From 286c399330bb7c4d87d714077c28993e130b0b0c Mon Sep 17 00:00:00 2001 From: Drake Date: Wed, 23 Sep 2026 22:20:15 -0500 Subject: [PATCH 1/2] Run QEMU boot test and verification suite in GitHub Actions CI - Add .github/workflows/ci.yml running on pull requests and pushes to main - Install QEMU AArch64 and AAVMF firmware packages on ubuntu-latest - Wire Step 6 into scripts/verify_all.sh to verify QEMU boot automatically - Closes #19 --- .github/workflows/ci.yml | 29 +++++++++++++++++++++++++++++ scripts/verify_all.sh | 9 +++++++++ 2 files changed, 38 insertions(+) create mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 00000000..20b3a1d6 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,29 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + branches: [main] + +jobs: + verify: + name: Verify and QEMU Boot Test + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Install Rust toolchain + uses: dtolnay/rust-toolchain@stable + with: + targets: aarch64-unknown-none, aarch64-unknown-uefi + components: clippy, rustfmt + + - name: Install QEMU and AAVMF firmware + run: | + sudo apt-get update + sudo apt-get install -y qemu-system-arm qemu-efi-aarch64 + + - name: Run verification harness and QEMU boot test + run: bash scripts/verify_all.sh diff --git a/scripts/verify_all.sh b/scripts/verify_all.sh index 9c3d27c9..5543da81 100755 --- a/scripts/verify_all.sh +++ b/scripts/verify_all.sh @@ -47,6 +47,15 @@ cargo run --quiet --release -p aienos-evidence -- verify-efi target/aarch64-unkn cargo build --release -p aienos-boot --target aarch64-unknown-uefi --features handoff --bin aienos-handoff cargo run --quiet --release -p aienos-evidence -- verify-efi target/aarch64-unknown-uefi/release/aienos-handoff.efi +# Step 6: QEMU AArch64 UEFI Boot Verification (Emulator Boot Test) +echo "" +echo "--- [QEMU AArch64 UEFI Boot Verification] ---" +if command -v qemu-system-aarch64 >/dev/null && [[ -r "${AAVMF_CODE:-/usr/share/AAVMF/AAVMF_CODE.no-secboot.fd}" ]]; then + ./scripts/qemu_boot_test.sh +else + echo "SKIPPED: qemu-system-aarch64 or AAVMF firmware not present on host." +fi + echo "" echo "============================================================" echo "HOST VERIFICATIONS PASSED." From a7ccba1c4fad1735d69cb6ccb545f8f308a7085f Mon Sep 17 00:00:00 2001 From: Drake Date: Wed, 23 Sep 2026 22:22:21 -0500 Subject: [PATCH 2/2] Allow dead code on non-aarch64 host architectures for exception hook --- crates/aienos-kernel/src/fatal.rs | 2 ++ 1 file changed, 2 insertions(+) diff --git a/crates/aienos-kernel/src/fatal.rs b/crates/aienos-kernel/src/fatal.rs index 0f4471b3..d6b92e27 100644 --- a/crates/aienos-kernel/src/fatal.rs +++ b/crates/aienos-kernel/src/fatal.rs @@ -84,12 +84,14 @@ impl fmt::Display for FaultInfo { /// Called for a fault once vectors are installed. Must not return. pub type FaultHook = fn(&FaultInfo) -> !; +#[cfg_attr(not(target_arch = "aarch64"), allow(dead_code))] static HOOK: AtomicUsize = AtomicUsize::new(0); pub fn set_fault_hook(hook: FaultHook) { HOOK.store(hook as usize, Ordering::SeqCst); } +#[cfg_attr(not(target_arch = "aarch64"), allow(dead_code))] fn call_hook(info: &FaultInfo) -> ! { let raw = HOOK.load(Ordering::SeqCst); if raw != 0 {