Skip to content

The dependency rule: Rust, QEMU, and declared C or C++ tools ToyOS can one day build and run; removing machinery updates every prompt that names it - #632

Merged
Japabu merged 8 commits into
mainfrom
wt/toyos-deprule
Sep 30, 2026
Merged

Japabu merged 8 commits into
mainfrom
wt/toyos-deprule

Conversation

@Japabu

@Japabu Japabu commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

The owner's rulings (2026-09-29)

Ruling 1, confirmed as "yes thats the rule we want":

Rust and QEMU for development, and beside them only tools built from C or C++ source that ToyOS can one day build and run itself — Python, Perl, CMake, Ninja, make — each declared, and taken only where no Rust tool does the job. No binary that exists for one host OS alone: a macOS binary is a hard no. ToyOS's own code is Rust; it writes no Python, Perl or shell of its own.

His context: "since we accepted llvm anyways: we can depend and build and ship stuff that can be built from c such as python and perl but will prefer rust native and toyos native binaries."

Ruling 2:

i think it makes sense that the tracks get the improvements we are working on as theyre landing. if we remove machinery we need to tell them how to do it right afterwards.

What changed, per decision

  • CLAUDE.md, Dependencies, states the rule and lists nothing. Beside Rust and QEMU, where no Rust tool does the job, only C or C++ tools ToyOS can one day build and run (Python, Perl, CMake, Ninja, make), each declared, and no binary for one host OS alone. It also carries two sentences word for word:

    • the ruling's "ToyOS's own code is Rust; it writes no Python, Perl or shell of its own.";
    • main's "Ask of anything new: could this ever run inside ToyOS?", where it stood. The ruling asks its question of host tools, and this one is asked of everything new.

    The bar sentence lists no failure. It points at .claude/agents/reviewer.md, "Arrivals", as where every host tool and every standing failure is declared. wc -w CLAUDE.md is 2614 on ace064f9d and 2645 here, and the growth is the owner's ruling.

  • reviewer.md, Arrivals. A host tool outside Rust and QEMU can arrive six ways: Command::new, libc::system, exec, posix_spawn, a build script or cc::Build, a .github/ run: step or package manager, or sh -c. It is declared in the declaration issue and nowhere else. Each of these is a BLOCKER:

    • an undeclared host tool;
    • one, like Go's gh, not built from C or C++ source ToyOS can one day build and run;
    • a binary for one host OS alone;
    • a C or C++ tool taken where a Rust tool does the job;
    • new Python, Perl or shell of ToyOS's own.
  • reviewer.md, Instructions (ruling 2). A change that removes or renames a command, flag or step an agent runs must update every prompt that names it in the same diff, saying what to do instead.

    • Such an instruction is outside "Prose is removed, never reviewed".
    • CLAUDE.md's "Stale or false prose is deleted", "an agent edits one only when briefed to" and "a CLAUDE.md never grows" do not bar the implementer who updates it.
    • One left naming what is gone is a BLOCKER.
  • orchestrator.md, Land (ruling 2). When a landing changes how agents work, every running agent is told the new way in one line and merges main before its next round.

  • implementer.md, at the orchestrator's request: "Never run git submodule in a linked worktree". The orchestrator measured why: a git submodule update rust in another worktree set the primary's .git/modules/rust/config core.worktree to a path that does not exist.

  • The declaration, issues/build/the-build-runs-host-tools-outside-rust-and-qemu.md, replaces issues/build/python-and-cc-are-declared.md.

    • It is a table of every tool that main's build, tests, workflows and metal loop run outside Rust and QEMU, plus every one that diag/flash.sh and the README's flashing steps run by hand.
    • Each row gives where the tool runs, its verdict with the reason, and its exit.
    • It has 33 rows: 8 admitted, 24 refused and 1 outside the rule (rg -c '\| admitted:', '\| refused:', '\| outside the rule:').

    Admitted:

    • Python for LLVM's CMake, and CMake.
    • git where gitoxide 0.85 cannot do the job.
    • Linux's cc, c++ and ar.
    • The toolchain's own clang, llvm-ar, rust-lld and llvm-config.
    • ovmf-generic and ca-certificates.
    • sudo on macOS.

    Refused:

    • Ninja, whose job n2 does.
    • git where gitoxide 0.85 does the job.
    • env.
    • rust/x and bootstrap.py.
    • curl, in two rows.
    • tar and zstd, gh, and ssh.
    • Apple's cc, c++, ar and xcrun.
    • newfs_msdos and hdiutil.
    • The two flashes by hand: diag/flash.sh, diskutil and plutil, shasum, lsblk, dd, sync, and sudo on Linux.
    • Shell of our own: rustup's rustup-init.sh, four multi-command nightly.yml steps, and src/metal.rs's umask 077 && cat >.

    Outside the rule: the T14's Ubuntu and every tool src/metal.rs runs on it.

  • issues/build/toyos-builds-itself.md, M5: the guest's toolchain builds its LLVM with Python and CMake built for ToyOS, so those rows' exit names a stage.

  • Filed: issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md. It covers sysroot::fork_checkout's git submodule update and ensure_submodule's, and its exit is that the build system runs no git submodule in a linked worktree's fork checkout.

  • The flash issue names the README's dd under sudo, and lsblk and sync on Linux, and its exit requires the README's flashing steps to run none of lsblk, dd or sync.

  • src/main.rs: "They go when the build no longer needs a host." is deleted from ALSO_USED's doc comment, since CMake's and Ninja's exits are M5 and n2.

  • README.md: two things are deleted. One is the Prerequisites sentence that called the four tools rustc's and not ToyOS's. The other is "no system linker" in the opening, since rustc links every host binary through cc.

  • Deleted because the rule made it false:

    • nightly.yml's "Only Rust and QEMU" quote.
    • The FAT issue's sentence calling the replaced rule the owner's.
    • From the flash issue, ", and no ledger declares it" in its title and its "None of these is in CLAUDE.md's standing failures".

The second review, answered

BLOCKERs:

  1. env is refused. src/release.rs already runs cargo run -- --build-only with GITHUB_ACTIONS and CI removed. Exit: the build system removes both itself.

  2. Ninja is measured, and refused. n2 does its job, measured as follows (full setup under Gates):

    • named ninja, CMake's Ninja generator configures LLVM for n2 and n2 builds llvm-tblgen, exit 0 each;
    • named n2, CMake refuses its version, exit 1.

    The row carries those exits. Its exit is rustc's bootstrap building LLVM under n2. M5 no longer builds Ninja for ToyOS.

  3. The bench is outside the rule, as the orchestrator ruled.

    • The orchestrator's reading on the T14: "Ubuntu 24.04.4 LTS", sudo 1.9.15p5 and dd (coreutils) 9.4, both C.
    • Its Ubuntu is recovery equipment on a test machine, not the build's host.
    • The per-tool row is replaced by one row that says so. Its tools leave with Ubuntu (issues/boot-media/the-machine-updates-itself-without-ubuntu.md).

NOTEs:

  • The toolchain's own tools. clang, llvm-ar, rust-lld and llvm-config, built from ToyOSOrg/llvm-project, are an admitted row. rustc links every guest binary with rust-lld. clang compiles the C corpus, hello.c and doomgeneric. cc::Build archives with llvm-ar. Bootstrap reads LLVM through llvm-config.
  • run: steps. Arrivals names a .github/ run: step. The declaration's intro no longer claims every row was found by the arrival paths: it names the two flashes by hand as its own scope.
  • git is judged per use, in two rows. What gitoxide 0.85 can do was read in its source in ~/.cargo/registry.
    • Admitted: adding, removing and pruning worktrees; updating submodules; the fork's fetch from the primary's and its checkout; the primary's fast-forward; the tests' fixture repositories, which must be what git makes; and rustc's bootstrap.
    • Why gix cannot:
      • it has worktrees() but no worktree add;
      • Submodule::update reads the config's setting and updates nothing;
      • there is no checkout of an existing worktree, no reset, no push and no staging;
      • gix-transport 0.57.2's local connect "will spawn a git process locally".
    • Refused, because gix does them:
      • every read: rev-parse, show-ref, for-each-ref, rev-list, log, branch --contains, merge-base, ls-tree, ls-files, cat-file, config --get-regexp, worktree list, status, diff, ls-remote and grep;
      • src/sync.rs's fetch of origin over HTTPS;
      • the workflows' checkouts.
    • A new git rev-parse therefore has one answer: refused.
  • The README's flashing steps. lsblk, sync and sudo on Linux have rows. The dd and macOS sudo rows name the README's steps.
  • "ToyOS's own code is Rust" and "Ask of anything new" are back in CLAUDE.md, word for word.
  • The Instructions carve-out now reaches CLAUDE.md's two rules for the implementer who updates an instruction.
  • The heading and slug say host tools. rg --hidden outside rust/ and target/ finds the old slug nowhere; its one citation, reviewer.md's, moved in the same commit.
  • src/sysroot.rs's git submodule update in a linked worktree is filed, as issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md.

REMOVEs: the fork line numbers after download.rs and apple.rs are deleted, and this body no longer describes another pull request.

The third review, answered

No BLOCKERs were raised. origin/main (#616, #625) is merged in 1a4ab450e, a clean merge.

NOTEs:

  • ensure_submodule. The fork-checkout issue now names it. sysroot::build_std and compiler::build_in_fork call it on the linked-worktree fork, and it runs git submodule update --init library/backtrace there whenever that fork's library/backtrace is empty or gone. A first fork_checkout that stops after adding the fork and before adding library/backtrace leaves the fork in that state. The exit is the build system's, not fork_checkout's alone.
  • lsblk, sync and the README's dd. The README's steps are live, because target/bootable.img is the build's default image (src/build.rs). So the flash issue's body names them, and its exit requires the README's flashing steps to run none of the three.
  • safe.directory. git config --global --add safe.directory, from nightly.yml's two container setups, is now in the refused git row: a Rust tool does it. gix-config 0.58, which gix 0.85 depends on, adds a value to a section (File::section_mut_or_create_new, SectionMut::push) and writes the file (File::write_to). I read that in its source in ~/.cargo/registry.
  • n2 is named in its row as github.com/evmar/n2 at b1fead5. gh api repos/evmar/n2/commits/b1fead5 resolves to b1fead52ccda.
  • macOS sudo stays admitted, on a citation: sudo-rs's README at 89bae8a (its main when read) says it "is targeted for FreeBSD and Linux-based operating systems only".
  • The Instructions carve-out also reaches CLAUDE.md's "a CLAUDE.md never grows".

REMOVEs, each deleted:

  • "merges," from the admitted git row;
  • the T14's point release, with its commas;
  • src/main.rs's "They go when the build no longer needs a host."

Gates

  • cargo run -- --ci host at 9ef3867e6: EXIT=0, "Host: 54 step(s), all green". Log: /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/deprule/host8.log. It was not run locally at e9262d7a6, where CI's host check is the gate.

  • cargo check -p toyos-build --bin toyos-build on e9262d7a6's tree: EXIT=0. The only change to src/main.rs is a doc comment.

  • The n2 measurement.

    • Setup:
      • n2 is github.com/evmar/n2 at b1fead5, built from source in a scratch directory; the crates.io n2 is an unrelated crate.
      • LLVM is the primary's rust/src/llvm-project/llvm at 52ed14fcd56a. The pin a79bc52c1d5e adds five ToyOS commits to that commit, none in llvm/CMakeLists.txt, llvm/cmake, lib/Support, lib/TableGen or utils/TableGen.
      • Flags: Release, X86 only, and no tests, benchmarks, examples or docs.
    • -G Ninja -DCMAKE_MAKE_PROGRAM=<n2>: exit 1, "The detected version of Ninja (0.1.0) is less than the version of Ninja required by CMake (1.3)".
    • -G Ninja -DCMAKE_MAKE_PROGRAM=<a symlink named ninja to n2>, which is how n2's README says CMake runs it:
      • configure: exit 0;
      • n2 -C build -j 8 llvm-tblgen: exit 0, "n2: ran 304 tasks, now up to date";
      • the same again, and cmake --build build --target llvm-tblgen: exit 0 each, "n2: no work to do";
      • bin/llvm-tblgen --version: exit 0, "LLVM version 22.1.8";
      • the build directory holds .n2_db and no .ninja_log.
    • The same with n2 built --no-default-features, which drops its jemalloc so that no C is linked into it: every step exits 0, and the build runs 304 tasks.
    • A find for files under the primary's llvm-project newer than a marker set before each arm printed nothing.
    • The scratch builds are deleted. Logs: /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/deprule/n2m/.
  • No guest test and no QEMU: this is prose, prompts and issues only. git diff --shortstat origin/main...HEAD: 13 files changed, 112 insertions(+), 149 deletions(-). The only change to code is a deleted doc-comment sentence in src/main.rs. Tests are +0 −0, so no negative control or oracle is owed.

  • wc -w on origin/main (deb8fa31d) and here:

    file main here
    CLAUDE.md 2611 2642
    reviewer.md 1443 1566
    orchestrator.md 878 903
    implementer.md 821 845
    README.md 2762 2744

    The declaration is 1615 words, and the file it replaces was 1103.

What I am unsure of

  • Ninja: only llvm-tblgen was built under n2. Two things are unmeasured: bootstrap's whole LLVM, clang and LLD build and install under n2, and bootstrap finding n2 named ninja on PATH.
  • gitoxide 0.85's capabilities were read in its source, not exercised.
  • curl in bootstrap: the refusal rests on rustup's beta-2026-07-13 being the stage0 that rust/src/stage0 pins. I read that; I did not run it.
  • sudo on macOS is admitted on sudo-rs's own README. sudo-rs was not built on this Mac.
  • gix-config's write was read in its source, not exercised.
  • The filed fork_checkout issue extends implementer.md's claim one level down, to library/backtrace, for both of its arms. It is unmeasured, because measuring it breaks git in the primary's rust/.

🤖 Generated with Claude Code

https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L

Japabu and others added 2 commits September 29, 2026 21:14
…ols ToyOS can one day build

The owner ruled (2026-09-29), confirmed as "yes thats the rule we want":

  Rust and QEMU for development, and beside them only tools built from C or
  C++ source that ToyOS can one day build and run itself — Python, Perl,
  CMake, Ninja, make — each declared, and taken only where no Rust tool does
  the job. No binary that exists for one host OS alone: a macOS binary is a
  hard no. ToyOS's own code is Rust; it writes no Python, Perl or shell of its
  own.

CLAUDE.md's Dependencies paragraph states it, pointing at `check_prerequisites`
for the declared tools. Its standing failures are now what the rule still
refuses: the two macOS FAT tools, and `diag/flash.sh`, the one shell file
`git ls-files '*.sh' '*.py' '*.pl'` lists. Python via `rust/x` and `cc` for
every host link stop being failures; they are declared C and C++ tools.

The reviewer's Arrivals rule becomes the same rule: a host tool outside Rust
and QEMU is a C or C++ tool ToyOS can one day build, declared in
`check_prerequisites` and in the issue, with the reason no Rust tool does the
job in the PR; a binary for one host OS alone, or new Python, Perl or shell of
ToyOS's own, is a BLOCKER.

`issues/build/python-and-cc-are-declared.md` becomes
`issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md`: per
tool (Python, `cc`, CMake and Ninja), where it runs and why no Rust tool does
the job, with one exit for the four — it builds and runs on ToyOS. Deleted as
stale under the rule: the Rust bootstrap in the fork as Python's only exit, the
"hole" framing, the 2026-08-08 and 2026-09-01 rulings, the Ubuntu version pins
that `nightly.yml` carries, and the pointer to the two macOS issues, which are
CLAUDE.md's now. `git` joins the list of what else is run, `gh` is marked Go
and so outside the rule. Perl and `make` are not listed: nothing on main runs
them. The one citation, in `issues/build/toyos-builds-itself.md`, follows the
rename.

README's Prerequisites loses the sentence that called the four tools `rustc`'s
and not ToyOS's.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…the rule made false goes

CLAUDE.md's Dependencies paragraph loses "Ask of anything new: could this ever
run inside ToyOS?", which "tools ToyOS can one day build and run" now says, and
its new clause is tightened. Its standing failures now name every use the rule
refuses, each read in the code first: `newfs_msdos` and `hdiutil`
(`toyos-fat32/tests/common/mod.rs`), macOS's `xcrun` (`src/llvm.rs`, which asks
it for the SDK on an apple-darwin host), Go's `gh` (`src/release.rs`, three
call sites) and `diag/flash.sh`, the one shell file `git ls-files '*.sh'
'*.py' '*.pl'` lists.

The issue that lists the C and C++ tools gains an `xcrun` entry with its exit,
so the failure CLAUDE.md names is recorded, and `xcrun` leaves the `cc` entry
it was a clause of.

Deleted, because the rule made them false:

- `issues/build/toyos-builds-itself.md`, M5: "Python (`bootstrap.py`), CMake
  and Ninja leave the build (...)". They are not to leave; the track's exit is
  the fixed point with no host in the loop.
- `issues/build/the-owners-flash-script-runs-diskutil.md`: "None of these is in
  CLAUDE.md's standing failures." `diag/flash.sh` is.
- `README.md`: "no system linker". The Prerequisites below it say `rustc`
  links every host binary through `cc`. "No Make" stays: nothing on main runs
  `make` (`rg -n 'Command::new\("make"\)' src tests kernel userland` and
  `rg -n -w make .github` both exit 1).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu
Japabu marked this pull request as ready for review September 29, 2026 19:40
…ents are told

The owner's second ruling of 2026-09-29: "i think it makes sense that the
tracks get the improvements we are working on as theyre landing. if we remove
machinery we need to tell them how to do it right afterwards."

reviewer.md gains an Instructions rule: a change that removes or renames a
command, flag or step an agent runs updates every prompt that names it, each
`CLAUDE.md` and `.claude/agents/*.md`, in the same diff, saying what to do
instead; an instruction left pointing at what is gone is a BLOCKER. It sits
directly before Arrivals.

orchestrator.md's Land section gains one sentence after "sync the primary
checkout": when a landing changes how agents work, every running agent is told
the new way in one line before its next round, and merges main before its
final gate.

`wc -w`: reviewer.md 1443 to 1491, orchestrator.md 863 to 892.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu Japabu changed the title The dependency rule: Rust and QEMU, and beside them only C and C++ tools ToyOS can one day build The dependency rule: Rust, QEMU and C or C++ tools ToyOS can one day build; removing machinery updates every prompt that names it Sep 29, 2026
@Japabu

Japabu commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

Round 1 at a9faca9. CI run 36621533086 (ci, job host): success. The branch adds no test and targets no hardware.

BLOCKER

  • CLAUDE.md:65 — the standing-failures list leaves out things main runs today that CLAUDE.md:61's own rule refuses. curl (src/release.rs:75,139; src/sdkversion.rs:118), tar and zstd (src/release.rs:164,171,261,273) and ssh (src/metal.rs:1203,1225,1491,1900,1928) are in neither check_prerequisites list (src/main.rs:20-51). They are also used where a Rust tool does the job: the issue's own exits say so (issue:57,60,62-64), and for ssh the tree already drives its own russh client (src/metaltalk.rs:730). c++ runs on every LLVM key (src/llvm.rs:162-166) and no list declares it. So the body's "The standing failures are now what the rule still refuses" does not hold.
  • .github/workflows/nightly.yml:69-74,102-120,191-203,218-221 — by the orchestrator's ruling this body records, these four multi-command run: steps are shell of our own. The branch records them in neither CLAUDE.md:65 nor any issue (body, "What I am unsure of"). A compromise the branch found must be removed or recorded with an exit; this one is silent debt.
  • issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md:21-27 — "No Rust tool does the job" for Python is contradicted by the entry's own clause on every build that reuses a keyed LLVM. Upstream's Rust src/bootstrap builds with stable cargo, fetches its own stage0 (rust/src/bootstrap/src/core/download.rs:595) and needs no Python. The deleted "That removes Python only from a build that reuses a keyed LLVM" was that qualification. On those builds Python is used where a Rust tool does the job, so CLAUDE.md:65 names it unless the owner rules the environment contract out; the branch cannot settle that by assertion.
  • CLAUDE.md:61, .claude/agents/reviewer.md:57 — "declared in check_prerequisites" goes further than the ruling's "each declared", and it cannot hold for tools that run only where check_prerequisites never does. --ci returns into ci::dispatch before it (src/main.rs:124-127), so gh, curl, tar and zstd (src/ci.rs:86,606,754) are never checked there, and ssh runs from src/bin/toyos-metal.rs. Declaring them there would print a note on every dev host about tools it never runs. Where the rule puts the declaration makes the tree fail it by construction.
  • .claude/agents/reviewer.md:56-60 — Arrivals labels only two things BLOCKER: a one-host-OS binary, and new Python, Perl or shell of our own. By Rank ("NOTE is everything else"), a new cross-platform tool not built from C or C++ (Go, like gh), an undeclared C tool, or one used where a Rust crate does the job is now only a NOTE. The old bullet refused every arrival outside the declared set, and the ruling admits only declared C/C++ tools where no Rust tool does the job. A branch that adds Command::new("gh") to a new file passes this bullet with a NOTE.
  • .claude/agents/orchestrator.md:56-57 — "merges main before its final gate" puts off what the ruling says happens "as theyre landing". The one-line new way a running agent is told before its next round names machinery its worktree does not have until that merge: an unknown cargo run flag is refused (src/flags.rs:99-117), and the removed machinery is still there to run. The merge belongs with the line, before the next round.

NOTE

  • Growth — git diff --shortstat origin/main...HEAD: 8 files, +89 −137; production code +0 −0, tests +0 −0. CLAUDE.md grows 16 words (wc -w 2614 → 2630); all of it is the ruling's except "in check_prerequisites" (BLOCKER 4).
  • CLAUDE.md:61 — drops the ruling's "— Python, Perl, CMake, Ninja, make —". Those are the only words saying that tools the old paragraph refused ("no Python") are now admitted. Next to "no Python, Perl or shell of our own", a reader of the old text can take Python as still refused.
  • .claude/agents/reviewer.md:57 — "ToyOS can one day build" drops the ruling's "and run", which CLAUDE.md:61 keeps.
  • .claude/agents/reviewer.md:56 — "however started or installed" replaced the list a reviewer searches (Command::new, libc::system, exec/posix_spawn, a build script's cc::Build, a .github manager or sh -c) to keep the word count level. Read literally, it also makes every sed, rm, env, apt-get or brew a workflow starts an arrival that must be declared.
  • .claude/agents/reviewer.md:53-55 against :107-108 — an instruction left naming a removed flag is a BLOCKER under the first and "a citation: never a send-back" under the second; an agent can apply either.
  • issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md:44-71 — reviewer.md:58 makes this file the declaration of record, but it is not the list of what main runs. Missing: newfs_msdos and hdiutil (toyos-fat32/tests/common/mod.rs:527,604); diskutil, plutil, shasum, dd and sudo (diag/flash.sh:37,82,105); c++ (src/llvm.rs:162); and sh (rust/x:1). The deleted pointer to the two macOS issues was what tied those binaries to their issues.
  • same file:46-47 and :36-42 — git has no exit and no reason why no Rust tool does its job. The CMake-and-Ninja entry argues from LLVM's build descriptions, which is CMake's case only, and gives no reason for Ninja, the executor.
  • same file:51-53 — rustc itself runs xcrun --sdk macosx --show-sdk-path on every macOS host link when SDKROOT is unset (rust/compiler/rustc_codegen_ssa/src/back/apple.rs:230; back/link.rs:4060). Meeting this exit therefore leaves the failure CLAUDE.md:65 names.
  • same file:11-13 — the exit cites issues/build/toyos-builds-itself.md, which after this diff has no stage for Python, CMake or Ninja, though M5 needs all three in the guest (body, "What I am unsure of").
  • PR body, T14 ruling — "C tools the rule admits" holds only for declared tools, and dd, efibootmgr and wipefs are declared nowhere. src/metal.rs runs mount, umount and reboot (:625-627) and visudo, install and sudo the same way. src/metal.rs:1901 also sends umask 077 && cat > {staged}, which is two commands of our own shell under the same body's run: ruling.

REMOVE

  • .github/workflows/nightly.yml:181 — "Only Rust and QEMU", run rather than argued: quotes the rule this PR deletes; the job it heads installs python3, cmake, ninja-build and build-essential (:194-195).
  • issues/filesystem/fat32-suite-needs-macos-binaries.md:12-14 — "The owner's rule that made that mandatory: "no dependencies on binaries that dont come with rust or qemu"." calls the owner's rule the one this PR replaces.
  • issues/build/the-owners-flash-script-runs-diskutil.md:7 — ", and no ledger declares it": CLAUDE.md:65 now names the script, and the body says so.
  • issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md:9-10 — "— REQUIRED, which exits, and ALSO_USED, which names what is absent and continues —" repeats src/main.rs:14,31-33.
  • same file:18-21 — "The preflight looks for any of those names … opens the Command Line Tools installer." repeats src/main.rs:53-58, where it is already stated at the site.
  • same file:38-40 — "CMake is in REQUIRED because … does not run it." repeats src/main.rs:24-27,35-39.
  • PR body — "Perl and make are not listed: nothing on main runs them" is false for Perl: diag/flash.sh:82 runs shasum, which on macOS is #!/usr/bin/perl (head -c 200 /usr/bin/shasum).
  • PR body — the bullet on the flash issue's title sits under "closed by the orchestrator's rulings" but is not one of them, and "that issue's owner" is nobody (status: open).
  • PR body — "The standing failures are now what the rule still refuses, each use read in the code" (BLOCKER 1).

SEND BACK

…and the rulings as written

CLAUDE.md states the rule and lists nothing. Dependencies carries the
ruling's examples (Python, Perl, CMake, Ninja, make) and "each declared";
"declared in `check_prerequisites`" goes, because `--ci` and the metal loop
run tools where `check_prerequisites` never runs. The standing-failures list
goes too: the bar sentence now points at reviewer.md's Arrivals as where every
host tool and every standing failure is declared, since a CLAUDE.md cites no
issue file and holds no list another source answers. To stay at main's 2614
words (`wc -w`), "nothing — build, test, or verification — rests on a host
binary. Self-hosting means" is deleted: the ruling's "tools ToyOS can one day
build and run" is that north star as a test, and the self-hosting sentence
keeps its definition.

reviewer.md, Arrivals, is the one pointer: it names the ways a tool arrives
that a reviewer searches (`Command::new`, `libc::system`, `exec`,
`posix_spawn`, a build script or `cc::Build`, a `.github/` package manager,
`sh -c`), names the issue as the only place a host tool is declared, keeps
the ruling's "and run", and makes each of five arrivals a BLOCKER: an
undeclared host tool, one not built from C or C++ source ToyOS can one day
build and run (Go's `gh`), a binary for one host OS alone, a C or C++ tool
taken where a Rust tool does the job, and new Python, Perl or shell of
ToyOS's own. Instructions says an instruction naming what is gone is not the
prose "Prose is removed, never reviewed" governs, so a stale one is a
BLOCKER there and not a citation here.

orchestrator.md: a running agent is told the new way in one line and merges
main before its next round, because until that merge its worktree still has
the removed machinery and refuses the new flag.

implementer.md, at the orchestrator's request: never run `git submodule` in a
linked worktree. One in another worktree wrote a `core.worktree` that does
not exist into the primary's `.git/modules/rust/config`, and every git
command in the primary's `rust/` failed until it was restored.

The declaration, issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md,
is now a table of every tool main's build, tests, workflows and metal loop
run outside Rust and QEMU, found by those arrival paths over src/, tests/,
kernel/, userland/, toyos-*/, .github/ and diag/: where each runs, admitted
or refused with the reason, and its exit. 28 rows, 10 admitted and 18
refused. Python is admitted for LLVM's CMake (`find_package(Python3 …
REQUIRED)`); `rust/x` and `bootstrap.py` are refused, because upstream's
bootstrap binary does their job. Apple's `cc`, `c++`, `ar` and `xcrun` are
refused as one host OS's, with M5 as their exit. The T14 bench's Ubuntu
tools are admitted until Ubuntu leaves the loop. The four multi-command
nightly steps and the metal loop's `umask 077 && cat >` are shell of our own.
The FAT and flash issues are named again as their tools' exits. What repeated
src/main.rs is gone.

toyos-builds-itself.md, M5, says its LLVM runs Python, CMake and Ninja built
for ToyOS, so the declaration's exit for those three names a stage.

Deleted as the review asked: nightly.yml's "Only Rust and QEMU" quote, the
FAT issue's sentence calling the replaced rule the owner's, and ", and no
ledger declares it" from the flash issue's title.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu Japabu changed the title The dependency rule: Rust, QEMU and C or C++ tools ToyOS can one day build; removing machinery updates every prompt that names it The dependency rule: Rust, QEMU, and declared C or C++ tools ToyOS can one day build and run; removing machinery updates every prompt that names it Sep 29, 2026
"nothing — build, test, or verification — rests on a host binary.
Self-hosting means" is restored to CLAUDE.md's Dependencies exactly as main
has it. It is the owner's own text, and it says tests and verification too,
which the rest of the sentence does not. Nothing else is cut in its place.
CLAUDE.md is 2628 words (`wc -w`) against main's 2614. The 14 words are the
owner's ruling's growth: line 61 goes from 192 to 214 words and line 65
from 48 to 40.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu

Japabu commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator Author

Round 2 at ae253b8. CI run 36633367013 (ci, job host): success at this head. The branch adds no test and targets no hardware.

Round 1's BLOCKERs

  1. CLAUDE.md:65, standing failures incomplete: CLOSED. CLAUDE.md:65 lists nothing. The declaration has rows for curl (:27, :28), tar and zstd (:29), ssh (:31) and c++ (:21, :32), read at ae253b8.
  2. nightly.yml, four multi-command steps: CLOSED. They are refused rows :40-43, with exit "each step is one command".
  3. Python: CLOSED. It is admitted only for LLVM's CMake (:17). find_package(Python3 ${LLVM_MINIMUM_PYTHON_VERSION} REQUIRED sits at llvm/CMakeLists.txt:1016 outside any if, read in the primary's rust/src/llvm-project. rust/x and bootstrap.py are refused (:26).
  4. check_prerequisites as the declaration: CLOSED. rg check_prerequisites over the tree finds it only in src/main.rs.
  5. Arrivals' BLOCKER cases: CLOSED. There are five, at reviewer.md:60-62.
  6. orchestrator.md, merge timing: CLOSED. orchestrator.md:56-57 says "merges main before its next round".

Nothing cites python-and-cc-are-declared (git grep at HEAD, and rg --hidden outside rust/ and target/). Round 1's nine REMOVEs are gone.

BLOCKER

  • issues/build/the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run.md:24 — env is admitted because "no Rust tool on the runner unsets a variable for one command", and src/release.rs:232-236 is one. The build system already runs cargo run -- --build-only with GITHUB_ACTIONS and CI removed. So the portability jobs' env -u (nightly.yml:206, :221) is a C tool taken where a Rust tool does the job, which is Arrivals' fourth case. The row is a refused one, a standing failure. Its exit is the build system removing the two variables itself, not M5.
  • same file:19 — Ninja's "no Rust tool does the job" is a guess, and the body concedes it: n2, "a Rust reimplementation of Ninja", was never tried. "No CMake generator targets a Rust tool" does not answer it, because what the Ninja generator writes is what n2 runs. Measure it: configure rust/src/llvm-project/llvm with -G Ninja -DCMAKE_MAKE_PROGRAM=<n2>, build llvm-tblgen under n2, and put the exit code in the row. If it is green, the row is refused with n2 as its exit. If it is red, the row stays admitted on that red.
  • same file:25 — the bench row admits on "no Rust tool does their job on that Ubuntu". That is a guess on the fact that decides it: the body says the T14's release is recorded nowhere, and that from 25.10 its sudo and coreutils are sudo-rs and uutils. The reason also answers only one clause of the rule, and several of the row's tools fail the others. udevadm, systemd-analyze, efibootmgr, wipefs and ip exist for Linux alone, and ToyOS will run none of them. orchestrator.md:85 calls that Ubuntu "recovery, not a tool", and the row's exit is the issue that removes it, which is the exit of a failure, not of an admitted tool. Measure the release (cat /etc/os-release on the bench; the bench is the orchestrator's) and give each tool the rule's verdict, or rule the bench outside the declaration and delete the row.

NOTE

  • Growth — git diff --shortstat origin/main...HEAD: 11 files, +72 −146. Production code +0 −0, tests +0 −0. wc -w from main to head: CLAUDE.md 2614 → 2628 (the orchestrator accepted this), reviewer.md 1443 → 1535, orchestrator.md 863 → 888, implementer.md 821 → 845. The declaration is 1228 words; the file it replaces was 1103.
  • .claude/agents/reviewer.md:57 — "outside Rust and QEMU" replaced main's "outside Rust's toolchain, git, QEMU and this repository's own Rust". The declaration has no row for the C++ tools the toolchain build makes and the host runs: its clang (tests/common/compile.rs:56, tests/common/clang.rs:45), the clang and llvm-ar that src/clang.rs:85-86 hands to cc::Build, and rust-lld. A reviewer can read a new Command::new(&c.clang) either as Rust or as an undeclared host tool.
  • .claude/agents/reviewer.md:57-58 — the arrival list names no .github/ run: step. That is how env, sed, sleep and the build job's sudo rm -rf arrive, and how anything a runner image carries would arrive. The declaration's intro (:9-10) says every row was found by the listed ways; its env row (:24) was not.
  • declaration:20 — git is admitted whole, for its worktree and submodule jobs, while Python (:17, :26) and curl (:27, :28) are judged per use. By that measure, the rev-parse reads (src/lib.rs:71, src/release.rs:46), which gix 0.85 does, are refused uses. As written, Arrivals' fourth case gives a new git rev-parse two answers.
  • declaration:35 — "and diskutil in the README's flashing steps" brings README.md:291-306 into the declaration, but that section's lsblk (Linux only), sync and sudo dd have no row. Either cover those steps or leave the README out.
  • CLAUDE.md:61 — the ruling's "ToyOS's own code is Rust" is dropped. With only "No Python, Perl or shell of our own" and Arrivals' fifth case (reviewer.md:62), a declared host helper of our own written in C passes every case but the fourth. The fourth catches it only if a tool nobody has written counts as a Rust tool that does the job.
  • CLAUDE.md:61 — "Ask of anything new: could this ever run inside ToyOS?" is deleted on the grounds that the ruling's test restates it. But that question was asked of everything new (a crate, a test's oracle, a mechanism), and the ruling asks it of host tools only. It is the owner's text, and the ruling did not retire it.
  • .claude/agents/reviewer.md:55-56 — the carve-out reaches only reviewer.md's Prose section. CLAUDE.md:103 ("Stale or false prose is deleted, never corrected or rewritten") and CLAUDE.md:102 ("an agent edits one only when briefed to") still bind the implementer who must write "what to do instead" into a CLAUDE.md. So the fix this rule demands is one CLAUDE.md forbids, unless the brief names that file.
  • declaration:7 — the heading and slug say "C and C++ tools", but the table also declares Go's gh, shell of our own, a Perl shasum, Apple's binaries, firmware and a trust store. By issues/README.md:100-101, a slug its own body refutes is renamed.
  • src/sysroot.rs:259 — by the claim implementer.md:58-59 makes from the orchestrator's measurement, the build does what that line forbids. In a worktree whose fork is a linked worktree of the primary's rust (:243), the build runs git submodule update --init library/backtrace whenever the primary's backtrace lacks the pinned commit. File it.

REMOVE

SEND BACK

…ed per use

The declaration is renamed to what its rows are, host tools and not only C
and C++ ones: issues/build/the-build-runs-host-tools-outside-rust-and-qemu.md.
Its one citation, reviewer.md's Arrivals, moves in this commit.

BLOCKERs:

- env is refused. src/release.rs already runs `cargo run -- --build-only`
  with GITHUB_ACTIONS and CI removed, so a Rust tool does the job. Exit: the
  build system removes both itself.
- Ninja is refused: n2 does its job. n2 is github.com/evmar/n2 at b1fead5,
  built from source in a scratch directory (the crates.io `n2` is an unrelated
  crate). LLVM was configured from the primary's rust/src/llvm-project/llvm at
  52ed14fcd56a, the upstream commit the pin a79bc52c1d5e adds five ToyOS
  commits to, none of them in llvm/CMakeLists.txt, llvm/cmake, lib/Support,
  lib/TableGen or utils/TableGen. Flags: Release, X86 only, no tests,
  benchmarks, examples or docs.
  - `cmake -G Ninja -DCMAKE_MAKE_PROGRAM=<n2>`: exit 1, "The detected version
    of Ninja (0.1.0) is less than the version of Ninja required by CMake
    (1.3)".
  - The same with CMAKE_MAKE_PROGRAM a symlink named `ninja` to n2, which is
    how n2's README says CMake runs it: configure exit 0; `n2 -C build -j 8
    llvm-tblgen` exit 0, "n2: ran 304 tasks, now up to date"; the same again
    and `cmake --build build --target llvm-tblgen` exit 0, "n2: no work to
    do"; `bin/llvm-tblgen --version` exit 0, "LLVM version 22.1.8". The build
    directory holds .n2_db and no .ninja_log.
  - The same again with n2 built --no-default-features, which drops its
    jemalloc so that no C is linked into it: every step exit 0, 304 tasks.
  `find` over the primary's llvm-project for files newer than a marker
  touched before each arm printed nothing. The scratch builds are deleted.
  M5 in issues/build/toyos-builds-itself.md no longer builds Ninja for ToyOS.
- The T14 bench is outside the rule. The orchestrator read the bench's
  release, "Ubuntu 24.04.4 LTS", with sudo 1.9.15p5 and dd (coreutils) 9.4,
  both C, and ruled its Ubuntu recovery equipment on a test machine, not the
  build's host. One row says so with that release, and its tools leave with
  Ubuntu.

NOTEs:

- The toolchain's own clang, llvm-ar, rust-lld and llvm-config, built from
  ToyOSOrg/llvm-project, are an admitted row: rustc links every guest binary
  with rust-lld, the C corpus, hello.c and doomgeneric compile with clang,
  cc::Build archives with llvm-ar, and bootstrap reads LLVM through
  llvm-config.
- reviewer.md's Arrivals names a `.github/` `run:` step, which is how env,
  sed, sleep and the build job's `sudo rm -rf` arrive. The declaration's
  intro no longer claims every row was found by those ways: it names the two
  flashes by hand as its own scope.
- git is two rows, split by what gitoxide 0.85 does, read in its source in
  ~/.cargo/registry. Admitted: adding, removing and pruning worktrees,
  updating submodules, the fork's fetch from the primary's and its checkout,
  the primary's fast-forward, the tests' fixture repositories, and rustc's
  bootstrap. gix 0.85 has worktrees() and no worktree add; Submodule::update
  reads the config's setting and updates nothing; there is no checkout of an
  existing worktree, no reset, no push and no staging (gix-index's add_entry
  builds an index from a tree); and gix-transport 0.57.2's local connect
  "will spawn a `git` process locally". Refused: every read (rev-parse,
  show-ref, for-each-ref, rev-list, log, branch --contains, merge-base,
  ls-tree, ls-files, cat-file, config --get-regexp, worktree list, status,
  diff, ls-remote, grep), src/sync.rs's fetch of origin over HTTPS, and the
  workflows' checkouts: gix has rev_parse, merge_base, rev_walk, status,
  worktrees, has_object, index, submodules, diff_tree_to_tree, ref_map and
  clone, and reqwest for HTTPS.
- The README's flashing steps: lsblk, sync and sudo on Linux have rows, and
  the dd and macOS sudo rows name the README's steps.
- CLAUDE.md carries the ruling's "ToyOS's own code is Rust; it writes no
  Python, Perl or shell of its own." in place of its paraphrase, and main's
  "Ask of anything new: could this ever run inside ToyOS?" where it was, both
  word for word. `wc -w CLAUDE.md`: 2614 on main, 2645 here.
- reviewer.md's Instructions carve-out reaches CLAUDE.md's "Stale or false
  prose is deleted" and "an agent edits one only when briefed to" for the
  implementer updating an instruction.
- Filed issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md:
  sysroot::fork_checkout runs `git submodule update --init library/backtrace`
  in a linked worktree of the primary's rust whenever the primary's backtrace
  lacks the pinned commit, which implementer.md forbids.

REMOVEs: the fork line numbers after download.rs and apple.rs are deleted,
and the pull request body no longer describes #631.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
@Japabu

Japabu commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator Author

Round 3 at 9ef3867. CI run 36713663931 (ci, job host, pull_request): success at this head. The branch adds no test and targets no hardware. Below, "declaration" is issues/build/the-build-runs-host-tools-outside-rust-and-qemu.md.

Round 2's BLOCKERs

  1. env: CLOSED. declaration:26 refuses it on src/release.rs:232-236, which runs cargo run -- --build-only with GITHUB_ACTIONS and CI removed. Its exit is "the build system removes both itself".

  2. Ninja unmeasured: CLOSED. The logs are in n2m/.

    • measure.log: a-configure EXIT=1, because CMake refuses n2's "0.1.0". b-configure EXIT=0, and n2 named ninja reports "Ninja version: 1.10.2" (b-configure.log:131).
    • b-build EXIT=0 ran 304 tasks, including llvm-min-tblgen's .inc custom commands (b-build.log:209-224, :307). b-tblgen-version EXIT=0.
    • measure2.log: the --no-default-features arm exits 0 at every step. Neither find printed a file.
    • The pin's five commits past the measured 52ed14fcd56a touch none of the build paths the body names (git diff --stat in the primary's llvm-project is empty).

    The refusal is sound on this evidence. It is the bar round 2 set, and the row claims llvm-tblgen and nothing more. Its exit, bootstrap building LLVM under n2, is the unmeasured whole build, so the row cannot close on less. It needs no line saying what is unmeasured.

  3. The T14 bench: CLOSED by the orchestrator's ruling. It is one row outside the rule (declaration:27).

Round 2's NOTEs are each answered: declaration:23, reviewer.md:60, declaration:20-21, declaration:39-43, CLAUDE.md:61 (both sentences word for word), reviewer.md:55-57, the slug, and the filed fork_checkout issue.

The git rows are sound. An absence can only be read, and gix 0.85.0's source shows each one the admitted row claims:

  • no worktree add (src/repository/worktree.rs);
  • Submodule::update returns the config's value (src/submodule/mod.rs:118);
  • push.rs holds only push.default;
  • gix-transport 0.57.2 "will spawn a git process" for a local path (src/client/blocking_io/file.rs:288).

The refused row's exit is where its claims get exercised.

Round 2's REMOVEs are gone. No old slug is cited. git grep at HEAD, rg --hidden outside rust/ and target/, and rg in rust/ outside src/llvm-project/ and build/ find neither python-and-cc-are-declared nor the-build-runs-c-and-cxx-tools-toyos-does-not-yet-run. origin/main's two citations are the two lines this branch rewrites.

BLOCKER

None.

NOTE

  • Growth — git diff --shortstat origin/main...HEAD: 12 files changed, +100 −146. Production code +0 −0, tests +0 −0. wc -w from ace064f9d to HEAD: CLAUDE.md 2614 → 2645 (the ruling's, accepted), reviewer.md 1443 → 1562, orchestrator.md 863 → 888, implementer.md 821 → 845, README.md 2762 → 2744. The declaration is 1576 words against the 1103 it replaces, and the filed issue is 129.
  • issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md:9-13, :20 — it names only fork_checkout's arm, so its exit can be met with the command still reachable. ensure_submodule (src/lib.rs:121-133) runs git submodule update --init library/backtrace in the same linked-worktree fork, from sysroot::build_std (src/sysroot.rs:390) and compiler::build_in_fork (src/compiler.rs:324). It does so whenever that fork's library/backtrace is empty or gone, which is what a first fork_checkout stopped between src/sysroot.rs:243 and :257 leaves.
  • declaration:39-41 — lsblk, sync and the README's dd exit through issues/build/the-owners-flash-script-runs-diskutil.md, but that issue's exit can be met with README.md:303-305 unchanged. Its body names only the script's dd and the README's diskutil. Its exit is "rg -l "diskutil|plutil" … finds nothing, and the build system writes the stick".
  • declaration:20-21 — git config --global --add safe.directory (nightly.yml:117, :199) is in neither git row. The admitted row lists no config write, and the refused row covers only config --get-regexp. Today it rides inside the refused shell rows (:46, :47). Once their exit makes it a step of its own, it has no per-use verdict: the gap round 2 named for rev-parse.
  • declaration:19 — the n2 on crates.io is a different crate, an unrelated neural-network library (n2-info.txt beside the n2m/ logs). The tool measured is github.com/evmar/n2 at b1fead5, which only the PR body names, and whoever takes the exit reads the row.
  • declaration:42 — the macOS sudo admission rests on "sudo-rs does not target macOS". The PR body calls that documentation as remembered, not a measurement. Reading sudo-rs's supported platforms, or building it on this Mac, decides admitted against refused.
  • .claude/agents/reviewer.md:55-58 — the carve-out now reaches both rules round 2 named, but a third CLAUDE.md rule bars the same fix. CLAUDE.md:105's "a CLAUDE.md never grows" refuses "saying what to do instead" wherever the new way takes more words than the line it replaces.

REMOVE

  • declaration:20 — "merges," in "stages, merges, resets and pushes nothing" is false. gix 0.85.0 has Repository::merge_trees and Repository::merge_commits (src/repository/merge.rs:135, :190). The admission of src/sync.rs's merge --ff-only rests on the checkout gix lacks, not on a merge.
  • declaration:27 — ", 24.04.4 LTS" goes stale at the T14's next point release, and no verdict rests on it now that the row is outside the rule.
  • src/main.rs:39 — "They go when the build no longer needs a host." is false against this branch's declaration. CMake's exit is M5 running it in the guest (declaration:18), and Ninja's is bootstrap building LLVM under n2 (declaration:19).

LAND AFTER NAMED CHANGES

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
- The fork-checkout issue reaches `ensure_submodule`, which runs
  `git submodule update --init library/backtrace` in the same linked-worktree
  fork from `sysroot::build_std` and `compiler::build_in_fork` whenever its
  `library/backtrace` is empty or gone. Its exit is now the build system's,
  not `fork_checkout`'s alone.
- The flash issue names the README's `dd` under `sudo`, and `lsblk` and
  `sync` on Linux, and its exit requires the README's flashing steps to run
  none of `lsblk`, `dd` or `sync`. The steps stay: `target/bootable.img` is
  the build's default image.
- `git config --global --add safe.directory` (nightly.yml) is in the refused
  git row: gix-config 0.58, which gix 0.85 depends on, adds a value to a
  section (`File::section_mut_or_create_new`, `SectionMut::push`) and writes
  the file (`File::write_to`), read in its source in ~/.cargo/registry.
- n2 is named as `github.com/evmar/n2` at `b1fead5`; the crates.io `n2` is an
  unrelated neural-network crate.
- macOS `sudo` stays admitted: sudo-rs's README at 89bae8a says it "is
  targeted for FreeBSD and Linux-based operating systems only".
- reviewer.md's Instructions carve-out also reaches CLAUDE.md's "a
  `CLAUDE.md` never grows".
- Deleted: "merges," from the admitted git row (gix 0.85 has
  `Repository::merge_trees` and `merge_commits`), the T14's Ubuntu point
  release, and src/main.rs's "They go when the build no longer needs a
  host.", false against the declaration's CMake and Ninja exits.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
@Japabu
Japabu added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit cd00be1 Sep 30, 2026
1 check passed
@Japabu
Japabu deleted the wt/toyos-deprule branch September 30, 2026 14:22
Japabu added a commit that referenced this pull request Sep 30, 2026
Three conflicts, each side accounted for:

- tests/metal-profile.toml: main added the rows of a third shared chunk
  (`shared-3`); this branch deletes the profile. The deletion stands. The
  chunk's numbers are new names to tests/metal/lenovo-20w0003amz.toml, so
  the next T14 run records them.
- src/metaldevices.rs, `unmet`'s doc: main's first paragraph (the kernel's
  records and blockd's lines, each table against its own writer), without
  the paragraph that cited the deleted profile, as this branch had it.
- tests/common/devices.rs, `on_metal`: main's `back.log()`, which blockd's
  table reads, without the profile load this branch deleted.

The record's rows: #536 renamed or deleted no boot, readback or device job
the record names, so no row moves and none goes.

The citations of the deleted profile go: the one #536 filed in the usbread
issue, the bare-name ones in the stop issue, and `devices.rs`'s doc on
`CONFIG`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu added a commit that referenced this pull request Sep 30, 2026
No conflict. The rust gitlink takes main's c4c65e3e8.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu added a commit that referenced this pull request Sep 30, 2026
#536 moved storage to userland file servers and deleted the kernel's
NVMe and FAT; #632 is prose and host-tool declarations.

One textual conflict, kernel/src/main.rs's imports: main dropped
`alloc::sync::Arc` and `drivers::nvme` with the mounts that used them,
this branch dropped `arch::smp` for the shared `crate::smp`. Both hold:
`use arch::{cpu, percpu};` and main's driver list.

Every other file both sides changed merged clean, each hunk read:
actuator.rs, xhci/mod.rs, quiesce.rs, syscall/dispatch.rs,
syscall/machine.rs, time.rs, log/mod.rs, src/build.rs,
tests/common/qemu.rs, tests/toyos.rs. None of main's new or moved code
names `arch::smp::`, `apic_id_for`, `hardware_id_of`, `AP_STARTED`,
`alloc_log_shard` or `park_ap`, and nothing this branch adds names the
deleted NVMe, FAT, iod, write-back or page-cache code. The merged tree's
diff against origin/main is this branch's diff against deb8fa3, file
for file and line for line, plus the rust gitlink main moved.

tests/virtsmpcase and tests/virtpaniccase keep logd and test-runner
alone, as main keeps tests/virtjobcase: the virt profiles attach no NVMe
for blockd and fsd to serve.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu added a commit that referenced this pull request Sep 30, 2026
Two conflicts, both in the negative-control feature lists:

- kernel/Cargo.toml and kernel-loom/Cargo.toml: #536 deletes
  `durability-settle-blind` with `durability.rs`; this branch rewrote the
  `device-irq-lossy` comment for the record's one read-modify-write, since
  the pass's `pending` swap is gone here. Both kept: the feature goes, the
  branch's comment stays.

Every other file both sides touched merged clean, and no hunk of this
branch lands on a site #536 deleted: the kernel's NVMe driver, FAT and
page cache it removes never took a claim's watch, `irq_ring` or the audio
watch. What moves under this branch's change is who holds a claim: #536
starts blockd ahead of netd, and blockd claims the NVMe controller the
kernel no longer drives, so the first claim init makes, slot 0, is
blockd's, and every interrupt that controller raises is now a handler's
post of a claim's watch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu added a commit that referenced this pull request Sep 30, 2026
Two conflicts, each resolved by accounting for both sides:

- README.md: main deleted "The last two lines are `rustc`'s and not
  ToyOS's" and this branch had moved it to "three"; main's deletion
  stands, and this branch's "Perl and `make`" line stays. The intro's
  "the four things `rustc`'s own bootstrap needs" is now six, so the
  count goes.
- issues/build/python-and-cc-are-declared.md: main deleted it into
  issues/build/the-build-runs-host-tools-outside-rust-and-qemu.md. This
  branch's hunk there declared Perl and `make` for the toolchain cargo's
  OpenSSL; both are rows of the new table, with the hunk's reasons and
  exit.

What main's new files said that this branch makes false:

- The host-tools table's git row cited `src/worktree.rs`, which this
  branch deletes, `src/sysroot.rs` as a runner of `git submodule`, which
  it no longer is, and a fetch of the fork that no longer happens; its
  nightly row named the build job's step by its old name.
- issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md
  named `sysroot::fork_checkout`, which this branch replaces. The same
  `ensure_submodule` call it names still runs in the linked worktrees
  this branch builds in, the shared checkout and a worktree's own
  `rust/`, so the issue stays open and now names them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu added a commit that referenced this pull request Sep 30, 2026
The rust gitlink conflicted: main pins the fork's c4c65e3e87a (#536's file
servers) and this branch 1c34252388d (LLVM's runtimes). It now pins
aca5f527fcb on the fork's main, the merge of the two, which differs from
c4c65e3e87a only in src/llvm-project.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant