Findings only — no script, profile or build file changed; no ISO built, nothing published.
documentation/audits/SPIKE-universal-iso-2026-07-31.md
- R-139 (HIGH): a disk filter matching >1 device does NOT fail safe. Observed in a nested VM —
the installer silently picked one of two matching disks and wiped it; validate-answer accepts
such an answer. The 'filter did not match any devices' guard covers the ZERO-match case only.
- No udev property distinguishes an internal system disk from external media. Measured on
demo-felhom with its 1TB external attached: ID_BUS='ata' for BOTH, lsblk RM=0 for both, and
device-info exposes no removability property. demo-hp's NVMe carries no ID_BUS/ID_TYPE at all.
- R-141 (HIGH): the answer schema makes a root credential mandatory, but root-password-hashed='*'
validates AND installs to completion. [first-boot].ordering accepts 'before-network', the only
ordering that closes the exposure window structurally.
- Q3: prepare-iso leaves grub.cfg byte-identical to stock (15 entries, automated AND interactive)
— a two-entry menu is purely a Felhom grub.cfg.tmpl change.
- R-129 resolved: demo-hp's key is the operator's own, added post-install; demo-felhom's IS baked
by an uncommitted profile.
The reachable-before-rotation measurement FAILED twice and is recorded as failed, not inferred.
Opens R-139..R-147; restates R-128.