diff --git a/CHANGELOG.md b/CHANGELOG.md index 2c7854d..70f7d89 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,15 @@ +## v0.137.0 — a guest outside the agent's ACL is not a known guest (2026-09-27, R-689, v0.136.0 regression) + +> **RELEASED 2026-09-27** by `scripts/release-agent.sh` — tag `v0.137.0` (`3ef095f`), sha256 `766c9166916a1bd3674b0dc69081f8a7619e770f1402d8ad7705b395937e7627`, verified by download. **NOT vouched** (the operator's act). + +**MinAgent impact:** none required by any controller. + +- v0.136.0 asked `GuestConfig` whether an archive's guest exists and treated anything but "does not exist" as a lookup + failure. PVE answers **403 "permission denied at /vms/"** for a vmid outside the token's pool — so on demo-hp the + deleted guest 9100's archive made the local tier UNKNOWN every evaluation. A guest the agent cannot read is not one it + manages; its archive is skipped. `TestR689_AGuestOutsideTheAgentsACLIsNotAKnownGuest`, red-proofed. Verified read-only + on demo-hp with the pre-release binary before the release. + ## v0.136.0 — … of a guest that still EXISTS (2026-09-27, R-689 second half) > **RELEASED 2026-09-27** by `scripts/release-agent.sh` — tag `v0.136.0` (`16dbc83`), sha256 `2eb0b5ebe253defd68b322312bbac12418c051b0a7a0d2d1831310d97fa6d755`, verified by download. **NOT vouched** (the operator's act).