Skip to content

chore: remove the appliance code that moved to cryptos-appliance - #350

Merged
Bugs5382 merged 1 commit into
mainfrom
chore/349-remove-appliance-code
Oct 6, 2026
Merged

Bugs5382 merged 1 commit into
mainfrom
chore/349-remove-appliance-code

Conversation

@Bugs5382

@Bugs5382 Bugs5382 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What and why

The OS layer moved to CryptOS-PKI/cryptos-appliance (cryptos-appliance#1, ported in
cryptos-appliance#8-#11 from cryptos-node@442b136). The image built there matches this
repo's build of the same commit, and its QEMU suite passes. This PR removes the moved
parts from cryptos-node:

  • build/ (kernel, cryptsetup, e2fsprogs, gptfdisk, dosfstools, squashfs, uki, iso, ci)
  • test/image/, test/integration/
  • cmd/cryptos-switchroot + internal/switchroot
  • cmd/cryptos-sbkey + internal/secureboot
  • .github/workflows/ci-image.yml, .github/workflows/ci-e2e-image.yml
  • docs/secure-boot.md, docs/image-upgrade.md
  • the matching Taskfile.yml tasks (kernel:build through qemu:run, iso*, image*,
    uki:*, rootfs:build, e2e:image, test:integration)

cmd/init, cmd/cryptos-install, cmd/cryptos-console, cryptosctl and the engine stay
here; cryptos-appliance builds them by import path.

task build's BUILDINFO var shelled out to build/ci/buildinfo.sh, which moves with
build/. Relocated it to scripts/buildinfo.sh (unchanged apart from its root-relative
path) so task build keeps stamping the binaries that stay in this repo; cryptos-appliance
carries its own copy for the image it builds.

README now points at cryptos-appliance for the boot image, Secure Boot and the QEMU suites.
.gitignore drops the stray-binary and build-artifact entries for the removed pieces.
ci-go.yml drops its now-dead build/** paths-ignore entry. A handful of comments in
files that stay (cmd/cryptosctl/image.go, image_test.go, internal/init/resolv.go,
internal/release/release.go, cmd/init/coverflush_e2ecover_linux.go) now name
cryptos-appliance instead of a local build//test/image path that no longer exists here.

Removed tests (now in cryptos-appliance)

  • internal/switchroot: TestRun_Sequence, TestRun_LoopFailureStopsBeforePivot,
    TestRun_SquashFSMountFailure, TestRun_ExistingDirsAreOK
  • cmd/cryptos-sbkey: TestRun_WritesAllOutputs, TestRun_RefusesOverwrite,
    TestRun_InvalidCN, TestRun_KeyBits
  • internal/secureboot: TestGenerate_KeyAndEncodings, TestGenerate_CertProperties,
    TestGenerate_SelfSigned, TestGenerate_DefaultValidity, TestGenerate_UniqueSerials,
    TestGenerate_Validation, TestGenerate_KeyBits
  • test/integration: TestImageSuite, TestPhase1CeremonyEndToEnd,
    TestConfigPersistsAcrossReboot, TestFirstBootFromESPStage,
    TestNodeIDNoTPMBootAndCeremony, TestResetWipesAndReprovisions, TestParseSectorSize

ci-image.yml also built and attached cryptosctl-* binaries and SHA256SUMS to this
repo's tagged GitHub Releases, alongside the image assets. cryptos-appliance's ported copy
of that workflow (CryptOS-PKI/cryptos-appliance#10) still builds cryptosctl from
cryptos-node by import path and publishes it the same way, so the release-asset set is
unchanged at the system level; it now ships under cryptos-appliance's tags instead of
cryptos-node's.

Merge order: this PR, then the website and cryptos-release companion PRs (Refs
#349).

Closes #349

Verification

  • Lint clean
  • Tests pass
  • Build succeeds
  • Documentation updated (if behavior or API changed)

How this was verified

task fmt, task proto:lint, task generate:verify, task lint (golangci-lint, 0 issues),
task vet, go test ./... under the memory-capped systemd-run/flock wrapper (all
packages pass), task build (produces bin/init, bin/cryptosctl, bin/cryptos-install),
task license (0/398 changed), actionlint -shellcheck= on the changed workflows.


Before merging: add a closing comment summarizing what was actually done in this PR
(not just the checked boxes).

The image build (build/), the QEMU suites (test/image, test/integration),
the image CI workflows (ci-image.yml, ci-e2e-image.yml), cryptos-switchroot,
cryptos-sbkey, and the Secure Boot and image upgrade docs moved to
CryptOS-PKI/cryptos-appliance, which pins this module and builds init,
cryptosctl and the console by import path.

task build's BUILDINFO var shelled out to build/ci/buildinfo.sh, which moved
with build/. Relocate it to scripts/buildinfo.sh (unchanged apart from its
root-relative path) so `task build` keeps stamping the binaries that stay
here; cryptos-appliance carries its own copy for the image it builds.

Removes 22 Go tests that now live in cryptos-appliance:
- internal/switchroot: TestRun_Sequence, TestRun_LoopFailureStopsBeforePivot,
  TestRun_SquashFSMountFailure, TestRun_ExistingDirsAreOK
- cmd/cryptos-sbkey: TestRun_WritesAllOutputs, TestRun_RefusesOverwrite,
  TestRun_InvalidCN, TestRun_KeyBits
- internal/secureboot: TestGenerate_KeyAndEncodings, TestGenerate_CertProperties,
  TestGenerate_SelfSigned, TestGenerate_DefaultValidity,
  TestGenerate_UniqueSerials, TestGenerate_Validation, TestGenerate_KeyBits
- test/integration: TestImageSuite, TestPhase1CeremonyEndToEnd,
  TestConfigPersistsAcrossReboot, TestFirstBootFromESPStage,
  TestNodeIDNoTPMBootAndCeremony, TestResetWipesAndReprovisions,
  TestParseSectorSize

Closes #349

Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
@Bugs5382 Bugs5382 self-assigned this Oct 6, 2026
@Bugs5382
Bugs5382 marked this pull request as ready for review October 6, 2026 19:31
@github-actions github-actions Bot added the skip-changelog Excluded from release notes (chore/ci/test/style). label Oct 6, 2026
@Bugs5382

Bugs5382 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Removed build/, test/image/, test/integration/, cmd/cryptos-switchroot + internal/switchroot, cmd/cryptos-sbkey + internal/secureboot, docs/secure-boot.md, docs/image-upgrade.md, and the two image workflows (ci-image.yml, ci-e2e-image.yml), all now in CryptOS-PKI/cryptos-appliance. Removed the matching Taskfile tasks and kept build for the binaries that stay (init, cryptosctl, cryptos-install), relocating its scripts/buildinfo.sh dependency out of build/. Updated the README, .gitignore and a handful of comments to point at cryptos-appliance. 22 Go tests moved with their packages (named in the PR body). Verified locally: task fmt, proto:lint, generate:verify, lint, vet, go test ./... (memory-capped), task build, task license, actionlint, all green.

@Bugs5382
Bugs5382 merged commit 3eec7e3 into main Oct 6, 2026
30 checks passed
@Bugs5382
Bugs5382 deleted the chore/349-remove-appliance-code branch October 6, 2026 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Excluded from release notes (chore/ci/test/style).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: remove the appliance code that moved to cryptos-appliance

1 participant