WIP: Validate artifact boundaries and signed runtime sources #2
No reviewers
Labels
No labels
bug
ci
docs
duplicate
enhancement
help wanted
invalid
performance
phase-6
question
refactor
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
erix/rootd!2
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/posix-compat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary and rationale
Correct a production artifact scanner that could misclassify stream failure as absence of a forbidden marker. Extract each selected object's strings once, require successful extraction, and distinguish no match from a scanner failure. Remove the unused Integration path override and align existing dependency pins with original signed runtime sources.
Tracking and scope
Tracks #3 and the component audit at #1. The final change covers the scanner, explicitly bounded checker tests, pinned CI helpers, dependency selectors and component documentation. Existing roadmap coordination references remain in scope.
Architecture, authority and failure behavior
Invocation-owned objects and string receipts are removed on success, rejection, extraction failure and partial allocation failure. Checker tests select pinned process-ownership helpers explicitly and retain bounded child lifetime and true failure status. The scanner consumes original pinned Cargo sources. Native Rust, bootstrap authority, runtime policy and semantic acceptance limits are unchanged.
Validation evidence
Coherent startup consumer acceptance — 18 September 2026: Signed Integration
8b1c037aed2503e1f2a4b17c8a8be0666d62a305adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required.Original coherent realm source CI acceptance — 18 September 2026: Signed
3babf21e4531f563559e0eda05378a7e69f8c3c2passes CI 1034 and CI 1033. All four terminal logs are complete (222,567 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.Explicit realm startup consumer checkpoint — 18 September 2026: Signed
3babf21e4531f563559e0eda05378a7e69f8c3c2consumes exact 72-byte LCH1 version 3, preserves explicit zero or positive realm capacity and rejects legacy/truncated payloads without adding to the seven peer routes. Scratch includes every supported typed codec. The original signed Integration prerequisite and shared graph resolve one revision per dependency. Eight strict configurations and eight native builds pass 429 default/production and 428 all-feature tests, formatting, host/native Clippy and private rustdoc. All 64 Python tests, console controls and production, baseline, threat, phase and ownership audits pass without warnings. The reviewed 15,256-line surface and 265,880-byte linked image retain authority, syscall, dependency-name and eight unsafe-site inventories. The native entry is verified in executable file backing. CI 1033 and CI 1034 are under observation. Matched image publication and actual consumer VMs remain required; no runnable realm or complete guest build is claimed.Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision
fc898a7f4020757b2571647641ca096f66c31b6fis pushed. Bootstrap abort/destruction retains the original generation and requires complete correlated native receipts. Four strict host/native matrices pass 429/428 units. All 64 Python tests, console controls, production boundary and baseline/threat/phase/ownership checks pass. Issue #5 corrects audit linking and preserves successful stderr: the actual entry is rootd_entry, the image is 265,912 bytes and all semantic inventory fields remain unchanged. The earlier 4,352-byte entry-less artifact is invalid runtime-size evidence, not an optimization. Original CI 1031/1032 passes from four complete logs (222,678 bytes), without warnings. Original cleanup CI 1029/1030 also passes with four complete logs (219,068 bytes); its revision precedes the audit fix. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open.Corrected original audit CI — 17 September 2026: Original CI 1027
and CI 1028 pass at
4265aab899d08782e97aaca6b28632b574b6f948. All four terminal logs are complete,218,052 bytes, with no warning candidates. The exact local semantic audit,
62 Python controls, production boundary and console checks pass as well. The
updated testing manual is signed at Docs
10ea454ebab2cb0ca465cedf52ff619c1fc7efd4;45 tests, its complete PDF, final warnings, all word bounds and the changed page
review pass. This closes only the stale audit-contract regression #4. Original
1025/1026 stays failed; ordinary image and realm execution remain open.
Bootstrap audit reconciliation — 17 September 2026: Signed correction
4265aab899d08782e97aaca6b28632b574b6f948updates the baseline, ownershipmatrix and the validator's independent native-operation list. The release-active
line count is 15,239; other semantic inventory fields match the original records.
The 4,352-byte audit artifact uses Rust 1.97.1 and is not compared with sizes
from different compilers. All 62 Python tests, development-console checks,
production boundary and baseline/threat/phase/operation validators pass. Rust
and Cargo sources exactly retain the full strict 425/424-unit matrix. The
original failed workflows remain failed; both corrected original runs are
under observation. Ordinary service-image adoption remains open.
Audit regression: #4.
Coordinated terminal observation checkpoint — 17 September 2026: Signed revision
08e636e8bb1f182b8e4a21e39174651dcf508f6eis pushed. The temporary native bootstrap consumer carries its retained generation, accepts only exact terminal evidence and gates native destruction on that proof. Both malformed-response controls and the strengthened cleanup-order tests pass with the complete strict host/native matrix. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.Signed Rootd
3bf295a05b587970bcd96f307c194c85caff85e0passes 423 default/runtime/release-image/product tests and 422 all-feature/development-console tests per development/release profile. Formatting, strict host/native Clippy, twelve native builds, private rustdoc, all 62 Python tests and the unchanged bootstrap, threat, phase and ownership gates pass without warnings. Four new real-checker regressions cover early/late forbidden markers, extraction and scan failures, cleanup and extraction reuse; the existing stale-object regression builds actual baseline and product objects. Rootd CI 1021/1022 fails during dependency preparation before compilation; complete logs identify the separate shallow-cache defect at erix/integration#51. Local scanner and strict component results remain valid at their stated scope. Complete corrected CI is required.The companion technical manual describes the corrected validation contract. This checkpoint does not establish coherent product-image adoption, component-wide authority closure or a build within EriX.
Signed Rootd
c458c155ef5403fbedff625672be79017d0c9afbselects helpercdf15c52f24bd463dcabdddb945f779fff4ab367in its workflow and denies Rust, rustdoc and Python diagnostics. Runtime sources and dependency pins are byte-identical to scanner checkpoint3bf295a05b587970bcd96f307c194c85caff85e0. The repeated default/all development/release Rust matrix and all 62 Python/bootstrap checks pass; the earlier twelve native configurations retain their unchanged inputs. Rootd CI 1023/1024 passes at the corrected head with all four complete classified logs and no warnings; the original shallow dependency preparation now completes, all 62 Python checks run, and the actual artifact/semantic boundary gates pass. The original failed 1021/1022 logs remain retained under Integration issue #51.Review checklist
Verified grant-rights checkpoint — 20 September 2026:
Signed commit 87a9f38bfbcf18828a9c03b0c229696aa997d970 requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 428/429-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 1037/1038 passes from four complete hashed logs (222,588 bytes), with zero warning candidates. Corrective audit commit 0890d3285d1e9efe5d701043f930e172971a0354 updates the independently reviewed bootstrap baseline to 15,247 active production lines and 265,872 linked bytes under Rust 1.97.1. All 64 Python tests and production, baseline, threat, phase and ownership audits pass. Authority inventory, direct syscalls, dependency names and eight unsafe sites are unchanged. Bug 6 retains original 1035/1036 failures.
Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256
6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.
Committed terminal-accounting consumers — 21 September 2026:
Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.
Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.
Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.
The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.
No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.
WIP: Keep roadmap evidence in owning issues and PRsto WIP: Validate artifact boundaries and signed runtime sourceserikinkinen referenced this pull request from erix/integration2026-09-15 19:34:19 +02:00
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.