review: iteration-2 fixes (fragment assertion, evidence paths, hardening)
- build-kernel.sh fragment assertion: survives a missing trailing newline (the read footgun, reproduced) and treats an absent symbol on a disable line as FATAL, symmetric with the enable arm. - fetch-kernel-tarball.sh checks the pin before downloading; both fetchers add --retry-connrefused. - mkimage rejects '.'/'..' state keys. - ui-shot: VM liveness checked before every QMP call, console.log preserved as evidence on every failure path, repaint deadline widened to 90s with the contended-runner rationale documented. - rs485-bridge: overflow discards back off one gap and rate-limit their log line, mirroring the accept-loop fix; clippy nit fixed. - .gitignore ignores *.elf/*.map so the untracked artifacts cannot silently return; CI shellcheck glob now covers build/ and the rootfs boot scripts (directives added for the deliberate in-guest source paths). - Docs: NPU parity row matches its sibling verification docs; line-pinned audit cross-references unpinned; CROSS_COMPILE documented in the build header; payload README lists warden-ui; ci-cd tense settled. Verified: guards negative-tested (bad state keys, no-newline fragment); boot smoke, portal scenario, ui-shot all PASS; 53 tests green; shellcheck clean across the widened glob; clippy zero. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
This commit is contained in:
co-authored by
Claude Fable 5
parent
2756de0b46
commit
973a414f07
@@ -19,6 +19,7 @@ Then:
|
||||
cp <flare-edge>/target/armv7-unknown-linux-musleabihf/release/warden-flared qemu/payload/
|
||||
```
|
||||
|
||||
Stage-2 init starts `warden-flared` and `warden-modbus` automatically when
|
||||
present (logs land in `/tmp/<name>.log` inside the guest). An empty payload is
|
||||
valid — the image boots to a busybox-only userspace.
|
||||
Stage-2 init starts `warden-flared`, `warden-modbus`, and `warden-ui` (the
|
||||
UI additionally needs `--display on|headless` + the virt.fragment kernel for
|
||||
/dev/fb0) automatically when present (logs land in `/tmp/<name>.log` inside
|
||||
the guest). An empty payload is valid — the image boots busybox-only.
|
||||
|
||||
Reference in New Issue
Block a user