WIP: Enforce native RELRO and stage exact realm mediators #2

Draft
erikinkinen wants to merge 8 commits from feature/posix-compat into main
Owner

Summary and rationale

Stage an unstarted mediator through the authenticated complete executable graph, transferring only the actual install grant.

Tracking and scope

Owning feature issue #1 and realm design. Signed checkpoint: b48365030459f854c9e36f3c14b654e9bb3535d8. The corrected native slot collision is tracked in capability ABI issue 3.

Architecture, authority and failure behavior

The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open.

Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed.

Validation evidence

Resolved by user-triggered reruns, verified 19 September 2026: CI 97 (attempt 1), CI 98 (attempt 2), pass at unchanged commit 6783df35e4fae8c01ff3d281f0ec9d047892e986. All four test/Markdown job logs are complete and hashed (110,409 bytes), with zero warning or failure candidates. This resolves the current validation blockage. Original failed-attempt status and HTTP 500 observations remain history; their missing output and causes are not recovered or explained by this result. No source fix is claimed. Bug 3 is closed.

Historical original CI log evidence gap — 19 September 2026: Failed original jobs return HTTP 500 for their logs; bug 3 retains the selected run/job identities. Available original test logs pass without warnings, but the missing terminal output prevents complete CI acceptance or source-level diagnosis. At that observation no workflow had been rerun or cancelled.

Coherent realm image service prerequisites — 18 September 2026: Signed 6783df35e4fae8c01ff3d281f0ec9d047892e986 selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 6 default, all-feature and separate production development/release configurations pass 108 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. The original push/PR CI observation and subsequent user-rerun disposition are recorded below. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.

Original supervisor service checkpoint — 18 September 2026: Signed 4f1fb6371d46740ab2d637235f69e3fc604b3318 is pushed. Attest the actual native pending caller on private executable preparation and forward that original supervisor in the exact 64-byte materialization begin. Ordinary roles require zeros. Split the native preparation handler into a focused module. Three new boundary controls and all 108 tests pass in six strict host/native configurations, including production mode and six native builds. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original CI 95 and CI 96 passes with all four terminal logs (110,466 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open.

Runtime consumer dependency alignment — 15 September 2026

Signed 0012b9e35a155b4b2608ebcb5ab221586e909cba aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 90 default / 90 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: loaderd-runtime: 90 development / 90 release tests. There are 6 supported native builds in total. Push/review CI 91/92 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.

90 tests, both complete-graph producer classes, strict host/native checks and native binaries pass. CI 89/90 passes with complete warning-free logs.

Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open.

Native RELRO checkpoint — 16 September 2026: signed ec353c90590b8b5529f34b43e48b61789c3ac70e validates protected ranges before effects and derives final read-only child mappings independently of original relocation authorization. Fifteen new independent ELF/handoff controls bring the suite to 105 tests in each of six configurations. Strict host/native Clippy, six native builds, formatting, private rustdoc and canonical Markdown checks pass without warnings. Static replay admits all 34 selected native dynamic artifacts. Existing construction writes, exact counts, authenticated bytes, writable initial stack and failure/abort semantics are retained. Matching native VM, complete current-head CI and the manual update are pending; full frame, realm and guest-build gates stay open.

Native RELRO manual — 16 September 2026: signed Docs 2560e70884ddcb1b2f262ef74ea0dd30084d4259 documents protected-page validation, exact final mapping fragments, the writable initial stack and privileged construction writes over an unstarted child. All 45 documentation tests and canonical checks pass. The complete manual has 2,375 pages and 434,088 in-bounds word boxes, with zero final warnings; both changed pages pass visual review. Exported API snapshots are unchanged. Loaderd CI 93/94 passes with all four complete classified logs (109,621 bytes) and zero warnings. Docs CI 889/890 passes with all four complete classified logs (762,216 bytes); both manual jobs pass 45 tests and converge with 35/1/0 reference warnings, leaving zero final warnings. The earlier diagnostic native command sequence passed while its permission observation failed; the subsequent repaired checkpoint below supersedes that scoped result. This checkpoint does not establish complete runtime permission, frame, authority, realm or guest-build acceptance.

Native permission checkpoint — 16 September 2026: signed Kernel 32c70109fe7663440aa56de6a49975accc1f0057 carries explicit live execution permission through single-page, batch and permission-only mappings. Data and construction aliases remain non-executable; ancestor promotion and splitting preserve neighbouring restrictions. Processor activation validates and enables execute-disable support on the bootstrap and application processors. Seven independent controls accompany the repair. Strict default/all-feature development/release suites pass 666/690 kernel unit tests plus two external controls per selection, retaining three existing ignores. Host/native Clippy, private rustdoc, formatting and ten native builds pass without warnings.

Separate one-CPU and two-CPU diagnostic VMs pass the unchanged native command sequence. A read-only hardware observer matches all 233,755 selected coreutils executable bytes, verifies CPL3 and enabled paging/execute-disable state, and confirms both observed RELRO pages are user-readable, read-only and non-executable; the current stack is user-writable and non-executable. Both processors report execute-disable enabled. This is an exact process-entry/table observation, not an injected instruction-fault test or whole-system permission proof. The diagnostic image SHA-256 is 8c3c24639e8e1ca8c4f2ad4e485323abf32ec07408241c3e4fa9713f6e07e812.

Signed Docs d221e725c2543316680e63fc5e8314ce0fe3bdf1 documents the mapping and processor contracts. All 45 documentation tests and canonical checks pass; the 2,375-page manual has 434,308 in-bounds word boxes and zero final warnings, with three changed pages visually reviewed. Exported API snapshots are unchanged. Kernel CI 574/575 passes with four complete warning-free logs (708,112 bytes), including existing optimized workload examples. Docs CI 891/892 passes all four complete logs (762,176 bytes), with 45 tests per manual job and zero final warnings. The later maintained permission regression is recorded below. Full frame proof, whole-codebase authority/documentation review, runnable realms and both complete guest build generations remain open.

Maintained permission regression — 16 September 2026: signed Integration 89d15e4536004c087dcebd63c87216c0fd58958d supplies the explicit-input runner, pure ELF/page-table checks and read-only GDB observer. The final maintained source passes 21 independent host controls and the complete strict default/all-feature development/release Rust matrix, host/native Clippy, private rustdoc, formatting and four native builds. Canonical checks pass after correcting one Markdown line wrap. Both host groups are wired into ordinary CI. All 2,995 inventoried authored code files are below 1,000 lines; this is physical size evidence, not semantic authority closure.

Actual one-CPU and two-CPU runs on the repaired diagnostic image pass the original native-time command sequence and the expanded hardware checks: all 58 selected code pages are user-readable, read-only and executable; both RELRO pages are read-only/non-executable; the current stack is writable/non-executable. Complete executable bytes match and NX interpretation is enabled on every selected processor. An earlier image is rejected by the maintained observer. Both child outcomes, exact original input bytes and temporary cleanup are retained, with empty debugger stderr in both positive runs. The final cleanup code also preserves reaping when a direct child exits between poll and termination.

The command's image CI gate awaits adoption of a coherent product catalog containing both required component fixes. Its explicit diagnostic invocations do not silently replace the older maintained image graph. Signed Docs 3fb0b12ff55d044cc4bbe142418ab7a5b07bb42d documents the maintained operator contract. All 45 tests and canonical checks pass; the 2,377-page manual has 434,563 in-bounds word boxes with zero final warnings, and the changed subsection passes visual review. Exported API snapshots are unchanged. Matching Docs CI 893/894 passes with all four complete logs (762,616 bytes) and zero final warnings. Current Integration CI, complete frame proof, whole-codebase authority/documentation closure, runnable realms and both guest-build generations remain open.

Review checklist

  • Document the concrete staging contract and exact custody.
  • Validate applicable unit, native, documentation and formatting checks.
  • Publish signed canonical source checkpoints with original dependency pins.
  • Complete every outstanding dependent CI and runtime acceptance gate.
  • Finish typed mediator startup, isolation and retirement.
  • Complete whole-codebase audits and both full guest build generations.

Verified grant-rights checkpoint — 20 September 2026:

Signed commit cdf08f8e5f2cf208390099598f86ccfaa7cc96eb requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 108-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 99/100 passes from four complete hashed logs (110,360 bytes), with zero warning candidates.

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.

Acknowledged terminal service dependencies — 21 September 2026: signed 2222a30dff752f9b8d9966471f41da10199ee91e selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 4 strict 108-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 101, 102 passes; complete hashed logs total 110,460 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.

## Summary and rationale Stage an unstarted mediator through the authenticated complete executable graph, transferring only the actual install grant. ## Tracking and scope Owning feature issue #1 and [realm design](https://git.erikinkinen.fi/erix/posixd/issues/1). Signed checkpoint: `b48365030459f854c9e36f3c14b654e9bb3535d8`. The corrected native slot collision is tracked in [capability ABI issue 3](https://git.erikinkinen.fi/erix/lib-capabi/issues/3). ## Architecture, authority and failure behavior The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open. Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed. ## Validation evidence Resolved by user-triggered reruns, verified 19 September 2026: [CI 97](https://git.erikinkinen.fi/erix/loaderd/actions/runs/97) (attempt 1), [CI 98](https://git.erikinkinen.fi/erix/loaderd/actions/runs/98) (attempt 2), pass at unchanged commit `6783df35e4fae8c01ff3d281f0ec9d047892e986`. All four test/Markdown job logs are complete and hashed (110,409 bytes), with zero warning or failure candidates. This resolves the current validation blockage. Original failed-attempt status and HTTP 500 observations remain history; their missing output and causes are not recovered or explained by this result. No source fix is claimed. [Bug 3](https://git.erikinkinen.fi/erix/loaderd/issues/3) is closed. Historical original CI log evidence gap — 19 September 2026: Failed original jobs return HTTP 500 for their logs; [bug 3](https://git.erikinkinen.fi/erix/loaderd/issues/3) retains the selected run/job identities. Available original test logs pass without warnings, but the missing terminal output prevents complete CI acceptance or source-level diagnosis. At that observation no workflow had been rerun or cancelled. Coherent realm image service prerequisites — 18 September 2026: Signed `6783df35e4fae8c01ff3d281f0ec9d047892e986` selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 6 default, all-feature and separate production development/release configurations pass 108 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. The original push/PR CI observation and subsequent user-rerun disposition are recorded below. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open. Original supervisor service checkpoint — 18 September 2026: Signed `4f1fb6371d46740ab2d637235f69e3fc604b3318` is pushed. Attest the actual native pending caller on private executable preparation and forward that original supervisor in the exact 64-byte materialization begin. Ordinary roles require zeros. Split the native preparation handler into a focused module. Three new boundary controls and all 108 tests pass in six strict host/native configurations, including production mode and six native builds. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original [CI 95](https://git.erikinkinen.fi/erix/loaderd/actions/runs/95) and [CI 96](https://git.erikinkinen.fi/erix/loaderd/actions/runs/96) passes with all four terminal logs (110,466 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open. ### Runtime consumer dependency alignment — 15 September 2026 Signed `0012b9e35a155b4b2608ebcb5ab221586e909cba` aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 90 default / 90 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: `loaderd-runtime`: 90 development / 90 release tests. There are 6 supported native builds in total. Push/review CI 91/92 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending. 90 tests, both complete-graph producer classes, strict host/native checks and native binaries pass. CI 89/90 passes with complete warning-free logs. Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open. Native RELRO checkpoint — 16 September 2026: signed `ec353c90590b8b5529f34b43e48b61789c3ac70e` validates protected ranges before effects and derives final read-only child mappings independently of original relocation authorization. Fifteen new independent ELF/handoff controls bring the suite to 105 tests in each of six configurations. Strict host/native Clippy, six native builds, formatting, private rustdoc and canonical Markdown checks pass without warnings. Static replay admits all 34 selected native dynamic artifacts. Existing construction writes, exact counts, authenticated bytes, writable initial stack and failure/abort semantics are retained. Matching native VM, complete current-head CI and the manual update are pending; full frame, realm and guest-build gates stay open. Native RELRO manual — 16 September 2026: signed Docs `2560e70884ddcb1b2f262ef74ea0dd30084d4259` documents protected-page validation, exact final mapping fragments, the writable initial stack and privileged construction writes over an unstarted child. All 45 documentation tests and canonical checks pass. The complete manual has 2,375 pages and 434,088 in-bounds word boxes, with zero final warnings; both changed pages pass visual review. Exported API snapshots are unchanged. Loaderd CI 93/94 passes with all four complete classified logs (109,621 bytes) and zero warnings. Docs CI 889/890 passes with all four complete classified logs (762,216 bytes); both manual jobs pass 45 tests and converge with 35/1/0 reference warnings, leaving zero final warnings. The earlier diagnostic native command sequence passed while its permission observation failed; the subsequent repaired checkpoint below supersedes that scoped result. This checkpoint does not establish complete runtime permission, frame, authority, realm or guest-build acceptance. Native permission checkpoint — 16 September 2026: signed Kernel `32c70109fe7663440aa56de6a49975accc1f0057` carries explicit live execution permission through single-page, batch and permission-only mappings. Data and construction aliases remain non-executable; ancestor promotion and splitting preserve neighbouring restrictions. Processor activation validates and enables execute-disable support on the bootstrap and application processors. Seven independent controls accompany the repair. Strict default/all-feature development/release suites pass 666/690 kernel unit tests plus two external controls per selection, retaining three existing ignores. Host/native Clippy, private rustdoc, formatting and ten native builds pass without warnings. Separate one-CPU and two-CPU diagnostic VMs pass the unchanged native command sequence. A read-only hardware observer matches all 233,755 selected coreutils executable bytes, verifies CPL3 and enabled paging/execute-disable state, and confirms both observed RELRO pages are user-readable, read-only and non-executable; the current stack is user-writable and non-executable. Both processors report execute-disable enabled. This is an exact process-entry/table observation, not an injected instruction-fault test or whole-system permission proof. The diagnostic image SHA-256 is `8c3c24639e8e1ca8c4f2ad4e485323abf32ec07408241c3e4fa9713f6e07e812`. Signed Docs `d221e725c2543316680e63fc5e8314ce0fe3bdf1` documents the mapping and processor contracts. All 45 documentation tests and canonical checks pass; the 2,375-page manual has 434,308 in-bounds word boxes and zero final warnings, with three changed pages visually reviewed. Exported API snapshots are unchanged. Kernel CI 574/575 passes with four complete warning-free logs (708,112 bytes), including existing optimized workload examples. Docs CI 891/892 passes all four complete logs (762,176 bytes), with 45 tests per manual job and zero final warnings. The later maintained permission regression is recorded below. Full frame proof, whole-codebase authority/documentation review, runnable realms and both complete guest build generations remain open. Maintained permission regression — 16 September 2026: signed Integration `89d15e4536004c087dcebd63c87216c0fd58958d` supplies the explicit-input runner, pure ELF/page-table checks and read-only GDB observer. The final maintained source passes 21 independent host controls and the complete strict default/all-feature development/release Rust matrix, host/native Clippy, private rustdoc, formatting and four native builds. Canonical checks pass after correcting one Markdown line wrap. Both host groups are wired into ordinary CI. All 2,995 inventoried authored code files are below 1,000 lines; this is physical size evidence, not semantic authority closure. Actual one-CPU and two-CPU runs on the repaired diagnostic image pass the original native-time command sequence and the expanded hardware checks: all 58 selected code pages are user-readable, read-only and executable; both RELRO pages are read-only/non-executable; the current stack is writable/non-executable. Complete executable bytes match and NX interpretation is enabled on every selected processor. An earlier image is rejected by the maintained observer. Both child outcomes, exact original input bytes and temporary cleanup are retained, with empty debugger stderr in both positive runs. The final cleanup code also preserves reaping when a direct child exits between poll and termination. The command's image CI gate awaits adoption of a coherent product catalog containing both required component fixes. Its explicit diagnostic invocations do not silently replace the older maintained image graph. Signed Docs `3fb0b12ff55d044cc4bbe142418ab7a5b07bb42d` documents the maintained operator contract. All 45 tests and canonical checks pass; the 2,377-page manual has 434,563 in-bounds word boxes with zero final warnings, and the changed subsection passes visual review. Exported API snapshots are unchanged. Matching Docs CI 893/894 passes with all four complete logs (762,616 bytes) and zero final warnings. Current Integration CI, complete frame proof, whole-codebase authority/documentation closure, runnable realms and both guest-build generations remain open. ## Review checklist - [x] Document the concrete staging contract and exact custody. - [x] Validate applicable unit, native, documentation and formatting checks. - [x] Publish signed canonical source checkpoints with original dependency pins. - [ ] Complete every outstanding dependent CI and runtime acceptance gate. - [ ] Finish typed mediator startup, isolation and retirement. - [ ] Complete whole-codebase audits and both full guest build generations. Verified grant-rights checkpoint — 20 September 2026: Signed commit [cdf08f8e5f2cf208390099598f86ccfaa7cc96eb](https://git.erikinkinen.fi/erix/loaderd/commit/cdf08f8e5f2cf208390099598f86ccfaa7cc96eb) requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 108-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 99/100 passes from four complete hashed logs (110,360 bytes), with zero warning candidates. Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. Full coordinated consumer acceptance remains open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19) and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Acknowledged terminal service dependencies — 21 September 2026: signed [2222a30dff752f9b8d9966471f41da10199ee91e](https://git.erikinkinen.fi/erix/loaderd/commit/2222a30dff752f9b8d9966471f41da10199ee91e) selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). All 4 strict 108-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI [101](https://git.erikinkinen.fi/erix/loaderd/actions/runs/101), [102](https://git.erikinkinen.fi/erix/loaderd/actions/runs/102) passes; complete hashed logs total 110,460 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in [Phase 6 completion](https://git.erikinkinen.fi/erix/integration/issues/65).
feat: Stage realm mediators through exact executable preparation
All checks were successful
CI / markdown (push) Successful in 8s
CI / test (push) Successful in 1m1s
CI / markdown (pull_request) Successful in 6s
CI / test (pull_request) Successful in 52s
adefd028c4
Handle the separate private mediator operation through the existing verified
complete-graph pipeline. Preserve exact executable authority and operation
correlation while requesting only the actual install grant from Procd; never
receive or export the mediator endpoint master. Exercise both staging classes
and malformed authority receipts through the real producer functions.

The full default/all development and release test, strict host/native Clippy,
freestanding build, rustdoc, formatting and Markdown matrices pass. Coordinated
native realm bootstrap and its VM acceptance remain open.
build: Align corrected native bootstrap dependencies
All checks were successful
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 10s
CI / test (push) Successful in 1m6s
CI / test (pull_request) Successful in 1m6s
b483650304
Pin the original signed shared IPC and capability contracts used by the
coordinated staged-mediator producers after the native bootstrap slot correction. Preserve helper behavior and authority
ceilings while keeping the complete transitive graph coherent.

Default/all development and release tests, strict host/native Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass.
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (push) Successful in 32s
CI / markdown (pull_request) Successful in 31s
CI / test (push) Successful in 1m45s
CI / test (pull_request) Successful in 1m46s
0012b9e35a
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
feat: Enforce native RELRO final mapping permissions
All checks were successful
CI / markdown (pull_request) Successful in 20s
CI / markdown (push) Successful in 20s
CI / test (push) Successful in 1m3s
CI / test (pull_request) Successful in 1m4s
ec353c9059
Validate complete relocation-protected page coverage before effects and stream
final read-only fragments separately from original relocation authorization.
Preserve authenticated file/BSS coverage, exact materialization counts and a
still-writable initial stack without adding IPC or capability authority.

Fifteen new independent controls and all 105 tests pass across six strict
host/native configurations. Six native builds, rustdoc, formatting and Markdown
pass without warnings. Static replay admits 34 native artifacts. Matching VM
execution and complete CI remain pending; this checkpoint does not establish
frame-proof, realm or full guest-build acceptance.
erikinkinen changed title from WIP: Stage realm mediators through exact executable preparation to WIP: Enforce native RELRO and stage exact realm mediators 2026-09-15 23:11:35 +02:00
feat: Forward attested realm supervisor through preparation
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 11s
CI / test (pull_request) Successful in 1m10s
CI / test (push) Successful in 1m12s
4f1fb6371d
Query the actual native caller on the private Launchd receiver before
executable graph preparation. Carry that original pair through the
supervisor-aware semantic begin request and require zero owner fields
for ordinary roles. Split private preparation into a focused runtime module.

Three new boundary controls and all 108 tests pass in six strict host/native
configurations, including production mode. Six native builds, formatting,
Clippy, private rustdoc and Markdown pass. Actual Launchd runtime and
coordinated consumer VM acceptance remain required.
build: Adopt coherent realm contract dependencies
All checks were successful
CI / markdown (push) Successful in 12s
CI / test (push) Successful in 1m27s
CI / markdown (pull_request) Successful in 6s
CI / test (pull_request) Successful in 45s
6783df35e4
Select original signed shared revisions so coordinated runtime images can
resolve one source identity for every dependency. Preserve the component
implementation and update the roadmap to keep consumer VM acceptance explicit.

Validate default and all-feature development/release tests, strict host/native
Clippy, freestanding builds, formatting and private-item rustdoc with warnings
denied. Full image and in-guest build acceptance remain separate requirements.
fix: Minimize staged installer authority
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 4s
CI / test (push) Successful in 58s
CI / test (pull_request) Successful in 58s
cdf08f8e5f
Require exact GRANT-only final installer receipts and adopt the coherent
original shared dependency graph. Preserve existing unique custody and
original-generation cleanup instead of accepting unnecessary MINT authority.

Four strict 108-test configurations, four native builds with maintained
linker layouts, host/native Clippy, private rustdoc and policy checks pass
without warnings. Coherent guest acceptance remains a separate requirement.
build: Adopt acknowledged terminal accounting dependencies
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / test (pull_request) Successful in 59s
CI / test (push) Successful in 1m2s
2222a30dff
Select the original signed shared revisions for repeated terminal observation,
exact acknowledgement and retained final CPU measurements. Preserve the local
component implementation while keeping the complete transitive wire graph
consistent with Kernel design 20. Full service CPU/profiler VM acceptance and
Phase 6 self-hosting remain open in Integration issue 65.

All 4 strict host test matrices, host/native Clippy, warning-denied host/native
builds, private rustdoc, formatting and dependency/Markdown policies pass.
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / test (pull_request) Successful in 59s
CI / test (push) Successful in 1m2s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.