f93738dc49
gates / gates (push) Successful in 36s
GOLDEN_SHA256=d6cf8b33ad58e5cfbf9566558044b2e1df692ef29d5353a40e39117794d16671, round trip MATCH; drill VM 9100 destroyed, VM reverted to virgin. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
59 lines
2.8 KiB
Markdown
59 lines
2.8 KiB
Markdown
# Golden 0.292.0 — bake + publish, 2026-10-04
|
||
|
||
Procedure: `documentation/runbooks/RUNBOOK-manual-build.md` §4.0 and §4.1 steps 1–4, in the drill VM
|
||
on DooPlex, repeating the 0.291.0 bake of the same day. Step 5 (vouching in the hub) and any floor
|
||
change were **not** done here; they are the main session's / operator's act.
|
||
|
||
- Controller image: `gitea.dooplex.hu/admin/felhom-controller:0.292.0` (manifest present in the
|
||
registry before the bake). Controller CHANGELOG header: **MinAgent 0.131.0** (unchanged).
|
||
- Build script: `felhom-agent/configs/build-golden.sh` v3.0.0, agent repo `main` = `2e2e8f56b843`
|
||
(tree clean, HEAD == origin/main after `git fetch`); sha256 of the copy in the VM matched the repo
|
||
file (`e4c9ede772e7…`, the same script bytes as the 0.291.0 bake).
|
||
- Drill VM: reverted to `virgin`, cold-booted per §4.0; `pveversion` = `pve-manager/9.2.2`.
|
||
- Step 2: `pveam update` → `update successful`; template `debian-13-standard_13.6-1_amd64.tar.zst`
|
||
(the only `_amd64` debian-13 entry), downloaded with checksum verified.
|
||
- Pre-gate: `GET …/generic/felhom-golden/0.292.0/golden.tar.zst` → **404** before the bake.
|
||
- Token: copied file → file (`scp`); launched via the in-VM runner script as transient unit
|
||
`golden-bake`. `systemctl show golden-bake -p Environment -p ExecStart | grep -c -F <token>` = **0**
|
||
(control: same output with the token appended = **1**).
|
||
|
||
## Result
|
||
|
||
```
|
||
GOLDEN_VERSION=0.292.0
|
||
GOLDEN_SHA256=d6cf8b33ad58e5cfbf9566558044b2e1df692ef29d5353a40e39117794d16671
|
||
```
|
||
|
||
## Pass markers (quoted verbatim from `bake.log`)
|
||
|
||
```
|
||
82: docker OK (overlay2; data-root /var/lib/docker)
|
||
321:INFO: including mount point rootfs ('/') in backup
|
||
322:INFO: including mount point mp0 ('/var/lib/felhom') in backup
|
||
327:[golden] pre-delete existing: HTTP 404 (404/204 expected)
|
||
328:[golden] upload OK (HTTP 201)
|
||
```
|
||
|
||
`grep -E 'excluding|FATAL' bake.log` → no matches.
|
||
|
||
## Token-leak grep
|
||
|
||
On the copy in this directory (the one that would be committed):
|
||
`grep -c -F "$(cat ~/.gitea-token)" bake.log` = **0**.
|
||
Positive control: a throwaway copy with the token appended → **1**; the copy was `shred -u`'d.
|
||
|
||
## Round trip
|
||
|
||
See `02-round-trip.txt`: the published package downloaded anonymously (HTTP 200, 648187281 bytes)
|
||
hashes to `d6cf8b33ad58e5cfbf9566558044b2e1df692ef29d5353a40e39117794d16671` — **matches**
|
||
GOLDEN_SHA256.
|
||
|
||
## Teardown state
|
||
|
||
- `pct destroy 9100 --purge` → rc 0 (both LVs removed); `pct list` empty.
|
||
- `/root/.gitea-token`, `/root/bake-run.sh`, `/root/bake.log` in the VM: `shred -u`, confirmed absent.
|
||
- VM powered off; no `qemu-system-x86` process remained.
|
||
- `qemu-img snapshot -a virgin drill.qcow2` → OK; snapshot list shows only `virgin`.
|
||
- Hub, k3s, demo boxes, ep0, PBS, Storage Box: not touched. No vouch, no floor change.
|
||
- `df -h`: `/mnt/5_hdd` 37 %, `/` 53 % (before and after).
|