[FEATURE] Audit authority, code quality and documentation in docs #2

Open
opened 2026-09-12 07:57:28 +02:00 by erikinkinen · 0 comments
Owner

Problem and motivation

This issue tracks continuous Phase 6 audit closure for docs. Maintain cross-component specifications, generated library API references, the TeX technical manual and their build/publication tooling.

An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance.

Proposed behavior and scope

Current targets: no Cargo targets. Validate the maintained scripts, workflow/templates and their tests; record Rust-only checks as individually not applicable with evidence.

There is no Cargo target. Review the API-reference generator, manual build/publication scripts, test fixtures and CI input/output ownership. Tie runtime capability and feature statements to their owning component evidence; justify each non-applicable runtime dimension separately.

Authority, security and reliability

Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption.

Acceptance criteria

  • Record origin, recipient, object, operations, delegation ceiling, lifetime and aliases for each relevant capability or caller-supplied authority-bearing value.
  • Audit ambient discovery/selectors, cwd/PATH/environment, numeric identities, inherited routes and host fallbacks; require explicit authorized intake.
  • Account for residual authority after success, error, cancellation, timeout, restart, failed transfer and teardown, including fork/exec where implemented.
  • Remove unnecessary endpoints, broad rights, duplicate aliases, provider/admin grants and debug routes.
  • Exercise stale generations, replay, pending replies, forged descriptive identity and object/path resolution races at the owned boundary.
  • Prove independent cleanup attempts and caller-specific error precedence; quarantine or terminate when retained authority cannot be accounted for.
  • Review unsafe/FFI/parser/arithmetic/lifetime/lock/publication invariants and add adversarial coverage where practical.
  • Inventory obsolete APIs, wrappers, fallback/dead paths and duplicate validators with their maintained callers.
  • Migrate callers and delete deprecated contracts/shims in a coherent signed revision graph; reject retired input versions where relevant.
  • Classify each size/count/depth/time bound as ABI, hardware, explicit resource policy or accidental limitation.
  • Test beyond removed boundaries and at allocation/ABI limits while preserving exhaustion errors, denial-of-service controls and bounded waits.
  • Keep every tracked authored code/test/script/workflow file below 1000 physical lines through thematic refactoring.
  • Run the deterministic tracked-source size gate, covering executable fixtures/generators and excluding only genuine non-code data or external payloads.
  • Audit production/test feature and symbol separation, including this repository's effect on rootd test orchestration.
  • Supply changes affecting rootd semantic surface to the maintained same-toolchain baseline; record a justified component-specific applicability result.
  • Check bootstrap ownership and development/release authority parity at this repository's producer/consumer boundary.
  • Use maintained integration#3 profiler evidence before optimizing; preserve live access checks, ownership and success criteria.
  • Audit build/CI inputs, secret handling, private outputs, symlink containment, deletion, subprocess bounds, warnings and host dependencies.
  • meaningful public/private inline documentation, crate/target missing_docs enforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate.
  • Validation: Run maintained Python/shell/template/Markdown tests and checks where present. For docs, regenerate the affected API references and build the full TeX manual with no warnings, errors or overflows; inspect changed rendered pages. Do not report absent Rust targets as passed Rust validation.
  • Documentation: update applicable README/ARCHITECTURE/ROADMAP in meta's canonical format and affected technical-manual TeX/API references; keep README evergreen and shared governance byte-identical to meta.
  • Evidence: record exact source/dependency revisions, commands, configurations, real exit status, CI run URLs and results; repeat the audit on final heads and obtain independent review of security closures. No skipped/pending/predecessor result counts as a pass.

Alternatives and tradeoffs

Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed.

Validation checkpoint — 14 September 2026: Signed Docs 013ec09aafd9412990fec8231ceb73e7d1a1c94f records all 156 public issues. All 45 documentation tests and 55 Markdown files pass. Manual/API/build inputs remain byte-identical to the preceding accepted source. CI 847 and 848 pass with four complete logs totaling 752,642 bytes. Both manual jobs converge through 2,325/2,339/2,339 pages and 31/1/0 reference warnings, with no final layout warnings. The reported PDF is 4,114,917 bytes; no CI artifact bytes were downloaded.

Validation checkpoint — 14 September 2026: Signed Posixd 52ef820d33399490c121aad3af1409139e4a8f44 selects the proposed realm custody owner: Procd deposits an ancestor SEND-lineage revoker into its exact native generation before export and retains a nested guard for earlier realm retirement. Exported aliases descend from the nested guard; ancestor-only bypass and setup aliases must be removed before publication. Kernel supplies the existing terminal trigger; children, provider leases, receiver aliases and pending operations retain separate owners and acknowledgments. This is a documented design; Posixd has no executable crate or implemented realm handshake. Posixd CI 5 and 6 pass with complete warning-free logs. Signed Docs d9bb106b94deb7c2af620775dc98be0cc46ae704 updates the process-services manual and records the separate owned invocation design. All 45 Docs tests and 55 Markdown files pass. The 2,341-page local manual has zero final warnings; 426,812 word boxes fit page bounds and the changed page was visually reviewed. Docs CI 849 and 850 pass; their manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with no final layout warning. All six complete Posixd/Docs job logs total 760,808 bytes. Runtime producer adoption, realm byte I/O and both complete guest build generations remain open.

Allocator validation checkpoint — 14 September 2026: Signed Docs 5b171773c78938b78d0b6d9865d50ece8535682f records all 158 public issues. All 45 documentation tests, Markdown and heading checks pass. Rendered manual/API/build inputs are unchanged from the accepted realm manual. CI 851 and 852 pass with four complete logs totaling 753,560 bytes. Both manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with no final layout warning. Static inventory covers 76 repositories and 2,890 code files below 1,000 lines; all 92 library/binary and 62 additional standalone test/example/bench/build-script roots directly gate missing_docs. This does not establish private-documentation quality or whole-authority closure.

Endpoint construction checkpoint — 14 September 2026: Signed Docs e923440acecfe775ed71a4f046b8e7daa3d25447 documents explicit endpoint construction and the proposed request/result custody obligations. All 45 documentation tests and canonical Markdown/structure checks pass. The local 2,341-page manual has zero final warnings; all 426,861 word boxes fit the pages and changed page 183 is visually reviewed. CI 853/854 passes with four complete logs totaling 753,568 bytes. Both manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with zero final layout warnings. All 158 public issues remain indexed.

Completed CI checkpoint — 15 September 2026: Signed Integration a869a81eb406a4f027a2b5db573b6330ca114d94 passes both 1607/1608; signed endpoint-construction checkpoint 989d44d604d07c4c9bcc23264912bdf2076b99eb passes both 1609/1610. Each run reports all 486 distinct VM scenarios passing, followed by the actual native lifetime scenario, physical/serial interactive checks and all four console modes. Rust and Markdown pass. The two six-log cohorts contain 26,769,289 and 26,769,316 bytes respectively, with zero warning candidates. The previously observed intermittent quota timeout remains documented without a causal-fix claim. These results establish the selected source checkpoints, not owned invocation transport, complete authority closure or either full in-EriX build generation.

Native transfer preparation checkpoint — 15 September 2026: Signed Docs 0fe830c906bc95255d4be18413b0c054bf224e0c documents complete native transfer preparation and the pre-delivery rollback serialization boundary. All 45 documentation tests and canonical Markdown/structure checks pass. The complete 2,341-page manual has zero final warnings; all 426,948 word boxes fit the pages and changed page 144 is visually reviewed. Docs CI 855/856 passes with zero final warnings; intermediate reference passes converge through 32/1/0 warnings. All 158 public issues remain indexed. Generated API/build inputs are unchanged. This implements preparation for the current IPC path. Its private records cannot survive userspace scheduling and own no retained source authority. Persistent request/result bytes and capability custody, exact delivery state and terminal hooks remain unimplemented under Kernel issue 11. No opcode, wire record, bootstrap-frame escrow eligibility or application-cancellation semantics are assigned.

Native invocation custody checkpoint — 15 September 2026: Signed Docs 76b657ad8b8ba8df7f55f17ce739301a80d22802 indexes all 159 public issues, including the canonical fixture bug report. The native custody manual checkpoint 073da485626c3d74f68d0beb2da47ac8400c23d3 passes CI 857/858: 45 tests, 2,343 pages and zero final warnings after 32/1/0 reference convergence. Local layout review checks all 427,174 word boxes within page bounds and visually reviews changed page 144. The later index-only checkpoint passes all 45 tests and changes no manual or generated API/build input. Corrected signed-head Kernel CI 548/549 and Docs 859/860 pass. All 8 complete logs total 1,413,966 bytes, with zero final warnings. The terminal cohort is classified. The syscall wire adapter, fresh userspace buffer/fault/overlap validation, authenticated caller-origin delivery fields and actual CPL3 owned-invocation peers remain unimplemented. Reachable backend disposal-failure coverage, sustained invocation-workload profiling, realm producer adoption, whole-codebase authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire record is assigned; the existing CALL/RECV/REPLY ABI is unchanged.

Authenticated delivery-origin checkpoint — 15 September 2026: Signed Docs c728670ccc57a1c200b1bfc2ebb359920c1a2256 updates the technical manual and roadmap with the origin/liveness/authority distinction. All 45 tests pass; the complete 2,343-page manual has zero final warnings, all 427,252 word boxes within page bounds, and visual review of changed pages 144/145. CI reference passes converge through 32/1/0 warnings. The public index retains all 159 issues; no new issue is introduced by this slice. Kernel CI 550/551 and Docs 861/862 pass. All eight complete logs total 1,414,891 bytes, with zero final warnings; the cohort is classified and stopped. The separate earlier fixture correction remains closed in Kernel issue 13, preserving original CI 546/547 and corrected 548/549. Sustained invocation-workload profiling, syscall wire and fresh-buffer/fault/overlap validation, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm producer adoption, whole authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire layout is assigned. Native progress and cleanup still do not certify application cancellation.

Native invocation profiling baseline — 15 September 2026: Signed Kernel 6cb703e1ed8b9de0d29a37189cd914cd501e732e provides an actual-object host workload for queued progress, collected progress, descriptive result reads and complete request/result cycles. Signed Integration f3e4359b34cb8f7db732fbf38823f722553c86d4 adds bounded capture, raw-evidence report verification and equivalent comparisons. Every sample checks exact bytes and SEND capability bindings, authenticated origin, foreign selection, duplicate completion refusal, FIFO position reuse, one-time collection and final invocation disposal. Source and executable bytes are observed against explicit original identities; compiler/host relationships remain declarations. Workload children and source Git reads receive minimal environments; capture owns memory, time, output and process cleanup. Completion is published only after deadline teardown succeeds. The operator guide and signed Docs 644273a0edd91e4c38dcd4418d6ae1119ff1f10b describe these boundaries. Kernel strict default/all development/release checks pass 632/656 units plus three standalone controls, three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. Integration passes all 161 helper commands, including 19 profiler controls and nine source-provenance controls, plus fresh strict 320/321-unit Rust matrices, private rustdoc and warning-free target builds. Four original socket-fixture failures are retained and attributed to the selected temporary directory exceeding the host Unix-socket path domain; a shorter explicit private directory passes the same fixtures. Docs passes 45 tests and renders 2,345 pages with zero final warnings; 427,592 word boxes fit page bounds and changed pages 2284/2285 pass visual review. Kernel CI 552/553 and Docs CI 863/864 pass; eight complete logs total 1,431,762 bytes with zero final warnings after manual reference convergence. No Kernel performance algorithm has changed in this baseline. Native syscall adapters, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The 76-repository inventory has 2,923 code files below 1,000 lines and 155 direct missing_docs crate-root gates; this does not close the semantic audits.

Measured native invocation lookup refinement — 15 September 2026: Signed Kernel 8349d68636382cc7e25a3347f5f1df216554203a retains only numeric carrier-search positions. Every use rechecks the actual CSpace capability type/rights, live endpoint identity and exact binding; stale positions take the complete search path. No successful authorization, capability or reference is cached. Draining scans fix their boundary on the first poll, visit each position at most once, skip busy stack owners and return exclusive custody after unlocking. Native disposal and first-failure retention preserve their existing semantics. Signed Integration 108501cf7ec20f05dd3d62ea401ea8adad6c6e9c selects this Kernel in its isolated native catalog, and signed Docs f10a1d375a326543ec0adda4569bc7cb4faca9b6 documents the invariants. The existing syscall ABI and ordinary image catalog are unchanged. All 15 actual-object native controls pass, including real alias compaction, rights/type/object replacement, busy ownership and allocation-free settlement. The unchanged four-mode workload control also passes. Full strict default/all development/release Kernel matrices pass 634/658 units plus three standalone controls, with three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. The existing native lifetime and entry-argument VM passes unchanged oracles in 21.978041 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its signed boot image is 2,207,744 bytes, SHA-256 4030cdfb8a13c000ff4716ecdc5203cb46273d6117a282f7375f25dccbbeedc9. Exact unchanged Integration Rust/helper bytes preserve the preceding strict 320/321-unit matrices and all 161 helper-command results; changed catalog/scenario policies pass. Docs passes all 45 tests and a complete 2,345-page render with zero final warnings, 427,679 bounded word boxes and visual review of page 145 plus continuation page 146. The original signed Kernel 6cb703e1ed8b9de0d29a37189cd914cd501e732e and the new signed Kernel use byte-identical workload sources, the same selected CPU/toolchain/context and explicit limits, distinct source targets, four modes, populations 0/32/128/512 and 256 operations per sample. Each capture retains 48 measured samples and 16 warmups; every sample passes actual semantic and native/process-cleanup checks. At population 512, median queued-progress cost changes from 117.578 to 37.673 microseconds (3.12x observed ratio), and full-cycle cost from 1167.847 to 443.055 microseconds (2.64x). Collected progress changes from 8.928 to 6.015 microseconds and descriptive reads from 9.124 to 6.212 microseconds. Timings include fixed checks, with no subtracted overhead or timing-ratio pass gate. No managed build/test workload runs concurrently during capture; external host scheduling remains unisolated. These are host operation wall times, not guest startup/build acceptance or a statistical guarantee. Kernel CI 554/555 succeeds; four complete logs total 679,280 bytes with no warnings, and its completed cohort is stopped. Docs CI 865/866 succeeds at observation three; four complete logs total 754,424 bytes, all 45 tests pass and each manual has 2,345 pages. Its normal reference passes report 32/1/0 warnings, with zero final warnings and no box diagnostics. The completed Docs cohort is stopped. Integration CI 1619/1620 is waiting at its first observation. Older Integration 1613/1614 is running; 1615/1616 and 1617/1618 are waiting. Accepted older Integration 1611/1612 passes all 486 catalog scenarios and later probes with complete warning-free logs. This does not establish the intermittent quota cause tracked in Integration issue 18. Current full-suite CI remains required; stopped cohorts are not polled again. Owned syscall wire adapters, actual owned CPL3 peers, fresh-buffer validation, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The refreshed 76-repository inventory has 2,924 code files below 1,000 lines and 155 direct missing_docs crate-root gates; those checks do not close whole-codebase semantic audits.

Owned invocation wire and native acceptance — 15 September 2026: Signed Kernel 5f497adaefa526108a0439e0e071717dddb85334, shared IPC de968da19898bef532ddb3b5974bb9562f51dee5, capability ABI a001a26f0eb3aebec3f5fd02a28d98f1bc23f8a0 and Integration 9030b217c490db6ad3ec60a799cb025eccbfcdb1 implement and exercise the immediate owned invocation boundary. The allocation-free shared codecs and shim preserve exact return metadata, including a retained draining owner on failed submission. The Kernel checks fresh complete user mappings and packet framing under one lifecycle guard before native effects. No user pointer or caller-selected identity is retained. Destination capacity and descriptive receipt capacity are independent; spare capacity acquires no authority and repeated collection cannot duplicate transfers. Existing numeric binding hints still recheck live capabilities on every use. The real three-process CPL3 scenario passes all eight operations, full-span pointer/rights/overflow/reserved-field rejection, actual returned selectors, payload/capability/origin checks, collection after server exit and repeated receipts. A second request rejects premature relinquishment, enters draining on caller release and retires only after the exact server acknowledgment. Current signed owned and unchanged older lifetime images are each 2,232,320 bytes, with SHA-256 588c6097c57ebd2ed92e0f0b76f2b1ad6b82630b4a0da272ee98e218eb8e333d and 8f9026aaefd2c5a745e35467ac01c71789c5f469f9cd42a477f87818747ee673 respectively. Both runs have clean teardown and empty QEMU stderr. Ordinary images contain neither diagnostic hook. Strict default/all development/release host, freestanding and rustdoc matrices pass: IPC 368 units, shim 20, capability ABI 191, Kernel 642/666 and Integration 320/321. Existing ignores remain one shim and three Kernel tests. All 162 maintained Integration helper commands pass; three prior correct concurrent-run lock refusals are retained and their sequential checks pass on unchanged executable inputs. Docs 46da7a4cb4d38a2bea5b5491a68f51f33e4b4305 publishes the normative register/packet contract and regenerates the three affected API references from original signed revisions. All 45 documentation tests pass. The complete 2,363-page manual has zero final warnings, 430,365 word boxes within page bounds and reviewed changed ABI/API pages. Shared IPC CI 337/338 and capability ABI CI 214/215 pass with eight complete warning-free logs. Both Kernel revisions pass CI 556/557 and 558/559 with eight complete warning-free logs. Those cohorts are stopped. Current Docs CI 867/868 passes at observation four; four complete logs total 758,328 bytes. Both 2,363-page manuals pass all 45 tests, report normal reference-pass warnings of 32/1/0, and finish with zero warnings or box diagnostics. Its cohort is stopped. Current full Integration 1621/1622 is waiting. Older full Integration 1613/1614 now passes all 486 catalog scenarios and later native/console probes, with six complete warning-free logs; its cohort is stopped. Older 1615/1616 is running, and 1617/1618 plus 1619/1620 are waiting. Current full-suite acceptance remains open, as does the intermittent quota cause in Integration issue 18. This checkpoint supersedes the earlier pending wire/CPL3/manual status. Reachable backend disposal-failure coverage, broader revocation/generation-reuse scenarios, producer adoption, realm runtime, complete authority/inline-documentation audits and both full EriX-in-EriX build generations remain open. The current inventory checks 76 repositories, 2,943 code files below 1,000 lines and 157 crate roots with direct missing_docs gates; it does not establish semantic audit closure. No complete guest build or guest performance result is claimed.

Process-bound native acceptance — 15 September 2026: Signed Kernel 60da5858d7198185efd103f0e91e5ac2e0b63e67 implements control operation 52, checking the actual moved install grant against expected process/generation with exact rights, including zero, under existing endpoint policies. Signed Procd f1105706cc19ed024a6cca79a29abc57c90c6661 uses this operation in its actual ordinary launch-description producer while retaining the narrow SEND receipt, pending state and exact failure cleanup. IPC c453b697b8cdb9cc1c36f1ad89ff868648190025, capability ABI fe8d558253ad01301b99554e20d287c4ea35bb1d and five aligned helper commits preserve original Git/type identity. Integration 58c925c564b69bebce8df6f3e75a9312824e18c4 passes the expanded lifetime CPL3 scenario with thirteen actual control calls, user-side reply checks, two staged children and full added-custody disposal. The corrected lifetime image SHA-256 is 8e6a9e8f68b90cc1ede61300958cec122b82a7c6dfd6318a51e40fefc7ba166e; the unchanged owned-invocation scenario also passes with image SHA-256 b76a380d3cd6b03b0ff61a3b626ace0667679920684ad7356a1c3a36e2224953. Both have clean teardown and empty QEMU stderr. The initial fixture setup-order failure is retained and corrected in Kernel issue #14. All strict default/all development/release matrices pass: IPC 371, shim 20, capability ABI 191, Kernel 648/672 including standalone controls, Procd 227/232 including auxiliary binaries, and Integration 320/321 tests. Existing native-only ignores are unchanged. Procd passes forty native binary builds with repository linker scripts. All 162 Integration helpers pass after updating the exact policy assertion to require the new marker; its initial mismatch remains recorded. Docs b0fcf0f43af2af741d520a0b1373cc346e08863c updates the native wire/ownership contract, operation registry, Procd boundary and three generated shared APIs. All 45 tests and the complete 2,367-page manual pass, with zero final warnings, 431,138 word boxes within page bounds and four reviewed protocol/API pages. Current IPC 339/340, capability ABI 216/217, Kernel 560/561 and 562/563, Procd 266/267, Docs 869/870 and all five helper push/review CIs pass with complete classified logs and no final warnings. Those component cohorts are stopped. Current full Integration 1623/1624 waits at observation 01. Older full Integration 1615/1616 is running at observation 11; 1617/1618, 1619/1620 and 1621/1622 wait at observations 09, 07 and 04. No pending full suite is counted as passed. Typed realm bootstrap, mediator startup/readiness/configuration/seal, complete consumer image adoption, fair terminal/provider retirement, broader native disposal failures and both full EriX-in-EriX build generations remain open. The new inventory covers 76 repositories, 2,950 code files below 1,000 lines and 158 direct missing_docs crate-root gates; complete inline documentation and whole-codebase authority closure remain open. Prior performance measurements retain their original signed source identities; this checkpoint claims no new timing or guest performance result.

Tracking and rollout

Signed Docs c6b0b677f16cd31cdc7555515729b376d5ff5c52 refreshes the public issue index to all 154 issues, including Integration issue 50, and records the accepted IPC platform manual CI. The two changed Markdown files pass all 45 documentation tests, 55-file Markdown lint, canonical governance/headings and exact public-link inventory checks.

Every manual source, API reference and manual build input remains identical to accepted Docs 87942ea7, whose complete local manual and CI 843/844 pass with zero final warnings. No Rust crate or runtime interface changes in this index/status update. Push CI 845 and PR CI 846 pass at this signed source. Four full logs total 752,638 bytes. Both manual jobs pass 45 tests and converge through 2,325/2,339/2,339 pages with 31/1/0 reference warnings and no final warnings or layout diagnostics. Both 55-file Markdown jobs pass. CI reports a 4,114,917-byte PDF; the artifact was not separately downloaded.

Signed Docs 87942ea7675e2a25fe3bf19f3cac19f9c5d8b1e2 specifies native IPC platform selection and hosted transport refusal, with both IPC API references generated from signed Lib-ipc 805717680d9dfb902216550a111d910807f30d23. All 2,593 ABI and 24 shim public signatures remain unchanged, as do the other 33 reference selections. Compile-target selection, local refusal, native observations and retirement evidence remain distinct.

All 45 documentation tests and 55 Markdown files pass. The complete 2,339-page manual builds in 163.82 seconds with zero final warnings. All 426,697 word boxes fit within page bounds, and three changed pages pass visual review. PDF SHA256 is 3a8e702ecf43066f4b3dde37d22d2a527fdce810bfe7e7b43f5f4912c020a6c5. Canonical governance, document headings, links, generated references and whitespace checks pass. Docs has no Cargo crate; the selected IPC source passes its strict matrix and CI 335/336.

Push CI 843 and PR CI 844 pass at this signed source. Four complete logs total 752,618 bytes. Each manual job passes 45 tests and converges through 2,325/2,339/2,339 pages; 31 first-pass and one second-pass reference warnings resolve, leaving zero final warnings and no layout diagnostics. Both Markdown jobs pass all 55 files. CI reports a 4,114,917-byte PDF; its artifact bytes were not independently inspected. The separate local PDF geometry and visual checks pass. Earlier native lifetime and runtime namespace documentation remains accepted at Docs 17b4d52a with CI 841/842. Realm adoption, separate operation-completion contracts, the whole-codebase audit and both full EriX-in-EriX builds remain open.

Signed Docs 17b4d52a9a84e0803746e3a38eb34f070bfb28a4 documents the accepted isolated native lifetime fixture and the Bootloader runtime-symbol namespace boundary. The diagnostic uses actual CPL3 owners, ordinary exit and Process-endpoint kill, exact alias/event witnesses and an explicit typed kernel-only reporter. Rust v0 defining-path recognition preserves the existing runtime namespace and exact authenticated export checks. The public coordination index contains all 153 current issues, including the three observed diagnostic/build defects.

All 45 documentation tests and 55 Markdown files pass locally. The complete 2,339-page manual builds in 164.50 seconds with zero final warnings. All 426,453 word boxes fit within page bounds; changed pages 65 and 162 pass visual review. PDF SHA256 is 2b5df3bb6edb8cbc6e667c798148c73f46a0170fc6abec7cb04615f158cf58af. Existing generated API references and renderer code are unchanged. Docs contains no Cargo crate; Rust behavior is validated in its owning repositories.

Push CI 841 and PR CI 842 pass for this signed source. Four complete logs total 752,178 bytes. Each manual job passes 45 tests and converges through 2,325/2,339/2,339 pages: 30 first-pass and one second-pass reference warnings resolve, with zero final warnings or layout diagnostics. Both Markdown jobs pass all 55 files. CI reports a 4,113,243-byte PDF; its bytes and geometry were not independently inspected. The separate local whole-PDF and two-page visual review passes. The earlier syscall/API checkpoint 28b44183 already passes CI 839/840. Kernel 03e13a78 passes CI 528/529 and Bootloader e7fa3935 passes CI 135/136; the coordinated Integration 4b65755f native VM passes the required exit and ordered unique markers. Realm adoption, provider/pending-operation completion, the full audit and both complete builds inside EriX remain open.

Current signed Docs 28b44183368c512da9c5b804f570ff497ae3b6fc passes push CI 839 and PR CI 840, completed by 08:14:56 UTC on September 14. Four complete logs total 752,154 bytes and correlate with the original workflow and build scripts. Each manual job passes 45 tests and finishes at 2,339 pages with zero final warnings; thirty first-pass and one second-pass convergence warnings resolve. Both Markdown jobs check 55 files with zero errors. CI logs report a 4,111,798-byte PDF; its artifact bytes and geometry were not independently inspected. The separate local full-PDF and five-page visual review passes. This closes renderer issue #7 only; native VM, realm producer, full audits and guest self-hosting remain open.

Signed Docs 28b44183368c512da9c5b804f570ff497ae3b6fc documents native local lifetime revocation and corrects the opaque named-field renderer (#7). Fresh original-source IPC/shim references preserve every old signature and add only the syscall assignment and safe wrapper. All 45 Docs tests, both generation checks, 55 Markdown files, canonical governance/headings/links and the 150-issue index pass. The full 2,339-page manual builds in 165.44 seconds with zero final warnings; all 426,181 word boxes fit and five selected pages pass visual review. Push CI 839 and PR CI 840 both pass as recorded above. Native VM, realm producer, complete audits and both full build generations inside EriX remain open.

  • Parent work: erix/integration#2 and #1.
  • Branch: feature/posix-compat; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages.
  • Baseline revision: 3beaff9142b46e5fdb1a4245aa629a90f0735b69; refresh component/dependency heads and their own CI evidence as implementation advances.
  • Cross-repository dependencies remain full lowercase commit hashes; update the selected graph deliberately. This issue does not authorize merges, release tags or replacement of published images.
## Problem and motivation This issue tracks continuous Phase 6 audit closure for `docs`. Maintain cross-component specifications, generated library API references, the TeX technical manual and their build/publication tooling. An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance. ## Proposed behavior and scope Current targets: no Cargo targets. Validate the maintained scripts, workflow/templates and their tests; record Rust-only checks as individually not applicable with evidence. There is no Cargo target. Review the API-reference generator, manual build/publication scripts, test fixtures and CI input/output ownership. Tie runtime capability and feature statements to their owning component evidence; justify each non-applicable runtime dimension separately. ## Authority, security and reliability Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption. ## Acceptance criteria - [ ] Record origin, recipient, object, operations, delegation ceiling, lifetime and aliases for each relevant capability or caller-supplied authority-bearing value. - [ ] Audit ambient discovery/selectors, cwd/PATH/environment, numeric identities, inherited routes and host fallbacks; require explicit authorized intake. - [ ] Account for residual authority after success, error, cancellation, timeout, restart, failed transfer and teardown, including fork/exec where implemented. - [ ] Remove unnecessary endpoints, broad rights, duplicate aliases, provider/admin grants and debug routes. - [ ] Exercise stale generations, replay, pending replies, forged descriptive identity and object/path resolution races at the owned boundary. - [ ] Prove independent cleanup attempts and caller-specific error precedence; quarantine or terminate when retained authority cannot be accounted for. - [ ] Review unsafe/FFI/parser/arithmetic/lifetime/lock/publication invariants and add adversarial coverage where practical. - [ ] Inventory obsolete APIs, wrappers, fallback/dead paths and duplicate validators with their maintained callers. - [ ] Migrate callers and delete deprecated contracts/shims in a coherent signed revision graph; reject retired input versions where relevant. - [ ] Classify each size/count/depth/time bound as ABI, hardware, explicit resource policy or accidental limitation. - [ ] Test beyond removed boundaries and at allocation/ABI limits while preserving exhaustion errors, denial-of-service controls and bounded waits. - [ ] Keep every tracked authored code/test/script/workflow file below 1000 physical lines through thematic refactoring. - [ ] Run the deterministic tracked-source size gate, covering executable fixtures/generators and excluding only genuine non-code data or external payloads. - [ ] Audit production/test feature and symbol separation, including this repository's effect on rootd test orchestration. - [ ] Supply changes affecting rootd semantic surface to the maintained same-toolchain baseline; record a justified component-specific applicability result. - [ ] Check bootstrap ownership and development/release authority parity at this repository's producer/consumer boundary. - [ ] Use maintained [integration#3](https://git.erikinkinen.fi/erix/integration/issues/3) profiler evidence before optimizing; preserve live access checks, ownership and success criteria. - [ ] Audit build/CI inputs, secret handling, private outputs, symlink containment, deletion, subprocess bounds, warnings and host dependencies. - [ ] meaningful public/private inline documentation, crate/target `missing_docs` enforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate. - [ ] Validation: Run maintained Python/shell/template/Markdown tests and checks where present. For docs, regenerate the affected API references and build the full TeX manual with no warnings, errors or overflows; inspect changed rendered pages. Do not report absent Rust targets as passed Rust validation. - [ ] Documentation: update applicable README/ARCHITECTURE/ROADMAP in meta's canonical format and affected technical-manual TeX/API references; keep README evergreen and shared governance byte-identical to meta. - [ ] Evidence: record exact source/dependency revisions, commands, configurations, real exit status, CI run URLs and results; repeat the audit on final heads and obtain independent review of security closures. No skipped/pending/predecessor result counts as a pass. ## Alternatives and tradeoffs Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed. Validation checkpoint — 14 September 2026: Signed Docs `013ec09aafd9412990fec8231ceb73e7d1a1c94f` records all 156 public issues. All 45 documentation tests and 55 Markdown files pass. Manual/API/build inputs remain byte-identical to the preceding accepted source. CI [847](https://git.erikinkinen.fi/erix/docs/actions/runs/847) and [848](https://git.erikinkinen.fi/erix/docs/actions/runs/848) pass with four complete logs totaling 752,642 bytes. Both manual jobs converge through 2,325/2,339/2,339 pages and 31/1/0 reference warnings, with no final layout warnings. The reported PDF is 4,114,917 bytes; no CI artifact bytes were downloaded. Validation checkpoint — 14 September 2026: Signed Posixd `52ef820d33399490c121aad3af1409139e4a8f44` selects the proposed realm custody owner: Procd deposits an ancestor SEND-lineage revoker into its exact native generation before export and retains a nested guard for earlier realm retirement. Exported aliases descend from the nested guard; ancestor-only bypass and setup aliases must be removed before publication. Kernel supplies the existing terminal trigger; children, provider leases, receiver aliases and pending operations retain separate owners and acknowledgments. This is a documented design; Posixd has no executable crate or implemented realm handshake. Posixd CI [5](https://git.erikinkinen.fi/erix/posixd/actions/runs/5) and [6](https://git.erikinkinen.fi/erix/posixd/actions/runs/6) pass with complete warning-free logs. Signed Docs `d9bb106b94deb7c2af620775dc98be0cc46ae704` updates the process-services manual and records the separate [owned invocation design](https://git.erikinkinen.fi/erix/kernel/issues/11). All 45 Docs tests and 55 Markdown files pass. The 2,341-page local manual has zero final warnings; 426,812 word boxes fit page bounds and the changed page was visually reviewed. Docs CI [849](https://git.erikinkinen.fi/erix/docs/actions/runs/849) and [850](https://git.erikinkinen.fi/erix/docs/actions/runs/850) pass; their manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with no final layout warning. All six complete Posixd/Docs job logs total 760,808 bytes. Runtime producer adoption, realm byte I/O and both complete guest build generations remain open. Allocator validation checkpoint — 14 September 2026: Signed Docs `5b171773c78938b78d0b6d9865d50ece8535682f` records all 158 public issues. All 45 documentation tests, Markdown and heading checks pass. Rendered manual/API/build inputs are unchanged from the accepted realm manual. CI [851](https://git.erikinkinen.fi/erix/docs/actions/runs/851) and [852](https://git.erikinkinen.fi/erix/docs/actions/runs/852) pass with four complete logs totaling 753,560 bytes. Both manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with no final layout warning. Static inventory covers 76 repositories and 2,890 code files below 1,000 lines; all 92 library/binary and 62 additional standalone test/example/bench/build-script roots directly gate missing_docs. This does not establish private-documentation quality or whole-authority closure. Endpoint construction checkpoint — 14 September 2026: Signed Docs `e923440acecfe775ed71a4f046b8e7daa3d25447` documents explicit endpoint construction and the proposed request/result custody obligations. All 45 documentation tests and canonical Markdown/structure checks pass. The local 2,341-page manual has zero final warnings; all 426,861 word boxes fit the pages and changed page 183 is visually reviewed. CI [853](https://git.erikinkinen.fi/erix/docs/actions/runs/853)/[854](https://git.erikinkinen.fi/erix/docs/actions/runs/854) passes with four complete logs totaling 753,568 bytes. Both manual jobs converge through 2,327/2,341/2,341 pages and 32/1/0 reference warnings, with zero final layout warnings. All 158 public issues remain indexed. Completed CI checkpoint — 15 September 2026: Signed Integration `a869a81eb406a4f027a2b5db573b6330ca114d94` passes both [1607](https://git.erikinkinen.fi/erix/integration/actions/runs/1607)/[1608](https://git.erikinkinen.fi/erix/integration/actions/runs/1608); signed endpoint-construction checkpoint `989d44d604d07c4c9bcc23264912bdf2076b99eb` passes both [1609](https://git.erikinkinen.fi/erix/integration/actions/runs/1609)/[1610](https://git.erikinkinen.fi/erix/integration/actions/runs/1610). Each run reports all 486 distinct VM scenarios passing, followed by the actual native lifetime scenario, physical/serial interactive checks and all four console modes. Rust and Markdown pass. The two six-log cohorts contain 26,769,289 and 26,769,316 bytes respectively, with zero warning candidates. The previously observed intermittent quota timeout remains documented without a causal-fix claim. These results establish the selected source checkpoints, not owned invocation transport, complete authority closure or either full in-EriX build generation. Native transfer preparation checkpoint — 15 September 2026: Signed Docs `0fe830c906bc95255d4be18413b0c054bf224e0c` documents complete native transfer preparation and the pre-delivery rollback serialization boundary. All 45 documentation tests and canonical Markdown/structure checks pass. The complete 2,341-page manual has zero final warnings; all 426,948 word boxes fit the pages and changed page 144 is visually reviewed. Docs CI [855](https://git.erikinkinen.fi/erix/docs/actions/runs/855)/[856](https://git.erikinkinen.fi/erix/docs/actions/runs/856) passes with zero final warnings; intermediate reference passes converge through 32/1/0 warnings. All 158 public issues remain indexed. Generated API/build inputs are unchanged. This implements preparation for the current IPC path. Its private records cannot survive userspace scheduling and own no retained source authority. Persistent request/result bytes and capability custody, exact delivery state and terminal hooks remain unimplemented under [Kernel issue 11](https://git.erikinkinen.fi/erix/kernel/issues/11). No opcode, wire record, bootstrap-frame escrow eligibility or application-cancellation semantics are assigned. Native invocation custody checkpoint — 15 September 2026: Signed Docs `76b657ad8b8ba8df7f55f17ce739301a80d22802` indexes all 159 public issues, including the canonical fixture bug report. The native custody manual checkpoint `073da485626c3d74f68d0beb2da47ac8400c23d3` passes CI [857](https://git.erikinkinen.fi/erix/docs/actions/runs/857)/[858](https://git.erikinkinen.fi/erix/docs/actions/runs/858): 45 tests, 2,343 pages and zero final warnings after 32/1/0 reference convergence. Local layout review checks all 427,174 word boxes within page bounds and visually reviews changed page 144. The later index-only checkpoint passes all 45 tests and changes no manual or generated API/build input. Corrected signed-head Kernel CI [548](https://git.erikinkinen.fi/erix/kernel/actions/runs/548)/[549](https://git.erikinkinen.fi/erix/kernel/actions/runs/549) and Docs [859](https://git.erikinkinen.fi/erix/docs/actions/runs/859)/[860](https://git.erikinkinen.fi/erix/docs/actions/runs/860) pass. All 8 complete logs total 1,413,966 bytes, with zero final warnings. The terminal cohort is classified. The syscall wire adapter, fresh userspace buffer/fault/overlap validation, authenticated caller-origin delivery fields and actual CPL3 owned-invocation peers remain unimplemented. Reachable backend disposal-failure coverage, sustained invocation-workload profiling, realm producer adoption, whole-codebase authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire record is assigned; the existing CALL/RECV/REPLY ABI is unchanged. Authenticated delivery-origin checkpoint — 15 September 2026: Signed Docs `c728670ccc57a1c200b1bfc2ebb359920c1a2256` updates the technical manual and roadmap with the origin/liveness/authority distinction. All 45 tests pass; the complete 2,343-page manual has zero final warnings, all 427,252 word boxes within page bounds, and visual review of changed pages 144/145. CI reference passes converge through 32/1/0 warnings. The public index retains all 159 issues; no new issue is introduced by this slice. Kernel CI [550](https://git.erikinkinen.fi/erix/kernel/actions/runs/550)/[551](https://git.erikinkinen.fi/erix/kernel/actions/runs/551) and Docs [861](https://git.erikinkinen.fi/erix/docs/actions/runs/861)/[862](https://git.erikinkinen.fi/erix/docs/actions/runs/862) pass. All eight complete logs total 1,414,891 bytes, with zero final warnings; the cohort is classified and stopped. The separate earlier fixture correction remains closed in [Kernel issue 13](https://git.erikinkinen.fi/erix/kernel/issues/13), preserving original CI 546/547 and corrected 548/549. Sustained invocation-workload profiling, syscall wire and fresh-buffer/fault/overlap validation, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm producer adoption, whole authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire layout is assigned. Native progress and cleanup still do not certify application cancellation. Native invocation profiling baseline — 15 September 2026: Signed Kernel `6cb703e1ed8b9de0d29a37189cd914cd501e732e` provides an actual-object host workload for queued progress, collected progress, descriptive result reads and complete request/result cycles. Signed Integration `f3e4359b34cb8f7db732fbf38823f722553c86d4` adds bounded capture, raw-evidence report verification and equivalent comparisons. Every sample checks exact bytes and SEND capability bindings, authenticated origin, foreign selection, duplicate completion refusal, FIFO position reuse, one-time collection and final invocation disposal. Source and executable bytes are observed against explicit original identities; compiler/host relationships remain declarations. Workload children and source Git reads receive minimal environments; capture owns memory, time, output and process cleanup. Completion is published only after deadline teardown succeeds. The operator guide and signed Docs `644273a0edd91e4c38dcd4418d6ae1119ff1f10b` describe these boundaries. Kernel strict default/all development/release checks pass 632/656 units plus three standalone controls, three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. Integration passes all 161 helper commands, including 19 profiler controls and nine source-provenance controls, plus fresh strict 320/321-unit Rust matrices, private rustdoc and warning-free target builds. Four original socket-fixture failures are retained and attributed to the selected temporary directory exceeding the host Unix-socket path domain; a shorter explicit private directory passes the same fixtures. Docs passes 45 tests and renders 2,345 pages with zero final warnings; 427,592 word boxes fit page bounds and changed pages 2284/2285 pass visual review. Kernel CI 552/553 and Docs CI 863/864 pass; eight complete logs total 1,431,762 bytes with zero final warnings after manual reference convergence. No Kernel performance algorithm has changed in this baseline. Native syscall adapters, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The 76-repository inventory has 2,923 code files below 1,000 lines and 155 direct missing_docs crate-root gates; this does not close the semantic audits. Measured native invocation lookup refinement — 15 September 2026: Signed Kernel `8349d68636382cc7e25a3347f5f1df216554203a` retains only numeric carrier-search positions. Every use rechecks the actual CSpace capability type/rights, live endpoint identity and exact binding; stale positions take the complete search path. No successful authorization, capability or reference is cached. Draining scans fix their boundary on the first poll, visit each position at most once, skip busy stack owners and return exclusive custody after unlocking. Native disposal and first-failure retention preserve their existing semantics. Signed Integration `108501cf7ec20f05dd3d62ea401ea8adad6c6e9c` selects this Kernel in its isolated native catalog, and signed Docs `f10a1d375a326543ec0adda4569bc7cb4faca9b6` documents the invariants. The existing syscall ABI and ordinary image catalog are unchanged. All 15 actual-object native controls pass, including real alias compaction, rights/type/object replacement, busy ownership and allocation-free settlement. The unchanged four-mode workload control also passes. Full strict default/all development/release Kernel matrices pass 634/658 units plus three standalone controls, with three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. The existing native lifetime and entry-argument VM passes unchanged oracles in 21.978041 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its signed boot image is 2,207,744 bytes, SHA-256 `4030cdfb8a13c000ff4716ecdc5203cb46273d6117a282f7375f25dccbbeedc9`. Exact unchanged Integration Rust/helper bytes preserve the preceding strict 320/321-unit matrices and all 161 helper-command results; changed catalog/scenario policies pass. Docs passes all 45 tests and a complete 2,345-page render with zero final warnings, 427,679 bounded word boxes and visual review of page 145 plus continuation page 146. The original signed Kernel `6cb703e1ed8b9de0d29a37189cd914cd501e732e` and the new signed Kernel use byte-identical workload sources, the same selected CPU/toolchain/context and explicit limits, distinct source targets, four modes, populations 0/32/128/512 and 256 operations per sample. Each capture retains 48 measured samples and 16 warmups; every sample passes actual semantic and native/process-cleanup checks. At population 512, median queued-progress cost changes from 117.578 to 37.673 microseconds (3.12x observed ratio), and full-cycle cost from 1167.847 to 443.055 microseconds (2.64x). Collected progress changes from 8.928 to 6.015 microseconds and descriptive reads from 9.124 to 6.212 microseconds. Timings include fixed checks, with no subtracted overhead or timing-ratio pass gate. No managed build/test workload runs concurrently during capture; external host scheduling remains unisolated. These are host operation wall times, not guest startup/build acceptance or a statistical guarantee. Kernel CI 554/555 succeeds; four complete logs total 679,280 bytes with no warnings, and its completed cohort is stopped. Docs CI 865/866 succeeds at observation three; four complete logs total 754,424 bytes, all 45 tests pass and each manual has 2,345 pages. Its normal reference passes report 32/1/0 warnings, with zero final warnings and no box diagnostics. The completed Docs cohort is stopped. Integration CI 1619/1620 is waiting at its first observation. Older Integration 1613/1614 is running; 1615/1616 and 1617/1618 are waiting. Accepted older Integration 1611/1612 passes all 486 catalog scenarios and later probes with complete warning-free logs. This does not establish the intermittent quota cause tracked in Integration issue 18. Current full-suite CI remains required; stopped cohorts are not polled again. Owned syscall wire adapters, actual owned CPL3 peers, fresh-buffer validation, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The refreshed 76-repository inventory has 2,924 code files below 1,000 lines and 155 direct missing_docs crate-root gates; those checks do not close whole-codebase semantic audits. Owned invocation wire and native acceptance — 15 September 2026: Signed Kernel `5f497adaefa526108a0439e0e071717dddb85334`, shared IPC `de968da19898bef532ddb3b5974bb9562f51dee5`, capability ABI `a001a26f0eb3aebec3f5fd02a28d98f1bc23f8a0` and Integration `9030b217c490db6ad3ec60a799cb025eccbfcdb1` implement and exercise the immediate owned invocation boundary. The allocation-free shared codecs and shim preserve exact return metadata, including a retained draining owner on failed submission. The Kernel checks fresh complete user mappings and packet framing under one lifecycle guard before native effects. No user pointer or caller-selected identity is retained. Destination capacity and descriptive receipt capacity are independent; spare capacity acquires no authority and repeated collection cannot duplicate transfers. Existing numeric binding hints still recheck live capabilities on every use. The real three-process CPL3 scenario passes all eight operations, full-span pointer/rights/overflow/reserved-field rejection, actual returned selectors, payload/capability/origin checks, collection after server exit and repeated receipts. A second request rejects premature relinquishment, enters draining on caller release and retires only after the exact server acknowledgment. Current signed owned and unchanged older lifetime images are each 2,232,320 bytes, with SHA-256 `588c6097c57ebd2ed92e0f0b76f2b1ad6b82630b4a0da272ee98e218eb8e333d` and `8f9026aaefd2c5a745e35467ac01c71789c5f469f9cd42a477f87818747ee673` respectively. Both runs have clean teardown and empty QEMU stderr. Ordinary images contain neither diagnostic hook. Strict default/all development/release host, freestanding and rustdoc matrices pass: IPC 368 units, shim 20, capability ABI 191, Kernel 642/666 and Integration 320/321. Existing ignores remain one shim and three Kernel tests. All 162 maintained Integration helper commands pass; three prior correct concurrent-run lock refusals are retained and their sequential checks pass on unchanged executable inputs. Docs `46da7a4cb4d38a2bea5b5491a68f51f33e4b4305` publishes the normative register/packet contract and regenerates the three affected API references from original signed revisions. All 45 documentation tests pass. The complete 2,363-page manual has zero final warnings, 430,365 word boxes within page bounds and reviewed changed ABI/API pages. Shared IPC CI 337/338 and capability ABI CI 214/215 pass with eight complete warning-free logs. Both Kernel revisions pass CI 556/557 and 558/559 with eight complete warning-free logs. Those cohorts are stopped. Current Docs CI 867/868 passes at observation four; four complete logs total 758,328 bytes. Both 2,363-page manuals pass all 45 tests, report normal reference-pass warnings of 32/1/0, and finish with zero warnings or box diagnostics. Its cohort is stopped. Current full Integration 1621/1622 is waiting. Older full Integration 1613/1614 now passes all 486 catalog scenarios and later native/console probes, with six complete warning-free logs; its cohort is stopped. Older 1615/1616 is running, and 1617/1618 plus 1619/1620 are waiting. Current full-suite acceptance remains open, as does the intermittent quota cause in Integration issue 18. This checkpoint supersedes the earlier pending wire/CPL3/manual status. Reachable backend disposal-failure coverage, broader revocation/generation-reuse scenarios, producer adoption, realm runtime, complete authority/inline-documentation audits and both full EriX-in-EriX build generations remain open. The current inventory checks 76 repositories, 2,943 code files below 1,000 lines and 157 crate roots with direct missing_docs gates; it does not establish semantic audit closure. No complete guest build or guest performance result is claimed. Process-bound native acceptance — 15 September 2026: Signed Kernel `60da5858d7198185efd103f0e91e5ac2e0b63e67` implements control operation 52, checking the actual moved install grant against expected process/generation with exact rights, including zero, under existing endpoint policies. Signed Procd `f1105706cc19ed024a6cca79a29abc57c90c6661` uses this operation in its actual ordinary launch-description producer while retaining the narrow SEND receipt, pending state and exact failure cleanup. IPC `c453b697b8cdb9cc1c36f1ad89ff868648190025`, capability ABI `fe8d558253ad01301b99554e20d287c4ea35bb1d` and five aligned helper commits preserve original Git/type identity. Integration `58c925c564b69bebce8df6f3e75a9312824e18c4` passes the expanded lifetime CPL3 scenario with thirteen actual control calls, user-side reply checks, two staged children and full added-custody disposal. The corrected lifetime image SHA-256 is `8e6a9e8f68b90cc1ede61300958cec122b82a7c6dfd6318a51e40fefc7ba166e`; the unchanged owned-invocation scenario also passes with image SHA-256 `b76a380d3cd6b03b0ff61a3b626ace0667679920684ad7356a1c3a36e2224953`. Both have clean teardown and empty QEMU stderr. The initial fixture setup-order failure is retained and corrected in Kernel issue #14. All strict default/all development/release matrices pass: IPC 371, shim 20, capability ABI 191, Kernel 648/672 including standalone controls, Procd 227/232 including auxiliary binaries, and Integration 320/321 tests. Existing native-only ignores are unchanged. Procd passes forty native binary builds with repository linker scripts. All 162 Integration helpers pass after updating the exact policy assertion to require the new marker; its initial mismatch remains recorded. Docs `b0fcf0f43af2af741d520a0b1373cc346e08863c` updates the native wire/ownership contract, operation registry, Procd boundary and three generated shared APIs. All 45 tests and the complete 2,367-page manual pass, with zero final warnings, 431,138 word boxes within page bounds and four reviewed protocol/API pages. Current IPC 339/340, capability ABI 216/217, Kernel 560/561 and 562/563, Procd 266/267, Docs 869/870 and all five helper push/review CIs pass with complete classified logs and no final warnings. Those component cohorts are stopped. Current full Integration 1623/1624 waits at observation 01. Older full Integration 1615/1616 is running at observation 11; 1617/1618, 1619/1620 and 1621/1622 wait at observations 09, 07 and 04. No pending full suite is counted as passed. Typed realm bootstrap, mediator startup/readiness/configuration/seal, complete consumer image adoption, fair terminal/provider retirement, broader native disposal failures and both full EriX-in-EriX build generations remain open. The new inventory covers 76 repositories, 2,950 code files below 1,000 lines and 158 direct missing_docs crate-root gates; complete inline documentation and whole-codebase authority closure remain open. Prior performance measurements retain their original signed source identities; this checkpoint claims no new timing or guest performance result. ## Tracking and rollout Signed Docs `c6b0b677f16cd31cdc7555515729b376d5ff5c52` refreshes the public issue index to all 154 issues, including [Integration issue 50](https://git.erikinkinen.fi/erix/integration/issues/50), and records the accepted IPC platform manual CI. The two changed Markdown files pass all 45 documentation tests, 55-file Markdown lint, canonical governance/headings and exact public-link inventory checks. Every manual source, API reference and manual build input remains identical to accepted Docs `87942ea7`, whose complete local manual and CI 843/844 pass with zero final warnings. No Rust crate or runtime interface changes in this index/status update. [Push CI 845](https://git.erikinkinen.fi/erix/docs/actions/runs/845) and [PR CI 846](https://git.erikinkinen.fi/erix/docs/actions/runs/846) pass at this signed source. Four full logs total 752,638 bytes. Both manual jobs pass 45 tests and converge through 2,325/2,339/2,339 pages with 31/1/0 reference warnings and no final warnings or layout diagnostics. Both 55-file Markdown jobs pass. CI reports a 4,114,917-byte PDF; the artifact was not separately downloaded. Signed Docs `87942ea7675e2a25fe3bf19f3cac19f9c5d8b1e2` specifies native IPC platform selection and hosted transport refusal, with both IPC API references generated from signed Lib-ipc `805717680d9dfb902216550a111d910807f30d23`. All 2,593 ABI and 24 shim public signatures remain unchanged, as do the other 33 reference selections. Compile-target selection, local refusal, native observations and retirement evidence remain distinct. All 45 documentation tests and 55 Markdown files pass. The complete 2,339-page manual builds in 163.82 seconds with zero final warnings. All 426,697 word boxes fit within page bounds, and three changed pages pass visual review. PDF SHA256 is `3a8e702ecf43066f4b3dde37d22d2a527fdce810bfe7e7b43f5f4912c020a6c5`. Canonical governance, document headings, links, generated references and whitespace checks pass. Docs has no Cargo crate; the selected IPC source passes its strict matrix and CI 335/336. [Push CI 843](https://git.erikinkinen.fi/erix/docs/actions/runs/843) and [PR CI 844](https://git.erikinkinen.fi/erix/docs/actions/runs/844) pass at this signed source. Four complete logs total 752,618 bytes. Each manual job passes 45 tests and converges through 2,325/2,339/2,339 pages; 31 first-pass and one second-pass reference warnings resolve, leaving zero final warnings and no layout diagnostics. Both Markdown jobs pass all 55 files. CI reports a 4,114,917-byte PDF; its artifact bytes were not independently inspected. The separate local PDF geometry and visual checks pass. Earlier native lifetime and runtime namespace documentation remains accepted at Docs `17b4d52a` with CI 841/842. Realm adoption, separate operation-completion contracts, the whole-codebase audit and both full EriX-in-EriX builds remain open. Signed Docs `17b4d52a9a84e0803746e3a38eb34f070bfb28a4` documents the accepted isolated native lifetime fixture and the Bootloader runtime-symbol namespace boundary. The diagnostic uses actual CPL3 owners, ordinary exit and Process-endpoint kill, exact alias/event witnesses and an explicit typed kernel-only reporter. Rust v0 defining-path recognition preserves the existing runtime namespace and exact authenticated export checks. The public coordination index contains all 153 current issues, including the three observed diagnostic/build defects. All 45 documentation tests and 55 Markdown files pass locally. The complete 2,339-page manual builds in 164.50 seconds with zero final warnings. All 426,453 word boxes fit within page bounds; changed pages 65 and 162 pass visual review. PDF SHA256 is `2b5df3bb6edb8cbc6e667c798148c73f46a0170fc6abec7cb04615f158cf58af`. Existing generated API references and renderer code are unchanged. Docs contains no Cargo crate; Rust behavior is validated in its owning repositories. [Push CI 841](https://git.erikinkinen.fi/erix/docs/actions/runs/841) and [PR CI 842](https://git.erikinkinen.fi/erix/docs/actions/runs/842) pass for this signed source. Four complete logs total 752,178 bytes. Each manual job passes 45 tests and converges through 2,325/2,339/2,339 pages: 30 first-pass and one second-pass reference warnings resolve, with zero final warnings or layout diagnostics. Both Markdown jobs pass all 55 files. CI reports a 4,113,243-byte PDF; its bytes and geometry were not independently inspected. The separate local whole-PDF and two-page visual review passes. The earlier syscall/API checkpoint `28b44183` already passes CI 839/840. Kernel `03e13a78` passes CI 528/529 and Bootloader `e7fa3935` passes CI 135/136; the coordinated Integration `4b65755f` native VM passes the required exit and ordered unique markers. Realm adoption, provider/pending-operation completion, the full audit and both complete builds inside EriX remain open. Current signed Docs `28b44183368c512da9c5b804f570ff497ae3b6fc` passes [push CI 839](https://git.erikinkinen.fi/erix/docs/actions/runs/839) and [PR CI 840](https://git.erikinkinen.fi/erix/docs/actions/runs/840), completed by 08:14:56 UTC on September 14. Four complete logs total 752,154 bytes and correlate with the original workflow and build scripts. Each manual job passes 45 tests and finishes at 2,339 pages with zero final warnings; thirty first-pass and one second-pass convergence warnings resolve. Both Markdown jobs check 55 files with zero errors. CI logs report a 4,111,798-byte PDF; its artifact bytes and geometry were not independently inspected. The separate local full-PDF and five-page visual review passes. This closes renderer issue #7 only; native VM, realm producer, full audits and guest self-hosting remain open. Signed Docs `28b44183368c512da9c5b804f570ff497ae3b6fc` documents native local lifetime revocation and corrects the opaque named-field renderer (#7). Fresh original-source IPC/shim references preserve every old signature and add only the syscall assignment and safe wrapper. All 45 Docs tests, both generation checks, 55 Markdown files, canonical governance/headings/links and the 150-issue index pass. The full 2,339-page manual builds in 165.44 seconds with zero final warnings; all 426,181 word boxes fit and five selected pages pass visual review. [Push CI 839](https://git.erikinkinen.fi/erix/docs/actions/runs/839) and [PR CI 840](https://git.erikinkinen.fi/erix/docs/actions/runs/840) both pass as recorded above. Native VM, realm producer, complete audits and both full build generations inside EriX remain open. - Parent work: https://git.erikinkinen.fi/erix/integration/issues/2 and https://git.erikinkinen.fi/erix/docs/issues/1. - Branch: `feature/posix-compat`; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages. - Baseline revision: `3beaff9142b46e5fdb1a4245aa629a90f0735b69`; refresh component/dependency heads and their own CI evidence as implementation advances. - Cross-repository dependencies remain full lowercase commit hashes; update the selected graph deliberately. This issue does not authorize merges, release tags or replacement of published images.
erikinkinen changed title from [FEATURE] [P02.R07] Audit authority, code quality and documentation in docs to [FEATURE] Audit authority, code quality and documentation in docs 2026-09-12 08:02:12 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
erix/docs#2
No description provided.