- Rust 99.1%
- Linker Script 0.9%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Merge the selected feature/native-cli history with an explicit two-parent commit so main retains the development lineage and the validated source snapshot. The resulting tree is identical to the selected feature commit; no dependency pins or runtime behavior are changed by this merge. Previous main: |
||
| .github | ||
| src | ||
| .editorconfig | ||
| .gitignore | ||
| .markdownlint-cli2.yaml | ||
| ARCHITECTURE.md | ||
| Cargo.toml | ||
| CODE_OF_CONDUCT.md | ||
| CONTRIBUTING.md | ||
| LICENSE | ||
| linker.ld | ||
| README.md | ||
| ROADMAP.md | ||
| rustfmt.toml | ||
| SECURITY.md | ||
drv-acpi
drv-acpi is the ACPI platform discovery daemon in EriX hardware mediation.
EriX is a clean-room, capability-based microkernel operating system written entirely in Rust.
Technical requirements are tracked in the EriX requirements, conventions, and project documentation.
See:
- docs for design documents, specifications, and development plans.
- Related architecture repositories for kernel, services, libraries, drivers, and integration tooling.
Purpose of This Repository
This repository implements the EriX ACPI platform-discovery driver. Its purpose
is to expose a small typed discovery service under explicit deviced / procd
ownership.
Functionally, it implements the driver startup, runtime, and validation contracts for acpi. The repository keeps the implementation, interface contracts, tests, and documentation for that behavior in one reviewable ownership boundary.
The maintained responsibilities are:
- implement the acpi driver logic behind explicit driver authority
- bind only to the startup-assigned service endpoint, dedicated ACPI RSDP-read
kernel-control endpoint, and
devicedreport endpoint - serve fixed typed driver operations without a service-local transport or work ceiling
- keep discovery diagnostics in typed responses and
devicedreports rather than direct kernel log/debug stamps - keep driver validation and failure behavior documented for integration tests
Clean-Room Policy
EriX follows a strict clean-room philosophy:
- No external source code may be copied.
- No external Rust crates are allowed.
- No code generation tools that embed third-party code.
- All code must be authored within the project.
Violations will result in rejection of the contribution.
License
All EriX repositories are licensed under the ISC License.
Development Model
EriX development is modular, deterministic, reproducible, authority-explicit, security-first, and self-hosting oriented.
This repository follows the project roadmap and the validation rules documented in its own roadmap.
Build
cargo build --release --target x86_64-unknown-none \
--features drv-acpi-integration-smoke,drv-acpi-integration-acpi
Test
cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test --all-targets --all-features
VM/system validation is executed through the integration repository scenarios.
Validation Note
The host/test QUERY_CAP fallback remains cfg-scoped so runtime/release builds
stay warning-free. Startup and runtime receive paths block on their explicitly
delegated endpoint instead of waking on an arbitrary service-local deadline.
Required deviced reports retain an exact-capacity client buffer from
acceptance through the authoritative reply, and server replies retain the full
receive buffer through transient delivery backpressure. The shared IPC
transport envelope is the only server-message capacity boundary; drv-acpi
retains no private transport ceiling or second full-envelope request copy.
Dynamic Boot Artifact Evidence
The image build packages drv-acpi as an ELF64 x86_64 ET_DYN executable with
.erix_dynlink metadata in the signed dynlink-store and mirrors it under
/lib/erix/dynlink with its required shared objects.
Startup remains deviced through procd dynamic driver creation with a role-
derived executable identity; authority remains the dedicated ACPI RSDP-read
endpoint and explicit startup peers. Dynamic packaging and filesystem mirror
records are evidence and launch inputs only; they do not grant filesystem,
loader, object-store, service-discovery, provider-bypass, block-device, or
dynlinkd authority. drv-acpi receives only the documented startup
endpoints, peers, and capabilities for its role.
Governance Principles
drv-acpi governance is scoped to the acpi driver role and its assigned
hardware/provider authority.
The scoped governance rules are:
- It must be started and supervised through
devicedandprocd, not as an independently discovered public service. - It uses only its service endpoint, dedicated ACPI RSDP-read endpoint, and
devicedreport endpoint, all explicitly installed at startup. - It keeps hardware-specific behavior inside the driver while leaving
device-matching policy to
deviced. - It rejects malformed device state and unexpected authority instead of broadening access.
Authority Boundaries
drv-acpidoes not receivenamed, filesystem-provider, or peer-driver authority.- Startup calls, runtime calls, kernel-control replies, and
devicedreplies are authority-free contracts. Complete unwanted receipts are retired before rejection; malformed receipt state or failed retirement terminates the process so kernel teardown revokes remaining aliases. - New hardware access requires explicit manifest, startup, and integration-test coverage.
Contact
Development occurs in EriX organization and discussions happen in issues and design documents.
No decisions are considered valid without documented rationale.
Maintainers can be reached via email: admin@erikinkinen.fi.