CHANGELOG/REPORT: v0.153.0 released and delivered
gates / gates (push) Successful in 1m33s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-07 19:06:04 +02:00
parent 2d1e5d0774
commit c9013bb47d
2 changed files with 13 additions and 18 deletions
+5 -1
View File
@@ -1,4 +1,8 @@
## Unreleased — part of v0.153.0: ring 0 stages exactly the told kernel (R-898; `09` §3 decision 176) (2026-10-07)
## v0.153.0 — ring 0 stages exactly the told kernel (R-898; `09` §3 decision 176) (2026-10-07)
Released by `scripts/release-agent.sh`: binary sha256 `b204ebe6d65944f43b70dcfa4ae0dfb90da38c92e2ba6a38a1826e488eeb6630`, bundle
`6db216275eb0dd39188d93481a2045998a69e8cb7838ad908a58d65d9a6a9b57` (tag `v0.153.0` = `2d1e5d0`). Delivered (binary only — the
bundle files are unchanged from 0.152.0) to demo-hp, demo-felhom, Tester 1 on 2026-10-07 19:03.
**Delivery: the agent binary only** — no root file changed (the wrapper is unchanged; its tests gained two cases).
+8 -17
View File
@@ -1,18 +1,9 @@
# REPORT — agent v0.152.0: the kernel lane (2026-10-07)
# REPORT — agent v0.153.0: ring 0 stages exactly the told kernel (2026-10-07, late evening)
**What:** R-836, `09` §3 decision 172 — a new kernel boots ONCE through a flag on the ESP; a crash falls back to the old
kernel by itself; a healthy boot (host health rule + the hub reached, 20 min) makes it the default; a booted-but-unhealthy
one is reverted ONCE. Design: `felhom.eu/documentation/architecture/11-os-updates.md` §5.11.
- Wrapper `configs/felhom-os-apply`: layer `kernel` (stage, kernel-reboot, kernel-boot, kernel-good, kernel-revert,
kernel-cancel, kernel-status; R20–R23). Bundle: `/etc/grub.d/01_felhom_oneshot`, `/etc/grub.d/42_felhom_oneshot`.
- Agent `internal/osupdate/kernel.go`: the night step (told nights only), `KernelAfterBoot`, `KernelStepExecutor`.
- Tests: `KernelLane` (27), `KernelStepCannotLeaveTheBoxOff` (3), `TestKernel*` (13); red-proofs
`felhom.eu/documentation/audits/kernel-lane-2026-10-07/A/redproof.txt`.
- Released `v0.152.0` (`d03ab7f`; binary `95ff4220…`, bundle `f0c2cec3…`) + step bundle `0.152.0-step1` (`0b71d32b…`).
Delivered by signed jobs to Tester 1, demo-hp, demo-felhom (binary → step bundle → bundle). Not vouched (the golden is
behind; waiver to 2026-10-13).
- **Proven on the Tester 1 box** (`felhom.eu/documentation/audits/kernel-lane-2026-10-07/E/RESULT.md`): forced panic →
fell_back by itself; held guest → one self-revert after 20 min; healthy → 7.0.14-22 the default.
- **Open:** the ring-0 night run (R-836 says where it stopped); R-898 (ring 0 stages the pending kernel, not exactly the
told one); R-897 (post-reboot drive re-bind races the first backup).
- R-898 (closed): the night kernel step on ring 0 stages the kernel the household was told about (`select listed`,
`osupdate.KernelSet(kver)`), never "whatever is pending tonight". A told version no longer installable → the wrapper
refuses before any change (R7); the hub re-tells the household for the newer kernel.
- Tests: `TestKernel_Ring0ToldNightStagesThenReboots` (red-proved against the old select), `TestKernelSet`; wrapper
cases `test_ring0_listed_installs_the_told_kernel_not_the_newest`, `test_ring0_told_kernel_gone_is_refused_before_any_change`.
- Released `v0.153.0`, binary `b204ebe6…`; delivered (binary only) to demo-hp, demo-felhom, Tester 1 at 19:03.
- Tonight (7→8): demo-felhom stages 7.0.14-20, demo-hp 7.0.14-22 — both households told. Read back 2026-10-08.