Security Fix
6987d9bf2c
installer: raise generated password entropy from ~23 to ~33 bits
...
generate_diceware_password() built the password from 3 words out of a 96
word list plus a single digit: 96^3 x 10 = 8,847,360 combinations, about
23 bits.
That one password is the desktop login, the 'free' account password, and
the only thing standing in front of the Hub, which runs as root and
displays the root password, the SSH passphrase, the RTL password and the
Vaultwarden admin token. 23 bits is thin for something that valuable, and
the rate limiting in front of it was weaker than intended (see "hub: make
the login lockout that LOGIN_FAIL_MAX described").
Now 4 words plus 2 digits: 96^4 x 100 = 8,493,465,600, about 33 bits,
for the cost of one more word to write down.
- iso/installer.py: generate_diceware_password().
- modules/credentials.nix: the three fallback generators in
root-password-setup, free-password-setup and free-password-migration,
so a machine provisioned without the installer gets the same strength.
Affects new installs only; existing passwords are untouched.
Checked by running the real thing. The installer function was exercised
2000 times: 96 words in the list, always word-word-word-word-NN, 33.0
bits. For the three services, the generator lines were taken from the
script the evaluated module really produces (nix eval on the nixpkgs
revision flake.lock pins) and run 1500 times each: 96 words in each
list, always word-word-word-word-NN, every two-digit suffix from 00 to 99
seen, and no repeated password.
2026-10-02 02:24:29 -05:00
Arena.ai Agent
34cfba4282
docs, hub, installer: say Server + Desktop makes the home IP public
...
Server + Desktop publishes services under the operator's own domain, and
the DNS record for that domain points at the home connection, so anyone
can look up the home IP address. None of the places that offer Server +
Desktop said so.
- README: new section "Server + Desktop and your home IP address" (what
becomes public, what does not, the alternatives, and what happens
technically), plus a note on the role table and in the security
overview.
- SECURITY.md: a matching section, the consequence noted next to "Public
web services exposed only when enabled by the operator", and the
supported versions row no longer pins 1.0.x.
- ISO installer: the Server + Desktop role card ends with the warning.
- Hub: the domain setup text (onboarding, feature setup and domain
reconfiguration share renderDomainNeedsHtml) and the upgrade dialog
carry the same notice.
- Add tests/test_exposure_guards.py. It fails if one of these places
loses the notice or the README anchor stops resolving.
2026-10-01 21:43:47 -05:00
naturallaw777
14db4282b7
ux: simplify domain and router setup guidance
2026-08-22 09:10:05 -05:00
naturallaw777 and arena-agent
f81b27cc19
iso: fix replaceStrings length mismatch in cleanVersion
...
builtins.replaceStrings requires the 'from' and 'to' lists to have the
same length. The 'to' list had a single empty string while 'from' had
three entries (v, newline, CR), which made evaluating image.baseName
fail with: 'from' and 'to' arguments passed to builtins.replaceStrings
have different lengths. Add the two missing empty strings.
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com >
2026-08-05 15:38:21 +00:00
naturallaw777 and arena-agent
5188cca9aa
Improve installer VM compatibility
...
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com >
2026-08-04 19:07:51 +00:00
naturallaw777 and arena-agent
c54823ff68
feat: automated stable releases, versioned ISOs, and Hub version badge
...
- Add release-stable.sh script with automatic tagging, CHANGELOG updates,
GitHub/Gitea release creation, and VERSION file management
- Update iso/common.nix to include version from VERSION file in ISO filename
- Add VERSION file (current: 1.0.3)
- Polish OS version badge in Sovran Hub header (top-right)
- Update README.md download link to versioned ISO
- Update CHANGELOG.md with existing tags (v1.0.0 – v1.0.3)
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com >
2026-07-29 15:11:59 +00:00
copilot-swe-agent[bot]
8869f16fec
feat: implement consistent restart UX across Sovran_SystemsOS Hub
...
- Add Restart Entire System sidebar action with amber treatment and divider
- Add shared restart confirmation dialog with conflict detection
- Update reboot overlay: new title, body copy, status progression, error card
- Improve doReboot(): failure handling, aria-live status messages
- Standardize 'restart required' / 'Restart Entire System' terminology
- Update security.js reboot flow to use shared doReboot()
- Update installer.py button label
- Add .btn-restart-amber, .restart-conflict-box, .sidebar-restart-btn CSS
2026-07-15 16:50:01 +00:00
copilot-swe-agent[bot]
2c5917e8d4
Remove orphaned ./branding.nix import from iso/common.nix
2026-06-10 18:41:49 +00:00
Sovran Systems
18a8b0e088
Add Sovran Hub icon SVG referenced by README
2026-05-23 11:35:09 -05:00
copilot-swe-agent[bot] and naturallaw777
ce55caf66f
fix(installer): pin deployed flake and log message to stable
...
Agent-Logs-Url: https://github.com/naturallaw777/sovran-systems/sessions/4648ebc7-45b1-4fd2-8636-29c15ee484fe
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 14:33:28 +00:00
copilot-swe-agent[bot] and naturallaw777
8f30e233e1
Use theme-safe installer notice styling
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a71df5f0-f463-4c08-b54d-946d97d0aafd
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 01:38:36 +00:00
copilot-swe-agent[bot] and naturallaw777
035e32028c
Add installer prerequisites notice
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a71df5f0-f463-4c08-b54d-946d97d0aafd
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 01:37:54 +00:00
copilot-swe-agent[bot] and naturallaw777
78724d4ac1
Make custom.nix read-write (644) on all new installs
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/1606cde2-b484-4570-a64e-649f80384367
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-30 17:45:45 +00:00
copilot-swe-agent[bot] and naturallaw777
2c2b2c6687
Remove Plymouth, add quiet boot params, add cpu-performance module
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/eda71495-cd38-4408-8d3b-b9d793f6445f
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-30 00:33:32 +00:00
copilot-swe-agent[bot] and naturallaw777
96205e8cdc
Harden GUI timechain detection temp mount handling
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:18:04 +00:00
copilot-swe-agent[bot] and naturallaw777
d4ef0b832f
Refine preservation detection messaging and label fallback
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:15:59 +00:00
copilot-swe-agent[bot] and naturallaw777
af7486d52e
Preserve existing Bitcoin data drive during reinstall
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:13:18 +00:00
copilot-swe-agent[bot] and naturallaw777
47686017ba
Fix chpasswd: remove broken chroot from installer, defer to first-boot service
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/e55c1e70-0958-4d77-a222-52dccc9459b2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 23:10:19 +00:00
copilot-swe-agent[bot] and naturallaw777
5fa5d8cf41
fix(installer): generate diceware password during install and display before reboot
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/ed1c266b-2f38-4831-9ba0-fa0f59cd162b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 21:38:18 +00:00
copilot-swe-agent[bot] and naturallaw777
a22092ba5c
Fix ISO build warning: use lib.mkForce to override root password options
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/aa57a263-33e8-4379-9cc3-379125371b46
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 02:14:14 +00:00
copilot-swe-agent[bot] and naturallaw777
df4839ecc5
Cleanup: Remove reverse SSH tunnel code, fix documentation accuracy
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3941ead1-cb20-4686-92bb-46e447791ae3
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 00:19:25 +00:00
copilot-swe-agent[bot] and naturallaw777
f9a23b6933
Build remote deployment system using Headscale (self-hosted Tailscale)
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/7fa16927-250f-4af4-bb11-e22ef7b2c997
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-11 23:33:35 +00:00
copilot-swe-agent[bot] and naturallaw777
b120d19e38
feat: add remote deployment mode (remote-deploy.nix, headless installer, ISO SSH/mDNS)
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8e2ed0be-2db9-4437-81d7-c6efec45d6db
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-11 22:27:55 +00:00
copilot-swe-agent[bot] and naturallaw777
cf3115dc2d
Fix installer branding and replace complete screen with auto-reboot
...
- Replace all "Sovran SystemsOS" (with space) with "Sovran_SystemsOS"
- Line 241: landing page title
- Line 262: internet notice text
- Line 328: welcome/role-selection hero title (was "Sovran Systems")
- Line 910: install progress title
- Replace push_complete method: remove credentials screen (username,
password, first-boot note, reboot button) and replace with a simple
status page that says "Rebooting…" then auto-reboots after 3 seconds
via GLib.timeout_add_seconds
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/2a39f2d5-6aef-42cf-a94a-e1db5c6a601a
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-08 16:59:14 +00:00
copilot-swe-agent[bot] and naturallaw777
b4685256af
fix: pre-resolve flake lock to staging-dev during installation
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/14550e27-a253-453b-b454-097575e924fa
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-08 02:48:59 +00:00
naturallaw777
60b9347ebb
updated installer.py
2026-04-07 17:59:53 -05:00
copilot-swe-agent[bot] and naturallaw777
b7959082c9
Fix installer DEPLOYED_FLAKE to point to staging-dev branch
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/43e96fac-1140-42e5-9981-00069570967c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 21:40:26 +00:00
copilot-swe-agent[bot] and naturallaw777
0eec097ecd
fix(installer): improve error handling for deployed flake.nix write
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/b7dfaecc-2b2e-4f5f-bb9a-f97ced90e76e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 20:20:36 +00:00
copilot-swe-agent[bot] and naturallaw777
f66443aa93
fix(installer): write deployed flake.nix and remove flake.lock after install cleanup
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/b7dfaecc-2b2e-4f5f-bb9a-f97ced90e76e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 20:18:36 +00:00
naturallaw777
a6ca190dbf
update flake and installer
2026-04-07 13:11:39 -05:00
copilot-swe-agent[bot] and naturallaw777
99b299ece3
Fix chpasswd: run directly from host with --root /mnt, no chroot needed
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3ff98bf4-8f62-4c81-90fd-36854e88266f
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 17:14:32 +00:00
copilot-swe-agent[bot] and naturallaw777
ac2355f18e
Fix chpasswd: find binary in Nix store and pipe password inline
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/630a25f6-417a-47de-b163-b519252b403c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 16:43:50 +00:00
copilot-swe-agent[bot] and naturallaw777
500bb44e96
Fix chpasswd not found by using nixos-enter instead of bare chroot
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/1bb103de-c4a5-4701-b1b8-6aad670b97c3
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 15:45:30 +00:00
copilot-swe-agent[bot] and naturallaw777
ca1dd18650
Factory security: per-device SSH passphrase, factory seal, password onboarding, remove PDF generator
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/4222f228-615c-4303-8286-979264c6f782
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 14:23:59 +00:00
copilot-swe-agent[bot] and naturallaw777
f678b9980f
feat: clean up /mnt/etc/nixos after nixos-install, keep only 5 required files
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/08d1a4eb-697e-46d4-bb8e-71af6bb4316f
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 02:02:19 +00:00
copilot-swe-agent[bot] and naturallaw777
c21d11260a
Remove PDF mention, icon, and fix reboot button color in push_complete
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3bb82d50-1a0b-4f1d-b186-1e4efde002d1
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-06 23:18:39 +00:00
Sovran_Systems
3818a71a50
Merge pull request #84 from naturallaw777/copilot/add-hardware-configuration-to-modules
...
Fix nixos-install: wire hardware-configuration.nix into flake and installer
2026-04-05 12:51:00 -05:00
copilot-swe-agent[bot] and naturallaw777
826b4a67f4
grey out node/server roles when no second internal drive detected
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/30ed5e6b-2d61-415c-ba07-aba31dbcd839
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 17:50:20 +00:00
copilot-swe-agent[bot] and naturallaw777
9381cad03a
Fix NixOS install: add hardware-configuration.nix to flake modules and installer
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/5db1cd99-2067-4b5c-ba11-3e9aa8fde973
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 17:50:18 +00:00
copilot-swe-agent[bot] and naturallaw777
d4cd416f0e
fix: copy role-state.nix and custom.nix to host /etc/nixos before nixos-install
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/38396f35-c812-43e5-9bf0-f7bd611cbba7
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 16:54:29 +00:00
copilot-swe-agent[bot] and naturallaw777
9f43bb38f0
Add --impure flag to nixos-install command
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/7723d784-dc2c-41da-b523-451a63f335eb
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 16:23:40 +00:00
copilot-swe-agent[bot] and naturallaw777
18e0111555
Drop disko: use direct sgdisk+mkfs+mount in installer, remove disko package and disko.nix
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3dbc739b-c3da-432d-b070-16217e58c76b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 15:40:42 +00:00
copilot-swe-agent[bot] and naturallaw777
e60d6dac03
Fix disko command: use single format,mount call since disks are pre-wiped
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/80b0e65c-24c9-4448-9fdb-870891ecc30e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 15:18:54 +00:00
copilot-swe-agent[bot] and naturallaw777
b701db897a
Fix disko mount failure by splitting destroy and format,mount into separate calls
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/0f9fe8d2-554e-4048-9dba-5a3c3c663410
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 14:41:16 +00:00
copilot-swe-agent[bot] and naturallaw777
e4816bc54d
Fix disko.nix partition syntax and remove broken Spinner from Plymouth theme
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/487cd80b-c747-44b8-9479-d3f7f7cc3328
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 14:02:40 +00:00
copilot-swe-agent[bot] and naturallaw777
8359eb6d34
Fix three installer blockers: disko --yes-wipe-all-disks, stdin=DEVNULL, nixos-install --no-root-password
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/477c45ee-0958-4ba8-9612-a3be1bff9c6d
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 13:36:15 +00:00
copilot-swe-agent[bot] and naturallaw777
783f85cb5c
Fix ISO installer: remove ports dialog, fix Plymouth paths/logo, add welcome page, fix pixelated icon, fix disko args
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/6b00bbbd-8ed5-4ef2-b2fc-bfbe6361e77c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 06:33:44 +00:00
copilot-swe-agent[bot] and naturallaw777
c6078b5f89
Fix disko mode, 2 TB threshold, add interactive disk selection, fix data_path scoping
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a0f15fe6-f9a7-4f43-9f9d-5892b0f3aba4
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 05:21:18 +00:00
copilot-swe-agent[bot] and naturallaw777
c10ba0d5a5
feat: enforce 128 GB minimum, skip data disk for Desktop Only role
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/2be6c138-feda-4c5d-9bd8-0e5f2f6416bc
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 05:07:55 +00:00
copilot-swe-agent[bot] and naturallaw777
f0ada0770a
Add dynamic port status detection and improved port forwarding instructions
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/cd52f6a2-250b-49e3-8558-aa2ae7512d1b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-03 17:29:02 +00:00