docs(v1.24.0): R-59/R-60/R-61 SHIPPED — CHANGELOG, README, ROADMAP (+R-62), runbook, capability map, drill evidence, REPORT

Virgin-ISO nested drill closed the train: dead-NIC install baked the
fallback (incl. the dead default gateway), the R-59 screen painted
(capture committed beside the spike doc), the cable move healed +
registered at the hub in 23s unaided, and the build's rootpw file
matched the installed box's shadow hash. R-59 SHIPPED with the recorded
deviation (first-boot gate; installer-initrd abort out of scope by
operator ack). R-60 SHIPPED (spike + drill cited; F-P9 route-flush fix
included). R-61 slice 1 SHIPPED. New R-62 row (hub delete-dialog
cosmetics, XS). Capability map: new PROVEN-LIVE row (nested != metal,
said so). Cleanup verified: felhom-pve interfaces byte-identical,
bridge/VMs/ISO removed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UuFPHmHNrCJj1VhY6QdDMU
This commit is contained in:
2026-07-22 11:45:55 +02:00
parent 699325bd8a
commit a12c6f9730
8 changed files with 218 additions and 87 deletions
@@ -36,6 +36,11 @@
memtest pass, SMART clean, BIOS queue for the single visit in B2.
3. **Install media:** the **reusable generic pairing ISO** (secret-free, slice C). Only rebuild it
when `scripts/` ships a new version — never per-customer. Flash via dd/Rufus-DD.
**Console credential for bench work (R-61, since v1.24.0):** every build emits the baked root
password into the 0600 sibling **`<iso>.rootpw.txt`** next to the ISO in the build output — that
file is how you log into the console of any box installed from that build (bench checks, dead-
network diagnosis). Operator-only; never commit or paste it anywhere; the G1 break-glass vault
remains the mechanism for a *lost* password on an enrolled box.
Loader per firmware — record the board model + loader choice in the customer record; full
fleet inventory in `operations/nodes.md`:
@@ -72,9 +77,14 @@
> HP t740 the cable was on the 4-port expansion card, which gets **no lease** — and instead of
> aborting, the installer baked its `192.168.100.2` fallback as a **static** config and
> completed: a box that looked installed and could never call home
> (`operations/nodes.md` — the NIC map and the trap; filed as **R-59** hard-abort and **R-60**
> first-boot NIC sweep, both pending). Until those ship, on any multi-NIC board confirm at the
> installer's network step that the interface holding the lease is the one with the cable.
> (`operations/nodes.md` — the NIC map and the trap). **Since ISO v1.24.0 the box handles this
> itself (R-59+R-60):** if the hub is unreachable on first boot it sweeps every NIC (bounded
> DHCP + hub probe) and keeps the first that works — a cable in the wrong port just costs the
> sweep a minute — and when nothing works it paints a legible Hungarian screen with the NIC
> table (név/MAC/kábel/sebesség) and retries every minute. Nested-drill proven
> (`audits/SPIKE-firstboot-nic-sweep-2026-07-22.md`); on a pre-v1.24.0 stick the old manual
> check still applies: confirm at the installer's network step that the leasing interface is
> the cabled one.
3. **Bind** to the customer — **the rehearsal used the SELF-BIND path, and it is now the default for
this runbook.** The link is already in the customer's inbox (auto-minted at creation, A1); the
customer opens it and completes the public two-factor `/bind/<token>` page (console pairing code