# CONTEXT — felhom-agent working state > Snapshot of the current state + open threads. Authoritative history lives in `CHANGELOG.md` (top > entry = current); the end-of-task detail lives in `REPORT.md`. ## Current - **v0.61.0** (2026-07-03) — blast-radius audit fixes **B1 + D1 + D2 + D3** from `felhom.eu/documentation/audits/AUDIT-blast-radius-hostroot-localapi-2026-07-02.md`: random temp staging for root-installed scripts (+ sudoers/manifest glob updates), mkfs-wrapper member/RO re-checks (validated by `scripts/mkfs-guarded-harness.sh`), classifyClaim empty-lsblk fail-safe, and the blank-format anti-retarget (durable-id-bound, AGENT-001's benign-branch twin). - Deployed on demo host `felhom-pve` (node `demo-felhom`), non-root `felhom-agent` service user, pool-scoped token (`felhom` pool). ## Open threads - **A1 (LOW, pending SPIKE — not fixed in v0.61.0):** stale-lock recovery (`internal/localapi/stalelock.go`) reaps guests by a pool-blind `ListLXC` scan, not ownership. Contained by the pool-scoped token today; **must be fixed before any broad/root-token deployment.** It is a spike, not a patch: the role lacks `Pool.Audit`, so there is no cheap authorized pool-membership read — which read to use is the open design question. - Deferred audit items (housekeeping/design, all INFO): C1 (controller-swap version floor), C2 (NAS server allowlist), A2 (gate journal cross-check), B2–B5, E1/E2. - Drive-enrollment leftovers: (a) `runStorageInit` slow-device detached-format polling; (b) Impl-3 shared-box operator format gate. - BUNDLE leftover: non-root agent can't read the PBS key; migration must preserve cert/key/tokens. - Not run (needs a supervised session): the destructive D1/D3 live proofs (real mkfs on a crafted member; a live /dev re-enumeration race during a real format).