WIP: Guard mediator construction and Launchd admission #2

Draft
erikinkinen wants to merge 19 commits from feature/posix-compat into main
Owner

Summary and rationale

Stage mediators without child root capabilities or an unused parent VSpace receipt, and authenticate Launchd ingress against the actual native caller before receipt validation or dispatch. Ordinary mediator start gates remain closed.

Tracking and scope

Tracks #1 and the coordinated realm design at erix/posixd#1. This review remains unfinished until its required runtime and dependent validation is complete.

Architecture, authority and failure behavior

Operation 54 omits initial child root capabilities while the native TCB retains backing. Procd retains the actual master and moves only the process-bound grant through staging. Caller authentication compares the kernel's actual pending caller with the retained running owner generation; a bearer sender or descriptive identity cannot substitute. Rejected transfers retain cleanup obligations. This grants no mediator start permission and does not attest a final seal.

Validation evidence

Original coherent realm source CI acceptance — 18 September 2026: Signed ea41ec37d36058f0027507ed1ecdb34d773b2aaf passes CI 291 and CI 290. All four terminal logs are complete (343,244 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.

Coherent realm image service prerequisites — 18 September 2026: Signed ea41ec37d36058f0027507ed1ecdb34d773b2aaf selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 14 default, all-feature and separate production development/release configurations pass 286/288/291 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.

Original supervisor service checkpoint — 18 September 2026: Signed 3210f44b4fee05a7dd4f0ff25c2664629cc76aa2 is pushed. Authenticate the actual private Loaderd caller and original Running Launchd before creation; retain supervision through preparation, grant handoff and owned bootstrap. Match the original owner before adopting stage rollback. Loaderd rollback ends at guard admission. Supervisor retirement exhausts active preparation and independent committed stages even after a cleanup refusal, preserving exact obligations and first errors. Eight new controls preserve earlier coverage. Four strict default/all matrices pass with 281/286 main units and five probe tests; ten production matrices also pass, for fifty native builds in total. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original CI 288 and CI 289 passes with all four terminal logs (343,310 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open.

Owned bootstrap receiver checkpoint — 18 September 2026: Signed 1e8713ae4c49ab9a3bc927031936585d4a1f76fd connects the Procd service loop to native owned bootstrap intake on the existing private receiver. It admits 16 request bytes and one actual grant, selects and proves empty exclusive ingress, authenticates claimed Launchd origin and validates native child scope before local relocation into the existing row. The obsolete legacy bootstrap handler is removed. Retained delivery and exact-stage custody survive draining; application cleanup precedes native relinquishment, and uncertain cleanup prevents ordinary intake. Ready owned and ordinary admission alternate with native deferred destruction first. Twelve owned-driver and two scheduling controls cover custody, negative cases and retirement. Four strict configurations pass: 273/278 main units, five probe tests, forty warning-free native builds, formatting, Clippy and private-item rustdoc. Original CI 286 and CI 287 pass from all four complete terminal logs (340,704 bytes), without warnings. These host controls and builds do not establish actual consumer VM execution. Actual Launchd runtime orchestration, full provider/terminal fairness, configuration, readiness, seal and both complete guest builds remain open.

Deferred native cleanup checkpoint — 18 September 2026: Signed 507a98f53462b688d9008931aab09902713ed805 gives each deferred native cleanup owner an independent turn before request intake. Unacknowledged owners rotate with their exact generation and first error retained. Five new controls and four strict matrices pass: 263/268 main units, five probe controls, forty native builds, formatting, strict Clippy and private-item rustdoc. The original Integration layout reader accepts both compiler-produced record layouts; checked page-rounded arenas remain unchanged. Original CI 284 and CI 285 pass from all four complete logs (337,764 bytes), without warnings. Bug 3 records the bounded scheduling correction. Legacy terminal/provider progress, actual consumer VM execution, complete realm fairness and both full guest builds remain open.

Returned-grant consumer checkpoint — 18 September 2026: Signed revision 4e233515341067f6b6d3503db0acb61da6d54422 is pushed. Actual native caller/grant admission precedes reservation of all five existing scratch columns. Matching-grant attenuation, ancestor lifetime deposit and a private nested sender/revoker remove original masters and bypass sources. Partial failure, failed acknowledgment delivery, exact supervisor loss and terminal retirement exhaust role-owned cleanup and preserve the first uncertainty, preventing ordinary continuation and row reuse. Eleven added controls pass with 258/263 main-binary units, five probe tests and forty native builds. Ordinary mediator execution remains denied. Formatting and Markdown checks pass. Original CI 282 and CI 283 passes; all four terminal logs are complete (336,168 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision 92e19c3ec60ffd5cb3bc16cde3a2316cd3bb1556 is pushed. Staged rollback and deferred destruction retain the original generation. Pre-service terminal events own exact native cleanup without managed successor or provider effects; intake checks cleanup capacity before dequeue. Complete native framing and correlation precede result interpretation. Nine added controls pass with 247/252 main-binary units, five probe tests and forty native builds across the strict default/all-feature development/release matrix. Native transport and cleanup custody are separate cohesive modules. Ordinary service-image execution remains required. Formatting and Markdown checks pass. Original CI 280 and CI 281 passes; all four terminal logs are complete (332,946 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.

Coordinated terminal observation checkpoint — 17 September 2026: Signed revision 2983f807cf7517250239872046f24d75bb9900c6 is pushed. The generation-bound consumer passes its full strict host/native matrix and original CI 278/279, with all four terminal logs complete and no warnings. The isolated native producer checks also pass; ordinary service-image adoption is separate. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.

Native terminal generation implementation — 17 September 2026: Signed revision 2983f807cf7517250239872046f24d75bb9900c6 is pushed. Native retirement, signal and stop completion compare the exact original process/generation pair. Stale and already observed generations cannot initiate accounting or cleanup. Four new controls and the complete strict host/native matrix pass, including forty freestanding binary builds. Matching native execution and coordinated consumer rollout remain in progress; runnable realm bootstrap and complete guest builds are not established. Original automatic CI is monitored without retries.

Runtime consumer dependency alignment — 15 September 2026

Signed a6658875dc767210a489389a1b2b8bbfb21a42e1 aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 239 default / 244 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: procd-runtime: 239 development / 239 release tests, procd-runtime-release-image: 239 development / 239 release tests, procd-runtime-logging: 239 development / 239 release tests, procd-runtime-crash-reporting: 241 development / 241 release tests, procd-runtime-interrupt: 241 development / 241 release tests. There are 50 supported native builds in total. Push/review CI 276/277 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.

Signed Procd c583614aa48f3e11a3ccabfeee06340f518de750 now checks the actual pending native caller on Launchd ingress against its retained running Launchd process and stage generation before operation-specific receipt validation or dispatch. Forwarded SEND aliases, request-body identities, other lifecycle roles, reused generations and unavailable identity cannot acquire this dispatch permission. Other receivers retain their policy; rejected delivered transfers still undergo local disposal, and uncertain disposal stops ordinary continuation.

Five new producer controls exercise accepted event dispatch and refusals without consuming the private event. The complete strict host/native development/release matrix passes: 239 default-feature tests, 244 all-feature tests, Clippy, rustdoc, formatting and forty native binary builds, with no warnings. The changed runtime-loop fragment is formatted by the repository formatter; its other code matches the formatted original outside the reviewed admission replacement.

Signed documentation 45d4d04c534f2ebca857ee203265232fd7c32bbe passes 45 tests and a frozen 2,375-page manual with 433,469 in-bounds word boxes and no final warnings. Page 212 was visually reviewed. The receiver inventory also corrects the existing powerbox omission and obsolete loader operation count. Shared API snapshots are unchanged.

Procd CI 274/275 and Docs CI 879/880 pass with complete classified logs and no final warnings. Both component cohorts are complete. Product runtime-image validation still requires a coherent original-commit dependency graph; this checkpoint does not claim a new Procd VM. Actual returned-grant custody, guarded bootstrap, readiness/configuration/seal, mediated client byte I/O, fair retirement and both complete guest build generations remain open.

Review checklist

  • Existing canonical documentation formats and applicable authority contracts preserved.
  • Changed source passes formatting, strict applicable checks and its complete local tests.
  • Native Procd binaries build with fatal warnings; new admission controls pass.
  • Complete manual rendered, all-page bounds checked and changed page visually reviewed.
  • Original commit selections and signed feature checkpoints retained.
  • Complete current component CI with classified logs and no final warnings.
  • Complete coherent runtime-image adoption and appropriate Procd VM acceptance.
  • Complete typed grant return, guarded bootstrap, real client execution and cleanup.
  • Demonstrate both complete EriX guest build generations.

Native guarded preparation — 19 September 2026: signed Integration 78557a6c672ecf426dfe894a01cc4aeec73b5e3c selects signed Exsh ffe50612889dd58a45a40d04593a4aa3a3ffa512 for the separate appliance-disk-image-realm-preparation-positive scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects bin/true inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.

Exactly one admission marker and one ERIX_EXSH:REALM_PREPARATION:VERIFIED precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is 7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff (55,776 bytes); post-VM writable disk SHA256 is 3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.

All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.

Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.

Minimum bootstrap design — 19 September 2026: signed Posixd proposal, in PR 5, specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate.

Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution.

The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original Posixd CI 19 and 20 pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added.

Native child-lifetime prerequisite — 19 September 2026: Kernel design #19 now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration a62d1381f56a01afc692112d9b427205eaeb6a2e. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor.

Verified grant-rights checkpoint — 20 September 2026:

Signed commit 1c80383afe1460f8d250472284225670f893937c requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 289/294-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 292/293 passes from four complete hashed logs (344,064 bytes), with zero warning candidates. Procd requests MINT only on actual derivation paths. It derives the final GRANT-only receipt into the disposed VSpace receipt slot and drops its delegating source before handoff. Derivation or disposal failure retains original-generation rollback and all remaining local custody.

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.

Installer return-slot regression — 21 September 2026:

Both original corrected-catalog runs are now classified: 1695 passes 431/489 VM scenarios and 1696 passes 430/489. All six complete logs are retained and hashed, 32,723,390 bytes, zero warning candidates. Rust, Markdown and full dependency equality pass. Catalog mismatch issue 68 is corrected; this does not establish full consumer acceptance. Each run has 57 initial-shell uncertain-disposition failures and a separately retained release-appliance stall. Run 1696 also retains the ext4 quota timeout under its original 120-second bound, tracked in issue 20.

Procd bug 4 records a concrete producer/consumer mismatch. The final installer was handed off from VSpace scratch slot 1056 while later TTY provisioning requires managed grant slot 1040. The added producer regression fails on the original code. Signed Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce in WIP PR 2 derives the exact GRANT-only result, disposes its delegating source and uniquely relocates the result back to the empty managed grant slot. Refusals preserve original-stage rollback and remaining custody. Four strict 291/296-unit configurations, four native builds, host/native Clippy, formatting, private rustdoc and policies pass with zero warnings. Corrected full-service VM validation and original CI remain open; bug 4 remains open.

Acceptance remains 15/460 leaves, 3.48% weighted. Full consumer lifecycle, terminal accounting, source/effect/frame proof, Pagerd, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full in-EriX build generations remain required.

Verified managed installer recovery — 21 September 2026:

Signed Integration 648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d in WIP PR 12 selects signed Procd ac8a12993bc8cbf134a11e141e459cb63df71123 and Docs PR 4. Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed.

Procd bug 4 is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings.

The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes.

The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged.

Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open.

Verified native terminal accounting — 21 September 2026: Kernel a9bdf6163813d378e0b4a164bceb839e24fbb6b7 is signed/pushed. Terminal preflight reserves final scalar CPU evidence independently of TCB/CSpace/VSpace reclamation; exact queries preserve final results or explicit errors. Repeat observations belong to the actual original observer until exact acknowledgement, and observer death releases that claim. Independent authorized observers can progress. Selector 55 is retired; checked selectors 59/60 have no destructive fallback.

Four strict 736/760-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings. Host controls include nonzero final counters after actual reclamation and ID reuse, original observer death, pending-final-charge destruction refusal, malformed requests, wrong callers, immutable errors and lost-acknowledgement reply retry. Original Kernel CI 624/625 and corrected 626/627 all pass from eight complete hashed logs (1,532,848 bytes), zero warnings.

Both maintained lifetime and owned-invocation VMs pass under the unchanged 60-second scenario limits and standard watchdogs, with no build warnings and empty QEMU stderr. Actual guest instructions check repeat observations and CPU queries, exact acknowledgement and absent-acknowledgement retry; executing children require nonzero user and kernel counters after native reclamation. Lifetime retains 2,025 serial bytes (SHA256 921edf5eadfdff61f2d85a63158555666e77e57a1e8aa4254ac30dcd216f8cf9); owned invocation retains 1,587 (SHA256 404bc4ecad5074349d9ba45d1caf5439aebe849d344b726e5dec2ee2b9c4d907). Normal stripping exactly matches both packaged kernels to retained original artifacts; all fifteen selected original signatures and clean checkouts verify.

Kernel regression 21 retains the first VM's final page-census failure. The corrected layout declares and allocates all six request pages and derives the independent census from that declaration. No unchanged retry or deadline relaxation occurred.

Integration fcd7b4a9608f629a12de78c53da5c3615d906b46 is signed/pushed with the verified isolated catalog. Twenty dependency and 46 immutable-source tests, native policies, Markdown and source checks pass. The unchanged orchestration crate, embedded fixture and original dependency closure retain verified four 320/321-unit and native/Clippy/rustdoc configurations. The full service catalogs retain their separately coordinated revisions; original Integration CI remains under observation.

Procd and Rootd consumer adoption, ordinary and mediator metric retention/consumer loss, manual updates, full service/profiler scenarios, complete authority/source/frame audits and full regression acceptance remain open under Kernel design 20. Canonical acceptance remains 3.48% weighted; 15 of 460 items. Native upstream Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory and unproven.

Committed terminal-accounting consumers — 21 September 2026:

Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.

Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.

Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.

The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.

No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.

Terminal selector documentation reconciliation — 21 September 2026:

Signed Procd 68748bc65ea3fb798e810d624845dcb298ae1346 removes stale operation 55 prose and documents observation 59 plus exact acknowledgement 60. All runtime inputs are byte-identical to the validated consumer implementation; its four strict 299/305-test configurations remain applicable. Original documentation-checkpoint CI 300/301 passes from four complete hashed logs (347,266 bytes, zero warnings).

Ordinary consumer loss/restart and final reply disposition remain audited acceptance gaps. Failed ordinary metrics transport currently terminates Procd; it is not evidence of continued execution and row reuse. Full service CPU/profiler VM acceptance, complete realm lifecycle and both guest build generations remain open.

Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.

Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.

Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.

## Summary and rationale Stage mediators without child root capabilities or an unused parent VSpace receipt, and authenticate Launchd ingress against the actual native caller before receipt validation or dispatch. Ordinary mediator start gates remain closed. ## Tracking and scope Tracks https://git.erikinkinen.fi/erix/procd/issues/1 and the coordinated realm design at https://git.erikinkinen.fi/erix/posixd/issues/1. This review remains unfinished until its required runtime and dependent validation is complete. ## Architecture, authority and failure behavior Operation 54 omits initial child root capabilities while the native TCB retains backing. Procd retains the actual master and moves only the process-bound grant through staging. Caller authentication compares the kernel's actual pending caller with the retained running owner generation; a bearer sender or descriptive identity cannot substitute. Rejected transfers retain cleanup obligations. This grants no mediator start permission and does not attest a final seal. ## Validation evidence Original coherent realm source CI acceptance — 18 September 2026: Signed `ea41ec37d36058f0027507ed1ecdb34d773b2aaf` passes [CI 291](https://git.erikinkinen.fi/erix/procd/actions/runs/291) and [CI 290](https://git.erikinkinen.fi/erix/procd/actions/runs/290). All four terminal logs are complete (343,244 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements. Coherent realm image service prerequisites — 18 September 2026: Signed `ea41ec37d36058f0027507ed1ecdb34d773b2aaf` selects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 14 default, all-feature and separate production development/release configurations pass 286/288/291 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open. Original supervisor service checkpoint — 18 September 2026: Signed `3210f44b4fee05a7dd4f0ff25c2664629cc76aa2` is pushed. Authenticate the actual private Loaderd caller and original Running Launchd before creation; retain supervision through preparation, grant handoff and owned bootstrap. Match the original owner before adopting stage rollback. Loaderd rollback ends at guard admission. Supervisor retirement exhausts active preparation and independent committed stages even after a cleanup refusal, preserving exact obligations and first errors. Eight new controls preserve earlier coverage. Four strict default/all matrices pass with 281/286 main units and five probe tests; ten production matrices also pass, for fifty native builds in total. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original [CI 288](https://git.erikinkinen.fi/erix/procd/actions/runs/288) and [CI 289](https://git.erikinkinen.fi/erix/procd/actions/runs/289) passes with all four terminal logs (343,310 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open. Owned bootstrap receiver checkpoint — 18 September 2026: Signed `1e8713ae4c49ab9a3bc927031936585d4a1f76fd` connects the Procd service loop to native owned bootstrap intake on the existing private receiver. It admits 16 request bytes and one actual grant, selects and proves empty exclusive ingress, authenticates claimed Launchd origin and validates native child scope before local relocation into the existing row. The obsolete legacy bootstrap handler is removed. Retained delivery and exact-stage custody survive draining; application cleanup precedes native relinquishment, and uncertain cleanup prevents ordinary intake. Ready owned and ordinary admission alternate with native deferred destruction first. Twelve owned-driver and two scheduling controls cover custody, negative cases and retirement. Four strict configurations pass: 273/278 main units, five probe tests, forty warning-free native builds, formatting, Clippy and private-item rustdoc. Original [CI 286](https://git.erikinkinen.fi/erix/procd/actions/runs/286) and [CI 287](https://git.erikinkinen.fi/erix/procd/actions/runs/287) pass from all four complete terminal logs (340,704 bytes), without warnings. These host controls and builds do not establish actual consumer VM execution. Actual Launchd runtime orchestration, full provider/terminal fairness, configuration, readiness, seal and both complete guest builds remain open. Deferred native cleanup checkpoint — 18 September 2026: Signed `507a98f53462b688d9008931aab09902713ed805` gives each deferred native cleanup owner an independent turn before request intake. Unacknowledged owners rotate with their exact generation and first error retained. Five new controls and four strict matrices pass: 263/268 main units, five probe controls, forty native builds, formatting, strict Clippy and private-item rustdoc. The original Integration layout reader accepts both compiler-produced record layouts; checked page-rounded arenas remain unchanged. Original [CI 284](https://git.erikinkinen.fi/erix/procd/actions/runs/284) and [CI 285](https://git.erikinkinen.fi/erix/procd/actions/runs/285) pass from all four complete logs (337,764 bytes), without warnings. [Bug 3](https://git.erikinkinen.fi/erix/procd/issues/3) records the bounded scheduling correction. Legacy terminal/provider progress, actual consumer VM execution, complete realm fairness and both full guest builds remain open. Returned-grant consumer checkpoint — 18 September 2026: Signed revision `4e233515341067f6b6d3503db0acb61da6d54422` is pushed. Actual native caller/grant admission precedes reservation of all five existing scratch columns. Matching-grant attenuation, ancestor lifetime deposit and a private nested sender/revoker remove original masters and bypass sources. Partial failure, failed acknowledgment delivery, exact supervisor loss and terminal retirement exhaust role-owned cleanup and preserve the first uncertainty, preventing ordinary continuation and row reuse. Eleven added controls pass with 258/263 main-binary units, five probe tests and forty native builds. Ordinary mediator execution remains denied. Formatting and Markdown checks pass. Original [CI 282](https://git.erikinkinen.fi/erix/procd/actions/runs/282) and [CI 283](https://git.erikinkinen.fi/erix/procd/actions/runs/283) passes; all four terminal logs are complete (336,168 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision `92e19c3ec60ffd5cb3bc16cde3a2316cd3bb1556` is pushed. Staged rollback and deferred destruction retain the original generation. Pre-service terminal events own exact native cleanup without managed successor or provider effects; intake checks cleanup capacity before dequeue. Complete native framing and correlation precede result interpretation. Nine added controls pass with 247/252 main-binary units, five probe tests and forty native builds across the strict default/all-feature development/release matrix. Native transport and cleanup custody are separate cohesive modules. Ordinary service-image execution remains required. Formatting and Markdown checks pass. Original [CI 280](https://git.erikinkinen.fi/erix/procd/actions/runs/280) and [CI 281](https://git.erikinkinen.fi/erix/procd/actions/runs/281) passes; all four terminal logs are complete (332,946 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements. Coordinated terminal observation checkpoint — 17 September 2026: Signed revision `2983f807cf7517250239872046f24d75bb9900c6` is pushed. The generation-bound consumer passes its full strict host/native matrix and original CI 278/279, with all four terminal logs complete and no warnings. The isolated native producer checks also pass; ordinary service-image adoption is separate. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open. Native terminal generation implementation — 17 September 2026: Signed revision `2983f807cf7517250239872046f24d75bb9900c6` is pushed. Native retirement, signal and stop completion compare the exact original process/generation pair. Stale and already observed generations cannot initiate accounting or cleanup. Four new controls and the complete strict host/native matrix pass, including forty freestanding binary builds. Matching native execution and coordinated consumer rollout remain in progress; runnable realm bootstrap and complete guest builds are not established. Original automatic CI is monitored without retries. ### Runtime consumer dependency alignment — 15 September 2026 Signed `a6658875dc767210a489389a1b2b8bbfb21a42e1` aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 239 default / 244 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds: `procd-runtime`: 239 development / 239 release tests, `procd-runtime-release-image`: 239 development / 239 release tests, `procd-runtime-logging`: 239 development / 239 release tests, `procd-runtime-crash-reporting`: 241 development / 241 release tests, `procd-runtime-interrupt`: 241 development / 241 release tests. There are 50 supported native builds in total. Push/review CI 276/277 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending. Signed Procd `c583614aa48f3e11a3ccabfeee06340f518de750` now checks the actual pending native caller on Launchd ingress against its retained running Launchd process and stage generation before operation-specific receipt validation or dispatch. Forwarded SEND aliases, request-body identities, other lifecycle roles, reused generations and unavailable identity cannot acquire this dispatch permission. Other receivers retain their policy; rejected delivered transfers still undergo local disposal, and uncertain disposal stops ordinary continuation. Five new producer controls exercise accepted event dispatch and refusals without consuming the private event. The complete strict host/native development/release matrix passes: 239 default-feature tests, 244 all-feature tests, Clippy, rustdoc, formatting and forty native binary builds, with no warnings. The changed runtime-loop fragment is formatted by the repository formatter; its other code matches the formatted original outside the reviewed admission replacement. Signed documentation `45d4d04c534f2ebca857ee203265232fd7c32bbe` passes 45 tests and a frozen 2,375-page manual with 433,469 in-bounds word boxes and no final warnings. Page 212 was visually reviewed. The receiver inventory also corrects the existing powerbox omission and obsolete loader operation count. Shared API snapshots are unchanged. Procd CI 274/275 and Docs CI 879/880 pass with complete classified logs and no final warnings. Both component cohorts are complete. Product runtime-image validation still requires a coherent original-commit dependency graph; this checkpoint does not claim a new Procd VM. Actual returned-grant custody, guarded bootstrap, readiness/configuration/seal, mediated client byte I/O, fair retirement and both complete guest build generations remain open. ## Review checklist - [x] Existing canonical documentation formats and applicable authority contracts preserved. - [x] Changed source passes formatting, strict applicable checks and its complete local tests. - [x] Native Procd binaries build with fatal warnings; new admission controls pass. - [x] Complete manual rendered, all-page bounds checked and changed page visually reviewed. - [x] Original commit selections and signed feature checkpoints retained. - [x] Complete current component CI with classified logs and no final warnings. - [ ] Complete coherent runtime-image adoption and appropriate Procd VM acceptance. - [ ] Complete typed grant return, guarded bootstrap, real client execution and cleanup. - [ ] Demonstrate both complete EriX guest build generations. Native guarded preparation — 19 September 2026: signed Integration `78557a6c672ecf426dfe894a01cc4aeec73b5e3c` selects signed Exsh `ffe50612889dd58a45a40d04593a4aa3a3ffa512` for the separate `appliance-disk-image-realm-preparation-positive` scenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selects `bin/true` inside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced. Exactly one admission marker and one `ERIX_EXSH:REALM_PREPARATION:VERIFIED` precede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is `7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff` (55,776 bytes); post-VM writable disk SHA256 is `3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499`. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena. All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required. Original [Integration CI 1677](https://git.erikinkinen.fi/erix/integration/actions/runs/1677) and [1678](https://git.erikinkinen.fi/erix/integration/actions/runs/1678) are queued. Original [Exsh CI 271](https://git.erikinkinen.fi/erix/exsh/actions/runs/271) and [272](https://git.erikinkinen.fi/erix/exsh/actions/runs/272) are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item. Minimum bootstrap design — 19 September 2026: signed [Posixd proposal](https://git.erikinkinen.fi/erix/posixd/src/commit/3e6292bd3e5c6a3e59dbae54124f8eea52141957/docs/minimum-bootstrap.md), in [PR 5](https://git.erikinkinen.fi/erix/posixd/pulls/5), specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate. Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution. The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original [Posixd CI 19](https://git.erikinkinen.fi/erix/posixd/actions/runs/19) and [20](https://git.erikinkinen.fi/erix/posixd/actions/runs/20) pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added. Native child-lifetime prerequisite — 19 September 2026: [Kernel design #19](https://git.erikinkinen.fi/erix/kernel/issues/19) now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration `a62d1381f56a01afc692112d9b427205eaeb6a2e`. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor. Verified grant-rights checkpoint — 20 September 2026: Signed commit [1c80383afe1460f8d250472284225670f893937c](https://git.erikinkinen.fi/erix/procd/commit/1c80383afe1460f8d250472284225670f893937c) requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 289/294-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 292/293 passes from four complete hashed logs (344,064 bytes), with zero warning candidates. Procd requests MINT only on actual derivation paths. It derives the final GRANT-only receipt into the disposed VSpace receipt slot and drops its delegating source before handoff. Derivation or disposal failure retains original-generation rollback and all remaining local custody. Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. Full coordinated consumer acceptance remains open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19) and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Installer return-slot regression — 21 September 2026: Both original corrected-catalog runs are now classified: [1695](https://git.erikinkinen.fi/erix/integration/actions/runs/1695) passes 431/489 VM scenarios and [1696](https://git.erikinkinen.fi/erix/integration/actions/runs/1696) passes 430/489. All six complete logs are retained and hashed, 32,723,390 bytes, zero warning candidates. Rust, Markdown and full dependency equality pass. Catalog mismatch [issue 68](https://git.erikinkinen.fi/erix/integration/issues/68) is corrected; this does not establish full consumer acceptance. Each run has 57 initial-shell uncertain-disposition failures and a separately retained release-appliance stall. Run 1696 also retains the ext4 quota timeout under its original 120-second bound, tracked in [issue 20](https://git.erikinkinen.fi/erix/integration/issues/20). [Procd bug 4](https://git.erikinkinen.fi/erix/procd/issues/4) records a concrete producer/consumer mismatch. The final installer was handed off from VSpace scratch slot 1056 while later TTY provisioning requires managed grant slot 1040. The added producer regression fails on the original code. Signed Procd [10d972b652297fd656e9a6ac6dbdf197f362c7ce](https://git.erikinkinen.fi/erix/procd/commit/10d972b652297fd656e9a6ac6dbdf197f362c7ce) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) derives the exact GRANT-only result, disposes its delegating source and uniquely relocates the result back to the empty managed grant slot. Refusals preserve original-stage rollback and remaining custody. Four strict 291/296-unit configurations, four native builds, host/native Clippy, formatting, private rustdoc and policies pass with zero warnings. Corrected full-service VM validation and original CI remain open; bug 4 remains open. Acceptance remains 15/460 leaves, 3.48% weighted. Full consumer lifecycle, terminal accounting, source/effect/frame proof, Pagerd, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full in-EriX build generations remain required. Verified managed installer recovery — 21 September 2026: Signed Integration [648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d](https://git.erikinkinen.fi/erix/integration/commit/648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d) in [WIP PR 12](https://git.erikinkinen.fi/erix/integration/pulls/12) selects signed Procd [ac8a12993bc8cbf134a11e141e459cb63df71123](https://git.erikinkinen.fi/erix/procd/commit/ac8a12993bc8cbf134a11e141e459cb63df71123) and [Docs PR 4](https://git.erikinkinen.fi/erix/docs/pulls/4). Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed. [Procd bug 4](https://git.erikinkinen.fi/erix/procd/issues/4) is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings. The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes. The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged. Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open. Verified native terminal accounting — 21 September 2026: Kernel [a9bdf6163813d378e0b4a164bceb839e24fbb6b7](https://git.erikinkinen.fi/erix/kernel/commit/a9bdf6163813d378e0b4a164bceb839e24fbb6b7) is signed/pushed. Terminal preflight reserves final scalar CPU evidence independently of TCB/CSpace/VSpace reclamation; exact queries preserve final results or explicit errors. Repeat observations belong to the actual original observer until exact acknowledgement, and observer death releases that claim. Independent authorized observers can progress. Selector 55 is retired; checked selectors 59/60 have no destructive fallback. Four strict 736/760-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings. Host controls include nonzero final counters after actual reclamation and ID reuse, original observer death, pending-final-charge destruction refusal, malformed requests, wrong callers, immutable errors and lost-acknowledgement reply retry. Original Kernel CI 624/625 and corrected 626/627 all pass from eight complete hashed logs (1,532,848 bytes), zero warnings. Both maintained lifetime and owned-invocation VMs pass under the unchanged 60-second scenario limits and standard watchdogs, with no build warnings and empty QEMU stderr. Actual guest instructions check repeat observations and CPU queries, exact acknowledgement and absent-acknowledgement retry; executing children require nonzero user and kernel counters after native reclamation. Lifetime retains 2,025 serial bytes (SHA256 `921edf5eadfdff61f2d85a63158555666e77e57a1e8aa4254ac30dcd216f8cf9`); owned invocation retains 1,587 (SHA256 `404bc4ecad5074349d9ba45d1caf5439aebe849d344b726e5dec2ee2b9c4d907`). Normal stripping exactly matches both packaged kernels to retained original artifacts; all fifteen selected original signatures and clean checkouts verify. [Kernel regression 21](https://git.erikinkinen.fi/erix/kernel/issues/21) retains the first VM's final page-census failure. The corrected layout declares and allocates all six request pages and derives the independent census from that declaration. No unchanged retry or deadline relaxation occurred. Integration [fcd7b4a9608f629a12de78c53da5c3615d906b46](https://git.erikinkinen.fi/erix/integration/commit/fcd7b4a9608f629a12de78c53da5c3615d906b46) is signed/pushed with the verified isolated catalog. Twenty dependency and 46 immutable-source tests, native policies, Markdown and source checks pass. The unchanged orchestration crate, embedded fixture and original dependency closure retain verified four 320/321-unit and native/Clippy/rustdoc configurations. The full service catalogs retain their separately coordinated revisions; original Integration CI remains under observation. Procd and Rootd consumer adoption, ordinary and mediator metric retention/consumer loss, manual updates, full service/profiler scenarios, complete authority/source/frame audits and full regression acceptance remain open under [Kernel design 20](https://git.erikinkinen.fi/erix/kernel/issues/20). Canonical acceptance remains **3.48% weighted; 15 of 460 items**. Native upstream Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory and unproven. Committed terminal-accounting consumers — 21 September 2026: Procd [66934642c4464fc738152a9e60790914ba27dd1c](https://git.erikinkinen.fi/erix/procd/commit/66934642c4464fc738152a9e60790914ba27dd1c) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI [298](https://git.erikinkinen.fi/erix/procd/actions/runs/298)/[299](https://git.erikinkinen.fi/erix/procd/actions/runs/299) passes from four complete hashed logs, 347,245 bytes, zero warnings. [Bug 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open for actual service acceptance. Rootd [64c97b13c450003d9c2b6bd9ed2a627088684b46](https://git.erikinkinen.fi/erix/rootd/commit/64c97b13c450003d9c2b6bd9ed2a627088684b46) in [WIP PR 2](https://git.erikinkinen.fi/erix/rootd/pulls/2) acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed [bug 7](https://git.erikinkinen.fi/erix/rootd/issues/7): a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI [1041](https://git.erikinkinen.fi/erix/rootd/actions/runs/1041)/[1042](https://git.erikinkinen.fi/erix/rootd/actions/runs/1042) passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates. Docs [e4525848ad4462901c9a6794ef1794cf85ea9e6b](https://git.erikinkinen.fi/erix/docs/commit/e4525848ad4462901c9a6794ef1794cf85ea9e6b) updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI [995](https://git.erikinkinen.fi/erix/docs/actions/runs/995)/[996](https://git.erikinkinen.fi/erix/docs/actions/runs/996) and corrected-table [997](https://git.erikinkinen.fi/erix/docs/actions/runs/997)/[998](https://git.erikinkinen.fi/erix/docs/actions/runs/998) passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved. The separate Integration orchestration library checkpoint [b06dfad00202765491a64552dde29eaca1c24838](https://git.erikinkinen.fi/erix/integration/commit/b06dfad00202765491a64552dde29eaca1c24838) passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance. No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure. Terminal selector documentation reconciliation — 21 September 2026: Signed Procd [68748bc65ea3fb798e810d624845dcb298ae1346](https://git.erikinkinen.fi/erix/procd/commit/68748bc65ea3fb798e810d624845dcb298ae1346) removes stale operation 55 prose and documents observation 59 plus exact acknowledgement 60. All runtime inputs are byte-identical to the validated consumer implementation; its four strict 299/305-test configurations remain applicable. Original documentation-checkpoint CI [300](https://git.erikinkinen.fi/erix/procd/actions/runs/300)/[301](https://git.erikinkinen.fi/erix/procd/actions/runs/301) passes from four complete hashed logs (347,266 bytes, zero warnings). Ordinary consumer loss/restart and final reply disposition remain audited acceptance gaps. Failed ordinary metrics transport currently terminates Procd; it is not evidence of continued execution and row reuse. Full service CPU/profiler VM acceptance, complete realm lifecycle and both guest build generations remain open. Coherent scalar-consumer validation — 21 September 2026: signed [Integration 07c883525ee5](https://git.erikinkinen.fi/erix/integration/commit/07c883525ee5e23378008232760d045f74f60d32) selects [Procd 59ee30a88534](https://git.erikinkinen.fi/erix/procd/commit/59ee30a885346db4db8c8791a23c15694f2a90a8) in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven. Procd's four strict 308/314-test configurations and original CI 302/303 pass. The [manual update](https://git.erikinkinen.fi/erix/docs/commit/2d05169e6974a495eab80b62edf0f23d1ad667da) passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines. Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.
fix: Bind launch description installation to the staged child
All checks were successful
CI / markdown (push) Successful in 3s
CI / test (push) Successful in 26s
CI / markdown (pull_request) Successful in 3s
CI / test (pull_request) Successful in 26s
f1105706cc
Pass the validated process and generation to the native install-grant
operation with exact SEND rights. Retain the pending stream and original
staging and child rollback obligations on native denial or lost replies.
Document the adapter and state transitions, and test the complete native
request plus stale-identity refusal before installation.

Align original helper dependencies to one IPC type identity. Default/all
development/release tests, strict host and native Clippy, forty freestanding
binary builds with repository linker scripts, private rustdoc, formatting
and Markdown pass. Typed realm bootstrap and image adoption remain open.
feat: Retain private custody for staged realm mediators
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / test (push) Successful in 1m12s
CI / test (pull_request) Successful in 1m11s
cdb0fe4d14
Materialize the separate mediator lifecycle class with a private parent
endpoint master and grant-only handoff. Keep ordinary start, immediate commit,
TTY provisioning, powerbox installation and automatic restart closed to this
class. Preserve exact-generation abort and lost-reply cleanup ownership.

Split lifecycle policy tests and the TTY transaction and test-support modules
into cohesive files below one thousand lines. Six new regressions cover
custody, bypass attempts and cleanup. Full strict host/native matrices and
forty freestanding binary builds pass; runnable realm acceptance remains open.
erikinkinen changed title from WIP: Bind launch description installation to the actual staged child to WIP: Own staged mediator authority and restrict child installation 2026-09-15 10:56:22 +02:00
build: Align corrected native bootstrap dependencies
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 10s
CI / test (pull_request) Successful in 1m10s
CI / test (push) Successful in 1m13s
e48a0e9992
Pin the original signed shared IPC and capability contracts used by the
coordinated staged-mediator producers after the native bootstrap slot correction. Preserve helper behavior and authority
ceilings while keeping the complete transitive graph coherent.

Default/all development and release tests, strict host/native Clippy,
freestanding builds, private rustdoc, formatting and Markdown checks pass.
feat: Omit root capabilities when staging realm mediators
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 10s
CI / test (pull_request) Successful in 1m5s
CI / test (push) Successful in 1m6s
3d9fe97bb6
Select checked native operation 54 only for the mediator lifecycle class and
omit the unused parent VSpace receipt and its successful drop. Preserve ordinary
construction, private endpoint-master custody, grant-only handoff, scratch
cleanup and all ordinary mediator start gates. Never fall back after refusal.

Extract creation and the test transport into documented fragments below the
code-file limit. Verify exact producer requests, omitted receipt/drop, actual
materialization requests, ordinary behavior and refusal without fallback.

Pass strict default/all development/release tests, host/native Clippy, all ten
freestanding binaries in each configuration, rustdoc and formatting. Native
object proof remains in the separately accepted Kernel fixture; complete
producer/runtime bootstrap and both full guest builds remain open.
erikinkinen changed title from WIP: Own staged mediator authority and restrict child installation to WIP: Stage mediators without child root capabilities 2026-09-15 14:20:43 +02:00
feat: Authenticate Launchd calls before runtime dispatch
All checks were successful
CI / markdown (push) Successful in 10s
CI / markdown (pull_request) Successful in 10s
CI / test (push) Successful in 56s
CI / test (pull_request) Successful in 56s
c583614aa4
Require the kernel-attested pending caller to match the retained running
Launchd process and stage generation before operation-specific receipt
validation or handlers. Preserve rejected-transfer disposal, native query
errors and other receiver policies without opening mediator start gates.

Five admission controls and the complete strict host/native matrix pass,
including forty native binary builds. Coherent runtime-image adoption and
the typed grant-return bootstrap remain required.
erikinkinen changed title from WIP: Stage mediators without child root capabilities to WIP: Guard mediator construction and Launchd admission 2026-09-15 14:56:41 +02:00
build: Align dependencies for coherent runtime adoption
All checks were successful
CI / markdown (push) Successful in 19s
CI / markdown (pull_request) Successful in 17s
CI / test (pull_request) Successful in 1m24s
CI / test (push) Successful in 1m27s
a6658875dc
Select the current original signed foundation commits in the existing Git
dependencies. Keep Rust implementation files unchanged and record the
separate product-image acceptance requirement in the roadmap.

The complete supported feature/profile matrix passes with formatting,
strict Clippy, unit tests, builds and private rustdoc. Product runtime
adoption remains pending the complete dependency graph.
fix: Match native terminal generations before process retirement
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 13s
CI / test (push) Successful in 1m14s
CI / test (pull_request) Successful in 1m13s
2983f807cf
Consume the checked generation-bearing native event and compare the original
process and generation before accounting, provider cleanup and publication.
Ignore stale or repeated observations; fail closed when no retained process
owner accounts for the event. Signal and stop completion use the same pair.
Remove the obsolete generation-free native reader without a fallback.

Four new retirement and malformed-response controls pass. The complete
host/native default and all-feature development/release matrix passes,
including strict Clippy, forty freestanding binary builds, rustdoc and format
and Markdown checks. Coordinated Kernel/Rootd VM adoption remains required.
fix: Retain exact native identity through process cleanup
All checks were successful
CI / markdown (pull_request) Successful in 13s
CI / markdown (push) Successful in 16s
CI / test (pull_request) Successful in 1m14s
CI / test (push) Successful in 1m14s
92e19c3ec6
Carry creation generations through staged rollback and retain process/generation
pairs in deployment-sized deferred destruction storage. Account for native
pre-service terminal events without applying managed successor or provider effects.
Reserve cleanup capacity before event intake and retire obligations only after
a complete correlated native success or exact-instance absence acknowledgement.

Extract native transport and cleanup custody into cohesive modules. Nine added
controls and migrated consumer fixtures pass the full default/all-feature
development/release matrix, strict host/native Clippy, forty freestanding builds,
rustdoc and formatting with warnings denied. Native Kernel VM checks pass
separately; ordinary service-image and runnable realm acceptance remain open.
feat: Retain guarded custody of returned mediator grants
All checks were successful
CI / markdown (pull_request) Successful in 11s
CI / markdown (push) Successful in 11s
CI / test (pull_request) Successful in 1m5s
CI / test (push) Successful in 1m6s
4e23351534
Authenticate the exact pending Launchd generation and sole live install grant
before reserving all five managed scratch columns. Narrow the Created receiver,
deposit an ancestor revoker into native lifetime custody, derive a private nested
branch and remove original masters and bypass senders before acknowledgment.

Retire all role-owned columns and the exact child on partial failure, lost reply,
abort or native terminal observation. Preserve the first uncertain result and
stop ordinary intake and row reuse. Keep guard retirement separate from ordinary
TTY and working-directory cleanup; ordinary mediator execution stays denied.

Eleven new controls pass with 258/263 units, five probe tests and forty native
builds across the full strict host/native matrix. Matching consumer VM execution,
Launchd producer adoption, fair owned progress and runnable bootstrap remain open.
fix: Give deferred native cleanup a turn before request intake
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 12s
CI / test (pull_request) Successful in 1m14s
CI / test (push) Successful in 1m13s
507a98f534
Attempt one exact-generation destruction per intake turn, retaining the first
unacknowledged failure and rotating its owner behind independent peers. Keep
the deployment-sized queue reserved across effects and remove an owner only
after a complete correlated native acknowledgment. Preserve legacy receive
semantics and distinguish native call-count bounds from full provider fairness.

Five new controls and four strict host/native matrices pass: 263/268 main units,
five probe controls, forty native builds, formatting, Clippy and rustdoc.
Actual consumer VM, terminal/provider progress and realm acceptance remain open.
feat: Drive owned realm bootstrap custody in Procd
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 9s
CI / test (pull_request) Successful in 50s
CI / test (push) Successful in 50s
1e8713ae4c
Register the existing private receiver with an exact request budget, authenticate
native claimed origin and validate actual grant scope before moving it into the
retained stage. Remove legacy bootstrap dispatch. Retain delivery and exact child
rollback through cancellation and draining; cleanup precedes native acknowledgment.
Alternate ready owned and ordinary intake with deferred native destruction first.

Four strict host/native configurations pass: 273/278 main units, five probe
controls and forty native builds, plus rustdoc, formatting and Markdown. Preserve
initial test-oracle and documentation failures. Launchd runtime orchestration,
consumer VM execution and full realm/guest-build acceptance remain open.
feat: Retain original realm ownership before materialization
All checks were successful
CI / markdown (push) Successful in 12s
CI / markdown (pull_request) Successful in 12s
CI / test (pull_request) Successful in 1m25s
CI / test (push) Successful in 1m25s
3210f44b4f
Authenticate native Loaderd origin and the original Running Launchd before
creation. Retain supervision through materialization, grant handoff and
owned bootstrap admission. Limit Loaderd rollback to pre-guard stages.
Exhaust independent preparation and committed-stage cleanup after failures;
preserve exact owners and first errors instead of resuming uncertain work.

Eight new controls preserve earlier coverage. Four strict default/all
matrices and ten production matrices pass: 281/286 main units, five probe
controls and fifty native builds. Formatting, rustdoc and Markdown pass.
Actual Launchd orchestration, consumer VM and full realm acceptance remain open.
build: Adopt coherent realm contract dependencies
All checks were successful
CI / markdown (push) Successful in 17s
CI / markdown (pull_request) Successful in 19s
CI / test (push) Successful in 1m35s
CI / test (pull_request) Successful in 1m36s
ea41ec37d3
Select original signed shared revisions so coordinated runtime images can
resolve one source identity for every dependency. Preserve the component
implementation and update the roadmap to keep consumer VM acceptance explicit.

Validate default and all-feature development/release tests, strict host/native
Clippy, freestanding builds, formatting and private-item rustdoc with warnings
denied. Full image and in-guest build acceptance remain separate requirements.
fix: Minimize staged installer authority
All checks were successful
CI / markdown (pull_request) Successful in 8s
CI / markdown (push) Successful in 8s
CI / test (push) Successful in 1m11s
CI / test (pull_request) Successful in 1m11s
1c80383afe
Request delegation only on actual derivation paths. Derive final GRANT-only
installers into the disposed VSpace receipt slot and drop the delegating source
before handoff. Preserve original-generation rollback after partial failure.

Four strict 289/294-test configurations, four native builds with maintained
linker layouts, host/native Clippy, private rustdoc and policy checks pass
without warnings. Coherent guest acceptance remains a separate requirement.
fix: Preserve the managed installer return slot
All checks were successful
CI / markdown (pull_request) Successful in 2s
CI / markdown (push) Successful in 2s
CI / test (pull_request) Successful in 26s
CI / test (push) Successful in 27s
10d972b652
Derive the GRANT-only handoff into the disposed VSpace slot, drop the
delegating source, then uniquely relocate the result into the empty managed
grant slot. Loaderd forwards that source as the destination required by
Procd's later TTY receipt checks. Preserve strict rights, original child
rollback and all remaining custody when any step fails.

Retain the producer regression that returned slot 1056 instead of 1040 and
cover relocation refusal and occupied destinations. Four strict unit/native
configurations and private rustdoc pass without warnings. Matching full
service VM and original CI remain required. Refs #4.
docs: Record verified installer return-slot recovery
All checks were successful
CI / markdown (push) Successful in 3s
CI / markdown (pull_request) Successful in 3s
CI / test (push) Successful in 27s
CI / test (pull_request) Successful in 27s
ac8a12993b
Record the strict unit/native matrix, both original CI passes and first-attempt
initial-shell and realm-admission VM passes for the installer slot correction.
Keep the complete regression suite and broader lifecycle acceptance separate.
Only roadmap evidence changes; the validated runtime source is unchanged.
fix: Commit terminal accounting before native acknowledgement
All checks were successful
CI / markdown (pull_request) Successful in 7s
CI / markdown (push) Successful in 8s
CI / test (pull_request) Successful in 1m0s
CI / test (push) Successful in 1m0s
66934642c4
Reserve publication storage before terminal cleanup, retain exact final CPU
evidence after mediator capability disposal, and acknowledge the native event
only after the local result and cleanup obligations are committed. Bind realm
metric delivery to the original supervisor and preserve state on lost replies.

Remove destructive event consumption and factor the observation and commit
responsibilities into documented modules. Four strict host configurations
pass 299/305 tests; native builds with the maintained linker layout, Clippy,
private rustdoc and policy checks pass without warnings. Full service VM and
CI acceptance remain open under Kernel #20 and Procd #5.
docs: Reconcile terminal observation and acknowledgement contracts
All checks were successful
CI / markdown (push) Successful in 13s
CI / markdown (pull_request) Successful in 16s
CI / test (pull_request) Successful in 1m44s
CI / test (push) Successful in 1m46s
68748bc65e
Replace the obsolete operation 55 contract with the implemented repeatable
observation and exact acknowledgement selectors. Remove duplicated superseded
roadmap prose and distinguish passing consumer Rust checks from pending
service VM and ordinary metrics lifetime acceptance.

Markdown and dependency policies pass. All runtime inputs are byte-identical
to the four validated strict consumer configurations and passing CI 298/299.
fix: Bind final CPU observations to their original consumer
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 11s
CI / test (push) Successful in 1m4s
CI / test (pull_request) Successful in 1m4s
59ee30a885
Record the authenticated Launchd generation after ordinary staged start and
require that same consumer for successor commit and live or terminal CPU
queries. Discharge scalar observation on exact consumer loss independently
of native resource destruction, visible events and realm capability custody.
Unsponsored immediate materialization does not infer a metrics consumer.

Add controls for both death orders, another live consumer, generation reuse,
duplicate observations, start refusal, successor refusal and immediate
construction. Preserve fail-stop reply delivery. Four strict configurations
pass 308/314 tests, host/native Clippy, native builds and private rustdoc
without warnings. Coherent catalog and service VM adoption remain pending.
All checks were successful
CI / markdown (push) Successful in 11s
CI / markdown (pull_request) Successful in 11s
CI / test (push) Successful in 1m4s
CI / test (pull_request) Successful in 1m4s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.