Golden 0.242.0 baked, round-trip verified and vouched (cadence rule, R-468). Fresh box from the public ISO on demo-hp: landed on the vouched set, two apps deployed and used, backup, remove, byte-identical restore, power cut and code typo all PASS. Stopped for a volunteer by R-493 (no instructions) and R-494 (the setup mail's dashboard link has no DNS; intervention I1). R-493..R-500 filed. Capability map: first-hour row added (PARTIAL), journey row scoped. Stopgap Hungarian volunteer guide written. Hub teardown layer pending. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
3.2 KiB
Golden bake 0.242.0 — 2026-09-14
Baked, published, round-trip verified and vouched. The fleet floor was already 0.242.0 (raised by
the v0.242.0 release under hub v0.112.0's declared-MinAgent rule), so it did not move.
This bake carries SIX releases: 0.237.0 … 0.242.0 were never baked. It was baked because the
cadence rule says a golden comes before any drill or fresh install (R-468, RUNBOOK-manual-build.md
§4.2) — the drill it precedes is audits/DRILL-fresh-install-0242-2026-09-14.md.
GOLDEN_SHA256 |
3ab480ddb7c1e690492db1a56ac3052ffeccea8ccf59ed7b7927054aae8ee6d8 |
| size | 653 288 425 B |
| baked controller | gitea.dooplex.hu/admin/felhom-controller:0.242.0 |
MinAgent |
0.129.0 — stated in v0.242.0's own header ("unchanged") |
| script | build-golden.sh v3.0.0, sha 7b0fb5cf…73b6a1, compared across the hop (02-template.txt) |
| template | debian-13-standard_13.6-1_amd64.tar.zst, after pveam update |
Acceptance markers — counted on the COMMITTED log (04-markers.txt)
docker OK (overlay2 : 1
including mount point rootfs : 1
including mount point mp0 : 1
upload OK (HTTP 201) : 1
--- must be ZERO ---
excluding : 0
FATAL : 0
Three independent readers agreed before anything was vouched
- The bake printed
GOLDEN_SHA256=3ab480dd…e6d8. - The round trip (
07-roundtrip.txt) —HTTP 200, 653 288 425 B, sha3ab480dd…e6d8, hashed from the downloaded bytes. The archive's./etc/felhom-controller-imagereadsgitea.dooplex.hu/admin/felhom-controller:0.242.0, with 19 382 entries undervar/lib/felhom/docker/. - The hub's Day-0 dropdown (
08-hub-before-vouch.txt):0.242.0 sha=3ab480ddb7c1e690492db1a5.
Pre-gates, each proven able to see something first (01-preconditions.txt, 03-bake-launch.txt)
| gate | result | control |
|---|---|---|
| 404 pre-gate | HTTP 404 for 0.242.0 before the bake |
the 0.236.0 package returns HTTP 200 on the same URL shape |
| token-leak grep on the committed log | 0 | token appended to a throwaway copy greps 1; copy shred -u'd |
| token off every command line | unit properties grep 0 | the same seeded control returns 1 |
A slip, recorded (02-template.txt)
My first template pick (pveam available | … | sort -V | tail -1) selected the arm64 image, which
sorts after amd64. Caught on read-back before the bake started; amd64 fetched by exact name, arm64
deleted. The runbook's step 2 says "list the current one" — list and pick by the _amd64 suffix.
The vouch — three fields, only one moved (09-vouch.txt, 11-vouch-verified.txt)
| field | before | after |
|---|---|---|
golden_version |
0.236.0 | 0.242.0 |
agent_version |
0.130.0 | 0.130.0 |
min_agent |
0.129.0 | 0.129.0 |
POST /configuration/artifacts → 303 flash=artifacts_set; re-read: golden 0.242.0 selected with
sha 3ab480dd…, R-120 refusal banner absent, floor 0.242.0.
Teardown (05-teardown.txt)
pct destroy 9100 --purge; token, runner, script and log shred -u'd after the log was copied
out (leftovers 0); poweroff; qemu confirmed exited with ps -eo comm; qemu-img snapshot -a virgin.