hub v0.143.0 (code): the kernel lane — the day-before household mail, the night instruction, the operator's kernel set (R-836, decision 172)
gates / gates (push) Successful in 2m47s

KernelDue / KernelNotify (09-20 h Budapest, one per 20 h, max 3, registered
address, only an accepted mail counts) / os_update.kernel {kver, tonight}
(no mail, no step) / layer kernel ingest + operator events / Approve kernel
set after every ring-0 box booted it healthily after a night stage / two
System page cells. 11 §5.11 written; §5.10 status corrected (proven).
Installer uninstall knows the two GRUB generators (unreleased).
Evidence: audits/kernel-lane-2026-10-07/ (red-proofs, boot timing).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-07 15:34:14 +02:00
parent 0c5dbfbfc1
commit ab3b7ea2f4
29 changed files with 1453 additions and 11 deletions
+9
View File
@@ -1,3 +1,12 @@
## installer — the uninstall knows the kernel lane's files (R-836; unreleased, lands with the next installer tag) (2026-10-07)
- `felhom-host-install.sh` uninstall: removes the two GRUB generators agent v0.152.0's bundle installs
(`/etc/grub.d/01_felhom_oneshot`, `/etc/grub.d/42_felhom_oneshot`), the one-shot env block's directory on the ESP
(`/boot/efi/EFI/felhom`) and `/var/lib/felhom-kernel`, then `update-grub`. It KEEPS
`/etc/default/grub.d/zz-felhom-kernel-default.cfg` and says so: it names the kernel the box booted healthily, and
without it GRUB would boot the newest installed kernel, which may be one that fell back. Found by
`test_bundle_list_is_current` (the frozen list now names both). SCRIPT_VERSION unchanged (no tag cut this session).
## gates — the ISO first-boot test is a gate, full runs only (R-502, `09` §3 decision 147) (2026-10-06)
- scripts: R-502 — new gate `iso-bootstrap` (scripts/iso_bootstrap_gate.py) runs the ISO first-boot harness in felhom-iso-assistant:trixie on FULL runs only (fast=False: never the pre-push hook, never CI); no docker/no image/docker error = exit 2 'not checked', never a pass; every green run is followed by a built-in decoy (a pairing banner that never paints) the harness must fail. Docker-free decoys in scripts/test_iso_bootstrap_gate.py, covered in test_gate_decoys.py (decision 147).
+14
View File
@@ -1367,6 +1367,20 @@ run_uninstall() {
if [[ -e "$cgf" ]]; then run rm -f "$cgf"; fi
done
if [[ -d /var/lib/felhom-crash-guard ]]; then run rm -rf /var/lib/felhom-crash-guard; fi
# Agent v0.152.0 (R-836, the kernel lane): the two GRUB generators the bundle installs, the one-shot flag's env
# block on the ESP and the step record — then grub.cfg is regenerated without them. The GRUB default pin
# (/etc/default/grub.d/zz-felhom-kernel-default.cfg) is KEPT on purpose: it names the kernel this box booted
# healthily, and without it GRUB would boot the newest installed kernel, which may be one that fell back.
local kgf _grub_touched=false
for kgf in /etc/grub.d/01_felhom_oneshot /etc/grub.d/42_felhom_oneshot; do
if [[ -e "$kgf" ]]; then run rm -f "$kgf"; _grub_touched=true; fi
done
if [[ -d /boot/efi/EFI/felhom ]]; then run rm -rf /boot/efi/EFI/felhom; fi
if [[ -d /var/lib/felhom-kernel ]]; then run rm -rf /var/lib/felhom-kernel; fi
if $_grub_touched && command -v update-grub >/dev/null 2>&1; then run update-grub; fi
if [[ -f /etc/default/grub.d/zz-felhom-kernel-default.cfg ]]; then
log_info " kept /etc/default/grub.d/zz-felhom-kernel-default.cfg (the kernel this box booted healthily stays the default)"
fi
# 1.31.0 (R-840): the bundle's previous copies and the wrapper's nonce record.
if [[ -d /var/lib/felhom-os-apply ]]; then run rm -rf /var/lib/felhom-os-apply; fi
if [[ -f /var/lib/vz/snippets/felhom-guest-hook.sh ]]; then run rm -f /var/lib/vz/snippets/felhom-guest-hook.sh; fi
+2
View File
@@ -44,6 +44,8 @@ BUNDLE_DESTS = [
"/etc/systemd/system/felhom-crash-guard-check.service",
"/etc/systemd/system/felhom-crash-guard-check.timer",
"/etc/felhom/crash-guard.conf",
"/etc/grub.d/01_felhom_oneshot",
"/etc/grub.d/42_felhom_oneshot",
"/etc/systemd/system/felhom-agent.service",
"/etc/systemd/system/felhom-agent-rollback.service",
"/etc/systemd/system/felhom-agent.service.d/felhom-agent-limits.conf",