Skip to content

A worktree's fork checkout is made and moved under its build lock, and ensure_shallow_fork initialises no submodule in a linked worktree - #683

Merged
Japabu merged 7 commits into
mainfrom
wt/toyos-forkmove
Oct 3, 2026
Merged

Japabu merged 7 commits into
mainfrom
wt/toyos-forkmove

Conversation

@Japabu

@Japabu Japabu commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

sysroot::fork_checkout makes a linked worktree's rust/, and moves one that is behind its pin, each as one Held::act_if(Scope::Worktree, …) on the build lock sysroot::ensure already receives. The decision and the act are one exclusive section, as build::invalidate_stale's cleans are.

Before, every build decided and acted under the shared lock. The guest suite's workers reach fork_checkout on their own threads and a second process reaches it whenever it starts, so git worktree add or git checkout --detach ran on one checkout from several movers at once, and a build arriving inside the git worktree add took a checkout git was still writing.

Closes issues/build/a-suites-first-run-after-the-fork-pin-moves-races-its-own-checkout.md and issues/build/a-worktrees-first-wide-run-reds-on-the-fork-checkout-it-is-still-making.md, two records of this one defect. git grep of both slugs over the tree at c402baf6c finds nothing.

Decisions

  • The lock the tree has, and no new one. flock is per open file description, so twelve workers' Helds exclude each other as two processes do. No call site is added: src/main.rs and tests/toyos.rs are main's.
  • Two act_ifs. Making and moving are two decisions, each asked again under the exclusive lock, as toolchain::ensure's steps are.
  • licence::std_library holds the worktree's lock shared for the call. It reads the fork's library/ after the call without it: nothing moves a checkout that is at its pin.
  • ensure_shallow_fork refuses a linked worktree. It is a CI runner's path, and std_library sent any fork checkout without library/Cargo.toml there. The lock closes the reader that arrives while the checkout is being made. It does not close the reader that finds what a killed maker left, and what that costs is measured below: git in the primary's rust/ stops working.
  • A plain --list makes and moves nothing, as on main.

What it does not fix

  • A build still takes a fork checkout a killed git worktree add left as made, as on main: issues/build/a-fork-checkout-a-killed-git-worktree-add-left-is-taken-as-made.md. The licence gate refuses the remains by name only for a kill before library/Cargo.toml is written: licence::std_library reaches ensure_shallow_fork only without that file, and past it the gate reads what library/ holds and runs no git submodule. The issue also names the builder's own kill, with its git worktree add still writing and the lock freed, as read from the code and unmeasured.
  • issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md is untouched, and its three arms stand.

Checks

Build-system concurrency over git state every worktree shares. The negative control is the whole change reverted onto cfd4931a6: git diff cfd4931a6 origin/main -- src tests, applied, run and reversed. The oracle is git: it refuses a second writer on its own (already exists, index.lock), it records a half-made worktree itself (locked initializing), and its trace says which commands ran.

The head is c402baf6c. Everything below but the first gate was measured at cfd4931a6, which the head differs from by one host test's name, a clause deleted from that test's doc, and the new issue's record: git diff --stat cfd4931a6 c402baf6c is src/sysroot.rs +4 −4, inside its #[cfg(test)] module, and the issue +23 −8.

In this worktree, at cfd4931a6

rust/ before tree command exit result load, 14 cores
empty stub cfd4931a6 cargo test --test toyos-build -- --list 0 298 names; rust/ still the empty stub 21
empty stub cfd4931a6 cargo test --test toyos-build -- screen_ 0 3 passed; one Making …; the other two workers took the lock 4.6 s later and made nothing 21
one commit behind the pin cfd4931a6 -- --list 0 HEAD not moved 19
one commit behind the pin cfd4931a6 -- screen_ 0 3 passed; one checked it out 19
empty stub cfd4931a6 two processes started together, -- screen_panic_muted and -- screen_fatal_halt_composited 0 and 0 one Making … between them; the other took the lock 5.2 s later 19
empty stub cfd4931a6 the same two, the second started when rust/.git appeared (1 of 37 top-level entries written) 0 and 0 the second printed waiting for the build lock (shared, test image) — held by pid … (make the fork checkout) 20
one commit behind the pin control -- screen_ 1 1 passed, 2 failed on Unable to create '…/worktrees/rust/index.lock': File exists 22
empty stub control -- screen_ 1 1 passed, 2 failed on fatal: '…/rust' already exists; three Making … 22

After every row but the two --list ones the checkout is at its pin with an empty git status, registered once in the primary's fork, and core.worktree of the primary's fork and of its library/backtrace is what it was. Each row's log is in the comment headed "Runs in the worktree".

In a fixture, never the real fork

A temporary host test (its patch is in the comment headed "Patches and fixture runs", #683 (comment)) builds sysroot::tests::two_pins and checks the fork's last file, x.py, out through a filter that waits, so a real git worktree add stops with rust/.git and HEAD written and x.py not.

tree reader what it did git submodule ran git in the fixture primary's rust/ afterwards
cfd4931a6 licence::std_library, while the maker is held waited on the lock (held by pid … (make the fork checkout)), and returned the whole checkout after the release 0 times runs
control the same returned while the maker was held once: git submodule--helper update --init --depth=1 -- rust git status exits 128, cannot chdir to '../../../../../../linked/rust'
cfd4931a6 std_library, on what a maker killed with SIGKILL left refused: … is a linked worktree's fork checkout and is not whole: no submodule is initialised there 0 times runs
a8dcbccb2, the lock without the guard the same returned Ok once, the same command exits 128, the same

The second row is main's code: by it, a --ci host whose licences step lands inside another process's git worktree add in the same worktree breaks git in the primary's rust/.

Host tests and mutations

  • sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout releases twelve threads, each holding its own Held, from one Barrier into fork_checkout, on a checkout not made and then on one behind its pin. Each returns it at the pin with library/backtrace there. What it sees that reading cannot: git under twelve concurrent callers, and that the Helds of one process's threads exclude each other.
  • sysroot::tests::ensure_shallow_fork_initialises_no_submodule_in_a_linked_worktree calls ensure_shallow_fork in a linked worktree whose rust/ is a checkout with no file. It asserts first that git in the primary's fork still runs, then the refusal. What it sees that reading cannot: what git does to the primary when that command runs there. At cfd4931a6, and in the logs taken there, its name is a_linked_worktree_initialises_no_submodule.
  • a_worktree_pinning_another_fork_commit_gets_its_own_checkout now asserts HEAD stays at the agent's own commit when the checkout is ahead of its pin.
mutation at cfd4931a6 test exit
both act_ifs replaced by decide-then-act under no lock twelve_builds_… 101, 5 runs of 5
a checkout ahead of its pin is moved (head != pinned || !ahead) a_worktree_pinning_… 101, a checkout ahead of its pin was moved
the guard in ensure_shallow_fork removed a_linked_worktree_…, the head's ensure_shallow_fork_initialises_… 101, on git's cannot chdir

Each was applied with git apply --check, built, run and reversed, leaving git status --porcelain empty. The patches and logs are in the comment headed "Patches and fixture runs", #683 (comment).

Gates

head command exit
c402baf6c cargo run -- --ci host 0, 67 steps; test sysroot::tests::ensure_shallow_fork_initialises_no_submodule_in_a_linked_worktree ... ok is its line 532
cfd4931a6 cargo run -- --ci host 0, 67 steps
cfd4931a6 cargo test --test toyos-build, from an empty stub, 12 wide 0, 26 of 26; one Making …, eleven workers took the lock 4.6 to 4.7 s later
cfd4931a6 cargo run -- --build-only, from a checkout one commit behind its pin 0; one checked it out

The log of the first is ~/.claude/jobs/2280e09e/tmp/scratchpad/orch/683-named/ci-host.log on the development machine; the logs at cfd4931a6 are in the comment headed "Gate logs". The guest suite and the image build were not run again at c402baf6c: neither compiles a #[cfg(test)] module of src/, and the head changes nothing else under src/ or tests/.

Net

git diff --shortstat origin/main...HEAD: 7 files, +195 −135.

  • Production +89 −65: src/sysroot.rs +73 −59 above its test module, of which +26 −12 is not indentation; src/lib.rs +9 −1, the guard; src/buildlock.rs +5 −4, its header and Scope::Worktree's doc; src/licence.rs +2 −1.
  • Tests +53 −6, all in src/sysroot.rs.
  • Issues +53 −64.

Unsure of

  • The runner's arm of ensure_shallow_fork, a primary checkout with no rust/x.py, gained one toolchain::owner call and was read, not run, on this machine: no checkout here is in that state. The hosted host and toolchain checks are its measurement. A draft skips them, and they run when the pull request is marked ready and again in its merge group, so a red in that arm stops this landing before it reaches main.
  • The unlocked mutation reds twelve_builds_… because at least two of twelve threads decide before one has acted, which is a race in the mutated code: red in 16 runs of 16 over the round that ended at cfd4931a6.
  • The control's rows ran at load average 22 and cfd4931a6's at 19 to 21, of 14 cores.

🤖 Generated with Claude Code

https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm

Japabu and others added 2 commits October 3, 2026 11:49
`sysroot::fork_checkout` made a linked worktree's `rust/` and moved one
behind its pin, and every build called it: the guest suite's workers reach
`toolchain::ensure` on their own threads, so the first run of a new worktree,
and the first after a merge moved the gitlink, ran `git worktree add` or
`git checkout --detach` on one checkout from every worker at once.

Measured at ec7de74 with `cargo test --test toyos-build -- screen_`, three
workers, on 14 cores:

- a new worktree's first run, at load average 74, exited 1 with 2 of 3 red:
  two workers each ran `git worktree add`, one died on `fatal: '…/rust'
  already exists`, and the third read the checkout the winner was still
  writing and died in `llvm::refuse_uncommitted_bootstrap` on every file of
  `src/bootstrap` as `D`;
- with the checkout one commit behind its pin, at load average 23, it exited
  1 with 2 of 3 red on `Unable to create '…/worktrees/rust2/index.lock': File
  exists`.

The move is now `sysroot::make_fork_checkout`, which a process calls once
where it starts, before it has a second thread: `cargo run` beside the
primary's `ensure_submodules`, the harness before its first build, and the
licence gate. `fork_checkout` is what a build calls, and it moves nothing: a
checkout that is not at the pin or ahead of it is refused by name, which is
what a build sees when the pin moves under a run. So no worker is a mover and
there is nothing to lock.

`a_build_reads_the_fork_checkout_and_never_moves_it` starts twelve builds at
once against a checkout that is not made and against one behind its pin: each
is refused and the checkout stands as it was, and all twelve read the one
`make_fork_checkout` made and the one it moved. With `fork_checkout` calling
`make_fork_checkout` again it exits 101, each of the twelve running
`git worktree add`.

Closes issues/build/a-suites-first-run-after-the-fork-pin-moves-races-its-own-checkout.md
and issues/build/a-worktrees-first-wide-run-reds-on-the-fork-checkout-it-is-still-making.md,
two records of this one defect. The `git submodule update --init
library/backtrace` arm
issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md
records is the same code under the mover's new name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
…fork checkout

One process is one mover now; two are still two. Measured with the mover
called where a process starts (020a97d), from an empty `rust/` stub at load
average 36 of 14 cores: two `cargo test --test toyos-build` started together,
one on `screen_panic_muted` and one on `screen_fatal_halt_composited`, both
printed `Making …/rust a fork checkout`, and they exited 101 and 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Mutation: a build moves the checkout again (fork_checkout calls make_fork_checkout), applied with git apply --check and git apply at e38dbc314, run, and reversed with git apply -R; git status --porcelain --ignore-submodules=none printed nothing after.

--- a/src/sysroot.rs
+++ b/src/sysroot.rs
@@ -513,6 +513,7 @@
 /// process builds at once, so a build moves no checkout: one that is not at the
 /// commit this tree pins or ahead of it is refused by name.
 pub fn fork_checkout(root: &Path) -> PathBuf {
+    make_fork_checkout(root);
     let fork = root.join("rust");
     match toolchain::owner(root) {
         Owner::Us => {}

cargo test --lib a_build_reads_the_fork_checkout_and_never_moves_it: exit 101. Its output, Compiling lines dropped and lines cut at 400 characters:

    Finished `test` profile [optimized + debuginfo] target(s) in 5.11s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)

running 1 test
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
Preparing worktree (detached HEAD c800e0f)
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
Preparing worktree (detached HEAD c800e0f)
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
Preparing worktree (detached HEAD c800e0f)
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust' already exists
fatal: Unable to create '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/.git/modules/rust/worktrees/rust/index.lock': File exists.

Another git process seems to be running in this repository, or the lock file may be stale
fatal: Unable to create '/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/.git/modules/rust/worktrees/rust/index.lock': File exists.

Another git process seems to be running in this repository, or the lock file may be stale
fatal: Could not write new index file.
test sysroot::tests::a_build_reads_the_fork_checkout_and_never_moves_it ... FAILED

failures:

---- sysroot::tests::a_build_reads_the_fork_checkout_and_never_moves_it stdout ----
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)
09:52:22 Making /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust a fork checkout at c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87 (a git worktree of the primary's)

thread '<unnamed>' (91531902) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace

thread '<unnamed>' (91531901) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531911) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531904) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531906) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531908) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531912) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531905) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531910) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531903) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531909) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread '<unnamed>' (91531907) panicked at src/sysroot.rs:1065:5:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed

thread 'sysroot::tests::a_build_reads_the_fork_checkout_and_never_moves_it' (91530463) panicked at src/sysroot.rs:1530:17:
git ["worktree", "add", "--detach", "/private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/linked/rust", "c800e0fae85fbfd8dd5eb3d7b609af94a7ba3d87"] in /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-49840-0/fork-builds-0/primary/rust failed


failures:
    sysroot::tests::a_build_reads_the_fork_checkout_and_never_moves_it

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 402 filtered out; finished in 0.72s

error: test failed, to rerun pass `--lib`

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Run logs, with the checkouts' parent directory written …/. Each is the command's whole output with Compiling, Updating files, [build-lock], Blocking waiting and blank lines dropped and lines cut at 400 characters; the exit is the command's own.

Base ec7de748c, rust/ an empty stub: cargo test --test toyos-build -- screen_

EXIT=1. Load: 11:31 up 3 days, 23:16, 3 users, load averages: 73.96 30.54 16.26. 300 D src/bootstrap/… lines dropped: every file of src/bootstrap, twice.

    Finished `test` profile [optimized + debuginfo] target(s) in 36.40s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)

09:32:29 running 3 tests, 12 wide

09:32:29   RUN   screen_panic_muted
09:32:29   RUN   screen_fatal_behind_a_painter
09:32:29   RUN   screen_fatal_halt_composited
09:32:29   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
09:32:29   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
09:32:29   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
09:32:30 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
09:32:30 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
Preparing worktree (detached HEAD 95960d6c214)
fatal: '…/toyos-forkmove/rust' already exists

thread '<unnamed>' (90932430) panicked at src/sysroot.rs:1037:5:
git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
09:32:30   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (98ms)
09:32:30 FAIL screen_fatal_halt_composited: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
09:32:30   FAIL  screen_fatal_halt_composited  (99ms)

thread '<unnamed>' (90932429) panicked at src/llvm.rs:263:5:
…/toyos-forkmove/rust/src/bootstrap holds changes no commit does, and an LLVM is keyed on the tree its commit records: commit them, and the build makes the LLVM they name

09:32:30   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (247ms)
09:32:30 FAIL screen_panic_muted: …/toyos-forkmove/rust/src/bootstrap holds changes no commit does, and an LLVM is keyed on the tree its commit records: commit them, and the build makes the LLVM they name

09:32:30   FAIL  screen_panic_muted  (100ms)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
09:32:43 external deps changed: cleaning …/toyos-forkmove/kernel
     Removed 0 files
09:32:43 external deps changed: cleaning …/toyos-forkmove/bootloader
     Removed 0 files
09:32:43 external deps changed: cleaning …/toyos-forkmove/userland
     Removed 0 files
09:33:21   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (52s)
09:33:28   PASS  screen_fatal_behind_a_painter  (7s)
09:33:28   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
09:33:28   --- irq census: 1 guest(s) reported, 320 interrupt(s), 282 of them on cpu0 (88.1%); per guest cpu0's share is median 88.1% p90 88.1% max 88.1%
09:33:28       timer            50 (15.6% of all), 42.0% of them on cpu0
09:33:28       xhci            134 (41.9% of all), 100.0% of them on cpu0
09:33:28       userdev         113 (35.3% of all), 100.0% of them on cpu0
09:33:28       tlb              23 (7.2% of all), 60.9% of them on cpu0
09:33:28       widest guest reported 2 cpu(s)

09:33:28 host: fastest boot 3549 ms against the reference 1424 ms — liveness ceilings paid at 2.49x
09:33:28 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:33:28 failures:
09:33:28     screen_fatal_halt_composited: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
09:33:28     screen_panic_muted: …/toyos-forkmove/rust/src/bootstrap holds changes no commit does, and an LLVM is keyed on the tree its commit records: commit them, and the build makes the LLVM they name

09:33:28 test result: FAILED. 1 passed, 2 failed, 0 invalidated, 3 total (58.7s; workers: 52s building, 7s testing)
09:33:28 [toyos] this red run's serial logs are kept at …/toyos-forkmove/target/red-run-serial/toyos-tmp-89762-0
error: test failed, to rerun pass `--test toyos-build`

Caused by:
  process didn't exit successfully: `…/toyos-forkmove/target/debug/deps/toyos_build-8802c76dc0791521 screen_` (exit status: 1)

020a97dd6, rust/ an empty stub: the same command

EXIT=0. Load: 11:50 up 3 days, 23:34, 3 users, load averages: 31.38 27.97 24.87.

    Finished `test` profile [optimized + debuginfo] target(s) in 12.49s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
09:50:13 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)

09:50:25 running 3 tests, 12 wide

09:50:25   RUN   screen_fatal_behind_a_painter
09:50:25   RUN   screen_panic_muted
09:50:25   RUN   screen_fatal_halt_composited
09:50:25   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
09:50:25   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
09:50:25   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
09:50:28 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
09:50:28 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
09:50:28   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (3s)
09:50:28   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (3s)
09:50:28   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (3s)
09:50:34   PASS  screen_panic_muted  (6s)
09:50:40   PASS  screen_fatal_behind_a_painter  (12s)
09:50:41   [panic] the fatal report is on the panel and sealed in the black box (14224 bytes)
09:50:41   PASS  screen_fatal_halt_composited  (14s)
09:50:41   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
09:50:41   --- irq census: 1 guest(s) reported, 337 interrupt(s), 230 of them on cpu0 (68.2%); per guest cpu0's share is median 68.2% p90 68.2% max 68.2%
09:50:41       timer           129 (38.3% of all), 34.1% of them on cpu0
09:50:41       xhci            126 (37.4% of all), 100.0% of them on cpu0
09:50:41       userdev          59 (17.5% of all), 100.0% of them on cpu0
09:50:41       tlb              23 (6.8% of all), 4.3% of them on cpu0
09:50:41       widest guest reported 2 cpu(s)

09:50:41 host: fastest boot 8266 ms against the reference 1424 ms — liveness ceilings paid at 5.80x
09:50:41 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:50:41 test result: ok. 3 passed, 3 total (16.2s; workers: 8s building, 31s testing)

Base ec7de748c, rust/ one commit behind the pin: the same command

EXIT=1. Load: 11:44 up 3 days, 23:28, 3 users, load averages: 22.66 26.71 23.02.

    Finished `test` profile [optimized + debuginfo] target(s) in 0.10s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)

09:44:02 running 3 tests, 12 wide

09:44:02   RUN   screen_panic_muted
09:44:02   RUN   screen_fatal_halt_composited
09:44:02   RUN   screen_fatal_behind_a_painter
09:44:02   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
09:44:02   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
09:44:02   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
fatal: Unable to create '…/toyos/.git/modules/rust/worktrees/rust2/index.lock': File exists.

Another git process seems to be running in this repository, or the lock file may be stale

thread '<unnamed>' (91249428) panicked at src/sysroot.rs:1037:5:
git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
09:44:02   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (543ms)
09:44:02 FAIL screen_panic_muted: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
09:44:02   FAIL  screen_panic_muted  (34ms)
fatal: Unable to create '…/toyos/.git/modules/rust/worktrees/rust2/index.lock': File exists.

Another git process seems to be running in this repository, or the lock file may be stale

thread '<unnamed>' (91249427) panicked at src/sysroot.rs:1037:5:
git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
09:44:02   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (628ms)
09:44:02 FAIL screen_fatal_behind_a_painter: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
09:44:02   FAIL  screen_fatal_behind_a_painter  (3ms)
09:44:02 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out
09:44:38 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
09:44:38 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
09:44:38   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (36s)
09:44:47   [panic] the fatal report is on the panel and sealed in the black box (14215 bytes)
09:44:47   PASS  screen_fatal_halt_composited  (9s)
09:44:47   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

09:44:47 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:44:47 failures:
09:44:47     screen_panic_muted: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
09:44:47     screen_fatal_behind_a_painter: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed

09:44:47 test result: FAILED. 1 passed, 2 failed, 0 invalidated, 3 total (45.2s; workers: 37s building, 9s testing)
09:44:47 [toyos] this red run's serial logs are kept at …/toyos-forkmove/target/red-run-serial/toyos-tmp-91140-0
error: test failed, to rerun pass `--test toyos-build`

Caused by:
  process didn't exit successfully: `…/toyos-forkmove/target/debug/deps/toyos_build-8802c76dc0791521 screen_` (exit status: 1)

e38dbc314, rust/ one commit behind the pin: the same command

EXIT=0. Load: 11:52 up 3 days, 23:36, 3 users, load averages: 24.40 27.52 25.29.

    Finished `test` profile [optimized + debuginfo] target(s) in 1.73s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
09:52:34 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out

09:52:34 running 3 tests, 12 wide

09:52:34   RUN   screen_fatal_behind_a_painter
09:52:34   RUN   screen_fatal_halt_composited
09:52:34   RUN   screen_panic_muted
09:52:34   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
09:52:34   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
09:52:34   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
09:52:36   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (2s)
09:52:36 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
09:52:36 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
09:52:36   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (2s)
09:52:36   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (2s)
09:52:38   PASS  screen_panic_muted  (3s)
09:52:42   PASS  screen_fatal_behind_a_painter  (6s)
09:52:44   [panic] the fatal report is on the panel and sealed in the black box (14211 bytes)
09:52:44   PASS  screen_fatal_halt_composited  (8s)
09:52:44   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
09:52:44   --- irq census: 1 guest(s) reported, 335 interrupt(s), 286 of them on cpu0 (85.4%); per guest cpu0's share is median 85.4% p90 85.4% max 85.4%
09:52:44       timer            63 (18.8% of all), 36.5% of them on cpu0
09:52:44       xhci            138 (41.2% of all), 100.0% of them on cpu0
09:52:44       userdev         111 (33.1% of all), 100.0% of them on cpu0
09:52:44       tlb              23 (6.9% of all), 60.9% of them on cpu0
09:52:44       widest guest reported 2 cpu(s)

09:52:44 host: fastest boot 3099 ms against the reference 1424 ms — liveness ceilings paid at 2.18x
09:52:44 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:52:44 test result: ok. 3 passed, 3 total (10.4s; workers: 6s building, 17s testing)

020a97dd6, rust/ an empty stub, two processes started together: cargo test --test toyos-build -- screen_panic_muted

EXIT=101. Load: 11:51 up 3 days, 23:35, 3 users, load averages: 35.88 29.67 25.69.

    Finished `test` profile [optimized + debuginfo] target(s) in 0.18s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
09:51:00 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
fatal: '…/toyos-forkmove/rust' already exists

thread 'main' (91511731) panicked at src/sysroot.rs:1064:5:
git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
09:51:00 [toyos] this red run's serial logs are kept at …/toyos-forkmove/target/red-run-serial/toyos-tmp-45610-0
error: test failed, to rerun pass `--test toyos-build`

… and cargo test --test toyos-build -- screen_fatal_halt_composited

EXIT=0.

    Finished `test` profile [optimized + debuginfo] target(s) in 0.16s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
09:51:00 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)

09:51:09 running 1 tests, 12 wide

09:51:09   RUN   screen_fatal_halt_composited
09:51:09   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
09:51:11 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
09:51:11 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
09:51:11   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (2s)
09:51:19   [panic] the fatal report is on the panel and sealed in the black box (14206 bytes)
09:51:19   PASS  screen_fatal_halt_composited  (8s)
09:51:19   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

09:51:19 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:51:19 test result: ok. 1 passed, 1 total (10.2s; workers: 2s building, 8s testing)

@Japabu

Japabu commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator Author

Gate logs at e38dbc314.

cargo test --test toyos-build, rust/ an empty stub

EXIT=0. Load: 11:52 up 3 days, 23:37, 3 users, load averages: 19.64 26.25 24.88.

    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
09:52:54 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)

09:53:04 running 26 tests, 12 wide

09:53:04   RUN   iommu_virtio_platform
09:53:04   RUN   nested_nmi_is_loud
09:53:04   RUN   screen_panic_muted
09:53:04   RUN   virt_early_panic
09:53:04   RUN   screen_fatal_behind_a_painter
09:53:04   RUN   screen_fatal_halt_composited
09:53:04   RUN   virt_early_fault
09:53:04   RUN   virt_el2_drop
09:53:04   RUN   virt_user_mode
09:53:04   RUN   virt_timer_preempts
09:53:04   BUILD aarch64 abuse_readonly_copyout of tests/toyos-rust-tests, for virt_timer_preempts
09:53:04   RUN   virt_irq_storm
09:53:04   RUN   machine_shutdown
09:53:04   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_irq_storm
09:53:04   BUILD x86_64 kernel, loader, ROOT of tests/testcases, for machine_shutdown
09:53:04   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
09:53:04   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_panic
09:53:04   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for nested_nmi_is_loud
09:53:04   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_el2_drop
09:53:04   BUILD aarch64 kernel, loader, ROOT of tests/testcases, for virt_user_mode
09:53:04   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_fault
09:53:05   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
09:53:05   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
09:53:05   BUILD x86_64 kernel, loader, ROOT of tests/netcase, for iommu_virtio_platform
09:53:38   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (34s)
09:53:43   PASS  screen_panic_muted  (5s)
09:53:43   RUN   virt_timer_floor
09:53:43   BUILD aarch64 ROOT of tests/testcases, for virt_timer_floor
09:53:45   BUILT aarch64 kernel, loader, ROOT of tests/testcases, for virt_user_mode  (40s)
09:53:45   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_irq_storm  (41s)
09:53:45   BUILT x86_64 kernel, loader, ROOT of tests/testcases, for machine_shutdown  (41s)
09:53:45   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_panic  (41s)
09:53:45   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for nested_nmi_is_loud  (41s)
09:53:46 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
09:53:46 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
09:53:46   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (41s)
09:53:46   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (41s)
09:53:46 external deps changed: cleaning …/toyos-forkmove/tests/toyos-rust-tests
09:53:46   PASS  virt_early_panic  (551ms)
09:53:46   RUN   virt_fp_isolation
     Removed 0 files
09:53:48   PASS  virt_user_mode  (3s)
09:53:48   RUN   virt_first_entry
09:53:50   [virt] [kernel 4.102 cpu0] irq-storm: PASS sgis=414481/414481 ticks=1000: the timer fired through the flood, and every SGI sent was taken
09:53:50   PASS  virt_irq_storm  (5s)
09:53:50   RUN   virt_unmap_touch
09:53:51   [nmi] nested: [nmi] NESTED NMI on cpu 0: a second NMI entered while IST2 was still in use.
09:53:51   PASS  nested_nmi_is_loud  (6s)
09:53:51   RUN   virt_debug_refused
09:53:51   [power] shutdown: QEMU stopped the guest for guest-shutdown
09:53:51   PASS  machine_shutdown  (6s)
09:53:51   RUN   virt_readonly_copyout
09:53:56   PASS  screen_fatal_behind_a_painter  (10s)
09:53:56   RUN   virt_mask_windows
09:53:56   BUILD aarch64 kernel mask-windows, ROOT of tests/virtsmpcase, for virt_mask_windows
09:53:58   [panic] the fatal report is on the panel and sealed in the black box (14229 bytes)
09:53:58   PASS  screen_fatal_halt_composited  (12s)
09:53:58   RUN   virt_smp
09:53:58   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_smp
09:54:06   BUILT aarch64 abuse_readonly_copyout of tests/toyos-rust-tests, for virt_timer_preempts  (62s)
09:54:06   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_fault  (62s)
09:54:06   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_el2_drop  (62s)
09:54:06   BUILT aarch64 ROOT of tests/testcases, for virt_timer_floor  (23s)
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_readonly_copyout
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_unmap_touch
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_timer_preempts
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_debug_refused
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_first_entry
09:54:06   BUILD aarch64 ROOT of tests/virtjobcase, for virt_fp_isolation
09:54:08   PASS  virt_early_fault  (1s)
09:54:08   RUN   virt_el1_smp
09:54:08   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_el1_smp
09:54:08   PASS  virt_el2_drop  (2s)
09:54:08   RUN   virt_failed_ap_leaves_no_hole
09:54:08   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_failed_ap_leaves_no_hole
09:54:10   [virt] [kernel 1.545 cpu0] timer-floor: PASS span=10000 floor=10000 ticks: the comparator past the counter it was set from
09:54:10   PASS  virt_timer_floor  (4s)
09:54:10   RUN   virt_fatal_halts_the_others_first
09:54:10   BUILD aarch64 panic_halts_first of tests/toyos-rust-tests, for virt_fatal_halts_the_others_first
09:54:19   BUILT x86_64 kernel, loader, ROOT of tests/netcase, for iommu_virtio_platform  (75s)
09:54:20   BUILT aarch64 ROOT of tests/virtjobcase, for virt_fp_isolation  (13s)
09:54:20   BUILT aarch64 panic_halts_first of tests/toyos-rust-tests, for virt_fatal_halts_the_others_first  (10s)
09:54:20   BUILD aarch64 ROOT of tests/virtpaniccase, for virt_fatal_halts_the_others_first
09:54:20   BUILT aarch64 kernel mask-windows, ROOT of tests/virtsmpcase, for virt_mask_windows  (24s)
09:54:20   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_smp  (22s)
09:54:20   BUILT aarch64 ROOT of tests/virtjobcase, for virt_unmap_touch  (14s)
09:54:20   BUILT aarch64 ROOT of tests/virtjobcase, for virt_first_entry  (14s)
09:54:20   BUILT aarch64 ROOT of tests/virtjobcase, for virt_readonly_copyout  (14s)
09:54:21   BUILT aarch64 ROOT of tests/virtjobcase, for virt_timer_preempts  (14s)
09:54:21   BUILT aarch64 ROOT of tests/virtjobcase, for virt_debug_refused  (14s)
09:54:21   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_el1_smp  (13s)
09:54:21   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_failed_ap_leaves_no_hole  (13s)
09:54:22   BUILT aarch64 ROOT of tests/virtpaniccase, for virt_fatal_halts_the_others_first  (2s)
09:54:24   [virt] {2.560 pid=5 test-runner} fp_isolation: v0-v31, FPCR and FPSR survived 3 switches to a thread that loads another state
09:54:24   PASS  virt_fp_isolation  (25s)
09:54:24   RUN   virt_reboot
09:54:24   BUILD aarch64 ROOT of tests/virtrebootcase, for virt_reboot
09:54:24   [virt] {2.384 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:24   [windows] cpu0 irqs_off_ns=48681000 preempt_off_ns=34166000
09:54:24   [windows] cpu1 irqs_off_ns=58299000 preempt_off_ns=4265000
09:54:24   [windows] cpu2 irqs_off_ns=3741000 preempt_off_ns=15472000
09:54:24   [windows] cpu3 irqs_off_ns=97410000 preempt_off_ns=55264000
09:54:24   [windows] cpu4 irqs_off_ns=36975000 preempt_off_ns=36966000
09:54:24   [windows] cpu5 irqs_off_ns=7801000 preempt_off_ns=7796000
09:54:24   [windows] cpu6 irqs_off_ns=2723000 preempt_off_ns=12766000
09:54:24   [windows] cpu7 irqs_off_ns=71901000 preempt_off_ns=71886000
09:54:24   PASS  virt_mask_windows  (4s)
09:54:24   RUN   virt_off_names_the_cpus_left_on
09:54:24   [virt] {2.476 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:24   [virt] 8 CPUs entered at EL2, started through SMC, and scheduling
09:54:24   [virt] stop: 5 of 5 userland thread(s) stopped across 8 cpu(s) in 0 ms of a 2010 ms budget over 1 sweep(s), 0 of 0 userland block operation(s) still open; every CPU but 0x0 called CPU_OFF, then 0x0 SYSTEM_OFF
09:54:24   PASS  virt_smp  (4s)
09:54:24   RUN   virt_reboot_refused_without_psci
09:54:24   BUILD aarch64 ROOT of tests/virtrebootcase, for virt_reboot_refused_without_psci
09:54:25   [iommu] headless: 3 virtio function(s) behind a unit = true, the audio function 00:04.0 among them
09:54:25   [virt] {2.431 pid=6 test-runner} first_entry: x1-x30 were zero at a new thread's first instruction
09:54:25   [virt] {2.146 pid=4 test-runner} preempt: the counting thread was preempted twice, at counts 4276625 and 8292308
09:54:25   PASS  virt_first_entry  (23s)
09:54:25   PASS  virt_timer_preempts  (4s)
09:54:26   [virt] {3.337 pid=7 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:26   PASS  virt_unmap_touch  (21s)
09:54:26   [virt] {2.372 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:26   [virt] 8 CPUs entered at EL1, started through HVC, and scheduling
09:54:26   [virt] stop: 5 of 5 userland thread(s) stopped across 8 cpu(s) in 0 ms of a 2010 ms budget over 1 sweep(s), 0 of 0 userland block operation(s) still open; every CPU but 0x0 called CPU_OFF, then 0x0 SYSTEM_OFF
09:54:26   PASS  virt_el1_smp  (5s)
09:54:26   [virt] {3.292 pid=17 test-runner} a syscall writes only where its caller could store
09:54:26   PASS  virt_readonly_copyout  (20s)
09:54:26   [virt] {3.054 pid=16 test-runner} debug_refused: SYS_DEBUG's double fault and TLB acknowledgement delay were refused
09:54:26   PASS  virt_debug_refused  (20s)
09:54:26   BUILT aarch64 ROOT of tests/virtrebootcase, for virt_reboot  (2s)
09:54:27   BUILT aarch64 ROOT of tests/virtrebootcase, for virt_reboot_refused_without_psci  (2s)
09:54:27   [panic] the fatal path on cpu3 left every other CPU halted with interrupts masked
09:54:27   PASS  virt_fatal_halts_the_others_first  (5s)
09:54:29   [virt] {2.083 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:29   [iommu] headless-no-iommu: 2 virtio function(s) behind a unit = false, the audio function 00:04.0 among them; the NIC's claim refused for want of a domain
09:54:30   [virt] Rebooting., then one SYSTEM_RESET, and QEMU stopped for guest-reset
09:54:30   PASS  virt_reboot  (3s)
09:54:30   [virt] reboot: this machine has no reset this kernel performs — refused, and the job ended exit 1
09:54:30   PASS  virt_reboot_refused_without_psci  (3s)
09:54:30   [virt] {6.919 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
09:54:30   [virt] a non-last AP never started and the dense machine ran its job
09:54:30   PASS  virt_failed_ap_leaves_no_hole  (9s)
09:54:33   [iommu] declined: [kernel 0.267 cpu0] virtio-sound: NOT INITIALISED — PCI 00:04.0 refused the feature set 0x100000000 the driver accepted, leaving DEVICE_STATUS=0x3 without FEATURES_OK
09:54:33   PASS  iommu_virtio_platform  (14s)
09:54:34   [virt] [6, 7] left on and named; the rest CPU_OFF, then 0x0 SYSTEM_OFF; 4603 PSCI call(s) traced
09:54:34   PASS  virt_off_names_the_cpus_left_on  (9s)
09:54:34   --- 28 guests, 21 of them not the shipping kernel, 3 kernel build(s): ["", "boot-actuators,test-actuators", "mask-windows"]
09:54:34   --- irq census: 16 guest(s) reported, 2158 interrupt(s), 1195 of them on cpu0 (55.4%); per guest cpu0's share is median 81.9% p90 100.0% max 100.0%
09:54:34       timer          1445 (67.0% of all), 37.3% of them on cpu0
09:54:34       xhci            427 (19.8% of all), 100.0% of them on cpu0
09:54:34       userdev         222 (10.3% of all), 100.0% of them on cpu0
09:54:34       tlb              64 (3.0% of all), 10.9% of them on cpu0
09:54:34       widest guest reported 8 cpu(s)

09:54:34 host: fastest boot 454 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
09:54:34 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
09:54:34 test result: ok. 26 passed, 26 total (89.1s; workers: 776s building, 227s testing)

cargo run -- --ci host

EXIT=0. Load: 11:54 up 3 days, 23:38, 3 users, load averages: 26.40 26.52 25.13. Its [ci] lines, cut at 300 characters:

09:54:43 === [ci] the build system
09:55:09 [ci] the build system: cargo test --lib
09:55:09 === [ci] the harness's own checks
09:55:15 [ci] the harness's own checks: cargo test --test toyos-checks
09:55:15 === [ci] the host workspace
09:58:49 [ci] the host workspace: cargo test --workspace --exclude toyos-build
09:58:49 === [ci] the licences of what ships
09:58:51 [ci] the licences of what ships: 6 exception(s) stand, and nothing else is refused
09:58:51 === [ci] clippy and the bare targets
09:58:51 [ci] clippy and the bare targets: installed
09:58:51 === [ci] clippy, warnings denied
10:00:10 [ci] clippy, warnings denied: clean
10:00:10 === [ci] kernel-loom without loom
10:00:11 [ci] kernel-loom without loom: cargo test --manifest-path kernel-loom/Cargo.toml --no-default-features --test log_zeroed_init --test log_body_words
10:00:11 === [ci] control `wake-fence-off`
10:00:12 [ci] control `wake-fence-off`: 1 verdict(s) reached
10:00:12 === [ci] control `lock-acquire-off`
10:00:13 [ci] control `lock-acquire-off`: 1 verdict(s) reached
10:00:13 === [ci] control `seqlock-writer-fence-off`
10:00:15 [ci] control `seqlock-writer-fence-off`: 1 verdict(s) reached
10:00:15 === [ci] control `serial-try-lock-then-some`
10:00:16 [ci] control `serial-try-lock-then-some`: 2 verdict(s) reached
10:00:16 === [ci] control `reap-raise-relaxed`
10:00:17 [ci] control `reap-raise-relaxed`: 1 verdict(s) reached
10:00:17 === [ci] control `shootdown-serve-relaxed`
10:00:18 [ci] control `shootdown-serve-relaxed`: 2 verdict(s) reached
10:00:18 === [ci] control `roster-commit-relaxed`
10:00:20 [ci] control `roster-commit-relaxed`: 1 verdict(s) reached
10:00:20 === [ci] control `smp-ready-split`
10:00:21 [ci] control `smp-ready-split`: 1 verdict(s) reached
10:00:21 === [ci] control `log-commit-release-off`
10:00:22 [ci] control `log-commit-release-off`: 2 verdict(s) reached
10:00:22 === [ci] control `shard-publish-relaxed`
10:00:23 [ci] control `shard-publish-relaxed`: 1 verdict(s) reached
10:00:23 === [ci] control `log-ring-publish-relaxed`
10:00:25 [ci] control `log-ring-publish-relaxed`: 3 verdict(s) reached
10:00:25 === [ci] control `log-ring-tail-relaxed`
10:00:26 [ci] control `log-ring-tail-relaxed`: 3 verdict(s) reached
10:00:26 === [ci] control `log-ring-loads-swapped`
10:00:28 [ci] control `log-ring-loads-swapped`: 1 verdict(s) reached
10:00:28 === [ci] control `post-is-an-answer`
10:00:29 [ci] control `post-is-an-answer`: 3 verdict(s) reached
10:00:29 === [ci] control `poll-fire-load-store`
10:00:30 [ci] control `poll-fire-load-store`: 2 verdict(s) reached
10:00:30 === [ci] control `sleeplock-acquire-off`
10:00:32 [ci] control `sleeplock-acquire-off`: 2 verdict(s) reached
10:00:32 === [ci] control `device-irq-lossy`
10:00:33 [ci] control `device-irq-lossy`: 1 verdict(s) reached
10:00:33 === [ci] control `dump-report-relaxed`
10:00:34 [ci] control `dump-report-relaxed`: 1 verdict(s) reached
10:00:34 === [ci] control `no-preempt-guard`
10:00:35 [ci] control `no-preempt-guard`: 1 verdict(s) reached
10:00:35 === [ci] control `doorbell-kick-relaxed`
10:00:37 [ci] control `doorbell-kick-relaxed`: 1 verdict(s) reached
10:00:37 === [ci] control `push-fence-relaxed`
10:00:37 [ci] control `push-fence-relaxed`: 1 verdict(s) reached
10:00:37 === [ci] control `commit-ignores-notify`
10:00:39 [ci] control `commit-ignores-notify`: 2 verdict(s) reached
10:00:39 === [ci] control `notify-flag-load-only`
10:00:43 [ci] control `notify-flag-load-only`: 1 verdict(s) reached
10:00:43 === [ci] control `gate-fence-off`
10:00:45 [ci] control `gate-fence-off`: 1 verdict(s) reached
10:00:45 === [ci] control `poll-fire-load-store`
10:00:47 [ci] control `poll-fire-load-store`: 3 verdict(s) reached
10:00:47 === [ci] control `fault-posted-before-it-is-set`
10:00:48 [ci] control `fault-posted-before-it-is-set`: 3 verdict(s) reached
10:00:48 === [ci] control `victim-retires-mid-probe`
10:00:49 [ci] control `victim-retires-mid-probe`: 1 verdict(s) reached
10:00:49 === [ci] control `mutate-spawn-skips-the-insert-recheck`
10:00:52 [ci] control `mutate-spawn-skips-the-insert-recheck`: 2 verdict(s) reached
10:00:52 === [ci] control `mutate-claim-teardown-always-wins`
10:00:54 [ci] control `mutate-claim-teardown-always-wins`: 1 verdict(s) reached
10:00:54 === [ci] control `mutate-kill-waits-for-its-victims`
10:00:56 [ci] control `mutate-kill-waits-for-its-victims`: 2 verdict(s) reached
10:00:56 === [ci] control `mutate-first-out-tears-down`
10:00:58 [ci] control `mutate-first-out-tears-down`: 1 verdict(s) reached
10:00:58 === [ci] control `mutate-join-collects-in-a-teardown`
10:01:01 [ci] control `mutate-join-collects-in-a-teardown`: 1 verdict(s) reached
10:01:01 === [ci] control `mutate-last-out-leaves-before-its-teardown`
10:01:03 [ci] control `mutate-last-out-leaves-before-its-teardown`: 2 verdict(s) reached
10:01:03 === [ci] control `mutate-place-skips-the-insert-recheck`
10:01:05 [ci] control `mutate-place-skips-the-insert-recheck`: 1 verdict(s) reached
10:01:05 === [ci] control `mutate-refused-spawn-keeps-the-count`
10:01:07 [ci] control `mutate-refused-spawn-keeps-the-count`: 1 verdict(s) reached
10:01:07 === [ci] control `mutate-landed-child-retires-nothing`
10:01:09 [ci] control `mutate-landed-child-retires-nothing`: 2 verdict(s) reached
10:01:09 === [ci] control `mutate-publish-before-the-children`
10:01:11 [ci] control `mutate-publish-before-the-children`: 1 verdict(s) reached
10:01:11 === [ci] control `mutate-walk-in-one-hold`
10:01:13 [ci] control `mutate-walk-in-one-hold`: 1 verdict(s) reached
10:01:13 === [ci] control `mutate-spawner-handle-after-the-landing`
10:01:15 [ci] control `mutate-spawner-handle-after-the-landing`: 2 verdict(s) reached
10:01:15 === [ci] control `mutate-spawner-handle-before-the-childs-own`
10:01:17 [ci] control `mutate-spawner-handle-before-the-childs-own`: 1 verdict(s) reached
10:01:17 === [ci] control `placement-ignores-staleness`
10:01:24 [ci] control `placement-ignores-staleness`: 1 verdict(s) reached
10:01:24 === [ci] control `mutate-session-end-forgets`
10:01:29 [ci] control `mutate-session-end-forgets`: 1 verdict(s) reached
10:01:29 === [ci] control `mutate-abort-keeps-inflight`
10:01:30 [ci] control `mutate-abort-keeps-inflight`: 1 verdict(s) reached
10:01:30 === [ci] control `mutate-no-reissue-after-loss`
10:01:32 [ci] control `mutate-no-reissue-after-loss`: 1 verdict(s) reached
10:01:32 === [ci] control `publish-relaxed`
10:01:34 [ci] control `publish-relaxed`: 1 verdict(s) reached
10:01:34 === [ci] control `no-clamp`
10:01:35 [ci] control `no-clamp`: 1 verdict(s) reached
10:01:35 === [ci] control `end-keeps-inflight`
10:01:35 [ci] control `end-keeps-inflight`: 1 verdict(s) reached
10:01:35 === [ci] userland/blockd
10:01:37 [ci] userland/blockd: cargo test --manifest-path userland/blockd/Cargo.toml --target aarch64-apple-darwin
10:01:37 === [ci] userland/calc
10:01:44 [ci] userland/calc: cargo test --manifest-path userland/calc/Cargo.toml --target aarch64-apple-darwin
10:01:44 === [ci] userland/fsd
10:01:47 [ci] userland/fsd: cargo test --manifest-path userland/fsd/Cargo.toml --target aarch64-apple-darwin
10:01:47 === [ci] userland/logd
10:01:47 [ci] userland/logd: cargo test --manifest-path userland/logd/Cargo.toml --target aarch64-apple-darwin
10:01:47 === [ci] userland/netd
10:01:49 [ci] userland/netd: cargo test --manifest-path userland/netd/Cargo.toml --target aarch64-apple-darwin
10:01:49 === [ci] userland/pkg
10:01:51 [ci] userland/pkg: cargo test --manifest-path userland/pkg/Cargo.toml --target aarch64-apple-darwin
10:01:51 === [ci] userland/soundd
10:01:55 [ci] userland/soundd: cargo test --manifest-path userland/soundd/Cargo.toml --target aarch64-apple-darwin
10:01:55 === [ci] userland/sshd
10:02:07 [ci] userland/sshd: cargo test --manifest-path userland/sshd/Cargo.toml --target aarch64-apple-darwin
10:02:07 === [ci] the apps for linux
10:02:31 [ci] the apps for linux: 11 app(s) pass `cargo check --target x86_64-unknown-linux-gnu`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
10:02:31 === [ci] the apps for macos
10:02:47 [ci] the apps for macos: 11 app(s) pass `cargo build --target aarch64-apple-darwin`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
10:02:47 === [ci] the apps for windows
10:03:05 [ci] the apps for windows: 11 app(s) pass `cargo check --target x86_64-pc-windows-msvc`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
10:03:05 === [ci] the toyos SDK
10:03:07 [ci] the toyos SDK: cargo test --manifest-path toyos/Cargo.toml --target aarch64-apple-darwin
10:03:07 === [ci] nothing left in $TMPDIR or /tmp
10:03:07 [ci] nothing left in $TMPDIR or /tmp: every test took its scratch with it
10:03:07 [ci] Host: 67 step(s), all green

cargo run -- --build-only, rust/ one commit behind the pin

EXIT=0. Load: 12:03 up 3 days, 23:47, 3 users, load averages: 50.68 46.77 36.61. Finished and root: lines dropped too:

    Finished `dev` profile [optimized + debuginfo] target(s) in 7.78s
     Running `target/debug/toyos-build --build-only`
10:03:25 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out
warning: the following packages contain code that will be rejected by a future version of Rust: winit v0.30.13 (https://github.com/ToyOSOrg/winit?branch=toyos-0.30.13#f58e1f3b)
note: to see what the problems were, use the option `--future-incompat-report`, or run `cargo report future-incompatibilities --id 1`
10:04:09 Signed with this checkout's throwaway key SHA256:<fingerprint replaced> at version 1791021805
10:04:09 Build finished.
Boot image: …/toyos-forkmove/target/bootable.img

Edited: the fingerprint of the checkout's throwaway signing key in the --build-only log is replaced by a placeholder.

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of e38dbc314 against origin/main (ec7de748c), round 1.

Net, git diff --shortstat origin/main...e38dbc314: 8 files, +157 −102. Production +62 −32 (src/sysroot.rs +59 −32 above its test module, src/main.rs +2, src/licence.rs +1). Tests +60 −2 (src/sysroot.rs +56 −2, tests/toyos.rs +4). Issues +35 −68.

Evidence at the head: cargo run -- --ci host exit 0, cargo test --test toyos-build exit 0 with 26 of 26, cargo run -- --build-only exit 0, each with its log; the control is the base at ec7de748c, exit 1 from both states of rust/. No finding there.

BLOCKER

  • src/sysroot.rs:550 — the ruling asked for: the two-process race does not land filed. It is not only a simultaneous start. rust/.git and HEAD exist from git's first moment, so a process that arrives anywhere in the git worktree add (9 to 12 s between Making … and running N tests in the body's three logs; git -C rust ls-files counts 61,561 files) returns from make_fork_checkout at :586, passes fork_checkout at :523, and builds in a checkout still being written. The base row's third worker did exactly that through the same two tests (rust/src/bootstrap holds changes no commit does), and the head changes neither test. Between two processes it is unmeasured: the body's run started both in the same second.
  • src/licence.rs:1177 — for the pairing the brief names, a gate beside a guest run, the late process is --ci host's licences step: its fourth step, 4 min 6 s into the body's log, not where the process starts. Until git has written library/Cargo.toml, :1179 sends it to ensure_shallow_fork (src/lib.rs:124), which finds no rust/x.py and runs git submodule update --init --depth 1 rust in the linked worktree: git submodule update rust, which issues/build/the-fork-checkout-runs-git-submodule-in-a-linked-worktree.md records as setting the primary's core.worktree to a path that does not exist. Read from the code, narrow, the base's too, and unmeasured: reproduce it in a fixture only, never against this machine's primary.
  • src/sysroot.rs:647 — a sibling of what the tree has, chosen on a guess. Held::act_if(Scope::Worktree, …) (src/buildlock.rs:161) is the tree's decide-shared, act-exclusive section for state a worktree owns, which src/CLAUDE.md says its fork checkout is; build::invalidate_stale (src/build.rs:279) takes it on the same lock for the same defect, "two processes that each decided before either acted"; and sysroot::ensure already receives that lock. The body says it "would have closed it too" and refuses it on a track's future with no measurement, while the brief's "no lock unless nothing else serves" is answered by the branch's own exits 101 and 0. No lock is added by using one the tree holds, and the track's cut deletes src/buildlock.rs and this call together. Hypothesis, yours to run: the make-or-move as one act_if where sysroot::ensure reads the checkout, and licence::std_library holding the worktree's lock shared as every build does; flock is per open file description, so twelve workers' Helds exclude each other as two processes do, and no reader sees a half-made checkout. Measure it on the two base reproductions and the two-process one, which must exit 0 and 0. If it holds, these go: the three make_fork_checkout call sites (src/main.rs:208, src/licence.rs:1177, tests/toyos.rs:4003), the refusal in fork_checkout, the new issue file and the four renames in the submodule issue. If it does not, the measurement that says so goes in the body.
  • issues/build/two-processes-starting-in-one-worktree-are-two-movers-of-its-fork-checkout.md:11 — the record is not true of the race it files: it states a simultaneous start and one outcome, 101 and 0. The half-made arm of the first two findings, which the deleted a-worktrees-first-wide-run-reds-on-the-fork-checkout-it-is-still-making.md stated ("it tests rust/.git, which exists from the first moment") and which stays true between processes, is recorded nowhere at this head. Closed by the third finding deleting the file, or by a file that says it.
  • tests/toyos.rs:4005 — plain --list builds nothing and now makes a 61,561-file checkout, moves one behind its pin, is a mover in the race above, and by reading exits 101 on a checkout off its pin with uncommitted work, where the base printed the names. The body's own "unsure of"; a listing writes nothing and refuses nothing. Gone with the third finding.
  • src/sysroot.rs:1498 — a test of what a reader checks. fork_checkout is four read-only git commands and calls no mover, and by reading the body's mutation reds one call as it reds twelve (refused() gets Ok), so the Barrier and the twelve threads see git serving readers, which is no claim of this branch. The two refusals are the boundary and are two assertions in a_worktree_pinning_another_fork_commit_gets_its_own_checkout, which already makes, reads, steps behind and moves; twelve_builds_read and the second test, 51 lines, go. Under the third finding the twelve threads have something to see: twelve builds at once on a checkout not made each return it.

NOTE

  • src/sysroot.rs:1481 — the ahead case asserts a path and nothing else: by reading, with off_pin returning Some for a checkout ahead of its pin, make_fork_checkout moves the agent's C3 back to the pin, fork_checkout passes there, and both tests stay green. "Left as it stands" (:543) needs HEAD asserted at C3 after the call.

REMOVE

  • src/sysroot.rs:551 — "Two movers of one checkout corrupt it": the body's oracle and its two-process run say git refuses the second and the checkout ends whole.

SEND BACK

Japabu and others added 4 commits October 3, 2026 12:31
…t_if each

The first round moved the checkout once where a process starts and had every
build refuse one off its pin. The review of #683 found that this left two
processes as two movers (measured there: exits 101 and 0), let a process
arriving inside the `git worktree add` take a checkout still being written,
and made a plain `--list` make a 61,561-file checkout, while the tree already
held the mechanism for a decide-then-act defect on state a worktree owns:
`Held::act_if(Scope::Worktree, …)`, which `build::invalidate_stale` uses, on
the `lock` `sysroot::ensure` already receives.

So `fork_checkout` is main's again and takes that lock: the making is one
`act_if` and the move to the pin another. `flock` is per open file
description, so twelve workers' `Held`s exclude each other as two processes
do. `licence::std_library` takes the worktree's lock shared for the call, as
a build does. The three `make_fork_checkout` call sites, the refusal in
`fork_checkout`, the issue file the first round added and its four renames in
the submodule issue are gone.

The twelve-thread test of readers goes. The test that replaces it starts
twelve builds at once on a checkout not made and on one behind its pin; each
returns it whole and at the pin. The ahead-of-pin case now asserts the commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
…s checkout has a record

`licence::std_library` sends a fork checkout without `library/Cargo.toml` to
`ensure_shallow_fork`, which is a CI runner's path. Under the worktree's lock a
checkout another process is still making no longer gets there: the reader
waits. One a killed `git worktree add` left still did. Measured in a fixture
at a8dcbcc: `fork_checkout` returned the remains, `git submodule--helper
update --init --depth=1 -- rust` ran in the linked worktree, and afterwards
`git status` in the fixture primary's `rust/` exits 128 on `cannot chdir to
'../../../../../../linked/rust'`.

`ensure_shallow_fork` now refuses a linked worktree by name, and
`a_linked_worktree_initialises_no_submodule` holds it: on what a killed maker
leaves, the refusal is returned and git in the primary's fork still runs.

That a build takes such remains as made is the base's too and stays true:
issues/build/a-fork-checkout-a-killed-git-worktree-add-left-is-taken-as-made.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
`git worktree add --no-checkout` leaves a checkout with `.git` and no file; a
killed one leaves some.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
@Japabu Japabu changed the title A process moves its fork checkout once, where it starts, and a build only reads it A worktree's fork checkout is made and moved under its build lock, and no submodule is initialised in a linked worktree Oct 3, 2026
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Runs in the worktree at cfd4931a6. Paths are written with their machine-specific parents as …/, <tmp>/ and <scratch>/. No line carried a MAC address, an IP address, a UUID or an e-mail address; the one key fingerprint, in the --build-only log, is replaced by a placeholder.

Each log is the command's whole output with these dropped: Compiling lines, git's Updating files progress, cargo's Blocking waiting lines, the artifact lock's [build-lock] lines, the irq census and blank lines; lines are cut at 400 characters. Its first line is the head, the load average and the command, and its last the exit code.

The sequence, and the checkout after each step

#### the head's measurements
head cfd4931a6a0e31b3403ed0a60682efe052c95d34
primary's fork: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, core.worktree ../../../rust; backtrace: HEAD f8a3e681743baf1f274c5620b78a62db19b80f4a, core.worktree ../../../../../../rust/library/backtrace
build-tests: EXIT=0
== a plain --list, from the empty stub
rust/: the empty stub (0 entries)
list-stub: EXIT=0
rust/: no checkout, 0 entries
== the first wide run of a new worktree
fresh: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
== a plain --list, one commit behind the pin
rust/: HEAD 01b8626673fcbe92000950d7be27a946e6b9a465, one commit behind the pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3
list-behind: EXIT=0
rust/: HEAD 01b8626673fcbe92000950d7be27a946e6b9a465, 0 status line(s), registered 1 time(s) in the primary's fork
== the first run after the pin moved
behind: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
== two processes started together, from the empty stub
rust/: the empty stub (0 entries)
together-a: EXIT=0
together-b: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
== a second process arriving while the first makes the checkout
rust/: the empty stub (0 entries)
rust/.git appeared after 30 polls; rust/ then holds 1 of 37 top-level entries, x.py missing
late-a: EXIT=0
late-b: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
primary's fork: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, core.worktree ../../../rust; backtrace: HEAD f8a3e681743baf1f274c5620b78a62db19b80f4a, core.worktree ../../../../../../rust/library/backtrace
status: []
DONE
#### the control: the whole change reverted onto the head
src and tests differ from origin/main in 0 line(s) of diffstat
control-build: EXIT=0
== control: the first run after the pin moved
rust/: HEAD 01b8626673fcbe92000950d7be27a946e6b9a465, one commit behind the pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3
control-behind: EXIT=1
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
primary's fork: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, core.worktree ../../../rust; backtrace: HEAD f8a3e681743baf1f274c5620b78a62db19b80f4a, core.worktree ../../../../../../rust/library/backtrace
== control: the first wide run of a new worktree
rust/: the empty stub (0 entries)
control-fresh: EXIT=1
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
primary's fork: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, core.worktree ../../../rust; backtrace: HEAD f8a3e681743baf1f274c5620b78a62db19b80f4a, core.worktree ../../../../../../rust/library/backtrace
RESTORE_EXIT=0
status after restore: []
#### the gates at cfd4931a6a0e31b3403ed0a60682efe052c95d34
== the guest suite, from the empty stub and wide
rust/: the empty stub (0 entries)
guest-suite: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
== the host suites
ci-host: EXIT=0
== the image, from a checkout one commit behind its pin
rust/: HEAD 01b8626673fcbe92000950d7be27a946e6b9a465, one commit behind the pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3
build-only: EXIT=0
rust/: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, 0 status line(s), registered 1 time(s) in the primary's fork
primary's fork: HEAD 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3, core.worktree ../../../rust; backtrace: HEAD f8a3e681743baf1f274c5620b78a62db19b80f4a, core.worktree ../../../../../../rust/library/backtrace
status: []
FINAL-DONE

--list, from the empty stub (the 298 names dropped)

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 21.28 14.49 9.12; cargo test --test toyos-build -- --list
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
EXIT=0

The first wide run of a new worktree

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 21.28 14.49 9.12; cargo test --test toyos-build -- screen_
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:08 running 3 tests, 12 wide
11:07:08   RUN   screen_fatal_halt_composited
11:07:08   RUN   screen_panic_muted
11:07:08   RUN   screen_fatal_behind_a_painter
11:07:08   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
11:07:08   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:07:08   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:07:08 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — held by other builds in this tree
11:07:08 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:07:08 [build-lock] acquired (exclusive, make the fork checkout) after 9.0ms
11:07:08 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — held by other builds in this tree
11:07:08 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
11:07:12 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:07:12 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:07:12 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:07:12 [build-lock] acquired (shared, test image) after 69.5µs
11:07:14   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (6s)
11:07:14   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (7s)
11:07:14 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
11:07:14 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
11:07:14   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (7s)
11:07:17   PASS  screen_panic_muted  (3s)
11:07:20   PASS  screen_fatal_behind_a_painter  (6s)
11:07:23   [panic] the fatal report is on the panel and sealed in the black box (14204 bytes)
11:07:23   PASS  screen_fatal_halt_composited  (8s)
11:07:23   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:07:23 host: fastest boot 2993 ms against the reference 1424 ms — liveness ceilings paid at 2.10x
11:07:23 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:07:23 test result: ok. 3 passed, 3 total (15.0s; workers: 20s building, 17s testing)
EXIT=0

--list, one commit behind the pin (the 298 names dropped)

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 18.84 14.35 9.19; cargo test --test toyos-build -- --list
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
EXIT=0

The first run after the pin moved

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 18.84 14.35 9.19; cargo test --test toyos-build -- screen_
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:24 running 3 tests, 12 wide
11:07:24   RUN   screen_fatal_behind_a_painter
11:07:24   RUN   screen_fatal_halt_composited
11:07:24   RUN   screen_panic_muted
11:07:24   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
11:07:24   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:07:24   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:07:24 [build-lock] waiting for the build lock (exclusive, move the fork checkout to its pin) — held by other builds in this tree
11:07:24 [build-lock] waiting for the build lock (exclusive, move the fork checkout to its pin) — an exclusive phase is queued ahead of it
11:07:24 [build-lock] acquired (exclusive, move the fork checkout to its pin) after 205.4µs
11:07:24 [build-lock] waiting for the build lock (exclusive, move the fork checkout to its pin) — held by pid 99440 (move the fork checkout to its pin), 0s so far
11:07:24 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out
11:07:24 [build-lock] acquired (exclusive, move the fork checkout to its pin) after 343.2ms
11:07:24 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:07:24 [build-lock] acquired (exclusive, move the fork checkout to its pin) after 358.9ms
11:07:24 [build-lock] waiting for the build lock (shared, test image) — held by pid 99440 (move the fork checkout to its pin), 0s so far
11:07:24 [build-lock] acquired (shared, test image) after 30.3ms
11:07:24 [build-lock] acquired (shared, test image) after 14.7ms
11:07:26 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
11:07:26 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
11:07:26   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (2s)
11:07:26   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (2s)
11:07:26   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (2s)
11:07:28   PASS  screen_panic_muted  (3s)
11:07:32   PASS  screen_fatal_behind_a_painter  (6s)
11:07:34   [panic] the fatal report is on the panel and sealed in the black box (14213 bytes)
11:07:34   PASS  screen_fatal_halt_composited  (8s)
11:07:34   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:07:34 host: fastest boot 2972 ms against the reference 1424 ms — liveness ceilings paid at 2.09x
11:07:34 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:07:34 test result: ok. 3 passed, 3 total (10.4s; workers: 7s building, 17s testing)
EXIT=0

Two processes started together: the first

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 19.37 14.61 9.35; cargo test --test toyos-build -- screen_panic_muted
    Finished `test` profile [optimized + debuginfo] target(s) in 0.09s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:37 running 1 tests, 12 wide
11:07:37   RUN   screen_panic_muted
11:07:37   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:07:37 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — held by other builds in this tree
11:07:42 [build-lock] acquired (exclusive, make the fork checkout) after 5.2s
11:07:45   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (8s)
11:07:48   PASS  screen_panic_muted  (3s)
11:07:48   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:07:48 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:07:48 test result: ok. 1 passed, 1 total (11.0s; workers: 8s building, 3s testing)
EXIT=0

Two processes started together: the second

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 19.37 14.61 9.35; cargo test --test toyos-build -- screen_fatal_halt_composited
    Finished `test` profile [optimized + debuginfo] target(s) in 0.07s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:37 running 1 tests, 12 wide
11:07:37   RUN   screen_fatal_halt_composited
11:07:37   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:07:37 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — held by other builds in this tree
11:07:37 [build-lock] acquired (exclusive, make the fork checkout) after 6.9ms
11:07:37 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
11:07:42 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:07:42 [build-lock] acquired (shared, test image) after 256.0µs
11:07:45 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
11:07:45 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
11:07:45   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (8s)
11:07:54   [panic] the fatal report is on the panel and sealed in the black box (14212 bytes)
11:07:54   PASS  screen_fatal_halt_composited  (8s)
11:07:54   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:07:54 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:07:54 test result: ok. 1 passed, 1 total (16.5s; workers: 8s building, 8s testing)
EXIT=0

A second process arriving during the make: the maker

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 20.29 15.12 9.65; cargo test --test toyos-build -- screen_panic_muted
    Finished `test` profile [optimized + debuginfo] target(s) in 0.06s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:57 running 1 tests, 12 wide
11:07:57   RUN   screen_panic_muted
11:07:57   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:07:57 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
11:08:05   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (8s)
11:08:08   PASS  screen_panic_muted  (3s)
11:08:08   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:08:08 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:08:08 test result: ok. 1 passed, 1 total (10.6s; workers: 8s building, 3s testing)
EXIT=0

A second process arriving during the make: the arrival

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 20.29 15.12 9.65; cargo test --test toyos-build -- screen_fatal_halt_composited
    Finished `test` profile [optimized + debuginfo] target(s) in 0.06s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:07:58 running 1 tests, 12 wide
11:07:58   RUN   screen_fatal_halt_composited
11:07:58   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:07:58 [build-lock] waiting for the build lock (shared, test image) — held by pid 3361 (make the fork checkout), 1s so far
11:08:03 [build-lock] acquired (shared, test image) after 5.4s
11:08:06 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
11:08:06 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
11:08:06   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (8s)
11:08:14   [panic] the fatal report is on the panel and sealed in the black box (14218 bytes)
11:08:14   PASS  screen_fatal_halt_composited  (8s)
11:08:14   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:08:14 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:08:14 test result: ok. 1 passed, 1 total (16.2s; workers: 8s building, 8s testing)
EXIT=0

Control, the whole change reverted: the first run after the pin moved

head cfd4931a6a0e31b3403ed0a60682efe052c95d34 + patch; load 22.09 15.93 10.10; cargo test --test toyos-build -- screen_
    Finished `test` profile [optimized + debuginfo] target(s) in 0.06s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:08:20 running 3 tests, 12 wide
11:08:20   RUN   screen_fatal_behind_a_painter
11:08:20   RUN   screen_panic_muted
11:08:20   RUN   screen_fatal_halt_composited
11:08:20   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
11:08:20   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:08:20   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
fatal: Unable to create '…/toyos/.git/modules/rust/worktrees/rust/index.lock': File exists.
Another git process seems to be running in this repository, or the lock file may be stale
thread '<unnamed>' (93197423) panicked at src/sysroot.rs:1037:5:
git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
11:08:21   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (540ms)
11:08:21 FAIL screen_fatal_halt_composited: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
11:08:21   FAIL  screen_fatal_halt_composited  (34ms)
fatal: Unable to create '…/toyos/.git/modules/rust/worktrees/rust/index.lock': File exists.
Another git process seems to be running in this repository, or the lock file may be stale
thread '<unnamed>' (93197424) panicked at src/sysroot.rs:1037:5:
git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
11:08:21   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (604ms)
11:08:21 FAIL screen_panic_muted: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
11:08:21   FAIL  screen_panic_muted  (34ms)
11:08:21 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out
11:08:22   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (2s)
11:08:28   PASS  screen_fatal_behind_a_painter  (6s)
11:08:28   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:08:28 host: fastest boot 2891 ms against the reference 1424 ms — liveness ceilings paid at 2.03x
11:08:28 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:08:28 failures:
11:08:28     screen_fatal_halt_composited: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
11:08:28     screen_panic_muted: git ["checkout", "--detach", "-q", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos-forkmove/rust failed
11:08:28 test result: FAILED. 1 passed, 2 failed, 0 invalidated, 3 total (8.3s; workers: 3s building, 6s testing)
11:08:28 [toyos] this red run's serial logs are kept at …/toyos-forkmove/target/red-run-serial/toyos-tmp-6740-0
error: test failed, to rerun pass `--test toyos-build`
Caused by:
  process didn't exit successfully: `…/toyos-forkmove/target/debug/deps/toyos_build-8802c76dc0791521 screen_` (exit status: 1)
EXIT=1

Control, the whole change reverted: the first wide run of a new worktree

head cfd4931a6a0e31b3403ed0a60682efe052c95d34 + patch; load 22.19 16.13 10.24; cargo test --test toyos-build -- screen_
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:08:32 running 3 tests, 12 wide
11:08:32   RUN   screen_panic_muted
11:08:32   RUN   screen_fatal_behind_a_painter
11:08:32   RUN   screen_fatal_halt_composited
11:08:32   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
11:08:32   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:08:32   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:08:32 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
11:08:32 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
11:08:32 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
Preparing worktree (detached HEAD 95960d6c214)
Preparing worktree (detached HEAD 95960d6c214)
fatal: '…/toyos-forkmove/rust' already exists
fatal: '…/toyos-forkmove/rust' already exists
thread '<unnamed>' (93203417) panicked at src/sysroot.rs:1037:5:
git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
thread '<unnamed>' (93203415) panicked at src/sysroot.rs:1037:5:
git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
11:08:32   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (52ms)
11:08:32   FAIL  x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (52ms)
11:08:32 FAIL screen_panic_muted: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
11:08:32 FAIL screen_fatal_halt_composited: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
11:08:32   FAIL  screen_panic_muted  (33ms)
11:08:32   FAIL  screen_fatal_halt_composited  (33ms)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
11:08:39   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (7s)
11:08:45   PASS  screen_fatal_behind_a_painter  (6s)
11:08:45   --- 3 guests, 3 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]
11:08:45 host: fastest boot 2836 ms against the reference 1424 ms — liveness ceilings paid at 1.99x
11:08:45 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:08:45 failures:
11:08:45     screen_panic_muted: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
11:08:45     screen_fatal_halt_composited: git ["worktree", "add", "--detach", "…/toyos-forkmove/rust", "95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3"] in …/toyos/rust failed
11:08:45 test result: FAILED. 1 passed, 2 failed, 0 invalidated, 3 total (12.6s; workers: 7s building, 6s testing)
11:08:45 [toyos] this red run's serial logs are kept at …/toyos-forkmove/target/red-run-serial/toyos-tmp-8841-0
error: test failed, to rerun pass `--test toyos-build`
Caused by:
  process didn't exit successfully: `…/toyos-forkmove/target/debug/deps/toyos_build-8802c76dc0791521 screen_` (exit status: 1)
EXIT=1

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Gate logs at cfd4931a6. Paths are written with their machine-specific parents as …/, <tmp>/ and <scratch>/. No line carried a MAC address, an IP address, a UUID or an e-mail address; the one key fingerprint, in the --build-only log, is replaced by a placeholder.

cargo test --test toyos-build, from an empty stub, 12 wide

The whole output with the same lines dropped as in "Runs in the worktree".

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 19.68 15.93 10.30; cargo test --test toyos-build
    Finished `test` profile [optimized + debuginfo] target(s) in 3.98s
     Running tests/toyos.rs (target/debug/deps/toyos_build-8802c76dc0791521)
11:08:53 running 26 tests, 12 wide
11:08:53   RUN   iommu_virtio_platform
11:08:53   RUN   screen_panic_muted
11:08:53   RUN   virt_irq_storm
11:08:53   RUN   machine_shutdown
11:08:53   RUN   virt_early_fault
11:08:53   RUN   screen_fatal_behind_a_painter
11:08:53   RUN   screen_fatal_halt_composited
11:08:53   RUN   nested_nmi_is_loud
11:08:53   RUN   virt_el2_drop
11:08:53   RUN   virt_user_mode
11:08:53   RUN   virt_timer_preempts
11:08:53   RUN   virt_early_panic
11:08:53   BUILD aarch64 abuse_readonly_copyout of tests/toyos-rust-tests, for virt_timer_preempts
11:08:53   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_irq_storm
11:08:53   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for nested_nmi_is_loud
11:08:53   BUILD x86_64 kernel, loader, ROOT of tests/testcases, for machine_shutdown
11:08:53   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter
11:08:53   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_el2_drop
11:08:53   BUILD aarch64 kernel, loader, ROOT of tests/testcases, for virt_user_mode
11:08:53   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_panic
11:08:53   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_fault
11:08:53   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited
11:08:53   BUILD x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted
11:08:53   BUILD x86_64 kernel, loader, ROOT of tests/netcase, for iommu_virtio_platform
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — held by other builds in this tree
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] waiting for the build lock (exclusive, make the fork checkout) — an exclusive phase is queued ahead of it
11:08:53 [build-lock] acquired (exclusive, make the fork checkout) after 5.9ms
11:08:53 Making …/toyos-forkmove/rust a fork checkout at 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3 (a git worktree of the primary's)
Preparing worktree (detached HEAD 95960d6c214)
HEAD is now at 95960d6c214 Revert "bootstrap: name ToyOS to CMake when building LLVM for it"
Preparing worktree (detached HEAD f8a3e68)
HEAD is now at f8a3e68 Merge upstream rust-lang/backtrace-rs (2026-08-02)
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, a test binary) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] acquired (shared, a test binary) after 63.0µs
11:08:58 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — an exclusive phase is queued ahead of it
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — held by pid 12517 (make the fork checkout), 0s so far
11:08:58 [build-lock] acquired (shared, test image) after 59.8µs
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.6s
11:08:58 [build-lock] acquired (shared, test image) after 37.9ms
11:08:58 [build-lock] acquired (shared, test image) after 37.9ms
11:08:58 [build-lock] acquired (shared, test image) after 37.9ms
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.7s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — held by other builds in this tree
11:08:58 [build-lock] acquired (shared, test image) after 96.0µs
11:08:58 [build-lock] acquired (shared, test image) after 58.1ms
11:08:58 [build-lock] acquired (shared, test image) after 38.7ms
11:08:58 [build-lock] acquired (exclusive, make the fork checkout) after 4.7s
11:08:58 [build-lock] waiting for the build lock (shared, test image) — held by other builds in this tree
11:08:58 [build-lock] acquired (shared, test image) after 224.7µs
11:09:02   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_fatal_behind_a_painter  (9s)
11:09:03   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_irq_storm  (10s)
11:09:03   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_fault  (10s)
11:09:03   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_el2_drop  (10s)
11:09:03   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_early_panic  (10s)
11:09:03   BUILT aarch64 abuse_readonly_copyout of tests/toyos-rust-tests, for virt_timer_preempts  (10s)
11:09:03   BUILT x86_64 kernel, loader, ROOT of tests/testcases, for machine_shutdown  (10s)
11:09:03   BUILD aarch64 ROOT of tests/virtjobcase, for virt_timer_preempts
11:09:03   PASS  virt_early_fault  (712ms)
11:09:03   RUN   virt_timer_floor
11:09:04 assets: leaving out assets/soundfont.sf2 — only /system/bin/doom opens it and this image builds no doom
11:09:04 assets: leaving out assets/DOOM1.WAD — only /system/bin/doom opens it and this image builds no doom
11:09:04   PASS  virt_early_panic  (668ms)
11:09:04   RUN   virt_fp_isolation
11:09:04   BUILD aarch64 ROOT of tests/virtjobcase, for virt_fp_isolation
11:09:04   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/metalcase, for screen_fatal_halt_composited  (11s)
11:09:04   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for nested_nmi_is_loud  (11s)
11:09:04   BUILT x86_64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for screen_panic_muted  (11s)
11:09:04   PASS  virt_el2_drop  (1s)
11:09:04   RUN   virt_first_entry
11:09:04   BUILD aarch64 ROOT of tests/virtjobcase, for virt_first_entry
11:09:04   BUILT aarch64 kernel, loader, ROOT of tests/testcases, for virt_user_mode  (11s)
11:09:04   BUILT x86_64 kernel, loader, ROOT of tests/netcase, for iommu_virtio_platform  (12s)
11:09:06   BUILT aarch64 ROOT of tests/virtjobcase, for virt_timer_preempts  (2s)
11:09:06   BUILT aarch64 ROOT of tests/virtjobcase, for virt_fp_isolation  (3s)
11:09:07   BUILT aarch64 ROOT of tests/virtjobcase, for virt_first_entry  (3s)
11:09:07   [virt] [kernel 1.713 cpu0] timer-floor: PASS span=10000 floor=10000 ticks: the comparator past the counter it was set from
11:09:07   PASS  virt_timer_floor  (4s)
11:09:07   RUN   virt_unmap_touch
11:09:08   [virt] [kernel 4.069 cpu0] irq-storm: PASS sgis=449824/449824 ticks=1000: the timer fired through the flood, and every SGI sent was taken
11:09:08   PASS  virt_irq_storm  (5s)
11:09:08   RUN   virt_debug_refused
11:09:09   [power] shutdown: QEMU stopped the guest for guest-shutdown
11:09:09   PASS  machine_shutdown  (6s)
11:09:09   RUN   virt_readonly_copyout
11:09:09   [nmi] nested: [nmi] NESTED NMI on cpu 0: a second NMI entered while IST2 was still in use.
11:09:09   PASS  nested_nmi_is_loud  (5s)
11:09:09   RUN   virt_mask_windows
11:09:09   BUILD aarch64 kernel mask-windows, ROOT of tests/virtsmpcase, for virt_mask_windows
11:09:09   PASS  screen_panic_muted  (5s)
11:09:09   RUN   virt_smp
11:09:09   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_smp
11:09:09   PASS  virt_user_mode  (5s)
11:09:09   RUN   virt_el1_smp
11:09:09   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_el1_smp
11:09:10   [virt] {1.966 pid=4 test-runner} preempt: the counting thread was preempted twice, at counts 5334702 and 8803626
11:09:10   PASS  virt_timer_preempts  (5s)
11:09:10   RUN   virt_failed_ap_leaves_no_hole
11:09:10   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_failed_ap_leaves_no_hole
11:09:11   [iommu] headless: 3 virtio function(s) behind a unit = true, the audio function 00:04.0 among them
11:09:11   [virt] {2.030 pid=5 test-runner} fp_isolation: v0-v31, FPCR and FPSR survived 3 switches to a thread that loads another state
11:09:11   PASS  virt_fp_isolation  (4s)
11:09:11   RUN   virt_fatal_halts_the_others_first
11:09:11   BUILD aarch64 panic_halts_first of tests/toyos-rust-tests, for virt_fatal_halts_the_others_first
11:09:11   [virt] {2.105 pid=6 test-runner} first_entry: x1-x30 were zero at a new thread's first instruction
11:09:11   PASS  virt_first_entry  (4s)
11:09:11   RUN   virt_reboot
11:09:11   BUILD aarch64 ROOT of tests/virtrebootcase, for virt_reboot
11:09:11   PASS  screen_fatal_behind_a_painter  (9s)
11:09:11   RUN   virt_off_names_the_cpus_left_on
11:09:11   BUILD aarch64 ROOT of tests/virtsmpcase, for virt_off_names_the_cpus_left_on
11:09:12   BUILT aarch64 kernel mask-windows, ROOT of tests/virtsmpcase, for virt_mask_windows  (3s)
11:09:12   [virt] {2.923 pid=7 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:12   PASS  virt_unmap_touch  (4s)
11:09:12   RUN   virt_reboot_refused_without_psci
11:09:12   BUILD aarch64 ROOT of tests/virtrebootcase, for virt_reboot_refused_without_psci
11:09:12   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_el1_smp  (3s)
11:09:12   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_smp  (3s)
11:09:12   [virt] {2.682 pid=16 test-runner} debug_refused: SYS_DEBUG's double fault and TLB acknowledgement delay were refused
11:09:12   PASS  virt_debug_refused  (4s)
11:09:13   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_failed_ap_leaves_no_hole  (2s)
11:09:13   BUILT aarch64 panic_halts_first of tests/toyos-rust-tests, for virt_fatal_halts_the_others_first  (2s)
11:09:13   BUILD aarch64 ROOT of tests/virtpaniccase, for virt_fatal_halts_the_others_first
11:09:13   [virt] {2.403 pid=17 test-runner} a syscall writes only where its caller could store
11:09:13   PASS  virt_readonly_copyout  (4s)
11:09:13   BUILT aarch64 ROOT of tests/virtsmpcase, for virt_off_names_the_cpus_left_on  (2s)
11:09:13   BUILT aarch64 ROOT of tests/virtrebootcase, for virt_reboot  (2s)
11:09:14   BUILT aarch64 ROOT of tests/virtrebootcase, for virt_reboot_refused_without_psci  (2s)
11:09:15   [panic] the fatal report is on the panel and sealed in the black box (14228 bytes)
11:09:15   PASS  screen_fatal_halt_composited  (11s)
11:09:15   [virt] {2.224 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:15   [windows] cpu0 irqs_off_ns=30577000 preempt_off_ns=30573000
11:09:15   [windows] cpu1 irqs_off_ns=49068000 preempt_off_ns=49063000
11:09:15   [windows] cpu2 irqs_off_ns=3294000 preempt_off_ns=8864000
11:09:15   [windows] cpu3 irqs_off_ns=16736000 preempt_off_ns=51497000
11:09:15   [windows] cpu4 irqs_off_ns=2250000 preempt_off_ns=30080000
11:09:15   [windows] cpu5 irqs_off_ns=9210000 preempt_off_ns=9204000
11:09:15   [windows] cpu6 irqs_off_ns=2583000 preempt_off_ns=3710000
11:09:15   [windows] cpu7 irqs_off_ns=52689000 preempt_off_ns=52298000
11:09:15   PASS  virt_mask_windows  (4s)
11:09:16   [iommu] headless-no-iommu: 2 virtio function(s) behind a unit = false, the audio function 00:04.0 among them; the NIC's claim refused for want of a domain
11:09:16   BUILT aarch64 ROOT of tests/virtpaniccase, for virt_fatal_halts_the_others_first  (3s)
11:09:16   [virt] {2.203 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:16   [virt] 8 CPUs entered at EL1, started through HVC, and scheduling
11:09:16   [virt] stop: 5 of 5 userland thread(s) stopped across 8 cpu(s) in 0 ms of a 2010 ms budget over 1 sweep(s), 0 of 0 userland block operation(s) still open; every CPU but 0x0 called CPU_OFF, then 0x0 SYSTEM_OFF
11:09:16   PASS  virt_el1_smp  (4s)
11:09:16   [virt] {2.240 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:16   [virt] 8 CPUs entered at EL2, started through SMC, and scheduling
11:09:16   [virt] stop: 5 of 5 userland thread(s) stopped across 8 cpu(s) in 0 ms of a 2010 ms budget over 1 sweep(s), 0 of 0 userland block operation(s) still open; every CPU but 0x0 called CPU_OFF, then 0x0 SYSTEM_OFF
11:09:16   PASS  virt_smp  (4s)
11:09:18   [virt] Rebooting., then one SYSTEM_RESET, and QEMU stopped for guest-reset
11:09:18   PASS  virt_reboot  (4s)
11:09:18   [virt] {2.578 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:18   [virt] reboot: this machine has no reset this kernel performs — refused, and the job ended exit 1
11:09:18   PASS  virt_reboot_refused_without_psci  (4s)
11:09:20   [iommu] declined: [kernel 0.266 cpu0] virtio-sound: NOT INITIALISED — PCI 00:04.0 refused the feature set 0x100000000 the driver accepted, leaving DEVICE_STATUS=0x3 without FEATURES_OK
11:09:20   PASS  iommu_virtio_platform  (16s)
11:09:20   [panic] the fatal path on cpu3 left every other CPU halted with interrupts masked
11:09:20   PASS  virt_fatal_halts_the_others_first  (4s)
11:09:22   [virt] {6.878 pid=4 test-runner} unmap_touch: 4 reads of a page just unmapped on the unmapping thread, and 4 on another, each ended their process
11:09:22   [virt] a non-last AP never started and the dense machine ran its job
11:09:22   PASS  virt_failed_ap_leaves_no_hole  (9s)
11:09:23   [virt] [6, 7] left on and named; the rest CPU_OFF, then 0x0 SYSTEM_OFF; 4988 PSCI call(s) traced
11:09:23   PASS  virt_off_names_the_cpus_left_on  (10s)
11:09:23   --- 28 guests, 21 of them not the shipping kernel, 3 kernel build(s): ["", "boot-actuators,test-actuators", "mask-windows"]
11:09:23 host: fastest boot 453 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
11:09:23 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
11:09:23 test result: ok. 26 passed, 26 total (30.5s; workers: 156s building, 139s testing)
EXIT=0

cargo run -- --ci host

Its [ci] lines, of 7,252: every step's name and verdict.

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 24.90 17.61 11.14; cargo run -- --ci host
11:09:24 === [ci] the build system
11:09:41 [ci] the build system: cargo test --lib
11:09:41 === [ci] the harness's own checks
11:09:43 [ci] the harness's own checks: cargo test --test toyos-checks
11:09:43 === [ci] the host workspace
11:11:41 [ci] the host workspace: cargo test --workspace --exclude toyos-build
11:11:41 === [ci] the licences of what ships
11:11:43 [ci] the licences of what ships: 6 exception(s) stand, and nothing else is refused
11:11:43 === [ci] clippy and the bare targets
11:11:43 [ci] clippy and the bare targets: installed
11:11:43 === [ci] clippy, warnings denied
11:11:50 [ci] clippy, warnings denied: clean
11:11:50 === [ci] kernel-loom without loom
11:11:50 [ci] kernel-loom without loom: cargo test --manifest-path kernel-loom/Cargo.toml --no-default-features --test log_zeroed_init --test log_body_words
11:11:50 === [ci] control `wake-fence-off`
11:11:50 [ci] control `wake-fence-off`: 1 verdict(s) reached
11:11:50 === [ci] control `lock-acquire-off`
11:11:50 [ci] control `lock-acquire-off`: 1 verdict(s) reached
11:11:50 === [ci] control `seqlock-writer-fence-off`
11:11:50 [ci] control `seqlock-writer-fence-off`: 1 verdict(s) reached
11:11:50 === [ci] control `serial-try-lock-then-some`
11:11:50 [ci] control `serial-try-lock-then-some`: 2 verdict(s) reached
11:11:50 === [ci] control `reap-raise-relaxed`
11:11:51 [ci] control `reap-raise-relaxed`: 1 verdict(s) reached
11:11:51 === [ci] control `shootdown-serve-relaxed`
11:11:51 [ci] control `shootdown-serve-relaxed`: 2 verdict(s) reached
11:11:51 === [ci] control `roster-commit-relaxed`
11:11:51 [ci] control `roster-commit-relaxed`: 1 verdict(s) reached
11:11:51 === [ci] control `smp-ready-split`
11:11:51 [ci] control `smp-ready-split`: 1 verdict(s) reached
11:11:51 === [ci] control `log-commit-release-off`
11:11:51 [ci] control `log-commit-release-off`: 2 verdict(s) reached
11:11:51 === [ci] control `shard-publish-relaxed`
11:11:51 [ci] control `shard-publish-relaxed`: 1 verdict(s) reached
11:11:51 === [ci] control `log-ring-publish-relaxed`
11:11:52 [ci] control `log-ring-publish-relaxed`: 3 verdict(s) reached
11:11:52 === [ci] control `log-ring-tail-relaxed`
11:11:52 [ci] control `log-ring-tail-relaxed`: 3 verdict(s) reached
11:11:52 === [ci] control `log-ring-loads-swapped`
11:11:52 [ci] control `log-ring-loads-swapped`: 1 verdict(s) reached
11:11:52 === [ci] control `post-is-an-answer`
11:11:52 [ci] control `post-is-an-answer`: 3 verdict(s) reached
11:11:52 === [ci] control `poll-fire-load-store`
11:11:52 [ci] control `poll-fire-load-store`: 2 verdict(s) reached
11:11:52 === [ci] control `sleeplock-acquire-off`
11:11:52 [ci] control `sleeplock-acquire-off`: 2 verdict(s) reached
11:11:52 === [ci] control `device-irq-lossy`
11:11:52 [ci] control `device-irq-lossy`: 1 verdict(s) reached
11:11:52 === [ci] control `dump-report-relaxed`
11:11:53 [ci] control `dump-report-relaxed`: 1 verdict(s) reached
11:11:53 === [ci] control `no-preempt-guard`
11:11:53 [ci] control `no-preempt-guard`: 1 verdict(s) reached
11:11:53 === [ci] control `doorbell-kick-relaxed`
11:11:53 [ci] control `doorbell-kick-relaxed`: 1 verdict(s) reached
11:11:53 === [ci] control `push-fence-relaxed`
11:11:53 [ci] control `push-fence-relaxed`: 1 verdict(s) reached
11:11:53 === [ci] control `commit-ignores-notify`
11:11:54 [ci] control `commit-ignores-notify`: 2 verdict(s) reached
11:11:54 === [ci] control `notify-flag-load-only`
11:11:56 [ci] control `notify-flag-load-only`: 1 verdict(s) reached
11:11:56 === [ci] control `gate-fence-off`
11:11:56 [ci] control `gate-fence-off`: 1 verdict(s) reached
11:11:56 === [ci] control `poll-fire-load-store`
11:11:56 [ci] control `poll-fire-load-store`: 3 verdict(s) reached
11:11:56 === [ci] control `fault-posted-before-it-is-set`
11:11:56 [ci] control `fault-posted-before-it-is-set`: 3 verdict(s) reached
11:11:56 === [ci] control `victim-retires-mid-probe`
11:11:57 [ci] control `victim-retires-mid-probe`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-spawn-skips-the-insert-recheck`
11:11:57 [ci] control `mutate-spawn-skips-the-insert-recheck`: 2 verdict(s) reached
11:11:57 === [ci] control `mutate-claim-teardown-always-wins`
11:11:57 [ci] control `mutate-claim-teardown-always-wins`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-kill-waits-for-its-victims`
11:11:57 [ci] control `mutate-kill-waits-for-its-victims`: 2 verdict(s) reached
11:11:57 === [ci] control `mutate-first-out-tears-down`
11:11:57 [ci] control `mutate-first-out-tears-down`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-join-collects-in-a-teardown`
11:11:57 [ci] control `mutate-join-collects-in-a-teardown`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-last-out-leaves-before-its-teardown`
11:11:57 [ci] control `mutate-last-out-leaves-before-its-teardown`: 2 verdict(s) reached
11:11:57 === [ci] control `mutate-place-skips-the-insert-recheck`
11:11:57 [ci] control `mutate-place-skips-the-insert-recheck`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-refused-spawn-keeps-the-count`
11:11:57 [ci] control `mutate-refused-spawn-keeps-the-count`: 1 verdict(s) reached
11:11:57 === [ci] control `mutate-landed-child-retires-nothing`
11:11:58 [ci] control `mutate-landed-child-retires-nothing`: 2 verdict(s) reached
11:11:58 === [ci] control `mutate-publish-before-the-children`
11:11:58 [ci] control `mutate-publish-before-the-children`: 1 verdict(s) reached
11:11:58 === [ci] control `mutate-walk-in-one-hold`
11:11:58 [ci] control `mutate-walk-in-one-hold`: 1 verdict(s) reached
11:11:58 === [ci] control `mutate-spawner-handle-after-the-landing`
11:11:58 [ci] control `mutate-spawner-handle-after-the-landing`: 2 verdict(s) reached
11:11:58 === [ci] control `mutate-spawner-handle-before-the-childs-own`
11:11:58 [ci] control `mutate-spawner-handle-before-the-childs-own`: 1 verdict(s) reached
11:11:58 === [ci] control `placement-ignores-staleness`
11:11:58 [ci] control `placement-ignores-staleness`: 1 verdict(s) reached
11:11:58 === [ci] control `mutate-session-end-forgets`
11:12:01 [ci] control `mutate-session-end-forgets`: 1 verdict(s) reached
11:12:01 === [ci] control `mutate-abort-keeps-inflight`
11:12:02 [ci] control `mutate-abort-keeps-inflight`: 1 verdict(s) reached
11:12:02 === [ci] control `mutate-no-reissue-after-loss`
11:12:02 [ci] control `mutate-no-reissue-after-loss`: 1 verdict(s) reached
11:12:02 === [ci] control `publish-relaxed`
11:12:02 [ci] control `publish-relaxed`: 1 verdict(s) reached
11:12:02 === [ci] control `no-clamp`
11:12:02 [ci] control `no-clamp`: 1 verdict(s) reached
11:12:02 === [ci] control `end-keeps-inflight`
11:12:02 [ci] control `end-keeps-inflight`: 1 verdict(s) reached
11:12:02 === [ci] userland/blockd
11:12:02 [ci] userland/blockd: cargo test --manifest-path userland/blockd/Cargo.toml --target aarch64-apple-darwin
11:12:02 === [ci] userland/calc
11:12:03 [ci] userland/calc: cargo test --manifest-path userland/calc/Cargo.toml --target aarch64-apple-darwin
11:12:03 === [ci] userland/fsd
11:12:04 [ci] userland/fsd: cargo test --manifest-path userland/fsd/Cargo.toml --target aarch64-apple-darwin
11:12:04 === [ci] userland/logd
11:12:04 [ci] userland/logd: cargo test --manifest-path userland/logd/Cargo.toml --target aarch64-apple-darwin
11:12:04 === [ci] userland/netd
11:12:04 [ci] userland/netd: cargo test --manifest-path userland/netd/Cargo.toml --target aarch64-apple-darwin
11:12:04 === [ci] userland/pkg
11:12:04 [ci] userland/pkg: cargo test --manifest-path userland/pkg/Cargo.toml --target aarch64-apple-darwin
11:12:04 === [ci] userland/soundd
11:12:04 [ci] userland/soundd: cargo test --manifest-path userland/soundd/Cargo.toml --target aarch64-apple-darwin
11:12:04 === [ci] userland/sshd
11:12:05 [ci] userland/sshd: cargo test --manifest-path userland/sshd/Cargo.toml --target aarch64-apple-darwin
11:12:05 === [ci] the apps for linux
11:12:06 [ci] the apps for linux: 11 app(s) pass `cargo check --target x86_64-unknown-linux-gnu`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
11:12:06 === [ci] the apps for macos
11:12:08 [ci] the apps for macos: 11 app(s) pass `cargo build --target aarch64-apple-darwin`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
11:12:08 === [ci] the apps for windows
11:12:09 [ci] the apps for windows: 11 app(s) pass `cargo check --target x86_64-pc-windows-msvc`; userland/doom, userland/proctest, userland/shell, userland/terminal, userland/toybox not attempted, as their manifests declare
11:12:09 === [ci] the toyos SDK
11:12:09 [ci] the toyos SDK: cargo test --manifest-path toyos/Cargo.toml --target aarch64-apple-darwin
11:12:09 === [ci] nothing left in $TMPDIR or /tmp
11:12:09 [ci] nothing left in $TMPDIR or /tmp: every test took its scratch with it
11:12:09 [ci] Host: 67 step(s), all green
EXIT=0

cargo run -- --build-only, from a checkout one commit behind its pin

head cfd4931a6a0e31b3403ed0a60682efe052c95d34; load 22.65 20.39 13.46; cargo run -- --build-only
    Finished `dev` profile [optimized + debuginfo] target(s) in 6.58s
     Running `target/debug/toyos-build --build-only`
11:12:16 …/toyos-forkmove/rust was at 01b8626673fcbe92000950d7be27a946e6b9a465, behind this tree's pin 95960d6c214338e9375b1c7c6c0d4e5ece4c4ba3: checked it out
    Finished `toyos` profile [optimized + debuginfo] target(s) in 0.11s
    Finished `toyos` profile [optimized + debuginfo] target(s) in 0.11s
    Finished `toyos` profile [optimized + debuginfo] target(s) in 4.39s
warning: the following packages contain code that will be rejected by a future version of Rust: winit v0.30.13 (https://github.com/ToyOSOrg/winit?branch=toyos-0.30.13#f58e1f3b)
note: to see what the problems were, use the option `--future-incompat-report`, or run `cargo report future-incompatibilities --id 1`
    Finished `toyos` profile [optimized + debuginfo] target(s) in 0.12s
11:12:22 root: adding 'bin/blockd' (982592 bytes)
11:12:22 root: adding 'bin/calc' (1547896 bytes)
11:12:22 root: adding 'bin/compositor' (3018360 bytes)
11:12:22 root: adding 'bin/doom' (2148320 bytes)
11:12:22 root: adding 'bin/editor' (997888 bytes)
11:12:22 root: adding 'bin/filepicker' (955488 bytes)
11:12:22 root: adding 'bin/files' (2792376 bytes)
11:12:22 root: adding 'bin/fsd' (1848392 bytes)
11:12:22 root: adding 'bin/host' (757552 bytes)
11:12:22 root: adding 'bin/init' (1587656 bytes)
11:12:22 root: adding 'bin/input-test' (741464 bytes)
11:12:22 root: adding 'bin/inspect' (933888 bytes)
11:12:22 root: adding 'bin/logd' (1245704 bytes)
11:12:22 root: adding 'bin/netd' (1326296 bytes)
11:12:22 root: adding 'bin/paint' (936352 bytes)
11:12:22 root: adding 'bin/pkg' (1047208 bytes)
11:12:22 root: adding 'bin/proctest' (908080 bytes)
11:12:22 root: adding 'bin/shell' (1022656 bytes)
11:12:22 root: adding 'bin/snake' (1248864 bytes)
11:12:22 root: adding 'bin/soundd' (1173384 bytes)
11:12:22 root: adding 'bin/sshd' (5418752 bytes)
11:12:22 root: adding 'bin/swap' (924248 bytes)
11:12:22 root: adding 'bin/terminal' (1034344 bytes)
11:12:22 root: adding 'bin/toybox' (1366640 bytes)
11:12:22 root: adding 'bin/toyos-ld' (2026624 bytes)
11:12:22 root: adding 'bin/update' (1015800 bytes)
11:12:22 root: adding 'etc/system.manifest' (1973 bytes)
11:12:22 root: adding 'share/doom1.wad' (4196020 bytes)
11:12:22 root: adding 'share/fonts/JetBrainsMono-Regular-8x16.font' (66404 bytes)
11:12:22 root: adding 'share/fonts/ofl.txt' (4216 bytes)
11:12:22 root: adding 'share/fonts/opensans-bold.ttf' (147264 bytes)
11:12:22 root: adding 'share/fonts/opensans-bolditalic.ttf' (153308 bytes)
11:12:22 root: adding 'share/fonts/opensans-italic.ttf' (153256 bytes)
11:12:22 root: adding 'share/fonts/opensans-regular.ttf' (147528 bytes)
11:12:22 root: adding 'share/hello.rs' (55 bytes)
11:12:22 root: adding 'share/icons/arrow-down-right-bold.svg' (211 bytes)
11:12:22 root: adding 'share/icons/crosshair-simple-bold.svg' (809 bytes)
11:12:22 root: adding 'share/icons/cursor-bold.svg' (560 bytes)
11:12:22 root: adding 'share/icons/file-bold.svg' (293 bytes)
11:12:22 root: adding 'share/icons/folder-bold.svg' (303 bytes)
11:12:22 root: adding 'share/icons/minus-bold.svg' (253 bytes)
11:12:22 root: adding 'share/icons/square-bold.svg' (264 bytes)
11:12:22 root: adding 'share/icons/x-bold.svg' (392 bytes)
11:12:22 root: adding 'share/soundfont.sf2' (15546764 bytes)
11:12:22 root: adding 'share/wallpaper.rgb' (6220808 bytes)
11:12:22 root: symlink 'bin/cat' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/cp' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/echo' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/free' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/grep' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/hexdump' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/locale' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/ls' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/mkdir' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/mv' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/net' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/ps' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/pwd' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/reboot' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/rm' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/screen' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/shutdown' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/spin' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/stats' -> '/system/bin/toybox'
11:12:22 root: symlink 'bin/tone' -> '/system/bin/toybox'
11:12:22 Signed with this checkout's throwaway key SHA256:<fingerprint replaced> at version 1791025936
11:12:23 Build finished.
Boot image: …/toyos-forkmove/target/bootable.img
EXIT=0

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

The review of e38dbc314, finding by finding, at cfd4931a6. The measurements are in the body and in the comments headed "Patches and fixture runs", "Runs in the worktree" and "Gate logs".

The hypothesis held as written. The make and the move are each one Held::act_if(Scope::Worktree, …) in fork_checkout, on the lock sysroot::ensure receives, and licence::std_library holds the worktree's lock shared for the call. Gone: the three make_fork_checkout call sites, the refusal in fork_checkout, the issue file the first round added and its four renames in the submodule issue.

BLOCKER

  • src/sysroot.rs:550, the two-process race: fixed. Two processes started together exit 0 and 0 with one Making … between them. A second process started when rust/.git appeared exits 0, as does the maker, and printed waiting for the build lock (shared, test image) — held by pid … (make the fork checkout).
  • src/licence.rs:1177, the licences step reaching ensure_shallow_fork: fixed, and reproduced in a fixture only. With the whole change reverted the reader returned while a real git worktree add was held mid-checkout, git traced git submodule--helper update --init --depth=1 -- rust in the linked worktree, and git status in the fixture primary's rust/ then exits 128 on cannot chdir to '../../../../../../linked/rust'. At the head the reader waits on the lock and the command runs 0 times.
    The fixture found a second way in that the lock does not close: what a maker killed with SIGKILL leaves has rust/.git and HEAD at the pin, so fork_checkout returns it, and at a8dcbccb2 the same command ran and broke the fixture primary the same way. ensure_shallow_fork now refuses a linked worktree by name, a_linked_worktree_initialises_no_submodule holds it, and removing the guard reds that test with exit 101.
  • src/sysroot.rs:647, the sibling: gone, as above.
  • issues/build/two-processes-starting-in-one-worktree-are-two-movers-of-its-fork-checkout.md:11, the record: the file is deleted, closed by the fix. What stays true of the half-made arm has one record, issues/build/a-fork-checkout-a-killed-git-worktree-add-left-is-taken-as-made.md: a build takes a killed maker's checkout as made, as on main.
  • tests/toyos.rs:4005, --list: gone. From the empty stub --list exits 0 and rust/ is still the empty stub; from one commit behind the pin it exits 0 and HEAD is not moved.
  • src/sysroot.rs:1498, the twelve-thread test of readers: gone with its helper and the second test. Its two refusals did not survive the redesign: a build makes and moves again, and refuses nothing it did not refuse on main. The twelve threads are now builds, in twelve_builds_at_once_make_and_move_one_fork_checkout, and the unlocked mutation reds it in 5 runs of 5 with eleven git worktree adds refused.

NOTE

  • src/sysroot.rs:1481, the ahead case: it asserts HEAD at C3 after the call, and the mutation the review names, a checkout ahead of its pin taken as off it, reds it with exit 101 on a checkout ahead of its pin was moved.

REMOVE

  • src/sysroot.rs:551, "Two movers of one checkout corrupt it": deleted, with the doc it stood in.

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of cfd4931a6 against origin/main (6a6c5faa5), round 2.

Net, git diff --shortstat origin/main...cfd4931a6: 7 files, +180 −135. Production +89 −65 (src/sysroot.rs +73 −59 above its test module, +26 −12 of it not indentation; src/lib.rs +9 −1; src/buildlock.rs +5 −4; src/licence.rs +2 −1). Tests +53 −6, all in src/sysroot.rs. Issues +38 −64. The production growth is two act_ifs and one refusal, each against a measured defect: accepted.

Evidence at the head: cargo run -- --ci host exit 0 with 67 steps, cargo test --test toyos-build exit 0 with 26 of 26 from an empty stub and 12 wide, cargo run -- --build-only exit 0 from a checkout one commit behind its pin, each with its log; the control is the whole change reverted onto the head, exit 1 from both states of rust/. The two closed issues' exits are met by those runs: one checked it out and three tests booted from behind the pin, and a new worktree's first run green 3 wide and 12 wide. No finding there.

Round 1's BLOCKERs

  • src/sysroot.rs:550, the two-process race does not land filed — CLOSED. From an empty stub two processes started together exit 0 and 0 with one Making … between them; a second started once rust/.git existed, with 1 of 37 top-level entries written, exits 0 as the maker does, after waiting for the build lock (shared, test image) — held by pid … (make the fork checkout) and 5.4 s. With the whole change reverted the same command exits 1 from the stub (already exists, twice) and 1 from behind the pin (index.lock': File exists, twice).
  • src/licence.rs:1177, the licences step reaching git submodule in a linked worktree — CLOSED, in a fixture only. At the head std_library, arriving while a real git worktree add is held mid-checkout, waits on the lock and git traces 0 git submodule commands; with the change reverted it returns while the maker is held, git traces git submodule--helper update --init --depth=1 -- rust once, and git status in the fixture primary's rust/ exits 128.
  • src/sysroot.rs:647, the sibling — CLOSED. git grep make_fork_checkout cfd4931a6 exits 1, git diff origin/main...cfd4931a6 -- tests src/main.rs is empty, and fork_checkout is two Held::act_if(Scope::Worktree, …) on the lock sysroot::ensure receives.
  • issues/build/two-processes-starting-in-one-worktree-are-two-movers-of-its-fork-checkout.md:11, the record — CLOSED. git grep of its slug at the head exits 1, and the race it filed is the first line's.
  • tests/toyos.rs:4005, --list — CLOSED. tests/toyos.rs is main's; --list exits 0 from the empty stub and leaves rust/ with 0 entries, and exits 0 one commit behind the pin and leaves HEAD there.
  • src/sysroot.rs:1498, a test of what a reader checks — CLOSED: both tests and their helper are gone. twelve_builds_at_once_make_and_move_one_fork_checkout stays. A type holds the half it can: fork_checkout takes &mut Held, so nothing reads the checkout without the worktree's lock. What is left is what git and flock do under twelve callers, which only the guest suite's first run reached, and a host test is the cheapest tier that does. It reds on the recorded failure: both act_ifs unlocked, exit 101 in 5 runs of 5, on eleven refused git worktree adds. At the head it is no race: no thread takes the exclusive lock until every other has decided and put its shared one down, so all twelve escalate on every run. And it guards what the reader of one diff would not: the track's toolchain item deletes src/buildlock.rs, and its exit measures two builds in two worktrees, which never reaches twelve in one.

Round 1's NOTE is done (HEAD asserted at C3; a checkout ahead of its pin moved, exit 101) and its REMOVE is deleted.

BLOCKER

None.

NOTE

  • src/lib.rs:130 — the runner's arm, a primary with no rust/x.py, is read and not run, and no runner has run this head: the pull request is a draft and gh pr checks 683 reads host, toolchain and guest as skipping. It needs no measurement before that. toolchain::owner answers Elsewhere only for a root that is not its own primary checkout, which a runner's is, and in the host job fork_checkout asks it of the same root one statement earlier in std_library and returns there, as on main. A red in it reds this pull request's own checks or its merge group and never main, so it stops this landing and no other. Marked ready, host and toolchain green at this head are the measurement, and the body's first "Unsure of" line takes their run before the pull request queues.
  • issues/build/a-fork-checkout-a-killed-git-worktree-add-left-is-taken-as-made.md:22 and the body's "What it does not fix" — "so the licence gate reds on it" and "The licence gate now refuses it by name" hold only for a kill before library/Cargo.toml is written. std_library (src/licence.rs:1179) reaches ensure_shallow_fork only without that file, which git ls-tree -r --name-only at the pin puts at path 2,930 of 61,561; two_pins has no such file at any point, and the 30,004-file run's own log lists it among the 253 files the kill left. Past it the gate reads what library/ holds and runs no git submodule. Both sentences say that, or go.
  • issues/build/a-fork-checkout-a-killed-git-worktree-add-left-is-taken-as-made.md:11 — filed and not fixed stands, on a record that names one kill of two. It records git killed; the kill src/buildlock.rs's header calls routine is the builder's alone. Then the kernel frees the lock at once, and git worktree add, the builder's child holding no descriptor of the lock (git_run is Command::status, and the lock file is opened close-on-exec), goes on writing: a build that starts then finds rust/.git, HEAD at the pin and the lock free. When that git ends, the checkout has no library/backtrace, the state the submodule issue's second paragraph records. All of it read, none measured: the issue says so as read and unmeasured, or the fixture measures it. Why filing stands: by reading, a build on either remains stops in llvm::key, because git writes the index last, git status -- src/bootstrap is not empty (30,007 status lines in the 30,004-file run) and refuse_uncommitted_bootstrap panics, under a sentence that names another cause. Nothing is built from it, and the destructive arm is the guard's.
  • the pull request's title, second clause — "no submodule is initialised in a linked worktree" is not true of the tree: src/sysroot.rs:554, ensure_submodule and bootstrap still run git submodule in a linked worktree's fork checkout, as the body's own second "does not fix" line says. The title is main's merge subject: it names ensure_shallow_fork, or rust. The test's name at src/sysroot.rs:1517 says the same.
  • the comment headed "Patches and fixture runs" (#issuecomment-5968630164) — the admin-directory listing of the 30,004-file run prints the local account's name and its group on nine lines, against that comment's own first paragraph and the owner's rule; the listing is masked or cut.

REMOVE

  • src/sysroot.rs:1513 — "No submodule is initialised in a linked worktree": :554 initialises one there.

LAND AFTER NAMED CHANGES

… issue says what the licence gate reaches

Round 2's review of cfd4931 on #683, its named changes.

`fork_checkout` and `ensure_submodule` still run `git submodule` in a linked
worktree's fork checkout, so "no submodule is initialised in a linked worktree"
is true of `ensure_shallow_fork` and not of the tree. The test is renamed to
`ensure_shallow_fork_initialises_no_submodule_in_a_linked_worktree`, and the
clause of its doc that claimed it of the tree is deleted.

The new issue said the licence gate reds on what a killed `git worktree add`
left. `licence::std_library` reaches `ensure_shallow_fork` only where the
checkout has no `library/Cargo.toml`, which the fixture's fork never has and
which the 30,004-file run's kill left among its 253 files; past it the gate
reads what `library/` holds. The issue now says that.

It also recorded one kill of two. The other is the builder's alone, with its
`git worktree add` still writing and the worktree's lock freed: the issue names
it as read from the code and unmeasured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Patches and fixture runs at cfd4931a6. Paths are written with their machine-specific parents as …/, <tmp>/ and <scratch>/. No line carried a MAC address, an IP address, a UUID or an e-mail address; the one key fingerprint, in the --build-only log, is replaced by a placeholder, and the owner and group columns of the one directory listing are written <user> and <group>.

Every patch was applied to the clean worktree with git apply --check and git apply, built, run, and reversed with git apply -R; each log ends with the empty git status --porcelain after it.

Mutation: the make and the move decide, then act, under no lock

--- a/src/sysroot.rs
+++ b/src/sysroot.rs
@@ -522,9 +522,8 @@
         Owner::Elsewhere(primary) => primary,
     };
     let pinned = pinned_fork(root);
-    lock.act_if(
-        Scope::Worktree,
-        "make the fork checkout",
+    let _ = &lock;
+    unlocked(
         || (!fork.join(".git").exists()).then_some(()),
         |()| {
             let stub = fs::read_dir(&fork).map_or(0, |d| d.count());
@@ -555,9 +554,7 @@
             }
         },
     );
-    lock.act_if(
-        Scope::Worktree,
-        "move the fork checkout to its pin",
+    unlocked(
         || {
             let head = git_out(&fork, &["rev-parse", "HEAD"]).trim().to_string();
             let ahead = Command::new("git")
@@ -591,6 +588,13 @@
     fork
 }
 
+/// The mutation: decide, then act, under no lock.
+fn unlocked<W>(decide: impl Fn() -> Option<W>, act: impl FnOnce(W)) {
+    if let Some(work) = decide() {
+        act(work);
+    }
+}
+
 /// What a sysroot's [`SOURCES`] says: its key, the fork checkout its std was
 /// built in, and the witness of the sources it was built from.
 fn sources_text(key: &Key, fork: &Path, witness: &str) -> String {

cargo test --lib -- twelve_builds a_worktree_pinning a_linked_worktree, five times: exit 101 each. The verdict lines, each panic with the line after it:

head cfd4931a6a0e31b3403ed0a60682efe052c95d34, mutation mutation-unlocked.patch
   Compiling toyos-build v0.1.0 (…/toyos-forkmove)
BUILD_EXIT=0
warning: unused import: `Scope`
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
Preparing worktree (detached HEAD f28c548)
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... FAILED
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
thread '<unnamed>' (93140425) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140426) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140420) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140429) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140423) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140430) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140424) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140427) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140421) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140422) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread '<unnamed>' (93140428) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-77974-0/fork-builds-1/linked/rust", "cf2e16ded05be4d941956c371ca01d4a0315a029"] in <tmp>/toyos-tmp-77974-0/fork-builds-1/primary/rust failed
thread 'sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout' (93138952) panicked at src/sysroot.rs:1500:13:
a scoped thread panicked
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 1.33s
EXIT=101 (run 1 of 5)
warning: unused import: `Scope`
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
HEAD is now at 33d4e07 C2
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... FAILED
Preparing worktree (detached HEAD 39a9294)
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
thread '<unnamed>' (93143354) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143356) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143368) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143371) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143355) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143364) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143367) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143358) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143360) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143359) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143366) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93143357) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-80353-0/fork-builds-2/linked/rust", "f02b0d7078df4814d27236ce916aedfa4fefd25a"] in <tmp>/toyos-tmp-80353-0/fork-builds-2/primary/rust failed
thread 'sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout' (93141914) panicked at src/sysroot.rs:1500:13:
a scoped thread panicked
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 1.04s
EXIT=101 (run 2 of 5)
warning: unused import: `Scope`
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
HEAD is now at 6cf1430 C2
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... FAILED
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
thread '<unnamed>' (93146065) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146071) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146066) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146069) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146077) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146070) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146068) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146082) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146078) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146074) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93146072) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-82607-0/fork-builds-2/linked/rust", "a4356eabdbc4edcaa68c13ab43f6e935d0817289"] in <tmp>/toyos-tmp-82607-0/fork-builds-2/primary/rust failed
thread 'sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout' (93144637) panicked at src/sysroot.rs:1500:13:
a scoped thread panicked
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 0.98s
EXIT=101 (run 3 of 5)
warning: unused import: `Scope`
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
Preparing worktree (detached HEAD d911f54)
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... FAILED
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
thread '<unnamed>' (93148851) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148865) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148854) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148862) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148855) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148860) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148853) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148861) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148858) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148852) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93148848) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-84933-0/fork-builds-2/linked/rust", "487335c7d09083af264cbc4fe246c155098ac99b"] in <tmp>/toyos-tmp-84933-0/fork-builds-2/primary/rust failed
thread 'sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout' (93147421) panicked at src/sysroot.rs:1500:13:
a scoped thread panicked
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 1.01s
EXIT=101 (run 4 of 5)
warning: unused import: `Scope`
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
HEAD is now at 7e8e2e8 C2
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... FAILED
Preparing worktree (detached HEAD 45f2f52)
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
thread '<unnamed>' (93151626) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151628) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151646) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151640) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151632) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151647) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151641) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151627) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151625) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151633) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151648) panicked at src/sysroot.rs:1055:5:
git ["worktree", "add", "--detach", "<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust", "e0a1a460e364b7b94eb189095254c510bdc8ea46"] in <tmp>/toyos-tmp-87259-0/fork-builds-2/primary/rust failed
thread '<unnamed>' (93151645) panicked at src/sysroot.rs:540:17:
<tmp>/toyos-tmp-87259-0/fork-builds-2/linked/rust pins no library/backtrace: ""
thread 'sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout' (93150203) panicked at src/sysroot.rs:1500:13:
a scoped thread panicked
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 0.98s
EXIT=101 (run 5 of 5)
RESTORE_EXIT=0
status after restore: []

Mutation: a checkout ahead of its pin is moved

--- a/src/sysroot.rs
+++ b/src/sysroot.rs
@@ -568,7 +568,7 @@
                 .current_dir(&fork)
                 .status()
                 .is_ok_and(|s| s.success());
-            (head != pinned && !ahead).then_some(head)
+            (head != pinned || !ahead).then_some(head)
         },
         |head| {
             let dirty = git_out(&fork, &["status", "--porcelain", "--ignore-submodules=none"]);

The same command, once: exit 101.

head cfd4931a6a0e31b3403ed0a60682efe052c95d34, mutation mutation-ahead.patch
   Compiling toyos-build v0.1.0 (…/toyos-forkmove)
BUILD_EXIT=0
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... ok
Preparing worktree (detached HEAD 644bc8d)
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... FAILED
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... ok
thread 'sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout' (93154769) panicked at src/sysroot.rs:1471:9:
assertion `left == right` failed: a checkout ahead of its pin was moved
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 1.10s
EXIT=101 (run 1 of 1)
RESTORE_EXIT=0
status after restore: []

Mutation: ensure_shallow_fork without its guard

--- a/src/lib.rs
+++ b/src/lib.rs
@@ -127,12 +127,6 @@
     if root.join("rust/x.py").exists() {
         return Ok(());
     }
-    if let toolchain::Owner::Elsewhere(_) = toolchain::owner(root) {
-        return Err(format!(
-            "{} is a linked worktree's fork checkout and is not whole: no submodule is initialised there",
-            root.join("rust").display()
-        ));
-    }
     let status = Command::new("git")
         .args(["submodule", "update", "--init", "--depth", "1", "rust"])
         .current_dir(root)

The same command, once: exit 101.

head cfd4931a6a0e31b3403ed0a60682efe052c95d34, mutation mutation-unguarded.patch
   Compiling toyos-build v0.1.0 (…/toyos-forkmove)
BUILD_EXIT=0
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
test sysroot::tests::a_linked_worktree_initialises_no_submodule ... FAILED
test sysroot::tests::a_worktree_pinning_another_fork_commit_gets_its_own_checkout ... ok
test sysroot::tests::twelve_builds_at_once_make_and_move_one_fork_checkout ... ok
thread 'sysroot::tests::a_linked_worktree_initialises_no_submodule' (93160824) panicked at src/sysroot.rs:1068:9:
git ["rev-parse", "HEAD"] in <tmp>/toyos-tmp-93598-0/fork-shallow-0/primary/rust: fatal: cannot chdir to '../../../../../../linked/rust': No such file or directory
test result: FAILED. 2 passed; 1 failed; 0 ignored; 0 measured; 401 filtered out; finished in 1.15s
EXIT=101 (run 1 of 1)
RESTORE_EXIT=0
status after restore: []

The fixture measurement

Two temporary tests in src/sysroot.rs, run alone with GIT_TRACE on and protocol.file.allow=always, since the fixture's remote is a path where the real one is a URL git may fetch. Every repository they touch is under $TMPDIR.

diff --git a/src/licence.rs b/src/licence.rs
index cc0b16556..f810bab5a 100644
--- a/src/licence.rs
+++ b/src/licence.rs
@@ -1173,7 +1173,7 @@ fn metadata(
 /// The fork's `library/`, checked out at the commit this tree pins. A checkout
 /// whose `rust/` was never initialised — a CI runner's — fetches that commit
 /// alone.
-fn std_library(root: &Path) -> Result<PathBuf, String> {
+pub(crate) fn std_library(root: &Path) -> Result<PathBuf, String> {
     let mut lock = crate::buildlock::shared(root, "the licences of what ships");
     let fork = crate::sysroot::fork_checkout(root, &mut lock);
     if !fork.join("library/Cargo.toml").exists() {
diff --git a/src/sysroot.rs b/src/sysroot.rs
index 73b5104fe..bc4860e91 100644
--- a/src/sysroot.rs
+++ b/src/sysroot.rs
@@ -1527,6 +1527,142 @@ mod tests {
         assert!(refused.as_ref().is_err_and(|why| why.contains("linked worktree")), "{refused:?}");
     }
 
+    // ---- MEASUREMENT, applied as a patch and never committed ----------------
+
+    /// [`two_pins`], whose fork checks `x.py` out through a filter that waits for
+    /// the returned file: a `git worktree add` there stops after it has written
+    /// `rust/.git`, `HEAD` and every file before `x.py`.
+    fn held_fixture(base: &Path) -> (PathBuf, PathBuf, String, PathBuf) {
+        let (primary, linked, _c1, c2) = two_pins(base);
+        let release = base.join("release");
+        write(&primary.join(".git/modules/rust/info/attributes"), "x.py filter=hold\n");
+        let hold = format!(
+            "n=0; until [ -e '{}' ] || [ $n -gt 1500 ]; do n=$((n+1)); sleep 0.02; done; cat",
+            release.display()
+        );
+        git(&primary.join("rust"), &["config", "filter.hold.smudge", &hold]);
+        (primary, linked, c2, release)
+    }
+
+    /// Return once `fork` is half-made: `rust/.git` and `HEAD` at `pin`, the
+    /// file before `x.py` written, `x.py` not.
+    fn half_made(fork: &Path, pin: &str) {
+        let deadline = std::time::Instant::now() + std::time::Duration::from_secs(20);
+        loop {
+            let head = Command::new("git").args(["rev-parse", "HEAD"]).current_dir(fork).output();
+            let at_pin = fork.join(".git").exists()
+                && head.is_ok_and(|o| String::from_utf8_lossy(&o.stdout).trim() == pin);
+            if at_pin && fork.join("library/std/src/lib.rs").exists() {
+                assert!(!fork.join("x.py").exists(), "the filter held nothing");
+                return;
+            }
+            assert!(std::time::Instant::now() < deadline, "the maker never got half-way");
+            std::thread::sleep(std::time::Duration::from_millis(5));
+        }
+    }
+
+    fn trace() -> String {
+        std::env::var("GIT_TRACE").ok().and_then(|file| fs::read_to_string(file).ok()).unwrap_or_default()
+    }
+
+    /// What git has traced since `seen` bytes that names a submodule command.
+    fn submodule_commands(seen: usize) {
+        let text = trace();
+        let ran: Vec<&str> =
+            text[seen..].lines().filter(|l| l.contains("built-in: git submodule")).collect();
+        eprintln!("MEASURE `git submodule` ran {} time(s): {ran:#?}", ran.len());
+    }
+
+    fn primarys_fork(primary: &Path, when: &str) {
+        let rust = primary.join("rust");
+        let out = |args: &[&str]| {
+            let o = Command::new("git").args(args).current_dir(&rust).output().unwrap();
+            format!(
+                "exit {:?} {:?} {:?}",
+                o.status.code(),
+                String::from_utf8_lossy(&o.stdout).trim(),
+                String::from_utf8_lossy(&o.stderr).trim()
+            )
+        };
+        eprintln!("MEASURE {when}: the primary fork's core.worktree: {}", out(&["config", "--get", "core.worktree"]));
+        eprintln!("MEASURE {when}: git status in the primary's rust/: {}", out(&["status", "--porcelain"]));
+    }
+
+    #[test]
+    fn measure_a_reader_arriving_while_the_checkout_is_made() {
+        let base = TempDir::new("fork-held");
+        let (primary, linked, c2, release) = held_fixture(&base);
+        let (fork, linked) = (linked.join("rust"), &linked);
+        primarys_fork(&primary, "before");
+        std::thread::scope(|s| {
+            let maker = s.spawn(|| {
+                let mut lock = buildlock::shared(linked, "the maker");
+                fork_checkout(linked, &mut lock)
+            });
+            half_made(&fork, &c2);
+            eprintln!("MEASURE half-made: rust/.git and HEAD at the pin; x.py {}", fork.join("x.py").exists());
+            let seen = trace().len();
+            let (tx, rx) = std::sync::mpsc::channel();
+            let reader = s.spawn(move || {
+                let read = crate::licence::std_library(linked);
+                let _ = tx.send(());
+                read
+            });
+            let early = rx.recv_timeout(std::time::Duration::from_secs(4)).is_ok();
+            eprintln!("MEASURE the reader returned while the maker was held: {early}");
+            submodule_commands(seen);
+            write(&release, "");
+            eprintln!("MEASURE the maker: {:?}", maker.join().map_err(|_| "panicked"));
+            eprintln!("MEASURE the reader: {:?}", reader.join().map_err(|_| "panicked"));
+            eprintln!("MEASURE after both: x.py {}", fork.join("x.py").exists());
+            submodule_commands(seen);
+        });
+        primarys_fork(&primary, "after");
+    }
+
+    #[test]
+    fn measure_a_reader_finding_what_a_killed_maker_left() {
+        use std::os::unix::process::CommandExt;
+        extern "C" {
+            fn kill(pid: i32, sig: i32) -> i32;
+        }
+        let base = TempDir::new("fork-killed");
+        let (primary, linked, c2, _release) = held_fixture(&base);
+        let fork = linked.join("rust");
+        fs::remove_dir(&fork).unwrap();
+        let mut maker = Command::new("git")
+            .args(["worktree", "add", "--detach", fork.to_str().unwrap(), &c2])
+            .current_dir(primary.join("rust"))
+            .process_group(0)
+            .spawn()
+            .unwrap();
+        half_made(&fork, &c2);
+        // SAFETY: the group is the maker's own, made by `process_group(0)`.
+        assert_eq!(unsafe { kill(-(maker.id() as i32), 9) }, 0);
+        eprintln!("MEASURE the maker, killed with its children: {:?}", maker.wait().unwrap());
+        let locked = fork.join(git(&fork, &["rev-parse", "--git-path", "locked"]));
+        eprintln!(
+            "MEASURE what it left: rust/.git {}, HEAD at the pin {}, x.py {}, git's `locked` {:?}",
+            fork.join(".git").exists(),
+            git(&fork, &["rev-parse", "HEAD"]) == c2,
+            fork.join("x.py").exists(),
+            fs::read_to_string(&locked)
+        );
+        primarys_fork(&primary, "before");
+        let seen = trace().len();
+        let mut lock = buildlock::shared(&linked, "a build");
+        let took = std::panic::catch_unwind(std::panic::AssertUnwindSafe(|| fork_checkout(&linked, &mut lock)));
+        eprintln!(
+            "MEASURE a build's fork_checkout on it: {:?}; x.py {}",
+            took.map_err(|_| "panicked"),
+            fork.join("x.py").exists()
+        );
+        drop(lock);
+        eprintln!("MEASURE the licence gate's std_library on it: {:?}", crate::licence::std_library(&linked));
+        submodule_commands(seen);
+        primarys_fork(&primary, "after");
+    }
+
     /// The primary's compiler under `base`: `rustc` and `rust-lld`, and the C
     /// toolchain `src/clang.rs` provisions beside them if `clang`; no cargo.
     fn primary_compiler(base: &Path, clang: bool) -> Compiler {

The control is git diff cfd4931a6 origin/main -- src tests with the first of the two tests, its maker calling fork_checkout(linked).

At cfd4931a6, the lock's still waiting repeats dropped:

head cfd4931a6a0e31b3403ed0a60682efe052c95d34, patch measure-head.patch
    Finished `test` profile [optimized + debuginfo] target(s) in 5.31s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)
running 1 test
test sysroot::tests::measure_a_reader_arriving_while_the_checkout_is_made ... 11:05:40 MEASURE before: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
11:05:40 MEASURE before: git status in the primary's rust/: exit Some(0) "" ""
11:05:40 Making <tmp>/toyos-tmp-75510-0/fork-held-0/linked/rust a fork checkout at bfa97dbceb660699f981635c16ec8456b44e8154 (a git worktree of the primary's)
Preparing worktree (detached HEAD bfa97db)
11:05:40 MEASURE half-made: rust/.git and HEAD at the pin; x.py false
11:05:40 [build-lock] waiting for the build lock (shared, the licences of what ships) — held by pid 75510 (make the fork checkout), 0s so far
11:05:44 MEASURE the reader returned while the maker was held: false
11:05:44 MEASURE `git submodule` ran 0 time(s): []
HEAD is now at bfa97db C2
Preparing worktree (detached HEAD 56b85ea)
HEAD is now at 56b85ea backtrace
11:05:45 [build-lock] acquired (shared, the licences of what ships) after 4.1s
11:05:45 MEASURE the maker: Ok("<tmp>/toyos-tmp-75510-0/fork-held-0/linked/rust")
11:05:45 MEASURE the reader: Ok(Ok("<tmp>/toyos-tmp-75510-0/fork-held-0/linked/rust/library"))
11:05:45 MEASURE after both: x.py true
11:05:45 MEASURE `git submodule` ran 0 time(s): []
11:05:45 MEASURE after: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
11:05:45 MEASURE after: git status in the primary's rust/: exit Some(0) "" ""
ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 405 filtered out; finished in 4.79s
EXIT=0 (measure_a_reader_arriving_while_the_checkout_is_made)
    Finished `test` profile [optimized + debuginfo] target(s) in 0.05s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)
running 1 test
test sysroot::tests::measure_a_reader_finding_what_a_killed_maker_left ... Preparing worktree (detached HEAD eba201b)
11:05:45 MEASURE the maker, killed with its children: ExitStatus(unix_wait_status(9))
11:05:45 MEASURE what it left: rust/.git true, HEAD at the pin true, x.py false, git's `locked` Ok("initializing\n")
11:05:45 MEASURE before: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
11:05:45 MEASURE before: git status in the primary's rust/: exit Some(0) "" ""
11:05:45 MEASURE a build's fork_checkout on it: Ok("<tmp>/toyos-tmp-76336-0/fork-killed-0/linked/rust"); x.py false
11:05:45 MEASURE the licence gate's std_library on it: Err("<tmp>/toyos-tmp-76336-0/fork-killed-0/linked/rust is a linked worktree's fork checkout and is not whole: no submodule is initialised there")
11:05:45 MEASURE `git submodule` ran 0 time(s): []
11:05:45 MEASURE after: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
11:05:45 MEASURE after: git status in the primary's rust/: exit Some(0) "" ""
ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 405 filtered out; finished in 0.69s
EXIT=0 (measure_a_reader_finding_what_a_killed_maker_left)
RESTORE_EXIT=0
status after restore: []

The control:

head cfd4931a6a0e31b3403ed0a60682efe052c95d34, patch measure-base.patch
    Finished `test` profile [optimized + debuginfo] target(s) in 5.45s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)
running 1 test
test sysroot::tests::measure_a_reader_arriving_while_the_checkout_is_made ... 11:05:52 MEASURE before: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
11:05:52 MEASURE before: git status in the primary's rust/: exit Some(0) "" ""
11:05:52 Making <tmp>/toyos-tmp-77052-0/fork-held-0/linked/rust a fork checkout at ad3d77359c770a57e77c1ec2a02f9ca393c88bc2 (a git worktree of the primary's)
Preparing worktree (detached HEAD ad3d773)
11:05:52 MEASURE half-made: rust/.git and HEAD at the pin; x.py false
11:05:52 MEASURE the reader returned while the maker was held: true
11:05:52 MEASURE `git submodule` ran 1 time(s): [
    "13:05:52.828504 git.c:502               trace: built-in: git submodule--helper update --init --depth=1 -- rust",
]
HEAD is now at ad3d773 C2
Preparing worktree (detached HEAD a8df64e)
HEAD is now at a8df64e backtrace
11:05:52 MEASURE the maker: Ok("<tmp>/toyos-tmp-77052-0/fork-held-0/linked/rust")
11:05:52 MEASURE the reader: Ok(Ok("<tmp>/toyos-tmp-77052-0/fork-held-0/linked/rust/library"))
11:05:52 MEASURE after both: x.py true
11:05:52 MEASURE `git submodule` ran 1 time(s): [
    "13:05:52.828504 git.c:502               trace: built-in: git submodule--helper update --init --depth=1 -- rust",
]
11:05:52 MEASURE after: the primary fork's core.worktree: exit Some(128) "" "fatal: cannot chdir to '../../../../../../linked/rust': No such file or directory"
11:05:52 MEASURE after: git status in the primary's rust/: exit Some(128) "" "fatal: cannot chdir to '../../../../../../linked/rust': No such file or directory"
ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 402 filtered out; finished in 0.79s
EXIT=0 (measure_a_reader_arriving_while_the_checkout_is_made)
RESTORE_EXIT=0
status after restore: []

At a8dcbccb2, the lock without the guard:

head a8dcbccb280038c0811c5195616fb1170cdb6d9a, patch measure-head.patch
    Finished `test` profile [optimized + debuginfo] target(s) in 5.23s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)
running 1 test
test sysroot::tests::measure_a_reader_arriving_while_the_checkout_is_made ... 10:57:51 MEASURE before: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
10:57:51 MEASURE before: git status in the primary's rust/: exit Some(0) "" ""
10:57:51 Making <tmp>/toyos-tmp-34363-0/fork-held-0/linked/rust a fork checkout at e3bc5171285f482a779647cdea48f4d3129ffd29 (a git worktree of the primary's)
Preparing worktree (detached HEAD e3bc517)
10:57:51 MEASURE half-made: rust/.git and HEAD at the pin; x.py false
10:57:51 [build-lock] waiting for the build lock (shared, the licences of what ships) — held by pid 34363 (make the fork checkout), 0s so far
10:57:55 MEASURE the reader returned while the maker was held: false
10:57:55 MEASURE `git submodule` ran 0 time(s): []
HEAD is now at e3bc517 C2
Preparing worktree (detached HEAD 27d4bb0)
HEAD is now at 27d4bb0 backtrace
10:57:55 [build-lock] acquired (shared, the licences of what ships) after 4.1s
10:57:55 MEASURE the maker: Ok("<tmp>/toyos-tmp-34363-0/fork-held-0/linked/rust")
10:57:55 MEASURE the reader: Ok(Ok("<tmp>/toyos-tmp-34363-0/fork-held-0/linked/rust/library"))
10:57:55 MEASURE after both: x.py true
10:57:55 MEASURE `git submodule` ran 0 time(s): []
10:57:55 MEASURE after: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
10:57:55 MEASURE after: git status in the primary's rust/: exit Some(0) "" ""
ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 404 filtered out; finished in 4.73s
EXIT=0 (measure_a_reader_arriving_while_the_checkout_is_made)
    Finished `test` profile [optimized + debuginfo] target(s) in 0.04s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-1bcdccf62ec13f12)
running 1 test
test sysroot::tests::measure_a_reader_finding_what_a_killed_maker_left ... Preparing worktree (detached HEAD 424c40c)
10:57:56 MEASURE the maker, killed with its children: ExitStatus(unix_wait_status(9))
10:57:56 MEASURE what it left: rust/.git true, HEAD at the pin true, x.py false, git's `locked` Ok("initializing\n")
10:57:56 MEASURE before: the primary fork's core.worktree: exit Some(0) "../../../rust" ""
10:57:56 MEASURE before: git status in the primary's rust/: exit Some(0) "" ""
10:57:56 MEASURE a build's fork_checkout on it: Ok("<tmp>/toyos-tmp-35207-0/fork-killed-0/linked/rust"); x.py false
10:57:56 MEASURE the licence gate's std_library on it: Ok("<tmp>/toyos-tmp-35207-0/fork-killed-0/linked/rust/library")
10:57:56 MEASURE `git submodule` ran 1 time(s): [
    "12:57:56.400653 git.c:502               trace: built-in: git submodule--helper update --init --depth=1 -- rust",
]
10:57:56 MEASURE after: the primary fork's core.worktree: exit Some(128) "" "fatal: cannot chdir to '../../../../../../linked/rust': No such file or directory"
10:57:56 MEASURE after: git status in the primary's rust/: exit Some(128) "" "fatal: cannot chdir to '../../../../../../linked/rust': No such file or directory"
ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 404 filtered out; finished in 0.68s
EXIT=0 (measure_a_reader_finding_what_a_killed_maker_left)
RESTORE_EXIT=0
status after restore: []

What a killed git worktree add leaves, in a fixture fork of 30,004 files

#!/bin/bash
# A scratch fixture, apart from every real repository: what a `git worktree add`
# killed mid-checkout leaves, and what git says of it afterwards.
set -u
S=<scratch>
rm -rf "$S/fx/killed" && mkdir -p "$S/fx/killed" && cd "$S/fx/killed" || exit 9
g() { git -c commit.gpgsign=false -c user.email=t@t -c user.name=t -c protocol.file.allow=always -c maintenance.auto=false -c gc.auto=0 "$@"; }

mkdir fork-src && cd fork-src && g init -q
mkdir -p library/std/src compiler src/bootstrap
printf 'pub fn a() {}\n' > library/std/src/lib.rs
printf '[workspace]\n' > library/Cargo.toml
printf '\n' > compiler/lib.rs; printf '\n' > x.py
i=0; while [ $i -lt 30000 ]; do d=src/bootstrap/d$((i/500)); mkdir -p $d; printf 'file %s\n' $i > $d/f$i.rs; i=$((i+1)); done
g add -A && g commit -qm C1; C1=$(g rev-parse HEAD)
printf 'pub fn b() {}\n' > library/std/src/lib.rs; g commit -qam C2; C2=$(g rev-parse HEAD)
cd ..
mkdir primary && cd primary && g init -q && printf 'x\n' > f && g add f
g submodule add -q ../fork-src rust && g commit -qm 'pins C2'
cd ..
g -C primary worktree add -q -b wt linked
echo "C1=$C1 C2=$C2"
echo "--- linked/rust entries (the stub): $(ls -A linked/rust | wc -l)"
echo "--- the fixture primary's core.worktree: $(git -C primary/rust config --get core.worktree)"
echo "--- start the maker and SIGKILL it once rust/.git exists and HEAD is the pin"
g -C primary/rust worktree add --detach "$PWD/linked/rust" "$C2" > add.log 2>&1 &
PID=$!
n=0; until { [ -e linked/rust/.git ] && [ "$(git -C linked/rust rev-parse HEAD 2>/dev/null)" = "$C2" ]; } || [ $((n+=1)) -gt 4000 ]; do sleep 0.005; done
CHILDREN=$(pgrep -P $PID)
kill -9 $PID $CHILDREN; wait $PID; echo "maker exit=$? after $n polls; children killed: $CHILDREN"
echo "--- add.log:"; cat add.log
echo "--- files written of 30004: $(find linked/rust -type f -not -name .git | wc -l)"
echo "--- library/Cargo.toml: $(ls linked/rust/library/Cargo.toml 2>&1)"
echo "--- x.py: $(ls linked/rust/x.py 2>&1)"
echo "--- HEAD: $(git -C linked/rust rev-parse HEAD 2>&1)"
echo "--- worktree list:"; git -C primary/rust worktree list --porcelain
echo "--- admin dir:"; ls -la primary/.git/modules/rust/worktrees/*/
echo "--- locked says: $(cat primary/.git/modules/rust/worktrees/*/locked 2>&1)"
echo "--- git rev-parse --git-path locked, in the remains: $(git -C linked/rust rev-parse --git-path locked 2>&1)"
echo "--- status lines in the remains: $(git -C linked/rust status --porcelain 2>&1 | wc -l)"
echo "--- a second add at the same path:"; g -C primary/rust worktree add --detach "$PWD/linked/rust" "$C2"; echo "exit=$?"
echo "--- worktree remove --force:"; g -C primary/rust worktree remove --force "$PWD/linked/rust"; echo "exit=$?"
echo "--- worktree remove --force --force:"; g -C primary/rust worktree remove --force --force "$PWD/linked/rust"; echo "exit=$?"
echo "--- linked/rust after: $(ls -A linked/rust 2>&1 | wc -l) entries, exists: $([ -e linked/rust ] && echo yes || echo no)"
echo "--- worktree list after:"; git -C primary/rust worktree list --porcelain
C1=379ae9d3568f6a414536a6dd4c5363b12a4ed2df C2=c24bc9a295d65ce517e9bb03430f434578c55b58
ls: linked/rust: No such file or directory
--- linked/rust entries (the stub):        0
--- the fixture primary's core.worktree: ../../../rust
--- start the maker and SIGKILL it once rust/.git exists and HEAD is the pin
<scratch>/fx-killed.sh: line 30: 71404 Killed: 9               g -C primary/rust worktree add --detach "$PWD/linked/rust" "$C2" > add.log 2>&1
maker exit=137 after 2 polls; children killed: 71406
--- add.log:
Preparing worktree (detached HEAD c24bc9a)
--- files written of 30004:      253
--- library/Cargo.toml: linked/rust/library/Cargo.toml
--- x.py: ls: linked/rust/x.py: No such file or directory
--- HEAD: c24bc9a295d65ce517e9bb03430f434578c55b58
--- worktree list:
worktree <scratch>/fx/killed/primary/.git/modules/rust
HEAD c24bc9a295d65ce517e9bb03430f434578c55b58
branch refs/heads/main

worktree <scratch>/fx/killed/linked/rust
HEAD c24bc9a295d65ce517e9bb03430f434578c55b58
detached
locked initializing

--- admin dir:
total 32
drwxr-xr-x@ 9 <user>  <group>  288 Oct  3 12:47 .
drwxr-xr-x@ 3 <user>  <group>   96 Oct  3 12:47 ..
-rw-r--r--@ 1 <user>  <group>   41 Oct  3 12:47 HEAD
-rw-r--r--@ 1 <user>  <group>    6 Oct  3 12:47 commondir
-rw-r--r--@ 1 <user>  <group>   87 Oct  3 12:47 gitdir
-rw-r--r--@ 1 <user>  <group>    0 Oct  3 12:47 index.lock
-rw-r--r--@ 1 <user>  <group>   13 Oct  3 12:47 locked
drwxr-xr-x@ 3 <user>  <group>   96 Oct  3 12:47 logs
drwxr-xr-x@ 2 <user>  <group>   64 Oct  3 12:47 refs
--- locked says: initializing
--- git rev-parse --git-path locked, in the remains: <scratch>/fx/killed/primary/.git/modules/rust/worktrees/rust/locked
--- status lines in the remains:    30007
--- a second add at the same path:
Preparing worktree (detached HEAD c24bc9a)
fatal: '<scratch>/fx/killed/linked/rust' already exists
exit=128
--- worktree remove --force:
fatal: cannot remove a locked working tree, lock reason: initializing
use 'remove -f -f' to override or unlock first
exit=128
--- worktree remove --force --force:
error: failed to delete '<scratch>/fx/killed/linked/rust': Directory not empty
exit=255
--- linked/rust after:        1 entries, exists: yes
--- worktree list after:
worktree <scratch>/fx/killed/primary/.git/modules/rust
HEAD c24bc9a295d65ce517e9bb03430f434578c55b58
branch refs/heads/main

@Japabu Japabu changed the title A worktree's fork checkout is made and moved under its build lock, and no submodule is initialised in a linked worktree A worktree's fork checkout is made and moved under its build lock, and ensure_shallow_fork initialises no submodule in a linked worktree Oct 3, 2026
@Japabu
Japabu marked this pull request as ready for review October 3, 2026 11:49
@Japabu
Japabu enabled auto-merge October 3, 2026 11:49
@Japabu
Japabu added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 1d2381b Oct 3, 2026
6 checks passed
@Japabu
Japabu deleted the wt/toyos-forkmove branch October 3, 2026 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant