review: iteration-2 fixes (fragment assertion, evidence paths, hardening)

- build-kernel.sh fragment assertion: survives a missing trailing newline
  (the read footgun, reproduced) and treats an absent symbol on a disable
  line as FATAL, symmetric with the enable arm.
- fetch-kernel-tarball.sh checks the pin before downloading; both fetchers
  add --retry-connrefused.
- mkimage rejects '.'/'..' state keys.
- ui-shot: VM liveness checked before every QMP call, console.log preserved
  as evidence on every failure path, repaint deadline widened to 90s with
  the contended-runner rationale documented.
- rs485-bridge: overflow discards back off one gap and rate-limit their log
  line, mirroring the accept-loop fix; clippy nit fixed.
- .gitignore ignores *.elf/*.map so the untracked artifacts cannot silently
  return; CI shellcheck glob now covers build/ and the rootfs boot scripts
  (directives added for the deliberate in-guest source paths).
- Docs: NPU parity row matches its sibling verification docs; line-pinned
  audit cross-references unpinned; CROSS_COMPILE documented in the build
  header; payload README lists warden-ui; ci-cd tense settled.

Verified: guards negative-tested (bad state keys, no-newline fragment);
boot smoke, portal scenario, ui-shot all PASS; 53 tests green; shellcheck
clean across the widened glob; clippy zero.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
This commit is contained in:
BFE Engineering
2026-08-30 08:34:47 -06:00
co-authored by Claude Fable 5
parent 2756de0b46
commit 973a414f07
17 changed files with 72 additions and 26 deletions
+14 -5
View File
@@ -61,6 +61,7 @@ pub fn pump_serial(
stream.set_read_timeout(Some(gap))?;
let mut buf: Vec<u8> = Vec::new();
let mut chunk = [0u8; 256];
let mut discards: u64 = 0;
loop {
match (&*stream).read(&mut chunk) {
Ok(0) => {
@@ -72,12 +73,20 @@ pub fn pump_serial(
Ok(n) => {
buf.extend_from_slice(&chunk[..n]);
if buf.len() > MAX_PENDING {
eprintln!(
"rs485: {} bytes buffered with no inter-frame gap — discarding \
(misbehaving master streaming continuously?)",
buf.len()
);
// Rate-limit the log and back off for one gap so a master
// streaming continuously cannot peg a core and flood
// stderr — mirroring the accept-loop backoff.
discards += 1;
if discards == 1 || discards.is_multiple_of(256) {
eprintln!(
"rs485: {} bytes buffered with no inter-frame gap — \
discarding (misbehaving master? {} discards so far)",
buf.len(),
discards
);
}
buf.clear();
std::thread::sleep(gap);
}
}
Err(e)