Files
felhom-agent/REPORT.md
T
admin e06ed97fa8
gates / gates (push) Successful in 22s
agent v0.146.1 REPORT
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-05 13:00:22 +02:00

3.4 KiB
Raw Blame History

REPORT — agent v0.146.0 / v0.146.1: the agent's root grants narrowed (R-861), the step bundle (R-880) — 2026-10-05

Brief: "an open-items batch … and the agent permission fix (R-861) as its own Part" (Part F). Full session report: felhom.eu/REPORT-hub-safety-2026-10-05.md. Design: felhom.eu/documentation/architecture/03-host-agent.md §3.1. Evidence: felhom.eu/documentation/audits/hub-safety-2026-10-05/partF/, delivery …/partH/.

Baseline and commits

  • Baseline 61345790ed (v0.145.0).
  • 6ab1e7c R-861 narrowing → released v0.146.0 (binary b860af46…, bundle 161c737e…) — never vouched, never delivered: a background security review of that commit found three holes.
  • fdd8717 the review fixes → released v0.146.1 (binary badd6c9a2e40c8bfe856d2d1a203443b21b7eb92ecc35d6090ab44518d4d082a, bundle 42333e969028867ad8142335e6c1bc4040eec231de0d8d330c2d4b2cf7bc3442). Two releases in one session, against "one release per repo" — the first one was unsafe to deliver.
  • e4b5cf9 scripts/build-step-bundle.py (R-880, tooling). Step bundle 0.146.1-step1, sha 8482851e….

What changed

  • Exact sudo patterns for every varying argument list (sudo regex ^…$). Measured with real sudo 1.9.16: the v0.145.0 sudoers allowed 23 of 29 attack lines; v0.146.1 allows 0 and still allows all 64 commands the capability check uses (container, and live on both demo boxes).
  • felhom-priv-apply (new root wrapper in the bundle) installs mount units, dnsmasq drop-ins, the WireGuard config and the OOB sshd config + key only after checking the CONTENT against the agent's own renderers.
  • Fixed bundle files: the guest pre-start hook and the shared drive parent (script + unit); the agent only checks and registers / enables.
  • The signed update is checked as root: felhom-os-apply mode agent_update (signature, host, window, nonce; the staged bytes read once, hashed, copied to a root-owned dir); felhom-selfupdate-guarded apply left the agent's sudoers and accepts only that root-owned dir.
  • The root escrow run pins its paths, refuses a storage id that is a path, and reads its staged files by walking the path with openat(O_NOFOLLOW).
  • NFS/SMB options gain nosuid,nodev.

Tests

go build/vet/test ./... green; configs/test_felhom_priv_apply.py 32 tests, test_felhom_config_bundle.py (incl. AgentUpdate, SelfupdateWrapperConfinement, StepBundle), test_felhom_os_apply.py green; Go contract tests feed each renderer's real output to the checker (internal/privapplytest); TestSudoersRefusesTheR861Injections, TestManifestCoveredBySudoers (regex-aware). Red-proofs F1–F9 and S1–S3: partF/red-proof.txt (F1's first run did NOT convict — masked by the name rule — and the test was strengthened; F3's first run errored rather than failed — the test now asserts cleanly).

Delivered (signed jobs, key felhom-op-1)

Per box: agent_update 0.146.1 → agent_config_update 0.146.1-step1 → agent_config_update 0.146.1. See the session report §5 for each box's result. Tester 2: offline (DOWN), nothing sent.

Not done / open

  • R-861 stays open, narrowed to three named residuals (03 §3.1): the controller-swap image ref is guest-scoped; the felhom-op SSH key is hub-delivered, unsigned (felhom-op's sudo is scoped); the escrow ceremony hands the agent R by design.
  • R-881: the installer's uninstall does not remove felhom-priv-apply.