WIP: Bind shell workspace and cleanup frame evidence #3

Draft
erikinkinen wants to merge 30 commits from feature/posix-compat into main
Owner

Summary and rationale

Move shell ordinary and emergency transport into separate authenticated workspace slices, removing the global accessor and automatic cleanup buffer. Check actual packaged workspace ownership independently from source lifetimes and stack bounds.

Bind frame evidence to original ELF ranges and one explicitly selected native dependency closure. Follow protected relative and symbolic slots through object-qualified call graphs, preserving grounded return/register contracts and every unresolved source/frame obligation. Derive saved-register equality, private write bounds and caller-specific argument/write contracts from original instruction bytes. Profile and remove redundant interpretation work without changing original budgets or acceptance gates.

Tracking and scope

Workspace and audit design: #2; full frame proof: #4; frame-pointer correction: #8; shell scope: #1. Producer: erix/integration#12. Manual: erix/docs#4. Signed head e7ba974e96ee77a41c6a861150da843d4c84c7d6 on feature/posix-compat. Required source/frame and product gates remain unfinished.

Architecture, authority and failure behavior

Descriptor state exclusively lends and erases a complete cleanup slice; ordinary I/O owns a separate slice. Short/dirty storage fails before metadata effects. Retirement, rollback and uncertain-cleanup behavior remain enforced. The version-22 producer/consumer graph still requires coherent adoption.

Explicit paths and hashes select the tool, images and exact runtime closure. Needed names and source paths grant no host lookup. Native pairing preserves allocated ownership, program contracts and code; stripped counterparts never waive original function identity. Ordered strong/weak providers and exact relocation expressions establish conditional targets, while complete RELRO coverage and one unique write protect each admitted slot. Successful checked native linking and unchanged disjoint mappings remain premises; actual load bases and source membership are unobserved.

The graph keeps function object identities separate from local instruction offsets. Foreign numerical aliases cannot acquire local control flow or root roles. Protected register loads retain all premises; conflicting joins, partial writes and unproved boundaries discard facts. Preservation and no-return facts require complete bodies and earlier grounded dependencies; recursive premises supply no initial authority. Exact saved values can establish restoration through owned live slots. Unknown aliasing, partial writes, conflicting joins and slot reuse erase those facts. Caller slots survive through separately grounded private write bounds or exact writes under explicit live caller bindings. Scoped masks never become unconditional guarantees. Return-address gaps, alias invalidation and checked coordinate translation remain required; equality never creates a pointer or call target. Candidate scheduling defers incompatible abstract fact kinds and cannot admit a proof. Calls clear live conditions, and frame-pointer evidence needs its own preservation proof.

All captured decodes share original input/output/time budgets and owned child cleanup. Late failure or exhaustion invalidates the invocation. Native schema 3 reports one composed graph; standalone schema 2 is preserved. Existing stack limits and source/direct-path gates remain enforced; partial static evidence cannot establish memory safety or complete runtime acceptance.

Validation evidence

Native caller diagnostic producer — 19 September 2026: Signed 183bcb9e9b4e37ecfab65bd0baa0cde53d02c728 adds an explicit diagnostic on the existing authenticated Launchd route, sending no capabilities. It exercises eleven calls covering reservation, full-width generation refusal, missing-scope refusal, retirement and record reuse. Five new adversarial controls cover malformed outcomes, every lost call and independent unexpected-receipt cleanup. Eight strict development/release Rust configurations pass 966 tests each, with eight native builds, strict host/native Clippy, formatting and private rustdoc without warnings. Seven authority precondition/cleanup helpers moved to a focused module with unchanged bodies; all authored code remains below 1,000 lines. All 355 checker controls pass. Six native frame observations validate the 4,300,800-byte workspace but retain incomplete frame proof: runtime/all/diagnostic modes have 97/62/99 unresolved observations under both policies. No complete frame or diagnostic VM acceptance is claimed. Matching Integration scenario validation and original CI are in progress; successful preparation, mediator startup/configuration/seal/client I/O, native toolchain rebuilding and both full OS builds remain required.

Original dependency CI outcome — 18 September 2026: Signed f7c1cd200ef13902b1025208ced6ddf659f10eb1 has complete original logs for CI 264 and CI 263 (315,374 bytes), with zero warnings. Both original runs fail the required complete frame-proof gate after 961 Rust units and 355 checker controls pass. All four CI workspace mappings complete. Runtime analysis retains 256 reached functions and 101 unresolved observations; all-feature analysis retains 236 and 64. Direct early-drop and ordinary source membership remain incomplete. These CI observations do not replace the separately retained empty local reports. No workflow was rerun and no gate was relaxed. Complete realm execution and both full guest builds remain required.

Coherent realm dependency prerequisites — 18 September 2026: Signed f7c1cd200ef13902b1025208ced6ddf659f10eb1 selects original shared dependency revisions without changing direct Rust implementation bytes. Six strict development/release Rust configurations pass 961 tests each, with six native builds, fatal linker warnings, strict host/native Clippy, formatting and private rustdoc. All 355 frame-checker controls pass. The initial optimized compiler no-output timeout is retained; the interrupted and remaining compiler commands completed within the separately bounded production compiler budget. Four actual local frame-checker invocations retain exit 1 and empty reports under their unchanged limits. Those runs provide no workspace or complete frame acceptance. Original push/PR CI is under observation. Complete source/effect/frame admission, source-bound consumer VMs, complete realm operation and both full guest builds remain required.

Caller-bound stack preservation — 17 September 2026: signed Exsh e7ba974e96ee77a41c6a861150da843d4c84c7d6 binds formal GP arguments to independently proved live caller stack intervals. Exact callee write spans preserve return-address gaps and invalidate every overlapping save. Scoped masks never enter the unconditional function index; loaded words, unknown contents, released storage and recursive assumptions supply no binding. Byte-checked SETcc writes exactly one unknown byte.

All 355 checker tests and 23 separately executed module suites pass. Six strict Rust configurations pass 961 tests each, host/native Clippy, private rustdoc and six warning-free native builds. Formatting, templates and Markdown pass. Original runtime/all/native replays retain 97/60/97 unresolved observations and actual exit 1. The native graph reaches 275 functions; the startup iterator now has caller-bound preservation for its exact live buffers. Complete source/frame and runtime acceptance remain open.

Profiling exposed repeated failed argument specializations. Mandatory opaque-prefix refusals, conservative GP demand and rejection-only control candidates avoid unnecessary interpretations without changing the original 60-second limit. Candidate records cannot become proofs, and incompatible fact kinds defer to actual interpretation: losing pointer identity can enable numeric refinement. Positive and negative controls compare filtered and eager behavior. Each CFG site has at most one pending visit and later changes still enqueue it without an iteration cap; every native proof decision agrees with the prior queue.

The final ordinary native replay takes 39.80 seconds. Complete tracing still exhausted the original deadline; failures and empty reports are retained. A separately identified selective profile measures only caller-context analysis: the complete invocation takes 56.59 seconds, with 26.92 profiled seconds in that scope. Instrumentation preserves the complete proof result. Different profiling scopes are not timing comparisons, and no guest performance claim is made. The replay selects 367 instances, evaluates 587 bodies, proves 190 and defers 51 candidate bodies for incompatible domains.

Signed Docs fc3ee44748c20a3aa6f55bd85ac1913c707e5d4e specifies these contracts. All 45 documentation tests pass. The complete 2,385-page manual has 437,275 in-bounds word boxes, zero final warnings and visual review of the changed pages. All 3,721 inventoried source/configuration files are below 1,000 lines. All new/modified definitions are documented; 87 unchanged older test definitions remain in the audit. Runtime Rust, dependencies, linker and workflow inputs are unchanged. Original Exsh CI 261/262 passes unit/strict/workspace stages and retains the required full-frame failure; Docs CI 923/924 passes. Both cohorts are fully classified. Complete semantic authority acceptance, coherent runtime adoption and both full builds inside EriX remain required.

Caller-bound checkpoint CI classification — 17 September 2026: Exsh 261/262 at e7ba974e96ee77a41c6a861150da843d4c84c7d6 passes 961 Rust tests, the combined 355-test checker suite, strict preceding stages and four workspace domains per run. Combined discovery checks isolated module imports; the 23 separate module-suite executions are additional local evidence. The required full-frame gate fails with 101/101/64/64 unresolved observations on its four original CI artifact selections. Four complete logs total 315,210 bytes with zero warnings. These CI selections remain distinct from the retained seven-object native replay.

Docs 923/924 at fc3ee44748c20a3aa6f55bd85ac1913c707e5d4e passes 45 tests and the complete 2,385-page manual. Four complete logs total 764,350 bytes; reference-resolution passes have 35/1/0 warnings, with zero final warnings or layout overflow. Both automatic cohorts are fully classified without workflow restarts or threshold changes. Existing Integration layout, quota and FAT32 regressions remain open. Full native source/frame acceptance, coherent runtime adoption, the semantic authority audit and both full builds inside EriX remain required.

Review checklist

  • Preserve explicit input authority, object identities and incomplete acceptance boundaries.
  • Update component contracts and the technical manual.
  • Retain original artifact identities, adversarial controls and strict local checks.
  • Classify matching automatic Exsh and Docs CI with complete terminal logs.
  • Complete dependent runtime, source/frame and both self-hosting builds before readiness.

Native diagnostic observation — 19 September 2026: the first actual caller VM fails before its required success marker. Exsh exits 0xe5, Rootd exits 0xdc and the unchanged progress watchdog stops QEMU. Integration issue 66 records exact reproduction and retained appliance/log identities. All 169 Integration helpers and four strict Rust configurations pass; this does not establish native execution. Request/error telemetry through the existing stdout route is under validation. No cause, weakened gate or completion credit is inferred.

Original Exsh CI 265 and 266, at 183bcb9e9b4e37ecfab65bd0baa0cde53d02c728, fail the complete frame gate. All 966 Rust tests and 355 checker controls pass. Four actual workspace mappings are complete; the runtime/all analyses retain 101/67 unresolved observations. All four terminal logs are complete and hashed, totaling 316,648 bytes without warnings. The different local counts remain separately retained. No workflow was rerun or cancelled.

Changed diagnostic observation — 19 September 2026: signed Exsh e81f0cf0aed0b5a3360d2ee2dac6d3f656c90d3f passes all eight strict 967-test configurations, native builds, fmt, host/native Clippy and private rustdoc without warnings. Six native frame observations remain incomplete (97/63/100 runtime/all/diagnostic observations). Its bounded failure output uses existing stdout and identifies request 1, BEGIN_REALM, as InvalidReply. The actual telemetry-only VM retains original Launchd 5837873167c5e6ed99045af7052004affb5c28ff, the original authority policy, 120-second hard limit and 45-second progress watchdog. It still fails and all 106 artifacts are retained; serial SHA256 520999cc511e72ccb0bcb138c107f52ff629e2e3b21aa4d116ff4ad9aa402000 (55,858 bytes). No unchanged retry or successful runtime acceptance is claimed.

Source review shows that shells receive private script senders, while the initial realm dispatch recognizes these operations only on the public receiver. A Launchd change is under strict validation to enter the shared realm handler after the existing active-envelope and native-owner proof, preserving original held-reply custody and adding no sender. A matching fixed-server VM is required to establish the correction. Integration issue 66 retains both failures. Original Exsh CI 267 and 268 are under observation.

Signed cleanup refinement — 19 September 2026: 9c0f7ab851d527dd9dd10161d6a98e1fdc14598e makes no stdout IPC after uncertain capability disposal. Reportable failures retain their full correlation and status fields through the existing output route. All eight strict configurations pass 968 tests each, with eight native builds, fmt, strict host/native Clippy, private rustdoc and Markdown without warnings. Six native frame observations retain complete workspace mapping and incomplete runtime/all/diagnostic proof (97/62/99 unresolved observations). Original CI 269 and 270 are running. The previous telemetry CI 267/268 finished with the full frame gate failed: all 967 Rust tests and 355 checker controls pass, four complete logs total 317,004 bytes and contain no warnings; runtime/all proof has 101/68 unresolved observations. No workflow was rerun. A fresh matching VM with the signed Launchd correction remains required for Integration issue 66.

Corrected native caller VM — 19 September 2026: signed Integration 9139c6c5fa38c139e92520f6d410626b4cf1e4aa selects Launchd ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6, Exsh 9c0f7ab851d527dd9dd10161d6a98e1fdc14598e and Docs ce8a1538ab2220f1b346e1a051265f58f83f47fc. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one ERIX_EXSH:REALM_ADMISSION:VERIFIED precedes ERIX_ROOTD:INITIAL_EXSH:EXITED_OK. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present.

All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7; the post-VM writable disk has SHA256 8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in issue 66.

The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original Integration CI 1675 and 1676 are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item.
Original Exsh CI 269/270 remains failed at the complete frame gate: 968 Rust tests and 355 checker controls pass, all four logs are complete (317,264 bytes) without warnings, and runtime/all proof retains 101/67 unresolved observations. Native diagnostic success does not waive that gate.

Native guarded preparation — 19 September 2026: signed Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c selects signed Exsh ffe50612889dd58a45a40d04593a4aa3a3ffa512 for the separate appliance-disk-image-realm-preparation-positive scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects bin/true inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.

Exactly one admission marker and one ERIX_EXSH:REALM_PREPARATION:VERIFIED precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is 7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff (55,776 bytes); post-VM writable disk SHA256 is 3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.

All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.

Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.

Original guarded-preparation CI — 19 September 2026: Exsh run 271 and 272, for signed ffe50612889dd58a45a40d04593a4aa3a3ffa512, both fail the required complete frame proof. All 976 Rust tests and 355 checker controls pass. Four complete hashed logs total 320,166 bytes without warnings; Markdown passes. Each original workflow reports four complete workspace mappings and incomplete runtime/all frame observations (101/68 unresolved). These actual CI observations are distinct from the local eight-configuration frame observations. The passing guarded-stage VM does not waive this failure. No workflow was rerun or cancelled to obtain acceptance.

Manual and dependency validation — 20 September 2026:

Thirty-one additional downstream consumers now have signed dependency-alignment checkpoints, each with four strict unit configurations, four native builds, host/native Clippy, formatting and private rustdoc passing without warnings. All 62 original CI runs pass. Their owning feature issues and WIP PRs retain exact revisions and log evidence. Catalog regression 68 remains open until the remaining Exsh selection and complete original catalog are validated together. Individual repository success is not full service-image acceptance.

Exsh's default development tests pass 976 units. Aggregate release-test compilation and a subsequent explicitly separated library compilation each reached the local unchanged 120-second silence limit before tests ran; both failures remain retained. No release-test success is inferred, no compiler setting or deadline was relaxed, and independent configurations are being collected without rerunning failed commands unchanged. The complete source/effect/frame gate also remains open.

Original Integration 1693/1694 also fails with 127 manifest/catalog mismatches each, before full VM execution. Six complete logs total 604,756 bytes, with no warning candidates. Together with 1683–1692 this is twelve retained original failing runs. Earlier full-VM filesystem timeouts remain separately tracked in ext-family issue 20 and FAT32 issue 58.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open.

Complete original catalog checkpoint — 20 September 2026:

Integration f9681efc30f1c48989def7f0e7db939974a30e27 is signed and pushed in WIP PR 12. Both complete catalogs now pass exact dependency equality against 73/70 clean original selected checkouts and 72/71 manifests; all 143 selected signatures verify. The original Integration library pin is retained independently of the catalog commit, avoiding a circular source reference. Twenty dependency-policy and 46 immutable-source tests, both native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Corrected-source original CI 1695/1696 is running; bug 68 remains open pending that observation and full consumer acceptance remains separate.

The executed inputs for both first-attempt native VM passes remain exact: 27 new ordinary CPL3 grant-right controls, every earlier lifetime/owned-invocation assertion, original 60-second bounds, zero build warnings and empty QEMU stderr. Both packaged kernels match retained original artifacts and all fifteen original source signatures verify. The final post-VM changes only select the full catalogs and reconcile documentation.

All 31 further fully validated consumer checkpoints pass four strict unit/native configurations and all 62 original CI runs; 124 complete logs total 3,041,213 bytes with no warning candidates. Their owning feature issues and WIP PRs preserve exact source and CI evidence. The full manual and regenerated IPC references are published in Docs WIP PR 4; its 45 tests, 2,429 pages, 448,913 word bounds and eleven changed-page reviews pass, as do original Docs CI 991/992 with zero final warnings.

Exsh dbc958bcdaa557a461e9308a31d23d3b8c189296 in WIP PR 3 is explicitly an incomplete-validation dependency checkpoint. Both development configurations pass 976 units, four native builds and strict Clippy/docs configurations pass, and all 355 checker tests pass. Three local release-unit compilation attempts reached the unchanged 120-second silence bound before tests ran. Four local frame checks return 1 with complete workspace mapping and 97/63 unresolved routes. Original CI 273/274 likewise passes 976 units and 355 checker tests, then fails the full frame/source gate with 101/68 unresolved observations. Four complete CI logs total 319,871 bytes with zero warning candidates. These local and CI artifacts are distinct; no frame or release-unit acceptance, relaxed deadline or unchanged retry is claimed.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. The full in-EriX builds and native external Rust/LLVM/runtime rebuild remain unproven. Full consumer lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate and profiler attribution remain required; no canonical leaf closes at this checkpoint.

Original terminal-accounting graph validation — 21 September 2026:

Signed 0d5d5ad9aff082ca75ec79dbc9c29d73f799d8ed adopts the original shared terminal-observation, exact-acknowledgement and final-CPU dependencies. Both development configurations pass 976 Rust tests; all four host/native Clippy, warning-denied host/native build, applicable doctest and private-rustdoc selections pass. All 355 checker controls pass. The shell implementation and release optimization/LTO policy are unchanged.

The new graph independently retains two release unit-test compilation failures: cargo test --locked --offline --release --all-targets stops at 126.117857 seconds and cargo test --locked --offline --all-features --release --all-targets at 120.024146 seconds. Both reach the existing 120-second silence bound within the 600-second hard bound; the child exits on signal 15, the owner reports status 124, and cleanup succeeds. No release unit test executes. These are new original-graph observations in compiler regression 9, with all prior failures retained. The cause needs an actual compiler profile; no optimization, LTO or deadline setting was relaxed.

Actual runtime and all-feature PIC artifacts are checked in both deployment profiles using the maintained frame configuration. All four reports return incomplete proof (exit 1), with 97 unresolved routes for runtime and 63 for all features. Workspace mapping passes separately. The original ELF and packaged artifact digests, selected tool/helper identities and failed reports remain retained. Frame regression 4 stays open. Original CI 275/276 is being observed without restart.

The WIP PR awards no complete runtime or self-hosting acceptance. Actual service CPU/profiler VMs, complete authority/source/effect/frame proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required in Phase 6 completion.

Original terminal-graph CI classification — 21 September 2026:

Signed 0d5d5ad9aff082ca75ec79dbc9c29d73f799d8ed reaches actual analysis in both original CI 275/276. Each passes 976 unit tests and 355 checker controls before the required frame gate fails. Each run retains four incomplete reports: 101 unresolved runtime observations in both profiles and 68 all-feature observations in both profiles. All four workspace mappings pass separately. These CI artifact observations differ from local 97/63 results and are not interchangeable proof.

All four terminal logs are complete and hash-verified (319,902 bytes), with zero warnings. The disassembler intake correction reaches the real proof boundary; tool-selection issue 5 is resolved. Complete frame issue 4 and local release compiler issue 9 remain open. No workflow restart, bound change or conversion of incomplete evidence to a pass occurred.

## Summary and rationale Move shell ordinary and emergency transport into separate authenticated workspace slices, removing the global accessor and automatic cleanup buffer. Check actual packaged workspace ownership independently from source lifetimes and stack bounds. Bind frame evidence to original ELF ranges and one explicitly selected native dependency closure. Follow protected relative and symbolic slots through object-qualified call graphs, preserving grounded return/register contracts and every unresolved source/frame obligation. Derive saved-register equality, private write bounds and caller-specific argument/write contracts from original instruction bytes. Profile and remove redundant interpretation work without changing original budgets or acceptance gates. ## Tracking and scope Workspace and audit design: #2; full frame proof: #4; frame-pointer correction: #8; shell scope: #1. Producer: https://git.erikinkinen.fi/erix/integration/pulls/12. Manual: https://git.erikinkinen.fi/erix/docs/pulls/4. Signed head `e7ba974e96ee77a41c6a861150da843d4c84c7d6` on `feature/posix-compat`. Required source/frame and product gates remain unfinished. ## Architecture, authority and failure behavior Descriptor state exclusively lends and erases a complete cleanup slice; ordinary I/O owns a separate slice. Short/dirty storage fails before metadata effects. Retirement, rollback and uncertain-cleanup behavior remain enforced. The version-22 producer/consumer graph still requires coherent adoption. Explicit paths and hashes select the tool, images and exact runtime closure. Needed names and source paths grant no host lookup. Native pairing preserves allocated ownership, program contracts and code; stripped counterparts never waive original function identity. Ordered strong/weak providers and exact relocation expressions establish conditional targets, while complete RELRO coverage and one unique write protect each admitted slot. Successful checked native linking and unchanged disjoint mappings remain premises; actual load bases and source membership are unobserved. The graph keeps function object identities separate from local instruction offsets. Foreign numerical aliases cannot acquire local control flow or root roles. Protected register loads retain all premises; conflicting joins, partial writes and unproved boundaries discard facts. Preservation and no-return facts require complete bodies and earlier grounded dependencies; recursive premises supply no initial authority. Exact saved values can establish restoration through owned live slots. Unknown aliasing, partial writes, conflicting joins and slot reuse erase those facts. Caller slots survive through separately grounded private write bounds or exact writes under explicit live caller bindings. Scoped masks never become unconditional guarantees. Return-address gaps, alias invalidation and checked coordinate translation remain required; equality never creates a pointer or call target. Candidate scheduling defers incompatible abstract fact kinds and cannot admit a proof. Calls clear live conditions, and frame-pointer evidence needs its own preservation proof. All captured decodes share original input/output/time budgets and owned child cleanup. Late failure or exhaustion invalidates the invocation. Native schema 3 reports one composed graph; standalone schema 2 is preserved. Existing stack limits and source/direct-path gates remain enforced; partial static evidence cannot establish memory safety or complete runtime acceptance. ## Validation evidence Native caller diagnostic producer — 19 September 2026: Signed `183bcb9e9b4e37ecfab65bd0baa0cde53d02c728` adds an explicit diagnostic on the existing authenticated Launchd route, sending no capabilities. It exercises eleven calls covering reservation, full-width generation refusal, missing-scope refusal, retirement and record reuse. Five new adversarial controls cover malformed outcomes, every lost call and independent unexpected-receipt cleanup. Eight strict development/release Rust configurations pass 966 tests each, with eight native builds, strict host/native Clippy, formatting and private rustdoc without warnings. Seven authority precondition/cleanup helpers moved to a focused module with unchanged bodies; all authored code remains below 1,000 lines. All 355 checker controls pass. Six native frame observations validate the 4,300,800-byte workspace but retain incomplete frame proof: runtime/all/diagnostic modes have 97/62/99 unresolved observations under both policies. No complete frame or diagnostic VM acceptance is claimed. Matching Integration scenario validation and original CI are in progress; successful preparation, mediator startup/configuration/seal/client I/O, native toolchain rebuilding and both full OS builds remain required. Original dependency CI outcome — 18 September 2026: Signed `f7c1cd200ef13902b1025208ced6ddf659f10eb1` has complete original logs for [CI 264](https://git.erikinkinen.fi/erix/exsh/actions/runs/264) and [CI 263](https://git.erikinkinen.fi/erix/exsh/actions/runs/263) (315,374 bytes), with zero warnings. Both original runs fail the required complete frame-proof gate after 961 Rust units and 355 checker controls pass. All four CI workspace mappings complete. Runtime analysis retains 256 reached functions and 101 unresolved observations; all-feature analysis retains 236 and 64. Direct early-drop and ordinary source membership remain incomplete. These CI observations do not replace the separately retained empty local reports. No workflow was rerun and no gate was relaxed. Complete realm execution and both full guest builds remain required. Coherent realm dependency prerequisites — 18 September 2026: Signed `f7c1cd200ef13902b1025208ced6ddf659f10eb1` selects original shared dependency revisions without changing direct Rust implementation bytes. Six strict development/release Rust configurations pass 961 tests each, with six native builds, fatal linker warnings, strict host/native Clippy, formatting and private rustdoc. All 355 frame-checker controls pass. The initial optimized compiler no-output timeout is retained; the interrupted and remaining compiler commands completed within the separately bounded production compiler budget. Four actual local frame-checker invocations retain exit 1 and empty reports under their unchanged limits. Those runs provide no workspace or complete frame acceptance. Original push/PR CI is under observation. Complete source/effect/frame admission, source-bound consumer VMs, complete realm operation and both full guest builds remain required. Caller-bound stack preservation — 17 September 2026: signed Exsh `e7ba974e96ee77a41c6a861150da843d4c84c7d6` binds formal GP arguments to independently proved live caller stack intervals. Exact callee write spans preserve return-address gaps and invalidate every overlapping save. Scoped masks never enter the unconditional function index; loaded words, unknown contents, released storage and recursive assumptions supply no binding. Byte-checked SETcc writes exactly one unknown byte. All 355 checker tests and 23 separately executed module suites pass. Six strict Rust configurations pass 961 tests each, host/native Clippy, private rustdoc and six warning-free native builds. Formatting, templates and Markdown pass. Original runtime/all/native replays retain 97/60/97 unresolved observations and actual exit 1. The native graph reaches 275 functions; the startup iterator now has caller-bound preservation for its exact live buffers. Complete source/frame and runtime acceptance remain open. Profiling exposed repeated failed argument specializations. Mandatory opaque-prefix refusals, conservative GP demand and rejection-only control candidates avoid unnecessary interpretations without changing the original 60-second limit. Candidate records cannot become proofs, and incompatible fact kinds defer to actual interpretation: losing pointer identity can enable numeric refinement. Positive and negative controls compare filtered and eager behavior. Each CFG site has at most one pending visit and later changes still enqueue it without an iteration cap; every native proof decision agrees with the prior queue. The final ordinary native replay takes 39.80 seconds. Complete tracing still exhausted the original deadline; failures and empty reports are retained. A separately identified selective profile measures only caller-context analysis: the complete invocation takes 56.59 seconds, with 26.92 profiled seconds in that scope. Instrumentation preserves the complete proof result. Different profiling scopes are not timing comparisons, and no guest performance claim is made. The replay selects 367 instances, evaluates 587 bodies, proves 190 and defers 51 candidate bodies for incompatible domains. Signed Docs `fc3ee44748c20a3aa6f55bd85ac1913c707e5d4e` specifies these contracts. All 45 documentation tests pass. The complete 2,385-page manual has 437,275 in-bounds word boxes, zero final warnings and visual review of the changed pages. All 3,721 inventoried source/configuration files are below 1,000 lines. All new/modified definitions are documented; 87 unchanged older test definitions remain in the audit. Runtime Rust, dependencies, linker and workflow inputs are unchanged. Original Exsh CI 261/262 passes unit/strict/workspace stages and retains the required full-frame failure; Docs CI 923/924 passes. Both cohorts are fully classified. Complete semantic authority acceptance, coherent runtime adoption and both full builds inside EriX remain required. Caller-bound checkpoint CI classification — 17 September 2026: Exsh 261/262 at `e7ba974e96ee77a41c6a861150da843d4c84c7d6` passes 961 Rust tests, the combined 355-test checker suite, strict preceding stages and four workspace domains per run. Combined discovery checks isolated module imports; the 23 separate module-suite executions are additional local evidence. The required full-frame gate fails with 101/101/64/64 unresolved observations on its four original CI artifact selections. Four complete logs total 315,210 bytes with zero warnings. These CI selections remain distinct from the retained seven-object native replay. Docs 923/924 at `fc3ee44748c20a3aa6f55bd85ac1913c707e5d4e` passes 45 tests and the complete 2,385-page manual. Four complete logs total 764,350 bytes; reference-resolution passes have 35/1/0 warnings, with zero final warnings or layout overflow. Both automatic cohorts are fully classified without workflow restarts or threshold changes. Existing Integration layout, quota and FAT32 regressions remain open. Full native source/frame acceptance, coherent runtime adoption, the semantic authority audit and both full builds inside EriX remain required. ## Review checklist - [x] Preserve explicit input authority, object identities and incomplete acceptance boundaries. - [x] Update component contracts and the technical manual. - [x] Retain original artifact identities, adversarial controls and strict local checks. - [x] Classify matching automatic Exsh and Docs CI with complete terminal logs. - [ ] Complete dependent runtime, source/frame and both self-hosting builds before readiness. Native diagnostic observation — 19 September 2026: the first actual caller VM fails before its required success marker. Exsh exits 0xe5, Rootd exits 0xdc and the unchanged progress watchdog stops QEMU. [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) records exact reproduction and retained appliance/log identities. All 169 Integration helpers and four strict Rust configurations pass; this does not establish native execution. Request/error telemetry through the existing stdout route is under validation. No cause, weakened gate or completion credit is inferred. Original [Exsh CI 265](https://git.erikinkinen.fi/erix/exsh/actions/runs/265) and [266](https://git.erikinkinen.fi/erix/exsh/actions/runs/266), at `183bcb9e9b4e37ecfab65bd0baa0cde53d02c728`, fail the complete frame gate. All 966 Rust tests and 355 checker controls pass. Four actual workspace mappings are complete; the runtime/all analyses retain 101/67 unresolved observations. All four terminal logs are complete and hashed, totaling 316,648 bytes without warnings. The different local counts remain separately retained. No workflow was rerun or cancelled. Changed diagnostic observation — 19 September 2026: signed Exsh `e81f0cf0aed0b5a3360d2ee2dac6d3f656c90d3f` passes all eight strict 967-test configurations, native builds, fmt, host/native Clippy and private rustdoc without warnings. Six native frame observations remain incomplete (97/63/100 runtime/all/diagnostic observations). Its bounded failure output uses existing stdout and identifies request 1, BEGIN_REALM, as InvalidReply. The actual telemetry-only VM retains original Launchd `5837873167c5e6ed99045af7052004affb5c28ff`, the original authority policy, 120-second hard limit and 45-second progress watchdog. It still fails and all 106 artifacts are retained; serial SHA256 `520999cc511e72ccb0bcb138c107f52ff629e2e3b21aa4d116ff4ad9aa402000` (55,858 bytes). No unchanged retry or successful runtime acceptance is claimed. Source review shows that shells receive private script senders, while the initial realm dispatch recognizes these operations only on the public receiver. A Launchd change is under strict validation to enter the shared realm handler after the existing active-envelope and native-owner proof, preserving original held-reply custody and adding no sender. A matching fixed-server VM is required to establish the correction. [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) retains both failures. Original [Exsh CI 267](https://git.erikinkinen.fi/erix/exsh/actions/runs/267) and [268](https://git.erikinkinen.fi/erix/exsh/actions/runs/268) are under observation. Signed cleanup refinement — 19 September 2026: `9c0f7ab851d527dd9dd10161d6a98e1fdc14598e` makes no stdout IPC after uncertain capability disposal. Reportable failures retain their full correlation and status fields through the existing output route. All eight strict configurations pass 968 tests each, with eight native builds, fmt, strict host/native Clippy, private rustdoc and Markdown without warnings. Six native frame observations retain complete workspace mapping and incomplete runtime/all/diagnostic proof (97/62/99 unresolved observations). Original [CI 269](https://git.erikinkinen.fi/erix/exsh/actions/runs/269) and [270](https://git.erikinkinen.fi/erix/exsh/actions/runs/270) are running. The previous telemetry CI 267/268 finished with the full frame gate failed: all 967 Rust tests and 355 checker controls pass, four complete logs total 317,004 bytes and contain no warnings; runtime/all proof has 101/68 unresolved observations. No workflow was rerun. A fresh matching VM with the signed [Launchd correction](https://git.erikinkinen.fi/erix/launchd/pulls/2) remains required for [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66). Corrected native caller VM — 19 September 2026: signed Integration `9139c6c5fa38c139e92520f6d410626b4cf1e4aa` selects Launchd `ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6`, Exsh `9c0f7ab851d527dd9dd10161d6a98e1fdc14598e` and Docs `ce8a1538ab2220f1b346e1a051265f58f83f47fc`. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one `ERIX_EXSH:REALM_ADMISSION:VERIFIED` precedes `ERIX_ROOTD:INITIAL_EXSH:EXITED_OK`. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present. All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 `bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7`; the post-VM writable disk has SHA256 `8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938`. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in [issue 66](https://git.erikinkinen.fi/erix/integration/issues/66). The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original [Integration CI 1675](https://git.erikinkinen.fi/erix/integration/actions/runs/1675) and [1676](https://git.erikinkinen.fi/erix/integration/actions/runs/1676) are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item. Original Exsh CI 269/270 remains failed at the complete frame gate: 968 Rust tests and 355 checker controls pass, all four logs are complete (317,264 bytes) without warnings, and runtime/all proof retains 101/67 unresolved observations. Native diagnostic success does not waive that gate. Native guarded preparation — 19 September 2026: signed Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` selects signed Exsh `ffe50612889dd58a45a40d04593a4aa3a3ffa512` for the separate `appliance-disk-image-realm-preparation-positive` scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects `bin/true` inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced. Exactly one admission marker and one `ERIX_EXSH:REALM_PREPARATION:VERIFIED` precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is `7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff` (55,776 bytes); post-VM writable disk SHA256 is `3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499`. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena. All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required. Original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) and [1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) are queued. Original [Exsh CI 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272) are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item. Original guarded-preparation CI — 19 September 2026: [Exsh run 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272), for signed `ffe50612889dd58a45a40d04593a4aa3a3ffa512`, both fail the required complete frame proof. All 976 Rust tests and 355 checker controls pass. Four complete hashed logs total 320,166 bytes without warnings; Markdown passes. Each original workflow reports four complete workspace mappings and incomplete runtime/all frame observations (101/68 unresolved). These actual CI observations are distinct from the local eight-configuration frame observations. The passing guarded-stage VM does not waive this failure. No workflow was rerun or cancelled to obtain acceptance. Manual and dependency validation — 20 September 2026: Thirty-one additional downstream consumers now have signed dependency-alignment checkpoints, each with four strict unit configurations, four native builds, host/native Clippy, formatting and private rustdoc passing without warnings. All 62 original CI runs pass. Their owning feature issues and WIP PRs retain exact revisions and log evidence. [Catalog regression 68](https://git.erikinkinen.fi/erix/integration/issues/68) remains open until the remaining Exsh selection and complete original catalog are validated together. Individual repository success is not full service-image acceptance. Exsh's default development tests pass 976 units. Aggregate release-test compilation and a subsequent explicitly separated library compilation each reached the local unchanged 120-second silence limit before tests ran; both failures remain retained. No release-test success is inferred, no compiler setting or deadline was relaxed, and independent configurations are being collected without rerunning failed commands unchanged. The complete source/effect/frame gate also remains open. Original Integration 1693/1694 also fails with 127 manifest/catalog mismatches each, before full VM execution. Six complete logs total 604,756 bytes, with no warning candidates. Together with 1683–1692 this is twelve retained original failing runs. Earlier full-VM filesystem timeouts remain separately tracked in [ext-family issue 20](https://git.erikinkinen.fi/erix/integration/issues/20) and [FAT32 issue 58](https://git.erikinkinen.fi/erix/integration/issues/58). Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open. Complete original catalog checkpoint — 20 September 2026: Integration [f9681efc30f1c48989def7f0e7db939974a30e27](https://git.erikinkinen.fi/erix/integration/commit/f9681efc30f1c48989def7f0e7db939974a30e27) is signed and pushed in [WIP PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12). Both complete catalogs now pass exact dependency equality against 73/70 clean original selected checkouts and 72/71 manifests; all 143 selected signatures verify. The original Integration library pin is retained independently of the catalog commit, avoiding a circular source reference. Twenty dependency-policy and 46 immutable-source tests, both native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Corrected-source original CI 1695/1696 is running; [bug 68](https://git.erikinkinen.fi/erix/integration/issues/68) remains open pending that observation and full consumer acceptance remains separate. The executed inputs for both first-attempt native VM passes remain exact: 27 new ordinary CPL3 grant-right controls, every earlier lifetime/owned-invocation assertion, original 60-second bounds, zero build warnings and empty QEMU stderr. Both packaged kernels match retained original artifacts and all fifteen original source signatures verify. The final post-VM changes only select the full catalogs and reconcile documentation. All 31 further fully validated consumer checkpoints pass four strict unit/native configurations and all 62 original CI runs; 124 complete logs total 3,041,213 bytes with no warning candidates. Their owning feature issues and WIP PRs preserve exact source and CI evidence. The full manual and regenerated IPC references are published in [Docs WIP PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4); its 45 tests, 2,429 pages, 448,913 word bounds and eleven changed-page reviews pass, as do original Docs CI 991/992 with zero final warnings. Exsh [dbc958bcdaa557a461e9308a31d23d3b8c189296](https://git.erikinkinen.fi/erix/exsh/commit/dbc958bcdaa557a461e9308a31d23d3b8c189296) in [WIP PR 3](https://git.erikinkinen.fi/erix/exsh/pulls/3) is explicitly an incomplete-validation dependency checkpoint. Both development configurations pass 976 units, four native builds and strict Clippy/docs configurations pass, and all 355 checker tests pass. Three local release-unit compilation attempts reached the unchanged 120-second silence bound before tests ran. Four local frame checks return 1 with complete workspace mapping and 97/63 unresolved routes. Original CI 273/274 likewise passes 976 units and 355 checker tests, then fails the full frame/source gate with 101/68 unresolved observations. Four complete CI logs total 319,871 bytes with zero warning candidates. These local and CI artifacts are distinct; no frame or release-unit acceptance, relaxed deadline or unchanged retry is claimed. Canonical acceptance remains 15/460 leaves, 3.48% weighted. The full in-EriX builds and native external Rust/LLVM/runtime rebuild remain unproven. Full consumer lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate and profiler attribution remain required; no canonical leaf closes at this checkpoint. Original terminal-accounting graph validation — 21 September 2026: Signed [0d5d5ad9aff082ca75ec79dbc9c29d73f799d8ed](https://git.erikinkinen.fi/erix/exsh/commit/0d5d5ad9aff082ca75ec79dbc9c29d73f799d8ed) adopts the original shared terminal-observation, exact-acknowledgement and final-CPU dependencies. Both development configurations pass 976 Rust tests; all four host/native Clippy, warning-denied host/native build, applicable doctest and private-rustdoc selections pass. All 355 checker controls pass. The shell implementation and release optimization/LTO policy are unchanged. The new graph independently retains two release unit-test compilation failures: `cargo test --locked --offline --release --all-targets` stops at 126.117857 seconds and `cargo test --locked --offline --all-features --release --all-targets` at 120.024146 seconds. Both reach the existing 120-second silence bound within the 600-second hard bound; the child exits on signal 15, the owner reports status 124, and cleanup succeeds. No release unit test executes. These are new original-graph observations in [compiler regression 9](https://git.erikinkinen.fi/erix/exsh/issues/9), with all prior failures retained. The cause needs an actual compiler profile; no optimization, LTO or deadline setting was relaxed. Actual runtime and all-feature PIC artifacts are checked in both deployment profiles using the maintained frame configuration. All four reports return incomplete proof (exit 1), with 97 unresolved routes for runtime and 63 for all features. Workspace mapping passes separately. The original ELF and packaged artifact digests, selected tool/helper identities and failed reports remain retained. [Frame regression 4](https://git.erikinkinen.fi/erix/exsh/issues/4) stays open. Original CI [275](https://git.erikinkinen.fi/erix/exsh/actions/runs/275)/[276](https://git.erikinkinen.fi/erix/exsh/actions/runs/276) is being observed without restart. The [WIP PR](https://git.erikinkinen.fi/erix/exsh/pulls/3) awards no complete runtime or self-hosting acceptance. Actual service CPU/profiler VMs, complete authority/source/effect/frame proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Original terminal-graph CI classification — 21 September 2026: Signed `0d5d5ad9aff082ca75ec79dbc9c29d73f799d8ed` reaches actual analysis in both original CI [275](https://git.erikinkinen.fi/erix/exsh/actions/runs/275)/[276](https://git.erikinkinen.fi/erix/exsh/actions/runs/276). Each passes 976 unit tests and 355 checker controls before the required frame gate fails. Each run retains four incomplete reports: 101 unresolved runtime observations in both profiles and 68 all-feature observations in both profiles. All four workspace mappings pass separately. These CI artifact observations differ from local 97/63 results and are not interchangeable proof. All four terminal logs are complete and hash-verified (319,902 bytes), with zero warnings. The disassembler intake correction reaches the real proof boundary; [tool-selection issue 5](https://git.erikinkinen.fi/erix/exsh/issues/5) is resolved. [Complete frame issue 4](https://git.erikinkinen.fi/erix/exsh/issues/4) and [local release compiler issue 9](https://git.erikinkinen.fi/erix/exsh/issues/9) remain open. No workflow restart, bound change or conversion of incomplete evidence to a pass occurred.
docs: Enforce documentation in manifest catalog test crate
All checks were successful
CI / markdown (push) Successful in 15s
CI / markdown (pull_request) Successful in 11s
CI / rust (push) Successful in 6m26s
CI / rust (pull_request) Successful in 6m14s
d55ec105cf
Document the integration-test inventory assumptions and enforce missing_docs
in the test crate. Check private-item Rustdoc using the original pinned source
helper, preserving test behavior and capability contracts.

Both default and all-feature host suites pass 957 tests; formatting, strict
Clippy, builds and Rustdoc pass without warnings. The unchanged optimized
frame checker still fails its required-symbol proof on the selected compiler;
retain that failure for correction without weakening its limits. Require
existing CI regressions alongside focused runtime VM coverage.
fix: Bind cleanup frame evidence to emitted ELF ranges
Some checks failed
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 3s
CI / rust (pull_request) Failing after 3m29s
CI / rust (push) Failing after 3m30s
9d1981caac
Replace incidental compiler symbol inventories with checked function ranges, matching decoded bytes and finite call-site stack state. Retain unknown targets and optimized source-domain gaps as incomplete evidence, preserving all existing stack ceilings and the full fallback scratch requirement.

Own disassembler intake, deadlines, cancellation and receipt publication explicitly. Add original byte fixtures and process regressions for overlapping mappings, frame restoration, call and tail accounting, malformed probes, stalled tools and primary failure preservation. Split inspection, state analysis and process ownership into cohesive modules.

Validation: 59 warning-denied host tests, all 11 Markdown files, workflow shell syntax and whitespace checks pass. One final-checker replay per retained optimized runtime/all-feature ELF returns incomplete with no tool warning or timeout. Runtime Rust sources and dependency pins are unchanged; complete source membership and direct-path proof remain required.
erikinkinen changed title from WIP: Enforce documentation in manifest-catalog tests to WIP: Inspect emitted cleanup frames and enforce test documentation 2026-09-12 15:07:27 +02:00
ci: Select the resolved regular cleanup disassembler
Some checks failed
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / rust (push) Failing after 5m40s
CI / rust (pull_request) Failing after 5m40s
7f9552abf3
Resolve the explicitly installed objdump path before passing it to regular-file intake, and fail selection when the resolved target is missing or not executable. Keep symlink rejection, tool byte receipts and all cleanup-proof budgets unchanged. Update the documented command and retain the distinct incomplete-proof status.

Validation: exact workflow shell/YAML checks, resolved-tool intake with symlink-negative and missing-target cases, all 11 Markdown files and whitespace checks pass. The checker and Rust sources are unchanged from the checkpoint whose 59 host tests and 957 Rust tests passed in CI before the recorded tool-intake failure. No complete emitted-frame proof is claimed.
fix: Account for guarded relative dispatch frames
Some checks failed
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / rust (pull_request) Failing after 5m45s
CI / rust (push) Failing after 5m47s
62a4f30ff5
Bind an explicitly guarded jump-table sequence to unique read-only image
bytes, check dynamic relocation ownership and reject table writes or edges
that bypass the guard. Account for every target arm and retain unsupported
flow as incomplete. Admit only the emitted accumulator identity padding.

Add literal positive, malformed-mapping, relocation and stack-join controls,
and bind the new checker module into evidence receipts. All 73 checker tests
pass. Retained default, all-feature and production Rust matrices each pass
957 tests with strict Clippy and eight native builds; their Rust, manifest
and linker inputs are unchanged since that validation. Align dependency
commits to the signed source graph, but keep product adoption pending.

The complete frame gate remains INCOMPLETE. A separate outlined candidate
resolves one targeted evaluator table; original runtime/all graph replays
retain 690/603 unresolved observations. No runtime outlining or VM acceptance
is included. Tracks issue #4.
erikinkinen changed title from WIP: Inspect emitted cleanup frames and enforce test documentation to WIP: Validate emitted cleanup paths and align runtime sources 2026-09-15 20:18:05 +02:00
refactor: Own transport scratch through the shell workspace
Some checks failed
CI / markdown (pull_request) Successful in 10s
CI / markdown (push) Successful in 12s
CI / rust (push) Failing after 6m52s
CI / rust (pull_request) Failing after 6m59s
b12e172e7b
Reserve ordinary and emergency transport slices in the authenticated
workspace and exclusively reborrow cleanup storage through descriptor state.
Reject dirty or insufficient backing before state effects, preserve full
capacity and erase the complete borrow after cleanup. Remove the global
UnsafeCell accessor and automatic 32 KiB fallback array. Group descriptor
backing and split startup tests into cohesive modules.

Coordinate layout version 22 with the Integration producer. All 961 tests
pass in six configurations with strict Clippy, rustdoc, eight native builds
and 73 checker tests. Actual fallback local frames measure 48 bytes, and
private packaging keeps a disjoint 64 KiB stack. The full frame gate remains
incomplete; catalog adoption and matching runtime VMs are still required.
erikinkinen changed title from WIP: Validate emitted cleanup paths and align runtime sources to WIP: Own shell transport workspace and validate cleanup paths 2026-09-15 21:00:30 +02:00
fix: Bind frame evidence to packaged transport mappings
Some checks failed
CI / markdown (push) Successful in 21s
CI / markdown (pull_request) Successful in 21s
CI / rust (pull_request) Failing after 5m58s
CI / rust (push) Failing after 6m0s
f17670c7f0
Replace the obsolete automatic-stack-scratch requirement with a separate
mandatory paired ELF workspace domain. Capture both actual artifacts, preserve
mapped bytes and permissions except the explicit capacity transformation, and
require complete disjoint transport spans and unique arena/stack ownership.
Reject overlapping claims, stale layouts, relocation writes and mismatched code.

Retain both input snapshots on rejected pairs. Remove the redundant prologue
reservation scan and publish report schema 2. Keep the existing frame ceilings
and unresolved source, nested-route and indirect-call obligations intact.

All 90 checker tests and four exact retained runtime/all dev/release mapping
replays pass, along with formatting and Markdown checks. Rust/build inputs are
unchanged from the strict validated workspace checkpoint. Full frame proof
remains incomplete; mapping evidence does not certify borrowing or erasure.
erikinkinen changed title from WIP: Own shell transport workspace and validate cleanup paths to WIP: Bind shell workspace and cleanup frame evidence 2026-09-15 22:17:09 +02:00
ci: Supply packaged shell workspace artifacts to frame checks
Some checks failed
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 12s
CI / rust (pull_request) Failing after 6m16s
CI / rust (push) Failing after 6m17s
453641cd19
Pin the original Integration helper that implements the version-22 transport
workspace and package separate copies of each runtime/all-feature ELF using
both canonical dev/release policies. Keep pristine compiler output intact
and pass each actual pair to its own complete frame checker invocation.

Bound packaging time, refuse existing outputs and stop on producer errors.
Preserve every unresolved source and call-path gate and its nonzero status;
a successful workspace mapping cannot substitute for a full frame proof.

The exact changed workflow block reproduces all four independently validated
packaged byte identities and complete mapping domains. Ninety checker tests,
formatting, Markdown, canonical and dependency policy checks pass. Rust and
linker inputs remain identical to the original strictly validated checkpoint.
test: Prove relative call targets in protected RELRO slots
Some checks failed
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 13s
CI / rust (push) Failing after 6m23s
CI / rust (pull_request) Failing after 6m22s
a26ecffb39
Share exact relative relocation records across frame proof domains and admit
only byte-checked RIP-relative calls or tails through completely protected
slots. Validate unique file/load ownership, final page restrictions and one
non-overlapping relocation naming an exact function entry. Preserve call
depth and tail restoration without using stored pointer words as authority.

All 102 checker tests and six 961-test Rust configurations pass with strict
host/native Clippy, rustdoc, formatting and six native builds. Exact retained
artifact pairs admit 641/591 explored edges and reduce unresolved observations
from 691/604 to 271/232 while preserving workspace mappings. Full frame/source
proof remains incomplete with original budgets; runtime Rust is unchanged.
test: Ground non-returning calls in checked control flow
Some checks failed
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 17s
CI / rust (push) Failing after 6m29s
CI / rust (pull_request) Failing after 6m37s
4bb35938b5
Derive no-ordinary-return facts from complete loop and trap bodies with earlier
proved tail continuations. Revisit affected callers through a dependency queue,
preserve exact callee and stack obligations, and retain each fact's original
body evidence. Unknown targets and unproved recursion cannot supply facts.

All 114 checker tests and six strict 961-test Rust configurations pass, along
with six native builds. Exact retained pairs establish thirteen facts each and
reduce unresolved observations to 181 and 150 with unchanged stack and resource
budgets. Workspace mapping passes; full source and frame proof remains open.
test: Admit exact direction-flag stack effects
Some checks failed
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 9s
CI / rust (pull_request) Failing after 6m2s
CI / rust (push) Failing after 6m12s
05eeb7bc0b
Recognize only operand-free FC and FD instruction bytes as stack-neutral
direction-flag updates. Preserve frame-pointer facts and reject mismatched
bytes, prefixes and operands. Keep string-memory and ABI flag safety separate.

All 117 checker tests and exact original artifact pairs pass scoped checks.
The two memmove frames now admit eight-byte local depth; indirect and source
proof remains incomplete. All Rust, Cargo, linker and build inputs are unchanged
from the six strict 961-test configurations and six native builds. Formatting,
canonical documentation checks and the full physical-file audit pass.
perf: Compile disassembly patterns once per input
Some checks failed
CI / markdown (pull_request) Successful in 20s
CI / markdown (push) Successful in 21s
CI / rust (pull_request) Failing after 6m16s
CI / rust (push) Failing after 6m17s
ffbe846cbc
Reuse the three literal regex objects while preserving instruction byte binding,
annotation handling and every disassembly deadline check. Paired host profiles
remove 571525 regex-cache lookups from the runtime checker and reduce median
profiled time from 5.088 to 4.214 seconds, including observer overhead.

All 117 checker tests and exact runtime/all-feature decision reports agree.
Rust, Cargo, linker and workflow inputs retain their existing strict validation.
Document the measurements; full frame and source-domain proof remain incomplete.
feat: Follow protected function values through register flow
Some checks failed
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 15s
CI / rust (pull_request) Failing after 6m48s
CI / rust (push) Failing after 6m49s
da8b75c906
Propagate exact full-width protected loads and register copies through all
reached predecessors. Preserve every agreeing load origin and discard facts
on alias or implicit writes, calls, syscalls and unknown effects. Revisited
edges replace stale proofs; frame and source gates remain unchanged.

All 138 checker tests and exact artifact replays pass. The retained runtime
and all-feature graphs have 164 and 132 unresolved sites, so full frame
admission remains incomplete. Profiling removes effect parsing for unknown
register states while preserving all decisions. Rust inputs retain their
validated strict matrix; the technical manual is updated separately.
feat: Derive complete local targets from bounded table values
Some checks failed
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 17s
CI / rust (pull_request) Failing after 7m19s
CI / rust (push) Failing after 7m20s
efb542a341
Track separate integer, relative-base, signed-offset and local-target facts.
Exact constants and zero extension establish bounds; every selected table
byte and every local target must pass ownership and boundary checks. Keep
all original premises and reject partial target sets and function-call use.

All 157 checker tests, exact artifact replays and independent byte audits
pass. Two table branches per retained pair are admitted while full source
and frame gates remain incomplete. Profiling removes repeated static regex
compilation without changing decisions or matching operations. Rust inputs
retain the original strict matrix; the updated manual is published separately.
feat: Prove comparison bounds through ordinary table flow
Some checks failed
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 22s
CI / rust (pull_request) Failing after 6m23s
CI / rust (push) Failing after 6m26s
4ed392bcc5
Replace the fixed-register dispatch collapse with byte-bound CMP/Jcc facts,
unsigned interval refinement, explicit flag lifetime and architectural-width
loop widening. Keep complete immutable target sets and all path premises.
Share decoder effects only within one function-body analysis.

Preserve terminal call discovery when a weakened join revisits a site with
an earlier fallthrough issue. Grounded no-return proof still requires the
actual callee; returning and unknown targets keep their obligations.

All 176 checker tests, formatting, canonical checks and original artifact
replays pass their scoped checks. Runtime/all unresolved observations fall
from 164/132 to 158/126; full frame and source-domain gates remain incomplete.
All Rust and build inputs retain their existing strict validation identities.

Related: #6
feat: Refine modular arithmetic guard evidence
Some checks failed
CI / markdown (pull_request) Successful in 16s
CI / markdown (push) Successful in 17s
CI / rust (pull_request) Failing after 5m53s
CI / rust (push) Failing after 5m53s
0cdaa88695
Bind immediate ADD/SUB carry and zero predicates to unchanged modular result
pieces, and derive full-register INC/DEC widths without retaining stale flags.
Full-width comparisons can use the architectural numeric domain while keeping
protected typed identities separate. Encoding contradictions remain flow errors.

Add independent concrete arithmetic and authority-negative controls. All 191
checker tests and exact original artifact audits pass; full source/frame proof
remains incomplete. Cache immutable stack-neutral grammar results per function
with identical paired decisions and reduced measured work. Update the contract.
fix: Initialize checker fixtures before independent imports
Some checks failed
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 19s
CI / rust (pull_request) Failing after 6m49s
CI / rust (push) Failing after 6m50s
12331e26f3
Load the shared literal fixture setup before implementation imports in the
arithmetic and comparison tests. Clean CI discovery must not rely on caller
PYTHONPATH or another module having initialized repository paths first.

Add a regression importing every checker test module in a fresh isolated
interpreter. It reproduces both original failures; the corrected clean workflow
passes all 192 tests. Formatting and Markdown checks pass. Retain original CI
245/246 failures in issue #7; checker/runtime bytes and proof gates are unchanged.
fix: Ground call preservation in original instruction evidence
Some checks failed
CI / markdown (push) Successful in 23s
CI / markdown (pull_request) Successful in 22s
CI / rust (push) Failing after 7m13s
CI / rust (pull_request) Failing after 7m13s
641ac2fc7c
Retain existing register facts only when complete captured bodies and earlier
callee contracts prove no write to the family. Invalidate the separate frame
pointer across unknown calls and syscalls, fixing stale restoration evidence.
Retain finite dependency proofs and remove redundant inventory work identified
by the profiler without changing artifact decisions or authority checks.

All 213 checker controls and six strict 961-test Rust configurations pass with
six native builds and no warnings. Exact original artifact replay reduces
unresolved observations to 107/70; full source/frame and guest-build gates stay
incomplete under the original budgets. Update the component contracts.
feat: Admit native Exsh artifact pairs for frame inspection
Some checks failed
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 12s
CI / rust (pull_request) Failing after 7m42s
CI / rust (push) Failing after 7m43s
d67dcb963f
Bind a retained ordinary-symbol image to its stripped packaged counterpart
through unchanged mapped bytes, allocated owners and program contracts.
Prove the exact native entry jump while retaining the shell frame limit.
Inventory checked symbolic write footprints without inferring local targets.

Add 18 native intake controls and preserve both standalone proof decisions.
Replay the original native pair under unchanged profiling and failure budgets;
full frame and dynamic closure acceptance remain incomplete.
feat: Bind explicit native dependency artifact inputs
Some checks failed
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 14s
CI / rust (pull_request) Failing after 7m24s
CI / rust (push) Failing after 7m25s
9827896d1c
Validate the selected runtime manifest and exact original/packaged library
pairs before exposing dependency evidence. Keep names as data, compare all
runtime owners and metadata, and retain one aggregate capture budget.

Preserve separate workspace, source-membership and symbolic-call gates.
Share section ownership helpers and document the input contract.

Validation: 259 checker controls, 16 isolated modules, six strict 961-test
Rust configurations and native builds, and three profiled original artifact
replays. Full frame and guest self-hosting acceptance remain incomplete.
feat: Bind ordered native symbol providers
Some checks failed
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 3s
CI / rust (pull_request) Failing after 4m23s
CI / rust (push) Failing after 4m24s
469bf1f1b9
Follow the loader's depth-first discovery order and require positional
DT_NEEDED agreement. Index strong and weak exports in the captured closure,
reject duplicate strong definitions, and retain object-qualified function
identities with exact ordinary executable ownership and S/S+A semantics.

Keep load-base arithmetic, protected call slots, cross-object frames and
source membership explicitly incomplete. Library names authorize no reads.
All 276 checker controls and strict Rust configurations pass; original
profiled replay decisions remain unchanged. Document the evidence boundary.
feat: Compose protected native call graphs across selected objects
Some checks failed
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 4s
CI / rust (pull_request) Failing after 4m31s
CI / rust (push) Failing after 4m32s
ac9646c84e
Retain object-qualified function identities through protected relative and
symbolic slots, register facts, grounded return and preservation proofs, and
shared stack-route accounting. Keep local CFG arithmetic separate so foreign
addresses cannot acquire caller control-flow or fallback roles. Share original
resource budgets across every captured decoder input; retain late failures.

Use native report schema 3 for the composed graph and preserve standalone
schema 2. Remove duplicate root-only work identified by profiling, retaining
identical composed decisions. Add authority-negative and late-failure controls;
299 checker tests and six strict Rust configurations pass. The retained native
graph reaches 275 functions with 111 unresolved observations; actual load bases,
source membership and complete frame acceptance remain open.
feat: Prove saved register values with checked stack write bounds
Some checks failed
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / rust (push) Failing after 4m30s
CI / rust (pull_request) Failing after 4m31s
8b6b93a329
Track equality with original incoming registers through byte-checked copies
and live stack slots. Invalidate partial or unknown aliases, retire slots on
deallocation, and require separately grounded callee write bounds before saves
survive calls. Translate bounds with checked arithmetic and retain every earlier
premise. No entry token, ABI convention or stored pointer creates target authority.

Use dependency-first work ordering, relevant fact wakeups and immutable decode
caches after profiling exposed duplicate analysis. Eager-worklist controls retain
the unwritten-register rule when saved-value analysis cannot proceed. Document
21 older test methods and preserve incomplete source, alias and full-frame gates.

All 329 checker tests and six strict Rust configurations pass. Original runtime,
all-feature and native replays complete under unchanged budgets, retaining
107/70/111 unresolved observations. Two earlier profiled timeouts remain explicit
failures; the saved iterator still requires proved pointer-write provenance.
feat: Prove caller-bound stack write contracts
Some checks failed
CI / markdown (pull_request) Successful in 3s
CI / markdown (push) Successful in 3s
CI / rust (push) Failing after 5m55s
CI / rust (pull_request) Failing after 5m55s
e7ba974e96
Bind formal arguments to independently established live caller intervals and
retain scoped preservation separately from unconditional function guarantees.
Translate exact nested writes, invalidate overlapping saves and byte-check
SETcc stores without inventing contents or pointer authority.

Use grounded dependency scheduling, conservative GP demand and rejection-only
control candidates. Defer incompatible abstract fact kinds and avoid duplicate
pending CFG visits. Preserve original source, frame and resource gates.

Validate 355 checker tests, 23 isolated modules, six strict Rust configurations
and six native builds without warnings. Original runtime/all/native replays
retain 97/60/97 unresolved observations and actual full-gate exit 1. Retain full
profile deadlines and a successful selective context profile separately.
build: Adopt coherent realm contract dependencies
Some checks failed
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 11s
CI / rust (pull_request) Failing after 10m8s
CI / rust (push) Failing after 10m11s
f7c1cd200e
Select original signed shared revisions for one coherent runtime-image
dependency graph. Preserve implementation bytes and document the current
validation boundary in the roadmap.

Six strict Rust configurations pass 961 tests each, and all 355 checker
controls pass. The required full source and frame gate remains incomplete:
four local checker invocations retain exit 1 and empty reports under their
unchanged limits. Consumer VMs and full guest builds remain required.
test: Exercise caller-bound realm admission
Some checks failed
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 12s
CI / rust (push) Failing after 10m15s
CI / rust (pull_request) Failing after 10m21s
183bcb9e9b
Use the existing authenticated Launchd route for an opt-in native probe
without transferring capabilities. Verify full-width generation refusal,
missing-scope refusal, retirement and record reuse before ordinary input.
Keep capability preconditions and independent cleanup in one focused module.

Five adversarial controls and eight strict Rust configurations pass 966
tests each, with warning-free native builds and documentation. All 355
checker controls pass. Six native observations retain incomplete frame
proof despite complete workspace mappings; no frame or VM acceptance is
claimed. Matching Integration execution and complete realms remain required.
test: Report the failing native realm diagnostic request
Some checks failed
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 12s
CI / rust (push) Failing after 10m7s
CI / rust (pull_request) Failing after 10m10s
e81f0cf0ae
Preserve the last allocated request correlation and full error fields through
the shell's existing stdout descriptor before the diagnostic fail-stop. Keep
telemetry descriptive and preserve every retirement acknowledgment and success
marker requirement. Separate diagnostic entry/output code from the main shell
loop to keep responsibilities and file size bounded.

The original actual VM exits 0xe5 before its marker; Integration issue #66
retains the failed image and logs. All eight strict 967-test configurations,
native builds, fmt, strict host/native Clippy and private rustdoc pass without
warnings. Six actual frame observations remain incomplete. The changed-input
VM, complete frame proof and full realm lifecycle remain required.
fix: Stop diagnostic output after uncertain cleanup
Some checks failed
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 8s
CI / rust (pull_request) Failing after 6m49s
CI / rust (push) Failing after 6m53s
9c0f7ab851
Return no telemetry report when received capability disposal is uncertain,
so the native diagnostic makes no stdout IPC before its existing terminal
failure path. Keep full-width failure reporting for other diagnostic refusals
and preserve the original success and retirement acknowledgment requirements.
Add a focused negative control for the no-output disposition.

All eight strict 968-test configurations, native builds, fmt, strict host/native
Clippy and private rustdoc pass without warnings. Six native frame observations
remain incomplete. The matching caller VM and complete frame proof remain open.
test: Exercise scoped guarded realm preparation
Some checks failed
CI / markdown (push) Successful in 22s
CI / markdown (pull_request) Successful in 22s
CI / rust (push) Failing after 10m21s
CI / rust (pull_request) Failing after 10m22s
ffe5061288
Add an opt-in diagnostic which copies only the existing cwd SEND scope to
the authenticated reservation, stages bin/true without starting it, and
requires Guarded reads and acknowledged retirement before stale refusal.
Reuse canonical reply disposal and application rejection reporting. Cover
literal operation order, exact transfer rights, correlation, cleanup and
no continuation after failure with independent negative controls.

All ten strict 976-test configurations and ten native builds pass without
warnings, including fmt, host/native Clippy and private rustdoc. Eight actual
frame observations remain incomplete. Matching native preparation, complete
frame proof, configured mediator execution, native toolchain rebuilding and
both full builds inside EriX remain required.
build: Align installer dependencies with open validation gates
Some checks failed
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / rust (pull_request) Failing after 6m24s
CI / rust (push) Failing after 6m25s
dbc958bcda
Select the original shared installer authority revisions for complete catalog
alignment without changing local implementation or capability policy.
Retain and document incomplete validation as a WIP checkpoint.

Both development configurations pass 976 units, all 355 checker tests pass,
and four native builds with strict Clippy and private rustdoc pass warning-free.
Three release-unit compilation attempts hit the unchanged silence bound.
Four frame checks return 1 with 97 or 63 unresolved routes and complete
workspace mapping. These gates and consumer-image acceptance remain open.
build: Adopt terminal dependencies with explicit validation gates
Some checks failed
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 9s
CI / rust (push) Failing after 10m35s
CI / rust (pull_request) Failing after 10m38s
0d5d5ad9af
Select the original shared revisions for repeated terminal observation and
exact acknowledgement while preserving the shell implementation and policy.
Keep incomplete compiler, frame and full service evidence distinct from the
passing prerequisites in the roadmap and Phase 6 completion tracker.

2 host configurations pass 976 tests. Four native builds, strict
host/native Clippy, doctests and private rustdoc pass without warnings; all
355 checker controls pass. Release-unit acceptance is False; complete
frame acceptance is False. Retain original failures and resource bounds.
Some checks failed
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 9s
CI / rust (push) Failing after 10m35s
CI / rust (pull_request) Failing after 10m38s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.