R-840/R-859/R-860 records: 11 §5.3.1 + §5.4.2, 03, 04, 00; runbooks config-bundle + os-updates-test-waits; register 333→334 (R-840/859/860 closed, R-861/862 opened); STATUS; report; evidence
gates / gates (push) Successful in 31s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 20:40:08 +02:00
parent c01d48f457
commit 79f07a7f10
18 changed files with 478 additions and 10 deletions
+12 -2
View File
@@ -644,8 +644,18 @@ buildable until then; recorded here so the front-half built in slice 7 lands rea
/var/lib/felhom-agent/os/plan-*.json`). The agent has no `apt` grant of its own for this; every rule (no removal,
no downgrade, no new or unlisted package, Debian origin only, the box's own customer guest only) is in the wrapper,
red-proved per rule. The leg runs after a successful primary whole-guest backup, under the heavy-op gate.
**[FACT] The signed agent update does NOT carry the wrapper or the sudoers line** — only the installer installs
them (R-840).
~~**[FACT] The signed agent update does NOT carry the wrapper or the sudoers line** — only the installer installs
them (R-840).~~ **[FACT, 2026-10-04, agent v0.143.0] The config bundle does:** a signed `agent_config_update` brings
every root-owned file (sudoers, wrappers, units) as one checked unit; `felhom-os-apply` verifies it itself, keeps the
previous copies and undoes on a failed self-check; the trust root (`/etc/felhom/operator-signers`, `os-trust.json`) is
never a bundle path. The installer installs the same bundle. A box from before 0.143.0 needs one by-hand bootstrap.
Design: `11` §5.4.2; runbook `runbooks/config-bundle.md`.
- **[FACT, 2026-10-04 — R-861] "Root-minimized" overstates it.** Read from `configs/felhom-agent.sudoers`: the agent user
can already reach root without the operator key — `FELHOM_GUESTHOOK` installs a hookscript from `/tmp` that Proxmox
runs as root at guest start (and `pct reboot` is granted); `FELHOM_INTERMEDIARY` installs a script and a systemd unit
that run as root at boot; `FELHOM_ESCROW` runs the agent binary as root, and `FELHOM_SELFUPDATE apply` accepts a sha
the agent itself passes. So a compromised agent PROCESS is root on its host; the root-owned trust files (decision 93,
the bundle's R17) are defence in depth, not a boundary, until R-861 narrows these grants.
- **Controller (the easy case — it's a guest).** The agent owns the controller's lifecycle,
so the **agent updates the controller**: snapshot-before-update (free rollback, because the
controller *is* a snapshottable guest) → pull new image → redeploy → health-check → rollback