burn-down night: installer 1.32.0 on main (R-275 R-276 R-881 R-306 R-130 R-180 R-179 R-310 R-274; ships with installer-v1.32.0), decision 131; agent halves R-349/R-25 recorded; R-444/R-99 need the operator; R-531 closed stale (196 -> 195)
gates / gates (push) Successful in 2m2s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:27:42 +02:00
parent f790734ec2
commit 86def579ed
7 changed files with 71 additions and 14 deletions
+25
View File
@@ -1,3 +1,28 @@
## felhom-host-install.sh 1.32.0 — the uninstall leaves nothing that holds a secret or a tunnel; pre-flight tells the truth (burn-down night, 2026-10-05; NOT published — ships with the tag `installer-v1.32.0`)
- **R-275:** the uninstall removes the agent's config directory with every copy of the config in it (the `.bak*` glob
missed `agent.json.campaign9-before` & co.), removes the sudoers' dotted copies, and names the vmbr9 stanza and the ISO
first-boot files under KEPT; a new install whose service user is freshly created makes any old copies root-only.
- **R-276:** the uninstall takes down the WireGuard tunnel to the off-site endpoint (`wg-quick@wg-felhom` disabled
`--now`, conf removed, observed down) and names the hub-side peer under KEPT.
- **R-881:** the uninstall removes `/usr/local/sbin/felhom-priv-apply`; the BYO disclosure says it and the guest hook
come from the agent's config bundle; a test fails when the bundle gains a file the uninstall does not name.
- **R-306:** `--preflight-only` writes no state at all; the banner's „no state written" is now true.
- **R-130:** the local-lvm check is named as what it is — a RECOMMENDED 120 GiB that warns and lets the install continue
(was called a hard minimum; behaviour unchanged, as `runbooks/day0-install.md` documents).
- **R-180:** pre-flight refuses an `--archive-storage` the agent's token will not be granted on (it used to fail at step
8/8 with HTTP 403 after root@pam was rotated); the backup target counts as granted (step 6, R-185).
- **R-179:** the uninstall removes the NAS network-storage `.automount`/`.mount` units the agent wrote, automounts first,
before the drive umounts; a busy share is never forced and is named under KEPT; drive and foreign units untouched.
- **R-310:** the named-golden refusal states the vouched version once; `--uninstall` without a terminal refuses with a
sentence before the typed confirmation instead of dying on `/dev/tty`.
- **R-274:** the BYO disclosure says a golden already on the archive storage is reused only when it matches the hub's
vouched golden (the check itself shipped with R-297); tests pin the check before the adopt.
- **New:** `scripts/test_hostinstall.py` — 33 behaviour tests that lift functions word for word from the script and run
them with recording PATH stubs (BusyBox-safe; picked up by the `script-tests` gate). Each behaviour fix was red-proved.
`hostinstall-mode-harness.sh`: GL4-D no longer reports present items missing when `grep` stops early; GL8-F1 checks the
new purge.
## gates + tools — burn-down round 2 (2026-10-05)
- **R-819:** `check_stands.py` rule 3 also accepts an id found in `CLOSED-ITEMS.md`; registered as the `stands` gate in