WIP: Remove duplicate RTC logging and correct readiness fixtures #3

Draft
erikinkinen wants to merge 5 commits from feature/posix-compat into main
Owner

Summary and rationale

Submit RTC readiness once after successful one-shot completion. The previous admin path made two submissions through the same Logd boundary. Keep the remaining request identity and the completed driver result independent of informational logging failure.

Correct an existing housekeeping fixture uncovered by the expanded release-feature checks. The original fixture queued SERIAL readiness, which already satisfied the ready predicate, while claiming to exercise registration deferral. Separate actual registration deferral from queued SERIAL internal-control delivery and assert each case's real prerequisites.

Tracking and scope

  • Signed revision: f7b4f8d8b994d08188010c1f5a42ff3144d9a50e on feature/posix-compat.
  • Component authority/quality audit: #1. Housekeeping fixture defect: #2.
  • Related startup observation: Integration #33. Its pre-shell silence cause remains unknown; this change does not claim to fix it.
  • The CI helper now selects original Integration e2b1cf5995bcf6334839cda9a013e90fa97787d5, preserving original cross-repository Cargo identities without path replacement. Cargo dependency revisions are unchanged.

Architecture, authority and failure behavior

The only production operation removed is the first duplicate RTC-success Logd submission. RTC preparation, start, waited exit, alias retirement, error ordering and the remaining delegated sender are unchanged. No new production capability, receiver, discovery path or retained authority is introduced. A rejected informational log does not undo completed lifecycle success or restart the one-shot.

Test-only thread-local hooks exercise the actual admin branch and common raw-log entry. They record success/failure ordering, isolate test threads and restore the unarmed path after panic. They do not simulate or prove guest capability retirement. The terminal-start failure path's separate duplicate logs remain an explicit follow-up audit item.

The housekeeping correction changes tests only. One case proves that an unready SERIAL provider keeps its registration receiver selected while an unrelated ready marker remains queued. Another preserves queued SERIAL control when the host lacks a Logd endpoint. Production registration and release-log policies are unchanged.

Validation evidence

Original coherent realm source CI acceptance — 18 September 2026: Signed 2a387fa1ef0bc06fb68217b5003cf8efd65dc522 passes CI 205 and CI 204. All four terminal logs are complete (210,392 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.

Coherent realm image service prerequisites — 18 September 2026: Signed 2a387fa1ef0bc06fb68217b5003cf8efd65dc522 selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 8 default, all-feature and separate production development/release configurations pass 135/136 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.

Runtime consumer dependency alignment — 15 September 2026

Signed 9a43680041574a0e227f3393f3a91540298a7f71 aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 135 default / 136 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: deviced-runtime: 135 development / 135 release tests, deviced-runtime-release-image: 136 development / 136 release tests. There are 16 supported native builds in total. Push/review CI 202/203 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.

Formatting, strict host/freestanding Clippy, warning-denied host builds, and host/freestanding private-item rustdoc pass. Final tests across the three binaries pass in every selected configuration:

Configuration Unit tests
Default 135
Runtime 135
Release-image feature 136
All features 136

Each suite includes all six RTC cases and both housekeeping cases. The original RTC call restored under the new test produces the expected two-submissions-versus-one failure. The old release assertion and the first incorrect fixture correction also fail and remain recorded separately. The final correction strengthens preconditions and postconditions; it changes no runtime policy or acceptance deadline.

All nine Markdown files, canonical document sections and ten workflow shell fragments pass. All three crate roots deny missing_docs, and every Rust file remains below 1000 lines (largest 986). Source/lock/tool checks preserve original package identities and the selected overlays. All recorded process cleanup results are clear; no compiler/test warnings remain. Exact-revision push CI 200 and PR CI 201 both pass. Each passes all four host/freestanding configuration matrices and 135/135/136/136 unit tests, including the six RTC and two housekeeping cases in each configuration. All four complete job logs are retained (210382 bytes), with zero warning or failure candidates. CI completes the pinned source preparation; full Cargo PackageID JSON remains separately supported by the local metadata receipts.

ARCHITECTURE and ROADMAP describe the corrected readiness behavior; touched invariants and fixtures use rustdoc. README and manual interface contracts require no change because the public interface and lifecycle contract are preserved. Freestanding checking is separate from linked-image and guest validation. No new VM, boot-time improvement or in-EriX build is claimed.

Integration now selects this exact component in both catalogs at signed 4658ee9fab995eab1812f219971cffd340e1eb70, tracked in Integration PR #12. The complete original 73-repository graph and 39 affected host fixtures pass without warnings. Integration CI and applicable guest validation remain pending.

Review checklist

  • Signed canonical checkpoint and exact source/helper selections
  • Actual-handler regression coverage and retained original failures
  • Strict supported configuration checks and useful rustdoc
  • Component documentation and code-size checks
  • Current-revision CI
  • Coordinated Integration graph and applicable guest validation
  • Remaining component authority/redundancy audit and phase acceptance

The PR remains WIP. No merge or release publication is authorized by this checkpoint.

Verified grant-rights checkpoint — 20 September 2026:

Signed commit 2c60b5d607997e671601044ae0f47dd0d8f69664 requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 135/136-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 206/207 passes from four complete hashed logs (210,344 bytes), with zero warning candidates. Bug 4 is corrected by test-only serialization of the shared quarantine flag; production fail-stop semantics are unchanged. The original failure is retained.

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.

Acknowledged terminal service dependencies — 21 September 2026: signed 496bc0f82601508892f9ffcd1e058a7833134c3a selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 8 strict 135/136-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 208, 209 passes; complete hashed logs total 210,462 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.

## Summary and rationale Submit RTC readiness once after successful one-shot completion. The previous admin path made two submissions through the same Logd boundary. Keep the remaining request identity and the completed driver result independent of informational logging failure. Correct an existing housekeeping fixture uncovered by the expanded release-feature checks. The original fixture queued SERIAL readiness, which already satisfied the ready predicate, while claiming to exercise registration deferral. Separate actual registration deferral from queued SERIAL internal-control delivery and assert each case's real prerequisites. ## Tracking and scope - Signed revision: `f7b4f8d8b994d08188010c1f5a42ff3144d9a50e` on `feature/posix-compat`. - Component authority/quality audit: #1. Housekeeping fixture defect: #2. - Related startup observation: [Integration #33](https://git.erikinkinen.fi/erix/integration/issues/33). Its pre-shell silence cause remains unknown; this change does not claim to fix it. - The CI helper now selects original Integration `e2b1cf5995bcf6334839cda9a013e90fa97787d5`, preserving original cross-repository Cargo identities without path replacement. Cargo dependency revisions are unchanged. ## Architecture, authority and failure behavior The only production operation removed is the first duplicate RTC-success Logd submission. RTC preparation, start, waited exit, alias retirement, error ordering and the remaining delegated sender are unchanged. No new production capability, receiver, discovery path or retained authority is introduced. A rejected informational log does not undo completed lifecycle success or restart the one-shot. Test-only thread-local hooks exercise the actual admin branch and common raw-log entry. They record success/failure ordering, isolate test threads and restore the unarmed path after panic. They do not simulate or prove guest capability retirement. The terminal-start failure path's separate duplicate logs remain an explicit follow-up audit item. The housekeeping correction changes tests only. One case proves that an unready SERIAL provider keeps its registration receiver selected while an unrelated ready marker remains queued. Another preserves queued SERIAL control when the host lacks a Logd endpoint. Production registration and release-log policies are unchanged. ## Validation evidence Original coherent realm source CI acceptance — 18 September 2026: Signed `2a387fa1ef0bc06fb68217b5003cf8efd65dc522` passes [CI 205](https://git.erikinkinen.fi/erix/deviced/actions/runs/205) and [CI 204](https://git.erikinkinen.fi/erix/deviced/actions/runs/204). All four terminal logs are complete (210,392 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements. Coherent realm image service prerequisites — 18 September 2026: Signed `2a387fa1ef0bc06fb68217b5003cf8efd65dc522` selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 8 default, all-feature and separate production development/release configurations pass 135/136 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open. ### Runtime consumer dependency alignment — 15 September 2026 Signed `9a43680041574a0e227f3393f3a91540298a7f71` aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 135 default / 136 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: `deviced-runtime`: 135 development / 135 release tests, `deviced-runtime-release-image`: 136 development / 136 release tests. There are 16 supported native builds in total. Push/review CI 202/203 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending. Formatting, strict host/freestanding Clippy, warning-denied host builds, and host/freestanding private-item rustdoc pass. Final tests across the three binaries pass in every selected configuration: | Configuration | Unit tests | | --- | ---: | | Default | 135 | | Runtime | 135 | | Release-image feature | 136 | | All features | 136 | Each suite includes all six RTC cases and both housekeeping cases. The original RTC call restored under the new test produces the expected two-submissions-versus-one failure. The old release assertion and the first incorrect fixture correction also fail and remain recorded separately. The final correction strengthens preconditions and postconditions; it changes no runtime policy or acceptance deadline. All nine Markdown files, canonical document sections and ten workflow shell fragments pass. All three crate roots deny missing_docs, and every Rust file remains below 1000 lines (largest 986). Source/lock/tool checks preserve original package identities and the selected overlays. All recorded process cleanup results are clear; no compiler/test warnings remain. Exact-revision [push CI 200](https://git.erikinkinen.fi/erix/deviced/actions/runs/200) and [PR CI 201](https://git.erikinkinen.fi/erix/deviced/actions/runs/201) both pass. Each passes all four host/freestanding configuration matrices and 135/135/136/136 unit tests, including the six RTC and two housekeeping cases in each configuration. All four complete job logs are retained (210382 bytes), with zero warning or failure candidates. CI completes the pinned source preparation; full Cargo PackageID JSON remains separately supported by the local metadata receipts. ARCHITECTURE and ROADMAP describe the corrected readiness behavior; touched invariants and fixtures use rustdoc. README and manual interface contracts require no change because the public interface and lifecycle contract are preserved. Freestanding checking is separate from linked-image and guest validation. No new VM, boot-time improvement or in-EriX build is claimed. Integration now selects this exact component in both catalogs at signed `4658ee9fab995eab1812f219971cffd340e1eb70`, tracked in [Integration PR #12](https://git.erikinkinen.fi/erix/integration/pulls/12). The complete original 73-repository graph and 39 affected host fixtures pass without warnings. Integration CI and applicable guest validation remain pending. ## Review checklist - [x] Signed canonical checkpoint and exact source/helper selections - [x] Actual-handler regression coverage and retained original failures - [x] Strict supported configuration checks and useful rustdoc - [x] Component documentation and code-size checks - [x] Current-revision CI - [ ] Coordinated Integration graph and applicable guest validation - [ ] Remaining component authority/redundancy audit and phase acceptance The PR remains WIP. No merge or release publication is authorized by this checkpoint. Verified grant-rights checkpoint — 20 September 2026: Signed commit [2c60b5d607997e671601044ae0f47dd0d8f69664](https://git.erikinkinen.fi/erix/deviced/commit/2c60b5d607997e671601044ae0f47dd0d8f69664) requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 135/136-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 206/207 passes from four complete hashed logs (210,344 bytes), with zero warning candidates. [Bug 4](https://git.erikinkinen.fi/erix/deviced/issues/4) is corrected by test-only serialization of the shared quarantine flag; production fail-stop semantics are unchanged. The original failure is retained. Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. Full coordinated consumer acceptance remains open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19) and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Acknowledged terminal service dependencies — 21 September 2026: signed [496bc0f82601508892f9ffcd1e058a7833134c3a](https://git.erikinkinen.fi/erix/deviced/commit/496bc0f82601508892f9ffcd1e058a7833134c3a) selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). All 8 strict 135/136-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI [208](https://git.erikinkinen.fi/erix/deviced/actions/runs/208), [209](https://git.erikinkinen.fi/erix/deviced/actions/runs/209) passes; complete hashed logs total 210,462 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65).
fix: Avoid duplicate RTC readiness submission
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 10s
CI / test (push) Successful in 1m34s
CI / test (pull_request) Successful in 1m31s
f7b4f8d8b9
Submit RTC readiness once after the one-shot driver has exited and its
received aliases have been retired. Keep the remaining request identity and
completed lifecycle result independent of informational logging failure.

Separate provider-registration deferral from queued SERIAL internal control
in housekeeping tests. Preserve both original fixture failures and strengthen
their literal prerequisites without changing runtime policy.

Exercise the actual admin branch with scoped test-only completion and logging
outcomes. Preserve error ordering and enforce warning-denied host and
freestanding checks for each supported feature configuration. Select the
original-source CI helper without cross-repository Cargo path patches.

The removed request is redundant work; this checkpoint does not establish a
cause or correction for the separately retained pre-shell startup stall.
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (push) Successful in 15s
CI / markdown (pull_request) Successful in 13s
CI / test (push) Successful in 2m8s
CI / test (pull_request) Successful in 2m9s
9a43680041
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
build: Adopt coherent realm contract dependencies
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 12s
CI / test (push) Successful in 1m49s
CI / test (pull_request) Successful in 1m48s
2a387fa1ef
Select original signed shared revisions so coordinated runtime images can
resolve one source identity for every dependency. Preserve the component
implementation and update the roadmap to keep consumer VM acceptance explicit.

Validate default and all-feature development/release tests, strict host/native
Clippy, freestanding builds, formatting and private-item rustdoc with warnings
denied. Full image and in-guest build acceptance remain separate requirements.
fix: Minimize staged installer authority
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 7s
CI / test (push) Successful in 1m30s
CI / test (pull_request) Successful in 1m29s
2c60b5d607
Require exact GRANT-only final installer receipts and adopt the coherent
original shared dependency graph. Preserve existing unique custody and
original-generation cleanup instead of accepting unnecessary MINT authority.

Serialize the two quarantine fixtures around reset, operation and observation
of the shared atomic, fixing the observed host test race without changing
production fail-stop behavior. Track the retained original failure in issue 4.

Four strict 135/136-test configurations, four native builds with maintained
linker layouts, host/native Clippy, private rustdoc and policy checks pass
without warnings. Coherent guest acceptance remains a separate requirement.
build: Adopt acknowledged terminal accounting dependencies
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 6s
CI / test (pull_request) Successful in 1m30s
CI / test (push) Successful in 1m31s
496bc0f826
Select the original signed shared revisions for repeated terminal observation,
exact acknowledgement and retained final CPU measurements. Preserve the local
component implementation while keeping the complete transitive wire graph
consistent with Kernel design 20. Full service CPU/profiler VM acceptance and
Phase 6 self-hosting remain open in Integration issue 65.

All 8 strict host test matrices, host/native Clippy, warning-denied host/native
builds, private rustdoc, formatting and dependency/Markdown policies pass.
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 6s
CI / test (pull_request) Successful in 1m30s
CI / test (push) Successful in 1m31s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.