ISO 1.28.0 source: the console stops showing the pairing code once bound (R-535)
gates / gates (push) Successful in 20s
gates / gates (push) Successful in 20s
Measured 2026-09-16: 25 minutes after a successful bind AND claim the console still showed the pairing code under a line promising the screen refreshes itself. print_bound_banner is printed the moment the bind delivery lands. It does NOT name the dashboard URL: the one-shot delivery carries the customer id, passphrase and mode, not the domain, so naming an address would mean inventing one. The residue — the console still does not reflect the later CLAIM, because this unit has exited by then — is recorded in the changelog rather than implied away. Not published: the built image needs the release gate and the operator's yes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,31 @@
|
|||||||
|
<stdin>:30: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal in a future version. Use timezone-aware objects to represent datetimes in UTC: datetime.datetime.now(datetime.UTC).
|
||||||
|
## 2026-09-16T15:03:54Z Part B live — enabling the off-site tier for tester-1 through the hub page
|
||||||
|
fields re-sent (values not printed): _csrf, cf_api_token, cf_tunnel_token, customer_id, customer_name, domain, dr_tier, email, git_token, git_username, offsite_box_type, offsite_enabled, offsite_quota_gb, offsite_type, pbsdr_storage_id
|
||||||
|
preserved-not-blanked: cf_api_token, cf_tunnel_token
|
||||||
|
Traceback (most recent call last):
|
||||||
|
File "<stdin>", line 36, in <module>
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 189, in urlopen
|
||||||
|
return opener.open(url, data, timeout)
|
||||||
|
~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 489, in open
|
||||||
|
response = self._open(req, data)
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 506, in _open
|
||||||
|
result = self._call_chain(self.handle_open, protocol, protocol +
|
||||||
|
'_open', req)
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 466, in _call_chain
|
||||||
|
result = func(*args)
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 1348, in http_open
|
||||||
|
return self.do_open(http.client.HTTPConnection, req)
|
||||||
|
~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|
||||||
|
File "/usr/lib/python3.13/urllib/request.py", line 1323, in do_open
|
||||||
|
r = h.getresponse()
|
||||||
|
File "/usr/lib/python3.13/http/client.py", line 1459, in getresponse
|
||||||
|
response.begin()
|
||||||
|
~~~~~~~~~~~~~~^^
|
||||||
|
File "/usr/lib/python3.13/http/client.py", line 336, in begin
|
||||||
|
version, status, reason = self._read_status()
|
||||||
|
~~~~~~~~~~~~~~~~~^^
|
||||||
|
File "/usr/lib/python3.13/http/client.py", line 305, in _read_status
|
||||||
|
raise RemoteDisconnected("Remote end closed connection without"
|
||||||
|
" response")
|
||||||
|
http.client.RemoteDisconnected: Remote end closed connection without response
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
## 2026-09-16T14:57:56Z ep0 ACL BEFORE (read-only) — scope: the hub's tenantsync auth-id only
|
||||||
|
--- all ACL entries:
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
|
| ugid | path | propagate | roleid |
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
|
--- users/tokens:
|
||||||
|
+============+========+========+===========+==========+=======+===============================================+
|
||||||
|
| userid | enable | expire | firstname | lastname | email | comment |
|
||||||
|
+============+========+========+===========+==========+=======+===============================================+
|
||||||
|
| felhom@pbs | 1 | never | | | | offsite tenancy (per-customer privsep tokens) |
|
||||||
|
+------------+--------+--------+-----------+----------+-------+-----------------------------------------------+
|
||||||
|
| root@pam | 1 | never | | | | Superuser |
|
||||||
|
+============+========+========+===========+==========+=======+===============================================+
|
||||||
|
--- roles that carry Datastore.Modify:
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
## 2026-09-16T15:03:10Z Part C.1 — the grant, narrowest role FIRST, measured at every step
|
||||||
|
--- BEFORE: effective permissions of felhom@pbs at the datastore ROOT (where R-534 failed):
|
||||||
|
Privileges with (*) have the propagate flag set
|
||||||
|
|
||||||
|
--- try the NARROWER role first: DatastorePowerUser
|
||||||
|
Privileges with (*) have the propagate flag set
|
||||||
|
|
||||||
|
Path: /datastore/felhom-offsite
|
||||||
|
- Datastore.Backup (*)
|
||||||
|
- Datastore.Prune (*)
|
||||||
|
## 2026-09-16T15:03:42Z DatastorePowerUser does NOT carry Datastore.Modify (measured above: Backup + Prune only).
|
||||||
|
## PBS has no role-create command and no custom roles, so the next role up is the narrowest that works.
|
||||||
|
--- apply DatastoreAdmin at the datastore ROOT for the hub user only:
|
||||||
|
--- remove the DatastorePowerUser line so exactly one entry remains:
|
||||||
|
--- AFTER: effective permissions at the datastore root:
|
||||||
|
Privileges with (*) have the propagate flag set
|
||||||
|
|
||||||
|
Path: /datastore/felhom-offsite
|
||||||
|
- Datastore.Audit (*)
|
||||||
|
- Datastore.Backup (*)
|
||||||
|
- Datastore.Modify (*)
|
||||||
|
- Datastore.Prune (*)
|
||||||
|
- Datastore.Read (*)
|
||||||
|
- Datastore.Verify (*)
|
||||||
|
--- AFTER: the full ACL table (nothing else changed):
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
|
| ugid | path | propagate | roleid |
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite | 1 | DatastoreAdmin |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
||||||
|
+------------------------+---------------------------------------+-----------+-----------------+
|
||||||
|
| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
||||||
|
+========================+=======================================+===========+=================+
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
## 2026-09-16T15:00:36Z releases
|
||||||
|
controller 0.244.0 image: pushed (registry tags now 0.241.0 0.242.0 0.243.0 0.244.0)
|
||||||
|
hub 0.116.0 image: pushed; manifest bumped; ArgoCD sync=Synced health=Healthy;
|
||||||
|
rollout complete; live image gitea.dooplex.hu/admin/felhom-hub:0.116.0
|
||||||
|
commits: felhom-controller 2f8ff24, felhom.eu 3738dfc (+ the manifest bump)
|
||||||
@@ -1,3 +1,21 @@
|
|||||||
|
## ISO v1.28.0 — the console stops showing the pairing code once the box is connected (2026-09-16, R-535) — NOT PUBLISHED
|
||||||
|
|
||||||
|
**The defect, measured on a fresh box 2026-09-16:** 25 minutes after a successful bind AND claim, with
|
||||||
|
four apps deploying, the physical console still read „a doboz készen áll, és a párosításra vár" with
|
||||||
|
the pairing code `37S-NFE`, under the line „Ez a képernyő magától frissül — nincs teendő a doboznál".
|
||||||
|
A volunteer watching the monitor has no way to tell the box is finished, and the screen promises that
|
||||||
|
waiting will update it.
|
||||||
|
|
||||||
|
- **`felhom-bootstrap.sh`: `print_bound_banner`**, printed the moment the bind delivery lands (the
|
||||||
|
`200` branch, before `run_direct`). It replaces the pairing screen with „a doboz össze van kötve",
|
||||||
|
says the setup continues by itself, and says there is nothing left to do at the machine.
|
||||||
|
- **What it deliberately does NOT say: the dashboard URL.** The one-shot delivery carries the customer
|
||||||
|
id, the passphrase and the mode — not the domain — so naming an address would mean inventing one.
|
||||||
|
The address is in the e-mail the customer already has. **The later CLAIM state is still not
|
||||||
|
reflected on the console**: this unit has exited by then (it hands over to the host install), so a
|
||||||
|
claim-aware console needs a different owner. R-535 is closed for the measured complaint — the code
|
||||||
|
stays on screen after binding — and that residue is recorded rather than implied away.
|
||||||
|
|
||||||
## ISO v1.27.1 — the FIRST boot is Felhom's too (2026-09-14, R-496) — NOT PUBLISHED
|
## ISO v1.27.1 — the FIRST boot is Felhom's too (2026-09-14, R-496) — NOT PUBLISHED
|
||||||
|
|
||||||
**Why 1.27.0 was not enough, measured on its proof install (VM 331, screen s20):** `pvebanner.service` ran
|
**Why 1.27.0 was not enough, measured on its proof install (VM 331, screen s20):** `pvebanner.service` ran
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ set -euo pipefail
|
|||||||
# does not exist: the ISO is a frozen artifact, while felhom-host-install.sh is fetched at RUN TIME
|
# does not exist: the ISO is a frozen artifact, while felhom-host-install.sh is fetched at RUN TIME
|
||||||
# from the website's git-sync of `main` (R-94/R-110), so whatever version an ISO carries, the script a
|
# from the website's git-sync of `main` (R-94/R-110), so whatever version an ISO carries, the script a
|
||||||
# box runs is always current. Coupling them would invent a constraint. The claim is corrected instead.
|
# box runs is always current. Coupling them would invent a constraint. The claim is corrected instead.
|
||||||
ISO_VERSION="1.27.1" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION,
|
ISO_VERSION="1.28.0" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION,
|
||||||
# which is fetched at run time from main and is not frozen into the image.
|
# which is fetched at run time from main and is not frozen into the image.
|
||||||
IMAGE="${FELHOM_ISO_ASSISTANT_IMAGE:-felhom-iso-assistant:trixie}"
|
IMAGE="${FELHOM_ISO_ASSISTANT_IMAGE:-felhom-iso-assistant:trixie}"
|
||||||
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
|||||||
@@ -77,6 +77,27 @@ print_pairing_banner() {
|
|||||||
} > "$CONSOLE_DEV" 2>/dev/null || printf 'Párosító kód: %s\n' "$code"
|
} > "$CONSOLE_DEV" 2>/dev/null || printf 'Párosító kód: %s\n' "$code"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# print_bound_banner (R-535, v1.28.0) — the pairing banner is the LAST thing the console shows, and it
|
||||||
|
# stays there. Measured 2026-09-16 on a fresh box: 25 minutes after a successful bind AND claim, with
|
||||||
|
# four apps deploying, the monitor still read „a doboz keszen all, es a parosisara var" with a pairing
|
||||||
|
# code, under a line promising the screen refreshes itself. A volunteer watching that has no way to
|
||||||
|
# tell the box is finished, and waiting does not help.
|
||||||
|
#
|
||||||
|
# WHAT THIS CAN AND CANNOT SAY. The bind delivery carries the customer id, the passphrase and the mode
|
||||||
|
# — it does NOT carry the domain (see the emit() block in the 200 branch), so this banner cannot name
|
||||||
|
# the dashboard URL without inventing one. It says the true thing it knows: the box is connected and
|
||||||
|
# the setup is running. The address is in the e-mail the customer already has.
|
||||||
|
print_bound_banner() {
|
||||||
|
set_console_font
|
||||||
|
{ printf '\n================================================\n'
|
||||||
|
printf ' Felhom — a doboz össze van kötve. ✔\n\n'
|
||||||
|
printf ' A beállítás magától folytatódik, ez néhány percig tart.\n'
|
||||||
|
printf ' A vezérlőpult címét az e-mailben kapott levél tartalmazza.\n\n'
|
||||||
|
printf ' Ezen a gépen nincs több teendőd.\n'
|
||||||
|
printf '================================================\n\n'
|
||||||
|
} > "$CONSOLE_DEV" 2>/dev/null || printf 'A doboz össze van kötve.\n'
|
||||||
|
}
|
||||||
|
|
||||||
# install_felhom_issue (R-496, v1.27.0) — the text above the console login prompt is Felhom's, not
|
# install_felhom_issue (R-496, v1.27.0) — the text above the console login prompt is Felhom's, not
|
||||||
# Proxmox's. Measured 2026-09-14 (drill screen s29): the first thing a household read on a fresh box was
|
# Proxmox's. Measured 2026-09-14 (drill screen s29): the first thing a household read on a fresh box was
|
||||||
# `Welcome to the Proxmox Virtual Environment … connect to https://<ip>:8006/` — the operator admin UI,
|
# `Welcome to the Proxmox Virtual Environment … connect to https://<ip>:8006/` — the operator admin UI,
|
||||||
@@ -501,6 +522,7 @@ run_pairing() {
|
|||||||
case "$code" in
|
case "$code" in
|
||||||
200)
|
200)
|
||||||
log "bind DELIVERED — writing credentials to the env and switching to direct install"
|
log "bind DELIVERED — writing credentials to the env and switching to direct install"
|
||||||
|
print_bound_banner # R-535: replace the pairing code on the console with the truth
|
||||||
# Parse the one-shot delivery into shell-safe env assignments (never echo the passphrase).
|
# Parse the one-shot delivery into shell-safe env assignments (never echo the passphrase).
|
||||||
local envtext
|
local envtext
|
||||||
envtext=$(printf '%s' "$body" | python3 -c '
|
envtext=$(printf '%s' "$body" | python3 -c '
|
||||||
|
|||||||
Reference in New Issue
Block a user