Skip to content

This is the multi-page printable view of this section. .

Return to the regular view of this page.

Release archive

Preserved pre-Farrow development records; Farrow has no public release yet.
Important

Farrow is pre-1.0. No public repository, Releases page, or downloadable Farrow artifact is available. Entries below are historical Piglet records; they do not establish post-rename Farrow validation or support.

1 - RC6 development candidate: owner-scoped Tier-1 delivery

Exact RC6 identity, four requested native product passes, durable network transactions, reproducible local archives, and the boundary that keeps this candidate unpublished.
Caution

Pre-Farrow historical record. It preserves the predecessor candidate’s exact identity and does not establish support for current Farrow bytes or paths. See current status.

Piglet 1.0.0-rc.6 is the owner-scoped local development candidate for the single native-QEMU path. It closes the requested Quick and exact four-node full scenarios on both Tier-1 hosts and adds durable privileged-network transactions. It is deliberately not a public release.

Warning

No Homebrew operation, public tag, remote push, GitHub Release, package repository, production signature, attestation, or support commitment was created. The hashes below identify retained local artifacts; this site does not provide them as downloads.

Frozen identity

Field RC6 value
Version 1.0.0-rc.6
Source commit 7db733184463cc189ffa738335c213fc9a2982de
Go go1.27.0
Source epoch 1787657920
Build timestamp 2026-08-25T11:38:40Z
Channel development
Signature / attestation false / false
Exact full profile SHA-256 912fea61bf1602c2a437570561a6ab4d0a5a8c152695147ad9e96ae831bc9336

Four requested product scenarios

Host Scenario Result Guest contract
macOS arm64 / HVF Quick PASS Ubuntu 24.04.4, dba UID/GID 88, 2 vCPU, 64 GiB root, 64 GiB /data
Linux amd64 / KVM Quick PASS same contract
macOS arm64 / HVF exact full PASS .10.13, UID 88, 64 GiB roots, 128 GiB data disks, 2/1/1/1 vCPU, four-way peers
Linux amd64 / KVM exact full PASS same contract

All eight final full-profile guests reported Ubuntu 24.04.4. The projects were destroyed through Piglet after assertions; shared image caches, project markers, and keys were intentionally retained.

Durable native networking

Network install and uninstall now use one root-owned strict-prefix transaction:

  • root planning returns an owner/host/prestate-bound token;
  • apply replans under the host-global lock and accepts only that token;
  • a typed, fsynced journal is published before mutation;
  • each fixed action is checkpointed after exact postcondition verification;
  • interrupted work blocks ordinary private mutation until an explicit forward or rollback recovery plan is separately token-approved.

Darwin completed a real interrupted forward recovery and ended protected and healthy in default host mode. Linux completed real install, rollback/retry, four-node operation, uninstall, and host restoration before the final adversarial patch. That patch closed socket-state canonicalization, overly broad systemd enablement, NetworkManager ordering, and field-scoped recovery effects, then passed consolidated source/race gates.

Per the owner’s final direction, no VM or network test ran after that last patch. Therefore the post-audit Linux install/uninstall/reinstall replay is explicitly not run. This page does not upgrade source/race evidence into a native result.

macOS shared mode and subnet conflicts

The supported default remains socket_vmnet host mode. Shared mode passed a two-node contract on a proven-free alternate subnet, but it is an explicit fallback and not an isolation boundary.

The historical default-subnet failure was VMNET_SHARING_SERVICE_BUSY (1009). VirtualBox was a plausible contaminant, not a proven owner of that incident. Immediately before the final migration, the observed subnet interface was the older Piglet-created bridge100. Preflight now rejects foreign interfaces by identity instead of adopting a matching .1/24 address. Operators can remove the confirmed owner or move the whole lab to one warned canonical RFC1918 /24; Piglet never changes only the guest addresses or selects a random escape subnet.

Reproducible local archives

Two independent local RC6 output trees passed the strict release verifier and were byte-identical for the four archives, checksums, release metadata, and formula:

Archive SHA-256
Darwin amd64 1295288ff198b53fcb761a6e8794087d75a46105fc19980fabcd44f0c70fb9ef
Darwin arm64 308310b0f2d179f98c8be78ea09f89d226167072c936387bc42d717a922ec0c6
Linux amd64 547a61f6cc0768071df349cbf5c17d7ddfe3ab3cea59e6b4026e3e3e616a5550
Linux arm64 afc9ce1043d377cc3b4ef8bdf77826a8139a8c839685025853e8bee8100c6a2e

The formula is an inert build artifact. Earlier candidates exercised offline RPM/DEB consumption and ephemeral Cosign/SLSA round trips, but those results are mechanism evidence and are not relabeled as RC6 publication/signing.

What remains public-GA work

  • literal reboot persistence on both Tier-1 hosts;
  • current native smoke on macOS amd64 and Linux arm64;
  • the deliberately deferred Linux final network replay;
  • remaining image normalization, byte-reproducibility decision, hosting, and active/standby manifest-key custody;
  • production release identity, signing/attestation, published Homebrew and Linux package channels, and clean-host consumption;
  • a durable owner-operated macOS HVF runner and explicit release authorization.

See the current tutorial, design, and status for the maintained boundary.

2 - Development snapshot: the Go 1.27 product surface

Quick and four-node private semantics, schema-3 owned profiles, Pigsty inventory integration, persistence, state migration, and verified release mechanisms.
Caution

Pre-Farrow historical record. Names, commands, paths, hashes, and claims on this page describe the predecessor snapshot only. Use the current Farrow status and guides for present behavior.

Piglet’s 2026-08-24 source snapshot has moved well beyond an initial QEMU spike. It now presents one coherent local-VM product: zero-configuration Quick, fixed-address private labs, 13 Piglet-owned profiles, an audited Pigsty inventory boundary, explicit persistence/state migration, diagnostics, and a reproducible release toolchain.

It is still a development snapshot—not a stable release.

Note

This page is a historical 2026-08-24 snapshot. A later predecessor candidate is archived separately; neither page is current Farrow release evidence.

Warning

There is no public v1.0 tag, signed production artifact, Homebrew tap, or DEB/RPM repository. All embedded image records remain testing. Local packages and signature round trips prove mechanisms, not production custody.

One native runtime

Piglet directly drives native QEMU through HVF on macOS and KVM on Linux. It owns strict specification resolution, image/qcow2 verification, pure-Go NoCloud CIDATA, QMP/process identity, SSH readiness, atomic state, journals, events, repair, and bounded deletion. QEMU runs as the invoking user and never silently falls back to TCG.

There is no second provider/runtime path and no arbitrary QEMU-argument escape.

Quick on both Tier-1 hosts

The retained Go 1.27 Quick runs cover the public no-YAML path on macOS arm64 and Linux amd64. The contract is meta/dba, 2 vCPU, 4 GiB memory, 64 GiB root, sparse 64 GiB /data, user NAT, SSH, and four loopback forwarding conventions.

The product supports plan, up, status, SSH/exec, stop/start/restart, drift classification, guarded recreate/destroy, no-wait, persistent-disk retention, key retirement, logs, repair, and redacted debug bundles.

Those forwards do not install applications. Pigsty/PostgreSQL bootstrap remains a separate integration gate.

Private labs and host networking

Private mode now has public preflight/status/install/uninstall flows on both Tier-1 host families. macOS uses pinned socket_vmnet v1.2.2 with host mode by default and evidence-backed shared/FD paths. Linux uses a reversible systemd-networkd/NetworkManager/bridge-helper transaction. Both keep QEMU unprivileged and block uninstall while the global lease is active.

The default 10.10.10.0/24 can be replaced by one explicit canonical RFC1918 /24. Profile, host install, lease, state, node addresses, and Pigsty inventory must move together. No random collision escape is chosen.

Retained four-node full and MinIO runs exercised fixed IPs, control-only lateral SSH, management internet, storage identity, stop/start persistence, and clean destroy on both Tier-1 paths. Earlier runs also cover crash recovery and 30/30 soak. The MinIO profile runs validate 16 VM data disks, not the MinIO application.

Schema-3 owned profiles and Pigsty inventory

The 13 embedded profiles contain 85 nodes, all using dba. Ordinary nodes have one 128 GiB /data; MinIO nodes have four 32 GiB disks. Catalog schema 3 owns scalability, image policy, and Pigsty inventory binding, with direct and build_subset modes.

piglet pigsty inventory reads a real Pigsty source tree, classifies and validates host/VIP/admin/service address semantics, rebases a coordinated custom subnet, and can atomically publish a mode-0600 marker-owned output. pigsty-vm exposes the same profile, network, lifecycle, and inventory contract through a small typed environment.

The wrapper has no provider fallback. Operational rollback means a prior verified Piglet artifact plus matching state backup.

Persistence, upgrade, and automation

Disks marked persistent: true survive ordinary destroy and compatible recreate. The current safety contract requires an independent TTY phrase or destroy --force --delete-persistent --yes-delete-persistent; project keys have a separate default-dry-run project purge-keys --yes boundary.

Schema 0→1 migration is stopped-only, no-lease, backup-first, atomic, and explicit through project upgrade-state --dry-run|--yes. Newer schemas are refused rather than downgraded.

Private node selectors, --no-wait, stable JSON responses, typed exit classes, shell completion, SSH config, marker-owned hosts blocks, per-node logs, and redacted support bundles complete the current operator/automation surface.

Images and release mechanisms

The formal embedded image set is el9, el10, d12, d13, u22, u24, and u26 on both Tier-1 native architectures. Retained matrix records report 7/7 per architecture; EL8 was retired from v1 because its arm64 kernel cannot satisfy the tested native HVF contract. The entries remain testing pending a production image channel and custody.

The source tree can build and verify four native archives, a Homebrew formula, Linux amd64/arm64 RPM and DEB packages, checksums, SPDX SBOMs, a combined release assembly, and Cosign signature/SLSA-provenance positive and tamper tests. Isolated package install/verify/remove and two-run reproducibility passed for the tested snapshots. The checked-in release workflow has not executed for a real tag.

Evidence must follow exact bytes

At this snapshot, catalog schema 3 and inventory integration had changed the checked-in profile/resolved digests after the retained full/MinIO runs, so exact-current native refresh was still required. Custom-subnet hosts publishing, applied storage.data_root/ssh.wait_timeout, and generic Quick users were also open.

RC6 later closed those implementation and exact-profile gaps. Historical native runs remain valid only for the bytes and behavior they actually exercised.

What remains before v1.0

The snapshot’s exact-profile, Pigsty-bootstrap, and Rocky 9.8 private-host gates were later exercised. The current remaining gates are production image/manifest/release custody, durable runner ownership, literal reboot recovery, Tier-2 native smoke, published package consumption, and a real signed/attested tag-bound release.

See the current tutorial, design, and status for the maintained boundary.