hub v0.130.0: OS updates, guest fast lane — rings, per-box switch, OS releases approved from ring 0, os-report, os_update desired block

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 10:56:39 +02:00
parent 6ed79cd2e9
commit c5f91174f6
25 changed files with 1338 additions and 2 deletions
@@ -0,0 +1,30 @@
node=demo-hp
libc6 2.41-12+deb13u3
adventurelog Up 38 minutes (healthy)
adventurelog-frontend Up 38 minutes (healthy)
adventurelog-postgres Up 38 minutes (healthy)
bentopdf Up 38 minutes (healthy)
bookstack Up 38 minutes (healthy)
bookstack-db Up 38 minutes (healthy)
calibre-web Up 38 minutes (healthy)
cloudflared Up 38 minutes
docmost Up 38 minutes (healthy)
docmost-postgres Up 38 minutes (healthy)
docmost-redis Up 38 minutes (healthy)
felhom-controller Up 38 minutes (healthy)
filebrowser Up 37 minutes (healthy)
kimai Up 38 minutes (healthy)
kimai-db Up 38 minutes (healthy)
opengist Up 38 minutes (healthy)
paperless-postgres Up 38 minutes (healthy)
paperless-redis Up 38 minutes (healthy)
paperless-webserver Up 37 minutes (healthy)
privatebin Up 38 minutes (healthy)
romm Up 37 minutes (healthy)
romm-db Up 37 minutes (healthy)
romm-redis Up 37 minutes (healthy)
traefik Up 38 minutes
python3: can't open file '/root/pveapi.py': [Errno 13] Permission denied
POST /nodes/demo-hp/lxc/9201/snapshot: http 200 task exit=snapshot feature is not available seconds=0.1
`-> current You are here!
data 61.90 2.69
@@ -0,0 +1,2 @@
data 61.90 2.69
`-> current You are here!
@@ -0,0 +1,19 @@
# Part A — the snapshot undo (R-837), demo-hp 9201, 2026-10-04 ~10:30 CEST
**Result: a snapshot of a customer guest is NOT possible. The automatic undo is not built (the brief's stop rule).**
- Thin pool before: data 61.90 %, metadata 2.69 % (`A1-snapshot.txt`). After: unchanged (`A2-after.txt`) — nothing was created.
- The agent's token has the rights: role `FelhomAgentGuest` on `/pool/felhom` holds `VM.Snapshot` and
`VM.Snapshot.Rollback`. Called AS THE TOKEN (`POST /nodes/demo-hp/lxc/9201/snapshot`, http 200): the task ends
`snapshot feature is not available` in 0.1 s. As root, `pct snapshot 9201 r837root`: the same.
- Why, from the PVE source: `PVE/AbstractConfig.pm:755-757` dies with that message when
`has_feature('snapshot', …, $snapname eq 'vzdump')` fails; `PVE/LXC/Config.pm:97-110` checks EVERY mount point and
skips non-backup ones ONLY when that last flag is set — i.e. only for the backup's own snapshot named `vzdump`. A
customer guest always carries two host-path binds (`mp8 /mnt/felhom-drives`, `mp9 …/bootstrap`), which have no
snapshot feature. So: rootfs and mp0 are LVM-thin and could snapshot; the guest cannot.
- The nightly whole-guest backup still works in snapshot mode (`create storage snapshot 'vzdump'`, 04:34:55).
- **Rejected, not tried:** naming a snapshot `vzdump` to pass the check — the name is the backup's own and a
collision would break the night's backup; and taking raw LVM thin snapshots of rootfs + mp0 behind PVE's back (a
new mechanism nobody has measured — a STATUS decision, not a session improvisation).
- Steps 2–3 (apply by hand, roll back) were not run: there is nothing to roll back to. 9201 is brought current by the
product's own OS leg in Part G.
@@ -0,0 +1,14 @@
# Red-proof of configs/felhom-os-apply, 2026-10-04: for each refusal code, every `raise Refused("Rx", …)` is replaced by `pass` in a COPY, and the suite is run against the copy.
R1: 7 raise(s) removed -> suite rc=1; failing tests: test_R1_not_owned_by_the_agent, test_R1_path_outside_the_plan_dir, test_R1_symlink; own test(s) failed: YES
R2: 2 raise(s) removed -> suite rc=1; failing tests: test_R2_non_debian_origin_in_the_plan, test_R2_non_debian_origin_in_the_simulation; own test(s) failed: YES
R3: 1 raise(s) removed -> suite rc=1; failing tests: test_R3_slow_lane; own test(s) failed: YES
R4: 1 raise(s) removed -> suite rc=1; failing tests: test_R4_removal; own test(s) failed: YES
R5: 1 raise(s) removed -> suite rc=1; failing tests: test_R5_downgrade_exact; own test(s) failed: YES
R6: 4 raise(s) removed -> suite rc=1; failing tests: test_R6_allow_new_is_slow_lane, test_R6_new_package, test_R6_unlisted_package; own test(s) failed: YES
R7: 7 raise(s) removed -> suite rc=1; failing tests: test_R7_not_downloadable_and_no_snapshot, test_snapshot_does_not_have_it_either; own test(s) failed: YES
R8: 1 raise(s) removed -> suite rc=1; failing tests: test_R8_free_space; own test(s) failed: YES
R9: 2 raise(s) removed -> suite rc=1; failing tests: test_R9_apt_lock_held, test_R9_guest_locked_by_a_backup; own test(s) failed: YES
R10: 4 raise(s) removed -> suite rc=1; failing tests: test_R10_bind_only_in_a_snapshot_section, test_R10_not_running, test_R10_not_the_boxs_own_guest, test_R10_reserved_vmid; own test(s) failed: YES
R11: 9 raise(s) removed -> suite rc=1; failing tests: test_R11_bad_name, test_R11_bad_version_string, test_R11_duplicate; own test(s) failed: YES
R12: 1 raise(s) removed -> suite rc=1; failing tests: test_R12_host_layer; own test(s) failed: YES
R13: 1 raise(s) removed -> suite rc=1; failing tests: test_R13_repair_does_not_fix_it; own test(s) failed: YES
@@ -0,0 +1,35 @@
# agent v0.140.0 OS leg red-proofs, 2026-10-04 (each mutation applied, COMPILES, tests run, reverted; the package result line is printed so a build failure cannot pass as a red-proof)
== mutation: fast-lane
--- FAIL: TestRing0_PlansTheFastLaneOnly (0.00s)
leg_test.go:114: ring-0 plan = [map[name:libc6 origin:Debian version:u4] map[name:openssl origin:Debian-Security version:u3] map[name:docker-ce origin:Debian version:29.8]], want libc6 + openssl only
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.199s
== mutation: switch
--- FAIL: TestSwitchOff_ReportsOnly (0.00s)
leg_test.go:174: rep={RunID:20261004T040000Z Trigger:night Mode:inventory Ring:0 ReleaseID:ring0-20261004T040000Z Outcome: Healthy:true HealthReason: VMID:9201 Upgraded:[] Installed:[{Name:libc6 Version:u3 Origin:Deb
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.216s
== mutation: health-containers
--- FAIL: TestHealth_FailsAfterTheWait (0.00s)
leg_test.go:187: rep = {RunID:20261004T040000Z Trigger:night Mode:apply Ring:0 ReleaseID:ring0-20261004T040000Z Outcome:health_failed Healthy:false HealthReason:app was healthy and is VMID:9201 Upgraded:[{Name:libc6
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.206s
== mutation: health-controller
ok gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.197s
== mutation: once-per-night
--- FAIL: TestOncePerNight (0.00s)
leg_test.go:235: a second night run in the same night ran: {RunID:20261004T040000Z Trigger:night Mode:apply Ring:0 ReleaseID:ring0-20261004T040000Z Outcome:applied Healthy:true HealthReason: VMID:9201 Upgraded:[{Name
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.203s
== mutation: ring1-uses-release
--- FAIL: TestRing1_InstallsExactlyTheRelease (0.00s)
leg_test.go:142: ring-1 plan = map[lane:fast layer:guest mode:apply packages:[map[name:libc6 origin:Debian version:u4-approvedx]] release_id:os-1 snapshot:20261004T080000Z vmid:9201]
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.195s
== reverted
ok gitea.dooplex.hu/admin/felhom-agent/internal/osupdate (cached)
== mutation: health-controller (after adding the case "only the controller differs")
--- FAIL: TestHealthVerdict (0.00s)
leg_test.go:225: only the controller differs: got true (), want false
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/osupdate 0.197s
== RP (local API hook): run the leg AFTER the gate is released
afterbackup_test.go:55: the heavy-op gate was free while the leg ran — a restore-test could overlap it
FAIL gitea.dooplex.hu/admin/felhom-agent/internal/localapi 0.563s
== RP (local API hook): run the leg after a FAILED backup too
afterbackup_test.go:60: the leg ran after a FAILED backup: [8200]
FAIL (recorded from the run above)
@@ -0,0 +1,18 @@
# hub v0.130.0 approval-rule red-proofs, 2026-10-04 (each mutation applied, tests run, reverted)
== mutation: age
--- FAIL: TestApproval_WaitHealthyAndOneNight (0.03s)
service_test.go:65: fresh set approved or wrong reason: {Fingerprint:8415f8a9ec63c815 FirstSeen:2026-10-04 12:00:00 +0000 UTC Packages:2 Waiting:hp has 0 of 1 night run(s) since the set was first seen}
== mutation: healthy
--- FAIL: TestApproval_UnhealthyRunBlocks (0.03s)
service_test.go:104: approved although a ring-0 run was not healthy: {Fingerprint:5088e82274a46ef8 FirstSeen:2026-10-04 12:00:00 +0000 UTC Packages:1 Waiting:}
== mutation: nights
--- FAIL: TestApproval_WaitHealthyAndOneNight (0.03s)
service_test.go:70: approved without a night run: {Fingerprint:8415f8a9ec63c815 FirstSeen:2026-10-04 12:00:00 +0000 UTC Packages:2 Waiting:}
== mutation: origin
--- FAIL: TestCandidate_OnlyDebianOrigins (0.03s)
service_test.go:140: a Docker package entered the candidate
== mutation: agree
--- FAIL: TestCandidate_DisagreementLeftOut (0.03s)
service_test.go:128: candidate = map[curl:{Name:curl Version:8.14.1-2+deb13u5 Origin:Debian} libc6:{Name:libc6 Version:2.41-12+deb13u4 Origin:Debian}]
== reverted
ok gitea.dooplex.hu/admin/felhom-hub/internal/osupdates (cached)
@@ -0,0 +1,11 @@
# controller R-726 (decision 78) red-proof, 2026-10-04
== mutation: drop the first-night condition
--- FAIL: TestR726_ReturningHouseholdFirstNightSetsAside (0.00s)
offbox_orphan_test.go:204: the returning household's box stayed orphaned
FAIL gitea.dooplex.hu/admin/felhom-controller/internal/backup 0.014s
== mutation: first night = any claimed box (ignore LastSuccess)
--- FAIL: TestOffbox_OrphanDetection_Claimed (10.10s)
offbox_orphan_test.go:81: expected exactly one offbox_repo_orphaned event, got [offbox_repo_orphaned offbox_repo_orphaned]
FAIL gitea.dooplex.hu/admin/felhom-controller/internal/backup 10.113s
== reverted
ok gitea.dooplex.hu/admin/felhom-controller/internal/backup 0.015s
@@ -0,0 +1,6 @@
# controller R-838 red-proof, 2026-10-04
== mutation: a running file browser is left alone again (the pre-fix behaviour)
infra_tunnel_test.go:275: compose after the move:
FAIL gitea.dooplex.hu/admin/felhom-controller/internal/stacks 0.009s
== reverted
ok gitea.dooplex.hu/admin/felhom-controller/internal/stacks 0.011s