[FEATURE] Audit authority, code quality and documentation in deviced #1
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/deviced#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem and motivation
This issue tracks continuous Phase 6 audit closure for
deviced. Own explicit device publication, discovery and driver-facing provider grants under process lifecycle control.An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance.
Proposed behavior and scope
Current inventory: 3 Cargo targets (3 bin); manifests:
Cargo.toml. Include explicit and automatically discovered targets, supported features and target-specific configurations.Inventory every startup/runtime grant and authenticated peer, then success, denial, cancellation, failed transfer, restart and teardown. Trace callers and downstream providers so names, numeric identities and retained aliases never become implicit authority.
Authority, security and reliability
Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption.
Acceptance criteria
missing_docsenforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate.cargo fmt --all -- --check, strict Clippy, unit/doctests and warning-denied builds/rustdoc for every owned crate/target under default and all valid feature, freestanding/host, SMP and profile combinations; test mutually exclusive combinations separately. Add focused VM regressions for runtime behavior and observe the older catalog and unit tests at the exact published heads.Alternatives and tradeoffs
Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed.
Coherent realm image service prerequisites — 18 September 2026: Signed
2a387fa1ef0bc06fb68217b5003cf8efd65dc522selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 8 default, all-feature and separate production development/release configurations pass 135/136 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.Original coherent realm source CI acceptance — 18 September 2026: Signed
2a387fa1ef0bc06fb68217b5003cf8efd65dc522passes CI 205 and CI 204. All four terminal logs are complete (210,392 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Tracking and rollout
Runtime consumer dependency alignment — 15 September 2026
Signed
9a43680041574a0e227f3393f3a91540298a7f71aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 135 default / 136 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds:deviced-runtime: 135 development / 135 release tests,deviced-runtime-release-image: 136 development / 136 release tests. There are 16 supported native builds in total. Push/review CI 202/203 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending. Review: #3.feature/posix-compat; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages.dd6287e6538e7645fb02344a2ed696637f55c480; refresh component/dependency heads and their own CI evidence as implementation advances.Verified grant-rights checkpoint — 20 September 2026:
Signed commit 2c60b5d607997e671601044ae0f47dd0d8f69664 requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 135/136-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 206/207 passes from four complete hashed logs (210,344 bytes), with zero warning candidates. Bug 4 is corrected by test-only serialization of the shared quarantine flag; production fail-stop semantics are unchanged. The original failure is retained.
Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256
6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.
Acknowledged terminal service dependencies — 21 September 2026: signed 496bc0f82601508892f9ffcd1e058a7833134c3a selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 8 strict 135/136-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 208, 209 passes; complete hashed logs total 210,462 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.
[FEATURE] [P02.R06] Audit authority, code quality and documentation in devicedto [FEATURE] Audit authority, code quality and documentation in deviced