# Attempt history

All timestamps and observations below were captured on 2026-08-09 UTC. Build
and test identifiers are included so the claims can be traced to the platform
records rather than reconstructed from screenshots.

## Ubuntu 24.04

| Attempt | Build ID | Outcome |
| --- | --- | --- |
| r1 | `fbef47ee-b807-4df2-be12-8df1543fc25c` | Planning failed after the default provider hit its weekly limit and the configured fallback timed out. No artifact was produced. |
| r2 | `dcbe5f88-aab5-4763-9ee7-6ef0c96f6e6b` | An explicitly pinned fallback provider lost its transport during planning. No artifact was produced. |
| r3 | `da36d67a-95ee-494f-b9bc-31d6f4c524ab` | Image assembly produced ISO SHA-256 `a490edad241ab0ad8dffb7797d2bcc46e8f4233517198b30cc5f849ef7c72151`, but publication remained blocked because the credential scanner could not decompress an initramfs and therefore could not prove the artifact safe. A quarantined local copy was admitted only to an isolated boot test; it was not published. |

The isolated r3 test run is `e40493d3-1054-49fa-8a92-b50ca1bc90dd`.
All 9 initial assertions passed. The retained proof then reported nginx 1.24.0,
an installed dpkg package, enabled and active service state, TCP/80, and HTTP
200 on both boots. The boot ID changed from
`b433d6e6-e307-4a0e-bdb6-4326a3d02a60` to
`fa7544cd-b867-45ad-a4f1-09ce382d8917`.

Ubuntu live media handles a graceful reboot like removable installation media:
it pauses at “remove the installation medium, then press Enter.” Because the
same immutable ISO must stay attached for the next live boot, the runner let
the guest enter that shutdown path and then issued a virtual reset. That cold
restart is recorded in `results-ubuntu.json`; it is not represented as an
unassisted disk-installed reboot. Cleanup removed one VM and one run. The
runtime proof does not clear the unresolved initramfs-scanner finding, so this
artifact is not offered as a public download here.

## Debian 13 (Trixie)

| Attempt | Build ID | Outcome |
| --- | --- | --- |
| r1 | `78026f5e-4f5a-4c8d-a65f-e1de1eb7a0c1` | Image assembly completed, but publication was blocked after the artifact scanner reported credential-file/private-key findings. The artifact was not published. |
| r2 | `91470573-07c5-4eaf-b527-b7c018ebf259` | Full pass. ISO SHA-256 `5b1b33254fc07fb72ebd7e53d6c6507248e52b2d3e9e0ed95d7c424292b193c4`; retained test run `0455e1e7-73f6-4e54-bc71-bc94a7f3c582`; 23/23 initial assertions passed. nginx 1.26.3 returned HTTP 200 before and after reboot. Boot ID changed from `d244a09e-9f09-4b42-83db-2aef510fff34` to `abebb757-47e0-45d0-8474-f6017b65bbbc`. Cleanup removed one VM and one run. |

The r2 build record later displayed `queued` after restart recovery even though
its canonical artifact and passed test record remained present. The evidence
file preserves both facts instead of rewriting the historical API response.

## Fedora 43

| Attempt | Build ID | Outcome |
| --- | --- | --- |
| r1 | `995ec57c-694c-4f1e-9a8f-0b343923d6c4` | Build failed in a firewall hook because the initial recipe inherited firewall enablement. The corrected recipe makes that choice explicit. |
| r2 | `7a3996bb-2fd2-4a84-8d52-3e8179b88b73` | Test run `06a6e754-3f2a-4854-bbcf-acbc0a9aa888` passed 12/16 assertions. The signed Fedora nginx 1.30.4 package was installed, but the service was disabled and inactive, port 80 was absent, and the HTTP check returned status 0. This exposed a hook that silently ignored `systemctl enable` failure. |
| r3 | `454fe8bc-bed8-46e4-95c0-983c5627322d` | ISO SHA-256 `6ae45279a70ea8e0c56089ec366bcffc4e42d1702db6a9a3b1ad8996e0ab6f67`; test run `70fec4bb-d89d-4ae0-a131-0252db17c137` again found nginx 1.30.4 installed but disabled and inactive, with no listener or HTTP response. Inspection of the finished ISO confirmed that the build-time wants symlink existed. Fedora's first-boot preset pass then applied the distro's terminal `disable *` rule and removed the enablement. |
| r4 | `c8c6033f-101b-47aa-ab17-3ffefa1cad43` | Full pass with the explicit `/etc/systemd/system-preset/00-openfactory-nginx.preset` rule. ISO SHA-256 `dcdd96f3d2a81d173ba1bd047a089bed10d90c67a0506a8cf7ca19f067cd2a5f`; test run `e469bce6-d012-4b60-b9fe-8628ade6c00f`; 16/16 initial assertions passed. nginx 1.30.4 returned HTTP 200 before and after reboot. Boot ID changed from `34ab5692-66d1-4c0e-bf78-63b00c454bf3` to `e34a0c83-125b-45ea-90da-70858f826016`. Cleanup removed one VM and one run. |

The r2 and r3 retained VMs were cleaned after the failed assertions.
`results-rpm.json` and `results-fedora-r3.json` preserve the failed runner
outcomes; `results-fedora.json` preserves the final r4 pass. The four failing
observations above were captured before cleanup. The r3 ISO was also mounted
read-only after the test: its
`multi-user.target.wants/nginx.service` symlink pointed at the packaged unit,
and Fedora's `99-default-disable.preset` contained `disable *`. This separates
the build-time enablement from the first-boot policy that later reversed it.
The service-specific preset in r4 made that intent survive first boot.

## openSUSE

| Attempt | Build ID | Outcome |
| --- | --- | --- |
| Tumbleweed r1 | `339a2cc4-550c-45c9-be97-03959b4f5762` | Build stopped on expired upstream signing-key metadata. No signature bypass was used; the maintained Leap target was selected instead. |
| Leap r2 | `17b5f9e8-a690-4e65-aa57-a1c01ec62b48` | ISO SHA-256 `f4a871cf64631968c2a02ec84760bd5fe7ad9f5d91c8f676951748a663ba5e17`; test run `4b5ca2fc-8cf7-4a73-9239-7b346f17caae` timed out after 600 seconds because the guest agent was not responsive. No nginx assertion was credited. Cleanup removed the retained environment. |
| Leap r3 | `a87c2fa2-f033-425d-a652-c695a4ace95f` | Built ISO SHA-256 `22bc6aede78009ca9c2576376c84bd5f3219eb108386bec2ac4bfb2169f56a76` with the `qemu-guest-agent` package present. Test runs `591b46cb-5ab4-4841-aa8a-bebc4158e134` and `4c5b8f74-84c2-51a8-8ace-56c8c488b74f` booted retained VMs, but both remained at zero credited assertions. A direct QEMU guest ping on each running VM returned `guest agent is not connected`; ISO inspection showed that the package's unit had no enablement link. The superseded runs were cancelled and cleaned instead of waiting for a duplicate timeout. |
| Leap r4 | `afdc7c8b-a3fa-4411-ab38-4de508e69580` | Built ISO SHA-256 `ce41fb58444dbb626087acdd43ec373bda13b83c2ae7d50a0c1efe3d5c844dbd` with fail-closed nginx and guest-agent enablement. Test run `698b8604-a532-4240-9fa9-917f19a83ecf` then stopped in dracut emergency mode before the live root mounted. The boot config requested `CDLABEL=openSUSE_Leap_15.6_KDE_Live`, while the remaster was labeled `openSUSE-Custom`. The superseded run was cancelled and cleaned after the boot console made the mismatch explicit. |
| Leap r5 | `6b282d85-1290-4c16-a27c-794ccc636b54` | ISO SHA-256 `0f1bfc66b8a94b0b58c4a3d13e0f141b86d64086d643972bb2d31199994d0c91` preserved the source label and booted successfully. The guest agent responded and test run `5b4cc8e7-2f3e-430e-a2ad-5de23afa98ba` passed boot and package checks, then failed its network assertion. NetworkManager had learned a runtime resolver, but `/etc/resolv.conf` was a baked regular file containing the build-host resolver address; `netconfig update -f` confirmed the diagnosis. A direct nginx probe also found an enabled, active service but HTTP 403 because openSUSE's `/srv/www/htdocs` had no index. The run was not credited and was cleaned. |
| Leap r6 | `f706b6f0-2951-4d76-887a-184bc767ab14` | Built but deliberately not tested. Its generated nginx hook contained the missing-index fix, but the preparation worker had not reloaded the resolver-restoration code, so inspection showed the old DNS-copy block unchanged. The artifact was superseded rather than represented as the intended correction. |
| Leap r7 | `03d3daf4-788f-43ce-9eb0-8507c2ebd072` | ISO SHA-256 `dcad4ad43af7eafdba8032177f6b75f82b5560f2fc646213542fb198f488c4be` preserved the source label, enabled the guest agent, and included the corrected nginx hook. Test run `d3bb1a55-4b62-4a73-bd58-ff35135ec162` resumed after a transient test-backend restart and reached the network assertion, where direct guest inspection found `/etc/resolv.conf` still baked with the build-host resolver address. The Leap source image contains no `/etc/resolv.conf`, so the prior restoration handled files and symlinks but failed to restore absence. Recovery run `5465a0ba-bae9-5de2-a990-feaac3bdc3f2` reproduced the same network failure. Neither run was credited; both runs and VMs were cleaned. |
| Leap r8 | `4239c9d1-e085-4d24-a85c-d0f1eb83c576` | Full nginx contract passed. ISO SHA-256 `8a55ad20a8906ff01f2c6133608e5412277e806e31d4b8ec418026974dd14e83`; retained provision-only run `5f22a7b7-72e8-49b0-a676-4d89fe591ad4`. The RPM was installed, nginx was enabled and active, TCP/80 listened, and local HTTP returned 200 before and after reboot. nginx 1.21.5 remained present while the boot ID changed from `5339a5ea-aa85-483c-8923-f3a45b52a929` to `638a60e1-839b-40dc-9ac1-a0bc165bc087`. Cleanup removed one VM and one run. |

The r8 artifact also resolved external DNS and reached HTTPS with the source
image's runtime `netconfig` resolver shape restored. Two screenshot-heavy test
launches were not credited: one was interrupted by a test-backend deployment,
and one stalled in the GUI capture layer even though direct guest checks were
green. The final record therefore uses the explicitly labeled provision-only
mode and the deterministic six-condition nginx command on both boots. It does
not claim a screenshot assertion count that did not complete.

Two startup-recovery attempts also revisited the unchanged r2 artifact while
r3 was waiting for build admission. Run
`d19e0d1f-ed6b-5c98-a9d3-26412e77751b` was cancelled as superseded after
12 minutes with no credited assertions. Run
`c829edaf-fb08-518e-bed4-883f665ee77a` then reproduced the original
600-second guest-agent timeout, again with zero assertions. The r2 build row
was reconciled to terminal `error` test state at 17:10 UTC so that the stale
recovery callback could not remain represented as an active test. Neither run
is counted as r3 evidence.

## Corrections made from the failures

1. Recipes now state firewall intent explicitly rather than inheriting a
   default that differs across builders.
2. The nginx feature hook treats service enablement as a build invariant. It
   no longer turns `systemctl enable` failure into a successful image.
3. The nginx hook now writes a service-specific systemd preset, because a
   build-time wants symlink alone does not survive Fedora live media's
   first-boot preset pass.
4. The openSUSE retained-test recipe includes the guest agent required by the
   assertion transport and explicitly preserves its service enablement across
   first-boot presets; installing the package alone was not sufficient.
5. The openSUSE remaster preserves its source ISO volume label; changing the
   label without rewriting the embedded `CDLABEL=` arguments makes dracut
   unable to locate the live root.
6. The openSUSE remaster restores the source `/etc/resolv.conf` shape after
   temporarily using build-host DNS inside the chroot. That means restoring a
   regular file, restoring a symlink, or removing the temporary file when the
   source has no resolver at all, so runtime DHCP can supply the guest's actual
   resolver.
7. The nginx hook writes a neutral index only when the distro's selected
   document root has no index; this turns openSUSE's otherwise healthy default
   403 into the same observable HTTP 200 contract without overwriting content.
8. Publication gates and runtime tests remain separate. A scanner failure is
   not relabeled as a safe public artifact merely because an isolated VM boots.
