WIP: Define native authority and staged construction contracts #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/lib-ipc!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Define checked root-capability-free construction framing alongside the existing native authority, owned invocation and staged endpoint contracts.
The feature branch also carries the coordinated process-bound installation, endpoint attenuation, owned invocation, lifetime and staged mediator prerequisites.
Tracking and scope
Owning feature issue #1, native mechanism, Procd bootstrap and realm design. Current signed original revision:
7c7712057cc5d16ab16a677a886caeac54814a16. Earlier constructor corrections retain their reports in Kernel issue 15 and capability ABI issue 3.Architecture, authority and failure behavior
Kernel operation 54 admits only actual Process endpoint holders and constructs a Created child with exactly one primary endpoint and no root capabilities. The native TCB retains address-space backing independently. The caller receives a unique install grant, an endpoint master and only an explicitly requested MAP-only VSpace receipt. The checked request distinguishes absence from a genuine slot-zero receipt. Former-root slots are usable; actual caller windows, native capacity, occupancy and child window scope remain enforced. Rollback disposes only successful new receipts and the partial child while preserving pre-existing bindings. Ordinary operation 32 remains unchanged. Initial inventory is not a seal or a permanent ban on later explicit installation.
Operation 53 separately narrows the primary endpoint through actual grant custody. Older kernels refuse the distinct constructor selector; consumers must not fall back to ignored legacy flags or a child self-report. Procd currently retains its private endpoint master while its move-only install grant passes through Loaderd and Launchd; adopting the new constructor is separate consumer work.
Procd adoption, authenticated grant return, guarded bootstrap authority, private mediator execution, readiness, configuration/seal, client I/O, fair retirement and both complete guest build generations remain open. Ordinary mediator start gates remain closed. Whole-codebase semantic authority and private-item documentation audits remain incomplete.
Validation evidence
Native child-custody wire checkpoint — 19 September 2026: signed lib-ipc PR 2,
aaf2df39700b43507b23ff2007bc0d573c4eea30, implementsChildLifetimeBindingV1, native operation 58 and supervisor-termination kill reason 4. The request preserves the exact child/generation and actual local grant slot, with no owner selector, rights mask or withdrawal form. Existing Process authority and current Running attribution remain separate native requirements. All reserved bits are rejected; replies carry zero result values and preserve uninterpreted codes. Lost replies retain the original cleanup obligation. See the shared contract and Kernel design #19.Seven new controls pass all eight strict library/shim configurations: 419 wire tests and 20 shim tests per configuration, eight freestanding builds, formatting, strict host/native Clippy and private rustdoc, with no warnings. The original kernel-only shim test remains ignored. Original lib-ipc CI 365 and 366 pass from four complete hashed logs, 494,246 bytes, without warnings. Kernel admission, descendant stopping, safe native reclamation progress, coherent consumer adoption and actual CPL3 failure coverage remain open. The shared codec does not enable private mediator execution or alter the current complete image's source graph.
The matching signed Docs PR 4,
54557713f4afad380c1166f6aa1c1622d3959744, updates the TeX chapter and both IPC API views from original signed source. All 45 tests, independent API regeneration, the complete 2,423-page manual, all 446,749 word bounds and nine visually reviewed contract pages pass, with zero final warnings. Original Docs CI 979 and 980 pass from four complete hashed logs, 773,034 bytes. Both runs pass 45 tests and the complete 2,423-page manual; successive TeX passes retain 36/1/0 warning observations, with zero final-pass warnings. No workflow rerun or cancellation supplies this result. Native upstream Rust/LLVM rebuilding and both complete EriX build generations inside EriX remain required.Caller-bound realm storage wire checkpoint — 18 September 2026: Signed revision
40edeee8f461c397e4bd6358e373f7a9185cbf34is pushed. Distinct caller-bound reservation, preparation, read and abort codecs carry no caller-supplied process or session identity. Exact UTF-8 selectors borrow input without an extra pathname ceiling; full generational handles and cap-free responses require independent correlation. Seven new adversarial controls and all eight library/shim matrices pass: 412 IPC and 20 shim tests per configuration, with one pre-existing shim ignore retained. Descriptions confer no authority. Formatting and Markdown checks pass. Original CI 363 and CI 364 passes; all four terminal logs are complete (486,490 bytes), without warnings. Actual admission dispatch, coordinated consumer VMs, runnable mediators and both full builds inside EriX remain separate open acceptance requirements.Original supervisor wire checkpoint — 18 September 2026: Signed revision
528598172136ee0db5d3733dd8eb6ca713a790d7is pushed. Materialization begin is exactly 64 bytes, with two full-width original supervisor words required for mediators and forbidden for other roles. The obsolete 56-byte shape is removed. Four new adversarial codec controls cover literal wire positions, truncation, suffixes and owner pairing. Both shared crates pass strict host/native matrices; actual caller attestation and lifecycle custody remain service responsibilities. Formatting and Markdown checks pass. Original CI 361 and CI 362 passes; all four terminal logs are complete (478,708 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Owned bootstrap wire checkpoint — 18 September 2026: Signed revision
d2f72761c11011c7f6991095ee304bca612119bais pushed. The bootstrap request now carries only request/opcode/process/generation in exactly 16 bytes; removed source/destination selectors and the old 32-byte request are rejected. The correlated 32-byte capability-free response is unchanged. Both shared crates pass all strict host/native matrices. Actual native origin and grant scope remain consumer checks. Formatting and Markdown checks pass. Original CI 359 and CI 360 passes; all four terminal logs are complete (472,116 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Explicit receiver admission checkpoint — 18 September 2026: Signed revision
e452014b25650de0f9ad174d2d1697653d0459d1is pushed. The shared RequestBudget and REGISTER shim require explicit byte and capability limits. Zero dimensions, immutable exact registration, complete addressability and admission before native request custody are documented. The unbounded signature is removed. Both shared crates pass the complete strict host/native matrix. Kernel and live service validation remain independent requirements. Formatting and Markdown checks pass. Original CI 357 and CI 358 passes; all four terminal logs are complete (472,078 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Caller-local grant relocation checkpoint — 18 September 2026: Signed revision
3b06ba8de988824ce1896d2664b27885636dd30dis pushed. The shared selector and safe register-only syscall helper define native operation 0x54. Literal selector and hosted refusal controls pass. The operation moves only an actual held install/revocation grant inside the Running caller CSpace and admitted slot window, preserving its unique record, rights, scope and lineage. Both shared crates pass the complete strict host/native matrix. Signed Kernel 56d398e0 passes both actual native VMs, including thirty-nine new CPL3 relocation controls; service consumer adoption remains open. Formatting and Markdown checks pass. Original CI 355 and CI 356 passes; all four terminal logs are complete (472,097 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Returned-grant shared contract checkpoint — 18 September 2026: Signed revision
3a751fb9eb58a22a7f2dd6f196c8ef09ed0ce8b5is pushed. The shared checked 32-byte request/response contract defines Procd operation 0x432, full-width source/destination slots, original stage identity, reserved fields and success-only guarded-stage acknowledgment. Six literal wire and correlation controls pass. Procd IDs are extracted into a cohesive documented inventory below the physical source limit. Both shared crates pass the complete strict host/native matrix. Native consumer and producer adoption remains open. Formatting and Markdown checks pass. Original CI 353 and CI 354 passes; all four terminal logs are complete (466,911 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision
e4781c0bdb725d867c2f6bb6a783283ca04b2fc5is pushed. The shared checked cleanup codec defines operations 56/57 with original process/generation identity, canonical reserved fields and zero result values. Selectors 8/35 are removed. Six new wire controls and the complete strict host/native matrix for both crates pass. Formatting and Markdown checks pass. Original CI 351 and CI 352 passes; all four terminal logs are complete (459,587 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Native terminal generation checkpoint — 17 September 2026: Signed revision
0e35b99d97064f54b2b14c23a9e0f0079246c083is pushed. The checked operation 55 codec preserves the original process generation, validates reserved requests and canonical empty-queue results, and retires selector 7. Seven new wire/malformed-input tests pass. Default/all-feature development and release units, strict host/native Clippy, freestanding builds, rustdoc, formatting and Markdown checks pass. Native producer/consumer migration, matching VM execution and full guest builds remain separate acceptance gates. Original automatic CI is being collected without retries.Runtime dependency alignment — 15 September 2026
Signed
83e267694ee23f0986a54562adcfd8d93c326a6aupdates the existing foundation pin without changing authored Rust implementation files or wire layouts. The root crate passes 381 tests and the nested syscall shim passes 20 tests with one existing native-only ignore in every default/all development/release configuration. Strict host/native Clippy, eight native builds, private rustdoc and formatting pass with no warnings. The nested shim's original metadata was admitted separately before its locked checks. CI 347/348 passes with all logs classified and no final warnings. This is part of coherent runtime-source adoption, not a new product VM or guest-build acceptance.All 381 IPC tests and the syscall shim matrix (20 tests, one existing native-only ignore) pass with strict default/all development/release host/native Clippy, builds, documentation and formatting. CI 345/346 has complete warning-free logs.
The expanded lifetime image has SHA256
9dc164d05415175fb509ea0228a0975a6e5184955bbc9c8b232baa29b10b3800. The unchanged owned-invocation scenario passes with image SHA25677a09c4d2c40e7444ce01197f81dadebd88b5b5df1432361e45c841d78000cdd. These are native mechanism tests. No guest build or new performance measurement is claimed. Docs CI 875/876 passes with complete classified logs and zero final warnings. Full Integration CI 1631/1632 remains queued.Applicable component documents and the technical manual describe the contract. The inventory covers 76 repositories, 2,970 code files below 1,000 lines and 160 direct missing_docs gates. This scan does not close the semantic authority or private-item documentation audits.
Review checklist
Explicit install-grant library checkpoint — 19 September 2026: signed/pushed commit 5fc20dc5195383c42d0997038196686dba78a0c1. Checked staged construction and derivation now carry exact own grant rights separately from child installation ceilings. Four wire matrices pass 423 tests each and four syscall-shim matrices pass 20 each, with one existing raw-syscall ignore retained. Eight native builds and matching strict checks pass. Validation has no warnings. Original CI 367/368 passes with four complete hashed logs (500,618 bytes), zero warnings.
Coordinated actual consumers and matching native execution remain open under Kernel design 19. This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. Phase completion retains native external Rust/LLVM/runtime rebuilding as an independent requirement.
Acknowledged terminal accounting — 21 September 2026: Kernel design 20 specifies final scalar CPU evidence retained independently of native resource reclamation, repeatable observations bound to actual original observer generations, independent authorized observers, exact acknowledgement and claim release on observer death. Both ordinary and mediator consumers must commit terminal measurements and cleanup duties before acknowledgement, including consumer-loss handling.
Shared wire commit 0b889095fd04f6f4b1da1d4c0064150551f52122 is signed and pushed. Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds, strict host/native Clippy, formatting, private rustdoc, Markdown and dependency checks pass without warnings. Native kernel and consumer adoption, actual CPL3/service VM acceptance and original CI observation remain open.
Canonical completion remains 3.48% weighted; 15 of 460 acceptance items. Full upstream Rust/LLVM/runtime rebuilding inside EriX remains mandatory together with both full EriX guest build generations. No acceptance item closes from this representation checkpoint.
Terminal-codec original CI — 21 September 2026: signed/pushed commit 0b889095fd04f6f4b1da1d4c0064150551f52122. Four wire configurations pass 427 tests each; four syscall-shim configurations pass 20 each with one existing ignore. Eight native builds and matching strict checks pass. Local validation is warning-free. Original CI 369/370 passes from four complete hashed logs (507,354 bytes), zero warnings.
Native producer and actual consumer adoption remains in progress under Kernel design 20. Runtime acceptance remains open; phase completion retains native upstream toolchain rebuilding and both EriX guest generations.
erikinkinen referenced this pull request from erix/docs2026-09-12 12:11:27 +02:00
WIP: Recognize native IPC result codes with preserved contextto WIP: Define lifetime revocation and checked IPC resultserikinkinen referenced this pull request from erix/docs2026-09-14 10:13:48 +02:00
WIP: Define lifetime revocation and checked IPC resultsto WIP: Scope native IPC transport and define lifetime revocationerikinkinen referenced this pull request from erix/docs2026-09-14 12:31:15 +02:00
WIP: Scope native IPC transport and define lifetime revocationto WIP: Define owned invocation transport and confine native syscallsWIP: Define owned invocation transport and confine native syscallsto WIP: Define owned invocation and process-bound installation contractsWIP: Define owned invocation and process-bound installation contractsto WIP: Define owned invocation and isolated staging contractsWIP: Define owned invocation and isolated staging contractsto WIP: Define native authority and staged endpoint contractsWIP: Define native authority and staged endpoint contractsto WIP: Define native authority and staged construction contractsView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.