diff --git a/CHANGELOG.md b/CHANGELOG.md index 38d3429..bec4b02 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,21 @@ +## v0.142.1 — a Docker step no longer leaves the controller and traefik blind (R-858, `09` decision 95) + +> **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.142.1` (`4950030`), sha256 +> `003f882a59abfc10021a1f97a4744ab78ab1e916b1392dcef132e7067f3c62bd`, verified by download. Not vouched at release time. + +**MinAgent impact:** none. A same-day patch release, by the operator's ruling 95 after a live incident. + +- **The incident.** v0.142.0's Docker step on demo-felhom (14:13 UTC) restarted dockerd, which recreates + `/run/docker.sock`. live-restore kept every container running — including `felhom-controller` and `traefik`, which + bind-mount the socket FILE and so kept the deleted inode. The controller could not reach Docker for 1 h 44 min (hub: + DOWN, "docker not reachable"); its own health check stayed "healthy", so the step's health rule PASSED. +- **The fix.** After a Docker step that installed something, the wrapper restarts ONLY the containers that mount + `/var/run/docker.sock` or `/run/docker.sock` (`os-apply: SOCKET-USERS restarted=…`; the apps and the engine untouched). + The guest health reading gains `controller_docker_ok` (`docker exec felhom-controller docker version`), and the health + rule fails when it is false — the consequence, not the mechanism. +- Proven live on demo-hp BEFORE the release (signed undo to 29.7.2): the two restarted, guest / controller / traefik on + the same socket inode, healthy. Red-proofs: `felhom.eu/documentation/audits/os-docker-crash-2026-10-04/partE-incident/`. + ## v0.142.0 — the Docker engine slow lane, the version report, the crash guard (`11` §5.8, §5.9; `09` decisions 87–89) > **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.142.0` (`b1746c2`), sha256 diff --git a/REPORT.md b/REPORT.md index 75db1e5..d654fed 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,9 +1,2 @@ -# REPORT — 2026-10-04: v0.142.0, Docker slow lane + version report + crash guard - -Full session report: `felhom.eu/REPORT-os-docker-crash-2026-10-04.md`. - -- Docker live-restore turned on by reload (never a restart); the Docker engine set as a slow lane whose authority the - root wrapper checks itself (signed job against a root-owned key file, or the root-owned ring-0 mark); same-id health. -- The box reports its versions (Proxmox, kernels, Debian, Docker, live-restore, held packages, taint, crash guard). -- The crash guard: a crashed host restarts, the 3rd unclean stop within an hour leaves it off, 24 h re-arm. -- Tests and 17 red-proofs; live on both demo boxes (see the session report). +- v0.142.1 (same day, ruling 95): a Docker step restarts the containers that mount the docker socket, and the health + rule checks the controller reaches Docker (R-858, found live by the operator on demo-felhom).