Files
esh-pfi-infrastructure/services/pve-nag-patch

pve-nag-patch: no "No valid subscription" popup on our Proxmox hosts

Prime, 2026-10-03: "every host". UI-only. One static file (proxmox-widget-toolkit's proxmoxlib.js) gets one edit, so no service restarts and no change to how Proxmox runs. Hard-refresh the browser once.

What it changes. In Proxmox.Utils.checked_command, the status test that guards the popup becomes false. The else-branch then runs the guarded command directly, so login, apt "Refresh" and the rest work with no popup. The common void(Ext.Msg.show… trick would swallow those commands. The regex is anchored on the popup itself: the status test must be followed immediately by ) { Ext.Msg.show({ title: gettext('No valid subscription'). The subscription panel's own status test stays untouched.

Why anchored: before rollout, I ran the patch offline against a copy of each host's live file. An unanchored first version would have patched the wrong line, the subscription panel, on nh3-pve and pfi-pve. Their older toolkits (4.3.11, 4.3.6) wrap the test across two lines (res⏎ .data.status…).

Kept across updates: /etc/apt/apt.conf.d/86pve-nag-patch re-runs /usr/local/sbin/pve-nag-patch after every dpkg run. Proven on nh3-pve-2 with apt-get install --reinstall proxmox-widget-toolkit: the original came back and the hook re-patched it. The script is idempotent and always exits 0, so it can never fail an apt run. It also leaves alone a file that another de-nag tool already handled.

Host Toolkit State (2026-10-03 1326)
nh3-pve-2 5.2.10 patched + hook (hook proven by reinstall)
nh3-pve 4.3.11 patched + hook
pfi-pve 4.3.6 patched + hook
esh-pve 4.3.17 patched + hook
esh-nas-pve 4.3.17 already de-nagged before this: pve-nag-buster (86pve-nags) + the community no-nag-script; file shows res.false. Left alone
esh-pve-2 n/a unplugged; run the playbook when it is back
sfsrv-ana n/a SureFire client hypervisor: NOT touched (coordinate first)
pbs-ana / pbs-nh3 n/a PBS has the same popup, but infra-ops has no sudo there. Not done

Checks run:

  • each served file passes node --check;
  • our marker is present;
  • the popup's status test is gone;
  • positive control: the same grep finds the live test in every unpatched original;
  • node --check caught a deliberately broken copy.
scripts/elway infra-ops@<host> --playbook playbooks/pve-nag-patch.yaml      # install / re-apply

Undo: remove /etc/apt/apt.conf.d/86pve-nag-patch and /usr/local/sbin/pve-nag-patch, then apt-get install --reinstall proxmox-widget-toolkit.