update docs

This commit is contained in:
2026-09-22 13:23:34 +08:00
parent 99bc3d15c5
commit 8a4788fca8
126 changed files with 7198 additions and 2425 deletions
+122
View File
@@ -0,0 +1,122 @@
# M8 desktop and network validation
Development reference and historical context. For current operating instructions, use the [user manual](../README.md). Acceptance applies only to the source and artifacts identified in each record.
[Usage guide](desktop.md) · [Implementation ledger](implementation-status.md)
M8 software acceptance passed on 2026-09-21, including corrected CLI and
development images and the complete M0–M7 regression suite. These results concern
actual ARM software under QEMU, not a physical Raspberry Pi or E-Ink display.
## Functional acceptance
`make rootfs PROFILE=development`, `make desktop-test`, `make rootfs-test`, and
`make system-card PROFILE=development` passed. Evidence is retained in
`out/m8-vm.kf5ohhq8/` and `out/logs/m8-verified-*.log`.
The test verified:
- No X server, WindowMaker, or DHCP client runs by default.
- The ordinary FDS user can request and stop the graphical session.
- X11 requires its authority cookie; a client without the cookie is rejected.
- WindowMaker manages a real xterm, and injected X11 keyboard input executes a
command inside that terminal as the ordinary user.
- The screenshot shows the shipped grayscale controls, Terminus font, white
background, and FDS terminal prompt. It is `desktop.png` in the evidence folder.
- No user font cache is generated when the session starts. Image construction
normalizes directory timestamps before generating the packaged cache.
- Stopping the desktop leaves no Xvfb, WindowMaker, or xterm process; Dasung
remains running. Starting a second session succeeds without a reboot.
- Each activation gets its own request/readiness times. The boot report retains
the first desktop-ready event instead of replacing it on restart.
- A recognized ENVIRONMENT cartridge starts the desktop. Safe eject and surprise
removal stop it. Manual deactivation remains effective while media is inserted;
removal/reinsertion permits automatic activation again. Unknown profiles do not
start a session.
- A PROGRAM cartridge initially disallows execution and never autoruns. Explicit
launch runs as UID 1000 with the application/library paths set. A symlink
escaping `app` and a path traversal name are rejected. Eject stops managed
consumers before unmounting and reporting SAFE.
- A virtual USB Ethernet adapter activates DHCP and receives a real virtual
lease. DHCP-provided DNS reaches the volatile resolver file. Explicit network
off stops the client and leaves the managed interfaces administratively down;
restarting networking obtains an address again.
- With Ethernet present but no DHCP server, the console and service controls
remain usable. DHCP readiness is never a lease wait.
The measured first activation was **1048.946380 ms** from request to WindowMaker
readiness in this software-emulated VM. This is a measurement of this run, not a
Pi performance claim. `activation.json` contains the raw CLOCK_BOOTTIME values.
## Retained development artifacts
| Artifact | Location | SHA-256 |
| --- | --- | --- |
| Development rootfs, 499210240 bytes | `out/rootfs-build.eTfJu2/rootfs-aarch64.tar` | `d3ee3b622c2ce9c34783a72a6b40d6a29b624768ac978b6db840347e32ea46c0` |
| Development SYSTEM GPT/EROFS | `out/system-build.p61o8p_o/system.img` | `e7c5c2e716260969eacbab3cd3b0a6bae16005826de1a90f0c325f3f60125855` |
The rootfs audit counted 191 packages and 1402 AArch64 ELF files. Its package
archives, signatures, versions, scripts, ownership, and hashes are retained
beside the rootfs. The graphical test uses a disposable root-console fixture with
Xvfb; the normal image still selects Xorg and the ordinary-user console.
## Regression acceptance
The corrected CLI rootfs contains 180 packages and 1390 AArch64 ELF files.
`make tooling-test`, `make check`, `make rootfs-test`, `make init-test`,
`make boot-test`, `make console-test`, `make cartridge-test`, and `make data-test`
all passed. Bootstrap and smoke-test also passed after the namespace-wrapper
change; their logs are `out/logs/m8-final-bootstrap.log` and
`out/logs/m8-final-smoke.log`.
| Artifact | Location | SHA-256 |
| --- | --- | --- |
| CLI rootfs, 495953920 bytes | `out/rootfs-build.0ayTj2/rootfs-aarch64.tar` | `1b82905789d00ba78f4474ad8613303c1d5684ba7f5f55a30cdde785a35cae06` |
| CLI SYSTEM | `out/system-build.jjgm8xox/system.img` | `be530d8076fffe1ca0de7951952e1bcec763bf6e811d068e40f75961ca3e46e1` |
| FAT32 boot partition | `out/boot-build.newd2icx/boot.fat` | `518deb1b8bee9f013d60c4cd22bea4380357e001db558a74026e2511da2c50a0` |
The boot matrix is in `out/m4-vm.TPiKHf/`, console checks in
`out/m5-vm.f9612amj/`, cartridge checks in `out/m6-vm.cnvl_fxp/`, and sustained
DATA writes plus independent filesystem checks in `out/m7-vm.rko_14_q/`.
The corrected archive and booted guest both verify the terminal-accounting
helper's `root:utmp` ownership, and the guest verifies loopback is up.
The normal kernel-to-console observation was 1854.724813 ms, compared with
1769.584786 ms in `out/m5-vm.6_55lhge/`: **+85.140027 ms**. The actual static ARM
`fds-boottrace compare` passed without a regression exception; output is in
`out/logs/m8-verified-boot-comparison.log`. This single software-emulated comparison
is below the 100 ms review threshold and does not establish Pi performance.
## Test corrections and build findings
The original `xprop -spy` approach could miss readiness when the EWMH atom was
created during startup. The final static helper speaks the small required part
of X11 directly: it installs its event subscription before starting WindowMaker,
then observes the supporting-window property. It adds no external Rust crate or
Xlib dependency to the FDS executable.
Terminus needed its supplied fontconfig acceptance rule enabled. Font caches
also needed the same normalized timestamp as the exported archive; otherwise
image creation invalidated directory timestamps and caused a user cache rebuild.
The final VM test checks the resulting behavior.
QEMU's restricted user network omitted DNS from its DHCP offer. The test now
runs QEMU in a separate network namespace and uses its normal virtual DHCP/DNS
backend there. That namespace has no host or Internet route. QEMU diagnostics
are saved separately from guest serial output, so emulator messages cannot be
mistaken for a CLI JSON response. No workstation network interface, physical
USB device, or physical block device is passed to the guest.
## Deferred acceptance
Pi DRM/VC4 output, virtual-terminal switching on the physical machine, monitor
resolution and E-Ink legibility/refresh quality, physical keyboard/pointer input,
and real CLI-to-desktop latency remain untested. The base Dasung daemon is still
mandatory and independent of optional services. Its physical recovery behavior
remains subject to the [Dasung hardware procedure](dasung.md).
The development profile currently adds X11 diagnostics. The broader development
toolchain, independent recovery, image signing, complete offline input lock, and
release packaging remain part of M12. Full shutdown ordering and broader fault
injection remain M10/M11 work.