Security Fix
6987d9bf2c
installer: raise generated password entropy from ~23 to ~33 bits
...
generate_diceware_password() built the password from 3 words out of a 96
word list plus a single digit: 96^3 x 10 = 8,847,360 combinations, about
23 bits.
That one password is the desktop login, the 'free' account password, and
the only thing standing in front of the Hub, which runs as root and
displays the root password, the SSH passphrase, the RTL password and the
Vaultwarden admin token. 23 bits is thin for something that valuable, and
the rate limiting in front of it was weaker than intended (see "hub: make
the login lockout that LOGIN_FAIL_MAX described").
Now 4 words plus 2 digits: 96^4 x 100 = 8,493,465,600, about 33 bits,
for the cost of one more word to write down.
- iso/installer.py: generate_diceware_password().
- modules/credentials.nix: the three fallback generators in
root-password-setup, free-password-setup and free-password-migration,
so a machine provisioned without the installer gets the same strength.
Affects new installs only; existing passwords are untouched.
Checked by running the real thing. The installer function was exercised
2000 times: 96 words in the list, always word-word-word-word-NN, 33.0
bits. For the three services, the generator lines were taken from the
script the evaluated module really produces (nix eval on the nixpkgs
revision flake.lock pins) and run 1500 times each: 96 words in each
list, always word-word-word-word-NN, every two-digit suffix from 00 to 99
seen, and no repeated password.
2026-10-02 02:24:29 -05:00
Arena.ai Agent
34cfba4282
docs, hub, installer: say Server + Desktop makes the home IP public
...
Server + Desktop publishes services under the operator's own domain, and
the DNS record for that domain points at the home connection, so anyone
can look up the home IP address. None of the places that offer Server +
Desktop said so.
- README: new section "Server + Desktop and your home IP address" (what
becomes public, what does not, the alternatives, and what happens
technically), plus a note on the role table and in the security
overview.
- SECURITY.md: a matching section, the consequence noted next to "Public
web services exposed only when enabled by the operator", and the
supported versions row no longer pins 1.0.x.
- ISO installer: the Server + Desktop role card ends with the warning.
- Hub: the domain setup text (onboarding, feature setup and domain
reconfiguration share renderDomainNeedsHtml) and the upgrade dialog
carry the same notice.
- Add tests/test_exposure_guards.py. It fails if one of these places
loses the notice or the README anchor stops resolving.
2026-10-01 21:43:47 -05:00
naturallaw777
14db4282b7
ux: simplify domain and router setup guidance
2026-08-22 09:10:05 -05:00
naturallaw777 and arena-agent
5188cca9aa
Improve installer VM compatibility
...
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com >
2026-08-04 19:07:51 +00:00
copilot-swe-agent[bot]
8869f16fec
feat: implement consistent restart UX across Sovran_SystemsOS Hub
...
- Add Restart Entire System sidebar action with amber treatment and divider
- Add shared restart confirmation dialog with conflict detection
- Update reboot overlay: new title, body copy, status progression, error card
- Improve doReboot(): failure handling, aria-live status messages
- Standardize 'restart required' / 'Restart Entire System' terminology
- Update security.js reboot flow to use shared doReboot()
- Update installer.py button label
- Add .btn-restart-amber, .restart-conflict-box, .sidebar-restart-btn CSS
2026-07-15 16:50:01 +00:00
copilot-swe-agent[bot] and naturallaw777
ce55caf66f
fix(installer): pin deployed flake and log message to stable
...
Agent-Logs-Url: https://github.com/naturallaw777/sovran-systems/sessions/4648ebc7-45b1-4fd2-8636-29c15ee484fe
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 14:33:28 +00:00
copilot-swe-agent[bot] and naturallaw777
8f30e233e1
Use theme-safe installer notice styling
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a71df5f0-f463-4c08-b54d-946d97d0aafd
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 01:38:36 +00:00
copilot-swe-agent[bot] and naturallaw777
035e32028c
Add installer prerequisites notice
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a71df5f0-f463-4c08-b54d-946d97d0aafd
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-05-21 01:37:54 +00:00
copilot-swe-agent[bot] and naturallaw777
78724d4ac1
Make custom.nix read-write (644) on all new installs
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/1606cde2-b484-4570-a64e-649f80384367
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-30 17:45:45 +00:00
copilot-swe-agent[bot] and naturallaw777
96205e8cdc
Harden GUI timechain detection temp mount handling
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:18:04 +00:00
copilot-swe-agent[bot] and naturallaw777
d4ef0b832f
Refine preservation detection messaging and label fallback
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:15:59 +00:00
copilot-swe-agent[bot] and naturallaw777
af7486d52e
Preserve existing Bitcoin data drive during reinstall
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/8a51f052-83d0-4079-8338-5cfdbb849aa2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-15 20:13:18 +00:00
copilot-swe-agent[bot] and naturallaw777
47686017ba
Fix chpasswd: remove broken chroot from installer, defer to first-boot service
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/e55c1e70-0958-4d77-a222-52dccc9459b2
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 23:10:19 +00:00
copilot-swe-agent[bot] and naturallaw777
5fa5d8cf41
fix(installer): generate diceware password during install and display before reboot
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/ed1c266b-2f38-4831-9ba0-fa0f59cd162b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-12 21:38:18 +00:00
copilot-swe-agent[bot] and naturallaw777
cf3115dc2d
Fix installer branding and replace complete screen with auto-reboot
...
- Replace all "Sovran SystemsOS" (with space) with "Sovran_SystemsOS"
- Line 241: landing page title
- Line 262: internet notice text
- Line 328: welcome/role-selection hero title (was "Sovran Systems")
- Line 910: install progress title
- Replace push_complete method: remove credentials screen (username,
password, first-boot note, reboot button) and replace with a simple
status page that says "Rebooting…" then auto-reboots after 3 seconds
via GLib.timeout_add_seconds
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/2a39f2d5-6aef-42cf-a94a-e1db5c6a601a
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-08 16:59:14 +00:00
copilot-swe-agent[bot] and naturallaw777
b4685256af
fix: pre-resolve flake lock to staging-dev during installation
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/14550e27-a253-453b-b454-097575e924fa
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-08 02:48:59 +00:00
naturallaw777
60b9347ebb
updated installer.py
2026-04-07 17:59:53 -05:00
copilot-swe-agent[bot] and naturallaw777
b7959082c9
Fix installer DEPLOYED_FLAKE to point to staging-dev branch
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/43e96fac-1140-42e5-9981-00069570967c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 21:40:26 +00:00
copilot-swe-agent[bot] and naturallaw777
0eec097ecd
fix(installer): improve error handling for deployed flake.nix write
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/b7dfaecc-2b2e-4f5f-bb9a-f97ced90e76e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 20:20:36 +00:00
copilot-swe-agent[bot] and naturallaw777
f66443aa93
fix(installer): write deployed flake.nix and remove flake.lock after install cleanup
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/b7dfaecc-2b2e-4f5f-bb9a-f97ced90e76e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 20:18:36 +00:00
naturallaw777
a6ca190dbf
update flake and installer
2026-04-07 13:11:39 -05:00
copilot-swe-agent[bot] and naturallaw777
99b299ece3
Fix chpasswd: run directly from host with --root /mnt, no chroot needed
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3ff98bf4-8f62-4c81-90fd-36854e88266f
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 17:14:32 +00:00
copilot-swe-agent[bot] and naturallaw777
ac2355f18e
Fix chpasswd: find binary in Nix store and pipe password inline
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/630a25f6-417a-47de-b163-b519252b403c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 16:43:50 +00:00
copilot-swe-agent[bot] and naturallaw777
500bb44e96
Fix chpasswd not found by using nixos-enter instead of bare chroot
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/1bb103de-c4a5-4701-b1b8-6aad670b97c3
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 15:45:30 +00:00
copilot-swe-agent[bot] and naturallaw777
ca1dd18650
Factory security: per-device SSH passphrase, factory seal, password onboarding, remove PDF generator
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/4222f228-615c-4303-8286-979264c6f782
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 14:23:59 +00:00
copilot-swe-agent[bot] and naturallaw777
f678b9980f
feat: clean up /mnt/etc/nixos after nixos-install, keep only 5 required files
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/08d1a4eb-697e-46d4-bb8e-71af6bb4316f
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-07 02:02:19 +00:00
copilot-swe-agent[bot] and naturallaw777
c21d11260a
Remove PDF mention, icon, and fix reboot button color in push_complete
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3bb82d50-1a0b-4f1d-b186-1e4efde002d1
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-06 23:18:39 +00:00
Sovran_Systems
3818a71a50
Merge pull request #84 from naturallaw777/copilot/add-hardware-configuration-to-modules
...
Fix nixos-install: wire hardware-configuration.nix into flake and installer
2026-04-05 12:51:00 -05:00
copilot-swe-agent[bot] and naturallaw777
826b4a67f4
grey out node/server roles when no second internal drive detected
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/30ed5e6b-2d61-415c-ba07-aba31dbcd839
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 17:50:20 +00:00
copilot-swe-agent[bot] and naturallaw777
9381cad03a
Fix NixOS install: add hardware-configuration.nix to flake modules and installer
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/5db1cd99-2067-4b5c-ba11-3e9aa8fde973
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 17:50:18 +00:00
copilot-swe-agent[bot] and naturallaw777
d4cd416f0e
fix: copy role-state.nix and custom.nix to host /etc/nixos before nixos-install
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/38396f35-c812-43e5-9bf0-f7bd611cbba7
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 16:54:29 +00:00
copilot-swe-agent[bot] and naturallaw777
9f43bb38f0
Add --impure flag to nixos-install command
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/7723d784-dc2c-41da-b523-451a63f335eb
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 16:23:40 +00:00
copilot-swe-agent[bot] and naturallaw777
18e0111555
Drop disko: use direct sgdisk+mkfs+mount in installer, remove disko package and disko.nix
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/3dbc739b-c3da-432d-b070-16217e58c76b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 15:40:42 +00:00
copilot-swe-agent[bot] and naturallaw777
e60d6dac03
Fix disko command: use single format,mount call since disks are pre-wiped
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/80b0e65c-24c9-4448-9fdb-870891ecc30e
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 15:18:54 +00:00
copilot-swe-agent[bot] and naturallaw777
b701db897a
Fix disko mount failure by splitting destroy and format,mount into separate calls
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/0f9fe8d2-554e-4048-9dba-5a3c3c663410
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 14:41:16 +00:00
copilot-swe-agent[bot] and naturallaw777
8359eb6d34
Fix three installer blockers: disko --yes-wipe-all-disks, stdin=DEVNULL, nixos-install --no-root-password
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/477c45ee-0958-4ba8-9612-a3be1bff9c6d
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 13:36:15 +00:00
copilot-swe-agent[bot] and naturallaw777
783f85cb5c
Fix ISO installer: remove ports dialog, fix Plymouth paths/logo, add welcome page, fix pixelated icon, fix disko args
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/6b00bbbd-8ed5-4ef2-b2fc-bfbe6361e77c
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 06:33:44 +00:00
copilot-swe-agent[bot] and naturallaw777
c6078b5f89
Fix disko mode, 2 TB threshold, add interactive disk selection, fix data_path scoping
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/a0f15fe6-f9a7-4f43-9f9d-5892b0f3aba4
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 05:21:18 +00:00
copilot-swe-agent[bot] and naturallaw777
c10ba0d5a5
feat: enforce 128 GB minimum, skip data disk for Desktop Only role
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/2be6c138-feda-4c5d-9bd8-0e5f2f6416bc
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-05 05:07:55 +00:00
copilot-swe-agent[bot] and naturallaw777
f0ada0770a
Add dynamic port status detection and improved port forwarding instructions
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/cd52f6a2-250b-49e3-8558-aa2ae7512d1b
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-03 17:29:02 +00:00
copilot-swe-agent[bot] and naturallaw777
8a31063ba8
Add network port requirements UI, install notification, and tile port info
...
Agent-Logs-Url: https://github.com/naturallaw777/staging_alpha/sessions/54981eb1-b1c5-4e1a-b587-730f41c59e01
Co-authored-by: naturallaw777 <99053422+naturallaw777@users.noreply.github.com >
2026-04-03 17:03:42 +00:00
naturallaw777
4dc1ebcaa6
updated python installer
2026-03-29 16:23:09 -05:00
naturallaw777
edd7d43456
updated python installer
2026-03-29 16:02:19 -05:00
naturallaw777
ae46d23c5d
removed old result and updated common
2026-03-29 14:46:39 -05:00
naturallaw777
309b8f9d1b
added python installer and common
2026-03-29 12:02:25 -05:00
naturallaw777
ac24f0fb44
added python installer removed bash script
2026-03-29 10:20:00 -05:00