Skip to content

release: notes say what changed; the report is KVM-only at 20 boots a row - #81

Merged
aledbf merged 2 commits into
mainfrom
release/notes-and-report
Oct 1, 2026
Merged

aledbf merged 2 commits into
mainfrom
release/notes-and-report

Conversation

@aledbf

@aledbf aledbf commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Three changes to how a spin-machine release is made and described.

1. The notes say what changed. Until now they said which checksums moved and which checkpoints stop resuming, but not why. hack/releasenotes (Go, with a test) reads git between the previous release and this one and writes what reached the machine:

  • the commits, grouped by the part they changed: QEMU and firmware, kernel, base image, the definition and CLI;
  • the pins in versions.yaml that moved;
  • the kernel options turned on, off or changed;
  • the patches added, changed or removed, named by their Subject, or by their commit when they are bare diffs.

Commits that did not reach the machine (tests, the lab, CI) are listed apart, collapsed. This section leads the notes, above the fingerprint verdict. Below is what it writes for v20261001.01 against v20260930.02.

2. Every qboot patch ships in the release. hack/release listed the qboot patches by name, and mtrr.patch (#75) was never added to that list. v20261001.01 shipped a qboot.bin without the GPL patch it was built with. It now copies every qemu/qboot/*.patch, so a new patch cannot be left out again.

3. The report is KVM-only, at 20 boots a row.

  • accel=tcg is gone: the TCG build is for CI runners without KVM, and timing it says nothing about a host.
  • At 3 boots a row, comparing v20261001.01 with v20260930.02 flagged every KVM row 5-11% slower. 20 boots of each release, alternated on construct, put them within 5 ms of each other.
  • The report takes about 5-8 minutes now.

Tests: task lint and task test pass. hack/releasenotes has a test over a temporary repository. With a planted bug (the kernel option comparison inverted), it fails.

What the new section writes for v20261001.01

What changed since v20260930.02

QEMU and firmware

Kernel

Base image

Kernel configuration

  • CONFIG_BPF_LSM n → y
  • CONFIG_DEVMEM y → n
  • CONFIG_DEVPORT y → n
  • CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY n → y
  • CONFIG_LSM n → "lockdown,bpf"
  • CONFIG_PROC_KCORE y → n
  • CONFIG_SECURITY n → y
  • CONFIG_SECURITYFS n → y
  • CONFIG_SECURITY_LOCKDOWN_LSM n → y
  • CONFIG_SECURITY_LOCKDOWN_LSM_EARLY n → y
  • CONFIG_SECURITY_NETWORK n → y
  • CONFIG_SECURITY_PATH n → y

Patches to upstream source

22 more, none of them in the machine: tests, the lab, CI, tooling

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

aledbf and others added 2 commits October 1, 2026 14:30
… row

The notes said which checksums moved and which checkpoints stop
resuming, not why. hack/releasenotes reads git between the previous
release and this one and writes what reached the machine: the commits
by the part they changed (QEMU and firmware, kernel, base image, the
definition and CLI), the pins that moved, the kernel options turned on,
off or changed, and the patches added, changed or removed. Commits that
did not reach the machine are listed apart, collapsed. It leads the
notes, above the fingerprint verdict.

hack/release ships every qboot patch, not a list of them: mtrr.patch
was added to the build and not to the list, and v20261001.01 shipped a
qboot.bin without the change it was built with.

The report drops accel=tcg (the TCG build is for CI runners without
KVM; timing it says nothing about a host) and boots each row 20 times:
at 3 the v20261001.01 comparison flagged every KVM row 5-11% slower,
and 20 boots of each release, alternated on construct, put them within
5 ms.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
main is run's: exit codes and an empty range are tested, a file in a
patch directory that is not a patch is left out, and the commit parser
no longer has an index that read the same at 1 and 2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aledbf
aledbf merged commit 2cd98f0 into main Oct 1, 2026
1 check passed
@aledbf
aledbf deleted the release/notes-and-report branch October 1, 2026 17:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant