R-840/R-859/R-860 records: 11 §5.3.1 + §5.4.2, 03, 04, 00; runbooks config-bundle + os-updates-test-waits; register 333→334 (R-840/859/860 closed, R-861/862 opened); STATUS; report; evidence
gates / gates (push) Successful in 31s
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -644,8 +644,18 @@ buildable until then; recorded here so the front-half built in slice 7 lands rea
|
||||
/var/lib/felhom-agent/os/plan-*.json`). The agent has no `apt` grant of its own for this; every rule (no removal,
|
||||
no downgrade, no new or unlisted package, Debian origin only, the box's own customer guest only) is in the wrapper,
|
||||
red-proved per rule. The leg runs after a successful primary whole-guest backup, under the heavy-op gate.
|
||||
**[FACT] The signed agent update does NOT carry the wrapper or the sudoers line** — only the installer installs
|
||||
them (R-840).
|
||||
~~**[FACT] The signed agent update does NOT carry the wrapper or the sudoers line** — only the installer installs
|
||||
them (R-840).~~ **[FACT, 2026-10-04, agent v0.143.0] The config bundle does:** a signed `agent_config_update` brings
|
||||
every root-owned file (sudoers, wrappers, units) as one checked unit; `felhom-os-apply` verifies it itself, keeps the
|
||||
previous copies and undoes on a failed self-check; the trust root (`/etc/felhom/operator-signers`, `os-trust.json`) is
|
||||
never a bundle path. The installer installs the same bundle. A box from before 0.143.0 needs one by-hand bootstrap.
|
||||
Design: `11` §5.4.2; runbook `runbooks/config-bundle.md`.
|
||||
- **[FACT, 2026-10-04 — R-861] "Root-minimized" overstates it.** Read from `configs/felhom-agent.sudoers`: the agent user
|
||||
can already reach root without the operator key — `FELHOM_GUESTHOOK` installs a hookscript from `/tmp` that Proxmox
|
||||
runs as root at guest start (and `pct reboot` is granted); `FELHOM_INTERMEDIARY` installs a script and a systemd unit
|
||||
that run as root at boot; `FELHOM_ESCROW` runs the agent binary as root, and `FELHOM_SELFUPDATE apply` accepts a sha
|
||||
the agent itself passes. So a compromised agent PROCESS is root on its host; the root-owned trust files (decision 93,
|
||||
the bundle's R17) are defence in depth, not a boundary, until R-861 narrows these grants.
|
||||
- **Controller (the easy case — it's a guest).** The agent owns the controller's lifecycle,
|
||||
so the **agent updates the controller**: snapshot-before-update (free rollback, because the
|
||||
controller *is* a snapshottable guest) → pull new image → redeploy → health-check → rollback
|
||||
|
||||
Reference in New Issue
Block a user