Files
bfe-core1106-sdk/qemu/rootfs/init
T
BFE EngineeringandClaude Fable 5 973a414f07 review: iteration-2 fixes (fragment assertion, evidence paths, hardening)
- build-kernel.sh fragment assertion: survives a missing trailing newline
  (the read footgun, reproduced) and treats an absent symbol on a disable
  line as FATAL, symmetric with the enable arm.
- fetch-kernel-tarball.sh checks the pin before downloading; both fetchers
  add --retry-connrefused.
- mkimage rejects '.'/'..' state keys.
- ui-shot: VM liveness checked before every QMP call, console.log preserved
  as evidence on every failure path, repaint deadline widened to 90s with
  the contended-runner rationale documented.
- rs485-bridge: overflow discards back off one gap and rate-limit their log
  line, mirroring the accept-loop fix; clippy nit fixed.
- .gitignore ignores *.elf/*.map so the untracked artifacts cannot silently
  return; CI shellcheck glob now covers build/ and the rootfs boot scripts
  (directives added for the deliberate in-guest source paths).
- Docs: NPU parity row matches its sibling verification docs; line-pinned
  audit cross-references unpinned; CROSS_COMPILE documented in the build
  header; payload README lists warden-ui; ci-cd tense settled.

Verified: guards negative-tested (bad state keys, no-newline fragment);
boot smoke, portal scenario, ui-shot all PASS; 53 tests green; shellcheck
clean across the widened glob; clippy zero.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
2026-08-30 08:34:47 -06:00

34 lines
1.1 KiB
Plaintext
Executable File

#!/bin/busybox sh
# WardenOS QEMU device sim: initramfs /init (PID 1).
#
# Phase-1 duty: prove the kernel booted on -M virt — print the sentinel the
# smoke test greps for, then power off (PSCI SYSTEM_OFF, so qemu exits).
# `warden.shell` on the kernel cmdline drops to an interactive shell instead.
/bin/busybox mount -t devtmpfs devtmpfs /dev 2>/dev/null
# The cpio archive carries no device nodes (it is built unprivileged, no
# mknod); reopen stdio on the real console now that devtmpfs is mounted.
exec </dev/console >/dev/console 2>&1
/bin/busybox --install -s /bin
mount -t proc proc /proc
mount -t sysfs sysfs /sys
echo "WARDEN-QEMU-BOOT-OK"
# With a virtio disk attached, hand over to the stage-1 rc (by-name symlinks,
# slot select, switch_root). It only returns on failure — then fall through to
# the diskless shell/poweroff behavior below.
if [ -b /dev/vda ]; then
# shellcheck source=qemu/rootfs/etc/rc disable=SC1091
. /etc/rc
fi
if grep -qw warden.shell /proc/cmdline; then
echo "warden.shell: interactive shell (exit to power off)"
setsid cttyhack sh
fi
poweroff -f