Repository navigation
fix(build): reject stale guest kernel bundles - #31
Merged
Merged
Conversation
Record the version from the input kernel banner in generated bundles. Rebuild stale or unversioned bundles on macOS and reject them before Windows linking, including SkipKernelBundle and native make builds. Force relinking when a stale cached library has a newer timestamp. Exercise the actual make and PowerShell packaging entry points. The regression checks fail on the previous revision and pass with the guard.
Run validation as an order-only prerequisite so checking an unchanged bundle does not invalidate an existing library.
Scan the version banner in chunks with overlap instead of reading the entire kernel image before conversion.
toksdotdev
added a commit
to superradcompany/microsandbox
that referenced
this pull request
Oct 2, 2026
bump libkrunfw for Linux 6.12.111 and stale kernel bundle protection (superradcompany/libkrunfw#30, superradcompany/libkrunfw#31). add the matching CI checksum. tested: six kernel builds, bundle regression checks, and macOS runtime smoke checks. cold boot to use the new kernel; full snapshots retain their original kernel. <!-- greptile_comment --> <!-- greptile_summary --> <h2><a href="https://app.greptile.com/api/retrigger?id=73422717"><picture><source media="(prefers-color-scheme: dark)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source media="(prefers-color-scheme: light)" srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img alt="Retrigger" src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2" align="right"></picture></a>Confidence Score: 5/5</h2> <!-- greptile-risk --> No blocking issue was established, so the PR appears safe to merge. <!-- greptile_confidence_score:5 --> <sub>Reviews (2) · Last reviewed commit: ["fix(runtime): include stale kernel bundl..."](https://github.com/superradcompany/microsandbox/commit/9608965686e432eb859d3ac8a1d197ddcf9ca691)</sub> <!-- /greptile_comment -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
rebuild stale kernel bundles on macOS and reject them before Windows linking, including
-SkipKernelBundle. fixes the review finding in #30.tested: regression checks fail before the fix and pass after it; real firmware kernel bytes are unchanged.
The PR appears safe to merge; the cached Windows DLL no longer relinks just to check its bundle.
What we checked:
kernel.c, whose phony, order-only check runs without forcing a relink.Reviews (2) · Last reviewed commit: "fix(build): bound memory used by kernel ..."