:00
parent c8da8e0439
commit 85de3f9b87
3 changed files with 487 additions and 28 deletions
+11 -20
View File
@@ -256,8 +256,11 @@ if [[ -n "$ustart" && -n "$uend" && "$ustart" -lt "$uend" ]]; then
for tok in 'felhom-selfupdate-guarded' 'felhom-agent-rollback.service' 'felhom-agent-limits.conf' \
'.prev' 'felhom-mgmt-watchdog' 'felhom-privsep.conf' 'felhom-mkfs-guarded' \
'felhom-guest-hook' '/mnt/felhom-drives' 'AGENT_SUDOERS' 'AGENT_STATE_DIR' \
'remove_scoped_acl' 'pveum user token remove' 'pveum pool delete' 'STATE_FILE'; do
echo "$usect" | grep -qF "$tok" || d_missing+="$tok "
'remove_scoped_acl' 'pveum user token remove' 'pveum pool delete' 'STATE_FILE' \
'felhom-priv-apply' '_teardown_wg_tunnel' '_purge_agent_config'; do
# a here-string, not `echo | grep -q`: under pipefail grep -q's early exit SIGPIPEs the echo
# and a token that IS present reads as missing (AGENT_SUDOERS did, 2026-10-05).
grep -qF -- "$tok" <<<"$usect" || d_missing+="$tok "
done
if [[ -z "$d_missing" ]]; then
verdict PASS "GL4-D disclosure↔uninstall parity (all artifact tokens covered)"
@@ -326,25 +329,13 @@ else
verdict FAIL "GL8-F6 byo :53 gate refuses+instructs, never mutates the owner's resolver"
fi
# GL8-F1(static): uninstall removes the agent config's .bak* siblings (not just agent.json).
if grep -q '"${agent_cfg}".bak\*' "$SCRIPT"; then
verdict PASS "GL8-F1 uninstall removes \${agent_cfg}.bak* (secret-bearing backups)"
# GL8-F1 / R-275: the agent config and EVERY copy of it go — the agent's own config dir is purged as a
# directory (the old `.bak*` glob missed `agent.json.campaign9-before` & co.). Behaviour is pinned by
# scripts/test_hostinstall.py (test_purge_*, run in CI); here only the call site.
if grep -q '^ _purge_agent_config "\$agent_cfg"' "$SCRIPT" && ! grep -q '"${agent_cfg}".bak\*' "$SCRIPT"; then
verdict PASS "GL8-F1 uninstall purges the agent config dir (every copy, R-275)"
else
verdict FAIL "GL8-F1 uninstall removes \${agent_cfg}.bak* (secret-bearing backups)"
fi
# GL8-F1(behavioural): the exact glob-removal pattern the script uses, exercised in a temp dir —
# both agent.json AND its .bak* siblings must go (a plain `rm -f agent.json` would leave the .bak).
f1dir="$WORK/etc-felhom-agent"; mkdir -p "$f1dir"
: > "$f1dir/agent.json"; : > "$f1dir/agent.json.bak-0.75.0"; : > "$f1dir/agent.json.bak-ceremony-2026-07-08"; : > "$f1dir/agent.json.bak-pre064"
agent_cfg="$f1dir/agent.json"
rm -f "$agent_cfg"
for _cfgbak in "${agent_cfg}".bak*; do [[ -e "$_cfgbak" ]] && rm -f "$_cfgbak"; done
rmdir "$f1dir" 2>/dev/null || true
if [[ ! -e "$f1dir" ]]; then
verdict PASS "GL8-F1b glob removal clears agent.json + every .bak* + the empty dir"
else
verdict FAIL "GL8-F1b glob removal clears agent.json + every .bak* + the empty dir" "residue: $(ls -A "$f1dir" 2>/dev/null | tr '\n' ' ')"
verdict FAIL "GL8-F1 uninstall purges the agent config dir (every copy, R-275)"
fi
echo ""