|
|
|
@@ -184,7 +184,7 @@
|
|
|
|
|
|
|
|
|
|
set -euo pipefail
|
|
|
|
|
|
|
|
|
|
SCRIPT_VERSION="1.28.0" # the SINGLE version source (F-1): -h and the run banners follow it.
|
|
|
|
|
SCRIPT_VERSION="1.29.0" # the SINGLE version source (F-1): -h and the run banners follow it.
|
|
|
|
|
# The hub used to carry a copy for its Setup tab; R-94 DELETED it
|
|
|
|
|
# (2026-08-02) because the hub cannot know which version a box runs —
|
|
|
|
|
# the Setup command fetches this script at run time. scripts/
|
|
|
|
@@ -1157,6 +1157,7 @@ run_uninstall() {
|
|
|
|
|
if [[ -f /usr/local/sbin/felhom-mkfs-guarded ]]; then run rm -f /usr/local/sbin/felhom-mkfs-guarded; else log_skip " felhom-mkfs-guarded already absent"; fi
|
|
|
|
|
if [[ -f /usr/local/sbin/felhom-pbs-apply ]]; then run rm -f /usr/local/sbin/felhom-pbs-apply; else log_skip " felhom-pbs-apply already absent"; fi
|
|
|
|
|
if [[ -f /usr/local/sbin/felhom-backup-target-apply ]]; then run rm -f /usr/local/sbin/felhom-backup-target-apply; else log_skip " felhom-backup-target-apply already absent"; fi
|
|
|
|
|
if [[ -f /usr/local/sbin/felhom-os-apply ]]; then run rm -f /usr/local/sbin/felhom-os-apply; else log_skip " felhom-os-apply already absent"; fi
|
|
|
|
|
if [[ -f /var/lib/vz/snippets/felhom-guest-hook.sh ]]; then run rm -f /var/lib/vz/snippets/felhom-guest-hook.sh; fi
|
|
|
|
|
local dconf _dnsmasq_touched=false
|
|
|
|
|
for dconf in /etc/dnsmasq.d/felhom-*.conf; do
|
|
|
|
@@ -2372,6 +2373,28 @@ step_agent_install() {
|
|
|
|
|
log_success " installed /usr/local/sbin/felhom-backup-target-apply (0755, the guarded backup-target path)"
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# OS updates, guest fast lane (agent >= 0.140.0, `11-os-updates.md` §8 step 2): the root wrapper behind the
|
|
|
|
|
# FELHOM_OSAPPLY sudoers alias. It ships in the AGENT repo at the same pinned tag as the sudoers file, so an older
|
|
|
|
|
# pinned agent has neither the wrapper nor the alias — a missing file is therefore SKIPPED with a warning (OS
|
|
|
|
|
# updates stay off), never fatal. Python 3 (stdlib only), syntax-checked before install, 0755 root:root.
|
|
|
|
|
if $DRY_RUN; then
|
|
|
|
|
log_dry "fetch configs/felhom-os-apply (if the pinned agent carries it) ; python3 syntax check ; install 0755 -> /usr/local/sbin/felhom-os-apply"
|
|
|
|
|
else
|
|
|
|
|
local ostmp; ostmp=$(mktemp -t felhom-os.XXXXXX)
|
|
|
|
|
local -a _osauth; _git_auth_args _osauth
|
|
|
|
|
if curl -fsS "${_osauth[@]}" -o "$ostmp" \
|
|
|
|
|
"$GITEA_BASE/$GITEA_OWNER/$AGENT_REPO/raw/tag/v$ART_AGENT_VER/configs/felhom-os-apply" 2>/dev/null \
|
|
|
|
|
&& [[ -s "$ostmp" ]]; then
|
|
|
|
|
python3 -c 'import ast,sys; ast.parse(open(sys.argv[1]).read())' "$ostmp" \
|
|
|
|
|
|| { rm -f "$ostmp"; die "fetched felhom-os-apply failed the python3 syntax check — refusing to install"; }
|
|
|
|
|
install -m 0755 -o root -g root "$ostmp" /usr/local/sbin/felhom-os-apply
|
|
|
|
|
log_success " installed /usr/local/sbin/felhom-os-apply (0755, the guarded OS-update path)"
|
|
|
|
|
else
|
|
|
|
|
log_warn " agent v$ART_AGENT_VER carries no felhom-os-apply (older than 0.140.0) — OS updates stay off on this box"
|
|
|
|
|
fi
|
|
|
|
|
rm -f "$ostmp"
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
# Sudoers — fetch the canonical file, validate with visudo -cf BEFORE installing (0440 root:root).
|
|
|
|
|
if $DRY_RUN; then
|
|
|
|
|
log_dry "fetch configs/felhom-agent.sudoers ; visudo -cf ; install 0440 -> $AGENT_SUDOERS"
|
|
|
|
|