WIP: Select exact executable preparation for realm mediators #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/launchd!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Select mediator preparation through the transfer-aware loader client and reject substituted operations or incorrect live grant receipts.
Tracking and scope
Owning feature issue #1 and realm design. Signed checkpoint:
e7ad077a1dce4602b116c89bcf2fded07261fac6. The corrected native slot collision is tracked in capability ABI issue 3.Architecture, authority and failure behavior
The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open.
Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed.
Validation evidence
Coherent startup consumer acceptance — 18 September 2026: Signed Integration
8b1c037aed2503e1f2a4b17c8a8be0666d62a305adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required.Original public realm dispatch CI acceptance — 18 September 2026: Signed Launchd
5837873167c5e6ed99045af7052004affb5c28ffpasses CI 141 and CI 142. All four terminal logs are complete (142,951 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime consumer adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.Public realm dispatch and progress checkpoint — 18 September 2026: Signed
5837873167c5e6ed99045af7052004affb5c28ffis pushed. Public BEGIN, PREPARE, ABORT and READ now dispatch canonical frames and actual receipts through original native caller proof. Held replies survive bounded native progress. Creation/abort reply loss requests cleanup; read or refused-request loss preserves earlier realm ownership. A rotating cursor advances independent retirement before ordinary work and yields while native custody blocks peer calls. Original mediator events match before ordinary job lookup. Eleven new controls and all six strict configurations pass: 322 library and 55 runtime tests, six freestanding builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. Process-event handling is split into its own module; all authored code stays below 1,000 lines. Original CI is under observation. Coordinated startup/image consumers and actual consumer VMs remain required, as do configuration, readiness, seal, mediated I/O and both complete builds inside EriX.Original exact preparation CI acceptance — 18 September 2026: Signed Launchd
5c58f9e702be3e130b7040be2a042b1a41a5aea8passes CI 139 and CI 140. All four terminal logs are complete (140,314 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.Exact realm executable preparation checkpoint — 18 September 2026: Signed
5c58f9e702be3e130b7040be2a042b1a41a5aea8is pushed. Realm preparation now uses actual framed VFS resolution, complete pinned manifest reads and Loaderd PREPARE_REALM. Ordinary TTY launches share the exact-program authenticator while retaining separate policy. The realm record repeats original native caller proof, retains each intermediate obligation and attaches the original bootstrap owner only after authenticated creation. Selector and manifest reuse deployment scratch. Ten new controls and all six strict configurations pass: 322 library and 44 runtime tests, six native builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. The ordinary orchestrator is reduced from 944 to 784 lines; new code stays below the physical file ceiling. Original CI is under observation. Public dispatcher, held replies, global scheduling, coordinated startup consumers and source-bound native VM acceptance remain required; host transport controls do not establish a runnable mediator or guest build.Caller-bound realm record checkpoint — 18 September 2026: Signed
b85b4d9fa9ccb334055e37630dd2c4889fa52f7cis pushed. Explicit LCH1 version 3 budgets separate noncopyable realm records and disjoint receipt slots; native arena layout version 6 exports their compiler-derived geometry. Semantic reservation, inspection, abort and scope intake authenticate the actual original published Running caller/job/process generation/session/authority realm. Generation never wraps. Independent scope deletion and absence proof retain full signed first errors, and stale cleanup cannot touch a reused slot. One checked slot partition replaces the old overloads and one type-layout definition replaces the duplicated array. Eleven new controls and all six strict configurations pass: 312 library and 44 runtime tests, six native builds, formatting, Clippy, private rustdoc and Markdown without warnings. Original CI 137 and CI 138 pass from four complete logs (137,874 bytes), without warnings. Actual public dispatch, VFS/Loaderd preparation, native progress scheduling, Rootd/Integration startup adoption and consumer VM proof remain required; storage semantics do not establish a runnable realm.Original retained caller CI acceptance — 18 September 2026: Signed Launchd
a084e1167221bacc5dd1b60fec2ae4f05fa39c12passes CI 135 and CI 136. All four terminal logs are complete (135,122 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.Retained realm caller checkpoint — 18 September 2026: Signed
a084e1167221bacc5dd1b60fec2ae4f05fa39c12is pushed. Replace the obsolete synchronous bootstrap API with a noncopyable native caller and immediate syscall binding. Keep original child, local grant and invocation ownership independent; retain nonzero native IDs on error, release cancellation before ordinary abort and preserve first failures. Require canonical cap-free collection, actual source absence and full invocation retirement. Permanent source absence prevents old cancellation from touching a reused receipt slot. Nineteen focused controls and all six strict default/all and production configurations pass: 302 library and 43 runtime tests, six native builds, formatting, strict host/native Clippy, private-item rustdoc and Markdown without warnings. Original CI 135/136 is under observation. Actual caller-bound runtime admission, deployment-sized owner storage, scheduler integration and real consumer VM execution remain open; this binding alone does not establish runnable realm acceptance.Returned-grant consumer checkpoint — 18 September 2026: Signed revision
41e2dbf8e0c55be2ce09216b31704c7862c59fcdis pushed. The distinct producer moves the sole real grant over the private Procd route. It requires exact correlated acknowledgment and independent source absence before any disposal; deleting a residual source cannot create success evidence. Failed exchanges exhaust local receipt disposal and exact-stage abort. Seven literal transport controls pass with 290 library and 43 runtime units and four native builds. The current adapter remains synchronous and runtime realm orchestration is not yet connected. Formatting and Markdown checks pass. Original CI 133 and CI 134 passes; all four terminal logs are complete (132,090 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Runtime consumer dependency alignment — 15 September 2026
Signed
7c9d8378eb8bf95bd5a99cf13707881f54c6c0f9aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 326 default / 326 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds:launchd-runtime: 326 development / 326 release tests. There are 6 supported native builds in total. Push/review CI 131/132 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.326 library/binary tests, strict host/native checks and native binaries pass. CI 129/130 passes with complete warning-free logs.
Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open.
Review checklist
Changed diagnostic observation — 19 September 2026: signed Exsh
e81f0cf0aed0b5a3360d2ee2dac6d3f656c90d3fpasses all eight strict 967-test configurations, native builds, fmt, host/native Clippy and private rustdoc without warnings. Six native frame observations remain incomplete (97/63/100 runtime/all/diagnostic observations). Its bounded failure output uses existing stdout and identifies request 1, BEGIN_REALM, as InvalidReply. The actual telemetry-only VM retains original Launchd5837873167c5e6ed99045af7052004affb5c28ff, the original authority policy, 120-second hard limit and 45-second progress watchdog. It still fails and all 106 artifacts are retained; serial SHA256520999cc511e72ccb0bcb138c107f52ff629e2e3b21aa4d116ff4ad9aa402000(55,858 bytes). No unchanged retry or successful runtime acceptance is claimed.Source review shows that shells receive private script senders, while the initial realm dispatch recognizes these operations only on the public receiver. A Launchd change is under strict validation to enter the shared realm handler after the existing active-envelope and native-owner proof, preserving original held-reply custody and adding no sender. A matching fixed-server VM is required to establish the correction. Integration issue 66 retains both failures. Original Exsh CI 267 and 268 are under observation.
Signed private-route correction — 19 September 2026: Launchd
ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6dispatches realm operations through the shell's existing private script receiver after active-envelope and original native-owner authentication. It repeats Running-job proof in the shared realm handler and preserves the original held reply across both ingress classes. No new sender is delegated. All six strict configurations pass 322 library and 55 runtime tests each, six native builds, fmt, strict host/native Clippy, private rustdoc and Markdown without warnings. Original CI 143 and 144 are under observation. A matching fixed-server VM is still required; Integration issue 66 remains open with both failed predecessor observations.Corrected native caller VM — 19 September 2026: signed Integration
9139c6c5fa38c139e92520f6d410626b4cf1e4aaselects Launchdca9e7f534e26023a6c011b5cb9a8e256fd56c2d6, Exsh9c0f7ab851d527dd9dd10161d6a98e1fdc14598eand Docsce8a1538ab2220f1b346e1a051265f58f83f47fc. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly oneERIX_EXSH:REALM_ADMISSION:VERIFIEDprecedesERIX_ROOTD:INITIAL_EXSH:EXITED_OK. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present.All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256
bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7; the post-VM writable disk has SHA2568f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in issue 66.The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original Integration CI 1675 and 1676 are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item.
Original CI update — 19 September 2026: Launchd run 143 passes with complete retained logs. Run 144, for the same signed
ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6source, fails its Markdown job while its Rust job passes. The complete 67,910-byte Rust log is retained without warnings. Two spaced GET observations of the failed Markdown job log return HTTP 500; that log is unavailable and the failure cause is unclassified. The workflow has not been rerun or cancelled, and the paired passing run does not replace this failure. The separately retained corrected caller VM passes; full original CI acceptance remains open.Native guarded preparation — 19 September 2026: signed Integration
78557a6c672ecf426dfe894a01cc4aeec73b5e3cselects signed Exshffe50612889dd58a45a40d04593a4aa3a3ffa512for the separateappliance-disk-image-realm-preparation-positivescenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selectsbin/trueinside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.Exactly one admission marker and one
ERIX_EXSH:REALM_PREPARATION:VERIFIEDprecede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff(55,776 bytes); post-VM writable disk SHA256 is3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.
Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.
Minimum bootstrap design — 19 September 2026: signed Posixd proposal, in PR 5, specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate.
Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution.
The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original Posixd CI 19 and 20 pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added.
Native child-lifetime prerequisite — 19 September 2026: Kernel design #19 now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration
a62d1381f56a01afc692112d9b427205eaeb6a2e. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor.Verified grant-rights checkpoint — 20 September 2026:
Signed commit be2e28730f714b35e356e925cee8061c67e0799d requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 377-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 145/146 passes from four complete hashed logs (142,882 bytes), with zero warning candidates.
Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256
6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.
Acknowledged terminal service dependencies — 21 September 2026: signed f5400949ec4e86055ea00e574ebe89f8f098f571 selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 4 strict 377-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 147, 148 passes; complete hashed logs total 142,968 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.