Files
felhom.eu/scripts/iso/grub/grub-release.cfg.tmpl
T
admin eb1ae37095
gates / gates (push) Successful in 23s
ISO 1.29.0 source + an English download page (R-559 slice 4, source only)
THE IMAGE IS NOT BUILT AND NOT PUBLISHED BY THIS COMMIT. Publishing to
iso.felhom.eu is public and irreversible and its runbook requires a proof
install on BOTH menu entries plus the 16-criterion gate run against the exact
uploaded bytes. That is the operator's step. The download pages therefore still
name 1.28.0 - the image that is actually published - and a new site gate
refuses the two pages naming different files or hashes.

Three texts a person meets before any dashboard become bilingual: Hungarian
block first, byte for byte as before, then English, inside the same frame. The
pairing banner, the bound banner, /etc/issue (and the postinst's byte-coupled
copy), plus an English half on the GRUB entries.

The Hungarian is a GOLDEN, not a grep: test/golden/*.hu.txt were captured from
the script at 183727db9c before one English line existed, and the harness
asserts each banner's first N lines are exactly the golden. Red-proofed by one
changed byte, by an "a" planted in the English block, and by an over-wide line.

R-586, found on the way in: running the harness UNCHANGED at the base commit
failed two R-496 checks. The script paints with `>`, which truncates a FILE but
is a no-op on a console device; ISO 1.28.0's new bound banner (c033b3b) paints
straight after the pairing one and wiped it before the check read it. c033b3b
did not touch the harness, and nobody saw it because the harness is in no gate
and no CI run. Fixed with a FIFO; production code untouched. The harness being
ungated is still open.

The release gate's G16 required every Felhom string to be Hungarian and would
have STOPPED this publication. Operator ruling 1b of 2026-09-17 supersedes that
scope, so G16 is rewritten rather than waived: Hungarian FIRST, pinned by the
golden, each secret named once per language.

letoltes.html changes by four lines only. The English link is not in the nav -
the nav is a shared block site_gates.py pins across every page, and the gate
convicted the first attempt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-18 17:40:29 +02:00

81 lines
2.9 KiB
Cheetah

# Felhom PUBLIC RELEASE ISO — GRUB menu. GENERATED by iso-repack.sh (FELHOM_MENU=release).
#
# TWO entries, both INTERACTIVE, and that is the whole design.
#
# WHY NOT THE AUTOMATED ENTRY: SPIKE-universal-iso-1 measured that no udev property distinguishes an
# internal system disk from a customer's external backup drive (ID_BUS is `ata` for BOTH on a SATA
# drive in a USB caddy; no removability property is exposed at all; NVMe carries a different property
# set), and that a filter matching two disks does NOT fail safe — the installer silently picks one and
# wipes it, while validate-answer accepts the answer. There is therefore no safe automated disk
# selection for hardware nobody has seen. The stock installer already shows the target disk and a
# `Bootdisk(s)` summary before erasing, so the human doing the choosing is the safety mechanism.
#
# WHY THE GRAPHICAL ENTRY IS DEFAULT: a tester who boots the stick and walks away must not land on a
# destructive unattended path. The default is the one that waits for a person.
#
# WHY timeout=15: SPIKE-universal-iso-2 lost an entire probe to the installed system's 1-SECOND menu.
# A human reading two options on unfamiliar hardware needs longer than a machine does. Note
# `timeout_style` (underscore) — the stock PVE config writes `timeout-style`, which GRUB does not
# recognise as a variable name at all, so the stock menu's own timeout directive is inert.
#
# The `linux` / `initrd` lines are lifted VERBATIM by iso-repack.sh from the stock ISO's own Graphical
# and Terminal-UI entries, so a PVE version bump that changes the kernel path tracks automatically
# instead of silently diverging from a copy frozen here.
insmod gzio
insmod iso9660
insmod png
insmod gfxmenu
if [ x$feature_default_font_path = xy ] ; then
font=unicode
else
font=$prefix/unicode.pf2
fi
set gfxmode=1024x768,800x600,640x480
set gfxpayload=1024x768
if loadfont $font; then
if test "${grub_platform}" = "efi"; then
insmod efi_gop
insmod efi_uga
fi
insmod video_bochs
insmod video_cirrus
insmod all_video
insmod gfxterm
set theme=/boot/grub/felhomtheme/theme.txt
export theme
terminal_input console
terminal_output gfxterm
fi
insmod serial
insmod usbserial_common
insmod usbserial_ftdi
insmod usbserial_pl2303
insmod usbserial_usbdebug
if serial --unit=0 --speed=115200; then
terminal_input --append serial
terminal_output --append serial
fi
set timeout_style=menu
set timeout=15
set default=0
menuentry 'Felhom telepítés / Install Felhom' --class felhom --class os {
echo 'A Felhom telepítése indul — válassza ki a lemezt a telepítőben...'
@@LINUX_GFX@@
echo 'Rendszerbetöltő betöltése...'
@@INITRD@@
}
menuentry 'Felhom telepítés (szöveges mód) / Install Felhom (text mode)' --class felhom --class os {
echo 'A Felhom telepítése indul szöveges módban...'
@@LINUX_TUI@@
echo 'Rendszerbetöltő betöltése...'
@@INITRD@@
}