- Rust 99%
- Linker Script 1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Merge the selected feature/native-cli history with an explicit two-parent commit so main retains the development lineage and the validated source snapshot. The resulting tree is identical to the selected feature commit; no dependency pins or runtime behavior are changed by this merge. Previous main: |
||
| .github | ||
| src | ||
| .editorconfig | ||
| .gitignore | ||
| .markdownlint-cli2.yaml | ||
| ARCHITECTURE.md | ||
| Cargo.toml | ||
| CODE_OF_CONDUCT.md | ||
| CONTRIBUTING.md | ||
| LICENSE | ||
| linker.ld | ||
| README.md | ||
| ROADMAP.md | ||
| rustfmt.toml | ||
| SECURITY.md | ||
timed
timed is the time service daemon for EriX.
EriX is a clean-room, capability-based microkernel operating system written entirely in Rust.
Technical requirements are tracked in the EriX requirements, conventions, and project documentation.
See:
- docs for design documents, specifications, and development plans.
- Related architecture repositories for kernel, services, libraries, drivers, and integration tooling.
Purpose of This Repository
This repository implements the EriX time service daemon. Its purpose in EriX is to provide the time service role through explicit IPC and startup authority.
Functionally, it implements the daemon runtime, state model, IPC handling, and validation tests. The repository keeps the implementation, interface contracts, tests, and documentation for that behavior in one reviewable ownership boundary.
The maintained responsibilities are:
- implement the time service runtime and state model
- validate startup authority before accepting IPC requests
- serve monotonic, legacy synthetic wall-clock, and source-qualified UTC wall-clock snapshots through the assigned public endpoint
- label production monotonic snapshots
CALIBRATED_PROCESSOR, using actual elapsed nanosecond ticks from the boot-calibrated kernel source rather than query-count or interrupt-count progress - accept stable RTC samples only through one separate receive-only private provider endpoint and advance accepted bases with monotonic time
- return a typed zero-sequence rejection for a fixed-size malformed provider body only when its request identifier and private operation remain exact
- leave blocking deadline delivery unimplemented until the kernel exposes an asynchronous scheduler-backed contract
- keep service behavior, tests, and authority invariants documented
Clean-Room Policy
EriX follows a strict clean-room philosophy:
- No external source code may be copied.
- No external Rust crates are allowed.
- No code generation tools that embed third-party code.
- All code must be authored within the project.
Violations will result in rejection of the contribution.
License
All EriX repositories are licensed under the ISC License.
Development Model
EriX development is modular, deterministic, reproducible, authority-explicit, security-first, and self-hosting oriented.
This repository follows the project roadmap and the validation rules documented in its own roadmap.
Build and test
cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test --all-targets --all-features
Dependencies
lib-bootstraplib-capabilib-ipcipc-syscall-x86_64
No external crates are used.
Validation Note
The host/test QUERY_CAP fallback remains cfg-scoped so runtime/release builds
stay warning-free.
Dynamic Boot Artifact Evidence
The runtime image contract documents timed as a dynamic boot artifact.
The image build
packages the time service daemon as an ELF64 x86_64 ET_DYN executable with
.erix_dynlink metadata in the signed dynlink-store and mirrors it under
/lib/erix/dynlink with its required shared objects.
Startup remains rootd through procd staged dynamic creation before dynlinkd;
authority remains the dedicated time-control endpoint and startup peers.
Dynamic packaging and filesystem mirror records are evidence and launch inputs
only; they do not grant filesystem, loader, object-store, service-discovery,
provider-bypass, block-device, or dynlinkd authority. timed receives only
the documented startup endpoints, peers, and capabilities for its role.
Governance Principles
timed governance is scoped to time-service publication and bounded time
queries.
The scoped governance rules are:
- It answers time requests only through the assigned service endpoint.
- It keeps time source assumptions documented and deterministic for tests.
- It validates request bounds before returning timestamps or timer state.
- It does not receive broad scheduling, interrupt, or hardware-clock authority.
- Timed receives no CMOS I/O authority and the RTC provider receives no public client route. The private receive is polled before a one-tick-bounded public receive, with no nested receive while a caller awaits reply.
- Service replies retain their shared transport buffer through delivery.
Authority Boundaries
timedoperates only through startup-assigned service capabilities.- New authority must be represented in bootstrap/capability validation and integration tests before use.
- Time requests carry no authority. Unexpected receipts are retired before rejection; malformed or uncleanable receipt metadata fails stop.
- RTC sample sequence numbers are consumed monotonically even when newer evidence is rejected, preventing replay or corrected-content equivocation.
- A malformed private body cannot create a trusted base. Timed preserves only its descriptive request identifier when the exact private operation remains recognizable; wrong operations and wrong-sized bodies receive no typed correlation payload.
Contact
Development occurs in EriX organization and discussions happen in issues and design documents.
No decisions are considered valid without documented rationale.
Maintainers can be reached via email: admin@erikinkinen.fi.