Repository navigation
The ABI is free to change, and the kernel takes on only what userland cannot - #666
Merged
2 commits merged intoOct 1, 2026
Merged
2 commits merged into
2 commits merged into
Conversation
…el can do Two owner rulings of 2026-10-01, written into the prompts that govern agents. The ABI. "We can change system calls. We can remove them, add them, change them. I want to have the cleanest, most sustainable ABI." Three lines said the opposite and steered agents away from the ABI: - Root CLAUDE.md, "Syscall ABI": "Never add or change a syscall without discussion; a deleted syscall's number is retired, never reused." It now says the cleanest, most sustainable ABI beats convenience and a removed number is free. "read the code" goes with it: the Architecture section's header already says it. The line is shorter than the one it replaces. Workflow's "An ABI change lands with the work that needs it" stays. - implementer.md: "Never touch toyos-abi/src, toyos/src or userland/libc/src unless the brief is an ABI brief." Deleted. The brief's fence already bounds what an implementer touches. - reviewer.md, "What no gate reads": a BLOCKER for reusing a retired syscall, SYS_DEBUG action or inbox op number, or declaring a retired ABI name. Deleted. Connect-by-name and pid-as-authority stay banned by root CLAUDE.md's Capabilities paragraph, which bans the design whatever it is called. Kernel or server. In the symlink incident, libc's symlink needed "refuse an existing name". The implementer avoided the kernel change and returned ENOSYS, and the reviewer asked for the kernel to refuse the name. Neither asked whether the kernel should own symlinks at all; fsd already resolves them. The owner: "one less thing for the kernel to do… the reviewer and implementer should know we try to use userland programs instead of the kernel." - implementer.md: before adding or keeping kernel behaviour, ask whether a userland server can own it. When the clean design changes the ABI, change the ABI. - reviewer.md, "Fit": a BLOCKER each for a kernel addition or a kept kernel path a userland server could own, and for a design made worse to spare the ABI. The code still keeps retired numbers: retired_syscalls!, the "formerly …" entries in toyos-abi, four test sites that use syscall 26 as their logged refusal, and seven issue files that plan by retirement. That is outside this branch's fence, so it is filed as issues/design-debt/the-abi-still-keeps-retired-syscall-numbers.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
Japabu
marked this pull request as ready for review
October 1, 2026 07:44
Collaborator
Author
|
Review of BLOCKER
NOTE
REMOVE
SEND BACK |
Review of 066e1a0 on #666 sent the branch back. - CLAUDE.md's Kernel line said new additions are "discussed" and named the filesystem a kernel job, against both rulings. It now says the kernel takes on only what userland cannot, keeps the job list without the filesystem, and points at the Capabilities paragraph, whose "Not yet true of files" sentence already records the machine-wide tree the kernel still holds. 132 characters replace 135. - implementer.md's closed list of kernel jobs was a second declaration of the kernel's scope that the owner never gave; deleted, along with the restated rule, which root CLAUDE.md now carries. - "or keeping" (implementer.md) and "or a kernel path the branch keeps" (reviewer.md) made every kernel-side defect fix a BLOCKER outside its fence; deleted. A kernel refusal is still "a kernel addition", and an ENOSYS dodge is still "a design made worse to spare the ABI". - "a userland server" became "userland" in both files: the owner's loader move puts relocation in a Ring 3 loader in the target's own address space, which is userland but no server. - implementer.md says a clean design that reaches past the fence blocks the implementer, so the ABI sentence does not widen the fence. - The Syscall ABI line drops "add, change or remove syscalls", which "completely unstable" already says. - issues/design-debt/the-abi-still-keeps-retired-syscall-numbers.md names an owner and lists the retired device classes 3 and 4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L
63cb34a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two owner rulings of 2026-10-01, written into the prompts that govern agents. Root
CLAUDE.mdgoes from 16077 to 16036 bytes.The ABI is completely unstable
"We can change system calls. We can remove them, add them, change them. I want to have the cleanest, most sustainable ABI."
CLAUDE.md, "Syscall ABI": "completely unstable, read the code. Never add or change a syscall without discussion; a deleted syscall's number is retired, never reused." (138 characters) becomes "completely unstable. The cleanest, most sustainable ABI beats convenience; a removed number is free." (100). "read the code" goes because the Architecture section's header already says it. Workflow's "An ABI change lands with the work that needs it" stays.implementer.md: the "unless the brief is an ABI brief" gate ontoyos-abi/src,toyos/srcanduserland/libc/srcis deleted. The brief's fence already bounds what an implementer touches.reviewer.md, "What no gate reads": the BLOCKER for reusing a retired syscall,SYS_DEBUGaction or inbox op number, or for declaring a retired ABI name (SharedToken,services::connect), is deleted. RootCLAUDE.md's Capabilities paragraph ("No registry, no connect-by-name, no pid-as-authority") still bans those designs under any name.issues/design-debt/the-abi-still-keeps-retired-syscall-numbers.md.The kernel takes on only what userland cannot
This comes from the symlink incident. libc's
symlinkneeded to refuse an existing name. The implementer returned ENOSYS to avoid a kernel change, and the reviewer asked the kernel to refuse the name. Neither asked whether the kernel should own symlinks at all.CLAUDE.md, Architecture "Kernel": "minimal; new additions are discussed and justified. Resource management, scheduling, process lifecycle, filesystem, device arbitration." (135 characters) becomes "takes on only what userland cannot. Resource management, scheduling, process lifecycle, device arbitration; files: see Capabilities." (132). "Discussed" no longer stands between a clean design and a new syscall. The filesystem leaves the job list because file systems are userland servers by design. The kernel still holds the machine-wide tree (kernel/src/vfs.rs,tmpfs.rs,SYS_SYMLINK), so the line points at the Capabilities paragraph, whose "Not yet true of files" sentence already records that. It adds no second record.implementer.md, a paragraph under "The brief is a fence": before adding kernel behaviour, ask whether userland can own it. When the clean design changes the ABI, change the ABI. A clean design that reaches past the fence blocks the implementer, so this paragraph does not widen the fence. The rule itself is stated once, in rootCLAUDE.md. There is no list of kernel jobs here.reviewer.md, "Fit": one BLOCKER for a kernel addition that userland could own. Another for a design made worse to spare the ABI. Both halves of the incident are covered: a kernel refusal is a kernel addition, and the ENOSYS dodge is a worse design. A branch that fixes a defect in kernel code that will leave the kernel later is not blocked for keeping it.Gates
cargo run -- --ci hostonec166f1b4: EXIT=0.Unsure
🤖 Generated with Claude Code
https://claude.ai/code/session_016t9wjdQkB8SH7bmfUoiy6L