fb8e5111cf
day0-install: F3 (no --allow-new-leaf on a populated BYO host) + F6 (:53 must be free, refusal + remediation). GO-LIVE-PACKAGE + DRILL-GL6 ledger flip F1/F3/F6 -> FIXED v1.12.0; GL-7 unblocked; F2/F7 stay open. CONTEXT + REPORT. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
68 lines
4.6 KiB
Markdown
68 lines
4.6 KiB
Markdown
# felhom.eu — task reports
|
|
|
|
> **Overwrite** this file with a summary of the most recent task only (uniform with the other repos; not cumulative). The cumulative hub history lives in [hub/CHANGELOG.md](hub/CHANGELOG.md); the scripts history lives in [scripts/CHANGELOG.md](scripts/CHANGELOG.md).
|
|
|
|
## TASK GL-8 — BYO coexistence hardening (host-install v1.12.0) — 2026-07-08
|
|
|
|
**Baseline confirmed:** felhom.eu `1dc86523`, `SCRIPT_VERSION="1.11.3"` → **`1.12.0`** (`18a556a5`).
|
|
Three independent fixes from the GL-6 drill findings, one file, one theme (BYO = Felhom is a guest
|
|
on a host it doesn't own). felhom.eu only; agent untouched. §13 STOP honored — no live install/
|
|
uninstall; the F6 refuse path is a read-only preflight die (safe to exercise), proven on felhom-pve.
|
|
|
|
### The three fixes
|
|
|
|
- **F3 — leaf guard narrowed.** The populated-host leaf-regeneration guard tested `pct list` (ANY
|
|
guest) and so over-fired on a BYO host's own non-Felhom guests, forcing `--allow-new-leaf` on
|
|
every fresh byo install. Now it tests `[[ -n "$(felhom_guests)" ]]` (the `/etc/felhom-bootstrap`
|
|
detector) — it fires only when a real Felhom guest exists (whose pinned fingerprint a leaf regen
|
|
would orphan — the 2026-06-28 incident). `--preserve-state-from` / `--allow-new-leaf` unchanged.
|
|
- **F6 — foreign `:53` refuse (byo), Viktor's §8 option 1.** In byo the agent's lan_resolver stays
|
|
off, so any `:53` bind is the owner's. GL-2's informational `:53` line is promoted to an actionable
|
|
gate that **`die`s with remediation and mutates nothing** — Felhom does not stop/mask/kill a DNS
|
|
service on a host it doesn't own (the break-glass analog). No stop/mask path, no consent-ack leg
|
|
(nothing to consent to). `ss` failure/absence degrades to a warn. Appliance mode untouched.
|
|
- **F1 — uninstall config purge.** The teardown removed `agent.json` but left `${agent_cfg}.bak*`
|
|
siblings — a GL-6 residue held a **live hub api_key**. Now it removes the config AND every `.bak*`
|
|
sibling, then the dir; the KEPT/WIPED statement + summary say "config (+ its .bak backups)". Paths
|
|
logged, contents never. GL-4 Scenario-D parity still green (the GL4-D token set unchanged — the
|
|
config removal was already covered).
|
|
|
|
### Tests (harness `hostinstall-mode-harness.sh`, extended)
|
|
|
|
Static (anywhere): **GL8-F3** (guard uses `felhom_guests`, not `pct list`), **GL8-F6** (byo `:53`
|
|
gate refuses+instructs; no `systemctl stop/mask` / `kill` of any `:53`/dnsmasq/resolv service
|
|
anywhere), **GL8-F1** (`${agent_cfg}.bak*` removal present) + **GL8-F1b** (behavioural: the exact
|
|
glob-removal clears `agent.json` + three `.bak*` + the emptied dir). PVE tier on felhom-pve:
|
|
**GL8-F6 live** — the byo preflight **actually refused at `:53`** (felhom-pve's leftover dnsmasq is
|
|
bound — the exact GL-6 F6 scenario) with the remediation + `PRE-FLIGHT FAIL (exit 1)`; and the
|
|
free-`:53` arm (ss shimmed empty) passes the gate. **36/36 on felhom-pve, 0 failed**; shellcheck
|
|
clean; GL-2 Scenario-A + GL-4 Scenario-D regression green.
|
|
|
|
**Red-proofs (mutate scratch copy → invariant fails → discard):** RP-F3 (revert to `pct list`) →
|
|
GL8-F3 FAILS; RP-F6 (drop the `:53` die) → GL8-F6 FAILS; RP-F1 (narrow to `agent.json` only) →
|
|
GL8-F1 FAILS. All confirmed.
|
|
|
|
### Judgment calls
|
|
|
|
- F3 behavioural runtime is impractical to isolate (the guard is inline in step 5, gated on the real
|
|
state dir's leaf; felhom-pve has BOTH a leaf and a Felhom guest) — validated grep-level + red-proof;
|
|
the true behavioural proof (fresh byo install on a populated non-Felhom host proceeds without
|
|
`--allow-new-leaf`) folds into GL-7's Peti install.
|
|
- F6 uses the existing `ss -H -ltnup` (UDP+TCP) invocation — catches a UDP-only resolver (dnsmasq)
|
|
too, not just TCP.
|
|
- F1 is surgical (`${agent_cfg}` + `${agent_cfg}.bak*`, then `rmdir`), not `rm -rf` the dir — respects
|
|
a non-default `-config` path that might share a directory.
|
|
|
|
### NOT live-validated (folds into GL-7 / a demo re-run)
|
|
|
|
The real populated-host byo install proceeding without `--allow-new-leaf` (F3); the real foreign-`:53`
|
|
refusal on Peti's box (F6 — proven read-only on felhom-pve here); the real uninstall purging a `.bak`
|
|
(F1 — behaviourally unit-tested + grep-verified). All fold into GL-7's Peti day-0 as the live proof.
|
|
|
|
### Findings status + what's next
|
|
|
|
F1/F3/F6 → **FIXED (v1.12.0)** in the GL-6 ledger + GO-LIVE-PACKAGE. **Still open (non-blocking):**
|
|
F2 (per-drive `mnt-*.mount` units survive uninstall), F7 (pool re-assert bring-up-only, no continuous
|
|
heal — `--adopt-pool` repairs). **GL-7 is unblocked** — Peti's day-0 command needs no `--allow-new-leaf`
|
|
workaround. **Next: GL-7** (Peti day-0 runbook + tester agreement).
|