erplibre/script
Mathieu Benoit e3138bea7e [FIX] proxmox : ne pas démarrer le pare-feu depuis l'extérieur
Une révision adversariale de la réparation à distance a rendu un constat que
ses TROIS lentilles — réseau, systemd, shell — ont trouvé indépendamment :
démarrer pve-firewall peut couper le ssh qui répare. Sa configuration vit dans
/var/lib/pve-cluster/config.db, donc elle est invisible tant que /etc/pve
n'est pas monté — c'est-à-dire exactement dans l'état qu'on répare. On
appliquerait des règles qu'on ne peut pas lire, sur la seule voie d'accès à la
machine.

Il n'est pas nécessaire au but : le stockage et le suivi demandent pve-cluster
et pvestatd, l'interface web pveproxy. Il repartira au prochain démarrage,
quand /etc/pve sera monté à temps. Le retirer de la liste coûte donc rien et
supprime le seul geste qui pouvait isoler un hôte.

Deux autres constats de la même révision, également réels.

Le gel de cloud-init gardait sur l'EXISTENCE du fichier. Or « printf … > » le
TRONQUE avant d'écrire : une coupure au mauvais moment laisse zéro octet, et
la garde annonce « déjà gelé » pour toujours. cloud-init continue de remettre
127.0.1.1 à chaque démarrage et le défaut redevient invisible — celui-là même
que ce code existe pour supprimer. La garde porte maintenant sur le CONTENU.

Et les adresses de lien-local passaient pour routables. Mesuré : « hostname
--ip-address » peut ne rendre QUE des fe80::, et une APIPA en 169.254 passait
le seul test « ne commence pas par 127. ». pmxcfs n'a alors rien
d'utilisable, mais le diagnostic concluait l'inverse et renvoyait vers
journalctl au lieu de /etc/hosts.

Enfin « la sonde n'a pas répondu » n'est plus lu comme « rien n'est monté » :
un dépassement de délai rend les mêmes vides, et on affirmait une cause qu'on
n'avait pas constatée.

--- EN ---

An adversarial review of the remote repair produced one finding all THREE of
its lenses — network, systemd, shell — reached independently: starting
pve-firewall can cut the ssh doing the repair. Its configuration lives in
/var/lib/pve-cluster/config.db, so it is invisible while /etc/pve is unmounted
— exactly the state being repaired. We would apply rules we cannot read, over
the machine's only way in.

It is not needed for the goal: storage and monitoring need pve-cluster and
pvestatd, the web interface pveproxy. It will come back at the next boot, when
/etc/pve mounts in time. Removing it from the list costs nothing and removes
the one gesture that could isolate a host.

Two more findings from the same review, equally real.

The cloud-init freeze guarded on the file's EXISTENCE. But "printf … >"
TRUNCATES before writing: an ill-timed cut leaves zero bytes, and the guard
then reports "already frozen" forever. cloud-init keeps putting 127.0.1.1 back
at every boot and the defect becomes invisible again — the very one this code
exists to remove. The guard now looks at the CONTENT.

And link-local addresses counted as routable. Measured: "hostname
--ip-address" can return ONLY fe80:: entries, and an APIPA 169.254 passed the
lone "does not start with 127." test. pmxcfs then has nothing usable, yet the
diagnosis concluded the opposite and pointed at journalctl instead of
/etc/hosts.

Finally "the probe did not answer" is no longer read as "nothing is mounted": a
timeout returns the same emptiness, and we were asserting a cause we had not
measured.

Assisted-by: Claude Opus 5
(cherry picked from commit fa9fb729d82e8d1a8e4fb549cc8061c7281b5dcb)
2026-08-29 01:53:03 -04:00
..
addons [ADD] script addons prod to dev support disable_payment_provider 2026-08-25 03:31:12 -04:00
analyse [FIX] analyse: chercher la liste de prix, pas son identifiant externe 2026-08-25 03:31:12 -04:00
apache [ADD] apache configuration template 2025-10-31 01:31:21 -04:00
code [UPD] script Format 2026-03-14 23:26:31 -04:00
code_generator [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
config [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
database [FIX] db_restore: la sonde du mot de passe maître ne validait rien 2026-08-25 03:19:18 -04:00
deployment [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
docker [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
execute [FIX] script: différer les annotations, la 12 tourne en Python 3.7 2026-08-23 03:13:58 -04:00
forgejo [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
fork_github_repo [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
git [FIX] script: différer les annotations, la 12 tourne en Python 3.7 2026-08-23 03:13:58 -04:00
ide [UPD] script Format 2026-03-14 23:26:31 -04:00
install [FIX] install : compiler pykcs11 avec SWIG 4.3 et au-delà 2026-08-23 02:11:50 -04:00
maintenance [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
manifest [FIX] manifest: give repo init a branch name, not a bare SHA 2026-08-10 03:10:50 -04:00
mobile [FIX] mobile: the bundle check refused a real build 2026-08-25 03:28:39 -04:00
nginx [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
odoo [FIX] migration: la sonde de visibilité déclare ce qu'elle n'a pas prouvé 2026-08-25 03:28:39 -04:00
performance [ADD] script performance: use tool to test request per second on website 2025-11-01 01:09:32 -04:00
poetry [ADD] poetry: pin a dependency per architecture 2026-08-16 06:11:44 -04:00
postgresql/migration [UPD] script Format 2026-03-14 23:26:31 -04:00
process [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
proxmox [FIX] proxmox : ne pas démarrer le pare-feu depuis l'extérieur 2026-08-29 01:53:03 -04:00
qemu [ADD] qemu : déployer Proxmox VE (amd64, arm64) 2026-08-23 03:28:03 -04:00
restful [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
selenium [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
shell_script_odoo [ADD] brin_advisor brin_cluster 2026-08-07 02:52:33 -04:00
statistic [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
system [ADD] script system: search_docker_compose_erplibre.sh 2024-05-03 23:13:59 -04:00
systemd [FIX] systemd : lancer run.sh par bash, contre les echecs 203/EXEC 2026-08-23 02:11:50 -04:00
terminal [IMP] todo support odoo upgrade 2025-10-31 01:43:26 -04:00
test [REF] déploiement : un seul socle pour ce qui décrit le système invité 2026-08-25 03:28:39 -04:00
todo [FIX] proxmox : ne pas démarrer le pare-feu depuis l'extérieur 2026-08-29 01:53:03 -04:00
version [REM] install: drop Ubuntu 20.04 and 22.04 2026-08-16 23:33:49 -04:00
__init__.py [IMP] Copy ERPLibre from https://github.com/mathbentech/InstallScript 2020-04-20 03:56:45 -04:00
generate_config.sh [FIX] generate_config: drop odoo_design-themes from the addons path 2026-08-07 02:09:40 -04:00
lib_asyncio.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
make.sh [FIX] script python: missing color log error 2024-05-03 23:13:59 -04:00
open_terminal_code_generator.sh [IMP] todo support odoo upgrade 2025-10-31 01:43:26 -04:00