timed is the time service daemon for EriX.
  • Rust 98.4%
  • Linker Script 1.6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Erik Inkinen 75b26e2eef
All checks were successful
CI / markdown (push) Successful in 6s
CI / test (push) Successful in 28s
Merge branch 'feature/dynlink'
2026-07-23 15:11:21 +03:00
.github Use branch-aware cargo overrides in CI 2026-06-23 18:31:42 +03:00
src Ungate timed kernel control helper for host tests 2026-04-22 04:39:24 +03:00
.editorconfig Initial commit 2026-03-05 10:48:19 +01:00
.gitignore Ignore local .ci workspace 2026-04-15 21:53:04 +03:00
.markdownlint-cli2.yaml Tighten CI markdown policy 2026-05-22 15:10:42 +03:00
ARCHITECTURE.md docs: record 5.4.37 dynamic evidence 2026-05-26 15:41:23 +03:00
Cargo.toml Point timed git dependencies at main branch 2026-04-22 04:55:19 +03:00
CODE_OF_CONDUCT.md Tighten CI markdown policy 2026-05-22 15:10:42 +03:00
CONTRIBUTING.md Tighten CI markdown policy 2026-05-22 15:10:42 +03:00
LICENSE Initial commit 2026-03-05 10:48:19 +01:00
linker.ld Keep stack reserve pages in runtime images 2026-04-24 09:13:07 +03:00
README.md docs: record 5.4.37 dynamic evidence 2026-05-26 15:41:23 +03:00
ROADMAP.md docs: record 5.4.37 dynamic evidence 2026-05-26 15:41:23 +03:00
rustfmt.toml timed: drop unstable rustfmt options for stable toolchains 2026-03-23 10:19:57 +02:00
SECURITY.md Tighten CI markdown policy 2026-05-22 15:10:42 +03:00

timed

timed is the time service daemon for EriX.

EriX is a clean-room, capability-based microkernel operating system written entirely in Rust.

Technical requirements are tracked in the EriX requirements, conventions, and project documentation.

See:

  • docs for design documents, specifications, and development plans.
  • Related architecture repositories for kernel, services, libraries, drivers, and integration tooling.

Purpose of This Repository

This repository implements the EriX time service daemon. Its purpose in EriX is to provide the time service role through explicit IPC and startup authority.

Functionally, it implements the daemon runtime, state model, IPC handling, and validation tests. The repository keeps the implementation, interface contracts, tests, and documentation for that behavior in one reviewable ownership boundary.

The maintained responsibilities are:

  • implement the time service runtime and state model
  • validate startup authority before accepting IPC requests
  • handle bounded service operations through the assigned endpoint set
  • keep service behavior, tests, and authority invariants documented

Clean-Room Policy

EriX follows a strict clean-room philosophy:

  • No external source code may be copied.
  • No external Rust crates are allowed.
  • No code generation tools that embed third-party code.
  • All code must be authored within the project.

Violations will result in rejection of the contribution.

License

All EriX repositories are licensed under the ISC License.

Development Model

EriX development is modular, deterministic, reproducible, authority-explicit, security-first, and self-hosting oriented.

This repository follows the project roadmap and the validation rules documented in its own roadmap.

Build and test

cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test --all-targets --all-features

Dependencies

  • lib-bootstrap
  • lib-capabi
  • lib-ipc
  • lib-service
  • ipc-syscall-x86_64

No external crates are used.

Validation Note

The host/test QUERY_CAP fallback remains cfg-scoped so runtime/release builds stay warning-free.

Dynamic Boot Artifact Evidence

Phase 5.4.37 documents timed as a dynamic boot artifact. The image build packages the time service daemon as an ELF64 x86_64 ET_DYN executable with .erix_dynlink metadata in the signed dynlink-store and mirrors it under /lib/erix/dynlink with its required shared objects.

Startup remains rootd through procd staged dynamic creation before dynlinkd; authority remains the dedicated time-control endpoint and startup peers. Dynamic packaging and filesystem mirror records are evidence and launch inputs only; they do not grant filesystem, loader, object-store, service-discovery, provider-bypass, block-device, or dynlinkd authority. timed receives only the documented startup endpoints, peers, and capabilities for its role.

Governance Principles

timed governance is scoped to time-service publication and bounded time queries.

The scoped governance rules are:

  • It answers time requests only through the assigned service endpoint.
  • It keeps time source assumptions documented and deterministic for tests.
  • It validates request bounds before returning timestamps or timer state.
  • It does not receive broad scheduling, interrupt, or hardware-clock authority.

Authority Boundaries

  • timed operates only through startup-assigned service capabilities.
  • New authority must be represented in bootstrap/capability validation and integration tests before use.

Contact

Development occurs in EriX organization and discussions happen in issues and design documents.

No decisions are considered valid without documented rationale.

Maintainers can be reached via email: admin@erikinkinen.fi.