erplibre/script/todo
Mathieu Benoit c046e027e9 [FIX] LongTest : ne pas détruire sous une descente vivante ; blocs ssh
Relecture adversaire du commit précédent : il avait CRÉÉ un danger. Le rapport
s'écrivant maintenant VM par VM, celui de la descente EN COURS est le plus
récent, et « --detruire » l'aurait choisi — qm destroy --purge sur l'arbre que
le processus installait encore. Deux garde-fous : un PID dans le rapport, et
un refus net tant qu'un autre deep_proxmox.py tourne. Le second est nécessaire
car une descente déjà lancée a l'ancien module en mémoire.

Reconnu par ARGUMENT, pas par sous-chaîne : mon propre « pgrep -f
deep_proxmox.py » de surveillance donnait deux faux positifs sur trois.

Trois autres, mêmes preuves :
- un rapport vide plus récent masquait celui qui nommait les VM réelles ;
- detruire() ne créditait jamais l'étage 1 : le décompte était décalé de un
  dans tous les cas, donc l'avertissement sortait toujours ;
- _ssh_config_drop_hosts prenait l'indentation pour de la syntaxe. Sur un bloc
  au corps non indenté, seule la ligne Host partait et ssh rattachait
  « StrictHostKeyChecking no » au bloc précédent — un serveur de production.
  Et un bloc partagé (« Host prod-db vm-a ») partait en entier.

Les cinq correctifs meurent sous mutation.

--- EN ---

Adversarial review of the previous commit: it had CREATED a hazard. With the
report now written VM by VM, the RUNNING descent's is the most recent, and
"--detruire" would have picked it — qm destroy --purge on the tree the process
was still installing. Two guards: a PID in the report, and a flat refusal
while another deep_proxmox.py runs. The second is needed because an
already-running descent holds the old module in memory.

Matched by ARGUMENT, not substring: my own monitoring "pgrep -f
deep_proxmox.py" produced two false positives out of three.

Three more, same evidence:
- a newer empty report masked the one naming the real VMs;
- detruire() never credited level 1: the count was off by one in every case,
  so the warning always fired;
- _ssh_config_drop_hosts took indentation for syntax. On a block with an
  unindented body only the Host line went, and ssh attached
  "StrictHostKeyChecking no" to the preceding block — a production server.
  And a shared block ("Host prod-db vm-a") went entirely.

All five fixes die under mutation.

Assisted-by: claude-opus-5
(cherry picked from commit 7d348d976f96e420b4fec4d879911b658a730ffa)
2026-08-29 01:53:03 -04:00
..
mail [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
auto_ask.py [ADD] migration: announce the countdown, and cycle three panel states 2026-08-22 07:23:59 -04:00
database_manager.py [ADD] analyse: inspect an Odoo database without restoring it 2026-08-10 03:10:50 -04:00
deploy_form_extras.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
deploy_form_lib.py [FIX] proxmox : viser la bonne machine, et dire la vérité sur le disque 2026-08-25 03:28:39 -04:00
deploy_form_plan.py [FIX] proxmox : quatre écrans qui parlaient d'une machine locale 2026-08-25 03:28:39 -04:00
kdbx_manager.py [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
logo_ascii.txt [IMP] bot assistant TODO 2025-04-27 02:40:20 -04:00
longtest_menu.py [FIX] LongTest : sh au lieu de bash, et --detruire trop large 2026-08-29 01:53:03 -04:00
migration_form.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
migration_stats.py [ADD] migration: see and repair the website COW views 2026-08-10 03:10:50 -04:00
migration_status.py [ADD] migration state: read the server log so nobody has to 2026-08-22 07:23:59 -04:00
migration_status_tui.py [FIX] migration state: open the quality screen in its own process 2026-08-22 07:23:59 -04:00
proxmox_deploy_form.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
proxmox_menu.py [ADD] LongTest : jusqu'à quel étage un Proxmox imbriqué tient-il 2026-08-29 01:53:03 -04:00
qemu_access.py [FIX] proxmox : quatre écrans qui parlaient d'une machine locale 2026-08-25 03:28:39 -04:00
qemu_deploy.py [ADD] déploiement : la VM clone le dépôt distant, pas ce checkout 2026-08-29 01:53:02 -04:00
qemu_deploy_form.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
qemu_hardware.py [ADD] qemu : régler le mode CPU, les écrans et le réseau d'une VM 2026-08-23 02:07:42 -04:00
qemu_install.py [REF] déploiement : un seul socle pour ce qui décrit le système invité 2026-08-25 03:28:39 -04:00
qemu_install_monitor.py [FIX] suivi : relevé Proxmox squelettique, index par nom, état terminal 2026-08-29 01:53:02 -04:00
qemu_manage.py [ADD] déploiement : la VM clone le dépôt distant, pas ce checkout 2026-08-29 01:53:02 -04:00
qemu_menu.py [FIX] todo : nettoyer ce que le découpage a laissé derrière 2026-08-25 03:17:13 -04:00
README.base.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.fr.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
source_todo.sh [ADD] install: mise as Python provider, pyenv as fallback 2026-08-16 23:33:49 -04:00
textual_setup.py [ADD] todo: install Textual on demand 2026-08-07 03:22:26 -04:00
todo.json [ADD] todo: QEMU/KVM menu 2026-08-07 03:22:26 -04:00
todo.py [FIX] LongTest : ne pas détruire sous une descente vivante ; blocs ssh 2026-08-29 01:53:03 -04:00
todo_example.json [UPD] TODO: simplify code by reusing method and support same command 2025-04-28 00:35:27 -04:00
todo_file_browser.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
todo_i18n.py [FIX] LongTest : rapport écrit VM par VM, retrait ssh sans bloc nu 2026-08-29 01:53:03 -04:00
todo_prefs.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
todo_telemetry.py [FIX] todo : rendre au découpage ses colonnes de télémétrie 2026-08-25 03:19:18 -04:00
todo_upgrade.py [ADD] migration: brancher les deux réparations qui ne tournaient jamais 2026-08-25 03:28:39 -04:00
version_manager.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00

TODO is an assistant robot to use ERPLibre Execute it with ./script/todo/todo.py or make todo.

For a new project, copy todo_example.json to private/todo/todo_override.json | private/todo/todo_override_private.json and edit it.

The mail/ package is the mail client reachable from Assistant > Mail: several IMAP/SMTP accounts, a local cache, and a Textual TUI. See ../../doc/EMAIL.md.

Where the code lives

todo.py carries the menus and the general helpers. Everything around a single subject sits in its own file, and the whole thing is assembled by mixins on the TODO class — one file, one subject, its header states its boundary.

File What it owns
todo.py the menus, the configuration, the general helpers
qemu_menu.py the QEMU/KVM menu, the image catalogue, the statistics
qemu_deploy.py deciding then running a deployment
qemu_install.py the recipes run inside a VM
qemu_manage.py lifecycle, disks, hardware, cleanup, addresses
qemu_access.py SSH, tunnels, consoles, Android emulator
proxmox_menu.py the same, on a REMOTE Proxmox VE host

The two deployment forms — libvirt here, Proxmox over there — ask the same questions, so they share a foundation rather than each holding a copy:

File What it owns
deploy_form_lib.py pure logic (sizes, plan, totals, spec), the shared CSS, the resource-row factory, the progress view
deploy_form_plan.py the plan's gestures: overrides, locks, copies, renaming, free values
qemu_deploy_form.py what QEMU/KVM adds: desktops, tools, branches, install profiles
proxmox_deploy_form.py what Proxmox adds: host, storage, bridge, VMID, address

A form inherits PlanMixin and provides three hooks: which presets each resource offers, the name a VM would fall back to, and what a lock freezes. test_todo_deploy_form_lib.py fails if a form redefines a gesture the foundation already carries — that is what keeps the architecture from drifting back into two copies.