# REPORT — agent v0.143.0: the config bundle (R-840) — 2026-10-04 **What:** a signed route for a box's root-owned files. `felhom-os-apply` gained mode `bundle` (signed `agent_config_update`, verified by the wrapper itself) and `--install-bundle` (the installer's root entry); `BUNDLE_FILES` is the one table of 22 paths; `scripts/build-config-bundle.py` builds it reproducibly; `release-agent.sh` publishes it beside the binary; the agent reports `system.config_bundle`; `felhom-opsign` signs it. Also `build-golden.sh` 3.2.0 (`GOLDEN_GUEST_PKGS`). **Released:** v0.143.0, binary `41c0d306…`, bundle `8d7273cf…` (reproducible), vouched in the hub with golden 0.293.0. **Delivered:** demo-hp and demo-felhom (signed `agent_update`), then the one-file bootstrap, then the bundle by the signed route (0 written of 22; probe 71/71). demo-hp also: a wrong sha refused, a one-line change and its undo, a replay rejected. Tester 2: the signed `agent_update` queued (operator ruling 97); its bundle waits for the operator's bootstrap (R-862). **Tests:** `configs/test_felhom_config_bundle.py` 43 (22 of 22 mutants red), Go `internal/osupdate/bundle_test.go`, `internal/hub/bundle_record_test.go`; `go vet ./... && go test ./...` rc=0; gates green. **Found:** R-861 — the sudoers already lets the agent user reach root (read, not exploited). Evidence and the full report: `felhom.eu/documentation/audits/r840-config-bundle-2026-10-04/`, `felhom.eu/REPORT-r840-config-bundle-2026-10-04.md`.