CHANGELOG + REPORT: v0.141.0 released (host fast lane, true tunnel status, fast leg)
gates / gates (push) Successful in 19s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 13:19:02 +02:00
parent cfba0d022a
commit 3bf77c3423
2 changed files with 39 additions and 9 deletions
+7 -9
View File
@@ -1,11 +1,9 @@
# REPORT — 2026-10-04: v0.140.0, OS updates (guest fast lane)
# REPORT — 2026-10-04: v0.141.0, the host fast lane, the true tunnel status, the fast leg
Full session report: `felhom.eu/REPORT-os-guest-lane-2026-10-04.md`.
Full session report: `felhom.eu/REPORT-os-host-lane-2026-10-04.md`.
- `felhom-os-apply` wrapper (R1–R13, repair first, snapshot.debian.org fallback), `FELHOM_OSAPPLY` sudoers, the OS leg
after the primary backup, `--selftest=os-update`. Released `9cac346`, sha256 `ae2d60b7…1250`, verified by download.
- Live on both demo boxes: ring 0 installed 53 packages each, healthy; ring 1 installed exactly the 3 approved versions;
a deliberately failed health check reported `health_failed` and mailed the operator.
- Found and fixed live: the `--selftest` flag refused `os-update` (and `wgtunnel`, since S3); the conffile log line
called an updated file "kept"; an app stopped between the inventory and the apply escaped the health check.
- No automatic undo (R-837: PVE refuses a snapshot of a guest with host-path binds).
- Tunnel (R-841): the agent reads the guest's cloudflared container and its health check; three states.
- Host fast lane: the wrapper gains the host layer (R12 appliance proof from the root-owned install record, R14 no
kernel/boot/firmware); the leg runs the host step after a healthy guest step; host health rule.
- Speed (R-845): one call per layer instead of one per package; measured before/after in the session report.
- Tests green; red-proofs in the audit folder.