WIP: Validate artifact boundaries and signed runtime sources #2

Draft
erikinkinen wants to merge 12 commits from feature/posix-compat into main
Owner

Summary and rationale

Correct a production artifact scanner that could misclassify stream failure as absence of a forbidden marker. Extract each selected object's strings once, require successful extraction, and distinguish no match from a scanner failure. Remove the unused Integration path override and align existing dependency pins with original signed runtime sources.

Tracking and scope

Tracks #3 and the component audit at #1. The final change covers the scanner, explicitly bounded checker tests, pinned CI helpers, dependency selectors and component documentation. Existing roadmap coordination references remain in scope.

Architecture, authority and failure behavior

Invocation-owned objects and string receipts are removed on success, rejection, extraction failure and partial allocation failure. Checker tests select pinned process-ownership helpers explicitly and retain bounded child lifetime and true failure status. The scanner consumes original pinned Cargo sources. Native Rust, bootstrap authority, runtime policy and semantic acceptance limits are unchanged.

Validation evidence

Coherent startup consumer acceptance — 18 September 2026: Signed Integration 8b1c037aed2503e1f2a4b17c8a8be0666d62a305 adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required.

Original coherent realm source CI acceptance — 18 September 2026: Signed 3babf21e4531f563559e0eda05378a7e69f8c3c2 passes CI 1034 and CI 1033. All four terminal logs are complete (222,567 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements.

Explicit realm startup consumer checkpoint — 18 September 2026: Signed 3babf21e4531f563559e0eda05378a7e69f8c3c2 consumes exact 72-byte LCH1 version 3, preserves explicit zero or positive realm capacity and rejects legacy/truncated payloads without adding to the seven peer routes. Scratch includes every supported typed codec. The original signed Integration prerequisite and shared graph resolve one revision per dependency. Eight strict configurations and eight native builds pass 429 default/production and 428 all-feature tests, formatting, host/native Clippy and private rustdoc. All 64 Python tests, console controls and production, baseline, threat, phase and ownership audits pass without warnings. The reviewed 15,256-line surface and 265,880-byte linked image retain authority, syscall, dependency-name and eight unsafe-site inventories. The native entry is verified in executable file backing. CI 1033 and CI 1034 are under observation. Matched image publication and actual consumer VMs remain required; no runnable realm or complete guest build is claimed.

Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision fc898a7f4020757b2571647641ca096f66c31b6f is pushed. Bootstrap abort/destruction retains the original generation and requires complete correlated native receipts. Four strict host/native matrices pass 429/428 units. All 64 Python tests, console controls, production boundary and baseline/threat/phase/ownership checks pass. Issue #5 corrects audit linking and preserves successful stderr: the actual entry is rootd_entry, the image is 265,912 bytes and all semantic inventory fields remain unchanged. The earlier 4,352-byte entry-less artifact is invalid runtime-size evidence, not an optimization. Original CI 1031/1032 passes from four complete logs (222,678 bytes), without warnings. Original cleanup CI 1029/1030 also passes with four complete logs (219,068 bytes); its revision precedes the audit fix. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open.

Corrected original audit CI — 17 September 2026: Original CI 1027
and CI 1028 pass at
4265aab899d08782e97aaca6b28632b574b6f948. All four terminal logs are complete,
218,052 bytes, with no warning candidates. The exact local semantic audit,
62 Python controls, production boundary and console checks pass as well. The
updated testing manual is signed at Docs 10ea454ebab2cb0ca465cedf52ff619c1fc7efd4;
45 tests, its complete PDF, final warnings, all word bounds and the changed page
review pass. This closes only the stale audit-contract regression #4. Original
1025/1026 stays failed; ordinary image and realm execution remain open.

Bootstrap audit reconciliation — 17 September 2026: Signed correction 4265aab899d08782e97aaca6b28632b574b6f948 updates the baseline, ownership
matrix and the validator's independent native-operation list. The release-active
line count is 15,239; other semantic inventory fields match the original records.
The 4,352-byte audit artifact uses Rust 1.97.1 and is not compared with sizes
from different compilers. All 62 Python tests, development-console checks,
production boundary and baseline/threat/phase/operation validators pass. Rust
and Cargo sources exactly retain the full strict 425/424-unit matrix. The
original failed workflows remain failed; both corrected original runs are
under observation. Ordinary service-image adoption remains open.

Audit regression: #4.

Coordinated terminal observation checkpoint — 17 September 2026: Signed revision 08e636e8bb1f182b8e4a21e39174651dcf508f6e is pushed. The temporary native bootstrap consumer carries its retained generation, accepts only exact terminal evidence and gates native destruction on that proof. Both malformed-response controls and the strengthened cleanup-order tests pass with the complete strict host/native matrix. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open.

Signed Rootd 3bf295a05b587970bcd96f307c194c85caff85e0 passes 423 default/runtime/release-image/product tests and 422 all-feature/development-console tests per development/release profile. Formatting, strict host/native Clippy, twelve native builds, private rustdoc, all 62 Python tests and the unchanged bootstrap, threat, phase and ownership gates pass without warnings. Four new real-checker regressions cover early/late forbidden markers, extraction and scan failures, cleanup and extraction reuse; the existing stale-object regression builds actual baseline and product objects. Rootd CI 1021/1022 fails during dependency preparation before compilation; complete logs identify the separate shallow-cache defect at erix/integration#51. Local scanner and strict component results remain valid at their stated scope. Complete corrected CI is required.

The companion technical manual describes the corrected validation contract. This checkpoint does not establish coherent product-image adoption, component-wide authority closure or a build within EriX.

Signed Rootd c458c155ef5403fbedff625672be79017d0c9afb selects helper cdf15c52f24bd463dcabdddb945f779fff4ab367 in its workflow and denies Rust, rustdoc and Python diagnostics. Runtime sources and dependency pins are byte-identical to scanner checkpoint 3bf295a05b587970bcd96f307c194c85caff85e0. The repeated default/all development/release Rust matrix and all 62 Python/bootstrap checks pass; the earlier twelve native configurations retain their unchanged inputs. Rootd CI 1023/1024 passes at the corrected head with all four complete classified logs and no warnings; the original shallow dependency preparation now completes, all 62 Python checks run, and the actual artifact/semantic boundary gates pass. The original failed 1021/1022 logs remain retained under Integration issue #51.

Review checklist

  • Signed canonical checkpoint and original source objects verified.
  • Applicable strict Rust, native, Python and semantic checks pass.
  • Canonical documents and failure/cleanup regression coverage updated.
  • Complete classified push/review CI with no final warnings.
  • Complete coherent product-image adoption and remaining component audit.

Verified grant-rights checkpoint — 20 September 2026:

Signed commit 87a9f38bfbcf18828a9c03b0c229696aa997d970 requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 428/429-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 1037/1038 passes from four complete hashed logs (222,588 bytes), with zero warning candidates. Corrective audit commit 0890d3285d1e9efe5d701043f930e172971a0354 updates the independently reviewed bootstrap baseline to 15,247 active production lines and 265,872 linked bytes under Rust 1.97.1. All 64 Python tests and production, baseline, threat, phase and ownership audits pass. Authority inventory, direct syscalls, dependency names and eight unsafe sites are unchanged. Bug 6 retains original 1035/1036 failures.

Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build.

Full coordinated consumer acceptance remains open under Kernel design 19 and phase completion.

Committed terminal-accounting consumers — 21 September 2026:

Procd 66934642c4464fc738152a9e60790914ba27dd1c in WIP PR 2 reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI 298/299 passes from four complete hashed logs, 347,245 bytes, zero warnings. Bug 5 remains open for actual service acceptance.

Rootd 64c97b13c450003d9c2b6bd9ed2a627088684b46 in WIP PR 2 acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed bug 7: a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI 1041/1042 passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates.

Docs e4525848ad4462901c9a6794ef1794cf85ea9e6b updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI 995/996 and corrected-table 997/998 passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved.

The separate Integration orchestration library checkpoint b06dfad00202765491a64552dde29eaca1c24838 passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance.

No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.

## Summary and rationale Correct a production artifact scanner that could misclassify stream failure as absence of a forbidden marker. Extract each selected object's strings once, require successful extraction, and distinguish no match from a scanner failure. Remove the unused Integration path override and align existing dependency pins with original signed runtime sources. ## Tracking and scope Tracks https://git.erikinkinen.fi/erix/rootd/issues/3 and the component audit at https://git.erikinkinen.fi/erix/rootd/issues/1. The final change covers the scanner, explicitly bounded checker tests, pinned CI helpers, dependency selectors and component documentation. Existing roadmap coordination references remain in scope. ## Architecture, authority and failure behavior Invocation-owned objects and string receipts are removed on success, rejection, extraction failure and partial allocation failure. Checker tests select pinned process-ownership helpers explicitly and retain bounded child lifetime and true failure status. The scanner consumes original pinned Cargo sources. Native Rust, bootstrap authority, runtime policy and semantic acceptance limits are unchanged. ## Validation evidence Coherent startup consumer acceptance — 18 September 2026: Signed Integration `8b1c037aed2503e1f2a4b17c8a8be0666d62a305` adopts exact 72-byte LCH1 version 3, explicit realm capacity and version-6 compiler-derived arena geometry across runtime profiles, wire/configuration boundaries and image packaging. Zero realm capacity disables admission while preserving native alignment; realm receipts remain separate from ordinary intake. Both catalogs retain their memberships and select one original 74-source union following 41 coordinated producer updates. The maintained 73-component source-policy gate passes. All 169 helpers and four strict 320/321-unit Rust configurations pass, including formatting, host/native Clippy, native builds and private rustdoc. Both actual consumer VMs pass their unchanged 120-second bounds: Launchd loads from ext4 and reaches ordered readiness; the initial shell prints its banner and exits successfully. Signed appliances, artifact and serial evidence are retained with zero build/VM warnings. Post-VM writable disk identity is recorded separately from the packaging checksum. Original Integration CI is under observation. Full source/effect/frame admission, complete realm operation and both full builds inside EriX remain required. Original coherent realm source CI acceptance — 18 September 2026: Signed `3babf21e4531f563559e0eda05378a7e69f8c3c2` passes [CI 1034](https://git.erikinkinen.fi/erix/rootd/actions/runs/1034) and [CI 1033](https://git.erikinkinen.fi/erix/rootd/actions/runs/1033). All four terminal logs are complete (222,567 bytes), with zero final warnings. This closes the original CI observation recorded above. Coherent catalog publication, actual consumer VMs and full guest-build acceptance remain separate open requirements. Explicit realm startup consumer checkpoint — 18 September 2026: Signed `3babf21e4531f563559e0eda05378a7e69f8c3c2` consumes exact 72-byte LCH1 version 3, preserves explicit zero or positive realm capacity and rejects legacy/truncated payloads without adding to the seven peer routes. Scratch includes every supported typed codec. The original signed Integration prerequisite and shared graph resolve one revision per dependency. Eight strict configurations and eight native builds pass 429 default/production and 428 all-feature tests, formatting, host/native Clippy and private rustdoc. All 64 Python tests, console controls and production, baseline, threat, phase and ownership audits pass without warnings. The reviewed 15,256-line surface and 265,880-byte linked image retain authority, syscall, dependency-name and eight unsafe-site inventories. The native entry is verified in executable file backing. [CI 1033](https://git.erikinkinen.fi/erix/rootd/actions/runs/1033) and [CI 1034](https://git.erikinkinen.fi/erix/rootd/actions/runs/1034) are under observation. Matched image publication and actual consumer VMs remain required; no runnable realm or complete guest build is claimed. Generation-bound cleanup consumer acceptance — 18 September 2026: Signed revision `fc898a7f4020757b2571647641ca096f66c31b6f` is pushed. Bootstrap abort/destruction retains the original generation and requires complete correlated native receipts. Four strict host/native matrices pass 429/428 units. All 64 Python tests, console controls, production boundary and baseline/threat/phase/ownership checks pass. Issue #5 corrects audit linking and preserves successful stderr: the actual entry is rootd_entry, the image is 265,912 bytes and all semantic inventory fields remain unchanged. The earlier 4,352-byte entry-less artifact is invalid runtime-size evidence, not an optimization. Original CI 1031/1032 passes from four complete logs (222,678 bytes), without warnings. Original cleanup CI 1029/1030 also passes with four complete logs (219,068 bytes); its revision precedes the audit fix. Runnable mediator bootstrap, fair retirement and both complete builds inside EriX remain open. Corrected original audit CI — 17 September 2026: Original [CI 1027](https://git.erikinkinen.fi/erix/rootd/actions/runs/1027) and [CI 1028](https://git.erikinkinen.fi/erix/rootd/actions/runs/1028) pass at `4265aab899d08782e97aaca6b28632b574b6f948`. All four terminal logs are complete, 218,052 bytes, with no warning candidates. The exact local semantic audit, 62 Python controls, production boundary and console checks pass as well. The updated testing manual is signed at Docs `10ea454ebab2cb0ca465cedf52ff619c1fc7efd4`; 45 tests, its complete PDF, final warnings, all word bounds and the changed page review pass. This closes only the stale audit-contract regression #4. Original 1025/1026 stays failed; ordinary image and realm execution remain open. Bootstrap audit reconciliation — 17 September 2026: Signed correction `4265aab899d08782e97aaca6b28632b574b6f948` updates the baseline, ownership matrix and the validator's independent native-operation list. The release-active line count is 15,239; other semantic inventory fields match the original records. The 4,352-byte audit artifact uses Rust 1.97.1 and is not compared with sizes from different compilers. All 62 Python tests, development-console checks, production boundary and baseline/threat/phase/operation validators pass. Rust and Cargo sources exactly retain the full strict 425/424-unit matrix. The original failed workflows remain failed; both corrected original runs are under observation. Ordinary service-image adoption remains open. Audit regression: #4. Coordinated terminal observation checkpoint — 17 September 2026: Signed revision `08e636e8bb1f182b8e4a21e39174651dcf508f6e` is pushed. The temporary native bootstrap consumer carries its retained generation, accepts only exact terminal evidence and gates native destruction on that proof. Both malformed-response controls and the strengthened cleanup-order tests pass with the complete strict host/native matrix. Typed mediator bootstrap, ordinary service-image adoption and both complete EriX builds inside EriX remain open. Signed Rootd `3bf295a05b587970bcd96f307c194c85caff85e0` passes 423 default/runtime/release-image/product tests and 422 all-feature/development-console tests per development/release profile. Formatting, strict host/native Clippy, twelve native builds, private rustdoc, all 62 Python tests and the unchanged bootstrap, threat, phase and ownership gates pass without warnings. Four new real-checker regressions cover early/late forbidden markers, extraction and scan failures, cleanup and extraction reuse; the existing stale-object regression builds actual baseline and product objects. Rootd CI 1021/1022 fails during dependency preparation before compilation; complete logs identify the separate shallow-cache defect at https://git.erikinkinen.fi/erix/integration/issues/51. Local scanner and strict component results remain valid at their stated scope. Complete corrected CI is required. The companion technical manual describes the corrected validation contract. This checkpoint does not establish coherent product-image adoption, component-wide authority closure or a build within EriX. Signed Rootd `c458c155ef5403fbedff625672be79017d0c9afb` selects helper `cdf15c52f24bd463dcabdddb945f779fff4ab367` in its workflow and denies Rust, rustdoc and Python diagnostics. Runtime sources and dependency pins are byte-identical to scanner checkpoint `3bf295a05b587970bcd96f307c194c85caff85e0`. The repeated default/all development/release Rust matrix and all 62 Python/bootstrap checks pass; the earlier twelve native configurations retain their unchanged inputs. Rootd CI 1023/1024 passes at the corrected head with all four complete classified logs and no warnings; the original shallow dependency preparation now completes, all 62 Python checks run, and the actual artifact/semantic boundary gates pass. The original failed 1021/1022 logs remain retained under Integration issue #51. ## Review checklist - [x] Signed canonical checkpoint and original source objects verified. - [x] Applicable strict Rust, native, Python and semantic checks pass. - [x] Canonical documents and failure/cleanup regression coverage updated. - [x] Complete classified push/review CI with no final warnings. - [ ] Complete coherent product-image adoption and remaining component audit. Verified grant-rights checkpoint — 20 September 2026: Signed commit [87a9f38bfbcf18828a9c03b0c229696aa997d970](https://git.erikinkinen.fi/erix/rootd/commit/87a9f38bfbcf18828a9c03b0c229696aa997d970) requires exact GRANT-only final installer receipts and selects the original shared dependency graph. Four strict 428/429-unit configurations, four native builds with the maintained linker layout, host/native Clippy, formatting and private rustdoc pass without warnings. Original CI 1037/1038 passes from four complete hashed logs (222,588 bytes), with zero warning candidates. Corrective audit commit [0890d3285d1e9efe5d701043f930e172971a0354](https://git.erikinkinen.fi/erix/rootd/commit/0890d3285d1e9efe5d701043f930e172971a0354) updates the independently reviewed bootstrap baseline to 15,247 active production lines and 265,872 linked bytes under Rust 1.97.1. All 64 Python tests and production, baseline, threat, phase and ownership audits pass. Authority inventory, direct syscalls, dependency names and eight unsafe sites are unchanged. [Bug 6](https://git.erikinkinen.fi/erix/rootd/issues/6) retains original 1035/1036 failures. Both maintained isolated native scenarios pass on their first attempts under the unchanged 60-second scenario limits, with no build warnings and empty QEMU stderr. Lifetime now exercises 27 ordinary CPL3 grant-right controls and requires INSTALL_GRANT_RIGHTS_OK before its existing cleanup assertions. Its 2,025-byte serial stream has SHA256 `6c685f1ceaf9080bf0bec628a4fac512bf9049d0fbcfe2b3737666adf414ca3a`; owned invocation retains 1,587 bytes. Normal stripping exactly matches both packaged kernels to retained original artifacts. All fifteen selected original source signatures and clean trees verify. These minimal native scenarios establish neither full service-image acceptance nor a guest build. Full coordinated consumer acceptance remains open under [Kernel design 19](https://git.erikinkinen.fi/erix/kernel/issues/19) and [phase completion](https://git.erikinkinen.fi/erix/integration/issues/65). Committed terminal-accounting consumers — 21 September 2026: Procd [66934642c4464fc738152a9e60790914ba27dd1c](https://git.erikinkinen.fi/erix/procd/commit/66934642c4464fc738152a9e60790914ba27dd1c) in [WIP PR 2](https://git.erikinkinen.fi/erix/procd/pulls/2) reserves notification/crash/cleanup storage before effects, obtains exact final CPU evidence, commits local status and cleanup obligations, then acknowledges on every actual event polling path. Lost acknowledgement replies preserve the local result without duplicate counters or notifications. Mediators retain only scalar counters and the original authenticated supervisor identity after disposing all capability columns; supervisor death discharges the pending scalar observation and a replacement cannot inherit it. Four strict 299/305-test configurations, native builds, Clippy and private rustdoc pass. Original CI [298](https://git.erikinkinen.fi/erix/procd/actions/runs/298)/[299](https://git.erikinkinen.fi/erix/procd/actions/runs/299) passes from four complete hashed logs, 347,245 bytes, zero warnings. [Bug 5](https://git.erikinkinen.fi/erix/procd/issues/5) remains open for actual service acceptance. Rootd [64c97b13c450003d9c2b6bd9ed2a627088684b46](https://git.erikinkinen.fi/erix/rootd/commit/64c97b13c450003d9c2b6bd9ed2a627088684b46) in [WIP PR 2](https://git.erikinkinen.fi/erix/rootd/pulls/2) acknowledges bootstrap evidence only after exact native destruction and local endpoint absence; both operations remain unavailable after temporary Process custody transfers to Procd. Four strict 430/429-test configurations, native builds, Clippy and private rustdoc pass. Original 1039/1040 exposed [bug 7](https://git.erikinkinen.fi/erix/rootd/issues/7): a stale source-call inventory and its matching semantic operation declarations. The correction explicitly inventories acknowledgement consumers and preserves the same temporary route and eventual Procd owner. All 64 Python controls, production-boundary, semantic baseline, threat model, phase contract and operation-ownership gates pass. Corrected original CI [1041](https://git.erikinkinen.fi/erix/rootd/actions/runs/1041)/[1042](https://git.erikinkinen.fi/erix/rootd/actions/runs/1042) passes from four complete verified logs, 222,969 bytes, zero warnings. Bug 7 is corrected; failed original runs remain retained without reruns or weaker gates. Docs [e4525848ad4462901c9a6794ef1794cf85ea9e6b](https://git.erikinkinen.fi/erix/docs/commit/e4525848ad4462901c9a6794ef1794cf85ea9e6b) updates the native contract, Procd/Rootd consumer custody and original signed IPC API references. Selector 55 is retired in both the detailed contract and summary; 58/59/60 are cross-checked against the shared registry. All 45 documentation tests and generated-reference checks pass. The complete 2,431-page manual builds without warnings; changed prose, selector and API pages pass visual review. Original documentation CI [995](https://git.erikinkinen.fi/erix/docs/actions/runs/995)/[996](https://git.erikinkinen.fi/erix/docs/actions/runs/996) and corrected-table [997](https://git.erikinkinen.fi/erix/docs/actions/runs/997)/[998](https://git.erikinkinen.fi/erix/docs/actions/runs/998) passes from eight complete logs, 1,549,628 bytes, with zero warnings in the final LaTeX passes. The 37 earlier convergence candidates per manual log are retained and resolved. The separate Integration orchestration library checkpoint [b06dfad00202765491a64552dde29eaca1c24838](https://git.erikinkinen.fi/erix/integration/commit/b06dfad00202765491a64552dde29eaca1c24838) passes four strict 320/321-test host/native configurations. Full service catalogs remain on their prior coherent graph while 35 remaining application/service repositories adopt the original shared revisions. Integration 1697/1698 remains running, and 1699/1700 plus 1701/1702 waits at the latest bounded observations. These are pending full regressions, not successful runtime acceptance. No new canonical acceptance leaf is closed: 15/460 and 3.48% weighted. Ordinary Launchd metric-consumer restart/disposal semantics, coherent service CPU/profiler VMs, complete realm/provider authority and I/O, source/effect/frame proof, Pagerd, native external Rust/LLVM/runtime rebuilding and both full EriX-in-EriX build generations remain required. The static audit finds 3,162 authored code files below 1,000 lines, 74 manifests, 259 original Git pins, 173 direct missing-docs gates and 92 conventional crate roots; this does not establish semantic authority or complete private-documentation closure.
docs: Keep roadmap tracking in owning issues
All checks were successful
CI / markdown (push) Successful in 20s
CI / test (push) Successful in 3m8s
CI / markdown (pull_request) Successful in 11s
CI / test (pull_request) Successful in 2m54s
ef30c1bdf5
Use public issue and PR references so the component roadmap stays
self-contained for contributors. Preserve runtime sources, feature scope
and validation requirements. All component Markdown files pass lint.
fix: Preserve artifact scanner failures
Some checks failed
CI / markdown (pull_request) Successful in 21s
CI / markdown (push) Successful in 21s
CI / test (pull_request) Failing after 26s
CI / test (push) Failing after 26s
3bf295a05b
Extract each selected object into one checked string receipt before marker
scans. Distinguish absent markers from scanner errors, retire partial owned
objects and receipts, and remove the obsolete Integration path patch. Add
real-checker coverage for marker positions, tool errors, cleanup and reuse.

Run checker tests through explicitly selected pinned process-ownership helpers
with bounded child inputs and lifetime. Align existing dependency pins with
the signed source graph and document the validation contract. All supported
strict Rust configurations, twelve native builds, 62 Python tests and the
unchanged semantic bootstrap gates pass without warnings. Native Rust and
authority behavior remain unchanged. Tracks issue #3.
erikinkinen changed title from WIP: Keep roadmap evidence in owning issues and PRs to WIP: Validate artifact boundaries and signed runtime sources 2026-09-15 19:19:44 +02:00
ci: Select complete original dependency transports
All checks were successful
CI / markdown (pull_request) Successful in 30s
CI / markdown (push) Successful in 30s
CI / test (push) Successful in 3m26s
CI / test (pull_request) Successful in 3m27s
c458c155ef
Pin the signed Integration helper that excludes shallow local object caches
before exact dependency fetches. Retain the runtime-library commit and all
Rootd Rust sources. Make Rust, rustdoc and Python diagnostics fatal in CI.

The strict local Rust matrix and all 62 Python/bootstrap contract tests pass.
Independent product configurations retain their exact unchanged build inputs
and prior successful native artifacts. Complete matching CI is still required
for the scanner and source-preparation fixes. Tracks issue #3 and Integration #51.
fix: Require exact terminal evidence before bootstrap destruction
Some checks failed
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / test (push) Failing after 2m51s
CI / test (pull_request) Failing after 2m52s
08e636e8bb
Carry the original staging generation through temporary native bootstrap
cleanup and consume the checked operation 55 response. Only canonical empty
queues permit another wait. Mismatched or failed terminal observations cannot
authorize destruction; caller-local endpoint disposal remains exhaustive.
Remove the old native event selector and align the actual orchestration
subcrate and shared libraries through full original commit pins.

Two new native-response controls and strengthened cleanup-order tests pass.
Default/all-feature development and release units, strict host/native Clippy,
freestanding builds, rustdoc, formatting and Markdown checks pass. The signed
Kernel's isolated native gates pass; ordinary service-image rollout remains open.
fix: Synchronize native terminal bootstrap audit contracts
All checks were successful
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 8s
CI / test (pull_request) Successful in 3m40s
CI / test (push) Successful in 3m42s
4265aab899
Bind the compiler-qualified baseline, operation matrix and independent validator
to the generation-bearing native wait. Review the nine-line source delta and
record compiler-specific image size without treating toolchain drift as a gain.
Update the architecture and roadmap to the measured contract.

All 62 Python checks, production boundary, console controls and semantic audits
pass. Rust/Cargo inputs retain the complete strict 425/424-test matrix. Original
CI failures are retained in issue #4; corrected workflows remain under review.
fix: Retain generation identity through bootstrap cleanup
All checks were successful
CI / markdown (pull_request) Successful in 4s
CI / markdown (push) Successful in 5s
CI / test (pull_request) Successful in 2m7s
CI / test (push) Successful in 2m10s
38962edd4b
Carry the original staged generation through native abort and terminal disposal.
Validate complete native reply framing and status correlation before interpreting
success, absence or empty terminal queues. Extract transport and typed cleanup
into cohesive modules while preserving borrowed temporary Process custody.

Four strict host/native matrices pass 429/428 unit tests. All 62 Python tests,
console controls, production boundary and semantic bootstrap audits pass. Review
the exact ten-line baseline delta and source ownership oracles without widening
authority. Coordinated native diagnostics pass separately; ordinary service-image
adoption and runnable realm bootstrap remain required.
fix: Link bootstrap audit artifacts with the native entry
All checks were successful
CI / markdown (push) Successful in 5s
CI / markdown (pull_request) Successful in 5s
CI / test (push) Successful in 1m47s
CI / test (pull_request) Successful in 1m47s
fc898a7f40
Use Rootd's maintained linker script and fatal linker warnings for production
object and semantic baseline builds. Retain successful command stderr so audit
logs cannot hide diagnostics. Add controls for successful and failed subprocess
output, and replace the entry-less artifact's invalid size evidence with the
265912-byte correctly linked image. All semantic inventory fields are unchanged.

All 64 Python tests, console controls and complete repository-specific audits
pass without warnings. The unchanged Rust source retains its strict 429/428-test
matrix. Verify the actual ELF entry matches rootd_entry inside executable file
backing. This repairs measurement evidence, not runtime performance. Tracks #5.
feat: Consume explicit realm startup capacity
All checks were successful
CI / markdown (pull_request) Successful in 10s
CI / markdown (push) Successful in 10s
CI / test (pull_request) Successful in 3m18s
CI / test (push) Successful in 3m19s
3babf21e45
Require exact LCH1 version 3 at role-payload and filesystem envelope boundaries.
Preserve explicit disabled and enabled realm storage without adding peer or
process authority. Size scratch for every typed configuration and reject
legacy or truncated records. Document the internal payload invariants and
adopt original signed shared and Integration orchestration dependencies.

Eight strict configurations and native builds pass 429/428 tests, with Clippy,
private rustdoc and formatting. All 64 Python tests, console controls and
production, baseline, threat, phase and ownership audits pass without warnings.
Review the exact decoder, seven code-line and real linked-byte inventory delta;
authority and unsafe sites are unchanged. Matched image publication and actual
consumer VMs remain required before complete realm or guest-build acceptance.
fix: Minimize staged installer authority
Some checks failed
CI / markdown (push) Successful in 8s
CI / markdown (pull_request) Successful in 6s
CI / test (push) Failing after 2m54s
CI / test (pull_request) Failing after 2m48s
87a9f38bfb
Require exact GRANT-only final installer receipts and adopt the coherent
original shared dependency graph. Preserve existing unique custody and
original-generation cleanup instead of accepting unnecessary MINT authority.

Four strict 428/429-test configurations, four native builds with maintained
linker layouts, host/native Clippy, private rustdoc and policy checks pass
without warnings. Coherent guest acceptance remains a separate requirement.
fix: Reconcile the installer authority audit baseline
All checks were successful
CI / markdown (pull_request) Successful in 6s
CI / markdown (push) Successful in 6s
CI / test (push) Successful in 2m8s
CI / test (pull_request) Successful in 2m8s
0890d3285d
Review the nine-line production source reduction and eight-byte smaller native
image after exact GRANT-only receipt admission. Keep the authority inventory,
syscall surface, dependency names and unsafe sites unchanged. Preserve both
original CI failures in issue 6 instead of weakening semantic comparisons.

All 64 Python tests and the production, baseline, threat, phase and ownership
audits pass without warnings. Rust and dependency sources remain identical
to the previously validated four strict host/native configurations.
fix: Acknowledge terminal evidence after bootstrap cleanup
Some checks failed
CI / markdown (push) Successful in 9s
CI / markdown (pull_request) Successful in 9s
CI / test (push) Failing after 2m24s
CI / test (pull_request) Failing after 2m25s
e6c0e23171
Route repeatable observation and exact acknowledgement only through temporary
Process custody. Release scalar evidence after matching native destruction and
proved local endpoint absence, preserving failures and rejecting retired
selectors without fallback. Adopt original shared and orchestration commits.

Four strict host configurations pass 430/429 controls, with four native builds,
host and native Clippy, private rustdoc and policy checks warning-free. Tests
cover acknowledgement ordering, cleanup failure, malformed replies, retired
selectors and denial after custody transfer. Coherent service VM and original
CI acceptance remain open under Kernel #20.
fix: Align bootstrap authority audits with terminal acknowledgement
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / test (push) Successful in 2m42s
CI / test (pull_request) Successful in 2m50s
64c97b13c4
Inventory the separate acknowledgement call and restrict its entire consumer
set to temporary bootstrap cleanup. Migrate the reviewed semantic baseline
and operation ownership matrix from retired wait to observe and acknowledge
without changing their temporary route or eventual Procd owner.

All 64 Python controls, the production boundary, semantic baseline, threat model,
phase contract and operation ownership checks pass without warnings. Retained
430/429-test Rust matrices, native builds, Clippy and rustdoc cover unchanged
Rust inputs. Review confirms the same compiler produces a 144-byte smaller
release binary and no other authority baseline fields change. Fixes Rootd #7;
original corrected-source CI and full service VM acceptance are still pending.
All checks were successful
CI / markdown (pull_request) Successful in 9s
CI / markdown (push) Successful in 10s
CI / test (push) Successful in 2m42s
CI / test (pull_request) Successful in 2m50s
This pull request is marked as a work in progress.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feature/posix-compat:feature/posix-compat
git switch feature/posix-compat

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --ff-only feature/posix-compat
git switch feature/posix-compat
git rebase main
git switch main
git merge --no-ff feature/posix-compat
git switch main
git merge --squash feature/posix-compat
git switch main
git merge --ff-only feature/posix-compat
git switch main
git merge feature/posix-compat
git push origin main
Sign in to join this conversation.
No description provided.