Files
felhom.eu/documentation/audits/kernel-lane-2026-10-07/A/redproof.txt
T
admin ab3b7ea2f4
gates / gates (push) Successful in 2m47s
hub v0.143.0 (code): the kernel lane — the day-before household mail, the night instruction, the operator's kernel set (R-836, decision 172)
KernelDue / KernelNotify (09-20 h Budapest, one per 20 h, max 3, registered
address, only an accepted mail counts) / os_update.kernel {kver, tonight}
(no mail, no step) / layer kernel ingest + operator events / Approve kernel
set after every ring-0 box booted it healthily after a night stage / two
System page cells. 11 §5.11 written; §5.10 status corrected (proven).
Installer uninstall knows the two GRUB generators (unreleased).
Evidence: audits/kernel-lane-2026-10-07/ (red-proofs, boot timing).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-07 15:34:14 +02:00

19 lines
2.1 KiB
Plaintext

# kernel lane red-proof 2026-10-07T13:08:35Z — each mutation must turn its test red (FAILED); the clean tree is green
clean: OK
no default pin before the install -> test_installing_a_kernel_does_not_change_the_grub_default: FAILED (failures=1)
no boot-setup check -> test_a_box_without_the_esp_flag_is_refused: FAILED (failures=1)
reboot without the flag check -> test_a_reboot_without_the_flag_is_refused: FAILED (failures=1)
no signed-set image check -> test_a_kernel_outside_the_approved_set_is_refused: FAILED (failures=1) (re-run after the test was sharpened: the first run stayed green because a second image was ALSO refused by the one-kernel rule)
no expect_kver check -> test_a_kernel_outside_the_approved_set_is_refused: FAILED (failures=1)
snippet sets the default before clearing the flag -> test_the_snippet_clears_the_flag_on_use: FAILED (errors=1)
no crash-guard check -> test_the_crash_guard_must_be_armed_and_quiet: FAILED (failures=1)
self-revert used twice -> test_one_self_revert_then_never_again: FAILED (failures=1)
guard trips one unclean boot early (LIMIT-2) -> KernelStepCannotLeaveTheBoxOff.test_planned_reboot_one_crash_one_self_revert: FAILED (failures=1)
go: kernelDue ignores Tonight -> TestKernel_NoMailNoStep: --- FAIL: TestKernel_NoMailNoStep (0.00s) FAIL
go: KernelVerdict ignores the hub -> TestKernelVerdict: --- FAIL: TestKernelVerdict (0.00s) FAIL
go: no self-revert call -> TestKernelAfterBoot_UnhealthyRevertsOnceAfterTheWait: --- FAIL: TestKernelAfterBoot_UnhealthyRevertsOnceAfterTheWait (0.00s) FAIL
hub: tonight without a mail -> TestKernel_DueButNotToldIsNotTonight: --- FAIL: TestKernel_DueButNotToldIsNotTonight (0.04s)
hub: a failed mail still recorded -> TestKernel_NoMailNoStep: --- FAIL: TestKernel_NoMailNoStep (0.04s)
hub: approval without a night stage -> TestKernel_ApproveNeedsEveryRing0BoxHealthyAfterANightStep: --- FAIL: TestKernel_ApproveNeedsEveryRing0BoxHealthyAfterANightStep (0.03s)
hub: kernel button without its readiness gate (.Fingerprint and Waiting dropped) -> TestSystemPage_KernelButtonOnlyWhenReady: --- FAIL: TestSystemPage_KernelButtonOnlyWhenReady (0.04s)