Skip to content

SHARD-232: package the guest kernel: a reproducible build, a release workflow, and a checksummed fetch - #176

Merged
presmihaylov merged 4 commits into
mainfrom
shard-232-guest-kernel
Sep 19, 2026
Merged

presmihaylov merged 4 commits into
mainfrom
shard-232-guest-kernel

Conversation

@presmihaylov

Copy link
Copy Markdown
Owner

Closes SHARD-232. Third of the M10 stack, stacked on #175.

Why. No distribution ships a kernel Virtualization.framework boots. shard ships its own, one per arch, and the daemon never boots bytes it cannot vouch for.

How.

  • Look first at packaging/kernel/build.sh and the Dockerfile: debian:13 by digest, always linux/amd64, fixed KBUILD_* and SOURCE_DATE_EPOCH.
  • The configs are Cloud Hypervisor's ch_defconfig at ch-6.12.8, no modules, no initrd; hypeman boots that kernel on VZ.
  • services/kernel.Ensure hashes the file on every call, so a changed file on disk never boots.
  • The kernel workflow builds twice on a PR that touches the build; a dispatch also publishes the release, and refuses a hash the Go table does not expect.
  • SHARD_KERNEL plus SHARD_KERNEL_SHA256 is the dev path, still hash-checked.

What. make kernel, services/kernel, docs/kernel.md, and kernel on the record, which SHARD-218 fills.

@presmihaylov
presmihaylov force-pushed the shard-231-hypeman-vz-take branch from 24b2c02 to 6b9616b Compare September 19, 2026 12:06
@presmihaylov
presmihaylov force-pushed the shard-231-hypeman-vz-take branch from 6b9616b to 84072fc Compare September 19, 2026 12:15
Comment thread packaging/kernel/Dockerfile Outdated
Comment thread .github/workflows/kernel.yml
Comment thread .github/workflows/kernel.yml Outdated
Comment thread services/kernel/kernel.go Outdated
@presmihaylov
presmihaylov merged commit 26cf820 into main Sep 19, 2026
6 checks passed
@presmihaylov
presmihaylov deleted the shard-232-guest-kernel branch September 24, 2026 05:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant