REPORT + CONTEXT: 2026-10-04 night (R-840 / R-860)
gates / gates (push) Successful in 20s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 20:39:47 +02:00
parent dc9164c5af
commit c8d12f1f2a
2 changed files with 27 additions and 2 deletions
+8
View File
@@ -1,5 +1,13 @@
# CONTEXT — felhom-agent working state # CONTEXT — felhom-agent working state
> **2026-10-04 night — v0.143.0 RELEASED + vouched (R-840, decision 96): the config bundle.** `felhom-os-apply` mode
> `bundle` (signed `agent_config_update`, verified by the wrapper itself; trust files never bundle paths) +
> `--install-bundle` (installer 1.31.0); `BUNDLE_FILES` is the one table; `scripts/build-config-bundle.py`;
> `release-agent.sh` publishes it. A box whose `felhom-os-apply` predates 0.143.0 needs ONE by-hand bootstrap
> (`felhom.eu/scripts/felhom-bundle-bootstrap.sh`) — done on both demo boxes; Tester 2 waits for the operator (R-862).
> Both demo boxes: agent 0.143.0, bundle 0.143.0 (record `/etc/felhom/config-bundle.json`). R-861 found: the sudoers is
> root-equivalent. `build-golden.sh` 3.2.0 (`GOLDEN_GUEST_PKGS`). Runbook `felhom.eu/documentation/runbooks/config-bundle.md`.
> **2026-09-25 night — v0.133.0 AND v0.134.0 DELIVERED to both demo boxes (CC-signed `agent_update`, ruling 1); > **2026-09-25 night — v0.133.0 AND v0.134.0 DELIVERED to both demo boxes (CC-signed `agent_update`, ruling 1);
> restore test back ON (the `-1` config kept as `agent.json.night-0925-off`). v0.134.0 = R-685:** `backup/runner.go` > restore test back ON (the `-1` config kept as `agent.json.night-0925-off`). v0.134.0 = R-685:** `backup/runner.go`
+19 -2
View File
@@ -1,2 +1,19 @@
- v0.142.1 (same day, ruling 95): a Docker step restarts the containers that mount the docker socket, and the health # REPORT — agent v0.143.0: the config bundle (R-840) — 2026-10-04
rule checks the controller reaches Docker (R-858, found live by the operator on demo-felhom).
**What:** a signed route for a box's root-owned files. `felhom-os-apply` gained mode `bundle` (signed
`agent_config_update`, verified by the wrapper itself) and `--install-bundle` (the installer's root entry);
`BUNDLE_FILES` is the one table of 22 paths; `scripts/build-config-bundle.py` builds it reproducibly;
`release-agent.sh` publishes it beside the binary; the agent reports `system.config_bundle`; `felhom-opsign` signs it.
Also `build-golden.sh` 3.2.0 (`GOLDEN_GUEST_PKGS`).
**Released:** v0.143.0, binary `41c0d306…`, bundle `8d7273cf…` (reproducible), vouched in the hub with golden 0.293.0.
**Delivered:** demo-hp and demo-felhom (signed `agent_update`), then the one-file bootstrap, then the bundle by the
signed route (0 written of 22; probe 71/71). demo-hp also: a wrong sha refused, a one-line change and its undo, a replay
rejected. Tester 2: the signed `agent_update` queued (operator ruling 97); its bundle waits for the operator's
bootstrap (R-862).
**Tests:** `configs/test_felhom_config_bundle.py` 43 (22 of 22 mutants red), Go `internal/osupdate/bundle_test.go`,
`internal/hub/bundle_record_test.go`; `go vet ./... && go test ./...` rc=0; gates green.
**Found:** R-861 — the sudoers already lets the agent user reach root (read, not exploited).
Evidence and the full report: `felhom.eu/documentation/audits/r840-config-bundle-2026-10-04/`,
`felhom.eu/REPORT-r840-config-bundle-2026-10-04.md`.