qemu: stage the panel's root credential files

The busybox skeleton had no /etc/shadow, so Settings/Security's root
password check (grep root: /etc/shadow, mkpasswd -m md5 with the same
salt) rejected the documented default password every time; the flow that
covers it could only record the rejection. The guest now carries
/etc/passwd, /etc/shadow (the overlay's root line, md5-crypt of the
default password with salt wardenrs, verified equal to openssl passwd -1)
and /etc/group.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3G6m9Aw5RyVY4ZowtKzEj
This commit is contained in:
Noah
2026-09-08 11:54:49 -06:00
co-authored by Claude Fable 5.1
parent e6f936ee8d
commit f809c6e5a3
4 changed files with 31 additions and 0 deletions
+5
View File
@@ -77,6 +77,11 @@ The VT cursor is kept off (`vt.global_cursor_default=0`): fbcon shares the
virtio-gpu framebuffer with warden-ui and its blinking cursor would otherwise
show up in screendumps at random (issue #18).
The guest carries the panel's own `/etc/passwd`, `/etc/shadow` and
`/etc/group` (root's md5-crypt of the documented default password), so a
screen that verifies the root password against `/etc/shadow` behaves as it
does on a panel instead of rejecting every attempt.
## Scenarios
All take the virt-fragment `<zImage>`; `FLARE_EDGE=<checkout>` where noted.