validation(device): isolated FR-014 v2 candidate after second audit - #8
Draft
Zhanfg wants to merge 152 commits into
Draft
validation(device): isolated FR-014 v2 candidate after second audit#8Zhanfg wants to merge 152 commits into
Zhanfg wants to merge 152 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Second-audit physical FR-014 candidate only. Do not merge or publish as a general release.
Reviewed runtime base:
f927a2738b7b3ae4cfc4a811897a1be9bc6acbe3.Candidate head:
a056541b99cbb2b3f64b6de404bfe040ba5745a4.This v2 candidate supersedes the old
857e963...candidate for final physical evidence. The old package remains useful only as evidence for any test already in progress.Audited candidate-only diff
Relative to the reviewed runtime base, candidate PR #8 changes only:
module/FLASH_REVIEW_BLOCKED;module/FR014_DEVICE_CANDIDATEmarker containing the reviewed base identity;scripts/package_module.shso a candidate ZIP requires the marker and refuses the review blocker;CANDIDATE_V2_AUDIT.md.No patch writer, restore, transaction, service, KPM, WebUI, ABI, installer, credential, or recovery runtime code differs from the reviewed base.
Second-audit fixes already included in the reviewed base
$MODPATHcleanup; helper trees survive target-resolution/abort failures;unresolved/bootloop state;/data/adb/patchnestrescue credentials/backups/bindings instead of destroying them while boot may remain patched;kptoolsadmission;openssl pkeyutl -verify -rawinand has deployment-key positive/tamper negative tests;kpatch kpm loadpaths are centralized behindkpatch_runtime_wrapper.sh+validate_kpm_file.sh; the reviewed ARM64 CLI is preserved as provenance-boundkpatch.real;KPM_CYCLEpath.Exact v2 candidate CI
Exact candidate head
a056541b99cbb2b3f64b6de404bfe040ba5745a4:31273464054: PASS31273464107: PASSFlash safety #222 executed and passed:
Build #294 passed source/WebUI validation and the full ARM64 package job: pinned dependency hashes, Public1158 userspace rebuild, kp-safemode build, ARM64 ABI checks, WebUI build, complete module validation, release-safety assembled-package validation, deterministic double-package comparison, and artifact upload.
Exact artifact identity
GitHub Actions artifact:
9026327034patchnest-module-0.13.5-2-0.13.3sha256:bf7c972785c79553aa1eb9ee3ab0b8c16bf40319c69b79fa53895cf5ae04bb0bThe downloadable outer artifact ZIP can be server-repacked and is not the flash identity. The exact installable inner module is:
PatchNest-Module.zip1,984,705bytesa9c7edba70f9c98daf3522599f75a65e4c78254da009b976e1ed6b12b5602ce5Direct inner-ZIP inspection confirmed:
FR014_DEVICE_CANDIDATEpresent;FLASH_REVIEW_BLOCKEDabsent;..//.// backslash archive paths;fr014_gate.sh, transaction/restore helpers, physical validation/recovery tools, hardened KPM installer/verifier, direct KPM validator and runtime wrapper all present;kpatch,kptools,kp-safemode, andmagiskbootare ARM64 Android ELF files;provenance/kpatch-public1158.jsonsource commit is7fed93c4e259a6edf191c1a9900874babb232c4b;252a3fc0e1f674e78917bdfaa159e8274104e8a5a4eeda5d2c5720f939f33ee4exactly matches the packaged pre-installbin/kpatchELF.Mandatory physical FR-014 sequence
Only the inner ZIP with SHA-256
a9c7edba70f9c98daf3522599f75a65e4c78254da009b976e1ed6b12b5602ce5is accepted for final v2 evidence.device_validation.sh preflight. It must pass the clean baseline gate and create the root-only one-time receipt.export_recovery_boot.shwithPATCHNEST_DEVICE_TEST_UNLOCK=RECOVERY_EXPORT.sys.boot_completed=1.device_validation.sh postboot; requirehello1158,kpver, KPM query/list, secure committed credential, clean transaction state and live rollback eligibility.rollback-negative; foreign-device/stale-byte binding copies must fail without modifying real boot/binding.kpm-cycle; normal candidate KPM install/direct-load paths are blocked.arm_auto_recovery.sh, allow exact bound restore + reboot, then runverify_auto_recovery.sh.postrestoreand prove current boot bytes equal the restore receipt SHA/size.Only after those physical gates pass may PR #5 be marked ready and PatchNest be called truly flashable.