WIP: Define native authority and staged construction contracts #2

Draft
erikinkinen wants to merge 20 commits from feature/posix-compat into main
Owner

Summary and rationale

Define checked root-capability-free construction framing alongside the existing native authority, owned invocation and staged endpoint contracts.

The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites.

Tracking and scope

Owning feature issue #1, native mechanism, Procd bootstrap and realm design. Current signed original revision: 7c7712057cc5d16ab16a677a886caeac54814a16. Earlier constructor corrections retain their reports in Kernel issue 15 and capability ABI issue 3.

Architecture, authority and failure behavior

Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation.

Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work.

Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete.

Validation evidence

Native child-custody wire checkpoint — 19 September 2026: signed lib-ipc PR 2, aaf2df39700b43507b23ff2007bc0d573c4eea30, implements ChildLifetimeBindingV1, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the shared contract and Kernel design #19.

Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original lib-ipc CI 365 and 366 pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph.

The matching signed Docs PR 4, 54557713f4afad380c1166f6aa1c1622d3959744, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original Docs CI 979 and 980 pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required.

Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision 40edeee8f461c397e4bd6358e373f7a9185cbf34 is pushed. Distinct caller-bound reservation, preparation, read and abort codecs carry no caller-supplied process or session identity. Exact UTF-8 selectors borrow input without an extra pathname ceiling; full generational handles and cap-free responses require independent correlation. Seven new adversarial controls and all eight library/shim matrices pass: 412 IPC and 20 shim tests per configuration, with one pre-existing shim ignore retained. Descriptions confer no authority. Formatting and Markdown checks pass. Original CI 363 and CI 364 passes; all four terminal logs are complete (486,490 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements.

Original supervisor wire checkpoint — 18 September 2026: Signed revision 528598172136ee0db5d3733dd8eb6ca713a790d7 is pushed. Materialization begin is exactly 64 bytes, with two full-width original supervisor words required for mediators and forbidden for other roles. The obsolete 56-byte shape is removed. Four new adversarial codec controls cover literal wire positions, truncation, suffixes and owner pairing. Both shared crates pass strict host/native matrices; actual caller attestation and lifecycle custody remain service responsibilities. Formatting and Markdown checks pass. Original CI 361 and CI 362 passes; all four terminal logs are complete (478,708 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Owned bootstrap wire checkpoint — 18 September 2026: Signed revision d2f72761c11011c7f6991095ee304bca612119ba is pushed. The bootstrap request now carries only request/opcode/process/generation in exactly 16 bytes; removed source/destination selectors and the old 32-byte request are rejected. The correlated 32-byte capability-free response is unchanged. Both shared crates pass all strict host/native matrices. Actual native origin and grant scope remain consumer checks. Formatting and Markdown checks pass. Original CI 359 and CI 360 passes; all four terminal logs are complete (472,116 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Explicit receiver admission checkpoint — 18 September 2026: Signed revision e452014b25650de0f9ad174d2d1697653d0459d1 is pushed. The shared RequestBudget and REGISTER shim require explicit byte and capability limits. Zero dimensions, immutable exact registration, complete addressability and admission before native request custody are documented. The unbounded signature is removed. Both shared crates pass the complete strict host/native matrix. Kernel and live service validation remain independent requirements. Formatting and Markdown checks pass. Original CI 357 and CI 358 passes; all four terminal logs are complete (472,078 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Caller-local grant relocation checkpoint — 18 September 2026: Signed revision 3b06ba8de988824ce1896d2664b27885636dd30d is pushed. The shared selector and safe register-only syscall helper define native operation 0x54. Literal selector and hosted refusal controls pass. The operation moves only an actual held install/revocation grant inside the Running caller CSpace and admitted slot window, preserving its unique record, rights, scope and lineage. Both shared crates pass the complete strict host/native matrix. Signed Kernel 56d398e0 passes both actual native VMs, including thirty-nine new CPL3 relocation controls; service consumer adoption remains open. Formatting and Markdown checks pass. Original CI 355 and CI 356 passes; all four terminal logs are complete (472,097 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Returned-grant shared contract checkpoint — 18 September 2026: Signed revision 3a751fb9eb58a22a7f2dd6f196c8ef09ed0ce8b5 is pushed. The shared checked 32-byte request/response contract defines Procd operation 0x432, full-width source/destination slots, original stage identity, reserved fields and success-only guarded-stage acknowledgment. Six literal wire and correlation controls pass. Procd IDs are extracted into a cohesive documented inventory below the physical source limit. Both shared crates pass the complete strict host/native matrix. Native consumer and producer adoption remains open. Formatting and Markdown checks pass. Original CI 353 and CI 354 passes; all four terminal logs are complete (466,911 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision e4781c0bdb725d867c2f6bb6a783283ca04b2fc5 is pushed. The shared checked cleanup codec defines operations 56/57 with original process/generation identity, canonical reserved fields and zero result values. Selectors 8/35 are removed. Six new wire controls and the complete strict host/native matrix for both crates pass. Formatting and Markdown checks pass. Original CI 351 and CI 352 passes; all four terminal logs are complete (459,587 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Native terminal generation checkpoint — 17 September 2026: Signed revision 0e35b99d97064f54b2b14c23a9e0f0079246c083 is pushed. The checked operation 55 codec preserves the original process generation, validates reserved requests and canonical empty-queue results, and retires selector 7. Seven new wire/malformed-input tests pass. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries.

Runtime dependency alignment — 15 September 2026

Signed 83e267694ee23f0986a54562adcfd8d93c326a6a updates the existing foundation pin without changing authored Rust implementation files or wire layouts. The root crate passes 381 tests and the nested syscall shim passes 20 tests with one existing native-only ignore in every default/all development/release configuration. Strict host/native Clippy, eight native builds, private rustdoc and formatting pass with no warnings. The nested shim's original metadata was admitted separately before its locked checks. CI 347/348 passes with all logs classified and no final warnings. This is part of coherent runtime-source adoption, not a new product VM or guest-build acceptance.

All 381 IPC tests and the syscall shim matrix (20 tests, one existing native-only ignore) pass with strict default/all development/release host/native Clippy, builds, documentation and formatting. CI 345/346 has complete warning-free logs.

The expanded lifetime image has SHA256 9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800. The unchanged owned-invocation scenario passes with image SHA256 77a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued.

Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits.

Review checklist

  • Preserve actual authority and signed original source selection.
  • Pass applicable strict checks and both native mechanism scenarios.
  • Update applicable component documents and the technical manual.
  • Complete pending full Integration CI.
  • Complete producer adoption, typed bootstrap, realm execution and retirement.
  • Finish whole-codebase audits and both full guest build generations.

Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit 5fc20dc5195383c42d0997038196686dba78a0c1. Checked staged construction and derivation now carry exact own grant rights separately from child installation ceilings. Four wire matrices pass 423 tests each and four syscall-shim matrices pass 20 each, with one existing raw-syscall ignore retained. Eight native builds and matching strict checks pass. Validation has no warnings. Original CI 367/368 passes with four complete hashed logs (500,618 bytes), zero warnings.

Coordinated actual consumers and matching native execution remain open under Kernel design 19. This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. Phase completion retains native external Rust/LLVM/runtime rebuilding as an independent requirement.

Acknowledged terminal accounting — 21 September 2026: Kernel design 20 specifies final scalar CPU evidence retained independently of native resource reclamation, repeatable observations bound to actual original observer generations, independent authorized observers, exact acknowledgement and claim release on observer death. Both ordinary and mediator consumers must commit terminal measurements and cleanup duties before acknowledgement, including consumer-loss handling.

Shared wire commit 0b889095fd04f6f4b1da1d4c0064150551f52122 is signed and pushed. Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds, strict host/native Clippy, formatting, private rustdoc, Markdown and dependency checks pass without warnings. Native kernel and consumer adoption, actual CPL3/service VM acceptance and original CI observation remain open.

Canonical completion remains 3.48% weighted; 15 of 460 acceptance items. Full upstream Rust/LLVM/runtime rebuilding inside EriX remains mandatory together with both full EriX guest build generations. No acceptance item closes from this representation checkpoint.

Terminal-codec original CI — 21 September 2026: signed/pushed commit 0b889095fd04f6f4b1da1d4c0064150551f52122. Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds and matching strict checks pass. Local validation is warning-free. Original CI 369/370 passes from four complete hashed logs (507,354 bytes), zero warnings.

Native producer and actual consumer adoption remains in progress under Kernel design 20. Runtime acceptance remains open; phase completion retains native upstream toolchain rebuilding and both EriX guest generations.

## Summary and rationale Define checked root-capability-free construction framing alongside the existing native authority, owned invocation and staged endpoint contracts. The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites. ## Tracking and scope Owning feature issue #1, [native mechanism](https://git.erikinkinen.fi/erix/kernel/issues/1), [Procd bootstrap](https://git.erikinkinen.fi/erix/procd/issues/1) and [realm design](https://git.erikinkinen.fi/erix/posixd/issues/1). Current signed original revision: `7c7712057cc5d16ab16a677a886caeac54814a16`. Earlier constructor corrections retain their reports in [Kernel issue 15](https://git.erikinkinen.fi/erix/kernel/issues/15) and [capability ABI issue 3](https://git.erikinkinen.fi/erix/lib-capabi/issues/3). ## Architecture, authority and failure behavior Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation. Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work. Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete. ## Validation evidence Native child-custody wire checkpoint — 19 September 2026: signed [lib-ipc PR 2](https://git.erikinkinen.fi/erix/lib-ipc/pulls/2), `aaf2df39700b43507b23ff2007bc0d573c4eea30`, implements `ChildLifetimeBindingV1`, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the [shared contract](https://git.erikinkinen.fi/erix/lib-ipc/src/commit/aaf2df39700b43507b23ff2007bc0d573c4eea30/docs/child-lifetime-binding.md) and [Kernel design #19](https://git.erikinkinen.fi/erix/kernel/issues/19). Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original [lib-ipc CI 365](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/365) and [366](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/366) pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph. The matching signed [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4), `54557713f4afad380c1166f6aa1c1622d3959744`, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original [Docs CI 979](https://git.erikinkinen.fi/erix/docs/actions/runs/979) and [980](https://git.erikinkinen.fi/erix/docs/actions/runs/980) pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required. Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision `40edeee8f461c397e4bd6358e373f7a9185cbf34` is pushed. Distinct caller-bound reservation, preparation, read and abort codecs carry no caller-supplied process or session identity. Exact UTF-8 selectors borrow input without an extra pathname ceiling; full generational handles and cap-free responses require independent correlation. Seven new adversarial controls and all eight library/shim matrices pass: 412 IPC and 20 shim tests per configuration, with one pre-existing shim ignore retained. Descriptions confer no authority. Formatting and Markdown checks pass. Original [CI 363](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/363) and [CI 364](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/364) passes; all four terminal logs are complete (486,490 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements. Original supervisor wire checkpoint — 18 September 2026: Signed revision `528598172136ee0db5d3733dd8eb6ca713a790d7` is pushed. Materialization begin is exactly 64 bytes, with two full-width original supervisor words required for mediators and forbidden for other roles. The obsolete 56-byte shape is removed. Four new adversarial codec controls cover literal wire positions, truncation, suffixes and owner pairing. Both shared crates pass strict host/native matrices; actual caller attestation and lifecycle custody remain service responsibilities. Formatting and Markdown checks pass. Original [CI 361](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/361) and [CI 362](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/362) passes; all four terminal logs are complete (478,708 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Owned bootstrap wire checkpoint — 18 September 2026: Signed revision `d2f72761c11011c7f6991095ee304bca612119ba` is pushed. The bootstrap request now carries only request/opcode/process/generation in exactly 16 bytes; removed source/destination selectors and the old 32-byte request are rejected. The correlated 32-byte capability-free response is unchanged. Both shared crates pass all strict host/native matrices. Actual native origin and grant scope remain consumer checks. Formatting and Markdown checks pass. Original [CI 359](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/359) and [CI 360](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/360) passes; all four terminal logs are complete (472,116 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Explicit receiver admission checkpoint — 18 September 2026: Signed revision `e452014b25650de0f9ad174d2d1697653d0459d1` is pushed. The shared RequestBudget and REGISTER shim require explicit byte and capability limits. Zero dimensions, immutable exact registration, complete addressability and admission before native request custody are documented. The unbounded signature is removed. Both shared crates pass the complete strict host/native matrix. Kernel and live service validation remain independent requirements. Formatting and Markdown checks pass. Original [CI 357](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/357) and [CI 358](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/358) passes; all four terminal logs are complete (472,078 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Caller-local grant relocation checkpoint — 18 September 2026: Signed revision `3b06ba8de988824ce1896d2664b27885636dd30d` is pushed. The shared selector and safe register-only syscall helper define native operation 0x54. Literal selector and hosted refusal controls pass. The operation moves only an actual held install/revocation grant inside the Running caller CSpace and admitted slot window, preserving its unique record, rights, scope and lineage. Both shared crates pass the complete strict host/native matrix. Signed Kernel 56d398e0 passes both actual native VMs, including thirty-nine new CPL3 relocation controls; service consumer adoption remains open. Formatting and Markdown checks pass. Original [CI 355](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/355) and [CI 356](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/356) passes; all four terminal logs are complete (472,097 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Returned-grant shared contract checkpoint — 18 September 2026: Signed revision `3a751fb9eb58a22a7f2dd6f196c8ef09ed0ce8b5` is pushed. The shared checked 32-byte request/response contract defines Procd operation 0x432, full-width source/destination slots, original stage identity, reserved fields and success-only guarded-stage acknowledgment. Six literal wire and correlation controls pass. Procd IDs are extracted into a cohesive documented inventory below the physical source limit. Both shared crates pass the complete strict host/native matrix. Native consumer and producer adoption remains open. Formatting and Markdown checks pass. Original [CI 353](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/353) and [CI 354](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/354) passes; all four terminal logs are complete (466,911 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision `e4781c0bdb725d867c2f6bb6a783283ca04b2fc5` is pushed. The shared checked cleanup codec defines operations 56/57 with original process/generation identity, canonical reserved fields and zero result values. Selectors 8/35 are removed. Six new wire controls and the complete strict host/native matrix for both crates pass. Formatting and Markdown checks pass. Original [CI 351](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/351) and [CI 352](https://git.erikinkinen.fi/erix/lib-ipc/actions/runs/352) passes; all four terminal logs are complete (459,587 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Native terminal generation checkpoint — 17 September 2026: Signed revision `0e35b99d97064f54b2b14c23a9e0f0079246c083` is pushed. The checked operation 55 codec preserves the original process generation, validates reserved requests and canonical empty-queue results, and retires selector 7. Seven new wire/malformed-input tests pass. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries. ### Runtime dependency alignment — 15 September 2026 Signed `83e267694ee23f0986a54562adcfd8d93c326a6a` updates the existing foundation pin without changing authored Rust implementation files or wire layouts. The root crate passes 381 tests and the nested syscall shim passes 20 tests with one existing native-only ignore in every default/all development/release configuration. Strict host/native Clippy, eight native builds, private rustdoc and formatting pass with no warnings. The nested shim's original metadata was admitted separately before its locked checks. CI 347/348 passes with all logs classified and no final warnings. This is part of coherent runtime-source adoption, not a new product VM or guest-build acceptance. All 381 IPC tests and the syscall shim matrix (20 tests, one existing native-only ignore) pass with strict default/all development/release host/native Clippy, builds, documentation and formatting. CI 345/346 has complete warning-free logs. The expanded lifetime image has SHA256 `9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800`. The unchanged owned-invocation scenario passes with image SHA256 `77a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd`. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued. Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits. ## Review checklist - [x] Preserve actual authority and signed original source selection. - [x] Pass applicable strict checks and both native mechanism scenarios. - [x] Update applicable component documents and the technical manual. - [ ] Complete pending full Integration CI. - [ ] Complete producer adoption, typed bootstrap, realm execution and retirement. - [ ] Finish whole-codebase audits and both full guest build generations. Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit [5fc20dc5195383c42d0997038196686dba78a0c1](https://git.erikinkinen.fi/erix/lib-ipc/commit/5fc20dc5195383c42d0997038196686dba78a0c1). Checked staged construction and derivation now carry exact own grant rights separately from child installation ceilings. Four wire matrices pass 423 tests each and four syscall-shim matrices pass 20 each, with one existing raw-syscall ignore retained. Eight native builds and matching strict checks pass. Validation has no warnings. Original CI 367/368 passes with four complete hashed logs (500,618 bytes), zero warnings. Coordinated actual consumers and matching native execution remain open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19). This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. [Phase completion](https://git.erikinkinen.fi/erix/integration/issues/65) retains native external Rust/LLVM/runtime rebuilding as an independent requirement. Acknowledged terminal accounting — 21 September 2026: [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20) specifies final scalar CPU evidence retained independently of native resource reclamation, repeatable observations bound to actual original observer generations, independent authorized observers, exact acknowledgement and claim release on observer death. Both ordinary and mediator consumers must commit terminal measurements and cleanup duties before acknowledgement, including consumer-loss handling. Shared wire commit [0b889095fd04f6f4b1da1d4c0064150551f52122](https://git.erikinkinen.fi/erix/lib-ipc/commit/0b889095fd04f6f4b1da1d4c0064150551f52122) is signed and pushed. Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds, strict host/native Clippy, formatting, private rustdoc, Markdown and dependency checks pass without warnings. Native kernel and consumer adoption, actual CPL3/service VM acceptance and original CI observation remain open. Canonical completion remains **3.48% weighted; 15 of 460 acceptance items**. Full upstream Rust/LLVM/runtime rebuilding inside EriX remains mandatory together with both full EriX guest build generations. No acceptance item closes from this representation checkpoint. Terminal-codec original CI — 21 September 2026: signed/pushed commit [0b889095fd04f6f4b1da1d4c0064150551f52122](https://git.erikinkinen.fi/erix/lib-ipc/commit/0b889095fd04f6f4b1da1d4c0064150551f52122). Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds and matching strict checks pass. Local validation is warning-free. Original CI 369/370 passes from four complete hashed logs (507,354 bytes), zero warnings. Native producer and actual consumer adoption remains in progress under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). Runtime acceptance remains open; [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65) retains native upstream toolchain rebuilding and both EriX guest generations.
feat: Recognize native IPC result codes without implying completion
All checks were successful
CI / markdown (push) Successful in 27s
CI / test (push) Successful in 1m36s
CI / markdown (pull_request) Successful in 20s
CI / test (pull_request) Successful in 1m12s
5ff18b2bf6
Add checked recognition of all nine existing native result assignments and retain unknown integers without fallback or truncation. The data type grants no authority and requires callers to preserve route, operation, completion and cleanup context.

Enforce missing documentation in the remaining integration test crates, correct redundant rustdoc links, and select the published Cargo source helper. Formatting, strict Clippy, host and freestanding builds, private rustdoc, and default/all-feature tests pass for the library and syscall shim.
feat: Define consumed process lifetime revocation
All checks were successful
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 3s
CI / test (pull_request) Successful in 1m5s
CI / test (push) Successful in 1m6s
de6892790d
Add the register-only lifetime revocation syscall assignment and safe x86_64
shim for the mechanism specified in Kernel issue 7. Custody consumes an exact
local SEND-branch guard into the current process generation without granting
a handle, foreign selector or pending-operation completion acknowledgment.

Document authority and failure boundaries, and cover both crates with warning
denial, shim lint/docs and optimized/freestanding CI checks. The 52-command
local matrix passes; emitted assembly confirms every syscall argument and the
unmodified result. Native kernel enforcement, producer adoption and VM/manual
acceptance remain required before runtime use.
erikinkinen changed title from WIP: Recognize native IPC result codes with preserved context to WIP: Define lifetime revocation and checked IPC results 2026-09-14 09:22:18 +02:00
fix: Confine native syscall transport to freestanding x86-64
All checks were successful
CI / markdown (push) Successful in 7s
CI / markdown (pull_request) Successful in 6s
CI / test (push) Successful in 2m13s
CI / test (pull_request) Successful in 2m13s
805717680d
Select the EriX instruction backend at compile time. Other targets retain
the bridge API for tools and tests with local DENIED and zero auxiliary
outputs; checked helpers preserve their preceding slice validation. Extract
the internal backend and document its pointer and platform boundaries.
No runtime probe, new wire result or host transport is introduced.

Three public host regressions check refusal, absent authority metadata and
unchanged message buffers. Both crates pass strict default/all-feature
host and freestanding checks in development and release: 359 ABI tests and
one doctest, plus 18 shim tests and one existing ignored native-only case.
Emitted host objects contain no syscall instruction; native backend
instruction sequences remain identical in both profiles. Current CI and
the source-matched technical-manual update follow this signed checkpoint.
erikinkinen changed title from WIP: Define lifetime revocation and checked IPC results to WIP: Scope native IPC transport and define lifetime revocation 2026-09-14 12:15:58 +02:00
feat: Define owned invocation packets and immediate syscall transport
All checks were successful
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 4s
CI / test (push) Successful in 1m26s
CI / test (pull_request) Successful in 1m27s
de968da198
Add checked allocation-free input and receive codecs and eight explicit
owned invocation operations. Keep caller origin descriptive, destination
and receipt capacities distinct, and draining ownership separate from
ordinary rejection. Preserve every return bit so failed submission cannot
lose an accounted owner ID. Hosted shims refuse without native transport.

Pin literal layouts, malformed fields, overflow, spare output capacity,
repeat collection and full-width cleanup codes with new controls. Both
crates pass default/all-feature development/release tests, strict Clippy,
private rustdoc and warning-denied freestanding builds. Kernel dispatch,
CPL3 proof and realm acceptance remain dependent work tracked in kernel#11.
erikinkinen changed title from WIP: Scope native IPC transport and define lifetime revocation to WIP: Define owned invocation transport and confine native syscalls 2026-09-15 08:17:15 +02:00
feat: Define exact process-bound capability installation requests
All checks were successful
CI / markdown (pull_request) Successful in 10s
CI / markdown (push) Successful in 10s
CI / test (push) Successful in 2m27s
CI / test (pull_request) Successful in 2m28s
c453b697b8
Add the packed control contract for validating an actual held install grant
against its intended child and staged generation before native installation.
Requested rights are exact, including zero, without an inheritance sentinel.
The shared type validates only framing and scalar constraints; it supplies no
capability, target authority or native receipt. Keep existing producer wire
semantics unchanged while the typed realm bootstrap path adopts this check.

Validation: independent literal and malformed request controls; full strict
default/all development and release matrices, 371 IPC and 20 shim tests with
one existing shim ignore, host/freestanding Clippy, eight warning-denied target
builds, private rustdoc, Markdown and template checks. Native installer and
producer/realm acceptance remain dependent work.
erikinkinen changed title from WIP: Define owned invocation transport and confine native syscalls to WIP: Define owned invocation and process-bound installation contracts 2026-09-15 10:21:15 +02:00
feat: Define exact executable preparation for realm mediators
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 7s
CI / test (push) Successful in 2m23s
CI / test (pull_request) Successful in 2m24s
5fa5fdb2ed
Assign a separate private loader operation and process lifecycle class while
retaining the exact executable request layout and receipt authority. Require
responses to echo the selected operation so ordinary preparation cannot
substitute for mediator staging. Keep typed bootstrap and native realm
acceptance explicit as remaining work in the coordinated design.

Default and all-feature development/release tests, strict host/native Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass.
erikinkinen changed title from WIP: Define owned invocation and process-bound installation contracts to WIP: Define owned invocation and isolated staging contracts 2026-09-15 10:56:13 +02:00
feat: Define process-bound staged endpoint attenuation
All checks were successful
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 11s
CI / test (push) Successful in 1m59s
CI / test (pull_request) Successful in 2m0s
74c75a5db2
Add the checked request for narrowing an existing staged primary endpoint
through an actually held install grant. Preserve full packed widths, exact
zero rights and fail-closed reserved-field and identity validation.
Document the native grant, stage, scope and non-amplification requirements.

All 376 IPC tests and the syscall shim matrix pass with strict host/native
Clippy, builds, private rustdoc and formatting. Native implementation and
mediator bootstrap adoption remain independently validated obligations.
erikinkinen changed title from WIP: Define owned invocation and isolated staging contracts to WIP: Define native authority and staged endpoint contracts 2026-09-15 12:49:10 +02:00
feat: Define staged construction without root capabilities
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / test (pull_request) Successful in 2m30s
CI / test (push) Successful in 2m31s
7c7712057c
Add the distinct operation and checked request for creating a child whose
initial capability inventory contains only its primary endpoint. Preserve
full scalar widths and explicitly distinguish an omitted VSpace receipt
from a receipt in slot zero. Document native authority, backing ownership,
transactional cleanup and independent mediator bootstrap obligations.

All 381 IPC tests and the syscall shim matrix pass with strict host/native
development/release checks, formatting, private rustdoc and warning-denied
builds. Native implementation and CPL3 acceptance remain separate gates.
erikinkinen changed title from WIP: Define native authority and staged endpoint contracts to WIP: Define native authority and staged construction contracts 2026-09-15 13:54:34 +02:00
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / test (pull_request) Successful in 2m22s
CI / test (push) Successful in 2m23s
83e267694e
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
feat: Bind native terminal observations to process generations
All checks were successful
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 14s
CI / test (pull_request) Successful in 2m40s
CI / test (push) Successful in 2m43s
0e35b99d97
Add the checked operation 55 request and process/generation/kind/status
response. Validate reserved requests and canonical empty-queue responses,
preserve full scalar widths, and retire selector 7 without reinterpreting it.
Kernel and service adoption must use a coherent pinned revision graph.

Seven new wire and malformed-input controls pass with both crates' default
and all-feature development/release units, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks. Producer,
consumer and VM acceptance remains separately required.
feat: Bind native cleanup requests to the original generation
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 10s
CI / test (pull_request) Successful in 2m35s
CI / test (push) Successful in 2m37s
e4781c0bdb
Define distinct terminal-destruction and staged-abort selectors with checked
process/generation packing, reserved fields and exact response correlation.
Retire selectors 8 and 35 without reinterpreting their former wire contracts.
Actual control authority and atomic native eligibility remain Kernel duties.

Six new literal, malformed, full-width and response controls pass with both
crates' complete default/all-feature development/release strict host/native
matrices, documentation and formatting checks. Producer, consumer and runtime
adoption remain required before this wire contract proves native cleanup.
feat: Define the returned-grant bootstrap custody contract
All checks were successful
CI / markdown (pull_request) Successful in 26s
CI / markdown (push) Successful in 26s
CI / test (pull_request) Successful in 3m10s
CI / test (push) Successful in 3m11s
3a751fb9eb
Add exact checked request and response bodies for guarded mediator staging.
Preserve complete slot widths, reserved-field validation, identity correlation
and raw failure results without treating descriptive fields as authority.
Split Procd operation constants into their own documented inventory.

Six literal wire controls and the full strict host/native matrix pass for
both shared crates. Native grant admission, producer custody, fair retirement
and runnable realm acceptance remain separate implementation requirements.
feat: Define caller-local move-only grant relocation
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / test (pull_request) Successful in 1m23s
CI / test (push) Successful in 1m23s
3b06ba8de9
Assign register-only syscall 0x54 and expose its immediate native bridge.
The actual running caller supplies both local slots; moving an existing grant
preserves rights, target identity, installation scope and revocation lineage.
No process selector, copy or additional authority is introduced. Hosted use
refuses locally without a syscall.

Literal selector and host refusal controls pass with both shared crates in all
four strict host/native configurations, rustdoc, formatting and Markdown.
Kernel CPL3 validation and coherent owned producer adoption remain required.
feat: Declare owned receiver request budgets
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 13s
CI / test (pull_request) Successful in 3m5s
CI / test (push) Successful in 3m6s
e452014b25
Require explicit payload and capability limits when registering an owned
receiver. Document zero dimensions, exact registration repetition and admission
before native request custody. Remove the unbounded shim signature without a
compatibility fallback or additional authority.

Default and all-feature development/release unit tests, strict host/native
Clippy, warning-denied freestanding builds and rustdoc pass for both crates.
Formatting and corrected Markdown checks pass. Kernel and live consumer
adoption, including actual CPL3 validation, remain in progress.
feat: Define owned realm bootstrap request identity
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 11s
CI / test (pull_request) Successful in 2m40s
CI / test (push) Successful in 2m42s
d2f72761c1
Replace caller-selected grant source and destination selectors with the exact
16-byte request identity for native-owned bootstrap delivery. Keep the correlated
32-byte capability-free result and reject the removed legacy request shape.
Actual claimed origin, receiver-selected storage and native grant scope remain
consumer obligations. Default/all development/release host and native tests,
strict Clippy, warning-denied builds, rustdoc, formatting and Markdown pass.
Procd and Launchd adoption and consumer VM validation remain in progress.
feat: Bind realm materialization to its original supervisor
All checks were successful
CI / markdown (push) Successful in 6s
CI / markdown (pull_request) Successful in 7s
CI / test (pull_request) Successful in 2m24s
CI / test (push) Successful in 2m25s
5285981721
Extend materialization begin to exactly 64 bytes, retaining the original
supervisor process and generation for mediator stages. Require zeros for
other roles and remove the obsolete 56-byte shape. Split begin validation
into a cohesive module and cover literal wire positions, every truncated
length, unassigned suffixes, full-width identities and invalid owner pairs.

Default/all development and release tests, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. Actual
caller authentication and lifetime custody remain service responsibilities;
coordinated consumer and VM validation is still required.
feat: Define caller-bound realm admission messages
All checks were successful
CI / markdown (pull_request) Successful in 14s
CI / markdown (push) Successful in 18s
CI / test (pull_request) Successful in 2m45s
CI / test (push) Successful in 2m45s
40edeee8f4
Add distinct reservation, explicit executable preparation, inspection and abort
contracts with complete generational handles and cap-free acknowledgments.
BEGIN carries no claimed caller or session identity. Selector decoding borrows
exact UTF-8 without a private path ceiling; descriptions confer no authority.

Seven independent wire/correlation controls and all eight strict library/shim
configurations pass formatting, tests, host/native Clippy, builds and rustdoc
without warnings. Coordinated startup policy, actual runtime admission and
consumer VM proof remain required before usable realm or guest-build acceptance.
feat: Define native child lifetime binding messages
All checks were successful
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 11s
CI / test (push) Successful in 2m45s
CI / test (pull_request) Successful in 2m46s
aaf2df3970
Reserve the exact child/generation and actual local install-grant envelope
for supervisor lifetime custody. Preserve full scalar widths, reject all
reserved input, and distinguish custody admission from final reclamation.
The request supplies no owner selector, withdrawal form or extra authority.

Add literal wire, malformed-field, result-correlation and kill-reason
controls with the shared authority contract. Native enforcement, safe
reclamation progress and coherent consumer adoption remain open in Kernel
issue 19; the codec does not enable private mediator execution.
feat: Represent explicit install grant authority
All checks were successful
CI / markdown (push) Successful in 17s
CI / markdown (pull_request) Successful in 17s
CI / test (push) Successful in 2m38s
CI / test (pull_request) Successful in 2m40s
5fc20dc519
Separate the grant capability own rights from its child installation ceiling
in native creation and checked derivation requests. Preserve full-width scalar
fields, exact zero rights and reserved-field rejection without implicit MINT.

Both shared crates pass strict host and native matrices and rustdoc with no
warnings; the existing raw-syscall shim ignore remains. Native subset checks,
coordinated consumers and matching-image acceptance remain required.
feat: Define acknowledged terminal observations
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / test (pull_request) Successful in 2m32s
CI / test (push) Successful in 2m33s
0b889095fd
Replace destructive terminal waiting with checked observe and acknowledgement
codecs. Keep exact original process generations and reject every reserved field;
observer binding and retained final CPU results are specified by Kernel #20.

Four wire and four syscall-shim configurations pass strict tests, native builds,
Clippy and private rustdoc without warnings. Formatting, Markdown and dependency
policy pass. Native producer and consumer adoption remains work in progress.
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / test (pull_request) Successful in 2m32s
CI / test (push) Successful in 2m33s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.