[FEATURE] Audit authority, code quality and documentation in integration #11

Open
opened 2026-09-12 07:57:37 +02:00 by erikinkinen · 0 comments
Owner

Problem and motivation

This issue tracks continuous Phase 6 audit closure for integration. Build exact component graphs, assemble images, generate media, run VM regressions and provide authority-free in-guest scenario policy.

An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance.

Proposed behavior and scope

Current inventory: 1 Cargo target (1 lib); manifests: lib/rootd-integration-orchestration/Cargo.toml. Include explicit and automatically discovered targets, supported features and target-specific configurations.

Review host source admission, subprocesses, caches, private outputs, image/signing provenance and VM teardown, plus the nested rootd-integration-orchestration crate. The in-guest library must remain authority-free and absent from production policy.

Tracked-source baseline: scripts/build-dynlink-image-manifest.py has 1029 physical lines and needs thematic refactoring.
Initial target-root inventory found no direct/shared missing_docs policy at lib/rootd-integration-orchestration/src/lib.rs; verify and enforce it with meaningful rustdoc.

Authority, security and reliability

Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption.

Acceptance criteria

  • Record origin, recipient, object, operations, delegation ceiling, lifetime and aliases for each relevant capability or caller-supplied authority-bearing value.
  • Audit ambient discovery/selectors, cwd/PATH/environment, numeric identities, inherited routes and host fallbacks; require explicit authorized intake.
  • Account for residual authority after success, error, cancellation, timeout, restart, failed transfer and teardown, including fork/exec where implemented.
  • Remove unnecessary endpoints, broad rights, duplicate aliases, provider/admin grants and debug routes.
  • Exercise stale generations, replay, pending replies, forged descriptive identity and object/path resolution races at the owned boundary.
  • Prove independent cleanup attempts and caller-specific error precedence; quarantine or terminate when retained authority cannot be accounted for.
  • Review unsafe/FFI/parser/arithmetic/lifetime/lock/publication invariants and add adversarial coverage where practical.
  • Inventory obsolete APIs, wrappers, fallback/dead paths and duplicate validators with their maintained callers.
  • Migrate callers and delete deprecated contracts/shims in a coherent signed revision graph; reject retired input versions where relevant.
  • Classify each size/count/depth/time bound as ABI, hardware, explicit resource policy or accidental limitation.
  • Test beyond removed boundaries and at allocation/ABI limits while preserving exhaustion errors, denial-of-service controls and bounded waits.
  • Keep every tracked authored code/test/script/workflow file below 1000 physical lines through thematic refactoring.
  • Run the deterministic tracked-source size gate, covering executable fixtures/generators and excluding only genuine non-code data or external payloads.
  • Audit production/test feature and symbol separation, including this repository's effect on rootd test orchestration.
  • Supply changes affecting rootd semantic surface to the maintained same-toolchain baseline; record a justified component-specific applicability result.
  • Check bootstrap ownership and development/release authority parity at this repository's producer/consumer boundary.
  • Use maintained integration#3 profiler evidence before optimizing; preserve live access checks, ownership and success criteria.
  • Audit build/CI inputs, secret handling, private outputs, symlink containment, deletion, subprocess bounds, warnings and host dependencies.
  • meaningful public/private inline documentation, crate/target missing_docs enforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate.
  • Validation: Run cargo fmt --all -- --check, strict Clippy, unit/doctests and warning-denied builds/rustdoc for every owned crate/target under default and all valid feature, freestanding/host, SMP and profile combinations; test mutually exclusive combinations separately. Add focused VM regressions for runtime behavior and observe the older catalog and unit tests at the exact published heads.
  • Documentation: update applicable README/ARCHITECTURE/ROADMAP in meta's canonical format and affected technical-manual TeX/API references; keep README evergreen and shared governance byte-identical to meta.
  • Evidence: record exact source/dependency revisions, commands, configurations, real exit status, CI run URLs and results; repeat the audit on final heads and obtain independent review of security closures. No skipped/pending/predecessor result counts as a pass.

Alternatives and tradeoffs

Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed.

Validation checkpoint — 14 September 2026: Signed Integration 7cc0593e101b2e0ca42f24d4fa189dd96cb1455c passes all 159 helper suites, the strict four-selection Rust matrix (320/321 units) and all 87 original Rootd feature selections from failed CI 1603/1604. Both final native VMs pass unchanged exit/marker rules with empty stderr. The lifetime image is 2,150,400 bytes, SHA256 7d8b99684110d38dd77d2be297f1d896d7bb94a2f60dc5a3ee3dcab06cea2c76; the ordinary Rootd image is 27,934,720 bytes, SHA256 3868790fac953843c62e3674ef149dc55e4502e5118212fcc95d1aef875cf1a0. Original compiler, runtime-import and entry-argument failures remain retained. Full CI 1605 and 1606 is running; no full-catalog pass is claimed.

Allocator validation checkpoint — 14 September 2026: Signed Integration a869a81eb406a4f027a2b5db573b6330ca114d94 selects both final source graphs and passes all 159 helper suites plus strict 320/321-unit development/release default/all Rust matrices. The final ordinary Rootd IPC-framing VM passes in 45.832335 seconds and the native distinct-argument/lifetime VM passes in 13.026853 seconds, under unchanged exit/marker/deadline rules with empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,934,720 bytes, SHA256 2a187127696d569ae5c627d9c1d154ad53c024e98d9a181dbb6006790f01a0cc; the lifetime image is 2,142,208 bytes, SHA256 8fa4c7512a5916a51ba956b1e55c84ac2945c2580ff9556c99c27cbaa6e3321d. Its final image, ELF and EFI bytes equal the preceding validated feature-tree artifacts. Older full CI 1605/1606 is still running; new 1607/1608 is waiting. No full-catalog pass, realm implementation or full guest build is claimed.

Endpoint construction checkpoint — 14 September 2026: Signed Integration 989d44d604d07c4c9bcc23264912bdf2076b99eb selects both endpoint-construction graphs with their original dependency objects. Fresh strict Rust checks pass 320/321 units in all four selections, doctests, private rustdoc and freestanding builds. The previous 159-helper result is reused only for unchanged helper implementation sources; changed catalog/scenario contracts are rechecked. The original Rootd IPC-framing VM passes in 45.868135 seconds and native lifetime/distinct-argument VM in 21.529775 seconds, with unchanged oracles and empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,934,720 bytes, SHA256 184a636fb1aec40bcefc04bbd23e4884c742f12ec2400428f40c88d597499dda; native image is 2,150,400 bytes, SHA256 616b6f18f9b47c5aefaae83f288284b5ab2f31242fc422cced8233f0dea490e8. Completed older Integration 1605/1606 at 7cc0593e101b2e0ca42f24d4fa189dd96cb1455c each reports 485 passes and one failure across all 486 scenarios. The sole failed scenario is the existing ext4 quota timeout tracked in #18. All six complete logs total 27,546,527 bytes with zero warning candidates; Rust and Markdown pass. There are no VM-worker dependency-feature compiler failures. Subsequent dependent image and terminal gates remain unestablished. The allocator cohort 1607/1608 is running; current endpoint-construction cohort 1609/1610 is waiting.

Completed CI checkpoint — 15 September 2026: Signed Integration a869a81eb406a4f027a2b5db573b6330ca114d94 passes both 1607/1608; signed endpoint-construction checkpoint 989d44d604d07c4c9bcc23264912bdf2076b99eb passes both 1609/1610. Each run reports all 486 distinct VM scenarios passing, followed by the actual native lifetime scenario, physical/serial interactive checks and all four console modes. Rust and Markdown pass. The two six-log cohorts contain 26,769,289 and 26,769,316 bytes respectively, with zero warning candidates. The previously observed intermittent quota timeout remains documented without a causal-fix claim. These results establish the selected source checkpoints, not owned invocation transport, complete authority closure or either full in-EriX build generation.

Native transfer preparation checkpoint — 15 September 2026: Signed Integration 97651e7289c23560d21cf6c41effa405c97bc80d selects both original Kernel source graphs. Fresh strict Rust checks pass 320/321 units across default/all development/release, doctests, private rustdoc and freestanding builds. The prior 159-helper result is reused only for unchanged helper implementation sources; changed catalog, scenario and native lifetime policy checks pass again. The actual Rootd IPC-framing VM passes in 54.851098 seconds and native lifetime/distinct-entry-argument VM in 21.601175 seconds, with unchanged oracles, clean process teardown and empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,951,104 bytes, SHA256 1aadb6a82edf2be056254365b94ba659210c076374b321384223c219ef499fcb; native image is 2,158,592 bytes, SHA256 95d0501b2164a4bd34e307347e174451fc9f05e49cd0d9477961c5c8f663e127. The 62-capability allocation-rejection controls execute against actual kernel objects on the host; these VMs validate the existing IPC/lifetime paths. All four completed Integration workflows 1607, 1608, 1609 and 1610 pass all 486 scenarios, the later native lifetime and interactive gates, and all four console modes. The two complete cohorts total 26,769,289 and 26,769,316 bytes with zero warning candidates. The existing intermittent quota timeout remains open in Integration issue 18; later successful runs do not establish its cause or a causal fix. Current transfer-preparation workflows 1611/1612 are running; their full-suite acceptance is pending.

Native invocation custody checkpoint — 15 September 2026: Signed Integration 660cdd99a5e9b36f88b21aaed6391569e0161926 selects this Kernel in its isolated native catalog while preserving the ordinary service graph at original Kernel d2438c7e56c964a9c16720586cf718ec11e7cc0a. The existing native lifetime and distinct-entry-argument VM passes unchanged oracles in 24.878415 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its 2,207,744-byte image has SHA256 9fcdc589f4eb598978095e69122589f51a9bd8c841523a8004094ec288dd6be0. This validates existing behavior through the changed lifecycle hooks, not the absent owned-invocation syscall interface. Fresh Integration strict default/all development/release checks pass 320/321 units, private rustdoc and freestanding builds. All 159 prior helper-command results are reused only after source equality outside catalogs and roadmap; changed catalog/scenario/native-policy checks pass again. Full Integration 1613/1614 at the new catalog are waiting at their first observation; predecessor 1611/1612 remains running at its fourth observation. All four older 1607–1610 workflows passed 486/486 scenarios, later native/interactive checks and all four console modes. The existing intermittent quota timeout in Integration issue 18 remains open with unknown cause; later passes do not establish a causal fix. Corrected signed-head Kernel CI 548/549 and Docs 859/860 pass. All 8 complete logs total 1,413,966 bytes, with zero final warnings. The terminal cohort is classified. The syscall wire adapter, fresh userspace buffer/fault/overlap validation, authenticated caller-origin delivery fields and actual CPL3 owned-invocation peers remain unimplemented. Reachable backend disposal-failure coverage, sustained invocation-workload profiling, realm producer adoption, whole-codebase authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire record is assigned; the existing CALL/RECV/REPLY ABI is unchanged.

Authenticated delivery-origin checkpoint — 15 September 2026: Signed Integration 73924191bb6f9e9c9c740240fca957936360bba5 selects this Kernel only in the isolated native catalog. The unchanged lifetime and distinct-entry-argument VM passes in 23.292658 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its 2,207,744-byte image has SHA256 d20f1b859228afbbf671c2c484efb24f2c1dd6d8e8d7c32f4560f33206b97df9. This is existing-path regression coverage; new owned-invocation CPL3 peer acceptance still requires a wire adapter. Exact source comparison preserves the preceding strict 320/321-unit Rust matrices, private rustdoc, freestanding builds and 159 helper-command results. Changed catalog/scenario/native policies pass again. The ordinary service graph and original dependencies remain unchanged. Kernel CI 550/551 and Docs 861/862 pass. All eight complete logs total 1,414,891 bytes, with zero final warnings; the cohort is classified and stopped. The separate earlier fixture correction remains closed in Kernel issue 13, preserving original CI 546/547 and corrected 548/549. Full Integration 1615/1616 is waiting at its first observation. Predecessor 1613/1614 is waiting at its second observation; 1611/1612 remains running at its fifth. Older complete 1607–1610 successes remain distinct from the unresolved intermittent quota timeout in Integration issue 18. Sustained invocation-workload profiling, syscall wire and fresh-buffer/fault/overlap validation, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm producer adoption, whole authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire layout is assigned. Native progress and cleanup still do not certify application cancellation.

Native invocation profiling baseline — 15 September 2026: Signed Kernel 6cb703e1ed8b9de0d29a37189cd914cd501e732e provides an actual-object host workload for queued progress, collected progress, descriptive result reads and complete request/result cycles. Signed Integration f3e4359b34cb8f7db732fbf38823f722553c86d4 adds bounded capture, raw-evidence report verification and equivalent comparisons. Every sample checks exact bytes and SEND capability bindings, authenticated origin, foreign selection, duplicate completion refusal, FIFO position reuse, one-time collection and final invocation disposal. Source and executable bytes are observed against explicit original identities; compiler/host relationships remain declarations. Workload children and source Git reads receive minimal environments; capture owns memory, time, output and process cleanup. Completion is published only after deadline teardown succeeds. The operator guide and signed Docs 644273a0edd91e4c38dcd4418d6ae1119ff1f10b describe these boundaries. Kernel strict default/all development/release checks pass 632/656 units plus three standalone controls, three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. Integration passes all 161 helper commands, including 19 profiler controls and nine source-provenance controls, plus fresh strict 320/321-unit Rust matrices, private rustdoc and warning-free target builds. Four original socket-fixture failures are retained and attributed to the selected temporary directory exceeding the host Unix-socket path domain; a shorter explicit private directory passes the same fixtures. Docs passes 45 tests and renders 2,345 pages with zero final warnings; 427,592 word boxes fit page bounds and changed pages 2284/2285 pass visual review. Kernel CI 552/553 and Docs CI 863/864 pass; eight complete logs total 1,431,762 bytes with zero final warnings after manual reference convergence. The original signed Kernel baseline retains 48 measured samples and 16 checked warmups: four modes, populations 0/32/128/512, 256 operations per sample, three measured repetitions and one warmup. A single selected host CPU is used after local build/test work completes; external host scheduling is not isolated. At population 512, operation medians are 117,577.723 ns for queued progress, 8,927.977 ns for collected progress, 9,124.098 ns for descriptive reads and 1,167,847.016 ns for complete cycles. At population zero they are 223.328, 166.199, 213.137 and 4,556.867 ns respectively. Every raw sample, process disposition and final native cleanup passes. Timings include fixed semantic checks; no cost is subtracted and no ratio is a pass threshold. Source review identifies repeated carrier-binding scans during full registry refresh and a registry-lock acquisition for every inactive settlement position. The next bounded change will retain only non-authoritative numeric search positions: every fast path must still check current capability type/rights, endpoint identity/in-use state and exact CSpace/slot binding, with complete lookup on a stale hint. Existing revocation and terminal hooks remain authoritative. Settlement may scan for the next draining owner under one lock while retaining the original pass boundary, increasing index order, busy-position exclusion and allocation-free stack-owner return; disposal remains outside the table lock. Original workload bytes and sample policy must remain unchanged for comparison. The older Integration CI 1611/1612 succeeds at all 486 catalog scenarios, native lifetime, interactive directory/editor and four console modes. Six complete logs total 26,771,244 bytes with zero warnings; this does not resolve the intermittent quota cause tracked in Integration issue 18. Integration 1613/1614 is running, 1615/1616 is waiting, and current profiler CI 1617/1618 is waiting. No completed cohort is polled again. No Kernel performance algorithm has changed in this baseline. Native syscall adapters, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The 76-repository inventory has 2,923 code files below 1,000 lines and 155 direct missing_docs crate-root gates; this does not close the semantic audits.

Measured native invocation lookup refinement — 15 September 2026: Signed Kernel 8349d68636382cc7e25a3347f5f1df216554203a retains only numeric carrier-search positions. Every use rechecks the actual CSpace capability type/rights, live endpoint identity and exact binding; stale positions take the complete search path. No successful authorization, capability or reference is cached. Draining scans fix their boundary on the first poll, visit each position at most once, skip busy stack owners and return exclusive custody after unlocking. Native disposal and first-failure retention preserve their existing semantics. Signed Integration 108501cf7ec20f05dd3d62ea401ea8adad6c6e9c selects this Kernel in its isolated native catalog, and signed Docs f10a1d375a326543ec0adda4569bc7cb4faca9b6 documents the invariants. The existing syscall ABI and ordinary image catalog are unchanged. All 15 actual-object native controls pass, including real alias compaction, rights/type/object replacement, busy ownership and allocation-free settlement. The unchanged four-mode workload control also passes. Full strict default/all development/release Kernel matrices pass 634/658 units plus three standalone controls, with three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. The existing native lifetime and entry-argument VM passes unchanged oracles in 21.978041 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its signed boot image is 2,207,744 bytes, SHA-256 4030cdfb8a13c000ff4716ecdc5203cb46273d6117a282f7375f25dccbbeedc9. Exact unchanged Integration Rust/helper bytes preserve the preceding strict 320/321-unit matrices and all 161 helper-command results; changed catalog/scenario policies pass. Docs passes all 45 tests and a complete 2,345-page render with zero final warnings, 427,679 bounded word boxes and visual review of page 145 plus continuation page 146. The original signed Kernel 6cb703e1ed8b9de0d29a37189cd914cd501e732e and the new signed Kernel use byte-identical workload sources, the same selected CPU/toolchain/context and explicit limits, distinct source targets, four modes, populations 0/32/128/512 and 256 operations per sample. Each capture retains 48 measured samples and 16 warmups; every sample passes actual semantic and native/process-cleanup checks. At population 512, median queued-progress cost changes from 117.578 to 37.673 microseconds (3.12x observed ratio), and full-cycle cost from 1167.847 to 443.055 microseconds (2.64x). Collected progress changes from 8.928 to 6.015 microseconds and descriptive reads from 9.124 to 6.212 microseconds. Timings include fixed checks, with no subtracted overhead or timing-ratio pass gate. No managed build/test workload runs concurrently during capture; external host scheduling remains unisolated. These are host operation wall times, not guest startup/build acceptance or a statistical guarantee. Kernel CI 554/555 succeeds; four complete logs total 679,280 bytes with no warnings, and its completed cohort is stopped. Docs CI 865/866 succeeds at observation three; four complete logs total 754,424 bytes, all 45 tests pass and each manual has 2,345 pages. Its normal reference passes report 32/1/0 warnings, with zero final warnings and no box diagnostics. The completed Docs cohort is stopped. Integration CI 1619/1620 is waiting at its first observation. Older Integration 1613/1614 is running; 1615/1616 and 1617/1618 are waiting. Accepted older Integration 1611/1612 passes all 486 catalog scenarios and later probes with complete warning-free logs. This does not establish the intermittent quota cause tracked in Integration issue 18. Current full-suite CI remains required; stopped cohorts are not polled again. Owned syscall wire adapters, actual owned CPL3 peers, fresh-buffer validation, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The refreshed 76-repository inventory has 2,924 code files below 1,000 lines and 155 direct missing_docs crate-root gates; those checks do not close whole-codebase semantic audits.

Owned invocation wire and native acceptance — 15 September 2026: Signed Kernel 5f497adaefa526108a0439e0e071717dddb85334, shared IPC de968da19898bef532ddb3b5974bb9562f51dee5, capability ABI a001a26f0eb3aebec3f5fd02a28d98f1bc23f8a0 and Integration 9030b217c490db6ad3ec60a799cb025eccbfcdb1 implement and exercise the immediate owned invocation boundary. The allocation-free shared codecs and shim preserve exact return metadata, including a retained draining owner on failed submission. The Kernel checks fresh complete user mappings and packet framing under one lifecycle guard before native effects. No user pointer or caller-selected identity is retained. Destination capacity and descriptive receipt capacity are independent; spare capacity acquires no authority and repeated collection cannot duplicate transfers. Existing numeric binding hints still recheck live capabilities on every use. The real three-process CPL3 scenario passes all eight operations, full-span pointer/rights/overflow/reserved-field rejection, actual returned selectors, payload/capability/origin checks, collection after server exit and repeated receipts. A second request rejects premature relinquishment, enters draining on caller release and retires only after the exact server acknowledgment. Current signed owned and unchanged older lifetime images are each 2,232,320 bytes, with SHA-256 588c6097c57ebd2ed92e0f0b76f2b1ad6b82630b4a0da272ee98e218eb8e333d and 8f9026aaefd2c5a745e35467ac01c71789c5f469f9cd42a477f87818747ee673 respectively. Both runs have clean teardown and empty QEMU stderr. Ordinary images contain neither diagnostic hook. Strict default/all development/release host, freestanding and rustdoc matrices pass: IPC 368 units, shim 20, capability ABI 191, Kernel 642/666 and Integration 320/321. Existing ignores remain one shim and three Kernel tests. All 162 maintained Integration helper commands pass; three prior correct concurrent-run lock refusals are retained and their sequential checks pass on unchanged executable inputs. Docs 46da7a4cb4d38a2bea5b5491a68f51f33e4b4305 publishes the normative register/packet contract and regenerates the three affected API references from original signed revisions. All 45 documentation tests pass. The complete 2,363-page manual has zero final warnings, 430,365 word boxes within page bounds and reviewed changed ABI/API pages. Shared IPC CI 337/338 and capability ABI CI 214/215 pass with eight complete warning-free logs. Both Kernel revisions pass CI 556/557 and 558/559 with eight complete warning-free logs. Those cohorts are stopped. Current Docs CI 867/868 passes at observation four; four complete logs total 758,328 bytes. Both 2,363-page manuals pass all 45 tests, report normal reference-pass warnings of 32/1/0, and finish with zero warnings or box diagnostics. Its cohort is stopped. Current full Integration 1621/1622 is waiting. Older full Integration 1613/1614 now passes all 486 catalog scenarios and later native/console probes, with six complete warning-free logs; its cohort is stopped. Older 1615/1616 is running, and 1617/1618 plus 1619/1620 are waiting. Current full-suite acceptance remains open, as does the intermittent quota cause in Integration issue 18. This checkpoint supersedes the earlier pending wire/CPL3/manual status. Reachable backend disposal-failure coverage, broader revocation/generation-reuse scenarios, producer adoption, realm runtime, complete authority/inline-documentation audits and both full EriX-in-EriX build generations remain open. The current inventory checks 76 repositories, 2,943 code files below 1,000 lines and 157 crate roots with direct missing_docs gates; it does not establish semantic audit closure. No complete guest build or guest performance result is claimed.

Process-bound native acceptance — 15 September 2026: Signed Kernel 60da5858d7198185efd103f0e91e5ac2e0b63e67 implements control operation 52, checking the actual moved install grant against expected process/generation with exact rights, including zero, under existing endpoint policies. Signed Procd f1105706cc19ed024a6cca79a29abc57c90c6661 uses this operation in its actual ordinary launch-description producer while retaining the narrow SEND receipt, pending state and exact failure cleanup. IPC c453b697b8cdb9cc1c36f1ad89ff868648190025, capability ABI fe8d558253ad01301b99554e20d287c4ea35bb1d and five aligned helper commits preserve original Git/type identity. Integration 58c925c564b69bebce8df6f3e75a9312824e18c4 passes the expanded lifetime CPL3 scenario with thirteen actual control calls, user-side reply checks, two staged children and full added-custody disposal. The corrected lifetime image SHA-256 is 8e6a9e8f68b90cc1ede61300958cec122b82a7c6dfd6318a51e40fefc7ba166e; the unchanged owned-invocation scenario also passes with image SHA-256 b76a380d3cd6b03b0ff61a3b626ace0667679920684ad7356a1c3a36e2224953. Both have clean teardown and empty QEMU stderr. The initial fixture setup-order failure is retained and corrected in Kernel issue #14. All strict default/all development/release matrices pass: IPC 371, shim 20, capability ABI 191, Kernel 648/672 including standalone controls, Procd 227/232 including auxiliary binaries, and Integration 320/321 tests. Existing native-only ignores are unchanged. Procd passes forty native binary builds with repository linker scripts. All 162 Integration helpers pass after updating the exact policy assertion to require the new marker; its initial mismatch remains recorded. Docs b0fcf0f43af2af741d520a0b1373cc346e08863c updates the native wire/ownership contract, operation registry, Procd boundary and three generated shared APIs. All 45 tests and the complete 2,367-page manual pass, with zero final warnings, 431,138 word boxes within page bounds and four reviewed protocol/API pages. Current IPC 339/340, capability ABI 216/217, Kernel 560/561 and 562/563, Procd 266/267, Docs 869/870 and all five helper push/review CIs pass with complete classified logs and no final warnings. Those component cohorts are stopped. Current full Integration 1623/1624 waits at observation 01. Older full Integration 1615/1616 is running at observation 11; 1617/1618, 1619/1620 and 1621/1622 wait at observations 09, 07 and 04. No pending full suite is counted as passed. Typed realm bootstrap, mediator startup/readiness/configuration/seal, complete consumer image adoption, fair terminal/provider retirement, broader native disposal failures and both full EriX-in-EriX build generations remain open. The new inventory covers 76 repositories, 2,950 code files below 1,000 lines and 158 direct missing_docs crate-root gates; complete inline documentation and whole-codebase authority closure remain open. Prior performance measurements retain their original signed source identities; this checkpoint claims no new timing or guest performance result.

Tracking and rollout

Current Integration 4b65755f1f2774798d4a909212db4e64c0349b86 finishes with failed push CI 1603 and PR CI 1604. Each complete catalog reports 54 passes and 432 failures out of 486 scenarios. Six full terminal logs total 14,427,322 bytes, with no warning candidates. Both Rust and Markdown jobs pass. The later isolated native diagnostic, canonical images and terminal modes are not reached by these runs.

Issue 50 tracks the observed shared-compiler regression: valid dependency-qualified Rootd selections are rejected as unknown local features. A minimal original-manifest check confirms the failure. The correction separates compiler cfg ownership and adds direct, transitive, malformed and real-compiler coverage; its full local checks are underway. Original failures remain retained, and these terminal runs are not being replayed unchanged. Earlier isolated native VM acceptance retains its separate exact source and artifact scope.

Signed Integration 4b65755f1f2774798d4a909212db4e64c0349b86 adds the isolated native lifetime scenario and corrects standalone kernel service selection, target-scoped cache identity and original-manifest feature closure. The redundant feature implication table is removed and the shared resolver joins the builder fingerprint. The normal component catalog remains independently selected.

The strict development/release default/all-feature Rust matrix passes 320/321 units, doctests, private rustdoc and freestanding builds; missing documentation remains denied. All 159 helper suites are accepted across the complete run and justified follow-ups: installed filesystem-tool routes and actual stage tracing, serialization after the real VM releases the global scenario lock, and declaration of the compiler fixture's selected feature. Original failures and actual statuses remain retained; assertions and production deadlines are unchanged.

The actual native VM passes both ordered unique markers, expected exit and forbidden-marker checks using signed Kernel 03e13a784bde08914864267a4e2a6324a22d05c7 and Bootloader e7fa39357a38c21529cccfd16cf3446eb07e8aa5. The 2,142,208-byte image has SHA256 4f021a40264739fef4979da2b0cd4647bde3f76b9dada6816aba6faa3594a797; QEMU stderr is empty. Complete preparation and execution takes 19.20 seconds under the unchanged 60/45-second VM limits, not a guest performance measurement. Kernel CI 528/529 and Bootloader CI 135/136 are green. Integration CI 1603/1604 is running; older suite and complete current-head acceptance remain pending. Realm adoption and both full guest build generations are unproved.

  • Parent work: #2 and erix/docs#1.
  • Branch: feature/posix-compat; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages.
  • Baseline revision: c86c0d89e51ed9818d62afa799d358768646c953; refresh component/dependency heads and their own CI evidence as implementation advances.
  • Cross-repository dependencies remain full lowercase commit hashes; update the selected graph deliberately. This issue does not authorize merges, release tags or replacement of published images.

Original acknowledged service catalog — 21 September 2026:

Signed dff878dd3545c4751b3c05d37b2bdd5e21cce548 selects the original terminal-observation, exact-acknowledgement and final CPU dependency graph in both complete catalogs. All 35 application/service checkpoints are signed; the bounded VFS checker correction and its manual are included. Clean original checkouts pass manifest/catalog equality and signature checks. Exsh's release compiler and complete frame gates remain explicitly open in issue 9 and issue 4.

All 169 maintained helper commands pass with recorded source and stream identities. The original stale memory-source rejection, quiet storage-fixture timeout and overly long socket-fixture path remain retained. Their respective corrected inputs use the explicitly verified original memory checkout, the previously maintained traced disk invocation (258.975743 seconds under unchanged 600/120 bounds), and a fresh owned shorter temporary directory (all 14 socket controls pass without changing the Unix pathname limit). None of these setup corrections changes test sources or bypasses source, timing or cleanup checks. The unchanged orchestration library retains all four strict 320/321-test configurations; formatting, policies and Markdown pass without warnings.

The published runner and original full source graph are prepared for the maintained shell CPU-accounting, two-CPU inspection and out-of-session denial scenarios. Actual VM evidence remains pending and no full guest-build acceptance is awarded. Original CI 1703/1704 is being monitored without restart. Complete authority/source/effect/frame and Pagerd gates, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory in Phase 6 completion.

Actual service CPU scenarios and startup admission — 21 September 2026:

The published original Integration catalog dff878dd3545c4751b3c05d37b2bdd5e21cce548 passes the maintained shell times, two-CPU Extop and out-of-session denial VM scenarios under their unchanged 120-second guest limits. Each retains 106 hashed evidence files, warning-free image builds, empty QEMU stderr and every required, forbidden, ordered and unique marker check. Build-plus-scenario wall times are 119.876978, 34.802620 and 36.173027 seconds respectively; these are not guest-only or startup measurements.

Times reports nonzero self and waited-child CPU. Extop observes both CPUs, memory and increasing job CPU nanoseconds with CTRL no; both per-CPU percentages remain --.--% in the two samples, so numeric utilization is unproven. The denial scenario confirms the existing out-of-session boundary. Complete mediator/lifecycle acceptance in Procd 5 remains open.

A separate ordinary development package also builds without warnings, but its required startup-contract preflight exits 1 before any VM or observer starts. Integration 69 records the missing full-runtime-transition contract selections and Kernel effective-feature/original-source evidence. Preserve the refused package and all admission controls; the 120/15/10 capture limits and performance thresholds are unchanged. No startup-profile acceptance is awarded. Complete source/effect/frame and Pagerd proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required by Phase 6 completion.

Signed startup source/feature correction — 21 September 2026:

Integration fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure.

All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; bug 71 retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices.

The technical manual update 76672dff8ff83 passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs 1001/1002 passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow.

A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under bug 69; no threshold or 120/15/10 capture limit changes. Original Integration 1705/1706 is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory.

Actual original-source startup capture — 21 September 2026:

Signed Integration fd8a5cf0dbcf builds the ordinary image without warnings and its actual Kernel-bound contract passes preflight. The VM and complete observer finish with all required stages, zero dropped records, empty QEMU stderr, successful cleanup and unchanged source image. Admission bug 69 is resolved independently of performance.

The strict timing gate fails: root-to-final readiness 5.974133160 seconds (limit 5), largest service interval 3.098663889 (limit 1), final readiness to caret 1.262470092 (limit 1), and four native commands 4.769234506 (limit 2). The maintained offline profiler identifies RTC-provider to TTYD as the largest service interval, followed by roughly one-second Powerboxd and Launchd intervals. These are host observation windows, not loader-only causal measurements. The new canonical timing bug retains the exact image, timing and command identities and every original limit. Host/toolchain description fields remain explicitly incomplete; no provenance or speedup is invented.

The sixteen helper stream-custody corrections also pass all changed controls; all 171 selected helper commands have successful warning-free final evidence. Bug 71 is resolved with its original 36 warnings retained. Full CI for 1705/1706 remains separately monitored. No startup-performance or full native toolchain/EriX guest-build acceptance is awarded.

Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.

Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.

Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.

## Problem and motivation This issue tracks continuous Phase 6 audit closure for `integration`. Build exact component graphs, assemble images, generate media, run VM regressions and provide authority-free in-guest scenario policy. An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance. ## Proposed behavior and scope Current inventory: 1 Cargo target (1 lib); manifests: `lib/rootd-integration-orchestration/Cargo.toml`. Include explicit and automatically discovered targets, supported features and target-specific configurations. Review host source admission, subprocesses, caches, private outputs, image/signing provenance and VM teardown, plus the nested rootd-integration-orchestration crate. The in-guest library must remain authority-free and absent from production policy. Tracked-source baseline: `scripts/build-dynlink-image-manifest.py` has 1029 physical lines and needs thematic refactoring. Initial target-root inventory found no direct/shared `missing_docs` policy at `lib/rootd-integration-orchestration/src/lib.rs`; verify and enforce it with meaningful rustdoc. ## Authority, security and reliability Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption. ## Acceptance criteria - [ ] Record origin, recipient, object, operations, delegation ceiling, lifetime and aliases for each relevant capability or caller-supplied authority-bearing value. - [ ] Audit ambient discovery/selectors, cwd/PATH/environment, numeric identities, inherited routes and host fallbacks; require explicit authorized intake. - [ ] Account for residual authority after success, error, cancellation, timeout, restart, failed transfer and teardown, including fork/exec where implemented. - [ ] Remove unnecessary endpoints, broad rights, duplicate aliases, provider/admin grants and debug routes. - [ ] Exercise stale generations, replay, pending replies, forged descriptive identity and object/path resolution races at the owned boundary. - [ ] Prove independent cleanup attempts and caller-specific error precedence; quarantine or terminate when retained authority cannot be accounted for. - [ ] Review unsafe/FFI/parser/arithmetic/lifetime/lock/publication invariants and add adversarial coverage where practical. - [ ] Inventory obsolete APIs, wrappers, fallback/dead paths and duplicate validators with their maintained callers. - [ ] Migrate callers and delete deprecated contracts/shims in a coherent signed revision graph; reject retired input versions where relevant. - [ ] Classify each size/count/depth/time bound as ABI, hardware, explicit resource policy or accidental limitation. - [ ] Test beyond removed boundaries and at allocation/ABI limits while preserving exhaustion errors, denial-of-service controls and bounded waits. - [ ] Keep every tracked authored code/test/script/workflow file below 1000 physical lines through thematic refactoring. - [ ] Run the deterministic tracked-source size gate, covering executable fixtures/generators and excluding only genuine non-code data or external payloads. - [ ] Audit production/test feature and symbol separation, including this repository's effect on rootd test orchestration. - [ ] Supply changes affecting rootd semantic surface to the maintained same-toolchain baseline; record a justified component-specific applicability result. - [ ] Check bootstrap ownership and development/release authority parity at this repository's producer/consumer boundary. - [ ] Use maintained [integration#3](https://git.erikinkinen.fi/erix/integration/issues/3) profiler evidence before optimizing; preserve live access checks, ownership and success criteria. - [ ] Audit build/CI inputs, secret handling, private outputs, symlink containment, deletion, subprocess bounds, warnings and host dependencies. - [ ] meaningful public/private inline documentation, crate/target `missing_docs` enforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate. - [ ] Validation: Run `cargo fmt --all -- --check`, strict Clippy, unit/doctests and warning-denied builds/rustdoc for every owned crate/target under default and all valid feature, freestanding/host, SMP and profile combinations; test mutually exclusive combinations separately. Add focused VM regressions for runtime behavior and observe the older catalog and unit tests at the exact published heads. - [ ] Documentation: update applicable README/ARCHITECTURE/ROADMAP in meta's canonical format and affected technical-manual TeX/API references; keep README evergreen and shared governance byte-identical to meta. - [ ] Evidence: record exact source/dependency revisions, commands, configurations, real exit status, CI run URLs and results; repeat the audit on final heads and obtain independent review of security closures. No skipped/pending/predecessor result counts as a pass. ## Alternatives and tradeoffs Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed. Validation checkpoint — 14 September 2026: Signed Integration `7cc0593e101b2e0ca42f24d4fa189dd96cb1455c` passes all 159 helper suites, the strict four-selection Rust matrix (320/321 units) and all 87 original Rootd feature selections from failed CI 1603/1604. Both final native VMs pass unchanged exit/marker rules with empty stderr. The lifetime image is 2,150,400 bytes, SHA256 `7d8b99684110d38dd77d2be297f1d896d7bb94a2f60dc5a3ee3dcab06cea2c76`; the ordinary Rootd image is 27,934,720 bytes, SHA256 `3868790fac953843c62e3674ef149dc55e4502e5118212fcc95d1aef875cf1a0`. Original compiler, runtime-import and entry-argument failures remain retained. Full CI [1605](https://git.erikinkinen.fi/erix/integration/actions/runs/1605) and [1606](https://git.erikinkinen.fi/erix/integration/actions/runs/1606) is running; no full-catalog pass is claimed. Allocator validation checkpoint — 14 September 2026: Signed Integration `a869a81eb406a4f027a2b5db573b6330ca114d94` selects both final source graphs and passes all 159 helper suites plus strict 320/321-unit development/release default/all Rust matrices. The final ordinary Rootd IPC-framing VM passes in 45.832335 seconds and the native distinct-argument/lifetime VM passes in 13.026853 seconds, under unchanged exit/marker/deadline rules with empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,934,720 bytes, SHA256 `2a187127696d569ae5c627d9c1d154ad53c024e98d9a181dbb6006790f01a0cc`; the lifetime image is 2,142,208 bytes, SHA256 `8fa4c7512a5916a51ba956b1e55c84ac2945c2580ff9556c99c27cbaa6e3321d`. Its final image, ELF and EFI bytes equal the preceding validated feature-tree artifacts. Older full CI [1605](https://git.erikinkinen.fi/erix/integration/actions/runs/1605)/[1606](https://git.erikinkinen.fi/erix/integration/actions/runs/1606) is still running; new [1607](https://git.erikinkinen.fi/erix/integration/actions/runs/1607)/[1608](https://git.erikinkinen.fi/erix/integration/actions/runs/1608) is waiting. No full-catalog pass, realm implementation or full guest build is claimed. Endpoint construction checkpoint — 14 September 2026: Signed Integration `989d44d604d07c4c9bcc23264912bdf2076b99eb` selects both endpoint-construction graphs with their original dependency objects. Fresh strict Rust checks pass 320/321 units in all four selections, doctests, private rustdoc and freestanding builds. The previous 159-helper result is reused only for unchanged helper implementation sources; changed catalog/scenario contracts are rechecked. The original Rootd IPC-framing VM passes in 45.868135 seconds and native lifetime/distinct-argument VM in 21.529775 seconds, with unchanged oracles and empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,934,720 bytes, SHA256 `184a636fb1aec40bcefc04bbd23e4884c742f12ec2400428f40c88d597499dda`; native image is 2,150,400 bytes, SHA256 `616b6f18f9b47c5aefaae83f288284b5ab2f31242fc422cced8233f0dea490e8`. Completed older Integration [1605](https://git.erikinkinen.fi/erix/integration/actions/runs/1605)/[1606](https://git.erikinkinen.fi/erix/integration/actions/runs/1606) at `7cc0593e101b2e0ca42f24d4fa189dd96cb1455c` each reports 485 passes and one failure across all 486 scenarios. The sole failed scenario is the existing ext4 quota timeout tracked in #18. All six complete logs total 27,546,527 bytes with zero warning candidates; Rust and Markdown pass. There are no VM-worker dependency-feature compiler failures. Subsequent dependent image and terminal gates remain unestablished. The allocator cohort 1607/1608 is running; current endpoint-construction cohort 1609/1610 is waiting. Completed CI checkpoint — 15 September 2026: Signed Integration `a869a81eb406a4f027a2b5db573b6330ca114d94` passes both [1607](https://git.erikinkinen.fi/erix/integration/actions/runs/1607)/[1608](https://git.erikinkinen.fi/erix/integration/actions/runs/1608); signed endpoint-construction checkpoint `989d44d604d07c4c9bcc23264912bdf2076b99eb` passes both [1609](https://git.erikinkinen.fi/erix/integration/actions/runs/1609)/[1610](https://git.erikinkinen.fi/erix/integration/actions/runs/1610). Each run reports all 486 distinct VM scenarios passing, followed by the actual native lifetime scenario, physical/serial interactive checks and all four console modes. Rust and Markdown pass. The two six-log cohorts contain 26,769,289 and 26,769,316 bytes respectively, with zero warning candidates. The previously observed intermittent quota timeout remains documented without a causal-fix claim. These results establish the selected source checkpoints, not owned invocation transport, complete authority closure or either full in-EriX build generation. Native transfer preparation checkpoint — 15 September 2026: Signed Integration `97651e7289c23560d21cf6c41effa405c97bc80d` selects both original Kernel source graphs. Fresh strict Rust checks pass 320/321 units across default/all development/release, doctests, private rustdoc and freestanding builds. The prior 159-helper result is reused only for unchanged helper implementation sources; changed catalog, scenario and native lifetime policy checks pass again. The actual Rootd IPC-framing VM passes in 54.851098 seconds and native lifetime/distinct-entry-argument VM in 21.601175 seconds, with unchanged oracles, clean process teardown and empty QEMU stderr. These are host build-and-run durations. The ordinary image is 27,951,104 bytes, SHA256 `1aadb6a82edf2be056254365b94ba659210c076374b321384223c219ef499fcb`; native image is 2,158,592 bytes, SHA256 `95d0501b2164a4bd34e307347e174451fc9f05e49cd0d9477961c5c8f663e127`. The 62-capability allocation-rejection controls execute against actual kernel objects on the host; these VMs validate the existing IPC/lifetime paths. All four completed Integration workflows [1607](https://git.erikinkinen.fi/erix/integration/actions/runs/1607), [1608](https://git.erikinkinen.fi/erix/integration/actions/runs/1608), [1609](https://git.erikinkinen.fi/erix/integration/actions/runs/1609) and [1610](https://git.erikinkinen.fi/erix/integration/actions/runs/1610) pass all 486 scenarios, the later native lifetime and interactive gates, and all four console modes. The two complete cohorts total 26,769,289 and 26,769,316 bytes with zero warning candidates. The existing intermittent quota timeout remains open in [Integration issue 18](https://git.erikinkinen.fi/erix/integration/issues/18); later successful runs do not establish its cause or a causal fix. Current transfer-preparation workflows [1611](https://git.erikinkinen.fi/erix/integration/actions/runs/1611)/[1612](https://git.erikinkinen.fi/erix/integration/actions/runs/1612) are running; their full-suite acceptance is pending. Native invocation custody checkpoint — 15 September 2026: Signed Integration `660cdd99a5e9b36f88b21aaed6391569e0161926` selects this Kernel in its isolated native catalog while preserving the ordinary service graph at original Kernel `d2438c7e56c964a9c16720586cf718ec11e7cc0a`. The existing native lifetime and distinct-entry-argument VM passes unchanged oracles in 24.878415 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its 2,207,744-byte image has SHA256 `9fcdc589f4eb598978095e69122589f51a9bd8c841523a8004094ec288dd6be0`. This validates existing behavior through the changed lifecycle hooks, not the absent owned-invocation syscall interface. Fresh Integration strict default/all development/release checks pass 320/321 units, private rustdoc and freestanding builds. All 159 prior helper-command results are reused only after source equality outside catalogs and roadmap; changed catalog/scenario/native-policy checks pass again. Full Integration [1613](https://git.erikinkinen.fi/erix/integration/actions/runs/1613)/[1614](https://git.erikinkinen.fi/erix/integration/actions/runs/1614) at the new catalog are waiting at their first observation; predecessor 1611/1612 remains running at its fourth observation. All four older 1607–1610 workflows passed 486/486 scenarios, later native/interactive checks and all four console modes. The existing intermittent quota timeout in [Integration issue 18](https://git.erikinkinen.fi/erix/integration/issues/18) remains open with unknown cause; later passes do not establish a causal fix. Corrected signed-head Kernel CI [548](https://git.erikinkinen.fi/erix/kernel/actions/runs/548)/[549](https://git.erikinkinen.fi/erix/kernel/actions/runs/549) and Docs [859](https://git.erikinkinen.fi/erix/docs/actions/runs/859)/[860](https://git.erikinkinen.fi/erix/docs/actions/runs/860) pass. All 8 complete logs total 1,413,966 bytes, with zero final warnings. The terminal cohort is classified. The syscall wire adapter, fresh userspace buffer/fault/overlap validation, authenticated caller-origin delivery fields and actual CPL3 owned-invocation peers remain unimplemented. Reachable backend disposal-failure coverage, sustained invocation-workload profiling, realm producer adoption, whole-codebase authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire record is assigned; the existing CALL/RECV/REPLY ABI is unchanged. Authenticated delivery-origin checkpoint — 15 September 2026: Signed Integration `73924191bb6f9e9c9c740240fca957936360bba5` selects this Kernel only in the isolated native catalog. The unchanged lifetime and distinct-entry-argument VM passes in 23.292658 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its 2,207,744-byte image has SHA256 `d20f1b859228afbbf671c2c484efb24f2c1dd6d8e8d7c32f4560f33206b97df9`. This is existing-path regression coverage; new owned-invocation CPL3 peer acceptance still requires a wire adapter. Exact source comparison preserves the preceding strict 320/321-unit Rust matrices, private rustdoc, freestanding builds and 159 helper-command results. Changed catalog/scenario/native policies pass again. The ordinary service graph and original dependencies remain unchanged. Kernel CI [550](https://git.erikinkinen.fi/erix/kernel/actions/runs/550)/[551](https://git.erikinkinen.fi/erix/kernel/actions/runs/551) and Docs [861](https://git.erikinkinen.fi/erix/docs/actions/runs/861)/[862](https://git.erikinkinen.fi/erix/docs/actions/runs/862) pass. All eight complete logs total 1,414,891 bytes, with zero final warnings; the cohort is classified and stopped. The separate earlier fixture correction remains closed in [Kernel issue 13](https://git.erikinkinen.fi/erix/kernel/issues/13), preserving original CI 546/547 and corrected 548/549. Full Integration [1615](https://git.erikinkinen.fi/erix/integration/actions/runs/1615)/[1616](https://git.erikinkinen.fi/erix/integration/actions/runs/1616) is waiting at its first observation. Predecessor 1613/1614 is waiting at its second observation; 1611/1612 remains running at its fifth. Older complete 1607–1610 successes remain distinct from the unresolved intermittent quota timeout in [Integration issue 18](https://git.erikinkinen.fi/erix/integration/issues/18). Sustained invocation-workload profiling, syscall wire and fresh-buffer/fault/overlap validation, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm producer adoption, whole authority/private-rustdoc closure and both complete EriX-in-EriX build generations remain open. No new syscall number or wire layout is assigned. Native progress and cleanup still do not certify application cancellation. Native invocation profiling baseline — 15 September 2026: Signed Kernel `6cb703e1ed8b9de0d29a37189cd914cd501e732e` provides an actual-object host workload for queued progress, collected progress, descriptive result reads and complete request/result cycles. Signed Integration `f3e4359b34cb8f7db732fbf38823f722553c86d4` adds bounded capture, raw-evidence report verification and equivalent comparisons. Every sample checks exact bytes and SEND capability bindings, authenticated origin, foreign selection, duplicate completion refusal, FIFO position reuse, one-time collection and final invocation disposal. Source and executable bytes are observed against explicit original identities; compiler/host relationships remain declarations. Workload children and source Git reads receive minimal environments; capture owns memory, time, output and process cleanup. Completion is published only after deadline teardown succeeds. The operator guide and signed Docs `644273a0edd91e4c38dcd4418d6ae1119ff1f10b` describe these boundaries. Kernel strict default/all development/release checks pass 632/656 units plus three standalone controls, three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. Integration passes all 161 helper commands, including 19 profiler controls and nine source-provenance controls, plus fresh strict 320/321-unit Rust matrices, private rustdoc and warning-free target builds. Four original socket-fixture failures are retained and attributed to the selected temporary directory exceeding the host Unix-socket path domain; a shorter explicit private directory passes the same fixtures. Docs passes 45 tests and renders 2,345 pages with zero final warnings; 427,592 word boxes fit page bounds and changed pages 2284/2285 pass visual review. Kernel CI 552/553 and Docs CI 863/864 pass; eight complete logs total 1,431,762 bytes with zero final warnings after manual reference convergence. The original signed Kernel baseline retains 48 measured samples and 16 checked warmups: four modes, populations 0/32/128/512, 256 operations per sample, three measured repetitions and one warmup. A single selected host CPU is used after local build/test work completes; external host scheduling is not isolated. At population 512, operation medians are 117,577.723 ns for queued progress, 8,927.977 ns for collected progress, 9,124.098 ns for descriptive reads and 1,167,847.016 ns for complete cycles. At population zero they are 223.328, 166.199, 213.137 and 4,556.867 ns respectively. Every raw sample, process disposition and final native cleanup passes. Timings include fixed semantic checks; no cost is subtracted and no ratio is a pass threshold. Source review identifies repeated carrier-binding scans during full registry refresh and a registry-lock acquisition for every inactive settlement position. The next bounded change will retain only non-authoritative numeric search positions: every fast path must still check current capability type/rights, endpoint identity/in-use state and exact CSpace/slot binding, with complete lookup on a stale hint. Existing revocation and terminal hooks remain authoritative. Settlement may scan for the next draining owner under one lock while retaining the original pass boundary, increasing index order, busy-position exclusion and allocation-free stack-owner return; disposal remains outside the table lock. Original workload bytes and sample policy must remain unchanged for comparison. The older Integration CI 1611/1612 succeeds at all 486 catalog scenarios, native lifetime, interactive directory/editor and four console modes. Six complete logs total 26,771,244 bytes with zero warnings; this does not resolve the intermittent quota cause tracked in Integration issue 18. Integration 1613/1614 is running, 1615/1616 is waiting, and current profiler CI 1617/1618 is waiting. No completed cohort is polled again. No Kernel performance algorithm has changed in this baseline. Native syscall adapters, actual owned CPL3 peers, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The 76-repository inventory has 2,923 code files below 1,000 lines and 155 direct missing_docs crate-root gates; this does not close the semantic audits. Measured native invocation lookup refinement — 15 September 2026: Signed Kernel `8349d68636382cc7e25a3347f5f1df216554203a` retains only numeric carrier-search positions. Every use rechecks the actual CSpace capability type/rights, live endpoint identity and exact binding; stale positions take the complete search path. No successful authorization, capability or reference is cached. Draining scans fix their boundary on the first poll, visit each position at most once, skip busy stack owners and return exclusive custody after unlocking. Native disposal and first-failure retention preserve their existing semantics. Signed Integration `108501cf7ec20f05dd3d62ea401ea8adad6c6e9c` selects this Kernel in its isolated native catalog, and signed Docs `f10a1d375a326543ec0adda4569bc7cb4faca9b6` documents the invariants. The existing syscall ABI and ordinary image catalog are unchanged. All 15 actual-object native controls pass, including real alias compaction, rights/type/object replacement, busy ownership and allocation-free settlement. The unchanged four-mode workload control also passes. Full strict default/all development/release Kernel matrices pass 634/658 units plus three standalone controls, with three existing ignores, private rustdoc, target Clippy and eight warning-free freestanding builds. The existing native lifetime and entry-argument VM passes unchanged oracles in 21.978041 seconds of host build-and-run time, with clean teardown and empty QEMU stderr. Its signed boot image is 2,207,744 bytes, SHA-256 `4030cdfb8a13c000ff4716ecdc5203cb46273d6117a282f7375f25dccbbeedc9`. Exact unchanged Integration Rust/helper bytes preserve the preceding strict 320/321-unit matrices and all 161 helper-command results; changed catalog/scenario policies pass. Docs passes all 45 tests and a complete 2,345-page render with zero final warnings, 427,679 bounded word boxes and visual review of page 145 plus continuation page 146. The original signed Kernel `6cb703e1ed8b9de0d29a37189cd914cd501e732e` and the new signed Kernel use byte-identical workload sources, the same selected CPU/toolchain/context and explicit limits, distinct source targets, four modes, populations 0/32/128/512 and 256 operations per sample. Each capture retains 48 measured samples and 16 warmups; every sample passes actual semantic and native/process-cleanup checks. At population 512, median queued-progress cost changes from 117.578 to 37.673 microseconds (3.12x observed ratio), and full-cycle cost from 1167.847 to 443.055 microseconds (2.64x). Collected progress changes from 8.928 to 6.015 microseconds and descriptive reads from 9.124 to 6.212 microseconds. Timings include fixed checks, with no subtracted overhead or timing-ratio pass gate. No managed build/test workload runs concurrently during capture; external host scheduling remains unisolated. These are host operation wall times, not guest startup/build acceptance or a statistical guarantee. Kernel CI 554/555 succeeds; four complete logs total 679,280 bytes with no warnings, and its completed cohort is stopped. Docs CI 865/866 succeeds at observation three; four complete logs total 754,424 bytes, all 45 tests pass and each manual has 2,345 pages. Its normal reference passes report 32/1/0 warnings, with zero final warnings and no box diagnostics. The completed Docs cohort is stopped. Integration CI 1619/1620 is waiting at its first observation. Older Integration 1613/1614 is running; 1615/1616 and 1617/1618 are waiting. Accepted older Integration 1611/1612 passes all 486 catalog scenarios and later probes with complete warning-free logs. This does not establish the intermittent quota cause tracked in Integration issue 18. Current full-suite CI remains required; stopped cohorts are not polled again. Owned syscall wire adapters, actual owned CPL3 peers, fresh-buffer validation, reachable backend disposal-failure coverage, realm adoption, full authority/private-documentation closure and both complete EriX-in-EriX build generations remain open. The refreshed 76-repository inventory has 2,924 code files below 1,000 lines and 155 direct missing_docs crate-root gates; those checks do not close whole-codebase semantic audits. Owned invocation wire and native acceptance — 15 September 2026: Signed Kernel `5f497adaefa526108a0439e0e071717dddb85334`, shared IPC `de968da19898bef532ddb3b5974bb9562f51dee5`, capability ABI `a001a26f0eb3aebec3f5fd02a28d98f1bc23f8a0` and Integration `9030b217c490db6ad3ec60a799cb025eccbfcdb1` implement and exercise the immediate owned invocation boundary. The allocation-free shared codecs and shim preserve exact return metadata, including a retained draining owner on failed submission. The Kernel checks fresh complete user mappings and packet framing under one lifecycle guard before native effects. No user pointer or caller-selected identity is retained. Destination capacity and descriptive receipt capacity are independent; spare capacity acquires no authority and repeated collection cannot duplicate transfers. Existing numeric binding hints still recheck live capabilities on every use. The real three-process CPL3 scenario passes all eight operations, full-span pointer/rights/overflow/reserved-field rejection, actual returned selectors, payload/capability/origin checks, collection after server exit and repeated receipts. A second request rejects premature relinquishment, enters draining on caller release and retires only after the exact server acknowledgment. Current signed owned and unchanged older lifetime images are each 2,232,320 bytes, with SHA-256 `588c6097c57ebd2ed92e0f0b76f2b1ad6b82630b4a0da272ee98e218eb8e333d` and `8f9026aaefd2c5a745e35467ac01c71789c5f469f9cd42a477f87818747ee673` respectively. Both runs have clean teardown and empty QEMU stderr. Ordinary images contain neither diagnostic hook. Strict default/all development/release host, freestanding and rustdoc matrices pass: IPC 368 units, shim 20, capability ABI 191, Kernel 642/666 and Integration 320/321. Existing ignores remain one shim and three Kernel tests. All 162 maintained Integration helper commands pass; three prior correct concurrent-run lock refusals are retained and their sequential checks pass on unchanged executable inputs. Docs `46da7a4cb4d38a2bea5b5491a68f51f33e4b4305` publishes the normative register/packet contract and regenerates the three affected API references from original signed revisions. All 45 documentation tests pass. The complete 2,363-page manual has zero final warnings, 430,365 word boxes within page bounds and reviewed changed ABI/API pages. Shared IPC CI 337/338 and capability ABI CI 214/215 pass with eight complete warning-free logs. Both Kernel revisions pass CI 556/557 and 558/559 with eight complete warning-free logs. Those cohorts are stopped. Current Docs CI 867/868 passes at observation four; four complete logs total 758,328 bytes. Both 2,363-page manuals pass all 45 tests, report normal reference-pass warnings of 32/1/0, and finish with zero warnings or box diagnostics. Its cohort is stopped. Current full Integration 1621/1622 is waiting. Older full Integration 1613/1614 now passes all 486 catalog scenarios and later native/console probes, with six complete warning-free logs; its cohort is stopped. Older 1615/1616 is running, and 1617/1618 plus 1619/1620 are waiting. Current full-suite acceptance remains open, as does the intermittent quota cause in Integration issue 18. This checkpoint supersedes the earlier pending wire/CPL3/manual status. Reachable backend disposal-failure coverage, broader revocation/generation-reuse scenarios, producer adoption, realm runtime, complete authority/inline-documentation audits and both full EriX-in-EriX build generations remain open. The current inventory checks 76 repositories, 2,943 code files below 1,000 lines and 157 crate roots with direct missing_docs gates; it does not establish semantic audit closure. No complete guest build or guest performance result is claimed. Process-bound native acceptance — 15 September 2026: Signed Kernel `60da5858d7198185efd103f0e91e5ac2e0b63e67` implements control operation 52, checking the actual moved install grant against expected process/generation with exact rights, including zero, under existing endpoint policies. Signed Procd `f1105706cc19ed024a6cca79a29abc57c90c6661` uses this operation in its actual ordinary launch-description producer while retaining the narrow SEND receipt, pending state and exact failure cleanup. IPC `c453b697b8cdb9cc1c36f1ad89ff868648190025`, capability ABI `fe8d558253ad01301b99554e20d287c4ea35bb1d` and five aligned helper commits preserve original Git/type identity. Integration `58c925c564b69bebce8df6f3e75a9312824e18c4` passes the expanded lifetime CPL3 scenario with thirteen actual control calls, user-side reply checks, two staged children and full added-custody disposal. The corrected lifetime image SHA-256 is `8e6a9e8f68b90cc1ede61300958cec122b82a7c6dfd6318a51e40fefc7ba166e`; the unchanged owned-invocation scenario also passes with image SHA-256 `b76a380d3cd6b03b0ff61a3b626ace0667679920684ad7356a1c3a36e2224953`. Both have clean teardown and empty QEMU stderr. The initial fixture setup-order failure is retained and corrected in Kernel issue #14. All strict default/all development/release matrices pass: IPC 371, shim 20, capability ABI 191, Kernel 648/672 including standalone controls, Procd 227/232 including auxiliary binaries, and Integration 320/321 tests. Existing native-only ignores are unchanged. Procd passes forty native binary builds with repository linker scripts. All 162 Integration helpers pass after updating the exact policy assertion to require the new marker; its initial mismatch remains recorded. Docs `b0fcf0f43af2af741d520a0b1373cc346e08863c` updates the native wire/ownership contract, operation registry, Procd boundary and three generated shared APIs. All 45 tests and the complete 2,367-page manual pass, with zero final warnings, 431,138 word boxes within page bounds and four reviewed protocol/API pages. Current IPC 339/340, capability ABI 216/217, Kernel 560/561 and 562/563, Procd 266/267, Docs 869/870 and all five helper push/review CIs pass with complete classified logs and no final warnings. Those component cohorts are stopped. Current full Integration 1623/1624 waits at observation 01. Older full Integration 1615/1616 is running at observation 11; 1617/1618, 1619/1620 and 1621/1622 wait at observations 09, 07 and 04. No pending full suite is counted as passed. Typed realm bootstrap, mediator startup/readiness/configuration/seal, complete consumer image adoption, fair terminal/provider retirement, broader native disposal failures and both full EriX-in-EriX build generations remain open. The new inventory covers 76 repositories, 2,950 code files below 1,000 lines and 158 direct missing_docs crate-root gates; complete inline documentation and whole-codebase authority closure remain open. Prior performance measurements retain their original signed source identities; this checkpoint claims no new timing or guest performance result. ## Tracking and rollout Current Integration `4b65755f1f2774798d4a909212db4e64c0349b86` finishes with failed [push CI 1603](https://git.erikinkinen.fi/erix/integration/actions/runs/1603) and [PR CI 1604](https://git.erikinkinen.fi/erix/integration/actions/runs/1604). Each complete catalog reports 54 passes and 432 failures out of 486 scenarios. Six full terminal logs total 14,427,322 bytes, with no warning candidates. Both Rust and Markdown jobs pass. The later isolated native diagnostic, canonical images and terminal modes are not reached by these runs. [Issue 50](https://git.erikinkinen.fi/erix/integration/issues/50) tracks the observed shared-compiler regression: valid dependency-qualified Rootd selections are rejected as unknown local features. A minimal original-manifest check confirms the failure. The correction separates compiler cfg ownership and adds direct, transitive, malformed and real-compiler coverage; its full local checks are underway. Original failures remain retained, and these terminal runs are not being replayed unchanged. Earlier isolated native VM acceptance retains its separate exact source and artifact scope. Signed Integration `4b65755f1f2774798d4a909212db4e64c0349b86` adds the isolated native lifetime scenario and corrects standalone kernel service selection, target-scoped cache identity and original-manifest feature closure. The redundant feature implication table is removed and the shared resolver joins the builder fingerprint. The normal component catalog remains independently selected. The strict development/release default/all-feature Rust matrix passes 320/321 units, doctests, private rustdoc and freestanding builds; missing documentation remains denied. All 159 helper suites are accepted across the complete run and justified follow-ups: installed filesystem-tool routes and actual stage tracing, serialization after the real VM releases the global scenario lock, and declaration of the compiler fixture's selected feature. Original failures and actual statuses remain retained; assertions and production deadlines are unchanged. The actual native VM passes both ordered unique markers, expected exit and forbidden-marker checks using signed Kernel `03e13a784bde08914864267a4e2a6324a22d05c7` and Bootloader `e7fa39357a38c21529cccfd16cf3446eb07e8aa5`. The 2,142,208-byte image has SHA256 `4f021a40264739fef4979da2b0cd4647bde3f76b9dada6816aba6faa3594a797`; QEMU stderr is empty. Complete preparation and execution takes 19.20 seconds under the unchanged 60/45-second VM limits, not a guest performance measurement. Kernel CI 528/529 and Bootloader CI 135/136 are green. Integration CI 1603/1604 is running; older suite and complete current-head acceptance remain pending. Realm adoption and both full guest build generations are unproved. - Parent work: https://git.erikinkinen.fi/erix/integration/issues/2 and https://git.erikinkinen.fi/erix/docs/issues/1. - Branch: `feature/posix-compat`; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages. - Baseline revision: `c86c0d89e51ed9818d62afa799d358768646c953`; refresh component/dependency heads and their own CI evidence as implementation advances. - Cross-repository dependencies remain full lowercase commit hashes; update the selected graph deliberately. This issue does not authorize merges, release tags or replacement of published images. Original acknowledged service catalog — 21 September 2026: Signed [dff878dd3545c4751b3c05d37b2bdd5e21cce548](https://git.erikinkinen.fi/erix/integration/commit/dff878dd3545c4751b3c05d37b2bdd5e21cce548) selects the original terminal-observation, exact-acknowledgement and final CPU dependency graph in both complete catalogs. All 35 application/service checkpoints are signed; the bounded VFS checker correction and its manual are included. Clean original checkouts pass manifest/catalog equality and signature checks. Exsh's release compiler and complete frame gates remain explicitly open in [issue 9](https://git.erikinkinen.fi/erix/exsh/issues/9) and [issue 4](https://git.erikinkinen.fi/erix/exsh/issues/4). All 169 maintained helper commands pass with recorded source and stream identities. The original stale memory-source rejection, quiet storage-fixture timeout and overly long socket-fixture path remain retained. Their respective corrected inputs use the explicitly verified original memory checkout, the previously maintained traced disk invocation (258.975743 seconds under unchanged 600/120 bounds), and a fresh owned shorter temporary directory (all 14 socket controls pass without changing the Unix pathname limit). None of these setup corrections changes test sources or bypasses source, timing or cleanup checks. The unchanged orchestration library retains all four strict 320/321-test configurations; formatting, policies and Markdown pass without warnings. The published runner and original full source graph are prepared for the maintained shell CPU-accounting, two-CPU inspection and out-of-session denial scenarios. Actual VM evidence remains pending and no full guest-build acceptance is awarded. Original CI [1703](https://git.erikinkinen.fi/erix/integration/actions/runs/1703)/[1704](https://git.erikinkinen.fi/erix/integration/actions/runs/1704) is being monitored without restart. Complete authority/source/effect/frame and Pagerd gates, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Actual service CPU scenarios and startup admission — 21 September 2026: The published original Integration catalog `dff878dd3545c4751b3c05d37b2bdd5e21cce548` passes the maintained shell times, two-CPU Extop and out-of-session denial VM scenarios under their unchanged 120-second guest limits. Each retains 106 hashed evidence files, warning-free image builds, empty QEMU stderr and every required, forbidden, ordered and unique marker check. Build-plus-scenario wall times are 119.876978, 34.802620 and 36.173027 seconds respectively; these are not guest-only or startup measurements. Times reports nonzero self and waited-child CPU. Extop observes both CPUs, memory and increasing job CPU nanoseconds with `CTRL no`; both per-CPU percentages remain `--.--%` in the two samples, so numeric utilization is unproven. The denial scenario confirms the existing out-of-session boundary. Complete mediator/lifecycle acceptance in [Procd 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open. A separate ordinary development package also builds without warnings, but its required startup-contract preflight exits 1 before any VM or observer starts. [Integration 69](https://git.erikinkinen.fi/erix/integration/issues/69) records the missing full-runtime-transition contract selections and Kernel effective-feature/original-source evidence. Preserve the refused package and all admission controls; the 120/15/10 capture limits and performance thresholds are unchanged. No startup-profile acceptance is awarded. Complete source/effect/frame and Pagerd proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required by [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Signed startup source/feature correction — 21 September 2026: Integration [fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa](https://git.erikinkinen.fi/erix/integration/commit/fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa) requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure. All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; [bug 71](https://git.erikinkinen.fi/erix/integration/issues/71) retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices. The technical manual update [76672dff8ff83](https://git.erikinkinen.fi/erix/docs/commit/76672dff8ff83b04914abe3c8f4b08b13835144f) passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs [1001](https://git.erikinkinen.fi/erix/docs/actions/runs/1001)/[1002](https://git.erikinkinen.fi/erix/docs/actions/runs/1002) passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow. A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under [bug 69](https://git.erikinkinen.fi/erix/integration/issues/69); no threshold or 120/15/10 capture limit changes. Original Integration [1705](https://git.erikinkinen.fi/erix/integration/actions/runs/1705)/[1706](https://git.erikinkinen.fi/erix/integration/actions/runs/1706) is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory. Actual original-source startup capture — 21 September 2026: Signed Integration [fd8a5cf0dbcf](https://git.erikinkinen.fi/erix/integration/commit/fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa) builds the ordinary image without warnings and its actual Kernel-bound contract passes preflight. The VM and complete observer finish with all required stages, zero dropped records, empty QEMU stderr, successful cleanup and unchanged source image. Admission bug 69 is resolved independently of performance. The strict timing gate fails: root-to-final readiness 5.974133160 seconds (limit 5), largest service interval 3.098663889 (limit 1), final readiness to caret 1.262470092 (limit 1), and four native commands 4.769234506 (limit 2). The maintained offline profiler identifies RTC-provider to TTYD as the largest service interval, followed by roughly one-second Powerboxd and Launchd intervals. These are host observation windows, not loader-only causal measurements. [The new canonical timing bug](https://git.erikinkinen.fi/erix/integration/issues/72) retains the exact image, timing and command identities and every original limit. Host/toolchain description fields remain explicitly incomplete; no provenance or speedup is invented. The sixteen helper stream-custody corrections also pass all changed controls; all 171 selected helper commands have successful warning-free final evidence. Bug 71 is resolved with its original 36 warnings retained. Full CI for 1705/1706 remains separately monitored. No startup-performance or full native toolchain/EriX guest-build acceptance is awarded. Coherent scalar-consumer validation — 21 September 2026: signed [Integration 07c883525ee5](https://git.erikinkinen.fi/erix/integration/commit/07c883525ee5e23378008232760d045f74f60d32) selects [Procd 59ee30a88534](https://git.erikinkinen.fi/erix/procd/commit/59ee30a885346db4db8c8791a23c15694f2a90a8) in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven. Procd's four strict 308/314-test configurations and original CI 302/303 pass. The [manual update](https://git.erikinkinen.fi/erix/docs/commit/2d05169e6974a495eab80b62edf0f23d1ad667da) passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines. Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.
erikinkinen changed title from [FEATURE] [P02.R23] Audit authority, code quality and documentation in integration to [FEATURE] Audit authority, code quality and documentation in integration 2026-09-12 08:02:20 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
erix/integration#11
No description provided.