erplibre/test
Mathieu Benoit e3138bea7e [FIX] proxmox : ne pas démarrer le pare-feu depuis l'extérieur
Une révision adversariale de la réparation à distance a rendu un constat que
ses TROIS lentilles — réseau, systemd, shell — ont trouvé indépendamment :
démarrer pve-firewall peut couper le ssh qui répare. Sa configuration vit dans
/var/lib/pve-cluster/config.db, donc elle est invisible tant que /etc/pve
n'est pas monté — c'est-à-dire exactement dans l'état qu'on répare. On
appliquerait des règles qu'on ne peut pas lire, sur la seule voie d'accès à la
machine.

Il n'est pas nécessaire au but : le stockage et le suivi demandent pve-cluster
et pvestatd, l'interface web pveproxy. Il repartira au prochain démarrage,
quand /etc/pve sera monté à temps. Le retirer de la liste coûte donc rien et
supprime le seul geste qui pouvait isoler un hôte.

Deux autres constats de la même révision, également réels.

Le gel de cloud-init gardait sur l'EXISTENCE du fichier. Or « printf … > » le
TRONQUE avant d'écrire : une coupure au mauvais moment laisse zéro octet, et
la garde annonce « déjà gelé » pour toujours. cloud-init continue de remettre
127.0.1.1 à chaque démarrage et le défaut redevient invisible — celui-là même
que ce code existe pour supprimer. La garde porte maintenant sur le CONTENU.

Et les adresses de lien-local passaient pour routables. Mesuré : « hostname
--ip-address » peut ne rendre QUE des fe80::, et une APIPA en 169.254 passait
le seul test « ne commence pas par 127. ». pmxcfs n'a alors rien
d'utilisable, mais le diagnostic concluait l'inverse et renvoyait vers
journalctl au lieu de /etc/hosts.

Enfin « la sonde n'a pas répondu » n'est plus lu comme « rien n'est monté » :
un dépassement de délai rend les mêmes vides, et on affirmait une cause qu'on
n'avait pas constatée.

--- EN ---

An adversarial review of the remote repair produced one finding all THREE of
its lenses — network, systemd, shell — reached independently: starting
pve-firewall can cut the ssh doing the repair. Its configuration lives in
/var/lib/pve-cluster/config.db, so it is invisible while /etc/pve is unmounted
— exactly the state being repaired. We would apply rules we cannot read, over
the machine's only way in.

It is not needed for the goal: storage and monitoring need pve-cluster and
pvestatd, the web interface pveproxy. It will come back at the next boot, when
/etc/pve mounts in time. Removing it from the list costs nothing and removes
the one gesture that could isolate a host.

Two more findings from the same review, equally real.

The cloud-init freeze guarded on the file's EXISTENCE. But "printf … >"
TRUNCATES before writing: an ill-timed cut leaves zero bytes, and the guard
then reports "already frozen" forever. cloud-init keeps putting 127.0.1.1 back
at every boot and the defect becomes invisible again — the very one this code
exists to remove. The guard now looks at the CONTENT.

And link-local addresses counted as routable. Measured: "hostname
--ip-address" can return ONLY fe80:: entries, and an APIPA 169.254 passed the
lone "does not start with 127." test. pmxcfs then has nothing usable, yet the
diagnosis concluded the opposite and pointed at journalctl instead of
/etc/hosts.

Finally "the probe did not answer" is no longer read as "nothing is mounted": a
timeout returns the same emptiness, and we were asserting a cause we had not
measured.

Assisted-by: Claude Opus 5
(cherry picked from commit fa9fb729d82e8d1a8e4fb549cc8061c7281b5dcb)
2026-08-29 01:53:03 -04:00
..
code_generator [FIX] make test with coverage: missing coverage parameter 2023-03-04 23:34:37 -05:00
mail_sandbox.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_analyse_custom_field.py [ADD] analyse: inspect an Odoo database without restoring it 2026-08-10 03:10:50 -04:00
test_analyse_lib.py [ADD] analyse: inspect an Odoo database without restoring it 2026-08-10 03:10:50 -04:00
test_analyse_schema_size.py [ADD] analyse: inspect an Odoo database without restoring it 2026-08-10 03:10:50 -04:00
test_analyse_view_custom.py [ADD] analyse: diff each website copy against the view it shadows 2026-08-23 02:09:59 -04:00
test_anonymize.py [ADD] analyse: anonymiser une copie, sans IA et sans rien casser 2026-08-25 03:31:12 -04:00
test_auto_execute.py [ADD] migration: make Enter mean the answer you always give 2026-08-22 07:23:59 -04:00
test_check_addons_exist.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_check_cow_views_render.py [ADD] migration: prédire la copie de site qui rendra 500 après le palier 2026-08-25 03:19:18 -04:00
test_check_filestore.py [ADD] filestore: purge once at the end, tidy at the restore, see the 30 MB 2026-08-23 02:09:59 -04:00
test_check_hidden_models.py [FIX] migration: la sonde de visibilité déclare ce qu'elle n'a pas prouvé 2026-08-25 03:28:39 -04:00
test_check_instance_state.py [ADD] analyse: l'état d'une instance, lu pour l'usage qu'on en fait 2026-08-25 03:28:39 -04:00
test_check_migration_quality.py [FIX] analyse: dire CE QUI est parti avec une pièce jointe 2026-08-25 03:28:39 -04:00
test_check_module_dependency.py [ADD] analyse: i, u et t — installés, en cours, applications 2026-08-23 04:03:18 -04:00
test_check_module_package.py [ADD] analyse: offer to install the suggested modules that are ready 2026-08-23 02:09:59 -04:00
test_check_stale_scss.py [FIX] migration: reset the stale SCSS after the bump, not before 2026-08-22 07:23:59 -04:00
test_code_generator_tools.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_config_file.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_database_cleanup.py [ADD] migration: « t » shows where the migration stands 2026-08-22 07:23:59 -04:00
test_database_tools.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_dms_access_repair.py [ADD] migration: repair DMS at the 13 bump, and catch the whole class 2026-08-22 07:24:00 -04:00
test_docker_update_version.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_error_retry_loop.py [ADD] migration: offer the theme uninstall where the theme is blamed 2026-08-22 07:24:00 -04:00
test_execute.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
test_fix_cow_render.py [ADD] migration: prédire la copie de site qui rendra 500 après le palier 2026-08-25 03:19:18 -04:00
test_fix_duplicate_index.py [ADD] migration: retirer les index qu'Odoo 17 a créés en double 2026-08-25 03:19:18 -04:00
test_fix_migration_120_to_130.py [ADD] migration: decode percent-encoded page anchors before the 13 bump 2026-08-23 02:20:19 -04:00
test_fix_view_type.py [ADD] migration: convert the <tree> tags Odoo 18 renamed to <list> 2026-08-22 07:24:00 -04:00
test_format_file_to_commit.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_git_tool.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_install_swig_compat.py [FIX] install : compiler pykcs11 avec SWIG 4.3 et au-delà 2026-08-23 02:11:50 -04:00
test_iscompatible.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_kdbx_manager.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
test_kill_process_by_port.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
test_mail_account_setup.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_accounts.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_charset.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_compose.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_crypto.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_imap_transport.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_live_server.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_menu.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_secrets.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_send.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_store.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_sync.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_account.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_help.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_layout.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_log.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_refresh.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_resize.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_splitter.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_mail_tui_text.py [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
test_master_password_retry.py [FIX] db_restore: la sonde du mot de passe maître ne validait rien 2026-08-25 03:19:18 -04:00
test_migration_form_back.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
test_migration_status.py [ADD] migration: repair views whose stored type contradicts their parent 2026-08-22 07:24:00 -04:00
test_migration_tools_i18n.py [ADD] migration: prédire la copie de site qui rendra 500 après le palier 2026-08-25 03:19:18 -04:00
test_mobile_bundle_transfer.py [FIX] mobile: the bundle check refused a real build 2026-08-25 03:28:39 -04:00
test_monitoring.py [ADD] analyse: anonymiser une copie, sans IA et sans rien casser 2026-08-25 03:31:12 -04:00
test_old_python_annotations.py [FIX] script: différer les annotations, la 12 tourne en Python 3.7 2026-08-23 03:13:58 -04:00
test_openupgrade_analysis.py [ADD] migration quality: lay OpenUpgrade's declared changes over the real ones 2026-08-22 07:24:00 -04:00
test_plan.base.md [ADD] test: add bilingual test plan with mmg 2026-03-11 23:07:01 -04:00
test_plan.fr.md [ADD] test: add bilingual test plan with mmg 2026-03-11 23:07:01 -04:00
test_plan.md [ADD] test: add bilingual test plan with mmg 2026-03-11 23:07:01 -04:00
test_prompt_defaults.py [ADD] migration: announce the countdown, and cycle three panel states 2026-08-22 07:23:59 -04:00
test_proxmox_deploy.py [FIX] proxmox : ne pas démarrer le pare-feu depuis l'extérieur 2026-08-29 01:53:03 -04:00
test_proxmox_form.py [ADD] déploiement : la VM clone le dépôt distant, pas ce checkout 2026-08-29 01:53:02 -04:00
test_qemu_cleanup.py [FIX] nettoyage : les enfants s'en vont avec leur rebond 2026-08-25 03:31:12 -04:00
test_qemu_deploy_form_disk.py [FIX] test : ne pas dépendre de la langue de l'interface 2026-08-25 03:19:18 -04:00
test_qemu_deploy_form_install.py [REF] déploiement : un seul socle pour ce qui décrit le système invité 2026-08-25 03:28:39 -04:00
test_qemu_deploy_monitor.py [FIX] proxmox : l'installation partait sur la mauvaise machine 2026-08-25 03:28:39 -04:00
test_qemu_desktop_tools.py [FIX] script todo: régler l'écran de l'émulateur au lancement, densité comprise 2026-08-23 02:07:42 -04:00
test_qemu_emulator_menu.py [FIX] test : ne pas dépendre de la langue de l'interface 2026-08-25 03:19:18 -04:00
test_qemu_forgejo.py [ADD] script todo: ouvrir l'écran d'une VM avec virt-viewer 2026-08-23 02:07:42 -04:00
test_qemu_gpu.py [ADD] qemu : régler le mode CPU, les écrans et le réseau d'une VM 2026-08-23 02:07:42 -04:00
test_qemu_install_profile.py [FIX] qemu : ne pas poser ERPLibre sur une VM Proxmox VE 2026-08-25 03:17:13 -04:00
test_qemu_install_summary.py [FIX] script todo: résumer les erreurs au lieu de chercher « error » 2026-08-23 02:07:42 -04:00
test_qemu_monitor_pve.py [FIX] suivi : relevé Proxmox squelettique, index par nom, état terminal 2026-08-29 01:53:02 -04:00
test_qemu_monitor_telemetry.py [ADD] script todo: dire depuis quand un journal d'installation est muet 2026-08-23 02:07:42 -04:00
test_qemu_monitor_vmstats.py [ADD] suivi : les statistiques de chaque VM (écriture, RAM, disque) 2026-08-23 02:20:10 -04:00
test_qemu_motd.py [ADD] qemu guide: dire comment démarrer le bureau, sur les VM qui en ont un 2026-08-23 02:07:42 -04:00
test_qemu_proxmox.py [ADD] qemu : déployer Proxmox VE (amd64, arm64) 2026-08-23 03:28:03 -04:00
test_qemu_tunnel_menu.py [ADD] script todo: ouvrir l'écran d'une VM avec virt-viewer 2026-08-23 02:07:42 -04:00
test_qemu_vm_table.py [IMP] script todo: RAM utilisée et uptime dans les infos avancées d'une VM 2026-08-23 02:07:42 -04:00
test_reset_stale_cow_prompt.py [ADD] migration: repair views whose stored type contradicts their parent 2026-08-22 07:24:00 -04:00
test_reset_stale_cow_tui.py [ADD] migration: repair views whose stored type contradicts their parent 2026-08-22 07:24:00 -04:00
test_restore_config_defaults.py [ADD] migration: recréer les réglages qu'aucun événement ne remet 2026-08-25 03:19:18 -04:00
test_run_sh_auto_db.py [ADD] run: choisir la base au démarrage, sans jamais bloquer 2026-08-23 17:26:41 -04:00
test_script_permissions.py [FIX] test: check the exec bit git stores, not the mode umask decides 2026-08-22 07:23:59 -04:00
test_smoke_final_url.py [FIX] smoke: two sites still unpacked three fields from the failure tuple 2026-08-23 02:07:42 -04:00
test_smoke_internal_ui.py [FIX] smoke: judge the back office AFTER the repair, and say why it failed 2026-08-22 07:23:59 -04:00
test_smoke_public_url.py [FIX] smoke: name the URL that actually failed, keep the previous log 2026-08-23 02:07:42 -04:00
test_target_version_default.py [ADD] migration: an auto-run that takes the default after five seconds 2026-08-22 07:23:59 -04:00
test_theme_on_error.py [ADD] migration: offer the theme uninstall where the theme is blamed 2026-08-22 07:24:00 -04:00
test_todo.py [FIX] security: the KeePass password leaves the command line too 2026-08-23 02:11:50 -04:00
test_todo_deploy_form_lib.py [FIX] deploy : la branche du dépôt, et la sortie pendant qu'elle arrive 2026-08-25 03:19:18 -04:00
test_todo_deploy_form_parity.py [REF] déploiement : la branche, le profil et le type se choisissent par VM 2026-08-25 03:31:12 -04:00
test_todo_deploy_progress.py [FIX] proxmox : viser la bonne machine, et dire la vérité sur le disque 2026-08-25 03:28:39 -04:00
test_todo_file_browser.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
test_todo_i18n.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
test_todo_menu.py [ADD] analyse: ausculter une base qui n'est pas ici 2026-08-25 03:28:39 -04:00
test_todo_sshfs.py [FIX] sshfs : n'annoncer un montage que s'il a eu lieu 2026-08-23 02:20:15 -04:00
test_todo_upgrade_archive.py [ADD] migration: keep the previous log when a run restarts 2026-08-17 01:25:23 -04:00
test_todo_upgrade_cow_prompt.py [ADD] migration: make Enter mean the answer you always give 2026-08-22 07:23:59 -04:00
test_todo_upgrade_repairs.py [ADD] migration: brancher les deux réparations qui ne tournaient jamais 2026-08-25 03:28:39 -04:00
test_todo_upgrade_steps.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
test_tooling_requirements.py [ADD] test: what the tooling imports must be declared 2026-08-17 00:40:01 -04:00
test_uninstall_addons_theme.py [ADD] migration: make Enter mean the answer you always give 2026-08-22 07:23:59 -04:00
test_uninstall_module_list.py [FIX] migration: un clone refait rejoue la liste de son palier 2026-08-23 04:35:58 -04:00
test_uninstall_verified.py [FIX] migration: un module fautif n'emporte plus tout le lot 2026-08-25 03:19:18 -04:00
test_version.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00