Skip to content

ToyOS writes its own crate where security asks, above all on a trust boundary or in the kernel; a host test reds on a kernel that resolves libc, and the owner's allocator ruling is filed - #696

Merged
Japabu merged 5 commits into
mainfrom
wt/toyos-cratesrule
Oct 3, 2026

Conversation

@Japabu

@Japabu Japabu commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

What changed, and why

Root CLAUDE.md, Dependencies: the owner's crate ruling

The owner's words, 2026-10-03:

"Code is a liability but if it makes sense we wrote our own elf parser or aml interpreter due to security or other important reasons we do it. Especially if we can make a crate with a clear boundary and is well tested"
"Especially in the kernel im worried about community crates"

The orchestrator then put a formulation to him: "a crate on a trust boundary or in the kernel is ours, with a clear boundary and tests, and everywhere else the ecosystem's". He answered:

"Our kernel must not depend on libc"
"Yes add a fitting rule to claudemd"

The old sentence ("Only general and widely used crates — one that does our job we write ourselves, and a driver crate never; third-party crates are used as published, and a fork carries …") is replaced by two sentences. Nothing else in the file changes.

  • The general rule is unchanged, only reworded: general and widely used crates, used as published, a crate that does our job written by us, no driver crate, and a fork kept only until upstream has the change. This is the accepted formulation's "everywhere else the ecosystem's".
  • The new sentence: "Where security or another important reason asks, above all on a trust boundary or in the kernel, we write our own crate, with a clear boundary and well tested; the kernel takes as few community crates as it can justify and depends on no libc."

Where each part comes from:

  • The owner's words. "Security or other important reasons" and "we do it" (we write our own crate). "A crate with a clear boundary and is well tested". "Especially in the kernel" (above all in the kernel). "Our kernel must not depend on libc".
  • The formulation he accepted. "On a trust boundary". Its "with a clear boundary and tests" also attaches the boundary and the tests to the crate, as the sentence does.
  • Neither. "As few community crates as it can justify" is the brief's statement, as a rule, of his worry about community crates in the kernel.

Why the sentence keeps the owner's condition and does not state the accepted formulation as an absolute: his own words make writing our own conditional ("if it makes sense … due to security or other important reasons we do it"). The accepted formulation says where that matters most, and the sentence keeps both.

libc: locked only, never compiled or linked

kernel/Cargo.lock names libc, windows-sys and windows-link. Where they come from: dlmalloc 0.2.13 declares libc under cfg(all(unix, not(target_arch = "wasm32"))) and windows-sys under cfg(target_os = "windows"), and windows-link comes in through windows-sys.

Neither kernel target satisfies either cfg. rustc --print cfg shows target_os="none" and no target_family for x86_64-unknown-none and for aarch64-unknown-none-softfloat, under both the stable compiler and the toyos fork compiler the kernel builds with.

What was measured in round 1, for both targets:

Measurement x86_64 aarch64
cargo tree --locked --offline --target <t> -e all -i libc (same for windows-sys and windows-link) "nothing to print", EXIT=0 "nothing to print", EXIT=0
Positive control: the same with --target all libc → dlmalloc → kernel, EXIT=0 (same command)
cargo +toyos build --unit-graph -Z unstable-options --profile toyos --target <t>: registry crates in the graph cfg-if, dlmalloc, hashbrown and rustc-demangle only, EXIT=0 the same, EXIT=0
Fresh worktree build (cargo run -- --build-only, and --arch aarch64 --build-only): libc or windows artifact in the deps directory none (EXIT=0) none (EXIT=0)
Kernel ELF: llvm-nm -u no undefined symbol no undefined symbol
Kernel ELF: llvm-readobj --needed-libs NeededLibraries [ ] NeededLibraries [ ]

So nothing was compiled that needed removing.

The lock entry goes with dlmalloc. The owner ruled on 2026-10-03 that the kernel's dlmalloc is replaced by our own allocator. This PR files that ruling as issues/kernel/toyos-has-its-own-allocator.md (below), whose exit removes libc, windows-sys and windows-link from kernel/Cargo.lock.

A host test that sees what the lock cannot

build::tests::the_kernel_resolves_no_libc_for_either_target (src/build.rs). For each Arch::kernel() it runs cargo tree --locked --all-features -e normal,no-proc-macro --target <t> on kernel/Cargo.toml. It reds if the kernel resolves libc. It also reds if cargo fails or prints no kernel root, so a changed output format cannot pass it vacuously.

Why a check and not only a sentence:

  • While dlmalloc is in the kernel, kernel/Cargo.lock names libc whatever the kernel targets take. So a dependency bump that widened its libc edge to a none target would change no line that names libc.
  • The negative control below shows the failure is otherwise silent: libc compiles for x86_64-unknown-none and the kernel builds green.

The test goes when dlmalloc does: issues/kernel/toyos-has-its-own-allocator.md's exit deletes it in the pull request that removes dlmalloc from the kernel.

Where it lives: in an existing gate, cargo run -- --ci host's "the build system" step (cargo test --lib). It costs about 0.1 s per target (/usr/bin/time, 0.11 s and 0.05 s real).

What it deliberately leaves out:

  • windows-sys and windows-link, because the ruling names libc only.
  • Build-dependencies and proc-macros, which run on the host and are not linked into the kernel.

Two issues filed

  • issues/kernel/toyos-has-its-own-allocator.md (track, owner the orchestrator) records the owner's allocator ruling of 2026-10-03, which no file recorded before: our own allocator crate, one core with two fronts; the kernel's first, built host-first and swapped in after the three steps of issues/kernel/toyos-beats-linuxs-latency-on-the-t14.md; std's for programs later, after measuring against dlmalloc; and the 2 MiB heap-growth stall fixed now. Its evidence for the stall is the code path: heap growth runs pmm::alloc_page, which scans the page bitmap and zeroes 2 MiB, inside ALLOCATOR.dlmalloc.lock(). Its length on the T14 is unmeasured, and the file says so. Its exit also deletes this PR's test.
  • issues/build/the-kernels-libc-test-reads-the-host-compilers-cfg-not-the-forks.md (tooling, owner the orchestrator) records the gap this branch found: the test resolves with the host's compiler, stable on CI, whose host job installs no ToyOS toolchain, while the kernel builds with the fork. Measured (comment 5973730043): rustc --print cfg on both kernel targets, stable 1.98.1 against the fork's 1.99.0-dev, every run EXIT=0. The fork prints every line stable prints and adds more, target_feature="x87" on x86_64 among them. The two agree on target_os, target_arch and the absence of unix, which are what dlmalloc 0.2.13 gates its libc and windows-sys edges on, so the test's verdict is the fork's today. Exit: the test resolves against the building compiler's cfg, or it is deleted with dlmalloc. The gap is recorded rather than removed: the host job has no fork compiler to ask, and asking it at kernel-build time would move the check into the build path.

Checks

Negative control, rerun at 24b11b6. The patch makes the kernel take libc directly (one line in each of kernel/Cargo.toml and kernel/Cargo.lock). It is posted as a comment on this PR. The script (mutation.sh) applied it with git apply --check (EXIT=0) on a clean tree, then restored it with git apply -R (EXIT=0), and git status --porcelain --ignore-submodules=none was empty afterwards. Under the patch:

  • cargo +toyos build --profile toyos --target x86_64-unknown-none of the kernel exits 0 and compiles liblibc-18df1fdaa3158a14.rlib.
  • cargo test --lib -- build::tests::the_kernel_resolves_no_libc_for_either_target exits 101: "the x86_64-unknown-none kernel resolves libc", at src/build.rs:2777.
  • After the restore, the same test exits 0.

The control has not been re-run since. b219c99 changes only two files under issues/. The merge 33b067c takes #694's kernel/Cargo.toml and kernel/Cargo.lock, which move the kernel's dependencies, dlmalloc among them, under [target.'cfg(target_os = "none")'.dependencies]. The test is unchanged, and the posted patch still applies at 33b067c (git apply --check, EXIT=0).

Oracle. Cargo's own resolver (cargo tree, --unit-graph) and the linked ELFs.

Gates

33b067c merges origin/main 42e5fca (#694). The only conflict was in src/build.rs. It keeps this branch's the_kernel_resolves_no_libc_for_either_target and #694's doc for declared_model_controls, as #694's review named (comment 5973672278). Per file, this branch's changed lines against origin/main are the ones it had against 932fb70.

  • cargo test -p toyos-build --lib at 33b067c: EXIT=0, "387 passed; 0 failed; 10 ignored". The new test is ok at its line 145. Log: /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/cratesrule-merge/lib-test.log, with lib-test.exit and lib-test.head beside it.
  • cargo run -- --ci host at 33b067c: EXIT=0, "Host: 69 step(s), all green" (the log's last line). The new test is ok at its line 136. Log: /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/cratesrule-merge/ci-host.log, with ci-host.exit and ci-host.head beside it. The tree was clean after it.
  • cargo run -- --build-only at 24b11b6: EXIT=0. It also moved this worktree's fork checkout to the merged pin a0d444933. Nothing this branch changed since then is something the image is built from. It was not run at 33b067c.
  • Guest tests: none reached. The change is root CLAUDE.md, a #[cfg(test)] function and two issue files, with no kernel, userland or harness code. No guest test is added.

Earlier logs: cargo run -- --ci host at b219c99 exited 0 ("Host: 67 step(s), all green"), in …/orch/cratesrule-named/. Round 2's are in /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/cratesrule-r2/ (ci-host.log, build-only.log and mutation-run.log, each with a .exit file holding its exit code); round 1's in …/orch/cratesrule/, posted as a comment. The round 3 cfg measurement is posted as comment 5973730043.

Net lines

git diff --shortstat origin/main...HEAD: 4 files changed, 96 insertions(+), 1 deletion(-).

  • Production: none. CLAUDE.md has one prose line replaced.
  • Tests: +30.
  • Issues: +65, two new files.

What was open, and how it closed

  • Whether the rule is absolute for the kernel or a trust boundary: the owner answered on 2026-10-03 that it is conditional, as the sentence says ("where security or another important reason asks").
  • That the test does not ask the fork's cfg: filed as issues/build/the-kernels-libc-test-reads-the-host-compilers-cfg-not-the-forks.md (above).

🤖 Generated with Claude Code

https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8

…s on a kernel that resolves libc

Root CLAUDE.md's Dependencies sentence on crates now carries the owner's
ruling of 2026-10-03: where security or another weighty reason asks, above
all in the kernel or a decoder of untrusted input, ToyOS writes its own crate
with a clear boundary, held to the no-panic track's lints and tested against
hostile input; the kernel takes as few community crates as it can justify and
depends on no libc. The general rule (general, widely used, used as published,
no driver crate, a fork goes when upstream has it) stands unchanged.

kernel/Cargo.lock names libc, windows-sys and windows-link. They are
dlmalloc's target-gated edges, cfg(all(unix, not(target_arch = "wasm32")))
and cfg(target_os = "windows"); neither kernel target has a target_family
(both are target_os = "none" under the stable and the fork compiler), so
cargo resolves, compiles and links none of them. Measured for both targets:
cargo tree -i prints nothing, the unit graph holds cfg-if, dlmalloc,
hashbrown and rustc-demangle as the only registry crates, a fresh build's
deps directory has no libc or windows rlib, and each kernel ELF has no
undefined symbol and no needed library.

A lock is platform-independent, so the entry stays as long as dlmalloc
declares the edge; dlmalloc 0.2.14, the newest published, declares it
unconditionally on unix. Reading the lock therefore cannot show the clause
holds, and a dependency bump that widened such an edge to a none target
would change no line naming libc. build::tests now asks cargo tree, per
Arch::kernel(), with every kernel feature, for the kernel's normal non-proc-
macro graph, and reds on libc. Negative control: the kernel given a libc
dependency builds green with a libc rlib compiled in, and the test reds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Evidence for f15b74c: the negative control's patch and run, and the libc measurements.

Negative control: mutation-kernel-takes-libc.patch

diff --git a/kernel/Cargo.lock b/kernel/Cargo.lock
index 90c5ca15e..d17b68c2c 100644
--- a/kernel/Cargo.lock
+++ b/kernel/Cargo.lock
@@ -36,6 +36,7 @@ dependencies = [
  "bcachefs",
  "dlmalloc",
  "hashbrown",
+ "libc",
  "rustc-demangle",
  "toyos-abi",
  "toyos-acpi",
diff --git a/kernel/Cargo.toml b/kernel/Cargo.toml
index b3c602b75..dbc84953d 100644
--- a/kernel/Cargo.toml
+++ b/kernel/Cargo.toml
@@ -393,3 +393,4 @@ toyos-xhci = { path = "../toyos-xhci" }
 rustc-demangle = "0.1"
 hashbrown = { version = "0.16", default-features = false }
 dlmalloc = { version = "0.2", default-features = false }
+libc = { version = "0.2", default-features = false }
mutation-run.log (apply, build, test, restore)
== git apply --check
check EXIT=0
== applied:
 kernel/Cargo.lock | 1 +
 kernel/Cargo.toml | 1 +
 2 files changed, 2 insertions(+)
== the mutated kernel builds, compiling libc (x86_64-unknown-none, profile toyos, toolchain toyos)
   Compiling toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
   Compiling libc v0.2.183
   Compiling toyos-elide v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elide)
   Compiling toyos-wallclock v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-wallclock)
   Compiling cfg-if v1.0.4
   Compiling toyos-elf v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elf)
   Compiling toyos-userbound v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-userbound)
   Compiling toyos-sched v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-sched)
   Compiling toyos-xhci v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-xhci)
   Compiling toyos-ps2 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-ps2)
   Compiling hashbrown v0.16.1
   Compiling bcachefs v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/bcachefs)
   Compiling toyos-tco v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-tco)
   Compiling toyos-quiesce v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-quiesce)
   Compiling dlmalloc v0.2.13
   Compiling toyos-fat32 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-fat32)
   Compiling toyos-rootimage v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-rootimage)
   Compiling toyos-hda v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-hda)
   Compiling toyos-gicv3 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-gicv3)
   Compiling toyos-untrusted v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-untrusted)
   Compiling toyos-pcid v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-pcid)
   Compiling toyos-dma v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-dma)
   Compiling toyos-blackbox v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-blackbox)
   Compiling toyos-gpt v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-gpt)
   Compiling toyos-bootmap v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-bootmap)
   Compiling toyos-pci v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-pci)
   Compiling toyos-symbols v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-symbols)
   Compiling toyos-proclife v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-proclife)
   Compiling toyos-acpi v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-acpi)
   Compiling rustc-demangle v0.1.27
   Compiling toyos-blockhold v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-blockhold)
   Compiling kernel v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/kernel)
    Finished `toyos` profile [optimized + debuginfo] target(s) in 9.04s
build EXIT=0
liblibc-859d50408ceca6b0.rlib
liblibc rlib grep EXIT=0
== the check under the mutation
    Finished `test` profile [optimized + debuginfo] target(s) in 0.17s
     Running unittests src/lib.rs (target/debug/deps/toyos_build-f4ef26863ef6a4a1)

running 1 test
test build::tests::the_kernel_resolves_no_libc_for_either_target ... FAILED

failures:

---- build::tests::the_kernel_resolves_no_libc_for_either_target stdout ----

thread 'build::tests::the_kernel_resolves_no_libc_for_either_target' (105903300) panicked at src/build.rs:2786:13:
the x86_64-unknown-none kernel resolves libc:
kernel v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/kernel)
bcachefs v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/bcachefs)
dlmalloc v0.2.13
cfg-if v1.0.4
hashbrown v0.16.1
libc v0.2.183
rustc-demangle v0.1.27
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-acpi v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-acpi)
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-bootmap v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-bootmap)
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-blackbox v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-blackbox)
toyos-blockhold v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-blockhold)
toyos-bootmap v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-bootmap) (*)
toyos-dma v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-dma)
toyos-elf v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elf)
toyos-elide v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elide)
toyos-fat32 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-fat32)
toyos-wallclock v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-wallclock)
toyos-gicv3 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-gicv3)
toyos-gpt v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-gpt)
toyos-hda v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-hda)
toyos-pci v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-pci)
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-pcid v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-pcid)
toyos-proclife v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-proclife)
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-ps2 v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-ps2)
toyos-quiesce v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-quiesce)
toyos-rootimage v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-rootimage)
toyos-sched v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-sched)
toyos-symbols v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-symbols)
toyos-abi v0.16.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-abi)
toyos-elf v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elf)
toyos-elide v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-elide)
toyos-tco v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-tco)
toyos-untrusted v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-untrusted)
toyos-userbound v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-userbound)
toyos-wallclock v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-wallclock)
toyos-xhci v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/toyos-xhci)

note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace


failures:
    build::tests::the_kernel_resolves_no_libc_for_either_target

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 396 filtered out; finished in 0.03s

error: test failed, to rerun pass `--lib`
test EXIT=101
== restored
 M CLAUDE.md
 M src/build.rs
script EXIT=0
measure-tree.log
== x86_64-unknown-none cfg
debug_assertions
panic="abort"
target_abi=""
target_arch="x86_64"
target_endian="little"
target_env=""
target_feature="fxsr"
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"
== x86_64-unknown-none tree -i libc
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== x86_64-unknown-none tree -i windows-sys
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== x86_64-unknown-none tree -i windows-link
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== aarch64-unknown-none-softfloat cfg
debug_assertions
panic="abort"
target_abi="softfloat"
target_arch="aarch64"
target_endian="little"
target_env=""
target_has_atomic="128"
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_primitive_alignment="128"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"
== aarch64-unknown-none-softfloat tree -i libc
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== aarch64-unknown-none-softfloat tree -i windows-sys
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== aarch64-unknown-none-softfloat tree -i windows-link
warning: nothing to print.

To find dependencies that require specific target platforms, try to use option `--target all` first, and then narrow your search scope accordingly.
EXIT=0
== all targets (positive control)
libc v0.2.183
└── dlmalloc v0.2.13
    └── kernel v0.1.0 (/Users/jan/Dev/jan/toyos-cratesrule/kernel)
        └── kernel feature "default" (command-line)
EXIT=0
measure-toyos-cfg.log
== rustc +toyos --print cfg --target x86_64-unknown-none
debug_assertions
fmt_debug="full"
overflow_checks
panic="abort"
relocation_model="pic"
target_abi=""
target_arch="x86_64"
target_endian="little"
target_env=""
target_feature="fxsr"
target_feature="x87"
target_has_atomic
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_load_store
target_has_atomic_load_store="16"
target_has_atomic_load_store="32"
target_has_atomic_load_store="64"
target_has_atomic_load_store="8"
target_has_atomic_load_store="ptr"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_has_reliable_f128
target_has_reliable_f16
target_has_reliable_f16_math
target_has_threads
target_object_format="elf"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"
ub_checks
EXIT=0
== rustc +toyos --print cfg --target aarch64-unknown-none-softfloat
debug_assertions
fmt_debug="full"
overflow_checks
panic="abort"
relocation_model="static"
target_abi="softfloat"
target_arch="aarch64"
target_endian="little"
target_env=""
target_has_atomic
target_has_atomic="128"
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_load_store
target_has_atomic_load_store="128"
target_has_atomic_load_store="16"
target_has_atomic_load_store="32"
target_has_atomic_load_store="64"
target_has_atomic_load_store="8"
target_has_atomic_load_store="ptr"
target_has_atomic_primitive_alignment="128"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_has_reliable_f128
target_has_reliable_f16
target_has_reliable_f16_math
target_has_threads
target_object_format="elf"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"
ub_checks
EXIT=0
measure-unitgraph.log
== x86_64-unknown-none: every unit cargo would compile for the kernel (cargo +toyos build --unit-graph)
EXIT=0
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/bcachefs#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/kernel#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-abi#0.16.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-acpi#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-blackbox#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-blockhold#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-bootmap#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-dma#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-elf#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-elide#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-fat32#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-gicv3#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-gpt#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-hda#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-pci#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-pcid#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-proclife#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-ps2#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-quiesce#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-rootimage#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-sched#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-symbols#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-tco#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-untrusted#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-userbound#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-wallclock#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-xhci#0.1.0"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#cfg-if@1.0.4"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#dlmalloc@0.2.13"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#hashbrown@0.16.1"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#rustc-demangle@0.1.27"
== aarch64-unknown-none-softfloat: every unit cargo would compile for the kernel (cargo +toyos build --unit-graph)
EXIT=0
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/bcachefs#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/kernel#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-abi#0.16.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-acpi#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-blackbox#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-blockhold#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-bootmap#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-dma#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-elf#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-elide#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-fat32#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-gicv3#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-gpt#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-hda#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-pci#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-pcid#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-proclife#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-ps2#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-quiesce#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-rootimage#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-sched#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-symbols#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-tco#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-untrusted#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-userbound#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-wallclock#0.1.0"
"pkg_id":"path+file:///Users/jan/Dev/jan/toyos-cratesrule/toyos-xhci#0.1.0"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#cfg-if@1.0.4"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#dlmalloc@0.2.13"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#hashbrown@0.16.1"
"pkg_id":"registry+https://github.com/rust-lang/crates.io-index#rustc-demangle@0.1.27"
measure-x86-artifacts.log
== community rlibs the x86_64 build compiled (fresh worktree, kernel/target/x86_64-unknown-none/toyos/deps)
libbcachefs-246691ef32f1175e.rlib
libcfg_if-fe824d79b7fbf0ff.rlib
libdlmalloc-14cfe9b18c44ca98.rlib
libhashbrown-e51d58f204f24ff3.rlib
librustc_demangle-5ee07dab43d0da48.rlib
libtoyos_abi-83b08cda24d0be30.rlib
libtoyos_acpi-cfb19899f8c129b8.rlib
libtoyos_blackbox-35148ec36f05c01f.rlib
libtoyos_blockhold-94557fa29253986a.rlib
libtoyos_bootmap-0dd14493b8aba31e.rlib
libtoyos_dma-2271e30875ad93bd.rlib
libtoyos_elf-cef72f751dff09d0.rlib
libtoyos_elide-bb87409183132b16.rlib
libtoyos_fat32-c49c5a95fe7a5155.rlib
libtoyos_gicv3-a31dbd1a340dfb74.rlib
libtoyos_gpt-a56bb35ac5d2e636.rlib
libtoyos_hda-918a9c0f053e9d07.rlib
libtoyos_pci-d9bf0537f3b55466.rlib
libtoyos_pcid-570c48bf901c9b03.rlib
libtoyos_proclife-43fdefa346b5a06b.rlib
libtoyos_ps2-b71c99ab11bc7983.rlib
libtoyos_quiesce-a42fc13a74660ea8.rlib
libtoyos_rootimage-3dbdc4c395d1dab6.rlib
libtoyos_sched-fe3198cbbeea001e.rlib
libtoyos_symbols-ab55052c147002e3.rlib
libtoyos_tco-ce2d7d4d11d7f844.rlib
libtoyos_untrusted-82f4be54061379e6.rlib
libtoyos_userbound-8f9152b13475bc48.rlib
libtoyos_wallclock-c6d4b56eeeb9d7d4.rlib
libtoyos_xhci-93077142b730159d.rlib
== any libc/windows artifact anywhere under kernel/target
kernel/target/x86_64-unknown-none/toyos/deps/libcfg_if-fe824d79b7fbf0ff.rmeta
kernel/target/x86_64-unknown-none/toyos/deps/libcfg_if-fe824d79b7fbf0ff.rlib
find EXIT=0
== kernel/target/x86_64-unknown-none/toyos/kernel: undefined symbols (llvm-nm -u)
EXIT=0
== kernel/target/x86_64-unknown-none/toyos/kernel: dynamic section and needed libraries

File: kernel/target/x86_64-unknown-none/toyos/kernel
Format: elf64-x86-64
Arch: x86_64
AddressSize: 64bit
LoadName: <Not found>
DynamicSection [ (14 entries)
  Tag                Type      Name/Value
  0x000000000000001E FLAGS     BIND_NOW 
  0x000000006FFFFFFB FLAGS_1   NOW PIE 
  0x0000000000000015 DEBUG     0x0
  0x0000000000000007 RELA      0x280
  0x0000000000000008 RELASZ    109944 (bytes)
  0x0000000000000009 RELAENT   24 (bytes)
  0x000000006FFFFFF9 RELACOUNT 4581
  0x0000000000000006 SYMTAB    0x238
  0x000000000000000B SYMENT    24 (bytes)
  0x0000000000000005 STRTAB    0x27C
  0x000000000000000A STRSZ     1 (bytes)
  0x000000006FFFFEF5 GNU_HASH  0x250
  0x0000000000000004 HASH      0x26C
  0x0000000000000000 NULL      0x0
]
NeededLibraries [
]
EXIT=0
measure-aarch64-artifacts.log
== rlibs the aarch64 build compiled (kernel/target/aarch64-unknown-none-softfloat/toyos/deps)
libbcachefs-867fe388777b9e84.rlib
libcfg_if-8585b6291344d874.rlib
libdlmalloc-456245eb2513b112.rlib
libhashbrown-86ace452c15b30be.rlib
librustc_demangle-f185c8e8ea7e1743.rlib
libtoyos_abi-abbce75065bd79fd.rlib
libtoyos_acpi-81655844c8e9e0d7.rlib
libtoyos_blackbox-c4a00d6d84340a9d.rlib
libtoyos_blockhold-3e5d9de2bfbaa8d3.rlib
libtoyos_bootmap-f55a669596f02cc9.rlib
libtoyos_dma-8648705cbbc45eff.rlib
libtoyos_elf-e32e17ddc656dd97.rlib
libtoyos_elide-cecc1f17acf6b826.rlib
libtoyos_fat32-033c22b4090327d4.rlib
libtoyos_gicv3-066a4ed1089a4c4a.rlib
libtoyos_gpt-2f55f8c2e484d827.rlib
libtoyos_hda-34277261f5c6ee99.rlib
libtoyos_pci-4851dd894774f602.rlib
libtoyos_pcid-e68f5af63c789ade.rlib
libtoyos_proclife-9e3338f7de4ac6b8.rlib
libtoyos_ps2-3995a00c72cc0e22.rlib
libtoyos_quiesce-8b87fd66a1b9256d.rlib
libtoyos_rootimage-684119455e8d1caa.rlib
libtoyos_sched-e273a493c0ed58d6.rlib
libtoyos_symbols-6eab8ed812abd9ff.rlib
libtoyos_tco-a889a038cadf82fd.rlib
libtoyos_untrusted-45d9c408fd764a74.rlib
libtoyos_userbound-21be870d6a0e4738.rlib
libtoyos_wallclock-ab2247d3340e29bf.rlib
libtoyos_xhci-c3a146dad6d56b66.rlib
== any libc or windows artifact under that target dir
find EXIT=0
== kernel/target/aarch64-unknown-none-softfloat/toyos/kernel: undefined symbols (llvm-nm -u)
EXIT=0
== kernel/target/aarch64-unknown-none-softfloat/toyos/kernel: needed libraries

File: kernel/target/aarch64-unknown-none-softfloat/toyos/kernel
Format: elf64-littleaarch64
Arch: aarch64
AddressSize: 64bit
LoadName: <Not found>
NeededLibraries [
]
EXIT=0
cargo-info-dlmalloc.log
    Updating crates.io index
dlmalloc
A Rust port of the dlmalloc allocator
version: 0.2.14
license: MIT/Apache-2.0
rust-version: unknown
documentation: https://docs.rs/dlmalloc
homepage: https://github.com/alexcrichton/dlmalloc-rs
repository: https://github.com/alexcrichton/dlmalloc-rs
crates.io: https://crates.io/crates/dlmalloc/0.2.14
features:
  core             = [dep:core]
  debug            = []
  global           = []
  rustc-dep-of-std = [core]
EXIT=0

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #696 at f15b74c, round 1.

Net lines: git diff --shortstat origin/main...f15b74ccf gives 2 files changed, 32 insertions(+), 1 deletion(-).

  • Production: 0. Root CLAUDE.md swaps one line for one.
  • Tests: +31.

Merge with origin/main (932fb70, #695): git merge-tree --write-tree origin/main f15b74ccf exits 0 and writes tree 7b270d6dc. Both hunks land unchanged: the sentence stays at CLAUDE.md:58, and the test lands at src/build.rs:2760. #695 rewrote CLAUDE.md:43 and :46, not line 58. Among the kernel's dependency manifests it changed only a comment in toyos-hda/Cargo.toml. The test names nothing the rename moved.

Evidence:

  • ci-host.log starts at 22:39:23, after the 22:39:16 commit, and ends Host: 67 step(s), all green, EXIT=0. The new test is ok at its line 134.
  • mutation-run.log: with the kernel taking libc, the build exits 0 and compiles liblibc. The test exits 101 at src/build.rs:2786, the committed assert.
  • No guest test is reached.

BLOCKER

  • CLAUDE.md:58 — "above all in the kernel or a decoder of untrusted input" — the owner's "especially" named the kernel alone ("Especially in the kernel im worried about community crates"). His ELF parser and AML interpreter are examples of what we may write ourselves, and both are kernel-side here; they are not a second site that ranks with the kernel. The clause gives every userland decoder of untrusted input the kernel's priority — russh in sshd, rustls-rustcrypto in doom, smoltcp in netd. He did not rule on those, so this states his ruling more broadly than he gave it. Drop "or a decoder of untrusted input".
  • CLAUDE.md:58 — "we write our own crate with a clear boundary, held to the no-panic track's lints and tested against hostile input" — he wrote "Especially if we can make a crate with a clear boundary and is well tested". That is a reason that favours writing our own, and "well tested" is unqualified. The sentence turns the boundary into an obligation and replaces "well tested" with two requirements the PR body says came from the brief, so it presents a design as his. State his clause as he gave it. The two requirements:
    • The lint set is broader than his words. It binds every such crate, including one written for "another weighty reason" that only an app links. issues/kernel/a-panic-is-never-an-accident.md leaves that crate at tier 4, "Normal Rust", so the clause is a second declaration of that track's scope and disagrees with it.
    • "Tested against hostile input" is narrower than "well tested" for a crate written for a reason other than security.

NOTE

  • f15b74c commit message, first paragraph — it calls the whole new sentence, the brief's clauses included, "the owner's ruling of 2026-10-03". Branch commits reach main through the merge, and history is not rewritten, so the answering commit's message must say which clauses were not his.
  • kernel/Cargo.lock:68 — the lock still names libc. The PR body says forking dlmalloc or replacing the allocator are "the owner's call", and files nothing. Settle it one of two ways:
    • If the owner owes a decision, record it as a kind: question, status: owner file (issues/README.md).
    • If the measurement that neither kernel target resolves libc already meets his "must not depend on libc", nothing is owed, and the body's paragraph about the two routes goes.

REMOVE

  • src/build.rs:2765-2766 — ", so it names libc, dlmalloc's edge on unix, whether a kernel target takes that edge or not" — it narrates a third-party manifest's current edge and becomes false the day dlmalloc changes. The clause before it already gives the reason.

SEND BACK

Japabu and others added 2 commits October 3, 2026 23:14
…c test names no third-party edge

Answers review round 1 of #696 (comment 5973524429).

Root CLAUDE.md's crate sentence now reads: "Where security or another
important reason asks, above all on a trust boundary or in the kernel, we
write our own crate, with a clear boundary and well tested; the kernel takes
as few community crates as it can justify and depends on no libc."

f15b74c called its whole sentence the owner's ruling of 2026-10-03. It was
not, and history keeps that message, so this one says where each part of the
sentence comes from:

- The owner's words, 2026-10-03: "if it makes sense ... due to security or
  other important reasons we do it" (where security or another important
  reason asks, we write our own crate), "a crate with a clear boundary and is
  well tested", "Especially in the kernel" (above all in the kernel), and
  "Our kernel must not depend on libc".
- A formulation the orchestrator put to him, which he accepted ("Yes add a
  fitting rule to claudemd"): "a crate on a trust boundary or in the kernel
  is ours, with a clear boundary and tests, and everywhere else the
  ecosystem's". "On a trust boundary" is its words. It replaces f15b74c's
  "a decoder of untrusted input", which was neither his nor accepted by him.
- Neither: "the kernel takes as few community crates as it can justify" is
  the brief's statement, as a rule, of his worry about community crates in
  the kernel.

f15b74c's "held to the no-panic track's lints and tested against hostile
input" was neither his words nor part of what he accepted. It is replaced by
his "well tested".

The libc test's doc comment drops the clause that named dlmalloc's current
edge on unix. That clause would go false the day dlmalloc changes, and the
reason before it already stands on its own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu Japabu changed the title The kernel's crates are ours where security asks, and a host test reds on a kernel that resolves libc The crate rule says only what the owner said or accepted, and a host test reds on a kernel that resolves libc Oct 3, 2026
@Japabu Japabu changed the title The crate rule says only what the owner said or accepted, and a host test reds on a kernel that resolves libc ToyOS writes its own crate where security asks, above all on a trust boundary or in the kernel, and a host test reds on a kernel that resolves libc Oct 3, 2026
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #696 at 24b11b6, round 2.

Net lines: git diff --shortstat origin/main...24b11b69a gives 2 files changed, 31 insertions(+), 1 deletion(-).

  • Production: 0. Root CLAUDE.md swaps one line for one.
  • Tests: +30 (src/build.rs).

The merge base is origin/main (932fb70). The two-dot and three-dot diffs agree, so the merge 1381a2e brought in nothing of its own. kernel/Cargo.toml and kernel/Cargo.lock are unchanged since f15b74c, so round 1's libc table still describes this head.

Round 1 BLOCKERs

  • CLAUDE.md:58, "or a decoder of untrusted input": CLOSED. git diff 1381a2ea4 24b11b69a -- CLAUDE.md shows the line now reads "above all on a trust boundary or in the kernel". "On a trust boundary" comes from the formulation the owner accepted, and the decoder clause is gone.
  • CLAUDE.md:58, "held to the no-panic track's lints and tested against hostile input": CLOSED. The same diff shows "with a clear boundary and well tested". That is his clause, and the formulation he accepted attaches the boundary and the tests to the crate.

Round 1 NOTEs and REMOVE

  • The f15b74c commit message: closed. 24b11b6's message says which clauses are his, which come from the formulation he accepted, and which are neither.
  • kernel/Cargo.lock:68: closed. The paragraph about two routes is gone, and the measurement already holds the libc clause. See the first REMOVE below for what replaced it.
  • src/build.rs:2765-2766: closed. The clause naming dlmalloc's edge is deleted.

Evidence at 24b11b6

  • cargo run -- --ci host: ci-host.exit holds EXIT=0, and ci-host.head holds 24b11b6. The log starts at 21:17:24 UTC, after the commit at 23:15:04 +0200. Its last line is Host: 67 step(s), all green, and the new test is ok at its line 123.
  • mutation-run.log, the negative control:
    • It starts on a clean tree at 24b11b6.
    • With the patch, the kernel builds with EXIT=0 and compiles liblibc-18df1fdaa3158a14.rlib.
    • The test exits 101 at src/build.rs:2777, the committed assert.
    • After git apply -R the tree is clean, and the test exits 0.
    • The patch is identical to the one posted in comment 5973335301.
  • No guest test is reached, and no hardware is targeted.

BLOCKER
(none)

NOTE

  • CLAUDE.md:58 and the PR body's "What I am unsure of", first bullet — the formulation the owner accepted makes "a crate on a trust boundary or in the kernel" ours outright, but line 58 makes it conditional ("where security or another important reason asks"), and "the kernel takes as few community crates as it can justify" allows a justified community crate in the kernel. The body leaves it to him whether he meant the absolute. Put the question to him before landing, and make line 58 say what he answers — if he meant the absolute, the line states his ruling more narrowly than he gave it, and a doubt about his ruling must not become main's record.
  • The PR body's "What I am unsure of", second bullet, and src/build.rs:2762 — Command::new("cargo") evaluates the kernel targets' cfg with whatever compiler the host gate runs, while the fork that builds the kernel is asked only at src/build.rs:558-560 — this is a gap the branch found. It is either removed or recorded in issues/ with an owner, evidence and an exit (reviewer.md, Growth), and it does not land in the merge commit as a doubt.
  • src/build.rs:2755-2783 and the PR body's "Why a check and not only a sentence", first bullet — the test sees what the lock cannot only while a kernel dependency names libc for another platform. Under the owner's ruling that ends with dlmalloc: kernel/Cargo.lock will then name no libc, and a libc line arriving in it is something a reviewer reads. The bullet's "that stays true after dlmalloc goes, for any dependency with a target-gated libc edge" keeps the test for a dependency nobody has added, which is code kept just in case (reviewer.md, Growth). The bullet goes, and whatever records the dlmalloc ruling names this test's deletion in its exit — today no file in issues/ records that ruling (rg -n dlmalloc issues/ finds only issues/kernel/the-kernel-heap-has-none-of-slubs-hardening.md, which names no replacement).

REMOVE

  • PR body, "libc: locked only, never compiled or linked", the sentence "It is built host-first and swapped in after the three steps of issues/kernel/toyos-beats-linuxs-latency-on-the-t14.md." — it schedules work this branch does not do. The track it cites names no allocator, and nothing in issues/ carries the ruling, so it reads as the owner's plan with nothing in the tree behind it.
  • PR body, "Why the sentence keeps the owner's condition …", the sentences "An absolute would also be false of the tree today. hashbrown and rustc-demangle run in the kernel, and smoltcp, rustls-rustcrypto and russh sit on trust boundaries in userland." — the tree's state is no reason for a weaker rule (root CLAUDE.md: "a tracked weakness is still a weakness"). smoltcp's replacement is already a track (issues/design-debt/toyos-has-its-own-network-stack.md), and the owner's condition in the sentence before is the reason the record needs.

LAND AFTER NAMED CHANGES

Review round 2 of #696 (comment 5973692927), its second and third NOTEs.

issues/kernel/toyos-has-its-own-allocator.md records the owner's ruling
of 2026-10-03, as the orchestrator relayed it: our own allocator crate,
one core with two fronts; the kernel's first, built host-first and
swapped in after the three steps of the latency track; std's for
programs later, after measuring against dlmalloc; and the 2 MiB
heap-growth stall fixed now. No file recorded that ruling before. Its
exit deletes build::tests::the_kernel_resolves_no_libc_for_either_target
once dlmalloc leaves the kernel: the test sees what the lock cannot only
while a kernel dependency names libc for another platform, and after
dlmalloc a libc line arriving in kernel/Cargo.lock is something a
reviewer reads.

issues/build/the-kernels-libc-test-reads-the-host-compilers-cfg-not-the-forks.md
records the gap the branch found: the test resolves with the host's
compiler, stable on CI, whose host job installs no ToyOS toolchain, and
the kernel builds with the fork. Measured with rustc --print cfg on both
kernel targets, stable 1.98.1 against the fork's 1.99.0-dev, every run
exiting 0: the fork prints every line stable does and adds more,
target_feature="x87" on x86_64 among them; the two agree on target_os,
target_arch and the absence of unix, which are what dlmalloc 0.2.13
gates its libc and windows-sys edges on.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Round 3 measurement behind issues/build/the-kernels-libc-test-reads-the-host-compilers-cfg-not-the-forks.md: rustc --print cfg --target <t> under the host's default compiler and under the fork, at b219c99.

Versions: rustc --version → rustc 1.98.1 (48a229cea 2026-09-01) (EXIT=0); rustc +toyos --version → rustc 1.99.0-dev (EXIT=0). Every --print cfg run below exited 0.

x86_64-unknown-none

Stable:

debug_assertions
panic="abort"
target_abi=""
target_arch="x86_64"
target_endian="little"
target_env=""
target_feature="fxsr"
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"

diff stable fork (EXIT=1, additions only):

1a2,3
> fmt_debug="full"
> overflow_checks
2a5
> relocation_model="pic"
7a11,12
> target_feature="x87"
> target_has_atomic
12a18,23
> target_has_atomic_load_store
> target_has_atomic_load_store="16"
> target_has_atomic_load_store="32"
> target_has_atomic_load_store="64"
> target_has_atomic_load_store="8"
> target_has_atomic_load_store="ptr"
17a29,33
> target_has_reliable_f128
> target_has_reliable_f16
> target_has_reliable_f16_math
> target_has_threads
> target_object_format="elf"
20a37
> ub_checks

aarch64-unknown-none-softfloat

Stable:

debug_assertions
panic="abort"
target_abi="softfloat"
target_arch="aarch64"
target_endian="little"
target_env=""
target_has_atomic="128"
target_has_atomic="16"
target_has_atomic="32"
target_has_atomic="64"
target_has_atomic="8"
target_has_atomic="ptr"
target_has_atomic_primitive_alignment="128"
target_has_atomic_primitive_alignment="16"
target_has_atomic_primitive_alignment="32"
target_has_atomic_primitive_alignment="64"
target_has_atomic_primitive_alignment="8"
target_has_atomic_primitive_alignment="ptr"
target_os="none"
target_pointer_width="64"
target_vendor="unknown"

diff stable fork (EXIT=1, additions only):

1a2,3
> fmt_debug="full"
> overflow_checks
2a5
> relocation_model="static"
6a10
> target_has_atomic
12a17,23
> target_has_atomic_load_store
> target_has_atomic_load_store="128"
> target_has_atomic_load_store="16"
> target_has_atomic_load_store="32"
> target_has_atomic_load_store="64"
> target_has_atomic_load_store="8"
> target_has_atomic_load_store="ptr"
18a30,34
> target_has_reliable_f128
> target_has_reliable_f16
> target_has_reliable_f16_math
> target_has_threads
> target_object_format="elf"
21a38
> ub_checks

@Japabu Japabu changed the title ToyOS writes its own crate where security asks, above all on a trust boundary or in the kernel, and a host test reds on a kernel that resolves libc ToyOS writes its own crate where security asks, above all on a trust boundary or in the kernel; a host test reds on a kernel that resolves libc, and the owner's allocator ruling is filed Oct 3, 2026
@Japabu
Japabu marked this pull request as ready for review October 3, 2026 21:42
@Japabu
Japabu enabled auto-merge October 3, 2026 21:43
@Japabu
Japabu added this pull request to the merge queue Oct 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 3, 2026
src/build.rs conflicted where this branch inserts
the_kernel_resolves_no_libc_for_either_target above the doc #694
rewrote for declared_model_controls. Resolved as #694's review named:
this branch's test, and #694's doc ("every feature of the kernel's
manifest but its builds and [`KERNEL_CARRIES`]...").

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu
Japabu enabled auto-merge October 3, 2026 22:31
@Japabu
Japabu added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 42bda52 Oct 3, 2026
3 checks passed
@Japabu
Japabu deleted the wt/toyos-cratesrule branch October 3, 2026 23:08
Japabu added a commit that referenced this pull request Oct 3, 2026
Japabu added a commit that referenced this pull request Oct 4, 2026
Japabu added a commit that referenced this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant