ISO 1.29.0 source + an English download page (R-559 slice 4, source only)
gates / gates (push) Successful in 23s

THE IMAGE IS NOT BUILT AND NOT PUBLISHED BY THIS COMMIT. Publishing to
iso.felhom.eu is public and irreversible and its runbook requires a proof
install on BOTH menu entries plus the 16-criterion gate run against the exact
uploaded bytes. That is the operator's step. The download pages therefore still
name 1.28.0 - the image that is actually published - and a new site gate
refuses the two pages naming different files or hashes.

Three texts a person meets before any dashboard become bilingual: Hungarian
block first, byte for byte as before, then English, inside the same frame. The
pairing banner, the bound banner, /etc/issue (and the postinst's byte-coupled
copy), plus an English half on the GRUB entries.

The Hungarian is a GOLDEN, not a grep: test/golden/*.hu.txt were captured from
the script at 183727db9c before one English line existed, and the harness
asserts each banner's first N lines are exactly the golden. Red-proofed by one
changed byte, by an "a" planted in the English block, and by an over-wide line.

R-586, found on the way in: running the harness UNCHANGED at the base commit
failed two R-496 checks. The script paints with `>`, which truncates a FILE but
is a no-op on a console device; ISO 1.28.0's new bound banner (c033b3b) paints
straight after the pairing one and wiped it before the check read it. c033b3b
did not touch the harness, and nobody saw it because the harness is in no gate
and no CI run. Fixed with a FIFO; production code untouched. The harness being
ungated is still open.

The release gate's G16 required every Felhom string to be Hungarian and would
have STOPPED this publication. Operator ruling 1b of 2026-09-17 supersedes that
scope, so G16 is rewritten rather than waived: Hungarian FIRST, pinned by the
golden, each secret named once per language.

letoltes.html changes by four lines only. The English link is not in the nav -
the nav is a shared block site_gates.py pins across every page, and the gate
convicted the first attempt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-18 17:40:29 +02:00
parent 183727db9c
commit eb1ae37095
18 changed files with 445 additions and 21 deletions
+48
View File
@@ -1,3 +1,51 @@
## ISO 1.29.0 source — the box's own screen speaks English too (2026-09-18, R-559)
**Source only. The image is NOT built or published by this commit** — see the release note at the end.
Three texts a person meets before they ever see a dashboard become **bilingual**: Hungarian block
first, byte for byte as before, then one blank line, then English, inside the same frame.
- `print_pairing_banner`, `print_bound_banner`, `install_felhom_issue` — and the `postinst`'s copy of
the issue text, which is byte-coupled to the bootstrap's (the harness `cmp`s them).
- The one-line fallbacks carry both: `Párosító kód / Pairing code: %s`.
- The GRUB entries gain an English half: `Felhom telepítés / Install Felhom` (and the text-mode twin).
`iso-repack.sh:405` greps a substring, so it still matches.
- `/etc/issue` stays ASCII in its English half for the same reason the Hungarian half avoids ő/ű: the
login screen is painted before the Latin-2 console font loads.
**The Hungarian is a GOLDEN, not a grep.** `test/golden/{pairing,bound,issue}.hu.txt` were captured
from the script at `183727db9c44` before one English line existed; the harness asserts each banner's
first N lines are exactly the golden. A grep for one phrase would pass a banner whose other nine lines
had been reworded. Red-proofed by a single changed byte.
Also asserted per banner: the English block exists, carries **no Hungarian letter** (with the
Hungarian block as the positive control), and **every line fits 80 columns** — the console's width,
counted in characters, because the Hungarian lines are multi-byte and `wc -c` would convict them
wrongly. The pairing code appears once per language; the bound banner carries none.
### A harness defect found on the way in, and it had been red for two days (R-586)
Running the harness UNCHANGED at the base commit failed two R-496 checks. The script paints with
`> "$CONSOLE_DEV"`; on a real console that is a device and truncation is a no-op, but the harness
pointed it at a plain FILE, so each banner erased the one before it. ISO 1.28.0's new bound banner
(commit `c033b3b`) paints right after the pairing banner — and did not touch the harness. **Nobody
saw it because the harness is in no gate and no CI run.** The harness now uses a FIFO, which restores
device semantics; production code is untouched.
### The release gate had to be amended, not waived
`iso-release-gate.md` **G16** read *"every Felhom-authored string on the volunteer's path is
Hungarian — PASS = no English sentence"*. It encoded the 2026-07-31 scope and would have **stopped
this publication**. Operator ruling **1b of 2026-09-17** supersedes that scope ("the console banner
and the download page ARE in scope"). G16 is rewritten: Hungarian FIRST, pinned by the golden, each
secret named once per language. What it protects is now stronger, not weaker.
**RELEASE STATE: the image is not built and not published.** `ISO_VERSION` is `1.29.0` in the build
script and the source is ready, but publishing to `iso.felhom.eu` is public and irreversible and its
runbook requires a proof install on **both** menu entries plus the 16-criterion gate against the exact
uploaded bytes. That is the operator's step. The download pages therefore still name **1.28.0** — the
image that is actually published — and a new gate refuses them naming different things.
## i18n inventory + wire-contract allowlist entry (2026-09-17, localisation starter)
- **`i18n_inventory.py` (new, a survey — never fails a build).** Counts every customer-visible
+1 -1
View File
@@ -48,7 +48,7 @@ set -euo pipefail
# does not exist: the ISO is a frozen artifact, while felhom-host-install.sh is fetched at RUN TIME
# from the website's git-sync of `main` (R-94/R-110), so whatever version an ISO carries, the script a
# box runs is always current. Coupling them would invent a constraint. The claim is corrected instead.
ISO_VERSION="1.28.0" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION,
ISO_VERSION="1.29.0" # the ISO's own version. INDEPENDENT of felhom-host-install.sh's SCRIPT_VERSION,
# which is fetched at run time from main and is not frozen into the image.
IMAGE="${FELHOM_ISO_ASSISTANT_IMAGE:-felhom-iso-assistant:trixie}"
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
+17 -4
View File
@@ -72,9 +72,15 @@ print_pairing_banner() {
printf ' ezt a kódot és a Tulajdonosi jelmondatodat\n'
printf ' (az 5 szót a Felhom üzemeltetőjétől kaptad).\n\n'
printf ' Ez a képernyő magától frissül — nincs teendő a\n'
printf ' doboznál, és nyugodtan itt hagyhatod bekapcsolva.\n'
printf ' doboznál, és nyugodtan itt hagyhatod bekapcsolva.\n\n'
printf ' Pairing code: %s\n\n' "$code"
printf ' Open the link from your e-mail and enter this code\n'
printf ' together with your Owner passphrase (the 5 words you\n'
printf ' received from your Felhom operator).\n\n'
printf ' This screen refreshes itself. There is nothing to do\n'
printf ' at the box; you can leave it switched on.\n'
printf '================================================\n\n'
} > "$CONSOLE_DEV" 2>/dev/null || printf 'Párosító kód: %s\n' "$code"
} > "$CONSOLE_DEV" 2>/dev/null || printf 'Párosító kód / Pairing code: %s\n' "$code"
}
# print_bound_banner (R-535, v1.28.0) — the pairing banner is the LAST thing the console shows, and it
@@ -93,9 +99,13 @@ print_bound_banner() {
printf ' Felhom — a doboz össze van kötve. ✔\n\n'
printf ' A beállítás magától folytatódik, ez néhány percig tart.\n'
printf ' A vezérlőpult címét az e-mailben kapott levél tartalmazza.\n\n'
printf ' Ezen a gépen nincs több teendőd.\n'
printf ' Ezen a gépen nincs több teendőd.\n\n'
printf ' Felhom — the box is linked.\n\n'
printf ' Setup carries on by itself; this takes a few minutes.\n'
printf ' Your dashboard address is in the e-mail you received.\n\n'
printf ' There is nothing left to do on this machine.\n'
printf '================================================\n\n'
} > "$CONSOLE_DEV" 2>/dev/null || printf 'A doboz össze van kötve.\n'
} > "$CONSOLE_DEV" 2>/dev/null || printf 'A doboz össze van kötve. / The box is linked.\n'
}
# install_felhom_issue (R-496, v1.27.0) — the text above the console login prompt is Felhom's, not
@@ -122,6 +132,9 @@ install_felhom_issue() {
printf ' Felhom otthoni szerver\n\n'
printf ' Ezen a gépen most nincs dolgod, és bejelentkezni sem kell.\n'
printf ' A beállításhoz kövesd a Felhomtól kapott útmutatót.\n\n'
printf ' Felhom home server\n\n'
printf ' There is nothing to do on this machine, and no need to log in.\n'
printf ' Follow the guide you received from Felhom.\n\n'
} > "$tmp" 2>/dev/null && mv -f "$tmp" "$ISSUE_FILE" 2>/dev/null; then
log "console: $ISSUE_FILE is the Felhom text (no admin URL)"
else
+2 -2
View File
@@ -65,14 +65,14 @@ set timeout_style=menu
set timeout=15
set default=0
menuentry 'Felhom telepítés' --class felhom --class os {
menuentry 'Felhom telepítés / Install Felhom' --class felhom --class os {
echo 'A Felhom telepítése indul — válassza ki a lemezt a telepítőben...'
@@LINUX_GFX@@
echo 'Rendszerbetöltő betöltése...'
@@INITRD@@
}
menuentry 'Felhom telepítés (szöveges mód)' --class felhom --class os {
menuentry 'Felhom telepítés (szöveges mód) / Install Felhom (text mode)' --class felhom --class os {
echo 'A Felhom telepítése indul szöveges módban...'
@@LINUX_TUI@@
echo 'Rendszerbetöltő betöltése...'
+1 -1
View File
@@ -68,7 +68,7 @@ set timeout_style=menu
set timeout=5
set default=0
menuentry 'Felhom telepítés' --class felhom --class os {
menuentry 'Felhom telepítés / Install Felhom' --class felhom --class os {
echo 'A Felhom telepítése indul...'
@@LINUX@@
echo 'Rendszerbetöltő betöltése...'
+3
View File
@@ -42,6 +42,9 @@ if [ "${1:-}" = "configure" ]; then
printf ' Felhom otthoni szerver\n\n'
printf ' Ezen a gépen most nincs dolgod, és bejelentkezni sem kell.\n'
printf ' A beállításhoz kövesd a Felhomtól kapott útmutatót.\n\n'
printf ' Felhom home server\n\n'
printf ' There is nothing to do on this machine, and no need to log in.\n'
printf ' Follow the guide you received from Felhom.\n\n'
} > /etc/issue.felhom-tmp 2>/dev/null && mv -f /etc/issue.felhom-tmp /etc/issue 2>/dev/null; then
echo "felhom-bootstrap postinst: /etc/issue is the Felhom text" >> "$LOG" 2>&1 || true
else
+84 -2
View File
@@ -26,6 +26,32 @@ FAKE=/work/fakebin; rm -rf "$FAKE"; mkdir -p "$FAKE"
CALLS=/work/curl.log
export PATH="$FAKE:$PATH"
fail=0
# --- console capture (R-586) -------------------------------------------------------------------
#
# THE SCRIPT WRITES EACH BANNER WITH `>`, WHICH TRUNCATES A FILE. On a real console that is a
# character device and truncation is a no-op — every paint simply appears. Pointed at a plain FILE,
# as this harness did until now, each banner ERASES the one before it.
#
# That is not hypothetical: ISO 1.28.0 (commit c033b3b, R-535) added print_bound_banner, which paints
# right after the pairing banner in the same invocation. From that commit onward
# `grep 'Párosító kód' /work/console.out` looked for a banner the NEXT paint had already wiped, and
# the two R-496 checks below have been FAILING ever since. Nobody saw it: this harness is not in CI
# and is not in repo_gates.py, so it runs only when someone runs it.
#
# A FIFO restores the device semantics: opening it with `>` truncates nothing, and a background
# reader accumulates every paint. `console_reset` starts a fresh capture per scenario.
CONSOLE_FIFO=/work/console.fifo
console_reset() {
[ -n "${CONSOLE_CAT_PID:-}" ] && kill "$CONSOLE_CAT_PID" 2>/dev/null
rm -f /work/console.out "$CONSOLE_FIFO"
mkfifo "$CONSOLE_FIFO"
# The reader holds the FIFO open so the script's short-lived `>` opens never block or EOF it.
( while :; do cat "$CONSOLE_FIFO" >> /work/console.out 2>/dev/null || true; done ) &
CONSOLE_CAT_PID=$!
: > /work/console.out
}
console_settle() { sleep 0.2; } # let the reader drain before a check reads the file
say() { echo "TEST: $*"; }
check() { if eval "$2"; then echo " ok: $1"; else echo " FAIL: $1"; fail=1; fi; }
@@ -200,12 +226,68 @@ FELHOM_HUB_URL=https://hub.example
ENV
echo 204 > /work/poll-mode
echo 3 > /work/sleep.flip # after 3 in-script waits the hub "binds" (poll flips to 200)
rm -f /work/console.out
env FELHOM_CONSOLE_DEV=/work/console.out FELHOM_ISSUE_FILE=/work/issue bash "$BSTRAP"; rc=$?
console_reset
env FELHOM_CONSOLE_DEV="$CONSOLE_FIFO" FELHOM_ISSUE_FILE=/work/issue bash "$BSTRAP"; rc=$?
console_settle
# R-496: the pairing banner names the secret the way the self-bind mail and page do (R-323).
check "R-496: banner painted to the console seam" "grep -q 'Párosító kód' /work/console.out"
check "R-496: banner names the Tulajdonosi jelmondat" "grep -q 'Tulajdonosi jelmondat' /work/console.out"
check "R-496: banner no longer says 'jelszavad'" "! grep -q 'jelszavad' /work/console.out"
# ===== R-559 (slice 4): the console is BILINGUAL — Hungarian frozen, English real, both fit 80 cols =====
#
# THE HUNGARIAN IS A GOLDEN, NOT A GREP. /work/golden/*.hu.txt were captured from the script at
# 183727db9c44, before a single English line was added. A grep for one phrase would pass a banner
# whose other nine lines had been reworded; the golden is the whole block, byte for byte.
#
# The golden is the banner WITHOUT its closing frame line, because the English block is appended
# INSIDE the frame and the closing line therefore moves down. So the assertion is: the banner's first
# N lines are exactly the golden, where N is the golden's own length.
split_banners() {
# $1 = the console capture. Writes /work/b.pairing and /work/b.bound, each the whole banner from
# its opening frame line to its closing one inclusive. Frames are counted, not guessed: the
# capture holds exactly two banners and therefore four frame lines.
awk -v out=/work/b '
/^=+$/ { f++
name = (f<=2 ? "pairing" : "bound")
print > (out "." name)
next }
{ if (f==1 || f==3) print > (out "." (f==1 ? "pairing" : "bound")) }
' "$1"
}
hu_head_matches() { # $1 = banner file, $2 = golden file
local n; n=$(wc -l < "$2")
head -n "$n" "$1" | diff -u "$2" - >/dev/null
}
split_banners /work/console.out
for b in pairing bound; do
check "R-559: the $b banner's Hungarian block is byte-identical to the golden" \
"hu_head_matches /work/b.$b /work/golden/$b.hu.txt"
# The English block is everything after the Hungarian block, above the closing frame.
n=$(wc -l < "/work/golden/$b.hu.txt")
tail -n +$((n+1)) "/work/b.$b" | grep -v '^={40,}$' > "/work/en.$b"
check "R-559: the $b English block exists" "[ -s /work/en.$b ]"
# ASCII-fragment search with BOTH controls (rule 9.8): the English block must carry no Hungarian
# letter, and the Hungarian block must carry one — or the check is matching nothing at all.
check "R-559: the $b English block has no Hungarian letter" "! grep -q '[áéíóöőúüűÁÉÍÓÖŐÚÜŰ]' /work/en.$b"
check "R-559: CONTROL — the $b Hungarian block does have one" "grep -q '[áéíóöőúüűÁÉÍÓÖŐÚÜŰ]' /work/golden/$b.hu.txt"
# 80 columns is the console's width, counted in CHARACTERS not bytes: the Hungarian lines are
# multi-byte, so `wc -c` would convict them wrongly.
check "R-559: every $b line fits 80 columns" \
"[ \"\$(awk '{ print length(\$0) }' /work/b.$b | sort -rn | head -1)\" -le 80 ]"
done
# The pairing code appears once per language — a person reads one block, and must find it there.
check "R-559: the pairing code appears in BOTH blocks" \
"[ \"\$(grep -c 'TST-CDE' /work/b.pairing)\" -eq 2 ]"
check "R-559: the bound banner carries no pairing code" "! grep -q 'TST-CDE' /work/b.bound"
# /etc/issue: the Hungarian half frozen, the English half added, still no ő/ű and still no admin URL.
check "R-559: /etc/issue still opens with the golden Hungarian" \
"head -n \$(wc -l < /work/golden/issue.hu.txt) /work/issue | diff -q /work/golden/issue.hu.txt - >/dev/null"
check "R-559: /etc/issue has an English half" "grep -q 'Felhom home server' /work/issue"
check "R-559: /etc/issue English half has no Hungarian letter" \
"! sed -n '/Felhom home server/,\$p' /work/issue | grep -q '[áéíóöőúüűÁÉÍÓÖŐÚÜŰ]'"
check "R-559: /etc/issue names no admin URL" "! grep -q '8006' /work/issue"
check "single invocation ran to done (exit 0)" "[ $rc -eq 0 ]"
check "POSTed /appliance/register" "grep -q '/appliance/register' $CALLS"
check "appliance token persisted 0600" "[ -f /etc/felhom/.bootstrap-done ] || { [ -f /etc/felhom/appliance-token ] && [ \"\$(stat -c %a /etc/felhom/appliance-token)\" = 600 ]; }"
+7
View File
@@ -0,0 +1,7 @@
================================================
Felhom — a doboz össze van kötve. ✔
A beállítás magától folytatódik, ez néhány percig tart.
A vezérlőpult címét az e-mailben kapott levél tartalmazza.
Ezen a gépen nincs több teendőd.
+6
View File
@@ -0,0 +1,6 @@
Felhom otthoni szerver
Ezen a gépen most nincs dolgod, és bejelentkezni sem kell.
A beállításhoz kövesd a Felhomtól kapott útmutatót.
+11
View File
@@ -0,0 +1,11 @@
================================================
Felhom — a doboz készen áll, és a párosításra vár.
Párosító kód: TST-CDE
Nyisd meg az e-mailben kapott linket, és add meg
ezt a kódot és a Tulajdonosi jelmondatodat
(az 5 szót a Felhom üzemeltetőjétől kaptad).
Ez a képernyő magától frissül — nincs teendő a
doboznál, és nyugodtan itt hagyhatod bekapcsolva.
+42 -2
View File
@@ -21,7 +21,17 @@ W = os.path.join(ROOT, "website")
PAGES = ["index.html", "kapcsolat.html", "alkalmazasok.html", "technologiak.html",
"biztonsagimentes.html", "gyik.html", "szolgaltatasok-nonpublic.html",
"letoltes.html"]
"letoltes.html",
# R-559 (2026-09-18): the English download page. The marketing site stays Hungarian by
# operator ruling 1b; this one page is its English twin because a volunteer who reads no
# Hungarian still has to fetch the installer.
os.path.join("en", "download.html")]
# EN_PAGES carry their OWN nav and footer, in English, and must not be compared with the Hungarian
# set. Everything else — BOM, emoji, banned tokens, analytics, no <style>, cache-busted assets —
# applies to them exactly as to any other page. Stated as a SET rather than a filename test so a
# second English page cannot join by accident.
EN_PAGES = {os.path.join("en", "download.html")}
ANALYTICS_EXEMPT = {"szolgaltatasok-nonpublic.html"}
ANALYTICS_MARK = "https://stats.felhom.eu/script.js"
@@ -79,9 +89,11 @@ for p, s in emoji_targets.items():
if total_emoji:
print(" emoji total: %d" % total_emoji)
# gate 3: nav + footer consistency
# gate 3: nav + footer consistency (Hungarian set only — see EN_PAGES)
ref_nav = ref_footer = None
for p, s in pages.items():
if p in EN_PAGES:
continue
nm = re.search(r"<nav>.*?</nav>", s, re.DOTALL)
fm = re.search(r"<footer>.*?</footer>", s, re.DOTALL)
if not nm or not fm:
@@ -122,6 +134,34 @@ for p, s in pages.items():
fail("%s: %d embedded <style> block(s)" % (p, c))
# gate 8: cache-busting on shared assets
# gate 12 (R-559): the two download pages name the SAME installer file and the SAME checksum.
#
# THE FAILURE THIS EXISTS FOR IS A HALF-DONE RELEASE. Publishing a new ISO means editing a filename,
# a size and a 64-character hash on TWO pages now. Update one and forget the other and an English
# reader downloads yesterday's image, or — worse — checks today's image against yesterday's hash,
# fails the comparison, and is told by the page itself not to use the file.
#
# It compares what the pages SAY, not what is published: a gate cannot reach the bucket, and a
# published-file check belongs to the ISO release gate (G11), which does exactly that.
_HU_DL, _EN_DL = "letoltes.html", os.path.join("en", "download.html")
if _HU_DL in pages and _EN_DL in pages:
_iso_re = re.compile(r"felhom-installer-[0-9.]+-pve[0-9.\-]+\.iso")
_sha_re = re.compile(r"\b[0-9a-f]{64}\b")
hu_iso = sorted(set(_iso_re.findall(pages[_HU_DL])))
en_iso = sorted(set(_iso_re.findall(pages[_EN_DL])))
hu_sha = sorted(set(_sha_re.findall(pages[_HU_DL])))
en_sha = sorted(set(_sha_re.findall(pages[_EN_DL])))
if not hu_iso:
fail("%s: names no installer file at all" % _HU_DL)
if not hu_sha:
fail("%s: names no SHA-256 at all" % _HU_DL)
if hu_iso != en_iso:
fail("the download pages name DIFFERENT installer files: hu=%s en=%s" % (hu_iso, en_iso))
if hu_sha != en_sha:
fail("the download pages name DIFFERENT checksums: hu=%s en=%s" % (hu_sha, en_sha))
else:
print(" download pages agree: %s, sha %s…" % (", ".join(hu_iso), (hu_sha or ["-"])[0][:12]))
for p, s in pages.items():
for m in re.finditer(r"/assets/(site\.css|icons\.svg)([^\"'#\s>]*)", s):
if not m.group(2).startswith("?v="):