- build-kernel.sh fragment assertion: survives a missing trailing newline (the read footgun, reproduced) and treats an absent symbol on a disable line as FATAL, symmetric with the enable arm. - fetch-kernel-tarball.sh checks the pin before downloading; both fetchers add --retry-connrefused. - mkimage rejects '.'/'..' state keys. - ui-shot: VM liveness checked before every QMP call, console.log preserved as evidence on every failure path, repaint deadline widened to 90s with the contended-runner rationale documented. - rs485-bridge: overflow discards back off one gap and rate-limit their log line, mirroring the accept-loop fix; clippy nit fixed. - .gitignore ignores *.elf/*.map so the untracked artifacts cannot silently return; CI shellcheck glob now covers build/ and the rootfs boot scripts (directives added for the deliberate in-guest source paths). - Docs: NPU parity row matches its sibling verification docs; line-pinned audit cross-references unpinned; CROSS_COMPILE documented in the build header; payload README lists warden-ui; ci-cd tense settled. Verified: guards negative-tested (bad state keys, no-newline fragment); boot smoke, portal scenario, ui-shot all PASS; 53 tests green; shellcheck clean across the widened glob; clippy zero. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
34 lines
1.1 KiB
Plaintext
Executable File
34 lines
1.1 KiB
Plaintext
Executable File
#!/bin/busybox sh
|
|
# WardenOS QEMU device sim: initramfs /init (PID 1).
|
|
#
|
|
# Phase-1 duty: prove the kernel booted on -M virt — print the sentinel the
|
|
# smoke test greps for, then power off (PSCI SYSTEM_OFF, so qemu exits).
|
|
# `warden.shell` on the kernel cmdline drops to an interactive shell instead.
|
|
|
|
/bin/busybox mount -t devtmpfs devtmpfs /dev 2>/dev/null
|
|
|
|
# The cpio archive carries no device nodes (it is built unprivileged, no
|
|
# mknod); reopen stdio on the real console now that devtmpfs is mounted.
|
|
exec </dev/console >/dev/console 2>&1
|
|
|
|
/bin/busybox --install -s /bin
|
|
mount -t proc proc /proc
|
|
mount -t sysfs sysfs /sys
|
|
|
|
echo "WARDEN-QEMU-BOOT-OK"
|
|
|
|
# With a virtio disk attached, hand over to the stage-1 rc (by-name symlinks,
|
|
# slot select, switch_root). It only returns on failure — then fall through to
|
|
# the diskless shell/poweroff behavior below.
|
|
if [ -b /dev/vda ]; then
|
|
# shellcheck source=qemu/rootfs/etc/rc disable=SC1091
|
|
. /etc/rc
|
|
fi
|
|
|
|
if grep -qw warden.shell /proc/cmdline; then
|
|
echo "warden.shell: interactive shell (exit to power off)"
|
|
setsid cttyhack sh
|
|
fi
|
|
|
|
poweroff -f
|