WIP: Align capability layouts and staged authority contracts #2

Draft
erikinkinen wants to merge 20 commits from feature/posix-compat into main
Owner

Summary and rationale

Select the original signed shared IPC framing while preserving capability registry and intake semantics.

The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites.

Tracking and scope

Owning feature issue #1, native mechanism, Procd bootstrap and realm design. Current signed original revision: 2d6b12832b3f0d798756a9c7f29a7c52a8b3bc70. Earlier constructor corrections retain their reports in Kernel issue 15 and capability ABI issue 3.

Architecture, authority and failure behavior

Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation.

Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work.

Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete.

Validation evidence

Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision 82e700576432245c0a3c656ae7e97bcecf11ffca is pushed. The coherent immutable graph adopts caller-bound realm messages and, where used, explicit version-3 deployment storage. Local authority and runtime policy are unchanged. Default/all development and release tests, strict host/native Clippy, freestanding builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 242 and CI 243 passes; all four terminal logs are complete (141,064 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements.

Original supervisor wire checkpoint — 18 September 2026: Signed revision 845ac85f93c5429aa7d64b57cf701ebc4984d388 is pushed. The coherent immutable dependency graph adopts the supervisor-aware materialization request. Local runtime policy is unchanged. Default/all development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 240 and CI 241 passes; all four terminal logs are complete (141,086 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Owned bootstrap wire checkpoint — 18 September 2026: Signed revision cc43a68431c1c0bc385bdf4397e2659779061f7a is pushed. The coherent immutable dependency graph adopts the identity-only owned bootstrap request. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 238 and CI 239 passes; all four terminal logs are complete (141,066 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Explicit receiver admission checkpoint — 18 September 2026: Signed revision 3c2e19862e5e84c5d8ffb3b6bacdf10e2aed478e is pushed. The coherent immutable dependency graph adopts explicit owned receiver request budgets. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 236 and CI 237 passes; all four terminal logs are complete (141,058 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Caller-local grant relocation checkpoint — 18 September 2026: Signed revision 6b5c065998b2a64fde76c14ad1a14744b63e4345 is pushed. The coherent immutable dependency graph adopts the caller-local grant relocation ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 234 and CI 235 passes; all four terminal logs are complete (141,084 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Returned-grant shared contract checkpoint — 18 September 2026: Signed revision 53ba7ac127ff587de1ff0e5a0f371d65ff3c0b96 is pushed. The coherent immutable dependency graph adopts the checked returned-grant bootstrap contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 232 and CI 233 passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision 8ee29f0dd4b1449348c8b703f078afc4e418b34b is pushed. The coherent immutable dependency graph adopts the checked generation-bound cleanup ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and rustdoc pass. Formatting and Markdown checks pass. Original CI 230 and CI 231 passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Native terminal generation checkpoint — 17 September 2026: Signed revision bcf34f035ee1672c1ff6a837f1a04421ed6c4010 is pushed. The coherent immutable dependency graph now selects the generation-bearing operation 55 contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries.

Coordinated library dependency update — 15 September 2026

Signed ca68aae97f83ee5e93bdf50e9324a6291d38242b aligns existing dependency pins with the original foundation commits for coherent runtime adoption. This update changes Cargo selections and the roadmap; Rust implementation files in this repository are unchanged. All default/all-feature development/release configurations pass 192 tests each, strict host/native Clippy, formatting, four native builds and private rustdoc without warnings. Final canonical documentation checks pass. Push/review CI 226/227 passes with complete classified logs and no final warnings. The product catalog remains unchanged; this update does not establish a new runtime VM, authority-lifecycle closure, performance result or guest build.

All 192 tests and strict default/all development/release host/native checks pass. CI 224/225 has complete warning-free logs.

The expanded lifetime image has SHA256 9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800. The unchanged owned-invocation scenario passes with image SHA256 77a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued.

Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits.

Review checklist

  • Preserve actual authority and signed original source selection.
  • Pass applicable strict checks and both native mechanism scenarios.
  • Update applicable component documents and the technical manual.
  • Complete pending full Integration CI.
  • Complete producer adoption, typed bootstrap, realm execution and retirement.
  • Finish whole-codebase audits and both full guest build generations.

Native child-custody dependency checkpoint — 19 September 2026: signed lib-capabi fbec491937 adopts original signed lib-ipc aaf2df39700b43507b23ff2007bc0d573c4eea30 before Kernel adoption, preserving one immutable IPC source in the native dependency graph. All four strict 192-test configurations, four freestanding builds, formatting, host/native Clippy and private rustdoc pass without warnings. Original CI 244 and 245 pass from four complete hashed logs, 141,078 bytes, without warnings. Local capability policy is unchanged. Actual binding, descendant stopping, safe reclamation, coherent consumer adoption and CPL3 evidence remain open in Kernel #19.

Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit 673da5b70458f33a606ae2663eff457beb7728c3. Original dependency pins now select the shared explicit grant-rights contract without mixed wire/capability revisions. The local API and authority policy are unchanged. Four host test matrices pass 192 tests each, alongside four native builds, strict host/native Clippy, formatting, private rustdoc and policy checks. Validation has no warnings. Original CI 246/247 passes with four complete hashed logs (141,068 bytes), zero warnings.

Coordinated actual consumers and matching native execution remain open under Kernel design 19. This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. Phase completion retains native external Rust/LLVM/runtime rebuilding as an independent requirement.

Terminal-codec original CI — 21 September 2026: signed/pushed commit 109c111a62e038f7b4c4eacf86be0c27cb32127e. Original dependency alignment selects the checked terminal codecs without changing the local capability API or authority policy. Four configurations pass 192 tests each with four native builds, strict host/native Clippy, formatting, private rustdoc and policies. Local validation is warning-free. Original CI 248/249 passes from four complete hashed logs (141,066 bytes), zero warnings.

Native producer and actual consumer adoption remains in progress under Kernel design 20. Runtime acceptance remains open; phase completion retains native upstream toolchain rebuilding and both EriX guest generations.

## Summary and rationale Select the original signed shared IPC framing while preserving capability registry and intake semantics. The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites. ## Tracking and scope Owning feature issue #1, [native mechanism](https://git.erikinkinen.fi/erix/kernel/issues/1), [Procd bootstrap](https://git.erikinkinen.fi/erix/procd/issues/1) and [realm design](https://git.erikinkinen.fi/erix/posixd/issues/1). Current signed original revision: `2d6b12832b3f0d798756a9c7f29a7c52a8b3bc70`. Earlier constructor corrections retain their reports in [Kernel issue 15](https://git.erikinkinen.fi/erix/kernel/issues/15) and [capability ABI issue 3](https://git.erikinkinen.fi/erix/lib-capabi/issues/3). ## Architecture, authority and failure behavior Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation. Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work. Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete. ## Validation evidence Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision `82e700576432245c0a3c656ae7e97bcecf11ffca` is pushed. The coherent immutable graph adopts caller-bound realm messages and, where used, explicit version-3 deployment storage. Local authority and runtime policy are unchanged. Default/all development and release tests, strict host/native Clippy, freestanding builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 242](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/242) and [CI 243](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/243) passes; all four terminal logs are complete (141,064 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements. Original supervisor wire checkpoint — 18 September 2026: Signed revision `845ac85f93c5429aa7d64b57cf701ebc4984d388` is pushed. The coherent immutable dependency graph adopts the supervisor-aware materialization request. Local runtime policy is unchanged. Default/all development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 240](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/240) and [CI 241](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/241) passes; all four terminal logs are complete (141,086 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Owned bootstrap wire checkpoint — 18 September 2026: Signed revision `cc43a68431c1c0bc385bdf4397e2659779061f7a` is pushed. The coherent immutable dependency graph adopts the identity-only owned bootstrap request. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 238](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/238) and [CI 239](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/239) passes; all four terminal logs are complete (141,066 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Explicit receiver admission checkpoint — 18 September 2026: Signed revision `3c2e19862e5e84c5d8ffb3b6bacdf10e2aed478e` is pushed. The coherent immutable dependency graph adopts explicit owned receiver request budgets. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 236](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/236) and [CI 237](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/237) passes; all four terminal logs are complete (141,058 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Caller-local grant relocation checkpoint — 18 September 2026: Signed revision `6b5c065998b2a64fde76c14ad1a14744b63e4345` is pushed. The coherent immutable dependency graph adopts the caller-local grant relocation ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 234](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/234) and [CI 235](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/235) passes; all four terminal logs are complete (141,084 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Returned-grant shared contract checkpoint — 18 September 2026: Signed revision `53ba7ac127ff587de1ff0e5a0f371d65ff3c0b96` is pushed. The coherent immutable dependency graph adopts the checked returned-grant bootstrap contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original [CI 232](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/232) and [CI 233](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/233) passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision `8ee29f0dd4b1449348c8b703f078afc4e418b34b` is pushed. The coherent immutable dependency graph adopts the checked generation-bound cleanup ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and rustdoc pass. Formatting and Markdown checks pass. Original [CI 230](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/230) and [CI 231](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/231) passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Native terminal generation checkpoint — 17 September 2026: Signed revision `bcf34f035ee1672c1ff6a837f1a04421ed6c4010` is pushed. The coherent immutable dependency graph now selects the generation-bearing operation 55 contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries. ### Coordinated library dependency update — 15 September 2026 Signed `ca68aae97f83ee5e93bdf50e9324a6291d38242b` aligns existing dependency pins with the original foundation commits for coherent runtime adoption. This update changes Cargo selections and the roadmap; Rust implementation files in this repository are unchanged. All default/all-feature development/release configurations pass 192 tests each, strict host/native Clippy, formatting, four native builds and private rustdoc without warnings. Final canonical documentation checks pass. Push/review CI 226/227 passes with complete classified logs and no final warnings. The product catalog remains unchanged; this update does not establish a new runtime VM, authority-lifecycle closure, performance result or guest build. All 192 tests and strict default/all development/release host/native checks pass. CI 224/225 has complete warning-free logs. The expanded lifetime image has SHA256 `9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800`. The unchanged owned-invocation scenario passes with image SHA256 `77a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd`. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued. Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits. ## Review checklist - [x] Preserve actual authority and signed original source selection. - [x] Pass applicable strict checks and both native mechanism scenarios. - [x] Update applicable component documents and the technical manual. - [ ] Complete pending full Integration CI. - [ ] Complete producer adoption, typed bootstrap, realm execution and retirement. - [ ] Finish whole-codebase audits and both full guest build generations. Native child-custody dependency checkpoint — 19 September 2026: signed lib-capabi fbec4919371603044b9c4dd57a35c10633be314f adopts original signed lib-ipc aaf2df39700b43507b23ff2007bc0d573c4eea30 before Kernel adoption, preserving one immutable IPC source in the native dependency graph. All four strict 192-test configurations, four freestanding builds, formatting, host/native Clippy and private rustdoc pass without warnings. Original [CI 244](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/244) and [245](https://git.erikinkinen.fi/erix/lib-capabi/actions/runs/245) pass from four complete hashed logs, 141,078 bytes, without warnings. Local capability policy is unchanged. Actual binding, descendant stopping, safe reclamation, coherent consumer adoption and CPL3 evidence remain open in [Kernel #19](https://git.erikinkinen.fi/erix/kernel/issues/19). Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit [673da5b70458f33a606ae2663eff457beb7728c3](https://git.erikinkinen.fi/erix/lib-capabi/commit/673da5b70458f33a606ae2663eff457beb7728c3). Original dependency pins now select the shared explicit grant-rights contract without mixed wire/capability revisions. The local API and authority policy are unchanged. Four host test matrices pass 192 tests each, alongside four native builds, strict host/native Clippy, formatting, private rustdoc and policy checks. Validation has no warnings. Original CI 246/247 passes with four complete hashed logs (141,068 bytes), zero warnings. Coordinated actual consumers and matching native execution remain open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19). This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. [Phase completion](https://git.erikinkinen.fi/erix/integration/issues/65) retains native external Rust/LLVM/runtime rebuilding as an independent requirement. Terminal-codec original CI — 21 September 2026: signed/pushed commit [109c111a62e038f7b4c4eacf86be0c27cb32127e](https://git.erikinkinen.fi/erix/lib-capabi/commit/109c111a62e038f7b4c4eacf86be0c27cb32127e). Original dependency alignment selects the checked terminal codecs without changing the local capability API or authority policy. Four configurations pass 192 tests each with four native builds, strict host/native Clippy, formatting, private rustdoc and policies. Local validation is warning-free. Original CI 248/249 passes from four complete hashed logs (141,066 bytes), zero warnings. Native producer and actual consumer adoption remains in progress under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). Runtime acceptance remains open; [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65) retains native upstream toolchain rebuilding and both EriX guest generations.
docs: Enforce documentation in job broker test crate
All checks were successful
CI / markdown (push) Successful in 13s
CI / test (push) Successful in 1m0s
CI / markdown (pull_request) Successful in 17s
CI / test (pull_request) Successful in 1m10s
3d4ac79dee
Document the integration-test inventory assumptions and enforce missing_docs
in the test crate. Check private-item Rustdoc using the original pinned source
helper, preserving test behavior and capability contracts.

Deny compiler and Rustdoc warnings in CI and cover host and freestanding
configurations. Both default and all-feature host suites pass 191 tests;
formatting, strict Clippy, builds and Rustdoc pass without warnings.
build: Align IPC revision for native lifetime custody
All checks were successful
CI / markdown (push) Successful in 2s
CI / markdown (pull_request) Successful in 3s
CI / test (push) Successful in 23s
CI / test (pull_request) Successful in 23s
984c9f7b0c
Select the signed IPC lifetime-revocation contract so the coordinated kernel
graph uses one original IPC revision through both direct and capability ABI
dependencies. Preserve capability types, rights, intake ceilings and APIs.

Default/all-feature development/release tests, doctests, strict Clippy and
warning-denied builds/private rustdoc pass, including freestanding libraries.
Document the dependency boundary and keep native enforcement, VM evidence and
the coordinated lifetime manual update with Kernel issue 7.
erikinkinen changed title from WIP: Enforce documentation in job-broker tests to WIP: Align lifetime IPC dependency and enforce test documentation 2026-09-14 09:27:45 +02:00
build: Align shared IPC revision for owned invocation transport
All checks were successful
CI / markdown (pull_request) Successful in 3s
CI / markdown (push) Successful in 3s
CI / test (push) Successful in 29s
CI / test (pull_request) Successful in 30s
a001a26f0e
Select the original signed shared codec and immediate syscall revision so
native consumers use one descriptive type and transport contract. Preserve
capability types, rights and all startup intake policies. Record the dependent
kernel dispatch and CPL3 acceptance without claiming runtime completion.

Default/all-feature development/release unit tests, strict host and native
Clippy, private rustdoc, freestanding builds and Markdown checks pass.
erikinkinen changed title from WIP: Align lifetime IPC dependency and enforce test documentation to WIP: Align owned invocation IPC and enforce test documentation 2026-09-15 08:17:16 +02:00
build: Align process-bound installation protocol dependency
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / test (pull_request) Successful in 57s
CI / test (push) Successful in 57s
fe8d558253
Pin the original IPC commit defining exact child and staged-generation
constraints for install-grant population. Preserve existing capability
representations and authority ceilings while exposing the coordinated wire
contract to native consumers.

Default and all-feature development and release tests, strict Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass
without warnings. Native producer adoption remains tracked separately.
erikinkinen changed title from WIP: Align owned invocation IPC and enforce test documentation to WIP: Align IPC contracts and enforce crate documentation 2026-09-15 10:21:16 +02:00
feat: Define the temporary realm bootstrap endpoint destination
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / test (push) Successful in 53s
CI / test (pull_request) Successful in 53s
e5a3e86449
Reserve the mediator's initial endpoint destination and document its explicit
custody: Procd retains the parent master, and the child must dispose its full
initial alias before seal. Align the original shared IPC preparation contract
without assigning authority to the slot number or relaxing capability ceilings.

All default/all development and release tests, strict host/native Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass.
erikinkinen changed title from WIP: Align IPC contracts and enforce crate documentation to WIP: Define native capability and mediator staging boundaries 2026-09-15 10:56:14 +02:00
fix: Keep the realm endpoint separate from native root bindings
All checks were successful
CI / markdown (push) Successful in 14s
CI / markdown (pull_request) Successful in 14s
CI / test (push) Successful in 1m4s
CI / test (pull_request) Successful in 1m4s
c7c72ae2a7
Move the temporary mediator endpoint from occupied CSpace-root slot 1 to
slot 4, after the mandatory CSpace, VSpace and TCB bindings. Add a direct
layout regression and preserve the actual native-constructor failure under
bug #3. The correction changes no endpoint rights or lifecycle authority.

The complete strict default/all host/native matrix passes. Native constructor
and CPL3 creation/cleanup acceptance are tracked with the coordinated fix.
build: Align capability ABI with staged endpoint attenuation
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 4s
CI / test (pull_request) Successful in 32s
CI / test (push) Successful in 32s
2a01c20570
Select the signed shared IPC request contract without expanding capability
types, intake rights or service grants. Keep native enforcement and realm
bootstrap adoption explicitly tracked as independent acceptance obligations.

All 192 tests and strict default/all host/native development/release checks
pass, including rustdoc, formatting and warning-denied builds.
erikinkinen changed title from WIP: Define native capability and mediator staging boundaries to WIP: Align capability layouts and staged authority contracts 2026-09-15 12:49:13 +02:00
build: Align capability ABI with root-capability-free creation
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 10s
CI / test (push) Successful in 1m1s
CI / test (pull_request) Successful in 1m2s
2d6b12832b
Select the signed shared request for staged construction without child
root capabilities. Preserve explicit optional receipts and native authority
validation while leaving capability types, intake rights and grants unchanged.

All 192 tests and strict host/native default/all development/release checks
pass, including formatting, private rustdoc and warning-denied builds.
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (pull_request) Successful in 18s
CI / markdown (push) Successful in 20s
CI / test (pull_request) Successful in 1m26s
CI / test (push) Successful in 1m30s
ca68aae97f
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
build: Adopt the generation-bearing terminal event contract
All checks were successful
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 14s
CI / test (pull_request) Successful in 1m6s
CI / test (push) Successful in 1m7s
bcf34f035e
Select the coherent signed shared IPC dependency graph with operation 55.
Keep native producer and consumer migration explicit; identifiers in event
responses confer no authority and do not replace actual endpoint custody.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
VM and runnable realm acceptance remains separately required.
build: Adopt the generation-bound native cleanup contract
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 12s
CI / test (pull_request) Successful in 1m3s
CI / test (push) Successful in 1m3s
8ee29f0dd4
Select the coherent signed shared IPC dependency graph with operations 56 and 57.
Keep native producer and consumer migration explicit; descriptive identifiers in cleanup
requests confer no authority and do not replace actual endpoint custody.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
VM and runnable realm acceptance remains separately required.
build: Adopt the returned-grant bootstrap custody contract
All checks were successful
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 18s
CI / test (pull_request) Successful in 1m12s
CI / test (push) Successful in 1m15s
53ba7ac127
Select the coherent signed shared IPC dependency graph with Procd operation 0x432.
Keep native producer and consumer migration explicit; descriptive identifiers in cleanup
requests confer no authority and do not replace actual endpoint custody.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
VM and runnable realm acceptance remains separately required.
build: Adopt the caller-local grant relocation contract
All checks were successful
CI / markdown (pull_request) Successful in 3s
CI / markdown (push) Successful in 3s
CI / test (pull_request) Successful in 30s
CI / test (push) Successful in 30s
6b5c065998
Select the coherent signed shared IPC dependency graph with native syscall 0x54.
Keep native producer and consumer migration explicit; descriptive local slots in relocation
requests confer no authority and do not replace actual endpoint custody.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
VM and runnable realm acceptance remains separately required.
build: Adopt explicit owned receiver request budgets
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 13s
CI / test (pull_request) Successful in 1m9s
CI / test (push) Successful in 1m9s
3c2e19862e
Select the coherent signed shared IPC dependency graph with explicit REGISTER budgets.
Keep native producer and consumer migration explicit; receiver byte and capability
limits confer no authority and precede native request custody.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
VM and runnable realm acceptance remains separately required.
build: Adopt owned realm bootstrap request identity
All checks were successful
CI / markdown (pull_request) Successful in 17s
CI / markdown (push) Successful in 17s
CI / test (push) Successful in 1m13s
CI / test (pull_request) Successful in 1m14s
cc43a68431
Select the signed shared IPC revision with the identity-only bootstrap request.
Actual claimed origin and grant custody remain consumer obligations. All four
strict host/native matrices, rustdoc and formatting pass. Retain the original
Markdown line-length failure; corrected documentation passes without changing
the tested Rust source or dependency graph.
build: Adopt original realm supervisor wire identity
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 7s
CI / test (pull_request) Successful in 52s
CI / test (push) Successful in 53s
845ac85f93
Select the coherent signed shared graph with the exact 64-byte materialization
begin body. Descriptive identity confers no authority; native caller attestation
and retained original child ownership remain service responsibilities.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
consumer VM and runnable realm acceptance remain separately required.
build: Adopt caller-bound realm admission contracts
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 13s
CI / test (pull_request) Successful in 49s
CI / test (push) Successful in 49s
82e7005764
Select the coherent signed shared graph with exact realm admission messages.
Reservation carries no claimed caller identity. Complete generational handles
and selectors confer no authority; native caller validation and original child
ownership remain service responsibilities.

Default/all-feature development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Coordinated
consumer VM and runnable realm acceptance remain separately required.
build: Align native child lifetime protocol dependency
All checks were successful
CI / markdown (pull_request) Successful in 22s
CI / markdown (push) Successful in 23s
CI / test (push) Successful in 1m15s
CI / test (pull_request) Successful in 1m14s
fbec491937
Select the original signed IPC child-custody representation before Kernel
adopts it, keeping a single immutable IPC revision in the native dependency
graph. This changes no capability policy and adds no runtime authority.

All four strict 192-test configurations, freestanding builds, host/native
Clippy, formatting and private rustdoc pass without warnings. Kernel stopping,
safe reclamation and consumer lifecycle evidence remain separate work.
build: Adopt explicit install grant authority layouts
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / test (push) Successful in 1m0s
CI / test (pull_request) Successful in 1m0s
673da5b704
Select the original signed IPC revision with exact creation and derivation
rights, preserving a coherent shared dependency graph for native adoption.
Own grant authority remains distinct from its child installation ceiling.

No local capability policy changes. Strict host and native matrices, private
rustdoc and source-policy checks pass without warnings; consumer proof remains.
build: Align acknowledged terminal observation codecs
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 7s
CI / test (push) Successful in 53s
CI / test (pull_request) Successful in 53s
109c111a62
Select the original signed IPC revision for coordinated native accounting
adoption without mixed wire revisions. The local capability API and authority
policy remain unchanged.

Four strict host and native matrices, private rustdoc, formatting, Markdown
and dependency checks pass without warnings. Runtime adoption remains open.
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 7s
CI / test (push) Successful in 53s
CI / test (pull_request) Successful in 53s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.