Files
felhom.eu/scripts/iso/pkg/debian/postinst
T
admin 27e8ec860c
gates / gates (push) Successful in 18s
iso 1.27.1: the FIRST boot is Felhom's — postinst masks pvebanner and writes /etc/issue
The 1.27.0 proof install (VM 331, screen s20) still showed Proxmox's
":8006" block on the first boot: pvebanner.service ran before
felhom-bootstrap could mask it, and the Felhom text lost its o/u double
acutes (painted before the Latin-2 font loads).
- postinst: mask pvebanner by symlink (a file act, valid in the chroot) and
  write /etc/issue; both guarded, still exit 0 (G8 self-checks unchanged).
- bootstrap: same text, byte-identical, no o/u double acutes (second line).
- harness: PI scenario (postinst in a container) + no-accent checks, red
  first against the 1.27.0 code; 55/55 green.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-14 17:55:08 +02:00

66 lines
3.8 KiB
Bash
Executable File

#!/bin/sh
# felhom-bootstrap postinst.
#
# THIS SCRIPT MUST NOT BE ABLE TO FAIL. It runs under `dpkg --configure -a` INSIDE THE PVE INSTALLER
# CHROOT, in the middle of a customer's installation. A non-zero exit surfaces to that customer as an
# install error — far worse than the bootstrap simply not running. The stub not running costs one
# documented command; a broken install costs the machine.
#
# Four constraints, every one MEASURED in SPIKE-universal-iso-4-2026-07-31.md §3:
# 1. NO `set -e` — it converts any unexpected non-zero into the failure above.
# 2. NO systemctl start / daemon-reload — pid1 in the chroot is `unconfigured.sh` and NO systemd is
# running; those verbs are meaningless there. `enable` is the only one
# that works, and it was measured to work (it wrote the symlink).
# 3. NO network use — the network was up in the probe ONLY because the installer's DHCP
# happened to hold. A box installed with the cable out has none.
# 4. Real work at first boot — the unit does it, where systemd, network and a booted kernel exist.
#
# Every statement below is therefore individually guarded and the script ends `exit 0` unconditionally.
UNIT=felhom-bootstrap.service
LOG=/var/log/felhom-bootstrap-postinst.log
# A positive observable that this ran. SPIKE 2 R-150: a hook that never ran is indistinguishable from
# one that succeeded if you only look for errors.
{
echo "felhom-bootstrap postinst: arg1=${1:-} date=$(date -u -Is 2>/dev/null || echo unknown)"
} >> "$LOG" 2>&1 || true
chmod 0644 "$LOG" 2>/dev/null || true
if [ "${1:-}" = "configure" ]; then
# R-496 (v1.27.1): the console's login text is Felhom's from the FIRST boot. pvebanner.service rewrites
# /etc/issue with the Proxmox admin URL on every boot; on 1.27.0 it ran before felhom-bootstrap could
# mask it (proof install screen 331-s20). Masking is a SYMLINK to /dev/null — a file act, valid in this
# systemd-less chroot, like the wants-symlink fallback below. Both acts guarded; neither can fail the install.
mkdir -p /etc/systemd/system 2>/dev/null || true
if ln -sf /dev/null /etc/systemd/system/pvebanner.service 2>/dev/null; then
echo "felhom-bootstrap postinst: pvebanner.service masked (symlink)" >> "$LOG" 2>&1 || true
fi
# Byte-identical to felhom-bootstrap.sh install_felhom_issue (harness PI pins it). No ő/ű: the login
# screen is painted before the Latin-2 font loads.
if { printf '\n'
printf ' Felhom otthoni szerver\n\n'
printf ' Ezen a gépen most nincs dolgod, és bejelentkezni sem kell.\n'
printf ' A beállításhoz kövesd a Felhomtól kapott útmutatót.\n\n'
} > /etc/issue.felhom-tmp 2>/dev/null && mv -f /etc/issue.felhom-tmp /etc/issue 2>/dev/null; then
echo "felhom-bootstrap postinst: /etc/issue is the Felhom text" >> "$LOG" 2>&1 || true
else
rm -f /etc/issue.felhom-tmp 2>/dev/null || true
fi
# `enable` only. Guarded, and its outcome recorded either way.
if systemctl enable "$UNIT" >> "$LOG" 2>&1; then
echo "felhom-bootstrap postinst: enabled $UNIT via systemctl" >> "$LOG" 2>&1 || true
else
# Fallback: write the wants-symlink by hand. Also guarded — if this fails too, the unit is
# simply not enabled and the operator runs the documented one-liner. The install still succeeds.
mkdir -p /etc/systemd/system/multi-user.target.wants 2>/dev/null || true
ln -sf "/lib/systemd/system/$UNIT" \
"/etc/systemd/system/multi-user.target.wants/$UNIT" 2>/dev/null || true
echo "felhom-bootstrap postinst: systemctl enable failed; wrote wants-symlink by hand" \
>> "$LOG" 2>&1 || true
fi
fi
exit 0