WIP: Guard mediator construction and Launchd admission #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/procd!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Stage mediators without child root capabilities or an unused parent VSpace receipt, and authenticate Launchd ingress against the actual native caller before receipt validation or dispatch. Ordinary mediator start gates remain closed.
Tracking and scope
Tracks #1 and the coordinated realm design at erix/posixd#1. This review remains unfinished until its required runtime and dependent validation is complete.
Architecture, authority and failure behavior
Operation 54 omits initial child root capabilities while the native TCB retains backing. Procd retains the actual master and moves only the process-bound grant through staging. Caller authentication compares the kernel's actual pending caller with the retained running owner generation; a bearer sender or descriptive identity cannot substitute. Rejected transfers retain cleanup obligations. This grants no mediator start permission and does not attest a final seal.
Validation evidence
Original coherent realm source CI acceptance — 18 September 2026: Signed
ea41ec37d36058f0027507ed1ecdb34d773b2aafpasses CI 291 and CI 290. All four terminal logs are complete (343,244 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Coherent realm image service prerequisites — 18 September 2026: Signed
ea41ec37d36058f0027507ed1ecdb34d773b2aafselects the original shared wire/startup dependency graph. Direct Rust implementation bytes are unchanged. All 14 default, all-feature and separate production development/release configurations pass 286/288/291 unit tests per configuration, strict host/native Clippy and freestanding linking with fatal linker warnings. Formatting, private-item rustdoc and Markdown pass, with zero warnings. Original push/PR CI is under observation. Matching catalog adoption and real consumer VMs remain requirements; complete realm and full in-guest build acceptance remain open.Original supervisor service checkpoint — 18 September 2026: Signed
3210f44b4fee05a7dd4f0ff25c2664629cc76aa2is pushed. Authenticate the actual private Loaderd caller and original Running Launchd before creation; retain supervision through preparation, grant handoff and owned bootstrap. Match the original owner before adopting stage rollback. Loaderd rollback ends at guard admission. Supervisor retirement exhausts active preparation and independent committed stages even after a cleanup refusal, preserving exact obligations and first errors. Eight new controls preserve earlier coverage. Four strict default/all matrices pass with 281/286 main units and five probe tests; ten production matrices also pass, for fifty native builds in total. Formatting, strict Clippy, private rustdoc and Markdown pass without warnings. Original CI 288 and CI 289 passes with all four terminal logs (343,310 bytes), without warnings. Actual Launchd owned producer/runtime adoption, coordinated consumer VM execution, complete fairness, configuration/readiness/seal and both full guest builds remain open.Owned bootstrap receiver checkpoint — 18 September 2026: Signed
1e8713ae4c49ab9a3bc927031936585d4a1f76fdconnects the Procd service loop to native owned bootstrap intake on the existing private receiver. It admits 16 request bytes and one actual grant, selects and proves empty exclusive ingress, authenticates claimed Launchd origin and validates native child scope before local relocation into the existing row. The obsolete legacy bootstrap handler is removed. Retained delivery and exact-stage custody survive draining; application cleanup precedes native relinquishment, and uncertain cleanup prevents ordinary intake. Ready owned and ordinary admission alternate with native deferred destruction first. Twelve owned-driver and two scheduling controls cover custody, negative cases and retirement. Four strict configurations pass: 273/278 main units, five probe tests, forty warning-free native builds, formatting, Clippy and private-item rustdoc. Original CI 286 and CI 287 pass from all four complete terminal logs (340,704 bytes), without warnings. These host controls and builds do not establish actual consumer VM execution. Actual Launchd runtime orchestration, full provider/terminal fairness, configuration, readiness, seal and both complete guest builds remain open.Deferred native cleanup checkpoint — 18 September 2026: Signed
507a98f53462b688d9008931aab09902713ed805gives each deferred native cleanup owner an independent turn before request intake. Unacknowledged owners rotate with their exact generation and first error retained. Five new controls and four strict matrices pass: 263/268 main units, five probe controls, forty native builds, formatting, strict Clippy and private-item rustdoc. The original Integration layout reader accepts both compiler-produced record layouts; checked page-rounded arenas remain unchanged. Original CI 284 and CI 285 pass from all four complete logs (337,764 bytes), without warnings. Bug 3 records the bounded scheduling correction. Legacy terminal/provider progress, actual consumer VM execution, complete realm fairness and both full guest builds remain open.Returned-grant consumer checkpoint — 18 September 2026: Signed revision
4e233515341067f6b6d3503db0acb61da6d54422is pushed. Actual native caller/grant admission precedes reservation of all five existing scratch columns. Matching-grant attenuation, ancestor lifetime deposit and a private nested sender/revoker remove original masters and bypass sources. Partial failure, failed acknowledgment delivery, exact supervisor loss and terminal retirement exhaust role-owned cleanup and preserve the first uncertainty, preventing ordinary continuation and row reuse. Eleven added controls pass with 258/263 main-binary units, five probe tests and forty native builds. Ordinary mediator execution remains denied. Formatting and Markdown checks pass. Original CI 282 and CI 283 passes; all four terminal logs are complete (336,168 bytes), without warnings. Matching consumer VM execution, runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Generation-bound native cleanup checkpoint — 18 September 2026: Signed revision
92e19c3ec60ffd5cb3bc16cde3a2316cd3bb1556is pushed. Staged rollback and deferred destruction retain the original generation. Pre-service terminal events own exact native cleanup without managed successor or provider effects; intake checks cleanup capacity before dequeue. Complete native framing and correlation precede result interpretation. Nine added controls pass with 247/252 main-binary units, five probe tests and forty native builds across the strict default/all-feature development/release matrix. Native transport and cleanup custody are separate cohesive modules. Ordinary service-image execution remains required. Formatting and Markdown checks pass. Original CI 280 and CI 281 passes; all four terminal logs are complete (332,946 bytes), without warnings. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain separate open acceptance requirements.Coordinated terminal observation checkpoint — 17 September 2026: Signed revision
2983f807cf7517250239872046f24d75bb9900c6is pushed. The generation-bound consumer passes its full strict host/native matrix and original CI 278/279, with all four terminal logs complete and no warnings. The isolated native producer checks also pass; ordinary service-image adoption is separate. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.Native terminal generation implementation — 17 September 2026: Signed revision
2983f807cf7517250239872046f24d75bb9900c6is pushed. Native retirement, signal and stop completion compare the exact original process/generation pair. Stale and already observed generations cannot initiate accounting or cleanup. Four new controls and the complete strict host/native matrix pass, including forty freestanding binary builds. Matching native execution and coordinated consumer rollout remain in progress; runnable realm bootstrap and complete guest builds are not established. Original automatic CI is monitored without retries.Runtime consumer dependency alignment — 15 September 2026
Signed
a6658875dc767210a489389a1b2b8bbfb21a42e1aligns the existing dependency selections with the original signed runtime graph. This checkpoint changes Cargo selections and the roadmap; this repository's Rust implementation files are unchanged. Formatting, strict Clippy, private rustdoc and canonical documentation checks pass without warnings. Default/all-feature development/release tests pass 239 default / 244 all-feature tests. Independent production configurations also pass strict host/native Clippy and native builds:procd-runtime: 239 development / 239 release tests,procd-runtime-release-image: 239 development / 239 release tests,procd-runtime-logging: 239 development / 239 release tests,procd-runtime-crash-reporting: 241 development / 241 release tests,procd-runtime-interrupt: 241 development / 241 release tests. There are 50 supported native builds in total. Push/review CI 276/277 passes with complete classified logs and no final warnings. The product catalog, product VM acceptance and guest build remain pending.Signed Procd
c583614aa48f3e11a3ccabfeee06340f518de750now checks the actual pending native caller on Launchd ingress against its retained running Launchd process and stage generation before operation-specific receipt validation or dispatch. Forwarded SEND aliases, request-body identities, other lifecycle roles, reused generations and unavailable identity cannot acquire this dispatch permission. Other receivers retain their policy; rejected delivered transfers still undergo local disposal, and uncertain disposal stops ordinary continuation.Five new producer controls exercise accepted event dispatch and refusals without consuming the private event. The complete strict host/native development/release matrix passes: 239 default-feature tests, 244 all-feature tests, Clippy, rustdoc, formatting and forty native binary builds, with no warnings. The changed runtime-loop fragment is formatted by the repository formatter; its other code matches the formatted original outside the reviewed admission replacement.
Signed documentation
45d4d04c534f2ebca857ee203265232fd7c32bbepasses 45 tests and a frozen 2,375-page manual with 433,469 in-bounds word boxes and no final warnings. Page 212 was visually reviewed. The receiver inventory also corrects the existing powerbox omission and obsolete loader operation count. Shared API snapshots are unchanged.Procd CI 274/275 and Docs CI 879/880 pass with complete classified logs and no final warnings. Both component cohorts are complete. Product runtime-image validation still requires a coherent original-commit dependency graph; this checkpoint does not claim a new Procd VM. Actual returned-grant custody, guarded bootstrap, readiness/configuration/seal, mediated client byte I/O, fair retirement and both complete guest build generations remain open.
Review checklist
Native guarded preparation — 19 September 2026: signed Integration
78557a6c672ecf426dfe894a01cc4aeec73b5e3cselects signed Exshffe50612889dd58a45a40d04593a4aa3a3ffa512for the separateappliance-disk-image-realm-preparation-positivescenario. The actual VM passes the eleven existing admission calls followed by BEGIN/Reserved, PREPARE/Guarded, READ/Guarded, ABORT/Retired and stale READ/NOT_FOUND. It transfers exactly one SEND-only copy of the explicitly supplied initial cwd to the authenticated reservation and selectsbin/trueinside that scope. This packaged executable remains an unstarted staging fixture. The existing private Launchd route is reused; no new endpoint, root grant or implicit namespace is introduced.Exactly one admission marker and one
ERIX_EXSH:REALM_PREPARATION:VERIFIEDprecede ordinary successful initial-shell exit. The original 120-second hard deadline and 45-second progress watchdog remain unchanged; scenario status is zero and build warnings are absent. The separate admission-only scenario is preserved. All 106 actual appliance artifacts and complete logs are retained. Serial SHA256 is7ef35833c2d88abcd093c8813791e11cea0d34edb2e29b8686df6996e2bc32ff(55,776 bytes); post-VM writable disk SHA256 is3439d0750ea456ceb8d9fbb063d6af763b4198a85f0270ae8d22c76c6ff99499. Its earlier packaging checksum is retained separately. Independent artifact review verifies all 73 original component revisions, both diagnostic markers in the actual packaged executable, and the signed image's exact 72-byte LCH1 version-3 configuration with four realm records and a 102,400-byte native arena.All 169 Integration helper commands, seventeen route/scenario controls and four strict 320/321-test Rust configurations pass, including native builds, fmt, strict host/native Clippy and private rustdoc; all 394 host streams are warning-free. The post-validation source delta changes only the two Exsh catalog pins and final documentation status, preserving checked implementation bytes. Exsh passes ten strict 976-test configurations, ten native builds and 355 frame-checker controls without warnings. Eight actual frame observations retain complete workspace mapping but incomplete 97/63/100/100 runtime/all/admission/preparation proof in both policies; the full frame gate remains required.
Original Integration CI 1677 and 1678 are queued. Original Exsh CI 271 and 272 are under observation. Complete typed mediator bootstrap, readiness/configuration/sealing, real client byte I/O, complete source/effect/frame proof, native upstream Rust/LLVM rebuilding and both full EriX build generations remain required. This prerequisite adds no accepted whole checklist item.
Minimum bootstrap design — 19 September 2026: signed Posixd proposal, in PR 5, specifies the next ownership boundary before codec or runtime implementation. Launchd uses its existing endpoint factory and retains the private configuration RECV/GRANT alias; the child receives only its existing control RECV and a guarded configuration SEND. Counted startup records and actual receipts must agree, with all temporary setup/grant disposal acknowledged before the separate private start gate.
Readiness requires actual CLAIM caller identity plus an acknowledged challenge through the retained control endpoint. COLLECT provides no server-origin evidence. Child-read-only startup mappings do not revoke Procd's trusted memory-write authority, and ordinary writable LCS1 startup mappings cannot silently stand in for this new contract. The current staged-only retirement path must gain exact running-child cleanup. A surviving child-termination owner after Procd loss remains a prerequisite: SEND lifetime revocation alone does not destroy that child, and Rootd exits after bootstrap. Resolve and validate this ownership before admitting private execution.
The proposal assigns no new wire layout/opcode and implements no Posixd runtime. Markdown, canonical document headings, governance bytes, local links, original source anchors and whitespace pass. Original Posixd CI 19 and 20 pass from two complete hashed logs (7,212 bytes), without warnings. Rust and new VM checks do not apply to this documentation-only repository. Existing native guarded-preparation acceptance remains separate; full runtime lifecycle, configuration/seal, real client I/O, full frame proof, native upstream toolchain rebuilding and both full EriX build generations remain open. No whole acceptance item is added.
Native child-lifetime prerequisite — 19 September 2026: Kernel design #19 now specifies opt-in custody through existing Process control authority plus the real matching install grant, with actual current supervisor attribution and separate stopping/reclamation obligations. An install grant alone must not confer child termination authority. The shared exit/kill prerequisite is signed, strictly validated and passes both original native lifetime/invocation scenarios at Integration
a62d1381f56a01afc692112d9b427205eaeb6a2e. The custody binding, safe reclamation progress point and producer adoption remain unimplemented. No private mediator start gate opens from this refactor.Verified grant-rights checkpoint — 20 September 2026:
Signed commit 1c80383afe1460f8d250472284225670f893937c requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 289/294-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 292/293 passes from four complete hashed logs (344,064 bytes), with zero warning candidates. Procd requests MINT only on actual derivation paths. It derives the final GRANT-only receipt into the disposed VSpace receipt slot and drops its delegating source before handoff. Derivation or disposal failure retains original-generation rollback and all remaining local custody.
Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256
6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.
Installer return-slot regression — 21 September 2026:
Both original corrected-catalog runs are now classified: 1695 passes 431/489 VM scenarios and 1696 passes 430/489. All six complete logs are retained and hashed, 32,723,390 bytes, zero warning candidates. Rust, Markdown and full dependency equality pass. Catalog mismatch issue 68 is corrected; this does not establish full consumer acceptance. Each run has 57 initial-shell uncertain-disposition failures and a separately retained release-appliance stall. Run 1696 also retains the ext4 quota timeout under its original 120-second bound, tracked in issue 20.
Procd bug 4 records a concrete producer/consumer mismatch. The final installer was handed off from VSpace scratch slot 1056 while later TTY provisioning requires managed grant slot 1040. The added producer regression fails on the original code. Signed Procd 10d972b652297fd656e9a6ac6dbdf197f362c7ce in WIP PR 2 derives the exact GRANT-only result, disposes its delegating source and uniquely relocates the result back to the empty managed grant slot. Refusals preserve original-stage rollback and remaining custody. Four strict 291/296-unit configurations, four native builds, host/native Clippy, formatting, private rustdoc and policies pass with zero warnings. Corrected full-service VM validation and original CI remain open; bug 4 remains open.
Acceptance remains 15/460 leaves, 3.48% weighted. Full consumer lifecycle, terminal accounting, source/effect/frame proof, Pagerd, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full in-EriX build generations remain required.
Verified managed installer recovery — 21 September 2026:
Signed Integration 648fbd5614d3d0b82223b1c3bb7f1b5a0c81ea7d in WIP PR 12 selects signed Procd ac8a12993bc8cbf134a11e141e459cb63df71123 and Docs PR 4. Both full original catalogs pass all 72/71 manifest checks against 73/70 clean selected checkouts and all 143 verified signatures. Twenty dependency and 46 immutable-source tests, native scenario policies, Markdown and whitespace pass. The unchanged orchestration crate retains its verified four 320/321-unit configurations, four native builds and strict Clippy/rustdoc evidence. Original Integration CI 1697/1698 is running; no complete regression-suite pass is claimed.
Procd bug 4 is corrected. The added producer regression reproduces the original 1056/1040 mismatch. Procd derives exactly GRANT into disposed VSpace scratch, drops its delegating source and uniquely relocates the result into the now-empty managed grant slot before handoff. The downstream TTY checks remain strict. Four 291/296-unit configurations, four native builds, formatting, strict Clippy and private rustdoc pass without warnings; relocation refusal and occupied-destination controls retain original-stage cleanup. Original correction CI 294/295 passes from four complete logs, 344,660 bytes. The subsequent roadmap-only checkpoint keeps every runtime source byte unchanged and original CI 296/297 passes from four complete logs, 344,680 bytes, zero warnings.
The maintained initial-shell start/exit, realm-admission and normal release-appliance VM scenarios all pass on their first corrected attempts with original guest bounds and watchdogs. The release appliance executes the real product-shell command and produces standalone LOOKUPOK output, separate from its echoed input. All three builds are warning-free and QEMU stderr is empty. Serial logs retain 55,702, 55,738 and 364 bytes respectively. Actual images, full artifact sets, scenario oracles and original signatures are retained. These runs execute Procd
10d972b652; the selected later Procd commit changes only its roadmap. All 73 executed component signatures and clean source trees verify. The earlier 431/489 and 430/489 full CI failures remain recorded, including the independent ext4 quota timeout; those runs are not rewritten as passes.The native-launch manual now explains the managed return destination, exact rights, unique relocation and partial-failure cleanup. All 45 tests, the complete 2,429-page manual, 448,970 word bounds and changed-page visual review pass without final warnings. Original Docs CI 993/994 passes from four complete logs, 774,342 bytes; each final TeX pass is warning-free after normal earlier reference resolution. Existing generated API references are unchanged.
Canonical acceptance remains 15/460 leaves, 3.48% weighted. This is a repaired runtime regression, not completion of a canonical lifecycle leaf. Original-generation terminal accounting, provider/lifetime completion, source/effect/frame proof, the 128-page Pagerd gate, profiler attribution, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. Exsh's retained release compiler and frame-proof failures stay open.
Verified native terminal accounting — 21 September 2026: Kernel a9bdf6163813d378e0b4a164bceb839e24fbb6b7 is signed/pushed. Terminal preflight reserves final scalar CPU evidence independently of TCB/CSpace/VSpace reclamation; exact queries preserve final results or explicit errors. Repeat observations belong to the actual original observer until exact acknowledgement, and observer death releases that claim. Independent authorized observers can progress. Selector 55 is retired; checked selectors 59/60 have no destructive fallback.
Four strict 736/760-unit configurations, both standalone controls and thirteen native build/Clippy profiles pass without warnings. Host controls include nonzero final counters after actual reclamation and ID reuse, original observer death, pending-final-charge destruction refusal, malformed requests, wrong callers, immutable errors and lost-acknowledgement reply retry. Original Kernel CI 624/625 and corrected 626/627 all pass from eight complete hashed logs (1,532,848 bytes), zero warnings.
Both maintained lifetime and owned-invocation VMs pass under the unchanged 60-second scenario limits and standard watchdogs, with no build warnings and empty QEMU stderr. Actual guest instructions check repeat observations and CPU queries, exact acknowledgement and absent-acknowledgement retry; executing children require nonzero user and kernel counters after native reclamation. Lifetime retains 2,025 serial bytes (SHA256
921edf5eadfdff61f2d85a63158555666e77e57a1e8aa4254ac30dcd216f8cf9); owned invocation retains 1,587 (SHA256404bc4ecad5074349d9ba45d1caf5439aebe849d344b726e5dec2ee2b9c4d907). Normal stripping exactly matches both packaged kernels to retained original artifacts; all fifteen selected original signatures and clean checkouts verify.Kernel regression 21 retains the first VM's final page-census failure. The corrected layout declares and allocates all six request pages and derives the independent census from that declaration. No unchanged retry or deadline relaxation occurred.
Integration fcd7b4a9608f629a12de78c53da5c3615d906b46 is signed/pushed with the verified isolated catalog. Twenty dependency and 46 immutable-source tests, native policies, Markdown and source checks pass. The unchanged orchestration crate, embedded fixture and original dependency closure retain verified four 320/321-unit and native/Clippy/rustdoc configurations. The full service catalogs retain their separately coordinated revisions; original Integration CI remains under observation.
Procd and Rootd consumer adoption, ordinary and mediator metric retention/consumer loss, manual updates, full service/profiler scenarios, complete authority/source/frame audits and full regression acceptance remain open under Kernel design 20. Canonical acceptance remains 3.48% weighted; 15 of 460 items. Native upstream Rust/LLVM/runtime rebuilding and both full EriX guest build generations remain mandatory and unproven.
Committed terminal-accounting consumers — 21 September 2026:
Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.
Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.
Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.
The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.
No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.
Terminal selector documentation reconciliation — 21 September 2026:
Signed Procd 68748bc65ea3fb798e810d624845dcb298ae1346 removes stale operation 55 prose and documents observation 59 plus exact acknowledgement 60. All runtime inputs are byte-identical to the validated consumer implementation; its four strict 299/305-test configurations remain applicable. Original documentation-checkpoint CI 300/301 passes from four complete hashed logs (347,266 bytes, zero warnings).
Ordinary consumer loss/restart and final reply disposition remain audited acceptance gaps. Failed ordinary metrics transport currently terminates Procd; it is not evidence of continued execution and row reuse. Full service CPU/profiler VM acceptance, complete realm lifecycle and both guest build generations remain open.
Coherent scalar-consumer validation — 21 September 2026: signed Integration 07c883525ee5 selects Procd 59ee30a88534 in both complete catalogs. All 171 maintained helper commands pass without warnings; unchanged orchestration inputs retain four strict matrices. Five actual service VMs pass: shell CPU accounting, exec successor replacement, two-CPU read-only inspection, out-of-session denial and guarded realm preparation. Each preserves 106 hashed evidence files, clean QEMU stderr, warning-free image builds and all original markers under the unchanged 120-second guest limit. The build-plus-scenario times are 119.746880, 38.325332, 35.346729, 35.773237 and 55.339698 seconds respectively; these are not guest performance measurements. Inspection reports increasing job CPU counters with control disabled; numeric CPU utilization remains unproven.
Procd's four strict 308/314-test configurations and original CI 302/303 pass. The manual update passes 45 tests, all 2,431 pages, 450,185 word bounds and changed-page visual review. Original Docs CI 1003/1004 passes from four complete logs (774,710 bytes); retained reference-convergence warnings resolve to zero on final passes. All 3,166 authored code files remain below 1,000 lines.
Original Integration 1701/1702 remains running; 1703–1710 remains queued. Logd 240 remains failed with terminal logs unavailable through HTTP 500; no cause is inferred. No original job was restarted or cancelled. Remaining lifecycle control/event ownership, complete native fault/cleanup acceptance and the measured startup timing failures remain open. No whole acceptance leaf closes: 15/460, weighted 3.48%. Rebuilding the external Rust/LLVM toolchain inside EriX and using it in the required full EriX guest-build generations remain mandatory and unproven.
WIP: Bind launch description installation to the actual staged childto WIP: Own staged mediator authority and restrict child installationWIP: Own staged mediator authority and restrict child installationto WIP: Stage mediators without child root capabilitiesWIP: Stage mediators without child root capabilitiesto WIP: Guard mediator construction and Launchd admissionView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.