validation(device): isolated FR-014 flash candidate - #7
Draft
Zhanfg wants to merge 97 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Isolated physical-device validation candidate for FR-014 only. Do not merge or publish as a release.
Reviewed runtime base:
9154127d3c6c2cea8828b236a7a791bfcf382b41.Candidate commit:
857e963d5c7e3a4e5a879b70231adc95326bd6bb.Audited runtime diff from reviewed base
module/FLASH_REVIEW_BLOCKEDso this one candidate can be installed for physical validation;module/FR014_DEVICE_CANDIDATEmarker containing the reviewed base identity.The only third diff is repository-side
scripts/package_module.sh: candidate packaging requires the FR-014 marker and refuses any ZIP that still contains the review blocker. It is not part of the module runtime.No boot patch, restore, service, ABI, WebUI, KPM, credential, transaction, or installer runtime implementation differs from the reviewed base.
Candidate CI
Exact candidate SHA
857e963d5c7e3a4e5a879b70231adc95326bd6bb:31245717266): PASS31245717261): PASSBuild #239 passed source/WebUI validation, pinned dependency hashes, Android ARM64 Public1158 CLI rebuild, kp-safemode build, ARM64 ABI inspection, complete module validation, deterministic double-package comparison, and artifact upload.
Flash safety #126 passed destructive fault injection, bootloop auto-rollback contract, Magisk/KernelSU/APatch installer simulation, off-device recovery export contract, ABI contract, and candidate deterministic package gate.
Exact artifact identity
GitHub artifact ID:
9018433008Artifact name:
patchnest-module-0.13.5-2-0.13.3Outer downloaded artifact SHA-256:
bfdd1aedece034330b4507ae0c220bbeb103d3b19fa10297b0f54f417170fb9aInner installable module:
PatchNest-Module.zip1,978,990bytesa252add7f7bd01c361089a5b27d28e22e1c6a52f1ddf4e1161bdeede97ffbf0eDirect artifact inspection confirmed:
FR014_DEVICE_CANDIDATEpresent;FLASH_REVIEW_BLOCKEDabsent;../or./archive paths;kpatch,kptools,kp-safemode, andmagiskbootare ARM64 Android ELF binaries;provenance/kpatch-public1158.jsonsource commit is7fed93c4e259a6edf191c1a9900874babb232c4band its binary SHA equals the packagedbin/kpatchSHA252a3fc0e1f674e78917bdfaa159e8274104e8a5a4eeda5d2c5720f939f33ee4.Mandatory physical FR-014 sequence
This exact ZIP is the only candidate allowed for the test. Do not rebuild locally or substitute another artifact.
device_validation.sh preflight; exact active slot/boot target must resolve and unpack.export_recovery_boot.shwithPATCHNEST_DEVICE_TEST_UNLOCK=RECOVERY_EXPORT.sys.boot_completed=1.device_validation.sh postboot; requirehello1158,kpver, KPM query/list, secure committed key, no pending transaction/recovery marker, and live rollback eligibility.postbootto prove persistence.device_validation.sh rollback-negative; production validator must reject foreign-device and stale-byte binding copies without changing real boot/binding.kpm-cyclewith its explicit unlock token.arm_auto_recovery.shwithPATCHNEST_DEVICE_TEST_UNLOCK=AUTO_RECOVERY, reboot, allow service to perform exact transaction-bound restore and request the second reboot, then runverify_auto_recovery.sh.device_validation.sh restorewithPATCHNEST_DEVICE_TEST_UNLOCK=RESTORE_BOUND_BACKUP, reboot, then runpostrestore.Only after all physical evidence passes may PR #5 be marked ready, the release branch remove
FLASH_REVIEW_BLOCKED, and PatchNest be described as truly flashable.