# REPORT — agent v0.152.0: the kernel lane (2026-10-07) **What:** R-836, `09` §3 decision 172 — a new kernel boots ONCE through a flag on the ESP; a crash falls back to the old kernel by itself; a healthy boot (host health rule + the hub reached, 20 min) makes it the default; a booted-but-unhealthy one is reverted ONCE. Design: `felhom.eu/documentation/architecture/11-os-updates.md` §5.11. - Wrapper `configs/felhom-os-apply`: layer `kernel` (stage, kernel-reboot, kernel-boot, kernel-good, kernel-revert, kernel-cancel, kernel-status; R20–R23). Bundle: `/etc/grub.d/01_felhom_oneshot`, `/etc/grub.d/42_felhom_oneshot`. - Agent `internal/osupdate/kernel.go`: the night step (told nights only), `KernelAfterBoot`, `KernelStepExecutor`. - Tests: `KernelLane` (27), `KernelStepCannotLeaveTheBoxOff` (3), `TestKernel*` (13); red-proofs `felhom.eu/documentation/audits/kernel-lane-2026-10-07/A/redproof.txt`. - Released `v0.152.0` (`d03ab7f`; binary `95ff4220…`, bundle `f0c2cec3…`) + step bundle `0.152.0-step1` (`0b71d32b…`). Delivered by signed jobs to Tester 1, demo-hp, demo-felhom (binary → step bundle → bundle). Not vouched (the golden is behind; waiver to 2026-10-13). - **Proven on the Tester 1 box** (`felhom.eu/documentation/audits/kernel-lane-2026-10-07/E/RESULT.md`): forced panic → fell_back by itself; held guest → one self-revert after 20 min; healthy → 7.0.14-22 the default. - **Open:** the ring-0 night run (R-836 says where it stopped); R-898 (ring 0 stages the pending kernel, not exactly the told one); R-897 (post-reboot drive re-bind races the first backup).