From 40281b57a5e80bbe699ae50d8927e629d09d05ad Mon Sep 17 00:00:00 2001 From: dh Date: Sat, 3 Oct 2026 18:58:10 +0200 Subject: [PATCH] Isolate measured UID watchdog failure in the native TCG diagnostic --- docs/macos-native-diagnostic.md | 4 +++- tools/ci/macos-native-readiness.sh | 8 ++++++-- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/docs/macos-native-diagnostic.md b/docs/macos-native-diagnostic.md index 88c72eb..de03757 100644 --- a/docs/macos-native-diagnostic.md +++ b/docs/macos-native-diagnostic.md @@ -20,7 +20,7 @@ Dependencies are the existing Linux/x64 runner, .NET 10 SDK, Git, Bash and Docke The helper clones Dockur commit `16a5b470cdd601bae8b05b02d748d7edfb36c12e`, verifies its exact Recovery patcher hash, and makes three narrowly verified source edits. The early `rc.cdrom.sh` hook only mounts the existing state share and returns. A same-length XML replacement makes the existing `com.apple.recoveryosd` LaunchDaemon execute `/bin/bash /Volumes/installstate/launch.sh` after boot tasks. The staged `launch.sh` is replaced entirely by the checked-in read-only readiness probe. All replacement counts are exact; an upstream mismatch fails. The two imported QEMU image digests are pinned and the final image/source/Recovery hashes are retained. Other upstream Dockerfile downloads are observed through the resulting image identity rather than asserted to be immutable. -The VM uses TCG (`KVM=N`), slirp networking, a 4-GiB guest, two virtual CPUs and a sparse 64-GiB data disk. Its container has a 6-GiB memory/swap ceiling and a two-CPU limit. The existing Docker daemon must report at least two CPUs and 6 GiB total memory, the runner must have at least 5 GiB available memory, and the Docker filesystem must have at least 8 GiB free before Recovery downloads or boot. Its own native commands retain 45-second watchdogs and a ten-minute readiness phase; the host orchestrator has a 40-minute deadline and the workflow a 45-minute limit. +The VM uses TCG (`KVM=N`), slirp networking, a 4-GiB guest, two virtual CPUs and a sparse 64-GiB data disk. Its container has a 6-GiB memory/swap ceiling and a two-CPU limit. The existing Docker daemon must report at least two CPUs and 6 GiB total memory, the runner must have at least 5 GiB available memory, and the Docker filesystem must have at least 8 GiB free before Recovery downloads or boot. Native commands have 45-second watchdogs, except the single UID gate's targeted 180-second timing experiment. The ten-minute disk-readiness phase, 40-minute host deadline and 45-minute workflow limit remain unchanged. Actual remote run 4155 stopped at the first `sw_vers` with exit 143. Run 4159 then proved native Darwin/x86_64, root identity and guest AVX2, but reached the host deadline before `sw_vers` or the service/disk gates. Its logged command durations included timer cleanup and output copying, so they did not isolate native execution time. @@ -28,6 +28,8 @@ The next probe runs mandatory architecture, root identity and platform gates bef After an initial platform failure the hook collects native launchd context and repeats the identical `sw_vers` command once, with the same 45-second limit. Native product version and all original identity/service/disk gates remain required. Optional process and CPU diagnostics run only after a gate fails. The upstream AVX2 warning reads host flags; run 4159 observed AVX2 in the actual guest. No host or guest CPU settings change. +Actual run 4161 separated native wait from timer cleanup: architecture passed after 39 seconds, but the UID gate was terminated by its 45-second watchdog (51-second fork/exec/wait duration). Native ps commands passed after 34-42 seconds; output flushes took 289 and 76 seconds. The next diagnostic changes only the UID gate's watchdog to 180 seconds while retaining exit-zero/exact-root checks. This tests whether the measured short limit caused that failure; it does not establish a guest startup or service cause, and it does not qualify native CI. The earlier local 16-case harness qualified the previous 45-second timer/cancellation/output behavior, not this new timing experiment or the actual emulated guest. + ## Evidence and cleanup Evidence is written under the requested output directory: run identity and candidate commit, Docker/runner resources, exact source patch artifacts and hashes, image/container inspection, Recovery hash, native platform/process/launchctl/diskutil logs, machine-readable guest result, outcome and cleanup receipt. The workflow retains these as a seven-day artifact. Phase names and up to 512 KiB of the final native proof also appear in CI stdout, on success or failure, with the run token replaced; no environment or credential dump is printed. A Docker start/build exit zero is not a successful native result. A missing, stale, unsupported-platform, read-only or wrong-size guest receipt fails. diff --git a/tools/ci/macos-native-readiness.sh b/tools/ci/macos-native-readiness.sh index 91bf3bb..db8ff48 100644 --- a/tools/ci/macos-native-readiness.sh +++ b/tools/ci/macos-native-readiness.sh @@ -112,7 +112,10 @@ cancel_probe() { run_command() { local name="$1" shift - local process timer exit_code started waited + local process timer exit_code started waited command_limit=45 + # Run 4161: even native uname/ps startup took 34-42s under TCG. + # Isolate only the failed UID gate; every other watchdog remains unchanged. + [[ "$name" != uid ]] || command_limit=180 LAST_OUTPUT="/tmp/native-diagnostic-$name.out" printf '\n[proof-command] %s:' "$name" >&3 printf ' %s' "$@" >&3 @@ -122,9 +125,10 @@ run_command() { process=$! ACTIVE_COMMAND="$process" printf '[proof-start] %s child=%s shell=%s parent=%s seconds=%s\n' "$name" "$process" "$$" "$PPID" "$started" >&3 + printf '[proof-limit] %s %ss\n' "$name" "$command_limit" >&3 ( trap 'exit 0' TERM INT - IFS= read -r -t 45 -u 9 unused || : + IFS= read -r -t "$command_limit" -u 9 unused || : printf '[proof-timeout] %s child=%s elapsed=%ss signal=TERM\n' "$name" "$process" "$((SECONDS - started))" >&3 kill -TERM "$process" 2>/dev/null || : IFS= read -r -t 2 -u 9 unused || :