diff --git a/13-inch-thin-cannon/docs/iso-build.md b/13-inch-thin-cannon/docs/iso-build.md index 391f7bb..eb6f2a2 100644 --- a/13-inch-thin-cannon/docs/iso-build.md +++ b/13-inch-thin-cannon/docs/iso-build.md @@ -316,6 +316,18 @@ before the closure finder runs). `persist-config` script (mounts the LUKS `/persistent` subvol itself — disko-install unmounts the target before exiting — and `cp -a`s the baked `/iso/repo`). Harness now checks `flake.nix`, not `configuration.nix`. +- **`users.defaultUserShell = pkgs.nushell` breaks the harness — RESOLVED + (2026-08-13).** `users.defaultUserShell` applies to **root** too, so + sshd runs every remote command through nushell. Nushell rejects POSIX-sh + redirects (`2>&1`, `2>/dev/null` are parse errors; nushell wants + `out+err>`/`err>`), so the harness's remote commands failed: `sbctl status + 2>&1` exited non-zero → `set -e` killed `iso-test.sh` with no output, and + the settle loop's `systemctl is-system-running 2>/dev/null` silently never + saw a state. The system itself was fine (Secure Boot/LUKS all good). + **Fix:** nushell is set **per user** only (`users.users.file_magic.shell + = pkgs.nushell`); root keeps the NixOS default. Found by `just up` on the + rebased `main` (the merged `outline` commit introduced it); green after the + fix. - **Harness: Secure Boot check parsing bug — RESOLVED.** `sbctl status` prints `Secure Boot: ✓ Enabled` (tab + checkmark); the grep is now `Secure Boot:.*Enabled`. @@ -359,6 +371,14 @@ wireguard WARN). Committed in this session: `modules/impermanence.nix` `persist-config`, harness robustness, and the four `configuration.nix` fixes above. +**Green (2026-08-13, rebased `main`):** `just up` also passes on `main` after +the old-`main` rebase onto the green baseline (WireGuard kill-switch, +defcon34 wifi profile, ipv6 wg rule, libvirtd, powersave, nushell for +`file_magic`). The rebase surfaced one real bug — the `outline` commit's +`users.defaultUserShell = pkgs.nushell` changed root's login shell and broke +the harness's POSIX-sh remote commands (see the nushell gotcha below); fixed +by scoping nushell to `file_magic`. Verify + fix committed together. + Remaining work (not blockers): - **Watchdog reboot on some cold boots** — the only intermittent noise left.