WIP: Document native authority and verify workspace and command evidence #4
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/docs!4
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Document shared compiler metadata consistency, equal-byte reuse, exclusive destination creation and cache ownership across executable and shared-library producers. Provider provenance, source lifetime and scratch cleanup remain explicit caller obligations.
Specify single-driver dynamic linking, exact compiler-host discovery when standalone tools are absent, preserved driver aliases, fatal warnings and visible successful diagnostics. A selected driver failure does not authorize another implementation or publication of partial output.
Document unambiguous Rust runtime archive selection for fresh Kernel, Rootd and service links, including the separate provenance, cache-coverage and toolchain-lifetime obligations. The corresponding implementation is tracked in Integration issue 62.
Document native staged construction, grant custody and authenticated caller
admission; specify owned shell workspaces and exact source/artifact/frame
evidence. Correct the syscall reference and native entry contract: IRETQ return,
the 136-byte saved prefix, 176-byte transient reservation, separate kernel stack,
preserved user flags, aligned exception calls and five/six-word hardware frames.
Document complete borrowed syscall capture, initialized stable storage and
resource refusal before operation dispatch. Render literal command-option
bytes without changing their meaning.
Describe one-way VSpace retirement, recorded withdrawal progress, consumed
frame references and retained final-process custody. Keep that contract separate
from whole-process destruction and ordinary VSpace activation.
Describe process cleanup custody, non-executable abort/destruction states,
retained private CSpace identity and the exact final retirement commit.
Earlier partial cleanup is not represented as whole-process rollback.
Tracking and scope
Signed head
64fc14411a3f1629ace2854ddc1c3b7875113343, branchfeature/posix-compat.Documentation audit #1; command rendering #8; corrected syscall reference #9 and
entry documentation #10. Dependent reviews:
Kernel,
Integration,
Exsh, and
lib-dynlink.
Realm design, runtime acceptance
and both full guest builds remain open.
Architecture, authority and failure behavior
Staged construction omits child root capabilities while retaining native TCB
backing. Procd authenticates the pending caller against its Launchd owner and
generation. Identities and bearer senders cannot replace actual authority;
rejected transfers retain cleanup obligations. Mediator start and sealing are
separate contracts. The manual introduces no runtime capability or ABI change.
Ordinary and emergency I/O own distinct authenticated workspace slices. Cleanup
borrows and erases its complete slice. Paired ELF evidence binds zero-fill
ownership, target layout, stack, bytes and permissions. Mapping evidence cannot
establish source borrowing or all-path safety. Missing proof remains incomplete.
Ordered providers and checked relocation expressions precede protected-slot
admission. Composed graphs retain object-qualified identities and grounded
dependencies. Live caller intervals constrain conditional callee writes while
preserving return-address gaps and invalidating overlapping saves; conditional
masks never become unconditional guarantees. Rejection-only scheduling and
deduplicated CFG work retain proof decisions without arbitrary pass limits.
Static receipts, host profiling, guest probes and full builds have distinct
acceptance requirements.
Validation evidence
The matching signed Docs PR 4,
54557713f4afad380c1166f6aa1c1622d3959744, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original Docs CI 979 and 980 pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required.Native child-custody wire checkpoint — 19 September 2026: signed lib-ipc PR 2,
aaf2df39700b43507b23ff2007bc0d573c4eea30, implementsChildLifetimeBindingV1, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the shared contract and Kernel design #19.Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original lib-ipc CI 365 and 366 pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph.
Native external-toolchain rebuild requirement — 19 September 2026: Signed
b54d28e755dd415079100a19683ee1474edb4ed1makes the native rebuild an explicit Phase 6 verification and acceptance gate. The first compiler may be cross-built for EriX against its libc/sysroot, Rust OS bindings and declared C/C++ runtime closure. The extended development image must then rebuild the selected upstream Rust/LLVM toolchain inside EriX using supplied offline recipes and an explicit bootstrap compiler. Require working guest-built tools and use in at least one full EriX build, with no unrecorded porting changes, downloads, Linux executables or host build delegation. Complete source, runtime, log and measured-resource evidence is required; compiler ownership remains distinct. All 45 documentation tests and the full 2,419-page manual pass, with 445,775 in-bounds word boxes, actual visual review of the changed page and zero final warnings. Shared API snapshots are unchanged. The phase master, toolchain issue and full-build issue contain the matching requirements. Original documentation CI is under observation; the native toolchain rebuild and both OS builds remain unproven.Original coherent realm source CI acceptance — 18 September 2026: Signed
33733ceba228669e27152aee32f997d6c72264ffpasses CI 972 and CI 971. All four terminal logs are complete (772,194 bytes), with zero final warnings. This closes the original CI observation recorded above. All 45 tests and both 2,419-page manuals pass; reference-pass warnings converge 36/1/0. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Realm startup consumer manual checkpoint — 18 September 2026: Signed
33733ceba228669e27152aee32f997d6c72264ffdescribes exact realm startup consumers, explicit disabled or positive deployment capacity and the reviewed Rootd production audit. All 45 tests and the complete 2,419-page manual pass, with 445,650 word boxes within page bounds, two visually reviewed changed pages and zero final warnings. Shared API snapshots are unchanged. Original CI 971/972 is under observation. Coherent catalog adoption and actual consumer VMs remain required before image acceptance; no runnable realm or full guest build is claimed.Original public realm dispatch manual CI acceptance — 18 September 2026: Signed Docs
099f0c570414ca486bb2104c1510fbf3b84d59fbpasses CI 969 and CI 970. All four terminal logs are complete (772,182 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Public realm dispatch and progress checkpoint — 18 September 2026: Signed
099f0c570414ca486bb2104c1510fbf3b84d59fbis pushed. The manual describes public realm intake, independently held replies, original-parent cleanup and fair native progress before ordinary dispatch, while preserving separate consumer VM and guest-build acceptance. All 45 tests and the complete 2,419-page manual pass. All 445,563 word boxes are within page bounds; both changed rendered pages are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI is under observation; no runnable realm or guest build is claimed.Original exact preparation manual CI acceptance — 18 September 2026: Signed Docs
880bdc59818b1eff9cf9929004680f354f8265a0passes CI 967 and CI 968. All four terminal logs are complete (772,086 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Exact realm executable preparation checkpoint — 18 September 2026: Signed
880bdc59818b1eff9cf9929004680f354f8265a0is pushed. The manual documents actual exact preparation, shared authentication, scratch reuse and independent retained cleanup, while keeping dispatcher, scheduler and consumer-image requirements open. All 45 tests and the full 2,419-page manual pass; all 445,389 word bounds and both changed rendered pages are reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI 967/968 is under observation. Complete mediated execution and both full builds inside EriX remain required.Original realm admission manual CI acceptance — 18 September 2026: Signed Docs
9868cf0e6f2c366b4a2c7992594a83c72789f1f0passes CI 965 and CI 966. All four terminal logs are complete (771,742 bytes), all 45 tests pass and both complete 2,417-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Caller-bound realm record checkpoint — 18 September 2026: Signed
9868cf0e6f2c366b4a2c7992594a83c72789f1f0is pushed. The manual describes exact realm admission messages, original-caller binding, explicit LCH1 version-3 capacity and independent native storage. Four API references select the signed shared graph; stale bootstrap width, version and route-stride prose is corrected. All 45 tests, API provenance/regeneration checks and the complete 2,417-page manual pass. All 445,195 word bounds are valid, seven rendered pages were reviewed and final warnings are zero. Original CI 965/966 is under observation. Actual runtime admission, coherent image consumers, mediated client I/O and both full guest builds remain open.Original retained caller manual CI acceptance — 18 September 2026: Signed Docs
4dcbc10e32ebf257139bcbaf07bc1081b9589780passes CI 963 and CI 964. All four terminal logs are complete (770,022 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Retained realm caller checkpoint — 18 September 2026: Signed
4dcbc10e32ebf257139bcbaf07bc1081b9589780is pushed. The process-service manual describes the retained native caller, permanent source absence, cancellation ordering and independent child retirement. All 45 tests and the complete 2,409-page manual pass. All 443,468 word bounds are valid, both changed pages were visually inspected and final warnings are zero. No Rust implementation or generated API snapshot changes. Original CI 963/964 is under observation. Runtime admission, scheduler integration, consumer VM proof and both full guest builds remain separate requirements.Original supervisor manual CI acceptance — 18 September 2026: Signed Docs
a410759e5515b18107f25efb0319ad7c85871a64passes CI 961 and CI 962. All four terminal logs are complete (769,994 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Original supervisor manual checkpoint — 18 September 2026: Signed
a410759e5515b18107f25efb0319ad7c85871a64documents private caller attestation, the exact 64-byte materialization begin, original ownership before creation and handoff, and separate caller RELEASE cancellation and application rollback. Three shared API snapshots match original signed source exports. All 45 tests, provenance/regeneration checks and the complete 2,409-page manual pass. All 443,265 word boxes are in bounds; seven rendered pages were inspected and final output has zero warnings. Original CI 961 and CI 962 remain under observation. Actual Launchd owned runtime adoption, consumer VM execution and both full guest builds remain open.Original owned bootstrap manual CI acceptance — 18 September 2026: Signed Docs
5c1cf6da319787738fa03f3cc6f526e49604aa09passes CI 959 and CI 960. All four terminal logs are complete (769,578 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Owned bootstrap receiver checkpoint — 18 September 2026: Signed Docs
5c1cf6da319787738fa03f3cc6f526e49604aa09updates the process-services contract and three source-bound shared API snapshots for the identity-only request and retained native delivery. All 45 tests, three signed API exports, provenance/regeneration checks and the complete 2,407-page manual pass. All 442,920 word boxes are in bounds; seven rendered pages were visually reviewed and final output has no warnings. Original CI 959/960 is under observation. Actual Launchd runtime orchestration, consumer VM execution and both complete guest builds remain open.Original receiver admission manual CI acceptance — 18 September 2026: Signed Docs
8361618f3f047479a9e52ffaba7f2607be99413cpasses CI 957 and CI 958. All four terminal logs are complete (769,554 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Explicit owned receiver admission acceptance — 18 September 2026: Signed
8361618f3f047479a9e52ffaba7f2607be99413c. The manual documents explicit receiver request limits, complete layout addressability, immutable registration and pre-custody refusal, with accurate allocation-observation scope. Three public API snapshots are regenerated from signed shared revisions. All 45 tests, provenance/regeneration checks and the 2,407-page manual pass. All 442,761 word boxes are in bounds; eight changed pages are visually reviewed, with zero final warnings. Original CI is under observation. Actual owned Procd/Launchd service adoption, consumer VM execution, complete realm fairness/readiness/sealing and both full builds inside EriX remain open.Original local grant relocation manual CI acceptance — 18 September 2026: Signed Docs
623609ee627a4afba1340ee06c53678c4a562a88passes CI 955 and CI 956. All four terminal logs are complete (768,754 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Caller-local grant relocation checkpoint — 18 September 2026: Signed
623609ee627a4afba1340ee06c53678c4a562a88documents syscall 0x54 register admission, actual Running caller and unique grant custody, exact error precedence and preserved installation/revocation scope. Three API references are regenerated from signed original shared revisions. All 45 tests, complete provenance/regeneration checks and the 2,403-page manual pass. All 442,370 word boxes are in bounds; nine changed pages are visually reviewed and final warnings are absent. The original whitespace preflight failure and subsequent terminology correction are retained. Original documentation CI is under observation. Actual owned service adoption, consumer VMs, complete realm fairness and both full builds inside EriX remain open.Original deferred-cleanup manual CI acceptance — 18 September 2026: Signed Docs
da66c0efd61fc05be023210e1c0c58196b51b878passes CI 953 and CI 954. All four terminal logs are complete (768,726 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Deferred native cleanup checkpoint — 18 September 2026: Signed Docs
da66c0efd61fc05be023210e1c0c58196b51b878specifies one queued native attempt before intake, exact-generation owner rotation, first-error retention and acknowledgment-based removal. All 45 tests and the complete 2,403-page manual pass, with 441,578 in-bounds word boxes, two changed pages visually reviewed and zero final warnings. Shared API references are unchanged. Original documentation CI is under observation. Runtime consumer VM, complete realm fairness and full guest-build acceptance remain open.Returned-grant manual checkpoint — 18 September 2026: Signed Docs
b6bd8ce32891a8b298228b8320d0565cef89141fdocuments the exact returned-grant request, custody acknowledgment, five retained scratch roles, native guard effects, source-absence requirement and cleanup boundaries. Three API snapshots come from the signed original component revisions; regeneration and provenance checks pass. All 45 tests pass. The complete 2,403-page manual has 441,471 in-bounds word boxes, seven changed pages visually reviewed and zero final warnings. Original CI 951 and CI 952 pass from all four complete logs (768,706 bytes); reference passes converge with 36/1/0 warnings and both final manuals have zero warnings. Runtime realm orchestration, actual consumer VM execution, fair progress and both complete builds inside EriX remain open requirements.Original cleanup manual CI acceptance — 18 September 2026: Signed Docs
323da983653e6d6d25d012c2354f97afaaaa0699passes CI 949 and CI 950. All four terminal logs are complete (767,338 bytes), all 45 tests pass and both complete 2,397-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision
323da983653e6d6d25d012c2354f97afaaaa0699is pushed. The manual documents native cleanup 56/57, retired selectors, exact framing, original deferred identity and pre-service retirement. Three API references are generated from verified signed source revisions. All 45 tests pass. The complete 2,397-page PDF has zero final warnings and 440,339 in-bounds word boxes; seven changed pages have been visually inspected. The testing chapter corrects Rootd audit-size evidence and records the actual native diagnostic scope. Original CI 949/950 remains under observation. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open.Corrected original manual CI — 18 September 2026: Docs
10ea454ebab2cb0ca465cedf52ff619c1fc7efd4passes original CI 947 and CI 948. All four logs are complete (765,634 bytes), all 45 tests pass, and the complete 2,389-page manual has zero final warnings after reference passes of 36/1/0 warnings. The later generation-bound cleanup manual update is still under local validation.Reviewed bootstrap baseline manual — 17 September 2026: Signed revision
10ea454ebab2cb0ca465cedf52ff619c1fc7efd4updates the testing chapter toRootd's reviewed 15,239-line release baseline and exact terminal-operation
ownership. Compiler-specific binary size is explicitly separate from performance
comparison. All 45 documentation tests and the complete 2,389-page manual pass;
there are no final warnings, all 439,184 word boxes are in bounds, and page 2334
was visually reviewed. Earlier original CI 945/946 passes with all four logs
complete (765,650 bytes; reference passes 36/1/0 warnings). The new signed
revision's original CI remains under observation. Complete builds inside EriX
and ordinary service-image adoption remain open.
Coordinated terminal observation checkpoint — 17 September 2026: Signed revision
be98a93e6f34a9c7ecaffabfa0af1c8f209feff3is pushed. The native and process-service manual contracts and three signed-source API snapshots are updated. All 45 documentation tests pass. The complete 2,389-page PDF has zero final warnings and 439,146 in-bounds word boxes; native, service and API pages were visually reviewed, including corrected literal shift operators. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.Current-head push CI 937
and PR CI 938 pass.
All four complete logs are classified: 765,226 bytes, 45 tests, 2,387 pages,
reference-resolution warning counts 36/1/0 and zero final warnings.
All 45 documentation tests, Markdown and canonical document-format checks pass.
The complete manual contains 2,387 pages and 438,174 in-bounds word boxes,
with zero final warnings. Changed page 132 is visually reviewed.
Original cleanup-reference push CI 935
and PR CI 936 pass.
All four complete logs are classified: 765,222 bytes, 45 tests, 2,387 pages,
reference-resolution warning counts 36/1/0 and zero final warnings.
Preceding capture-reference push CI 933
and PR CI 934 pass.
All four complete logs are classified: 765,238 bytes, reference-resolution
warning counts 36/1/0 and zero final warnings. Earlier CI 931/932
passes with four classified logs and zero final warnings.
The earlier syscall and entry-documentation defects (#9/#10) remain closed
after their separately retained successful CI cohorts. Generated API snapshots
and runtime ABI are unchanged by this documentation correction.
No Rust crate is altered in this repository. Runtime and full guest-build
validation belongs to the linked component reviews and is not implied here.
Runtime archive checkpoint — 17 September 2026, signed
cf684745b08b59e0efc98c4b904708d0c17d735d: All 45 documentation tests pass. The complete 2,387-page manual renders with zero final warnings and 438,260 in-bounds word boxes; page 2292 is visually reviewed. No Rust API, runtime code or API snapshot changes in this documentation checkpoint. Original Docs CI 939/940 passes with all four complete terminal logs classified (765,226 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted.Linker selection checkpoint — 17 September 2026, signed
050b9bcc3a5d8e0f57efc62e8775dee10a48af84: All 45 documentation tests pass. The complete 2,387-page manual has 438,385 in-bounds word boxes and zero final warnings. Page 2292 is visually reviewed. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 941/942 passes with all four complete terminal logs classified (765,214 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.Compiler metadata checkpoint — 17 September 2026, signed
64fc14411a3f1629ace2854ddc1c3b7875113343: All 45 documentation tests pass. The complete 2,387-page manual has 438,492 in-bounds word boxes and zero final warnings. The changed paragraph is visually reviewed across pages 2292 and 2293. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 943/944 passes with all four complete terminal logs classified (765,158 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.Review checklist
Original Docs CI 973 and 974, at
b54d28e755dd415079100a19683ee1474edb4ed1, pass. All 45 tests and the complete 2,419-page manual pass; intermediate reference-resolution passes converge to zero final warnings. All four terminal logs are complete and hashed, totaling 772,186 bytes. This validates the native-toolchain rebuild requirement in the phase document and manual, not an actual toolchain or EriX build inside EriX.Signed private-route manual correction — 19 September 2026:
ce8a1538ab2220f1b346e1a051265f58f83f47fcdocuments realm admission through both the public receiver and the shell's authenticated private script route, retaining original reply custody and caller proof. A stale startup-publication paragraph now states the permanent coherent-source and distinct runtime-evidence requirements. All 45 tests and the full 2,419-page manual pass; all 445,834 rendered words are within bounds, revised page 224 has been visually reviewed and final warnings are absent. Shared API snapshots are unchanged. Original CI 975 and 976 are running. Native external Rust/LLVM rebuilding and both full EriX build generations remain required.Original manual CI 975/976 passes from all four complete hashed logs (772,174 bytes): 45 tests, the full 2,419-page manual and zero final-pass warnings. Signed Integration
9139c6c5fa38c139e92520f6d410626b4cf1e4aanow adopts this documentation with the matching corrected-server VM, which passes its unchanged caller-admission scenario. Complete mediator execution, native toolchain rebuilding and both full guest builds remain required.Guarded-custody documentation reconciliation — 19 September 2026: signed Posixd PR 5,
9b031a8c2f996491a322046a4f2acd5dacdc55c2, replaces stale grant-return and proposed-custody gaps with the implemented producer boundary. Procd uses the actual returned grant to attenuate the initial endpoint to RECV before execution, removes bypass sources, and retains nested custody beneath Kernel lifetime custody. A later mediator disposal report cannot prove absence of bypass senders. Exact staged abort and the remaining counted startup, readiness, configuration, sealing, client I/O and running-realm retirement requirements are distinguished. This repository still has no Posixd executable.Markdown, canonical headings/governance, local links, original source anchors and whitespace checks pass. Original Posixd CI 17 and 18 both pass from two complete hashed logs totaling 7,232 bytes without warnings. Rust checks do not apply to this documentation-only repository.
Signed Docs PR 4,
7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d, removes the matching stale passages from the process-services manual. All 45 tests and the full 2,419-page manual pass. All 445,847 word boxes lie within page bounds; the actual changed paragraphs and continuation on pages 222, 226 and 227 are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original Docs CI 977 and 978 are running. These documentation corrections add no runtime behavior; the previously retained Integration78557a6c672ecf426dfe894a01cc4aeec73b5e3cappliance retains its original source selection and passing guarded-preparation evidence. Native upstream Rust/LLVM rebuilding and both complete EriX builds remain required.Original Docs CI 977/978 passes for signed
7b79f8d50a. All four complete hashed logs total 772,186 bytes. Both runs pass 45 tests and the full 2,419-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No unchanged workflow rerun or cancellation supplies this result.Native child lifetime checkpoint — 19 September 2026: Signed Docs
9ca5a5e811updates the technical manual's native admission, preflight, stopping, partial cleanup and safe return/idle contracts. All 45 tests and the complete 2,425-page manual pass with zero final warnings. All 447,213 word boxes are in bounds and all three changed contract pages are visually reviewed. Shared API reference source is unchanged. Original Docs CI 981 and 982 pass from four complete hashed logs, 773,510 bytes. Both pass 45 tests and the complete 2,425-page manual. TeX pass warning counts are 36/1/0, with zero final-pass warnings; neither workflow was rerun or cancelled.The matching original signed Kernel and both maintained native VMs pass without warnings; Kernel issue 19 retains exact runtime evidence and open executing-child, no-successor, further failure and consumer gates. Signed Integration 581226ab5435dc66c6f93157606b6d4d83475b15 selects the coherent original Kernel/lib-capabi/lib-ipc graph and updated manual. All four current strict 320/321-test configurations, four native builds, fmt, strict host/native Clippy and private rustdoc pass without warnings. Source and updated native-policy checks pass; the full 169-helper evidence remains bound to unchanged orchestration bytes. The final post-VM changes select only the newer Docs revision and update roadmap status; native source catalog, scenario, runtime and orchestration bytes are unchanged. Original Integration CI 1683 and 1684 are queued.
Executing-child and terminal-reply checkpoint — 19 September 2026: signed Kernel dd9eace5 validates actual CPL3 nested-child execution and current-child ancestor termination. Synchronous control dispatch now ends its request borrow before effects and checks original caller identity, generation and terminal state before any response write. It keeps terminal completion in Kernel-owned result registers with zero reply length; ordinary native return switches away. A surviving caller retains its normal encoded response. Two focused actual-object regressions cover terminal request preservation and the surviving-caller reply. The dispatcher is split from the tracing/policy file. A supervisor binds and starts a child; that child binds a staged grandchild and kills its supervisor through its own explicit Process SEND route. Read-only witnesses require terminal caller storage to survive dispatch, then exact child/grandchild absence before the independent observer reads child-before-supervisor events. Both terminal payloads have immediate UD2 sentinels. An unrelated Created process retains its exact record, empty capability inventory and mappings until explicitly aborted. All four additional lifetimes and twenty-two mapped pages must be disposed for
ERIX_KERNEL:CHILD_EXECUTION_OK.Four strict Kernel configurations pass 720/744 library tests and both standalone controls; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Signed Integration c14c5a61 requires the additional marker while preserving every earlier marker and the original 60-second limit. Both actual native scenarios pass, with 1,870/1,587 complete serial bytes, empty QEMU stderr and no build warnings. Packaged Kernel bytes equal retained original artifacts after normal stripping; all fifteen original source signatures verify. Lifetime serial SHA256 is
1b2f983239efca55c8bc0f6f08ee91cfdcd37d4d1f6951bbd740e4d9b45d1a2f. Four current Integration 320/321-test configurations, native builds, strict Clippy, formatting, private rustdoc and updated policy checks pass. Earlier 169-helper evidence is hash-verified against unchanged orchestration; it was not rerun for these scenario/catalog changes.Signed Docs b4b01d87 documents the executing-child observations and remaining limits. All 45 tests, the full 2,425-page manual, 447,382 word bounds and visual review of the changed pages pass, with zero final warnings. The API reference source is unchanged.
This extends native executing-child evidence; it does not establish no-successor native idle/wake behavior, provider completion, Procd adoption or a complete service lifecycle. The original install-grant constructor still gives
GRANT | MINTwhile binding needs onlyGRANT; move-only transfer preserves exact rights. Both diagnostic grants are consumed, but rights minimization remains an explicit audit follow-up. Full source/effect/frame proof, the Pagerd gate, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.Related implementation tracking: Kernel feature, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.
Original Kernel CI 614 and 615 pass from four complete hashed logs, 753,462 bytes, without warnings. Original Docs CI 983 and 984 pass from four complete hashed logs, 773,542 bytes. Both pass all 45 tests and the complete 2,425-page final manual; reference-resolution warning counts are 36/1/0, with zero final warnings. Original Integration CI 1685/1686 remains queued at its second observation.
Older original Integration CI 1678 passes all 489 catalog scenarios and both native Kernel diagnostics, then fails the development COM1 editor probe after its physical counterpart passes. Rust and Markdown pass. All three complete logs total 13,384,697 bytes with no warnings; the outer input status does not establish cause. The canonical bug report is issue 67, with bug/ci/phase-6 metadata. Earlier editor and filesystem failures remain separate. No original workflow was cancelled or rerun.
Native cleanup without a userspace successor — 19 September 2026: signed Kernel 2cf5b34c adds a seventh actual CPL3 caller to the maintained lifetime diagnostic. After every earlier assertion, the observer binds/starts the final child and yields. The child kills that supervisor through its own explicit Process SEND route. Immediate faulting sentinels forbid either terminal payload from resuming. Ordinary native return closes CPU accounting, detaches current attribution, progresses reclamation and finds no runnable successor.
A diagnostic-only read-only witness then requires empty CPU accounting, only terminal retained records, no bound cleanup duties or event reservations, exact child identity/CSpace/mapping absence and both unconsumed child-before-supervisor events. All six final child pages retire; three original unbound terminal records remain for prior assertions. The witness neither performs cleanup nor selects a process nor installs an interrupt.
ERIX_KERNEL:CHILD_IDLE_CLEANUP_OKprecedes completion before HLT, so actual hardware halt/wakeup remains a separate gate.Signed Integration 4d6f4fe8 requires the additional marker while preserving all earlier assertions and both 60-second scenario limits. Both actual native VMs pass: 1,905/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256:
4a7cba61f75f4eeac47896d165b8dbcd217e4c75e2a81c8ae0f29957facb929c. Packaged Kernel images match retained build artifacts after normal stripping; all fifteen original component signatures verify. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Post-VM changes only select updated Docs in full catalogs and update roadmap status.Signed Docs 69466a64 documents the pre-halt boundary and consolidates stale status paragraphs. All 45 tests, the complete 2,425-page manual, 447,534 word bounds and visual review of pages 562–564 pass with zero final warnings. API reference source remains unchanged. The static audit passes 3,140 authored code files below 1,000 lines, 74 manifests, 259 full Git selections, 171 direct missing_docs gates and 92 conventional crate roots; semantic authority and complete private-rustdoc closure remain open.
Original Kernel CI 616 and 617 pass from four complete hashed logs, 753,458 bytes, with no warnings. Original Docs CI 985 and 986 also pass: four complete hashed logs, 773,510 bytes; both pass 45 tests and the final 2,425-page manual. Reference-resolution warning counts are 36/1/0 with zero final warnings. Original Integration CI 1687/1688 remains queued at its first observation.
Older original Integration CI 1677 is now terminal failure: all 489 catalog cases, both native diagnostics, development physical/COM1 editor and release physical editor pass before release COM1 fails. Rust and Markdown pass. Three complete logs total 13,385,246 bytes without warnings; bug 37 retains this evidence. Companion 1678's earlier development COM1 failure remains separate in bug 67; a common cause is unproven. No original workflow was cancelled or rerun.
Further native failure controls, grant-rights minimization, terminal accounting, Procd adoption and complete service lifecycle acceptance remain open. Existing install-grant creation still supplies GRANT | MINT while binding needs GRANT, so minimum authority is not claimed. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.
Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.
Native terminal-event allocation refusal — 19 September 2026: signed Kernel ba03995f extends the actual executing-child sequence with one deliberately refused heap allocation. Separate diagnostic preparation captures the original supervisor, child, staged grandchild and independent process records/capability inventories, then gives an empty event queue one-event capacity. No queued event or existing reservation is discarded. The first terminal-event reservation succeeds; the second arms exactly one null return from the real Kernel allocator. Ordinary collection growth and Process dispatch return RESOURCE_EXHAUSTED before any terminal effect.
Read-only witnesses require complete reservation rollback, an empty event queue, unchanged exact records and capabilities, and preserved code/stack/message mapping ranges. Actual CPL3 instructions validate the refusal reply before the next ordinary ancestor kill succeeds with allocation available. Every earlier terminal, descendant-disposal, independent-process and no-successor idle assertion remains required.
ERIX_KERNEL:TERMINAL_EVENT_RESERVATION_OKrequires one consumed allocator refusal and no remaining armed fault. Fault controls are absent from ordinary images; this covers injected allocation failure, not spontaneous heap exhaustion or independent resource-release failure. No witness supplies a syscall result, cleanup effect or scheduler choice.Signed Integration cf5b2f5f requires the new marker without changing either 60-second limit. Both maintained native VMs pass: 1,948/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is
d485019082175f769ecc2d406d88c6cc84a7df323605027663f5bcc79ca03ad9. Packaged Kernel bytes match retained original artifacts after normal stripping, and all fifteen original source signatures verify. Post-VM changes only select updated Docs in full catalogs and consolidate roadmap status.Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and updated policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 62ba2ffa passes 45 tests, the complete 2,425-page manual, all 447,688 word bounds and actual visual review of pages 562–565, with zero final warnings; API reference source remains unchanged. The static audit passes 3,142 authored code files below 1,000 lines, 74 manifests, 259 full Git pins, 171 direct missing_docs gates and 92 conventional roots. Complete semantic authority and private-rustdoc closure remain open.
Original Kernel CI 618 and 619 pass from four complete hashed logs, 753,434 bytes, with zero warnings. Original Docs CI 987 and 988 pass from four complete hashed logs, 773,506 bytes: both pass 45 tests and the final 2,425-page manual, with reference-resolution warning counts 36/1/0 and zero final warnings. Original Integration CI 1689/1690 is queued. Earlier filesystem, directory, editor and full-frame regressions remain unresolved; original workflows were not cancelled or rerun.
The terminal-accounting audit confirms that ordinary Procd terminal handling queries original TCB counters after receiving its event, while automatic bound-child reclamation removes that TCB. Its separate private-mediator branch does not take the same query path; adoption must state which lifetimes require retained metrics and preserve their original generation without fabricated zero/wall-clock values. Independent release-failure coverage, grant-rights minimization, accounting, Procd adoption and full mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.
Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.
Independent native child release recovery — 19 September 2026: signed Kernel 82d88b60 extends actual supervisor-exit coverage with two deliberate refusals at the original staged child's final VSpace-release callback, after capability disposal and unlinking. The first error is KernelHeapExhausted, the second CspaceSlotMissing. Read-only observations around two ordinary CPL3 observer yields require the original full record, generation, abort custody and first error retained, an empty original CSpace and retained mapped backing. The independent running child must already be absent from native TCB, CSpace and VSpace directories. The selected child's earlier directory position ensures its failure preceded that independent disposal.
The third callback must perform normal VSpace release before all original terminal-event, generation and resource-absence checks pass.
ERIX_KERNEL:CHILD_RELEASE_ISOLATION_OKrequires exactly two refusals and complete eventual disposal. Fault control uses only atomics at the locked callback boundary and exists only in the isolated native diagnostic. No witness performs cleanup, supplies a successful release/syscall result or chooses a scheduler target. This establishes injected callback-refusal coverage, not an observed hardware or allocator malfunction. All earlier nested-child, allocation-refusal and no-successor pre-halt assertions remain required.Signed Integration 294a467a requires the added marker with both original 60-second limits unchanged. Both maintained native VMs pass: 1,988/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is
606fff037be022c876220d8e8f329c9046ffea5dcdf80831026649aedfbe0b08. Packaged Kernel bytes match retained original unstripped artifacts after normal stripping, and all fifteen original component signatures verify. Post-VM changes only select the updated manual source in full catalogs and reconcile roadmap status.Four strict Kernel 720/744-test configurations, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test configurations, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 2a0ccc1a passes 45 tests, the complete 2,427-page manual, all 447,789 word bounds and actual visual review of pages 562–565 with zero final warnings. API reference source is unchanged. Static audit passes 3,143 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 171 direct missing_docs gates and 92 conventional roots; complete semantic authority/private-rustdoc closure remains open.
Original Kernel CI 620/621 and Docs CI 989/990 pass from four complete hashed logs each (753,438/773,910 bytes), with zero final warnings. Current Integration originals are observed after publication. Earlier filesystem, directory, editor and full-frame regressions remain unresolved, with original evidence retained; no workflow is cancelled or retried unchanged.
The grant-rights audit confirms actual Procd derivation callers and exact GRANT | MINT receipt checks in Procd and Launchd. Grant authority minimization must coordinate those consumers and distinguish the grant's own rights from its installation ceiling. Original generation-bound terminal accounting, Procd adoption, provider completion, hardware halt/wakeup and complete mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.
Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.
Manual and dependency validation — 20 September 2026:
Docs commit f4621ce2921b2b9fe3b1d25b4321d6b28289418e is signed and pushed. Native selectors 32/33/54 now document exact own rights separately from installation ceilings. The process and launch chapters require GRANT-only final receipts, explicit derivation/source disposal, and original-generation rollback. Both IPC references are regenerated from signed source. All 45 tests and API checks pass; the complete 2,429-page manual has zero final warnings, all 448,913 word bounds pass, and eleven changed pages were visually reviewed. Original Docs CI 991/992 passes with four complete hashed logs, 774,346 bytes, both 45-test runs and final 2,429-page manuals. Intermediate TeX reference warnings resolve before the final pass.
Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open.
Verified managed installer recovery — 21 September 2026:
Signed Integration 648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d in WIP PR 12 selects signed Procd ac8a12993bc8cbf134a11e141e459cb63df71123 and Docs PR 4. Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed.
Procd bug 4 is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings.
The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes.
The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged.
Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open.
Committed terminal-accounting consumers — 21 September 2026:
Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.
Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.
Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.
The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.
No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.
Explicit frame-tool manual — 21 September 2026: signed f8a40d45fbbd631660f3adca9152fbb398a4ee6d documents selected disassembler/helper custody, minimal child environment, bounded cleanup and preserved failure evidence. All 45 tests, the complete 2,431-page manual and 449,997 rendered word bounds pass. The changed page passes visual review, final warnings are absent and shared API reference sources remain unchanged. Original CI 999/1000 is monitored separately. Full native Rust/LLVM/runtime rebuilding and both EriX guest build generations remain required in Phase 6 completion.
Original frame-manual CI acceptance — 21 September 2026: signed
f8a40d45fbbd631660f3adca9152fbb398a4ee6dpasses both original 999/1000, including 45 tests and the complete 2,431-page manual. Four complete hashed logs total 774,750 bytes. Each manual log retains 37 initial warning candidates; LaTeX reference-convergence passes report 35/1/0 warnings, and the final pass has no warnings or layout overflow. These expected early convergence messages remain visible in the original logs. The native external toolchain rebuild and both full guest build requirements remain open.Signed startup source/feature correction — 21 September 2026:
Integration fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure.
All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; bug 71 retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices.
The technical manual update 76672dff8ff83 passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs 1001/1002 passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow.
A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under bug 69; no threshold or 120/15/10 capture limit changes. Original Integration 1705/1706 is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory.
Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.
Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.
Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.
Executed-code profiling checkpoint — 22 September 2026: signed Integration 4fa27f942bc2, tracked in Integration PR 12, adds bounded host TCG execution counters, explicit fresh-output ownership and exact packaged-ELF code candidates without adding guest authority. All 172 maintained helper commands pass without warnings. The profiler passes five Rust tests in both profiles, strict Clippy, private rustdoc, eleven Python controls and five actual selected-emulator controls. Unchanged orchestration inputs retain their preceding four strict matrices. The operator guide distinguishes complete counters from VM acceptance.
One original-image diagnostic retains 92,896 translated blocks, 1,994,216 code bytes and zero missed execution counts. Its top 100 code groups cover 85.65% of the translated instruction upper bound; 33.30% has Kernel mapping-batch candidates and 7.70% has VSpace permission-switch candidates among the selected ELF inputs. Unknown and ambiguous work remains visible. These are code matches, not process ownership or elapsed-time attribution. Both the instrumented attempt and its same-emulator uninstrumented control fail waiting for the final native-command marker under unchanged 120/15/10 collection bounds. Neither proves startup acceptance, whole-transcript instrumentation overhead or a speedup. Profiler acceptance and startup performance remain open. The next optimization must preserve complete validation, live backing checks, page permissions, invalidation ordering and cleanup on errors.
The signed manual update, tracked in Docs PR 4, passes 45 tests, all 2,431 pages, 450,367 word bounds and both changed-page visual reviews with zero final warnings or overflow. Original Docs CI 1005/1006 passes from four complete logs (774,674 bytes); initial reference-convergence warnings resolve on the final passes. Integration 1711/1712 is queued, while original 1701/1702 still runs. Existing queued jobs remain untouched. All 3,174 authored code files remain below 1,000 lines. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and completing the required full guest-build generations remain mandatory and unproven.
Ordinary mapping-domain checkpoint — 22 September 2026: resolved admission report records the original host failure and bounded fix. The fixture regression retains all three distinct failed attempts and the verified layout correction. Kernel now validates the complete ordinary user page before backing or mapping changes, with both control paths covered. Four strict 745/769-test configurations, thirteen native builds, Clippy and private rustdoc pass without warnings. Three exact-source native executions pass lifetime, invocation and mapping; four maintained scenario contracts are checked, with sparse and isolation sharing their identical runtime capture. All fifteen selected native signatures and packaged Kernel identities verify.
Integration pins the exact Kernel in all three catalogs, preserves every other selection and passes all 172 helpers. The unchanged ordinary exec-successor VM passes against the complete source graph, preserving its 120-second guest deadline, with no image warnings or QEMU stderr. Docs documents the domain and bootstrap distinction; all 45 tests and 2,431 pages pass, with 450,473 word bounds checked and no final warnings. The earlier Kernel CI 632/633 passes from four complete logs and zero warnings; current original CI remains under observation.
Bootstrap provenance, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.
Verified documentation and CI follow-up — 22 September 2026: Kernel documentation and Integration documentation record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in report 24, separately from the fixed admission defect. The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure.
Original full Integration 1703/1704, source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel 634/635 report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel 636/637 and Docs 1007/1008 pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued.
The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open.
VSpace MAP authority checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Current local MAP rights now govern map, protection and unmap requests. Empty and MANAGE-only aliases are denied; MAP-only access remains valid. Four strict 750/774-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.
The Integration catalog selects the exact signed Kernel in all three catalogs and passes all 172 helpers. Actual CPL3 calls preserve the authorized RW/NX page across restricted-alias refusals and drop all five temporary grants. Three native executions cover all four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signed sources and retained packaged artifacts. The original exec-successor service VM passes against all 73 components with its unchanged 120-second guest limit. All image warnings and QEMU stderr remain absent. Manual validation passes 45 tests, 2,431 pages and 450,550 checked word bounds, with both changed pages reviewed and zero final warnings.
The static audit covers 3,181 authored code files below 1,000 lines, 259 exact Git dependency pins and existing direct missing_docs gates. It does not close semantic authority review. Earlier full Integration runs 1705/1706 are running; 1707–1720 remain queued at the latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 638/639 and Docs 1009/1010 pass. Each pair has four complete logs: Kernel totals 777,250 bytes with zero warnings, and Docs totals 774,674 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1721/1722 remains queued; it receives no CI acceptance credit.
Canonical acceptance remains 15/460 leaves, weighted 3.48%. Independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven.
Frame access checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Explicit READ now governs admission and hardware activation. No-access mappings retain backing with USER/WRITE clear and NX set; write-only and execute-only requests are rejected without adding READ. Existing protection-transition rules remain in force. Four strict 757/781-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.
The Integration catalog selects the signed Kernel in all three catalogs and passes 172 helpers. Twenty-four actual CPL3 calls preserve earlier witnesses and cover no-access protection, write-only refusal, MAP-only frame derivation, denied READ and unmap after both frame grants are dropped. Three native executions pass four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signatures and retained packaged artifacts. The ordinary exec-successor VM passes against all 73 components with its unchanged 120-second guest limit. Builds emit no warnings and QEMU stderr is empty. Manual validation passes 45 tests, 2,433 pages and 450,702 checked word bounds, with the changed page reviewed and zero final warnings.
Static review covers 3,182 authored code files below 1,000 lines, 259 exact Git pins and existing direct missing_docs gates. This does not close semantic authority review. Earlier full Integration runs 1705/1706 remain running and 1707–1722 remain queued at their latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 640/641 and Docs 1011/1012 pass. Each pair has four complete logs: Kernel totals 782,838 bytes with zero warnings, and Docs totals 775,110 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1723/1724 remains queued; it receives no CI acceptance credit.
Canonical acceptance remains 15/460 leaves, weighted 3.48%. Authorized protection restoration, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.
Ordinary protection contract — 22 September 2026: the runtime memory design now specifies in-place no-access/R/RW/RX changes using current VSpace MAP and exact selected frame authority, including same-backing aliases and complete backing checks. Preserve W^X, explicit READ, object kind, reference custody, error ordering and all native witnesses. Kernel-owned anonymous loader materialization and Process endpoint target scope retain separate audit obligations. The implementation and exact-source VM evidence are pending. This earns no canonical acceptance credit; external toolchain rebuilding and both complete EriX guest-build generations remain mandatory.
Current-grant protection checkpoint — 22 September 2026: the resolved device-backing report distinguishes its original metadata-authority inconsistency from the separate restoration feature gaps. The Kernel implementation permits representable no-access/R/RW/RX changes through current exact-backing grants and aliases while active or inactive. It removes historical access ceilings and original-slot equality while preserving current VSpace MAP, selected frame rights, kind/range/identity checks, W^X, explicit READ, backing custody and failure ordering. Four strict 766/790-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.
The coordinated catalog selects that original signed Kernel in all three catalogs and passes all 172 helpers. Fifteen managed-frame calls and twenty-nine device/domain calls pass inside the original lifetime window and deadline. Actual user instructions write, execute, rewrite and execute managed RAM, check narrow alias authority and final disposal, while a reused device slot cannot authorize unrelated backing. Every prior marker remains required. Three native executions pass four original contracts with complete signed source and artifact checks; the ordinary exec-successor VM passes the full 73-component graph and original 120-second limit. Image warnings and QEMU stderr are absent. Manual validation passes 45 tests, 2,433 pages and 450,954 word bounds; both changed pages are reviewed with no final warnings or overflow.
Static review covers 3,184 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins and 174 direct missing_docs gates. Full semantic authority review remains open. Older Integration CI 1705/1706 has eleven real ext4 timeouts across eight scenarios, with complete retained logs and no accepted rerun. Their root cause and correction remain unresolved. Publication CI: Kernel 642/643 and Docs 1013/1014 pass. Each pair has four complete original logs: Kernel totals 790,650 bytes with 766/790 tests and zero warning candidates; Docs totals 775,150 bytes with 45 tests, 2,433 pages and zero final warnings or overflow. Retain the original 35/1/0 LaTeX warning convergence. Integration 1725/1726 remains queued and receives no completed CI acceptance. The separate older ext4 deadline report remains open.
Canonical acceptance remains 15/460 leaves, weighted 3.48%. Complete POSIX protection support, Process endpoint scope, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.
Supervisor physical-access window — 22 September 2026: the signed Kernel implementation shares one restoring supervisor scratch transaction between frame scrubbing and physical mapping-byte copies. Caller backing custody and page-table/interrupt custody remain live through byte access, exact leaf restoration and local invalidation. Scratch is released afterward; read aliases clear the write bit and all temporary aliases clear user access and set NX. The unreachable raw-VA fallback is removed, and complete preflight rejects missing or ambiguous backing metadata before any range effects. No new userspace operation or capability grant is introduced. This is preparatory work for owned address spaces; independent roots and their switching/reclamation proof remain open.
Eight added host controls cover geometry, permissions, preparation and partial-effect failures, restoration/release ordering, and malformed later-page metadata without partial reads or writes. Four strict host configurations pass 774/798 tests with three existing ignored cases. Fourteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. The coordinated Integration catalog passes all 172 maintained helpers; its exact marker expectation is updated alongside the strengthened scenarios. Unchanged orchestration and profiler sources retain strict validation.
Six native executions satisfy seven maintained scenario contracts. Both allocator scenarios require the new same-VA/different-backing byte-and-leaf proof after complete cleanup, retaining every preceding marker and the original 60/120-second deadlines. Three further executions satisfy mapping, sparse, owned-invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Exact original signed source, retained artifacts and packaged Kernel matches are verified; no image warnings or QEMU stderr were observed. These checks establish no performance improvement. The technical manual documents backing and scratch custody; all 45 document tests and the complete manual build pass without final warnings.
Static checks cover 3,190 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Complete semantic authority and inline-documentation review remain open. Publication CI: Kernel 648/649 and Docs 1015/1016 pass. Eight complete original logs (1,572,758 bytes) confirm Kernel 774/798 tests, 45 document tests and the 2,433-page manual. Initial TeX reference warnings resolve through normal multipass generation; final passes are clean. Integration 1731/1732 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and its runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.
Owned supervisor baseline — 22 September 2026: the signed Kernel implementation captures and verifies independently allocated supervisor tables before root VSpace creation, Rootd preparation and RAM seeding. Each copied page has one typed aligned Box owner before a parent references it; the recursive entry selects the copied root. Source boot/AP tables and mapped backing retain separate custody. User leaves, malformed geometry and invalid recursive identity are refused. Leaf permissions, cache policy and huge-page sizes are preserved; newly owned table branches use WriteBack and clear USER. Failed construction releases all unpublished allocations. This replaces a raw-pointer table-storage owner with shared typed storage and adds no unsafe Send/Sync implementation or userspace operation.
Eleven new host controls cover independent storage, allocation/read failures, invalid translation geometry, user leaves, recursive and huge-page errors, source-permission drift, retained owner links and table counts beyond the unrelated 64-page batch size. Four strict host configurations pass 785/809 tests with three existing ignored cases; fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The coordinated catalog passes all 172 maintained helpers. Both allocator scenarios require successful baseline capture before their original marker sequence, with capability grants and original 60/120-second deadlines preserved.
Six native executions satisfy seven maintained contracts: both allocator scenarios, mapping and sparse checks sharing identical runtime settings, owned invocation, lifetime revocation and ordinary exec-successor across all 73 components. Exact signed source and retained packaged artifacts are verified; no image warnings or QEMU stderr were observed. The technical manual specifies the custody boundary and passes 45 tests, complete 2,433-page generation, all 451,287 word bounds and changed-page visual review without final warnings or overflow. Static audits cover 3,194 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots.
Publication CI: original Kernel push 650 passes and PR 651 retains the host fixture failure. Regression 29 is resolved by signed Kernel
12184850cd73: a deterministic private predecessor reproduces the original defect, and the corrected fixture passes the complete local matrix and push CI 652/PR CI 653. Four complete corrected CI logs total 807,886 bytes with zero warning candidates. Only host tests and roadmap change; validated production sources and all catalog selections remain unchanged. Docs 1017/1018 pass with four complete logs (775,122 bytes), 45 tests and the 2,433-page manual. Initial TeX reference warnings resolve before clean final passes. Integration 1733/1734 remains queued at the latest retained observation and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. The retained baseline is a construction prerequisite for owned address spaces. Per-VSpace population, CR3 activation, invalidation and live-root reclamation remain open, and no speedup is claimed. Full semantic authority and inline-documentation review also remain open. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.Huge-leaf geometry correction — 22 September 2026: the bug report preserves four original host failures and one passing WriteBack control. The signed correction separates PAT from physical address bits, preserves permissions/cache indices across both huge splits, and gives newly allocated tables WriteBack policy. Scalar and batched translation, split preparation, snapshots and baseline validation share the documented geometry. No new userspace authority, original native exploit or universal boot failure is claimed.
Four strict Kernel configurations pass 796/820 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: mapping and sparse, lifetime, invocation, both allocator checks and ordinary exec-successor across all 73 components. The new native witness verifies real 2 MiB PAT translation, splitting and complete restoration; host controls additionally cover 1 GiB. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and changed-page visual review without final warnings or overflow.
Publication CI: Kernel 654/655 and Docs 1019/1020 pass. Eight complete original logs (1,592,794 bytes) confirm Kernel 796/820 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1735/1736 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,197 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, live-root reclamation and full semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.
First-start register custody — 22 September 2026: the stack-domain bug report preserves three original host failures and one valid-stack control at unchanged production sources; the same four controls pass against the signed correction. Ordinary anonymous stack materialization now rejects addresses outside the existing user domain, and direct bootstrap writes require retained writable registered backing. Initial registers have Kernel-owned storage; stack preparation preserves the synthetic return slot, complete admission, startup arguments and rollback. The obsolete saved-frame user overlay and directory scan are removed. Complete external start-context admission and the separate bootstrap code/stack overlay remain distinct work.
Four strict Kernel configurations pass 807/831 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: lifetime, invocation, mapping and sparse, both allocator checks and ordinary exec-successor across all 73 components. The new witness checks all original initial register words after two real user stack mutations and before ordinary syscall capture. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and four changed-page visual reviews without final warnings or overflow.
Publication CI: Kernel 656/657 and Docs 1021/1022 pass. Eight complete original logs (1,600,791 bytes) confirm Kernel 807/831 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1737/1738 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,201 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, CPU residency, live-root reclamation and complete semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.
WIP: Document POSIX compatibility work and acceptance trackingto WIP: Enforce warning-free manual builds and document compatibility workerikinkinen referenced this pull request from erix/integration2026-09-12 09:18:44 +02:00
WIP: Enforce warning-free manual builds and document compatibility workto WIP: Enforce warning-free manuals and document compatibility contractserikinkinen referenced this pull request from erix/lib-posixabi2026-09-12 11:12:14 +02:00
erikinkinen referenced this pull request from erix/kernel2026-09-12 11:12:16 +02:00
erikinkinen referenced this pull request from erix/lib-ipc2026-09-12 12:00:32 +02:00
WIP: Enforce warning-free manuals and document compatibility contractsto WIP: Enforce warning-free manuals and preserve public API declarationsWIP: Enforce warning-free manuals and preserve public API declarationsto WIP: Preserve complete API declarations and validate the technical manualerikinkinen referenced this pull request from erix/bootloader2026-09-12 18:47:28 +02:00
WIP: Preserve complete API declarations and validate the technical manualto WIP: Preserve complete ABI references and validate the technical manualerikinkinen referenced this pull request from erix/integration2026-09-12 20:00:23 +02:00
WIP: Preserve complete ABI references and validate the technical manualto WIP: Document POSIX realm ownership and preserve complete ABI referenceserikinkinen referenced this pull request from erix/posixd2026-09-12 20:52:06 +02:00
erikinkinen referenced this pull request from erix/posixd2026-09-12 20:52:07 +02:00
WIP: Document POSIX realm ownership and preserve complete ABI referencesto WIP: Document physical input failures and POSIX realm ownershipWIP: Document physical input failures and POSIX realm ownershipto WIP: Document C memory interfaces and startup image admissionerikinkinen referenced this pull request from erix/lib-cstd2026-09-13 00:15:31 +02:00
WIP: Document C memory interfaces and startup image admissionto WIP: Document C memory and query interfaces and native build supportWIP: Document C memory and query interfaces and native build supportto WIP: Document C memory and string interfaces and native build supportWIP: Document C memory and string interfaces and native build supportto WIP: Document file status, C strings and native authority boundariesWIP: Document file status, C strings and native authority boundariesto WIP: Document lifetime revocation and preserve opaque API contractserikinkinen referenced this pull request from erix/kernel2026-09-14 10:41:15 +02:00
erikinkinen referenced this pull request from erix/kernel2026-09-14 10:41:15 +02:00
erikinkinen referenced this pull request from erix/kernel2026-09-14 10:41:16 +02:00
WIP: Document lifetime revocation and preserve opaque API contractsto WIP: Document native lifetime validation and scoped runtime resolutionWIP: Document native lifetime validation and scoped runtime resolutionto WIP: Document native IPC platform and lifetime boundariesWIP: Document native IPC platform and lifetime boundariesto WIP: Document owned invocation transport and native custodyWIP: Document owned invocation transport and native custodyto WIP: Document owned invocation and staged installation contractsWIP: Document owned invocation and staged installation contractsto WIP: Document native authority and mediator bootstrap contractsWIP: Document native authority and mediator bootstrap contractsto WIP: Document staged mediator construction and caller admissionWIP: Document staged mediator construction and caller admissionto WIP: Document staged construction and artifact validationWIP: Document staged construction and artifact validationto WIP: Document native custody, shell workspace and artifact validationWIP: Document native custody, shell workspace and artifact validationto WIP: Document native authority and verify workspace and command evidenceView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.