WIP: Select exact executable preparation for realm mediators #2

Draft
erikinkinen wants to merge 11 commits from feature/posix-compat into main
Owner

Summary and rationale

Select mediator preparation through the transfer-aware loader client and reject substituted operations or incorrect live grant receipts.

Tracking and scope

Owning feature issue #1 and realm design. Signed checkpoint: e7ad077a1dce4602b116c89bcf2fded07261fac6. The corrected native slot collision is tracked in capability ABI issue 3.

Architecture, authority and failure behavior

The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open.

Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed.

Validation evidence

Coherent startup consumer acceptance — 18 September 2026: Signed Integration 8b1c037aed2503e1f2a4b17c8a8be0666d62a305 adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required.

Original public realm dispatch CI acceptance — 18 September 2026: Signed Launchd 5837873167c5e6ed99045af7052004affb5c28ff passes CI 141 and CI 142. All four terminal logs are complete (142,951 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime consumer adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.

Public realm dispatch and progress checkpoint — 18 September 2026: Signed 5837873167c5e6ed99045af7052004affb5c28ff is pushed. Public BEGIN, PREPARE, ABORT and READ now dispatch canonical frames and actual receipts through original native caller proof. Held replies survive bounded native progress. Creation/abort reply loss requests cleanup; read or refused-request loss preserves earlier realm ownership. A rotating cursor advances independent retirement before ordinary work and yields while native custody blocks peer calls. Original mediator events match before ordinary job lookup. Eleven new controls and all six strict configurations pass: 322 library and 55 runtime tests, six freestanding builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. Process-event handling is split into its own module; all authored code stays below 1,000 lines. Original CI is under observation. Coordinated startup/image consumers and actual consumer VMs remain required, as do configuration, readiness, seal, mediated I/O and both complete builds inside EriX.

Original exact preparation CI acceptance — 18 September 2026: Signed Launchd 5c58f9e702be3e130b7040be2a042b1a41a5aea8 passes CI 139 and CI 140. All four terminal logs are complete (140,314 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.

Exact realm executable preparation checkpoint — 18 September 2026: Signed 5c58f9e702be3e130b7040be2a042b1a41a5aea8 is pushed. Realm preparation now uses actual framed VFS resolution, complete pinned manifest reads and Loaderd PREPARE_REALM. Ordinary TTY launches share the exact-program authenticator while retaining separate policy. The realm record repeats original native caller proof, retains each intermediate obligation and attaches the original bootstrap owner only after authenticated creation. Selector and manifest reuse deployment scratch. Ten new controls and all six strict configurations pass: 322 library and 44 runtime tests, six native builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. The ordinary orchestrator is reduced from 944 to 784 lines; new code stays below the physical file ceiling. Original CI is under observation. Public dispatcher, held replies, global scheduling, coordinated startup consumers and source-bound native VM acceptance remain required; host transport controls do not establish a runnable mediator or guest build.

Caller-bound realm record checkpoint — 18 September 2026: Signed b85b4d9fa9ccb334055e37630dd2c4889fa52f7c is pushed. Explicit LCH1 version 3 budgets separate noncopyable realm records and disjoint receipt slots; native arena layout version 6 exports their compiler-derived geometry. Semantic reservation, inspection, abort and scope intake authenticate the actual original published Running caller/job/process generation/session/authority realm. Generation never wraps. Independent scope deletion and absence proof retain full signed first errors, and stale cleanup cannot touch a reused slot. One checked slot partition replaces the old overloads and one type-layout definition replaces the duplicated array. Eleven new controls and all six strict configurations pass: 312 library and 44 runtime tests, six native builds, formatting, Clippy, private rustdoc and Markdown without warnings. Original CI 137 and CI 138 pass from four complete logs (137,874 bytes), without warnings. Actual public dispatch, VFS/Loaderd preparation, native progress scheduling, Rootd/Integration startup adoption and consumer VM proof remain required; storage semantics do not establish a runnable realm.

Original retained caller CI acceptance — 18 September 2026: Signed Launchd a084e1167221bacc5dd1b60fec2ae4f05fa39c12 passes CI 135 and CI 136. All four terminal logs are complete (135,122 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed.

Retained realm caller checkpoint — 18 September 2026: Signed a084e1167221bacc5dd1b60fec2ae4f05fa39c12 is pushed. Replace the obsolete synchronous bootstrap API with a noncopyable native caller and immediate syscall binding. Keep original child, local grant and invocation ownership independent; retain nonzero native IDs on error, release cancellation before ordinary abort and preserve first failures. Require canonical cap-free collection, actual source absence and full invocation retirement. Permanent source absence prevents old cancellation from touching a reused receipt slot. Nineteen focused controls and all six strict default/all and production configurations pass: 302 library and 43 runtime tests, six native builds, formatting, strict host/native Clippy, private-item rustdoc and Markdown without warnings. Original CI 135/136 is under observation. Actual caller-bound runtime admission, deployment-sized owner storage, scheduler integration and real consumer VM execution remain open; this binding alone does not establish runnable realm acceptance.

Returned-grant consumer checkpoint — 18 September 2026: Signed revision 41e2dbf8e0c55be2ce09216b31704c7862c59fcd is pushed. The distinct producer moves the sole real grant over the private Procd route. It requires exact correlated acknowledgment and independent source absence before any disposal; deleting a residual source cannot create success evidence. Failed exchanges exhaust local receipt disposal and exact-stage abort. Seven literal transport controls pass with 290 library and 43 runtime units and four native builds. The current adapter remains synchronous and runtime realm orchestration is not yet connected. Formatting and Markdown checks pass. Original CI 133 and CI 134 passes; all four terminal logs are complete (132,090 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Runtime consumer dependency alignment — 15 September 2026

Signed 7c9d8378eb8bf95bd5a99cf13707881f54c6c0f9 aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 326 default / 326 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: launchd-runtime: 326 development / 326 release tests. There are 6 supported native builds in total. Push/review CI 131/132 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.

326 library/binary tests, strict host/native checks and native binaries pass. CI 129/130 passes with complete warning-free logs.

Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open.

Review checklist

  • Document the concrete staging contract and exact custody.
  • Validate applicable unit, native, documentation and formatting checks.
  • Publish signed canonical source checkpoints with original dependency pins.
  • Complete every outstanding dependent CI and runtime acceptance gate.
  • Finish typed mediator startup, isolation and retirement.
  • Complete whole-codebase audits and both full guest build generations.

Changed diagnostic observation — 19 September 2026: signed Exsh e81f0cf0aed0b5a3360d2ee2dac6d3f656c90d3f passes all eight strict 967-test configurations, native builds, fmt, host/native Clippy and private rustdoc without warnings. Six native frame observations remain incomplete (97/63/100 runtime/all/diagnostic observations). Its bounded failure output uses existing stdout and identifies request 1, BEGIN_REALM, as InvalidReply. The actual telemetry-only VM retains original Launchd 5837873167c5e6ed99045af7052004affb5c28ff, the original authority policy, 120-second hard limit and 45-second progress watchdog. It still fails and all 106 artifacts are retained; serial SHA256 520999cc511e72ccb0bcb138c107f52ff629e2e3b21aa4d116ff4ad9aa402000 (55,858 bytes). No unchanged retry or successful runtime acceptance is claimed.

Source review shows that shells receive private script senders, while the initial realm dispatch recognizes these operations only on the public receiver. A Launchd change is under strict validation to enter the shared realm handler after the existing active-envelope and native-owner proof, preserving original held-reply custody and adding no sender. A matching fixed-server VM is required to establish the correction. Integration issue 66 retains both failures. Original Exsh CI 267 and 268 are under observation.

Signed private-route correction — 19 September 2026: Launchd ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6 dispatches realm operations through the shell's existing private script receiver after active-envelope and original native-owner authentication. It repeats Running-job proof in the shared realm handler and preserves the original held reply across both ingress classes. No new sender is delegated. All six strict configurations pass 322 library and 55 runtime tests each, six native builds, fmt, strict host/native Clippy, private rustdoc and Markdown without warnings. Original CI 143 and 144 are under observation. A matching fixed-server VM is still required; Integration issue 66 remains open with both failed predecessor observations.

Corrected native caller VM — 19 September 2026: signed Integration 9139c6c5fa38c139e92520f6d410626b4cf1e4aa selects Launchd ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6, Exsh 9c0f7ab851d527dd9dd10161d6a98e1fdc14598e and Docs ce8a1538ab2220f1b346e1a051265f58f83f47fc. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one ERIX_EXSH:REALM_ADMISSION:VERIFIED precedes ERIX_ROOTD:INITIAL_EXSH:EXITED_OK. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present.

All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7; the post-VM writable disk has SHA256 8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in issue 66.

The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original Integration CI 1675 and 1676 are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item.

Original CI update — 19 September 2026: Launchd run 143 passes with complete retained logs. Run 144, for the same signed ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6 source, fails its Markdown job while its Rust job passes. The complete 67,910-byte Rust log is retained without warnings. Two spaced GET observations of the failed Markdown job log return HTTP 500; that log is unavailable and the failure cause is unclassified. The workflow has not been rerun or cancelled, and the paired passing run does not replace this failure. The separately retained corrected caller VM passes; full original CI acceptance remains open.

Native guarded preparation — 19 September 2026: signed Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c selects signed Exsh ffe50612889dd58a45a40d04593a4aa3a3ffa512 for the separate appliance-disk-image-realm-preparation-positive scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects bin/true inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.

Exactly one admission marker and one ERIX_EXSH:REALM_PREPARATION:VERIFIED precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is 7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff (55,776 bytes); post-VM writable disk SHA256 is 3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.

All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.

Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.

Minimum bootstrap design — 19 September 2026: signed Posixd proposal, in PR 5, specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate.

Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution.

The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original Posixd CI 19 and 20 pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added.

Native child-lifetime prerequisite — 19 September 2026: Kernel design #19 now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration a62d1381f56a01afc692112d9b427205eaeb6a2e. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor.

Verified grant-rights checkpoint — 20 September 2026:

Signed commit be2e28730f714b35e356e925cee8061c67e0799d requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 377-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 145/146 passes from four complete hashed logs (142,882 bytes), with zero warning candidates.

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.

Acknowledged terminal service dependencies — 21 September 2026: signed f5400949ec4e86055ea00e574ebe89f8f098f571 selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 4 strict 377-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 147, 148 passes; complete hashed logs total 142,968 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.

## Summary and rationale Select mediator preparation through the transfer-aware loader client and reject substituted operations or incorrect live grant receipts. ## Tracking and scope Owning feature issue #1 and [realm design](https://git.erikinkinen.fi/erix/posixd/issues/1). Signed checkpoint: `e7ad077a1dce4602b116c89bcf2fded07261fac6`. The corrected native slot collision is tracked in [capability ABI issue 3](https://git.erikinkinen.fi/erix/lib-capabi/issues/3). ## Architecture, authority and failure behavior The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open. Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed. ## Validation evidence Coherent startup consumer acceptance — 18 September 2026: Signed Integration `8b1c037aed2503e1f2a4b17c8a8be0666d62a305` adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required. Original public realm dispatch CI acceptance — 18 September 2026: Signed Launchd `5837873167c5e6ed99045af7052004affb5c28ff` passes [CI 141](https://git.erikinkinen.fi/erix/launchd/actions/runs/141) and [CI 142](https://git.erikinkinen.fi/erix/launchd/actions/runs/142). All four terminal logs are complete (142,951 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime consumer adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed. Public realm dispatch and progress checkpoint — 18 September 2026: Signed `5837873167c5e6ed99045af7052004affb5c28ff` is pushed. Public BEGIN, PREPARE, ABORT and READ now dispatch canonical frames and actual receipts through original native caller proof. Held replies survive bounded native progress. Creation/abort reply loss requests cleanup; read or refused-request loss preserves earlier realm ownership. A rotating cursor advances independent retirement before ordinary work and yields while native custody blocks peer calls. Original mediator events match before ordinary job lookup. Eleven new controls and all six strict configurations pass: 322 library and 55 runtime tests, six freestanding builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. Process-event handling is split into its own module; all authored code stays below 1,000 lines. Original CI is under observation. Coordinated startup/image consumers and actual consumer VMs remain required, as do configuration, readiness, seal, mediated I/O and both complete builds inside EriX. Original exact preparation CI acceptance — 18 September 2026: Signed Launchd `5c58f9e702be3e130b7040be2a042b1a41a5aea8` passes [CI 139](https://git.erikinkinen.fi/erix/launchd/actions/runs/139) and [CI 140](https://git.erikinkinen.fi/erix/launchd/actions/runs/140). All four terminal logs are complete (140,314 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed. Exact realm executable preparation checkpoint — 18 September 2026: Signed `5c58f9e702be3e130b7040be2a042b1a41a5aea8` is pushed. Realm preparation now uses actual framed VFS resolution, complete pinned manifest reads and Loaderd PREPARE_REALM. Ordinary TTY launches share the exact-program authenticator while retaining separate policy. The realm record repeats original native caller proof, retains each intermediate obligation and attaches the original bootstrap owner only after authenticated creation. Selector and manifest reuse deployment scratch. Ten new controls and all six strict configurations pass: 322 library and 44 runtime tests, six native builds, formatting, host/native Clippy, private rustdoc and Markdown, without warnings. The ordinary orchestrator is reduced from 944 to 784 lines; new code stays below the physical file ceiling. Original CI is under observation. Public dispatcher, held replies, global scheduling, coordinated startup consumers and source-bound native VM acceptance remain required; host transport controls do not establish a runnable mediator or guest build. Caller-bound realm record checkpoint — 18 September 2026: Signed `b85b4d9fa9ccb334055e37630dd2c4889fa52f7c` is pushed. Explicit LCH1 version 3 budgets separate noncopyable realm records and disjoint receipt slots; native arena layout version 6 exports their compiler-derived geometry. Semantic reservation, inspection, abort and scope intake authenticate the actual original published Running caller/job/process generation/session/authority realm. Generation never wraps. Independent scope deletion and absence proof retain full signed first errors, and stale cleanup cannot touch a reused slot. One checked slot partition replaces the old overloads and one type-layout definition replaces the duplicated array. Eleven new controls and all six strict configurations pass: 312 library and 44 runtime tests, six native builds, formatting, Clippy, private rustdoc and Markdown without warnings. Original [CI 137](https://git.erikinkinen.fi/erix/launchd/actions/runs/137) and [CI 138](https://git.erikinkinen.fi/erix/launchd/actions/runs/138) pass from four complete logs (137,874 bytes), without warnings. Actual public dispatch, VFS/Loaderd preparation, native progress scheduling, Rootd/Integration startup adoption and consumer VM proof remain required; storage semantics do not establish a runnable realm. Original retained caller CI acceptance — 18 September 2026: Signed Launchd `a084e1167221bacc5dd1b60fec2ae4f05fa39c12` passes [CI 135](https://git.erikinkinen.fi/erix/launchd/actions/runs/135) and [CI 136](https://git.erikinkinen.fi/erix/launchd/actions/runs/136). All four terminal logs are complete (135,122 bytes), with no warnings or failed tests. This closes the original caller CI observation above. Actual runtime admission, scheduler adoption and coordinated consumer VM proof remain required; no complete realm or guest-build acceptance is claimed. Retained realm caller checkpoint — 18 September 2026: Signed `a084e1167221bacc5dd1b60fec2ae4f05fa39c12` is pushed. Replace the obsolete synchronous bootstrap API with a noncopyable native caller and immediate syscall binding. Keep original child, local grant and invocation ownership independent; retain nonzero native IDs on error, release cancellation before ordinary abort and preserve first failures. Require canonical cap-free collection, actual source absence and full invocation retirement. Permanent source absence prevents old cancellation from touching a reused receipt slot. Nineteen focused controls and all six strict default/all and production configurations pass: 302 library and 43 runtime tests, six native builds, formatting, strict host/native Clippy, private-item rustdoc and Markdown without warnings. Original CI 135/136 is under observation. Actual caller-bound runtime admission, deployment-sized owner storage, scheduler integration and real consumer VM execution remain open; this binding alone does not establish runnable realm acceptance. Returned-grant consumer checkpoint — 18 September 2026: Signed revision `41e2dbf8e0c55be2ce09216b31704c7862c59fcd` is pushed. The distinct producer moves the sole real grant over the private Procd route. It requires exact correlated acknowledgment and independent source absence before any disposal; deleting a residual source cannot create success evidence. Failed exchanges exhaust local receipt disposal and exact-stage abort. Seven literal transport controls pass with 290 library and 43 runtime units and four native builds. The current adapter remains synchronous and runtime realm orchestration is not yet connected. Formatting and Markdown checks pass. Original [CI 133](https://git.erikinkinen.fi/erix/launchd/actions/runs/133) and [CI 134](https://git.erikinkinen.fi/erix/launchd/actions/runs/134) passes; all four terminal logs are complete (132,090 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. ### Runtime consumer dependency alignment — 15 September 2026 Signed `7c9d8378eb8bf95bd5a99cf13707881f54c6c0f9` aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 326 default / 326 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: `launchd-runtime`: 326 development / 326 release tests. There are 6 supported native builds in total. Push/review CI 131/132 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending. 326 library/binary tests, strict host/native checks and native binaries pass. CI 129/130 passes with complete warning-free logs. Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open. ## Review checklist - [x] Document the concrete staging contract and exact custody. - [x] Validate applicable unit, native, documentation and formatting checks. - [x] Publish signed canonical source checkpoints with original dependency pins. - [ ] Complete every outstanding dependent CI and runtime acceptance gate. - [ ] Finish typed mediator startup, isolation and retirement. - [ ] Complete whole-codebase audits and both full guest build generations. Changed diagnostic observation — 19 September 2026: signed Exsh `e81f0cf0aed0b5a3360d2ee2dac6d3f656c90d3f` passes all eight strict 967-test configurations, native builds, fmt, host/native Clippy and private rustdoc without warnings. Six native frame observations remain incomplete (97/63/100 runtime/all/diagnostic observations). Its bounded failure output uses existing stdout and identifies request 1, BEGIN_REALM, as InvalidReply. The actual telemetry-only VM retains original Launchd `5837873167c5e6ed99045af7052004affb5c28ff`, the original authority policy, 120-second hard limit and 45-second progress watchdog. It still fails and all 106 artifacts are retained; serial SHA256 `520999cc511e72ccb0bcb138c107f52ff629e2e3b21aa4d116ff4ad9aa402000` (55,858 bytes). No unchanged retry or successful runtime acceptance is claimed. Source review shows that shells receive private script senders, while the initial realm dispatch recognizes these operations only on the public receiver. A Launchd change is under strict validation to enter the shared realm handler after the existing active-envelope and native-owner proof, preserving original held-reply custody and adding no sender. A matching fixed-server VM is required to establish the correction. [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) retains both failures. Original [Exsh CI 267](https://git.erikinkinen.fi/erix/exsh/actions/runs/267) and [268](https://git.erikinkinen.fi/erix/exsh/actions/runs/268) are under observation. Signed private-route correction — 19 September 2026: Launchd `ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6` dispatches realm operations through the shell's existing private script receiver after active-envelope and original native-owner authentication. It repeats Running-job proof in the shared realm handler and preserves the original held reply across both ingress classes. No new sender is delegated. All six strict configurations pass 322 library and 55 runtime tests each, six native builds, fmt, strict host/native Clippy, private rustdoc and Markdown without warnings. Original [CI 143](https://git.erikinkinen.fi/erix/launchd/actions/runs/143) and [144](https://git.erikinkinen.fi/erix/launchd/actions/runs/144) are under observation. A matching fixed-server VM is still required; [Integration issue 66](https://git.erikinkinen.fi/erix/integration/issues/66) remains open with both failed predecessor observations. Corrected native caller VM — 19 September 2026: signed Integration `9139c6c5fa38c139e92520f6d410626b4cf1e4aa` selects Launchd `ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6`, Exsh `9c0f7ab851d527dd9dd10161d6a98e1fdc14598e` and Docs `ce8a1538ab2220f1b346e1a051265f58f83f47fc`. The actual VM passes all eleven admission calls over the shell's existing private script route: reservation, reads, full-width stale-generation rejection, missing-scope refusal, acknowledged retirement, record reuse and stale-abort rejection. Exactly one `ERIX_EXSH:REALM_ADMISSION:VERIFIED` precedes `ERIX_ROOTD:INITIAL_EXSH:EXITED_OK`. The original 120-second hard limit and 45-second progress watchdog are unchanged; scenario status is 0 and no build warning is present. All 106 actual appliance artifacts and complete logs are retained. The 55,738-byte serial log has SHA256 `bbf41401e975cb0b39c6d62ca32f8e612f4f751a505a7dbb113fe1f05c6415f7`; the post-VM writable disk has SHA256 `8f7faf83e8923de675bf5d030458f7bf7e8065dc4fdb95ec98714dfebc5f7938`. The earlier packaging checksum is retained separately. Independent review verifies all 73 original component revisions, the packaged diagnostic executable and the signed image's exact 72-byte LCH1 version-3 capacity record (four realm records; native arena 102,400 bytes). All 169 helper commands, twelve route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. Both failed predecessor images remain evidence in [issue 66](https://git.erikinkinen.fi/erix/integration/issues/66). The first BEGIN failed because the shell's private script intake lacked realm dispatch. The correction retains active-envelope and original native-owner checks and original reply custody, without delegating a new sender. Exsh's uncertain-disposal path makes no stdout IPC before terminal failure. Original [Integration CI 1675](https://git.erikinkinen.fi/erix/integration/actions/runs/1675) and [1676](https://git.erikinkinen.fi/erix/integration/actions/runs/1676) are queued. Successful preparation, mediator configuration/readiness/sealing, client byte I/O, complete source/effect/frame proof, native Rust/LLVM rebuilding and both full EriX builds remain required. This partial lifecycle acceptance adds no whole checklist item. Original CI update — 19 September 2026: [Launchd run 143](https://git.erikinkinen.fi/erix/launchd/actions/runs/143) passes with complete retained logs. [Run 144](https://git.erikinkinen.fi/erix/launchd/actions/runs/144), for the same signed `ca9e7f534e26023a6c011b5cb9a8e256fd56c2d6` source, fails its Markdown job while its Rust job passes. The complete 67,910-byte Rust log is retained without warnings. Two spaced GET observations of the failed Markdown job log return HTTP 500; that log is unavailable and the failure cause is unclassified. The workflow has not been rerun or cancelled, and the paired passing run does not replace this failure. The separately retained corrected caller VM passes; full original CI acceptance remains open. Native guarded preparation — 19 September 2026: signed Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` selects signed Exsh `ffe50612889dd58a45a40d04593a4aa3a3ffa512` for the separate `appliance-disk-image-realm-preparation-positive` scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects `bin/true` inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced. Exactly one admission marker and one `ERIX_EXSH:REALM_PREPARATION:VERIFIED` precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is `7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff` (55,776 bytes); post-VM writable disk SHA256 is `3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499`. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena. All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required. Original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) and [1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) are queued. Original [Exsh CI 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272) are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item. Minimum bootstrap design — 19 September 2026: signed [Posixd proposal](https://git.erikinkinen.fi/erix/posixd/src/commit/3e6292bd3e5c6a3e59dbae54124f8eea52141957/docs/minimum-bootstrap.md), in [PR 5](https://git.erikinkinen.fi/erix/posixd/pulls/5), specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate. Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution. The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original [Posixd CI 19](https://git.erikinkinen.fi/erix/posixd/actions/runs/19) and [20](https://git.erikinkinen.fi/erix/posixd/actions/runs/20) pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added. Native child-lifetime prerequisite — 19 September 2026: [Kernel design #19](https://git.erikinkinen.fi/erix/kernel/issues/19) now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration `a62d1381f56a01afc692112d9b427205eaeb6a2e`. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor. Verified grant-rights checkpoint — 20 September 2026: Signed commit [be2e28730f714b35e356e925cee8061c67e0799d](https://git.erikinkinen.fi/erix/launchd/commit/be2e28730f714b35e356e925cee8061c67e0799d) requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 377-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 145/146 passes from four complete hashed logs (142,882 bytes), with zero warning candidates. Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. Full coordinated consumer acceptance remains open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19) and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Acknowledged terminal service dependencies — 21 September 2026: signed [f5400949ec4e86055ea00e574ebe89f8f098f571](https://git.erikinkinen.fi/erix/launchd/commit/f5400949ec4e86055ea00e574ebe89f8f098f571) selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). All 4 strict 377-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI [147](https://git.erikinkinen.fi/erix/launchd/actions/runs/147), [148](https://git.erikinkinen.fi/erix/launchd/actions/runs/148) passes; complete hashed logs total 142,968 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65).
feat: Select exact executable preparation for realm mediators
All checks were successful
CI / markdown (push) Successful in 7s
CI / rust (push) Successful in 1m22s
CI / markdown (pull_request) Successful in 6s
CI / rust (pull_request) Successful in 1m15s
64b563482c
Expose the private mediator preparation constructor through the existing
transfer-aware loader client. Preserve the exact executable SEND receipt and
actual install-grant validation, and reject ordinary-operation reply
substitution. Align the coherent original dependency graph.

Full default/all development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. The typed
bootstrap orchestrator and native realm acceptance remain required.
build: Align corrected native bootstrap dependencies
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 10s
CI / rust (pull_request) Successful in 1m21s
CI / rust (push) Successful in 1m21s
e7ad077a1d
Pin the original signed shared IPC and capability contracts used by the
coordinated staged-mediator producers after the native bootstrap slot correction. Preserve helper behavior and authority
ceilings while keeping the complete transitive graph coherent.

Default/all development and release tests, strict host/native Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass.
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (pull_request) Successful in 35s
CI / markdown (push) Successful in 37s
CI / rust (push) Successful in 2m21s
CI / rust (pull_request) Successful in 2m22s
7c9d8378eb
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
feat: Return mediator grants through guarded bootstrap transport
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 8s
CI / rust (pull_request) Successful in 1m27s
CI / rust (push) Successful in 1m28s
41e2dbf8e0
Move the sole actual installation grant through Procd's distinct private
bootstrap operation. Validate exact framing, original stage correlation and
source absence before accepting guarded staging. Dispose every unexpected
receipt and attempt exact-generation abort independently after exchange failure;
uncertain cleanup remains an outstanding obligation.

Seven new literal transport controls and the full strict host/native matrix pass:
290 library and 43 runtime units, four native builds and private-item rustdoc.
The current peer adapter remains synchronous. Runnable realm orchestration,
owned fair progress and matching consumer VM acceptance remain open.
feat: Retain native realm bootstrap caller custody
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 10s
CI / rust (push) Successful in 1m20s
CI / rust (pull_request) Successful in 1m23s
a084e11672
Replace the synchronous guarded-bootstrap helper with a noncopyable caller that
retains native invocation, original child and source-grant obligations separately.
Release cancellation before ordinary child rollback, require canonical cap-free
results and actual source absence, and never touch a receipt slot after its
original obligation ends. Preserve first errors and exact cleanup identity.

Adopt the signed supervisor protocol graph and bind immediate native effects.
Nineteen focused controls and six strict configurations pass: 302 library and
43 runtime tests, six freestanding builds, Clippy, rustdoc and formatting without
warnings. Actual runtime admission, scheduler adoption and consumer VM proof
remain required before realm acceptance or a complete guest-build claim.
feat: Retain caller-bound realm admission storage
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / rust (push) Successful in 1m11s
CI / rust (pull_request) Successful in 1m11s
b85b4d9fa9
Allocate independent noncopyable realm records and disjoint receipt slots from
explicit LCH1 version 3 policy. Match actual pending callers to their original
published Running job, process generation, session and authority realm. Keep
nonwrapping identity, source absence and first cleanup failures across reuse.
Use one checked slot partition and one native type-layout definition.

Eleven new controls and all six strict configurations pass 312 library and 44
runtime tests, six native builds, Clippy, rustdoc, formatting and Markdown with
no warnings. Public dispatch, actual Loaderd preparation, scheduler wiring and
coordinated Rootd/Integration consumers remain required before runtime or VM
acceptance. This checkpoint does not demonstrate a usable realm or guest build.
feat: Retain exact realm executable preparation
All checks were successful
CI / markdown (pull_request) Successful in 19s
CI / markdown (push) Successful in 19s
CI / rust (push) Successful in 1m42s
CI / rust (pull_request) Successful in 1m42s
5c58f9e702
Share exact scoped executable and manifest authentication with ordinary TTY
launch while preserving separate policy. Obtain the original realm child only
through real Loaderd preparation, repeat native caller proof and retain each
intermediate cleanup obligation. Reuse deployment scratch for selector then
manifest. Preserve permanent source absence, exact child retirement, the first
cleanup error and global exclusion while native custody requires progress.

Ten new controls and all six strict configurations pass: 322 library and 44
runtime tests, six native builds, Clippy, rustdoc, formatting and Markdown,
without warnings. Public dispatcher, held replies, scheduler integration,
coordinated image consumers and native VM acceptance remain required.
feat: Connect caller-bound realm dispatch and progress
All checks were successful
CI / markdown (pull_request) Successful in 21s
CI / markdown (push) Successful in 24s
CI / rust (pull_request) Successful in 2m3s
CI / rust (push) Successful in 2m5s
5837873167
Dispatch canonical BEGIN, PREPARE, ABORT and READ frames through actual native
caller proof and exact preparation. Retain original replies across bounded
native work, rotate independent record cleanup and gate every ordinary peer
class while native custody remains. Keep cancellation bound to the creating
or aborting request, and preserve earlier records on lost reads or refusals.
Split process-event routing into its own module and match original mediators
before ordinary jobs. Preserve complete retirement before generation reuse.

Eleven new controls and six strict configurations pass: 322 library and 55
runtime tests, six native builds, Clippy, private rustdoc, formatting and
Markdown without warnings. Coordinated startup consumers and actual consumer
VMs remain required; this does not establish runnable realms or guest builds.
fix: Dispatch realm requests on authenticated script routes
Some checks failed
CI / markdown (push) Successful in 28s
CI / rust (pull_request) Successful in 1m47s
CI / rust (push) Successful in 1m52s
CI / markdown (pull_request) Failing after 1h0m49s
ca9e7f534e
Shell startup supplies a private script sender, while realm operations were
recognized only by the public receiver. Dispatch those operations after the
existing active-envelope and original native-owner checks, using the shared
realm handler and its repeated Running-job authentication. Defer new intake
on both ingress classes while the serial dispatcher holds an original realm
reply, preserving its receiver and cleanup ownership. Delegate no new sender.

Integration issue 66 retains the actual failing VM and a changed diagnostic
identifying the first BEGIN reply as invalid. All six strict configurations
pass 322 library and 55 runtime tests, six native builds, fmt, strict
host/native Clippy, private rustdoc and Markdown without warnings. The matching
corrected-server VM remains required before runtime acceptance.
fix: Minimize staged installer authority
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / rust (push) Successful in 1m32s
CI / rust (pull_request) Successful in 1m34s
be2e28730f
Require exact GRANT-only final installer receipts and adopt the coherent
original shared dependency graph. Preserve existing unique custody and
original-generation cleanup instead of accepting unnecessary MINT authority.

Four strict 377-test configurations, four native builds with maintained
linker layouts, host/native Clippy, private rustdoc and policy checks pass
without warnings. Coherent guest acceptance remains a separate requirement.
build: Adopt acknowledged terminal accounting dependencies
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 1m21s
CI / rust (push) Successful in 1m21s
f5400949ec
Select the original signed shared revisions for repeated terminal observation,
exact acknowledgement and retained final CPU measurements. Preserve the local
component implementation while keeping the complete transitive wire graph
consistent with Kernel design 20. Full service CPU/profiler VM acceptance and
Phase 6 self-hosting remain open in Integration issue 65.

All 4 strict host test matrices, host/native Clippy, warning-denied host/native
builds, private rustdoc, formatting and dependency/Markdown policies pass.
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / rust (pull_request) Successful in 1m21s
CI / rust (push) Successful in 1m21s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.