install report: first cut, generated by the helpers
Every run writes a timestamped install-report.md recording what was installed, changed, kept, skipped, started and run as root. Written for an adversarial read: the person who just ran a setup script off the internet hands it to an agent of their choosing and asks whether it did anything it should not have. Recorded by the HELPERS rather than by the sections. pkg_install and install_config report themselves, so anything installed or written through them appears whether or not a section author remembered — a section that has to remember is a section that will forget, and an incomplete report is worse than none because it reads as a full account. "Kept" is recorded as carefully as "changed". Leaving somebody's .zshrc alone is the claim a reviewer most wants substantiated, and it is invisible unless stated. Secrets are redacted at the moment of recording rather than filtered at render, so a credential never sits in memory formatted for printing. Verified against a POSTGRES_URL and an api_key/password pair. REPORT_FILE is passed through the sudo re-exec. It was not, first time, and the report silently vanished — the third variable this evening lost to env_reset. Unfinished on purpose, paused mid-task at the owner's request: machine-setup's 26 sections still only report through the two shared helpers, so the sections that change system state directly — systemd units, netplan, ufw, sshd drop-ins — are not yet recorded. That is the half a reviewer would care most about. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -72,6 +72,14 @@ esac
|
||||
|
||||
SELF="$SCRIPT_DIR/install.sh"
|
||||
|
||||
# One report for the whole run, not one per half. Both scripts append to this
|
||||
# file, so the person reviewing it sees a single account of what happened rather
|
||||
# than two they have to stitch together and hope are complete.
|
||||
#
|
||||
# Exported before either half starts, and timestamped once here — if each script
|
||||
# made its own name they would differ by however long the first one took.
|
||||
export REPORT_FILE="${REPORT_FILE:-${HOME}/officer-install-report-$(date '+%Y%m%d-%H%M%S').md}"
|
||||
|
||||
# ── Privileges: asked for, not demanded ──
|
||||
#
|
||||
# Run this as YOURSELF. On Linux it needs root for apt, systemd units, useradd,
|
||||
@@ -95,6 +103,7 @@ if [[ "$KERNEL" != "Darwin" && "$EUID" -ne 0 ]]; then
|
||||
OFFICER_ROOT="${OFFICER_ROOT:-}" \
|
||||
SETUP_USERNAME="${SETUP_USERNAME:-}" \
|
||||
MACHINE_ROLE="${MACHINE_ROLE:-}" \
|
||||
REPORT_FILE="${REPORT_FILE:-}" \
|
||||
bash "$SELF" "$@"
|
||||
fi
|
||||
|
||||
|
||||
Reference in New Issue
Block a user