diff --git a/scripts/iso/profiles/hp.profile b/scripts/iso/profiles/hp.profile new file mode 100644 index 0000000..22091ba --- /dev/null +++ b/scripts/iso/profiles/hp.profile @@ -0,0 +1,43 @@ +# Felhom ISO build profile — HP mini (second pilot board, 2026-07-21). +# +# Same shape as profiles/n100.profile, with ONE deliberate difference: the loader default is left at +# the stock signed `shim` chain rather than `mkimage`. +# +# WHY: `mkimage` exists to work around the N100's early AMI (AN3PLUS-class) firmware, which cannot +# USB-boot the ISO's stock signed GRUB (VALIDATION-n100-baremetal F1, `relocation 0x0`). That is a +# defect of that firmware, not a Felhom requirement. HP business-desktop firmware is Secure-Boot +# capable and generally standards-compliant, so `shim` is the one to try FIRST — it keeps Secure +# Boot working, which `mkimage` cannot (it is unsigned; an SB-enforcing board refuses it outright +# with "Access Denied" — proven, RUNBOOK-B leg 3). +# +# The board's firmware is nevertheless UNKNOWN until it is in hand, so BOTH loader variants are +# built from this one profile — the AMI lesson is to carry both rather than make one trip: +# bash scripts/iso/build-felhom-iso.sh … --profile scripts/iso/profiles/hp.profile --pairing --loader shim +# bash scripts/iso/build-felhom-iso.sh … --profile scripts/iso/profiles/hp.profile --pairing --loader mkimage +# +# ⚠ THIS PROFILE IS DELIBERATELY INERT — it ships the MATCH-NOTHING disk filter as a safety default, +# exactly like n100.profile. Built as-is it is the `hp-safety` pre-flight ISO: it boots the full +# installer path and then ABORTS having touched no disk (spike S5c). That is the point — the first +# thing a brand-new board ever runs should be provably harmless, and it proves the loader + Secure +# Boot setting before anything destructive exists on a USB stick. +# +# To ARM it for the real install, do NOT edit this file: copy it to an UNCOMMITTED working profile +# (the n100-demo.profile precedent — a real serial and any baked key must never be committed), +# replace the serial below with the target SSD's real ID_SERIAL_SHORT harvested from the board +# pre-wipe (`lsblk -o NAME,SERIAL` / `udevadm info`), and rebuild. Confirm the serial is the +# INTERNAL SSD and not an attached backup drive — that check is what protected the N100's external +# HDD on the rehearsal run. + +FELHOM_FQDN="felhom-host.local" + +# Loader: stock signed shim (Secure Boot stays ON). Override per-build with `--loader mkimage` if the +# board turns out to have the N100's GRUB relocation defect — and set Secure Boot OFF if you do. + +FELHOM_DISK_SETUP='[disk-setup] +filesystem = "ext4" +filter-match = "all" +filter.ID_SERIAL_SHORT = "REPLACE-WITH-TARGET-SSD-SERIAL"' + +# Optional emergency/validation key baked into root's authorized_keys (blank -> not baked). +# Leave blank here; bake it only in the uncommitted armed profile if durable break-glass is wanted: +# FELHOM_ROOT_SSH_KEY="ssh-ed25519 AAAA... ops@felhom"