d03ab7f1f5
gates / gates (push) Successful in 44s
Wrapper layer kernel (stage / reboot / boot / good / revert / cancel / status; R20-R23), the two GRUB generators in the bundle (option C on the one-shot entry), the agent's night step and after-boot judge (host health rule + hub reached, 20 min measured), the signed os_kernel_step (stage only). Red-proofs: felhom.eu audits/kernel-lane-2026-10-07/A/redproof.txt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
37 lines
1.8 KiB
Bash
37 lines
1.8 KiB
Bash
#!/bin/sh
|
|
# /etc/grub.d/01_felhom_oneshot — the kernel lane's ONE-SHOT boot (R-836, `09` §3 decisions 164 + 172, `11` §5.11).
|
|
# Installed by the config bundle (felhom-os-apply BUNDLE_FILES), 0755 root. update-grub runs it; it prints GRUB script.
|
|
#
|
|
# At boot, GRUB reads `felhom_next` from an environment block on the ESP (vfat — GRUB can rewrite a file there; it
|
|
# cannot on the LVM /boot, R-836), CLEARS it, and — only if it names an installed kernel — boots that kernel's one-shot
|
|
# entry (42_felhom_oneshot) instead of the default. The next boot uses the default again whatever happens: a new kernel
|
|
# that panics comes back on the old one by itself. felhom-os-apply writes the flag (mode apply) and never the default
|
|
# for a new kernel. Measured on the Tester 1 VM, demo-felhom and demo-hp (Secure Boot on):
|
|
# `audits/kernel-spike-2026-10-07/` (candidate 2).
|
|
#
|
|
# No vfat ESP at /boot/efi, or no Proxmox kernel → prints nothing (the box boots exactly as before).
|
|
set -e
|
|
esp_uuid=$(findmnt -n -o UUID,FSTYPE /boot/efi 2>/dev/null | awk '$2 == "vfat" { print $1 }')
|
|
[ -n "$esp_uuid" ] || exit 0
|
|
kernels=$(ls /boot/vmlinuz-*-pve 2>/dev/null | sed 's#^/boot/vmlinuz-##' | grep -E '^[0-9]+\.[0-9]+\.[0-9]+-[0-9]+-pve$' || true)
|
|
[ -n "$kernels" ] || exit 0
|
|
cat <<EOF
|
|
# felhom kernel lane: a one-shot kernel named on the ESP, read and cleared before the menu
|
|
insmod part_gpt
|
|
insmod fat
|
|
search --no-floppy --fs-uuid --set=felhom_esp $esp_uuid
|
|
if [ -f (\$felhom_esp)/EFI/felhom/oneshot.env ]; then
|
|
load_env -f (\$felhom_esp)/EFI/felhom/oneshot.env felhom_next
|
|
if [ "\${felhom_next}" ]; then
|
|
set felhom_boot="\${felhom_next}"
|
|
set felhom_next=
|
|
save_env -f (\$felhom_esp)/EFI/felhom/oneshot.env felhom_next
|
|
EOF
|
|
for k in $kernels; do
|
|
printf ' if [ "${felhom_boot}" = "%s" ]; then set default="felhom-oneshot-%s"; fi\n' "$k" "$k"
|
|
done
|
|
cat <<EOF
|
|
fi
|
|
fi
|
|
EOF
|