add pinned NoAVX boot kext to isolated KVM Recovery probe

This commit is contained in:
dh
2026-10-05 13:07:37 +02:00
parent 720a43158c
commit 7ea1c7f517
2 changed files with 124 additions and 15 deletions
+10 -2
View File
@@ -1,9 +1,11 @@
# macOS 13 KVM/Cryptex compatibility diagnostic
# macOS 13 KVM/Cryptex/NoAVX compatibility diagnostic
This separate manual candidate probes Recovery readiness on the existing Ubuntu Docker daemon with KVM, the real Intel host CPU and macOS 13. It does not install macOS, erase a disk, install .NET or Apple CLT, or run Meeting Assistant. Passing proves only a fresh macOS 13+ x86_64 Recovery guest with root identity, a working launchd system domain, DiskArbitration and exactly one writable 64-GiB guest disk.
Baseline: bootstrap commit `4606de069678e8f95dfe3c7dad1bf5ce5384d30c`; separate branch `codex/macos-ci-kvm-compatibility`. KVM, CPU passthrough, Recovery major version and guest Cryptex staging change together. This is a compatibility experiment, not a causal single-variable A/B test. The TCG/bootstrap experiment remains separate.
The NoAVX continuation compares against KVM Recovery commit `720a431`. Its only guest change is adding `NoAVXFSCompressionTypeZlib-AVXpel.kext` to the existing OpenCore overlay and `Kernel.Add`. Existing Lilu/CryptexFixup, CPU passthrough, macOS 13 Recovery, disk, probes and deadlines are preserved. The hypothesis is that an AVX-dependent filesystem decompression path blocks native file loading on the Celeron; this has not been established as the cause of the disk-readiness hang. Application source is unchanged, and this candidate has only offline validation evidence.
## Reasons and remaining gaps
The existing daemon's Intel Celeron 1037U lacks AVX/AVX2; a separate diagnostic proved KVM enabled/paused state and clean exit. `CPU_MODEL=host` preserves actual instruction availability rather than advertising AVX2 through emulated Skylake. This candidate refuses a TCG or CPU-model fallback.
@@ -23,7 +25,7 @@ Orchestration/validation remain the .NET 10 file-based app `tools/ci/MacOsNative
~~~sh
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --help
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --validate
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --validate --source /path/to/clean/pinned/dockur-clone --cryptex-archive /path/to/CryptexFixup-1.0.5-RELEASE.zip --output /path/to/fresh/validation
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --validate --source /path/to/clean/pinned/dockur-clone --cryptex-archive /path/to/CryptexFixup-1.0.5-RELEASE.zip --noavx-archive /path/to/NoAVXFSCompressionTypeZlib-AVXpel-v12.6.zip --output /path/to/fresh/validation
~~~
`--validate` checks result/container contracts without Docker. With `--source` it verifies the actual Cryptex ZIP/bundle, source seams, generated OpenCore configuration and staging/checksum contracts, checks Bash syntax, then exercises four raw/zlib Recovery fixtures and twelve rejection cases with independent C# CRC32 readback. It also checks preservation of a successful resource snapshot after a later failed capture, leaving the supplied source untouched. It does not download/extract the LongQT ISO, verify a complete Apple Recovery image or execute the active-Lilu runtime checks. The ISO checksum is enforced during the later Docker build; active Lilu and EFI-copy checks execute only during container boot. The optional local Cryptex ZIP must match the release size/hash; omitting it downloads only the public 69,703-byte release. Use a fresh output directory. Dependencies are .NET 10, Git, Bash and Python 3 with its standard library; manual execution also requires the existing Linux/x64 Docker daemon and its existing KVM device.
@@ -35,6 +37,8 @@ dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --run --output artifacts/
dotnet run --file tools/ci/MacOsNativeDiagnostic.cs -- --cleanup --output artifacts/native-macos
~~~
The optional `--noavx-archive` supplies the exact local upstream ZIP; omitting it downloads only the pinned 98,356-byte archive. Offline validation reads the actual generated OpenCore plist and staged executable bytes, rejects four invalid archive inputs, two missing/corrupted staging cases and five wrong `Kernel.Add` variants, then restores the valid fixture. `noavx-validation.json` records these checks. No Docker or guest is executed, and no new runner dependencies are introduced.
## Exact bootasset contract
Dockur stays pinned to `16a5b470cdd601bae8b05b02d748d7edfb36c12e`. Original Recovery patcher/staging, Dockerfile, OpenCore script and active config hashes are verified before edits. Both existing QEMU image digests remain pinned; other existing upstream downloads are observed through image identity. `source-hashes.json` includes the generated Recovery patcher, both original/replacement daemon variants and `udif_checksums.py`, staged from `tools/ci/macos-native-udif-checksums.py`. This small Python module belongs to the existing Linux UDIF runtime; C# supplies orchestration, validation fixtures and an independent CRC32 implementation.
@@ -51,6 +55,10 @@ The [original LongQT v0.7 template](https://github.com/LongQT-sea/OpenCore-ISO/r
Active `/assets/config.plist` receives exactly one enabled Cryptex immediately after enabled Lilu, preserving every other kext's order. Entry: `Arch=x86_64`, `BundlePath=CryptexFixup.kext`, `ExecutablePath=Contents/MacOS/CryptexFixup`, `PlistPath=Contents/Info.plist`, `MinKernel=22.0.0`, empty `MaxKernel`. [OpenCore Kernel.Add](https://github.com/acidanthera/OpenCorePkg/blob/1.0.7/Docs/Configuration.tex) requires dependencies first; bounds are Darwin versions. Runtime rechecks order/enabled/paths/architecture/bounds and rejects unverified `/custom.plist`.
The additional [OCLP 2.5.1 NoAVX AVXpel archive](https://raw.githubusercontent.com/dortania/OpenCore-Legacy-Patcher/f40057a5292f4804b51bcfe78d5047c7302a6434/payloads/Kexts/Misc/NoAVXFSCompressionTypeZlib-AVXpel-v12.6.zip) is pinned to commit `f40057a5292f4804b51bcfe78d5047c7302a6434`, size 98,356 and SHA256 `b5d6319d0a1f335684a92ecf23369bc3deb776be19e92b0a40860021409d20df`. The checksum is a locally verified content pin. Only its two expected bundle files are staged; ZIP resource-fork metadata is excluded. Bundle identity `com.apple.AppleFSCompression.NoAVXFSCompressionTypeZlib`, versions `1.0.0` / `132.100.2` and `OSBundleRequired=Root` are checked before copying.
NoAVX follows Cryptex in `Kernel.Add`, enabled with `Arch=x86_64`, `ExecutablePath=Contents/MacOS/NoAVXFSCompressionTypeZlib`, `PlistPath=Contents/Info.plist`, `MinKernel=22.0.0` and empty `MaxKernel`. The executable name intentionally omits `-AVXpel`. [OCLP's upstream configuration](https://github.com/dortania/OpenCore-Legacy-Patcher/blob/2.5.1/payloads/Config/config.plist#L1270) selects this 12.6-based patched binary for Ventura 13.0+, rather than the older non-AVX 12.3.1 bundle limited to Darwin 21. Both overlay files enter the existing SHA256SUMS checks before and after the guest-EFI copy. OpenCore boot injection also applies to Recovery; this is no installed-APFS-only root patch. Whether it fixes this guest's hang remains an operational question.
No new force/beta argument is needed for actual no-AVX2 CPUs. Baseline arguments remain. Validation rejects disabling arguments, `-crypt_allow_hash_validation` (disables the APFS patch) and unexpected Cryptex force/beta overrides. Manifest/profile enter the boot signature; this candidate always rebuilds `boot.img` and accepts no old cache as evidence.
## Gates, privileges and cleanup