## v0.146.1 — R-861 review fixes: the signed update flips a root-owned copy; no Wants=/continuations in mount units; the escrow read follows no symlink anywhere (2026-10-05) Released by `scripts/release-agent.sh`: binary sha256 `badd6c9a2e40c8bfe856d2d1a203443b21b7eb92ecc35d6090ab44518d4d082a`, config bundle sha256 `42333e969028867ad8142335e6c1bc4040eec231de0d8d330c2d4b2cf7bc3442`. **Supersedes v0.146.0, which was released but never vouched or delivered to any box.** The same order applies: signed `agent_update` first, then the signed `agent_config_update`. A background security review of the v0.146.0 commit found three holes in the new code; each is fixed and red-proved (`felhom.eu/documentation/audits/hub-safety-2026-10-05/partF/red-proof.txt`, S1–S3): - **S1 — a race in the signed update.** `felhom-os-apply` hashed the agent's staged file and then let the A/B wrapper copy it BY PATH; the agent owns that directory and could swap the file in between. Now the root step reads the file ONCE (`read_staged_once`: O_NOFOLLOW, fstat, owner, size), hashes those bytes, writes them to a root-owned directory (`/var/lib/felhom-os-apply/agent-update/`) and hands ONLY that copy to `felhom-selfupdate-guarded apply`, which now refuses any other directory, a symlink, or a file not owned by root. Tests: `AgentUpdate` (+1), `SelfupdateWrapperConfinement`. - **S2 — an allowlist escape in `felhom-priv-apply`.** `[Unit]` accepted `Wants=`/`Requires=`/`Before=` naming any unit, so a mount unit could start e.g. `reboot.target`. `[Unit]` now holds only `Description` and `After=local-fs-pre.target` (what the renderers write), and any line ending in a backslash (a systemd continuation this parser would read differently) is refused. Tests `test_U2_wants_starts_another_unit`, `test_U2_continuation_line`. - **S3 — a path traversal in the escrow read.** `O_NOFOLLOW` guards only the last component; a symlinked DIRECTORY in the agent's own state dir still redirected the root read. `readStagedNoFollow` now walks the path from `/` with `openat(O_NOFOLLOW)` per component. Test `TestAttach_RefusesASymlinkedDirectory`. ## v0.146.0 — the agent's root grants narrowed: exact sudo patterns, a root content checker, fixed files from the bundle, the signed update checked as root (R-861) (2026-10-05) Released by `scripts/release-agent.sh`: binary sha256 `b860af465076041e07f35fed1b12d64ae2b2985d8995f0ce167418d39c2b00d5`, config bundle sha256 `161c737e523aa7910cf32ce41b83f989569bee55b8c5938e7211c92aef68548e`. **Order on a box: the signed `agent_update` FIRST (the old bundle still grants the old flip), then the signed `agent_config_update`.** Between the two (minutes) the new agent's checker calls are refused and retried; nothing is lost. After the bundle, an agent BELOW 0.146.0 cannot update itself on that box any more (the unsigned flip grant is gone) — deliver both together. Design: `felhom.eu/documentation/architecture/03-host-agent.md` §3.1 (new). Measured before the change (real sudo 1.9.16, a throwaway container): the v0.145.0 sudoers let **23 of 29** attack command lines through; v0.146.0 lets **0** through and still allows all **64** commands the agent's capability check uses. - **Exact patterns.** A sudoers `*` in the arguments also matches spaces: `pct set [0-9]* -onboot 1` matched `pct set 100 --dev0 /dev/sda -onboot 1` (a raw host disk for a guest), `mount --bind /mnt/*/felhom-data /mnt/felhom-drives/*` matched a `..` path onto `/etc/sudoers.d`, `nft add element … *` took a chained `; flush ruleset`. Every varying argument list is now a sudo regex (`^…$`): one value per slot, a fixed character set, no `..`, no extra argument. `TestSudoersRefusesTheR861Injections` (29 attacks) + `TestManifestCoveredBySudoers` (regex-aware now). - **`felhom-priv-apply`** (new root wrapper, in the bundle). A systemd mount/automount unit, a dnsmasq drop-in, the WireGuard config and the OOB sshd config + felhom-op key reach their root-read places only through it: fixed source, fixed destination, CONTENT checked against what the agent's renderers write (no `[Service]`, `Where=` only `/mnt/` or `/mnt/felhom-drives/` and equal to the unit name, no `bind`/`suid`; a network share must carry `nosuid,nodev`; no `dhcp-script=`; no `PostUp=`; the sshd config only the one template with its Port). Its 30 tests (`configs/test_felhom_priv_apply.py`) + Go contract tests feeding each renderer's real output (`internal/privapplytest`). Pre-flight: every live file on both demo boxes reads OK. - **NFS/SMB options gain `nosuid,nodev`** (a set-uid file on a server outside the box never acts on the host). - **Fixed files from the bundle.** The guest pre-start hook (`/var/lib/vz/snippets/felhom-guest-hook.sh`, run as root at every guest start) and the shared drive parent script + unit are bundle files now (byte-identical to the agent's constants, pinned). The agent no longer installs them from `/tmp`; it checks them (`guesthook.SnippetReady`, `ensureSharedParentBoot`) and only registers / enables. - **The signed update is checked as root.** `felhom-os-apply` mode `agent_update` verifies the operator signature (root-owned signers, this host, the window, the nonce), re-hashes the staged binary against the SIGNED sha, then runs the A/B flip; `felhom-selfupdate-guarded apply` is no longer in the agent's sudoers. 7 tests (`AgentUpdate`). - **The root escrow run reads no path from the agent's config.** As root it pins the PVE secret dir and the WireGuard state dir to their defaults, refuses a storage id that is a path, and reads its two staged files without following a symlink (`readStagedNoFollow`) — before, a symlink in the agent's own directory sealed any root file into the blob. - **Not narrowed here (named in `03` §3.1):** `FELHOM_CONTROLLERSWAP` stays guest-scoped (a compromised agent can run a chosen controller image in the guest — the household's data, not host root); `FELHOM_ESCROW` still hands the agent R by design (the agent relays the ceremony); the mkfs / pbs-apply / backup-target wrappers keep a coarse argument and their own checks. - Red-proofs F1–F9: `felhom.eu/documentation/audits/hub-safety-2026-10-05/partF/red-proof.txt` (F1's first run did NOT convict — the name rule masked it — and the test now uses the pair only the Where rule stops). ## v0.145.0 — the OS update repairs itself after a power cut; a short-session box gets restore-tested; "sent late" (R-876, R-874, R-875) (2026-10-05) Released by `scripts/release-agent.sh`: binary sha256 `894da35c7b9e1ac78885690b78352b634e6831e7d99b321573c75d878db8886e`, config bundle sha256 `78c00adce662d2d966b2ac50ebde46cde1ae225f0107c6a7c02b70ec8ce80c4f`. The wrapper changed: a box needs the signed `agent_update` AND the signed `agent_config_update`. - **R-876.** After a crash during an install, `dpkg --audit` can read clean while dpkg's update journal (`/var/lib/dpkg/updates/`) is not — and apt refuses every install until `dpkg --configure -a` (measured on demo-hp 2026-10-05: every later pass failed until a person typed it). The wrapper now reads `--audit` and the journal in ONE `sh -c` call (`DPKG_STATE_SCRIPT`) — a clean pass still costs one call (R-845's speed, pinned) — and repairs when either shows something; as a belt, when apt itself says "dpkg was interrupted", it repairs and retries the install ONCE. `REPAIR` now logs `journal=N`; a journal still not empty after the repair refuses (R13). Tests `CrashLeftTheJournal` (the measured shape, the speed, the belt); 3 red-proofs. - **R-874.** The restore-test's first due-check runs 30 minutes after the agent starts (`DefaultFirstEval`), then every interval; a box whose power-on sessions are shorter than the 6 h interval never evaluated. A crash-looping agent restarting faster than 30 minutes still never evaluates (the earned restraint, pinned). - **R-875.** A kept report's reason is neutral — "sent late — kept on the box until the hub could take it" — the copy cannot tell a killed agent from an absent hub. - Red-proofs: `felhom.eu/documentation/audits/catchup-2026-10-05/part{C,D}/`. ## v0.144.1 — a killed pass really keeps its report: the wrapper survives a dead reader; the agent looks again every 5 minutes (R-868, measured live) (2026-10-05) Released by `scripts/release-agent.sh`: binary sha256 `6ccd521d47e64999017e8eb5bc613d724543cfdc5ef9b13bcae9e3ea8c53b8f3`, config bundle sha256 `e89a9ddfb767e177f8874d56f3dcd3bfd47409d157ff830d362653333bf815e8`. The wrapper changed again: a box needs the signed `agent_update` AND the signed `agent_config_update`. - **Found live on demo-hp 2026-10-05 05:45 UTC with v0.144.0** (the night's A5 shape: kill -9 of the pass and the daemon while apt-get ran): apt finished all 13 packages, but the wrapper's next log line went to a stderr pipe no process read any more → `BrokenPipeError` → the wrapper died before it saved its report copy (journal: `PLAN upgrade=13`, then nothing; no copy; the hub got nothing). v0.144.0's mechanism was right and never reached. `Runner.log` and the final `OSAPPLY-REPORT` line now survive a dead reader (the journal still gets every line). Test `AgentDiesMidPass` drives the REAL `log()` into a pipe that breaks while apt-get runs. - **Also found live:** the restarted daemon looked for kept copies ~7 s before the orphaned wrapper wrote one. The daemon now looks at start and every 5 minutes (`Leg.SendUnsentLoop`); `TestR868_ACopyWrittenAfterTheStartIsSentByTheLoop`. - Red-proofs: `felhom.eu/documentation/audits/night-fixes-2026-10-05/partD/r868-brokenpipe-red-proof.txt`. - A second agent release in one session, against "one release per repo": recorded as `09` decision 108 (operator may reverse) — the alternative was to ship a fix proven not to work. ## v0.144.0 — R8 measures the real download; an OS pass reports even when its agent was killed; the debug pass runs with the hub away (R-865, R-868, R-866) (2026-10-05) Released by `scripts/release-agent.sh`: binary sha256 `f18093c3466749ec4cd47f83f97a401160a24bad1e704f1183051adad14db928`, config bundle `felhom-config-bundle.json` sha256 `6acf42fe46df5223384d767801cb2bf73238ba4dab82debb7811ca2f790591d8`. The wrapper `felhom-os-apply` changed, so a box needs BOTH the signed `agent_update` and the signed `agent_config_update`. - **R-865.** `download_bytes` runs `apt-get --print-uris` WITHOUT `-s`: with `-s` apt prints the simulation and no URI list, so R8 summed 0 B and only its 500 MB floor ever applied. `--print-uris` alone downloads nothing (measured on 9202: the archive cache and the versions unchanged). The test fake now answers like real apt (with `-s`: no URIs), and `test_R8_counts_the_real_download` / `test_download_bytes_never_simulates` pin it. - **R-868.** The wrapper writes every apply pass's report to `/report---apply.json` before it prints it (root writes into the agent's dir: the dir opened O_NOFOLLOW and checked to be the agent's own, the file created O_EXCL|O_NOFOLLOW, 0600, handed to the agent). The plan now carries `run_id`, `trigger`, `ring`, echoed in the report. The agent deletes the copy once the hub has the report; a copy left on disk (the agent was killed, or the hub was away) is sent at the agent's start and before every pass (`Leg.SendUnsent`), then deleted. A pass lock (flock on `pass.lock`, across the daemon and a selftest) keeps the sender off a pass that is still running. - **R-866.** The daemon saves the hub's newest os_update block (`os-update-block.json`); `--selftest=os-update` uses it when the hub cannot be reached and says so in its header (`block=SAVED(