# Part B live proof — the Proxmox package lane on demo-felhom (2026-10-07 14:15 CEST) Agent 0.151.0 + its bundle (probe 68/68), hub 0.142.0. One signed `os_pve_step` (the product's ring-1 path, used by hand outside 02:00–08:30; the debug selftest was NOT used because it also runs the Docker step the brief forbids). The set: 66 packages of origin "Proxmox Debian Repository" from a dry-run (`B1`, `B2-params.json`); 14 left out — shim, firmware, `proxmox-first-boot`, the kernel names (`B2-skipped.txt`). - Journal (`B6-after.txt`): `pve step holds the /etc/pve write gate` → `os-apply: START … layer=pve:9201 lane=slow select=listed packages=66 authority=signed` → `PLAN upgrade=65 not-installed=1` → `NEW proxmox-firewall-data=0.1 (on the pve lane's allow-list)` → `DONE rc=0 seconds=69.6 upgraded=65 restart-needed=watchdog-mux reboot-needed=no` → `osupdate: DONE … outcome=applied healthy=true` → `released the /etc/pve write gate` → `signed op COMPLETED`. - `pveversion`: 9.2.2 → **9.2.21**; running kernel unchanged (7.0.2-6). - The guest kept running: every container's `StartedAt` identical before and after (`B3`, `B6`). - opengist through traefik every 5 s: **31 of 31 answered 302** from 14:14:30 to 14:18:00 (`B4-sampler-5s.log`). - Second channel, the hub's log: `demo-felhom-8363b5 reported pve run 20261007T121513Z … outcome=applied healthy=true upgraded=65` (`B8-hub-log.txt`). The System page's pve row still reads „a ring-0 box has not reported a Proxmox step" — by design: the candidate needs every ring-0 box's pve report, and demo-hp has run none (`osupdates/service.go:305-313`).