docs: 06-doc S3 SHIPPED (agent v0.64.0) + agent-side revocation semantics + CONTEXT/REPORT

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
This commit is contained in:
2026-07-04 08:58:44 +02:00
parent 4fe895eaa4
commit 76ee25e5e8
4 changed files with 48 additions and 100 deletions
+10
View File
@@ -1,5 +1,15 @@
# Felhom scripts — Changelog
## docs — 06-doc S3 row SHIPPED + agent-side revocation semantics (2026-07-04)
Docs-only companion to **felhom-agent v0.64.0** (the S3 slice — keygen, registration,
agent-managed `wg-quick@wg-felhom`, escrow join; live-validated on felhom-pve incl. revocation
drill, reboot persistence, 30-min soak). 06-doc §3.5 now records: register-once marker,
revoked-stays-revoked, re-add via the registration endpoint (the raw registry add doesn't bump
the host generation — live finding), `wg_tunnel.enabled` default-FALSE rollout gate. S6 backlog
notes added (hub poll constant configurable + first-adoption log; registry-add bump-or-label).
CGNAT/mobile-hotspot appendix deferred (operator-assisted; §7's open validation stands).
## felhom-peersync.sh v1.0.1 — strip out of process substitution (exit-swallow fix) (2026-07-04)
The S1 REPORT's exit-swallow class, fixed: `wg syncconf wg0 <(wg-quick strip "$tmp")` hid the