Skip to content

Two T14 judges judge what their boots stage: hda_client_stall the second stream's resume, lan_dhcp_lease this boot's own lease - #684

Closed
Japabu wants to merge 6 commits into
mainfrom
wt/toyos-judges
Closed

Japabu wants to merge 6 commits into
mainfrom
wt/toyos-judges

Conversation

@Japabu

@Japabu Japabu commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Two T14 rows were red on main by their judges and not by ToyOS, so every T14 run exited 1. Both judges now judge what their boots stage. Head 9e709f7a2, on origin/main at 6a6c5faa5.

The T14

  • At c154c2220, the head before this one (the orchestrator's reading): three boots, each toyos-metal exit 0. hda_client_stall judged exit 0: soundd: suspended at 7.543, the second stream opened at 7.545 and soundd: resumed at 7.545, the job exited 0, and no audio error: line. lan_ judged exit 0, 4 passed, 0 failed, 2 boot(s): leased 192.168.1.48/24 from 192.168.1.1 in 13326 ms, the address the boot answered for its name at.
  • At this head no T14 reading exists yet. Since c154c2220 the stall job asks through another asker, the loop reads the claimed function's address before the flash and prints one line differently, and lanleasecase names the function again. The three boots are owed again and are staged (684-r2/metal/request.txt in the orchestrator's scratchpad); the orchestrator runs the machine and adds the reading.
  • The record's rows are not committed. Judging the c154c2220 boots wrote six, boot.testcases.* and boot.lantalkcase.*: each boot carried a red row on main, and a boot with a red adds none. boot.testcases.panel_max_us read 6582 there. The testcases boot of Every QEMU ceiling is at most three times what its test takes; wedges end in seconds; two LAN boots ride the talking boot #638's head read 3842, and every other recorded boot records 3608 to 3950 but testcases-deaf, at 5247. The rows come from the judging of this head's boots, and a panel_max_us outside that range is said here and not committed.

hda_client_stall

  • The judge asks for the second stream's resume, not two resumes. On the shared testcases boot the job's first stream opens 3 ms after the tone's is removed (5.681 removed, 5.684 opened, on the run of Every QEMU ceiling is at most three times what its test takes; wedges end in seconds; two LAN boots ride the talking boot #638's head), and soundd suspended 20 to 28 ms after a removal on the six removals the closed issue and that run's capture carry, so the first stream joins a running soundd. The resume the job stages is the second stream's, and client_stall_on_metal asks for a soundd: resumed after the first session's end.
  • The job holds no flat wait. It slept 500 ms before closing each stream and 300 ms after. A stream now plays one more stretch of tone after its last stall (60 periods, as between two stalls) and closes on the callback that ends it; each stretch's end is a channel message, bounded at 5 s. The second stream opens once soundd's own inspect answer reads sound.stream.state = suspended, bounded at 5 s, each ask by the asker's own 2 s; every bound panics by name.
  • Why a poll. soundd tells no client that it suspended, and a notification would ship for this test alone. Its inspect answer is the one place a client reads its state. The mix loop publishes once a wake and a draining device wakes it once a period, so the job asks once a period, the period read off the same answer.
  • One asker. userland/inspect is a library and a binary, as userland/blockd is. inspect::ask is what /system/bin/inspect and the job both call, and the MAX_SNAPSHOT_BYTES == ipc::MAX_FRAME_LEN assert toyos-inspect asks of a reader stands beside it. No SDK change. The test crate takes inspect as a path dependency on a crate of this tree; toyos-inspect was already there.

lan_dhcp_lease

  • The old premise. The loop read the address Ubuntu held on the I219 before the flash, pinged it across the reboot, and lan::on_metal refused a boot whose lease was another address, or whose reply fell outside the boot by the two operating systems' clocks. The bench's router leases ToyOS another address than Ubuntu (192.168.1.48 against .46 on the run of Every QEMU ceiling is at most three times what its test takes; wedges end in seconds; two LAN boots ride the talking boot #638's head), so the reply the judge counted was Ubuntu's, 39 s after this boot's stop.
  • The row stays, on this boot's own lease. The three passing rows do not hold what it holds: the lease record in netd's own lines on the shipping-shaped boot, netd's MAC against Ubuntu's reading of the same function, and that record tied to an address the boot answers at. lan_lease_report judges the probe's file on a boot armed with --exit-with-lease, and issues/diagnostics/netds-lease-probe-answers-a-question-its-lines-already-answer.md has that probe going because this row reads the lease.
  • The host already learns the address from the boot, so nothing is added to the loop: netd answers for the machine's name once it holds a lease, and the talking boot's loop reads the log served at the address the name answered with (talk.txt's talk_peer). The judge holds netd's lease record to that address. The ping of that address is lan_talk's: the loop refuses a boot whose address answered none before any judge is called.
  • What went with the old premise, having no reader left: Ping, Reply, the clock read of Driver::wire (date -u +%s), clock_skew, Refusal::Probe, four keys of boot.txt, Cable and its parser, bootlog::host_second_inside_this_boot with its margin and record_unix_secs, and icmp::wire_is_down with its arm in echo and its test. That arm read a send the host's routing refused as silence, for a probe asked across a reboot. The one caller of echo left asks an address a stream has just opened from, where such a send is the host's failing; either answer refuses the boot as Refusal::Talk.
  • The cable is still refused before the flash. Driver::wire reads the claimed function's IPv4 address and refuses a function that holds none as Refusal::Wire: exit 2, the loop's, with nothing written. brief_address and its test are main's. Both LAN boots name the function, so a bench whose cable is out has neither flashed. No judge reads the address; Wire carries it, so no Wire is built without one.
  • lan_lease_report loses a print. It printed the old ping and judged nothing by it. Its verdict is unchanged, the probe's exit code and report.

What the loop and the judge print

Nothing that identifies the owner's machines or network goes into this repository or onto a pull request (his ruling on this pull request), and a run's log and a judge's lines are what a pull request quotes. Three lines carried the T14's MAC or the bench's resolvers; none does at this head, in a commit of its own (9e709f7a2):

  • the loop's line for the claimed function names the interface and the address it holds, and the MAC crosses in boot.txt alone;
  • lan_dhcp_lease's [lan] leased … line counts the resolvers;
  • its red for a MAC that is not the one Ubuntu read names wire_mac in boot.txt and netd's record instead of quoting either.

The lease check's fixture is the T14's lantalkcase readback at c154c2220 with a locally administered MAC and two RFC 5737 addresses standing in for the machine's MAC and its resolvers. netd's own records in a boot's log carry both, as before; a readback is not committed.

Issues

Closed: hda-client-stall-reads-one-resume-where-its-judge-wants-two and the-benchs-router-leases-toyos-another-address-than-ubuntu, each of whose exit is its row passing on the T14 run of this head; and the-cable-judge-spends-two-premises-nothing-has-measured, since no judge compares the two operating systems' clocks or addresses any more. Their one durable line each is at client_stall_on_metal and lan::on_metal.

Filed, found beside the task and not fixed, each tooling with an exit condition: issues/audio/the-tone-client-waits-a-flat-200-ms-for-its-tail.md, issues/audio/hda-client-stall-prints-a-stream-error-and-passes.md, issues/build/lan-hold-holds-two-boots-open-for-a-flat-twenty-seconds.md.

Checks

The oracle is a recorded real failure: the T14's own lines. The stall check's fixture is the run of #638's head, the lease check's the run of c154c2220, and <capture> is the readback of #638's head (testcases, lantalkcase, lanleasecase, copied without their images), judged whole. All at 9e709f7a2; patches and outputs are in the round's comment.

command exit
cargo run -- --ci host (Host: 67 step(s), all green) 0
cargo run -- --build-only 0
cargo test --test toyos-checks metal_audio_judges 0
cargo test --test toyos-checks metal_lease_judged_is_this_boots_own 0
cargo test --lib -- an_interface_with_no_address_is_refused_by_name 0
control A: main's tests/common/audio.rs under metal_audio_judges 101
control B: main's lease judge and loop under metal_lease_judged_is_this_boots_own 101
control C: brief_address answering an address where the interface has none, under its test 101
cargo test --test toyos-build -- --metal --metal-readback <capture> hda_client_stall (PASS hda_client_stall) 0
cargo test --test toyos-build -- --metal --metal-readback <capture> lan_ (4 passed, 0 failed, 2 boot(s)) 0
control D: the whole change reverted (git diff 9e709f7a2 origin/main -- src tests userland), the same two commands 1, 1
staging, --metal --metal-readback <dir> hda_client_stall and lan_ (staged, nothing judged) 2, 2
  • Control A reds with the T14's stalled client refused a log it has to pass: soundd resumed 1 time(s), the T14 run's own red.
  • Control B reds with this readback names ["wire_mac"] and a cable is ping_addr, wire_mac and clock_skew together: the fixture is a readback this head's loop wrote, which main's reader refuses whole. The T14's two recorded findings are control D's.
  • Control C reds with called `Result::unwrap_err()` on an `Ok` value: 0.0.0.0.
  • Control D reds with FAIL hda_client_stall: soundd resumed 1 time(s), and with FAIL lan_dhcp_lease naming this boot leased 192.168.1.48 and the host pinged 192.168.1.46 and the reply -39 s apart (3 passed, 1 failed): main's judges on the T14's lines, for facts about the bench.
  • The new judges still red where a capture deserves it, in the committed checks: the T14's stall lines with the suspend and the second resume taken out; the T14's talking boot with the lease record naming another address than the one it answered at, with a MAC that is not netd's, and with no lease record.
  • What the two checks see that reading cannot: a judge's verdict on the machine's bytes. main's judges read as correct and were red on the T14's lines.

The stall job in a guest. No QEMU test runs it (audio is judged on the T14), and this change reaches no guest test: no test runs /system/bin/inspect, whose asker the job now shares. A temporary probe ran the job once on the Headless machine's virtio-sound and was restored:

arm, at 9e709f7a2 probe exit job exit soundd's records the row's judge on them
as committed 0 0 removed 2.272, suspended 2.303, opened 2.309, resumed 2.312 passes the resume; reds on deferred, which virtio-sound's queue does and the T14's ring does not
await_suspended() not called 0 0 removed 2.300, opened 2.303, no suspend between, no resume no soundd: resumed after the first stream's end

Lines

git diff --shortstat origin/main...9e709f7a2: 437 insertions, 895 deletions over 25 files. Build system (src/): +45, −563. Harness (tests/common, tests/toyos.rs): +57, −93. Host checks (tests/checks*): +112, −1. Guest binaries (tests/toyos-rust-tests): +73, −25. userland/inspect: +82, −65, the asker moved from its binary to its library. Issues: +68, −148.

Unsure

  • The stall job's shape moved. After its last stall a stream played a flat 500 ms and now plays 60 periods. The T14 run of c154c2220 carried no audio error: line under it; that line is filed, not judged.
  • The reach into src/metal.rs. The ping across the reboot was the old judge's premise, so it went with it; the alternative was to leave it running on two boots for a line nobody judges.
  • lanleasecase names the function again. It costs that boot three ssh reads, and Ubuntu has to hold a lease on the I219 when the loop asks, as on main.
  • What a judge prints. A red for the MAC no longer shows the two values side by side; a reader opens boot.txt and the log. If a judge should print them after all, 9e709f7a2 is the commit to revert.

🤖 Generated with Claude Code

https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm

Japabu and others added 3 commits October 3, 2026 11:52
…me, and this boot's own lease

hda_client_stall. The judge wanted two `soundd: resumed` in the job's
window, one per stream. On the shared `testcases` boot the job's first
stream opens 3 ms after the tone's is removed (5.681 to 5.684 on the T14
run of #638's head), and soundd suspends 20 to 25 ms after a removal, so
the first stream joins a running soundd and the window carries one
resume: the second stream's, which is the one the job stages. The judge
now asks for a resume after the first session's end.

The job itself waited a flat 500 ms before closing each stream and a flat
300 ms after it. A stream now plays one more stretch of tone after its
last stall and is closed on the callback that ends it, and the second
stream opens once soundd's own `inspect` answer reads `suspended`, asked
once a period, each wait bounded at 5 s and panicking by name.

lan_dhcp_lease. The loop read the address Ubuntu held on the I219 before
the flash, pinged it across the reboot, and the judge refused a boot whose
lease was another address or whose reply fell outside the boot by the two
operating systems' clocks. The bench's router leases ToyOS another address
than Ubuntu (192.168.1.48 against .46), so the reply it counted was
Ubuntu's, after the reset. The talking boot already tells the host its
address: netd answers for the machine's name once it holds a lease, and
the loop reads the log served there and pings it. The judge now holds the
lease record in netd's own lines to that address and to that ping.

With no judge of it left, the ping across the reboot goes: `Ping`,
`Reply`, the address and clock-skew reads of `Driver::wire`, four keys of
`boot.txt`, `Refusal::Probe`, `bootlog::host_second_inside_this_boot` and
its margin. `--nic` still reads the function's MAC, which the judge holds
netd's to. `lan_lease_report` printed that ping and judged nothing by it;
its boot no longer names the function.

Both judges are checked against the T14's own lines: each passes today's
capture and reds on it with the resume, the address, the ping or the MAC
taken away.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
…se; three flat waits and a printed stream error are filed

Closed, each by the judge no longer resting on what it named:

- hda-client-stall-reads-one-resume-where-its-judge-wants-two: the judge
  asks for the second stream's resume. Its exit is the row passing on the
  T14 run of this head.
- the-benchs-router-leases-toyos-another-address-than-ubuntu: the judge
  holds the lease to the address this boot answered the host at. Its exit
  is the row passing on the T14 run of this head.
- the-cable-judge-spends-two-premises-nothing-has-measured: no judge
  compares the two operating systems' clocks or addresses any more, and
  the reads that fed the comparison are gone.

Filed, found beside the task and not fixed:

- audio/the-tone-client-waits-a-flat-200-ms-for-its-tail
- audio/hda-client-stall-prints-a-stream-error-and-passes
- build/lan-hold-holds-two-boots-open-for-a-flat-twenty-seconds

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
… fixture says what its extra keys are

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Patches and runs behind the body's checks, at c154c2220. Each patch was applied with git apply, run, and reversed with git apply -R in the same script; git status --porcelain --ignore-submodules=none printed nothing after each.

Control A: main's stall judge under the new check (exit 101)

git diff c154c2220 ec7de748c -- tests/common/audio.rs, then cargo test --test toyos-checks metal_audio_judges:

diff --git a/tests/common/audio.rs b/tests/common/audio.rs
index b065cf7dd..ec0892336 100644
--- a/tests/common/audio.rs
+++ b/tests/common/audio.rs
@@ -106,19 +106,14 @@ pub(crate) const DEVICE_STARTED: &str = "soundd: resumed";
 /// buffer it completes, so soundd has to fill the periods the client did not
 /// cover (`underruns`) and may hold none of them back (`deferred`), across a
 /// suspend and a resume.
-///
-/// The resume is the second stream's, which the job stages. Whether the first
-/// stream finds soundd suspended is the job before it: on a shared boot it can
-/// open while soundd still plays that job's tail out.
 pub fn client_stall_on_metal(log: &Serial) -> Result<(), String> {
-    const JOB: &str = "test_rs_hda_client_stall";
     log.must_not_say("repeated completion for free buffer")?;
-    let first = job_window(log.text(), JOB, 1)?;
-    let window = job_window(log.text(), JOB, 2)?;
-    if !window[first.len()..].contains(DEVICE_STARTED) {
+    let window = job_window(log.text(), "test_rs_hda_client_stall", 2)?;
+    let resumes = window.matches("soundd: resumed").count();
+    if resumes < 2 {
         return Err(format!(
-            "no `{DEVICE_STARTED}` after the first stream's end — the second stream did not find \
-             a suspended daemon, so nothing here tests a resume:\n{window}"
+            "soundd resumed {resumes} time(s) — the second stream did not find a suspended \
+             daemon, so nothing here tests a resume:\n{window}"
         ));
     }
     if !window.contains("soundd: wakes=") {

Control B: main's lease judge and loop under the new check (exit 101)

The patch is 1044 lines and is exactly git diff c154c2220 ec7de748c -- src/metal.rs src/bootlog.rs tests/common/lan.rs tests/common/metal.rs tests/toyos.rs tests/toyos-rust-tests/src/bin/lan_hold.rs; then cargo test --test toyos-checks metal_lease_judged_is_this_boots_own.

The script's own output

== head c154c22203012bd7c270dbd611b58dd58c91d989
== green arm: both checks at this head
stall check, new judge: EXIT=0
lease check, new judge: EXIT=0
== control A: main's stall judge under the new check
stall check, main's judge: EXIT=101
== control B: main's lease judge and loop under the new check
lease check, main's judge: EXIT=101
== the capture, judged offline at this head
hda_client_stall over the capture: EXIT=0
lan_ over the capture: EXIT=0
== tree after: []

The stall job in a QEMU guest: the probe (exit 0)

cargo test --test toyos-build -- --nocapture stall_probe with this applied:

--- a/tests/toyos.rs
+++ b/tests/toyos.rs
@@ -188,6 +188,7 @@
     // no way to turn it back on, so only a machine QEMU reports stopping can
     // be asked. `machine_soft_off_decoded` reads the T14's own decode.
     "machine_shutdown",
+    "stall_probe",
 ];
 
 /// **The metal profile**: which registrations run on the ThinkPad T14, what
@@ -2289,6 +2290,22 @@
         "iommu_virtio_platform" => common::iommu::iommu_virtio_platform(test_config),
         "nested_nmi_is_loud" => faults::nested_nmi_is_loud(test_config),
         "machine_shutdown" => power::machine_shutdown(test_config),
+        "stall_probe" => {
+            let bins = qemu::build_toyos_bins(
+                &Path::new(env!("CARGO_MANIFEST_DIR")).join("tests/toyos-rust-tests"),
+            );
+            let mut guest =
+                QemuInstance::boot_with_options(test_config, &[], &bins, BootOptions::default());
+            let result = guest.run_test("test_rs_hda_client_stall", Duration::from_secs(120));
+            let text = format!(
+                "[kernel 1.000 cpu0] spawn: /system/bin/test_rs_hda_client_stall pid=9\n{}",
+                result.stdout
+            );
+            let verdict = audio::client_stall_on_metal(&serial::Serial::named("the probe", text));
+            eprintln!("PROBE exit={:?} error={:?}", result.exit_code, result.error);
+            eprintln!("PROBE-JUDGE {verdict:?}\nPROBE-END");
+            if result.exit_code == Some(0) { Ok(()) } else { Err("the stall job did not exit 0".to_string()) }
+        }
         other => Err(format!("unknown machine test {other}")),
     }
 }

The mutation: await_suspended() not called (job exit 0; the row's judge reds)

The probe patch and this one, same command:

--- a/tests/toyos-rust-tests/src/bin/hda_client_stall.rs
+++ b/tests/toyos-rust-tests/src/bin/hda_client_stall.rs
@@ -44,7 +44,7 @@
     // suspended: on a ring the drain gives the periods up rather than holding
     // them, so what the resume primes and where in the ring it starts are both
     // state the first stream left behind.
-    await_suspended();
+    let _ = await_suspended;
     play(2);
     println!("stalled {STALLS} then 2 times, soundd survived");
 }
== head c154c22203012bd7c270dbd611b58dd58c91d989
probe, await_suspended() not called: EXIT=0
tree after: []

soundd's records and the judge's verdict, as committed:

10:07:59 [serial 0] {0.467 soundd} soundd: suspended
10:07:59 [serial 0] {0.501 test-runner} ===TEST_START test_rs_hda_client_stall===
10:07:59 [serial 0] {0.518 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
10:07:59 [serial 0] {0.521 soundd} soundd: client 0 connected (id=0)
10:07:59 [serial 0] {0.522 soundd} soundd: resumed
10:08:01 [serial 0] {2.278 soundd} soundd: client 0 removed (closed)
10:08:01 [serial 0] {2.300 soundd} soundd: suspended
10:08:01 [serial 0] {2.313 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
10:08:01 [serial 0] {2.316 soundd} soundd: client 0 connected (id=1)
10:08:01 [serial 0] {2.317 soundd} soundd: resumed
10:08:01 [serial 0] {2.897 soundd} soundd: client 1 removed (closed)
10:08:01 [serial 0] {2.911 test-runner} ===TEST_END test_rs_hda_client_stall exit=0===
10:08:01 PROBE exit=Some(0) error=None
10:08:01 PROBE-JUDGE Err("soundd deferred 378 period(s) on a ring that replays every one and completes it again, which is the panic this exists for:\npid=9\nsoundd: opening stream: 44100Hz 2ch fmt=0\nsoundd: client 0 connected (id=0)\nsound
10:08:02 test result: ok. 1 passed, 1 total (10.1s; workers: 3s building, 7s testing)

and with the mutation:

10:13:54 [serial 0] {0.456 soundd} soundd: suspended
10:13:54 [serial 0] {0.492 test-runner} ===TEST_START test_rs_hda_client_stall===
10:13:54 [serial 0] {0.507 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
10:13:54 [serial 0] {0.510 soundd} soundd: client 0 connected (id=0)
10:13:54 [serial 0] {0.511 soundd} soundd: resumed
10:13:56 [serial 0] {2.275 soundd} soundd: client 0 removed (closed)
10:13:56 [serial 0] {2.280 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
10:13:56 [serial 0] {2.283 soundd} soundd: client 0 connected (id=1)
10:13:56 [serial 0] {2.859 soundd} soundd: client 1 removed (closed)
10:13:56 [serial 0] {2.872 test-runner} ===TEST_END test_rs_hda_client_stall exit=0===
10:13:56 PROBE exit=Some(0) error=None
10:13:56 PROBE-JUDGE Err("no `soundd: resumed` after the first stream's end — the second stream did not find a suspended daemon, so nothing here tests a resume:\npid=9\nsoundd: opening stream: 44100Hz 2ch fmt=0\nsoundd: client 0 connected (
10:13:56 test result: ok. 1 passed, 1 total (9.9s; workers: 4s building, 6s testing)

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of c154c2220 against origin/main (6a6c5faa5; merge base ec7de748c, and main has moved since by issue files only). Round 1: no earlier BLOCKER.

Evidence. cargo run -- --ci host at the head: exit 0 (judges/ci-host.log, Host: 67 step(s), all green). Guest tests reached: none, as the body says (both changed binaries are in RUST_SKIP; the harness changes are metal judges). Hardware: read at the head by the orchestrator in the comment above, and absent from the body (NOTE).

Growth. git diff --shortstat origin/main...c154c2220: 18 files, +358 −821. Production (src/ outside its test modules) +26 −365. Tests (src/ test modules and tests/) +270 −308. Issues +62 −148.

Rulings the brief asked for

  1. The poll is a wait on the event, not a flat wait. tests/toyos-rust-tests/src/bin/hda_client_stall.rs:107-128 ends on soundd's own reading and its bound panics by name; the period it sleeps between two asks decides nothing. Measured: with await_suspended() taken out the job still exits 0 and the judge reds (the mutation in the first comment), and on the T14 the second stream opened 2 ms after soundd: suspended (testcases/kernel.log:434-435, 7.543 and 7.545). Main holds the same shape in the same words, "a pace and never a verdict", at tests/toyos-rust-tests/src/census_wait.rs:16 and tests/toyos-rust-tests/src/netd_stream.rs:127,138, both with no bound of their own where this one has one. The flat wait was the 300 ms it replaces: a duration standing in for the reading. Nothing smaller turns the pace into a notification on this branch: the event is soundd's to send, and a soundd that sends it ships it for this test alone.
  2. hda_client_stall's judge still fails on a resume that does not happen, and is weaker on no claim the row makes. metal_audio_judges (exit 0 at the head) holds it twice: tests/checks/audio.rs:105-110, a log whose first stream resumed and whose second did not, is what pins "after the first stream's end" against "anywhere in the window", and :132-139 is the T14's own lines with the suspend and the second resume out; control A reds main's judge on the T14's lines. What it no longer asks is that the first stream start a stopped engine. Main's resumes < 2 asked that and the T14 never gave it behind the tone; neither the judge's doc nor the job claims it, and the first stream's eight stalls are judged as before (underruns, deferred, no repeated completion).
  3. lan_dhcp_lease still judges a lease, and one refusal the 556 lines held has no home. The lease is lease_in over netd's own record, held to the address the log stream opened from (tests/common/lan.rs:113-128); a log with no record reds (tests/checks/lan.rs:71-73); the T14 at the head read leased 192.168.1.48/24 from 192.168.1.1 in 13326 ms against peer .48. Its ping arm judges nothing (first NOTE). Of the rest: the reply's place in the boot is now sequence (metaltalk::converse asks its ping of the peer a logd connection has just carried a line from), the address match is lease.address != heard.peer, the half-cable refusals went with their keys, the MAC judge stayed. The one without a home is the second BLOCKER.

BLOCKER

  • tests/toyos-rust-tests/src/bin/hda_client_stall.rs:130-151 — inspect_sound is userland/inspect/src/main.rs:97-139's ask written a second time — a sibling of what the tree has. toyos-inspect/src/lib.rs:6 names one generic reader and :112 has the reader assert MAX_SNAPSHOT_BYTES == ipc::MAX_FRAME_LEN, which the copy drops. The body's reason, sparing toyos's identity, is not one: an asker both call needs no SDK change, as userland/blockd is a library and a binary for blockd_io (tests/toyos-rust-tests/Cargo.toml:15-17).
  • src/metal.rs:1096-1120 — Driver::wire no longer refuses a claimed function that holds no IPv4 address, and nothing else does — on main brief_address refused it before the flash as Refusal::Wire (the loop's, exit 2), and its test called a cable that is out "exactly the machine this loop must not go on to flash". At the head, by the code, that bench has both LAN boots flashed, lantalkcase's three rows red as Refusal::Talk (about_the_boot, exit 1) and lan_lease_report as netd's verdict: a red for the bench named as the boot's, which is the class of red this branch exists to end. The body lists brief_address among what had "no judge left"; it was a refusal, cut with its test. Restore it (the address itself need not be kept), or show by a reading what refuses that bench before the flash.

NOTE

  • tests/common/lan.rs:130-140, tests/checks/lan.rs:57-63 — the ping arm judges what the loop has already refused the boot for — talk_verdict reds a talk_ping no (src/metal.rs:2019, src/metaltalk.rs:1165), the loop always asks (src/metal.rs:1633), and a refused boot's rows are handed the refusal without a judge being called (tests/common/metal.rs:844, :1097-1100), so no readback that reaches on_metal carries no or none. The check's case plants a passed verdict beside talk_ping no, which no loop writes. The arm, the case, the doc's "and the host's ping" and the body's "and to that ping" go: the ping is lan_talk's.
  • src/icmp.rs:39-44,76-89,232-265 — wire_is_down, its arm in echo and its test were the deleted probe's (eeb3cf711: an address "down for the whole span it is asked across"); the one caller left asks an address a stream has just opened from. They go with the probe, or the body names the state of the talk's ping that reaches them and the comments say that.
  • tests/checks/lan.rs:18-22 — the fixture's boot.txt carries four keys no loop writes and no code reads, with a sentence to explain them; the T14 at this head left a readback without them (judges/metal/lantalkcase/), and the fixture is that one.
  • tests/checks/lan.rs:10,13,22 — the T14's MAC and the bench's ISP resolvers become a fixture in a public tree; on main only the issue this branch deletes names them, and the judge needs a MAC equal on both sides and any resolver. The owner's ruling, or a fixture that names neither.
  • issues/build/lan-hold-holds-two-boots-open-for-a-flat-twenty-seconds.md — filed as kind: finding with no exit condition, though it states a wait root CLAUDE.md forbids, as the-tone-client-waits-a-flat-200-ms-for-its-tail.md does under tooling with one — a compromise is recorded with an exit a build or test can fail.
  • src/lan.rs:16 — pub const LEASE has no reader outside its module since tests/common/lan.rs stopped importing it.
  • PR body and tests/metal/lenovo-20w0003amz.toml — the body still reads "No T14 reading exists at this head" and its Unsure section "not measured"; the reading is the orchestrator's comment, and the rows it wrote are uncommitted (judges/judge-hda.record-rows.patch, judges/judge-lan.record-rows.patch). The head that lands carries its own T14 reading in the body and that run's rows in the record; a head that changes the stall job or the loop owes the machine its changed boots again. boot.testcases.panel_max_us read 6582 where every boot but testcases-deaf records 3608 to 3950, and a recorded row is never moved by a later run (src/metaltimings.rs:7-9).

REMOVE

  • PR body, lan_dhcp_lease: "A readback written by the old loop still reads: the lease check's fixture is one."
  • tests/checks/lan.rs:18-19: "It also names 192.168.1.46, the address Ubuntu held on this MAC, which no judge reads."

SEND BACK

Japabu and others added 2 commits October 3, 2026 13:05
…se fixture that names nobody

Answers the review of c154c22 on #684.

The stall job asked soundd with a copy of `/system/bin/inspect`'s `ask`,
without the frame-size assert `toyos-inspect` asks of a reader. `userland/inspect`
is now a library and a binary, as `userland/blockd` is: `inspect::ask` is the
one asker, the assert stands beside it, and the reader and the job both call
it. No SDK change. The job's answer bound is the reader's 2 s where its copy
had 5 s.

`Driver::wire` reads the claimed function's IPv4 address again and refuses a
function that holds none as `Refusal::Wire`, before anything is written: exit
2, the loop's. c154c22 cut that read with the ping it fed, and a bench whose
cable is out would have had both LAN boots flashed and reported red as the
boot's. `brief_address` and its test are `main`'s; `Wire` carries the address
so a `Wire` without one cannot be built. `lanleasecase` names the function
again, so its boot is refused on that bench too. Nothing judges the address:
`boot.txt` carries `wire_mac` as before.

`lan_dhcp_lease`'s ping arm went: the loop refuses a talking boot whose
address answered no ping before any judge is called, so no readback that
reaches the judge carries `talk_ping no`, and the ping is `lan_talk`'s.

`icmp::wire_is_down`, its arm in `echo` and its test went with the probe they
were written for. The one caller left asks an address a stream has just
opened from, where a send the host's routing refuses is the host's failing.

The lease check's fixture is now the T14's `lantalkcase` readback at
c154c22, which carries none of the four keys the old loop wrote. Its MAC
and its two resolvers are stand-ins: a locally administered MAC and RFC 5737
addresses. The tree is public and the judge needs a MAC equal on both sides
and a resolver list that parses.

`lan::LEASE` lost its last reader outside its module and is private. The
`lan_hold` issue is `tooling` with an exit condition.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
…lvers

The owner's ruling on #684: nothing that identifies his machines or network
goes into this repository or onto a pull request. A run's log and a judge's
lines are what a pull request quotes, and three of them carried one or the
other: the loop's `the claimed function ... MAC ...` line, the lease judge's
`[lan] leased ... dns [...]` line on every pass, and its red for a MAC that is
not the one the operating system before the boot read, which quoted that MAC.

The loop's line now names the interface and the address it holds, which is a
private one; the MAC still crosses in `boot.txt`. The judge counts the
resolvers, and its red names where both MACs are read instead of quoting one.

netd's own records in a boot's log carry both, as before: those are the
product's lines and a readback is not committed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UDZQ6fSKw14e4w2TKTRfm
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Round 2, at 9e709f7a2: the answer to the review of c154c2220, and the patches and runs behind the body's checks. Each patch was applied with git apply, run, and reversed with git apply -R in the same script; git status --porcelain --ignore-submodules=none printed nothing before and after each.

Per finding

  • BLOCKER 1, the second asker. userland/inspect is a library and a binary; inspect::ask is the one asker, the frame-size assert stands beside it, and /system/bin/inspect and the stall job both call it. inspect_sound is gone. Measured in a guest: the probe below, exit 0, the job exit 0 with soundd: suspended before the second stream opens.
  • BLOCKER 2, the cable refusal. Driver::wire reads the claimed function's IPv4 address again and refuses one that holds none as Refusal::Wire before the flash; brief_address and an_interface_with_no_address_is_refused_by_name are main's; lanleasecase names the function again. Control C below is the refusal taken out: exit 101.
  • NOTE, the ping arm. Gone from lan::on_metal, its case from the check, and the doc's and the body's words with it.
  • NOTE, icmp::wire_is_down. Gone with its arm in echo and its test.
  • NOTE, the fixture's four keys; NOTE, the MAC and the resolvers; REMOVE, the fixture's sentence. The fixture is the T14's lantalkcase readback at c154c2220, which carries none of the four keys, with a locally administered MAC and two RFC 5737 addresses standing in.
  • NOTE, the lan_hold issue. kind: tooling, with an exit condition.
  • NOTE, lan::LEASE. Private.
  • NOTE, the body and the record. The body carries the reading of c154c2220 and says this head's is owed; no row is committed, and boot.testcases.panel_max_us is said there.
  • REMOVE, the body's sentence. Deleted.
  • Beyond the review, on the owner's ruling: the loop and the lease judge print neither the MAC nor the resolvers (9e709f7a2, a commit of its own).

The host checks, their controls and the capture: the script's own output

== head 9e709f7a2b8236c719c75812c0681515d908825b
== tree before: []
== green arm: the checks at this head
stall check, this head: EXIT=0
lease check, this head: EXIT=0
cable refusal's test, this head: EXIT=0
== control A: main's stall judge under the stall check
stall check, main's judge: EXIT=101
== control B: main's lease judge and loop under the lease check
lease check, main's judge and loop: EXIT=101
== control C: an interface with no address not refused
cable refusal's test, refusal taken out: EXIT=101
== the capture of #638's head, judged offline at this head
hda_client_stall over the capture, this head: EXIT=0
lan_ over the capture, this head: EXIT=0
== control D: the whole change reverted, over the same capture
hda_client_stall over the capture, main's tree: EXIT=1
lan_ over the capture, main's tree: EXIT=1
== tree after: []
  • Control A is git diff 9e709f7a2 origin/main -- tests/common/audio.rs, the patch quoted in the first comment, unchanged.
  • Control B is git diff 9e709f7a2 origin/main -- src/metal.rs src/bootlog.rs src/icmp.rs src/lan.rs tests/common/lan.rs tests/common/metal.rs tests/toyos.rs tests/toyos-rust-tests/src/bin/lan_hold.rs.
  • Control D is git diff 9e709f7a2 origin/main -- src tests userland: every file of the change outside issues/.
  • Control C:
diff --git a/src/metal.rs b/src/metal.rs
index 66bf690e8..88cd8c2b3 100644
--- a/src/metal.rs
+++ b/src/metal.rs
@@ -1058,7 +1058,7 @@ fn brief_address(iface: &str, text: &str) -> Result<std::net::Ipv4Addr, String>
     let cidr = line
         .split_whitespace()
         .nth(2)
-        .ok_or_else(|| format!("{iface} holds no IPv4 address: {line:?}"))?;
+        .unwrap_or("0.0.0.0/0");
     cidr.split('/')
         .next()
         .unwrap_or(cidr)

Judging the capture at this head wrote six rows into tests/metal/lenovo-20w0003amz.toml (boot.testcases.*, boot.lantalkcase.*), which the script restored: they are another head's numbers.

The stall job in a QEMU guest

cargo test --test toyos-build -- --nocapture stall_probe under the probe patch quoted in the first comment, which applies to this head unchanged; the second arm adds that comment's await_suspended() mutation.

== head 9e709f7a2b8236c719c75812c0681515d908825b
== tree before: []
probe, as committed: EXIT=0
== tree after: []
== head 9e709f7a2b8236c719c75812c0681515d908825b
== tree before: []
probe, await_suspended() not called: EXIT=0
== tree after: []

soundd's records and the judge's verdict, as committed:

11:09:24 [serial 0] {0.464 soundd} soundd: suspended
11:09:24 [serial 0] {0.496 test-runner} ===TEST_START test_rs_hda_client_stall===
11:09:24 [serial 0] {0.513 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
11:09:24 [serial 0] {0.516 soundd} soundd: client 0 connected (id=0)
11:09:24 [serial 0] {0.517 soundd} soundd: resumed
11:09:26 [serial 0] {2.272 soundd} soundd: client 0 removed (closed)
11:09:26 [serial 0] {2.303 soundd} soundd: suspended
11:09:26 [serial 0] {2.309 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
11:09:26 [serial 0] {2.312 soundd} soundd: client 0 connected (id=1)
11:09:26 [serial 0] {2.312 soundd} soundd: resumed
11:09:27 [serial 0] {2.847 soundd} soundd: client 1 removed (closed)
11:09:27 [serial 0] {2.848 pid=9 test-runner} stalled 8 then 2 times, soundd survived
11:09:27 [serial 0] {2.853 test-runner} ===TEST_END test_rs_hda_client_stall exit=0===
11:09:27 PROBE exit=Some(0) error=None
11:09:27 PROBE-JUDGE Err("soundd deferred 510 period(s) on a ring that replays every one and completes it again, which is the panic this exists for:\npid=9\nsoundd: opening stream: 44100Hz 2ch fmt=0\nsoundd: client 0 connected (id=0)\nsound
11:09:27 test result: ok. 1 passed, 1 total (13.8s; workers: 7s building, 6s testing)

and with await_suspended() not called:

11:15:05 [serial 0] {0.477 soundd} soundd: suspended
11:15:05 [serial 0] {0.510 test-runner} ===TEST_START test_rs_hda_client_stall===
11:15:05 [serial 0] {0.527 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
11:15:05 [serial 0] {0.530 soundd} soundd: client 0 connected (id=0)
11:15:05 [serial 0] {0.531 soundd} soundd: resumed
11:15:07 [serial 0] {2.300 soundd} soundd: client 0 removed (closed)
11:15:07 [serial 0] {2.303 tid=1 soundd} soundd: opening stream: 44100Hz 2ch fmt=0
11:15:07 [serial 0] {2.306 soundd} soundd: client 0 connected (id=1)
11:15:07 [serial 0] {2.864 soundd} soundd: client 1 removed (closed)
11:15:07 [serial 0] {2.865 pid=9 test-runner} stalled 8 then 2 times, soundd survived
11:15:07 [serial 0] {2.869 test-runner} ===TEST_END test_rs_hda_client_stall exit=0===
11:15:07 PROBE exit=Some(0) error=None
11:15:07 PROBE-JUDGE Err("no `soundd: resumed` after the first stream's end — the second stream did not find a suspended daemon, so nothing here tests a resume:\npid=9\nsoundd: opening stream: 44100Hz 2ch fmt=0\nsoundd: client 0 connected (
11:15:07 test result: ok. 1 passed, 1 total (10.3s; workers: 4s building, 7s testing)

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

T14 at c154c2220, run by the orchestrator from judges/metal/request.txt: three boots, each image's sha256 checked against the request before it was flashed, each toyos-metal exit 0; then the two judges from the clean worktree at the head.

boot image sha256 toyos-metal
testcases 7eaba6571ec2fd716b4d72d1b33b1388677c3f6319daf593382e22734580da33 exit 0
lanleasecase b8f489d29bc468bff71616f311a9952200ffb6ccb19cf59b96c1468bc2169a89 exit 0; its loop log holds no the claimed function, answered a ping or nothing answered line
lantalkcase (--nic 0000:00:1f.6 --talk …) 3ac72a4ed7ff1507822022a00775f672dda973ed6dfa29f76771d513d4deb3cc exit 0; the claimed function 0000:00:1f.6 is enp0s31f6, MAC <the T14's own> with no address; talk: 192.168.1.48 answered a ping; Boot: complete (1151 ms) carried 700 ms after the stream opened; reboot accepted
  • hda_client_stall: exit 0. PASS hda_client_stall; 1 passed, 0 failed, 1 boot(s). In testcases/kernel.log, the stall job's lines in order: :429-431 the first stream opens, connects (id=1) and is removed; :434 soundd: suspended; :435-436 the second stream opens and connects (id=2); :437 soundd: resumed; :438 removed; :441 stalled 8 then 2 times, soundd survived; :453 exit: test_rs_hda_client_stall pid=12 code=0. No audio error: line among them.
  • lan_: exit 0. PASS lan_dhcp_lease (leased 192.168.1.48/24 from 192.168.1.1 in 13326 ms; 192.168.1.48, where this boot answered for its name, answered the host's ping), PASS lan_message_delivery, PASS lan_lease_report (netd exit 83; 5 sent and 10 received; no ping line under it), PASS lan_talk (415 lines over the cable in the stick's order). 4 passed, 0 failed, 2 boot(s).

Each judging ended tests/metal/lenovo-20w0003amz.toml now records 76 number(s) for this machine: commit it. The rows it wrote are saved, not committed, and the worktree was restored clean: judges/judge-hda.record-rows.patch and judges/judge-lan.record-rows.patch (14 lines each), for this branch to carry.

Readbacks and judge logs: /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/judges/ (metal/…, judge-hda.log, judge-lan.log).

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

T14 at 9e709f7a2, run by the orchestrator from 684-r2/metal/request.txt: three boots, each image's sha256 checked against the request before it was flashed, each toyos-metal exit 0; then the two judges from the clean worktree at the head. Values that identify the bench are masked or absent by the owner's rule; the judges at this head print none.

boot image sha256 toyos-metal
testcases 3d0caae62bb73255211ae824667e006aa8a85ff844054b643561efa9c04b102d exit 0
lanleasecase (--nic 0000:00:1f.6) 02b1d47c842d3c074fca73465ad92b0de5317d743261b94343874c7af1edf999 exit 0; before the flash, the claimed function 0000:00:1f.6 is enp0s31f6 at 192.168.1.46
lantalkcase (--nic … --talk …) 74f3d04a494f8d542ef9fa17556e9f6ddfc037e74c0434699ec7b1f91747ed39 exit 0; the same claimed-function line; talk: 192.168.1.48 answered a ping; Boot: complete (1152 ms) carried 699 ms after the stream opened; reboot accepted
  • hda_client_stall: exit 0. PASS hda_client_stall; 1 passed, 0 failed, 1 boot(s). In testcases/kernel.log, the stall job's lines in order: :429-431 the first stream; :434 soundd: suspended; :435-436 the second stream opens and connects; :437 soundd: resumed; :441 stalled 8 then 2 times, soundd survived; :453 exit: test_rs_hda_client_stall pid=12 code=0.
  • lan_: exit 0. PASS lan_dhcp_lease (leased 192.168.1.48/24 from 192.168.1.1 in 13285 ms, gateway 192.168.1.1, 2 resolver(s)), PASS lan_message_delivery, PASS lan_lease_report (netd exit 83; 6 sent and 12 received), PASS lan_talk (415 lines over the cable in the stick's order). 4 passed, 0 failed, 2 boot(s).

Each judging ended … now records 76 number(s) for this machine: commit it; the rows are saved as 684-r2/judge-hda.record-rows.patch and 684-r2/judge-lan.record-rows.patch and not committed (the body says why boot.testcases.panel_max_us is not taken from one boot). The worktree was clean before and after.

Readbacks and judge logs: orch/684-r2/ (metal/…, judge-hda.log, judge-lan.log).

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of 9e709f7a2 against origin/main (6a6c5faa5), round 2. Since round 1's c154c2220: 1c06a0b94 (a merge of main, issue files only, no conflict), 92bdd976b and 9e709f7a2.

Round 1's BLOCKERs

  • CLOSED: the second asker. inspect_sound is in no file at the head. userland/inspect/src/lib.rs's ask, its bound and the MAX_SNAPSHOT_BYTES assert differ from what main holds in main.rs by pub alone (diffed), and /system/bin/inspect and the stall job both call it. Measured: cargo run -- --build-only (684-r2/build-only.log ends Build finished.) and cargo run -- --ci host exit 0 at the head; the job through that asker exits 0 in the guest probe with soundd: suspended before the second stream opens; on the T14 at this head testcases/kernel.log:431-437 reads removed 7.521, suspended 7.542, opened 7.545, resumed 7.546, :453 the job's code=0, and the row is PASS hda_client_stall.
  • CLOSED: the cable refusal before the flash. brief_address and an_interface_with_no_address_is_refused_by_name are byte for byte main's (diffed); Driver::wire builds no Wire without the address (src/metal.rs:1148-1152) and run asks it at :1877, before flash at :1886; LANLEASECASE names lan::NIC as on main. Measured: the test exits 0 at the head and 101 under control C; on the T14 at this head both LAN boots printed the claimed function 0000:00:1f.6 is enp0s31f6 at … before their flash.

Round 1's NOTEs and REMOVEs are taken, all but the body and the record: the first NOTE below.

Evidence. cargo run -- --ci host at 9e709f7a2: exit 0 (684-r2/ci-host.log and ci-host.head; Host: 67 step(s), all green). Guest tests reached: none. At the head tests/ names inspect in the stall job and its manifest alone, and that job is in RUST_SKIP. Hardware: read at this head by the orchestrator in the comment above; the three verdict.txt read passed, 684-r2/judge-hda.log ends 1 passed, 0 failed, 1 boot(s) and judge-lan.log 4 passed, 0 failed, 2 boot(s). The body does not carry it (NOTE).

Growth. git diff --shortstat origin/main...9e709f7a2: 25 files, +437 −895. Production: src/ outside its test modules +34 −360; userland/inspect +82 −65, the asker moved. Tests: src/ test modules +11 −203; tests/ +242 −119. Issues +68 −148.

What identifies the bench. Searched without printing a value: the head's tree, the body with its three recorded edits, and the five comments, for the bench's own MAC and resolvers and for any universally administered MAC, public IPv4 address or email. None. The lease fixture's MAC is locally administered and its resolvers are RFC 5737's.

BLOCKER

None.

NOTE

  • PR body, "The T14"; tests/metal/lenovo-20w0003amz.toml — the body still reads "At this head no T14 reading exists yet" and "The record's rows are not committed", and the record lacks the rows this head's judging wrote — the reading exists (the comment above), and the reason the body gives for holding a row back is gone: boot.testcases.panel_max_us read 3810 and boot.lantalkcase.panel_max_us 3919, inside the 3608 to 3950 the record's other boots hold. The body carries this head's reading in place of both bullets, and the record takes the six rows of 684-r2/judge-hda.record-rows.patch and 684-r2/judge-lan.record-rows.patch (boot.testcases.* 1152, 3810, 20866; boot.lantalkcase.* 1152, 3919, 20906).
  • PR body, "What the loop and the judge print"; src/metal.rs:1935; src/lan.rs:46,53; tests/common/metal.rs:208,210 — "a run's log and a judge's lines are what a pull request quotes. Three lines carried the T14's MAC or the bench's resolvers; none does at this head" reads as a run's log being clear of both, and it is not — the loop prints the stick's log whole (print!("{loader}{log}"), which drive leaves on the run's stdout), and this head's own lanleasecase and lantalkcase readbacks hold in that text one netd: MAC record equal to boot.txt's wire_mac and one lease record naming two public resolvers (counted in 684-r2/metal/*/kernel.log, not printed here); lease_in's refusals quote the lease record whole into lan_dhcp_lease's red, and Readback::new's quote boot.txt whole. The body says which three lines no longer carry them and that a run's log and those reds still do, so whoever quotes one masks it.
  • the landing commit — the branch is to be recreated as one commit, and nothing measured here names it. Its tree is 9e709f7a2's plus the six rows above and the two source REMOVEs below, and nothing else: git diff --stat 9e709f7a2 <landing> names tests/metal/lenovo-20w0003amz.toml, src/metal.rs and userland/inspect/src/lib.rs alone, comments and rows, which changes no boot and no judge, so the T14 reading at 9e709f7a2 is its reading. cargo run -- --ci host is run at it and the body gives its exit; the body names it as the head and cites no commit main will not have (today it cites 9e709f7a2 and c154c2220). A landing commit that differs by more owes the machine the boots it changes, and a review.

REMOVE

  • src/metal.rs:1878-1879: "The MAC goes to the readback and not to this log, which is quoted in public." It is false: :1935 prints netd's own MAC record into the same log.
  • userland/inspect/src/lib.rs:2-4: "/system/bin/inspect is src/main.rs beside this; a library so a program that waits on an owner's state asks as the reader does." userland/inspect/Cargo.toml:7-9 says it.
  • PR body, "The T14": the bullet "At c154c2220, the head before this one".
  • PR body, "Unsure": "If a judge should print them after all, 9e709f7a2 is the commit to revert."

LAND AFTER NAMED CHANGES

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #685: the same change as one commit on a fresh branch, so that earlier commits of this branch never reach main. The reviews and the T14 runs recorded here are #685's evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant