[FEATURE] Audit authority, code quality and documentation in lib-tty #1
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/lib-tty#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem and motivation
This issue tracks continuous Phase 6 audit closure for
lib-tty. Separate PTY state/control from byte streams using caller-owned event storage and authenticated endpoint roles.An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance.
Proposed behavior and scope
Current inventory: 1 Cargo target (1 lib); manifests:
Cargo.toml. Include explicit and automatically discovered targets, supported features and target-specific configurations.Trace authority-bearing values across callers and public APIs; prove that the library does not acquire hidden service, hardware or host authority. Treat startup/teardown and rootd parity dimensions as caller/consumer contracts where this crate owns no process, with a separate evidence-backed applicability decision per row.
Authority, security and reliability
Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption.
Acceptance criteria
missing_docsenforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate.cargo fmt --all -- --check, strict Clippy, unit/doctests and warning-denied builds/rustdoc for every owned crate/target under default and all valid feature, freestanding/host, SMP and profile combinations; test mutually exclusive combinations separately. Add focused VM regressions for runtime behavior and observe the older catalog and unit tests at the exact published heads.Alternatives and tradeoffs
Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed.
Coherent realm image library prerequisite — 18 September 2026: Signed
1c22be326c49bd0738d287549d943c661067ac59selects the original shared caller-bound wire/startup dependency graph. Four strict default/all-feature development/release configurations pass 12 unit tests each, host/native Clippy, four freestanding builds, formatting, private-item rustdoc and Markdown with zero warnings. Direct Rust implementation bytes and authority behavior are unchanged. Original CI is under observation. Downstream manifest/catalog adoption and actual consumer VM acceptance remain required; this is not full guest-build evidence.Original coherent realm source CI acceptance — 18 September 2026: Signed
1c22be326c49bd0738d287549d943c661067ac59passes CI 13 and CI 12. All four terminal logs are complete (31,365 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Tracking and rollout
Coordinated library dependency update — 15 September 2026
Signed
8ae9539d31a67196d40ed15acdb60ff62327be50aligns existing dependency pins with the original foundation commits for coherent runtime adoption. This update changes Cargo selections and the roadmap; Rust implementation files in this repository are unchanged. All default/all-feature development/release configurations pass 12 tests each, strict host/native Clippy, formatting, four native builds and private rustdoc without warnings. Final canonical documentation checks pass. Push/review CI 10/11 passes with complete classified logs and no final warnings. The product catalog remains unchanged; this update does not establish a new runtime VM, authority-lifecycle closure, performance result or guest build. Review: #2.feature/posix-compat; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages.26a979afd137c25ac57d8d08a397bd5315c3115e; refresh component/dependency heads and their own CI evidence as implementation advances.Explicit install-grant library checkpoint — 20 September 2026: signed/pushed commit 7ada3478d4aa6834f98c9073928a5d542714a016. Original dependency pins now select the shared explicit grant-rights contract without mixed wire/capability revisions. The local API and authority policy are unchanged. Four host test matrices pass 12 tests each, alongside four native builds, strict host/native Clippy, formatting, private rustdoc and policy checks. Validation has no warnings. Original CI 14/15 passes with four complete hashed logs (31,364 bytes), zero warnings.
Both isolated native scenarios pass on their first attempts; full coordinated service-image execution remains open under Kernel design 19. This dependency/wire checkpoint does not establish complete lifecycle acceptance or either full EriX build generation. Phase completion retains native external Rust/LLVM/runtime rebuilding as an independent requirement.
Acknowledged terminal consumer dependencies — 21 September 2026: signed commit a42c108c203047075484bc22c1c83c9a8021c652 aligns original shared revisions for repeatable terminal observation and exact acknowledgement under Kernel design 20. No local API or capability policy changes. Four strict 12-unit host configurations, four native builds, host/native Clippy, private rustdoc, formatting and dependency checks pass without warnings. Original CI 16, 17 passes; four complete logs total 31,394 bytes with verified hashes and zero warning candidates. Actual service consumer and coherent full VM adoption remain open in phase completion.
[FEATURE] [P02.R55] Audit authority, code quality and documentation in lib-ttyto [FEATURE] Audit authority, code quality and documentation in lib-tty