evidence: verify cross-root repository service on JD
This commit is contained in:
parent
b7925420ff
commit
9b19fee681
6 changed files with 128 additions and 8 deletions
|
|
@ -0,0 +1,69 @@
|
|||
schema: guanghu.jd-cross-root-repository-qemu-receipt/v1
|
||||
receipt_id: JD-FD-PRIMARY-cross-root-repository-qemu-0759625
|
||||
issued_at: 2026-08-16T00:52:14+08:00
|
||||
development_id: DEV-20260815-001
|
||||
development_id_role: EVIDENCE_NAMESPACE_ONLY_NOT_ACTIVE_LANE
|
||||
node_id: JD-FD-PRIMARY
|
||||
node_dmi: f3d4b730-7f02-452f-975b-7091a4800431
|
||||
source_commit: b7925420ff161301704800c98e2b15bea2a01c40
|
||||
source_tree: 815aacf80273ad264e36ef8adcaa5abb6f59b686
|
||||
workorder_sha256: 93416b8d0f2ce2d6e45ea81e8cdfd34f03dbb61e2df1f0485307ae28cfbc2189
|
||||
root_image_sha256: 1c71f1dd3d150b9be4df510c6760ec680670b9c44fc4e62bfa752896a883b6d9
|
||||
root_image_size: 134217728
|
||||
accepted_serial_sha256: 041824dad20c0e48bea12ecc4887695434a14ada3c3d5b9c599c423acc840b2a
|
||||
accepted_serial_size: 32842
|
||||
trigger: The real Forgejo shadow lifecycle passed on the Linux host, but the same bounded controller had not yet executed after switch_root under the root Guanghu supervisor.
|
||||
emergence:
|
||||
- The portable lifecycle controller and loopback repository service were added to the read-only cross-root fixture.
|
||||
- Attempt 1 reached the root supervisor but BusyBox wget 1.30.1 crashed because its unsupported -T option was used; no pass receipt was accepted.
|
||||
- The readback was changed to BusyBox timeout wrapping supported wget arguments.
|
||||
- Attempt 2 completed service wake, readback, verification, and reclaim, then failed when the read-only root rejected the final receipt write; no pass receipt was accepted.
|
||||
- A 1 MiB volatile receipt plane was mounted at /guanghu/receipts while the root image remained read-only.
|
||||
- Attempt 3 completed cross-root supervision, bounded repository readback, final DORMANT verification, and QEMU poweroff.
|
||||
lock:
|
||||
- GUANGHU_FIRST_BOOT_SUPERVISOR_ACTIVE
|
||||
- GUANGHU_SWITCH_ROOT_INIT_ACTIVE
|
||||
- GUANGHU_ROOT_SUPERVISOR_ACTIVE
|
||||
- GUANGHU_CROSS_ROOT_PERSISTENCE_VERIFIED
|
||||
- GUANGHU_REPOSITORY_BRIDGE_LIFECYCLE_PASS_100 request=REQ-QEMU-CROSS-ROOT-001 final=DORMANT
|
||||
- GUANGHU_CROSS_ROOT_REPOSITORY_SERVICE_EQUIVALENCE_VERIFIED request=REQ-QEMU-CROSS-ROOT-001 final=DORMANT
|
||||
why: The real Forgejo proof establishes that the Linux repository implementation can obey the bounded lifecycle, while this proof establishes that Guanghu retains the same lifecycle authority after switch_root. Neither proof alone is sufficient.
|
||||
rejected:
|
||||
- Counting either failed attempt as partial completion.
|
||||
- Making the root image writable merely to obtain a receipt.
|
||||
- Sharing the live Forgejo data path or attaching the physical JD disk.
|
||||
- Treating a one-capability loopback service as full Forgejo, physical boot, or complete Linux on-demand subcontrol.
|
||||
accepted_run:
|
||||
attempt: 3
|
||||
qemu_exit: 0
|
||||
qemu_boot_id: 25ec94fe-5032-4dbd-a6aa-8dbe76cd4807
|
||||
request_id: REQ-QEMU-CROSS-ROOT-001
|
||||
capability: repository-main-readback
|
||||
observed_main: b7925420ff161301704800c98e2b15bea2a01c40
|
||||
initial_state: DORMANT
|
||||
active_state: READY
|
||||
final_state: DORMANT
|
||||
live_readback:
|
||||
physical_boot_id_before_and_after: 68d4a3c9-c866-4f4a-be2e-0aa5f41a61b1
|
||||
repository_service: active
|
||||
repository_pid_before_and_after: 760
|
||||
public_code_http: 200
|
||||
public_repository_http: 200
|
||||
public_main: b7925420ff161301704800c98e2b15bea2a01c40
|
||||
host_port_39301_after: ABSENT
|
||||
residual_qemu_processes: 0
|
||||
physical_boot_files_changed: false
|
||||
physical_reboot_performed: false
|
||||
claims:
|
||||
jd_host_qemu_cross_root_repository_service_equivalence: 100
|
||||
combined_bounded_repository_bridge_control_model: 100
|
||||
physical_guanghu_first_boot: 0
|
||||
linux_on_demand_subcontrol: 0
|
||||
final_guanghu_os_master: 0
|
||||
next_gate: Build and QEMU-verify a one-time physical-boot candidate that includes bounded repository control and automatic return to the preserved Linux rescue entry before any real reboot.
|
||||
sources:
|
||||
- /guanghu/recovery/JD-FD-PRIMARY-cross-root-repository-qemu-0759625/WORKORDER.hldp
|
||||
- /guanghu/recovery/JD-FD-PRIMARY-cross-root-repository-qemu-0759625/qemu-cross-root-repository-attempt-3.serial.log
|
||||
- /guanghu/recovery/JD-FD-PRIMARY-cross-root-repository-qemu-0759625/qemu-cross-root-repository.serial.log
|
||||
- /guanghu/recovery/JD-FD-PRIMARY-cross-root-repository-qemu-0759625/qemu-cross-root-repository-attempt-2.serial.log
|
||||
- ADR-0182
|
||||
Loading…
Reference in a new issue