WIP: Enforce native RELRO and stage exact realm mediators #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/loaderd!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Stage an unstarted mediator through the authenticated complete executable graph, transferring only the actual install grant.
Tracking and scope
Owning feature issue #1 and realm design. Signed checkpoint:
b48365030459f854c9e36f3c14b654e9bb3535d8. The corrected native slot collision is tracked in capability ABI issue 3.Architecture, authority and failure behavior
The producer authenticates the actual executable and exact install-grant receipt. Procd owns the endpoint master; the mediator remains unstarted. Numeric operations, lifecycle classes, paths and slots confer no authority. The temporary endpoint uses slot 4 after native roots 1–3. Broader failure-path coverage and all typed startup gates remain open.
Actual grant-return provisioning, authenticated receiver readiness, configuration/seal, client I/O, fair retirement, whole-codebase authority/documentation closure and both complete guest build generations remain required. No runnable Posixd realm or guest-build acceptance is claimed.
Validation evidence
Resolved by user-triggered reruns, verified 19 September 2026: CI 97 (attempt 1), CI 98 (attempt 2), pass at unchanged commit
6783df35e4fae8c01ff3d281f0ec9d047892e986. All four test/Markdown job logs are complete and hashed (110,409 bytes), with zero warning or failure candidates. This resolves the current validation blockage. Original failed-attempt status and HTTP 500 observations remain history; their missing output and causes are not recovered or explained by this result. No source fix is claimed. Bug 3 is closed.Historical original CI log evidence gap — 19 September 2026: Failed original jobs return HTTP 500 for their logs; bug 3 retains the selected run/job identities. Available original test logs pass without warnings, but the missing terminal output prevents complete CI acceptance or source-level diagnosis. At that observation no workflow had been rerun or cancelled.
Coherent realm image service prerequisites — 18 September 2026: Signed
6783df35e4fae8c01ff3d281f0ec9d047892e986selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 6 default, all-feature and separate production development/release configurations pass 108 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. The original push/PR CI observation and subsequent user-rerun disposition are recorded below. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.Original supervisor service checkpoint — 18 September 2026: Signed
4f1fb6371d46740ab2d637235f69e3fc604b3318is pushed. Attest the actual native pending caller on private executable preparation and forward that original supervisor in the exact 64-byte materialization begin. Ordinary roles require zeros. Split the native preparation handler into a focused module. Three new boundary controls and all 108 tests pass in six strict host/native configurations, including production mode and six native builds. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original CI 95 and CI 96 passes with all four terminal logs (110,466 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open.Runtime consumer dependency alignment — 15 September 2026
Signed
0012b9e35a155b4b2608ebcb5ab221586e909cbaaligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 90 default / 90 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds:loaderd-runtime: 90 development / 90 release tests. There are 6 supported native builds in total. Push/review CI 91/92 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.90 tests, both complete-graph producer classes, strict host/native checks and native binaries pass. CI 89/90 passes with complete warning-free logs.
Formatting and applicable warning-denied builds pass. No new guest-performance result is claimed. Current inventory covers 76 repositories and 2958 code files below 1000 lines, with direct missing_docs gates on 158 Rust roots; semantic and private-item documentation closure remain open.
Native RELRO checkpoint — 16 September 2026: signed
ec353c90590b8b5529f34b43e48b61789c3ac70evalidates protected ranges before effects and derives final read-only child mappings independently of original relocation authorization. Fifteen new independent ELF/handoff controls bring the suite to 105 tests in each of six configurations. Strict host/native Clippy, six native builds, formatting, private rustdoc and canonical Markdown checks pass without warnings. Static replay admits all 34 selected native dynamic artifacts. Existing construction writes, exact counts, authenticated bytes, writable initial stack and failure/abort semantics are retained. Matching native VM, complete current-head CI and the manual update are pending; full frame, realm and guest-build gates stay open.Native RELRO manual — 16 September 2026: signed Docs
2560e70884ddcb1b2f262ef74ea0dd30084d4259documents protected-page validation, exact final mapping fragments, the writable initial stack and privileged construction writes over an unstarted child. All 45 documentation tests and canonical checks pass. The complete manual has 2,375 pages and 434,088 in-bounds word boxes, with zero final warnings; both changed pages pass visual review. Exported API snapshots are unchanged. Loaderd CI 93/94 passes with all four complete classified logs (109,621 bytes) and zero warnings. Docs CI 889/890 passes with all four complete classified logs (762,216 bytes); both manual jobs pass 45 tests and converge with 35/1/0 reference warnings, leaving zero final warnings. The earlier diagnostic native command sequence passed while its permission observation failed; the subsequent repaired checkpoint below supersedes that scoped result. This checkpoint does not establish complete runtime permission, frame, authority, realm or guest-build acceptance.Native permission checkpoint — 16 September 2026: signed Kernel
32c70109fe7663440aa56de6a49975accc1f0057carries explicit live execution permission through single-page, batch and permission-only mappings. Data and construction aliases remain non-executable; ancestor promotion and splitting preserve neighbouring restrictions. Processor activation validates and enables execute-disable support on the bootstrap and application processors. Seven independent controls accompany the repair. Strict default/all-feature development/release suites pass 666/690 kernel unit tests plus two external controls per selection, retaining three existing ignores. Host/native Clippy, private rustdoc, formatting and ten native builds pass without warnings.Separate one-CPU and two-CPU diagnostic VMs pass the unchanged native command sequence. A read-only hardware observer matches all 233,755 selected coreutils executable bytes, verifies CPL3 and enabled paging/execute-disable state, and confirms both observed RELRO pages are user-readable, read-only and non-executable; the current stack is user-writable and non-executable. Both processors report execute-disable enabled. This is an exact process-entry/table observation, not an injected instruction-fault test or whole-system permission proof. The diagnostic image SHA-256 is
8c3c24639e8e1ca8c4f2ad4e485323abf32ec07408241c3e4fa9713f6e07e812.Signed Docs
d221e725c2543316680e63fc5e8314ce0fe3bdf1documents the mapping and processor contracts. All 45 documentation tests and canonical checks pass; the 2,375-page manual has 434,308 in-bounds word boxes and zero final warnings, with three changed pages visually reviewed. Exported API snapshots are unchanged. Kernel CI 574/575 passes with four complete warning-free logs (708,112 bytes), including existing optimized workload examples. Docs CI 891/892 passes all four complete logs (762,176 bytes), with 45 tests per manual job and zero final warnings. The later maintained permission regression is recorded below. Full frame proof, whole-codebase authority/documentation review, runnable realms and both complete guest build generations remain open.Maintained permission regression — 16 September 2026: signed Integration
89d15e4536004c087dcebd63c87216c0fd58958dsupplies the explicit-input runner, pure ELF/page-table checks and read-only GDB observer. The final maintained source passes 21 independent host controls and the complete strict default/all-feature development/release Rust matrix, host/native Clippy, private rustdoc, formatting and four native builds. Canonical checks pass after correcting one Markdown line wrap. Both host groups are wired into ordinary CI. All 2,995 inventoried authored code files are below 1,000 lines; this is physical size evidence, not semantic authority closure.Actual one-CPU and two-CPU runs on the repaired diagnostic image pass the original native-time command sequence and the expanded hardware checks: all 58 selected code pages are user-readable, read-only and executable; both RELRO pages are read-only/non-executable; the current stack is writable/non-executable. Complete executable bytes match and NX interpretation is enabled on every selected processor. An earlier image is rejected by the maintained observer. Both child outcomes, exact original input bytes and temporary cleanup are retained, with empty debugger stderr in both positive runs. The final cleanup code also preserves reaping when a direct child exits between poll and termination.
The command's image CI gate awaits adoption of a coherent product catalog containing both required component fixes. Its explicit diagnostic invocations do not silently replace the older maintained image graph. Signed Docs
3fb0b12ff55d044cc4bbe142418ab7a5b07bb42ddocuments the maintained operator contract. All 45 tests and canonical checks pass; the 2,377-page manual has 434,563 in-bounds word boxes with zero final warnings, and the changed subsection passes visual review. Exported API snapshots are unchanged. Matching Docs CI 893/894 passes with all four complete logs (762,616 bytes) and zero final warnings. Current Integration CI, complete frame proof, whole-codebase authority/documentation closure, runnable realms and both guest-build generations remain open.Review checklist
Verified grant-rights checkpoint — 20 September 2026:
Signed commit cdf08f8e5f2cf208390099598f86ccfaa7cc96eb requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 108-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 99/100 passes from four complete hashed logs (110,360 bytes), with zero warning candidates.
Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256
6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.
Acknowledged terminal service dependencies — 21 September 2026: signed 2222a30dff752f9b8d9966471f41da10199ee91e selects the original shared libraries for repeated terminal observation, exact acknowledgement and final CPU measurements under Kernel design 20. All 4 strict 108-test selected development/release feature configurations, warning-denied host/native builds with the maintained linker layout, host/native Clippy, private rustdoc, applicable doctests, formatting and dependency/Markdown checks pass. All authored code remains below 1,000 lines. Original CI 101, 102 passes; complete hashed logs total 110,460 bytes with zero warning candidates. Full service CPU/profiler VM acceptance and guest builds remain open in Phase 6 completion.
WIP: Stage realm mediators through exact executable preparationto WIP: Enforce native RELRO and stage exact realm mediatorsView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.