installer 1.30.0 (not yet tagged): the crash guard units + config, the root-owned slow-lane trust files (os-trust.json, operator-signers), their removal on uninstall
gates / gates (push) Successful in 28s
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,17 @@
|
||||
## felhom-host-install.sh 1.30.0 — the crash guard and the slow-lane trust files (2026-10-04)
|
||||
|
||||
Needs agent ≥ 0.142.0 at the pinned tag for the crash guard (an older agent: skipped with a warning, the box keeps
|
||||
`kernel.panic = 0`).
|
||||
|
||||
- **The crash guard** (`09` decision 88, R-851, `11` §5.9): fetches `configs/felhom-crash-guard`, its two services, the
|
||||
timer and `crash-guard.conf` from the pinned agent tag; syntax-checks; installs (0755 / 0644 root); enables
|
||||
`felhom-crash-guard.service` + `felhom-crash-guard-check.timer` now. An existing `/etc/felhom/crash-guard.conf` is kept.
|
||||
- **The root-owned slow-lane trust files** (`11` §5.8, the wrapper's R3): `/etc/felhom/os-trust.json` (this box's
|
||||
`host_id`; `ring0_slow_lane` false — an existing file keeps its mark) and `/etc/felhom/operator-signers` (the
|
||||
operational operator key in ssh `allowed_signers` form). The agent's own config is agent-writable and is not trusted
|
||||
for a Docker step.
|
||||
- Uninstall removes all of it (`kernel.panic` returns to the kernel default 0 at the next boot).
|
||||
|
||||
## felhom-host-install.sh 1.29.0 — installs the OS-update wrapper (2026-10-04, `11-os-updates.md` §8 step 2)
|
||||
|
||||
- Step 5 fetches `configs/felhom-os-apply` from the pinned agent tag and installs it as
|
||||
|
||||
Reference in New Issue
Block a user