The image is BUILT but NOT PUBLISHED, and that is deliberate: publishing to iso.felhom.eu is public and irreversible, and the runbook needs a proof install on BOTH menu entries plus a reboot against the uploaded bytes. That is supervised, so I stopped there. felhom-installer-1.29.0-pve9.2-1.iso, sha256 c67ceaa3…fb02, with every mechanically checkable criterion passing (G1, G2, G5, G6, G7, G9, G16 — including both payload files byte-identical to repo HEAD). The download pages still name 1.28.0, the image that IS published. Pointing them at a file that is not there would hand every reader a 404. A new site gate refuses the two pages naming different installer files or checksums, so whoever publishes 1.29.0 cannot update one and forget the other. Measured rather than read: the pairing banner is 24 rows on a 25-row console. One row of margin — so the height is now pinned, because two more lines push the HUNGARIAN code at row 5 off the top, and a banner whose code has scrolled away is furniture. R-587: two root-password files from July sit in the directory the public ISO is published from. Both 404 on the bucket (against a 200 control), so nothing leaked — but the only thing keeping them off is an --include pattern they miss by an accident of naming. A pattern that protects by coincidence is not a control. R-588: release records live in two different places, which made me wrongly conclude 1.28.0's gate had never been run. It had. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
Slice 4 — bilingual console, English download page (R-559). 2026-09-18
Source shipped. The ISO is BUILT but NOT PUBLISHED — that step is the operator's (§Stop, below).
The claim in the task that mattered most, and it was wrong
"the GRUB menu has one entry" — the release image has two (
grub-release.cfg.tmpl: graphical and text mode). The single-entry template is the appliance image. Both were updated.
Others: 25 Hungarian printf/echo lines, not 27. A test DOES compare the banner text — and a
second one cmps /etc/issue against the postinst's copy byte for byte. The console seam already
existed (FELHOM_CONSOLE_DEV). The publish runbook is documentation/runbooks/iso-release-gate.md
(correctly not in the ISO README). VM 321/322 were not reachable to confirm — no VM was created
(see Stop). ISO 1.28.0's gate WAS recorded, under documentation/audits/evidence-backup- promise-2026-09-16/phaseD-iso-gate.txt rather than a documentation/tests/iso-release-* directory;
I briefly concluded it had not been, which is why R-588 is about where records live.
Two defects found before any feature work
R-586 — the harness had been RED for two days and nobody saw. Running
scripts/iso/test/bootstrap-modes.sh unchanged at the base commit failed two R-496 checks. The
script paints with > "$CONSOLE_DEV": on a console that is a device and truncation is a no-op, but
the harness pointed it at a plain FILE, so each banner erased the one before it. ISO 1.28.0's new
bound banner (commit c033b3b, 2026-09-16) paints straight after the pairing banner and wiped it
before the check read it — and that commit did not touch the harness. The harness is in no gate and
no CI run. Fixed with a FIFO; production code untouched.
The release gate would have stopped this task. iso-release-gate.md G16 read "every
Felhom-authored string on the volunteer's path is Hungarian — PASS = no English sentence". That
encodes the 2026-07-31 scope. Operator ruling 1b of 2026-09-17 supersedes it ("the console banner
and the download page ARE in scope"). G16 was rewritten, not waived: Hungarian FIRST, pinned by a
golden, each secret named once per language. What it protects is now stronger.
What is proven, and how
| Claim | How |
|---|---|
| The Hungarian is unchanged | Goldens captured from the script at 183727db9c44 before one English line existed; the harness asserts each banner's first N lines are exactly the golden. Red-proofed by one changed byte. |
| The English is English | No Hungarian letter in the English block, with the Hungarian block as the positive control. Red-proofed by planting an ó. |
| It fits the screen | Every line ≤ 80 columns (characters, not bytes), and the whole paint ≤ 25 rows. Red-proofed both ways. |
/etc/issue still agrees with postinst |
The existing cmp check, still green — both files were changed identically. |
| The payload in the ISO is the repo's | cmp of both files extracted from the built .deb against repo HEAD: IDENTICAL. |
The pairing banner is 24 rows on a 25-row console. One row of margin. That is the measurement the plan asked for, and it is why the height check exists: two more English lines make it 26 and the Hungarian pairing code — which sits at row 5 — scrolls off the top. A banner whose code has scrolled away is furniture.
The built image (not published)
felhom-installer-1.29.0-pve9.2-1.iso
sha256 c67ceaa3793b38639d0f24c9c9704270d04e50b74f1ea88b1129fdd1dec6fb02
size 1 705 324 544 bytes
menu 2 entries: 'Felhom telepítés / Install Felhom'
'Felhom telepítés (szöveges mód) / Install Felhom (text mode)'
timeout 15, timeout_style=menu, default=0, banned entries 0
Gate criteria run mechanically against the built file: G1 no answer.toml (0 hits) · G2 no
.rootpw.txt emitted · G5 no credential-shaped literal in the payload (Bearer is
Bearer $token, a variable) · G6 two entries, timeout 15, underscore spelling, 0 banned ·
G7 package present at 1.29.0 · G9 both payload files byte-identical to repo HEAD · G16
jelszavad 0, Tulajdonosi jelmondat 1, Owner passphrase 1, harness green.
STOP — what is left, and why it is not mine
The image is not published. iso.felhom.eu is public and irreversible, and the runbook requires,
against the exact uploaded bytes: G11 a published checksum and a verified round trip, G15 the
console after a first boot and one reboot, G14 a person choosing the disk, and a proof
install on BOTH menu entries (the felhom-build-deploy skill is explicit that reasoning from one
entry to the other was tried in Spike 4 and found insufficient in 1.26.0).
No VM was created and none destroyed; demo-hp guest 9201 was not touched at all this task.
Therefore the download pages still name 1.28.0 — the image that is actually published. Pointing them at an unpublished file would hand every reader a 404. A new site gate refuses the two pages naming different files or hashes, so whoever publishes 1.29.0 cannot update one page and forget the other.
The English download page IS live
https://felhom.eu/en/download 200 <html lang="en">
https://felhom.eu/letoltes 200 links to it, hreflang both ways
both name felhom-installer-1.28.0-pve9.2-1.iso, sha a4cd9b6ddcb5… (verified live)