release: notes say what changed; the report is KVM-only at 20 boots a row - #81
Merged
Merged
Conversation
… row The notes said which checksums moved and which checkpoints stop resuming, not why. hack/releasenotes reads git between the previous release and this one and writes what reached the machine: the commits by the part they changed (QEMU and firmware, kernel, base image, the definition and CLI), the pins that moved, the kernel options turned on, off or changed, and the patches added, changed or removed. Commits that did not reach the machine are listed apart, collapsed. It leads the notes, above the fingerprint verdict. hack/release ships every qboot patch, not a list of them: mtrr.patch was added to the build and not to the list, and v20261001.01 shipped a qboot.bin without the change it was built with. The report drops accel=tcg (the TCG build is for CI runners without KVM; timing it says nothing about a host) and boots each row 20 times: at 3 the v20261001.01 comparison flagged every KVM row 5-11% slower, and 20 boots of each release, alternated on construct, put them within 5 ms. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
main is run's: exit codes and an empty range are tested, a file in a patch directory that is not a patch is left out, and the commit parser no longer has an index that read the same at 1 and 2. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three changes to how a spin-machine release is made and described.
1. The notes say what changed. Until now they said which checksums moved and which checkpoints stop resuming, but not why.
hack/releasenotes(Go, with a test) reads git between the previous release and this one and writes what reached the machine:versions.yamlthat moved;Commits that did not reach the machine (tests, the lab, CI) are listed apart, collapsed. This section leads the notes, above the fingerprint verdict. Below is what it writes for v20261001.01 against v20260930.02.
2. Every qboot patch ships in the release.
hack/releaselisted the qboot patches by name, andmtrr.patch(#75) was never added to that list. v20261001.01 shipped aqboot.binwithout the GPL patch it was built with. It now copies everyqemu/qboot/*.patch, so a new patch cannot be left out again.3. The report is KVM-only, at 20 boots a row.
accel=tcgis gone: the TCG build is for CI runners without KVM, and timing it says nothing about a host.Tests:
task lintandtask testpass.hack/releasenoteshas a test over a temporary repository. With a planted bug (the kernel option comparison inverted), it fails.What the new section writes for v20261001.01
What changed since v20260930.02
QEMU and firmware
Kernel
Base image
Kernel configuration
CONFIG_BPF_LSMn → yCONFIG_DEVMEMy → nCONFIG_DEVPORTy → nCONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITYn → yCONFIG_LSMn → "lockdown,bpf"CONFIG_PROC_KCOREy → nCONFIG_SECURITYn → yCONFIG_SECURITYFSn → yCONFIG_SECURITY_LOCKDOWN_LSMn → yCONFIG_SECURITY_LOCKDOWN_LSM_EARLYn → yCONFIG_SECURITY_NETWORKn → yCONFIG_SECURITY_PATHn → yPatches to upstream source
qemu/patches/0002-hw-virtio-blk-account-discard-operations.patch: hw/virtio-blk: Account discard operationsqemu/qboot/mtrr.patch: qboot: enable the MTRRs, write-back by default (qboot: enable the MTRRs, write-back by default #75)22 more, none of them in the machine: tests, the lab, CI, tooling
🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.