Decisions 157-158 recorded; R-892 corrected (VM 341), R-894 filed (unreadable off-site storage reads due after an agent restart); Part C/E/F evidence; nodes.md: the Tester 1 box; 11 §5.8: the memory-kill check
gates / gates (push) Successful in 2m47s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 19:18:14 +02:00
parent eed1dbd80c
commit 01c4a5d2a9
30 changed files with 845 additions and 2 deletions
@@ -415,6 +415,14 @@ must never overlap a backup, a restore-test or a self-update.~~
- **Approval**: the hub never approves a Docker set automatically; the System page's button works after every ring-0 box
ran the set in 2 healthy night Docker steps (`OS_DOCKER_APPROVE_NIGHTS` TEST override, logged). An approval nudges no
box. Undo: `runbooks/os-updates-docker-undo.md`.
- **The engine must report a memory kill (decision 157, agent v0.150.0 + hub v0.140.0, 2026-10-06).** After a Docker step
the wrapper runs `oom_check`: a throwaway container from the image the running controller uses (`--pull never`,
`--network none`, no volume, label `felhom.oomcheck=1`, 64 MB cap) asks for one 200 MB block; pass = `OOMKilled=true` AND
the `oom` event; the container is removed whatever happens; the result rides the report as `oom_check`. The approval
button waits until every ring-0 box reported a PASSING check with the set, and refuses while any report of the set
carries a failed or errored one. **Measured by hand on demo-hp's guest (29.8.2):** `OOMKilled=true`, exit 137, the
event `create attach start oom die` — but only when the events window ends a second AFTER the run (a window closed in
the same second missed it); the wrapper waits 2 s and reads to epoch + 1 (`audits/readback-2026-10-07/F/`).
**The design as written before the build:**