hub-safety session: R-135/R-133/R-604/R-530/R-508/R-509/R-880 closed, R-861/R-173/R-518/R-519 narrowed, R-879/R-881 opened (336 → 332); 03 §3.1, 05 §16, golden 0.296.0, the hub-DB off-site plan, STATUS
gates / gates (push) Successful in 32s
gates / gates (push) Successful in 32s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -31,6 +31,24 @@ sign; no bundle may add, remove or change them. A box that has no signers file g
|
||||
4. **Undo** = send the previous release's bundle the same way. The previous copies also stay on the box in
|
||||
`/var/lib/felhom-os-apply/bundle-prev/<time>-before-<version>/` (the last 3).
|
||||
|
||||
## A release whose bundle ADDS a path — the step bundle (R-880, decision 124)
|
||||
|
||||
The box's INSTALLED `felhom-os-apply` checks every path of an incoming bundle against its OWN table (R16). So when a
|
||||
release adds a path (agent v0.146.1 added four), every box on an older bundle refuses it. Send a step first:
|
||||
|
||||
```bash
|
||||
# the bundle the boxes run now — check its sha against the hub's Root files / config-bundle record
|
||||
curl -fsS -o base.json https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/<old>/felhom-config-bundle.json
|
||||
python3 felhom-agent/scripts/build-step-bundle.py base.json <new>-step1 step.json # prints the step sha
|
||||
curl -u admin:<token from a file> -X PUT --upload-file step.json \
|
||||
https://gitea.dooplex.hu/api/packages/admin/generic/felhom-agent/<new>-step1/felhom-config-bundle.json # 201
|
||||
# per box: agent_update <new> → agent_config_update <new>-step1 (step sha) → agent_config_update <new> (release sha)
|
||||
```
|
||||
|
||||
The step is the old bundle with ONLY `felhom-os-apply` replaced, so the old wrapper accepts it (`written=1 same=20`);
|
||||
the new wrapper then accepts the release's bundle. Done this way on demo-hp, demo-felhom and Tester 1 on 2026-10-05
|
||||
(`audits/hub-safety-2026-10-05/partH/`). Keep the step package while any box may still be on the old bundle.
|
||||
|
||||
## A box from before agent v0.143.0 — the ONE by-hand step (bootstrap)
|
||||
|
||||
Such a box's `felhom-os-apply` has no bundle mode, and no signed job can write a root file there (that gap IS
|
||||
|
||||
Reference in New Issue
Block a user