[FEATURE] Audit authority, code quality and documentation in logd #1
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/logd#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem and motivation
This issue tracks continuous Phase 6 audit closure for
logd. Validate log startup/IPC, retain records and enforce console-mirror policy through explicit endpoints.An initial inventory is not a security or documentation closure claim. Evidence must follow each changed boundary through final heads, with priority security, reliability, then performance.
Proposed behavior and scope
Current inventory: 1 Cargo target (1 bin); manifests:
Cargo.toml. Include explicit and automatically discovered targets, supported features and target-specific configurations.Inventory every startup/runtime grant and authenticated peer, then success, denial, cancellation, failed transfer, restart and teardown. Trace callers and downstream providers so names, numeric identities and retained aliases never become implicit authority.
Authority, security and reliability
Maintain a finding register with public finding references, exact revisions, invariants, reproduction, owners, regression tests and closure evidence. Publish only non-sensitive status here; suspected vulnerabilities follow SECURITY.md. Each dimension below needs its own result and rationale; an absent daemon or current Rust target is not a blanket exemption.
Acceptance criteria
missing_docsenforcement without blanket allowances or hidden-API escapes, warning-denied private-item rustdoc and an undocumented-public-API negative gate.cargo fmt --all -- --check, strict Clippy, unit/doctests and warning-denied builds/rustdoc for every owned crate/target under default and all valid feature, freestanding/host, SMP and profile combinations; test mutually exclusive combinations separately. Add focused VM regressions for runtime behavior and observe the older catalog and unit tests at the exact published heads.Alternatives and tradeoffs
Use cohesive local refactoring or a justified shared extraction only after identifying real common semantics and authority boundaries. Remove superseded paths after preserving maintained coverage. Profile before optimization; document unavoidable ABI/hardware limits and explicit quotas rather than weakening security for speed.
Original coherent realm runtime prerequisites — 18 September 2026: Signed
a3cc7a06beefdb604d1b372ec7fdeb9def0356ecselects original shared dependency revisions. All 20 host/native output-policy configurations pass 43/45/59/62/133/138 tests per configuration and 20 native builds, including separate release logging, serial and framebuffer combinations. Formatting, strict host/native Clippy, private rustdoc and Markdown pass with zero warnings. Direct Rust implementation bytes are unchanged. Original CI is under observation. Matching catalogs, source-bound consumer VMs, complete realm operation and both full guest builds remain required.Original coherent realm source CI acceptance — 18 September 2026: Signed
a3cc7a06beefdb604d1b372ec7fdeb9def0356ecpasses CI 236 and CI 235. All four terminal logs are complete (631,831 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Tracking and rollout
Production output configuration validation — 15 September 2026
Signed
bc15238f25f818a28fe51b249e2db33f667c4599passes the complete warning-denied host/native matrix: default and runtime/logging configurations each pass 43 tests, serial-only 59, framebuffer/all-feature 133, release-only/release+logging 45, release+serial 62, and release+framebuffer 138, in both development and release profiles. All twenty native builds, strict host/native Clippy, formatting, private host/native rustdoc and documentation checks pass. Earlier failures are retained. Push/review CI 233/234 passes with complete classified logs and no final warnings. Product catalog and runtime-image adoption remain separate. Review: #4.feature/posix-compat; update linked WIP PRs after coherent signed checkpoints using canonical CONTRIBUTING.md messages.a543fe17624a5fada001851706821ad82ebf27f1; refresh component/dependency heads and their own CI evidence as implementation advances.Coherent dependency checkpoint — 20 September 2026: signed/pushed commit e54d56ee3de36ea9d4490fd93558abfdf4c1f4de aligns original shared dependency pins with the explicit installer-rights contract. Only the manifest and roadmap change; local implementation, APIs and authority policy are unchanged. Four strict 43/133-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting, private rustdoc and dependency checks pass without warnings. Original CI 237/238 passes with four complete hashed logs (631,829 bytes), zero warning candidates.
Full catalog equality and actual consumer-image validation remain required under Integration regression 68. The broader work remains tracked by phase completion, including native external Rust/LLVM/runtime rebuilding and both complete EriX-in-EriX generations. This dependency checkpoint does not close full lifecycle, frame or self-hosting acceptance.
Original CI observation — 21 September 2026: run 239 passes. Run 240 has now failed at original source
651024dd6956012697af1d1cafaf28950dacfa82; Forgejo returns HTTP 500 for both terminal test and Markdown job logs. The original failure and unavailable responses are retained. Cause, complete logs and warning classification remain unresolved; no restart or passing-regression claim is made.[FEATURE] [P02.R58] Audit authority, code quality and documentation in logdto [FEATURE] Audit authority, code quality and documentation in logd