qemu: device-sim bringup — boot smoke, A/B disk harness, virt kernel variant

The third simulator (deliberately not named "sim"): a QEMU -M virt VM that
boots the real 6.18.46 kernel and enters at -kernel zImage — everything below
(BootROM/idblock/U-Boot/real BCB A/B selection) is closed blobs + mask ROM
and is explicitly out of scope.

- qemu/mkinitramfs.sh: pinned static busybox (sha256 fail-closed) + rootfs/
- qemu/mkimage.sh: unprivileged sparse disk image with the device's canonical
  12-partition blkdevparts A/B layout (vda == mmcblk0 mapping)
- qemu/rootfs/: stage-1 init (by-name symlinks from PARTNAME uevents,
  whole-token warden.slot= parse, switch_root) + stage-2 init (userdata/oem
  mounts, slirp networking, payload daemon start)
- qemu/run.sh: runner with --slot/--rtc/--watchdog/--rs485/--qmp/--display
- qemu/configs/virt.fragment + WARDEN_KCONFIG_FRAGMENT hook in
  build/build-kernel.sh (canonical RV1106 build untouched when unset):
  adds PCI, pci-serial, i6300esb watchdog, WireGuard, virtio-gpu/input
- qemu/tests/boot-smoke.sh: sentinel-asserting boot test

Verified on QEMU 10.0.11: canonical zImage boots -M virt unmodified (the
feared DEBUG_UNCOMPRESS decompressor hang does not exist in 6.18); full
stack boots both slots; 12 by-name symlinks; userdata persists across
reboot; -rtc base=2021-01-01 reproduces the no-RTC wrong-clock class.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
This commit is contained in:
BFE Engineering
2026-08-29 18:53:16 -06:00
co-authored by Claude Fable 5
parent 44cdf2bf38
commit bf3c93cf85
16 changed files with 680 additions and 0 deletions
+36
View File
@@ -0,0 +1,36 @@
# QEMU -M virt kernel variant — merged onto build/warden_defconfig via
# WARDEN_KCONFIG_FRAGMENT (see build/build-kernel.sh). The RV1106 zImage stays
# canonical and byte-identical when the variable is unset.
#
# The canonical zImage already BOOTS on -M virt as-is (verified 2026-08-29:
# the multi_v7 heritage supplies ARCH_VIRT + the virtio set, and DEBUG_LL's
# hardcoded RV1106 UART is inert as long as `earlyprintk` is never passed on
# the cmdline). This fragment therefore only ADDS what the device-sim
# scenarios need beyond the canonical config.
# -M virt exposes exactly one PL011 (probed: QEMU 10 dtb has a single
# pl011@9000000); every additional device below rides the machine's PCIe
# (ECAM "host generic") root.
CONFIG_PCI=y
CONFIG_PCI_HOST_GENERIC=y
# Second UART for the RS485/Modbus bridge: -device pci-serial (16550-class,
# shows up as ttyS0; stage-2 init aliases it to the device's /dev/ttyS4).
CONFIG_SERIAL_8250_PCI=y
# /dev/watchdog for flared's watchdog_loop() — untestable on both existing
# sims. i6300esb is the watchdog QEMU offers on arm virt (PCI device):
# -device i6300esb -action watchdog=reset.
CONFIG_WATCHDOG=y
CONFIG_I6300ESB_WDT=y
# wg0 mesh scenarios (flared owns identity, the panel shells out `wg`).
CONFIG_WIREGUARD=y
# Display + touch: virtio-gpu scanout with fbdev emulation (the VM UI build
# uses LVGL's fbdev backend — no libdrm needed in the guest), virtio-tablet
# for absolute-coordinate touch injection via QMP.
CONFIG_FB=y
CONFIG_DRM_VIRTIO_GPU=y
CONFIG_DRM_FBDEV_EMULATION=y
CONFIG_VIRTIO_INPUT=y