qemu: full OTA apply scenario — write rootfs_b, flip AvbABData, boot it
Closes the loop every prior harness stopped short of, entirely off-hardware: the real flared (WARDEN_HARD_RESET-gated build) pulls a real signed tier-1 .wfw whose payload is a BOOTABLE rootfs stamped 0.0.2, verifies it, writes /dev/block/by-name/rootfs_b inside disk.img, and flips the AvbABData (slot B: priority 15, 3 tries, unsuccessful — the exact pre-first-boot arming state, round-tripped through a portal check-in). The harness then boots slot _b and asserts the applied version + marker are what runs. OTA-APPLY-PASS verified end to end. - mkimage: the misc partition now carries REAL provisioned AvbABData (bytes mirror flare-edge's provisioning defaults) — slotctl fail-closes on bad AB magic before writing, which a zeroed misc tripped. - run.sh --allow-apply / cmdline warden.fwapply: per-boot opt-in that makes stage-2 init export WARDEN_FW_ALLOW_APPLY=1; never the default. - stage-2 init also exports WARDEN_HARD_RESET=0 (the CRU poke is fatal on virt, same class as the HPMCU probe); the harness performs the reboot. - ADR-0006 boundary documented in the scenario and README: BCB slot CHOICE and the physical reset remain emulated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
This commit is contained in:
co-authored by
Claude Fable 5
parent
ff62991e8d
commit
d63c2117c1
+5
-1
@@ -22,6 +22,8 @@
|
||||
# --http-port N hostfwd 127.0.0.1:N -> guest :80 (default 8080; 0 disables)
|
||||
# --api-port N hostfwd 127.0.0.1:N -> guest :28443 (default 28443; 0 disables)
|
||||
# --shell interactive shell in the guest instead of daemon hold
|
||||
# --allow-apply let flared ACTUALLY apply OTA firmware (writes rootfs_b
|
||||
# inside disk.img — safe in the VM, never the default)
|
||||
set -euo pipefail
|
||||
|
||||
QEMU_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
@@ -30,7 +32,7 @@ QEMU_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
OUT="${OUT:-$QEMU_DIR/out}"
|
||||
|
||||
KERNEL="" INITRD="$OUT/initramfs.cpio.gz" DISK="" NO_DISK=0 SLOT="_a"
|
||||
RTC="" RS485="" WATCHDOG=0 QMP="" DISPLAY_MODE="off" SHELL_FLAG=0
|
||||
RTC="" RS485="" WATCHDOG=0 QMP="" DISPLAY_MODE="off" SHELL_FLAG=0 ALLOW_APPLY=0
|
||||
SSH_PORT=2222 HTTP_PORT=8080 API_PORT=28443
|
||||
EXTRA=()
|
||||
|
||||
@@ -50,6 +52,7 @@ while [ $# -gt 0 ]; do
|
||||
--http-port) HTTP_PORT="${2:?}"; shift 2 ;;
|
||||
--api-port) API_PORT="${2:?}"; shift 2 ;;
|
||||
--shell) SHELL_FLAG=1; shift ;;
|
||||
--allow-apply) ALLOW_APPLY=1; shift ;;
|
||||
--) shift; EXTRA=("$@"); break ;;
|
||||
*) echo "FATAL: unknown argument '$1' (see header of $0)" >&2; exit 1 ;;
|
||||
esac
|
||||
@@ -99,6 +102,7 @@ if [ -n "$DISK" ] && [ "$NO_DISK" -eq 0 ]; then
|
||||
-device "virtio-blk-device,drive=vd0" )
|
||||
fi
|
||||
[ "$SHELL_FLAG" -eq 1 ] && APPEND="$APPEND warden.shell"
|
||||
[ "$ALLOW_APPLY" -eq 1 ] && APPEND="$APPEND warden.fwapply"
|
||||
[ -n "$RTC" ] && ARGS+=( -rtc "base=$RTC" )
|
||||
[ "$WATCHDOG" -eq 1 ] && ARGS+=( -device i6300esb -action watchdog=reset )
|
||||
[ -n "$RS485" ] && ARGS+=( -chardev "socket,id=rs485,path=$RS485,server=on,wait=off"
|
||||
|
||||
Reference in New Issue
Block a user