diff --git a/CHANGELOG.md b/CHANGELOG.md index 2ce50ce..ec01ef4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,43 @@ +## v0.142.0 — the Docker engine slow lane, the version report, the crash guard (`11` §5.8, §5.9; `09` decisions 87–89) + +> **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.142.0` (`b1746c2`), sha256 +> `7beb32224d6495e9561acfd3ad8a48393a799520f196080011cb27fceb6d1de6`, verified by download. Not vouched at release time. + +**MinAgent impact:** none. **Needs hub v0.132.0** for the System page, the Docker approval and the crash events; an older +hub stores the new `system` stanza unread. **Needs the new root files** on an installed box (R-840): the wrapper, +`/etc/felhom/os-trust.json`, `/etc/felhom/operator-signers` and the crash guard — the installer 1.30.0 writes them; the +demo boxes got them by hand. + +- **Docker `live-restore` ON** (decision 87). Wrapper mode `live-restore-on`: merge `"live-restore": true` into the + guest's `/etc/docker/daemon.json` and `systemctl reload docker` — never a restart (R-835). An invalid daemon.json is + left alone (R16); a reload that does not enable it puts the old file back. The leg runs it once before a Docker step; + `--selftest=live-restore -vmid N` runs it by hand. Measured: demo-hp 24 containers, demo-felhom 5 — the same ids after. +- **The Docker engine slow lane** (`11` §5.8). Wrapper layer `docker`, lane `slow` only, the six Docker packages only, + origin `Docker CE` only (R2; a Docker package in a fast-lane plan is refused). **R3 — the wrapper checks the authority + itself**, never the agent's config: a ring-1 step or ANY undo needs a signed `os_docker_step` it verifies with + `ssh-keygen -Y verify` against the ROOT-owned `/etc/felhom/operator-signers` (namespace `felhom-op-v1`, the blob's + `key_id`), bound to `/etc/felhom/os-trust.json` `host_id`, inside its time window, never replayed (a root-owned nonce + file), with exactly the signed packages and undo flag; an unsigned ring-0 step needs that file's + `"ring0_slow_lane": true` (the demo boxes only, set by hand). **R15:** live-restore must be on. An undo may downgrade + (`--allow-downgrades`) only inside a signed job. The leg: ring 0 runs the Docker step at night after a healthy guest + and host step (`select pending-docker`); ring 1 never does — only `DockerStepExecutor` (signed job, heavy-op gate). + **Health:** the guest rule + every container running at the start has the SAME id after + the engine reports the + installed version; a changed id is `health_failed`. Measured ring 0: 29.7.x → 29.8.2 on both demo boxes, every id kept. +- **The version report** (R-852, decision 89). Wrapper mode `facts` (read-only): host Debian, running and next-boot + kernel (`next_entry` > saved default > newest installed, by dpkg order), held packages (R-848), kernel taint (oops, + warn), `kernel.panic`, the crash guard state; guest Debian, Docker engine, containerd, live-restore. The host report + gains `system {pve_version, kernel_version, vmid, facts, facts_error}`, read at most every 10 min (~2 s); + `--selftest=os-facts -vmid N`. A value nobody could read is `unknown`. +- **R-849:** the guest is scanned for "restart needed" on every pass too, so a guest restart clears it. +- **The crash guard** (decision 88, R-851): `configs/felhom-crash-guard` + `felhom-crash-guard.service` (early boot; + its ExecStop writes a clean-stop marker) + an hourly re-arm timer + `/etc/felhom/crash-guard.conf`. A boot without + the marker followed an unclean stop (a crash, a power cut or a hard reset — pstore saved nothing for a real panic on + demo-hp, so they cannot be told apart). Armed: `kernel.panic = 10`. After the 2nd unclean boot within 60 min it + TRIPS (`kernel.panic = 0`), so the 3rd crash within the hour leaves the box off; it re-arms after 24 h of normal + running or `felhom-crash-guard rearm`. State in `/var/lib/felhom-crash-guard/state.json` (0644; read by facts). +- Tests: wrapper 76 (DockerLane, LiveRestore, Facts, RealSignatureCheck with a throwaway key), crash guard 9, Go leg + + executor; red-proofs `felhom.eu/documentation/audits/os-docker-crash-2026-10-04/partB/agent-redproofs.txt` (17 caught). + ## v0.141.1 — "reboot needed" is true on the host (found live on demo-felhom, 2026-10-04) > **RELEASED 2026-10-04** by `scripts/release-agent.sh` — tag `v0.141.1` (`a6bc3f1`), sha256 diff --git a/REPORT.md b/REPORT.md index b4d8c6b..75db1e5 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,11 +1,9 @@ -# REPORT — 2026-10-04: v0.141.0 + v0.141.1, the host fast lane, the true tunnel status, the fast leg +# REPORT — 2026-10-04: v0.142.0, Docker slow lane + version report + crash guard -Full session report: `felhom.eu/REPORT-os-host-lane-2026-10-04.md`. +Full session report: `felhom.eu/REPORT-os-docker-crash-2026-10-04.md`. -- Tunnel (R-841): the agent reads the guest's cloudflared container and its health check; three states. -- Host fast lane: the wrapper gains the host layer (R12 appliance proof from the root-owned install record, R14 no - kernel/boot/firmware); the leg runs the host step after a healthy guest step; host health rule. -- Speed (R-845): one call per layer instead of one per package; measured before/after in the session report. -- Tests green; red-proofs in the audit folder. -- v0.141.1 (same day): the host "reboot needed" scan hid `lxc-start` and was never cleared by a reboot — both fixed, - found live on demo-felhom, red-proved. +- Docker live-restore turned on by reload (never a restart); the Docker engine set as a slow lane whose authority the + root wrapper checks itself (signed job against a root-owned key file, or the root-owned ring-0 mark); same-id health. +- The box reports its versions (Proxmox, kernels, Debian, Docker, live-restore, held packages, taint, crash guard). +- The crash guard: a crashed host restarts, the 3rd unclean stop within an hour leaves it off, 24 h re-arm. +- Tests and 17 red-proofs; live on both demo boxes (see the session report).