UPGRADE-01 on shadowfetch-5.0.0-amd64.iso sha256 2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21 (source 9587a7c)
Method: identical to a83d7d8a (upgrade-5.0.0-a83d/), same scripts (verify_upgrade_u01.sh, extra_checks.sh, login_shots.sh,
keyring_probe.py with the probe label changed to 2d8a).

Served repo: repo/ rebuilt 2026-09-30 19:14Z from 9587a7c; all 19 pool .debs byte-identical to build/ (served-repo-check.txt);
  Packages sha256 7c191d12...; shadowfetch-defaults 5.0.0-1 ships /usr/share/pam-configs/shadowfetch-gnome-keyring
  ("Session: optional pam_gnome_keyring.so auto_start") and its postinst runs pam-auth-update --package; the served
  shadowfetch-control-center has the guide_page.py busutil import (line 18); the served shadowfetch-welcome menu entry is
  "Exec=shadowfetch-welcome --force" (autostart entry unchanged: "Exec=shadowfetch-welcome").
  Served by tools/qa_5_0_0/serve_repo.sh on 127.0.0.1:8805 (access log: repo-server-access.log); server stopped afterwards.
Base: images/base-41-ice -> vm/upg41-prep, untouched (base-stat-before/after identical, and identical to the a83d values).
Test setup overlay u2d8-idx over upg41-prep: refreshed ONLY the local source index (guest Packages sha256 == host 7c191d12...).
  4.1 common-session had no pam_gnome_keyring line (41-pam-before.txt).

Harness: vm_acceptance.py run --case upgrade --record (under flock), run upgrade-20260930T193737Z-2d8a72e044e8: VERDICT PASS 7/7
  (base 4.1.0; apt-get exit 0, no removals; 5.0.0; user data byte-identical; machine-id kept; dpkg --audit clean; running).
  NOT RECORDED only because of the case's manifest_gap (no Phoenix Point restore after the upgrade). Receipt: harness-receipt.json.
  The harness's own post-upgrade screenshot (upgrade-after.png, the FIRST 5.0 login on that disk, 15:40 local) shows the
  "Shared Secure Boot signing key" notice (first-login-notice/harness-first-50-login-shared-mok-notice.png, -crop.png);
  the stamp .shared-mok-notice = "shown" was written at 15:40:14 by that login.

Verify 1 (overlay u2d8-v1 on the harness-upgraded disk):
  verify_upgrade.sh (scratch copy: VM name/out dir/4 vCPU 6 GB/keep-running only; expects shadowcode-2): 14/14 PASSED.
  extra_checks.sh 19/19: stamp shadowcode-2; ColorScheme ShadowfetchDark; Selection gold; doctor sec.dkms_mok status fail,
  shipped_in 4.1.0; notice stamp shown; element gone, agent-network offline (system+user); Buzz/codex/code-agent paths gone;
  shadow-code 1.0.0 ii, ShadowCode 1.0.0.
  NEW on 2d8a -- Control Center: opened shadowfetch-control and clicked every sidebar page: Guide, ShadowCode, Grok Bot,
  Hermes & OpenClaw, Workbench, Ignite, Watch, Recover, Workspaces, Drivers, Software, Mission Control -> app alive after each,
  0 tracebacks, empty stderr (control-center/pages.txt, pages-stderr-note.txt (stderr empty), pages-sheet.png). Guide renders the System Passport
  ("Ready, with a few notes", compatibility checks) instead of crashing; "Check again" re-ran the check, still alive, 0 tracebacks
  (13-guide-check-again.png). The a83d NameError (busutil, guide_page.py:195) is FIXED.
  NEW -- Welcome menu entry: the upgraded 4.1 user had never completed Welcome (no welcome-completed flag), so autostart showed
  Ignition at the first logins. (a) Menu -> "Shadowfetch Welcome" -> Enter opened the Welcome window (process
  "shadowfetch-welcome --force"; welcome-01/02). (b) Setup was then completed through the UI (Core -> Finish setup, Continue,
  Set up my desktop -> Choose manually -> network/graphics/apps/agents with nothing picked, agent network stayed Offline ->
  All set -> Finish without opening): welcome-completed written, /var/lib/shadowfetch/ignition-done written. With setup
  complete, plain `shadowfetch-welcome` (the autostart path) exits 0 without a window, and Menu -> "Shadowfetch Welcome"
  opened the Welcome window again ("Your computer. Your agents.", welcome-16-menu-opened-after-setup.png). The next login
  showed no Welcome window (relogin-contact-sheet.png). Also exercised: Welcome "Check this computer" opens Control Center
  -> Guide with results, no crash (welcome-06-check-this-computer.png). welcome-menu.txt has the process lines.
  Relogin (autologin, reboot): 34 screenshots, no shared-MOK notice and no Welcome; stamp mtimes unchanged (relogin-stamps.txt);
  re-running /usr/lib/shadowfetch/shared-mok-notice.sh under dbus-monitor: 0 Notify (positive control: one gdbus Notify
  -> 1 seen) (notice-rerun-dbus.txt).
  Secret Service: /etc/pam.d/common-session line 27 "session optional pam_gnome_keyring.so auto_start". Autologin conf removed
  (test setup), no keyrings existed; password typed at the SDDM greeter: journal "gkr-pam: unlocked login keyring";
  login.keyring created (GnomeKeyring binary); org.freedesktop.secrets owned by gnome-keyring-daemon; python3-secretstorage
  CreateItem on the default (Login) collection WITHOUT Unlock + SearchItems -> value, collection unlocked, no prompter process,
  no dialog on screen (keyring-probe.txt, keyring-03-store-no-prompt.png). Reboot + second typed-password login: lookup of the
  stored item and a new store both work, no prompt (keyring-probe-relogin.txt, keyring-05-relogin-lookup-no-prompt.png).
  No session drop seen in either password login (the a83d one-off was not reproduced).

Run 2 (independent manual upgrade, overlay u2d8-man over u2d8-idx, same package list and the harness's apt command, apt exit 0,
  16 upgraded, 1 newly installed, 0 to remove):
  4.1 before: element ice, Selection 154,117,56 / accent 216,162,74, Buzz/codex/code-agent present, shared MOK c66f9437...,
  no pam_gnome_keyring line; seeded codex-cli.desktop + claude-code.desktop as the 4.1 helpers write them and a user
  qa-my-app.desktop, plus 1 MiB random blob, notes, picture, .bashrc edit.
  After the upgrade: 5.0.0, common-session has the pam_gnome_keyring auto_start line, dpkg --audit clean.
  First 5.0 login: look-migrate accent 216,162,74 -> 242,179,61, both retired launchers removed (journal-first-login.txt);
  shared-MOK notice sent (stamp "shown" at 16:06:04, which the script writes only when notify-send succeeds). The popup had
  already expired before the first screenshot 12 s later, so it is not on this run's screenshots; the on-screen proof of the
  first-login notice is the harness disk's first login above. extra_checks.sh 19/19.
  User data: 23 home files sha256-identical before/after (home-manifest-before/after.txt, user-data-check.txt);
  qa-my-app.desktop byte-identical (2aefbeca...).
  Second 5.0 login: 40 screenshots, no shared-MOK notice; stamp "shown", mtime unchanged (notice-stamp-*-relogin.txt).
  Further login on a third clone of the harness disk (u2d8-n1, 184 screenshots from power-on): no notice
  (first-login-notice/n1-later-login-sheet.png, stamp-and-journal.txt).

Cleanup: repo server stopped (port 8805 closed); overlays u2d8-idx, u2d8-v1, u2d8-man, u2d8-n1 and the harness run's
  upgraded disk deleted; base chain unchanged.

Not proven: the recovery leg (restoring a Phoenix Point on the upgraded system) - harness gap.
Defects found on 2d8a: none.
Observation (not a defect): the Guide's Graphics row said "Ready with a note" when Control Center was started from a guest-exec
  session and "Needs attention - software rendering" when started from Welcome in the real session; this VM has no DRM
  render node, so both are plausible for the environment.
