WIP: Document native authority and verify workspace and command evidence #4

Draft
erikinkinen wants to merge 117 commits from feature/posix-compat into main
Owner

Summary and rationale

Document shared compiler metadata consistency, equal-byte reuse, exclusive destination creation and cache ownership across executable and shared-library producers. Provider provenance, source lifetime and scratch cleanup remain explicit caller obligations.

Specify single-driver dynamic linking, exact compiler-host discovery when standalone tools are absent, preserved driver aliases, fatal warnings and visible successful diagnostics. A selected driver failure does not authorize another implementation or publication of partial output.

Document unambiguous Rust runtime archive selection for fresh Kernel, Rootd and service links, including the separate provenance, cache-coverage and toolchain-lifetime obligations. The corresponding implementation is tracked in Integration issue 62.

Document native staged construction, grant custody and authenticated caller
admission; specify owned shell workspaces and exact source/artifact/frame
evidence. Correct the syscall reference and native entry contract: IRETQ return,
the 136-byte saved prefix, 176-byte transient reservation, separate kernel stack,
preserved user flags, aligned exception calls and five/six-word hardware frames.
Document complete borrowed syscall capture, initialized stable storage and
resource refusal before operation dispatch. Render literal command-option
bytes without changing their meaning.

Describe one-way VSpace retirement, recorded withdrawal progress, consumed
frame references and retained final-process custody. Keep that contract separate
from whole-process destruction and ordinary VSpace activation.

Describe process cleanup custody, non-executable abort/destruction states,
retained private CSpace identity and the exact final retirement commit.
Earlier partial cleanup is not represented as whole-process rollback.

Tracking and scope

Signed head 64fc14411a3f1629ace2854ddc1c3b7875113343, branch feature/posix-compat.
Documentation audit #1; command rendering #8; corrected syscall reference #9 and
entry documentation #10. Dependent reviews:
Kernel,
Integration,
Exsh, and
lib-dynlink.
Realm design, runtime acceptance
and both full guest builds remain open.

Architecture, authority and failure behavior

Staged construction omits child root capabilities while retaining native TCB
backing. Procd authenticates the pending caller against its Launchd owner and
generation. Identities and bearer senders cannot replace actual authority;
rejected transfers retain cleanup obligations. Mediator start and sealing are
separate contracts. The manual introduces no runtime capability or ABI change.

Ordinary and emergency I/O own distinct authenticated workspace slices. Cleanup
borrows and erases its complete slice. Paired ELF evidence binds zero-fill
ownership, target layout, stack, bytes and permissions. Mapping evidence cannot
establish source borrowing or all-path safety. Missing proof remains incomplete.

Ordered providers and checked relocation expressions precede protected-slot
admission. Composed graphs retain object-qualified identities and grounded
dependencies. Live caller intervals constrain conditional callee writes while
preserving return-address gaps and invalidating overlapping saves; conditional
masks never become unconditional guarantees. Rejection-only scheduling and
deduplicated CFG work retain proof decisions without arbitrary pass limits.
Static receipts, host profiling, guest probes and full builds have distinct
acceptance requirements.

Validation evidence

The matching signed Docs PR 4, 54557713f4afad380c1166f6aa1c1622d3959744, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original Docs CI 979 and 980 pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required.

Native child-custody wire checkpoint — 19 September 2026: signed lib-ipc PR 2, aaf2df39700b43507b23ff2007bc0d573c4eea30, implements ChildLifetimeBindingV1, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the shared contract and Kernel design #19.

Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original lib-ipc CI 365 and 366 pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph.

Native external-toolchain rebuild requirement — 19 September 2026: Signed b54d28e755dd415079100a19683ee1474edb4ed1 makes the native rebuild an explicit Phase 6 verification and acceptance gate. The first compiler may be cross-built for EriX against its libc/sysroot, Rust OS bindings and declared C/C++ runtime closure. The extended development image must then rebuild the selected upstream Rust/LLVM toolchain inside EriX using supplied offline recipes and an explicit bootstrap compiler. Require working guest-built tools and use in at least one full EriX build, with no unrecorded porting changes, downloads, Linux executables or host build delegation. Complete source, runtime, log and measured-resource evidence is required; compiler ownership remains distinct. All 45 documentation tests and the full 2,419-page manual pass, with 445,775 in-bounds word boxes, actual visual review of the changed page and zero final warnings. Shared API snapshots are unchanged. The phase master, toolchain issue and full-build issue contain the matching requirements. Original documentation CI is under observation; the native toolchain rebuild and both OS builds remain unproven.

Original coherent realm source CI acceptance — 18 September 2026: Signed 33733ceba228669e27152aee32f997d6c72264ff passes CI 972 and CI 971. All four terminal logs are complete (772,194 bytes), with zero final warnings. This closes the original CI observation recorded above. All 45 tests and both 2,419-page manuals pass; reference-pass warnings converge 36/1/0. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.

Realm startup consumer manual checkpoint — 18 September 2026: Signed 33733ceba228669e27152aee32f997d6c72264ff describes exact realm startup consumers, explicit disabled or positive deployment capacity and the reviewed Rootd production audit. All 45 tests and the complete 2,419-page manual pass, with 445,650 word boxes within page bounds, two visually reviewed changed pages and zero final warnings. Shared API snapshots are unchanged. Original CI 971/972 is under observation. Coherent catalog adoption and actual consumer VMs remain required before image acceptance; no runnable realm or full guest build is claimed.

Original public realm dispatch manual CI acceptance — 18 September 2026: Signed Docs 099f0c570414ca486bb2104c1510fbf3b84d59fb passes CI 969 and CI 970. All four terminal logs are complete (772,182 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Public realm dispatch and progress checkpoint — 18 September 2026: Signed 099f0c570414ca486bb2104c1510fbf3b84d59fb is pushed. The manual describes public realm intake, independently held replies, original-parent cleanup and fair native progress before ordinary dispatch, while preserving separate consumer VM and guest-build acceptance. All 45 tests and the complete 2,419-page manual pass. All 445,563 word boxes are within page bounds; both changed rendered pages are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI is under observation; no runnable realm or guest build is claimed.

Original exact preparation manual CI acceptance — 18 September 2026: Signed Docs 880bdc59818b1eff9cf9929004680f354f8265a0 passes CI 967 and CI 968. All four terminal logs are complete (772,086 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Exact realm executable preparation checkpoint — 18 September 2026: Signed 880bdc59818b1eff9cf9929004680f354f8265a0 is pushed. The manual documents actual exact preparation, shared authentication, scratch reuse and independent retained cleanup, while keeping dispatcher, scheduler and consumer-image requirements open. All 45 tests and the full 2,419-page manual pass; all 445,389 word bounds and both changed rendered pages are reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI 967/968 is under observation. Complete mediated execution and both full builds inside EriX remain required.

Original realm admission manual CI acceptance — 18 September 2026: Signed Docs 9868cf0e6f2c366b4a2c7992594a83c72789f1f0 passes CI 965 and CI 966. All four terminal logs are complete (771,742 bytes), all 45 tests pass and both complete 2,417-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Caller-bound realm record checkpoint — 18 September 2026: Signed 9868cf0e6f2c366b4a2c7992594a83c72789f1f0 is pushed. The manual describes exact realm admission messages, original-caller binding, explicit LCH1 version-3 capacity and independent native storage. Four API references select the signed shared graph; stale bootstrap width, version and route-stride prose is corrected. All 45 tests, API provenance/regeneration checks and the complete 2,417-page manual pass. All 445,195 word bounds are valid, seven rendered pages were reviewed and final warnings are zero. Original CI 965/966 is under observation. Actual runtime admission, coherent image consumers, mediated client I/O and both full guest builds remain open.

Original retained caller manual CI acceptance — 18 September 2026: Signed Docs 4dcbc10e32ebf257139bcbaf07bc1081b9589780 passes CI 963 and CI 964. All four terminal logs are complete (770,022 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Retained realm caller checkpoint — 18 September 2026: Signed 4dcbc10e32ebf257139bcbaf07bc1081b9589780 is pushed. The process-service manual describes the retained native caller, permanent source absence, cancellation ordering and independent child retirement. All 45 tests and the complete 2,409-page manual pass. All 443,468 word bounds are valid, both changed pages were visually inspected and final warnings are zero. No Rust implementation or generated API snapshot changes. Original CI 963/964 is under observation. Runtime admission, scheduler integration, consumer VM proof and both full guest builds remain separate requirements.

Original supervisor manual CI acceptance — 18 September 2026: Signed Docs a410759e5515b18107f25efb0319ad7c85871a64 passes CI 961 and CI 962. All four terminal logs are complete (769,994 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Original supervisor manual checkpoint — 18 September 2026: Signed a410759e5515b18107f25efb0319ad7c85871a64 documents private caller attestation, the exact 64-byte materialization begin, original ownership before creation and handoff, and separate caller RELEASE cancellation and application rollback. Three shared API snapshots match original signed source exports. All 45 tests, provenance/regeneration checks and the complete 2,409-page manual pass. All 443,265 word boxes are in bounds; seven rendered pages were inspected and final output has zero warnings. Original CI 961 and CI 962 remain under observation. Actual Launchd owned runtime adoption, consumer VM execution and both full guest builds remain open.

Original owned bootstrap manual CI acceptance — 18 September 2026: Signed Docs 5c1cf6da319787738fa03f3cc6f526e49604aa09 passes CI 959 and CI 960. All four terminal logs are complete (769,578 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Owned bootstrap receiver checkpoint — 18 September 2026: Signed Docs 5c1cf6da319787738fa03f3cc6f526e49604aa09 updates the process-services contract and three source-bound shared API snapshots for the identity-only request and retained native delivery. All 45 tests, three signed API exports, provenance/regeneration checks and the complete 2,407-page manual pass. All 442,920 word boxes are in bounds; seven rendered pages were visually reviewed and final output has no warnings. Original CI 959/960 is under observation. Actual Launchd runtime orchestration, consumer VM execution and both complete guest builds remain open.

Original receiver admission manual CI acceptance — 18 September 2026: Signed Docs 8361618f3f047479a9e52ffaba7f2607be99413c passes CI 957 and CI 958. All four terminal logs are complete (769,554 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Explicit owned receiver admission acceptance — 18 September 2026: Signed 8361618f3f047479a9e52ffaba7f2607be99413c. The manual documents explicit receiver request limits, complete layout addressability, immutable registration and pre-custody refusal, with accurate allocation-observation scope. Three public API snapshots are regenerated from signed shared revisions. All 45 tests, provenance/regeneration checks and the 2,407-page manual pass. All 442,761 word boxes are in bounds; eight changed pages are visually reviewed, with zero final warnings. Original CI is under observation. Actual owned Procd/Launchd service adoption, consumer VM execution, complete realm fairness/readiness/sealing and both full builds inside EriX remain open.

Original local grant relocation manual CI acceptance — 18 September 2026: Signed Docs 623609ee627a4afba1340ee06c53678c4a562a88 passes CI 955 and CI 956. All four terminal logs are complete (768,754 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Caller-local grant relocation checkpoint — 18 September 2026: Signed 623609ee627a4afba1340ee06c53678c4a562a88 documents syscall 0x54 register admission, actual Running caller and unique grant custody, exact error precedence and preserved installation/revocation scope. Three API references are regenerated from signed original shared revisions. All 45 tests, complete provenance/regeneration checks and the 2,403-page manual pass. All 442,370 word boxes are in bounds; nine changed pages are visually reviewed and final warnings are absent. The original whitespace preflight failure and subsequent terminology correction are retained. Original documentation CI is under observation. Actual owned service adoption, consumer VMs, complete realm fairness and both full builds inside EriX remain open.

Original deferred-cleanup manual CI acceptance — 18 September 2026: Signed Docs da66c0efd61fc05be023210e1c0c58196b51b878 passes CI 953 and CI 954. All four terminal logs are complete (768,726 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Deferred native cleanup checkpoint — 18 September 2026: Signed Docs da66c0efd61fc05be023210e1c0c58196b51b878 specifies one queued native attempt before intake, exact-generation owner rotation, first-error retention and acknowledgment-based removal. All 45 tests and the complete 2,403-page manual pass, with 441,578 in-bounds word boxes, two changed pages visually reviewed and zero final warnings. Shared API references are unchanged. Original documentation CI is under observation. Runtime consumer VM, complete realm fairness and full guest-build acceptance remain open.

Returned-grant manual checkpoint — 18 September 2026: Signed Docs b6bd8ce32891a8b298228b8320d0565cef89141f documents the exact returned-grant request, custody acknowledgment, five retained scratch roles, native guard effects, source-absence requirement and cleanup boundaries. Three API snapshots come from the signed original component revisions; regeneration and provenance checks pass. All 45 tests pass. The complete 2,403-page manual has 441,471 in-bounds word boxes, seven changed pages visually reviewed and zero final warnings. Original CI 951 and CI 952 pass from all four complete logs (768,706 bytes); reference passes converge with 36/1/0 warnings and both final manuals have zero warnings. Runtime realm orchestration, actual consumer VM execution, fair progress and both complete builds inside EriX remain open requirements.

Original cleanup manual CI acceptance — 18 September 2026: Signed Docs 323da983653e6d6d25d012c2354f97afaaaa0699 passes CI 949 and CI 950. All four terminal logs are complete (767,338 bytes), all 45 tests pass and both complete 2,397-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements.

Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision 323da983653e6d6d25d012c2354f97afaaaa0699 is pushed. The manual documents native cleanup 56/57, retired selectors, exact framing, original deferred identity and pre-service retirement. Three API references are generated from verified signed source revisions. All 45 tests pass. The complete 2,397-page PDF has zero final warnings and 440,339 in-bounds word boxes; seven changed pages have been visually inspected. The testing chapter corrects Rootd audit-size evidence and records the actual native diagnostic scope. Original CI 949/950 remains under observation. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open.

Corrected original manual CI — 18 September 2026: Docs 10ea454ebab2cb0ca465cedf52ff619c1fc7efd4 passes original CI 947 and CI 948. All four logs are complete (765,634 bytes), all 45 tests pass, and the complete 2,389-page manual has zero final warnings after reference passes of 36/1/0 warnings. The later generation-bound cleanup manual update is still under local validation.

Reviewed bootstrap baseline manual — 17 September 2026: Signed revision 10ea454ebab2cb0ca465cedf52ff619c1fc7efd4 updates the testing chapter to
Rootd's reviewed 15,239-line release baseline and exact terminal-operation
ownership. Compiler-specific binary size is explicitly separate from performance
comparison. All 45 documentation tests and the complete 2,389-page manual pass;
there are no final warnings, all 439,184 word boxes are in bounds, and page 2334
was visually reviewed. Earlier original CI 945/946 passes with all four logs
complete (765,650 bytes; reference passes 36/1/0 warnings). The new signed
revision's original CI remains under observation. Complete builds inside EriX
and ordinary service-image adoption remain open.

Coordinated terminal observation checkpoint — 17 September 2026: Signed revision be98a93e6f34a9c7ecaffabfa0af1c8f209feff3 is pushed. The native and process-service manual contracts and three signed-source API snapshots are updated. All 45 documentation tests pass. The complete 2,389-page PDF has zero final warnings and 439,146 in-bounds word boxes; native, service and API pages were visually reviewed, including corrected literal shift operators. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.

  • Current-head push CI 937
    and PR CI 938 pass.
    All four complete logs are classified: 765,226 bytes, 45 tests, 2,387 pages,
    reference-resolution warning counts 36/1/0 and zero final warnings.

  • All 45 documentation tests, Markdown and canonical document-format checks pass.

  • The complete manual contains 2,387 pages and 438,174 in-bounds word boxes,
    with zero final warnings. Changed page 132 is visually reviewed.

  • Original cleanup-reference push CI 935
    and PR CI 936 pass.
    All four complete logs are classified: 765,222 bytes, 45 tests, 2,387 pages,
    reference-resolution warning counts 36/1/0 and zero final warnings.

  • Preceding capture-reference push CI 933
    and PR CI 934 pass.
    All four complete logs are classified: 765,238 bytes, reference-resolution
    warning counts 36/1/0 and zero final warnings. Earlier CI 931/932
    passes with four classified logs and zero final warnings.

  • The earlier syscall and entry-documentation defects (#9/#10) remain closed
    after their separately retained successful CI cohorts. Generated API snapshots
    and runtime ABI are unchanged by this documentation correction.

  • No Rust crate is altered in this repository. Runtime and full guest-build
    validation belongs to the linked component reviews and is not implied here.

Runtime archive checkpoint — 17 September 2026, signed cf684745b08b59e0efc98c4b904708d0c17d735d: All 45 documentation tests pass. The complete 2,387-page manual renders with zero final warnings and 438,260 in-bounds word boxes; page 2292 is visually reviewed. No Rust API, runtime code or API snapshot changes in this documentation checkpoint. Original Docs CI 939/940 passes with all four complete terminal logs classified (765,226 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted.

Linker selection checkpoint — 17 September 2026, signed 050b9bcc3a5d8e0f57efc62e8775dee10a48af84: All 45 documentation tests pass. The complete 2,387-page manual has 438,385 in-bounds word boxes and zero final warnings. Page 2292 is visually reviewed. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 941/942 passes with all four complete terminal logs classified (765,214 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.

Compiler metadata checkpoint — 17 September 2026, signed 64fc14411a3f1629ace2854ddc1c3b7875113343: All 45 documentation tests pass. The complete 2,387-page manual has 438,492 in-bounds word boxes and zero final warnings. The changed paragraph is visually reviewed across pages 2292 and 2293. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 943/944 passes with all four complete terminal logs classified (765,158 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.

Review checklist

  • Signed canonical commits and current source/reference contracts.
  • Tests, templates, Markdown, full manual layout and final-warning checks.
  • Changed-page visual review and literal option-byte preservation.
  • Classify preceding capture-reference CI (933/934).
  • Classify preceding cleanup-reference CI (935/936).
  • Classify current process-custody CI (937/938).
  • Complete dependent runtime, source/frame and self-hosting acceptance.

Original Docs CI 973 and 974, at b54d28e755dd415079100a19683ee1474edb4ed1, pass. All 45 tests and the complete 2,419-page manual pass; intermediate reference-resolution passes converge to zero final warnings. All four terminal logs are complete and hashed, totaling 772,186 bytes. This validates the native-toolchain rebuild requirement in the phase document and manual, not an actual toolchain or EriX build inside EriX.

Signed private-route manual correction — 19 September 2026: ce8a1538ab2220f1b346e1a051265f58f83f47fc documents realm admission through both the public receiver and the shell's authenticated private script route, retaining original reply custody and caller proof. A stale startup-publication paragraph now states the permanent coherent-source and distinct runtime-evidence requirements. All 45 tests and the full 2,419-page manual pass; all 445,834 rendered words are within bounds, revised page 224 has been visually reviewed and final warnings are absent. Shared API snapshots are unchanged. Original CI 975 and 976 are running. Native external Rust/LLVM rebuilding and both full EriX build generations remain required.

Original manual CI 975/976 passes from all four complete hashed logs (772,174 bytes): 45 tests, the full 2,419-page manual and zero final-pass warnings. Signed Integration 9139c6c5fa38c139e92520f6d410626b4cf1e4aa now adopts this documentation with the matching corrected-server VM, which passes its unchanged caller-admission scenario. Complete mediator execution, native toolchain rebuilding and both full guest builds remain required.

Guarded-custody documentation reconciliation — 19 September 2026: signed Posixd PR 5, 9b031a8c2f996491a322046a4f2acd5dacdc55c2, replaces stale grant-return and proposed-custody gaps with the implemented producer boundary. Procd uses the actual returned grant to attenuate the initial endpoint to RECV before execution, removes bypass sources, and retains nested custody beneath Kernel lifetime custody. A later mediator disposal report cannot prove absence of bypass senders. Exact staged abort and the remaining counted startup, readiness, configuration, sealing, client I/O and running-realm retirement requirements are distinguished. This repository still has no Posixd executable.

Markdown, canonical headings/governance, local links, original source anchors and whitespace checks pass. Original Posixd CI 17 and 18 both pass from two complete hashed logs totaling 7,232 bytes without warnings. Rust checks do not apply to this documentation-only repository.

Signed Docs PR 4, 7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d, removes the matching stale passages from the process-services manual. All 45 tests and the full 2,419-page manual pass. All 445,847 word boxes lie within page bounds; the actual changed paragraphs and continuation on pages 222, 226 and 227 are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original Docs CI 977 and 978 are running. These documentation corrections add no runtime behavior; the previously retained Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c appliance retains its original source selection and passing guarded-preparation evidence. Native upstream Rust/LLVM rebuilding and both complete EriX builds remain required.

Original Docs CI 977/978 passes for signed 7b79f8d50a. All four complete hashed logs total 772,186 bytes. Both runs pass 45 tests and the full 2,419-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No unchanged workflow rerun or cancellation supplies this result.

Native child lifetime checkpoint — 19 September 2026: Signed Docs 9ca5a5e811 updates the technical manual's native admission, preflight, stopping, partial cleanup and safe return/idle contracts. All 45 tests and the complete 2,425-page manual pass with zero final warnings. All 447,213 word boxes are in bounds and all three changed contract pages are visually reviewed. Shared API reference source is unchanged. Original Docs CI 981 and 982 pass from four complete hashed logs, 773,510 bytes. Both pass 45 tests and the complete 2,425-page manual. TeX pass warning counts are 36/1/0, with zero final-pass warnings; neither workflow was rerun or cancelled.

The matching original signed Kernel and both maintained native VMs pass without warnings; Kernel issue 19 retains exact runtime evidence and open executing-child, no-successor, further failure and consumer gates. Signed Integration 581226ab5435dc66c6f93157606b6d4d83475b15 selects the coherent original Kernel/lib-capabi/lib-ipc graph and updated manual. All four current strict 320/321-test configurations, four native builds, fmt, strict host/native Clippy and private rustdoc pass without warnings. Source and updated native-policy checks pass; the full 169-helper evidence remains bound to unchanged orchestration bytes. The final post-VM changes select only the newer Docs revision and update roadmap status; native source catalog, scenario, runtime and orchestration bytes are unchanged. Original Integration CI 1683 and 1684 are queued.

Executing-child and terminal-reply checkpoint — 19 September 2026: signed Kernel dd9eace5 validates actual CPL3 nested-child execution and current-child ancestor termination. Synchronous control dispatch now ends its request borrow before effects and checks original caller identity, generation and terminal state before any response write. It keeps terminal completion in Kernel-owned result registers with zero reply length; ordinary native return switches away. A surviving caller retains its normal encoded response. Two focused actual-object regressions cover terminal request preservation and the surviving-caller reply. The dispatcher is split from the tracing/policy file. A supervisor binds and starts a child; that child binds a staged grandchild and kills its supervisor through its own explicit Process SEND route. Read-only witnesses require terminal caller storage to survive dispatch, then exact child/grandchild absence before the independent observer reads child-before-supervisor events. Both terminal payloads have immediate UD2 sentinels. An unrelated Created process retains its exact record, empty capability inventory and mappings until explicitly aborted. All four additional lifetimes and twenty-two mapped pages must be disposed for ERIX_KERNEL:CHILD_EXECUTION_OK.

Four strict Kernel configurations pass 720/744 library tests and both standalone controls; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Signed Integration c14c5a61 requires the additional marker while preserving every earlier marker and the original 60-second limit. Both actual native scenarios pass, with 1,870/1,587 complete serial bytes, empty QEMU stderr and no build warnings. Packaged Kernel bytes equal retained original artifacts after normal stripping; all fifteen original source signatures verify. Lifetime serial SHA256 is 1b2f983239efca55c8bc0f6f08ee91cfdcd37d4d1f6951bbd740e4d9b45d1a2f. Four current Integration 320/321-test configurations, native builds, strict Clippy, formatting, private rustdoc and updated policy checks pass. Earlier 169-helper evidence is hash-verified against unchanged orchestration; it was not rerun for these scenario/catalog changes.

Signed Docs b4b01d87 documents the executing-child observations and remaining limits. All 45 tests, the full 2,425-page manual, 447,382 word bounds and visual review of the changed pages pass, with zero final warnings. The API reference source is unchanged.

This extends native executing-child evidence; it does not establish no-successor native idle/wake behavior, provider completion, Procd adoption or a complete service lifecycle. The original install-grant constructor still gives GRANT | MINT while binding needs only GRANT; move-only transfer preserves exact rights. Both diagnostic grants are consumed, but rights minimization remains an explicit audit follow-up. Full source/effect/frame proof, the Pagerd gate, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related implementation tracking: Kernel feature, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Original Kernel CI 614 and 615 pass from four complete hashed logs, 753,462 bytes, without warnings. Original Docs CI 983 and 984 pass from four complete hashed logs, 773,542 bytes. Both pass all 45 tests and the complete 2,425-page final manual; reference-resolution warning counts are 36/1/0, with zero final warnings. Original Integration CI 1685/1686 remains queued at its second observation.

Older original Integration CI 1678 passes all 489 catalog scenarios and both native Kernel diagnostics, then fails the development COM1 editor probe after its physical counterpart passes. Rust and Markdown pass. All three complete logs total 13,384,697 bytes with no warnings; the outer input status does not establish cause. The canonical bug report is issue 67, with bug/ci/phase-6 metadata. Earlier editor and filesystem failures remain separate. No original workflow was cancelled or rerun.

Native cleanup without a userspace successor — 19 September 2026: signed Kernel 2cf5b34c adds a seventh actual CPL3 caller to the maintained lifetime diagnostic. After every earlier assertion, the observer binds/starts the final child and yields. The child kills that supervisor through its own explicit Process SEND route. Immediate faulting sentinels forbid either terminal payload from resuming. Ordinary native return closes CPU accounting, detaches current attribution, progresses reclamation and finds no runnable successor.

A diagnostic-only read-only witness then requires empty CPU accounting, only terminal retained records, no bound cleanup duties or event reservations, exact child identity/CSpace/mapping absence and both unconsumed child-before-supervisor events. All six final child pages retire; three original unbound terminal records remain for prior assertions. The witness neither performs cleanup nor selects a process nor installs an interrupt. ERIX_KERNEL:CHILD_IDLE_CLEANUP_OK precedes completion before HLT, so actual hardware halt/wakeup remains a separate gate.

Signed Integration 4d6f4fe8 requires the additional marker while preserving all earlier assertions and both 60-second scenario limits. Both actual native VMs pass: 1,905/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256: 4a7cba61f75f4eeac47896d165b8dbcd217e4c75e2a81c8ae0f29957facb929c. Packaged Kernel images match retained build artifacts after normal stripping; all fifteen original component signatures verify. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Post-VM changes only select updated Docs in full catalogs and update roadmap status.

Signed Docs 69466a64 documents the pre-halt boundary and consolidates stale status paragraphs. All 45 tests, the complete 2,425-page manual, 447,534 word bounds and visual review of pages 562–564 pass with zero final warnings. API reference source remains unchanged. The static audit passes 3,140 authored code files below 1,000 lines, 74 manifests, 259 full Git selections, 171 direct missing_docs gates and 92 conventional crate roots; semantic authority and complete private-rustdoc closure remain open.

Original Kernel CI 616 and 617 pass from four complete hashed logs, 753,458 bytes, with no warnings. Original Docs CI 985 and 986 also pass: four complete hashed logs, 773,510 bytes; both pass 45 tests and the final 2,425-page manual. Reference-resolution warning counts are 36/1/0 with zero final warnings. Original Integration CI 1687/1688 remains queued at its first observation.

Older original Integration CI 1677 is now terminal failure: all 489 catalog cases, both native diagnostics, development physical/COM1 editor and release physical editor pass before release COM1 fails. Rust and Markdown pass. Three complete logs total 13,385,246 bytes without warnings; bug 37 retains this evidence. Companion 1678's earlier development COM1 failure remains separate in bug 67; a common cause is unproven. No original workflow was cancelled or rerun.

Further native failure controls, grant-rights minimization, terminal accounting, Procd adoption and complete service lifecycle acceptance remain open. Existing install-grant creation still supplies GRANT | MINT while binding needs GRANT, so minimum authority is not claimed. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Native terminal-event allocation refusal — 19 September 2026: signed Kernel ba03995f extends the actual executing-child sequence with one deliberately refused heap allocation. Separate diagnostic preparation captures the original supervisor, child, staged grandchild and independent process records/capability inventories, then gives an empty event queue one-event capacity. No queued event or existing reservation is discarded. The first terminal-event reservation succeeds; the second arms exactly one null return from the real Kernel allocator. Ordinary collection growth and Process dispatch return RESOURCE_EXHAUSTED before any terminal effect.

Read-only witnesses require complete reservation rollback, an empty event queue, unchanged exact records and capabilities, and preserved code/stack/message mapping ranges. Actual CPL3 instructions validate the refusal reply before the next ordinary ancestor kill succeeds with allocation available. Every earlier terminal, descendant-disposal, independent-process and no-successor idle assertion remains required. ERIX_KERNEL:TERMINAL_EVENT_RESERVATION_OK requires one consumed allocator refusal and no remaining armed fault. Fault controls are absent from ordinary images; this covers injected allocation failure, not spontaneous heap exhaustion or independent resource-release failure. No witness supplies a syscall result, cleanup effect or scheduler choice.

Signed Integration cf5b2f5f requires the new marker without changing either 60-second limit. Both maintained native VMs pass: 1,948/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is d485019082175f769ecc2d406d88c6cc84a7df323605027663f5bcc79ca03ad9. Packaged Kernel bytes match retained original artifacts after normal stripping, and all fifteen original source signatures verify. Post-VM changes only select updated Docs in full catalogs and consolidate roadmap status.

Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and updated policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 62ba2ffa passes 45 tests, the complete 2,425-page manual, all 447,688 word bounds and actual visual review of pages 562–565, with zero final warnings; API reference source remains unchanged. The static audit passes 3,142 authored code files below 1,000 lines, 74 manifests, 259 full Git pins, 171 direct missing_docs gates and 92 conventional roots. Complete semantic authority and private-rustdoc closure remain open.

Original Kernel CI 618 and 619 pass from four complete hashed logs, 753,434 bytes, with zero warnings. Original Docs CI 987 and 988 pass from four complete hashed logs, 773,506 bytes: both pass 45 tests and the final 2,425-page manual, with reference-resolution warning counts 36/1/0 and zero final warnings. Original Integration CI 1689/1690 is queued. Earlier filesystem, directory, editor and full-frame regressions remain unresolved; original workflows were not cancelled or rerun.

The terminal-accounting audit confirms that ordinary Procd terminal handling queries original TCB counters after receiving its event, while automatic bound-child reclamation removes that TCB. Its separate private-mediator branch does not take the same query path; adoption must state which lifetimes require retained metrics and preserve their original generation without fabricated zero/wall-clock values. Independent release-failure coverage, grant-rights minimization, accounting, Procd adoption and full mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Independent native child release recovery — 19 September 2026: signed Kernel 82d88b60 extends actual supervisor-exit coverage with two deliberate refusals at the original staged child's final VSpace-release callback, after capability disposal and unlinking. The first error is KernelHeapExhausted, the second CspaceSlotMissing. Read-only observations around two ordinary CPL3 observer yields require the original full record, generation, abort custody and first error retained, an empty original CSpace and retained mapped backing. The independent running child must already be absent from native TCB, CSpace and VSpace directories. The selected child's earlier directory position ensures its failure preceded that independent disposal.

The third callback must perform normal VSpace release before all original terminal-event, generation and resource-absence checks pass. ERIX_KERNEL:CHILD_RELEASE_ISOLATION_OK requires exactly two refusals and complete eventual disposal. Fault control uses only atomics at the locked callback boundary and exists only in the isolated native diagnostic. No witness performs cleanup, supplies a successful release/syscall result or chooses a scheduler target. This establishes injected callback-refusal coverage, not an observed hardware or allocator malfunction. All earlier nested-child, allocation-refusal and no-successor pre-halt assertions remain required.

Signed Integration 294a467a requires the added marker with both original 60-second limits unchanged. Both maintained native VMs pass: 1,988/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is 606fff037be022c876220d8e8f329c9046ffea5dcdf80831026649aedfbe0b08. Packaged Kernel bytes match retained original unstripped artifacts after normal stripping, and all fifteen original component signatures verify. Post-VM changes only select the updated manual source in full catalogs and reconcile roadmap status.

Four strict Kernel 720/744-test configurations, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test configurations, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 2a0ccc1a passes 45 tests, the complete 2,427-page manual, all 447,789 word bounds and actual visual review of pages 562–565 with zero final warnings. API reference source is unchanged. Static audit passes 3,143 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 171 direct missing_docs gates and 92 conventional roots; complete semantic authority/private-rustdoc closure remains open.

Original Kernel CI 620/621 and Docs CI 989/990 pass from four complete hashed logs each (753,438/773,910 bytes), with zero final warnings. Current Integration originals are observed after publication. Earlier filesystem, directory, editor and full-frame regressions remain unresolved, with original evidence retained; no workflow is cancelled or retried unchanged.

The grant-rights audit confirms actual Procd derivation callers and exact GRANT | MINT receipt checks in Procd and Launchd. Grant authority minimization must coordinate those consumers and distinguish the grant's own rights from its installation ceiling. Original generation-bound terminal accounting, Procd adoption, provider completion, hardware halt/wakeup and complete mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Manual and dependency validation — 20 September 2026:

Docs commit f4621ce2921b2b9fe3b1d25b4321d6b28289418e is signed and pushed. Native selectors 32/33/54 now document exact own rights separately from installation ceilings. The process and launch chapters require GRANT-only final receipts, explicit derivation/source disposal, and original-generation rollback. Both IPC references are regenerated from signed source. All 45 tests and API checks pass; the complete 2,429-page manual has zero final warnings, all 448,913 word bounds pass, and eleven changed pages were visually reviewed. Original Docs CI 991/992 passes with four complete hashed logs, 774,346 bytes, both 45-test runs and final 2,429-page manuals. Intermediate TeX reference warnings resolve before the final pass.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open.

Verified managed installer recovery — 21 September 2026:

Signed Integration 648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d in WIP PR 12 selects signed Procd ac8a12993bc8cbf134a11e141e459cb63df71123 and Docs PR 4. Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed.

Procd bug 4 is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings.

The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes.

The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open.

Committed terminal-accounting consumers — 21 September 2026:

Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.

Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.

Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.

The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.

No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.

Explicit frame-tool manual — 21 September 2026: signed f8a40d45fbbd631660f3adca9152fbb398a4ee6d documents selected disassembler/helper custody, minimal child environment, bounded cleanup and preserved failure evidence. All 45 tests, the complete 2,431-page manual and 449,997 rendered word bounds pass. The changed page passes visual review, final warnings are absent and shared API reference sources remain unchanged. Original CI 999/1000 is monitored separately. Full native Rust/LLVM/runtime rebuilding and both EriX guest build generations remain required in Phase 6 completion.

Original frame-manual CI acceptance — 21 September 2026: signed f8a40d45fbbd631660f3adca9152fbb398a4ee6d passes both original 999/1000, including 45 tests and the complete 2,431-page manual. Four complete hashed logs total 774,750 bytes. Each manual log retains 37 initial warning candidates; LaTeX reference-convergence passes report 35/1/0 warnings, and the final pass has no warnings or layout overflow. These expected early convergence messages remain visible in the original logs. The native external toolchain rebuild and both full guest build requirements remain open.

Signed startup source/feature correction — 21 September 2026:

Integration fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure.

All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; bug 71 retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices.

The technical manual update 76672dff8ff83 passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs 1001/1002 passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow.

A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under bug 69; no threshold or 120/15/10 capture limit changes. Original Integration 1705/1706 is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory.

Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.

Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.

Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.

Executed-code profiling checkpoint — 22 September 2026: signed Integration 4fa27f942bc2, tracked in Integration PR 12, adds bounded host TCG execution counters, explicit fresh-output ownership and exact packaged-ELF code candidates without adding guest authority. All 172 maintained helper commands pass without warnings. The profiler passes five Rust tests in both profiles, strict Clippy, private rustdoc, eleven Python controls and five actual selected-emulator controls. Unchanged orchestration inputs retain their preceding four strict matrices. The operator guide distinguishes complete counters from VM acceptance.

One original-image diagnostic retains 92,896 translated blocks, 1,994,216 code bytes and zero missed execution counts. Its top 100 code groups cover 85.65% of the translated instruction upper bound; 33.30% has Kernel mapping-batch candidates and 7.70% has VSpace permission-switch candidates among the selected ELF inputs. Unknown and ambiguous work remains visible. These are code matches, not process ownership or elapsed-time attribution. Both the instrumented attempt and its same-emulator uninstrumented control fail waiting for the final native-command marker under unchanged 120/15/10 collection bounds. Neither proves startup acceptance, whole-transcript instrumentation overhead or a speedup. Profiler acceptance and startup performance remain open. The next optimization must preserve complete validation, live backing checks, page permissions, invalidation ordering and cleanup on errors.

The signed manual update, tracked in Docs PR 4, passes 45 tests, all 2,431 pages, 450,367 word bounds and both changed-page visual reviews with zero final warnings or overflow. Original Docs CI 1005/1006 passes from four complete logs (774,674 bytes); initial reference-convergence warnings resolve on the final passes. Integration 1711/1712 is queued, while original 1701/1702 still runs. Existing queued jobs remain untouched. All 3,174 authored code files remain below 1,000 lines. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and completing the required full guest-build generations remain mandatory and unproven.

Ordinary mapping-domain checkpoint — 22 September 2026: resolved admission report records the original host failure and bounded fix. The fixture regression retains all three distinct failed attempts and the verified layout correction. Kernel now validates the complete ordinary user page before backing or mapping changes, with both control paths covered. Four strict 745/769-test configurations, thirteen native builds, Clippy and private rustdoc pass without warnings. Three exact-source native executions pass lifetime, invocation and mapping; four maintained scenario contracts are checked, with sparse and isolation sharing their identical runtime capture. All fifteen selected native signatures and packaged Kernel identities verify.

Integration pins the exact Kernel in all three catalogs, preserves every other selection and passes all 172 helpers. The unchanged ordinary exec-successor VM passes against the complete source graph, preserving its 120-second guest deadline, with no image warnings or QEMU stderr. Docs documents the domain and bootstrap distinction; all 45 tests and 2,431 pages pass, with 450,473 word bounds checked and no final warnings. The earlier Kernel CI 632/633 passes from four complete logs and zero warnings; current original CI remains under observation.

Bootstrap provenance, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Verified documentation and CI follow-up — 22 September 2026: Kernel documentation and Integration documentation record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in report 24, separately from the fixed admission defect. The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure.

Original full Integration 1703/1704, source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel 634/635 report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel 636/637 and Docs 1007/1008 pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued.

The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open.

VSpace MAP authority checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Current local MAP rights now govern map, protection and unmap requests. Empty and MANAGE-only aliases are denied; MAP-only access remains valid. Four strict 750/774-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The Integration catalog selects the exact signed Kernel in all three catalogs and passes all 172 helpers. Actual CPL3 calls preserve the authorized RW/NX page across restricted-alias refusals and drop all five temporary grants. Three native executions cover all four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signed sources and retained packaged artifacts. The original exec-successor service VM passes against all 73 components with its unchanged 120-second guest limit. All image warnings and QEMU stderr remain absent. Manual validation passes 45 tests, 2,431 pages and 450,550 checked word bounds, with both changed pages reviewed and zero final warnings.

The static audit covers 3,181 authored code files below 1,000 lines, 259 exact Git dependency pins and existing direct missing_docs gates. It does not close semantic authority review. Earlier full Integration runs 1705/1706 are running; 1707–1720 remain queued at the latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 638/639 and Docs 1009/1010 pass. Each pair has four complete logs: Kernel totals 777,250 bytes with zero warnings, and Docs totals 774,674 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1721/1722 remains queued; it receives no CI acceptance credit.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven.

Frame access checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Explicit READ now governs admission and hardware activation. No-access mappings retain backing with USER/WRITE clear and NX set; write-only and execute-only requests are rejected without adding READ. Existing protection-transition rules remain in force. Four strict 757/781-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The Integration catalog selects the signed Kernel in all three catalogs and passes 172 helpers. Twenty-four actual CPL3 calls preserve earlier witnesses and cover no-access protection, write-only refusal, MAP-only frame derivation, denied READ and unmap after both frame grants are dropped. Three native executions pass four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signatures and retained packaged artifacts. The ordinary exec-successor VM passes against all 73 components with its unchanged 120-second guest limit. Builds emit no warnings and QEMU stderr is empty. Manual validation passes 45 tests, 2,433 pages and 450,702 checked word bounds, with the changed page reviewed and zero final warnings.

Static review covers 3,182 authored code files below 1,000 lines, 259 exact Git pins and existing direct missing_docs gates. This does not close semantic authority review. Earlier full Integration runs 1705/1706 remain running and 1707–1722 remain queued at their latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 640/641 and Docs 1011/1012 pass. Each pair has four complete logs: Kernel totals 782,838 bytes with zero warnings, and Docs totals 775,110 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1723/1724 remains queued; it receives no CI acceptance credit.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Authorized protection restoration, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Ordinary protection contract — 22 September 2026: the runtime memory design now specifies in-place no-access/R/RW/RX changes using current VSpace MAP and exact selected frame authority, including same-backing aliases and complete backing checks. Preserve W^X, explicit READ, object kind, reference custody, error ordering and all native witnesses. Kernel-owned anonymous loader materialization and Process endpoint target scope retain separate audit obligations. The implementation and exact-source VM evidence are pending. This earns no canonical acceptance credit; external toolchain rebuilding and both complete EriX guest-build generations remain mandatory.

Current-grant protection checkpoint — 22 September 2026: the resolved device-backing report distinguishes its original metadata-authority inconsistency from the separate restoration feature gaps. The Kernel implementation permits representable no-access/R/RW/RX changes through current exact-backing grants and aliases while active or inactive. It removes historical access ceilings and original-slot equality while preserving current VSpace MAP, selected frame rights, kind/range/identity checks, W^X, explicit READ, backing custody and failure ordering. Four strict 766/790-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The coordinated catalog selects that original signed Kernel in all three catalogs and passes all 172 helpers. Fifteen managed-frame calls and twenty-nine device/domain calls pass inside the original lifetime window and deadline. Actual user instructions write, execute, rewrite and execute managed RAM, check narrow alias authority and final disposal, while a reused device slot cannot authorize unrelated backing. Every prior marker remains required. Three native executions pass four original contracts with complete signed source and artifact checks; the ordinary exec-successor VM passes the full 73-component graph and original 120-second limit. Image warnings and QEMU stderr are absent. Manual validation passes 45 tests, 2,433 pages and 450,954 word bounds; both changed pages are reviewed with no final warnings or overflow.

Static review covers 3,184 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins and 174 direct missing_docs gates. Full semantic authority review remains open. Older Integration CI 1705/1706 has eleven real ext4 timeouts across eight scenarios, with complete retained logs and no accepted rerun. Their root cause and correction remain unresolved. Publication CI: Kernel 642/643 and Docs 1013/1014 pass. Each pair has four complete original logs: Kernel totals 790,650 bytes with 766/790 tests and zero warning candidates; Docs totals 775,150 bytes with 45 tests, 2,433 pages and zero final warnings or overflow. Retain the original 35/1/0 LaTeX warning convergence. Integration 1725/1726 remains queued and receives no completed CI acceptance. The separate older ext4 deadline report remains open.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Complete POSIX protection support, Process endpoint scope, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Supervisor physical-access window — 22 September 2026: the signed Kernel implementation shares one restoring supervisor scratch transaction between frame scrubbing and physical mapping-byte copies. Caller backing custody and page-table/interrupt custody remain live through byte access, exact leaf restoration and local invalidation. Scratch is released afterward; read aliases clear the write bit and all temporary aliases clear user access and set NX. The unreachable raw-VA fallback is removed, and complete preflight rejects missing or ambiguous backing metadata before any range effects. No new userspace operation or capability grant is introduced. This is preparatory work for owned address spaces; independent roots and their switching/reclamation proof remain open.

Eight added host controls cover geometry, permissions, preparation and partial-effect failures, restoration/release ordering, and malformed later-page metadata without partial reads or writes. Four strict host configurations pass 774/798 tests with three existing ignored cases. Fourteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. The coordinated Integration catalog passes all 172 maintained helpers; its exact marker expectation is updated alongside the strengthened scenarios. Unchanged orchestration and profiler sources retain strict validation.

Six native executions satisfy seven maintained scenario contracts. Both allocator scenarios require the new same-VA/different-backing byte-and-leaf proof after complete cleanup, retaining every preceding marker and the original 60/120-second deadlines. Three further executions satisfy mapping, sparse, owned-invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Exact original signed source, retained artifacts and packaged Kernel matches are verified; no image warnings or QEMU stderr were observed. These checks establish no performance improvement. The technical manual documents backing and scratch custody; all 45 document tests and the complete manual build pass without final warnings.

Static checks cover 3,190 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Complete semantic authority and inline-documentation review remain open. Publication CI: Kernel 648/649 and Docs 1015/1016 pass. Eight complete original logs (1,572,758 bytes) confirm Kernel 774/798 tests, 45 document tests and the 2,433-page manual. Initial TeX reference warnings resolve through normal multipass generation; final passes are clean. Integration 1731/1732 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and its runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Owned supervisor baseline — 22 September 2026: the signed Kernel implementation captures and verifies independently allocated supervisor tables before root VSpace creation, Rootd preparation and RAM seeding. Each copied page has one typed aligned Box owner before a parent references it; the recursive entry selects the copied root. Source boot/AP tables and mapped backing retain separate custody. User leaves, malformed geometry and invalid recursive identity are refused. Leaf permissions, cache policy and huge-page sizes are preserved; newly owned table branches use WriteBack and clear USER. Failed construction releases all unpublished allocations. This replaces a raw-pointer table-storage owner with shared typed storage and adds no unsafe Send/Sync implementation or userspace operation.

Eleven new host controls cover independent storage, allocation/read failures, invalid translation geometry, user leaves, recursive and huge-page errors, source-permission drift, retained owner links and table counts beyond the unrelated 64-page batch size. Four strict host configurations pass 785/809 tests with three existing ignored cases; fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The coordinated catalog passes all 172 maintained helpers. Both allocator scenarios require successful baseline capture before their original marker sequence, with capability grants and original 60/120-second deadlines preserved.

Six native executions satisfy seven maintained contracts: both allocator scenarios, mapping and sparse checks sharing identical runtime settings, owned invocation, lifetime revocation and ordinary exec-successor across all 73 components. Exact signed source and retained packaged artifacts are verified; no image warnings or QEMU stderr were observed. The technical manual specifies the custody boundary and passes 45 tests, complete 2,433-page generation, all 451,287 word bounds and changed-page visual review without final warnings or overflow. Static audits cover 3,194 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots.

Publication CI: original Kernel push 650 passes and PR 651 retains the host fixture failure. Regression 29 is resolved by signed Kernel 12184850cd73: a deterministic private predecessor reproduces the original defect, and the corrected fixture passes the complete local matrix and push CI 652/PR CI 653. Four complete corrected CI logs total 807,886 bytes with zero warning candidates. Only host tests and roadmap change; validated production sources and all catalog selections remain unchanged. Docs 1017/1018 pass with four complete logs (775,122 bytes), 45 tests and the 2,433-page manual. Initial TeX reference warnings resolve before clean final passes. Integration 1733/1734 remains queued at the latest retained observation and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. The retained baseline is a construction prerequisite for owned address spaces. Per-VSpace population, CR3 activation, invalidation and live-root reclamation remain open, and no speedup is claimed. Full semantic authority and inline-documentation review also remain open. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Huge-leaf geometry correction — 22 September 2026: the bug report preserves four original host failures and one passing WriteBack control. The signed correction separates PAT from physical address bits, preserves permissions/cache indices across both huge splits, and gives newly allocated tables WriteBack policy. Scalar and batched translation, split preparation, snapshots and baseline validation share the documented geometry. No new userspace authority, original native exploit or universal boot failure is claimed.

Four strict Kernel configurations pass 796/820 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: mapping and sparse, lifetime, invocation, both allocator checks and ordinary exec-successor across all 73 components. The new native witness verifies real 2 MiB PAT translation, splitting and complete restoration; host controls additionally cover 1 GiB. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and changed-page visual review without final warnings or overflow.

Publication CI: Kernel 654/655 and Docs 1019/1020 pass. Eight complete original logs (1,592,794 bytes) confirm Kernel 796/820 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1735/1736 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,197 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, live-root reclamation and full semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.

First-start register custody — 22 September 2026: the stack-domain bug report preserves three original host failures and one valid-stack control at unchanged production sources; the same four controls pass against the signed correction. Ordinary anonymous stack materialization now rejects addresses outside the existing user domain, and direct bootstrap writes require retained writable registered backing. Initial registers have Kernel-owned storage; stack preparation preserves the synthetic return slot, complete admission, startup arguments and rollback. The obsolete saved-frame user overlay and directory scan are removed. Complete external start-context admission and the separate bootstrap code/stack overlay remain distinct work.

Four strict Kernel configurations pass 807/831 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: lifetime, invocation, mapping and sparse, both allocator checks and ordinary exec-successor across all 73 components. The new witness checks all original initial register words after two real user stack mutations and before ordinary syscall capture. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and four changed-page visual reviews without final warnings or overflow.

Publication CI: Kernel 656/657 and Docs 1021/1022 pass. Eight complete original logs (1,600,791 bytes) confirm Kernel 807/831 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1737/1738 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,201 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, CPU residency, live-root reclamation and complete semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.

## Summary and rationale Document shared compiler metadata consistency, equal-byte reuse, exclusive destination creation and cache ownership across executable and shared-library producers. Provider provenance, source lifetime and scratch cleanup remain explicit caller obligations. Specify single-driver dynamic linking, exact compiler-host discovery when standalone tools are absent, preserved driver aliases, fatal warnings and visible successful diagnostics. A selected driver failure does not authorize another implementation or publication of partial output. Document unambiguous Rust runtime archive selection for fresh Kernel, Rootd and service links, including the separate provenance, cache-coverage and toolchain-lifetime obligations. The corresponding implementation is tracked in [Integration issue 62](https://git.erikinkinen.fi/erix/integration/issues/62). Document native staged construction, grant custody and authenticated caller admission; specify owned shell workspaces and exact source/artifact/frame evidence. Correct the syscall reference and native entry contract: IRETQ return, the 136-byte saved prefix, 176-byte transient reservation, separate kernel stack, preserved user flags, aligned exception calls and five/six-word hardware frames. Document complete borrowed syscall capture, initialized stable storage and resource refusal before operation dispatch. Render literal command-option bytes without changing their meaning. Describe one-way VSpace retirement, recorded withdrawal progress, consumed frame references and retained final-process custody. Keep that contract separate from whole-process destruction and ordinary VSpace activation. Describe process cleanup custody, non-executable abort/destruction states, retained private CSpace identity and the exact final retirement commit. Earlier partial cleanup is not represented as whole-process rollback. ## Tracking and scope Signed head `64fc14411a3f1629ace2854ddc1c3b7875113343`, branch `feature/posix-compat`. Documentation audit #1; command rendering #8; corrected syscall reference #9 and entry documentation #10. Dependent reviews: [Kernel](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration](https://git.erikinkinen.fi/erix/integration/pulls/12), [Exsh](https://git.erikinkinen.fi/erix/exsh/pulls/3), and [lib-dynlink](https://git.erikinkinen.fi/erix/lib-dynlink/pulls/3). [Realm design](https://git.erikinkinen.fi/erix/posixd/issues/1), runtime acceptance and both full guest builds remain open. ## Architecture, authority and failure behavior Staged construction omits child root capabilities while retaining native TCB backing. Procd authenticates the pending caller against its Launchd owner and generation. Identities and bearer senders cannot replace actual authority; rejected transfers retain cleanup obligations. Mediator start and sealing are separate contracts. The manual introduces no runtime capability or ABI change. Ordinary and emergency I/O own distinct authenticated workspace slices. Cleanup borrows and erases its complete slice. Paired ELF evidence binds zero-fill ownership, target layout, stack, bytes and permissions. Mapping evidence cannot establish source borrowing or all-path safety. Missing proof remains incomplete. Ordered providers and checked relocation expressions precede protected-slot admission. Composed graphs retain object-qualified identities and grounded dependencies. Live caller intervals constrain conditional callee writes while preserving return-address gaps and invalidating overlapping saves; conditional masks never become unconditional guarantees. Rejection-only scheduling and deduplicated CFG work retain proof decisions without arbitrary pass limits. Static receipts, host profiling, guest probes and full builds have distinct acceptance requirements. ## Validation evidence The matching signed [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), `54557713f4afad380c1166f6aa1c1622d3959744`, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original [Docs CI 979](https://git.erikinkinen.fi/erix/docs/actions/runs/979) and [980](https://git.erikinkinen.fi/erix/docs/actions/runs/980) pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required. Native child-custody wire checkpoint — 19 September 2026: signed [lib-ipc PR 2](https://git.erikinkinen.fi/erix/lib-ipc/pulls/2), `aaf2df39700b43507b23ff2007bc0d573c4eea30`, implements `ChildLifetimeBindingV1`, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the [shared contract](https://git.erikinkinen.fi/erix/lib-ipc/src/commit/aaf2df39700b43507b23ff2007bc0d573c4eea30/docs/child-lifetime-binding.md) and [Kernel design #19](https://git.erikinkinen.fi/erix/kernel/issues/19). Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original [lib-ipc CI 365](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/365) and [366](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/366) pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph. Native external-toolchain rebuild requirement — 19 September 2026: Signed `b54d28e755dd415079100a19683ee1474edb4ed1` makes the native rebuild an explicit Phase 6 verification and acceptance gate. The first compiler may be cross-built for EriX against its libc/sysroot, Rust OS bindings and declared C/C++ runtime closure. The extended development image must then rebuild the selected upstream Rust/LLVM toolchain inside EriX using supplied offline recipes and an explicit bootstrap compiler. Require working guest-built tools and use in at least one full EriX build, with no unrecorded porting changes, downloads, Linux executables or host build delegation. Complete source, runtime, log and measured-resource evidence is required; compiler ownership remains distinct. All 45 documentation tests and the full 2,419-page manual pass, with 445,775 in-bounds word boxes, actual visual review of the changed page and zero final warnings. Shared API snapshots are unchanged. [The phase master](https://git.erikinkinen.fi/erix/integration/issues/65), [toolchain issue](https://git.erikinkinen.fi/erix/integration/issues/7) and [full-build issue](https://git.erikinkinen.fi/erix/integration/issues/9) contain the matching requirements. Original documentation CI is under observation; the native toolchain rebuild and both OS builds remain unproven. Original coherent realm source CI acceptance — 18 September 2026: Signed `33733ceba228669e27152aee32f997d6c72264ff` passes [CI 972](https://git.erikinkinen.fi/erix/docs/actions/runs/972) and [CI 971](https://git.erikinkinen.fi/erix/docs/actions/runs/971). All four terminal logs are complete (772,194 bytes), with zero final warnings. This closes the original CI observation recorded above. All 45 tests and both 2,419-page manuals pass; reference-pass warnings converge 36/1/0. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements. Realm startup consumer manual checkpoint — 18 September 2026: Signed `33733ceba228669e27152aee32f997d6c72264ff` describes exact realm startup consumers, explicit disabled or positive deployment capacity and the reviewed Rootd production audit. All 45 tests and the complete 2,419-page manual pass, with 445,650 word boxes within page bounds, two visually reviewed changed pages and zero final warnings. Shared API snapshots are unchanged. Original CI 971/972 is under observation. Coherent catalog adoption and actual consumer VMs remain required before image acceptance; no runnable realm or full guest build is claimed. Original public realm dispatch manual CI acceptance — 18 September 2026: Signed Docs `099f0c570414ca486bb2104c1510fbf3b84d59fb` passes [CI 969](https://git.erikinkinen.fi/erix/docs/actions/runs/969) and [CI 970](https://git.erikinkinen.fi/erix/docs/actions/runs/970). All four terminal logs are complete (772,182 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Public realm dispatch and progress checkpoint — 18 September 2026: Signed `099f0c570414ca486bb2104c1510fbf3b84d59fb` is pushed. The manual describes public realm intake, independently held replies, original-parent cleanup and fair native progress before ordinary dispatch, while preserving separate consumer VM and guest-build acceptance. All 45 tests and the complete 2,419-page manual pass. All 445,563 word boxes are within page bounds; both changed rendered pages are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI is under observation; no runnable realm or guest build is claimed. Original exact preparation manual CI acceptance — 18 September 2026: Signed Docs `880bdc59818b1eff9cf9929004680f354f8265a0` passes [CI 967](https://git.erikinkinen.fi/erix/docs/actions/runs/967) and [CI 968](https://git.erikinkinen.fi/erix/docs/actions/runs/968). All four terminal logs are complete (772,086 bytes), all 45 tests pass and both complete 2,419-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Exact realm executable preparation checkpoint — 18 September 2026: Signed `880bdc59818b1eff9cf9929004680f354f8265a0` is pushed. The manual documents actual exact preparation, shared authentication, scratch reuse and independent retained cleanup, while keeping dispatcher, scheduler and consumer-image requirements open. All 45 tests and the full 2,419-page manual pass; all 445,389 word bounds and both changed rendered pages are reviewed, with zero final warnings. Shared API snapshots are unchanged. Original CI 967/968 is under observation. Complete mediated execution and both full builds inside EriX remain required. Original realm admission manual CI acceptance — 18 September 2026: Signed Docs `9868cf0e6f2c366b4a2c7992594a83c72789f1f0` passes [CI 965](https://git.erikinkinen.fi/erix/docs/actions/runs/965) and [CI 966](https://git.erikinkinen.fi/erix/docs/actions/runs/966). All four terminal logs are complete (771,742 bytes), all 45 tests pass and both complete 2,417-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Caller-bound realm record checkpoint — 18 September 2026: Signed `9868cf0e6f2c366b4a2c7992594a83c72789f1f0` is pushed. The manual describes exact realm admission messages, original-caller binding, explicit LCH1 version-3 capacity and independent native storage. Four API references select the signed shared graph; stale bootstrap width, version and route-stride prose is corrected. All 45 tests, API provenance/regeneration checks and the complete 2,417-page manual pass. All 445,195 word bounds are valid, seven rendered pages were reviewed and final warnings are zero. Original CI 965/966 is under observation. Actual runtime admission, coherent image consumers, mediated client I/O and both full guest builds remain open. Original retained caller manual CI acceptance — 18 September 2026: Signed Docs `4dcbc10e32ebf257139bcbaf07bc1081b9589780` passes [CI 963](https://git.erikinkinen.fi/erix/docs/actions/runs/963) and [CI 964](https://git.erikinkinen.fi/erix/docs/actions/runs/964). All four terminal logs are complete (770,022 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Retained realm caller checkpoint — 18 September 2026: Signed `4dcbc10e32ebf257139bcbaf07bc1081b9589780` is pushed. The process-service manual describes the retained native caller, permanent source absence, cancellation ordering and independent child retirement. All 45 tests and the complete 2,409-page manual pass. All 443,468 word bounds are valid, both changed pages were visually inspected and final warnings are zero. No Rust implementation or generated API snapshot changes. Original CI 963/964 is under observation. Runtime admission, scheduler integration, consumer VM proof and both full guest builds remain separate requirements. Original supervisor manual CI acceptance — 18 September 2026: Signed Docs `a410759e5515b18107f25efb0319ad7c85871a64` passes [CI 961](https://git.erikinkinen.fi/erix/docs/actions/runs/961) and [CI 962](https://git.erikinkinen.fi/erix/docs/actions/runs/962). All four terminal logs are complete (769,994 bytes), all 45 tests pass and both complete 2,409-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Original supervisor manual checkpoint — 18 September 2026: Signed `a410759e5515b18107f25efb0319ad7c85871a64` documents private caller attestation, the exact 64-byte materialization begin, original ownership before creation and handoff, and separate caller RELEASE cancellation and application rollback. Three shared API snapshots match original signed source exports. All 45 tests, provenance/regeneration checks and the complete 2,409-page manual pass. All 443,265 word boxes are in bounds; seven rendered pages were inspected and final output has zero warnings. Original [CI 961](https://git.erikinkinen.fi/erix/docs/actions/runs/961) and [CI 962](https://git.erikinkinen.fi/erix/docs/actions/runs/962) remain under observation. Actual Launchd owned runtime adoption, consumer VM execution and both full guest builds remain open. Original owned bootstrap manual CI acceptance — 18 September 2026: Signed Docs `5c1cf6da319787738fa03f3cc6f526e49604aa09` passes [CI 959](https://git.erikinkinen.fi/erix/docs/actions/runs/959) and [CI 960](https://git.erikinkinen.fi/erix/docs/actions/runs/960). All four terminal logs are complete (769,578 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Owned bootstrap receiver checkpoint — 18 September 2026: Signed Docs `5c1cf6da319787738fa03f3cc6f526e49604aa09` updates the process-services contract and three source-bound shared API snapshots for the identity-only request and retained native delivery. All 45 tests, three signed API exports, provenance/regeneration checks and the complete 2,407-page manual pass. All 442,920 word boxes are in bounds; seven rendered pages were visually reviewed and final output has no warnings. Original CI 959/960 is under observation. Actual Launchd runtime orchestration, consumer VM execution and both complete guest builds remain open. Original receiver admission manual CI acceptance — 18 September 2026: Signed Docs `8361618f3f047479a9e52ffaba7f2607be99413c` passes [CI 957](https://git.erikinkinen.fi/erix/docs/actions/runs/957) and [CI 958](https://git.erikinkinen.fi/erix/docs/actions/runs/958). All four terminal logs are complete (769,554 bytes), all 45 tests pass and both complete 2,407-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Explicit owned receiver admission acceptance — 18 September 2026: Signed `8361618f3f047479a9e52ffaba7f2607be99413c`. The manual documents explicit receiver request limits, complete layout addressability, immutable registration and pre-custody refusal, with accurate allocation-observation scope. Three public API snapshots are regenerated from signed shared revisions. All 45 tests, provenance/regeneration checks and the 2,407-page manual pass. All 442,761 word boxes are in bounds; eight changed pages are visually reviewed, with zero final warnings. Original CI is under observation. Actual owned Procd/Launchd service adoption, consumer VM execution, complete realm fairness/readiness/sealing and both full builds inside EriX remain open. Original local grant relocation manual CI acceptance — 18 September 2026: Signed Docs `623609ee627a4afba1340ee06c53678c4a562a88` passes [CI 955](https://git.erikinkinen.fi/erix/docs/actions/runs/955) and [CI 956](https://git.erikinkinen.fi/erix/docs/actions/runs/956). All four terminal logs are complete (768,754 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Caller-local grant relocation checkpoint — 18 September 2026: Signed `623609ee627a4afba1340ee06c53678c4a562a88` documents syscall 0x54 register admission, actual Running caller and unique grant custody, exact error precedence and preserved installation/revocation scope. Three API references are regenerated from signed original shared revisions. All 45 tests, complete provenance/regeneration checks and the 2,403-page manual pass. All 442,370 word boxes are in bounds; nine changed pages are visually reviewed and final warnings are absent. The original whitespace preflight failure and subsequent terminology correction are retained. Original documentation CI is under observation. Actual owned service adoption, consumer VMs, complete realm fairness and both full builds inside EriX remain open. Original deferred-cleanup manual CI acceptance — 18 September 2026: Signed Docs `da66c0efd61fc05be023210e1c0c58196b51b878` passes [CI 953](https://git.erikinkinen.fi/erix/docs/actions/runs/953) and [CI 954](https://git.erikinkinen.fi/erix/docs/actions/runs/954). All four terminal logs are complete (768,726 bytes), all 45 tests pass and both complete 2,403-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Deferred native cleanup checkpoint — 18 September 2026: Signed Docs `da66c0efd61fc05be023210e1c0c58196b51b878` specifies one queued native attempt before intake, exact-generation owner rotation, first-error retention and acknowledgment-based removal. All 45 tests and the complete 2,403-page manual pass, with 441,578 in-bounds word boxes, two changed pages visually reviewed and zero final warnings. Shared API references are unchanged. Original documentation CI is under observation. Runtime consumer VM, complete realm fairness and full guest-build acceptance remain open. Returned-grant manual checkpoint — 18 September 2026: Signed Docs `b6bd8ce32891a8b298228b8320d0565cef89141f` documents the exact returned-grant request, custody acknowledgment, five retained scratch roles, native guard effects, source-absence requirement and cleanup boundaries. Three API snapshots come from the signed original component revisions; regeneration and provenance checks pass. All 45 tests pass. The complete 2,403-page manual has 441,471 in-bounds word boxes, seven changed pages visually reviewed and zero final warnings. Original [CI 951](https://git.erikinkinen.fi/erix/docs/actions/runs/951) and [CI 952](https://git.erikinkinen.fi/erix/docs/actions/runs/952) pass from all four complete logs (768,706 bytes); reference passes converge with 36/1/0 warnings and both final manuals have zero warnings. Runtime realm orchestration, actual consumer VM execution, fair progress and both complete builds inside EriX remain open requirements. Original cleanup manual CI acceptance — 18 September 2026: Signed Docs `323da983653e6d6d25d012c2354f97afaaaa0699` passes [CI 949](https://git.erikinkinen.fi/erix/docs/actions/runs/949) and [CI 950](https://git.erikinkinen.fi/erix/docs/actions/runs/950). All four terminal logs are complete (767,338 bytes), all 45 tests pass and both complete 2,397-page manuals have zero final warnings. Reference passes converge with 36/1/0 warnings. This closes the manual CI observation recorded above; complete Integration catalog, runnable realm and guest-build acceptance remain separate open requirements. Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision `323da983653e6d6d25d012c2354f97afaaaa0699` is pushed. The manual documents native cleanup 56/57, retired selectors, exact framing, original deferred identity and pre-service retirement. Three API references are generated from verified signed source revisions. All 45 tests pass. The complete 2,397-page PDF has zero final warnings and 440,339 in-bounds word boxes; seven changed pages have been visually inspected. The testing chapter corrects Rootd audit-size evidence and records the actual native diagnostic scope. Original CI 949/950 remains under observation. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open. Corrected original manual CI — 18 September 2026: Docs `10ea454ebab2cb0ca465cedf52ff619c1fc7efd4` passes original [CI 947](https://git.erikinkinen.fi/erix/docs/actions/runs/947) and [CI 948](https://git.erikinkinen.fi/erix/docs/actions/runs/948). All four logs are complete (765,634 bytes), all 45 tests pass, and the complete 2,389-page manual has zero final warnings after reference passes of 36/1/0 warnings. The later generation-bound cleanup manual update is still under local validation. Reviewed bootstrap baseline manual — 17 September 2026: Signed revision `10ea454ebab2cb0ca465cedf52ff619c1fc7efd4` updates the testing chapter to Rootd's reviewed 15,239-line release baseline and exact terminal-operation ownership. Compiler-specific binary size is explicitly separate from performance comparison. All 45 documentation tests and the complete 2,389-page manual pass; there are no final warnings, all 439,184 word boxes are in bounds, and page 2334 was visually reviewed. Earlier original CI 945/946 passes with all four logs complete (765,650 bytes; reference passes 36/1/0 warnings). The new signed revision's original CI remains under observation. Complete builds inside EriX and ordinary service-image adoption remain open. Coordinated terminal observation checkpoint — 17 September 2026: Signed revision `be98a93e6f34a9c7ecaffabfa0af1c8f209feff3` is pushed. The native and process-service manual contracts and three signed-source API snapshots are updated. All 45 documentation tests pass. The complete 2,389-page PDF has zero final warnings and 439,146 in-bounds word boxes; native, service and API pages were visually reviewed, including corrected literal shift operators. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open. - Current-head [push CI 937](https://git.erikinkinen.fi/erix/docs/actions/runs/937) and [PR CI 938](https://git.erikinkinen.fi/erix/docs/actions/runs/938) pass. All four complete logs are classified: 765,226 bytes, 45 tests, 2,387 pages, reference-resolution warning counts 36/1/0 and zero final warnings. - All 45 documentation tests, Markdown and canonical document-format checks pass. - The complete manual contains 2,387 pages and 438,174 in-bounds word boxes, with zero final warnings. Changed page 132 is visually reviewed. - Original cleanup-reference [push CI 935](https://git.erikinkinen.fi/erix/docs/actions/runs/935) and [PR CI 936](https://git.erikinkinen.fi/erix/docs/actions/runs/936) pass. All four complete logs are classified: 765,222 bytes, 45 tests, 2,387 pages, reference-resolution warning counts 36/1/0 and zero final warnings. - Preceding capture-reference [push CI 933](https://git.erikinkinen.fi/erix/docs/actions/runs/933) and [PR CI 934](https://git.erikinkinen.fi/erix/docs/actions/runs/934) pass. All four complete logs are classified: 765,238 bytes, reference-resolution warning counts 36/1/0 and zero final warnings. Earlier CI 931/932 passes with four classified logs and zero final warnings. - The earlier syscall and entry-documentation defects (#9/#10) remain closed after their separately retained successful CI cohorts. Generated API snapshots and runtime ABI are unchanged by this documentation correction. - No Rust crate is altered in this repository. Runtime and full guest-build validation belongs to the linked component reviews and is not implied here. Runtime archive checkpoint — 17 September 2026, signed `cf684745b08b59e0efc98c4b904708d0c17d735d`: All 45 documentation tests pass. The complete 2,387-page manual renders with zero final warnings and 438,260 in-bounds word boxes; page 2292 is visually reviewed. No Rust API, runtime code or API snapshot changes in this documentation checkpoint. Original Docs CI 939/940 passes with all four complete terminal logs classified (765,226 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Linker selection checkpoint — 17 September 2026, signed `050b9bcc3a5d8e0f57efc62e8775dee10a48af84`: All 45 documentation tests pass. The complete 2,387-page manual has 438,385 in-bounds word boxes and zero final warnings. Page 2292 is visually reviewed. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 941/942 passes with all four complete terminal logs classified (765,214 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open. Compiler metadata checkpoint — 17 September 2026, signed `64fc14411a3f1629ace2854ddc1c3b7875113343`: All 45 documentation tests pass. The complete 2,387-page manual has 438,492 in-bounds word boxes and zero final warnings. The changed paragraph is visually reviewed across pages 2292 and 2293. No Rust API or runtime source changes are included in this documentation checkpoint. Original Docs CI 943/944 passes with all four complete terminal logs classified (765,158 bytes). Reference-resolution passes contain 36/1/0 warnings; the final render has zero warnings. No earlier failed workflow is restarted. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open. ## Review checklist - [x] Signed canonical commits and current source/reference contracts. - [x] Tests, templates, Markdown, full manual layout and final-warning checks. - [x] Changed-page visual review and literal option-byte preservation. - [x] Classify preceding capture-reference CI (933/934). - [x] Classify preceding cleanup-reference CI (935/936). - [x] Classify current process-custody CI (937/938). - [ ] Complete dependent runtime, source/frame and self-hosting acceptance. Original [Docs CI 973](https://git.erikinkinen.fi/erix/docs/actions/runs/973) and [974](https://git.erikinkinen.fi/erix/docs/actions/runs/974), at `b54d28e755dd415079100a19683ee1474edb4ed1`, pass. All 45 tests and the complete 2,419-page manual pass; intermediate reference-resolution passes converge to zero final warnings. All four terminal logs are complete and hashed, totaling 772,186 bytes. This validates the native-toolchain rebuild requirement in the phase document and manual, not an actual toolchain or EriX build inside EriX. Signed private-route manual correction — 19 September 2026: `ce8a1538ab2220f1b346e1a051265f58f83f47fc` documents realm admission through both the public receiver and the shell's authenticated private script route, retaining original reply custody and caller proof. A stale startup-publication paragraph now states the permanent coherent-source and distinct runtime-evidence requirements. All 45 tests and the full 2,419-page manual pass; all 445,834 rendered words are within bounds, revised page 224 has been visually reviewed and final warnings are absent. Shared API snapshots are unchanged. Original [CI 975](https://git.erikinkinen.fi/erix/docs/actions/runs/975) and [976](https://git.erikinkinen.fi/erix/docs/actions/runs/976) are running. Native external Rust/LLVM rebuilding and both full EriX build generations remain required. Original manual CI 975/976 passes from all four complete hashed logs (772,174 bytes): 45 tests, the full 2,419-page manual and zero final-pass warnings. Signed Integration `9139c6c5fa38c139e92520f6d410626b4cf1e4aa` now adopts this documentation with the matching corrected-server VM, which passes its unchanged caller-admission scenario. Complete mediator execution, native toolchain rebuilding and both full guest builds remain required. Guarded-custody documentation reconciliation — 19 September 2026: signed [Posixd PR 5](https://git.erikinkinen.fi/erix/posixd/pulls/5), `9b031a8c2f996491a322046a4f2acd5dacdc55c2`, replaces stale grant-return and proposed-custody gaps with the implemented producer boundary. Procd uses the actual returned grant to attenuate the initial endpoint to RECV before execution, removes bypass sources, and retains nested custody beneath Kernel lifetime custody. A later mediator disposal report cannot prove absence of bypass senders. Exact staged abort and the remaining counted startup, readiness, configuration, sealing, client I/O and running-realm retirement requirements are distinguished. This repository still has no Posixd executable. Markdown, canonical headings/governance, local links, original source anchors and whitespace checks pass. Original [Posixd CI 17](https://git.erikinkinen.fi/erix/posixd/actions/runs/17) and [18](https://git.erikinkinen.fi/erix/posixd/actions/runs/18) both pass from two complete hashed logs totaling 7,232 bytes without warnings. Rust checks do not apply to this documentation-only repository. Signed [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), `7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d`, removes the matching stale passages from the process-services manual. All 45 tests and the full 2,419-page manual pass. All 445,847 word boxes lie within page bounds; the actual changed paragraphs and continuation on pages 222, 226 and 227 are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original [Docs CI 977](https://git.erikinkinen.fi/erix/docs/actions/runs/977) and [978](https://git.erikinkinen.fi/erix/docs/actions/runs/978) are running. These documentation corrections add no runtime behavior; the previously retained Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` appliance retains its original source selection and passing guarded-preparation evidence. Native upstream Rust/LLVM rebuilding and both complete EriX builds remain required. Original Docs CI 977/978 passes for signed 7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d. All four complete hashed logs total 772,186 bytes. Both runs pass 45 tests and the full 2,419-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No unchanged workflow rerun or cancellation supplies this result. Native child lifetime checkpoint — 19 September 2026: Signed Docs 9ca5a5e811766a4506c0626cd58f8e228d0bacf8 updates the technical manual's native admission, preflight, stopping, partial cleanup and safe return/idle contracts. All 45 tests and the complete 2,425-page manual pass with zero final warnings. All 447,213 word boxes are in bounds and all three changed contract pages are visually reviewed. Shared API reference source is unchanged. Original [Docs CI 981](https://git.erikinkinen.fi/erix/docs/actions/runs/981) and [982](https://git.erikinkinen.fi/erix/docs/actions/runs/982) pass from four complete hashed logs, 773,510 bytes. Both pass 45 tests and the complete 2,425-page manual. TeX pass warning counts are 36/1/0, with zero final-pass warnings; neither workflow was rerun or cancelled. The matching original signed Kernel and both maintained native VMs pass without warnings; [Kernel issue 19](https://git.erikinkinen.fi/erix/kernel/issues/19) retains exact runtime evidence and open executing-child, no-successor, further failure and consumer gates. Signed Integration 581226ab5435dc66c6f93157606b6d4d83475b15 selects the coherent original Kernel/lib-capabi/lib-ipc graph and updated manual. All four current strict 320/321-test configurations, four native builds, fmt, strict host/native Clippy and private rustdoc pass without warnings. Source and updated native-policy checks pass; the full 169-helper evidence remains bound to unchanged orchestration bytes. The final post-VM changes select only the newer Docs revision and update roadmap status; native source catalog, scenario, runtime and orchestration bytes are unchanged. Original [Integration CI 1683](https://git.erikinkinen.fi/erix/integration/actions/runs/1683) and [1684](https://git.erikinkinen.fi/erix/integration/actions/runs/1684) are queued. Executing-child and terminal-reply checkpoint — 19 September 2026: signed [Kernel dd9eace5](https://git.erikinkinen.fi/erix/kernel/commit/dd9eace5b52edc02e624f142e92b85032f59bace) validates actual CPL3 nested-child execution and current-child ancestor termination. Synchronous control dispatch now ends its request borrow before effects and checks original caller identity, generation and terminal state before any response write. It keeps terminal completion in Kernel-owned result registers with zero reply length; ordinary native return switches away. A surviving caller retains its normal encoded response. Two focused actual-object regressions cover terminal request preservation and the surviving-caller reply. The dispatcher is split from the tracing/policy file. A supervisor binds and starts a child; that child binds a staged grandchild and kills its supervisor through its own explicit Process SEND route. Read-only witnesses require terminal caller storage to survive dispatch, then exact child/grandchild absence before the independent observer reads child-before-supervisor events. Both terminal payloads have immediate UD2 sentinels. An unrelated Created process retains its exact record, empty capability inventory and mappings until explicitly aborted. All four additional lifetimes and twenty-two mapped pages must be disposed for `ERIX_KERNEL:CHILD_EXECUTION_OK`. Four strict Kernel configurations pass 720/744 library tests and both standalone controls; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Signed [Integration c14c5a61](https://git.erikinkinen.fi/erix/integration/commit/c14c5a617196a9b135b479601ca47a21371a9482) requires the additional marker while preserving every earlier marker and the original 60-second limit. Both actual native scenarios pass, with 1,870/1,587 complete serial bytes, empty QEMU stderr and no build warnings. Packaged Kernel bytes equal retained original artifacts after normal stripping; all fifteen original source signatures verify. Lifetime serial SHA256 is `1b2f983239efca55c8bc0f6f08ee91cfdcd37d4d1f6951bbd740e4d9b45d1a2f`. Four current Integration 320/321-test configurations, native builds, strict Clippy, formatting, private rustdoc and updated policy checks pass. Earlier 169-helper evidence is hash-verified against unchanged orchestration; it was not rerun for these scenario/catalog changes. Signed [Docs b4b01d87](https://git.erikinkinen.fi/erix/docs/commit/b4b01d870757d9b626dd2cfa7c6424332087bf62) documents the executing-child observations and remaining limits. All 45 tests, the full 2,425-page manual, 447,382 word bounds and visual review of the changed pages pass, with zero final warnings. The API reference source is unchanged. This extends native executing-child evidence; it does not establish no-successor native idle/wake behavior, provider completion, Procd adoption or a complete service lifecycle. The original install-grant constructor still gives `GRANT | MINT` while binding needs only `GRANT`; move-only transfer preserves exact rights. Both diagnostic grants are consumed, but rights minimization remains an explicit audit follow-up. Full source/effect/frame proof, the Pagerd gate, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related implementation tracking: [Kernel feature](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Original [Kernel CI 614](https://git.erikinkinen.fi/erix/kernel/actions/runs/614) and [615](https://git.erikinkinen.fi/erix/kernel/actions/runs/615) pass from four complete hashed logs, 753,462 bytes, without warnings. Original [Docs CI 983](https://git.erikinkinen.fi/erix/docs/actions/runs/983) and [984](https://git.erikinkinen.fi/erix/docs/actions/runs/984) pass from four complete hashed logs, 773,542 bytes. Both pass all 45 tests and the complete 2,425-page final manual; reference-resolution warning counts are 36/1/0, with zero final warnings. Original Integration CI 1685/1686 remains queued at its second observation. Older original [Integration CI 1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) passes all 489 catalog scenarios and both native Kernel diagnostics, then fails the development COM1 editor probe after its physical counterpart passes. Rust and Markdown pass. All three complete logs total 13,384,697 bytes with no warnings; the outer input status does not establish cause. The canonical bug report is [issue 67](https://git.erikinkinen.fi/erix/integration/issues/67), with bug/ci/phase-6 metadata. Earlier editor and filesystem failures remain separate. No original workflow was cancelled or rerun. Native cleanup without a userspace successor — 19 September 2026: signed [Kernel 2cf5b34c](https://git.erikinkinen.fi/erix/kernel/commit/2cf5b34c77451e4ddfa50f6bab9ae65cc5c47068) adds a seventh actual CPL3 caller to the maintained lifetime diagnostic. After every earlier assertion, the observer binds/starts the final child and yields. The child kills that supervisor through its own explicit Process SEND route. Immediate faulting sentinels forbid either terminal payload from resuming. Ordinary native return closes CPU accounting, detaches current attribution, progresses reclamation and finds no runnable successor. A diagnostic-only read-only witness then requires empty CPU accounting, only terminal retained records, no bound cleanup duties or event reservations, exact child identity/CSpace/mapping absence and both unconsumed child-before-supervisor events. All six final child pages retire; three original unbound terminal records remain for prior assertions. The witness neither performs cleanup nor selects a process nor installs an interrupt. `ERIX_KERNEL:CHILD_IDLE_CLEANUP_OK` precedes completion before HLT, so actual hardware halt/wakeup remains a separate gate. Signed [Integration 4d6f4fe8](https://git.erikinkinen.fi/erix/integration/commit/4d6f4fe8b383603b225b04a7771a11f32886e0a9) requires the additional marker while preserving all earlier assertions and both 60-second scenario limits. Both actual native VMs pass: 1,905/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256: `4a7cba61f75f4eeac47896d165b8dbcd217e4c75e2a81c8ae0f29957facb929c`. Packaged Kernel images match retained build artifacts after normal stripping; all fifteen original component signatures verify. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Post-VM changes only select updated Docs in full catalogs and update roadmap status. Signed [Docs 69466a64](https://git.erikinkinen.fi/erix/docs/commit/69466a64c032d575569adeff14f17a445e5a9c03) documents the pre-halt boundary and consolidates stale status paragraphs. All 45 tests, the complete 2,425-page manual, 447,534 word bounds and visual review of pages 562–564 pass with zero final warnings. API reference source remains unchanged. The static audit passes 3,140 authored code files below 1,000 lines, 74 manifests, 259 full Git selections, 171 direct missing_docs gates and 92 conventional crate roots; semantic authority and complete private-rustdoc closure remain open. Original [Kernel CI 616](https://git.erikinkinen.fi/erix/kernel/actions/runs/616) and [617](https://git.erikinkinen.fi/erix/kernel/actions/runs/617) pass from four complete hashed logs, 753,458 bytes, with no warnings. Original [Docs CI 985](https://git.erikinkinen.fi/erix/docs/actions/runs/985) and [986](https://git.erikinkinen.fi/erix/docs/actions/runs/986) also pass: four complete hashed logs, 773,510 bytes; both pass 45 tests and the final 2,425-page manual. Reference-resolution warning counts are 36/1/0 with zero final warnings. Original Integration CI 1687/1688 remains queued at its first observation. Older original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) is now terminal failure: all 489 catalog cases, both native diagnostics, development physical/COM1 editor and release physical editor pass before release COM1 fails. Rust and Markdown pass. Three complete logs total 13,385,246 bytes without warnings; [bug 37](https://git.erikinkinen.fi/erix/integration/issues/37) retains this evidence. Companion 1678's earlier development COM1 failure remains separate in [bug 67](https://git.erikinkinen.fi/erix/integration/issues/67); a common cause is unproven. No original workflow was cancelled or rerun. Further native failure controls, grant-rights minimization, terminal accounting, Procd adoption and complete service lifecycle acceptance remain open. Existing install-grant creation still supplies GRANT | MINT while binding needs GRANT, so minimum authority is not claimed. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Native terminal-event allocation refusal — 19 September 2026: signed [Kernel ba03995f](https://git.erikinkinen.fi/erix/kernel/commit/ba03995fe0dcfc3d4a1f72eb000e0c7698bbcbaa) extends the actual executing-child sequence with one deliberately refused heap allocation. Separate diagnostic preparation captures the original supervisor, child, staged grandchild and independent process records/capability inventories, then gives an empty event queue one-event capacity. No queued event or existing reservation is discarded. The first terminal-event reservation succeeds; the second arms exactly one null return from the real Kernel allocator. Ordinary collection growth and Process dispatch return RESOURCE_EXHAUSTED before any terminal effect. Read-only witnesses require complete reservation rollback, an empty event queue, unchanged exact records and capabilities, and preserved code/stack/message mapping ranges. Actual CPL3 instructions validate the refusal reply before the next ordinary ancestor kill succeeds with allocation available. Every earlier terminal, descendant-disposal, independent-process and no-successor idle assertion remains required. `ERIX_KERNEL:TERMINAL_EVENT_RESERVATION_OK` requires one consumed allocator refusal and no remaining armed fault. Fault controls are absent from ordinary images; this covers injected allocation failure, not spontaneous heap exhaustion or independent resource-release failure. No witness supplies a syscall result, cleanup effect or scheduler choice. Signed [Integration cf5b2f5f](https://git.erikinkinen.fi/erix/integration/commit/cf5b2f5f1d63631e69df3074d7c1c0b9b4921480) requires the new marker without changing either 60-second limit. Both maintained native VMs pass: 1,948/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is `d485019082175f769ecc2d406d88c6cc84a7df323605027663f5bcc79ca03ad9`. Packaged Kernel bytes match retained original artifacts after normal stripping, and all fifteen original source signatures verify. Post-VM changes only select updated Docs in full catalogs and consolidate roadmap status. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and updated policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed [Docs 62ba2ffa](https://git.erikinkinen.fi/erix/docs/commit/62ba2ffa30ff9f04840c8d38d188b414e5b24b90) passes 45 tests, the complete 2,425-page manual, all 447,688 word bounds and actual visual review of pages 562–565, with zero final warnings; API reference source remains unchanged. The static audit passes 3,142 authored code files below 1,000 lines, 74 manifests, 259 full Git pins, 171 direct missing_docs gates and 92 conventional roots. Complete semantic authority and private-rustdoc closure remain open. Original [Kernel CI 618](https://git.erikinkinen.fi/erix/kernel/actions/runs/618) and [619](https://git.erikinkinen.fi/erix/kernel/actions/runs/619) pass from four complete hashed logs, 753,434 bytes, with zero warnings. Original [Docs CI 987](https://git.erikinkinen.fi/erix/docs/actions/runs/987) and [988](https://git.erikinkinen.fi/erix/docs/actions/runs/988) pass from four complete hashed logs, 773,506 bytes: both pass 45 tests and the final 2,425-page manual, with reference-resolution warning counts 36/1/0 and zero final warnings. Original Integration CI 1689/1690 is queued. Earlier filesystem, directory, editor and full-frame regressions remain unresolved; original workflows were not cancelled or rerun. The terminal-accounting audit confirms that ordinary Procd terminal handling queries original TCB counters after receiving its event, while automatic bound-child reclamation removes that TCB. Its separate private-mediator branch does not take the same query path; adoption must state which lifetimes require retained metrics and preserve their original generation without fabricated zero/wall-clock values. Independent release-failure coverage, grant-rights minimization, accounting, Procd adoption and full mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Independent native child release recovery — 19 September 2026: signed [Kernel 82d88b60](https://git.erikinkinen.fi/erix/kernel/commit/82d88b609bd808a840780993da315230dd14399a) extends actual supervisor-exit coverage with two deliberate refusals at the original staged child's final VSpace-release callback, after capability disposal and unlinking. The first error is KernelHeapExhausted, the second CspaceSlotMissing. Read-only observations around two ordinary CPL3 observer yields require the original full record, generation, abort custody and first error retained, an empty original CSpace and retained mapped backing. The independent running child must already be absent from native TCB, CSpace and VSpace directories. The selected child's earlier directory position ensures its failure preceded that independent disposal. The third callback must perform normal VSpace release before all original terminal-event, generation and resource-absence checks pass. `ERIX_KERNEL:CHILD_RELEASE_ISOLATION_OK` requires exactly two refusals and complete eventual disposal. Fault control uses only atomics at the locked callback boundary and exists only in the isolated native diagnostic. No witness performs cleanup, supplies a successful release/syscall result or chooses a scheduler target. This establishes injected callback-refusal coverage, not an observed hardware or allocator malfunction. All earlier nested-child, allocation-refusal and no-successor pre-halt assertions remain required. Signed [Integration 294a467a](https://git.erikinkinen.fi/erix/integration/commit/294a467a3bcd9464ea55c32dbce98acf19d0e400) requires the added marker with both original 60-second limits unchanged. Both maintained native VMs pass: 1,988/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is `606fff037be022c876220d8e8f329c9046ffea5dcdf80831026649aedfbe0b08`. Packaged Kernel bytes match retained original unstripped artifacts after normal stripping, and all fifteen original component signatures verify. Post-VM changes only select the updated manual source in full catalogs and reconcile roadmap status. Four strict Kernel 720/744-test configurations, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test configurations, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed [Docs 2a0ccc1a](https://git.erikinkinen.fi/erix/docs/commit/2a0ccc1a595c3e03aa6c7b7ecbcaca8830082ddd) passes 45 tests, the complete 2,427-page manual, all 447,789 word bounds and actual visual review of pages 562–565 with zero final warnings. API reference source is unchanged. Static audit passes 3,143 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 171 direct missing_docs gates and 92 conventional roots; complete semantic authority/private-rustdoc closure remains open. Original Kernel CI 620/621 and Docs CI 989/990 pass from four complete hashed logs each (753,438/773,910 bytes), with zero final warnings. Current Integration originals are observed after publication. Earlier filesystem, directory, editor and full-frame regressions remain unresolved, with original evidence retained; no workflow is cancelled or retried unchanged. The grant-rights audit confirms actual Procd derivation callers and exact GRANT | MINT receipt checks in Procd and Launchd. Grant authority minimization must coordinate those consumers and distinguish the grant's own rights from its installation ceiling. Original generation-bound terminal accounting, Procd adoption, provider completion, hardware halt/wakeup and complete mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Manual and dependency validation — 20 September 2026: Docs commit [f4621ce2921b2b9fe3b1d25b4321d6b28289418e](https://git.erikinkinen.fi/erix/docs/commit/f4621ce2921b2b9fe3b1d25b4321d6b28289418e) is signed and pushed. Native selectors 32/33/54 now document exact own rights separately from installation ceilings. The process and launch chapters require GRANT-only final receipts, explicit derivation/source disposal, and original-generation rollback. Both IPC references are regenerated from signed source. All 45 tests and API checks pass; the complete 2,429-page manual has zero final warnings, all 448,913 word bounds pass, and eleven changed pages were visually reviewed. Original Docs CI 991/992 passes with four complete hashed logs, 774,346 bytes, both 45-test runs and final 2,429-page manuals. Intermediate TeX reference warnings resolve before the final pass. Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open. Verified managed installer recovery — 21 September 2026: Signed Integration [648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d](https://git.erikinkinen.fi/erix/integration/commit/648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d) in [WIP PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12) selects signed Procd [ac8a12993bc8cbf134a11e141e459cb63df71123](https://git.erikinkinen.fi/erix/procd/commit/ac8a12993bc8cbf134a11e141e459cb63df71123) and [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4). Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed. [Procd bug 4](https://git.erikinkinen.fi/erix/procd/issues/4) is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings. The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes. The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged. Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open. Committed terminal-accounting consumers — 21 September 2026: Procd [66934642c4464fc738152a9e60790914ba27dd1c](https://git.erikinkinen.fi/erix/procd/commit/66934642c4464fc738152a9e60790914ba27dd1c) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI [298](https://git.erikinkinen.fi/erix/procd/actions/runs/298)/[299](https://git.erikinkinen.fi/erix/procd/actions/runs/299) passes from four complete hashed logs, 347,245 bytes, zero warnings. [Bug 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open for actual service acceptance. Rootd [64c97b13c450003d9c2b6bd9ed2a627088684b46](https://git.erikinkinen.fi/erix/rootd/commit/64c97b13c450003d9c2b6bd9ed2a627088684b46) in [WIP PR 2](https://git.erikinkinen.fi/erix/rootd/pulls/2) acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed [bug 7](https://git.erikinkinen.fi/erix/rootd/issues/7): a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI [1041](https://git.erikinkinen.fi/erix/rootd/actions/runs/1041)/[1042](https://git.erikinkinen.fi/erix/rootd/actions/runs/1042) passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates. Docs [e4525848ad4462901c9a6794ef1794cf85ea9e6b](https://git.erikinkinen.fi/erix/docs/commit/e4525848ad4462901c9a6794ef1794cf85ea9e6b) updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI [995](https://git.erikinkinen.fi/erix/docs/actions/runs/995)/[996](https://git.erikinkinen.fi/erix/docs/actions/runs/996) and corrected-table [997](https://git.erikinkinen.fi/erix/docs/actions/runs/997)/[998](https://git.erikinkinen.fi/erix/docs/actions/runs/998) passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved. The separate Integration orchestration library checkpoint [b06dfad00202765491a64552dde29eaca1c24838](https://git.erikinkinen.fi/erix/integration/commit/b06dfad00202765491a64552dde29eaca1c24838) passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance. No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure. Explicit frame-tool manual — 21 September 2026: signed [f8a40d45fbbd631660f3adca9152fbb398a4ee6d](https://git.erikinkinen.fi/erix/docs/commit/f8a40d45fbbd631660f3adca9152fbb398a4ee6d) documents selected disassembler/helper custody, minimal child environment, bounded cleanup and preserved failure evidence. All 45 tests, the complete 2,431-page manual and 449,997 rendered word bounds pass. The changed page passes visual review, final warnings are absent and shared API reference sources remain unchanged. Original CI [999](https://git.erikinkinen.fi/erix/docs/actions/runs/999)/[1000](https://git.erikinkinen.fi/erix/docs/actions/runs/1000) is monitored separately. Full native Rust/LLVM/runtime rebuilding and both EriX guest build generations remain required in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Original frame-manual CI acceptance — 21 September 2026: signed `f8a40d45fbbd631660f3adca9152fbb398a4ee6d` passes both original [999](https://git.erikinkinen.fi/erix/docs/actions/runs/999)/[1000](https://git.erikinkinen.fi/erix/docs/actions/runs/1000), including 45 tests and the complete 2,431-page manual. Four complete hashed logs total 774,750 bytes. Each manual log retains 37 initial warning candidates; LaTeX reference-convergence passes report 35/1/0 warnings, and the final pass has no warnings or layout overflow. These expected early convergence messages remain visible in the original logs. The native external toolchain rebuild and both full guest build requirements remain open. Signed startup source/feature correction — 21 September 2026: Integration [fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa](https://git.erikinkinen.fi/erix/integration/commit/fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa) requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure. All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; [bug 71](https://git.erikinkinen.fi/erix/integration/issues/71) retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices. The technical manual update [76672dff8ff83](https://git.erikinkinen.fi/erix/docs/commit/76672dff8ff83b04914abe3c8f4b08b13835144f) passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs [1001](https://git.erikinkinen.fi/erix/docs/actions/runs/1001)/[1002](https://git.erikinkinen.fi/erix/docs/actions/runs/1002) passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow. A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under [bug 69](https://git.erikinkinen.fi/erix/integration/issues/69); no threshold or 120/15/10 capture limit changes. Original Integration [1705](https://git.erikinkinen.fi/erix/integration/actions/runs/1705)/[1706](https://git.erikinkinen.fi/erix/integration/actions/runs/1706) is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory. Coherent scalar-consumer validation — 21 September 2026: signed [Integration 07c883525ee5](https://git.erikinkinen.fi/erix/integration/commit/07c883525ee5e23378008232760d045f74f60d32) selects [Procd 59ee30a88534](https://git.erikinkinen.fi/erix/procd/commit/59ee30a885346db4db8c8791a23c15694f2a90a8) in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven. Procd's four strict 308/314-test configurations and original CI 302/303 pass. The [manual update](https://git.erikinkinen.fi/erix/docs/commit/2d05169e6974a495eab80b62edf0f23d1ad667da) passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines. Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven. Executed-code profiling checkpoint — 22 September 2026: signed [Integration 4fa27f942bc2](https://git.erikinkinen.fi/erix/integration/commit/4fa27f942bc2c6511eedceb5b20b8212f2bc94b0), tracked in [Integration PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12), adds bounded host TCG execution counters, explicit fresh-output ownership and exact packaged-ELF code candidates without adding guest authority. All 172 maintained helper commands pass without warnings. The profiler passes five Rust tests in both profiles, strict Clippy, private rustdoc, eleven Python controls and five actual selected-emulator controls. Unchanged orchestration inputs retain their preceding four strict matrices. The [operator guide](https://git.erikinkinen.fi/erix/integration/src/commit/4fa27f942bc2c6511eedceb5b20b8212f2bc94b0/docs/tcg-profiling.md) distinguishes complete counters from VM acceptance. One original-image diagnostic retains 92,896 translated blocks, 1,994,216 code bytes and zero missed execution counts. Its top 100 code groups cover 85.65% of the translated instruction upper bound; 33.30% has Kernel mapping-batch candidates and 7.70% has VSpace permission-switch candidates among the selected ELF inputs. Unknown and ambiguous work remains visible. These are code matches, not process ownership or elapsed-time attribution. Both the instrumented attempt and its same-emulator uninstrumented control fail waiting for the final native-command marker under unchanged 120/15/10 collection bounds. Neither proves startup acceptance, whole-transcript instrumentation overhead or a speedup. [Profiler acceptance](https://git.erikinkinen.fi/erix/integration/issues/3) and [startup performance](https://git.erikinkinen.fi/erix/integration/issues/72) remain open. The next optimization must preserve complete validation, live backing checks, page permissions, invalidation ordering and cleanup on errors. The signed [manual update](https://git.erikinkinen.fi/erix/docs/commit/1ade28490f4577bbf618f4cec49debf1f747aa6d), tracked in [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), passes 45 tests, all 2,431 pages, 450,367 word bounds and both changed-page visual reviews with zero final warnings or overflow. Original Docs CI 1005/1006 passes from four complete logs (774,674 bytes); initial reference-convergence warnings resolve on the final passes. Integration 1711/1712 is queued, while original 1701/1702 still runs. Existing queued jobs remain untouched. All 3,174 authored code files remain below 1,000 lines. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and completing the required full guest-build generations remain mandatory and unproven. Ordinary mapping-domain checkpoint — 22 September 2026: [resolved admission report](https://git.erikinkinen.fi/erix/kernel/issues/23) records the original host failure and bounded fix. The [fixture regression](https://git.erikinkinen.fi/erix/kernel/issues/24) retains all three distinct failed attempts and the verified layout correction. [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/ef3fd9293eaf691269fdb9e6b72eb15dac1f3f06) now validates the complete ordinary user page before backing or mapping changes, with both control paths covered. Four strict 745/769-test configurations, thirteen native builds, Clippy and private rustdoc pass without warnings. Three exact-source native executions pass lifetime, invocation and mapping; four maintained scenario contracts are checked, with sparse and isolation sharing their identical runtime capture. All fifteen selected native signatures and packaged Kernel identities verify. [Integration](https://git.erikinkinen.fi/erix/integration/commit/cd560584d034720ac179d5abc6f2a9d965943c63) pins the exact Kernel in all three catalogs, preserves every other selection and passes all 172 helpers. The unchanged ordinary exec-successor VM passes against the complete source graph, preserving its 120-second guest deadline, with no image warnings or QEMU stderr. [Docs](https://git.erikinkinen.fi/erix/docs/commit/043df99baaa9d4539da627fbfe4a234e41e74135) documents the domain and bootstrap distinction; all 45 tests and 2,431 pages pass, with 450,473 word bounds checked and no final warnings. The earlier Kernel CI 632/633 passes from four complete logs and zero warnings; current original CI remains under observation. Bootstrap provenance, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Verified documentation and CI follow-up — 22 September 2026: [Kernel documentation](https://git.erikinkinen.fi/erix/kernel/commit/d0d9e25b71664126c29727265f285df2f5ae7fea) and [Integration documentation](https://git.erikinkinen.fi/erix/integration/commit/c41bb92cd0ff5444c1680bee476a70072529fdb0) record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in [report 24](https://git.erikinkinen.fi/erix/kernel/issues/24), separately from the fixed [admission defect](https://git.erikinkinen.fi/erix/kernel/issues/23). The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure. Original full Integration [1703](https://git.erikinkinen.fi/erix/integration/actions/runs/1703)/[1704](https://git.erikinkinen.fi/erix/integration/actions/runs/1704), source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel [634](https://git.erikinkinen.fi/erix/kernel/actions/runs/634)/[635](https://git.erikinkinen.fi/erix/kernel/actions/runs/635) report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel [636](https://git.erikinkinen.fi/erix/kernel/actions/runs/636)/[637](https://git.erikinkinen.fi/erix/kernel/actions/runs/637) and Docs [1007](https://git.erikinkinen.fi/erix/docs/actions/runs/1007)/[1008](https://git.erikinkinen.fi/erix/docs/actions/runs/1008) pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued. The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open. VSpace MAP authority checkpoint — 22 September 2026: [the resolved bug report](https://git.erikinkinen.fi/erix/kernel/issues/25) records three original failing host controls and the verified correction in [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/9fdf1a17acc9204719fee42d263dacfcd701d56c). Current local MAP rights now govern map, protection and unmap requests. Empty and MANAGE-only aliases are denied; MAP-only access remains valid. Four strict 750/774-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/c62dbf9d7096d41b5d073bc497949e16f5f16e13) selects the exact signed Kernel in all three catalogs and passes all 172 helpers. Actual CPL3 calls preserve the authorized RW/NX page across restricted-alias refusals and drop all five temporary grants. Three native executions cover all four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signed sources and retained packaged artifacts. The original exec-successor service VM passes against all 73 components with its unchanged 120-second guest limit. All image warnings and QEMU stderr remain absent. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/a96c994750ed10205e7bac17be6922a53070e2d6) passes 45 tests, 2,431 pages and 450,550 checked word bounds, with both changed pages reviewed and zero final warnings. The static audit covers 3,181 authored code files below 1,000 lines, 259 exact Git dependency pins and existing direct missing_docs gates. It does not close semantic authority review. Earlier full Integration runs 1705/1706 are running; 1707–1720 remain queued at the latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel [638](https://git.erikinkinen.fi/erix/kernel/actions/runs/638)/[639](https://git.erikinkinen.fi/erix/kernel/actions/runs/639) and Docs [1009](https://git.erikinkinen.fi/erix/docs/actions/runs/1009)/[1010](https://git.erikinkinen.fi/erix/docs/actions/runs/1010) pass. Each pair has four complete logs: Kernel totals 777,250 bytes with zero warnings, and Docs totals 774,674 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration [1721](https://git.erikinkinen.fi/erix/integration/actions/runs/1721)/[1722](https://git.erikinkinen.fi/erix/integration/actions/runs/1722) remains queued; it receives no CI acceptance credit. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven. Frame access checkpoint — 22 September 2026: [the resolved bug report](https://git.erikinkinen.fi/erix/kernel/issues/26) records three original failing host controls and the verified correction in [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/6671466a84cdc4994384e1b8391d6a01fa66fb09). Explicit READ now governs admission and hardware activation. No-access mappings retain backing with USER/WRITE clear and NX set; write-only and execute-only requests are rejected without adding READ. Existing protection-transition rules remain in force. Four strict 757/781-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/b45edf143f599699f80e70a13827762d3e4da77e) selects the signed Kernel in all three catalogs and passes 172 helpers. Twenty-four actual CPL3 calls preserve earlier witnesses and cover no-access protection, write-only refusal, MAP-only frame derivation, denied READ and unmap after both frame grants are dropped. Three native executions pass four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signatures and retained packaged artifacts. The ordinary exec-successor VM passes against all 73 components with its unchanged 120-second guest limit. Builds emit no warnings and QEMU stderr is empty. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/45dae3cee4116b9387c4f3d3d2687a87f0fa340b) passes 45 tests, 2,433 pages and 450,702 checked word bounds, with the changed page reviewed and zero final warnings. Static review covers 3,182 authored code files below 1,000 lines, 259 exact Git pins and existing direct missing_docs gates. This does not close semantic authority review. Earlier full Integration runs 1705/1706 remain running and 1707–1722 remain queued at their latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel [640](https://git.erikinkinen.fi/erix/kernel/actions/runs/640)/[641](https://git.erikinkinen.fi/erix/kernel/actions/runs/641) and Docs [1011](https://git.erikinkinen.fi/erix/docs/actions/runs/1011)/[1012](https://git.erikinkinen.fi/erix/docs/actions/runs/1012) pass. Each pair has four complete logs: Kernel totals 782,838 bytes with zero warnings, and Docs totals 775,110 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration [1723](https://git.erikinkinen.fi/erix/integration/actions/runs/1723)/[1724](https://git.erikinkinen.fi/erix/integration/actions/runs/1724) remains queued; it receives no CI acceptance credit. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Authorized protection restoration, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Ordinary protection contract — 22 September 2026: [the runtime memory design](https://git.erikinkinen.fi/erix/kernel/issues/1) now specifies in-place no-access/R/RW/RX changes using current VSpace MAP and exact selected frame authority, including same-backing aliases and complete backing checks. Preserve W^X, explicit READ, object kind, reference custody, error ordering and all native witnesses. Kernel-owned anonymous loader materialization and Process endpoint target scope retain separate audit obligations. The implementation and exact-source VM evidence are pending. This earns no canonical acceptance credit; external toolchain rebuilding and both complete EriX guest-build generations remain mandatory. Current-grant protection checkpoint — 22 September 2026: [the resolved device-backing report](https://git.erikinkinen.fi/erix/kernel/issues/27) distinguishes its original metadata-authority inconsistency from the separate restoration feature gaps. The [Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/f5dd939c462de9d62f317ab7d29c21779cbe11c7) permits representable no-access/R/RW/RX changes through current exact-backing grants and aliases while active or inactive. It removes historical access ceilings and original-slot equality while preserving current VSpace MAP, selected frame rights, kind/range/identity checks, W^X, explicit READ, backing custody and failure ordering. Four strict 766/790-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [coordinated catalog](https://git.erikinkinen.fi/erix/integration/commit/8a9f865364656351fd8b12914e404a97b0be11c7) selects that original signed Kernel in all three catalogs and passes all 172 helpers. Fifteen managed-frame calls and twenty-nine device/domain calls pass inside the original lifetime window and deadline. Actual user instructions write, execute, rewrite and execute managed RAM, check narrow alias authority and final disposal, while a reused device slot cannot authorize unrelated backing. Every prior marker remains required. Three native executions pass four original contracts with complete signed source and artifact checks; the ordinary exec-successor VM passes the full 73-component graph and original 120-second limit. Image warnings and QEMU stderr are absent. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/155b2a0cd2771cb45fa881155baf2cd0f1d1db27) passes 45 tests, 2,433 pages and 450,954 word bounds; both changed pages are reviewed with no final warnings or overflow. Static review covers 3,184 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins and 174 direct missing_docs gates. Full semantic authority review remains open. [Older Integration CI 1705/1706](https://git.erikinkinen.fi/erix/integration/issues/73) has eleven real ext4 timeouts across eight scenarios, with complete retained logs and no accepted rerun. Their root cause and correction remain unresolved. Publication CI: Kernel [642](https://git.erikinkinen.fi/erix/kernel/actions/runs/642)/[643](https://git.erikinkinen.fi/erix/kernel/actions/runs/643) and Docs [1013](https://git.erikinkinen.fi/erix/docs/actions/runs/1013)/[1014](https://git.erikinkinen.fi/erix/docs/actions/runs/1014) pass. Each pair has four complete original logs: Kernel totals 790,650 bytes with 766/790 tests and zero warning candidates; Docs totals 775,150 bytes with 45 tests, 2,433 pages and zero final warnings or overflow. Retain the original 35/1/0 LaTeX warning convergence. Integration [1725](https://git.erikinkinen.fi/erix/integration/actions/runs/1725)/[1726](https://git.erikinkinen.fi/erix/integration/actions/runs/1726) remains queued and receives no completed CI acceptance. The separate older ext4 deadline report remains open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Complete POSIX protection support, Process endpoint scope, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Supervisor physical-access window — 22 September 2026: the [signed Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/046951899b8064be1cc90667a73e5abd2faa51ec) shares one restoring supervisor scratch transaction between frame scrubbing and physical mapping-byte copies. Caller backing custody and page-table/interrupt custody remain live through byte access, exact leaf restoration and local invalidation. Scratch is released afterward; read aliases clear the write bit and all temporary aliases clear user access and set NX. The unreachable raw-VA fallback is removed, and complete preflight rejects missing or ambiguous backing metadata before any range effects. No new userspace operation or capability grant is introduced. This is preparatory work for [owned address spaces](https://git.erikinkinen.fi/erix/kernel/issues/22); independent roots and their switching/reclamation proof remain open. Eight added host controls cover geometry, permissions, preparation and partial-effect failures, restoration/release ordering, and malformed later-page metadata without partial reads or writes. Four strict host configurations pass 774/798 tests with three existing ignored cases. Fourteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. The [coordinated Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/4fe89e021e08e45e3a9ecb1c939aba03f90e5fb1) passes all 172 maintained helpers; its exact marker expectation is updated alongside the strengthened scenarios. Unchanged orchestration and profiler sources retain strict validation. Six native executions satisfy seven maintained scenario contracts. Both allocator scenarios require the new same-VA/different-backing byte-and-leaf proof after complete cleanup, retaining every preceding marker and the original 60/120-second deadlines. Three further executions satisfy mapping, sparse, owned-invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Exact original signed source, retained artifacts and packaged Kernel matches are verified; no image warnings or QEMU stderr were observed. These checks establish no performance improvement. The [technical manual](https://git.erikinkinen.fi/erix/docs/commit/589449e4172b48e31a889c82addc83096a94e02d) documents backing and scratch custody; all 45 document tests and the complete manual build pass without final warnings. Static checks cover 3,190 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Complete semantic authority and inline-documentation review remain open. Publication CI: Kernel [648](https://git.erikinkinen.fi/erix/kernel/actions/runs/648)/[649](https://git.erikinkinen.fi/erix/kernel/actions/runs/649) and Docs [1015](https://git.erikinkinen.fi/erix/docs/actions/runs/1015)/[1016](https://git.erikinkinen.fi/erix/docs/actions/runs/1016) pass. Eight complete original logs (1,572,758 bytes) confirm Kernel 774/798 tests, 45 document tests and the 2,433-page manual. Initial TeX reference warnings resolve through normal multipass generation; final passes are clean. Integration [1731](https://git.erikinkinen.fi/erix/integration/actions/runs/1731)/[1732](https://git.erikinkinen.fi/erix/integration/actions/runs/1732) remains queued and has no completed acceptance. [Earlier ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and its runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Owned supervisor baseline — 22 September 2026: the [signed Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/0f5049592f7801b2a2d92b1290fdcc655952f72f) captures and verifies independently allocated supervisor tables before root VSpace creation, Rootd preparation and RAM seeding. Each copied page has one typed aligned Box owner before a parent references it; the recursive entry selects the copied root. Source boot/AP tables and mapped backing retain separate custody. User leaves, malformed geometry and invalid recursive identity are refused. Leaf permissions, cache policy and huge-page sizes are preserved; newly owned table branches use WriteBack and clear USER. Failed construction releases all unpublished allocations. This replaces a raw-pointer table-storage owner with shared typed storage and adds no unsafe Send/Sync implementation or userspace operation. Eleven new host controls cover independent storage, allocation/read failures, invalid translation geometry, user leaves, recursive and huge-page errors, source-permission drift, retained owner links and table counts beyond the unrelated 64-page batch size. Four strict host configurations pass 785/809 tests with three existing ignored cases; fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [coordinated catalog](https://git.erikinkinen.fi/erix/integration/commit/122a3d77f7f879c32eba45ccdf2eba2fd9f8d3db) passes all 172 maintained helpers. Both allocator scenarios require successful baseline capture before their original marker sequence, with capability grants and original 60/120-second deadlines preserved. Six native executions satisfy seven maintained contracts: both allocator scenarios, mapping and sparse checks sharing identical runtime settings, owned invocation, lifetime revocation and ordinary exec-successor across all 73 components. Exact signed source and retained packaged artifacts are verified; no image warnings or QEMU stderr were observed. The [technical manual](https://git.erikinkinen.fi/erix/docs/commit/18b8b7160fc2f058f059ea3c41adeca5846f9f69) specifies the custody boundary and passes 45 tests, complete 2,433-page generation, all 451,287 word bounds and changed-page visual review without final warnings or overflow. Static audits cover 3,194 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Publication CI: original Kernel [push 650](https://git.erikinkinen.fi/erix/kernel/actions/runs/650) passes and [PR 651](https://git.erikinkinen.fi/erix/kernel/actions/runs/651) retains the host fixture failure. [Regression 29](https://git.erikinkinen.fi/erix/kernel/issues/29) is resolved by [signed Kernel `12184850cd73`](https://git.erikinkinen.fi/erix/kernel/commit/12184850cd73fff066abcb7f97039a0828b2a928): a deterministic private predecessor reproduces the original defect, and the corrected fixture passes the complete local matrix and [push CI 652](https://git.erikinkinen.fi/erix/kernel/actions/runs/652)/[PR CI 653](https://git.erikinkinen.fi/erix/kernel/actions/runs/653). Four complete corrected CI logs total 807,886 bytes with zero warning candidates. Only host tests and roadmap change; validated production sources and all catalog selections remain unchanged. Docs [1017](https://git.erikinkinen.fi/erix/docs/actions/runs/1017)/[1018](https://git.erikinkinen.fi/erix/docs/actions/runs/1018) pass with four complete logs (775,122 bytes), 45 tests and the 2,433-page manual. Initial TeX reference warnings resolve before clean final passes. Integration [1733](https://git.erikinkinen.fi/erix/integration/actions/runs/1733)/[1734](https://git.erikinkinen.fi/erix/integration/actions/runs/1734) remains queued at the latest retained observation and has no completed acceptance. [Earlier ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. The retained baseline is a construction prerequisite for [owned address spaces](https://git.erikinkinen.fi/erix/kernel/issues/22). Per-VSpace population, CR3 activation, invalidation and live-root reclamation remain open, and no speedup is claimed. Full semantic authority and inline-documentation review also remain open. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Huge-leaf geometry correction — 22 September 2026: [the bug report](https://git.erikinkinen.fi/erix/kernel/issues/30) preserves four original host failures and one passing WriteBack control. The [signed correction](https://git.erikinkinen.fi/erix/kernel/commit/4f9cfcaeb63e9080f6d6a3e9fd190e6cb288c6fc) separates PAT from physical address bits, preserves permissions/cache indices across both huge splits, and gives newly allocated tables WriteBack policy. Scalar and batched translation, split preparation, snapshots and baseline validation share the documented geometry. No new userspace authority, original native exploit or universal boot failure is claimed. Four strict Kernel configurations pass 796/820 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [catalog](https://git.erikinkinen.fi/erix/integration/commit/ccc32eed0b4029a1ef82279c665811692c859985) passes all 172 maintained helpers. Six native executions satisfy seven original contracts: mapping and sparse, lifetime, invocation, both allocator checks and ordinary exec-successor across all 73 components. The new native witness verifies real 2 MiB PAT translation, splitting and complete restoration; host controls additionally cover 1 GiB. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The [manual](https://git.erikinkinen.fi/erix/docs/commit/587a280f59e55598e3a26b788d589955ebb84212) passes 45 tests, 2,433 pages and changed-page visual review without final warnings or overflow. Publication CI: Kernel [654](https://git.erikinkinen.fi/erix/kernel/actions/runs/654)/[655](https://git.erikinkinen.fi/erix/kernel/actions/runs/655) and Docs [1019](https://git.erikinkinen.fi/erix/docs/actions/runs/1019)/[1020](https://git.erikinkinen.fi/erix/docs/actions/runs/1020) pass. Eight complete original logs (1,592,794 bytes) confirm Kernel 796/820 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration [1735](https://git.erikinkinen.fi/erix/integration/actions/runs/1735)/[1736](https://git.erikinkinen.fi/erix/integration/actions/runs/1736) remains queued and has no completed acceptance. Earlier [ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Static audits cover 3,197 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, live-root reclamation and full semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven. First-start register custody — 22 September 2026: [the stack-domain bug report](https://git.erikinkinen.fi/erix/kernel/issues/31) preserves three original host failures and one valid-stack control at unchanged production sources; the same four controls pass against the [signed correction](https://git.erikinkinen.fi/erix/kernel/commit/5bad7a1285089a20ee6425e0335ed3a5e96f7e29). Ordinary anonymous stack materialization now rejects addresses outside the existing user domain, and direct bootstrap writes require retained writable registered backing. Initial registers have Kernel-owned storage; stack preparation preserves the synthetic return slot, complete admission, startup arguments and rollback. The obsolete saved-frame user overlay and directory scan are removed. Complete external start-context admission and the separate bootstrap code/stack overlay remain distinct work. Four strict Kernel configurations pass 807/831 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [catalog](https://git.erikinkinen.fi/erix/integration/commit/483da1e42cbdc79b56dea6fb0806980a128787b8) passes all 172 maintained helpers. Six native executions satisfy seven original contracts: lifetime, invocation, mapping and sparse, both allocator checks and ordinary exec-successor across all 73 components. The new witness checks all original initial register words after two real user stack mutations and before ordinary syscall capture. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The [manual](https://git.erikinkinen.fi/erix/docs/commit/57bdb2811e2a90d0121ff6de6ab58ff797806b78) passes 45 tests, 2,433 pages and four changed-page visual reviews without final warnings or overflow. Publication CI: Kernel [656](https://git.erikinkinen.fi/erix/kernel/actions/runs/656)/[657](https://git.erikinkinen.fi/erix/kernel/actions/runs/657) and Docs [1021](https://git.erikinkinen.fi/erix/docs/actions/runs/1021)/[1022](https://git.erikinkinen.fi/erix/docs/actions/runs/1022) pass. Eight complete original logs (1,600,791 bytes) confirm Kernel 807/831 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration [1737](https://git.erikinkinen.fi/erix/integration/actions/runs/1737)/[1738](https://git.erikinkinen.fi/erix/integration/actions/runs/1738) remains queued and has no completed acceptance. Earlier [ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Static audits cover 3,201 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, CPU residency, live-root reclamation and complete semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.
docs: Record POSIX compatibility coordination
All checks were successful
CI / markdown (push) Successful in 33s
CI / manual (push) Successful in 7m17s
5fd27ea4da
Link the organization project, planned work streams, repository audits and
confirmed manual-warning defect through public Forgejo references. Document
canonical issue and PR metadata, evidence-based board transitions and the
separate requirement to verify actual card attachment. Keep implementation
and self-hosting acceptance distinct from planning publication.

Update documentation navigation and scope without changing runtime, ABI or
manual TeX contracts. Validation: Markdown lint passes for all 55 documents;
all 20 documentation helper unit tests pass; the index has 99 unique issue
links. The existing final-pass manual diagnostic defect remains open at
#3.
docs: Coordinate phase work through issues and pull requests
All checks were successful
CI / markdown (push) Successful in 31s
CI / markdown (pull_request) Successful in 1m27s
CI / manual (push) Successful in 7m22s
CI / manual (pull_request) Successful in 7m12s
7a85e1608e
Keep the published work index and delivery rules aligned with issue labels, dependency links and WIP pull requests. Date the baseline CI observation so pending runs are not presented as current results.
fix: Reject final manual warnings and correct reference layout
All checks were successful
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 9s
CI / manual (pull_request) Successful in 3m40s
CI / manual (push) Successful in 3m40s
22d524bf23
Display generated API headings separately and use deliberate prose, page and
table alignment so long identifiers remain readable without typesetting
warnings. Require a readable nonempty final TeX log free of box, font,
reference and compiler warnings before copying the PDF and checksum.

Preserve API source provenance, content, labels and bookmarks. Document startup
profiling and update issue-based coordination. The complete 1991-page manual
build has no warnings or out-of-page text; all 26 documentation-helper tests
and Markdown checks pass. Exact-head CI remains required.
erikinkinen changed title from WIP: Document POSIX compatibility work and acceptance tracking to WIP: Enforce warning-free manual builds and document compatibility work 2026-09-12 09:13:12 +02:00
docs: Explain build-scope evidence and retain editor regression tracking
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / manual (pull_request) Successful in 5m9s
CI / manual (push) Successful in 5m13s
08e89f2aa3
Document the distinction between complete static input/output declarations,
verified artifact bytes and observed guest build execution. Require the full
VM catalog and all later image probes for Integration acceptance. Add the
release physical-editor failure to the public issue index without treating
its separate later pass as a demonstrated fix.

The complete manual builds without final warnings in 145.13 seconds, with all
87 selected inputs unchanged during compilation. Markdown and whitespace
checks pass. The warning correction already passed both push and PR CI; the
new documentation head still requires its own CI review.
docs: Describe compatibility codecs and VM failure evidence
All checks were successful
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 20s
CI / manual (pull_request) Successful in 6m48s
CI / manual (push) Successful in 6m48s
f1f06bff4e
Document descriptive compatibility identifiers, checked query framing and the
future native adapter's authority and cleanup responsibilities. Explain bounded
runner diagnostics and update the public issue index and CI status.

The complete manual renders without final warnings; 26 documentation tests
and all 55 Markdown files pass. Runtime ABI and self-hosting acceptance remain
open.
docs: Record target identity and governance validation checkpoints
All checks were successful
CI / markdown (push) Successful in 6s
CI / markdown (pull_request) Successful in 6s
CI / manual (pull_request) Successful in 4m11s
CI / manual (push) Successful in 4m13s
baee852b90
Track the distinct-target inventory defect and its published correction,
and record the complete explicit governance comparison across the fleet.
Preserve the distinction between selected policy or scope evidence and a
full build performed inside EriX.

All Markdown files pass lint. Manual, generator and test sources are
unchanged from the complete warning-free render and passing CI checkpoint.
docs: Describe integer ABI and mapping contracts with current CRC APIs
All checks were successful
CI / markdown (pull_request) Successful in 22s
CI / markdown (push) Successful in 22s
CI / manual (pull_request) Successful in 7m7s
CI / manual (push) Successful in 7m9s
4964e7c939
Document the reviewed integer C compatibility subset and its distinction from native authority, serialized wire bytes and complete ABI conformance. Describe managed-frame hint invalidation, live guards, storage costs and measured selector work without claiming guest timing. Regenerate the eight CRC API routes from their declared signed original source revision and update the public issue/CI index.

The 1997-page manual builds under bounded deadlines with no final warnings; all 87 tracked build inputs remain unchanged through rendering, all 380661 word boxes stay within page bounds, and affected pages were visually reviewed. All 26 document-generation tests and 55 Markdown files pass. Current compatibility and kernel runtime/image acceptance remain separate work.
erikinkinen changed title from WIP: Enforce warning-free manual builds and document compatibility work to WIP: Enforce warning-free manuals and document compatibility contracts 2026-09-12 11:12:12 +02:00
docs: Record scenario corrections and quota timeout evidence
All checks were successful
CI / markdown (push) Successful in 24s
CI / markdown (pull_request) Successful in 22s
CI / manual (pull_request) Successful in 6m47s
CI / manual (push) Successful in 6m53s
4e2b734db2
Link the filesystem quota timeout and distinguish the published scenario-lock correction from its pending full CI. Preserve the passing baseline and incomplete artifact identities without attributing the timeout to a source change.

Validate all 107 issue references, relative links, Markdown and whitespace. The technical manual inputs are unchanged from the complete warning-free render.
docs: Specify EriX errno values and native result boundaries
All checks were successful
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 12s
CI / manual (pull_request) Successful in 4m38s
CI / manual (push) Successful in 4m40s
d91ddf63bc
Select POSIX.1-2024 Base as the semantic reference while keeping optional and full workload coverage explicit. Document nineteen stable EriX errno integers, their checked Rust and C boundary, and the nine native IPC result codes without treating descriptive values as completion or authority.

Correct the manual table and running title without altering its values or suppressing diagnostics. The complete 1997-page render passes the strict final warning gate; all 381158 word boxes lie inside their pages and the changed pages are visually checked. Preserve both earlier render failures. Update public coordination to the published source-identity fix and confirmed quota catalog failures.
docs: Preserve public declaration shapes in generated API references
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 22s
CI / manual (pull_request) Successful in 6m54s
CI / manual (push) Successful in 7m11s
c8e754bff3
Render explicit Rustdoc struct and variant shapes, opaque private fields and
public field visibility without inventing constructors or numeric named fields.
Retain independent regression evidence and refresh IPC and compatibility
references from their selected original source revisions.

Correct retained historical JSON renderings without changing their original
source labels or claiming fresh source provenance. The complete 2027-page
manual passes its warning and layout gates; 32 documentation tests and all
34 generation checks pass. Update the public coordination index with the
reported standalone service-link defects and preserved regression status.
erikinkinen changed title from WIP: Enforce warning-free manuals and document compatibility contracts to WIP: Enforce warning-free manuals and preserve public API declarations 2026-09-12 12:55:29 +02:00
docs: Explain contextual completion and standalone validation
All checks were successful
CI / markdown (pull_request) Successful in 27s
CI / markdown (push) Successful in 28s
CI / manual (push) Successful in 7m14s
CI / manual (pull_request) Successful in 7m13s
581f474a56
Refresh the compatibility API from its original published revision and explain
route, operation, effect, cleanup and committed-progress assertions without
claiming runtime authentication or complete POSIX mappings. Document explicit
service linker scripts and checker selection with their host-validation limits.

The 117-route reference preserves earlier signatures. All 32 documentation
tests and generation checks pass; the complete 2041-page manual has no final
warnings or out-of-page text. Runtime and guest-build acceptance remain open.
docs: Reconcile component evidence and retained CI failures
All checks were successful
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 19s
CI / manual (pull_request) Successful in 6m18s
CI / manual (push) Successful in 6m24s
1cee255590
Record verified Rust target documentation coverage, code-size inventory and
component CI alongside the remaining stack, filesystem and source-fixture
failures. Keep host image construction distinct from controlled timing and
both required guest-built generations; link all current public issue records.

Validate all 55 Markdown files, issue-link coverage and private-reference
exclusion. Manual source and generated API inputs are unchanged.
docs: Explain compiler coordinates and current validation evidence
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 8s
CI / manual (pull_request) Successful in 5m21s
CI / manual (push) Successful in 5m24s
962ac6fcb6
Document shared package-based source and scratch coordinates, exact external-entry ownership, and the limits of host artifact equality and cache coverage. Preserve the distinction between compiler paths, source provenance and runtime authority.

Update issue and component evidence with published corrections and retained host/VM failures. Record exact CI observations without substituting predecessor success or incomplete stack evidence for acceptance.

Validation: 32 documentation tests, all 55 Markdown files and the full 2041-page manual pass. The final render has no warnings or out-of-page word boxes; API snapshots and inherited governance remain unchanged.
docs: Specify executable cache admission and failure behavior
All checks were successful
CI / markdown (push) Successful in 29s
CI / markdown (pull_request) Successful in 24s
CI / manual (push) Successful in 5m15s
CI / manual (pull_request) Successful in 5m18s
fe6f8f7dd8
Document selected input identity, supported cache bypass and first-error
cleanup rules alongside the host regression evidence. Reconcile the public
issue index and CI observations with the signed cache and tool-selection
checkpoints while keeping incomplete image and guest acceptance explicit.

All 32 documentation tests and 55 Markdown files pass. The complete manual
renders 2041 pages with no final warnings or out-of-page word boxes.
fix: Preserve trait implementation direction in API references
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 11s
CI / manual (pull_request) Successful in 6m31s
CI / manual (push) Successful in 6m34s
3fd9a53548
Render complete implementation headers and retain distinct defining type identities so conversions and generic constraints remain unambiguous. Add enum summaries, regenerate the selected original references and document checked file/time arithmetic, UEFI artifact policy and watchdog evidence limits.

Retain historical source provenance and earlier failures. Validate 44 documentation tests, all 34 selected references and a complete 2313-page manual without final warnings or out-of-page text, with independent review of the changed pages.
erikinkinen changed title from WIP: Enforce warning-free manuals and preserve public API declarations to WIP: Preserve complete API declarations and validate the technical manual 2026-09-12 18:19:43 +02:00
docs: Document numeric byte extents and native probe diagnostics
All checks were successful
CI / markdown (push) Successful in 20s
CI / markdown (pull_request) Successful in 19s
CI / manual (pull_request) Successful in 7m5s
CI / manual (push) Successful in 7m9s
0912e7313c
Generate the compatibility reference from the signed original byte-extent
implementation while preserving every existing public signature and the other
library snapshots. Explain arithmetic-only validation, raw C layout and the
wide endpoint without implying pointer or memory authority.

Document correlated native-probe status reporting and refresh coordination
with scoped image reproducibility and component CI evidence. Keep guest
profiling, runtime compatibility and self-hosting acceptance explicit.
erikinkinen changed title from WIP: Preserve complete API declarations and validate the technical manual to WIP: Preserve complete ABI references and validate the technical manual 2026-09-12 20:00:19 +02:00
docs: Describe isolated POSIX realm bootstrap and retirement
All checks were successful
CI / markdown (pull_request) Successful in 23s
CI / markdown (push) Successful in 25s
CI / manual (pull_request) Successful in 6m51s
CI / manual (push) Successful in 6m56s
9afcefa356
Document the planned process-per-realm ownership boundary and distinguish native
bootstrap execution from later sealing and client publication. Preserve current
service protocols and identify the coordinated producer and surviving retirement
contracts still required before runtime acceptance.

Update the public coordination index with the signed Posixd design, component CI
and the separate release repeated-interrupt regression. Retain unchanged API
references and validate the complete technical manual, its final warnings and
page geometry. This checkpoint does not implement runtime mediation or self-hosting.
erikinkinen changed title from WIP: Preserve complete ABI references and validate the technical manual to WIP: Document POSIX realm ownership and preserve complete ABI references 2026-09-12 20:52:04 +02:00
docs: Explain physical input operation failure evidence
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 21s
CI / manual (pull_request) Successful in 6m10s
CI / manual (push) Successful in 6m15s
3195304828
Describe the optional physical three-line diagnostic receipt, its correlation
with the original runner status and the separation of operation and cleanup
failures. Preserve command assertions, status precedence and existing timing
limits. Keep raw evidence outside the supplementary diagnostic line.

Update the public coordination record with the signed Integration checkpoint
and retained boot/probe failures. All generated API references remain unchanged.
Validate the complete manual, final warnings, page geometry and changed pages;
the narrative supplies diagnostic guidance without claiming a guest bug fix.
erikinkinen changed title from WIP: Document POSIX realm ownership and preserve complete ABI references to WIP: Document physical input failures and POSIX realm ownership 2026-09-12 22:17:54 +02:00
docs: Document explicit C memory and startup image contracts
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 14s
CI / manual (pull_request) Successful in 6m49s
CI / manual (push) Successful in 6m50s
8c61739fae
Describe caller-owned byte ranges and the explicitly linked lib-cstd memory
companion, using Rustdoc JSON generated from its original signed source. Add
five public API routes while preserving the preceding 34 reference snapshots.

Document the packaged startup-profile receipt, final media identity and
preflight ordering without changing the complete readiness/timing oracle or
claiming publisher authentication or guest execution. Update public issue and
CI coordination with actual partial results and unresolved regressions.

Validate the documentation generators, templates, links and complete manual.
Native consumers, image validation and the complete self-hosted build remain
separate required work.
erikinkinen changed title from WIP: Document physical input failures and POSIX realm ownership to WIP: Document C memory interfaces and startup image admission 2026-09-13 00:15:30 +02:00
docs: Describe byte queries and native memory support
All checks were successful
CI / markdown (pull_request) Successful in 28s
CI / markdown (push) Successful in 28s
CI / manual (push) Successful in 7m2s
CI / manual (pull_request) Successful in 7m2s
1b8057c080
Generate the C query reference from the exact signed original source and document
termination, count, initialized-byte and returned-pointer obligations. Preserve
the existing memory interface and distinguish the eight-function library from
the separately selected native memory companion.

Synchronize loader and build chapters with explicit companion ownership, schema
three registry and cache identities, and the optional legacy allocator-policy
accessor. Preserve caller authority, original failure behavior and the boundary
between host validation and complete guest build acceptance.

Validation: 44 documentation tests, the fresh selected API generation check and
55 Markdown files pass. The complete 2,325-page manual renders with zero final
warnings and no out-of-page word boxes; fifteen changed pages pass visual review.
An initial extra-blank-line Markdown failure is retained, followed by affected
prose checks. Final issue/status updates preserve all rendered input bytes.
The full build inside EriX and its second-generation rebuild remain open.
erikinkinen changed title from WIP: Document C memory interfaces and startup image admission to WIP: Document C memory and query interfaces and native build support 2026-09-13 02:37:05 +02:00
docs: Document first and last C character searches
All checks were successful
CI / markdown (pull_request) Successful in 5s
CI / markdown (push) Successful in 5s
CI / manual (push) Successful in 3m48s
CI / manual (pull_request) Successful in 3m49s
6cce15a8ba
Synchronize the system-libraries chapter and generated API with the signed
character-search runtime. Specify target char conversion, searchable NUL,
full-string validity and returned-pointer access restrictions. Preserve all
prior signatures and other component references, and update tracked CI facts.

Validation: 44 documentation tests, the selected API check and all 55 Markdown
files pass. The complete 2,325-page manual renders with zero final warnings;
all 421,044 word boxes fit within page bounds and four changed pages pass
visual review. Final status updates preserve every rendered input byte.
Complete libc and the full build inside EriX remain open.
docs: Document C string copy and concatenation contracts
All checks were successful
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 17s
CI / manual (push) Successful in 7m5s
CI / manual (pull_request) Successful in 7m7s
b11a745b5d
Describe caller-owned destination capacity, nonoverlap, padding, termination
and the distinct zero-count rules for strcpy, strncpy, strcat and strncat.
Select the original signed fourteen-function Rustdoc reference, preserving
previous API signatures and the separate native memory-only consumer graph.
Update the public issue index and current validation status.

Validation: all 44 documentation tests, API consistency, 55 Markdown files,
source/template/link and whitespace checks pass. The complete 2,327-page
manual has zero final warnings and 422,032 word boxes within page bounds;
six changed pages pass visual review. Preserve the corrected finalization
receipt-path setup failure. New documentation CI remains pending.
erikinkinen changed title from WIP: Document C memory and query interfaces and native build support to WIP: Document C memory and string interfaces and native build support 2026-09-13 05:24:18 +02:00
docs: Document string spans and guarded realm bootstrap
All checks were successful
CI / markdown (pull_request) Successful in 21s
CI / markdown (push) Successful in 21s
CI / manual (pull_request) Successful in 7m11s
CI / manual (push) Successful in 7m11s
928ff81a1d
Refresh the libc reference from signed 4207509c with seventeen functions and
nineteen API routes, preserving earlier signatures and every other library
reference. Explain byte-set membership, source-derived pointer permissions
and caller-owned stack scratch. Correct the realm bootstrap sequence so
actual revoker custody precedes export, and distinguish typed installation,
private configuration pulls and the unselected surviving retirement owner.

Update public coordination for the two separately observed VM regressions.
All 44 documentation tests, API consistency and 55 Markdown files pass. The
full 2,331-page manual has no final warnings and all 423,064 word boxes fit;
nine selected pages pass visual review. A page-selection bound failure and
a private finalization-prefix collision are retained and corrected without
repeating the render or runtime tests. Guest mediation and two-generation
self-hosting acceptance remain open.
docs: Replace duplicated README history with contract links
All checks were successful
CI / markdown (pull_request) Successful in 21s
CI / markdown (push) Successful in 23s
CI / manual (pull_request) Successful in 7m5s
CI / manual (push) Successful in 7m9s
a6f83f4711
Replace nineteen mapping, storage, provider, terminal and CI-history
paragraphs with links to their existing detailed contracts. Preserve every
heading, prior link, the original introduction and all later product themes.
The authority rules, numerical gates and cleanup requirements remain in
ARCHITECTURE and the manual; historical evidence remains in its owning
documents and signed history. Correct one navigation label for grammar.

All 44 documentation tests and 55 Markdown files pass without warnings,
along with whitespace, six canonical governance files and local links.
Review binds nineteen original paragraphs and 55 retained source ranges.
Only README changes among 162 source files, removing 198 lines and 13,784
bytes. Manual and API inputs remain unchanged; no render or runtime replay
is needed. Later README history and complete phase acceptance remain open.
docs: Document file status and bounded string length
All checks were successful
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 3s
CI / manual (pull_request) Successful in 2m53s
CI / manual (push) Successful in 2m54s
7ccbe0bfa8
Select the signed file-status ABI and eighteen-function C runtime in the
source-derived API reference. Explain raw aggregate layout, encoded modes,
metadata authority limits, checked unsigned size narrowing and bounded
string reads. Preserve the other 33 references and refresh the issue index.

All 44 documentation tests, both API checks and 55 Markdown files pass.
The complete 2339-page manual has zero final warnings; all 425255 word
boxes fit and nine changed or adjacent pages pass visual review. Preserve
the first interrupted render and correct only its outer watchdog budget.
Native metadata, companion migration and full guest builds remain open.
erikinkinen changed title from WIP: Document C memory and string interfaces and native build support to WIP: Document file status, C strings and native authority boundaries 2026-09-14 07:57:37 +02:00
fix: Preserve opaque API fields and document lifetime revocation
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / manual (pull_request) Successful in 2m52s
CI / manual (push) Successful in 2m53s
28b4418336
Keep one private-field marker when Rustdoc JSON includes hidden named fields,
so generated signatures preserve the actual public construction boundary.
Document consumed local revocation custody, terminal failure retention and
independent completion. Regenerate IPC and syscall references from their
signed source and update the public issue index without private identifiers.

All 45 documentation tests, both API checks, 55 Markdown files and canonical
structure checks pass. The complete 2339-page manual has zero final warnings,
all 426181 word boxes within bounds and five visually reviewed pages. Original
renderer and whitespace failures remain recorded. Native VM and realm producer
acceptance and complete guest builds remain open.
erikinkinen changed title from WIP: Document file status, C strings and native authority boundaries to WIP: Document lifetime revocation and preserve opaque API contracts 2026-09-14 10:13:47 +02:00
docs: Describe validated native lifetime and runtime symbol boundaries
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / manual (pull_request) Successful in 3m49s
CI / manual (push) Successful in 3m50s
17b4d52a9a
Document the real CPL3 custody fixture, explicit typed marker ownership and
its isolated VM acceptance without claiming realm adoption or guest builds.
Describe length-delimited legacy and defining-path Rust v0 runtime checks
while preserving exact authenticated kernel export lookup. Add the three
related regression issues to the public coordination index.

All 45 documentation tests and 55 Markdown files pass. The complete manual
has 2339 pages, zero final warnings and 426453 word boxes within page bounds.
Both changed narrative pages pass visual review. Existing API references
are unchanged; no Rust crate is present in this documentation repository.
erikinkinen changed title from WIP: Document lifetime revocation and preserve opaque API contracts to WIP: Document native lifetime validation and scoped runtime resolution 2026-09-14 11:44:45 +02:00
docs: Specify native IPC platform selection and host refusal
All checks were successful
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 4s
CI / manual (pull_request) Successful in 3m4s
CI / manual (push) Successful in 3m6s
87942ea767
Document the freestanding x86-64 transport boundary, local host refusal and
ordinary checked-helper input validation. Keep compile-target selection,
kernel identity and native retirement evidence distinct. Refresh both IPC
references from the signed source while preserving every public signature.

All 45 documentation tests and 55 Markdown files pass. The full 2339-page
manual builds with zero final warnings, all 426697 word boxes within page
bounds and three changed pages visually reviewed. No Rust crate is changed
in this repository; selected IPC source passes its strict matrix and CI.
erikinkinen changed title from WIP: Document native lifetime validation and scoped runtime resolution to WIP: Document native IPC platform and lifetime boundaries 2026-09-14 12:31:14 +02:00
docs: Refresh regression ownership and platform validation status
All checks were successful
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 5s
CI / manual (push) Successful in 3m0s
CI / manual (pull_request) Successful in 3m0s
c6b0b677f1
Record the observed Integration dependency-feature build regression and
correct the public inventory to all 154 tracked issues. Record accepted
IPC platform manual CI separately from the new status-only update.

All 45 documentation tests and 55 Markdown files pass with canonical
headings and governance unchanged. Every manual, generated API and build
input matches the accepted preceding source; no Rust crate is present.
docs: Record entry-argument defects and reopened fixture isolation
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 5s
CI / manual (pull_request) Successful in 3m12s
CI / manual (push) Successful in 3m14s
013ec09aaf
Keep the public coordination index complete at 156 issues. Record the
Kernel argument overwrite, the Bootloader constraint finding and the
synthetic fixture failures from CI 530 separately from passing native VMs.

All 45 documentation tests and 55 Markdown files pass; canonical headings
and governance remain unchanged. Manual, generated API and build inputs
match the previous accepted source byte for byte. No Rust crate is present.
docs: Align planned realm ownership with native lifetime custody
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 10s
CI / manual (push) Successful in 6m16s
CI / manual (pull_request) Successful in 6m15s
d9bb106b94
Document the selected Kernel ancestor guard and independent Procd early
retirement guard, without conflating SEND revocation with receiver, child,
provider or operation cleanup. Link the existing syscall contract and keep
runtime mediation unimplemented. Record all 157 public issues, including
the owned-invocation design whose ABI and implementation remain open.

All 45 documentation tests and 55 Markdown files pass. The complete
2341-page manual has zero final warnings; all 426812 word boxes fit page
bounds and the changed page is visually reviewed. All generated API and
build inputs remain unchanged. No Rust crate is present in this repository.
docs: Track CSpace allocation identity loss and measured scaling
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 13s
CI / manual (pull_request) Successful in 6m34s
CI / manual (push) Successful in 6m40s
5b171773c7
Record the demonstrated failed-reservation identity loss in the complete
158-issue public coordination index. Keep correction and native acceptance
with the owning Kernel issue. The manual and generated API/build inputs
are unchanged from green CI 849/850 at 2341 final pages and zero warnings.
All 45 documentation tests, Markdown and heading checks pass.
docs: Specify explicit endpoint construction before alias transfer
All checks were successful
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 4s
CI / manual (pull_request) Successful in 3m56s
CI / manual (push) Successful in 4m4s
e923440ace
Explain that endpoint copy requires an existing object before destination
installation, preserving rights and endpoint-family restrictions. Extend
the owned-invocation coordination record with carrier, byte and capability
custody obligations while keeping its ABI and runtime unimplemented.

All 45 documentation tests, Markdown and canonical structure checks pass.
The complete 2341-page manual renders with zero final warnings; all 426861
word boxes fit the page bounds and changed page 183 is visually reviewed.
The public coordination index retains all 158 issues.
docs: Describe native capability transfer preparation and rollback
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 7s
CI / manual (push) Successful in 3m37s
CI / manual (pull_request) Successful in 3m38s
0fe830c906
Document complete batch reservation before capability ownership changes,
including cumulative aliases, typed bindings, containing lineages and unique
grant custody. Keep preparation within existing BSP serialization and
distinguish pre-delivery rollback from persistent invocation ownership and
application cancellation. No syscall number or wire record changes.

All 45 documentation tests and canonical Markdown/structure checks pass.
The complete 2341-page manual has zero final warnings and 426948 word boxes
inside page bounds; changed page 144 is visually reviewed. The public index
retains all 158 issues and generated API/build inputs remain unchanged.
docs: Describe native invocation custody and terminal progress
All checks were successful
CI / markdown (pull_request) Successful in 16s
CI / markdown (push) Successful in 16s
CI / manual (pull_request) Successful in 6m34s
CI / manual (push) Successful in 6m37s
073da48562
Document the private native capability owner, explicit receiver registration,
retained carrier lineage, accepted result lifetime and exactly-once result
collection. Distinguish caller release, server acknowledgment and native
disposal from application cancellation. Keep syscall wire adapters and
CPL3 peer acceptance explicitly open under Kernel issue 11.

All 45 documentation tests and canonical Markdown/structure checks pass.
The complete 2343-page manual renders with zero final warnings; all 427174
word boxes fit the pages and changed page 144 is visually reviewed. Generated
API references and manual build inputs remain unchanged.
docs: Track inherited process state in endpoint fixtures
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 11s
CI / manual (pull_request) Successful in 6m44s
CI / manual (push) Successful in 6m48s
76b657ad8b
Index the observed Kernel CI fixture regression with its canonical bug report
and preserve the distinction between host setup and production behavior.
Record successful manual CI for native invocation custody. All 159 public
issues are indexed, all 45 documentation tests pass, and manual/build inputs
are unchanged from the reviewed warning-free 2,343-page render.
docs: Explain authenticated native delivery origin
All checks were successful
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 13s
CI / manual (pull_request) Successful in 6m50s
CI / manual (push) Successful in 6m51s
c728670ccc
Specify the kernel-retained submitting process and staged generation returned
by native invocation delivery. Distinguish submission identity from later
liveness and authority, and require services to correlate exact retained
ownership and revalidate after blocking effects.

All 45 documentation tests pass. The complete 2,343-page manual renders with
zero final warnings, 427,252 bounded word boxes and visual review of pages
144 and 145. Syscall wire and realm adoption remain separate open gates.
docs: Explain checked native invocation host profiling
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 9s
CI / manual (pull_request) Successful in 5m55s
CI / manual (push) Successful in 5m59s
644273a0ed
Document the maintained actual-object Kernel workload and Integration capture,
report, and comparison boundaries. Explain exact capability and cleanup checks,
minimal child environments, original source and binary identities, owned process
budgets, separate phase durations, and equivalent sampling policy. Preserve the
limits of host measurements and caller-declared build relationships.

All 45 documentation tests pass. The complete 2345-page manual has no final
warnings; all 427592 word boxes fit page bounds and both changed pages were
visually reviewed. Native wire adapters and full self-hosting remain open.
docs: Explain native invocation lookup and settlement invariants
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 12s
CI / manual (pull_request) Successful in 6m43s
CI / manual (push) Successful in 6m45s
f10a1d375a
Describe numeric carrier search hints with live authority checks and complete
fallback, plus increasing allocation-free settlement with exclusive stack
ownership and disposal outside the registry lock. Preserve the distinction
between implemented native custody and the pending syscall/realm adapters.

All 45 documentation tests pass. The complete 2345-page manual has no final
warnings, all 427679 word boxes fit page bounds, and the changed page and its
continuation pass visual inspection. Existing generated API inputs are unchanged.
docs: Specify immediate owned invocation packets and native evidence
All checks were successful
CI / markdown (push) Successful in 17s
CI / markdown (pull_request) Successful in 17s
CI / manual (push) Successful in 6m59s
CI / manual (pull_request) Successful in 7m0s
46da7a4cb4
Document register assignments, checked request/receive layouts, independent
receipt capacity, retained draining ownership and fresh mapping admission.
Explain the current lifetime proof and the isolated CPL3 checks including
caller release and exact server acknowledgment. Regenerate the three affected
library API references from their original signed dependency revisions.

Validation: 45 documentation tests, deterministic API references, Markdown
and template checks; 2363-page manual with zero final warnings and no word
boxes outside page bounds. Visually review the five changed ABI/API pages.
Realm adoption and complete guest build acceptance remain separate gates.
erikinkinen changed title from WIP: Document native IPC platform and lifetime boundaries to WIP: Document owned invocation transport and native custody 2026-09-15 09:02:08 +02:00
docs: Specify process-bound staged installation and producer custody
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / manual (push) Successful in 3m50s
CI / manual (pull_request) Successful in 3m52s
b0fcf0f43a
Document the packed kernel-control request, exact grant identity constraints,
rights, revocation lineage and failure ownership. Record Procd description
adoption while keeping typed realm bootstrap and seal as separate work.
Update the operation registry and three shared API snapshots from original
signed source revisions.

All 45 documentation tests and Markdown checks pass. The complete 2367-page
manual has no final warnings; all 431138 word boxes remain within page bounds
and four changed protocol and API pages were visually reviewed.
erikinkinen changed title from WIP: Document owned invocation transport and native custody to WIP: Document owned invocation and staged installation contracts 2026-09-15 10:21:17 +02:00
docs: Document the staged mediator handoff and native destination
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 14s
CI / manual (pull_request) Successful in 6m47s
CI / manual (push) Successful in 6m50s
8ef5d83839
Describe the separately correlated exact-executable preparation path, private
endpoint-master custody and unstarted mediator lifecycle. Record slot 4 after
the native root bindings and the remaining typed bootstrap obligations.
Regenerate the shared API references from original signed IPC and CapABI.

All 45 documentation tests and API checks pass. The full 2369-page manual
has no final warnings or out-of-page word boxes; changed pages were viewed.
docs: Specify staged primary endpoint attenuation
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / manual (pull_request) Successful in 5m59s
CI / manual (push) Successful in 6m2s
b751a385ca
Document operation 53, exact grant and identity admission, lifecycle locking,
current-rights ceilings and preserved object and revocation associations.
Describe actual native controls and retain the independent Procd bootstrap
and guest-build obligations. Regenerate the three shared API references
from signed original IPC and capability ABI revisions.

All 45 documentation tests pass. The full 2371-page manual renders without
final warnings; every word box fits and the changed pages pass visual review.
erikinkinen changed title from WIP: Document owned invocation and staged installation contracts to WIP: Document native authority and mediator bootstrap contracts 2026-09-15 12:49:14 +02:00
docs: Specify staged construction without child root capabilities
All checks were successful
CI / markdown (push) Successful in 20s
CI / markdown (pull_request) Successful in 19s
CI / manual (pull_request) Successful in 6m50s
CI / manual (push) Successful in 6m57s
4af92b0b1a
Document operation 54 framing, explicit optional VSpace receipts, initial child
inventory, independent native backing and tracked rollback. Preserve operation
32 compatibility and distinguish the available native mechanism from pending
Procd adoption and guarded mediator execution.

Regenerate shared references from the signed IPC and capability ABI graph. Pass
all 45 documentation tests, source-reference checks, Markdown, template checks,
warning-free final manual rendering and visual review of actual changed pages.
Retain the rejected first render separately from accepted frozen-source evidence.
docs: Record root-capability-free mediator staging in Procd
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / manual (pull_request) Successful in 4m11s
CI / manual (push) Successful in 4m12s
8b30523f3d
Document Procd's selection of operation 54 without the unused parent VSpace
receipt, independent native TCB backing, refusal without fallback and unchanged
ordinary construction. Keep authenticated grant return, guarded private
execution and complete realm acceptance separate from this producer change.

Pass all 45 documentation tests, Markdown and template checks, source-bound
manual rendering with zero final warnings, page-boundary checks and visual
review. Preserve the unchanged original signed shared API snapshots.
docs: Specify native caller admission for Launchd ingress
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 18s
CI / manual (push) Successful in 7m0s
CI / manual (pull_request) Successful in 7m1s
45d4d04c53
Document the pending-caller process and generation check before Procd
receipt validation or dispatch, including rejected-transfer disposal and
query-error handling. Correct the receiver inventory to include powerbox
installation and remove the obsolete materialization-operation count.

Documentation tests, source/template checks and the frozen complete manual
pass. All 2,375 pages have in-bounds word boxes, page 212 was visually
reviewed, and the final reference pass is warning-free.
erikinkinen changed title from WIP: Document native authority and mediator bootstrap contracts to WIP: Document staged mediator construction and caller admission 2026-09-15 14:56:42 +02:00
docs: Describe checked artifact boundary receipts
All checks were successful
CI / markdown (push) Successful in 37s
CI / markdown (pull_request) Successful in 36s
CI / manual (pull_request) Successful in 8m0s
CI / manual (push) Successful in 8m4s
507ae8f084
Document the production scanner contract for completed string extraction,
marker and tool failure distinctions, and cleanup of partial owned artifacts.
Describe explicitly selected process helpers and original pinned sources,
and distinguish the minimal bootstrap from the interactive product library.

All 45 documentation tests and Markdown checks pass. The complete manual
renders with no final warnings; all page word bounds pass and the changed
page is visually reviewed. Existing API snapshots remain unchanged.
erikinkinen changed title from WIP: Document staged mediator construction and caller admission to WIP: Document staged construction and artifact validation 2026-09-15 19:19:55 +02:00
docs: Describe exclusive shell transport workspace ownership
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 11s
CI / manual (pull_request) Successful in 6m59s
CI / manual (push) Successful in 7m3s
79cdd4c369
Document the coordinated version-22 target and producer contract, disjoint
ordinary and cleanup buffers, pre-effect storage validation and complete
cleanup erasure. Preserve the distinction between host evidence, full frame
proof, matching runtime validation and the complete self-hosting goal.

All 45 documentation tests and canonical checks pass. The complete manual
renders 2,375 pages without final warnings; all 433,713 word boxes stay in
bounds and changed page 2280 passes visual review. API snapshots are unchanged.
erikinkinen changed title from WIP: Document staged construction and artifact validation to WIP: Document native custody, shell workspace and artifact validation 2026-09-15 21:00:44 +02:00
docs: Describe complete native companion source validation
All checks were successful
CI / markdown (push) Successful in 19s
CI / markdown (pull_request) Successful in 18s
CI / manual (push) Successful in 6m53s
CI / manual (pull_request) Successful in 6m56s
31bd9524c3
Document the eight assembly inputs and original producer script shared by native
selection and support-manifest validation. Explain exact receipt matching and
contract-byte invalidation of both outer artifact cache keys.

All 45 documentation tests and canonical checks pass. The 2375-page manual
renders without final warnings, with the changed page reviewed visually and
all extracted word boxes inside page bounds. Original API snapshots remain
unchanged; diagnostic image evidence has a separate acceptance scope.
docs: Bind workspace evidence and preserve literal command options
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 18s
CI / manual (pull_request) Successful in 7m0s
CI / manual (push) Successful in 7m7s
5d77dc2b82
Document the separate pristine/packaged ELF workspace mapping domain and
its loader assumption without claiming source lifetime or all-path frame
proof. Preserve the unchanged stack ceilings and independent obligations.

Prevent TeX ligatures from changing 24 existing inline command options and
argument delimiters, which otherwise turn ASCII double hyphens into an en
dash. Preserve prose ranges, verbatim commands and original API snapshots.

All 45 documentation tests, canonical and Markdown checks pass. The full
2375-page manual renders without warnings; all 433924 word boxes are in
bounds. Extracted options and nine affected pages pass text/visual review.
Full frame proof and both complete guest build generations remain open.
erikinkinen changed title from WIP: Document native custody, shell workspace and artifact validation to WIP: Document native authority and verify workspace and command evidence 2026-09-15 22:29:14 +02:00
docs: Explain native RELRO construction and final permissions
All checks were successful
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 17s
CI / manual (pull_request) Successful in 7m2s
CI / manual (push) Successful in 7m3s
2560e70884
Document complete protected-page validation and exact final mapping fragments,
while retaining original relocation authorization and privileged construction
writes over an unstarted child. Clarify initial-stack selection and the separate
whole-authority and emitted-frame proof obligations.

All 45 documentation tests and canonical Markdown checks pass. The complete
2375-page manual renders without final warnings; all 434088 word boxes are in
bounds and both changed pages pass visual review. No exported API changes.
docs: Explain native hardware execution permissions
All checks were successful
CI / markdown (push) Successful in 22s
CI / markdown (pull_request) Successful in 19s
CI / manual (pull_request) Successful in 6m56s
CI / manual (push) Successful in 6m59s
d221e725c2
Document explicit mapping permissions, non-executable data aliases and
processor activation. Describe restriction-preserving ancestor promotion
and exact mapping restoration without adding capability authority.

All 45 documentation tests and canonical checks pass. The complete manual
has 2375 pages and 434308 in-bounds word boxes with zero final warnings;
three changed pages pass visual review. Whole authority and guest-build
acceptance remain separate.
docs: Explain maintained native permission validation
All checks were successful
CI / markdown (pull_request) Successful in 16s
CI / markdown (push) Successful in 16s
CI / manual (pull_request) Successful in 6m51s
CI / manual (push) Successful in 6m54s
3fb0b12ff5
Document the explicit image, ELF, tool and firmware selections, private
debugger ownership, full code identity and effective hardware permission
checks. Preserve original command deadlines, both child outcomes and cleanup
requirements without claiming complete authority or guest-build acceptance.

All 45 documentation tests and canonical checks pass. The complete manual
has 2377 pages and 434563 in-bounds word boxes with zero final warnings.
The changed subsection and neighbouring heading pass visual review.
Exported API snapshots are unchanged.
docs: Explain protected relative target proof requirements
All checks were successful
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 19s
CI / manual (pull_request) Successful in 7m11s
CI / manual (push) Successful in 7m15s
83b2d4a2df
Document exact instruction and relocation evidence for calls and tails through
final read-only RELRO slots. Preserve remaining indirect, non-returning and
source-boundary obligations and distinguish partial proof from acceptance.

All 45 documentation tests and canonical checks pass. The full 2377-page manual
renders without final warnings; every word box is in bounds and the changed
page has been visually reviewed. Exported API snapshots are unchanged.
docs: Explain grounded ordinary-return refinement
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 13s
CI / manual (pull_request) Successful in 6m53s
CI / manual (push) Successful in 6m54s
97ce65dcb8
Describe how earlier complete loop and trap proofs suppress call fallthrough
while retaining exact callee, depth and relocation evidence. Document grounded
tail dependencies and the limits of the ordinary-call model without weakening
stack budgets or source-domain requirements.

All 45 documentation tests and canonical checks pass. The complete manual is
rendered without final warnings, every word box is in bounds and the changed
page has been visually reviewed. Exported API snapshots remain unchanged.
docs: Explain interactive failure progress and cleanup uncertainty
All checks were successful
CI / markdown (pull_request) Successful in 24s
CI / markdown (push) Successful in 25s
CI / manual (pull_request) Successful in 7m2s
CI / manual (push) Successful in 7m5s
c4bfc12245
Document fixed private evidence reads and descriptive shell-line and interrupt
milestones. Distinguish unknown input status and requested cleanup from waited
input failure, while preserving all guest acceptance and timing requirements.

All 45 documentation tests and full rendering pass without final warnings.
Review both changed pages and all word bounds; earlier release failures remain
unresolved and no new guest execution or full build is established.
docs: Explain protected register target provenance
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 15s
CI / manual (push) Successful in 6m59s
CI / manual (pull_request) Successful in 7m0s
4f770bee4c
Document predecessor agreement, original protected load receipts, complete
register-family and implicit clobbers, and call-boundary invalidation. Keep
macro effects, encoding limits and incomplete source/frame obligations
explicit so static evidence cannot imply whole guest acceptance.

All 45 documentation tests, Markdown checks and the complete manual render
pass. Every word box is within its page, the changed page was visually
reviewed, and the final render has no warnings.
docs: Explain bounded relative table branch evidence
All checks were successful
CI / markdown (push) Successful in 19s
CI / markdown (pull_request) Successful in 15s
CI / manual (pull_request) Successful in 7m14s
CI / manual (push) Successful in 7m21s
242b78c8f3
Describe distinct numeric, base and offset facts, complete immutable read
windows and original anchors. Require every target boundary before retaining
a branch proof, and keep guard relationships, enum validity, function-call
authority and complete source/frame admission explicit.

All 45 tests and Markdown checks pass. The 2379-page manual renders with no
final warnings, all word boxes fit, and both changed pages were visually
reviewed. This documentation does not establish a full guest build.
docs: Explain comparison bounds and ordinary table flow
All checks were successful
CI / markdown (push) Successful in 26s
CI / markdown (pull_request) Successful in 24s
CI / manual (pull_request) Successful in 7m19s
CI / manual (push) Successful in 7m24s
d8fbc3a1f3
Document exact comparison widths, flag lifetime, conditional edge evidence and
producer-width widening in the build manual. Describe ordinary table dispatch
and function-owned decoder-effect caching while retaining full source, frame,
authority and guest-build obligations.

All 45 documentation tests and canonical checks pass. The 2379-page manual has
435637 in-bounds word boxes, no final warnings and reviewed changed pages.
docs: Explain modular arithmetic frame evidence
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 20s
CI / manual (pull_request) Successful in 7m36s
CI / manual (push) Successful in 7m40s
07181c34b1
Document exact ADD/SUB result pieces, carry and zero conditions, defined INC/DEC
widths and full-width numeric guards without inferring caller authority. Preserve
narrow-width proof requirements, encoding refusals and full source/frame gates.

Describe function-scoped immutable grammar caching. All 45 documentation tests,
Markdown checks and the 2379-page manual pass; the final render has no warnings
and changed pages have been visually reviewed. Full guest builds remain unproved.
docs: Explain grounded call preservation and frame invalidation
All checks were successful
CI / markdown (push) Successful in 21s
CI / markdown (pull_request) Successful in 19s
CI / manual (pull_request) Successful in 7m13s
CI / manual (push) Successful in 7m20s
7a7c3ff009
Document conditional register contracts from original bodies and earlier
callee evidence, including typed facts, unknown effects and frame-pointer
invalidation. Explain finite proof retention and profiled work removal while
preserving the separate source/frame and full in-system build requirements.

All 45 documentation tests and canonical Markdown checks pass. The complete
2379-page manual has no final warnings, all word boxes fit their pages, and
the changed pages have been visually checked. API snapshots are unchanged.
docs: Explain native artifact frame inspection
All checks were successful
CI / markdown (push) Successful in 18s
CI / markdown (pull_request) Successful in 18s
CI / manual (pull_request) Successful in 7m0s
CI / manual (push) Successful in 7m3s
12c6d0a91e
Document original-to-stripped pairing, the exact entry trampoline and
symbolic relocation write footprints without implied target authority.
Keep native dependency closure and complete guest builds explicitly open.

Validate all 45 tests and the complete warning-free manual, including
visual review of the changed native intake contract.
docs: Specify symbol-only relocation values
All checks were successful
CI / markdown (push) Successful in 20s
CI / markdown (pull_request) Successful in 16s
CI / manual (pull_request) Successful in 7m15s
CI / manual (push) Successful in 7m20s
214b08666b
Document S, S+A and B+A and the unchanged provider and writable target
contracts. Regenerate only the lib-dynlink API snapshot from its exact
signed correction, preserving all other library snapshots.

Pass 45 documentation tests and canonical Markdown checks. Render all
2383 manual pages with zero final warnings, check 436424 word boxes and
visually review the changed contract and generated API pages. Consumer
candidate validation does not establish coherent image or realm adoption.
docs: Explain closed native dependency artifact intake
All checks were successful
CI / markdown (pull_request) Successful in 15s
CI / markdown (push) Successful in 15s
CI / manual (push) Successful in 7m5s
CI / manual (pull_request) Successful in 7m15s
88537b23e1
Document explicit JSON selectors, exact runtime closure membership and
aggregate input ownership. Distinguish library stripping invariants and
packaged content identity from unverified producer source claims.

Keep provider resolution and cross-object frame acceptance explicit as
remaining work. Validate 45 documentation tests, canonical Markdown and
the complete 2383-page manual with no final warnings, all word boxes
in bounds and visual review of the changed native intake page.
docs: Specify ordered native symbol evidence
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 9s
CI / manual (pull_request) Successful in 3m47s
CI / manual (push) Successful in 3m50s
24cefeb2dc
Describe loader discovery order, positional dependencies, native strong and
weak lookup, and object-qualified conditional function identities. Preserve
the distinction from relocated slots, complete frames and source membership.

Validate documentation controls and the complete warning-free manual,
including page bounds, command typography and changed-page visual review.
docs: Specify protected cross-object frame evidence
All checks were successful
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 8s
CI / manual (push) Successful in 4m6s
CI / manual (pull_request) Successful in 4m7s
44cd6c4aa9
Document shared native decode budgets, object-qualified function identities,
protected relative and symbolic slots, and grounded cross-library call rules.
Distinguish native report schema 3 from standalone schema 2 and retain the
successful checked-loader premise without claiming observed load bases or
complete source/frame acceptance. Both full builds inside EriX remain required.
docs: Specify saved value and stack write preservation contracts
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 5s
CI / manual (push) Successful in 3m10s
CI / manual (pull_request) Successful in 3m12s
c3401e5f6b
Separate equality with incoming register values from callee memory confinement.
Document checked slot ownership, alias invalidation, deallocation retirement,
signed write bounds and grounded dependency refinement. Preserve the distinction
between conditional static evidence, full source/frame proof and both complete
builds inside EriX. No calling-convention or memory-safety assumption is added.
docs: Specify caller-bound stack preservation evidence
All checks were successful
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 5s
CI / manual (push) Successful in 4m0s
CI / manual (pull_request) Successful in 4m0s
fc3ee44748
Describe explicit live caller bindings, nested write translation, return-address
gaps and per-slot invalidation. Keep conditional masks separate from general
function guarantees and prevent discarded contents from granting authority.

Explain conservative demand, rejection-only candidates, incompatible fact
kinds and pending CFG work. Preserve complete source/frame and guest-build
acceptance requirements alongside partial static evidence.
docs: Define caller-local query ownership and native canary checks
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / manual (pull_request) Successful in 3m7s
CI / manual (push) Successful in 3m7s
4ff9a60ed9
Document one attributed caller record, explicit CSpace metadata reads, preserved
error precedence and cleared descriptive payloads. Describe fifteen real CPL3
query cases with private live-stack and saved-register checks before the existing
invocation fixture, while keeping finite observations separate from general
kernel memory guarantees and complete guest-build acceptance.

All 45 documentation tests, Markdown checks and the complete 2385-page manual
pass. Final rendering has no warnings; 437473 word boxes remain in bounds and
the three affected pages have been visually reviewed. Public API snapshots and
runtime implementations are unchanged in this documentation checkpoint.
docs: Use one complete syscall selector inventory
All checks were successful
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 9s
CI / manual (push) Successful in 5m54s
CI / manual (pull_request) Successful in 5m55s
0a0f305464
Replace the stale detailed-reference list with a link to the complete IPC
operation table. The duplicate omitted eight owned-invocation selectors and
incorrectly classified them as unassigned. Keep the removed host-report
selector explicitly rejected. This repairs issue 9 without changing the ABI
or generated API snapshots.

All 45 documentation tests, Markdown and template checks pass. The complete
2,385-page manual renders with no final warnings; all 437,463 word boxes are
in bounds, and pages 142 and 163 were visually reviewed. Runtime checks are
inapplicable to this documentation-only correction. Automatic CI is pending.
docs: Reconcile syscall entry and retained resume state
All checks were successful
CI / markdown (push) Successful in 15s
CI / markdown (pull_request) Successful in 18s
CI / manual (pull_request) Successful in 7m11s
CI / manual (push) Successful in 7m25s
c7bfffc4a2
Describe the actual IRETQ return, seventeen-word resume prefix, separate
176-byte entry reservation and 256 KiB kernel stack. Replace obsolete
SYSRETQ and user-stack construction claims, addressing issue 10. Document
the explicit entry direction contract and bounded native diagnostics without
claiming general syscall memory preservation or a complete guest build.

All 45 documentation tests and Markdown/template checks pass. The complete
2,387-page manual has 437,732 in-bounds word boxes and no final warnings;
pages 146, 166, 168 and 169 were visually reviewed. No API snapshot changes.
Runtime checks are inapplicable to this documentation-only change; automatic
CI remains pending.
docs: Specify aligned exception calls and exact hardware frame bounds
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / manual (pull_request) Successful in 3m41s
CI / manual (push) Successful in 3m43s
2a6bb72066
Distinguish the preserved hardware-frame pointer from the aligned compiled
call stack. Document the actual pre-prologue callee sample, five or six saved
words, and the independent double-fault IST diagnostic. Preserve the stated
limits of finite native evidence and leave API snapshots unchanged.

All 45 documentation tests and Markdown/template checks pass. The complete
2,387-page manual has 437,838 in-bounds word boxes and no final warnings;
pages 147 and 166 were visually reviewed. Runtime checks are inapplicable to
this prose-only change. Original automatic CI remains pending.
docs: Describe borrowed syscall capture and failure disposition
All checks were successful
CI / markdown (pull_request) Successful in 16s
CI / markdown (push) Successful in 17s
CI / manual (pull_request) Successful in 7m9s
CI / manual (push) Successful in 7m22s
2435bf5ed1
Document the complete initialized entry prefix, internal borrowed capture,
stable owned copies and refusal before operation dispatch. Preserve the
existing hardware word layout and distinguish capture guarantees from an
unproved general syscall memory-effect contract.

All 45 documentation tests, Markdown and template checks pass. The complete
2387-page manual has 437959 in-bounds word boxes and no final warnings; pages
167 and 169 were visually inspected. Rust builds and VM execution belong to
the corresponding Kernel change and are not documentation test results.
docs: Define retained VSpace cleanup ownership and progress
All checks were successful
CI / markdown (push) Successful in 18s
CI / markdown (pull_request) Successful in 16s
CI / manual (push) Successful in 7m29s
CI / manual (pull_request) Successful in 7m27s
d1f635a475
Document one-way retirement, separate access-withdrawal progress, exact frame
reference consumption and retention of the final process reference on error.
Keep this contract distinct from the surrounding process-destruction sequence
and ordinary VSpace activation, which need their own validation.

All 45 documentation tests, Markdown and format checks pass. The complete
2387-page manual has 438059 in-bounds word boxes and zero final warnings;
page 132 was visually checked. Runtime validation belongs to the paired
Kernel change, and neither checkpoint establishes a full guest build.
docs: Describe process cleanup custody before identity reuse
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 6s
CI / manual (pull_request) Successful in 3m58s
CI / manual (push) Successful in 3m59s
d7f1a59620
Specify distinct aborting and destroying states and retention of the empty
private CSpace through the final VSpace release. Document exact TCB validation,
lock order and the infallible final identity-retirement commit without claiming
rollback of earlier cleanup effects or whole-process atomicity.

All 45 documentation tests, Markdown and document-format checks pass. The
complete 2387-page manual has 438174 in-bounds word boxes and zero final
warnings; page 132 is visually reviewed. Runtime and full guest-build
acceptance retain their separate component validation requirements.
docs: Specify unambiguous compiler runtime archive selection
All checks were successful
CI / markdown (pull_request) Successful in 3s
CI / markdown (push) Successful in 3s
CI / manual (pull_request) Successful in 3m10s
CI / manual (push) Successful in 3m12s
cf684745b0
Describe the shared final-link rule for Kernel, Rootd and native services.
Missing, ambiguous and non-file candidates fail instead of using filesystem
modification time; provenance, cache coverage and toolchain lifetime remain
separate obligations.

Validate 45 documentation tests and the complete 2387-page manual with zero
final warnings, in-bounds geometry and visual review of the changed page.
docs: Specify single-driver linking and fatal diagnostics
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 10s
CI / manual (push) Successful in 6m45s
CI / manual (pull_request) Successful in 6m44s
050b9bcc3a
Document explicit compiler-host discovery when standalone tools are absent,
retained driver aliases, fatal warnings and visible successful diagnostics.
A selected driver's failure must not invoke another implementation or admit
partial output; standalone linking needs no compiler identity query.

Validate 45 tests and the complete 2387-page manual with zero final warnings,
in-bounds geometry and visual review of the complete changed paragraph.
docs: Specify compiler metadata consistency
All checks were successful
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 12s
CI / manual (pull_request) Successful in 7m10s
CI / manual (push) Successful in 7m16s
64fc14411a
Document one byte-consistency policy for executable and shared-library
compiler metadata, including inherited providers and internal aliases.
Preserve identical repetitions, use exclusive new destinations and bind the
policy into both artifact cache identities. Retain caller obligations for
source provenance, lifetime and scratch cleanup.

All 45 documentation tests and the complete 2387-page manual pass. All 438492
word boxes stay within their pages; the changed paragraph is visually reviewed
on pages 2292 and 2293. The final manual has no warnings.
docs: Specify generation-bound native terminal observation
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 9s
CI / manual (pull_request) Successful in 5m32s
CI / manual (push) Successful in 5m34s
be98a93e6f
Document operation 55 and its exact process/generation/kind/status contract,
pre-dequeue validation and retired selector. Explain Procd's generation check
before retirement and Rootd's requirement for terminal proof before native
destruction. Regenerate shared API references from the signed IPC graph and
render packed-word shifts as literal operators.

All 45 documentation tests pass. The complete 2389-page manual is warning-free,
with 439146 in-bounds word boxes and reviewed native, service and API pages.
Both isolated Kernel native gates pass separately; ordinary service-image
adoption, typed mediator bootstrap and full guest builds remain open.
docs: Reconcile the native terminal bootstrap baseline
All checks were successful
CI / markdown (push) Successful in 21s
CI / markdown (pull_request) Successful in 16s
CI / manual (push) Successful in 7m15s
CI / manual (pull_request) Successful in 7m25s
10ea454eba
Record the reviewed generation-bearing Rootd operation inventory and its
15,239 release-active lines. Keep compiler-specific image size separate from
comparable performance evidence and preserve the full guest-build requirements.

All 45 documentation tests and the complete 2,389-page manual pass. Final PDF
warnings are zero; all 439,184 word boxes are in bounds and the changed testing
page was visually reviewed. Ordinary service-image adoption remains open.
docs: Specify exact-generation native cleanup and audit linking
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / manual (pull_request) Successful in 3m40s
CI / manual (push) Successful in 3m44s
323da98365
Document generation-bound destroy and abort, retired selectors, exact native
reply framing and retained cleanup identity across service and bootstrap paths.
Regenerate three shared API references from their signed source revisions and
record nineteen actual CPL3 cleanup controls with unchanged native VM gates.

Correct the operation registry and bootstrap artifact measurement: native audit
linking now selects Rootd's real entry, so the earlier entry-less image is invalid
runtime-size evidence. All 45 documentation tests and API provenance checks pass.
The complete 2397-page PDF has no final warnings, 440339 in-bounds word boxes and
seven visually reviewed changed pages. Runnable realms and guest builds remain
open acceptance requirements.
docs: Specify returned-grant bootstrap custody and producer checks
All checks were successful
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 19s
CI / manual (pull_request) Successful in 7m6s
CI / manual (push) Successful in 7m10s
b6bd8ce328
Document the exact guarded-stage request and acknowledgment, authenticated
supervisor and real grant admission, five scratch-column roles and native
ancestor/nested revocation custody. Require source absence before accepting
success and preserve exhaustive exact-stage cleanup and uncertainty boundaries.

Regenerate three shared API references from signed source revisions. All 45
documentation tests and API provenance checks pass. The complete manual has
2403 pages, 441471 in-bounds word boxes and seven reviewed changed pages with
zero final warnings. Runtime realm orchestration, actual consumer VM coverage,
owned fair progress and both complete builds inside EriX remain required.
docs: Specify bounded deferred native cleanup scheduling
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / manual (pull_request) Successful in 7m22s
CI / manual (push) Successful in 7m30s
da66c0efd6
Document the exact-generation queue, one native attempt before runtime intake,
rotation of uncertain owners and retained first failure. Separate per-turn
call-count bounds from elapsed time and unresolved legacy provider progress.

All 45 tests and the complete 2403-page manual pass. All 441578 word boxes
remain in bounds, both changed pages are visually reviewed and final warnings
are absent. Shared API references remain unchanged. Consumer VM and complete
realm and guest-build acceptance remain open.
docs: Specify caller-local grant relocation and native evidence
All checks were successful
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 17s
CI / manual (pull_request) Successful in 7m27s
CI / manual (push) Successful in 7m29s
623609ee62
Document syscall 0x54 register admission, actual Running caller and unique grant
custody, unchanged installation/revocation scope and exact result precedence.
Describe the safe native shim, local hosted refusal and thirty-nine real CPL3
controls preceding the existing installation and lifetime oracles. Regenerate
three API references from signed original shared source revisions.

All 45 tests and the complete 2403-page manual pass with 442370 in-bounds word
boxes and zero final warnings. Nine changed pages are visually reviewed and
API provenance/regeneration checks pass. Actual owned service adoption, consumer
VMs, complete realm fairness and both full guest builds remain open.
docs: Specify explicit owned receiver admission
All checks were successful
CI / markdown (push) Successful in 18s
CI / markdown (pull_request) Successful in 18s
CI / manual (push) Successful in 7m4s
CI / manual (pull_request) Successful in 7m8s
8361618f3f
Document REGISTER request byte and capability limits, exact repetition,
zero dimensions, complete addressability and refusal before native custody.
Explain direct descriptor iteration and the scope of allocation observations.
Regenerate three public API references from the signed shared dependency graph.

All 45 tests, provenance/regeneration checks, Markdown and the complete manual
pass. The 2,407-page output has 442,761 in-bounds word boxes; eight changed pages
were visually reviewed and final warnings are absent. Actual owned service
adoption, consumer VM and full EriX-in-EriX builds remain separate requirements.
docs: Specify owned bootstrap delivery and retirement
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / manual (push) Successful in 3m50s
CI / manual (pull_request) Successful in 3m50s
5c1cf6da31
Document the identity-only request, actual claimed origin, exclusive existing
grant ingress, native scope checks before relocation, exact rollback and retained
draining bookkeeping in the Procd runtime. Explain alternating admission classes
and keep actual Launchd orchestration and consumer VM acceptance open.

Regenerate three shared API snapshots from original signed source. All 45 tests,
provenance checks and the complete 2407-page manual pass. All 442920 word boxes
are in bounds; seven rendered pages were inspected and final output has no warnings.
docs: Specify original realm supervisor and cancellation custody
All checks were successful
CI / markdown (push) Successful in 19s
CI / markdown (pull_request) Successful in 20s
CI / manual (push) Successful in 7m18s
CI / manual (pull_request) Successful in 7m18s
a410759e55
Document actual private service attestation, the exact 64-byte materialization
begin, retained original ownership before creation and handoff, and independent
preparation and stage retirement. Distinguish caller RELEASE cancellation from
application rollback and server RELINQUISH. Refresh three signed API snapshots.

All 45 tests, API provenance and regeneration checks pass. The complete manual
has 2,409 pages and 443,265 in-bounds word boxes; seven rendered pages were
inspected and final output has no warnings. Actual Launchd runtime adoption,
consumer VM execution, complete realm operation and full guest builds remain open.
docs: Describe retained realm bootstrap caller ownership
All checks were successful
CI / markdown (push) Successful in 20s
CI / markdown (pull_request) Successful in 16s
CI / manual (pull_request) Successful in 7m26s
CI / manual (push) Successful in 7m30s
4dcbc10e32
Document immediate native submission, cap-free collection and retirement while
keeping original child rollback separate. Describe source-slot absence that
survives reuse, preserved first errors and the ordinary-call boundary required
by scheduler integration. Runtime admission and consumer VM proof remain open.

All 45 documentation tests and the complete 2409-page manual pass. All 443468
word bounds are valid, both changed pages are visually reviewed and final
warnings are zero. No Rust implementation or generated API snapshot changes.
docs: Specify caller-bound realm admission and storage
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 12s
CI / manual (pull_request) Successful in 6m13s
CI / manual (push) Successful in 6m17s
9868cf0e6f
Describe exact admission messages, actual original-caller semantics, explicit
72-byte LCH1 version 3 and independently retained native realm records. Update
four shared API snapshots from their signed dependency graph and correct stale
bootstrap width, version and slot-count descriptions. Keep actual dispatcher,
Loaderd, scheduler and coordinated image adoption explicitly pending.

All 45 tests, signed API provenance/regeneration checks and the full 2417-page
manual pass. All 445195 word bounds and seven rendered pages are reviewed, with
zero final warnings. This manual does not accept a runnable realm or guest build.
docs: Describe retained exact realm preparation
All checks were successful
CI / markdown (push) Successful in 20s
CI / markdown (pull_request) Successful in 21s
CI / manual (pull_request) Successful in 7m17s
CI / manual (push) Successful in 7m25s
880bdc5981
Document actual scoped executable and manifest authentication through VFS and
Loaderd, shared preparation with separate TTY policy, deployment scratch reuse
and independent original resource cleanup. Distinguish implemented effects from
pending dispatcher, held reply, scheduler and native image acceptance.

All 45 tests and the complete 2419-page manual pass. All 445389 word bounds
and both changed rendered pages are reviewed, with zero final warnings. Shared
API snapshots remain unchanged; complete in-guest builds are still required.
docs: Describe public realm dispatch and native progress
All checks were successful
CI / markdown (pull_request) Successful in 15s
CI / markdown (push) Successful in 17s
CI / manual (pull_request) Successful in 6m44s
CI / manual (push) Successful in 6m57s
099f0c5704
Document canonical public intake, independently retained replies and rotating
native progress before ordinary dispatch. Explain reply-loss cancellation,
original-parent cleanup and complete retirement before record reuse. Keep
coordinated image consumers, native VM proof and complete guest builds open.

All 45 documentation tests and the complete manual pass. Every rendered word
is within its page and all changed pages are visually reviewed, with zero
final warnings. Shared API snapshots are unchanged.
docs: Describe realm startup consumers and production audit
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 13s
CI / manual (pull_request) Successful in 6m55s
CI / manual (push) Successful in 7m0s
33733ceba2
Document exact version-3 startup consumers, explicit realm storage and native
empty-allocation alignment. Record Rootd's reviewed decoder, code-line and
linked-byte audit while preserving unchanged authority and unsafe inventories.
Keep coordinated image publication, native consumer proof and guest builds open.

All 45 documentation tests and the complete manual pass. Every rendered word
is within its page and both changed pages are visually reviewed, with zero
final warnings. Shared API snapshots are unchanged.
docs: Require native rebuilding of the imported toolchain
All checks were successful
CI / markdown (push) Successful in 21s
CI / markdown (pull_request) Successful in 17s
CI / manual (pull_request) Successful in 7m26s
CI / manual (push) Successful in 7m31s
b54d28e755
Distinguish the EriX-targeted cross-bootstrap compiler from the required
Rust/LLVM rebuild inside an extended development realm. Require offline
recipes, declared runtime linkage, functional guest-built tools and use in
a complete EriX build. Retain independent compiler ownership as later work.

All 45 documentation tests and the complete manual pass, with every word
inside its page and the changed page visually reviewed. Final output has
no warnings; shared API snapshots are unchanged.
docs: Clarify realm admission on private script routes
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / manual (push) Successful in 4m45s
CI / manual (pull_request) Successful in 4m44s
ce8a1538ab
Describe the private sender actually supplied to shells and the active-envelope
and original native-owner authentication before shared realm intake. Preserve
the serial dispatcher's original reply custody and separate deployment record
capacity. Replace an obsolete startup-publication status paragraph with the
permanent matching-source and distinct runtime-evidence requirements.

All 45 documentation tests and the complete manual build pass. Every rendered
word remains in bounds and the changed page has been visually reviewed without
final warnings. Shared API snapshots are unchanged. Matching corrected-server
VM evidence, native toolchain rebuilding and both full EriX builds remain open.
docs: Distinguish guarded custody from running realm work
All checks were successful
CI / markdown (pull_request) Successful in 23s
CI / markdown (push) Successful in 24s
CI / manual (pull_request) Successful in 7m10s
CI / manual (push) Successful in 7m12s
7b79f8d50a
Remove stale proposed-custody and pending-dispatch claims from the process
services chapter. Describe implemented unstarted Procd guard ownership and
keep kernel-only lifetime evidence distinct from producer preparation and
the remaining startup, readiness, running-realm retirement and cleanup gates.
No Posixd execution or whole-realm acceptance follows from the guarded fixture.

All 45 tests and the complete manual pass. Every word box is within its page,
all changed pages are visually reviewed and final warnings are absent. Shared
API snapshots remain unchanged. Rust and new runtime checks do not apply to
this TeX/Markdown-only change; original documentation CI remains required.
docs: Specify native child lifetime binding admission
All checks were successful
CI / markdown (pull_request) Successful in 23s
CI / markdown (push) Successful in 23s
CI / manual (pull_request) Successful in 7m30s
CI / manual (push) Successful in 7m33s
54557713f4
Document the exact shared child/grant envelope and separate existing
Process authority from target evidence, committed custody, stopping and
safe reclamation. Preserve lost-response cleanup and replacement identity
constraints without implying that Kernel enables the new operation.

Regenerate both IPC API views from original signed sources. All 45 tests,
source/regeneration checks and the complete 2423-page manual pass; all word
bounds and nine selected contract pages are reviewed without final warnings.
Native enforcement and consumer adoption remain open in Kernel issue 19.
docs: Describe native child lifetime enforcement and reclamation
All checks were successful
CI / markdown (pull_request) Successful in 20s
CI / markdown (push) Successful in 23s
CI / manual (pull_request) Successful in 6m57s
CI / manual (push) Successful in 7m12s
9ca5a5e811
Document actual Process/grant admission, descendant preflight and stopping,
exact Kernel cleanup custody and safe return/idle accounting boundaries.
Explain partial abort after unlinking and distinguish the new CPL3 supervisor
proof from executing-child, no-successor and full consumer acceptance.

All 45 documentation tests and the complete 2425-page manual pass without
final warnings. Every word box is in bounds and all three changed contract
pages are visually reviewed. Shared API reference source remains unchanged.
Full source/effect/frame proof, external toolchain rebuilding and both full
EriX build generations inside EriX remain mandatory.
docs: Specify terminal control reply and native child cleanup boundaries
All checks were successful
CI / markdown (pull_request) Successful in 16s
CI / markdown (push) Successful in 17s
CI / manual (pull_request) Successful in 7m21s
CI / manual (push) Successful in 7m27s
b4b01d8707
Document the synchronous control request borrow boundary and suppression of reply
writes after the original caller becomes terminal. Explain the executing-child
native observations, nested cleanup, exact events and unrelated process survival.
Retain separate native idle, consumer and full guest-build acceptance gates.
docs: Describe native child reclamation at the pre-halt boundary
All checks were successful
CI / markdown (pull_request) Successful in 20s
CI / markdown (push) Successful in 20s
CI / manual (pull_request) Successful in 6m49s
CI / manual (push) Successful in 6m53s
69466a64c0
Document the final bound-child diagnostic with no runnable userspace successor.
Explain ordinary accounting/cleanup ordering, retained unconsumed terminal events,
exact child resource absence and the read-only Kernel observation boundary.

Keep actual hardware wakeup, provider completion, consumer adoption and full
guest/toolchain builds as separate acceptance requirements.
docs: Specify native terminal event allocation refusal evidence
All checks were successful
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 16s
CI / manual (push) Successful in 7m26s
CI / manual (pull_request) Successful in 7m53s
62ba2ffa30
Describe explicit fault preparation, real allocator refusal and ordinary Process
error delivery with subtree preservation and reservation rollback. Keep later
successful termination, independent release failures and full guest toolchain
and EriX build requirements distinct.
docs: Describe independent native child release recovery
All checks were successful
CI / markdown (push) Successful in 19s
CI / markdown (pull_request) Successful in 16s
CI / manual (pull_request) Successful in 7m58s
CI / manual (push) Successful in 8m1s
2a0ccc1a59
Document two diagnostic refusals at the original child final VSpace-release
callback and read-only observations of its retained first error and cleanup
duty while another child retires. Keep all prior native acceptance gates.

The complete manual, documentation tests and visual/layout checks pass with
zero final warnings. Consumer adoption and full guest rebuilds remain open.
docs: Specify exact installer authority and final handoff
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / manual (push) Successful in 3m55s
CI / manual (pull_request) Successful in 3m56s
f4621ce292
Document independent grant-own rights and child installation ceilings for
native creation and derivation. Replace obsolete reserved-field and
GRANT-plus-MINT receipt contracts, describe explicit source disposal before
final handoff, and regenerate both IPC references from the signed source.
Record the actual CPL3 grant controls and their service-acceptance limits.

All 45 tests, API checks and the complete 2429-page manual pass without
warnings. All 448913 word bounds and eleven rendered changed pages pass
review. Full consumer lifecycle and guest self-hosting remain open.
docs: Explain the managed installer return-slot contract
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / manual (pull_request) Successful in 3m16s
CI / manual (push) Successful in 3m21s
9d464d3ebc
Document unique relocation after disposing the delegating source so the
GRANT-only handoff returns to the slot required by later TTY provisioning.
Keep occupied-destination refusal and original-stage cleanup explicit.

All 45 tests, the complete 2429-page manual and 448970 word bounds pass
without final warnings. The changed handoff page passes visual review.
The existing generated API references are unchanged.
docs: Specify acknowledged terminal accounting and consumer custody
All checks were successful
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 14s
CI / manual (pull_request) Successful in 6m24s
CI / manual (push) Successful in 6m28s
18f13764c5
Describe repeatable observation, exact acknowledgement and retained final CPU
evidence after native reclamation. Document consumer queue preflight, mediator
scalar ownership, original supervisor loss and Rootd discard after proved cleanup.
Regenerate shared API references from the original signed IPC revision.

All 45 documentation tests, generated-reference equality, Markdown and template
checks pass. The complete 2431-page manual builds without warnings and changed
prose and API pages pass visual review. Full service and native guest toolchain
and EriX build acceptance remain required.
docs: Align the kernel selector summary with terminal observation
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 8s
CI / manual (pull_request) Successful in 3m42s
CI / manual (push) Successful in 3m46s
e4525848ad
Mark destructive terminal selector 55 retired and include lifetime binding and
the separate observation and acknowledgement selectors in the summary table.
Keep the summary consistent with the detailed contract and signed IPC registry.

All 45 documentation tests and Markdown/template checks pass. The complete
2431-page manual rebuilds without warnings; the changed selector page passes
visual review and its entries match the original shared constants.
docs: Specify explicit provider frame tool custody
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / manual (pull_request) Successful in 6m37s
CI / manual (push) Successful in 6m41s
f8a40d45fb
Document the selected disassembler and original helper boundary, minimal
child environment, bounded ownership and retained failures. Preserve the
distinction between local byte receipts and complete guest stack proof.

All 45 documentation tests and the full 2431-page manual pass with no final
warnings. All rendered word bounds and the changed page are reviewed; the
shared API reference inputs remain unchanged.
docs: Specify original Kernel startup profile admission
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 5s
CI / manual (push) Successful in 4m48s
CI / manual (pull_request) Successful in 4m49s
76672dff8f
Document the required complete runtime transition and the Kernel compiler
feature/source binding. Distinguish original direct compilation from custom
source and synthetic wrappers while preserving all startup timing gates.

All 45 tests and the complete 2431-page manual pass without final warnings.
All 450096 word bounds and both changed pages are reviewed. No host receipt
establishes boot performance or native toolchain and EriX self-hosting.
docs: Specify original process metrics consumer custody
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 14s
CI / manual (pull_request) Successful in 6m39s
CI / manual (push) Successful in 6m40s
2d05169e69
Document authenticated ordinary start and exact consumer checks for successor
commit and live or terminal measurements. Distinguish scalar retention from
realm capability custody, resource destruction and visible event delivery.
Preserve unsponsored materialization and fail-stop reply semantics.

All 45 tests and the complete 2431-page manual pass without final warnings.
All 450185 word bounds and the changed page are reviewed. Coherent service VM
adoption and complete lifecycle authority acceptance remain separate.
docs: Specify bounded host execution profiling
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / manual (push) Successful in 3m55s
CI / manual (pull_request) Successful in 3m56s
1ade28490f
Document explicit emulator and plugin admission, fresh output ownership,
complete-capture framing and exact packaged ELF code candidates. Separate
translated instruction upper bounds from process identity and elapsed time;
retain guest authority boundaries and the original timing acceptance rules.

All 45 tests and the complete 2431-page manual pass. All 450367 rendered word
bounds and both changed pages are reviewed, with zero final warnings or
layout overflow. Full-build profiling and in-EriX toolchain rebuilding remain
required and unproven.
docs: Specify the ordinary user mapping address domain
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 7s
CI / manual (pull_request) Successful in 5m2s
CI / manual (push) Successful in 5m12s
043df99baa
Document complete-page admission shared by VSpace-slot and Process-child
requests, preserving capability and alignment checks before address-domain
validation and backing changes. Retain zero and the final complete user page;
bootstrap mappings require their separate provenance and retirement proof.

All 45 tests and the complete 2431-page manual pass without final warnings.
All 450473 word bounds and the changed page are reviewed. This contract does
not establish owned hardware roots or successful guest toolchain builds.
docs: Specify current VSpace mapping authority
All checks were successful
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 13s
CI / manual (push) Successful in 7m0s
CI / manual (pull_request) Successful in 6m56s
a96c994750
Document the MAP right required for caller-local mapping, protection and
unmapping independently of live object identity. Empty and MANAGE-only
attenuations cannot mutate mappings; MAP alone suffices when frame authority
and the existing mapping rules permit the request. Preserve identity and
retirement precedence and separate Kernel lifecycle obligations.

All 45 tests and the complete 2431-page manual pass without final warnings.
All 450550 word bounds and both changed pages are reviewed.
docs: Specify frame access and retained backing
All checks were successful
CI / markdown (push) Successful in 6s
CI / markdown (pull_request) Successful in 6s
CI / manual (push) Successful in 5m21s
CI / manual (pull_request) Successful in 5m19s
45dae3cee4
Separate MAP custody from requested user access. Document ordinary x86
READ requirements, unsupported access refusal, no-access leaf policy and
backing lifetime across capability disposal and mapping reactivation.
Existing protection-transition rules remain in force.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 450702 word bounds and the changed rendered page are reviewed.
docs: Specify current-grant frame protection and disposal
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 13s
CI / manual (pull_request) Successful in 6m49s
CI / manual (push) Successful in 6m51s
155b2a0cd2
Document representable protection restoration through exact managed or
device backing, live alias rights and final mapping custody. Distinguish
reversible user access from irreversible disposal of control grants and
from the separate anonymous materializer's union of requested rights.
Describe actual managed-RAM data and code validation without granting
complete POSIX or toolchain self-hosting acceptance.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 450954 word bounds and both changed rendered pages are reviewed.
docs: Specify supervisor access to retained physical backing
All checks were successful
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 17s
CI / manual (pull_request) Successful in 7m17s
CI / manual (push) Successful in 7m20s
589449e417
Document the shared physical window for frame scrubbing and mapping-byte
copies, including caller custody, supervisor/NX permissions, unchanged
cache policy and restoration before allocation release. Describe the
same-VA/different-backing native control and keep independent hardware
roots and remote invalidation as separate requirements.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 451145 word bounds and both changed rendered pages are reviewed.
docs: Specify ownership of the supervisor baseline
All checks were successful
CI / markdown (pull_request) Successful in 5s
CI / markdown (push) Successful in 5s
CI / manual (pull_request) Successful in 4m36s
CI / manual (push) Successful in 4m38s
18b8b7160f
Document pre-root capture, independently owned table allocations, borrowed
boot/AP tables and leaf backing, cache policy and complete unpublished
rollback. Keep per-VSpace population, activation, invalidation and live-root
retirement distinct from retaining the supervisor template.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 451287 word bounds and the changed rendered page are reviewed.
docs: Specify huge-leaf address and cache preservation
All checks were successful
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 20s
CI / manual (pull_request) Successful in 7m14s
CI / manual (push) Successful in 7m14s
587a280f59
Document level-aware physical address decoding, PAT conversion for small
leaves, preserved leaf permissions and independent WriteBack table storage.
Describe private native probe custody and exact restoration before backing
or temporary table release. Keep private-root activation separate.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 451388 word bounds and the changed rendered page are reviewed.
docs: Specify Kernel-owned first-start register custody
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / manual (push) Successful in 4m54s
CI / manual (pull_request) Successful in 4m59s
57bdb2811e
Document separately owned initial registers, complete startup stack admission,
registered bootstrap write custody, rollback and exact terminal disposal.
Preserve the user return slot and distinguish it from privileged resume state.
Remove the obsolete description placing the register prefix on the user stack.

All 45 tests and the complete 2433-page manual pass without final warnings.
All 451642 word bounds and four changed rendered pages are reviewed.
Independent root activation and complete guest rebuilding remain open.
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / manual (push) Successful in 4m54s
CI / manual (pull_request) Successful in 4m59s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.