ac-os: boot sticks on stock Chromebooks — vboot kernel partition + embedded stub master
Stock Chromebook firmware (developer mode, Ctrl+U) only boots a kernel packed by vbutil_kernel from a ChromeOS-kernel GPT partition and hands it no initrd. Every stick now carries that partition next to the UEFI layouts: - initramfs-stub/init: tiny embedded initramfs (static busybox + one script) that finds the stick, unpacks the real initramfs.cpio.gz into tmpfs and switch_roots into it. On UEFI boots the external initrd overlays it. - docker-build.sh: Step 3b builds the stub, sets CONFIG_INITRAMFS_SOURCE, and packs + verifies vmlinuz.kpart with the public devkeys after bzImage. Missing tooling fails the build; AC_SKIP_KPART=1 opts out loudly. - Dockerfile.builder: vboot-utils. - oven/native-builder.mjs + upload-release.sh: extract and publish native-notepat-latest.vmlinuz.kpart (required unless opted out). - ac-os pull: fetch the kpart when the release has one. - flash-mac.sh: third partition KERN-A (type 7f00, priority 10 / tries 5 / successful) between ACBOOT and ACEFI, dd the blob, read it back to verify. Releases without a kpart still flash two-partition UEFI sticks. - docs/chromebook-boot.md: layout, boot path, Chromebook-side steps. First target: Lenovo 500e Chromebook 2nd Gen (phaser360 / Octopus).