eb1ae37095
gates / gates (push) Successful in 23s
THE IMAGE IS NOT BUILT AND NOT PUBLISHED BY THIS COMMIT. Publishing to iso.felhom.eu is public and irreversible and its runbook requires a proof install on BOTH menu entries plus the 16-criterion gate run against the exact uploaded bytes. That is the operator's step. The download pages therefore still name 1.28.0 - the image that is actually published - and a new site gate refuses the two pages naming different files or hashes. Three texts a person meets before any dashboard become bilingual: Hungarian block first, byte for byte as before, then English, inside the same frame. The pairing banner, the bound banner, /etc/issue (and the postinst's byte-coupled copy), plus an English half on the GRUB entries. The Hungarian is a GOLDEN, not a grep: test/golden/*.hu.txt were captured from the script at183727db9cbefore one English line existed, and the harness asserts each banner's first N lines are exactly the golden. Red-proofed by one changed byte, by an "a" planted in the English block, and by an over-wide line. R-586, found on the way in: running the harness UNCHANGED at the base commit failed two R-496 checks. The script paints with `>`, which truncates a FILE but is a no-op on a console device; ISO 1.28.0's new bound banner (c033b3b) paints straight after the pairing one and wiped it before the check read it.c033b3bdid not touch the harness, and nobody saw it because the harness is in no gate and no CI run. Fixed with a FIFO; production code untouched. The harness being ungated is still open. The release gate's G16 required every Felhom string to be Hungarian and would have STOPPED this publication. Operator ruling 1b of 2026-09-17 supersedes that scope, so G16 is rewritten rather than waived: Hungarian FIRST, pinned by the golden, each secret named once per language. letoltes.html changes by four lines only. The English link is not in the nav - the nav is a shared block site_gates.py pins across every page, and the gate convicted the first attempt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
77 lines
2.9 KiB
Cheetah
77 lines
2.9 KiB
Cheetah
# Felhom ISO — GRUB menu (scripts v1.22.0, R-38 GRUB slice). GENERATED by iso-repack.sh; the stock
|
|
# PVE grub.cfg is REPLACED by this file at repack time.
|
|
#
|
|
# TWO jobs, one file:
|
|
#
|
|
# 1. BRANDING — a Felhom gfxmenu theme (felhomtheme/) over a 1024x768 card built from the website's
|
|
# og-image_2.png. The stock `set theme=/boot/grub/pvetheme/theme.txt` is gone.
|
|
#
|
|
# 2. SAFETY — exactly ONE entry is exposed. The stock menu offers Graphical / Terminal UI / serial,
|
|
# plus an "Advanced Options" submenu with nomodeset, three debug variants, Rescue Boot, memtest
|
|
# and UEFI firmware settings. Every one of those reaches the MANUAL installer, whose first
|
|
# question is which disk to wipe. A customer — or their helpful nephew — must not be able to get
|
|
# there from a boot menu. They are not hidden, they are NOT EMITTED.
|
|
#
|
|
# The `linux` / `initrd` lines below are lifted VERBATIM by iso-repack.sh from the stock
|
|
# 'Install Proxmox VE (Automated)' entry of the ISO being repacked, so a PVE version bump that
|
|
# changes the kernel path or the append line is tracked automatically instead of silently diverging
|
|
# from a copy frozen here. iso-repack.sh fails the build if it cannot find them, and asserts the
|
|
# append line still carries `proxmox-start-auto-installer` — the flag that makes the install
|
|
# unattended. Boot behavior is therefore byte-identical to v1.21.0; only the menu around it changed.
|
|
|
|
insmod gzio
|
|
insmod iso9660
|
|
insmod png
|
|
insmod gfxmenu
|
|
|
|
if [ x$feature_default_font_path = xy ] ; then
|
|
font=unicode
|
|
else
|
|
font=$prefix/unicode.pf2
|
|
fi
|
|
|
|
# Matches the background canvas exactly (1024x768). 800x600/640x480 are fallbacks for firmware that
|
|
# refuses the preferred mode — the theme is percentage-positioned, so it degrades cleanly.
|
|
set gfxmode=1024x768,800x600,640x480
|
|
set gfxpayload=1024x768
|
|
|
|
if loadfont $font; then
|
|
if test "${grub_platform}" = "efi"; then
|
|
insmod efi_gop
|
|
insmod efi_uga
|
|
fi
|
|
insmod video_bochs
|
|
insmod video_cirrus
|
|
insmod all_video
|
|
insmod gfxterm
|
|
set theme=/boot/grub/felhomtheme/theme.txt
|
|
export theme
|
|
terminal_input console
|
|
terminal_output gfxterm
|
|
fi
|
|
|
|
# Serial stays available for operator/nested-canary debugging (the stock cfg does this too). What we
|
|
# do NOT do is the stock's `set show_serial_entry=y` — that would add a fourth menu entry.
|
|
insmod serial
|
|
insmod usbserial_common
|
|
insmod usbserial_ftdi
|
|
insmod usbserial_pl2303
|
|
insmod usbserial_usbdebug
|
|
if serial --unit=0 --speed=115200; then
|
|
terminal_input --append serial
|
|
terminal_output --append serial
|
|
fi
|
|
|
|
# Short and decisive: one entry, default, 5s. Note `timeout_style` (underscore) — the stock cfg
|
|
# writes `timeout-style`, which GRUB does not recognise as a variable name at all.
|
|
set timeout_style=menu
|
|
set timeout=5
|
|
set default=0
|
|
|
|
menuentry 'Felhom telepítés / Install Felhom' --class felhom --class os {
|
|
echo 'A Felhom telepítése indul...'
|
|
@@LINUX@@
|
|
echo 'Rendszerbetöltő betöltése...'
|
|
@@INITRD@@
|
|
}
|