From c033b3b617af2e1c2df3d6aa3140331fd0725166 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 16 Sep 2026 17:05:35 +0200 Subject: [PATCH] ISO 1.28.0 source: the console stops showing the pairing code once bound (R-535) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Measured 2026-09-16: 25 minutes after a successful bind AND claim the console still showed the pairing code under a line promising the screen refreshes itself. print_bound_banner is printed the moment the bind delivery lands. It does NOT name the dashboard URL: the one-shot delivery carries the customer id, passphrase and mode, not the domain, so naming an address would mean inventing one. The residue — the console still does not reflect the later CLAIM, because this unit has exited by then — is recorded in the changelog rather than implied away. Not published: the built image needs the release gate and the operator's yes. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .../phaseB-tester1-offsite.txt | 31 ++++++++++++++ .../phaseC-ep0-acl-before.txt | 26 ++++++++++++ .../phaseC-ep0-grant.txt | 42 +++++++++++++++++++ .../releases.txt | 5 +++ scripts/CHANGELOG.md | 18 ++++++++ scripts/iso/build-felhom-iso.sh | 2 +- scripts/iso/felhom-bootstrap.sh | 22 ++++++++++ 7 files changed, 145 insertions(+), 1 deletion(-) create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-acl-before.txt create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-grant.txt create mode 100644 documentation/audits/evidence-backup-promise-2026-09-16/releases.txt diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt new file mode 100644 index 00000000..ca489a24 --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseB-tester1-offsite.txt @@ -0,0 +1,31 @@ +:30: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC). +## 2026-09-16T15:03:54Z Part B live — enabling the off-site tier for tester-1 through the hub page + fields re-sent (values not printed): _csrf, cf_api_token, cf_tunnel_token, customer_id, customer_name, domain, dr_tier, email, git_token, git_username, offsite_box_type, offsite_enabled, offsite_quota_gb, offsite_type, pbsdr_storage_id + preserved-not-blanked: cf_api_token, cf_tunnel_token +Traceback (most recent call last): + File "", line 36, in + File "/usr/lib/python3.13/urllib/request.py", line 189, in urlopen + return opener.open(url, data, timeout) + ~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^ + File "/usr/lib/python3.13/urllib/request.py", line 489, in open + response = self._open(req, data) + File "/usr/lib/python3.13/urllib/request.py", line 506, in _open + result = self._call_chain(self.handle_open, protocol, protocol + + '_open', req) + File "/usr/lib/python3.13/urllib/request.py", line 466, in _call_chain + result = func(*args) + File "/usr/lib/python3.13/urllib/request.py", line 1348, in http_open + return self.do_open(http.client.HTTPConnection, req) + ~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + File "/usr/lib/python3.13/urllib/request.py", line 1323, in do_open + r = h.getresponse() + File "/usr/lib/python3.13/http/client.py", line 1459, in getresponse + response.begin() + ~~~~~~~~~~~~~~^^ + File "/usr/lib/python3.13/http/client.py", line 336, in begin + version, status, reason = self._read_status() + ~~~~~~~~~~~~~~~~~^^ + File "/usr/lib/python3.13/http/client.py", line 305, in _read_status + raise RemoteDisconnected("Remote end closed connection without" + " response") +http.client.RemoteDisconnected: Remote end closed connection without response diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-acl-before.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-acl-before.txt new file mode 100644 index 00000000..0ef36002 --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-acl-before.txt @@ -0,0 +1,26 @@ +## 2026-09-16T14:57:56Z ep0 ACL BEFORE (read-only) — scope: the hub's tenantsync auth-id only +--- all ACL entries: ++========================+=======================================+===========+=================+ +| ugid | path | propagate | roleid | ++========================+=======================================+===========+=================+ +| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup | ++========================+=======================================+===========+=================+ +--- users/tokens: ++============+========+========+===========+==========+=======+===============================================+ +| userid | enable | expire | firstname | lastname | email | comment | ++============+========+========+===========+==========+=======+===============================================+ +| felhom@pbs | 1 | never | | | | offsite tenancy (per-customer privsep tokens) | ++------------+--------+--------+-----------+----------+-------+-----------------------------------------------+ +| root@pam | 1 | never | | | | Superuser | ++============+========+========+===========+==========+=======+===============================================+ +--- roles that carry Datastore.Modify: diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-grant.txt b/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-grant.txt new file mode 100644 index 00000000..76556341 --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/phaseC-ep0-grant.txt @@ -0,0 +1,42 @@ +## 2026-09-16T15:03:10Z Part C.1 — the grant, narrowest role FIRST, measured at every step +--- BEFORE: effective permissions of felhom@pbs at the datastore ROOT (where R-534 failed): +Privileges with (*) have the propagate flag set + +--- try the NARROWER role first: DatastorePowerUser +Privileges with (*) have the propagate flag set + +Path: /datastore/felhom-offsite +- Datastore.Backup (*) +- Datastore.Prune (*) +## 2026-09-16T15:03:42Z DatastorePowerUser does NOT carry Datastore.Modify (measured above: Backup + Prune only). +## PBS has no role-create command and no custom roles, so the next role up is the narrowest that works. +--- apply DatastoreAdmin at the datastore ROOT for the hub user only: +--- remove the DatastorePowerUser line so exactly one entry remains: +--- AFTER: effective permissions at the datastore root: +Privileges with (*) have the propagate flag set + +Path: /datastore/felhom-offsite +- Datastore.Audit (*) +- Datastore.Backup (*) +- Datastore.Modify (*) +- Datastore.Prune (*) +- Datastore.Read (*) +- Datastore.Verify (*) +--- AFTER: the full ACL table (nothing else changed): ++========================+=======================================+===========+=================+ +| ugid | path | propagate | roleid | ++========================+=======================================+===========+=================+ +| felhom@pbs | /datastore/felhom-offsite | 1 | DatastoreAdmin | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup | ++------------------------+---------------------------------------+-----------+-----------------+ +| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup | ++========================+=======================================+===========+=================+ diff --git a/documentation/audits/evidence-backup-promise-2026-09-16/releases.txt b/documentation/audits/evidence-backup-promise-2026-09-16/releases.txt new file mode 100644 index 00000000..bb1da5b4 --- /dev/null +++ b/documentation/audits/evidence-backup-promise-2026-09-16/releases.txt @@ -0,0 +1,5 @@ +## 2026-09-16T15:00:36Z releases + controller 0.244.0 image: pushed (registry tags now 0.241.0 0.242.0 0.243.0 0.244.0) + hub 0.116.0 image: pushed; manifest bumped; ArgoCD sync=Synced health=Healthy; + rollout complete; live image gitea.dooplex.hu/admin/felhom-hub:0.116.0 + commits: felhom-controller 2f8ff24, felhom.eu 3738dfc (+ the manifest bump) diff --git a/scripts/CHANGELOG.md b/scripts/CHANGELOG.md index 4d572017..6764063d 100644 --- a/scripts/CHANGELOG.md +++ b/scripts/CHANGELOG.md @@ -1,3 +1,21 @@ +## ISO v1.28.0 — the console stops showing the pairing code once the box is connected (2026-09-16, R-535) — NOT PUBLISHED + +**The defect, measured on a fresh box 2026-09-16:** 25 minutes after a successful bind AND claim, with +four apps deploying, the physical console still read „a doboz készen áll, és a párosításra vár" with +the pairing code `37S-NFE`, under the line „Ez a képernyő magától frissül — nincs teendő a doboznál". +A volunteer watching the monitor has no way to tell the box is finished, and the screen promises that +waiting will update it. + +- **`felhom-bootstrap.sh`: `print_bound_banner`**, printed the moment the bind delivery lands (the + `200` branch, before `run_direct`). It replaces the pairing screen with „a doboz össze van kötve", + says the setup continues by itself, and says there is nothing left to do at the machine. +- **What it deliberately does NOT say: the dashboard URL.** The one-shot delivery carries the customer + id, the passphrase and the mode — not the domain — so naming an address would mean inventing one. + The address is in the e-mail the customer already has. **The later CLAIM state is still not + reflected on the console**: this unit has exited by then (it hands over to the host install), so a + claim-aware console needs a different owner. R-535 is closed for the measured complaint — the code + stays on screen after binding — and that residue is recorded rather than implied away. + ## ISO v1.27.1 — the FIRST boot is Felhom's too (2026-09-14, R-496) — NOT PUBLISHED **Why 1.27.0 was not enough, measured on its proof install (VM 331, screen s20):** `pvebanner.service` ran diff --git a/scripts/iso/build-felhom-iso.sh b/scripts/iso/build-felhom-iso.sh index 59499aca..bcedd0fb 100755 --- a/scripts/iso/build-felhom-iso.sh +++ b/scripts/iso/build-felhom-iso.sh @@ -48,7 +48,7 @@ set -euo pipefail # does not exist: the ISO is a frozen artifact, while felhom-host-install.sh is fetched at RUN TIME # from the website's git-sync of `main` (R-94/R-110), so whatever version an ISO carries, the script a # box runs is always current. Coupling them would invent a constraint. The claim is corrected instead. -ISO_VERSION="1.27.1" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION, +ISO_VERSION="1.28.0" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION, # which is fetched at run time from main and is not frozen into the image. IMAGE="${FELHOM_ISO_ASSISTANT_IMAGE:-felhom-iso-assistant:trixie}" HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" diff --git a/scripts/iso/felhom-bootstrap.sh b/scripts/iso/felhom-bootstrap.sh index 0aa9c470..99bf3d7b 100644 --- a/scripts/iso/felhom-bootstrap.sh +++ b/scripts/iso/felhom-bootstrap.sh @@ -77,6 +77,27 @@ print_pairing_banner() { } > "$CONSOLE_DEV" 2>/dev/null || printf 'Párosító kód: %s\n' "$code" } +# print_bound_banner (R-535, v1.28.0) — the pairing banner is the LAST thing the console shows, and it +# stays there. Measured 2026-09-16 on a fresh box: 25 minutes after a successful bind AND claim, with +# four apps deploying, the monitor still read „a doboz keszen all, es a parosisara var" with a pairing +# code, under a line promising the screen refreshes itself. A volunteer watching that has no way to +# tell the box is finished, and waiting does not help. +# +# WHAT THIS CAN AND CANNOT SAY. The bind delivery carries the customer id, the passphrase and the mode +# — it does NOT carry the domain (see the emit() block in the 200 branch), so this banner cannot name +# the dashboard URL without inventing one. It says the true thing it knows: the box is connected and +# the setup is running. The address is in the e-mail the customer already has. +print_bound_banner() { + set_console_font + { printf '\n================================================\n' + printf ' Felhom — a doboz össze van kötve. ✔\n\n' + printf ' A beállítás magától folytatódik, ez néhány percig tart.\n' + printf ' A vezérlőpult címét az e-mailben kapott levél tartalmazza.\n\n' + printf ' Ezen a gépen nincs több teendőd.\n' + printf '================================================\n\n' + } > "$CONSOLE_DEV" 2>/dev/null || printf 'A doboz össze van kötve.\n' +} + # install_felhom_issue (R-496, v1.27.0) — the text above the console login prompt is Felhom's, not # Proxmox's. Measured 2026-09-14 (drill screen s29): the first thing a household read on a fresh box was # `Welcome to the Proxmox Virtual Environment … connect to https://:8006/` — the operator admin UI, @@ -501,6 +522,7 @@ run_pairing() { case "$code" in 200) log "bind DELIVERED — writing credentials to the env and switching to direct install" + print_bound_banner # R-535: replace the pairing code on the console with the truth # Parse the one-shot delivery into shell-safe env assignments (never echo the passphrase). local envtext envtext=$(printf '%s' "$body" | python3 -c '