diff --git a/scripts/CHANGELOG.md b/scripts/CHANGELOG.md index f3654f0d..937d6efe 100644 --- a/scripts/CHANGELOG.md +++ b/scripts/CHANGELOG.md @@ -1,3 +1,12 @@ +## felhom-host-install.sh 1.29.0 — installs the OS-update wrapper (2026-10-04, `11-os-updates.md` §8 step 2) + +- Step 5 fetches `configs/felhom-os-apply` from the pinned agent tag and installs it as + `/usr/local/sbin/felhom-os-apply` (0755 root:root, python3 syntax check first). The FELHOM_OSAPPLY sudoers line rides + the canonical sudoers fetch from the same tag. An agent older than 0.140.0 carries neither, so a missing wrapper is + SKIPPED with a warning (OS updates stay off), never fatal. `--uninstall` removes it. +- **Existing boxes get neither the wrapper nor the sudoers line from this** — the installer runs on a new box; the + agent's signed self-update replaces only the binary (R-840). + ## one-register reads suffix ids and splits on pipes outside code (2026-10-03, backlog triage, Part D) - `one_register_gate.py`: the id pattern was `R-(\d+)`, so ROADMAP rows R-27b, R-27c and R-50b were never read; diff --git a/scripts/felhom-host-install.sh b/scripts/felhom-host-install.sh index 65cccef3..1f0fc7a2 100644 --- a/scripts/felhom-host-install.sh +++ b/scripts/felhom-host-install.sh @@ -184,7 +184,7 @@ set -euo pipefail -SCRIPT_VERSION="1.28.0" # the SINGLE version source (F-1): -h and the run banners follow it. +SCRIPT_VERSION="1.29.0" # the SINGLE version source (F-1): -h and the run banners follow it. # The hub used to carry a copy for its Setup tab; R-94 DELETED it # (2026-08-02) because the hub cannot know which version a box runs — # the Setup command fetches this script at run time. scripts/ @@ -1157,6 +1157,7 @@ run_uninstall() { if [[ -f /usr/local/sbin/felhom-mkfs-guarded ]]; then run rm -f /usr/local/sbin/felhom-mkfs-guarded; else log_skip " felhom-mkfs-guarded already absent"; fi if [[ -f /usr/local/sbin/felhom-pbs-apply ]]; then run rm -f /usr/local/sbin/felhom-pbs-apply; else log_skip " felhom-pbs-apply already absent"; fi if [[ -f /usr/local/sbin/felhom-backup-target-apply ]]; then run rm -f /usr/local/sbin/felhom-backup-target-apply; else log_skip " felhom-backup-target-apply already absent"; fi + if [[ -f /usr/local/sbin/felhom-os-apply ]]; then run rm -f /usr/local/sbin/felhom-os-apply; else log_skip " felhom-os-apply already absent"; fi if [[ -f /var/lib/vz/snippets/felhom-guest-hook.sh ]]; then run rm -f /var/lib/vz/snippets/felhom-guest-hook.sh; fi local dconf _dnsmasq_touched=false for dconf in /etc/dnsmasq.d/felhom-*.conf; do @@ -2372,6 +2373,28 @@ step_agent_install() { log_success " installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)" fi + # OS updates, guest fast lane (agent >= 0.140.0, `11-os-updates.md` §8 step 2): the root wrapper behind the + # FELHOM_OSAPPLY sudoers alias. It ships in the AGENT repo at the same pinned tag as the sudoers file, so an older + # pinned agent has neither the wrapper nor the alias — a missing file is therefore SKIPPED with a warning (OS + # updates stay off), never fatal. Python 3 (stdlib only), syntax-checked before install, 0755 root:root. + if $DRY_RUN; then + log_dry "fetch configs/felhom-os-apply (if the pinned agent carries it) ; python3 syntax check ; install 0755 -> /usr/local/sbin/felhom-os-apply" + else + local ostmp; ostmp=$(mktemp -t felhom-os.XXXXXX) + local -a _osauth; _git_auth_args _osauth + if curl -fsS "${_osauth[@]}" -o "$ostmp" \ + "$GITEA_BASE/$GITEA_OWNER/$AGENT_REPO/raw/tag/v$ART_AGENT_VER/configs/felhom-os-apply" 2>/dev/null \ + && [[ -s "$ostmp" ]]; then + python3 -c 'import ast,sys; ast.parse(open(sys.argv[1]).read())' "$ostmp" \ + || { rm -f "$ostmp"; die "fetched felhom-os-apply failed the python3 syntax check — refusing to install"; } + install -m 0755 -o root -g root "$ostmp" /usr/local/sbin/felhom-os-apply + log_success " installed /usr/local/sbin/felhom-os-apply (0755, the guarded OS-update path)" + else + log_warn " agent v$ART_AGENT_VER carries no felhom-os-apply (older than 0.140.0) — OS updates stay off on this box" + fi + rm -f "$ostmp" + fi + # Sudoers — fetch the canonical file, validate with visudo -cf BEFORE installing (0440 root:root). if $DRY_RUN; then log_dry "fetch configs/felhom-agent.sudoers ; visudo -cf ; install 0440 -> $AGENT_SUDOERS"