Conversation
chrysh
force-pushed
the
rewalk-after-update
branch
from
September 28, 2026 08:07
67f32c5 to
97ba652
Compare
This was referenced Sep 30, 2026
chrysh
force-pushed
the
rewalk-after-update
branch
from
September 30, 2026 16:21
97ba652 to
c3a51b0
Compare
This was referenced Oct 2, 2026
chrysh
force-pushed
the
rewalk-after-update
branch
from
October 5, 2026 08:52
c3a51b0 to
03c4797
Compare
chrysh
force-pushed
the
ocp-global-demo-wip
branch
from
October 5, 2026 08:53
21be398 to
79ddd63
Compare
Activation only proposes the image. The device keeps running the old one until it is reset, so the machine now enters PreSupervision instead of returning to Ready: that entry quiesces every live component and verifies each image at rest before releasing it, which is the reset that boots the candidate. It also fixes a stale floor commit. CommitSvnFloor advances to verified_svn, which only the walk's VerifyFirmware records. Without the re-walk a BootConfirmed after an update committed the floor to the previous image's SVN, leaving the downgrade window the floor exists to close. The walk re-verifies the new image first, so the commit takes its SVN. The commit window now spans that walk, so every state it passes through has to answer CommitTimeout. PreSupervision is unsupervised and had no arm, and the supervising handler had none either, so a watchdog fire during the walk was dropped and never came again: commit-or-lock went unenforced for the length of a boot. Both arms added. The image is judged twice, by the pumped verifier before activation and by the walk after the reset. That is the point: the second one covers code at rest, in the slot the device actually booted. The effect bound still holds: this dispatch emits ActivateUpdate plus N quiesce asserts plus the entry's two walk effects, N+3 against the E >= 2N+2 the buffer is sized for. The documented bound came from the gate cascade, which is the larger path. Assisted-by: Claude
chrysh
force-pushed
the
rewalk-after-update
branch
from
October 5, 2026 09:03
03c4797 to
6a27e42
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebased onto
ocp-global-demo-wip. One commit, no stack note: #511 and the arm->start rename merged, and #512 (slot re-sync) is independent of this one.This was a port, not a replay. The old
sm/src/lib.rsmonolith is now split intomodel/sink/status/rot, so the state-machine changes moved torot.rs, andEvent::UpdateVerifiedlost its component id whileEvent::UpdateRequestgained one.Activation only proposes the image. The device keeps running the old one until it is reset, so the machine enters
PreSupervisioninstead of returning toReady: that entry quiesces every live component and verifies each image at rest before releasing it, and the release is the reset that boots the candidate.It also fixes a stale floor commit.
CommitSvnFlooradvances toverified_svn, which only the walk'sVerifyFirmwarerecords. Without the re-walk aBootConfirmedafter an update committed the floor to the previous image's SVN, leaving open the downgrade window the floor exists to close.The commit window now spans that walk, so every state it passes through has to answer
CommitTimeout.PreSupervisionis unsupervised and had no arm, and the supervising handler had none either, so a watchdog fire during the walk was dropped and never came again.Four existing tests needed the walk-completing
VerificationPassedbefore theirBootConfirmed, includinga_sibling_boot_confirmed_does_not_consume_the_window, which postdates the original branch.Open, and the reason this is still a draft: the walk re-verifies and reboots every component, not only the one that was updated. The neighbours are reset into byte-identical firmware. Scoping it to the updated component (plus whatever the chain says falls with it) is the next step, and it is not in this commit.