Skip to content

fix(build): reject stale guest kernel bundles - #31

Merged
toksdotdev merged 3 commits into
krunfwfrom
toks/validate-kernel-bundle
Oct 2, 2026
Merged

toksdotdev merged 3 commits into
krunfwfrom
toks/validate-kernel-bundle

Conversation

@toksdotdev

@toksdotdev toksdotdev commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

rebuild stale kernel bundles on macOS and reject them before Windows linking, including -SkipKernelBundle. fixes the review finding in #30.

tested: regression checks fail before the fix and pass after it; real firmware kernel bytes are unchanged.

RetriggerConfidence Score: 5/5

The PR appears safe to merge; the cached Windows DLL no longer relinks just to check its bundle.

What we checked:

  • Cached DLL skips the check: Yes. The DLL depends on kernel.c, whose phony, order-only check runs without forcing a relink.

Reviews (2) · Last reviewed commit: "fix(build): bound memory used by kernel ..."

Record the version from the input kernel banner in generated bundles. Rebuild stale or unversioned bundles on macOS and reject them before Windows linking, including SkipKernelBundle and native make builds. Force relinking when a stale cached library has a newer timestamp.

Exercise the actual make and PowerShell packaging entry points. The regression checks fail on the previous revision and pass with the guard.
Comment thread Makefile Outdated
Run validation as an order-only prerequisite so checking an unchanged bundle does not invalidate an existing library.
Scan the version banner in chunks with overlap instead of reading the entire kernel image before conversion.
@toksdotdev
toksdotdev merged commit 21f169f into krunfw Oct 2, 2026
10 checks passed
toksdotdev added a commit to superradcompany/microsandbox that referenced this pull request Oct 2, 2026
bump libkrunfw for Linux 6.12.111 and stale kernel bundle protection
(superradcompany/libkrunfw#30, superradcompany/libkrunfw#31). add the
matching CI checksum.

tested: six kernel builds, bundle regression checks, and macOS runtime
smoke checks. cold boot to use the new kernel; full snapshots retain
their original kernel.


<!-- greptile_comment -->

<!-- greptile_summary -->

<h2><a
href="https://app.greptile.com/api/retrigger?id=73422717"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/RetriggerDark.svg?v=2"><source
media="(prefers-color-scheme: light)"
srcset="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"><img
alt="Retrigger"
src="https://greptile-static-assets.s3.amazonaws.com/badges/Retrigger.svg?v=2"
align="right"></picture></a>Confidence Score: 5/5</h2>

<!-- greptile-risk -->

No blocking issue was established, so the PR appears safe to merge.

<!-- greptile_confidence_score:5 -->

<sub>Reviews (2) · Last reviewed commit: ["fix(runtime): include stale
kernel
bundl..."](https://github.com/superradcompany/microsandbox/commit/9608965686e432eb859d3ac8a1d197ddcf9ca691)</sub>

<!-- /greptile_comment -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant