- The R-297 named-golden refusal no longer repeats "The vouched golden is X." when its reason
already says it (kept when the reason does not name the version).
- --uninstall checks it can open /dev/tty before the typed vmid confirmation and, if not, refuses
with a sentence (deliberate; --force does not skip it) instead of "/dev/tty: No such device".
scripts/test_hostinstall.py: test_golden_refusal_* (2), test_require_tty_* (3, with a pty control).
The runbook line naming the pty requirement is a documentation edit for the lead.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Units carrying the agent's network-storage marker (mnt-*.automount first, then mnt-*.mount) are
disabled --now, reset-failed and removed before the drive umount loop; a share that will not stop is
not forced — its unit is kept and named in KEPT with the commands. Enrolled-drive and foreign units
are never touched. scripts/test_hostinstall.py: test_net_units_* (5).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
The step-8 restore reads the golden as the agent's token; a storage outside PVE_STORAGES (and not
the backup target, which step 6 grants since R-185) 403'd at step 8/8 — after the token was minted
and root@pam rotated. Pre-flight now refuses it with the two remedies (move the golden, or add the
storage to --acl-storages). scripts/test_hostinstall.py: test_archive_storage_* (4).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
HARD_MIN_LVM_GIB -> RECOMMENDED_MIN_LVM_GIB; the warning says the install continues and to proceed
only with deliberately sized grows (the day0-install runbook's wording). Behaviour unchanged.
scripts/test_hostinstall.py: test_lvm_minimum_is_named_as_what_it_does.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
_state_put and _state_mark are no-ops under --preflight-only as well as --dry-run, so the banner
"no state written" is true and the dnsmasq ownership answer is recorded only by the real install's
own preflight. The log says "would be recorded at install" on a preflight-only run.
scripts/test_hostinstall.py: test_preflight_only_writes_no_state (+ its control and a no-other-writer check).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
- R-275: the agent's own config dir is purged as a directory (the .bak* glob missed all five
demo-hp copies); a custom config path loses agent.json + every agent.json.* sibling only.
Sudoers dotted copies go too. At install, a freshly created service user cannot read what an old
install left in /etc/felhom-agent (sealed root 0600, named, never deleted). vmbr9 and the ISO
first-boot files are now NAMED under KEPT.
- R-276: wg-quick@wg-felhom is disabled --now and its conf removed, then observed down; the hub-side
peer is named under KEPT (removing it is the hub's job).
- R-881: /usr/local/sbin/felhom-priv-apply is removed; the disclosure says it and the guest hook
come from the config bundle.
- scripts/test_hostinstall.py: lifts the functions verbatim and runs them with PATH stubs (13 tests,
BusyBox-safe); harness GL4-D here-string (SIGPIPE false miss), GL8-F1 follows the new purge.
- SCRIPT_VERSION 1.32.0 (not published; no tag).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS