From 92d647a6f6dfd9af877daaa30d495143fecd5d2f Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 7 Oct 2026 15:42:26 +0200 Subject: [PATCH] CHANGELOG: v0.152.0 released (shas, step bundle); host_stale is 45 min (comment fix) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CHANGELOG.md | 9 +++++++-- cmd/felhom-agent/main.go | 3 ++- internal/osupdate/kernel.go | 2 +- 3 files changed, 10 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 363e8c8..547d73d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,4 +1,9 @@ -## Unreleased — part of v0.152.0: the kernel lane (R-836; `09` §3 decisions 164, 172; `11` §5.11) (2026-10-07) +## v0.152.0 — the kernel lane (R-836; `09` §3 decisions 164, 172; `11` §5.11) (2026-10-07) + +Released by `scripts/release-agent.sh`: binary sha256 `95ff42208e36ba49b6e2b09a97e81a6fa11562ecc8042f1ed18d378b8b1f88b1`, +config bundle sha256 `f0c2cec374b711b3c131c955012b33fd0ad495337d049b7a743c3eef9e85c20b` (tag `v0.152.0` = `d03ab7f`). +Step bundle `0.152.0-step1` sha256 `0b71d32b054cf3b7ade0234ffcbb0df159901f542cde540adaee411db466f48e` (the 0.151.0 bundle +with only `felhom-os-apply` replaced; `scripts/build-step-bundle.py`), published as package version `0.152.0-step1`. **Delivery: agent binary, then the STEP bundle `0.152.0-step1`, then the bundle `0.152.0`** — the bundle ADDS two paths (the GRUB generators), and an installed `felhom-os-apply` refuses a path its own table lacks (R16, R-880). @@ -34,7 +39,7 @@ candidate 2 (`audits/kernel-spike-2026-10-07/`), with option C on the one-shot e signed `os_kernel_step` staged (`KernelStepExecutor`: stage only, under the heavy-op gate). The hub hears `staged` BEFORE the reboot. At every start `KernelAfterBoot`: on the new kernel it JUDGES the boot — `KernelVerdict` = the host health rule (`11` §8.2) AND the box reached the hub (the `judging` report itself) — for 20 minutes (measured: - everything healthy 68 s after the reboot on demo-felhom, 272 s on demo-hp; under the hub's 30-minute `host_stale`). + everything healthy 68 s after the reboot on demo-felhom, 272 s on demo-hp; under the hub's 45-minute `host_stale` (`alerting.stale_threshold`)). Healthy → `kernel-good`, outcome `applied`; not healthy → outcome `health_failed`, then ONE `kernel-revert`. Tests: `TestKernel*` (13); red-proofs in the same file. - `internal/hub`: `WireOSUpdate.Kernel` {kver, tonight, notified_at}. `internal/reconcile`: `os_kernel_step` is diff --git a/cmd/felhom-agent/main.go b/cmd/felhom-agent/main.go index d42ce8a..40e82cb 100644 --- a/cmd/felhom-agent/main.go +++ b/cmd/felhom-agent/main.go @@ -881,7 +881,8 @@ func runDaemon(cfg config.Config, logger *slog.Logger, logRing *applog.Ring) int // judge it (the host health rule + the hub reached) for KernelJudgeWait, then make it the default or revert ONCE. // The wait: measured 2026-10-07 (`audits/kernel-lane-2026-10-07/B/`) — every container healthy 68 s after the // reboot on demo-felhom and 272 s on demo-hp (the hub reached at 63 s / 189 s); 20 minutes leaves room for a slow - // network and stays under the hub's 30-minute host_stale. On a box without the kernel lane (an older wrapper, a BYO host) the check is refused and logged. + // network and stays under the hub's 45-minute host_stale (its + // alerting.stale_threshold; host_down at 90). On a box without the kernel lane (an older wrapper, a BYO host) the check is refused and logged. go osLeg.KernelAfterBoot(ctx, 0, osupdate.KernelJudge{Wait: osupdate.DefaultKernelJudgeWait}) // Reconcile (slice 4) runs alongside the hub loop, sharing the per-guest queue diff --git a/internal/osupdate/kernel.go b/internal/osupdate/kernel.go index bbbcdd9..5447476 100644 --- a/internal/osupdate/kernel.go +++ b/internal/osupdate/kernel.go @@ -33,7 +33,7 @@ const OpKernelStep = "os_kernel_step" // DefaultKernelJudgeWait is how long a one-shot boot may take to come back healthy before the agent reverts it ONCE. // Measured 2026-10-07 (`audits/kernel-lane-2026-10-07/B/`): every container healthy 68 s after a reboot on demo-felhom, -// 272 s on demo-hp; 20 minutes stays under the hub's 30-minute host_stale (a box that never comes back alarms after it). +// 272 s on demo-hp; 20 minutes stays under the hub's 45-minute host_stale (a box that never comes back alarms after it). const DefaultKernelJudgeWait = 20 * time.Minute var kverRE = regexp.MustCompile(`^[0-9]+\.[0-9]+\.[0-9]+-[0-9]+-pve$`)