Skip to content

The clock's, the boot check's and the integrity and installer suites' comments are shorter, with their reasons kept - #248

Merged
DevomB merged 1 commit into
mainfrom
comments-update-boot
Oct 7, 2026
Merged

DevomB merged 1 commit into
mainfrom
comments-update-boot

Conversation

@DevomB

@DevomB DevomB commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Part of the cleanup-held redo, after #241-#244, #246 and #247: the files that my merged batch (#231, #234, #236, #238) had held. Comments only in compartments/kryptikd/src/time.rs, build/recipes/boot-check.sh, tools/image/integrity-test.sh and tools/tests/installer.sh, and one sentence of prose in docs/design/time.md.

How it was done. The same procedure as #242. Cleanup-held's change was merged onto main, and only regions where every changed line is a comment or blank were kept; code, messages and conflicts went back to main. Each kept cut was then read by hand. Stripping comments from main's version and this one gives the same code in all four files, and bash -n passes on the shell ones. integrity-test.sh's --help prints lines 2-22, and those lines are unchanged.

Changed from the cut, to keep a reason it dropped: time.rs's module doc keeps why the time is a claim: only zone 0 sets the clock, and it has no network. As in the cut, decide's purity moves onto decide. boot-check.sh loses the stage 04 recipe header, as services.sh did in #241.

Kept from main, because the cut is stale or loses what a reader needs:

  • time.rs: Knowledge::floor is the build date or a later release this machine has committed to. The cut said the build date only, and it conflicted on floor_of_this_system for the same reason.
  • integrity-test.sh: the header is the suite's --help, so it keeps its charter. Step 5's introduction keeps its pointer to sysinit.sh's trust boundary. The attacker's payload keeps why it is signed: valid against the planted anchor, not against the image's.
  • boot-check.sh: the regulatory database is compressed like all of /lib/firmware, which is why the check names regulatory.db.zst.
  • update-esp.sh: the cut lost that flock is the real one and that rollback refuses a slot being written, so the file is unchanged.

Dropped from the cut:

  • time/tests.rs renames a test, which is code.
  • docs/design/time.md's "Open points" says the committed release's date "is not used yet", but main now uses it.
  • installer.sh: the cut removes the harness self-check and the unused note helper, and rewords a failure message. Those are code and messages.
  • integrity-test.sh: the cut removes the --commit-slot repair check and changes sbattach's error handling, both code.

How the run proves it. CI's compartment layer builds and tests kryptikd, and shell lint and the fixture step cover the shell files. Nothing else changes.

… comments are shorter, with their reasons kept: cleanup-held's cut of time.rs, docs/design/time.md, boot-check.sh, integrity-test.sh and tests/installer.sh, redone on main by hand, comments only

Only comment regions are taken from 65a6fbb. Main's text stays wherever the
cut would drop what main now relies on: the floor may be a later committed
release; integrity-test.sh's header is its --help text, step 5 points at
sysinit.sh's trust boundary and says why the attacker's payload is signed; the
regulatory database is compressed like all of /lib/firmware. time.rs's module
doc keeps why the time is a claim: only zone 0 sets the clock, and it has no
network.
@DevomB
DevomB merged commit 488c091 into main Oct 7, 2026
11 checks passed
@DevomB
DevomB deleted the comments-update-boot branch October 7, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant