CHANGELOG + REPORT: v0.140.0 released (OS updates, guest fast lane)
gates / gates (push) Successful in 18s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 11:30:14 +02:00
parent 9cac3462bb
commit a55eedcf2c
2 changed files with 38 additions and 8 deletions
+9 -8
View File
@@ -1,10 +1,11 @@
# REPORT — 2026-10-04: v0.139.0 (R-834)
# REPORT — 2026-10-04: v0.140.0, OS updates (guest fast lane)
Full session report: `felhom.eu/REPORT-backup-close-os-spike-2026-10-04.md`.
Full session report: `felhom.eu/REPORT-os-guest-lane-2026-10-04.md`.
- **Measured** on demo-hp: the scheduled restore-test's scratch guest has `onboot: 0` and throwaway stand-ins for
mp8/mp9 on every config read until teardown — it was already safe. Evidence `felhom.eu/documentation/audits/backup-close-2026-10-04/partA/`.
- **Fixed:** the DR bring-up refuses beside a live original (source guest present, a drives bind on another guest,
or an unreadable config). On a replaced host it is unchanged.
- Tests `TestRunBringUp_DRRefusesBesideALiveOriginal`, `TestRestoreTest_NoHostPathBindBesideTheOriginal` and two
more; both rules red-proved. No sudoers change (said why in the CHANGELOG).
- `felhom-os-apply` wrapper (R1–R13, repair first, snapshot.debian.org fallback), `FELHOM_OSAPPLY` sudoers, the OS leg
after the primary backup, `--selftest=os-update`. Released `9cac346`, sha256 `ae2d60b7…1250`, verified by download.
- Live on both demo boxes: ring 0 installed 53 packages each, healthy; ring 1 installed exactly the 3 approved versions;
a deliberately failed health check reported `health_failed` and mailed the operator.
- Found and fixed live: the `--selftest` flag refused `os-update` (and `wgtunnel`, since S3); the conffile log line
called an updated file "kept"; an app stopped between the inventory and the apply escaped the health check.
- No automatic undo (R-837: PVE refuses a snapshot of a guest with host-path binds).