Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
1.5 KiB
REPORT — agent v0.143.0: the config bundle (R-840) — 2026-10-04
What: a signed route for a box's root-owned files. felhom-os-apply gained mode bundle (signed
agent_config_update, verified by the wrapper itself) and --install-bundle (the installer's root entry);
BUNDLE_FILES is the one table of 22 paths; scripts/build-config-bundle.py builds it reproducibly;
release-agent.sh publishes it beside the binary; the agent reports system.config_bundle; felhom-opsign signs it.
Also build-golden.sh 3.2.0 (GOLDEN_GUEST_PKGS).
Released: v0.143.0, binary 41c0d306…, bundle 8d7273cf… (reproducible), vouched in the hub with golden 0.293.0.
Delivered: demo-hp and demo-felhom (signed agent_update), then the one-file bootstrap, then the bundle by the
signed route (0 written of 22; probe 71/71). demo-hp also: a wrong sha refused, a one-line change and its undo, a replay
rejected. Tester 2: the signed agent_update queued (operator ruling 97); its bundle waits for the operator's
bootstrap (R-862).
Tests: configs/test_felhom_config_bundle.py 43 (22 of 22 mutants red), Go internal/osupdate/bundle_test.go,
internal/hub/bundle_record_test.go; go vet ./... && go test ./... rc=0; gates green.
Found: R-861 — the sudoers already lets the agent user reach root (read, not exploited).
Evidence and the full report: felhom.eu/documentation/audits/r840-config-bundle-2026-10-04/,
felhom.eu/REPORT-r840-config-bundle-2026-10-04.md.