diff --git a/CHANGELOG.md b/CHANGELOG.md index 313fa0c..b77632e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,22 @@ +## v0.138.0 — the restore test takes only THIS box's archives (2026-09-30, R-727, `09` §3 decision 51) + +> **RELEASED 2026-09-30** by `scripts/release-agent.sh` — tag `v0.138.0` (`e1b8269`), sha256 +> `55916026001790a79ebf97d32c032610cfde8e09d02979b9b9d8c2cbc5d88195`, verified by download. **Not vouched** (the golden +> keeps 0.137.0 until the next bake); delivered to the demo boxes by signed `agent_update` jobs. + +**MinAgent impact:** none required by any controller. + +- A returning customer's PBS namespace can hold archives of EARLIER boxes: same guest id (9201), same token, written + with a different key. Measured 2026-09-30: the newest SETTLED archive was an earlier box's, and the test failed + `wrong key … manifest's key 6b:ca:5f:3f… does not match provided key de:51:7a:18…` every evaluation. The archive + carries no host id; it carries its key fingerprint (PVE content `encrypted`), and the storage carries its own + (`GET /storage` → `encryption-key`). `PickSettledRestoreCandidateOn` now skips — and logs by name, once — an archive + whose fingerprint is not the storage's own; an unencrypted storage is not filtered; a failed storage read is an + error (tier UNKNOWN), never "nothing to prove". +- Tests: `TestR727_TheRestoreTestTakesOnlyThisBoxsArchives` (the 2026-09-30 shape: nothing picked while this box's + archive settles, then exactly it), `TestR727_UnencryptedStorageIsNotFiltered`, `TestR727_KeyLookupFailureIsUnknown`. + Red-proof RP39: the skip removed → the earlier box's `2026-09-16T21:59:54Z` is picked. + ## v0.137.0 — a guest outside the agent's ACL is not a known guest (2026-09-27, R-689, v0.136.0 regression) > **RELEASED 2026-09-27** by `scripts/release-agent.sh` — tag `v0.137.0` (`3ef095f`), sha256 `766c9166916a1bd3674b0dc69081f8a7619e770f1402d8ad7705b395937e7627`, verified by download. **NOT vouched** (the operator's act).