WIP: Coordinate native authority, shell workspace and source transport #12

Draft
erikinkinen wants to merge 104 commits from feature/posix-compat into main
Owner

Summary and rationale

Executable and shared-library builders use one documented compiler metadata consistency policy and crate-name mapping. Inherited, direct and internal-alias inputs must agree for each compiler-visible destination. Identical repetitions preserve the earlier file; exclusive creation prevents replacement of a newly appearing destination. Both artifact cache identities include the shared policy.

Shared dynamic linking selects one available driver, validates compiler-host discovery when needed, preserves driver aliases and successful diagnostics, and treats warnings as errors. A selected driver failure cannot execute another implementation or admit partial output. Standalone links avoid unnecessary compiler queries.

Fresh Kernel, Rootd and service links now require an unambiguous Rust runtime archive for each requested role; timestamps no longer select a provider. The shared selector rejects missing, ambiguous and non-file candidates. This addresses the bounded final-link defect in #62. Complete compiler provenance, cache coverage and concurrent toolchain lifetime remain separate obligations.

Coordinate exact-source image construction and native authority regression
coverage. The diagnostic catalog selects signed Kernel
829b949dd591bb82e6cac0fcbb47fdd1d6346cbd; four standard-wrapper scenarios cover
owned invocation, lifetime retirement, UD2 direction and hardware double-fault
entry. The two exception profiles observe the actual pre-prologue callee stack.

Source preparation preserves original Git objects, rejects shallow transport
shortcuts, and binds complete native companion inputs into provenance and cache
identity. Standalone manifest construction uses the selected catalog. Shell
workspace production derives ordinary and emergency storage from the version-22
target layout; coordinated ordinary-image catalog adoption remains unfinished.

Tracking and scope

The Phase 6 master completion checklist tracks all 460 acceptance items, including supplementary requirements, section weights, current acceptance, owning issues and PRs. Update it alongside this record whenever scope, accepted evidence, regressions or CI disposition changes. Current accepted completion is 15 items, 3.48% weighted; both complete builds inside EriX remain required.

Signed head 56e035d46a11dc803d654bf2151e484fab307682, branch feature/posix-compat.
Owning issue #1; Kernel mechanism,
shell review,
Procd bootstrap, and
realm design.
The isolated catalog-packaging defect in #59 is closed. Older full-suite layout
failures (#57), storage timeouts (#18), companion adoption (#52) and the
accelerator-specific preboot observation (#60) retain their own acceptance gates.

Architecture, authority and failure behavior

Catalog names, manifests and descriptive identities do not confer capabilities.
Diagnostic inputs retain explicit component revisions, source membership,
artifact digests and bounded child-process ownership. Native oracles check
actual process-bound grant custody, endpoint attenuation, caller identity,
disposal and preservation of private user state. Negative scenarios retain
their exact fatal exit, marker requirements and sixty-second deadline.

Ordinary and emergency shell workspace slices have separate ownership and
authenticated layout contracts. Reject missing or stale producer evidence
before packaging. Profiling records measured host scopes and real timeout or
cleanup outcomes; it does not establish guest performance or full-build success.
Typed grant return, guarded bootstrap, mediator execution, complete semantic
authority/source/frame audits and both complete guest build generations remain
open. The ordinary runtime selection has not adopted the diagnostic graph.

Validation evidence

Original coherent-graph CI classification — 19 September 2026: CI 1669 records 485 passes/1 failure; CI 1670 records 484 passes/2 failures, each across all 486 scenarios at 8b1c037aed2503e1f2a4b17c8a8be0666d62a305. Both retain the original 120-second ext4 quota timeout in bug 18; the latter also fails physical input observation in the exact-selector race scenario, now bug 64. That scenario explicitly passes in the paired run. All six terminal logs are complete (27,557,577 bytes), with no warning candidates; Rust and Markdown pass. No incompatible shell-layout refusal remains. The layout issue’s full source/frame prerequisites and later native-image gates remain unproved. Neither workflow was rerun, and no deadline or admission check was relaxed.

Explicit zero-realm startup acceptance — 19 September 2026: Signed Integration c479813423fb71c606fa30e5cf7d4dfb16f557d0 adds the bounded startup scenario using the existing explicit standard CLI policy. The actual VM passes the unchanged 120-second ceiling and ordered readiness checks; its signed image contains zero realm capacity in the exact 72-byte version-3 record, matching the version-6 native arena of 3,104,768 bytes. Eight route/capacity controls and four strict 320/321-unit Rust configurations pass, including fmt, host/native Clippy, native builds and private rustdoc. The original 169-helper run retains one physical-directory fixture timeout. The fixture now selects the probe’s existing ten-second command budget and has deterministic expiry controls; all four affected suites pass (9, 5, 5 and 7 tests), with unaffected source bytes verified unchanged. The original failure remains in bug 63. Build and validation streams contain no warnings. Original CI 1671/1672 is running. This proves ordinary startup with admission disabled; complete realm execution, source/effect/frame admission and both full builds inside EriX remain required.

Coherent startup consumer acceptance — 18 September 2026: Signed Integration 8b1c037aed2503e1f2a4b17c8a8be0666d62a305 adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required.

Original realm contract library prerequisite — 18 September 2026: Signed ad85421257b7d964845fd4b84931966ad36cc122 selects the original bootstrap, capability and IPC revisions in Rootd orchestration. Only the Cargo dependency selection is published; Rust implementation and image policy remain unchanged in this commit. Four strict default/all development/release configurations pass 320/321 tests, host/native Clippy, native builds, formatting and private rustdoc without warnings. Compiler inputs contain no unpublished image-consumer changes. CI 1667 and CI 1668 are queued. Rootd can now pin this real original prerequisite before coordinated startup/image publication. Consumer VMs and both complete builds inside EriX remain required. Older CI 1663/1664 remains failed with 78 known layout refusals and one quota timeout per run; existing issues #57 and #18 retain the complete original evidence.

Explicit owned receiver admission acceptance — 18 September 2026: Signed 435e69a9840b37108529e5f9f9915937a12bafc9. The isolated native catalog selects the signed receiver-budget Kernel and coherent dependencies. All 169 helpers, four strict 320/321-unit Rust matrices and both actual native VMs pass without warnings. The owned scenario requires the receiver-admission marker before its final ownership marker; all prior lifetime and ordinary source/effect/frame gates remain intact. The existing profiler validates 48 current-source native sample processes. Costs still grow with retained populations and remain follow-up work. The changed registration fixture has a different workload hash, so no cross-source speedup comparison is admitted. Direct-native timings do not measure the separately removed packet descriptor allocation. Original CI is under observation. Actual owned Procd/Launchd service adoption, consumer VM execution, complete realm fairness/readiness/sealing and both full builds inside EriX remain open.

Caller-local grant relocation checkpoint — 18 September 2026: Signed 8e66e54c86d93f257b6051da0381ff8cdc84fe2f selects Kernel 56d398e077c140c58e23f9cc2d8b79f19bc4cc2f and its coherent signed shared dependencies for the isolated native diagnostics. All 169 helpers, four strict 320/321-unit Rust matrices, formatting, strict Clippy, rustdoc and both actual native VMs pass without warnings. The lifetime scenario requires thirty-nine additional real CPL3 relocation controls before the original installation, revocation, terminal, inventory, queue and page oracles, with the original 60-second bound. Packaged artifacts reproduce the build outputs and all fifteen original component signatures are verified. Original CI 1663/1664 is waiting. Ordinary service source/effect and frame admission, actual owned consumer execution and both full guest builds remain separate open gates.

Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision 4d4628f565d7102e6ef2987e4085fd8d97d247d3 is pushed. All 169 helpers and four strict 320/321-unit Rust matrices pass. Both actual 60-second native scenarios pass, including nineteen new CPL3 cleanup calls and the mandatory GENERATION_CLEANUP_OK marker. All earlier lifetime oracles remain required, and normally stripped packaged Kernels match their original builds. Both original CI 1661/1662 runs remain under observation. The ordinary service catalog is unchanged; ordinary source/effect/frame admission remains open. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open.

Coordinated terminal observation checkpoint — 17 September 2026: Signed revision 0db8a679f5d1acb50d9ff92e003cec91f145dfc8 is pushed. The isolated catalog selects the signed generation-bearing Kernel graph. Both original 60-second native gates pass with reviewed unstripped/packaged artifacts and fifteen clean component checkouts. Four strict Rust configurations and all 169 helper commands pass; the old marker assertion was corrected to require the added generation marker. Rootd orchestration selects the same immutable shared revisions. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.

Original archive-head CI 1653/1654 is fully classified with 406/486 passing in each run; layout and filesystem timeout failures remain in #18, #20 and #57. The bounded archive-selection repair #62 is closed on its specific evidence. Current CI 1659/1660 remains under observation without restarts.

  • Four standard-wrapper native scenarios pass on the selected signed Kernel,
    with warning-free images, unchanged deadlines and exact original source
    selections. UD2 and double-fault reports contain five and six hardware words.
  • The 166-helper suite and four strict Rust development/release matrices
    (320 default / 321 all-feature tests) cover unchanged helper and Rust sources;
    affected scenario, wrapper, catalog and policy checks pass on this checkpoint.
    Formatting, strict Clippy, private rustdoc and Markdown checks pass.
  • Current-head automatic CI is pending. Earlier original runs
    1647,
    1648,
    1649 and
    1650 are fully
    classified: twelve complete logs, 52,533,051 bytes, zero warnings; all
    Rust/Markdown jobs pass. Three suites pass 408/486 with the same 78 known
    layout refusals; run 1647 passes 407/486 and also repeats the known quota
    timeout. Every full suite remains failed; no new failure set is observed.
  • The older automatic-KVM int8 run stalls before an EriX marker. A single
    explicit-TCG control passes with identical Kernel ELF bytes and unchanged
    deadlines; it does not replace the failed configuration (#60).
  • Selected Kernel push CI 582 passes; PR CI 583 fails a host receive fixture,
    tracked in Kernel #6.
    No unchanged failed workflow or VM has been restarted for this checkpoint.

Original CI reconciliation — 17 September 2026: CI 1651/1652 at
fa86d1b64f8e1299c0ee0c886e6f1b35d58ea15b retains full-catalog failure.
All six logs are complete, 27,230,062 bytes, zero warnings; Rust/Markdown pass.
Both runs retain 78 layout refusals and the quota timeout. PR CI 1652 also
retains the named idle-time-resolution timeout in #61, while original
push CI 1651 passes that scenario. Totals are 407/79 and 406/80 of 486.
No unchanged retry, increased deadline or accepted full guest build is claimed.

Runtime archive checkpoint — 17 September 2026, signed 77921a7d97874e3f44aae66ae9bef6e6196af2f5: Eight selector controls pass, including four original refusal subcases that fail against the predecessor. All 167 helper commands and four strict Rust configurations pass (320 default/321 all-feature tests), with formatting, Clippy, freestanding builds and private rustdoc. Both original 60-second native invocation/lifetime scenarios pass; their Kernel bytes match the earlier signed diagnostics. A separate retained-graph host package performs 38 fresh native links and reproduces its original Kernel ELF before and after stripping. These are host builds and bounded native regressions, not a complete guest build. Original automatic CI monitoring is pending; no earlier failed workflow is restarted.

Linker selection checkpoint — 17 September 2026, signed bc0e67f927ded76dd3ff5790180a7bded0886885: Thirteen focused controls pass, including real bundled-LLD linking and warning refusal. All 168 helper commands, four strict 320/321-unit configurations, freestanding builds, formatting, Clippy and private rustdoc pass. Both original 60-second native VMs pass and preserve earlier signed Kernel bytes. A retained older graph packages through 38 fresh native links with fatal linker warnings and reproduces its original Kernel ELF. An interleaved host cProfile comparison retains twelve identical shared ELFs and verifies elimination of one compiler query per standalone link; no guest or whole-build speedup is claimed. Original automatic CI remains pending. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.

Compiler metadata checkpoint — 17 September 2026, signed 56e035d46a11dc803d654bf2151e484fab307682: Fourteen focused controls and all 169 helper commands pass, including actual cache-key mutation coverage. Four strict 320/321-unit configurations, freestanding builds, formatting, Clippy and private rustdoc pass. Both original 60-second native VMs pass with unchanged signed diagnostic Kernel bytes. A retained older graph packages through 38 fresh native links and reproduces its original Kernel and six provider metadata/shared-object pairs. That host diagnostic retains the older deployment adapters with only the new cache-input declaration; complete current adapters have separate helper and native VM coverage. Earlier incomplete/mismatched diagnostic overlays remain recorded failures. Original automatic CI remains pending. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open.

Original Integration catalog completion — 18 September 2026: At exact revision 0db8a679f5d1acb50d9ff92e003cec91f145dfc8, CI 1659 finishes with 396 passes and 90 failures out of 486; CI 1660 finishes with 393 passes and 93 failures. Each retains the 78 known Exsh layout refusals. The remaining 12 and 15 failures are original 120-second QEMU storage-scenario timeouts. All six terminal logs are complete (36,570,659 bytes), with zero warning candidates. Rust/unit and Markdown jobs pass. No workflow was restarted, no deadline was enlarged and no failed scenario is accepted. A shared guest or host cause is unestablished.

Original generation-cleanup catalog completion — 18 September 2026: At exact revision 4d4628f565d7102e6ef2987e4085fd8d97d247d3, CI 1661 and CI 1662 each finish with 408 passes and 78 failures out of 486. The exact failed set is the 78 known Exsh layout refusals. There are no storage timeout failures in these two observations; earlier timeout failures remain unresolved. All six terminal logs are complete (26,074,278 bytes), with zero warning candidates. Rust/unit and Markdown jobs pass. No workflow was restarted, no deadline was enlarged and no failed scenario is accepted.

Review checklist

  • Signed original source selection, canonical commit format and exact artifacts.
  • Applicable strict checks, bounded diagnostics and current documentation.
  • Inline contracts and changed code files below 1,000 lines.
  • Complete current-head CI and remaining ordinary-image regressions.
  • Finish coordinated runtime adoption and whole-codebase authority audits.
  • Demonstrate both complete EriX builds inside EriX before readiness.

Native diagnostic observation — 19 September 2026: the first actual caller VM fails before its required success marker. Exsh exits 0xe5, Rootd exits 0xdc and the unchanged progress watchdog stops QEMU. Integration issue 66 records exact reproduction and retained appliance/log identities. All 169 Integration helpers and four strict Rust configurations pass; this does not establish native execution. Request/error telemetry through the existing stdout route is under validation. No cause, weakened gate or completion credit is inferred.

Signed reproducer — 19 September 2026: Integration 76411ed6d96356b20ee0a4c21ad219dacc56340d publishes the explicit scenario and selector. With the documented image signing inputs, run bash scripts/run-scenario.sh tests/scenarios/appliance-disk-image-realm-admission-positive.toml components.toml. The original failed runtime uses the same scenario, implementation and component graph; only roadmap status changed after validation. Its VM result remains FAIL. All 169 helpers and four strict Rust configurations pass without warnings. Original CI 1673 and 1674 are queued. Issue 66 retains the failure. No acceptance credit or complete realm execution is claimed.

Original CI observation — 19 September 2026: CI 1671 finishes with 471 passes/16 failures and CI 1672 with 465 passes/22 failures across all 487 scenarios at c479813423fb71c606fa30e5cf7d4dfb16f557d0. Every failed scenario is an ext3/ext4 positive filesystem case reporting error: qemu timed out after 120s, with scenario status 1. The existing filesystem deadline report retains the expanded matrix; quota issue 18 applies to the quota failure in 1672. All six complete logs are hashed (41,592,478 bytes), with zero warning candidates. Rust, Markdown and the full helper step pass. The zero-realm startup and exact-selector race scenarios explicitly pass in both runs. No common cause, source regression boundary or performance diagnosis is inferred; all actual deadlines and failure statuses remain unchanged, and neither workflow was rerun.

Corrected native caller VM — 19 September 2026: signed Integration 9139c6c5fa38c139e92520f6d410626b4cf1e4aa selects Launchd ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6, Exsh 9c0f7ab851d527dd9dd10161d6a98e1fdc14598e and Docs ce8a1538ab2220f1b346e1a051265f58f83f47fc. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one ERIX_EXSH:REALM_ADMISSION:VERIFIED precedes ERIX_ROOTD:INITIAL_EXSH:EXITED_OK. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present.

All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7; the post-VM writable disk has SHA256 8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in issue 66.

The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original Integration CI 1675 and 1676 are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item.

Native guarded preparation — 19 September 2026: signed Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c selects signed Exsh ffe50612889dd58a45a40d04593a4aa3a3ffa512 for the separate appliance-disk-image-realm-preparation-positive scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects bin/true inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.

Exactly one admission marker and one ERIX_EXSH:REALM_PREPARATION:VERIFIED precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is 7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff (55,776 bytes); post-VM writable disk SHA256 is 3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.

All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.

Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.

Original guarded-preparation CI — 19 September 2026: Exsh run 271 and 272, for signed ffe50612889dd58a45a40d04593a4aa3a3ffa512, both fail the required complete frame proof. All 976 Rust tests and 355 checker controls pass. Four complete hashed logs total 320,166 bytes without warnings; Markdown passes. Each original workflow reports four complete workspace mappings and incomplete runtime/all frame observations (101/68 unresolved). These actual CI observations are distinct from the local eight-configuration frame observations. The passing guarded-stage VM does not waive this failure. No workflow was rerun or cancelled to obtain acceptance.

Guarded-custody documentation reconciliation — 19 September 2026: signed Posixd PR 5, 9b031a8c2f996491a322046a4f2acd5dacdc55c2, replaces stale grant-return and proposed-custody gaps with the implemented producer boundary. Procd uses the actual returned grant to attenuate the initial endpoint to RECV before execution, removes bypass sources, and retains nested custody beneath Kernel lifetime custody. A later mediator disposal report cannot prove absence of bypass senders. Exact staged abort and the remaining counted startup, readiness, configuration, sealing, client I/O and running-realm retirement requirements are distinguished. This repository still has no Posixd executable.

Markdown, canonical headings/governance, local links, original source anchors and whitespace checks pass. Original Posixd CI 17 and 18 both pass from two complete hashed logs totaling 7,232 bytes without warnings. Rust checks do not apply to this documentation-only repository.

Signed Docs PR 4, 7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d, removes the matching stale passages from the process-services manual. All 45 tests and the full 2,419-page manual pass. All 445,847 word boxes lie within page bounds; the actual changed paragraphs and continuation on pages 222, 226 and 227 are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original Docs CI 977 and 978 are running. These documentation corrections add no runtime behavior; the previously retained Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c appliance retains its original source selection and passing guarded-preparation evidence. Native upstream Rust/LLVM rebuilding and both complete EriX builds remain required.

Process-start census correction — 19 September 2026: signed Kernel b762e19d0c16acd605d0f6123994a586cc6fcde1 requires a successful install-grant absence census before process start. An unavailable census returns the existing refusal and preserves the whole staged child and grant state. Hosted controls cover unavailable census, actual grant disposal and malformed-target precedence. Normal bootstrap initializes tracking before admission; production reachability of the injected condition or a native authority escape is not established. Kernel issue 18 uses the canonical bug report and records the original failure and bounded correction.

Four strict Kernel matrices pass 704/728 library tests and two standalone controls each; three existing ignored tests remain ignored. Formatting, strict host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass. Original Kernel CI 606 and 607 pass from all four complete hashed logs (739,843 bytes), without warnings.

Signed Integration b65183ddb93eb4396d4140a002c3727fec42ff87 selects that Kernel and the reconciled Docs 7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d, preserving all other catalog entries and all previously checked orchestration bytes. The matching guarded-preparation VM passes both unique markers and ordinary successful shell exit under unchanged 120-second hard and 45-second progress limits. All 106 artifacts, all 73 original component identities and the actual signed image are verified without warnings. Serial SHA256: a373a8ccd81ac3efbaa492cbf2e1f991f3cc34dcbf23a1435c1c48cd75cd5c1c (55,776 bytes); signed boot-image SHA256: 3b88d37183cf36dcbd5f1105cc0fd86e79aa4489d311300003f3f362c24bcd0a. This remains an unstarted staging fixture. Normal native execution does not exercise the hosted unavailable-census condition.

The prior complete 169-helper/four-matrix Integration evidence is verified against unchanged implementation bytes. Focused catalog/source checks pass, including 46 immutable-source and five tool-selection tests. An initial host fixture failure caused by disabling its deliberate Git replacement setup is retained; the established helper environment passes without altering product checks. The static census covers 3,127 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 170 direct missing_docs gates and 92 conventional crate roots; complete semantic authority and private-documentation closure remain open.

Original Integration CI 1679 and 1680 are queued. Earlier 1677/1678 remains queued and 1675/1676 is running. No unchanged workflow is rerun or cancelled. Complete mediator execution, full source/effect/frame proof, upstream Rust/LLVM rebuilding and both full EriX build generations inside EriX remain required. No whole acceptance item is newly completed.

Shared native terminal transition — 19 September 2026: signed Kernel 37d9c74d6d1209729c520a52a274c1646efe225c consolidates exit and kill event reservation, lifetime preflight, exact-generation commit and receiver/invocation retirement into one documented implementation. Existing public behavior and root exit cleanup remain unchanged. Terminal state and actual resource destruction stay separate. This completes the terminal-refactor prerequisite in child lifetime design #19; it introduces no lifetime binding, new opcode or additional authority.

Four strict Kernel matrices pass 704/728 library tests and both standalone controls, with three existing ignored tests unchanged. All thirteen native build/Clippy profiles, formatting, host/native Clippy and private rustdoc pass without warnings. Original Kernel CI 608 and 609 pass from all four complete hashed logs (739,870 bytes), without warnings.

Signed Integration a62d1381f56a01afc692112d9b427205eaeb6a2e updates both full Kernel selectors and five stale native diagnostic selectors while preserving source memberships and tested orchestration bytes. Both maintained native runners pass their original 60-second scenarios: lifetime revocation and owned invocation. Complete serial logs are retained (1,807 and 1,587 bytes), QEMU stderr is empty, and build warnings are absent. Packaged Kernel bytes match retained unstripped artifacts; all fifteen exact original component trees and signatures verify. Four current strict 320/321-test Integration matrices, native builds, formatting, host/native Clippy and private rustdoc pass. Seven focused source/native-policy checks pass; the complete 169-helper evidence remains hash-bound to unchanged implementation bytes.

Original Integration CI 1681 and 1682 are queued; older corrected 1675/1676 remains running. The static census covers 3,128 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 170 direct missing_docs gates and 92 conventional roots. Full semantic authority and private rustdoc closure remain open. Native child-lifetime custody, running mediator lifecycle, full frame proof, upstream Rust/LLVM rebuilding and both full EriX build generations inside EriX remain required. No whole phase acceptance item is added.

Original corrected-source CI checkpoint — 19 September 2026: at signed Integration 9139c6c5fa, original push CI 1675 passes all 488 VM scenarios. Original PR CI 1676 passes 487/488 and fails only subsystem-e2fs-fat-ext3-htree-positive at the unchanged 120-second QEMU limit. Both pass appliance-disk-image-realm-admission-positive; both Rust and Markdown jobs pass. Six complete hashed logs contain 27,276,890 bytes and no warnings. No rerun or cancellation supplies either result. The ext3 timeout remains tracked in issue 20; its cause is not inferred from the passing sibling run. The private script-route admission defect is corrected and natively demonstrated, while full realm lifecycle, complete frame proof and guest builds remain open.

Native child lifetime checkpoint — 19 September 2026: signed Kernel 1428885e6d27e8e2bcefbbf68caf22ece253aac9 implements operation 58 using the actual Running caller, an exact Created child, independent Process authority and its real local install grant. It consumes only that grant, reserves cohort events before terminal effects, stops descendants before their supervisor and retains each bound child's cleanup duty and first failure independently of userspace survival. Return-boundary disposal closes outgoing accounting and respects current/active-interval protection. Fourteen new real-object controls cover refusals, rollback, nested stopping, a 257-descendant tree, late preflight failure, exact reuse and failed explicit abort after unlinking. Four strict 718/742-test configurations and both standalone controls pass; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Original Kernel CI 610 and 611 pass from four complete hashed logs, 751,929 bytes, without warnings.

The matching maintained lifetime VM passes its original 60-second scenario with the additional ERIX_KERNEL:CHILD_LIFETIME_OK marker. A real CPL3 supervisor proves ChildPopulate refusal, malformed/generation refusal, actual Process-route binding, start and exit. An independent observer verifies both exact children, CSpaces and mappings absent before terminal-event consumption, then disposes the unbound supervisor. The runnable child has a faulting sentinel and intentionally does not execute. All sixteen additional mapped pages are disposed. The original owned-invocation VM also passes its unchanged scenario. Complete serial logs contain 1,838 and 1,587 bytes; QEMU stderr is empty and build warnings are absent. Packaged Kernel bytes match retained original unstripped artifacts and all fifteen selected component signatures verify. Lifetime serial SHA256 is 012b46541b7c1c89d954cdbebda855037152a4e39ffad20ad7bdcc8c7b5c2572.

This establishes explicit native supervision with actual caller-side CPL3 evidence. Executing-child, no-successor native idle, allocation/partial-effect failure coverage, Procd adoption, running-mediator failure, provider completion, complete source/effect/frame proof, upstream Rust/LLVM rebuilding and both full EriX-in-EriX generations remain open. Host idle controls do not establish native interrupt or wakeup behavior. No whole phase acceptance leaf is added.

Signed Docs 9ca5a5e811766a4506c0626cd58f8e228d0bacf8 updates the technical manual's native admission, preflight, stopping, partial cleanup and safe return/idle contracts. All 45 tests and the complete 2,425-page manual pass with zero final warnings. All 447,213 word boxes are in bounds and all three changed contract pages are visually reviewed. Shared API reference source is unchanged. Original Docs CI 981 and 982 pass from four complete hashed logs, 773,510 bytes. Both pass 45 tests and the complete 2,425-page manual. TeX pass warning counts are 36/1/0, with zero final-pass warnings; neither workflow was rerun or cancelled.

Signed Integration 581226ab54 selects the coherent original Kernel/lib-capabi/lib-ipc graph and updated manual. All four current strict 320/321-test configurations, four native builds, fmt, strict host/native Clippy and private rustdoc pass without warnings. Source and updated native-policy checks pass; the full 169-helper evidence remains bound to unchanged orchestration bytes. The final post-VM changes select only the newer Docs revision and update roadmap status; native source catalog, scenario, runtime and orchestration bytes are unchanged. Original Integration CI 1683 and 1684 are queued.

Executing-child and terminal-reply checkpoint — 19 September 2026: signed Kernel dd9eace5 validates actual CPL3 nested-child execution and current-child ancestor termination. Synchronous control dispatch now ends its request borrow before effects and checks original caller identity, generation and terminal state before any response write. It keeps terminal completion in Kernel-owned result registers with zero reply length; ordinary native return switches away. A surviving caller retains its normal encoded response. Two focused actual-object regressions cover terminal request preservation and the surviving-caller reply. The dispatcher is split from the tracing/policy file. A supervisor binds and starts a child; that child binds a staged grandchild and kills its supervisor through its own explicit Process SEND route. Read-only witnesses require terminal caller storage to survive dispatch, then exact child/grandchild absence before the independent observer reads child-before-supervisor events. Both terminal payloads have immediate UD2 sentinels. An unrelated Created process retains its exact record, empty capability inventory and mappings until explicitly aborted. All four additional lifetimes and twenty-two mapped pages must be disposed for ERIX_KERNEL:CHILD_EXECUTION_OK.

Four strict Kernel configurations pass 720/744 library tests and both standalone controls; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Signed Integration c14c5a61 requires the additional marker while preserving every earlier marker and the original 60-second limit. Both actual native scenarios pass, with 1,870/1,587 complete serial bytes, empty QEMU stderr and no build warnings. Packaged Kernel bytes equal retained original artifacts after normal stripping; all fifteen original source signatures verify. Lifetime serial SHA256 is 1b2f983239efca55c8bc0f6f08ee91cfdcd37d4d1f6951bbd740e4d9b45d1a2f. Four current Integration 320/321-test configurations, native builds, strict Clippy, formatting, private rustdoc and updated policy checks pass. Earlier 169-helper evidence is hash-verified against unchanged orchestration; it was not rerun for these scenario/catalog changes.

Signed Docs b4b01d87 documents the executing-child observations and remaining limits. All 45 tests, the full 2,425-page manual, 447,382 word bounds and visual review of the changed pages pass, with zero final warnings. The API reference source is unchanged.

This extends native executing-child evidence; it does not establish no-successor native idle/wake behavior, provider completion, Procd adoption or a complete service lifecycle. The original install-grant constructor still gives GRANT | MINT while binding needs only GRANT; move-only transfer preserves exact rights. Both diagnostic grants are consumed, but rights minimization remains an explicit audit follow-up. Full source/effect/frame proof, the Pagerd gate, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related implementation tracking: Kernel feature, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Original Kernel CI 614 and 615 pass from four complete hashed logs, 753,462 bytes, without warnings. Original Docs CI 983 and 984 pass from four complete hashed logs, 773,542 bytes. Both pass all 45 tests and the complete 2,425-page final manual; reference-resolution warning counts are 36/1/0, with zero final warnings. Original Integration CI 1685/1686 remains queued at its second observation.

Older original Integration CI 1678 passes all 489 catalog scenarios and both native Kernel diagnostics, then fails the development COM1 editor probe after its physical counterpart passes. Rust and Markdown pass. All three complete logs total 13,384,697 bytes with no warnings; the outer input status does not establish cause. The canonical bug report is issue 67, with bug/ci/phase-6 metadata. Earlier editor and filesystem failures remain separate. No original workflow was cancelled or rerun.

Native cleanup without a userspace successor — 19 September 2026: signed Kernel 2cf5b34c adds a seventh actual CPL3 caller to the maintained lifetime diagnostic. After every earlier assertion, the observer binds/starts the final child and yields. The child kills that supervisor through its own explicit Process SEND route. Immediate faulting sentinels forbid either terminal payload from resuming. Ordinary native return closes CPU accounting, detaches current attribution, progresses reclamation and finds no runnable successor.

A diagnostic-only read-only witness then requires empty CPU accounting, only terminal retained records, no bound cleanup duties or event reservations, exact child identity/CSpace/mapping absence and both unconsumed child-before-supervisor events. All six final child pages retire; three original unbound terminal records remain for prior assertions. The witness neither performs cleanup nor selects a process nor installs an interrupt. ERIX_KERNEL:CHILD_IDLE_CLEANUP_OK precedes completion before HLT, so actual hardware halt/wakeup remains a separate gate.

Signed Integration 4d6f4fe8 requires the additional marker while preserving all earlier assertions and both 60-second scenario limits. Both actual native VMs pass: 1,905/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256: 4a7cba61f75f4eeac47896d165b8dbcd217e4c75e2a81c8ae0f29957facb929c. Packaged Kernel images match retained build artifacts after normal stripping; all fifteen original component signatures verify. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Post-VM changes only select updated Docs in full catalogs and update roadmap status.

Signed Docs 69466a64 documents the pre-halt boundary and consolidates stale status paragraphs. All 45 tests, the complete 2,425-page manual, 447,534 word bounds and visual review of pages 562–564 pass with zero final warnings. API reference source remains unchanged. The static audit passes 3,140 authored code files below 1,000 lines, 74 manifests, 259 full Git selections, 171 direct missing_docs gates and 92 conventional crate roots; semantic authority and complete private-rustdoc closure remain open.

Original Kernel CI 616 and 617 pass from four complete hashed logs, 753,458 bytes, with no warnings. Original Docs CI 985 and 986 also pass: four complete hashed logs, 773,510 bytes; both pass 45 tests and the final 2,425-page manual. Reference-resolution warning counts are 36/1/0 with zero final warnings. Original Integration CI 1687/1688 remains queued at its first observation.

Older original Integration CI 1677 is now terminal failure: all 489 catalog cases, both native diagnostics, development physical/COM1 editor and release physical editor pass before release COM1 fails. Rust and Markdown pass. Three complete logs total 13,385,246 bytes without warnings; bug 37 retains this evidence. Companion 1678's earlier development COM1 failure remains separate in bug 67; a common cause is unproven. No original workflow was cancelled or rerun.

Further native failure controls, grant-rights minimization, terminal accounting, Procd adoption and complete service lifecycle acceptance remain open. Existing install-grant creation still supplies GRANT | MINT while binding needs GRANT, so minimum authority is not claimed. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Further original CI observations — 19 September 2026: original Integration b65183ddb93eb4396d4140a002c3727fec42ff87 now has both terminal outcomes recorded. Run 1679 passes 488/489 catalog cases; only ext4 quota exceeds its unchanged 120-second deadline, retained in bug 18. Its later native/interactive gates are not reached. Run 1680 passes all 489 catalog cases and both native diagnostics, then fails development COM1 directory input after its physical counterpart passes; the last observation is command 6 injection, retained in bug 56. Later release directory/editor gates are not reached. Both Rust and Markdown jobs pass. Six complete hashed logs total 27,238,688 bytes with zero warning candidates. Causes remain unclassified; no unchanged rerun, cancellation or deadline change occurred. Original current Integration 1687/1688 remains queued at its second observation. Acceptance stays 15/460, 3.48% weighted; native toolchain rebuilding and both full EriX-in-EriX generations remain open.

Native terminal-event allocation refusal — 19 September 2026: signed Kernel ba03995f extends the actual executing-child sequence with one deliberately refused heap allocation. Separate diagnostic preparation captures the original supervisor, child, staged grandchild and independent process records/capability inventories, then gives an empty event queue one-event capacity. No queued event or existing reservation is discarded. The first terminal-event reservation succeeds; the second arms exactly one null return from the real Kernel allocator. Ordinary collection growth and Process dispatch return RESOURCE_EXHAUSTED before any terminal effect.

Read-only witnesses require complete reservation rollback, an empty event queue, unchanged exact records and capabilities, and preserved code/stack/message mapping ranges. Actual CPL3 instructions validate the refusal reply before the next ordinary ancestor kill succeeds with allocation available. Every earlier terminal, descendant-disposal, independent-process and no-successor idle assertion remains required. ERIX_KERNEL:TERMINAL_EVENT_RESERVATION_OK requires one consumed allocator refusal and no remaining armed fault. Fault controls are absent from ordinary images; this covers injected allocation failure, not spontaneous heap exhaustion or independent resource-release failure. No witness supplies a syscall result, cleanup effect or scheduler choice.

Signed Integration cf5b2f5f requires the new marker without changing either 60-second limit. Both maintained native VMs pass: 1,948/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is d485019082175f769ecc2d406d88c6cc84a7df323605027663f5bcc79ca03ad9. Packaged Kernel bytes match retained original artifacts after normal stripping, and all fifteen original source signatures verify. Post-VM changes only select updated Docs in full catalogs and consolidate roadmap status.

Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and updated policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 62ba2ffa passes 45 tests, the complete 2,425-page manual, all 447,688 word bounds and actual visual review of pages 562–565, with zero final warnings; API reference source remains unchanged. The static audit passes 3,142 authored code files below 1,000 lines, 74 manifests, 259 full Git pins, 171 direct missing_docs gates and 92 conventional roots. Complete semantic authority and private-rustdoc closure remain open.

Original Kernel CI 618 and 619 pass from four complete hashed logs, 753,434 bytes, with zero warnings. Original Docs CI 987 and 988 pass from four complete hashed logs, 773,506 bytes: both pass 45 tests and the final 2,425-page manual, with reference-resolution warning counts 36/1/0 and zero final warnings. Original Integration CI 1689/1690 is queued. Earlier filesystem, directory, editor and full-frame regressions remain unresolved; original workflows were not cancelled or rerun.

The terminal-accounting audit confirms that ordinary Procd terminal handling queries original TCB counters after receiving its event, while automatic bound-child reclamation removes that TCB. Its separate private-mediator branch does not take the same query path; adoption must state which lifetimes require retained metrics and preserve their original generation without fabricated zero/wall-clock values. Independent release-failure coverage, grant-rights minimization, accounting, Procd adoption and full mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Historical pre-correction CI reconciliation — 19 September 2026: original Integration run 1673 and 1674, at 76411ed6d96356b20ee0a4c21ad219dacc56340d, are terminal failures. Each passes 487/488 catalog scenarios and fails only appliance-disk-image-realm-admission-positive, reporting the unchanged 45-second serial-progress watchdog. Later native and interactive workflow gates are not reached. Both Rust and Markdown jobs pass. Six complete hashed logs total 27,087,569 bytes with zero warning candidates. Neither workflow was cancelled or rerun.

These runs precede the retained correction at 9139c6c5fa38c139e92520f6d410626b4cf1e4aa; both later original runs 1675/1676 passed that realm-admission scenario. Issue 66 retains the historical evidence and its existing closed state. This does not establish a new current-source regression, full lifecycle acceptance or full guest builds. Current Integration 1689/1690 remains queued at its second observation; acceptance stays 15/460, 3.48% weighted.

Independent native child release recovery — 19 September 2026: signed Kernel 82d88b60 extends actual supervisor-exit coverage with two deliberate refusals at the original staged child's final VSpace-release callback, after capability disposal and unlinking. The first error is KernelHeapExhausted, the second CspaceSlotMissing. Read-only observations around two ordinary CPL3 observer yields require the original full record, generation, abort custody and first error retained, an empty original CSpace and retained mapped backing. The independent running child must already be absent from native TCB, CSpace and VSpace directories. The selected child's earlier directory position ensures its failure preceded that independent disposal.

The third callback must perform normal VSpace release before all original terminal-event, generation and resource-absence checks pass. ERIX_KERNEL:CHILD_RELEASE_ISOLATION_OK requires exactly two refusals and complete eventual disposal. Fault control uses only atomics at the locked callback boundary and exists only in the isolated native diagnostic. No witness performs cleanup, supplies a successful release/syscall result or chooses a scheduler target. This establishes injected callback-refusal coverage, not an observed hardware or allocator malfunction. All earlier nested-child, allocation-refusal and no-successor pre-halt assertions remain required.

Signed Integration 294a467a requires the added marker with both original 60-second limits unchanged. Both maintained native VMs pass: 1,988/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is 606fff037be022c876220d8e8f329c9046ffea5dcdf80831026649aedfbe0b08. Packaged Kernel bytes match retained original unstripped artifacts after normal stripping, and all fifteen original component signatures verify. Post-VM changes only select the updated manual source in full catalogs and reconcile roadmap status.

Four strict Kernel 720/744-test configurations, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test configurations, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed Docs 2a0ccc1a passes 45 tests, the complete 2,427-page manual, all 447,789 word bounds and actual visual review of pages 562–565 with zero final warnings. API reference source is unchanged. Static audit passes 3,143 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 171 direct missing_docs gates and 92 conventional roots; complete semantic authority/private-rustdoc closure remains open.

Original Kernel CI 620/621 and Docs CI 989/990 pass from four complete hashed logs each (753,438/773,910 bytes), with zero final warnings. Current Integration originals are observed after publication. Earlier filesystem, directory, editor and full-frame regressions remain unresolved, with original evidence retained; no workflow is cancelled or retried unchanged.

The grant-rights audit confirms actual Procd derivation callers and exact GRANT | MINT receipt checks in Procd and Launchd. Grant authority minimization must coordinate those consumers and distinguish the grant's own rights from its installation ceiling. Original generation-bound terminal accounting, Procd adoption, provider completion, hardware halt/wakeup and complete mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted.

Related: Kernel design, Kernel WIP PR, Integration WIP PR, manual WIP PR, and phase completion.

Explicit grant implementation progress — 20 September 2026:

Kernel commit 4a5333f760e258ebca23047a362d1cff4fded0c0 is signed and pushed. Creation preserves exact own grant rights, including zero. Derivation requires actual MINT and subsets of both own rights and installation scope. Zero-right custody still blocks process start until disposed. Four strict 724/748-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings; three existing ignores remain. Original CI 622/623 passes from four complete hashed logs, 756,715 bytes, zero warnings. The new actual CPL3 derivation/disposal controls and GRANT-only relocation/installation compile; their matching VM execution remains pending.

Integration commit 9166f7bde6a0b42afd3ef1c9898b9e818df9af86 is a signed orchestration-library dependency checkpoint. Four strict 320/321-unit configurations and four native library builds pass without warnings. Original CI 1693/1694 is waiting at its first observation. The full image catalogs still retain their preceding coordinated selection until actual consumers are validated together.

Shared wire and dependency checkpoints, each with strict matrices and original CI passing: lib-ipc issue/PR, lib-capabi issue/PR, lib-bootstrap issue/PR, lib-interrupt issue/PR, lib-service issue/PR, lib-time issue/PR, lib-block issue/PR, lib-log issue/PR, lib-driver issue/PR, lib-vfs issue/PR. Their linked WIP PRs retain the detailed signed revisions and validation.

The consumer audit also identified Loaderd and Deviced receipt checks. Procd's move-only handoff cannot attenuate the original delegating grant: it now derives a GRANT-only final receipt into the already-disposed VSpace receipt slot and drops the source before returning that receipt. Nonderiving materialization and rootless mediator paths request GRANT directly. Partial failure retains original-generation rollback and all remaining local custody. Procd, Launchd, Rootd, Loaderd and Deviced pass their default unit suites; their full strict matrices and coherent guest validation remain open. Deviced bug 4 records a separately observed quarantine test race and its test-only serialization correction.

This is partial implementation evidence, not completed lifecycle or self-hosting acceptance. The canonical checklist remains 15 of 460 leaves, 3.48% weighted. Full terminal accounting, provider completion, consumer lifecycle, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both complete EriX-in-EriX generations remain required.

Verified grant-rights checkpoint — 20 September 2026:

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

All thirteen shared libraries pass their strict matrices and original CI. The five direct receipt consumers pass four strict host/native configurations; original CI passes for procd 292/293, launchd 145/146, rootd 1037/1038, loaderd 99/100, deviced 206/207. Rootd baseline regression and Deviced quarantine fixture race are corrected with retained original failures and successful corrected-source CI. Manual/API updates and remaining full-catalog alignment are in progress.

Integration bug 68 records five original CI failures (1683/1684, 1685/1686 and 1688), each with 127 manifest/catalog revision mismatches before full VM execution. All fifteen complete logs are retained, 1,512,137 bytes with no warning candidates. Individual-crate and minimal-native validation did not prove full catalog coherence. Remaining dependents are being aligned and validated bottom-up; equality and immutable-source checks are unchanged. Earlier 1681/1682 separately reached 479/489 and 487/489 VM passes, with ten and two scenario timeouts at the original 120-second bounds. Those filesystem failures require separate analysis.

Canonical acceptance remains 15 of 460 leaves, 3.48% weighted. Complete lifecycle and terminal accounting, provider completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required.

Manual and dependency validation — 20 September 2026:

Docs commit f4621ce2921b2b9fe3b1d25b4321d6b28289418e is signed and pushed. Native selectors 32/33/54 now document exact own rights separately from installation ceilings. The process and launch chapters require GRANT-only final receipts, explicit derivation/source disposal, and original-generation rollback. Both IPC references are regenerated from signed source. All 45 tests and API checks pass; the complete 2,429-page manual has zero final warnings, all 448,913 word bounds pass, and eleven changed pages were visually reviewed. Original Docs CI 991/992 passes with four complete hashed logs, 774,346 bytes, both 45-test runs and final 2,429-page manuals. Intermediate TeX reference warnings resolve before the final pass.

Thirty-one additional downstream consumers now have signed dependency-alignment checkpoints, each with four strict unit configurations, four native builds, host/native Clippy, formatting and private rustdoc passing without warnings. All 62 original CI runs pass. Their owning feature issues and WIP PRs retain exact revisions and log evidence. Catalog regression 68 remains open until the remaining Exsh selection and complete original catalog are validated together. Individual repository success is not full service-image acceptance.

Exsh's default development tests pass 976 units. Aggregate release-test compilation and a subsequent explicitly separated library compilation each reached the local unchanged 120-second silence limit before tests ran; both failures remain retained. No release-test success is inferred, no compiler setting or deadline was relaxed, and independent configurations are being collected without rerunning failed commands unchanged. The complete source/effect/frame gate also remains open.

Original Integration 1693/1694 also fails with 127 manifest/catalog mismatches each, before full VM execution. Six complete logs total 604,756 bytes, with no warning candidates. Together with 1683–1692 this is twelve retained original failing runs. Earlier full-VM filesystem timeouts remain separately tracked in ext-family issue 20 and FAT32 issue 58.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open.

Complete original catalog checkpoint — 20 September 2026:

Integration f9681efc30f1c48989def7f0e7db939974a30e27 is signed and pushed in WIP PR 12. Both complete catalogs now pass exact dependency equality against 73/70 clean original selected checkouts and 72/71 manifests; all 143 selected signatures verify. The original Integration library pin is retained independently of the catalog commit, avoiding a circular source reference. Twenty dependency-policy and 46 immutable-source tests, both native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Corrected-source original CI 1695/1696 is running; bug 68 remains open pending that observation and full consumer acceptance remains separate.

The executed inputs for both first-attempt native VM passes remain exact: 27 new ordinary CPL3 grant-right controls, every earlier lifetime/owned-invocation assertion, original 60-second bounds, zero build warnings and empty QEMU stderr. Both packaged kernels match retained original artifacts and all fifteen original source signatures verify. The final post-VM changes only select the full catalogs and reconcile documentation.

All 31 further fully validated consumer checkpoints pass four strict unit/native configurations and all 62 original CI runs; 124 complete logs total 3,041,213 bytes with no warning candidates. Their owning feature issues and WIP PRs preserve exact source and CI evidence. The full manual and regenerated IPC references are published in Docs WIP PR 4; its 45 tests, 2,429 pages, 448,913 word bounds and eleven changed-page reviews pass, as do original Docs CI 991/992 with zero final warnings.

Exsh dbc958bcdaa557a461e9308a31d23d3b8c189296 in WIP PR 3 is explicitly an incomplete-validation dependency checkpoint. Both development configurations pass 976 units, four native builds and strict Clippy/docs configurations pass, and all 355 checker tests pass. Three local release-unit compilation attempts reached the unchanged 120-second silence bound before tests ran. Four local frame checks return 1 with complete workspace mapping and 97/63 unresolved routes. Original CI 273/274 likewise passes 976 units and 355 checker tests, then fails the full frame/source gate with 101/68 unresolved observations. Four complete CI logs total 319,871 bytes with zero warning candidates. These local and CI artifacts are distinct; no frame or release-unit acceptance, relaxed deadline or unchanged retry is claimed.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. The full in-EriX builds and native external Rust/LLVM/runtime rebuild remain unproven. Full consumer lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate and profiler attribution remain required; no canonical leaf closes at this checkpoint.

Installer return-slot regression — 21 September 2026:

Both original corrected-catalog runs are now classified: 1695 passes 431/489 VM scenarios and 1696 passes 430/489. All six complete logs are retained and hashed, 32,723,390 bytes, zero warning candidates. Rust, Markdown and full dependency equality pass. Catalog mismatch issue 68 is corrected; this does not establish full consumer acceptance. Each run has 57 initial-shell uncertain-disposition failures and a separately retained release-appliance stall. Run 1696 also retains the ext4 quota timeout under its original 120-second bound, tracked in issue 20.

Procd bug 4 records a concrete producer/consumer mismatch. The final installer was handed off from VSpace scratch slot 1056 while later TTY provisioning requires managed grant slot 1040. The added producer regression fails on the original code. Signed Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce in WIP PR 2 derives the exact GRANT-only result, disposes its delegating source and uniquely relocates the result back to the empty managed grant slot. Refusals preserve original-stage rollback and remaining custody. Four strict 291/296-unit configurations, four native builds, host/native Clippy, formatting, private rustdoc and policies pass with zero warnings. Corrected full-service VM validation and original CI remain open; bug 4 remains open.

Acceptance remains 15/460 leaves, 3.48% weighted. Full consumer lifecycle, terminal accounting, source/effect/frame proof, Pagerd, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full in-EriX build generations remain required.

Verified managed installer recovery — 21 September 2026:

Signed Integration 648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d in WIP PR 12 selects signed Procd ac8a12993bc8cbf134a11e141e459cb63df71123 and Docs PR 4. Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed.

Procd bug 4 is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings.

The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes.

The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open.

Verified native terminal accounting — 21 September 2026: Kernel a9bdf6163813d378e0b4a164bceb839e24fbb6b7 is signed/pushed. Terminal preflight reserves final scalar CPU evidence independently of TCB/CSpace/VSpace reclamation; exact queries preserve final results or explicit errors. Repeat observations belong to the actual original observer until exact acknowledgement, and observer death releases that claim. Independent authorized observers can progress. Selector 55 is retired; checked selectors 59/60 have no destructive fallback.

Four strict 736/760-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings. Host controls include nonzero final counters after actual reclamation and ID reuse, original observer death, pending-final-charge destruction refusal, malformed requests, wrong callers, immutable errors and lost-acknowledgement reply retry. Original Kernel CI 624/625 and corrected 626/627 all pass from eight complete hashed logs (1,532,848 bytes), zero warnings.

Both maintained lifetime and owned-invocation VMs pass under the unchanged 60-second scenario limits and standard watchdogs, with no build warnings and empty QEMU stderr. Actual guest instructions check repeat observations and CPU queries, exact acknowledgement and absent-acknowledgement retry; executing children require nonzero user and kernel counters after native reclamation. Lifetime retains 2,025 serial bytes (SHA256 921edf5eadfdff61f2d85a63158555666e77e57a1e8aa4254ac30dcd216f8cf9); owned invocation retains 1,587 (SHA256 404bc4ecad5074349d9ba45d1caf5439aebe849d344b726e5dec2ee2b9c4d907). Normal stripping exactly matches both packaged kernels to retained original artifacts; all fifteen selected original signatures and clean checkouts verify.

Kernel regression 21 retains the first VM's final page-census failure. The corrected layout declares and allocates all six request pages and derives the independent census from that declaration. No unchanged retry or deadline relaxation occurred.

Integration fcd7b4a9608f629a12de78c53da5c3615d906b46 is signed/pushed with the verified isolated catalog. Twenty dependency and 46 immutable-source tests, native policies, Markdown and source checks pass. The unchanged orchestration crate, embedded fixture and original dependency closure retain verified four 320/321-unit and native/Clippy/rustdoc configurations. The full service catalogs retain their separately coordinated revisions; original Integration CI remains under observation.

Procd and Rootd consumer adoption, ordinary and mediator metric retention/consumer loss, manual updates, full service/profiler scenarios, complete authority/source/frame audits and full regression acceptance remain open under Kernel design 20. Canonical acceptance remains 3.48% weighted; 15 of 460 items. Native upstream Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory and unproven.

Committed terminal-accounting consumers — 21 September 2026:

Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.

Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.

Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.

The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.

No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.

Original acknowledged service catalog — 21 September 2026:

Signed dff878dd3545c4751b3c05d37b2bdd5e21cce548 selects the original terminal-observation, exact-acknowledgement and final CPU dependency graph in both complete catalogs. All 35 application/service checkpoints are signed; the bounded VFS checker correction and its manual are included. Clean original checkouts pass manifest/catalog equality and signature checks. Exsh's release compiler and complete frame gates remain explicitly open in issue 9 and issue 4.

All 169 maintained helper commands pass with recorded source and stream identities. The original stale memory-source rejection, quiet storage-fixture timeout and overly long socket-fixture path remain retained. Their respective corrected inputs use the explicitly verified original memory checkout, the previously maintained traced disk invocation (258.975743 seconds under unchanged 600/120 bounds), and a fresh owned shorter temporary directory (all 14 socket controls pass without changing the Unix pathname limit). None of these setup corrections changes test sources or bypasses source, timing or cleanup checks. The unchanged orchestration library retains all four strict 320/321-test configurations; formatting, policies and Markdown pass without warnings.

The published runner and original full source graph are prepared for the maintained shell CPU-accounting, two-CPU inspection and out-of-session denial scenarios. Actual VM evidence remains pending and no full guest-build acceptance is awarded. Original CI 1703/1704 is being monitored without restart. Complete authority/source/effect/frame and Pagerd gates, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory in Phase 6 completion.

Actual service CPU scenarios and startup admission — 21 September 2026:

The published original Integration catalog dff878dd3545c4751b3c05d37b2bdd5e21cce548 passes the maintained shell times, two-CPU Extop and out-of-session denial VM scenarios under their unchanged 120-second guest limits. Each retains 106 hashed evidence files, warning-free image builds, empty QEMU stderr and every required, forbidden, ordered and unique marker check. Build-plus-scenario wall times are 119.876978, 34.802620 and 36.173027 seconds respectively; these are not guest-only or startup measurements.

Times reports nonzero self and waited-child CPU. Extop observes both CPUs, memory and increasing job CPU nanoseconds with CTRL no; both per-CPU percentages remain --.--% in the two samples, so numeric utilization is unproven. The denial scenario confirms the existing out-of-session boundary. Complete mediator/lifecycle acceptance in Procd 5 remains open.

A separate ordinary development package also builds without warnings, but its required startup-contract preflight exits 1 before any VM or observer starts. Integration 69 records the missing full-runtime-transition contract selections and Kernel effective-feature/original-source evidence. Preserve the refused package and all admission controls; the 120/15/10 capture limits and performance thresholds are unchanged. No startup-profile acceptance is awarded. Complete source/effect/frame and Pagerd proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required by Phase 6 completion.

Original full-regression observation — 21 September 2026:

Original Integration 1699/1700, source fcd7b4a9608f629a12de78c53da5c3615d906b46, each finish at 487/489 VM passes. All six complete logs retain 28,483,276 bytes with zero warning candidates; Rust and Markdown jobs pass. The original worker boundaries identify quota's 120-second timeout in 1699 and 45-second serial stall in 1700, ext4 links' 120-second timeout in 1700, and FAT32 directory metadata's 120-second timeout in 1699. The latter has a distinct canonical bug report. Existing quota 18 and links 20 remain open. No shared root cause is inferred, and no unchanged rerun, cancellation or threshold relaxation is requested.

Signed startup source/feature correction — 21 September 2026:

Integration fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure.

All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; bug 71 retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices.

The technical manual update 76672dff8ff83 passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs 1001/1002 passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow.

A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under bug 69; no threshold or 120/15/10 capture limit changes. Original Integration 1705/1706 is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory.

Actual original-source startup capture — 21 September 2026:

Signed Integration fd8a5cf0dbcf builds the ordinary image without warnings and its actual Kernel-bound contract passes preflight. The VM and complete observer finish with all required stages, zero dropped records, empty QEMU stderr, successful cleanup and unchanged source image. Admission bug 69 is resolved independently of performance.

The strict timing gate fails: root-to-final readiness 5.974133160 seconds (limit 5), largest service interval 3.098663889 (limit 1), final readiness to caret 1.262470092 (limit 1), and four native commands 4.769234506 (limit 2). The maintained offline profiler identifies RTC-provider to TTYD as the largest service interval, followed by roughly one-second Powerboxd and Launchd intervals. These are host observation windows, not loader-only causal measurements. The new canonical timing bug retains the exact image, timing and command identities and every original limit. Host/toolchain description fields remain explicitly incomplete; no provenance or speedup is invented.

The sixteen helper stream-custody corrections also pass all changed controls; all 171 selected helper commands have successful warning-free final evidence. Bug 71 is resolved with its original 36 warnings retained. Full CI for 1705/1706 remains separately monitored. No startup-performance or full native toolchain/EriX guest-build acceptance is awarded.

Current observation checkpoint — 21 September 2026: signed 9c62af2d2484 records the actual startup outcome in the roadmap; executable and library inputs remain identical to the measured fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa implementation. Markdown, template structure and source policy pass. Original Integration 1701/1702 remains running; 1703–1708 remains queued. Logd 239 passes; 240 has failed, with both terminal log endpoints still returning HTTP 500. Its cause and warning classification remain unresolved. Original runs are preserved without restart or cancellation. All 3,165 authored code files remain below 1,000 lines; the static pin and missing-docs declaration checks remain intact. Full authority/source/effect/frame, startup performance and native external-toolchain/EriX guest-build acceptance remain open.

Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.

Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.

Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.

Executed-code profiling checkpoint — 22 September 2026: signed Integration 4fa27f942bc2, tracked in Integration PR 12, adds bounded host TCG execution counters, explicit fresh-output ownership and exact packaged-ELF code candidates without adding guest authority. All 172 maintained helper commands pass without warnings. The profiler passes five Rust tests in both profiles, strict Clippy, private rustdoc, eleven Python controls and five actual selected-emulator controls. Unchanged orchestration inputs retain their preceding four strict matrices. The operator guide distinguishes complete counters from VM acceptance.

One original-image diagnostic retains 92,896 translated blocks, 1,994,216 code bytes and zero missed execution counts. Its top 100 code groups cover 85.65% of the translated instruction upper bound; 33.30% has Kernel mapping-batch candidates and 7.70% has VSpace permission-switch candidates among the selected ELF inputs. Unknown and ambiguous work remains visible. These are code matches, not process ownership or elapsed-time attribution. Both the instrumented attempt and its same-emulator uninstrumented control fail waiting for the final native-command marker under unchanged 120/15/10 collection bounds. Neither proves startup acceptance, whole-transcript instrumentation overhead or a speedup. Profiler acceptance and startup performance remain open. The next optimization must preserve complete validation, live backing checks, page permissions, invalidation ordering and cleanup on errors.

The signed manual update, tracked in Docs PR 4, passes 45 tests, all 2,431 pages, 450,367 word bounds and both changed-page visual reviews with zero final warnings or overflow. Original Docs CI 1005/1006 passes from four complete logs (774,674 bytes); initial reference-convergence warnings resolve on the final passes. Integration 1711/1712 is queued, while original 1701/1702 still runs. Existing queued jobs remain untouched. All 3,174 authored code files remain below 1,000 lines. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and completing the required full guest-build generations remain mandatory and unproven.

Native table-custody checkpoint — 22 September 2026: signed Kernel 2e744897de7c, in Kernel PR 3, gives unpublished table allocations one cleanup owner through translation and initialization. Empty-table installation and huge splits transfer custody at parent publication. The raw allocation-return helper and duplicate huge-split initialization are removed. Parent/leaf invalidation, interrupt masking, permission templates and current shared-hierarchy lifetime remain intact. Five host controls cover allocation/translation failure, invalid geometry, abandoned preparation and publication. Four strict configurations pass 742 default / 766 all-feature tests, retaining three existing ignored cases; formatting, host/native Clippy, private rustdoc and thirteen native builds pass without warnings. Original Kernel CI 630/631 passes from four complete logs, 771,607 bytes and zero warnings.

Signed Integration fe63adde8ff9, in Integration PR 12, selects that exact Kernel in all three catalogs. Every other selection and Kernel dependency manifest is unchanged. All 172 maintained helper commands pass without warnings; unchanged Rust inputs retain their preceding strict matrices. Three original-source native executions pass lifetime revocation, owned invocation and mapping checks with unchanged 60-second guest limits, warning-free builds and empty QEMU stderr. Mapping isolation and sparse mappings have identical runtime settings; both maintained marker contracts pass on the retained mapping capture. All fifteen selected component signatures verify, and each packaged Kernel image equals its retained artifact after normal stripping. These results cover the current shared hierarchy, not independent hardware roots.

The Kernel evidence update and Integration evidence update change documentation only, with executable inputs proven unchanged. Their original Kernel CI 632/633 is running and Integration 1715/1716 is queued. Older full Integration CI 1701/1702 at b06dfad002 passes from six complete logs, 26,962,712 bytes and zero warnings, including both runs' ext4 quota, ext4 links and FAT32 directory-metadata cases. Their earlier timing failures remain retained with unestablished causes; 18, 20 and 70 have exact follow-up observations. No workflow was rerun or cancelled.

All 3,176 authored code files remain below 1,000 lines. The next work in Kernel 22 must resolve the supervisor baseline, bootstrap/saved-frame overlays and inactive-space population before adding root ownership, residency and retirement. Startup timing acceptance, complete authority cleanup and the profiler's measured speedup remain open. The phase checklist stays at 15/460 accepted leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven.

Ordinary mapping-domain checkpoint — 22 September 2026: resolved admission report records the original host failure and bounded fix. The fixture regression retains all three distinct failed attempts and the verified layout correction. Kernel now validates the complete ordinary user page before backing or mapping changes, with both control paths covered. Four strict 745/769-test configurations, thirteen native builds, Clippy and private rustdoc pass without warnings. Three exact-source native executions pass lifetime, invocation and mapping; four maintained scenario contracts are checked, with sparse and isolation sharing their identical runtime capture. All fifteen selected native signatures and packaged Kernel identities verify.

Integration pins the exact Kernel in all three catalogs, preserves every other selection and passes all 172 helpers. The unchanged ordinary exec-successor VM passes against the complete source graph, preserving its 120-second guest deadline, with no image warnings or QEMU stderr. Docs documents the domain and bootstrap distinction; all 45 tests and 2,431 pages pass, with 450,473 word bounds checked and no final warnings. The earlier Kernel CI 632/633 passes from four complete logs and zero warnings; current original CI remains under observation.

Bootstrap provenance, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Verified documentation and CI follow-up — 22 September 2026: Kernel documentation and Integration documentation record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in report 24, separately from the fixed admission defect. The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure.

Original full Integration 1703/1704, source dff878dd35, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel 634/635 report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel 636/637 and Docs 1007/1008 pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued.

The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open.

VSpace MAP authority checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Current local MAP rights now govern map, protection and unmap requests. Empty and MANAGE-only aliases are denied; MAP-only access remains valid. Four strict 750/774-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The Integration catalog selects the exact signed Kernel in all three catalogs and passes all 172 helpers. Actual CPL3 calls preserve the authorized RW/NX page across restricted-alias refusals and drop all five temporary grants. Three native executions cover all four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signed sources and retained packaged artifacts. The original exec-successor service VM passes against all 73 components with its unchanged 120-second guest limit. All image warnings and QEMU stderr remain absent. Manual validation passes 45 tests, 2,431 pages and 450,550 checked word bounds, with both changed pages reviewed and zero final warnings.

The static audit covers 3,181 authored code files below 1,000 lines, 259 exact Git dependency pins and existing direct missing_docs gates. It does not close semantic authority review. Earlier full Integration runs 1705/1706 are running; 1707–1720 remain queued at the latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 638/639 and Docs 1009/1010 pass. Each pair has four complete logs: Kernel totals 777,250 bytes with zero warnings, and Docs totals 774,674 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1721/1722 remains queued; it receives no CI acceptance credit.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven.

Frame access checkpoint — 22 September 2026: the resolved bug report records three original failing host controls and the verified correction in Kernel. Explicit READ now governs admission and hardware activation. No-access mappings retain backing with USER/WRITE clear and NX set; write-only and execute-only requests are rejected without adding READ. Existing protection-transition rules remain in force. Four strict 757/781-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The Integration catalog selects the signed Kernel in all three catalogs and passes 172 helpers. Twenty-four actual CPL3 calls preserve earlier witnesses and cover no-access protection, write-only refusal, MAP-only frame derivation, denied READ and unmap after both frame grants are dropped. Three native executions pass four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signatures and retained packaged artifacts. The ordinary exec-successor VM passes against all 73 components with its unchanged 120-second guest limit. Builds emit no warnings and QEMU stderr is empty. Manual validation passes 45 tests, 2,433 pages and 450,702 checked word bounds, with the changed page reviewed and zero final warnings.

Static review covers 3,182 authored code files below 1,000 lines, 259 exact Git pins and existing direct missing_docs gates. This does not close semantic authority review. Earlier full Integration runs 1705/1706 remain running and 1707–1722 remain queued at their latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel 640/641 and Docs 1011/1012 pass. Each pair has four complete logs: Kernel totals 782,838 bytes with zero warnings, and Docs totals 775,110 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration 1723/1724 remains queued; it receives no CI acceptance credit.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Authorized protection restoration, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Ordinary protection contract — 22 September 2026: the runtime memory design now specifies in-place no-access/R/RW/RX changes using current VSpace MAP and exact selected frame authority, including same-backing aliases and complete backing checks. Preserve W^X, explicit READ, object kind, reference custody, error ordering and all native witnesses. Kernel-owned anonymous loader materialization and Process endpoint target scope retain separate audit obligations. The implementation and exact-source VM evidence are pending. This earns no canonical acceptance credit; external toolchain rebuilding and both complete EriX guest-build generations remain mandatory.

Older VM regression observation — 22 September 2026: the ext4 deadline report preserves original Integration CI 1705/1706 at fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa. The complete 489-scenario catalog reports 482/7 and 485/4 pass/fail outcomes; eleven actual 120-second QEMU timeouts cover eight distinct ext4 scenarios. Rust 320/321-test configurations and Markdown pass. All six complete original logs are retained without warning candidates. Root cause, isolated reproduction and correction remain open; no rerun or relaxed limit supplies acceptance. External toolchain rebuilding and both complete EriX guest-build generations remain required.

Current-grant protection checkpoint — 22 September 2026: the resolved device-backing report distinguishes its original metadata-authority inconsistency from the separate restoration feature gaps. The Kernel implementation permits representable no-access/R/RW/RX changes through current exact-backing grants and aliases while active or inactive. It removes historical access ceilings and original-slot equality while preserving current VSpace MAP, selected frame rights, kind/range/identity checks, W^X, explicit READ, backing custody and failure ordering. Four strict 766/790-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings.

The coordinated catalog selects that original signed Kernel in all three catalogs and passes all 172 helpers. Fifteen managed-frame calls and twenty-nine device/domain calls pass inside the original lifetime window and deadline. Actual user instructions write, execute, rewrite and execute managed RAM, check narrow alias authority and final disposal, while a reused device slot cannot authorize unrelated backing. Every prior marker remains required. Three native executions pass four original contracts with complete signed source and artifact checks; the ordinary exec-successor VM passes the full 73-component graph and original 120-second limit. Image warnings and QEMU stderr are absent. Manual validation passes 45 tests, 2,433 pages and 450,954 word bounds; both changed pages are reviewed with no final warnings or overflow.

Static review covers 3,184 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins and 174 direct missing_docs gates. Full semantic authority review remains open. Older Integration CI 1705/1706 has eleven real ext4 timeouts across eight scenarios, with complete retained logs and no accepted rerun. Their root cause and correction remain unresolved. Publication CI: Kernel 642/643 and Docs 1013/1014 pass. Each pair has four complete original logs: Kernel totals 790,650 bytes with 766/790 tests and zero warning candidates; Docs totals 775,150 bytes with 45 tests, 2,433 pages and zero final warnings or overflow. Retain the original 35/1/0 LaTeX warning convergence. Integration 1725/1726 remains queued and receives no completed CI acceptance. The separate older ext4 deadline report remains open.

Canonical acceptance remains 15/460 leaves, weighted 3.48%. Complete POSIX protection support, Process endpoint scope, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

VSpace ownership preparation — 22 September 2026:

Live VSpace records and production mapping tables are non-cloneable. Test observations contain descriptive metadata, synthetic selectors use independent tables, and leaf-encoder checks borrow live mappings under the record lock. Selectors accept only the mapping table they consume. Current grants, backing custody, first-match ordering, reference scans and hint visit-count controls remain intact; the rights control now uses actual activation/deactivation. The former whole-record snapshot helpers are removed.

Four strict Kernel configurations pass 766/790 tests with three existing ignored cases; thirteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. All 172 Integration helpers pass. Three exact-source native executions pass the four maintained mapping, sparse, invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Original 60/120-second guest limits, existing markers, exact component signatures and retained packaged artifacts remain required; image warnings and QEMU stderr are absent. No startup speedup or independent hardware-root acceptance is inferred.

The Kernel implementation and Integration source selection are published with Kernel validation evidence and Integration validation evidence. Continue under owned-root design 22, Kernel PR 3 and Integration PR 12. Publication CI: Kernel 644/645 pass with four complete original logs (790,604 bytes), 766/790 tests and zero warning candidates. Integration 1727/1728 remains queued and has no completed acceptance; earlier ext4 deadlines remain tracked in Integration report 73. Complete authority cleanup, external toolchain rebuilding within EriX and both full guest build generations remain open. Canonical acceptance remains 15/460 leaves (3.48% weighted).

Native occupancy diagnostic regression — 22 September 2026: the original failure is retained with exact signed source and packaged-ELF identity. The fixture maps a Kernel heap VA that the correct ordinary-domain guard rejects on the native upper-half heap. Host allocator addresses did not expose the mismatch. The correction must preserve the guard, 64-page/alias/hole/byte/cleanup controls and both maintained VM deadlines. The report was subsequently resolved by the verified recovery below. No canonical acceptance leaf closes.

Managed-frame diagnostic recovery — 22 September 2026: Kernel report 28 is resolved by the signed correction and coordinated catalog. The diagnostic admits an initially empty lower-half window while preserving the ordinary-domain guard and all 64-page, alias, hole, physical-byte and cleanup controls. The unnecessary heap allocation and raw-pointer cleanup state are removed, with expanded inline rustdoc.

Four strict 766/790-test configurations, fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. All 172 Integration helpers pass. Both maintained allocator scenarios pass independently with their original 60/120-second deadlines and complete markers; exact signed source and retained packaged-ELF checks pass. The ordinary exec-successor VM also passes against all 73 components. Image warnings and QEMU stderr are absent. The original failed native image remains retained; no unchanged rerun is used as the correction.

Static review still covers 3,186 code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Full semantic authority and inline-documentation review remain open. Older original Integration 1707/1708 both pass all 489 VM scenarios, Rust 320/321 and Markdown; six complete logs total 26,966,330 bytes with zero warning candidates. Publication CI: Kernel 646/647 pass with four complete original logs (790,634 bytes), 766/790 tests and zero warning candidates. Integration 1729/1730 remains queued and has no completed acceptance; earlier ext4 CI deadline failures remain unresolved. The separate supervisor physical-access window and independent hardware roots remain implementation work. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Supervisor physical-access window — 22 September 2026: the signed Kernel implementation shares one restoring supervisor scratch transaction between frame scrubbing and physical mapping-byte copies. Caller backing custody and page-table/interrupt custody remain live through byte access, exact leaf restoration and local invalidation. Scratch is released afterward; read aliases clear the write bit and all temporary aliases clear user access and set NX. The unreachable raw-VA fallback is removed, and complete preflight rejects missing or ambiguous backing metadata before any range effects. No new userspace operation or capability grant is introduced. This is preparatory work for owned address spaces; independent roots and their switching/reclamation proof remain open.

Eight added host controls cover geometry, permissions, preparation and partial-effect failures, restoration/release ordering, and malformed later-page metadata without partial reads or writes. Four strict host configurations pass 774/798 tests with three existing ignored cases. Fourteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. The coordinated Integration catalog passes all 172 maintained helpers; its exact marker expectation is updated alongside the strengthened scenarios. Unchanged orchestration and profiler sources retain strict validation.

Six native executions satisfy seven maintained scenario contracts. Both allocator scenarios require the new same-VA/different-backing byte-and-leaf proof after complete cleanup, retaining every preceding marker and the original 60/120-second deadlines. Three further executions satisfy mapping, sparse, owned-invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Exact original signed source, retained artifacts and packaged Kernel matches are verified; no image warnings or QEMU stderr were observed. These checks establish no performance improvement. The technical manual documents backing and scratch custody; all 45 document tests and the complete manual build pass without final warnings.

Static checks cover 3,190 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Complete semantic authority and inline-documentation review remain open. Publication CI: Kernel 648/649 and Docs 1015/1016 pass. Eight complete original logs (1,572,758 bytes) confirm Kernel 774/798 tests, 45 document tests and the 2,433-page manual. Initial TeX reference warnings resolve through normal multipass generation; final passes are clean. Integration 1731/1732 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and its runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Owned supervisor baseline — 22 September 2026: the signed Kernel implementation captures and verifies independently allocated supervisor tables before root VSpace creation, Rootd preparation and RAM seeding. Each copied page has one typed aligned Box owner before a parent references it; the recursive entry selects the copied root. Source boot/AP tables and mapped backing retain separate custody. User leaves, malformed geometry and invalid recursive identity are refused. Leaf permissions, cache policy and huge-page sizes are preserved; newly owned table branches use WriteBack and clear USER. Failed construction releases all unpublished allocations. This replaces a raw-pointer table-storage owner with shared typed storage and adds no unsafe Send/Sync implementation or userspace operation.

Eleven new host controls cover independent storage, allocation/read failures, invalid translation geometry, user leaves, recursive and huge-page errors, source-permission drift, retained owner links and table counts beyond the unrelated 64-page batch size. Four strict host configurations pass 785/809 tests with three existing ignored cases; fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The coordinated catalog passes all 172 maintained helpers. Both allocator scenarios require successful baseline capture before their original marker sequence, with capability grants and original 60/120-second deadlines preserved.

Six native executions satisfy seven maintained contracts: both allocator scenarios, mapping and sparse checks sharing identical runtime settings, owned invocation, lifetime revocation and ordinary exec-successor across all 73 components. Exact signed source and retained packaged artifacts are verified; no image warnings or QEMU stderr were observed. The technical manual specifies the custody boundary and passes 45 tests, complete 2,433-page generation, all 451,287 word bounds and changed-page visual review without final warnings or overflow. Static audits cover 3,194 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots.

Publication CI: original Kernel push 650 passes and PR 651 retains the host fixture failure. Regression 29 is resolved by signed Kernel 12184850cd73: a deterministic private predecessor reproduces the original defect, and the corrected fixture passes the complete local matrix and push CI 652/PR CI 653. Four complete corrected CI logs total 807,886 bytes with zero warning candidates. Only host tests and roadmap change; validated production sources and all catalog selections remain unchanged. Docs 1017/1018 pass with four complete logs (775,122 bytes), 45 tests and the 2,433-page manual. Initial TeX reference warnings resolve before clean final passes. Integration 1733/1734 remains queued at the latest retained observation and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. The retained baseline is a construction prerequisite for owned address spaces. Per-VSpace population, CR3 activation, invalidation and live-root reclamation remain open, and no speedup is claimed. Full semantic authority and inline-documentation review also remain open. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven.

Huge-leaf geometry correction — 22 September 2026: the bug report preserves four original host failures and one passing WriteBack control. The signed correction separates PAT from physical address bits, preserves permissions/cache indices across both huge splits, and gives newly allocated tables WriteBack policy. Scalar and batched translation, split preparation, snapshots and baseline validation share the documented geometry. No new userspace authority, original native exploit or universal boot failure is claimed.

Four strict Kernel configurations pass 796/820 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: mapping and sparse, lifetime, invocation, both allocator checks and ordinary exec-successor across all 73 components. The new native witness verifies real 2 MiB PAT translation, splitting and complete restoration; host controls additionally cover 1 GiB. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and changed-page visual review without final warnings or overflow.

Publication CI: Kernel 654/655 and Docs 1019/1020 pass. Eight complete original logs (1,592,794 bytes) confirm Kernel 796/820 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1735/1736 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,197 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, live-root reclamation and full semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.

First-start register custody — 22 September 2026: the stack-domain bug report preserves three original host failures and one valid-stack control at unchanged production sources; the same four controls pass against the signed correction. Ordinary anonymous stack materialization now rejects addresses outside the existing user domain, and direct bootstrap writes require retained writable registered backing. Initial registers have Kernel-owned storage; stack preparation preserves the synthetic return slot, complete admission, startup arguments and rollback. The obsolete saved-frame user overlay and directory scan are removed. Complete external start-context admission and the separate bootstrap code/stack overlay remain distinct work.

Four strict Kernel configurations pass 807/831 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The catalog passes all 172 maintained helpers. Six native executions satisfy seven original contracts: lifetime, invocation, mapping and sparse, both allocator checks and ordinary exec-successor across all 73 components. The new witness checks all original initial register words after two real user stack mutations and before ordinary syscall capture. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The manual passes 45 tests, 2,433 pages and four changed-page visual reviews without final warnings or overflow.

Publication CI: Kernel 656/657 and Docs 1021/1022 pass. Eight complete original logs (1,600,791 bytes) confirm Kernel 807/831 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration 1737/1738 remains queued and has no completed acceptance. Earlier ext4 CI deadline failures remain unresolved. Static audits cover 3,201 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, CPU residency, live-root reclamation and complete semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.

## Summary and rationale Executable and shared-library builders use one documented compiler metadata consistency policy and crate-name mapping. Inherited, direct and internal-alias inputs must agree for each compiler-visible destination. Identical repetitions preserve the earlier file; exclusive creation prevents replacement of a newly appearing destination. Both artifact cache identities include the shared policy. Shared dynamic linking selects one available driver, validates compiler-host discovery when needed, preserves driver aliases and successful diagnostics, and treats warnings as errors. A selected driver failure cannot execute another implementation or admit partial output. Standalone links avoid unnecessary compiler queries. Fresh Kernel, Rootd and service links now require an unambiguous Rust runtime archive for each requested role; timestamps no longer select a provider. The shared selector rejects missing, ambiguous and non-file candidates. This addresses the bounded final-link defect in #62. Complete compiler provenance, cache coverage and concurrent toolchain lifetime remain separate obligations. Coordinate exact-source image construction and native authority regression coverage. The diagnostic catalog selects signed Kernel `829b949dd591bb82e6cac0fcbb47fdd1d6346cbd`; four standard-wrapper scenarios cover owned invocation, lifetime retirement, UD2 direction and hardware double-fault entry. The two exception profiles observe the actual pre-prologue callee stack. Source preparation preserves original Git objects, rejects shallow transport shortcuts, and binds complete native companion inputs into provenance and cache identity. Standalone manifest construction uses the selected catalog. Shell workspace production derives ordinary and emergency storage from the version-22 target layout; coordinated ordinary-image catalog adoption remains unfinished. ## Tracking and scope The [Phase 6 master completion checklist](https://git.erikinkinen.fi/erix/integration/issues/65) tracks all 460 acceptance items, including supplementary requirements, section weights, current acceptance, owning issues and PRs. Update it alongside this record whenever scope, accepted evidence, regressions or CI disposition changes. Current accepted completion is 15 items, 3.48% weighted; both complete builds inside EriX remain required. Signed head `56e035d46a11dc803d654bf2151e484fab307682`, branch `feature/posix-compat`. Owning issue #1; [Kernel mechanism](https://git.erikinkinen.fi/erix/kernel/issues/1), [shell review](https://git.erikinkinen.fi/erix/exsh/pulls/3), [Procd bootstrap](https://git.erikinkinen.fi/erix/procd/issues/1), and [realm design](https://git.erikinkinen.fi/erix/posixd/issues/1). The isolated catalog-packaging defect in #59 is closed. Older full-suite layout failures (#57), storage timeouts (#18), companion adoption (#52) and the accelerator-specific preboot observation (#60) retain their own acceptance gates. ## Architecture, authority and failure behavior Catalog names, manifests and descriptive identities do not confer capabilities. Diagnostic inputs retain explicit component revisions, source membership, artifact digests and bounded child-process ownership. Native oracles check actual process-bound grant custody, endpoint attenuation, caller identity, disposal and preservation of private user state. Negative scenarios retain their exact fatal exit, marker requirements and sixty-second deadline. Ordinary and emergency shell workspace slices have separate ownership and authenticated layout contracts. Reject missing or stale producer evidence before packaging. Profiling records measured host scopes and real timeout or cleanup outcomes; it does not establish guest performance or full-build success. Typed grant return, guarded bootstrap, mediator execution, complete semantic authority/source/frame audits and both complete guest build generations remain open. The ordinary runtime selection has not adopted the diagnostic graph. ## Validation evidence Original coherent-graph CI classification — 19 September 2026: [CI 1669](https://git.erikinkinen.fi/erix/integration/actions/runs/1669) records 485 passes/1 failure; [CI 1670](https://git.erikinkinen.fi/erix/integration/actions/runs/1670) records 484 passes/2 failures, each across all 486 scenarios at `8b1c037aed2503e1f2a4b17c8a8be0666d62a305`. Both retain the original 120-second ext4 quota timeout in [bug 18](https://git.erikinkinen.fi/erix/integration/issues/18); the latter also fails physical input observation in the exact-selector race scenario, now [bug 64](https://git.erikinkinen.fi/erix/integration/issues/64). That scenario explicitly passes in the paired run. All six terminal logs are complete (27,557,577 bytes), with no warning candidates; Rust and Markdown pass. No incompatible shell-layout refusal remains. The layout issue’s full source/frame prerequisites and later native-image gates remain unproved. Neither workflow was rerun, and no deadline or admission check was relaxed. Explicit zero-realm startup acceptance — 19 September 2026: Signed Integration `c479813423fb71c606fa30e5cf7d4dfb16f557d0` adds the bounded startup scenario using the existing explicit standard CLI policy. The actual VM passes the unchanged 120-second ceiling and ordered readiness checks; its signed image contains zero realm capacity in the exact 72-byte version-3 record, matching the version-6 native arena of 3,104,768 bytes. Eight route/capacity controls and four strict 320/321-unit Rust configurations pass, including fmt, host/native Clippy, native builds and private rustdoc. The original 169-helper run retains one physical-directory fixture timeout. The fixture now selects the probe’s existing ten-second command budget and has deterministic expiry controls; all four affected suites pass (9, 5, 5 and 7 tests), with unaffected source bytes verified unchanged. The original failure remains in [bug 63](https://git.erikinkinen.fi/erix/integration/issues/63). Build and validation streams contain no warnings. Original CI 1671/1672 is running. This proves ordinary startup with admission disabled; complete realm execution, source/effect/frame admission and both full builds inside EriX remain required. Coherent startup consumer acceptance — 18 September 2026: Signed Integration `8b1c037aed2503e1f2a4b17c8a8be0666d62a305` adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required. Original realm contract library prerequisite — 18 September 2026: Signed `ad85421257b7d964845fd4b84931966ad36cc122` selects the original bootstrap, capability and IPC revisions in Rootd orchestration. Only the Cargo dependency selection is published; Rust implementation and image policy remain unchanged in this commit. Four strict default/all development/release configurations pass 320/321 tests, host/native Clippy, native builds, formatting and private rustdoc without warnings. Compiler inputs contain no unpublished image-consumer changes. [CI 1667](https://git.erikinkinen.fi/erix/integration/actions/runs/1667) and [CI 1668](https://git.erikinkinen.fi/erix/integration/actions/runs/1668) are queued. Rootd can now pin this real original prerequisite before coordinated startup/image publication. Consumer VMs and both complete builds inside EriX remain required. Older CI 1663/1664 remains failed with 78 known layout refusals and one quota timeout per run; existing issues #57 and #18 retain the complete original evidence. Explicit owned receiver admission acceptance — 18 September 2026: Signed `435e69a9840b37108529e5f9f9915937a12bafc9`. The isolated native catalog selects the signed receiver-budget Kernel and coherent dependencies. All 169 helpers, four strict 320/321-unit Rust matrices and both actual native VMs pass without warnings. The owned scenario requires the receiver-admission marker before its final ownership marker; all prior lifetime and ordinary source/effect/frame gates remain intact. The existing profiler validates 48 current-source native sample processes. Costs still grow with retained populations and remain follow-up work. The changed registration fixture has a different workload hash, so no cross-source speedup comparison is admitted. Direct-native timings do not measure the separately removed packet descriptor allocation. Original CI is under observation. Actual owned Procd/Launchd service adoption, consumer VM execution, complete realm fairness/readiness/sealing and both full builds inside EriX remain open. Caller-local grant relocation checkpoint — 18 September 2026: Signed `8e66e54c86d93f257b6051da0381ff8cdc84fe2f` selects Kernel `56d398e077c140c58e23f9cc2d8b79f19bc4cc2f` and its coherent signed shared dependencies for the isolated native diagnostics. All 169 helpers, four strict 320/321-unit Rust matrices, formatting, strict Clippy, rustdoc and both actual native VMs pass without warnings. The lifetime scenario requires thirty-nine additional real CPL3 relocation controls before the original installation, revocation, terminal, inventory, queue and page oracles, with the original 60-second bound. Packaged artifacts reproduce the build outputs and all fifteen original component signatures are verified. Original CI 1663/1664 is waiting. Ordinary service source/effect and frame admission, actual owned consumer execution and both full guest builds remain separate open gates. Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision `4d4628f565d7102e6ef2987e4085fd8d97d247d3` is pushed. All 169 helpers and four strict 320/321-unit Rust matrices pass. Both actual 60-second native scenarios pass, including nineteen new CPL3 cleanup calls and the mandatory GENERATION_CLEANUP_OK marker. All earlier lifetime oracles remain required, and normally stripped packaged Kernels match their original builds. Both original CI 1661/1662 runs remain under observation. The ordinary service catalog is unchanged; ordinary source/effect/frame admission remains open. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open. Coordinated terminal observation checkpoint — 17 September 2026: Signed revision `0db8a679f5d1acb50d9ff92e003cec91f145dfc8` is pushed. The isolated catalog selects the signed generation-bearing Kernel graph. Both original 60-second native gates pass with reviewed unstripped/packaged artifacts and fifteen clean component checkouts. Four strict Rust configurations and all 169 helper commands pass; the old marker assertion was corrected to require the added generation marker. Rootd orchestration selects the same immutable shared revisions. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open. Original archive-head CI 1653/1654 is fully classified with 406/486 passing in each run; layout and filesystem timeout failures remain in #18, #20 and #57. The bounded archive-selection repair #62 is closed on its specific evidence. Current CI 1659/1660 remains under observation without restarts. - Four standard-wrapper native scenarios pass on the selected signed Kernel, with warning-free images, unchanged deadlines and exact original source selections. UD2 and double-fault reports contain five and six hardware words. - The 166-helper suite and four strict Rust development/release matrices (320 default / 321 all-feature tests) cover unchanged helper and Rust sources; affected scenario, wrapper, catalog and policy checks pass on this checkpoint. Formatting, strict Clippy, private rustdoc and Markdown checks pass. - Current-head automatic CI is pending. Earlier original runs [1647](https://git.erikinkinen.fi/erix/integration/actions/runs/1647), [1648](https://git.erikinkinen.fi/erix/integration/actions/runs/1648), [1649](https://git.erikinkinen.fi/erix/integration/actions/runs/1649) and [1650](https://git.erikinkinen.fi/erix/integration/actions/runs/1650) are fully classified: twelve complete logs, 52,533,051 bytes, zero warnings; all Rust/Markdown jobs pass. Three suites pass 408/486 with the same 78 known layout refusals; run 1647 passes 407/486 and also repeats the known quota timeout. Every full suite remains failed; no new failure set is observed. - The older automatic-KVM int8 run stalls before an EriX marker. A single explicit-TCG control passes with identical Kernel ELF bytes and unchanged deadlines; it does not replace the failed configuration (#60). - Selected Kernel push CI 582 passes; PR CI 583 fails a host receive fixture, tracked in [Kernel #6](https://git.erikinkinen.fi/erix/kernel/issues/6). No unchanged failed workflow or VM has been restarted for this checkpoint. Original CI reconciliation — 17 September 2026: CI 1651/1652 at `fa86d1b64f8e1299c0ee0c886e6f1b35d58ea15b` retains full-catalog failure. All six logs are complete, 27,230,062 bytes, zero warnings; Rust/Markdown pass. Both runs retain 78 layout refusals and the quota timeout. PR CI 1652 also retains the named idle-time-resolution timeout in #61, while original push CI 1651 passes that scenario. Totals are 407/79 and 406/80 of 486. No unchanged retry, increased deadline or accepted full guest build is claimed. Runtime archive checkpoint — 17 September 2026, signed `77921a7d97874e3f44aae66ae9bef6e6196af2f5`: Eight selector controls pass, including four original refusal subcases that fail against the predecessor. All 167 helper commands and four strict Rust configurations pass (320 default/321 all-feature tests), with formatting, Clippy, freestanding builds and private rustdoc. Both original 60-second native invocation/lifetime scenarios pass; their Kernel bytes match the earlier signed diagnostics. A separate retained-graph host package performs 38 fresh native links and reproduces its original Kernel ELF before and after stripping. These are host builds and bounded native regressions, not a complete guest build. Original automatic CI monitoring is pending; no earlier failed workflow is restarted. Linker selection checkpoint — 17 September 2026, signed `bc0e67f927ded76dd3ff5790180a7bded0886885`: Thirteen focused controls pass, including real bundled-LLD linking and warning refusal. All 168 helper commands, four strict 320/321-unit configurations, freestanding builds, formatting, Clippy and private rustdoc pass. Both original 60-second native VMs pass and preserve earlier signed Kernel bytes. A retained older graph packages through 38 fresh native links with fatal linker warnings and reproduces its original Kernel ELF. An interleaved host cProfile comparison retains twelve identical shared ELFs and verifies elimination of one compiler query per standalone link; no guest or whole-build speedup is claimed. Original automatic CI remains pending. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open. Compiler metadata checkpoint — 17 September 2026, signed `56e035d46a11dc803d654bf2151e484fab307682`: Fourteen focused controls and all 169 helper commands pass, including actual cache-key mutation coverage. Four strict 320/321-unit configurations, freestanding builds, formatting, Clippy and private rustdoc pass. Both original 60-second native VMs pass with unchanged signed diagnostic Kernel bytes. A retained older graph packages through 38 fresh native links and reproduces its original Kernel and six provider metadata/shared-object pairs. That host diagnostic retains the older deployment adapters with only the new cache-input declaration; complete current adapters have separate helper and native VM coverage. Earlier incomplete/mismatched diagnostic overlays remain recorded failures. Original automatic CI remains pending. Complete compiler-source admission, ordinary runtime adoption and both full guest builds remain open. Original Integration catalog completion — 18 September 2026: At exact revision `0db8a679f5d1acb50d9ff92e003cec91f145dfc8`, [CI 1659](https://git.erikinkinen.fi/erix/integration/actions/runs/1659) finishes with 396 passes and 90 failures out of 486; [CI 1660](https://git.erikinkinen.fi/erix/integration/actions/runs/1660) finishes with 393 passes and 93 failures. Each retains the 78 known Exsh layout refusals. The remaining 12 and 15 failures are original 120-second QEMU storage-scenario timeouts. All six terminal logs are complete (36,570,659 bytes), with zero warning candidates. Rust/unit and Markdown jobs pass. No workflow was restarted, no deadline was enlarged and no failed scenario is accepted. A shared guest or host cause is unestablished. Original generation-cleanup catalog completion — 18 September 2026: At exact revision `4d4628f565d7102e6ef2987e4085fd8d97d247d3`, [CI 1661](https://git.erikinkinen.fi/erix/integration/actions/runs/1661) and [CI 1662](https://git.erikinkinen.fi/erix/integration/actions/runs/1662) each finish with 408 passes and 78 failures out of 486. The exact failed set is the 78 known Exsh layout refusals. There are no storage timeout failures in these two observations; earlier timeout failures remain unresolved. All six terminal logs are complete (26,074,278 bytes), with zero warning candidates. Rust/unit and Markdown jobs pass. No workflow was restarted, no deadline was enlarged and no failed scenario is accepted. ## Review checklist - [x] Signed original source selection, canonical commit format and exact artifacts. - [x] Applicable strict checks, bounded diagnostics and current documentation. - [x] Inline contracts and changed code files below 1,000 lines. - [ ] Complete current-head CI and remaining ordinary-image regressions. - [ ] Finish coordinated runtime adoption and whole-codebase authority audits. - [ ] Demonstrate both complete EriX builds inside EriX before readiness. Native diagnostic observation — 19 September 2026: the first actual caller VM fails before its required success marker. Exsh exits 0xe5, Rootd exits 0xdc and the unchanged progress watchdog stops QEMU. [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) records exact reproduction and retained appliance/log identities. All 169 Integration helpers and four strict Rust configurations pass; this does not establish native execution. Request/error telemetry through the existing stdout route is under validation. No cause, weakened gate or completion credit is inferred. Signed reproducer — 19 September 2026: Integration `76411ed6d96356b20ee0a4c21ad219dacc56340d` publishes the explicit scenario and selector. With the documented image signing inputs, run `bash scripts/run-scenario.sh tests/scenarios/appliance-disk-image-realm-admission-positive.toml components.toml`. The original failed runtime uses the same scenario, implementation and component graph; only roadmap status changed after validation. Its VM result remains FAIL. All 169 helpers and four strict Rust configurations pass without warnings. Original [CI 1673](https://git.erikinkinen.fi/erix/integration/actions/runs/1673) and [1674](https://git.erikinkinen.fi/erix/integration/actions/runs/1674) are queued. [Issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) retains the failure. No acceptance credit or complete realm execution is claimed. Original CI observation — 19 September 2026: [CI 1671](https://git.erikinkinen.fi/erix/integration/actions/runs/1671) finishes with 471 passes/16 failures and [CI 1672](https://git.erikinkinen.fi/erix/integration/actions/runs/1672) with 465 passes/22 failures across all 487 scenarios at `c479813423fb71c606fa30e5cf7d4dfb16f557d0`. Every failed scenario is an ext3/ext4 positive filesystem case reporting `error: qemu timed out after 120s`, with scenario status 1. The existing [filesystem deadline report](https://git.erikinkinen.fi/erix/integration/issues/20) retains the expanded matrix; [quota issue 18](https://git.erikinkinen.fi/erix/integration/issues/18) applies to the quota failure in 1672. All six complete logs are hashed (41,592,478 bytes), with zero warning candidates. Rust, Markdown and the full helper step pass. The zero-realm startup and exact-selector race scenarios explicitly pass in both runs. No common cause, source regression boundary or performance diagnosis is inferred; all actual deadlines and failure statuses remain unchanged, and neither workflow was rerun. Corrected native caller VM — 19 September 2026: signed Integration `9139c6c5fa38c139e92520f6d410626b4cf1e4aa` selects Launchd `ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6`, Exsh `9c0f7ab851d527dd9dd10161d6a98e1fdc14598e` and Docs `ce8a1538ab2220f1b346e1a051265f58f83f47fc`. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one `ERIX_EXSH:REALM_ADMISSION:VERIFIED` precedes `ERIX_ROOTD:INITIAL_EXSH:EXITED_OK`. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present. All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 `bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7`; the post-VM writable disk has SHA256 `8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938`. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in [issue 66](https://git.erikinkinen.fi/erix/integration/issues/66). The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original [Integration CI 1675](https://git.erikinkinen.fi/erix/integration/actions/runs/1675) and [1676](https://git.erikinkinen.fi/erix/integration/actions/runs/1676) are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item. Native guarded preparation — 19 September 2026: signed Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` selects signed Exsh `ffe50612889dd58a45a40d04593a4aa3a3ffa512` for the separate `appliance-disk-image-realm-preparation-positive` scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects `bin/true` inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced. Exactly one admission marker and one `ERIX_EXSH:REALM_PREPARATION:VERIFIED` precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is `7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff` (55,776 bytes); post-VM writable disk SHA256 is `3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499`. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena. All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required. Original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) and [1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) are queued. Original [Exsh CI 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272) are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item. Original guarded-preparation CI — 19 September 2026: [Exsh run 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272), for signed `ffe50612889dd58a45a40d04593a4aa3a3ffa512`, both fail the required complete frame proof. All 976 Rust tests and 355 checker controls pass. Four complete hashed logs total 320,166 bytes without warnings; Markdown passes. Each original workflow reports four complete workspace mappings and incomplete runtime/all frame observations (101/68 unresolved). These actual CI observations are distinct from the local eight-configuration frame observations. The passing guarded-stage VM does not waive this failure. No workflow was rerun or cancelled to obtain acceptance. Guarded-custody documentation reconciliation — 19 September 2026: signed [Posixd PR 5](https://git.erikinkinen.fi/erix/posixd/pulls/5), `9b031a8c2f996491a322046a4f2acd5dacdc55c2`, replaces stale grant-return and proposed-custody gaps with the implemented producer boundary. Procd uses the actual returned grant to attenuate the initial endpoint to RECV before execution, removes bypass sources, and retains nested custody beneath Kernel lifetime custody. A later mediator disposal report cannot prove absence of bypass senders. Exact staged abort and the remaining counted startup, readiness, configuration, sealing, client I/O and running-realm retirement requirements are distinguished. This repository still has no Posixd executable. Markdown, canonical headings/governance, local links, original source anchors and whitespace checks pass. Original [Posixd CI 17](https://git.erikinkinen.fi/erix/posixd/actions/runs/17) and [18](https://git.erikinkinen.fi/erix/posixd/actions/runs/18) both pass from two complete hashed logs totaling 7,232 bytes without warnings. Rust checks do not apply to this documentation-only repository. Signed [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), `7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d`, removes the matching stale passages from the process-services manual. All 45 tests and the full 2,419-page manual pass. All 445,847 word boxes lie within page bounds; the actual changed paragraphs and continuation on pages 222, 226 and 227 are visually reviewed, with zero final warnings. Shared API snapshots are unchanged. Original [Docs CI 977](https://git.erikinkinen.fi/erix/docs/actions/runs/977) and [978](https://git.erikinkinen.fi/erix/docs/actions/runs/978) are running. These documentation corrections add no runtime behavior; the previously retained Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` appliance retains its original source selection and passing guarded-preparation evidence. Native upstream Rust/LLVM rebuilding and both complete EriX builds remain required. Process-start census correction — 19 September 2026: signed Kernel `b762e19d0c16acd605d0f6123994a586cc6fcde1` requires a successful install-grant absence census before process start. An unavailable census returns the existing refusal and preserves the whole staged child and grant state. Hosted controls cover unavailable census, actual grant disposal and malformed-target precedence. Normal bootstrap initializes tracking before admission; production reachability of the injected condition or a native authority escape is not established. [Kernel issue 18](https://git.erikinkinen.fi/erix/kernel/issues/18) uses the canonical bug report and records the original failure and bounded correction. Four strict Kernel matrices pass 704/728 library tests and two standalone controls each; three existing ignored tests remain ignored. Formatting, strict host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass. Original [Kernel CI 606](https://git.erikinkinen.fi/erix/kernel/actions/runs/606) and [607](https://git.erikinkinen.fi/erix/kernel/actions/runs/607) pass from all four complete hashed logs (739,843 bytes), without warnings. Signed Integration `b65183ddb93eb4396d4140a002c3727fec42ff87` selects that Kernel and the reconciled Docs `7b79f8d50ab1aa123c6c74c427f5aa1a50a1db9d`, preserving all other catalog entries and all previously checked orchestration bytes. The matching guarded-preparation VM passes both unique markers and ordinary successful shell exit under unchanged 120-second hard and 45-second progress limits. All 106 artifacts, all 73 original component identities and the actual signed image are verified without warnings. Serial SHA256: `a373a8ccd81ac3efbaa492cbf2e1f991f3cc34dcbf23a1435c1c48cd75cd5c1c` (55,776 bytes); signed boot-image SHA256: `3b88d37183cf36dcbd5f1105cc0fd86e79aa4489d311300003f3f362c24bcd0a`. This remains an unstarted staging fixture. Normal native execution does not exercise the hosted unavailable-census condition. The prior complete 169-helper/four-matrix Integration evidence is verified against unchanged implementation bytes. Focused catalog/source checks pass, including 46 immutable-source and five tool-selection tests. An initial host fixture failure caused by disabling its deliberate Git replacement setup is retained; the established helper environment passes without altering product checks. The static census covers 3,127 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 170 direct missing_docs gates and 92 conventional crate roots; complete semantic authority and private-documentation closure remain open. Original [Integration CI 1679](https://git.erikinkinen.fi/erix/integration/actions/runs/1679) and [1680](https://git.erikinkinen.fi/erix/integration/actions/runs/1680) are queued. Earlier 1677/1678 remains queued and 1675/1676 is running. No unchanged workflow is rerun or cancelled. Complete mediator execution, full source/effect/frame proof, upstream Rust/LLVM rebuilding and both full EriX build generations inside EriX remain required. No whole acceptance item is newly completed. Shared native terminal transition — 19 September 2026: signed Kernel `37d9c74d6d1209729c520a52a274c1646efe225c` consolidates exit and kill event reservation, lifetime preflight, exact-generation commit and receiver/invocation retirement into one documented implementation. Existing public behavior and root exit cleanup remain unchanged. Terminal state and actual resource destruction stay separate. This completes the terminal-refactor prerequisite in [child lifetime design #19](https://git.erikinkinen.fi/erix/kernel/issues/19); it introduces no lifetime binding, new opcode or additional authority. Four strict Kernel matrices pass 704/728 library tests and both standalone controls, with three existing ignored tests unchanged. All thirteen native build/Clippy profiles, formatting, host/native Clippy and private rustdoc pass without warnings. Original [Kernel CI 608](https://git.erikinkinen.fi/erix/kernel/actions/runs/608) and [609](https://git.erikinkinen.fi/erix/kernel/actions/runs/609) pass from all four complete hashed logs (739,870 bytes), without warnings. Signed Integration `a62d1381f56a01afc692112d9b427205eaeb6a2e` updates both full Kernel selectors and five stale native diagnostic selectors while preserving source memberships and tested orchestration bytes. Both maintained native runners pass their original 60-second scenarios: lifetime revocation and owned invocation. Complete serial logs are retained (1,807 and 1,587 bytes), QEMU stderr is empty, and build warnings are absent. Packaged Kernel bytes match retained unstripped artifacts; all fifteen exact original component trees and signatures verify. Four current strict 320/321-test Integration matrices, native builds, formatting, host/native Clippy and private rustdoc pass. Seven focused source/native-policy checks pass; the complete 169-helper evidence remains hash-bound to unchanged implementation bytes. Original [Integration CI 1681](https://git.erikinkinen.fi/erix/integration/actions/runs/1681) and [1682](https://git.erikinkinen.fi/erix/integration/actions/runs/1682) are queued; older corrected 1675/1676 remains running. The static census covers 3,128 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 170 direct missing_docs gates and 92 conventional roots. Full semantic authority and private rustdoc closure remain open. Native child-lifetime custody, running mediator lifecycle, full frame proof, upstream Rust/LLVM rebuilding and both full EriX build generations inside EriX remain required. No whole phase acceptance item is added. Original corrected-source CI checkpoint — 19 September 2026: at signed Integration 9139c6c5fa38c139e92520f6d410626b4cf1e4aa, original [push CI 1675](https://git.erikinkinen.fi/erix/integration/actions/runs/1675) passes all 488 VM scenarios. Original [PR CI 1676](https://git.erikinkinen.fi/erix/integration/actions/runs/1676) passes 487/488 and fails only `subsystem-e2fs-fat-ext3-htree-positive` at the unchanged 120-second QEMU limit. Both pass `appliance-disk-image-realm-admission-positive`; both Rust and Markdown jobs pass. Six complete hashed logs contain 27,276,890 bytes and no warnings. No rerun or cancellation supplies either result. The ext3 timeout remains tracked in [issue 20](https://git.erikinkinen.fi/erix/integration/issues/20); its cause is not inferred from the passing sibling run. The private script-route admission defect is corrected and natively demonstrated, while full realm lifecycle, complete frame proof and guest builds remain open. Native child lifetime checkpoint — 19 September 2026: signed Kernel 1428885e6d27e8e2bcefbbf68caf22ece253aac9 implements operation 58 using the actual Running caller, an exact Created child, independent Process authority and its real local install grant. It consumes only that grant, reserves cohort events before terminal effects, stops descendants before their supervisor and retains each bound child's cleanup duty and first failure independently of userspace survival. Return-boundary disposal closes outgoing accounting and respects current/active-interval protection. Fourteen new real-object controls cover refusals, rollback, nested stopping, a 257-descendant tree, late preflight failure, exact reuse and failed explicit abort after unlinking. Four strict 718/742-test configurations and both standalone controls pass; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Original [Kernel CI 610](https://git.erikinkinen.fi/erix/kernel/actions/runs/610) and [611](https://git.erikinkinen.fi/erix/kernel/actions/runs/611) pass from four complete hashed logs, 751,929 bytes, without warnings. The matching maintained lifetime VM passes its original 60-second scenario with the additional `ERIX_KERNEL:CHILD_LIFETIME_OK` marker. A real CPL3 supervisor proves ChildPopulate refusal, malformed/generation refusal, actual Process-route binding, start and exit. An independent observer verifies both exact children, CSpaces and mappings absent before terminal-event consumption, then disposes the unbound supervisor. The runnable child has a faulting sentinel and intentionally does not execute. All sixteen additional mapped pages are disposed. The original owned-invocation VM also passes its unchanged scenario. Complete serial logs contain 1,838 and 1,587 bytes; QEMU stderr is empty and build warnings are absent. Packaged Kernel bytes match retained original unstripped artifacts and all fifteen selected component signatures verify. Lifetime serial SHA256 is `012b46541b7c1c89d954cdbebda855037152a4e39ffad20ad7bdcc8c7b5c2572`. This establishes explicit native supervision with actual caller-side CPL3 evidence. Executing-child, no-successor native idle, allocation/partial-effect failure coverage, Procd adoption, running-mediator failure, provider completion, complete source/effect/frame proof, upstream Rust/LLVM rebuilding and both full EriX-in-EriX generations remain open. Host idle controls do not establish native interrupt or wakeup behavior. No whole phase acceptance leaf is added. Signed Docs 9ca5a5e811766a4506c0626cd58f8e228d0bacf8 updates the technical manual's native admission, preflight, stopping, partial cleanup and safe return/idle contracts. All 45 tests and the complete 2,425-page manual pass with zero final warnings. All 447,213 word boxes are in bounds and all three changed contract pages are visually reviewed. Shared API reference source is unchanged. Original [Docs CI 981](https://git.erikinkinen.fi/erix/docs/actions/runs/981) and [982](https://git.erikinkinen.fi/erix/docs/actions/runs/982) pass from four complete hashed logs, 773,510 bytes. Both pass 45 tests and the complete 2,425-page manual. TeX pass warning counts are 36/1/0, with zero final-pass warnings; neither workflow was rerun or cancelled. Signed Integration 581226ab5435dc66c6f93157606b6d4d83475b15 selects the coherent original Kernel/lib-capabi/lib-ipc graph and updated manual. All four current strict 320/321-test configurations, four native builds, fmt, strict host/native Clippy and private rustdoc pass without warnings. Source and updated native-policy checks pass; the full 169-helper evidence remains bound to unchanged orchestration bytes. The final post-VM changes select only the newer Docs revision and update roadmap status; native source catalog, scenario, runtime and orchestration bytes are unchanged. Original [Integration CI 1683](https://git.erikinkinen.fi/erix/integration/actions/runs/1683) and [1684](https://git.erikinkinen.fi/erix/integration/actions/runs/1684) are queued. Executing-child and terminal-reply checkpoint — 19 September 2026: signed [Kernel dd9eace5](https://git.erikinkinen.fi/erix/kernel/commit/dd9eace5b52edc02e624f142e92b85032f59bace) validates actual CPL3 nested-child execution and current-child ancestor termination. Synchronous control dispatch now ends its request borrow before effects and checks original caller identity, generation and terminal state before any response write. It keeps terminal completion in Kernel-owned result registers with zero reply length; ordinary native return switches away. A surviving caller retains its normal encoded response. Two focused actual-object regressions cover terminal request preservation and the surviving-caller reply. The dispatcher is split from the tracing/policy file. A supervisor binds and starts a child; that child binds a staged grandchild and kills its supervisor through its own explicit Process SEND route. Read-only witnesses require terminal caller storage to survive dispatch, then exact child/grandchild absence before the independent observer reads child-before-supervisor events. Both terminal payloads have immediate UD2 sentinels. An unrelated Created process retains its exact record, empty capability inventory and mappings until explicitly aborted. All four additional lifetimes and twenty-two mapped pages must be disposed for `ERIX_KERNEL:CHILD_EXECUTION_OK`. Four strict Kernel configurations pass 720/744 library tests and both standalone controls; three existing ignored tests remain. Formatting, host/native Clippy, private rustdoc and thirteen native build/Clippy profiles pass without warnings. Signed [Integration c14c5a61](https://git.erikinkinen.fi/erix/integration/commit/c14c5a617196a9b135b479601ca47a21371a9482) requires the additional marker while preserving every earlier marker and the original 60-second limit. Both actual native scenarios pass, with 1,870/1,587 complete serial bytes, empty QEMU stderr and no build warnings. Packaged Kernel bytes equal retained original artifacts after normal stripping; all fifteen original source signatures verify. Lifetime serial SHA256 is `1b2f983239efca55c8bc0f6f08ee91cfdcd37d4d1f6951bbd740e4d9b45d1a2f`. Four current Integration 320/321-test configurations, native builds, strict Clippy, formatting, private rustdoc and updated policy checks pass. Earlier 169-helper evidence is hash-verified against unchanged orchestration; it was not rerun for these scenario/catalog changes. Signed [Docs b4b01d87](https://git.erikinkinen.fi/erix/docs/commit/b4b01d870757d9b626dd2cfa7c6424332087bf62) documents the executing-child observations and remaining limits. All 45 tests, the full 2,425-page manual, 447,382 word bounds and visual review of the changed pages pass, with zero final warnings. The API reference source is unchanged. This extends native executing-child evidence; it does not establish no-successor native idle/wake behavior, provider completion, Procd adoption or a complete service lifecycle. The original install-grant constructor still gives `GRANT | MINT` while binding needs only `GRANT`; move-only transfer preserves exact rights. Both diagnostic grants are consumed, but rights minimization remains an explicit audit follow-up. Full source/effect/frame proof, the Pagerd gate, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related implementation tracking: [Kernel feature](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Original [Kernel CI 614](https://git.erikinkinen.fi/erix/kernel/actions/runs/614) and [615](https://git.erikinkinen.fi/erix/kernel/actions/runs/615) pass from four complete hashed logs, 753,462 bytes, without warnings. Original [Docs CI 983](https://git.erikinkinen.fi/erix/docs/actions/runs/983) and [984](https://git.erikinkinen.fi/erix/docs/actions/runs/984) pass from four complete hashed logs, 773,542 bytes. Both pass all 45 tests and the complete 2,425-page final manual; reference-resolution warning counts are 36/1/0, with zero final warnings. Original Integration CI 1685/1686 remains queued at its second observation. Older original [Integration CI 1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) passes all 489 catalog scenarios and both native Kernel diagnostics, then fails the development COM1 editor probe after its physical counterpart passes. Rust and Markdown pass. All three complete logs total 13,384,697 bytes with no warnings; the outer input status does not establish cause. The canonical bug report is [issue 67](https://git.erikinkinen.fi/erix/integration/issues/67), with bug/ci/phase-6 metadata. Earlier editor and filesystem failures remain separate. No original workflow was cancelled or rerun. Native cleanup without a userspace successor — 19 September 2026: signed [Kernel 2cf5b34c](https://git.erikinkinen.fi/erix/kernel/commit/2cf5b34c77451e4ddfa50f6bab9ae65cc5c47068) adds a seventh actual CPL3 caller to the maintained lifetime diagnostic. After every earlier assertion, the observer binds/starts the final child and yields. The child kills that supervisor through its own explicit Process SEND route. Immediate faulting sentinels forbid either terminal payload from resuming. Ordinary native return closes CPU accounting, detaches current attribution, progresses reclamation and finds no runnable successor. A diagnostic-only read-only witness then requires empty CPU accounting, only terminal retained records, no bound cleanup duties or event reservations, exact child identity/CSpace/mapping absence and both unconsumed child-before-supervisor events. All six final child pages retire; three original unbound terminal records remain for prior assertions. The witness neither performs cleanup nor selects a process nor installs an interrupt. `ERIX_KERNEL:CHILD_IDLE_CLEANUP_OK` precedes completion before HLT, so actual hardware halt/wakeup remains a separate gate. Signed [Integration 4d6f4fe8](https://git.erikinkinen.fi/erix/integration/commit/4d6f4fe8b383603b225b04a7771a11f32886e0a9) requires the additional marker while preserving all earlier assertions and both 60-second scenario limits. Both actual native VMs pass: 1,905/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256: `4a7cba61f75f4eeac47896d165b8dbcd217e4c75e2a81c8ae0f29957facb929c`. Packaged Kernel images match retained build artifacts after normal stripping; all fifteen original component signatures verify. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Post-VM changes only select updated Docs in full catalogs and update roadmap status. Signed [Docs 69466a64](https://git.erikinkinen.fi/erix/docs/commit/69466a64c032d575569adeff14f17a445e5a9c03) documents the pre-halt boundary and consolidates stale status paragraphs. All 45 tests, the complete 2,425-page manual, 447,534 word bounds and visual review of pages 562–564 pass with zero final warnings. API reference source remains unchanged. The static audit passes 3,140 authored code files below 1,000 lines, 74 manifests, 259 full Git selections, 171 direct missing_docs gates and 92 conventional crate roots; semantic authority and complete private-rustdoc closure remain open. Original [Kernel CI 616](https://git.erikinkinen.fi/erix/kernel/actions/runs/616) and [617](https://git.erikinkinen.fi/erix/kernel/actions/runs/617) pass from four complete hashed logs, 753,458 bytes, with no warnings. Original [Docs CI 985](https://git.erikinkinen.fi/erix/docs/actions/runs/985) and [986](https://git.erikinkinen.fi/erix/docs/actions/runs/986) also pass: four complete hashed logs, 773,510 bytes; both pass 45 tests and the final 2,425-page manual. Reference-resolution warning counts are 36/1/0 with zero final warnings. Original Integration CI 1687/1688 remains queued at its first observation. Older original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) is now terminal failure: all 489 catalog cases, both native diagnostics, development physical/COM1 editor and release physical editor pass before release COM1 fails. Rust and Markdown pass. Three complete logs total 13,385,246 bytes without warnings; [bug 37](https://git.erikinkinen.fi/erix/integration/issues/37) retains this evidence. Companion 1678's earlier development COM1 failure remains separate in [bug 67](https://git.erikinkinen.fi/erix/integration/issues/67); a common cause is unproven. No original workflow was cancelled or rerun. Further native failure controls, grant-rights minimization, terminal accounting, Procd adoption and complete service lifecycle acceptance remain open. Existing install-grant creation still supplies GRANT | MINT while binding needs GRANT, so minimum authority is not claimed. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Further original CI observations — 19 September 2026: original Integration `b65183ddb93eb4396d4140a002c3727fec42ff87` now has both terminal outcomes recorded. [Run 1679](https://git.erikinkinen.fi/erix/integration/actions/runs/1679) passes 488/489 catalog cases; only ext4 quota exceeds its unchanged 120-second deadline, retained in [bug 18](https://git.erikinkinen.fi/erix/integration/issues/18). Its later native/interactive gates are not reached. [Run 1680](https://git.erikinkinen.fi/erix/integration/actions/runs/1680) passes all 489 catalog cases and both native diagnostics, then fails development COM1 directory input after its physical counterpart passes; the last observation is command 6 injection, retained in [bug 56](https://git.erikinkinen.fi/erix/integration/issues/56). Later release directory/editor gates are not reached. Both Rust and Markdown jobs pass. Six complete hashed logs total 27,238,688 bytes with zero warning candidates. Causes remain unclassified; no unchanged rerun, cancellation or deadline change occurred. Original current Integration 1687/1688 remains queued at its second observation. Acceptance stays 15/460, 3.48% weighted; native toolchain rebuilding and both full EriX-in-EriX generations remain open. Native terminal-event allocation refusal — 19 September 2026: signed [Kernel ba03995f](https://git.erikinkinen.fi/erix/kernel/commit/ba03995fe0dcfc3d4a1f72eb000e0c7698bbcbaa) extends the actual executing-child sequence with one deliberately refused heap allocation. Separate diagnostic preparation captures the original supervisor, child, staged grandchild and independent process records/capability inventories, then gives an empty event queue one-event capacity. No queued event or existing reservation is discarded. The first terminal-event reservation succeeds; the second arms exactly one null return from the real Kernel allocator. Ordinary collection growth and Process dispatch return RESOURCE_EXHAUSTED before any terminal effect. Read-only witnesses require complete reservation rollback, an empty event queue, unchanged exact records and capabilities, and preserved code/stack/message mapping ranges. Actual CPL3 instructions validate the refusal reply before the next ordinary ancestor kill succeeds with allocation available. Every earlier terminal, descendant-disposal, independent-process and no-successor idle assertion remains required. `ERIX_KERNEL:TERMINAL_EVENT_RESERVATION_OK` requires one consumed allocator refusal and no remaining armed fault. Fault controls are absent from ordinary images; this covers injected allocation failure, not spontaneous heap exhaustion or independent resource-release failure. No witness supplies a syscall result, cleanup effect or scheduler choice. Signed [Integration cf5b2f5f](https://git.erikinkinen.fi/erix/integration/commit/cf5b2f5f1d63631e69df3074d7c1c0b9b4921480) requires the new marker without changing either 60-second limit. Both maintained native VMs pass: 1,948/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is `d485019082175f769ecc2d406d88c6cc84a7df323605027663f5bcc79ca03ad9`. Packaged Kernel bytes match retained original artifacts after normal stripping, and all fifteen original source signatures verify. Post-VM changes only select updated Docs in full catalogs and consolidate roadmap status. Four strict Kernel 720/744-test matrices, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test matrices, four native builds, formatting, host/native Clippy, private rustdoc and updated policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed [Docs 62ba2ffa](https://git.erikinkinen.fi/erix/docs/commit/62ba2ffa30ff9f04840c8d38d188b414e5b24b90) passes 45 tests, the complete 2,425-page manual, all 447,688 word bounds and actual visual review of pages 562–565, with zero final warnings; API reference source remains unchanged. The static audit passes 3,142 authored code files below 1,000 lines, 74 manifests, 259 full Git pins, 171 direct missing_docs gates and 92 conventional roots. Complete semantic authority and private-rustdoc closure remain open. Original [Kernel CI 618](https://git.erikinkinen.fi/erix/kernel/actions/runs/618) and [619](https://git.erikinkinen.fi/erix/kernel/actions/runs/619) pass from four complete hashed logs, 753,434 bytes, with zero warnings. Original [Docs CI 987](https://git.erikinkinen.fi/erix/docs/actions/runs/987) and [988](https://git.erikinkinen.fi/erix/docs/actions/runs/988) pass from four complete hashed logs, 773,506 bytes: both pass 45 tests and the final 2,425-page manual, with reference-resolution warning counts 36/1/0 and zero final warnings. Original Integration CI 1689/1690 is queued. Earlier filesystem, directory, editor and full-frame regressions remain unresolved; original workflows were not cancelled or rerun. The terminal-accounting audit confirms that ordinary Procd terminal handling queries original TCB counters after receiving its event, while automatic bound-child reclamation removes that TCB. Its separate private-mediator branch does not take the same query path; adoption must state which lifetimes require retained metrics and preserve their original generation without fabricated zero/wall-clock values. Independent release-failure coverage, grant-rights minimization, accounting, Procd adoption and full mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Historical pre-correction CI reconciliation — 19 September 2026: original [Integration run 1673](https://git.erikinkinen.fi/erix/integration/actions/runs/1673) and [1674](https://git.erikinkinen.fi/erix/integration/actions/runs/1674), at `76411ed6d96356b20ee0a4c21ad219dacc56340d`, are terminal failures. Each passes 487/488 catalog scenarios and fails only `appliance-disk-image-realm-admission-positive`, reporting the unchanged 45-second serial-progress watchdog. Later native and interactive workflow gates are not reached. Both Rust and Markdown jobs pass. Six complete hashed logs total 27,087,569 bytes with zero warning candidates. Neither workflow was cancelled or rerun. These runs precede the retained correction at `9139c6c5fa38c139e92520f6d410626b4cf1e4aa`; both later original runs 1675/1676 passed that realm-admission scenario. [Issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) retains the historical evidence and its existing closed state. This does not establish a new current-source regression, full lifecycle acceptance or full guest builds. Current Integration 1689/1690 remains queued at its second observation; acceptance stays 15/460, 3.48% weighted. Independent native child release recovery — 19 September 2026: signed [Kernel 82d88b60](https://git.erikinkinen.fi/erix/kernel/commit/82d88b609bd808a840780993da315230dd14399a) extends actual supervisor-exit coverage with two deliberate refusals at the original staged child's final VSpace-release callback, after capability disposal and unlinking. The first error is KernelHeapExhausted, the second CspaceSlotMissing. Read-only observations around two ordinary CPL3 observer yields require the original full record, generation, abort custody and first error retained, an empty original CSpace and retained mapped backing. The independent running child must already be absent from native TCB, CSpace and VSpace directories. The selected child's earlier directory position ensures its failure preceded that independent disposal. The third callback must perform normal VSpace release before all original terminal-event, generation and resource-absence checks pass. `ERIX_KERNEL:CHILD_RELEASE_ISOLATION_OK` requires exactly two refusals and complete eventual disposal. Fault control uses only atomics at the locked callback boundary and exists only in the isolated native diagnostic. No witness performs cleanup, supplies a successful release/syscall result or chooses a scheduler target. This establishes injected callback-refusal coverage, not an observed hardware or allocator malfunction. All earlier nested-child, allocation-refusal and no-successor pre-halt assertions remain required. Signed [Integration 294a467a](https://git.erikinkinen.fi/erix/integration/commit/294a467a3bcd9464ea55c32dbce98acf19d0e400) requires the added marker with both original 60-second limits unchanged. Both maintained native VMs pass: 1,988/1,587 serial bytes, empty QEMU stderr and no build warnings. Lifetime serial SHA256 is `606fff037be022c876220d8e8f329c9046ffea5dcdf80831026649aedfbe0b08`. Packaged Kernel bytes match retained original unstripped artifacts after normal stripping, and all fifteen original component signatures verify. Post-VM changes only select the updated manual source in full catalogs and reconcile roadmap status. Four strict Kernel 720/744-test configurations, both standalone controls and thirteen native build/Clippy profiles pass; three existing ignored tests remain. Four strict Integration 320/321-test configurations, four native builds, formatting, host/native Clippy, private rustdoc and changed policies pass without warnings. Prior 169-helper evidence is hash-verified against unchanged orchestration. Signed [Docs 2a0ccc1a](https://git.erikinkinen.fi/erix/docs/commit/2a0ccc1a595c3e03aa6c7b7ecbcaca8830082ddd) passes 45 tests, the complete 2,427-page manual, all 447,789 word bounds and actual visual review of pages 562–565 with zero final warnings. API reference source is unchanged. Static audit passes 3,143 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 171 direct missing_docs gates and 92 conventional roots; complete semantic authority/private-rustdoc closure remains open. Original Kernel CI 620/621 and Docs CI 989/990 pass from four complete hashed logs each (753,438/773,910 bytes), with zero final warnings. Current Integration originals are observed after publication. Earlier filesystem, directory, editor and full-frame regressions remain unresolved, with original evidence retained; no workflow is cancelled or retried unchanged. The grant-rights audit confirms actual Procd derivation callers and exact GRANT | MINT receipt checks in Procd and Launchd. Grant authority minimization must coordinate those consumers and distinguish the grant's own rights from its installation ceiling. Original generation-bound terminal accounting, Procd adoption, provider completion, hardware halt/wakeup and complete mediator lifecycle remain open. Full source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain mandatory. No whole acceptance leaf is added: 15/460, 3.48% weighted. Related: [Kernel design](https://git.erikinkinen.fi/erix/kernel/issues/19), [Kernel WIP PR](https://git.erikinkinen.fi/erix/kernel/pulls/3), [Integration WIP PR](https://git.erikinkinen.fi/erix/integration/pulls/12), [manual WIP PR](https://git.erikinkinen.fi/erix/docs/pulls/4), and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Explicit grant implementation progress — 20 September 2026: Kernel commit [4a5333f760e258ebca23047a362d1cff4fded0c0](https://git.erikinkinen.fi/erix/kernel/commit/4a5333f760e258ebca23047a362d1cff4fded0c0) is signed and pushed. Creation preserves exact own grant rights, including zero. Derivation requires actual MINT and subsets of both own rights and installation scope. Zero-right custody still blocks process start until disposed. Four strict 724/748-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings; three existing ignores remain. Original CI 622/623 passes from four complete hashed logs, 756,715 bytes, zero warnings. The new actual CPL3 derivation/disposal controls and GRANT-only relocation/installation compile; their matching VM execution remains pending. Integration commit [9166f7bde6a0b42afd3ef1c9898b9e818df9af86](https://git.erikinkinen.fi/erix/integration/commit/9166f7bde6a0b42afd3ef1c9898b9e818df9af86) is a signed orchestration-library dependency checkpoint. Four strict 320/321-unit configurations and four native library builds pass without warnings. Original CI 1693/1694 is waiting at its first observation. The full image catalogs still retain their preceding coordinated selection until actual consumers are validated together. Shared wire and dependency checkpoints, each with strict matrices and original CI passing: [lib-ipc issue/PR](https://git.erikinkinen.fi/erix/lib-ipc/issues/1), [lib-capabi issue/PR](https://git.erikinkinen.fi/erix/lib-capabi/issues/1), [lib-bootstrap issue/PR](https://git.erikinkinen.fi/erix/lib-bootstrap/issues/1), [lib-interrupt issue/PR](https://git.erikinkinen.fi/erix/lib-interrupt/issues/1), [lib-service issue/PR](https://git.erikinkinen.fi/erix/lib-service/issues/1), [lib-time issue/PR](https://git.erikinkinen.fi/erix/lib-time/issues/1), [lib-block issue/PR](https://git.erikinkinen.fi/erix/lib-block/issues/1), [lib-log issue/PR](https://git.erikinkinen.fi/erix/lib-log/issues/1), [lib-driver issue/PR](https://git.erikinkinen.fi/erix/lib-driver/issues/1), [lib-vfs issue/PR](https://git.erikinkinen.fi/erix/lib-vfs/issues/1). Their linked WIP PRs retain the detailed signed revisions and validation. The consumer audit also identified Loaderd and Deviced receipt checks. Procd's move-only handoff cannot attenuate the original delegating grant: it now derives a GRANT-only final receipt into the already-disposed VSpace receipt slot and drops the source before returning that receipt. Nonderiving materialization and rootless mediator paths request GRANT directly. Partial failure retains original-generation rollback and all remaining local custody. Procd, Launchd, Rootd, Loaderd and Deviced pass their default unit suites; their full strict matrices and coherent guest validation remain open. [Deviced bug 4](https://git.erikinkinen.fi/erix/deviced/issues/4) records a separately observed quarantine test race and its test-only serialization correction. This is partial implementation evidence, not completed lifecycle or self-hosting acceptance. The canonical checklist remains 15 of 460 leaves, 3.48% weighted. Full terminal accounting, provider completion, consumer lifecycle, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both complete EriX-in-EriX generations remain required. Verified grant-rights checkpoint — 20 September 2026: Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. All thirteen shared libraries pass their strict matrices and original CI. The five direct receipt consumers pass four strict host/native configurations; original CI passes for procd 292/293, launchd 145/146, rootd 1037/1038, loaderd 99/100, deviced 206/207. [Rootd baseline regression](https://git.erikinkinen.fi/erix/rootd/issues/6) and [Deviced quarantine fixture race](https://git.erikinkinen.fi/erix/deviced/issues/4) are corrected with retained original failures and successful corrected-source CI. Manual/API updates and remaining full-catalog alignment are in progress. [Integration bug 68](https://git.erikinkinen.fi/erix/integration/issues/68) records five original CI failures (1683/1684, 1685/1686 and 1688), each with 127 manifest/catalog revision mismatches before full VM execution. All fifteen complete logs are retained, 1,512,137 bytes with no warning candidates. Individual-crate and minimal-native validation did not prove full catalog coherence. Remaining dependents are being aligned and validated bottom-up; equality and immutable-source checks are unchanged. Earlier 1681/1682 separately reached 479/489 and 487/489 VM passes, with ten and two scenario timeouts at the original 120-second bounds. Those filesystem failures require separate analysis. Canonical acceptance remains 15 of 460 leaves, 3.48% weighted. Complete lifecycle and terminal accounting, provider completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Manual and dependency validation — 20 September 2026: Docs commit [f4621ce2921b2b9fe3b1d25b4321d6b28289418e](https://git.erikinkinen.fi/erix/docs/commit/f4621ce2921b2b9fe3b1d25b4321d6b28289418e) is signed and pushed. Native selectors 32/33/54 now document exact own rights separately from installation ceilings. The process and launch chapters require GRANT-only final receipts, explicit derivation/source disposal, and original-generation rollback. Both IPC references are regenerated from signed source. All 45 tests and API checks pass; the complete 2,429-page manual has zero final warnings, all 448,913 word bounds pass, and eleven changed pages were visually reviewed. Original Docs CI 991/992 passes with four complete hashed logs, 774,346 bytes, both 45-test runs and final 2,429-page manuals. Intermediate TeX reference warnings resolve before the final pass. Thirty-one additional downstream consumers now have signed dependency-alignment checkpoints, each with four strict unit configurations, four native builds, host/native Clippy, formatting and private rustdoc passing without warnings. All 62 original CI runs pass. Their owning feature issues and WIP PRs retain exact revisions and log evidence. [Catalog regression 68](https://git.erikinkinen.fi/erix/integration/issues/68) remains open until the remaining Exsh selection and complete original catalog are validated together. Individual repository success is not full service-image acceptance. Exsh's default development tests pass 976 units. Aggregate release-test compilation and a subsequent explicitly separated library compilation each reached the local unchanged 120-second silence limit before tests ran; both failures remain retained. No release-test success is inferred, no compiler setting or deadline was relaxed, and independent configurations are being collected without rerunning failed commands unchanged. The complete source/effect/frame gate also remains open. Original Integration 1693/1694 also fails with 127 manifest/catalog mismatches each, before full VM execution. Six complete logs total 604,756 bytes, with no warning candidates. Together with 1683–1692 this is twelve retained original failing runs. Earlier full-VM filesystem timeouts remain separately tracked in [ext-family issue 20](https://git.erikinkinen.fi/erix/integration/issues/20) and [FAT32 issue 58](https://git.erikinkinen.fi/erix/integration/issues/58). Canonical acceptance remains 15/460 leaves, 3.48% weighted. Full service lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX generations remain required. Static audit currently passes 3,150 authored code files below 1,000 lines, 74 manifests, 259 explicit Git pins, 172 direct missing_docs gates and 92 conventional Rust roots; full semantic authority and documentation review remain open. Complete original catalog checkpoint — 20 September 2026: Integration [f9681efc30f1c48989def7f0e7db939974a30e27](https://git.erikinkinen.fi/erix/integration/commit/f9681efc30f1c48989def7f0e7db939974a30e27) is signed and pushed in [WIP PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12). Both complete catalogs now pass exact dependency equality against 73/70 clean original selected checkouts and 72/71 manifests; all 143 selected signatures verify. The original Integration library pin is retained independently of the catalog commit, avoiding a circular source reference. Twenty dependency-policy and 46 immutable-source tests, both native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Corrected-source original CI 1695/1696 is running; [bug 68](https://git.erikinkinen.fi/erix/integration/issues/68) remains open pending that observation and full consumer acceptance remains separate. The executed inputs for both first-attempt native VM passes remain exact: 27 new ordinary CPL3 grant-right controls, every earlier lifetime/owned-invocation assertion, original 60-second bounds, zero build warnings and empty QEMU stderr. Both packaged kernels match retained original artifacts and all fifteen original source signatures verify. The final post-VM changes only select the full catalogs and reconcile documentation. All 31 further fully validated consumer checkpoints pass four strict unit/native configurations and all 62 original CI runs; 124 complete logs total 3,041,213 bytes with no warning candidates. Their owning feature issues and WIP PRs preserve exact source and CI evidence. The full manual and regenerated IPC references are published in [Docs WIP PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4); its 45 tests, 2,429 pages, 448,913 word bounds and eleven changed-page reviews pass, as do original Docs CI 991/992 with zero final warnings. Exsh [dbc958bcdaa557a461e9308a31d23d3b8c189296](https://git.erikinkinen.fi/erix/exsh/commit/dbc958bcdaa557a461e9308a31d23d3b8c189296) in [WIP PR 3](https://git.erikinkinen.fi/erix/exsh/pulls/3) is explicitly an incomplete-validation dependency checkpoint. Both development configurations pass 976 units, four native builds and strict Clippy/docs configurations pass, and all 355 checker tests pass. Three local release-unit compilation attempts reached the unchanged 120-second silence bound before tests ran. Four local frame checks return 1 with complete workspace mapping and 97/63 unresolved routes. Original CI 273/274 likewise passes 976 units and 355 checker tests, then fails the full frame/source gate with 101/68 unresolved observations. Four complete CI logs total 319,871 bytes with zero warning candidates. These local and CI artifacts are distinct; no frame or release-unit acceptance, relaxed deadline or unchanged retry is claimed. Canonical acceptance remains 15/460 leaves, 3.48% weighted. The full in-EriX builds and native external Rust/LLVM/runtime rebuild remain unproven. Full consumer lifecycle, terminal accounting, source/effect/frame proof, the 128-page Pagerd gate and profiler attribution remain required; no canonical leaf closes at this checkpoint. Installer return-slot regression — 21 September 2026: Both original corrected-catalog runs are now classified: [1695](https://git.erikinkinen.fi/erix/integration/actions/runs/1695) passes 431/489 VM scenarios and [1696](https://git.erikinkinen.fi/erix/integration/actions/runs/1696) passes 430/489. All six complete logs are retained and hashed, 32,723,390 bytes, zero warning candidates. Rust, Markdown and full dependency equality pass. Catalog mismatch [issue 68](https://git.erikinkinen.fi/erix/integration/issues/68) is corrected; this does not establish full consumer acceptance. Each run has 57 initial-shell uncertain-disposition failures and a separately retained release-appliance stall. Run 1696 also retains the ext4 quota timeout under its original 120-second bound, tracked in [issue 20](https://git.erikinkinen.fi/erix/integration/issues/20). [Procd bug 4](https://git.erikinkinen.fi/erix/procd/issues/4) records a concrete producer/consumer mismatch. The final installer was handed off from VSpace scratch slot 1056 while later TTY provisioning requires managed grant slot 1040. The added producer regression fails on the original code. Signed Procd [10d972b652297fd656e9a6ac6dbdf197f362c7ce](https://git.erikinkinen.fi/erix/procd/commit/10d972b652297fd656e9a6ac6dbdf197f362c7ce) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) derives the exact GRANT-only result, disposes its delegating source and uniquely relocates the result back to the empty managed grant slot. Refusals preserve original-stage rollback and remaining custody. Four strict 291/296-unit configurations, four native builds, host/native Clippy, formatting, private rustdoc and policies pass with zero warnings. Corrected full-service VM validation and original CI remain open; bug 4 remains open. Acceptance remains 15/460 leaves, 3.48% weighted. Full consumer lifecycle, terminal accounting, source/effect/frame proof, Pagerd, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full in-EriX build generations remain required. Verified managed installer recovery — 21 September 2026: Signed Integration [648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d](https://git.erikinkinen.fi/erix/integration/commit/648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d) in [WIP PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12) selects signed Procd [ac8a12993bc8cbf134a11e141e459cb63df71123](https://git.erikinkinen.fi/erix/procd/commit/ac8a12993bc8cbf134a11e141e459cb63df71123) and [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4). Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed. [Procd bug 4](https://git.erikinkinen.fi/erix/procd/issues/4) is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings. The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes. The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged. Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open. Verified native terminal accounting — 21 September 2026: Kernel [a9bdf6163813d378e0b4a164bceb839e24fbb6b7](https://git.erikinkinen.fi/erix/kernel/commit/a9bdf6163813d378e0b4a164bceb839e24fbb6b7) is signed/pushed. Terminal preflight reserves final scalar CPU evidence independently of TCB/CSpace/VSpace reclamation; exact queries preserve final results or explicit errors. Repeat observations belong to the actual original observer until exact acknowledgement, and observer death releases that claim. Independent authorized observers can progress. Selector 55 is retired; checked selectors 59/60 have no destructive fallback. Four strict 736/760-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings. Host controls include nonzero final counters after actual reclamation and ID reuse, original observer death, pending-final-charge destruction refusal, malformed requests, wrong callers, immutable errors and lost-acknowledgement reply retry. Original Kernel CI 624/625 and corrected 626/627 all pass from eight complete hashed logs (1,532,848 bytes), zero warnings. Both maintained lifetime and owned-invocation VMs pass under the unchanged 60-second scenario limits and standard watchdogs, with no build warnings and empty QEMU stderr. Actual guest instructions check repeat observations and CPU queries, exact acknowledgement and absent-acknowledgement retry; executing children require nonzero user and kernel counters after native reclamation. Lifetime retains 2,025 serial bytes (SHA256 `921edf5eadfdff61f2d85a63158555666e77e57a1e8aa4254ac30dcd216f8cf9`); owned invocation retains 1,587 (SHA256 `404bc4ecad5074349d9ba45d1caf5439aebe849d344b726e5dec2ee2b9c4d907`). Normal stripping exactly matches both packaged kernels to retained original artifacts; all fifteen selected original signatures and clean checkouts verify. [Kernel regression 21](https://git.erikinkinen.fi/erix/kernel/issues/21) retains the first VM's final page-census failure. The corrected layout declares and allocates all six request pages and derives the independent census from that declaration. No unchanged retry or deadline relaxation occurred. Integration [fcd7b4a9608f629a12de78c53da5c3615d906b46](https://git.erikinkinen.fi/erix/integration/commit/fcd7b4a9608f629a12de78c53da5c3615d906b46) is signed/pushed with the verified isolated catalog. Twenty dependency and 46 immutable-source tests, native policies, Markdown and source checks pass. The unchanged orchestration crate, embedded fixture and original dependency closure retain verified four 320/321-unit and native/Clippy/rustdoc configurations. The full service catalogs retain their separately coordinated revisions; original Integration CI remains under observation. Procd and Rootd consumer adoption, ordinary and mediator metric retention/consumer loss, manual updates, full service/profiler scenarios, complete authority/source/frame audits and full regression acceptance remain open under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). Canonical acceptance remains **3.48% weighted; 15 of 460 items**. Native upstream Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory and unproven. Committed terminal-accounting consumers — 21 September 2026: Procd [66934642c4464fc738152a9e60790914ba27dd1c](https://git.erikinkinen.fi/erix/procd/commit/66934642c4464fc738152a9e60790914ba27dd1c) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI [298](https://git.erikinkinen.fi/erix/procd/actions/runs/298)/[299](https://git.erikinkinen.fi/erix/procd/actions/runs/299) passes from four complete hashed logs, 347,245 bytes, zero warnings. [Bug 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open for actual service acceptance. Rootd [64c97b13c450003d9c2b6bd9ed2a627088684b46](https://git.erikinkinen.fi/erix/rootd/commit/64c97b13c450003d9c2b6bd9ed2a627088684b46) in [WIP PR 2](https://git.erikinkinen.fi/erix/rootd/pulls/2) acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed [bug 7](https://git.erikinkinen.fi/erix/rootd/issues/7): a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI [1041](https://git.erikinkinen.fi/erix/rootd/actions/runs/1041)/[1042](https://git.erikinkinen.fi/erix/rootd/actions/runs/1042) passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates. Docs [e4525848ad4462901c9a6794ef1794cf85ea9e6b](https://git.erikinkinen.fi/erix/docs/commit/e4525848ad4462901c9a6794ef1794cf85ea9e6b) updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI [995](https://git.erikinkinen.fi/erix/docs/actions/runs/995)/[996](https://git.erikinkinen.fi/erix/docs/actions/runs/996) and corrected-table [997](https://git.erikinkinen.fi/erix/docs/actions/runs/997)/[998](https://git.erikinkinen.fi/erix/docs/actions/runs/998) passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved. The separate Integration orchestration library checkpoint [b06dfad00202765491a64552dde29eaca1c24838](https://git.erikinkinen.fi/erix/integration/commit/b06dfad00202765491a64552dde29eaca1c24838) passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance. No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure. Original acknowledged service catalog — 21 September 2026: Signed [dff878dd3545c4751b3c05d37b2bdd5e21cce548](https://git.erikinkinen.fi/erix/integration/commit/dff878dd3545c4751b3c05d37b2bdd5e21cce548) selects the original terminal-observation, exact-acknowledgement and final CPU dependency graph in both complete catalogs. All 35 application/service checkpoints are signed; the bounded VFS checker correction and its manual are included. Clean original checkouts pass manifest/catalog equality and signature checks. Exsh's release compiler and complete frame gates remain explicitly open in [issue 9](https://git.erikinkinen.fi/erix/exsh/issues/9) and [issue 4](https://git.erikinkinen.fi/erix/exsh/issues/4). All 169 maintained helper commands pass with recorded source and stream identities. The original stale memory-source rejection, quiet storage-fixture timeout and overly long socket-fixture path remain retained. Their respective corrected inputs use the explicitly verified original memory checkout, the previously maintained traced disk invocation (258.975743 seconds under unchanged 600/120 bounds), and a fresh owned shorter temporary directory (all 14 socket controls pass without changing the Unix pathname limit). None of these setup corrections changes test sources or bypasses source, timing or cleanup checks. The unchanged orchestration library retains all four strict 320/321-test configurations; formatting, policies and Markdown pass without warnings. The published runner and original full source graph are prepared for the maintained shell CPU-accounting, two-CPU inspection and out-of-session denial scenarios. Actual VM evidence remains pending and no full guest-build acceptance is awarded. Original CI [1703](https://git.erikinkinen.fi/erix/integration/actions/runs/1703)/[1704](https://git.erikinkinen.fi/erix/integration/actions/runs/1704) is being monitored without restart. Complete authority/source/effect/frame and Pagerd gates, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Actual service CPU scenarios and startup admission — 21 September 2026: The published original Integration catalog `dff878dd3545c4751b3c05d37b2bdd5e21cce548` passes the maintained shell times, two-CPU Extop and out-of-session denial VM scenarios under their unchanged 120-second guest limits. Each retains 106 hashed evidence files, warning-free image builds, empty QEMU stderr and every required, forbidden, ordered and unique marker check. Build-plus-scenario wall times are 119.876978, 34.802620 and 36.173027 seconds respectively; these are not guest-only or startup measurements. Times reports nonzero self and waited-child CPU. Extop observes both CPUs, memory and increasing job CPU nanoseconds with `CTRL no`; both per-CPU percentages remain `--.--%` in the two samples, so numeric utilization is unproven. The denial scenario confirms the existing out-of-session boundary. Complete mediator/lifecycle acceptance in [Procd 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open. A separate ordinary development package also builds without warnings, but its required startup-contract preflight exits 1 before any VM or observer starts. [Integration 69](https://git.erikinkinen.fi/erix/integration/issues/69) records the missing full-runtime-transition contract selections and Kernel effective-feature/original-source evidence. Preserve the refused package and all admission controls; the 120/15/10 capture limits and performance thresholds are unchanged. No startup-profile acceptance is awarded. Complete source/effect/frame and Pagerd proof, native external Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain required by [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65). Original full-regression observation — 21 September 2026: Original Integration [1699](https://git.erikinkinen.fi/erix/integration/actions/runs/1699)/[1700](https://git.erikinkinen.fi/erix/integration/actions/runs/1700), source `fcd7b4a9608f629a12de78c53da5c3615d906b46`, each finish at 487/489 VM passes. All six complete logs retain 28,483,276 bytes with zero warning candidates; Rust and Markdown jobs pass. The original worker boundaries identify quota's 120-second timeout in 1699 and 45-second serial stall in 1700, ext4 links' 120-second timeout in 1700, and FAT32 directory metadata's 120-second timeout in 1699. The latter has a distinct [canonical bug report](https://git.erikinkinen.fi/erix/integration/issues/70). Existing [quota 18](https://git.erikinkinen.fi/erix/integration/issues/18) and [links 20](https://git.erikinkinen.fi/erix/integration/issues/20) remain open. No shared root cause is inferred, and no unchanged rerun, cancellation or threshold relaxation is requested. Signed startup source/feature correction — 21 September 2026: Integration [fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa](https://git.erikinkinen.fi/erix/integration/commit/fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa) requires the complete runtime transition in both Rootd and its orchestration policy. The direct Kernel builder records the actual local compiler feature closure, compares original source before and after linking, and includes source identity in its cache key. Contract v2 requires the Kernel revision/tree and actual artifact/metadata binding; old receipts, synthetic wrappers and modified source cannot acquire this declaration. This remains local observed provenance, not publisher authentication or complete compiler closure. All 171 maintained helper commands have successful, warning-free final evidence. Eight new Kernel controls cover original trees, actual cfg closure, changed inputs, hidden/redirected source, custom builds, synthetic wrappers and cache identity. Sixteen fixture readers/writers now close files explicitly; [bug 71](https://git.erikinkinen.fi/erix/integration/issues/71) retains the original 36 resource warnings from 15 exit-zero commands. The previously unlisted filesystem-mirror fixture now participates in CI. Earlier Markdown failures also remain retained. Formatting, source policy and final Markdown pass; identical Rust inputs retain four strict orchestration matrices. The technical manual update [76672dff8ff83](https://git.erikinkinen.fi/erix/docs/commit/76672dff8ff83b04914abe3c8f4b08b13835144f) passes 45 tests, 2,431 pages, 450,096 word bounds and both changed-page visual reviews. Original Docs [1001](https://git.erikinkinen.fi/erix/docs/actions/runs/1001)/[1002](https://git.erikinkinen.fi/erix/docs/actions/runs/1002) passes from four complete logs totaling 774,770 bytes. Each manual log retains its earlier reference-convergence warnings; final LaTeX passes have no warnings or layout overflow. A fresh ordinary package from the signed Integration runner is under construction. Actual corrected image admission and startup capture remain pending under [bug 69](https://git.erikinkinen.fi/erix/integration/issues/69); no threshold or 120/15/10 capture limit changes. Original Integration [1705](https://git.erikinkinen.fi/erix/integration/actions/runs/1705)/[1706](https://git.erikinkinen.fi/erix/integration/actions/runs/1706) is monitored separately. Native external Rust/LLVM/runtime rebuilding and both complete EriX guest build generations remain mandatory. Actual original-source startup capture — 21 September 2026: Signed Integration [fd8a5cf0dbcf](https://git.erikinkinen.fi/erix/integration/commit/fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa) builds the ordinary image without warnings and its actual Kernel-bound contract passes preflight. The VM and complete observer finish with all required stages, zero dropped records, empty QEMU stderr, successful cleanup and unchanged source image. Admission bug 69 is resolved independently of performance. The strict timing gate fails: root-to-final readiness 5.974133160 seconds (limit 5), largest service interval 3.098663889 (limit 1), final readiness to caret 1.262470092 (limit 1), and four native commands 4.769234506 (limit 2). The maintained offline profiler identifies RTC-provider to TTYD as the largest service interval, followed by roughly one-second Powerboxd and Launchd intervals. These are host observation windows, not loader-only causal measurements. [The new canonical timing bug](https://git.erikinkinen.fi/erix/integration/issues/72) retains the exact image, timing and command identities and every original limit. Host/toolchain description fields remain explicitly incomplete; no provenance or speedup is invented. The sixteen helper stream-custody corrections also pass all changed controls; all 171 selected helper commands have successful warning-free final evidence. Bug 71 is resolved with its original 36 warnings retained. Full CI for 1705/1706 remains separately monitored. No startup-performance or full native toolchain/EriX guest-build acceptance is awarded. Current observation checkpoint — 21 September 2026: signed [9c62af2d2484](https://git.erikinkinen.fi/erix/integration/commit/9c62af2d2484b1ab0cadba768adc025dfd017485) records the actual startup outcome in the roadmap; executable and library inputs remain identical to the measured `fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa` implementation. Markdown, template structure and source policy pass. Original Integration 1701/1702 remains running; 1703–1708 remains queued. Logd 239 passes; 240 has failed, with both terminal log endpoints still returning HTTP 500. Its cause and warning classification remain unresolved. Original runs are preserved without restart or cancellation. All 3,165 authored code files remain below 1,000 lines; the static pin and missing-docs declaration checks remain intact. Full authority/source/effect/frame, startup performance and native external-toolchain/EriX guest-build acceptance remain open. Coherent scalar-consumer validation — 21 September 2026: signed [Integration 07c883525ee5](https://git.erikinkinen.fi/erix/integration/commit/07c883525ee5e23378008232760d045f74f60d32) selects [Procd 59ee30a88534](https://git.erikinkinen.fi/erix/procd/commit/59ee30a885346db4db8c8791a23c15694f2a90a8) in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven. Procd's four strict 308/314-test configurations and original CI 302/303 pass. The [manual update](https://git.erikinkinen.fi/erix/docs/commit/2d05169e6974a495eab80b62edf0f23d1ad667da) passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines. Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven. Executed-code profiling checkpoint — 22 September 2026: signed [Integration 4fa27f942bc2](https://git.erikinkinen.fi/erix/integration/commit/4fa27f942bc2c6511eedceb5b20b8212f2bc94b0), tracked in [Integration PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12), adds bounded host TCG execution counters, explicit fresh-output ownership and exact packaged-ELF code candidates without adding guest authority. All 172 maintained helper commands pass without warnings. The profiler passes five Rust tests in both profiles, strict Clippy, private rustdoc, eleven Python controls and five actual selected-emulator controls. Unchanged orchestration inputs retain their preceding four strict matrices. The [operator guide](https://git.erikinkinen.fi/erix/integration/src/commit/4fa27f942bc2c6511eedceb5b20b8212f2bc94b0/docs/tcg-profiling.md) distinguishes complete counters from VM acceptance. One original-image diagnostic retains 92,896 translated blocks, 1,994,216 code bytes and zero missed execution counts. Its top 100 code groups cover 85.65% of the translated instruction upper bound; 33.30% has Kernel mapping-batch candidates and 7.70% has VSpace permission-switch candidates among the selected ELF inputs. Unknown and ambiguous work remains visible. These are code matches, not process ownership or elapsed-time attribution. Both the instrumented attempt and its same-emulator uninstrumented control fail waiting for the final native-command marker under unchanged 120/15/10 collection bounds. Neither proves startup acceptance, whole-transcript instrumentation overhead or a speedup. [Profiler acceptance](https://git.erikinkinen.fi/erix/integration/issues/3) and [startup performance](https://git.erikinkinen.fi/erix/integration/issues/72) remain open. The next optimization must preserve complete validation, live backing checks, page permissions, invalidation ordering and cleanup on errors. The signed [manual update](https://git.erikinkinen.fi/erix/docs/commit/1ade28490f4577bbf618f4cec49debf1f747aa6d), tracked in [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), passes 45 tests, all 2,431 pages, 450,367 word bounds and both changed-page visual reviews with zero final warnings or overflow. Original Docs CI 1005/1006 passes from four complete logs (774,674 bytes); initial reference-convergence warnings resolve on the final passes. Integration 1711/1712 is queued, while original 1701/1702 still runs. Existing queued jobs remain untouched. All 3,174 authored code files remain below 1,000 lines. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and completing the required full guest-build generations remain mandatory and unproven. Native table-custody checkpoint — 22 September 2026: signed [Kernel 2e744897de7c](https://git.erikinkinen.fi/erix/kernel/commit/2e744897de7c330d3d095a65daed761a4e4a9406), in [Kernel PR 3](https://git.erikinkinen.fi/erix/kernel/pulls/3), gives unpublished table allocations one cleanup owner through translation and initialization. Empty-table installation and huge splits transfer custody at parent publication. The raw allocation-return helper and duplicate huge-split initialization are removed. Parent/leaf invalidation, interrupt masking, permission templates and current shared-hierarchy lifetime remain intact. Five host controls cover allocation/translation failure, invalid geometry, abandoned preparation and publication. Four strict configurations pass 742 default / 766 all-feature tests, retaining three existing ignored cases; formatting, host/native Clippy, private rustdoc and thirteen native builds pass without warnings. Original Kernel CI 630/631 passes from four complete logs, 771,607 bytes and zero warnings. Signed [Integration fe63adde8ff9](https://git.erikinkinen.fi/erix/integration/commit/fe63adde8ff9529faf1261dbd5da3d7f39c0f2a6), in [Integration PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12), selects that exact Kernel in all three catalogs. Every other selection and Kernel dependency manifest is unchanged. All 172 maintained helper commands pass without warnings; unchanged Rust inputs retain their preceding strict matrices. Three original-source native executions pass lifetime revocation, owned invocation and mapping checks with unchanged 60-second guest limits, warning-free builds and empty QEMU stderr. Mapping isolation and sparse mappings have identical runtime settings; both maintained marker contracts pass on the retained mapping capture. All fifteen selected component signatures verify, and each packaged Kernel image equals its retained artifact after normal stripping. These results cover the current shared hierarchy, not independent hardware roots. The [Kernel evidence update](https://git.erikinkinen.fi/erix/kernel/commit/f50535bfcd9aa57271762bb0b4da7d759d08906e) and [Integration evidence update](https://git.erikinkinen.fi/erix/integration/commit/1621164b93a7705eae381ff95aeec59b4e9527c3) change documentation only, with executable inputs proven unchanged. Their original Kernel CI 632/633 is running and Integration 1715/1716 is queued. Older full Integration CI 1701/1702 at b06dfad00202765491a64552dde29eaca1c24838 passes from six complete logs, 26,962,712 bytes and zero warnings, including both runs' ext4 quota, ext4 links and FAT32 directory-metadata cases. Their earlier timing failures remain retained with unestablished causes; [18](https://git.erikinkinen.fi/erix/integration/issues/18), [20](https://git.erikinkinen.fi/erix/integration/issues/20) and [70](https://git.erikinkinen.fi/erix/integration/issues/70) have exact follow-up observations. No workflow was rerun or cancelled. All 3,176 authored code files remain below 1,000 lines. The next work in [Kernel 22](https://git.erikinkinen.fi/erix/kernel/issues/22) must resolve the supervisor baseline, bootstrap/saved-frame overlays and inactive-space population before adding root ownership, residency and retirement. Startup timing acceptance, complete authority cleanup and the profiler's measured speedup remain open. The [phase checklist](https://git.erikinkinen.fi/erix/integration/issues/65) stays at 15/460 accepted leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven. Ordinary mapping-domain checkpoint — 22 September 2026: [resolved admission report](https://git.erikinkinen.fi/erix/kernel/issues/23) records the original host failure and bounded fix. The [fixture regression](https://git.erikinkinen.fi/erix/kernel/issues/24) retains all three distinct failed attempts and the verified layout correction. [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/ef3fd9293eaf691269fdb9e6b72eb15dac1f3f06) now validates the complete ordinary user page before backing or mapping changes, with both control paths covered. Four strict 745/769-test configurations, thirteen native builds, Clippy and private rustdoc pass without warnings. Three exact-source native executions pass lifetime, invocation and mapping; four maintained scenario contracts are checked, with sparse and isolation sharing their identical runtime capture. All fifteen selected native signatures and packaged Kernel identities verify. [Integration](https://git.erikinkinen.fi/erix/integration/commit/cd560584d034720ac179d5abc6f2a9d965943c63) pins the exact Kernel in all three catalogs, preserves every other selection and passes all 172 helpers. The unchanged ordinary exec-successor VM passes against the complete source graph, preserving its 120-second guest deadline, with no image warnings or QEMU stderr. [Docs](https://git.erikinkinen.fi/erix/docs/commit/043df99baaa9d4539da627fbfe4a234e41e74135) documents the domain and bootstrap distinction; all 45 tests and 2,431 pages pass, with 450,473 word bounds checked and no final warnings. The earlier Kernel CI 632/633 passes from four complete logs and zero warnings; current original CI remains under observation. Bootstrap provenance, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Verified documentation and CI follow-up — 22 September 2026: [Kernel documentation](https://git.erikinkinen.fi/erix/kernel/commit/d0d9e25b71664126c29727265f285df2f5ae7fea) and [Integration documentation](https://git.erikinkinen.fi/erix/integration/commit/c41bb92cd0ff5444c1680bee476a70072529fdb0) record the accepted native mapping, three-grant cleanup and ordinary exec-successor evidence. Every executable file is identical to the tested implementation; Markdown and diff checks pass. All three failed fixture attempts remain in [report 24](https://git.erikinkinen.fi/erix/kernel/issues/24), separately from the fixed [admission defect](https://git.erikinkinen.fi/erix/kernel/issues/23). The complete manual passes 45 tests and 2,431 pages with no final warnings. The final static inventory covers 3,180 authored code files below 1,000 lines, 259 exact Git pins and the existing direct missing_docs declarations; it does not establish full semantic authority closure. Original full Integration [1703](https://git.erikinkinen.fi/erix/integration/actions/runs/1703)/[1704](https://git.erikinkinen.fi/erix/integration/actions/runs/1704), source dff878dd3545c4751b3c05d37b2bdd5e21cce548, pass from six complete logs totalling 26,964,178 bytes and zero warnings. Their ext4 quota/links and FAT32 directory scenarios explicitly pass. Earlier timing failures remain retained and their causes are unestablished. Kernel [634](https://git.erikinkinen.fi/erix/kernel/actions/runs/634)/[635](https://git.erikinkinen.fi/erix/kernel/actions/runs/635) report cancelled, with runner context-cancellation messages and four complete logs. No cancellation request was issued during this work; the workflow declares no cancellation policy, and the initiating cause remains unestablished. These runs receive no CI acceptance credit. Current Kernel [636](https://git.erikinkinen.fi/erix/kernel/actions/runs/636)/[637](https://git.erikinkinen.fi/erix/kernel/actions/runs/637) and Docs [1007](https://git.erikinkinen.fi/erix/docs/actions/runs/1007)/[1008](https://git.erikinkinen.fi/erix/docs/actions/runs/1008) pass. Each pair has four complete logs: Kernel totals 773,796 bytes with zero warnings, and Docs totals 774,706 bytes with zero final warnings. Both manual builds retain their initial 35/1/0 LaTeX warning sequence through convergence. Integration 1717–1720 remains queued. The phase checklist remains at 15/460 accepted leaves, weighted 3.48%. Private hardware roots, complete authority cleanup, measured startup improvement, native external Rust/LLVM/runtime rebuilding and both complete EriX guest-build generations remain open. VSpace MAP authority checkpoint — 22 September 2026: [the resolved bug report](https://git.erikinkinen.fi/erix/kernel/issues/25) records three original failing host controls and the verified correction in [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/9fdf1a17acc9204719fee42d263dacfcd701d56c). Current local MAP rights now govern map, protection and unmap requests. Empty and MANAGE-only aliases are denied; MAP-only access remains valid. Four strict 750/774-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/c62dbf9d7096d41b5d073bc497949e16f5f16e13) selects the exact signed Kernel in all three catalogs and passes all 172 helpers. Actual CPL3 calls preserve the authorized RW/NX page across restricted-alias refusals and drop all five temporary grants. Three native executions cover all four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signed sources and retained packaged artifacts. The original exec-successor service VM passes against all 73 components with its unchanged 120-second guest limit. All image warnings and QEMU stderr remain absent. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/a96c994750ed10205e7bac17be6922a53070e2d6) passes 45 tests, 2,431 pages and 450,550 checked word bounds, with both changed pages reviewed and zero final warnings. The static audit covers 3,181 authored code files below 1,000 lines, 259 exact Git dependency pins and existing direct missing_docs gates. It does not close semantic authority review. Earlier full Integration runs 1705/1706 are running; 1707–1720 remain queued at the latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel [638](https://git.erikinkinen.fi/erix/kernel/actions/runs/638)/[639](https://git.erikinkinen.fi/erix/kernel/actions/runs/639) and Docs [1009](https://git.erikinkinen.fi/erix/docs/actions/runs/1009)/[1010](https://git.erikinkinen.fi/erix/docs/actions/runs/1010) pass. Each pair has four complete logs: Kernel totals 777,250 bytes with zero warnings, and Docs totals 774,674 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration [1721](https://git.erikinkinen.fi/erix/integration/actions/runs/1721)/[1722](https://git.erikinkinen.fi/erix/integration/actions/runs/1722) remains queued; it receives no CI acceptance credit. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX, then completing both full EriX guest-build generations, remains mandatory and unproven. Frame access checkpoint — 22 September 2026: [the resolved bug report](https://git.erikinkinen.fi/erix/kernel/issues/26) records three original failing host controls and the verified correction in [Kernel](https://git.erikinkinen.fi/erix/kernel/commit/6671466a84cdc4994384e1b8391d6a01fa66fb09). Explicit READ now governs admission and hardware activation. No-access mappings retain backing with USER/WRITE clear and NX set; write-only and execute-only requests are rejected without adding READ. Existing protection-transition rules remain in force. Four strict 757/781-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/b45edf143f599699f80e70a13827762d3e4da77e) selects the signed Kernel in all three catalogs and passes 172 helpers. Twenty-four actual CPL3 calls preserve earlier witnesses and cover no-access protection, write-only refusal, MAP-only frame derivation, denied READ and unmap after both frame grants are dropped. Three native executions pass four maintained lifetime/invocation/mapping/sparse contracts with original limits, exact signatures and retained packaged artifacts. The ordinary exec-successor VM passes against all 73 components with its unchanged 120-second guest limit. Builds emit no warnings and QEMU stderr is empty. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/45dae3cee4116b9387c4f3d3d2687a87f0fa340b) passes 45 tests, 2,433 pages and 450,702 checked word bounds, with the changed page reviewed and zero final warnings. Static review covers 3,182 authored code files below 1,000 lines, 259 exact Git pins and existing direct missing_docs gates. This does not close semantic authority review. Earlier full Integration runs 1705/1706 remain running and 1707–1722 remain queued at their latest original observations. No workflow was rerun or cancelled. Publication CI: Kernel [640](https://git.erikinkinen.fi/erix/kernel/actions/runs/640)/[641](https://git.erikinkinen.fi/erix/kernel/actions/runs/641) and Docs [1011](https://git.erikinkinen.fi/erix/docs/actions/runs/1011)/[1012](https://git.erikinkinen.fi/erix/docs/actions/runs/1012) pass. Each pair has four complete logs: Kernel totals 782,838 bytes with zero warnings, and Docs totals 775,110 bytes with zero final warnings or overflow. The manual retains its initial 35/1/0 LaTeX warning sequence through convergence. Integration [1723](https://git.erikinkinen.fi/erix/integration/actions/runs/1723)/[1724](https://git.erikinkinen.fi/erix/integration/actions/runs/1724) remains queued; it receives no CI acceptance credit. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Authorized protection restoration, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Ordinary protection contract — 22 September 2026: [the runtime memory design](https://git.erikinkinen.fi/erix/kernel/issues/1) now specifies in-place no-access/R/RW/RX changes using current VSpace MAP and exact selected frame authority, including same-backing aliases and complete backing checks. Preserve W^X, explicit READ, object kind, reference custody, error ordering and all native witnesses. Kernel-owned anonymous loader materialization and Process endpoint target scope retain separate audit obligations. The implementation and exact-source VM evidence are pending. This earns no canonical acceptance credit; external toolchain rebuilding and both complete EriX guest-build generations remain mandatory. Older VM regression observation — 22 September 2026: [the ext4 deadline report](https://git.erikinkinen.fi/erix/integration/issues/73) preserves original Integration CI 1705/1706 at `fd8a5cf0dbcf9a9cd3ddb6038370295e6ec2c8fa`. The complete 489-scenario catalog reports 482/7 and 485/4 pass/fail outcomes; eleven actual 120-second QEMU timeouts cover eight distinct ext4 scenarios. Rust 320/321-test configurations and Markdown pass. All six complete original logs are retained without warning candidates. Root cause, isolated reproduction and correction remain open; no rerun or relaxed limit supplies acceptance. External toolchain rebuilding and both complete EriX guest-build generations remain required. Current-grant protection checkpoint — 22 September 2026: [the resolved device-backing report](https://git.erikinkinen.fi/erix/kernel/issues/27) distinguishes its original metadata-authority inconsistency from the separate restoration feature gaps. The [Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/f5dd939c462de9d62f317ab7d29c21779cbe11c7) permits representable no-access/R/RW/RX changes through current exact-backing grants and aliases while active or inactive. It removes historical access ceilings and original-slot equality while preserving current VSpace MAP, selected frame rights, kind/range/identity checks, W^X, explicit READ, backing custody and failure ordering. Four strict 766/790-test configurations, thirteen native builds, strict Clippy and private rustdoc pass without warnings. The [coordinated catalog](https://git.erikinkinen.fi/erix/integration/commit/8a9f865364656351fd8b12914e404a97b0be11c7) selects that original signed Kernel in all three catalogs and passes all 172 helpers. Fifteen managed-frame calls and twenty-nine device/domain calls pass inside the original lifetime window and deadline. Actual user instructions write, execute, rewrite and execute managed RAM, check narrow alias authority and final disposal, while a reused device slot cannot authorize unrelated backing. Every prior marker remains required. Three native executions pass four original contracts with complete signed source and artifact checks; the ordinary exec-successor VM passes the full 73-component graph and original 120-second limit. Image warnings and QEMU stderr are absent. [Manual validation](https://git.erikinkinen.fi/erix/docs/commit/155b2a0cd2771cb45fa881155baf2cd0f1d1db27) passes 45 tests, 2,433 pages and 450,954 word bounds; both changed pages are reviewed with no final warnings or overflow. Static review covers 3,184 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins and 174 direct missing_docs gates. Full semantic authority review remains open. [Older Integration CI 1705/1706](https://git.erikinkinen.fi/erix/integration/issues/73) has eleven real ext4 timeouts across eight scenarios, with complete retained logs and no accepted rerun. Their root cause and correction remain unresolved. Publication CI: Kernel [642](https://git.erikinkinen.fi/erix/kernel/actions/runs/642)/[643](https://git.erikinkinen.fi/erix/kernel/actions/runs/643) and Docs [1013](https://git.erikinkinen.fi/erix/docs/actions/runs/1013)/[1014](https://git.erikinkinen.fi/erix/docs/actions/runs/1014) pass. Each pair has four complete original logs: Kernel totals 790,650 bytes with 766/790 tests and zero warning candidates; Docs totals 775,150 bytes with 45 tests, 2,433 pages and zero final warnings or overflow. Retain the original 35/1/0 LaTeX warning convergence. Integration [1725](https://git.erikinkinen.fi/erix/integration/actions/runs/1725)/[1726](https://git.erikinkinen.fi/erix/integration/actions/runs/1726) remains queued and receives no completed CI acceptance. The separate older ext4 deadline report remains open. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Complete POSIX protection support, Process endpoint scope, independent hardware roots, complete authority cleanup and measured startup improvement remain open. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. VSpace ownership preparation — 22 September 2026: Live VSpace records and production mapping tables are non-cloneable. Test observations contain descriptive metadata, synthetic selectors use independent tables, and leaf-encoder checks borrow live mappings under the record lock. Selectors accept only the mapping table they consume. Current grants, backing custody, first-match ordering, reference scans and hint visit-count controls remain intact; the rights control now uses actual activation/deactivation. The former whole-record snapshot helpers are removed. Four strict Kernel configurations pass 766/790 tests with three existing ignored cases; thirteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. All 172 Integration helpers pass. Three exact-source native executions pass the four maintained mapping, sparse, invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Original 60/120-second guest limits, existing markers, exact component signatures and retained packaged artifacts remain required; image warnings and QEMU stderr are absent. No startup speedup or independent hardware-root acceptance is inferred. The [Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/fa9491c65d173fa618c4c0ad241a5c4fe93d28e2) and [Integration source selection](https://git.erikinkinen.fi/erix/integration/commit/c17d8f1f18f55c0d159a80772ab8e5bbad8d7f04) are published with [Kernel validation evidence](https://git.erikinkinen.fi/erix/kernel/commit/14e38ec244976759214a5421c659de9b6f27beaf) and [Integration validation evidence](https://git.erikinkinen.fi/erix/integration/commit/29d778de650ba665b1ad9f143c12ef22baf62cbc). Continue under [owned-root design 22](https://git.erikinkinen.fi/erix/kernel/issues/22), [Kernel PR 3](https://git.erikinkinen.fi/erix/kernel/pulls/3) and [Integration PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12). Publication CI: Kernel [644](https://git.erikinkinen.fi/erix/kernel/actions/runs/644)/[645](https://git.erikinkinen.fi/erix/kernel/actions/runs/645) pass with four complete original logs (790,604 bytes), 766/790 tests and zero warning candidates. Integration [1727](https://git.erikinkinen.fi/erix/integration/actions/runs/1727)/[1728](https://git.erikinkinen.fi/erix/integration/actions/runs/1728) remains queued and has no completed acceptance; earlier ext4 deadlines remain tracked in [Integration report 73](https://git.erikinkinen.fi/erix/integration/issues/73). Complete authority cleanup, external toolchain rebuilding within EriX and both full guest build generations remain open. Canonical acceptance remains 15/460 leaves (3.48% weighted). Native occupancy diagnostic regression — 22 September 2026: [the original failure](https://git.erikinkinen.fi/erix/kernel/issues/28) is retained with exact signed source and packaged-ELF identity. The fixture maps a Kernel heap VA that the correct ordinary-domain guard rejects on the native upper-half heap. Host allocator addresses did not expose the mismatch. The correction must preserve the guard, 64-page/alias/hole/byte/cleanup controls and both maintained VM deadlines. The report was subsequently resolved by the verified recovery below. No canonical acceptance leaf closes. Managed-frame diagnostic recovery — 22 September 2026: [Kernel report 28](https://git.erikinkinen.fi/erix/kernel/issues/28) is resolved by the [signed correction](https://git.erikinkinen.fi/erix/kernel/commit/bc49d6da2684dae6073a03c422e0ea2265d03f31) and [coordinated catalog](https://git.erikinkinen.fi/erix/integration/commit/69a1303d848d629efebcc532fff73457c3ab834f). The diagnostic admits an initially empty lower-half window while preserving the ordinary-domain guard and all 64-page, alias, hole, physical-byte and cleanup controls. The unnecessary heap allocation and raw-pointer cleanup state are removed, with expanded inline rustdoc. Four strict 766/790-test configurations, fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. All 172 Integration helpers pass. Both maintained allocator scenarios pass independently with their original 60/120-second deadlines and complete markers; exact signed source and retained packaged-ELF checks pass. The ordinary exec-successor VM also passes against all 73 components. Image warnings and QEMU stderr are absent. The original failed native image remains retained; no unchanged rerun is used as the correction. Static review still covers 3,186 code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Full semantic authority and inline-documentation review remain open. Older original Integration [1707](https://git.erikinkinen.fi/erix/integration/actions/runs/1707)/[1708](https://git.erikinkinen.fi/erix/integration/actions/runs/1708) both pass all 489 VM scenarios, Rust 320/321 and Markdown; six complete logs total 26,966,330 bytes with zero warning candidates. Publication CI: Kernel [646](https://git.erikinkinen.fi/erix/kernel/actions/runs/646)/[647](https://git.erikinkinen.fi/erix/kernel/actions/runs/647) pass with four complete original logs (790,634 bytes), 766/790 tests and zero warning candidates. Integration [1729](https://git.erikinkinen.fi/erix/integration/actions/runs/1729)/[1730](https://git.erikinkinen.fi/erix/integration/actions/runs/1730) remains queued and has no completed acceptance; [earlier ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. The separate supervisor physical-access window and independent hardware roots remain implementation work. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Supervisor physical-access window — 22 September 2026: the [signed Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/046951899b8064be1cc90667a73e5abd2faa51ec) shares one restoring supervisor scratch transaction between frame scrubbing and physical mapping-byte copies. Caller backing custody and page-table/interrupt custody remain live through byte access, exact leaf restoration and local invalidation. Scratch is released afterward; read aliases clear the write bit and all temporary aliases clear user access and set NX. The unreachable raw-VA fallback is removed, and complete preflight rejects missing or ambiguous backing metadata before any range effects. No new userspace operation or capability grant is introduced. This is preparatory work for [owned address spaces](https://git.erikinkinen.fi/erix/kernel/issues/22); independent roots and their switching/reclamation proof remain open. Eight added host controls cover geometry, permissions, preparation and partial-effect failures, restoration/release ordering, and malformed later-page metadata without partial reads or writes. Four strict host configurations pass 774/798 tests with three existing ignored cases. Fourteen native builds and binary Clippy profiles, formatting and host/native private rustdoc pass without warnings. The [coordinated Integration catalog](https://git.erikinkinen.fi/erix/integration/commit/4fe89e021e08e45e3a9ecb1c939aba03f90e5fb1) passes all 172 maintained helpers; its exact marker expectation is updated alongside the strengthened scenarios. Unchanged orchestration and profiler sources retain strict validation. Six native executions satisfy seven maintained scenario contracts. Both allocator scenarios require the new same-VA/different-backing byte-and-leaf proof after complete cleanup, retaining every preceding marker and the original 60/120-second deadlines. Three further executions satisfy mapping, sparse, owned-invocation and lifetime contracts. The ordinary exec-successor VM passes against all 73 components. Exact original signed source, retained artifacts and packaged Kernel matches are verified; no image warnings or QEMU stderr were observed. These checks establish no performance improvement. The [technical manual](https://git.erikinkinen.fi/erix/docs/commit/589449e4172b48e31a889c82addc83096a94e02d) documents backing and scratch custody; all 45 document tests and the complete manual build pass without final warnings. Static checks cover 3,190 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Complete semantic authority and inline-documentation review remain open. Publication CI: Kernel [648](https://git.erikinkinen.fi/erix/kernel/actions/runs/648)/[649](https://git.erikinkinen.fi/erix/kernel/actions/runs/649) and Docs [1015](https://git.erikinkinen.fi/erix/docs/actions/runs/1015)/[1016](https://git.erikinkinen.fi/erix/docs/actions/runs/1016) pass. Eight complete original logs (1,572,758 bytes) confirm Kernel 774/798 tests, 45 document tests and the 2,433-page manual. Initial TeX reference warnings resolve through normal multipass generation; final passes are clean. Integration [1731](https://git.erikinkinen.fi/erix/integration/actions/runs/1731)/[1732](https://git.erikinkinen.fi/erix/integration/actions/runs/1732) remains queued and has no completed acceptance. [Earlier ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Canonical acceptance remains 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and its runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Owned supervisor baseline — 22 September 2026: the [signed Kernel implementation](https://git.erikinkinen.fi/erix/kernel/commit/0f5049592f7801b2a2d92b1290fdcc655952f72f) captures and verifies independently allocated supervisor tables before root VSpace creation, Rootd preparation and RAM seeding. Each copied page has one typed aligned Box owner before a parent references it; the recursive entry selects the copied root. Source boot/AP tables and mapped backing retain separate custody. User leaves, malformed geometry and invalid recursive identity are refused. Leaf permissions, cache policy and huge-page sizes are preserved; newly owned table branches use WriteBack and clear USER. Failed construction releases all unpublished allocations. This replaces a raw-pointer table-storage owner with shared typed storage and adds no unsafe Send/Sync implementation or userspace operation. Eleven new host controls cover independent storage, allocation/read failures, invalid translation geometry, user leaves, recursive and huge-page errors, source-permission drift, retained owner links and table counts beyond the unrelated 64-page batch size. Four strict host configurations pass 785/809 tests with three existing ignored cases; fourteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [coordinated catalog](https://git.erikinkinen.fi/erix/integration/commit/122a3d77f7f879c32eba45ccdf2eba2fd9f8d3db) passes all 172 maintained helpers. Both allocator scenarios require successful baseline capture before their original marker sequence, with capability grants and original 60/120-second deadlines preserved. Six native executions satisfy seven maintained contracts: both allocator scenarios, mapping and sparse checks sharing identical runtime settings, owned invocation, lifetime revocation and ordinary exec-successor across all 73 components. Exact signed source and retained packaged artifacts are verified; no image warnings or QEMU stderr were observed. The [technical manual](https://git.erikinkinen.fi/erix/docs/commit/18b8b7160fc2f058f059ea3c41adeca5846f9f69) specifies the custody boundary and passes 45 tests, complete 2,433-page generation, all 451,287 word bounds and changed-page visual review without final warnings or overflow. Static audits cover 3,194 authored code files below 1,000 lines, 75 manifests, 259 exact Git pins, 174 direct missing_docs gates and 93 conventional crate roots. Publication CI: original Kernel [push 650](https://git.erikinkinen.fi/erix/kernel/actions/runs/650) passes and [PR 651](https://git.erikinkinen.fi/erix/kernel/actions/runs/651) retains the host fixture failure. [Regression 29](https://git.erikinkinen.fi/erix/kernel/issues/29) is resolved by [signed Kernel `12184850cd73`](https://git.erikinkinen.fi/erix/kernel/commit/12184850cd73fff066abcb7f97039a0828b2a928): a deterministic private predecessor reproduces the original defect, and the corrected fixture passes the complete local matrix and [push CI 652](https://git.erikinkinen.fi/erix/kernel/actions/runs/652)/[PR CI 653](https://git.erikinkinen.fi/erix/kernel/actions/runs/653). Four complete corrected CI logs total 807,886 bytes with zero warning candidates. Only host tests and roadmap change; validated production sources and all catalog selections remain unchanged. Docs [1017](https://git.erikinkinen.fi/erix/docs/actions/runs/1017)/[1018](https://git.erikinkinen.fi/erix/docs/actions/runs/1018) pass with four complete logs (775,122 bytes), 45 tests and the 2,433-page manual. Initial TeX reference warnings resolve before clean final passes. Integration [1733](https://git.erikinkinen.fi/erix/integration/actions/runs/1733)/[1734](https://git.erikinkinen.fi/erix/integration/actions/runs/1734) remains queued at the latest retained observation and has no completed acceptance. [Earlier ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. The retained baseline is a construction prerequisite for [owned address spaces](https://git.erikinkinen.fi/erix/kernel/issues/22). Per-VSpace population, CR3 activation, invalidation and live-root reclamation remain open, and no speedup is claimed. Full semantic authority and inline-documentation review also remain open. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and completing both full EriX guest-build generations remain mandatory and unproven. Huge-leaf geometry correction — 22 September 2026: [the bug report](https://git.erikinkinen.fi/erix/kernel/issues/30) preserves four original host failures and one passing WriteBack control. The [signed correction](https://git.erikinkinen.fi/erix/kernel/commit/4f9cfcaeb63e9080f6d6a3e9fd190e6cb288c6fc) separates PAT from physical address bits, preserves permissions/cache indices across both huge splits, and gives newly allocated tables WriteBack policy. Scalar and batched translation, split preparation, snapshots and baseline validation share the documented geometry. No new userspace authority, original native exploit or universal boot failure is claimed. Four strict Kernel configurations pass 796/820 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [catalog](https://git.erikinkinen.fi/erix/integration/commit/ccc32eed0b4029a1ef82279c665811692c859985) passes all 172 maintained helpers. Six native executions satisfy seven original contracts: mapping and sparse, lifetime, invocation, both allocator checks and ordinary exec-successor across all 73 components. The new native witness verifies real 2 MiB PAT translation, splitting and complete restoration; host controls additionally cover 1 GiB. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The [manual](https://git.erikinkinen.fi/erix/docs/commit/587a280f59e55598e3a26b788d589955ebb84212) passes 45 tests, 2,433 pages and changed-page visual review without final warnings or overflow. Publication CI: Kernel [654](https://git.erikinkinen.fi/erix/kernel/actions/runs/654)/[655](https://git.erikinkinen.fi/erix/kernel/actions/runs/655) and Docs [1019](https://git.erikinkinen.fi/erix/docs/actions/runs/1019)/[1020](https://git.erikinkinen.fi/erix/docs/actions/runs/1020) pass. Eight complete original logs (1,592,794 bytes) confirm Kernel 796/820 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration [1735](https://git.erikinkinen.fi/erix/integration/actions/runs/1735)/[1736](https://git.erikinkinen.fi/erix/integration/actions/runs/1736) remains queued and has no completed acceptance. Earlier [ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Static audits cover 3,197 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, live-root reclamation and full semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven. First-start register custody — 22 September 2026: [the stack-domain bug report](https://git.erikinkinen.fi/erix/kernel/issues/31) preserves three original host failures and one valid-stack control at unchanged production sources; the same four controls pass against the [signed correction](https://git.erikinkinen.fi/erix/kernel/commit/5bad7a1285089a20ee6425e0335ed3a5e96f7e29). Ordinary anonymous stack materialization now rejects addresses outside the existing user domain, and direct bootstrap writes require retained writable registered backing. Initial registers have Kernel-owned storage; stack preparation preserves the synthetic return slot, complete admission, startup arguments and rollback. The obsolete saved-frame user overlay and directory scan are removed. Complete external start-context admission and the separate bootstrap code/stack overlay remain distinct work. Four strict Kernel configurations pass 807/831 tests with three existing ignored cases, including eleven new controls. Sixteen native builds and binary Clippy profiles, formatting and private rustdoc pass without warnings. The [catalog](https://git.erikinkinen.fi/erix/integration/commit/483da1e42cbdc79b56dea6fb0806980a128787b8) passes all 172 maintained helpers. Six native executions satisfy seven original contracts: lifetime, invocation, mapping and sparse, both allocator checks and ordinary exec-successor across all 73 components. The new witness checks all original initial register words after two real user stack mutations and before ordinary syscall capture. Exact source signatures and retained artifacts pass, with no image warnings or QEMU stderr. The [manual](https://git.erikinkinen.fi/erix/docs/commit/57bdb2811e2a90d0121ff6de6ab58ff797806b78) passes 45 tests, 2,433 pages and four changed-page visual reviews without final warnings or overflow. Publication CI: Kernel [656](https://git.erikinkinen.fi/erix/kernel/actions/runs/656)/[657](https://git.erikinkinen.fi/erix/kernel/actions/runs/657) and Docs [1021](https://git.erikinkinen.fi/erix/docs/actions/runs/1021)/[1022](https://git.erikinkinen.fi/erix/docs/actions/runs/1022) pass. Eight complete original logs (1,600,791 bytes) confirm Kernel 807/831 tests, 45 document tests and the 2,433-page manual. All 74 initial TeX reference warning candidates precede clean final passes. Integration [1737](https://git.erikinkinen.fi/erix/integration/actions/runs/1737)/[1738](https://git.erikinkinen.fi/erix/integration/actions/runs/1738) remains queued and has no completed acceptance. Earlier [ext4 CI deadline failures](https://git.erikinkinen.fi/erix/integration/issues/73) remain unresolved. Static audits cover 3,201 authored code files below 1,000 lines, 75 manifests, 259 Git pins and 174 direct missing_docs gates. Private root population, CR3 activation, CPU residency, live-root reclamation and complete semantic authority/documentation review remain open; no speedup is claimed. Canonical acceptance stays 15/460 leaves, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain and runtime inside EriX and both full EriX guest-build generations remain mandatory and unproven.
feat: Add bounded startup profiling and document orchestration contracts
Some checks failed
CI / markdown (push) Successful in 5s
CI / rust (push) Successful in 41s
CI / markdown (pull_request) Successful in 4s
CI / rust (pull_request) Successful in 45s
CI / integration (pull_request) Failing after 10m48s
CI / integration (push) Has been cancelled
4416bcb251
Collect explicit startup policy, cancellation and record-loss evidence and
report conservative service and shell intervals from digest-bound inputs.
Preserve incomplete provenance and the unchanged strict timing oracle; reject
late events and retain cancellation that arrives during result serialization.
The reporter grants no guest, process or network authority.

Enforce missing_docs throughout the orchestration crate and extract cohesive
launch, transport and negative-spawn types without changing re-exports. Split
dynamic-image serialization and include it in both cache identities. Select
explicit offline networking in maintained VM runners and test their arguments.
Update component documentation and CI for the maintained helpers.

Exact-source strict host and bare-metal checks pass with 320/321 unit tests.
All 82 profiler/oracle tests, packaging/cache regressions and VM runner fixtures
pass. A fresh retained historical-image VM capture completes but still fails
the unchanged caret/command limits; no speedup or full-build proof is claimed.
Full published-head CI and the broader component audit remain required.
test: Make profiler mutation checks independent of timestamp precision
Some checks failed
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 16s
CI / rust (pull_request) Successful in 59s
CI / rust (push) Successful in 59s
CI / integration (push) Has been cancelled
CI / integration (pull_request) Has been cancelled
7c1fe71b4f
Set an explicitly distinct mtime in the same-size rewrite fixture instead of
assuming an immediate write advances filesystem timestamps. Preserve path
replacement and descriptor cleanup checks, and exercise whole-second metadata
precision without sleeps. Clarify that callers finish input writes before
profiling and that metadata checks do not provide an atomic snapshot.

The original PR CI failure and a separate coarse-timestamp reproduction are
retained. All 83 collector, reporter and unchanged-oracle tests now pass with
warnings denied. Production reader behavior is unchanged; exact-head CI still
must validate the correction. Track the regression in erix/integration#14.
feat: Validate declared build scope and retain VM failure status
Some checks failed
CI / markdown (push) Successful in 23s
CI / markdown (pull_request) Successful in 22s
CI / rust (pull_request) Successful in 1m4s
CI / rust (push) Successful in 1m6s
CI / integration (push) Failing after 12m33s
CI / integration (pull_request) Failing after 1h28m36s
e7995dc7a2
Bind complete build inventories to original selected catalogs, Git objects,
Cargo targets and documentation revisions. Require explicit output ownership
and match independent receipts without claiming guest execution. Preserve
distinct target identities and reject omissions or ambiguous declarations.

Record bounded invocation-correlated VM diagnostics without exposing guest
content or changing failure precedence. Fifty-six scope tests, thirteen
diagnostic tests and existing runner fixtures pass; full CI remains required.
erikinkinen changed title from WIP: Add startup profiling and strengthen integration validation to WIP: Validate build scope and profile startup with bounded evidence 2026-09-12 10:21:05 +02:00
ci: Preserve predecessor regression runs across checkpoints
Some checks failed
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 49s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m22s
CI / integration (push) Failing after 1h30m13s
CI / integration (pull_request) Failing after 1h46m9s
5bf0fd2c84
Disable successor cancellation while preserving the existing concurrency
groups, release routing, validation jobs and deadlines. Regular signed
checkpoints must not erase the full VM evidence needed for acceptance.

The deployed Forgejo concurrency contract, exact workflow delta, YAML and
Markdown checks were reviewed. Cancelled prior runs remain incomplete;
subsequent monitoring must confirm retention of currently active runs.
fix: Join scenario catalog helpers before returning
Some checks failed
CI / markdown (push) Successful in 8s
CI / rust (push) Successful in 49s
CI / markdown (pull_request) Successful in 22s
CI / rust (pull_request) Successful in 1m29s
CI / integration (push) Failing after 1h37m46s
CI / integration (pull_request) Successful in 1h20m34s
2ae6c9cd34
Wait for complete catalog production and propagate its exit status before accepting a matching component or starting scenario work. The former asynchronous lookup could return while its catalog helper retained the scenario lock, causing a subsequent sequential invocation to fail with exit 75; it also hid failures following plausible output.

Preserve standalone/group lock ownership and concurrent exclusion. Four deterministic host regressions cover catalog completion, exclusion, failure-after-output and missing-component cleanup; original runner bytes fail three of them. The corrected tests and 12 focused existing runner/schema/worker and syntax/documentation checks pass without warnings. Test helper cleanup remains bounded and process-local. Full exact-revision CI remains required.
fix: Preserve original Cargo sources through local transport
Some checks failed
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 42s
CI / integration (push) Failing after 11m46s
CI / markdown (pull_request) Successful in 5s
CI / rust (pull_request) Successful in 36s
CI / integration (pull_request) Failing after 8m39s
e2b1cf5995
Remove cross-repository Cargo path substitution and prepare verified original Git caches for offline resolution. Validate package source identities and repository membership before exposing the generated environment. Preserve existing locks, selected tool inputs and caller process state while bounding preparation, cleanup and evidence writes.

Source-policy and process regressions pass, including cold caches and moved branches. The real Integration library passes its 21-command strict matrix with original dependency sources and 320/321 default/all-feature unit tests. Image and full catalog acceptance remain separate requirements.
test: Verify original runtime sources through Cargo metadata
Some checks failed
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m13s
CI / integration (push) Failing after 19m7s
CI / markdown (pull_request) Successful in 4s
CI / rust (pull_request) Successful in 34s
CI / integration (pull_request) Failing after 1h19m2s
b518b6ad1d
Replace the obsolete path-patch assertion with actual offline Cargo package
and lockfile Git identities, preserving the distinction between runtime and
orchestration sources. Compare original fixture bytes and prove a missing
runtime clone fails before invoking Cargo despite available sibling history.

The five source-separation tests and all 36 original-source regressions pass
with warnings denied. Preserve the original CI and local failure; full CI
remains required. Update the source contract and public tracking references.
fix: Normalize compiler coordinates across dynamic artifacts
Some checks failed
CI / markdown (push) Successful in 5s
CI / rust (push) Successful in 38s
CI / integration (push) Failing after 1m46s
CI / markdown (pull_request) Successful in 19s
CI / rust (pull_request) Successful in 1m24s
CI / integration (pull_request) Failing after 4m6s
27ca5c035c
Share explicit package and scratch path mapping across kernel, service and shared-library compilation so identical inputs retain identical compiler coordinates in separate build directories. Bind the helper into both cache ownership lists and retain exact-file handling for supported external entry sources.

Add real compiler regressions for object, metadata, ELF and graph identities and run them in CI. Close fixture readers explicitly to eliminate ignored ResourceWarnings. Record the remaining external cache coverage and full-image comparison limits separately.

Validation: 55 focused unit tests, five changed host fixtures, original-input artifact equality, syntax, all 113 Markdown files and whitespace checks pass. Production Rust sources and dependency pins are unchanged.
test: Retain bounded console watchdog fixture observations
Some checks failed
CI / markdown (push) Successful in 8s
CI / rust (push) Successful in 1m5s
CI / integration (push) Failing after 3m15s
CI / markdown (pull_request) Successful in 13s
CI / rust (pull_request) Successful in 1m14s
CI / integration (pull_request) Failing after 4m1s
4bb694279e
Close synthetic observer writes explicitly and retain scalar file observations before temporary fixture cleanup. Failed status assertions now include bounded byte identity, written-record count and last known event alongside unchanged raw stderr. Written records do not establish watchdog acceptance or the timing cause of a previous CI failure.

Preserve original fixture cadence, progress expiry order, deadlines and status assertions. The production watchdog is unchanged. Document the scope so host observations cannot be mistaken for guest progress or a resolved timeout.

Validation: all 15 focused tests pass with warnings denied, all 113 Markdown files and whitespace checks pass, and independent source review preserves fixture semantics. The original positive CI timeout remains open.
fix: Bind selected cache inputs and preserve build failures
Some checks failed
CI / markdown (push) Successful in 17s
CI / rust (push) Successful in 1m20s
CI / markdown (pull_request) Successful in 15s
CI / rust (pull_request) Successful in 1m12s
CI / integration (pull_request) Failing after 17m0s
CI / integration (push) Successful in 1h33m6s
381bccd87c
Include selected source and linker ownership in executable cache identity,
and bypass reuse when declared coverage is incomplete. Preserve the first
preparation, restore or publication failure under conditional shell callers
with owned lock and temporary cleanup. Derive host fixture inputs from the
maintained builder inventory so new helpers cannot silently be omitted.

All 32 focused warning-denied tests and the existing cache fixture pass;
original failures remain recorded. Wire regression coverage into CI and
document the remaining dependency and image-comparison limitations.
test: Make console watchdog timing deterministic
Some checks failed
CI / markdown (pull_request) Successful in 5s
CI / markdown (push) Successful in 5s
CI / rust (pull_request) Successful in 45s
CI / rust (push) Successful in 45s
CI / integration (push) Failing after 10m39s
CI / integration (pull_request) Failing after 1h12m12s
96f1c21848
Exercise the real progress reader and watchdog loop with an independent finite
clock and child schedule, so the positive contract does not depend on two host
processes meeting a short scheduling interval. Preserve exact expiry, late
evidence rejection, original child results and the real negative CLI cases.

All 21 focused warning-denied tests and four deliberate sensitivity controls
pass. Production code and deadlines are unchanged; historical failures remain
retained without claiming their scheduling cause or guest performance.
test: Accept process disappearance during cleanup observation
Some checks failed
CI / markdown (push) Successful in 15s
CI / rust (push) Successful in 1m14s
CI / markdown (pull_request) Successful in 17s
CI / rust (pull_request) Successful in 1m13s
CI / integration (push) Failing after 1h36m18s
CI / integration (pull_request) Failing after 1h33m28s
194f01c61f
Handle an absent proc entry and a dead process descriptor consistently in the bounded descendant observer. Preserve zombie acceptance, live-state rejection and unrelated I/O errors, without changing production process-group retirement or the real fork/readiness fixture.

Add seven deterministic observation controls and retain original failures. The full 43-case source/process suite passes with warnings denied after correcting its outer validation environment; document the limited process-identity evidence.
fix: Retain native probe diagnostics and pin reproducible EFI
Some checks failed
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m10s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m8s
CI / integration (push) Failing after 1h38m20s
CI / integration (pull_request) Failing after 1h37m33s
74f16acc4e
Give each physical and serial native-launch probe a private correlated status
receipt and runner log. Preserve actual failure precedence and exact command
markers while exposing only bounded scalar diagnostics. The retained serial
transport failure remains unexplained; these checks improve its attribution.

Select the validated signed Bootloader in both source catalogs. Preserve every
other source revision and build command, and keep the completed controlled
image pair distinct from validation of the newly selected graph.

Validate the 19 diagnostic cases, 39 source and policy fixtures, exact original
73-node dependency graph, scenario declarations and Markdown. Runtime and
compiler sources remain unchanged; current-head CI remains required.
fix: Preserve physical input operation failure diagnostics
Some checks failed
CI / markdown (push) Successful in 14s
CI / rust (push) Successful in 1m18s
CI / markdown (pull_request) Successful in 11s
CI / rust (pull_request) Successful in 1m13s
CI / integration (push) Failing after 1h42m28s
CI / integration (pull_request) Failing after 1h40m49s
9e8e2917de
Record the first failed host operation and command index for physical
three-line probes, retaining cleanup failures separately. Require the original
correlated runner receipt and actual physical-input status before printing
bounded scalar diagnostics. Consume and unexport receipt selection before
spawning helpers, and give no file route to unrelated input profiles.

Preserve existing VM failure precedence, command assertions and deadlines.
Validate 70 host cases, two shell syntax checks and the original omission
witness after correcting a retained fixture executable-mode setup failure.
This improves failure evidence; the underlying guest CI regression remains open.
build: Select the validated Deviced readiness cleanup
Some checks failed
CI / markdown (push) Successful in 19s
CI / rust (push) Successful in 1m20s
CI / markdown (pull_request) Successful in 13s
CI / rust (pull_request) Successful in 1m14s
CI / integration (push) Failing after 1h41m59s
CI / integration (pull_request) Failing after 1h42m52s
4658ee9fab
Pin both component catalogs to the original Deviced revision that removes
its duplicate successful RTC readiness submission and corrects the driver
housekeeping fixtures. The component passed its strict local matrix and
both CI runs before propagation.

Validate the complete original 73-repository source graph and 39 affected
host fixtures. This source-selection checkpoint does not establish a new
image build or resolve the outstanding startup and physical-input failures.
fix: Require an image-bound startup profiling contract
Some checks failed
CI / markdown (push) Successful in 19s
CI / rust (push) Successful in 1m17s
CI / markdown (pull_request) Successful in 17s
CI / rust (pull_request) Successful in 1m15s
CI / integration (push) Failing after 1h28m23s
CI / integration (pull_request) Failing after 1h36m25s
2604971484
Reject unsupported images before starting startup observers or VM runners.
Bind the supported service and shell configuration to actual packaged source,
artifact and configuration bytes, then bind final disk bytes in the external
identity. Ordinary unsupported packages remain buildable without this claim.

Record verified original Rootd provenance in direct artifacts and both cache
layers. Preserve epoch metadata, the complete readiness oracle and its timing
limits. Finite receipt operations retain the first observed failure and owned
cleanup even when an inner handler catches a timeout.

Validate 102 distinct warning-denied host cases, package/cache fixtures, syntax,
Markdown and CI wiring. Retain the original admission failure and fixture
corrections. Guest startup, comparable timings and complete self-hosted builds
remain separate pending validation.
refactor: Select original C memory support for native links
Some checks failed
CI / markdown (push) Successful in 15s
CI / rust (push) Successful in 1m21s
CI / markdown (pull_request) Successful in 12s
CI / rust (pull_request) Successful in 1m18s
CI / integration (pull_request) Failing after 22m25s
CI / integration (push) Failing after 1h36m5s
e67e4d3ad9
Use the explicitly selected lib-cstd assembler companion for kernel and shared
object links, retaining kernel allocation shims in Integration and removing the
duplicate memory instruction owner. Bind original source, selected tools and
actual producer results into direct and outer cache identities and schema-three
registry metadata. Preserve independent emitted-byte and failure regressions.

Keep caller-selected catalog paths coherent across source inspection and cache
keys. Propagate setup, lock, build and publication failures under conditional
shell callers, with owned lock lifetime and first-failure cleanup behavior.
Separate linker responsibilities into focused modules and document the native
support role without claiming a complete guest toolchain or self-hosted build.

Retain the known legacy Rust allocator-policy accessor only when referenced,
while requiring unambiguous mandatory functions from one compiler namespace.
Preserve allocator-shim instructions and reject unsupported symbol forms. Link
fixtures compare exact dependency exports with imports and relocations instead
of assuming one compiler version's Rust symbol spelling.

Validate 116 warning-denied Python cases, eight shell fixtures and 39 reused
source-policy cases. Kernel and service links, metadata rejection, original
companion byte equality, 115 Markdown files and 71 workflow shell bodies pass.
Preserve original failures and source-correlated corrections; current image
and VM acceptance remains pending.
erikinkinen changed title from WIP: Validate build scope and profile startup with bounded evidence to WIP: Bind native build inputs and profile startup with bounded evidence 2026-09-13 01:34:55 +02:00
docs: Consolidate mapping checkpoint documentation
Some checks failed
CI / markdown (pull_request) Successful in 16s
CI / rust (pull_request) Successful in 1m15s
CI / markdown (push) Successful in 14s
CI / rust (push) Successful in 1m10s
CI / integration (pull_request) Failing after 1h22m56s
CI / integration (push) Failing after 1h35m21s
07c41b6b08
Keep live mapping and authority requirements in Architecture and make the
startup profiling guide the shared owner of unchanged image acceptance rules.
Replace repeated checkpoint narratives with signed history links, preserving
all public headings and the distinction between host results and guest timing.
Correct the native language overview and nested Cargo dependency description.

Validation: Markdown checks pass for 115 files. Source checks preserve four
heading sequences, both canonical template section sets and all fourteen
paragraph dispositions; five local and three signed-history destinations are
verified against selected sources. This prose-only slice changes no runtime
code or performance limit. The broader documentation cleanup remains open.
feat: Add bounded native input failure progress
Some checks failed
CI / markdown (pull_request) Successful in 27s
CI / rust (pull_request) Successful in 1m32s
CI / markdown (push) Successful in 21s
CI / rust (push) Successful in 1m31s
CI / integration (pull_request) Failing after 1h27m55s
CI / integration (push) Failing after 2h1m52s
9f004461b2
Report the last recorded directory or editor input milestone only after a
matching runner receipt and independently observed input failure. Read fixed
private files through a retained directory descriptor, refuse changed evidence,
and project a bounded sequential JSON prefix without publishing guest text,
report-selected paths or exception details. Load the original sibling decoder
from source and preserve the wrapper's original failure if formatting fails.

Keep supplementary frames non-advancing and stop at malformed or cleanup
records. Bound newline splitting before allocating its record list. Update CI
and the focused diagnostic guide, with links from the canonical documents.
No success oracle, guest capability, runtime deadline or image policy changes.

Validation: 126 relevant Python tests pass, including 13 new prefix, private-file
and actual-wrapper controls. The 13 affected tests pass again after the bounded
split refinement; all other executable inputs remain unchanged. Markdown passes
for 116 files after correcting an overlong example. All 71 workflow shell blocks,
source/heading/link checks and whitespace pass. Original failures are retained.
The existing directory/editor runtime regressions and full guest builds remain
open pending diagnosis and current CI; no new VM or image was run locally.
fix: Bound host fixture serial writes independently
Some checks failed
CI / markdown (pull_request) Successful in 13s
CI / rust (pull_request) Successful in 1m12s
CI / markdown (push) Successful in 18s
CI / rust (push) Successful in 1m20s
CI / integration (pull_request) Failing after 1h51m3s
CI / integration (push) Successful in 1h57m46s
fe8c810371
Keep synthetic serial sockets nonblocking and separate receive polling from
one finite write deadline. Preserve stop, disconnect and timeout failures and
attempt every owned thread join while retaining the first guest error. Apply
the same socket contract to the editor and powerbox fixture overrides.

Validation: 88 focused host tests pass, including actual socket backpressure,
stop, partial-progress and cleanup controls. All 116 Markdown files, 71 workflow
shell bodies, source contracts, syntax and whitespace checks pass. Preserve the
initial readiness failures at an overlong validation temporary path and the
changed-input continuation. Production command and VM thresholds remain intact;
full CI and guest acceptance remain pending.
fix: Own socket fixture startup through client admission
Some checks failed
CI / markdown (pull_request) Successful in 19s
CI / rust (pull_request) Successful in 1m17s
CI / markdown (push) Successful in 18s
CI / rust (push) Successful in 1m17s
CI / integration (pull_request) Failing after 1h33m8s
CI / integration (push) Failing after 1h43m3s
37299e719d
Record every attempted worker before starting it and preserve the first
worker, launch or initial-output error through all join attempts. Gate
client handling until initial output and the final startup check complete;
early connections cannot consume partially initialized fixture state.
Listener setup and acceptance share their original absolute deadline.

Validation: all 122 cases across 15 host suites pass, including 20 startup,
partial-launch, early-client, stop and cleanup controls. Preserve the initial
runtime-errors failure that exposed the early-connect ordering assumption.
All 116 Markdown files, 71 workflow shell bodies, source contracts, syntax,
canonical headings and whitespace checks pass. Production observer limits
are unchanged; connected QMP cleanup uncertainty still fails. Full current
CI and guest acceptance remain pending.
fix: Describe retained serial native-time input progress
Some checks failed
CI / markdown (pull_request) Successful in 7s
CI / rust (pull_request) Successful in 39s
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m3s
CI / integration (pull_request) Failing after 1h41m58s
CI / integration (push) Failing after 1h34m47s
84e876b0a0
Extend the existing private-prefix diagnostic to the exact six-command
serial time profile. Admit only its fixed milestones, stop on unsupported
frames, and preserve the original waited failure if optional formatting
fails. This supplies descriptive evidence without granting guest authority
or weakening any command, VM deadline or success assertion.

Validation: all 68 cases across five host suites pass, including seven new
prefix, privacy, status and real-wrapper controls. All 116 Markdown files,
71 workflow shell bodies, wrapper syntax, source, canonical headings, links
and whitespace checks pass. Preserve the corrected documentation wrapping
failure without repeating runtime tests. New CI and guest acceptance remain
pending; the cause of the earlier serial time failure remains unknown.
docs: Remove duplicate historical results from README
Some checks failed
CI / markdown (pull_request) Successful in 6s
CI / rust (pull_request) Successful in 44s
CI / markdown (push) Successful in 16s
CI / rust (push) Successful in 1m21s
CI / integration (pull_request) Failing after 2h2m42s
CI / integration (push) Failing after 1h21m25s
5a593a5b30
Remove repeated console, utility, startup and migration measurements from
Purpose. Existing architecture, roadmap and manual destinations retain those
results. Keep live authority, cleanup, build and command contracts together
with every heading and link; do not create another history appendix.

Validation: all 116 Markdown files and whitespace checks pass. Exact source
checks reconstruct 97 deletion spans, verify 115 measurement and eight history
destinations through 502 retained anchors, and preserve all 12 headings, ten
local links and the complete suffix. Only README changes among 1,168 original
source files, removing 329 lines and 3,397 words. No runtime, workflow, API or
manual execution is required for this prose-only deletion; new CI is pending.
perf: Skip impossible startup summary searches when root is absent
Some checks failed
CI / markdown (pull_request) Successful in 19s
CI / rust (pull_request) Successful in 1m20s
CI / markdown (push) Successful in 19s
CI / rust (push) Successful in 1m18s
CI / integration (pull_request) Failing after 1h35m53s
CI / integration (push) Successful in 1h39m9s
47c27a1614
Avoid repeated linear list searches for a READY after a missing root record.
Preserve complete output bytes, failure precedence, event gaps and existing
first-equal-record behavior when a root exists. Input revalidation and guest
acceptance rules are unchanged.

The bounded synthetic host benchmark removes 16,384 real list.index calls
at the admitted record limit. Three-sample median process CPU time falls
from 4,857.964 ms to 17.224 ms with identical serialized summaries. The
present-root control remains semantically identical; no guest-startup
speedup or cause for the earlier serial-silence failure is established.

All 91 affected host tests pass, including eight new literal/count controls;
the original implementation fails only the intended redundant-search check.
All 116 Markdown files and source, whitespace, template and code-size checks
pass without warnings.
test: Validate native lifetime custody in an isolated VM graph
Some checks failed
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / rust (pull_request) Successful in 41s
CI / rust (push) Successful in 42s
CI / integration (pull_request) Failing after 50m46s
CI / integration (push) Failing after 50m54s
4b65755f1f
Add a coherent pinned diagnostic catalog, exclusive fixture selection and
an explicit bounded VM runner alongside the existing scenario catalog.
Two native owners exercise consumed lifetime custody, exit and Process
kill while the observer checks exact descendants and independent aliases.

Fix standalone builds to select only their actual services and cache target.
Resolve direct rustc feature implications from the original Cargo manifest,
removing the duplicated table and fingerprinting the shared resolver.

Strict default/all-feature development/release Rust checks pass, including
320/321 unit tests, documentation and bare-metal builds. All 159 CI helper
suites are accepted with original failures retained. The signed-source VM
passes both ordered unique markers and the required exit without warnings.
Realm adoption and both full guest build generations remain open.
Tracks integration issue 49 and kernel issues 7 and 9.
erikinkinen changed title from WIP: Bind native build inputs and profile startup with bounded evidence to WIP: Validate native lifetime custody and bounded build profiling 2026-09-14 11:38:13 +02:00
fix: Resolve dependency feature selectors and preserve native entry arguments
Some checks failed
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 5s
CI / rust (push) Successful in 46s
CI / rust (pull_request) Successful in 46s
CI / integration (push) Failing after 1h43m7s
CI / integration (pull_request) Failing after 1h43m17s
7cc0593e10
Separate local compiler cfg names from declared dependency selectors and
share one manifest read and visited closure. Preserve unknown-local refusal
and dependency-owned feature validation. Seven resolver and twelve real
compiler cases pass; all 87 Rootd selections from the failed CI logs resolve.

Select signed Bootloader argument/runtime corrections and coherent Kernel
revisions. The ordinary graph uses an original signed maintenance ancestor
with unchanged IPC/capability dependencies; the isolated lifetime graph
keeps its newer syscall dependencies. Both actual native VMs pass unchanged
exit/marker checks with empty stderr, including distinct CPL3 entry values.

All 159 helper suites and the strict development/release default/all Rust
matrix pass with 320/321 units. Preserve the earlier compilation, runtime
import and entry failures. Full current-head CI remains required; Kernel
issue 8 owns the separately corrected synthetic fixture regression.
Tracks Integration issues 49 and 50. No realm or self-hosting claim is made.
erikinkinen changed title from WIP: Validate native lifetime custody and bounded build profiling to WIP: Restore dynamic build coverage and validate native entry 2026-09-14 13:41:08 +02:00
perf: Select the validated CSpace allocator on both image graphs
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 44s
CI / rust (pull_request) Successful in 41s
CI / integration (push) Successful in 1h59m34s
CI / integration (pull_request) Successful in 1h59m40s
a869a81eb4
Use signed Kernel feature and ordinary maintenance ancestors with the same
allocator correction and their original IPC/capability dependency objects.
Preserve vacant-record reuse, reservation before identity publication and
existing native authority/lifetime contracts. No branch replacement is used.

All 159 helper suites and strict four-selection Rust matrices pass at
unchanged implementation sources. Both final native lifetime/distinct-
argument and ordinary Rootd IPC-framing VMs pass unchanged exit/marker
oracles with empty stderr. The final lifetime artifacts equal the prior
validated feature tree. Kernel CI 536/537 and Docs CI 851/852 pass.

Full current-head integration CI remains required. Kernel issue 12 tracks
the allocation defect; owned invocation custody and full guest builds
remain separate acceptance gates. The existing manual ABI stays valid.
erikinkinen changed title from WIP: Restore dynamic build coverage and validate native entry to WIP: Restore build coverage and validate native lifecycle changes 2026-09-14 14:52:32 +02:00
build: Select explicit endpoint construction on both image graphs
All checks were successful
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 48s
CI / rust (pull_request) Successful in 44s
CI / integration (push) Successful in 1h58m12s
CI / integration (pull_request) Successful in 1h58m15s
989d44d604
Pin the signed Kernel feature and ordinary maintenance ancestor with the
same endpoint identity rule and their original IPC/capability dependencies.
Capability copying requires an existing object before destination mutation;
explicit constructors preserve object kind and original rights.

Fresh strict Integration Rust checks pass all four configurations. Existing
159-helper results apply to unchanged helper sources; catalog, scenario and
lifetime policy checks pass again. Both actual Rootd IPC-framing and native
lifetime/entry-argument VMs pass unchanged oracles with empty QEMU stderr.
Both Kernel source graphs pass independent strict host/target matrices.

The matching technical manual is updated. Full Integration CI, owned native
invocation transport, realm mediation and two-generation guest builds remain
required; this checkpoint does not assign a new syscall ABI.
build: Select prepared capability transfer on both image graphs
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / rust (pull_request) Successful in 41s
CI / rust (push) Successful in 42s
CI / integration (pull_request) Successful in 2h7m1s
CI / integration (push) Successful in 2h7m10s
97651e7289
Pin the signed Kernel feature and ordinary maintenance ancestor with
cumulative native capability transfer preparation. Each graph retains its
original IPC and capability dependencies. Complete destination, rollback,
typed binding and lineage storage precedes capability mutation; actual-object
controls cover allocation failure, unique custody and allocation-free rollback.

Fresh strict Integration Rust checks pass all four selections. Prior helper
results apply only to identical implementation sources; changed catalog and
scenario contracts pass again. Both actual Rootd IPC-framing and native
lifetime VMs pass unchanged oracles with empty QEMU stderr. Kernel and Docs
CI pass with zero final warnings. Consolidate current roadmap evidence and
retain the intermittent quota regression without claiming its cause is fixed.

Current full Integration CI, persistent owned invocation transport, realm
mediation and both complete guest builds remain required.
build: Validate invocation lifecycle hooks in the native image
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 51s
CI / rust (push) Successful in 43s
CI / integration (push) Successful in 2h4m28s
CI / integration (pull_request) Successful in 2h4m46s
660cdd99a5
Select the signed Kernel invocation-custody and endpoint-fixture correction
in the isolated native catalog, preserving the ordinary service dependency
graph. The existing lifetime and entry-argument VM passes unchanged oracles
with clean teardown and empty QEMU stderr; this is regression coverage for
the new hooks, not proof of a new userspace invocation wire interface.

Strict Integration default/all development/release checks pass 320/321 units,
private rustdoc and freestanding builds. Unchanged helper implementation
retains all 159 command results; changed catalog and scenario policies pass
again. Update the roadmap with exact evidence and remaining wire/realm gates.
build: Select authenticated native invocation origin
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 50s
CI / rust (pull_request) Successful in 45s
CI / integration (push) Successful in 2h6m59s
CI / integration (pull_request) Successful in 2h6m59s
73924191bb
Advance the isolated native Kernel catalog to the signed caller-origin
implementation. The existing lifetime and entry-argument VM passes unchanged
oracles with clean process teardown and empty QEMU stderr; owned-invocation
wire and CPL3 peer acceptance remain separate open gates.

Exact source comparison preserves the preceding strict 320/321-unit Rust
matrix, private rustdoc, freestanding builds and 159 helper-command results.
Changed catalog, scenario and native policies pass again. Update the roadmap
with native identity semantics, current validation and remaining scope.
feat: Capture checked native invocation profiles
Some checks failed
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 47s
CI / rust (pull_request) Successful in 46s
CI / integration (push) Failing after 1h54m42s
CI / integration (pull_request) Failing after 1h54m50s
f3e4359b34
Add explicit bounded capture, raw-evidence reporting, and equivalent comparisons
for the maintained Kernel host workload. Require original source and executable
identities, fixed semantic checks, complete sample matrices, and successful
process cleanup. Limit child environment, memory, time, and output; publish
completion only after deadline teardown. Keep host and compiler declarations
separate from observed byte identity, and preserve all failed capture evidence.

Source provenance Git reads now use a minimal environment without inherited
credentials, loader settings, or transport authority. Add CI controls for real
owned child execution, deadlines, byte changes, malformed receipts, and exact
cleanup. All 161 helper commands pass; four initial socket-path setup failures
remain retained and pass with an explicitly shorter private temporary directory.
Strict default/all development/release checks pass 320/321 Rust units, private
rustdoc, and warning-free target builds. No guest code or catalog is changed.
build: Validate measured native invocation lookup refinements
Some checks failed
CI / markdown (push) Successful in 16s
CI / markdown (pull_request) Successful in 10s
CI / rust (push) Successful in 1m7s
CI / rust (pull_request) Successful in 1m2s
CI / integration (push) Failing after 2h0m25s
CI / integration (pull_request) Successful in 2h26m6s
108501cf7e
Select the signed Kernel refinement in the isolated native lifetime catalog.
Retain exact capability revalidation, exclusive draining ownership and the
existing VM oracles. Record checked original/candidate host profiles without
promoting their timing ratios to guest or self-hosting acceptance.

The existing native lifetime/entry-argument VM passes with clean teardown and
empty QEMU stderr. Unchanged Rust/helper bytes preserve strict 320/321-unit
matrices and 161 helper-command results; changed catalog and scenario policies
pass. Full published-head CI and owned invocation wire/CPL3 adoption remain
separate gates. Ordinary image selection is unchanged.
build: Validate owned invocation transport in native user processes
Some checks failed
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 42s
CI / markdown (pull_request) Successful in 12s
CI / rust (pull_request) Successful in 1m7s
CI / integration (push) Failing after 1h26m35s
CI / integration (pull_request) Failing after 2h1m14s
9030b217c4
Select the signed Kernel, shared IPC and capability ABI graph and add an
isolated three-process CPL3 scenario for all eight owned operations. Check
fresh user-memory admission, exact returned selectors, payload/capability
receipts, collection after server exit and draining release acknowledgment.
Share the native runner while preserving the older lifetime scenario and
reject mixed bootstrap fixtures before building or running either image.

Validation: 162 maintained helper checks; strict default/all development and
release Rust matrices with 320/321 tests; both native VM scenarios pass with
empty QEMU stderr. Retain three correct concurrent-run lock refusals and
subsequent sequential checks. Full remote CI and realm adoption remain open.
erikinkinen changed title from WIP: Restore build coverage and validate native lifecycle changes to WIP: Validate owned invocation transport and profile native workloads 2026-09-15 09:02:06 +02:00
test: Require native process-bound installation and cleanup
Some checks failed
CI / markdown (push) Successful in 12s
CI / rust (push) Successful in 1m15s
CI / integration (push) Failing after 20m25s
CI / markdown (pull_request) Successful in 18s
CI / rust (pull_request) Successful in 1m24s
CI / integration (pull_request) Failing after 20m34s
58c925c564
Select the original coordinated kernel and shared protocol graph for native
diagnostics. Require the expanded lifetime fixture to demonstrate exact
child/grant installation, userspace reply checks and complete added-custody
cleanup before its original lifetime oracle finishes. Preserve the unchanged
owned-invocation scenario and all ordinary component selections.

Both native VMs pass with clean teardown and empty QEMU stderr. The complete
strict Rust matrix, all 162 maintained helpers, scenario parsing, dependency
policy, formatting and Markdown pass. Update the policy assertion to require
the additional ordered marker, retaining its initial mismatch evidence.
erikinkinen changed title from WIP: Validate owned invocation transport and profile native workloads to WIP: Validate native custody and profile invocation workloads 2026-09-15 10:21:16 +02:00
test: Require native realm construction and cleanup evidence
Some checks failed
CI / markdown (push) Successful in 14s
CI / rust (push) Successful in 1m24s
CI / markdown (pull_request) Successful in 11s
CI / rust (pull_request) Successful in 1m10s
CI / integration (push) Failing after 1h36m49s
CI / integration (pull_request) Failing after 1h28m3s
f8fba7520d
Pin the original signed native constructor graph with bootstrap slot 4.
Require ordered and unique staging evidence after six actual CPL3 calls
covering reserved-root refusal, creation, exact abort and receipt disposal.
Keep the owned-invocation scenario and ordinary product graph independent.

The strict Rust matrices, complete helper suite and both native VMs pass.
The images have no warnings, QEMU stderr is empty and owned cleanup succeeds.
test: Require complete rollback on staged output refusal
Some checks failed
CI / markdown (push) Successful in 20s
CI / rust (push) Successful in 1m21s
CI / markdown (pull_request) Successful in 11s
CI / rust (pull_request) Successful in 1m16s
CI / integration (push) Failing after 1h58m5s
CI / integration (pull_request) Failing after 1h44m46s
3c4e260256
Select the original signed constructor repair and exercise an occupied grant
output through the actual CPL3 Process route. Preserve that route and remove
new parent receipts before the following successful creation and cleanup.

Both native VMs and policy checks pass with empty QEMU stderr and owned
teardown. The unchanged Rust and helper source retains the completed strict
matrix and 162-helper evidence; only the native Kernel pin and docs change.
erikinkinen changed title from WIP: Validate native custody and profile invocation workloads to WIP: Validate native authority and staged process rollback 2026-09-15 11:59:48 +02:00
test: Verify native staged endpoint attenuation
Some checks failed
CI / markdown (push) Successful in 15s
CI / rust (push) Successful in 1m14s
CI / markdown (pull_request) Successful in 10s
CI / rust (pull_request) Successful in 1m4s
CI / integration (push) Failing after 1h34m50s
CI / integration (pull_request) Failing after 2h3m2s
2d6f830e84
Select the signed original kernel and shared ABI graph for the isolated
native fixtures. Require the new ordered, unique attenuation marker after
actual CPL3 rights checks and complete added-custody disposal. Preserve
constructor rollback and the unchanged owned-invocation scenario.

Both real VMs pass with empty QEMU stderr and clean teardown. The complete
162-helper workflow and strict 320/321-test Rust matrix pass. Update the
component documents while retaining separate full CI, typed bootstrap and
guest-build acceptance requirements.
erikinkinen changed title from WIP: Validate native authority and staged process rollback to WIP: Validate native authority and staged endpoint attenuation 2026-09-15 12:54:07 +02:00
test: Require native construction without child root capabilities
Some checks failed
CI / markdown (push) Successful in 16s
CI / rust (push) Successful in 1m17s
CI / markdown (pull_request) Successful in 16s
CI / rust (pull_request) Successful in 1m22s
CI / integration (pull_request) Failing after 19m3s
CI / integration (push) Failing after 1h50m48s
9e607330da
Select the signed IPC, capability ABI and Kernel construction graph. Extend the
lifetime oracle with an ordered unique rootless-staging marker covering fourteen
actual CPL3 calls, while preserving the existing installation, attenuation and
terminal lifetime sequences.

Both native scenarios pass with clean teardown and empty QEMU stderr. All 162
workflow helpers and strict default/all development/release Rust checks pass,
including profiler regressions. Update component documents with actual native
inventory, backing lifetime and cleanup checks. Producer adoption, runnable
realms and both complete guest builds remain separate acceptance requirements.
erikinkinen changed title from WIP: Validate native authority and staged endpoint attenuation to WIP: Validate native authority and staged construction 2026-09-15 13:54:44 +02:00
build: Align dependencies for coherent runtime adoption
Some checks failed
CI / markdown (pull_request) Successful in 16s
CI / rust (pull_request) Successful in 1m11s
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m15s
CI / integration (push) Failing after 15m27s
CI / integration (pull_request) Failing after 1h34m5s
2a16b1a7ac
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
fix: Exclude shallow dependency transport caches
Some checks failed
CI / markdown (push) Successful in 10s
CI / rust (push) Successful in 1m13s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m15s
CI / integration (push) Failing after 1h48m44s
CI / integration (pull_request) Failing after 1h58m12s
cdf15c52f2
Select the canonical catalog URL when a local cache lacks complete history.
Preserve the cache and its original objects without following its configured
remote, changing dependency revisions or synthesizing replacement commits.
Retain complete local cache reuse and failure on unavailable canonical history.

Add real Git controls for shallow selection, original parents, mirror identity,
cache preservation and missing sources. All supported strict Rust configurations
and 162 helper checks pass without warnings. Rootd consumer CI must adopt this
helper checkpoint; the runtime source and product catalogs remain unchanged.
Tracks issue #51.
erikinkinen changed title from WIP: Validate native authority and staged construction to WIP: Validate native authority and original source transports 2026-09-15 19:34:18 +02:00
feat: Derive shell transport storage from the target layout
Some checks failed
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m15s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m13s
CI / integration (push) Failing after 1h24m59s
CI / integration (pull_request) Failing after 1h38m18s
38424571b7
Consume workspace layout version 22 and reserve both target-sized transport
buffers before interpreter state. Preserve caller resource classes and reject
old or mixed layouts. Extend layout and packaging controls and document the
coordinated runtime ownership change.

All 162 helper commands and the strict Rust matrix pass. Both actual optimized
shell configurations package under canonical dev/release policies with
4,300,800 workspace bytes and the disjoint 64 KiB stack unchanged. The catalog
still selects the earlier shell; this WIP producer requires coordinated
catalog adoption and full frame and runtime validation before acceptance.
erikinkinen changed title from WIP: Validate native authority and original source transports to WIP: Coordinate native authority, shell workspace and source transport 2026-09-15 21:00:41 +02:00
fix: Bind complete native companion source receipts
Some checks failed
CI / markdown (push) Successful in 9s
CI / rust (push) Successful in 46s
CI / markdown (pull_request) Successful in 11s
CI / rust (pull_request) Successful in 1m18s
CI / integration (push) Failing after 1h37m36s
CI / integration (pull_request) Failing after 1h37m48s
db80a2c1df
Share the eight assembly input roles and producer script between native source
selection and support-manifest validation. Pin the matching original lib-cstd
producer and bind the contract module into both outer cache namespaces.
Reject incomplete, extra or altered source receipts after successful tool waits.

Exercise real hidden/public production, receipt mutations and both cache keys.
Repair the isolated source-layout fixture and close watchdog fixture streams.
Retain 160 successful helpers plus the two corrected fixture passes, strict Rust
matrices and a warning-free diagnostic image with three existing guest probes.
Full CI, shell frame proof and coordinated product adoption remain pending.
test: Make serial watchdog refresh fixtures deterministic
Some checks failed
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 41s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m12s
CI / integration (push) Failing after 1h38m35s
CI / integration (pull_request) Failing after 1h36m27s
01daadd3d7
Exercise the actual watchdog loop and real serial bytes with finite logical
child schedules for positive timing checks. Add independent marker, exact
expiry, completion-status and interrupted-observation controls while keeping
real negative subprocess tests and production thresholds unchanged.

All 13 serial and 21 console tests pass with warnings denied; four incorrect
refresh, expiry, arming and status mutations are rejected. Strict current
Rust matrices, formatting, private rustdoc and four native builds pass.
Retain CI1633 as the original failure; matching full CI remains required
before closing the fixture regression.
test: Verify native permissions through owned VM observation
Some checks failed
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 42s
CI / markdown (pull_request) Successful in 14s
CI / rust (pull_request) Successful in 1m14s
CI / integration (push) Failing after 1h33m12s
CI / integration (pull_request) Failing after 1h36m17s
89d15e4536
Add explicit image, ELF, tool, firmware and CPU selection to a bounded native
permission runner. Match complete executable bytes at CPL3 and accumulate
effective hardware rights for code, RELRO and stack pages. Keep every CPU NX
check, both child outcomes, unchanged inputs and temporary cleanup mandatory.
No guest capability is added and debugger auto-loading remains disabled.

Twenty-one independent host controls and strict Rust matrices pass. One-CPU
and two-CPU native runs pass the unchanged command sequence and permissions;
the original negative image is refused with clean teardown. Four native
builds and canonical checks pass without warnings. Image CI activation awaits
coherent catalog adoption; full frame, authority and guest-build gates remain
open. The technical manual update is being validated separately.
feat: Describe shell and interrupt failure progress
Some checks failed
CI / markdown (push) Successful in 5s
CI / rust (push) Successful in 41s
CI / markdown (pull_request) Successful in 13s
CI / rust (pull_request) Successful in 1m11s
CI / integration (push) Failing after 1h33m38s
CI / integration (pull_request) Failing after 1h5m16s
df8147dfa4
Extend private prefix diagnostics to shell lines and physical interrupt reuse.
Correlate the original waited runner status and retain unknown input exits and
cleanup requests explicitly on VM stall or timeout. Render only fixed scalar
fields without changing guest authority, failure precedence or time budgets.

Eight independent producer, privacy and wrapper controls join 172 passing host
cases. Strict Rust matrices, native builds, rustdoc and formatting pass without
warnings. Document the operator contract; release input bugs remain unresolved.
fix: Bind native image preparation to its selected component catalog
Some checks failed
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 42s
CI / rust (push) Successful in 43s
CI / integration (pull_request) Failing after 1h38m56s
CI / integration (push) Failing after 1h39m5s
75ebaa21e6
Carry the caller's explicit source catalog into launch metadata and registry
construction. Resolve authority catalogs only for executable members actually
present in the image, retaining capacity and missing-metadata refusals for
shipped programs. Seven controls cover independent catalogs and absent inputs.
Select the coherent original diagnostic graph and corrected signed query kernel;
keep ordinary image pins independent and preserve the original VM limits.

All 165 helper commands and four strict Rust matrices pass, with 320 default or
321 all-feature tests, formatting, native builds and private rustdoc. The real
query/invocation and lifetime scenarios both pass within their original 60-second
deadlines without warnings. This addresses issue 59; complete automatic CI
classification and full guest-build acceptance remain separate requirements.
test: Exercise explicit kernel entry direction in native images
Some checks failed
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 46s
CI / rust (pull_request) Successful in 54s
CI / integration (pull_request) Failing after 1h37m29s
CI / integration (push) Failing after 1h37m39s
110caecccf
Add the isolated entry-direction wrapper mode and UD2 scenario with exact
ordered markers, preserved flags and the expected fatal exit. Keep the
60-second VM deadline and existing invocation/lifetime assertions unchanged.
Select the signed Kernel entry normalization through the coherent original
diagnostic catalog. Ordinary image dependency selections remain independent.

All 166 helper commands and four strict Rust matrices pass, with 320 default
or 321 all-feature tests, formatting, Clippy, native builds and private rustdoc.
The standard wrapper passes invocation, entry-direction and lifetime VMs on
the selected signed Kernel without build warnings. Complete automatic CI and
both full guest-build generations remain separate acceptance requirements.
test: Require aligned native exception entry on both frame shapes
Some checks failed
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 46s
CI / rust (pull_request) Successful in 50s
CI / integration (pull_request) Failing after 1h44m38s
CI / integration (push) Failing after 1h44m45s
fa86d1b64f
Add an isolated hardware double-fault mode with actual callee-stack and IST
oracles. Require the same pre-prologue stack sample on the no-error UD2 path.
Select the signed Kernel frame correction through the coherent diagnostic
catalog; preserve all existing marker, expected-exit and 60-second VM gates.
The separate automatic-KVM preboot observation remains tracked in issue 60.

Affected scenario, wrapper and policy checks pass. The prior complete
166-helper suite and four strict 320/321-test Rust matrices retain their
byte-identical source scope. All four standard-wrapper native scenarios pass
without build warnings on the selected signed Kernel. Full automatic CI and
both complete guest-build generations remain separate requirements.
fix: Reject ambiguous compiler runtime archive selection
Some checks failed
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 46s
CI / rust (push) Successful in 47s
CI / integration (pull_request) Failing after 1h40m15s
CI / integration (push) Failing after 1h40m30s
77921a7d97
Require one regular-file candidate per Rust runtime role in fresh Kernel,
Rootd and service links. Remove the mtime-based selector so touching an
archive cannot silently choose a compiler identity. Preserve valid single
file aliases and keep provenance/cache lifetime obligations explicit.

Add eight owned selection controls and retain predecessor refusal failures.
Validate all 167 helpers, strict Rust matrices, two existing native VMs and
38 fresh native links in a retained-graph host package. Full guest builds
and complete automatic catalog acceptance remain separate requirements.
fix: Preserve linker selection and diagnostics
Some checks failed
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 1m14s
CI / rust (push) Successful in 1m4s
CI / integration (pull_request) Failing after 1h45m3s
CI / integration (push) Failing after 1h44m57s
bc0e67f927
Select a single available driver and validate the selected compiler host when
standalone LLD is absent. Preserve driver alias names and both output streams,
make linker warnings fatal, and retain the original selected-driver failure.
Avoid unnecessary compiler queries for standalone links.

Thirteen focused controls and all 168 helper commands pass, together with four
strict Rust configurations, two bounded native VMs and a host image containing
38 fresh native links. An interleaved profile retains identical ELF outputs
and confirms elimination of one compiler query per standalone link. Full
source admission, automatic CI review and complete guest builds remain open.
fix: Reject conflicting compiler metadata inputs
Some checks failed
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 55s
CI / rust (push) Successful in 45s
CI / integration (pull_request) Failing after 1h44m20s
CI / integration (push) Failing after 1h44m29s
56e035d46a
Use one documented staging helper and crate-name mapping for executable and
shared-library producers. Require byte agreement for inherited metadata,
explicit externs and internal aliases. Preserve identical files without
rewriting and use exclusive creation for new destinations. Bind the shared
policy into both artifact cache identities.

Fourteen focused controls, all 169 helpers, four strict Rust configurations
and both bounded native VMs pass. The older host graph packages through 38
fresh links with its original deployment adapters plus the new cache input;
its Kernel and six provider metadata/shared-object pairs remain identical.
Two earlier incomplete or incompatible diagnostic overlays remain failures.
Full compiler/effect admission, automatic CI review and guest builds remain open.
test: Require generation-bound native terminal observations
Some checks failed
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 50s
CI / rust (push) Successful in 48s
CI / integration (pull_request) Failing after 1h47m17s
CI / integration (push) Failing after 1h47m8s
0db8a679f5
Select the signed Kernel and coherent shared IPC graph in the isolated native
catalog. Require the terminal-generation marker alongside all prior lifetime,
staging and ownership markers under the unchanged sixty-second VM budget.
Align the orchestration crate so Rootd can consume one original source graph.

Both actual native VMs pass with exact artifact and source review. Four strict
Rust matrices and all 169 helper commands pass after correcting the old marker
assertion; retain that failure and two earlier pre-VM setup failures. Full
service-image adoption and complete guest builds remain required.
test: Require generation-bound native cleanup evidence
Some checks failed
CI / integration (push) Failing after 1h44m26s
CI / integration (pull_request) Failing after 1h44m45s
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 54s
CI / rust (push) Successful in 44s
4d4628f565
Select the coherent signed Kernel/shared graph and require the new cleanup
marker after nineteen actual CPL3 requests. Preserve every existing lifetime
and owned-invocation oracle and the original sixty-second VM budgets. Update
the deployment fixture to describe both deferred process identity words.

All 169 helper commands and four strict orchestration matrices pass. Both real
native scenarios pass; normally stripped Kernel bytes match packaged images
and all fifteen original component checkouts are verified. Initial helper-input
and Markdown failures remain recorded. Ordinary service-image adoption and
both complete builds inside EriX remain separate open acceptance gates.
test: Require actual caller-local grant relocation
Some checks failed
CI / integration (pull_request) Failing after 1h43m42s
CI / integration (push) Failing after 1h44m0s
CI / markdown (push) Successful in 15s
CI / markdown (pull_request) Successful in 7s
CI / rust (push) Successful in 1m1s
CI / rust (pull_request) Successful in 53s
8e66e54c86
Select the signed native Kernel and coherent shared dependencies. Require the
lifetime diagnostic to perform thirty-nine real CPL3 grant relocation calls
before its original installation, revocation and complete lifetime checks.
Preserve original native deadlines and ordinary service image admission.

All 169 helpers, four strict 320/321-unit Rust matrices and both actual native
VMs pass without warnings. Verify packaged artifacts against build outputs and
all fifteen original component signatures. Record the older original CI layout
and quota failures; consumer VM and full guest-build acceptance remain open.
test: Require actual owned receiver admission
Some checks failed
CI / integration (pull_request) Failing after 1h53m18s
CI / integration (push) Failing after 1h53m13s
CI / markdown (pull_request) Successful in 15s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 51s
CI / rust (push) Successful in 45s
435e69a984
Select the signed native Kernel and coherent shared dependencies. Require ten
additional CPL3 controls for receiver request budgets, exact registration and
oversized canonical requests before the original owned custody oracles.
Preserve every lifetime check, original VM deadline and ordinary image gate.

All 169 helpers, four strict 320/321-unit Rust matrices and both native VMs pass
without warnings. Verify packaged artifacts against original build outputs and
all fifteen native component signatures. Profile 48 current-source native
samples without weakening workload equivalence or claiming guest performance.
Live consumer adoption and complete EriX-in-EriX builds remain open.
build: Adopt original realm contract dependencies
Some checks failed
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 54s
CI / rust (push) Successful in 44s
CI / integration (pull_request) Failing after 1h37m16s
CI / integration (push) Failing after 1h37m14s
ad85421257
Select the signed original bootstrap, capability and IPC revisions in Rootd
orchestration so its consumer can adopt the exact realm startup contract with
one revision per dependency. Rust source and runtime policy remain unchanged.
Keep the image-builder migration separate until Rootd can consume its payload.

Four strict default/all development/release configurations pass 320/321 tests,
with host/native Clippy, native builds, formatting and private rustdoc without
warnings. Full realm consumer VM and guest-build acceptance remain pending.
feat: Adopt coherent realm startup and image consumers
Some checks failed
CI / integration (pull_request) Failing after 1h45m32s
CI / integration (push) Failing after 1h45m38s
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 50s
CI / rust (push) Successful in 43s
8b1c037aed
Encode exact LCH1 version 3 with explicit realm capacity across runtime policy,
profile selection, shell handoff and image arguments. Read version-6 native
arena geometry and preserve alignment even for empty realm storage. Reserve
realm receipts separately while keeping an ordinary-intake tail.

Select the original coordinated producer revisions in both catalogs. Preserve
their memberships and the distinction between the Integration runtime library
and orchestration tools. Extend wire, policy, geometry and packaging controls,
and correct the obsolete description of monorepo dependency transport.

All 169 helpers and four strict 320/321-unit Rust configurations pass without
warnings, including formatting, host/native Clippy, native builds and private
rustdoc. Both actual 120-second consumer VMs pass: Launchd filesystem startup
and initial shell startup/exit. Full source/effect/frame admission, complete
realm execution and both full guest builds remain required.
test: Cover startup with realm admission disabled
Some checks failed
CI / markdown (push) Successful in 4s
CI / markdown (pull_request) Successful in 4s
CI / rust (push) Successful in 47s
CI / rust (pull_request) Successful in 47s
CI / integration (push) Failing after 1h53m8s
CI / integration (pull_request) Failing after 1h53m16s
c479813423
Add a focused disk-image VM using the existing explicit standard CLI policy,
whose realm capacity is zero. Keep ordinary filesystem startup and its ordered
Launchd readiness gates, and collect enabled, disabled and initial-shell startup
in one focused scenario group. Bind the selected policy to the exact version-3
wire field in a host regression without duplicating a runtime configuration.

The original 169-helper run retained one directory host timeout. Align its
fixture with the existing ten-second probe budget, and add controlled-clock
checks for consent observation and both deadline ceilings. All four affected
suites pass; unaffected helper and product bytes retain their passing evidence.
Eight route/capacity controls and four strict 320/321-unit Rust configurations
pass without warnings. The actual 120-second VM passes, with
zero in the signed image's 72-byte record and a matching version-6 native arena.
Original CI for the fixture correction, complete realm operation and both full
guest builds remain required. See issue #63 for the preserved initial failure.
test: Add the native realm admission regression scenario
Some checks failed
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 7s
CI / rust (push) Successful in 54s
CI / rust (pull_request) Successful in 48s
CI / integration (push) Failing after 1h53m57s
CI / integration (pull_request) Failing after 1h54m0s
76411ed6d9
Select the explicit Exsh diagnostic through initial-shell fixture controls,
with default-off selection and the existing runtime launch policy. Require
its unique success marker followed by ordinary shell exit, and include the
scenario in the realm startup group without adding authority or changing
runtime deadlines. Select the original signed Exsh and documentation revisions.

The original actual VM fails: Exsh exits 0xe5 before the marker, Rootd exits
0xdc and the existing progress watchdog stops QEMU. Preserve this reproducer
and all 106 appliance artifacts while investigating issue #66. No native
acceptance or root cause is inferred. All 169 helpers, twelve route controls
and four strict 320/321-test Rust configurations pass without build warnings,
including native builds, fmt, strict host/native Clippy and private rustdoc.
Complete mediator operation, full frame proof and both guest builds remain open.
build: Adopt corrected native realm admission producers
Some checks failed
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 8s
CI / rust (push) Successful in 57s
CI / rust (pull_request) Successful in 48s
CI / integration (push) Successful in 2h18m36s
CI / integration (pull_request) Failing after 1h52m5s
9139c6c5fa
Select the original signed Launchd private-script dispatch correction and Exsh
cleanup fail-stop, together with the matching process-service manual. Preserve
the existing component memberships, actual caller proof and reply ownership;
no additional sender or runtime authority is installed.

The fresh native VM completes all eleven diagnostic calls and its ordinary
successful shell exit with unchanged hard and progress deadlines. Both failed
predecessor images remain retained. All 169 helpers, twelve route/scenario
controls and four strict 320/321-test Rust configurations pass without warnings,
including native builds, fmt, host/native Clippy and private rustdoc. Full frame
proof, configured mediator execution, native toolchain rebuilding and both
complete EriX build generations remain required.
test: Cover native guarded realm preparation
Some checks failed
CI / integration (push) Failing after 1h53m33s
CI / integration (pull_request) Failing after 1h40m59s
CI / markdown (push) Successful in 13s
CI / rust (push) Successful in 1m21s
CI / markdown (pull_request) Successful in 6s
CI / rust (pull_request) Successful in 40s
78557a6c67
Add a separate opt-in scenario that copies only the shell's existing cwd SEND
scope to its authenticated reservation and stages bin/true without starting
it. Require guarded preparation and read, acknowledged retirement and stale
read refusal before the diagnostic marker and ordinary successful shell exit.
Preserve the admission-only scenario and existing startup authority. Reuse
the common selector checks and cover independent feature composition.

The actual matching VM passes under unchanged hard and progress deadlines.
All 169 helper commands, seventeen route controls and four strict 320/321-test
Rust configurations pass without warnings, including native builds, fmt,
host/native Clippy and private rustdoc. The original signed producer passes
ten strict 976-test configurations but retains incomplete frame proof.
Complete mediator execution, native toolchain rebuilding and both full builds
inside EriX remain required.
build: Adopt checked process-start grant census
Some checks failed
CI / markdown (push) Successful in 19s
CI / rust (push) Successful in 1m20s
CI / markdown (pull_request) Successful in 10s
CI / rust (pull_request) Successful in 1m22s
CI / integration (pull_request) Failing after 1h45m32s
CI / integration (push) Failing after 1h32m44s
b65183ddb9
Select the signed Kernel correction that refuses process start when the
install-grant census is unavailable, and the reconciled manual source.
Keep every other catalog entry and all checked orchestration bytes unchanged.

The matching guarded-preparation appliance passes its original hard and
progress limits without warnings. Verify all original component revisions,
actual packaged diagnostics and signed startup configuration. Kernel passes
four strict matrices, thirteen native build/Clippy profiles and original CI.
Retain prior complete host evidence for unchanged Integration implementation,
new focused source checks and the original host fixture environment failure.
Complete mediator execution, full frame proof, native toolchain rebuilding
and both complete EriX builds inside EriX remain required.
build: Align native terminal regression sources
Some checks failed
CI / markdown (pull_request) Successful in 12s
CI / rust (pull_request) Successful in 1m25s
CI / integration (pull_request) Failing after 1h53m33s
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 46s
CI / integration (push) Failing after 1h49m59s
a62d1381f5
Select the signed shared Kernel terminal transition in both complete catalogs
and reconcile five native diagnostic pins with the accepted original graph.
Preserve maintained runner behavior, source memberships and original VM limits.

Both actual lifetime and owned-invocation VMs pass without warnings. Match
packaged Kernel bytes to retained original artifacts and verify all fifteen
component signatures. Four current strict 320/321-test Rust matrices, native
builds, formatting, host/native Clippy and private rustdoc pass. Seven focused
checks pass; retain full 169-helper evidence for unchanged orchestration bytes.
Native child-lifetime custody, running mediator lifecycle, complete frame proof
and both EriX build generations inside EriX remain required.
test: Require native child lifetime disposal evidence
Some checks failed
CI / integration (push) Failing after 15m44s
CI / markdown (pull_request) Successful in 15s
CI / rust (pull_request) Successful in 1m20s
CI / markdown (push) Successful in 6s
CI / rust (push) Successful in 43s
CI / integration (pull_request) Failing after 23m14s
581226ab54
Select the signed native child custody dependency graph and updated manual.
Extend the maintained lifetime scenario with a separate supervisor and its
required child-disposal marker while preserving every original VM limit.

Both actual lifetime and owned-invocation VMs pass without warnings. Verify
packaged Kernel artifacts and all fifteen original source signatures. Four
strict 320/321-test matrices, native builds, formatting, Clippy and private
rustdoc pass. Retain full helper evidence for unchanged orchestration and
revalidate changed scenario policy. Full running realm lifecycle, executing
child and no-successor native coverage and all guest builds remain open.
test: Require executing child termination and safe native reply cleanup
Some checks failed
CI / markdown (push) Successful in 5s
CI / integration (pull_request) Failing after 15m38s
CI / rust (push) Successful in 39s
CI / integration (push) Failing after 12m20s
CI / markdown (pull_request) Successful in 7s
CI / rust (pull_request) Successful in 41s
c14c5a6171
Adopt the original signed Kernel correction and require actual CPL3 nested-child
execution, current-child ancestor termination, exact event ordering and independent
process preservation. Keep every previous native marker and the 60-second bounds.

Both maintained native scenarios and strict Integration checks pass without
warnings. Select the updated complete manual and retain separate full lifecycle,
frame, external toolchain and two-generation guest-build acceptance requirements.
test: Require native cleanup with no userspace successor
Some checks failed
CI / markdown (pull_request) Successful in 4s
CI / rust (pull_request) Successful in 44s
CI / markdown (push) Successful in 8s
CI / rust (push) Successful in 1m6s
CI / integration (pull_request) Failing after 13m46s
CI / integration (push) Failing after 12m8s
4d6f4fe8b3
Select the original signed Kernel and require final child reclamation, closed
CPU accounting and preserved terminal events at its ordinary pre-halt boundary.
Keep all earlier assertions, exact source identities and both 60-second limits.

Both maintained native scenarios and strict Integration checks pass without
warnings. Select the updated manual and preserve separate hardware wakeup,
consumer lifecycle, full frame, native toolchain and guest-build requirements.
test: Require native terminal event allocation rollback
Some checks failed
CI / integration (pull_request) Failing after 12m28s
CI / integration (push) Failing after 12m21s
CI / markdown (pull_request) Successful in 4s
CI / rust (pull_request) Successful in 41s
CI / markdown (push) Successful in 5s
CI / rust (push) Successful in 41s
cf5b2f5f1d
Select the original signed Kernel and require resource-exhaustion delivery from
actual CPL3 dispatch after one injected allocator refusal. Preserve exact native
subtree state, reservation rollback and every earlier cleanup/idle assertion.

Both maintained native scenarios and strict Integration checks pass without
warnings. Select the reviewed complete manual and retain independent release,
authority/accounting, full frame, toolchain and guest-build acceptance gates.
test: Require independent native child release recovery
Some checks failed
CI / rust (pull_request) Successful in 39s
CI / markdown (pull_request) Successful in 4s
CI / integration (pull_request) Failing after 14m9s
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 44s
CI / integration (push) Failing after 12m12s
294a467a3b
Select the original signed Kernel and require eventual resource disposal from
ordinary cleanup after two injected final-release refusals. Preserve exact native
identity, the first error, independent disposal and every earlier native assertion.

Both maintained native scenarios and strict Integration checks pass without
warnings. Select the reviewed complete manual and retain
authority/accounting, full frame, toolchain and guest-build acceptance gates.
build: Align orchestration with explicit grant rights
Some checks failed
CI / markdown (pull_request) Successful in 5s
CI / rust (pull_request) Successful in 52s
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 46s
CI / integration (pull_request) Failing after 12m19s
CI / integration (push) Failing after 12m9s
9166f7bde6
Select the original shared IPC, capability ABI and bootstrap revisions so
Rootd can adopt the coordinated install-grant authority contract without
duplicate wire types. Image catalogs retain their preceding coherent graph
until native Kernel and consumer validation completes.

Validate four host test and strict Clippy configurations, four native builds
and Clippy configurations, private rustdoc, formatting and dependency policy.
fix: Align the full original installer authority catalog
Some checks failed
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 9s
CI / rust (push) Successful in 58s
CI / rust (pull_request) Successful in 59s
CI / integration (pull_request) Failing after 1h54m35s
CI / integration (push) Failing after 1h54m44s
f9681efc30
Select the signed shared libraries and every dependent bottom-up, correcting
the 127 manifest/catalog mismatches from original CI. Verify both complete
catalogs against clean original checkouts and all 143 selected signatures.
Require the actual CPL3 installer-rights marker and select the reviewed manual.

Both maintained native scenarios pass with original deadlines and no warnings.
Unchanged Integration Rust evidence and targeted source/policy tests pass.
Keep Exsh release-unit compilation and complete frame proof explicitly open,
alongside full service lifecycle, toolchain rebuilding and guest self-hosting.
fix: Select the verified installer return-slot correction
Some checks failed
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / rust (push) Successful in 47s
CI / rust (pull_request) Successful in 48s
CI / integration (pull_request) Failing after 2h0m10s
CI / integration (push) Failing after 2h0m24s
648fbd5614
Select the signed Procd correction and updated manual in both full original
catalogs. The installer retains exactly GRANT and returns through the managed
slot required by later TTY provisioning, without relaxing receipt validation.

The maintained initial-shell start/exit, realm-admission and normal release
appliance scenarios pass on their first corrected attempts with no warnings
and empty QEMU stderr. Retain the prior 431/489 and 430/489 CI results; the
complete corrected regression suite and wider lifecycle gates remain open.
Both full original catalogs, immutable-source controls and documentation
checks pass. The orchestration crate and validated native runner are unchanged.
test: Select verified acknowledged terminal accounting
Some checks failed
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 7s
CI / rust (pull_request) Successful in 1m1s
CI / rust (push) Successful in 1m2s
CI / integration (pull_request) Failing after 2h4m55s
CI / integration (push) Failing after 2h4m52s
fcd7b4a960
Advance the isolated native catalog to the original signed Kernel and shared
wire revisions. Actual CPL3 checks cover repeat observation, final nonzero CPU
measurements after reclamation, exact acknowledgement and lost-reply retry.

Both maintained native scenarios pass under original deadlines with no build
warnings. Verify all fifteen original source signatures and normal stripping
against retained packaged artifacts. Source/policy tests and unchanged strict
orchestration evidence pass. Retain the first page-census failure in Kernel #21;
full service consumers, manual updates and self-hosting remain required.
build: Align terminal accounting orchestration dependencies
All checks were successful
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 51s
CI / rust (push) Successful in 42s
CI / integration (pull_request) Successful in 2h2m49s
CI / integration (push) Successful in 2h2m50s
b06dfad002
Select original shared commits for acknowledged terminal observations in the
Rootd orchestration library. Keep this library checkpoint separate from later
service catalog adoption so the dependency graph remains acyclic.

Four strict host and native configurations, private rustdoc, formatting and
dependency checks pass without warnings. Full service acceptance remains open.
build: Adopt the original acknowledged terminal service graph
All checks were successful
CI / markdown (pull_request) Successful in 15s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 1m1s
CI / rust (push) Successful in 50s
CI / integration (pull_request) Successful in 2h5m18s
CI / integration (push) Successful in 2h5m14s
dff878dd35
Align both complete catalogs with the signed terminal-observation, exact
acknowledgement and final CPU consumers. Include the bounded VFS frame-tool
correction and its manual while retaining Exsh compiler and frame gates.

Original signed catalog checkouts pass dependency equality. All 169 helper
commands pass with explicit memory sources and the maintained traced disk
fixture; earlier source and silence failures remain retained. Identical
orchestration Rust inputs retain four strict 320/321-test configurations.
Actual service CPU/profiler VMs and full guest builds remain separate gates.
fix: Bind startup admission to original Kernel compiler inputs
Some checks failed
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 5s
CI / rust (pull_request) Successful in 54s
CI / rust (push) Successful in 47s
CI / integration (pull_request) Failing after 1h45m4s
CI / integration (push) Failing after 1h45m6s
fd8a5cf0db
Require the complete runtime transition in Rootd and its policy library.
Record the Kernel feature closure actually compiled and its original source
revision/tree, recheck after linking and bind source identity into cache keys.
Contract v2 refuses old receipts, synthetic wrappers and unproved Kernel input.

All 171 maintained host helpers pass, including eight new provenance tests.
Close fixture files explicitly across sixteen helpers; original resource
warnings remain retained under issue 71. All final streams are warning-free.
Formatting, dependency policies and Markdown pass without warnings; unchanged
Rust inputs retain all four strict orchestration matrices. Actual startup
capture and its unchanged performance gates remain pending under issue 69.
docs: Record actual startup profiling limits
All checks were successful
CI / markdown (pull_request) Successful in 12s
CI / markdown (push) Successful in 5s
CI / rust (pull_request) Successful in 49s
CI / rust (push) Successful in 41s
CI / integration (push) Successful in 2h7m33s
CI / integration (pull_request) Successful in 2h7m53s
9c62af2d24
Record corrected original Kernel admission and the first complete capture.
Preserve the failed timing gate and distinguish observed service intervals
from loader-only causes. Keep all existing authority and timing requirements.

The exact implementation has warning-free image builds and 171 accepted
helper commands. This roadmap-only change passes Markdown, template and
source-policy checks; executable inputs match the retained capture exactly.
build: Adopt original process metrics consumer custody
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 50s
CI / rust (pull_request) Successful in 41s
CI / integration (push) Successful in 2h6m1s
CI / integration (pull_request) Successful in 2h6m0s
07c883525e
Select the signed Procd consumer-generation update in both complete catalogs.
Keep all other original component revisions and the orchestration library
unchanged. The new Procd manifest retains the previously verified transitive
graph, and its four strict matrices and original CI pass without warnings.

All 171 maintained integration helper commands pass without warnings, along
with formatting, source policy and Markdown checks. Unchanged Rust inputs
retain their four strict matrices. Coherent service VM adoption, remaining
lifecycle authority and full native guest builds remain separate gates.
feat: Add bounded host TCG execution profiling
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 56s
CI / rust (pull_request) Successful in 48s
CI / integration (pull_request) Successful in 2h8m41s
CI / integration (push) Successful in 2h9m11s
4fa27f942b
Record actual translated-block entries and instruction bytes with explicit
host resource budgets, fresh output ownership and completion framing. Match
selected packaged ELF bytes without inferring process identity or elapsed
cost. Reuse the ELF inspector and separate counter completion from VM gates.

All 172 helpers pass, with five profiler Rust tests in both profiles, eleven
Python controls, strict Clippy and warning-free private rustdoc. Five actual
emulator controls pass. An original-image capture retains 92896 translations;
its command collector and same-emulator uninstrumented control both fail the
unchanged deadline. Kernel mapping code is a leading candidate for further
optimization; no speedup or startup acceptance is claimed. Whole-build guest
profiling and toolchain self-hosting remain required.
build: Select the owned table preparation checkpoint
Some checks are pending
CI / integration (pull_request) Has started running
CI / markdown (pull_request) Successful in 4s
CI / integration (push) Has started running
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 52s
CI / rust (push) Successful in 49s
fe63adde8f
Pin all three source catalogs to the signed Kernel allocation-custody
refactor while preserving every other source and original manifest selector.
The Kernel keeps unpublished storage until parent publication; independent
VSpace roots and table retirement remain separate work under Kernel issue 22.

All 172 maintained Integration helper commands pass without warnings.
Unchanged Rust source retains its validated strict matrices and profiler
controls. Matching mapping, owned-invocation and lifetime native regressions
remain explicit gates before runtime acceptance.
docs: Record native table custody regression evidence
Some checks are pending
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (push) Waiting to run
CI / markdown (pull_request) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
1621164b93
Record the retained lifetime, owned-invocation and mapping executions. The
isolation and sparse marker contracts share one capture with identical
runtime settings. Verify all fifteen original component signatures and
normal stripping equality for each packaged Kernel image.

Executable inputs are unchanged and retain their strict validation. The
Markdown and diff checks pass. Private VSpace roots, startup performance
and full guest toolchain builds remain separate acceptance requirements.
Select the exact signed Kernel implementation in all three source catalogs.
Keep all other components and transitive dependency selections unchanged.
Extend the maintained lifetime marker contract with actual CPL3 address
admission, positive memory access, unmap and local grant cleanup evidence.
Preserve every earlier witness, failure marker and the 60-second guest limit.

All 172 helper commands and source policy checks pass without warnings.
Unchanged Rust sources retain their preceding strict validation matrices.
The signed checkpoint is retained privately until matching native execution.
Pin the signed Kernel fixture correction in all three catalogs. Keep every
other source selection and all helper/Rust implementations unchanged from
the complete 172-helper validation. The native caller owns an explicit
MAP-only VSpace alias and must remove all three temporary grants.

Dependency and lifetime policy, Markdown and diff checks pass. Preserve the
first failed native inventory witness; matching corrected execution remains
required before publication. No runtime deadline or oracle is relaxed.
Pin the signed Kernel fixture correction in all three catalogs. Keep every
other source selection and all helper/Rust implementations unchanged from
the complete 172-helper validation. The native caller keeps all three grants within its existing admitted slot
window and must dispose of each through actual CPL3 calls.

Dependency and lifetime policy, Markdown and diff checks pass. Preserve the
first failed native inventory witness; matching corrected execution remains
required before publication. No runtime deadline or oracle is relaxed.
test: Select the nonoverlapping native mapping grant layout
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
cd560584d0
Pin the signed Kernel fixture correction in all three catalogs. Keep every
other source selection and all helper/Rust implementations unchanged from
the complete 172-helper validation. The native caller keeps all three grants within its existing admitted slot
window and must dispose of each through actual CPL3 calls.

Dependency and lifetime policy, Markdown and diff checks pass. Preserve the
first failed native inventory witness; matching corrected execution remains
required before publication. No runtime deadline or oracle is relaxed.
docs: Record verified native mapping domain and cleanup evidence
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
c41bb92cd0
Record the corrected actual CPL3 mapping boundary, complete grant disposal,
invocation and shared mapping/sparse capture. Retain all three failed native
fixture attempts and the final nonoverlapping layout within the original
caller window. Record the unchanged ordinary exec-successor VM acceptance.

Document exact explicit grant custody and preserve the distinction from
private hardware roots and guest toolchain rebuilding. Markdown and diff
checks pass; every executable source remains identical to the validated tree.
Select the signed Kernel mapping-rights correction in all three source
catalogs. Require the added CPL3 attenuation marker after actual map,
protection and unmap denials, preserved RW/NX backing and disposal of every
temporary grant. Keep every prior marker, source selection, caller window
and guest deadline unchanged.

All 172 maintained helper commands pass; unchanged orchestration and
profiler Rust sources retain their strict validation. Exact-source native
and ordinary service execution remain required before publication.
docs: Record verified VSpace mapping authority evidence
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
44a43755ad
Record current host, native and ordinary service acceptance after actual
execution. Keep every executable and source selection identical to the
validated signed implementation. Original caller windows, marker contracts,
guest deadlines and complete retained artifact checks remain authoritative.

Markdown and diff checks pass. Independent hardware roots, complete authority
cleanup and full guest toolchain rebuilding remain open.
Require the frame-access witness after all existing mapping and VSpace
rights checks. Preserve the original caller window, failure markers and
60-second limit while selecting the exact signed Kernel in all three
catalogs. No other source selection or Cargo dependency is changed.

The maintained helper suite and unchanged Rust matrices validate the host
runner. Native and ordinary service VM acceptance remain required before
publication; retained source and artifact identities govern those checks.
docs: Record verified frame access and backing evidence
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
507c13cbb1
Record current host, native and ordinary service acceptance after actual
execution. Keep every executable and source selection identical to the
validated signed implementation. Original caller windows, marker contracts,
guest deadlines and complete retained artifact checks remain authoritative.

Markdown and diff checks pass. Independent hardware roots, complete authority
cleanup and full guest toolchain rebuilding remain open.
Select the exact signed Kernel implementing current-grant ordinary
protection. Require real managed-RAM write, execute, rewrite and execute
witnesses, exact alias authority and final allocation reclamation in the
maintained lifetime scenario. Preserve every earlier marker, the caller
window, request extent and original guest deadline.

All maintained helper checks pass against the coordinated catalog graph.
Exact-source native and ordinary service VM execution remains pending
before publication. Other component selections and Git dependencies are
unchanged; full toolchain self-hosting remains an open acceptance gate.
docs: Record verified protection restoration and disposal
Some checks are pending
CI / integration (push) Waiting to run
CI / rust (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
011afe1d55
Record current host, native and ordinary service acceptance after actual
execution. Preserve all executable sources and catalog selections from
the signed implementation. Original caller windows, marker contracts,
guest deadlines and complete retained artifact checks remain required.

Markdown and diff checks pass. Independent hardware roots, full authority
cleanup, measured speedup and complete guest toolchain rebuilding remain
open acceptance requirements.
Pin the exact signed Kernel that separates live ownership from test
observations and synthetic selector tables in all three source catalogs.
Keep every other component revision, dependency selector, capability
window, scenario marker and runtime deadline unchanged.

All 172 maintained helper commands pass without warnings. Unchanged Rust
orchestration and profiler sources retain their strict validation. Exact
source native and ordinary service VM acceptance remains pending; private
roots and full guest rebuilding remain open.
docs: Record VSpace ownership refactor validation
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
29d778de65
Record the strict host, native and ordinary service results after actual
execution and exact source/artifact verification. Preserve all executable
sources and catalog selections from the signed implementation. Existing
capability windows, marker contracts and guest deadlines remain required.

Markdown and diff checks pass. Independent hardware roots, full authority
cleanup, measured speedup and complete guest toolchain rebuilding remain
open acceptance requirements.
Pin the exact signed Kernel diagnostic correction in all three catalogs.
Its explicit lower-half fixture window preserves production address-domain
enforcement and the original occupancy, alias, byte and cleanup controls.
Keep every other component pin, dependency selector, marker and deadline.

All 172 maintained helper commands pass without warnings. Unchanged Rust
orchestration and profiler sources retain their strict validation. Both
maintained allocator VM contracts remain pending against this signed graph.
Independent roots and complete guest rebuilding remain open.
docs: Record native managed-frame diagnostic recovery
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
372daa7ee0
Record both maintained allocator contracts passing against the corrected
signed graph with original deadlines and complete marker checks. Preserve
the original failing image separately. The ordinary exec-successor VM
passes against all 73 components; no image warnings or QEMU stderr remain.

Exact signatures, source membership and retained packaged artifact checks
pass. These documentation-only updates preserve all executable inputs and
catalog selections. Independent roots and full guest rebuilding remain open.
Pin the exact signed Kernel implementation in all three catalogs. Require
the new same-VA byte isolation marker in both allocator scenarios after
complete diagnostic cleanup. Preserve all existing capability grants,
markers, component pins and original 60/120-second deadlines.

All 172 maintained helper commands pass without warnings. Unchanged Rust
orchestration and profiler sources retain their strict validation. Native
execution remains pending against this signed graph. Independent roots,
toolchain rebuilding and complete guest-build generations remain open.
docs: Record native physical-window validation
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
1d7f8d9136
Record six native executions satisfying seven existing scenario contracts
against the coordinated signed source graph. Both allocator contracts
require the new active/inactive backing control with every prior marker
and original deadline preserved. Retain all original artifacts and failures.

Exact signatures, source membership and packaged artifact checks pass.
These documentation-only updates preserve all executable inputs and
catalog selections. Independent roots, external toolchain rebuilding and
both full EriX guest-build generations remain open.
Pin the exact signed Kernel in all three catalogs. Both allocator scenarios
require verified supervisor capture before the original marker sequence.
Update the policy helper's exact order and retain original grants, deadlines
and all other component selections. No root activation is claimed.

All 172 maintained helpers pass without warnings. Unchanged Rust and profiler
sources retain strict validation. Native execution remains pending.
docs: Record native supervisor baseline capture
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
cdc13324e2
Record six native executions satisfying seven original scenario contracts.
Both allocator scenarios require verified pre-root capture with prior
markers, grants and deadlines preserved. Source signatures and retained
packaged artifacts pass; no image warnings or QEMU stderr remain.

This evidence-only change preserves executable inputs and catalog pins.
Per-VSpace population, CR3 activation, invalidation and live-root retirement
remain open, as do external toolchain and complete EriX guest rebuilding.
Select the exact signed Kernel correction in all three catalogs. Require the
new hardware witness in both maintained mapping scenarios and update the
policy helper's exact marker order. Preserve prior markers, original grants,
all other component selections and the original sixty-second guest bounds.

All 172 maintained helpers pass without warnings. Unchanged Rust and profiler
sources retain their strict validation. Native execution remains required;
this is not acceptance of private roots or complete guest toolchain builds.
docs: Record verified huge-leaf geometry correction
Some checks are pending
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / markdown (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
f69b4bc5d3
Record six native executions satisfying seven original scenario contracts.
The new mapping witness verifies real huge-PAT translation, splitting and
restoration with prior markers, grants and deadlines preserved. Source signatures and retained
packaged artifacts pass; no image warnings or QEMU stderr remain.

This evidence-only change preserves executable inputs and catalog pins.
Per-VSpace population, CR3 activation, invalidation and live-root retirement
remain open, as do external toolchain and complete EriX guest rebuilding.
Select the exact signed Kernel in all three catalogs and require the new
pre-capture ownership witness in the native lifetime scenario. Actual CPL3
stack mutation must preserve the separately owned initial register words.
Keep prior checks, grants, other source selections and the original deadline.

All 172 maintained helpers pass without warnings. Unchanged Rust and profiler
sources retain strict validation. Native execution and complete guest builds
remain required; private-root activation is not established.
docs: Record verified first-start register ownership
Some checks are pending
CI / markdown (push) Waiting to run
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
3a31b07bd3
Record six native executions satisfying seven maintained scenario contracts.
Two actual user programs mutate their red zones before the pre-capture witness
checks all initial register words in independently owned Kernel storage.
Preserve prior grants, markers and deadlines. Verify exact source signatures
and retained packaged artifacts without image warnings or QEMU stderr.

This evidence-only change preserves executable sources and catalog selections.
Private-root activation, CPU residency and live-root retirement remain open,
as do external toolchain and complete EriX guest rebuilding.
Some checks are pending
CI / markdown (push) Waiting to run
CI / rust (push) Waiting to run
CI / integration (push) Waiting to run
CI / rust (pull_request) Waiting to run
CI / integration (pull_request) Waiting to run
CI / markdown (pull_request) Waiting to run
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.