Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,5 +1,13 @@
|
|||||||
# CONTEXT — felhom-agent working state
|
# CONTEXT — felhom-agent working state
|
||||||
|
|
||||||
|
> **2026-10-04 night — v0.143.0 RELEASED + vouched (R-840, decision 96): the config bundle.** `felhom-os-apply` mode
|
||||||
|
> `bundle` (signed `agent_config_update`, verified by the wrapper itself; trust files never bundle paths) +
|
||||||
|
> `--install-bundle` (installer 1.31.0); `BUNDLE_FILES` is the one table; `scripts/build-config-bundle.py`;
|
||||||
|
> `release-agent.sh` publishes it. A box whose `felhom-os-apply` predates 0.143.0 needs ONE by-hand bootstrap
|
||||||
|
> (`felhom.eu/scripts/felhom-bundle-bootstrap.sh`) — done on both demo boxes; Tester 2 waits for the operator (R-862).
|
||||||
|
> Both demo boxes: agent 0.143.0, bundle 0.143.0 (record `/etc/felhom/config-bundle.json`). R-861 found: the sudoers is
|
||||||
|
> root-equivalent. `build-golden.sh` 3.2.0 (`GOLDEN_GUEST_PKGS`). Runbook `felhom.eu/documentation/runbooks/config-bundle.md`.
|
||||||
|
|
||||||
|
|
||||||
> **2026-09-25 night — v0.133.0 AND v0.134.0 DELIVERED to both demo boxes (CC-signed `agent_update`, ruling 1);
|
> **2026-09-25 night — v0.133.0 AND v0.134.0 DELIVERED to both demo boxes (CC-signed `agent_update`, ruling 1);
|
||||||
> restore test back ON (the `-1` config kept as `agent.json.night-0925-off`). v0.134.0 = R-685:** `backup/runner.go`
|
> restore test back ON (the `-1` config kept as `agent.json.night-0925-off`). v0.134.0 = R-685:** `backup/runner.go`
|
||||||
|
|||||||
@@ -1,2 +1,19 @@
|
|||||||
- v0.142.1 (same day, ruling 95): a Docker step restarts the containers that mount the docker socket, and the health
|
# REPORT — agent v0.143.0: the config bundle (R-840) — 2026-10-04
|
||||||
rule checks the controller reaches Docker (R-858, found live by the operator on demo-felhom).
|
|
||||||
|
**What:** a signed route for a box's root-owned files. `felhom-os-apply` gained mode `bundle` (signed
|
||||||
|
`agent_config_update`, verified by the wrapper itself) and `--install-bundle` (the installer's root entry);
|
||||||
|
`BUNDLE_FILES` is the one table of 22 paths; `scripts/build-config-bundle.py` builds it reproducibly;
|
||||||
|
`release-agent.sh` publishes it beside the binary; the agent reports `system.config_bundle`; `felhom-opsign` signs it.
|
||||||
|
Also `build-golden.sh` 3.2.0 (`GOLDEN_GUEST_PKGS`).
|
||||||
|
|
||||||
|
**Released:** v0.143.0, binary `41c0d306…`, bundle `8d7273cf…` (reproducible), vouched in the hub with golden 0.293.0.
|
||||||
|
**Delivered:** demo-hp and demo-felhom (signed `agent_update`), then the one-file bootstrap, then the bundle by the
|
||||||
|
signed route (0 written of 22; probe 71/71). demo-hp also: a wrong sha refused, a one-line change and its undo, a replay
|
||||||
|
rejected. Tester 2: the signed `agent_update` queued (operator ruling 97); its bundle waits for the operator's
|
||||||
|
bootstrap (R-862).
|
||||||
|
|
||||||
|
**Tests:** `configs/test_felhom_config_bundle.py` 43 (22 of 22 mutants red), Go `internal/osupdate/bundle_test.go`,
|
||||||
|
`internal/hub/bundle_record_test.go`; `go vet ./... && go test ./...` rc=0; gates green.
|
||||||
|
**Found:** R-861 — the sudoers already lets the agent user reach root (read, not exploited).
|
||||||
|
Evidence and the full report: `felhom.eu/documentation/audits/r840-config-bundle-2026-10-04/`,
|
||||||
|
`felhom.eu/REPORT-r840-config-bundle-2026-10-04.md`.
|
||||||
|
|||||||
Reference in New Issue
Block a user