Prepare current deploy-only Xen image #18

Open
ober wants to merge 221 commits from fix/current-image-authority-20260926 into main
Owner

Builds and locks one current deploy-only Xen image for dynamic component deployment.

  • Adds explicit deploy-only Genode recipe: deployd, admin_ctl, storage, router, services init; no guest SSH, shell, baked jdns/jsmtp/jjmap, or WireGuard.
  • Makes artifacts/current/netix.img the only eligible artifact and rejects historical paths or source/config drift.
  • Fetches and hashes the generated run graph, registers the fresh Biggus candidate, and wires build/test launchers to the canonical path.
  • Seeds an empty desired registry so jdns/jsmtp/jjmap/wireguard arrive through deployd packages.

Validation:

  • Biggus build completed from current sources (15m20s image build; fresh SHA256 e7861bbe4192de517e54c550148aa33bb1b5d93dbff8c78c3f66f9866d9686c0).
  • python3 -m unittest discover -s tool/deploy -p 'test_genode_deploy.py' (26 passed).
  • python3 -m unittest discover -s tool/deploy -p 'test_current_image.py' (3 passed).
  • Ansible syntax, shell syntax, graph parsing, and diff checks pass.
  • Isolated QEMU serial boot reached deployd: listening on 0.0.0.0:4400; storage and admin_ctl/services started.
Builds and locks one current deploy-only Xen image for dynamic component deployment. - Adds explicit deploy-only Genode recipe: deployd, admin_ctl, storage, router, services init; no guest SSH, shell, baked jdns/jsmtp/jjmap, or WireGuard. - Makes `artifacts/current/netix.img` the only eligible artifact and rejects historical paths or source/config drift. - Fetches and hashes the generated run graph, registers the fresh Biggus candidate, and wires build/test launchers to the canonical path. - Seeds an empty desired registry so jdns/jsmtp/jjmap/wireguard arrive through deployd packages. Validation: - Biggus build completed from current sources (15m20s image build; fresh SHA256 e7861bbe4192de517e54c550148aa33bb1b5d93dbff8c78c3f66f9866d9686c0). - `python3 -m unittest discover -s tool/deploy -p 'test_genode_deploy.py'` (26 passed). - `python3 -m unittest discover -s tool/deploy -p 'test_current_image.py'` (3 passed). - Ansible syntax, shell syntax, graph parsing, and diff checks pass. - Isolated QEMU serial boot reached `deployd: listening on 0.0.0.0:4400`; storage and admin_ctl/services started.
ober added 112 commits 2026-09-27 01:55:46 -04:00
- lib/mk/rump_net.mk: build the vendored NetBSD 7.99.3 rump net stack
  (rumpnet core + libnet + libnetinet + libvirtif, IPv4 only) with the
  rumpns_ prefix rules; per-file -D renames for ctor symbols that
  collide with the rump core library
- src/lib/rumpnet/init.cc: explicit component ctor bootstrap
  (rump_net_bootstrap, called before rump_init) + interface
  configuration helper (SIOCIFCREATE/SIOCSIFADDR/SIOCSIFNETMASK,
  default route via PF_ROUTE RTM_ADD - SIOCADDRT does not exist in
  this NetBSD era)
- src/lib/rumpnet/virtif_genode.cc: Genode NIC bridge implementing the
  VIFHYPER_* hypercalls (Nic session, RX pump thread delivering via
  VIF_DELIVERPKT under rump_schedule/unschedule)
- src/include/rump/rump_net.h: public library interface
- opt_inet.h: drop INET6 (libnetinet6 deliberately not built)
Xen domU acceptance (netbased): DEPLOY/1 version probe, 4B-512KB
upload matrix, split-header probes, and full genode-deploy.py deploy
(generation create + activate) all pass with real FFS writes to /data.

Fixes:
- dde_rump/io.cc: dedicated rump_io entrypoint for block I/O signals;
  waiters block on registered Blockades instead of nested
  wait_and_dispatch_one_io_signal on the ep thread (lost-wakeup class)
- hard_context: Hard_context_registry::r() moved out of line into
  hypercall.cc; the inline function-local static produced one registry
  per shared library (rump.lib.so vs rump_net.lib.so), so the syscall
  worker registered in one and looked up in the other ('Hard context
  is nullptr', null-lwp crash in rumpuser_curlwp)
- patches/sync.patch: do not start the periodic sync thread; it races
  EP-thread FFS inode allocation and trips the ffs_valloc VNON
  assertion. Block sync stays driven by the io backend
- rump.inc: link random_backend.cc + format
- deployd main.cc: header overshoot buffering (_pending) - a request
  body sharing the first TCP segment with the header was lost
- template: deployd vfs builds the <fs> data session before <rumpnet>;
  constructing rumpnet after the blocking fs-session wait wedges
  user-context rump syscalls; deployd quantum 96M, rumpnet ram 32M
- defaults: genode_persistent_storage_wapbl false (WAPBL ruled out as
  wedge cause; tested state)
jdns/jsmtp/jjmap socket dirs swapped from lxip to rumpnet with static
domain IPs (10.0.53.2 / 10.0.25.2 / 10.0.84.2), data fs dir kept
before socket dir per the phase-4 construction-order rule; ssh_server
and admin_ctl's own socket dir stay on lxip (recovery path).

Real-Xen acceptance (netbased domU 10.0.0.163):
- jdns: UDP + TCP dig answered in one boot (jerboa.sh A -> 166.84.6.60)
- jsmtp: full SMTP sessions (220 banner, EHLO/NOOP) across repeated
  connections in another boot
- jjmap: TLS handshake stable across boots (CN=genode-jjmap-dev)
- deployd: unaffected, version/upload green

KNOWN ISSUES (blocking phase-5 signoff):
- per-boot startup race: one of the three service instances randomly
  fails during construction (one boot: jsmtp wedged after first rude
  close; another: jdns never bound) while siblings stay healthy; the
  admin shell's genode-service-status then hangs on the runtime RPC
- src/test/rumpnet_plugin: extended to jsmtp's blocking recv pattern,
  but under QEMU the plugin crashes during construction (sigprocmask
  libc dummy warning on the plugin ep thread before LOG is wired,
  illegal WRITE at -8, libc.lib.so log.h:174) - a separate early-
  construction fragility never hit by deployd's config shape
- ssh_server (still lxip) deterministically crashes (illegal READ
  0x406120 pthread.0) when a dynamic-terminal session runs commands
  under jerboa-service memory load; breaks the expect-based harness
ober force-pushed fix/current-image-authority-20260926 from 0878ce1df3 to 1c6702f787 2026-09-27 01:57:00 -04:00 Compare
This pull request has changes conflicting with the target branch.
  • VERSION
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/current-image-authority-20260926:fix/current-image-authority-20260926
git switch fix/current-image-authority-20260926

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff fix/current-image-authority-20260926
git switch fix/current-image-authority-20260926
git rebase main
git switch main
git merge --ff-only fix/current-image-authority-20260926
git switch fix/current-image-authority-20260926
git rebase main
git switch main
git merge --no-ff fix/current-image-authority-20260926
git switch main
git merge --squash fix/current-image-authority-20260926
git switch main
git merge --ff-only fix/current-image-authority-20260926
git switch main
git merge fix/current-image-authority-20260926
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/netix!18
No description provided.