generated from erix/meta
WIP: Align capability layouts and staged authority contracts #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/lib-capabi!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Select the original signed shared IPC framing while preserving capability registry and intake semantics.
The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites.
Tracking and scope
Owning feature issue #1, native mechanism, Procd bootstrap and realm design. Current signed original revision:
2d6b12832b3f0d798756a9c7f29a7c52a8b3bc70. Earlier constructor corrections retain their reports in Kernel issue 15 and capability ABI issue 3.Architecture, authority and failure behavior
Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation.
Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work.
Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete.
Validation evidence
Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision
82e700576432245c0a3c656ae7e97bcecf11ffcais pushed. The coherent immutable graph adopts caller-bound realm messages and, where used, explicit version-3 deployment storage. Local authority and runtime policy are unchanged. Default/all development and release tests, strict host/native Clippy, freestanding builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 242 and CI 243 passes; all four terminal logs are complete (141,064 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements.Original supervisor wire checkpoint — 18 September 2026: Signed revision
845ac85f93c5429aa7d64b57cf701ebc4984d388is pushed. The coherent immutable dependency graph adopts the supervisor-aware materialization request. Local runtime policy is unchanged. Default/all development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 240 and CI 241 passes; all four terminal logs are complete (141,086 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Owned bootstrap wire checkpoint — 18 September 2026: Signed revision
cc43a68431c1c0bc385bdf4397e2659779061f7ais pushed. The coherent immutable dependency graph adopts the identity-only owned bootstrap request. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 238 and CI 239 passes; all four terminal logs are complete (141,066 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Explicit receiver admission checkpoint — 18 September 2026: Signed revision
3c2e19862e5e84c5d8ffb3b6bacdf10e2aed478eis pushed. The coherent immutable dependency graph adopts explicit owned receiver request budgets. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 236 and CI 237 passes; all four terminal logs are complete (141,058 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Caller-local grant relocation checkpoint — 18 September 2026: Signed revision
6b5c065998b2a64fde76c14ad1a14744b63e4345is pushed. The coherent immutable dependency graph adopts the caller-local grant relocation ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 234 and CI 235 passes; all four terminal logs are complete (141,084 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Returned-grant shared contract checkpoint — 18 September 2026: Signed revision
53ba7ac127ff587de1ff0e5a0f371d65ff3c0b96is pushed. The coherent immutable dependency graph adopts the checked returned-grant bootstrap contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and private-item rustdoc pass. Formatting and Markdown checks pass. Original CI 232 and CI 233 passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision
8ee29f0dd4b1449348c8b703f078afc4e418b34bis pushed. The coherent immutable dependency graph adopts the checked generation-bound cleanup ABI. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, native builds and rustdoc pass. Formatting and Markdown checks pass. Original CI 230 and CI 231 passes; all four terminal logs are complete (141,110 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Native terminal generation checkpoint — 17 September 2026: Signed revision
bcf34f035ee1672c1ff6a837f1a04421ed6c4010is pushed. The coherent immutable dependency graph now selects the generation-bearing operation 55 contract. Local runtime policy is unchanged. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries.Coordinated library dependency update — 15 September 2026
Signed
ca68aae97f83ee5e93bdf50e9324a6291d38242baligns existing dependency pins with the original foundation commits for coherent runtime adoption. This update changes Cargo selections and the roadmap; Rust implementation files in this repository are unchanged. All default/all-feature development/release configurations pass 192 tests each, strict host/native Clippy, formatting, four native builds and private rustdoc without warnings. Final canonical documentation checks pass. Push/review CI 226/227 passes with complete classified logs and no final warnings. The product catalog remains unchanged; this update does not establish a new runtime VM, authority-lifecycle closure, performance result or guest build.All 192 tests and strict default/all development/release host/native checks pass. CI 224/225 has complete warning-free logs.
The expanded lifetime image has SHA256
9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800. The unchanged owned-invocation scenario passes with image SHA25677a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued.Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits.
Review checklist
Native child-custody dependency checkpoint — 19 September 2026: signed lib-capabi
fbec491937adopts original signed lib-ipc aaf2df39700b43507b23ff2007bc0d573c4eea30 before Kernel adoption, preserving one immutable IPC source in the native dependency graph. All four strict 192-test configurations, four freestanding builds, formatting, host/native Clippy and private rustdoc pass without warnings. Original CI 244 and 245 pass from four complete hashed logs, 141,078 bytes, without warnings. Local capability policy is unchanged. Actual binding, descendant stopping, safe reclamation, coherent consumer adoption and CPL3 evidence remain open in Kernel #19.Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit 673da5b70458f33a606ae2663eff457beb7728c3. Original dependency pins now select the shared explicit grant-rights contract without mixed wire/capability revisions. The local API and authority policy are unchanged. Four host test matrices pass 192 tests each, alongside four native builds, strict host/native Clippy, formatting, private rustdoc and policy checks. Validation has no warnings. Original CI 246/247 passes with four complete hashed logs (141,068 bytes), zero warnings.
Coordinated actual consumers and matching native execution remain open under Kernel design 19. This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. Phase completion retains native external Rust/LLVM/runtime rebuilding as an independent requirement.
Terminal-codec original CI — 21 September 2026: signed/pushed commit 109c111a62e038f7b4c4eacf86be0c27cb32127e. Original dependency alignment selects the checked terminal codecs without changing the local capability API or authority policy. Four configurations pass 192 tests each with four native builds, strict host/native Clippy, formatting, private rustdoc and policies. Local validation is warning-free. Original CI 248/249 passes from four complete hashed logs (141,066 bytes), zero warnings.
Native producer and actual consumer adoption remains in progress under Kernel design 20. Runtime acceptance remains open; phase completion retains native upstream toolchain rebuilding and both EriX guest generations.
WIP: Enforce documentation in job-broker teststo WIP: Align lifetime IPC dependency and enforce test documentationerikinkinen referenced this pull request from erix/docs2026-09-14 10:13:48 +02:00
WIP: Align lifetime IPC dependency and enforce test documentationto WIP: Align owned invocation IPC and enforce test documentationWIP: Align owned invocation IPC and enforce test documentationto WIP: Align IPC contracts and enforce crate documentationWIP: Align IPC contracts and enforce crate documentationto WIP: Define native capability and mediator staging boundariesWIP: Define native capability and mediator staging boundariesto WIP: Align capability layouts and staged authority contractsView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.