This is the multi-page printable view of this section. .
Release archive
- 1: RC6 development candidate: owner-scoped Tier-1 delivery
- 2: Development snapshot: the Go 1.27 product surface
Farrow is pre-1.0. No public repository, Releases page, or downloadable Farrow artifact is available. Entries below are historical Piglet records; they do not establish post-rename Farrow validation or support.
1 - RC6 development candidate: owner-scoped Tier-1 delivery
Pre-Farrow historical record. It preserves the predecessor candidate’s exact identity and does not establish support for current Farrow bytes or paths. See current status.
Piglet 1.0.0-rc.6 is the owner-scoped local development candidate for the
single native-QEMU path. It closes the requested Quick and exact four-node
full scenarios on both Tier-1 hosts and adds durable privileged-network
transactions. It is deliberately not a public release.
No Homebrew operation, public tag, remote push, GitHub Release, package repository, production signature, attestation, or support commitment was created. The hashes below identify retained local artifacts; this site does not provide them as downloads.
Frozen identity
| Field | RC6 value |
|---|---|
| Version | 1.0.0-rc.6 |
| Source commit | 7db733184463cc189ffa738335c213fc9a2982de |
| Go | go1.27.0 |
| Source epoch | 1787657920 |
| Build timestamp | 2026-08-25T11:38:40Z |
| Channel | development |
| Signature / attestation | false / false |
Exact full profile SHA-256 |
912fea61bf1602c2a437570561a6ab4d0a5a8c152695147ad9e96ae831bc9336 |
Four requested product scenarios
| Host | Scenario | Result | Guest contract |
|---|---|---|---|
| macOS arm64 / HVF | Quick | PASS | Ubuntu 24.04.4, dba UID/GID 88, 2 vCPU, 64 GiB root, 64 GiB /data |
| Linux amd64 / KVM | Quick | PASS | same contract |
| macOS arm64 / HVF | exact full |
PASS | .10–.13, UID 88, 64 GiB roots, 128 GiB data disks, 2/1/1/1 vCPU, four-way peers |
| Linux amd64 / KVM | exact full |
PASS | same contract |
All eight final full-profile guests reported Ubuntu 24.04.4. The projects were destroyed through Piglet after assertions; shared image caches, project markers, and keys were intentionally retained.
Durable native networking
Network install and uninstall now use one root-owned strict-prefix transaction:
- root planning returns an owner/host/prestate-bound token;
- apply replans under the host-global lock and accepts only that token;
- a typed, fsynced journal is published before mutation;
- each fixed action is checkpointed after exact postcondition verification;
- interrupted work blocks ordinary private mutation until an explicit forward or rollback recovery plan is separately token-approved.
Darwin completed a real interrupted forward recovery and ended protected and healthy in default host mode. Linux completed real install, rollback/retry, four-node operation, uninstall, and host restoration before the final adversarial patch. That patch closed socket-state canonicalization, overly broad systemd enablement, NetworkManager ordering, and field-scoped recovery effects, then passed consolidated source/race gates.
Per the owner’s final direction, no VM or network test ran after that last patch. Therefore the post-audit Linux install/uninstall/reinstall replay is explicitly not run. This page does not upgrade source/race evidence into a native result.
macOS shared mode and subnet conflicts
The supported default remains socket_vmnet host mode. Shared mode passed a two-node contract on a proven-free alternate subnet, but it is an explicit fallback and not an isolation boundary.
The historical default-subnet failure was
VMNET_SHARING_SERVICE_BUSY (1009). VirtualBox was a plausible contaminant,
not a proven owner of that incident. Immediately before the final migration,
the observed subnet interface was the older Piglet-created bridge100.
Preflight now rejects foreign interfaces by identity instead of adopting a
matching .1/24 address. Operators can remove the confirmed owner or move the
whole lab to one warned canonical RFC1918 /24; Piglet never changes only the
guest addresses or selects a random escape subnet.
Reproducible local archives
Two independent local RC6 output trees passed the strict release verifier and were byte-identical for the four archives, checksums, release metadata, and formula:
| Archive | SHA-256 |
|---|---|
| Darwin amd64 | 1295288ff198b53fcb761a6e8794087d75a46105fc19980fabcd44f0c70fb9ef |
| Darwin arm64 | 308310b0f2d179f98c8be78ea09f89d226167072c936387bc42d717a922ec0c6 |
| Linux amd64 | 547a61f6cc0768071df349cbf5c17d7ddfe3ab3cea59e6b4026e3e3e616a5550 |
| Linux arm64 | afc9ce1043d377cc3b4ef8bdf77826a8139a8c839685025853e8bee8100c6a2e |
The formula is an inert build artifact. Earlier candidates exercised offline RPM/DEB consumption and ephemeral Cosign/SLSA round trips, but those results are mechanism evidence and are not relabeled as RC6 publication/signing.
What remains public-GA work
- literal reboot persistence on both Tier-1 hosts;
- current native smoke on macOS amd64 and Linux arm64;
- the deliberately deferred Linux final network replay;
- remaining image normalization, byte-reproducibility decision, hosting, and active/standby manifest-key custody;
- production release identity, signing/attestation, published Homebrew and Linux package channels, and clean-host consumption;
- a durable owner-operated macOS HVF runner and explicit release authorization.
See the current tutorial, design, and status for the maintained boundary.
2 - Development snapshot: the Go 1.27 product surface
Pre-Farrow historical record. Names, commands, paths, hashes, and claims on this page describe the predecessor snapshot only. Use the current Farrow status and guides for present behavior.
Piglet’s 2026-08-24 source snapshot has moved well beyond an initial QEMU spike. It now presents one coherent local-VM product: zero-configuration Quick, fixed-address private labs, 13 Piglet-owned profiles, an audited Pigsty inventory boundary, explicit persistence/state migration, diagnostics, and a reproducible release toolchain.
It is still a development snapshot—not a stable release.
This page is a historical 2026-08-24 snapshot. A later predecessor candidate is archived separately; neither page is current Farrow release evidence.
There is no public v1.0 tag, signed production artifact, Homebrew tap, or
DEB/RPM repository. All embedded image records remain testing. Local
packages and signature round trips prove mechanisms, not production custody.
One native runtime
Piglet directly drives native QEMU through HVF on macOS and KVM on Linux. It owns strict specification resolution, image/qcow2 verification, pure-Go NoCloud CIDATA, QMP/process identity, SSH readiness, atomic state, journals, events, repair, and bounded deletion. QEMU runs as the invoking user and never silently falls back to TCG.
There is no second provider/runtime path and no arbitrary QEMU-argument escape.
Quick on both Tier-1 hosts
The retained Go 1.27 Quick runs cover the public no-YAML path on macOS arm64 and
Linux amd64. The contract is meta/dba, 2 vCPU, 4 GiB memory, 64 GiB root,
sparse 64 GiB /data, user NAT, SSH, and four loopback forwarding conventions.
The product supports plan, up, status, SSH/exec, stop/start/restart, drift classification, guarded recreate/destroy, no-wait, persistent-disk retention, key retirement, logs, repair, and redacted debug bundles.
Those forwards do not install applications. Pigsty/PostgreSQL bootstrap remains a separate integration gate.
Private labs and host networking
Private mode now has public preflight/status/install/uninstall flows on both
Tier-1 host families. macOS uses pinned socket_vmnet v1.2.2 with host mode by
default and evidence-backed shared/FD paths. Linux uses a reversible
systemd-networkd/NetworkManager/bridge-helper transaction. Both keep QEMU
unprivileged and block uninstall while the global lease is active.
The default 10.10.10.0/24 can be replaced by one explicit canonical RFC1918
/24. Profile, host install, lease, state, node addresses, and Pigsty inventory
must move together. No random collision escape is chosen.
Retained four-node full and MinIO runs exercised fixed IPs, control-only
lateral SSH, management internet, storage identity, stop/start persistence, and
clean destroy on both Tier-1 paths. Earlier runs also cover crash recovery and
30/30 soak. The MinIO profile runs validate 16 VM data disks, not the MinIO
application.
Schema-3 owned profiles and Pigsty inventory
The 13 embedded profiles contain 85 nodes, all using dba. Ordinary nodes have
one 128 GiB /data; MinIO nodes have four 32 GiB disks. Catalog schema 3 owns
scalability, image policy, and Pigsty inventory binding, with direct and
build_subset modes.
piglet pigsty inventory reads a real Pigsty source tree, classifies and
validates host/VIP/admin/service address semantics, rebases a coordinated custom
subnet, and can atomically publish a mode-0600 marker-owned output. pigsty-vm
exposes the same profile, network, lifecycle, and inventory contract through a
small typed environment.
The wrapper has no provider fallback. Operational rollback means a prior verified Piglet artifact plus matching state backup.
Persistence, upgrade, and automation
Disks marked persistent: true survive ordinary destroy and compatible
recreate. The current safety contract requires an independent TTY phrase or
destroy --force --delete-persistent --yes-delete-persistent; project keys
have a separate default-dry-run project purge-keys --yes boundary.
Schema 0→1 migration is stopped-only, no-lease, backup-first, atomic, and
explicit through project upgrade-state --dry-run|--yes. Newer schemas are
refused rather than downgraded.
Private node selectors, --no-wait, stable JSON responses, typed exit classes,
shell completion, SSH config, marker-owned hosts blocks, per-node logs, and
redacted support bundles complete the current operator/automation surface.
Images and release mechanisms
The formal embedded image set is el9, el10, d12, d13, u22, u24,
and u26 on both Tier-1 native architectures. Retained matrix records report
7/7 per architecture; EL8 was retired from v1 because its arm64 kernel cannot
satisfy the tested native HVF contract. The entries remain testing pending a
production image channel and custody.
The source tree can build and verify four native archives, a Homebrew formula, Linux amd64/arm64 RPM and DEB packages, checksums, SPDX SBOMs, a combined release assembly, and Cosign signature/SLSA-provenance positive and tamper tests. Isolated package install/verify/remove and two-run reproducibility passed for the tested snapshots. The checked-in release workflow has not executed for a real tag.
Evidence must follow exact bytes
At this snapshot, catalog schema 3 and inventory integration had changed the
checked-in profile/resolved digests after the retained full/MinIO runs, so
exact-current native refresh was still required. Custom-subnet hosts
publishing, applied storage.data_root/ssh.wait_timeout, and generic
Quick users were also open.
RC6 later closed those implementation and exact-profile gaps. Historical native runs remain valid only for the bytes and behavior they actually exercised.
What remains before v1.0
The snapshot’s exact-profile, Pigsty-bootstrap, and Rocky 9.8 private-host gates were later exercised. The current remaining gates are production image/manifest/release custody, durable runner ownership, literal reboot recovery, Tier-2 native smoke, published package consumption, and a real signed/attested tag-bound release.
See the current tutorial, design, and status for the maintained boundary.