hub v0.131.0: the tunnel status is true (R-841: three states, tunnel_down after two not_running reports, unknown never alarms); OS updates per layer (guest/host separate approved sets, host candidate leaves out kernel/boot/firmware, host_release in the box block), the fleet view and four hourly operator alarms (11 §8 steps 3+4); red-proofs in audits/os-host-lane-2026-10-04
gates / gates (push) Successful in 30s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 13:05:00 +02:00
parent 0ed2e8de4c
commit 88b0a2e761
24 changed files with 1254 additions and 149 deletions
+8
View File
@@ -687,6 +687,14 @@ var operatorOnlyEvents = map[string]bool{
"os_release_approved": true,
"os_release_approved_now": true,
"os_update_settings_changed": true,
// R-841 (hub v0.131.0): the tunnel alarm — a box fact the household can do nothing about from inside.
"tunnel_down": true,
"tunnel_recovered": true,
// `11` §8.3 (hub v0.131.0): the four OS-update alarms — fleet facts only the operator can act on.
"os_update_stale": true,
"os_reboot_needed": true,
"os_ring0_stalled": true,
"os_not_covered": true,
// R-197 (v0.93.0). "The sealed offsite repository key changed" is a custody fact about escrow
// blobs. A customer can take no action on it — the remedy is the operator's inspection of the
// off-site tier — and the text is operator-grade English naming host ids and retained-blob