Skip to content

Every crate with one consumer moves under it, and the track closes - #703

Merged
Japabu merged 4 commits into
mainfrom
wt/toyos-folders4
Oct 4, 2026
Merged

Japabu merged 4 commits into
mainfrom
wt/toyos-folders4

Conversation

@Japabu

@Japabu Japabu commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Step 4 of issues/build/code-used-by-one-program-lives-in-that-program.md, the track's last step. Every crate with exactly one consumer moves under that consumer, and the track closes.

The count

The count follows the step's own definition. It reads cargo metadata --offline --no-deps over every manifest git ls-files '*Cargo.toml' lists (97 manifests, 96 packages; userland/Cargo.toml is a virtual workspace). Every path dependency of any kind counts. A shipped program is its own consumer.

My count at the base, 42e5fca73, matches the scout's list exactly: the same 14 packages have one consumer. There is one difference in the result, which comes from the pair rule below: toyos-net-tcp moves too, which the scout's list did not include.

What moved, and why

Every package keeps its name. That means no use line changes, and kernel/Cargo.lock and userland/Cargo.lock do not change. The root Cargo.lock drops the three packages that left the host workspace (−18).

package from to consumer
toyos-dma, toyos-gicv3, toyos-pci, toyos-ps2 toyos-* kernel/{dma,gicv3,pci,ps2} the kernel
toyos-transport toyos-transport toyos-blockring/transport toyos-blockring
toyos-net-testnet toyos-net-testnet toyos-net-shard/testnet toyos-net-shard (dev)
toyos-net-tcp toyos-net-tcp toyos-net-shard/tcp the shard/testnet pair
toyos-desktop toyos-desktop userland/compositor/desktop compositor
toyos-mdns toyos-mdns userland/netstack/mdns netstack
toyos-mixer toyos-mixer userland/soundserver/mixer soundserver
  • The kernel's four and the two network crates stay members of the host workspace, at their new paths, the way kernel/loom and kernel/sim already are. They are tested and linted exactly as before.
  • The pair. toyos-net-testnet and toyos-net-shard are each other's only consumer, so the step as written could not be met. I added one sentence to the step. It is the orchestrator's reading, not an owner ruling: "Of two crates that are each other's only consumer, the one the other names only as a dev-dependency moves under it, and the count treats the pair as one crate." So the testnet moves under the shard. Under the same sentence, toyos-net-tcp's two consumers, the shard and the testnet, count as one, so the TCP crate moves under the shard as well.
  • The three under userland programs join the userland workspace. A crate under userland/ belongs to the workspace userland/Cargo.toml roots, so they leave the host workspace and are listed in the userland workspace's members.
    • Each gains [lib] doctest = false, which the survey asks of every userland library because the toyos toolchain builds no rustdoc. None of the three has a doc-test (-- --list at base shows 0 for each), so no test is lost.
    • Each manifest's header comment is deleted, save toyos-mixer's "No dependencies, deliberately" paragraph: what was left restated the description or the modules.
  • src/userlandhost.rs's survey gates a nested crate's tests instead of listing them as escapes, as the step says. --ci host now runs cargo test --manifest-path userland/<program>/<crate>/Cargo.toml --target <host> for each nested crate that holds a test.
    • The survey's fixture test now expects gated/sub among the gated crates, where it used to expect an escape.
    • The module doc no longer says "directly under userland/".
  • src/clippy.rs lints every nested crate the survey gates. The host workspace's shapes no longer reach the three userland crates, and the step's check says --clippy lints them. The runs are not listed: clippy::run takes userlandhost::survey's gated crates whose directory holds a / and runs cargo clippy --manifest-path userland/<dir>/Cargo.toml --all-targets -- $ADOPTED -D warnings for each, against the host, the way ci.rs derives the tests. A crate moved under a program later is linted once it holds a test, with nothing to add by hand.
    • The userland programs themselves stay unlinted. At base, cargo clippy -D warnings on each gated program fails: calc, diskserver, fileserver, logkeeper, netstack and pkg each exited 101 on real findings, and soundserver and sshserver exited 101 when the manifest load failed mid-move. issues/build/userland-programs-are-never-linted.md now says which crates are linted and that no program is.
    • The module doc's sentence on why userland is absent is deleted.
  • Citations of the moved paths are updated, in userland/CLAUDE.md and six issue files. userland/soundserver/src/main.rs's header lines that cited toyos-mixer/ and toyos-desktop/ are deleted. Three kinds stay as they were:
    • issues/build/the-host-job-runs-the-toolchain-the-runner-ships.md quotes toyos-desktop/src/input.rs and toyos-mixer/src/channel.rs inside a pasted clippy log. That is output, so it stays verbatim, following toyos-fat32-check moves to toyos-fat32/check, beside the one subject it judges #691.
    • Prose that names a crate by its package name ("like toyos-ps2") is still true.
    • issues/design-debt/what-is-owed-on-file-size.md's history keeps the paths 763712b and the mixer's split wrote, toyos-desktop/ and toyos-mixer/, and says they have moved since.
  • Outside the tree: rg over the fork clones beside the monorepo, rust/library and rust/compiler/rustc_target finds none of the ten names. ~/.cargo/git/checkouts/ finds them only in a cargo checkout of this repository at 6115718, as in toyos-fat32-check moves to toyos-fat32/check, beside the one subject it judges #691.

The track closes

The second commit deletes the track file, because its exit is met.

  • No directory the file names as moved or merged still exists. Step 4 names none, and steps 1, 2, 3 and 5 each left the file with their own pull requests.
  • Step 4's count finds no crate outside its one consumer. I re-ran the count at a08850a80. Of its 14 packages with one consumer:
    • ten sit under that consumer: the nine in the table besides toyos-net-tcp, which now has two, and tls-dep, already under tls-multi-crate;
    • toyos-net-shard is one half of the pair, whose only consumer is the other half;
    • diskserver, inspect and terminal are programs system.toml ships, so each is its own consumer.
  • git grep finds no citation of the slug or its title.
  • The rule the track carried already has a home: .claude/agents/reviewer.md's Fit line, as the track itself said.

Gates

The branch merges origin/main at 42bda5268 (#696). That run includes #696's the_kernel_resolves_no_libc_for_either_target, which runs cargo tree --locked on kernel/Cargo.toml, whose four path dependencies this branch moves. It passes.

gate head exit log
cargo run -- --ci host dec6bef21 0, Host: 72 step(s), all green folders4-r2/ci-host.log
cargo run -- --build-only dec6bef21 0, Build finished. folders4-r2/build-only.log
cargo test, the whole guest suite dec6bef21 0, 26 passed, 26 total folders4-r2/guest.log
cargo run -- --clippy dec6bef21 0, 22 invocations clean folders4-r2/clippy-clean.log

The logs are in the brief's log directory, under orch/. The host run has three more steps than before: userland/compositor/desktop, userland/netstack/mdns and userland/soundserver/mixer.

I ran the guest suite whole because the kernel, compositor, netstack and soundserver were all rebuilt from moved paths. The source is unchanged, but the bytes are not: panic locations carry the file's path.

The step's check, part 1: --ci host runs every test each package lists today. I listed each package's tests at base with cargo test -p <package> -- --list. At head I used the same command for the root members, and for the three userland crates the gate's own command, cargo test --manifest-path … --target aarch64-apple-darwin -- --list. Every run exited 0. Each package lists the same names at both heads, once a doc-test's path prefix is mapped to its new directory.

package base head
toyos-desktop 95 95
toyos-mdns 12 12
toyos-mixer 55 55
toyos-transport 17 (4 doc) 17 (4 doc)
toyos-net-tcp 376 (5 doc) 376 (5 doc)
toyos-net-testnet 2 2
toyos-dma 17 17
toyos-gicv3 9 9
toyos-pci 75 75
toyos-ps2 24 24

In ci-host.log, the three userland steps read 95 passed, 12 passed and 55 passed.

The step's check, part 2: --clippy lints them. The root members stay under the existing workspace shapes. For the three userland crates, I ran a checked mutation at dec6bef21, posted as a comment on this pull request (folders4-r2/mutation.log):

  • The patch: a test asserting v.len() == 0 on a &[u8], added to userland/compositor/desktop/src/budget.rs.
  • Build: cargo test --manifest-path userland/compositor/desktop/Cargo.toml --target aarch64-apple-darwin --no-run exited 0.
  • Clippy: cargo run -- --clippy exited 1. It reported clippy::len_zero at compositor/desktop/src/budget.rs:133:17 under the derived run cargo clippy --manifest-path userland/compositor/desktop/Cargo.toml --all-targets, and 1 of 22 invocation(s) found warnings.
  • Restore: git apply -R exited 0, and the tree was clean.

The survey gate has a negative control, run at e169ca7a4 and posted as a comment. I put back the base's nested-crate escape branch as a checked patch:

  • cargo build --lib exited 0.
  • cargo test --lib userlandhost exited 101. every_userland_test_is_in_the_gate failed, naming every test file under compositor/desktop, netstack/mdns and soundserver/mixer, and the fixture test failed too.
  • git apply -R exited 0.

Growth

git diff --shortstat origin/main...dec6bef21: 118 files, +137 −195. Every non-manifest file moves as a 100% rename. Each moved manifest changes only its paths, and the three userland manifests also lose their headers and gain [lib]. Git reads the desktop and mdns manifests as a delete and an add.

  • Build system (src/): +62 −45. clippy.rs +52 −28: the derived runs, and run reporting how many ran. userlandhost.rs +9 −16, the survey and its docs. ci.rs +1 −1.
  • The track: −42.
  • Lockfile: −18.
  • The rest is manifests and citation paths.

Unsure

  • Doc-test names carry the file's path, so toyos-transport's and toyos-net-tcp's doc-tests now read under their new directories. git grep 'rs - (' finds nothing in the tree that keys on those names.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8

Japabu and others added 2 commits October 4, 2026 00:36
Step 4 of issues/build/code-used-by-one-program-lives-in-that-program.md.
The count reads `cargo metadata --no-deps` over every manifest
`git ls-files '*Cargo.toml'` lists; a shipped program is its own consumer.

- kernel/dma, kernel/gicv3, kernel/pci, kernel/ps2: the kernel's alone.
  They stay members of the host workspace, as kernel/loom and kernel/sim
  are.
- toyos-blockring/transport: toyos-blockring's alone.
- toyos-net-shard/testnet and toyos-net-shard/tcp: the shard and the
  testnet are each other's only consumer, the shard naming the testnet
  only as a dev-dependency. The step now says how such a pair counts (the
  orchestrator's reading, not an owner ruling): the dev-dependency moves
  under the other, and the pair counts as one crate, which makes the
  pair toyos-net-tcp's one consumer too.
- userland/compositor/desktop, userland/netstack/mdns,
  userland/soundserver/mixer: each one program's alone. They leave the
  host workspace for the userland one, with `[lib] doctest = false` as
  the survey asks of a userland library (none has a doc-test).

src/userlandhost.rs's survey now gates a nested crate's tests instead of
listing them as escapes, so `--ci host` runs the three userland crates'
tests with `cargo test --target <host>`. src/clippy.rs gains a shape that
lints the three against the host, since the host workspace's shapes no
longer reach them; the other userland crates are not linted, as before.

Every package keeps its name, so no `use` changes, and no lockfile but
the root's changes: it drops the three that left its workspace.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
…oses

Its last step, step 4, landed in the previous commit, and its exit is
met. No directory the file names as moved or merged exists: step 4 names
none, and steps 1, 2, 3 and 5 left with their own pull requests. Step 4's
count, `cargo metadata --no-deps` over every manifest
`git ls-files '*Cargo.toml'` lists, run at that commit, finds 14
packages with one consumer:
- 10 sit under their consumer: kernel/{dma,gicv3,pci,ps2},
  toyos-blockring/transport, toyos-net-shard/testnet,
  userland/{compositor/desktop,netstack/mdns,soundserver/mixer}, and
  tests/toyos-rust-tests/tls-multi-crate/dep.
- toyos-net-shard is the testnet's, the pair the step counts as one.
- diskserver, inspect and terminal are programs the images ship, each
  its own consumer.

The rule it carried has its home already: `.claude/agents/reviewer.md`'s
Fit line states the layout, as the track itself said. No file cites the
slug.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Mutation patches for #703, each applied with git apply --check then git apply, run, and restored with git apply -R (results in the body).

Clippy reaches the userland nested crates (cargo run -- --clippy exit 1, clippy::len_zero at compositor/desktop/src/budget.rs:133:17):

diff --git a/userland/compositor/desktop/src/budget.rs b/userland/compositor/desktop/src/budget.rs
index 592846086..d9f30afbd 100644
--- a/userland/compositor/desktop/src/budget.rs
+++ b/userland/compositor/desktop/src/budget.rs
@@ -124,3 +124,12 @@ mod tests {
         assert_eq!(create_verdict((0, 0), Rect::new(0, 0, 4, 4), 0, 10), Verdict::Allow);
     }
 }
+
+#[cfg(test)]
+mod planted {
+    #[test]
+    fn planted() {
+        let v: &[u8] = &[];
+        assert!(v.len() == 0);
+    }
+}

Negative control: the base survey branch back (cargo test --lib userlandhost exit 101):

diff --git a/src/userlandhost.rs b/src/userlandhost.rs
index 9d74d61c5..43866c0c9 100644
--- a/src/userlandhost.rs
+++ b/src/userlandhost.rs
@@ -101,7 +101,11 @@ pub fn survey(userland: &Path) -> Result<Survey, String> {
             continue;
         }
         let inside = rel(owner, file);
-        if !(inside.starts_with("src/") || inside.starts_with("tests/")) {
+        if crate_name.contains('/') {
+            escapes.insert(format!(
+                "{at}: a test in the nested crate {crate_name}, which the gate does not discover"
+            ));
+        } else if !(inside.starts_with("src/") || inside.starts_with("tests/")) {
             escapes.insert(format!(
                 "{at}: a test outside {crate_name}'s src/ and tests/, which cargo test does not run"
             ));

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 1, head e169ca7a4.

Net: 116 files, +110 −158. Of that, src/ production is +28 −15 (clippy.rs +20 −3, userlandhost.rs survey and its docs +8 −12) and the survey's fixture test is +1 −4. The rest is moves, manifests, the root lock (−18) and the track (−42).

I re-ran the count myself: cargo metadata --offline --no-deps over all 97 git ls-files '*Cargo.toml' at e169ca7a4, 96 packages. 14 packages have one consumer, and they are the ones the PR body names. toyos-net-tcp's consumers are toyos-net-shard and toyos-net-shard/testnet. The gate exits are 0 in orch/folders4/*.exit. The mutation and negative-control results files read clippy EXIT=1 and survey test EXIT=101, each with a clean restore.

On the brief's question, whether the pair sentence makes the toyos-net-tcp move follow: it does. "The count treats the pair as one crate" turns tcp's two consumers, the shard and the testnet, into one. The sentence's first clause puts the testnet under the shard, so the pair's directory is toyos-net-shard/. The sentence never states an owner ruling as his: the commit and the PR body both call it the orchestrator's reading. The file is added and deleted in the same PR, so the PR body is the only record of the reading on main.

BLOCKER

  • src/clippy.rs:191-207 — the shape lists toyos-desktop, toyos-mdns and toyos-mixer by hand. A fourth crate moved under a userland program would be gated by the survey on its first test but never linted, and nothing would go red. — That makes a second declaration of the nested userland crates, beside userland/Cargo.toml's members and the survey. src/userlandhost.rs's own module doc says "There is no list", and the root Cargo.toml header records lists like this drifting three times. Fix: build the nested-crate clippy invocations at run time from userlandhost::survey(...).gated entries that contain /, one --manifest-path userland/<dir>/Cargo.toml --all-targets each, as ci.rs:598-605 already does for tests, and delete the hand list. Re-run the planted len_zero in userland/compositor/desktop/src/budget.rs: it must still turn --clippy red.

NOTE

REMOVE

  • userland/compositor/desktop/Cargo.toml:1-3 — a rewritten header that restates description.
  • userland/netstack/mdns/Cargo.toml:1-2 — a rewritten header that restates description.
  • userland/soundserver/mixer/Cargo.toml:1-3 — a rewritten header that lists what the crate's modules already show. The "No dependencies, deliberately" paragraph stays.
  • userland/soundserver/src/main.rs:3-10 — doc lines corrected instead of deleted. Lines 7-8 are also chronology ("the answer this program used to compute inline").
  • userland/soundserver/src/main.rs:12 — "The split is userland/compositor/'s, against its desktop/" is a corrected cross-reference, not a contract.
  • src/clippy.rs:7-9 — a doc line corrected instead of deleted, and its reason is not this branch's: the survey's programs build for the host, and the PR body's own measurement says they are left out because they are not clippy-clean.

SEND BACK

Japabu and others added 2 commits October 4, 2026 01:19
…rom the survey

src/clippy.rs listed toyos-desktop, toyos-mdns and toyos-mixer by hand, a
second declaration beside userland/Cargo.toml's members and the survey: a
fourth crate moved under a program would have been tested but never linted.
The runs are now derived when clippy runs, one `--manifest-path
userland/<dir>/Cargo.toml --all-targets` for each nested crate
src/userlandhost.rs's survey gates, as ci.rs derives the tests.

The moved crates' manifest headers that restated their descriptions go, and
so do the soundserver header lines that were corrected rather than deleted.
issues/build/userland-programs-are-never-linted.md says what is linted now,
and the file-size issue's history names the paths its commits wrote.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 1 control, re-run at dec6bef21, where the nested crates' clippy runs come from the survey. Applied with git apply --check (exit 0) and git apply (exit 0); the planted test built (cargo test --manifest-path userland/compositor/desktop/Cargo.toml --target aarch64-apple-darwin --no-run exit 0); cargo run -- --clippy exited 1 with clippy::len_zero at compositor/desktop/src/budget.rs:133:17 under cargo clippy --manifest-path userland/compositor/desktop/Cargo.toml --all-targets, 1 of 22 invocation(s) found warnings; git apply -R exit 0, tree clean. Unpatched, --clippy exits 0, 22 invocations clean.

diff --git a/userland/compositor/desktop/src/budget.rs b/userland/compositor/desktop/src/budget.rs
--- a/userland/compositor/desktop/src/budget.rs
+++ b/userland/compositor/desktop/src/budget.rs
@@ -124,3 +124,12 @@ mod tests {
         assert_eq!(create_verdict((0, 0), Rect::new(0, 0, 4, 4), 0, 10), Verdict::Allow);
     }
 }
+
+#[cfg(test)]
+mod planted {
+    #[test]
+    fn planted() {
+        let v: &[u8] = &[];
+        assert!(v.len() == 0);
+    }
+}

@Japabu

Japabu commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 2, head dec6bef21.

Round 1:

  • BLOCKER src/clippy.rs hand list of the nested userland crates — CLOSED. SHAPES no longer names toyos-desktop, toyos-mdns or toyos-mixer. clippy::runs now derives one NESTED run for each survey.gated entry that holds a /, the way ci.rs:598-605 derives the tests. The measurement is folders4-r2/mutation.log at dec6bef21: clean --clippy EXIT=0 with 22 invocations clean. With the planted len_zero in userland/compositor/desktop/src/budget.rs applied, --clippy EXIT=1, reported under the derived --manifest-path userland/compositor/desktop/Cargo.toml run. Restore EXIT=0. clippy-clean.log shows the three derived runs, and ci-host.log reads Host: 72 step(s), all green at that head.
  • NOTE issues/build/userland-programs-are-never-linted.md — addressed. It now says the nested crates are linted and no program is.
  • NOTE what-is-owed-on-file-size.md history — addressed. It keeps toyos-desktop/ and toyos-mixer/ and says they have moved since.
  • NOTE merge of ToyOS writes its own crate where security asks, above all on a trust boundary or in the kernel; a host test reds on a kernel that resolves libc, and the owner's allocator ruling is filed #696 — addressed. Merged at 48fa9c3c6, and --ci host is green on that tree. main has since taken The kernel heap acquires and zeroes no frame while its lock is held #699 (836b2bc8f). That change touches only kernel/src/mm/{alloc,pmm}.rs and two new issue files, and neither cites a moved path. git merge-tree --write-tree origin/main dec6bef21 exits 0.
  • NOTE PR body "Unsure" — addressed. The two bullets addressed to the reviewer are gone.
  • REMOVE ×6 — all deleted. The desktop and mdns manifest headers, the mixer header's restating lines (its "No dependencies" paragraph stays), soundserver/src/main.rs's corrected lines and cross-reference, and clippy.rs's userland sentence.

Net: 118 files, +137 −195. In src/, production is +62 −45: clippy.rs +52 −28, userlandhost.rs +9 −16 (the fixture test −3 net), ci.rs +1 −1. The track's 42 lines and 18 lines of the root lock are deleted.

BLOCKER

NOTE

REMOVE

LAND

@Japabu
Japabu marked this pull request as ready for review October 3, 2026 23:35
@Japabu
Japabu enabled auto-merge October 3, 2026 23:35
@Japabu
Japabu added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 7a6b667 Oct 4, 2026
6 checks passed
@Japabu
Japabu deleted the wt/toyos-folders4 branch October 4, 2026 00:04
Japabu added a commit that referenced this pull request Oct 4, 2026
github-merge-queue Bot pushed a commit that referenced this pull request Oct 4, 2026
…under one observability umbrella (#704)

Notes only: no source, test or manifest changes. This branch writes the
owner's rulings of 2026-10-03 into the issues whose tracks they change,
each quoted in his words; what was derived from them is attributed to
the orchestrator or cut.

## What changed, per decision

- **The umbrella track, new:
`issues/diagnostics/toyos-explains-itself.md`** (kind: track, 85 lines).
Three parts:
- **The owner's rulings**, quoted: the diary reader shipping ("its
obvious that we want to be able to understand kernel metrics from within
toyos ... should be shipped with toyos"), "Keep crash records", "Only
with permission" (his option text verbatim: power and per-device
interrupts are the revealing counters, and ordinary programs and the
toolbox go without "until each program can be granted rights on its
own"), "General counters", "Always on", and symbols "adopt".
- **Decided by the orchestrator, not ruled.** Each line says where it
came from. Its strategy and the roast of it were adopted by the
orchestrator. A line marked *told* was told to the owner with his veto
open; the rest were not put to him. The lines: on-demand counters with
the roast's bound (*told*); one sampler per CPU (*told*); and the
request vector. The roast's Ring 3 self-IPI is cut as untold design no
exit reads. Design a reader would not pay to re-derive (readers in every
image, the decoder crate, the four places) is cut, since a track carries
no design.
- **A pillar table** that points at each pillar's track, the
orchestrator's build order, and an exit. The exit reads "Only with
permission": a program without the counters right is refused a counter
read, and one holding it but not `trace` is refused the power and
per-device interrupt counters. The track holds the counters and sizes
pillars itself, because no other track does.
- **Folding.** Each of these gains one line naming the umbrella:
  - the logging track;
  - `redesign-the-log-subsystem.md` (its sinks and layout half);
  - the inspect track;
  - both accounting tracks;
  - the T14 firmware-SMI issue.

Where a fold line carries a plan (logging, inspect), it says the plan is
the orchestrator's and not ruled. No track was closed or merged.
- **Symbols, Move 3 of
`the-kernel-still-parses-what-userland-writes.md`.** It quotes "adopt".
The kernel keeping `toyos-elf` is cited to the owner's separate crate
ruling ("if it makes sense we wrote our own elf parser ... we do it") as
the orchestrator's reading of it. The move now names the work left:
  - the kernel stops naming a program's addresses;
- `read_backtrace_table`'s per-spawn table and each task's copy are
deleted;
  - a userland service names a reported file and offset;
  - `rustc-demangle`'s standing is decided.

  It gains an exit that reads each of these.
- **The trace track**
(`nothing-in-the-machine-can-read-the-trace-ring.md`). "Ruled" became
"Proposal accepted (owner, 'Build it as proposed')", and "The lines he
drew" became "The proposal's other lines, accepted with it". The line
"The reader tool is not in the shipped image", which was never his, is
deleted. His quote about shipping the reader replaces it. Step 3 gains
slow system calls under "Always on", and its exit reads one back with
its number and its program.
- **MOR.**
`the-loader-never-sets-the-firmwares-memory-overwrite-request.md` is now
`kind: rejected`, `status: none`: setting the request is declined by
"Keep crash records". The parity track names that line as a place ToyOS
stays below Linux. A new defect,
`a-memory-overwrite-request-ubuntu-left-set-stays-set-under-toyos.md`,
records the T14 reading under Ubuntu, with its command:
`MemoryOverwriteRequestControl` 0x01 and its lock 0x00. Its exit: the
loader clears a set request where the firmware defines it, and on the
T14 a boot that finds it set logs it.
`the-update-rig-the-guest-cut-deleted-is-still-cited.md` drops the MOR
file's two lines.
- **Latency bar** (`toyos-beats-linuxs-latency-on-the-t14.md`). "131 µs"
is ruled. The exit holds the timer interrupt's lateness under 131 µs
with every CPU spawning a program that exits at once, the load under
which Linux read 131 µs (idle it read 99 µs). The woken thread is held
under Linux's loaded longest on the same seven CPUs, 503 µs, so the
ruling is not stretched to a figure he did not give for it.
- **Linux's counter readings before the wipe.** The before-the-wipe
issue gains three outputs whole (with trailing blanks stripped), each
with its exact command and a decoded summary: turbostat idle, turbostat
loaded (eight `yes`), and `perf stat` msr idle. They carry no machine or
network identifier. Taking that Linux as the counters' oracle is
attributed to the orchestrator. The T14 row in the umbrella's exit is
what reads them.
- **ACPI.** The track carries "General counters", "Back to legacy mode",
"Extracts only" and "full clean room write with the spec". Running uACPI
and ACPICA as black-box oracles is moved out of the ruled block and
attributed to the orchestrator. Stage 1's exit reads `MSR_SMI_COUNT`
through the general counters, not by a check of its own, so "General
counters" is read by an exit; it gains a T14 row that kills the server
and reads `SCI_EN` clear.
- **Views.** `every-program-sees-only-the-files-it-was-given.md` gains
"Restrict", "Adopt" and "Per session"; stage 3's "private `/tmp`" became
the session's own. `where-everything-lives.md` amends its `/tmp` line
and rule.
- **Stale crate names.** These paths are re-pointed:
  - `toyos-sched/src/` → `kernel/pure/sched/`
  - `toyos-sched/loom` → `kernel/loom`
  - `toyos-sched/sim` → `kernel/sim`
- `toyos_sched::`/`toyos_proclife::` →
`kernel::sched::`/`kernel::proclife::`
  - `toyos-proclife`/`toyos-pcid` → `kernel/pure/…`

Transcripts of past runs stay as written, because each is true of when
it ran:
  - `739af0c2`'s sweeps;
  - the steal-probe loom run;
  - the two-watch model's evidence;
  - a CI panic log;
  - an `aaddf38a^:` path and a branch name;
- `parallel-tests-red-under-other-suites.md`'s `toyos-sched-sim`
sighting.

In `spawn-thread-disagrees-about-a-reaped-parent.md`, the test that file
cited was deleted in `fa1e3254d`, and the file now says so. Whether the
model that replaced it reaches the state is marked unread.

## Gates

- `cargo run -- --ci host` at `accd59656`: EXIT=0, "72 step(s), all
green" (log
`/Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/rulings-r4/host.log`).
- No guest test is reached: the diff touches only `issues/`.

## Unsure

- **The woken thread's bar.** It is held to Linux's loaded longest, 503
µs, to match the load of his 131 µs. The idle figure was 571 µs.
- **Crate names #703 moved.** `origin/main` still cites `toyos-desktop`,
`toyos-ps2`, `toyos-mixer`, `toyos-net-tcp` and others in `issues/`,
which #703 moved. That is outside this branch's brief.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant