ISO 1.29.0 source + an English download page (R-559 slice 4, source only)
gates / gates (push) Successful in 23s
gates / gates (push) Successful in 23s
THE IMAGE IS NOT BUILT AND NOT PUBLISHED BY THIS COMMIT. Publishing to iso.felhom.eu is public and irreversible and its runbook requires a proof install on BOTH menu entries plus the 16-criterion gate run against the exact uploaded bytes. That is the operator's step. The download pages therefore still name 1.28.0 - the image that is actually published - and a new site gate refuses the two pages naming different files or hashes. Three texts a person meets before any dashboard become bilingual: Hungarian block first, byte for byte as before, then English, inside the same frame. The pairing banner, the bound banner, /etc/issue (and the postinst's byte-coupled copy), plus an English half on the GRUB entries. The Hungarian is a GOLDEN, not a grep: test/golden/*.hu.txt were captured from the script at183727db9cbefore one English line existed, and the harness asserts each banner's first N lines are exactly the golden. Red-proofed by one changed byte, by an "a" planted in the English block, and by an over-wide line. R-586, found on the way in: running the harness UNCHANGED at the base commit failed two R-496 checks. The script paints with `>`, which truncates a FILE but is a no-op on a console device; ISO 1.28.0's new bound banner (c033b3b) paints straight after the pairing one and wiped it before the check read it.c033b3bdid not touch the harness, and nobody saw it because the harness is in no gate and no CI run. Fixed with a FIFO; production code untouched. The harness being ungated is still open. The release gate's G16 required every Felhom string to be Hungarian and would have STOPPED this publication. Operator ruling 1b of 2026-09-17 supersedes that scope, so G16 is rewritten rather than waived: Hungarian FIRST, pinned by the golden, each secret named once per language. letoltes.html changes by four lines only. The English link is not in the nav - the nav is a shared block site_gates.py pins across every page, and the gate convicted the first attempt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+42
-2
@@ -21,7 +21,17 @@ W = os.path.join(ROOT, "website")
|
||||
|
||||
PAGES = ["index.html", "kapcsolat.html", "alkalmazasok.html", "technologiak.html",
|
||||
"biztonsagimentes.html", "gyik.html", "szolgaltatasok-nonpublic.html",
|
||||
"letoltes.html"]
|
||||
"letoltes.html",
|
||||
# R-559 (2026-09-18): the English download page. The marketing site stays Hungarian by
|
||||
# operator ruling 1b; this one page is its English twin because a volunteer who reads no
|
||||
# Hungarian still has to fetch the installer.
|
||||
os.path.join("en", "download.html")]
|
||||
|
||||
# EN_PAGES carry their OWN nav and footer, in English, and must not be compared with the Hungarian
|
||||
# set. Everything else — BOM, emoji, banned tokens, analytics, no <style>, cache-busted assets —
|
||||
# applies to them exactly as to any other page. Stated as a SET rather than a filename test so a
|
||||
# second English page cannot join by accident.
|
||||
EN_PAGES = {os.path.join("en", "download.html")}
|
||||
ANALYTICS_EXEMPT = {"szolgaltatasok-nonpublic.html"}
|
||||
ANALYTICS_MARK = "https://stats.felhom.eu/script.js"
|
||||
|
||||
@@ -79,9 +89,11 @@ for p, s in emoji_targets.items():
|
||||
if total_emoji:
|
||||
print(" emoji total: %d" % total_emoji)
|
||||
|
||||
# gate 3: nav + footer consistency
|
||||
# gate 3: nav + footer consistency (Hungarian set only — see EN_PAGES)
|
||||
ref_nav = ref_footer = None
|
||||
for p, s in pages.items():
|
||||
if p in EN_PAGES:
|
||||
continue
|
||||
nm = re.search(r"<nav>.*?</nav>", s, re.DOTALL)
|
||||
fm = re.search(r"<footer>.*?</footer>", s, re.DOTALL)
|
||||
if not nm or not fm:
|
||||
@@ -122,6 +134,34 @@ for p, s in pages.items():
|
||||
fail("%s: %d embedded <style> block(s)" % (p, c))
|
||||
|
||||
# gate 8: cache-busting on shared assets
|
||||
|
||||
# gate 12 (R-559): the two download pages name the SAME installer file and the SAME checksum.
|
||||
#
|
||||
# THE FAILURE THIS EXISTS FOR IS A HALF-DONE RELEASE. Publishing a new ISO means editing a filename,
|
||||
# a size and a 64-character hash on TWO pages now. Update one and forget the other and an English
|
||||
# reader downloads yesterday's image, or — worse — checks today's image against yesterday's hash,
|
||||
# fails the comparison, and is told by the page itself not to use the file.
|
||||
#
|
||||
# It compares what the pages SAY, not what is published: a gate cannot reach the bucket, and a
|
||||
# published-file check belongs to the ISO release gate (G11), which does exactly that.
|
||||
_HU_DL, _EN_DL = "letoltes.html", os.path.join("en", "download.html")
|
||||
if _HU_DL in pages and _EN_DL in pages:
|
||||
_iso_re = re.compile(r"felhom-installer-[0-9.]+-pve[0-9.\-]+\.iso")
|
||||
_sha_re = re.compile(r"\b[0-9a-f]{64}\b")
|
||||
hu_iso = sorted(set(_iso_re.findall(pages[_HU_DL])))
|
||||
en_iso = sorted(set(_iso_re.findall(pages[_EN_DL])))
|
||||
hu_sha = sorted(set(_sha_re.findall(pages[_HU_DL])))
|
||||
en_sha = sorted(set(_sha_re.findall(pages[_EN_DL])))
|
||||
if not hu_iso:
|
||||
fail("%s: names no installer file at all" % _HU_DL)
|
||||
if not hu_sha:
|
||||
fail("%s: names no SHA-256 at all" % _HU_DL)
|
||||
if hu_iso != en_iso:
|
||||
fail("the download pages name DIFFERENT installer files: hu=%s en=%s" % (hu_iso, en_iso))
|
||||
if hu_sha != en_sha:
|
||||
fail("the download pages name DIFFERENT checksums: hu=%s en=%s" % (hu_sha, en_sha))
|
||||
else:
|
||||
print(" download pages agree: %s, sha %s…" % (", ".join(hu_iso), (hu_sha or ["-"])[0][:12]))
|
||||
for p, s in pages.items():
|
||||
for m in re.finditer(r"/assets/(site\.css|icons\.svg)([^\"'#\s>]*)", s):
|
||||
if not m.group(2).startswith("?v="):
|
||||
|
||||
Reference in New Issue
Block a user