From 2fba92d8b374b2924e567e12a56ade1b34d4bd31 Mon Sep 17 00:00:00 2001 From: reachableceo Date: Thu, 30 Jul 2026 15:31:20 -0500 Subject: [PATCH] docs: update STATUS and JOURNAL for ISO build verification session MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Session 10 results: demo ISO built (825MB) and boot-verified to login prompt via serial console in QEMU VM. STATUS updated from "ready to build" to "built and boot-verified." JOURNAL entry documents the full session: reproducible setup script, Dockerfile pin refresh, QEMU/TPM fallback work, and ISO boot verification with key lessons. 💘 Generated with Crush Assisted-by: GLM-4.7 via Crush --- JOURNAL.md | 54 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ STATUS.md | 25 +++++++++++++++++-------- 2 files changed, 71 insertions(+), 8 deletions(-) diff --git a/JOURNAL.md b/JOURNAL.md index 4e02c4c..6baeaac 100644 --- a/JOURNAL.md +++ b/JOURNAL.md @@ -6,6 +6,60 @@ --- +## Entry 2026-07-30 (Session 10): Reproducible Dev Environment + ISO Build Verification + +### Context +Fresh clone on a new dev machine. No working dev environment — Docker image pins had +rotted (Debian security updates made 8 pinned versions unavailable), no VM tooling +installed, no git hooks. Goal: restore full working environment reproducibly and verify +the ISO actually boots. + +### Changes + +**Reproducible setup script (`scripts/setup-dev-environment.sh`):** +- New idempotent script that sets up the entire dev environment from a fresh clone +- Installs Docker, builds dev image, configures git hooks, creates working dirs +- Installs VM tooling (libvirt/qemu/ovmf/swtpm) by default; `--skip-vm` to opt out +- Runs smoke test (lint + unit tests) and prints status summary +- AGENTS.md mandatory first-actions now points at this script + +**Dockerfile pin refresh (fix: broken build on fresh clone):** +- curl 8.14.1-2+deb13u2 -> deb13u4 +- grub-pc-bin / grub-efi-amd64-bin / grub-efi-ia32-bin 2.12-9+deb13u1 -> deb13u2 +- shim-signed 1.47+15.8-1 -> 1.51~1+deb13u1+16.1-2~deb13u1 +- systemd-boot-efi 257.9-1~deb13u1 -> 257.13-1~deb13u1 +- gpg / gpg-agent 2.4.7-21+deb13u1+b2 -> +b4 +- Lesson: apt-pinned versions rot as Debian ships security updates. Consider CI check. + +**VM testing QEMU fallback (`run.sh` + `vm/template.xml`):** +- VM template: hardcoded `type='kvm'` + `cpu mode='host-passthrough'` replaced with + `@DOMAIN_TYPE@` and `@CPU_ELEMENT@` placeholders +- run.sh: detects `/dev/kvm` at runtime; falls back to `type='qemu'` + `qemu64` CPU + model when KVM unavailable (nested VMs, CI, containers) +- TPM retry: if VM start fails with swtpm, retries without TPM (not needed for boot test) +- 6 new unit tests covering placeholder existence, KVM detection, substitution logic + +**ISO build + boot verification:** +- Built demo ISO: `output/knel-football-secure.iso` (825MB, demo mode, serial console) +- Booted in QEMU VM (no KVM available — parent hypervisor doesn't expose VT-x) +- Serial console captured: kernel boot, systemd init, live-config, reached login prompt +- Login prompt confirmed: `Debian GNU/Linux 13 debian ttyS0` / `debian login:` + +### Key Lessons +1. **Apt version pins rot** — pinned versions disappear from archives after security + updates. Rotted pins completely broke the build on a fresh clone months later. +2. **QEMU TCG emulation works for boot testing** — ~10x slower but gets the job done + when KVM isn't available. VM reached login prompt after ~30 min CPU time. +3. **Nested virt requires parent-level config** — `kvm_intel` returns I/O error if the + parent hypervisor doesn't expose VT-x. Cannot fix from inside the guest VM. +4. **swtpm setup can fail silently** — the permission fix script + qemu.conf config + help, but swtpm_setup can still fail for other reasons. TPM retry in vm_create() + makes boot testing resilient. +5. **Serial console needs pseudo-TTY** — `virsh console` requires a real/pseudo TTY + (`script` command works); direct `cat` of the PTY device gets permission denied. + +--- + ## Entry 2026-05-08 (Session 9): Host FDE Removal + Final Partials Fix ### Context diff --git a/STATUS.md b/STATUS.md index c288d63..cf7675b 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,17 +1,25 @@ # KNEL-Football Project Status Report -> **Last Updated**: 2026-05-08 (Session 9 - Remove host FDE, fix remaining partials) +> **Last Updated**: 2026-07-30 (Session 10 - ISO built and verified) > **Maintained By**: AI Agent (Crush) > **Purpose**: Quick-glance status for project manager --- -## Current Status: 🔧 ALL TECHNICAL FIXES APPLIED — READY FOR ISO BUILD +## Current Status: ✅ ISO BUILT AND BOOT-VERIFIED ### Executive Summary -All 39 findings from DeepReport-2026-05-08.md have been addressed. -Host FDE requirement removed — only guest (ISO) FDE is required. -ISO is ready to build: `./run.sh iso` +Demo ISO built successfully (825MB) and verified booting to login prompt in QEMU VM. +Reproducible dev environment setup script added (`scripts/setup-dev-environment.sh`). +VM testing tooling now supports QEMU fallback when KVM is unavailable. + +### Build & Verification Results (Session 10) +- **ISO**: `output/knel-football-secure.iso` (825MB, demo mode) +- **SHA256**: `c9b11932ce0fe015274c81a13bc3202ec4b52178e8fbbe146f9d0010a09b7559` +- **Boot test**: PASS — kernel, systemd init, live-config, reached login prompt +- **Serial console**: `Debian GNU/Linux 13 debian ttyS0` / `debian login:` +- **Tests**: 788 pass, 0 fail (6 new KVM/QEMU fallback tests) +- **Lint**: 0 warnings ### Immediate Action: Build the ISO ```bash @@ -79,10 +87,11 @@ ISO is ready to build: `./run.sh iso` | Item | Status | |------|--------| -| Docker image | ✅ Built with new packages | +| Docker image | ✅ Built with refreshed pins | | Lint (shellcheck) | ✅ 0 warnings | -| Tests | ✅ 782 pass, 0 fail | -| ISO build | ⬜ Ready — run `./run.sh iso` | +| Tests | ✅ 788 pass, 0 fail | +| ISO build | ✅ Built (demo, 825MB) | +| ISO boot test | ✅ Reached login prompt via serial console | ---