felhom-host-install.sh 1.29.0: installs the OS-update wrapper (felhom-os-apply) from the pinned agent tag; skipped with a warning on an agent older than 0.140.0; uninstall removes it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 11:40:37 +02:00
parent 0e22a0ecc7
commit 9f797b0849
2 changed files with 33 additions and 1 deletions
+9
View File
@@ -1,3 +1,12 @@
## felhom-host-install.sh 1.29.0 — installs the OS-update wrapper (2026-10-04, `11-os-updates.md` §8 step 2)
- Step 5 fetches `configs/felhom-os-apply` from the pinned agent tag and installs it as
`/usr/local/sbin/felhom-os-apply` (0755 root:root, python3 syntax check first). The FELHOM_OSAPPLY sudoers line rides
the canonical sudoers fetch from the same tag. An agent older than 0.140.0 carries neither, so a missing wrapper is
SKIPPED with a warning (OS updates stay off), never fatal. `--uninstall` removes it.
- **Existing boxes get neither the wrapper nor the sudoers line from this** — the installer runs on a new box; the
agent's signed self-update replaces only the binary (R-840).
## one-register reads suffix ids and splits on pipes outside code (2026-10-03, backlog triage, Part D)
- `one_register_gate.py`: the id pattern was `R-(\d+)`, so ROADMAP rows R-27b, R-27c and R-50b were never read;
+24 -1
View File
@@ -184,7 +184,7 @@
set -euo pipefail
SCRIPT_VERSION="1.28.0" # the SINGLE version source (F-1): -h and the run banners follow it.
SCRIPT_VERSION="1.29.0" # the SINGLE version source (F-1): -h and the run banners follow it.
# The hub used to carry a copy for its Setup tab; R-94 DELETED it
# (2026-08-02) because the hub cannot know which version a box runs —
# the Setup command fetches this script at run time. scripts/
@@ -1157,6 +1157,7 @@ run_uninstall() {
if [[ -f /usr/local/sbin/felhom-mkfs-guarded ]]; then run rm -f /usr/local/sbin/felhom-mkfs-guarded; else log_skip " felhom-mkfs-guarded already absent"; fi
if [[ -f /usr/local/sbin/felhom-pbs-apply ]]; then run rm -f /usr/local/sbin/felhom-pbs-apply; else log_skip " felhom-pbs-apply already absent"; fi
if [[ -f /usr/local/sbin/felhom-backup-target-apply ]]; then run rm -f /usr/local/sbin/felhom-backup-target-apply; else log_skip " felhom-backup-target-apply already absent"; fi
if [[ -f /usr/local/sbin/felhom-os-apply ]]; then run rm -f /usr/local/sbin/felhom-os-apply; else log_skip " felhom-os-apply already absent"; fi
if [[ -f /var/lib/vz/snippets/felhom-guest-hook.sh ]]; then run rm -f /var/lib/vz/snippets/felhom-guest-hook.sh; fi
local dconf _dnsmasq_touched=false
for dconf in /etc/dnsmasq.d/felhom-*.conf; do
@@ -2372,6 +2373,28 @@ step_agent_install() {
log_success " installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)"
fi
# OS updates, guest fast lane (agent >= 0.140.0, `11-os-updates.md` §8 step 2): the root wrapper behind the
# FELHOM_OSAPPLY sudoers alias. It ships in the AGENT repo at the same pinned tag as the sudoers file, so an older
# pinned agent has neither the wrapper nor the alias — a missing file is therefore SKIPPED with a warning (OS
# updates stay off), never fatal. Python 3 (stdlib only), syntax-checked before install, 0755 root:root.
if $DRY_RUN; then
log_dry "fetch configs/felhom-os-apply (if the pinned agent carries it) ; python3 syntax check ; install 0755 -> /usr/local/sbin/felhom-os-apply"
else
local ostmp; ostmp=$(mktemp -t felhom-os.XXXXXX)
local -a _osauth; _git_auth_args _osauth
if curl -fsS "${_osauth[@]}" -o "$ostmp" \
"$GITEA_BASE/$GITEA_OWNER/$AGENT_REPO/raw/tag/v$ART_AGENT_VER/configs/felhom-os-apply" 2>/dev/null \
&& [[ -s "$ostmp" ]]; then
python3 -c 'import ast,sys; ast.parse(open(sys.argv[1]).read())' "$ostmp" \
|| { rm -f "$ostmp"; die "fetched felhom-os-apply failed the python3 syntax check — refusing to install"; }
install -m 0755 -o root -g root "$ostmp" /usr/local/sbin/felhom-os-apply
log_success " installed /usr/local/sbin/felhom-os-apply (0755, the guarded OS-update path)"
else
log_warn " agent v$ART_AGENT_VER carries no felhom-os-apply (older than 0.140.0) — OS updates stay off on this box"
fi
rm -f "$ostmp"
fi
# Sudoers — fetch the canonical file, validate with visudo -cf BEFORE installing (0440 root:root).
if $DRY_RUN; then
log_dry "fetch configs/felhom-agent.sudoers ; visudo -cf ; install 0440 -> $AGENT_SUDOERS"