Skip to content

The owner's 2026-10-03 rulings are recorded in their tracks, quoted, under one observability umbrella - #704

Merged
Japabu merged 6 commits into
mainfrom
wt/toyos-rulings
Oct 4, 2026
Merged

Japabu merged 6 commits into
mainfrom
wt/toyos-rulings

Conversation

@Japabu

@Japabu Japabu commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Notes only: no source, test or manifest changes. This branch writes the owner's rulings of 2026-10-03 into the issues whose tracks they change, each quoted in his words; what was derived from them is attributed to the orchestrator or cut.

What changed, per decision

  • The umbrella track, new: issues/diagnostics/toyos-explains-itself.md (kind: track, 85 lines). Three parts:

    • The owner's rulings, quoted: the diary reader shipping ("its obvious that we want to be able to understand kernel metrics from within toyos ... should be shipped with toyos"), "Keep crash records", "Only with permission" (his option text verbatim: power and per-device interrupts are the revealing counters, and ordinary programs and the toolbox go without "until each program can be granted rights on its own"), "General counters", "Always on", and symbols "adopt".
    • Decided by the orchestrator, not ruled. Each line says where it came from. Its strategy and the roast of it were adopted by the orchestrator. A line marked told was told to the owner with his veto open; the rest were not put to him. The lines: on-demand counters with the roast's bound (told); one sampler per CPU (told); and the request vector. The roast's Ring 3 self-IPI is cut as untold design no exit reads. Design a reader would not pay to re-derive (readers in every image, the decoder crate, the four places) is cut, since a track carries no design.
    • A pillar table that points at each pillar's track, the orchestrator's build order, and an exit. The exit reads "Only with permission": a program without the counters right is refused a counter read, and one holding it but not trace is refused the power and per-device interrupt counters. The track holds the counters and sizes pillars itself, because no other track does.
  • Folding. Each of these gains one line naming the umbrella:

    • the logging track;
    • redesign-the-log-subsystem.md (its sinks and layout half);
    • the inspect track;
    • both accounting tracks;
    • the T14 firmware-SMI issue.

    Where a fold line carries a plan (logging, inspect), it says the plan is the orchestrator's and not ruled. No track was closed or merged.

  • Symbols, Move 3 of the-kernel-still-parses-what-userland-writes.md. It quotes "adopt". The kernel keeping toyos-elf is cited to the owner's separate crate ruling ("if it makes sense we wrote our own elf parser ... we do it") as the orchestrator's reading of it. The move now names the work left:

    • the kernel stops naming a program's addresses;
    • read_backtrace_table's per-spawn table and each task's copy are deleted;
    • a userland service names a reported file and offset;
    • rustc-demangle's standing is decided.

    It gains an exit that reads each of these.

  • The trace track (nothing-in-the-machine-can-read-the-trace-ring.md). "Ruled" became "Proposal accepted (owner, 'Build it as proposed')", and "The lines he drew" became "The proposal's other lines, accepted with it". The line "The reader tool is not in the shipped image", which was never his, is deleted. His quote about shipping the reader replaces it. Step 3 gains slow system calls under "Always on", and its exit reads one back with its number and its program.

  • MOR. the-loader-never-sets-the-firmwares-memory-overwrite-request.md is now kind: rejected, status: none: setting the request is declined by "Keep crash records". The parity track names that line as a place ToyOS stays below Linux. A new defect, a-memory-overwrite-request-ubuntu-left-set-stays-set-under-toyos.md, records the T14 reading under Ubuntu, with its command: MemoryOverwriteRequestControl 0x01 and its lock 0x00. Its exit: the loader clears a set request where the firmware defines it, and on the T14 a boot that finds it set logs it. the-update-rig-the-guest-cut-deleted-is-still-cited.md drops the MOR file's two lines.

  • Latency bar (toyos-beats-linuxs-latency-on-the-t14.md). "131 µs" is ruled. The exit holds the timer interrupt's lateness under 131 µs with every CPU spawning a program that exits at once, the load under which Linux read 131 µs (idle it read 99 µs). The woken thread is held under Linux's loaded longest on the same seven CPUs, 503 µs, so the ruling is not stretched to a figure he did not give for it.

  • Linux's counter readings before the wipe. The before-the-wipe issue gains three outputs whole (with trailing blanks stripped), each with its exact command and a decoded summary: turbostat idle, turbostat loaded (eight yes), and perf stat msr idle. They carry no machine or network identifier. Taking that Linux as the counters' oracle is attributed to the orchestrator. The T14 row in the umbrella's exit is what reads them.

  • ACPI. The track carries "General counters", "Back to legacy mode", "Extracts only" and "full clean room write with the spec". Running uACPI and ACPICA as black-box oracles is moved out of the ruled block and attributed to the orchestrator. Stage 1's exit reads MSR_SMI_COUNT through the general counters, not by a check of its own, so "General counters" is read by an exit; it gains a T14 row that kills the server and reads SCI_EN clear.

  • Views. every-program-sees-only-the-files-it-was-given.md gains "Restrict", "Adopt" and "Per session"; stage 3's "private /tmp" became the session's own. where-everything-lives.md amends its /tmp line and rule.

  • Stale crate names. These paths are re-pointed:

    • toyos-sched/src/ → kernel/pure/sched/
    • toyos-sched/loom → kernel/loom
    • toyos-sched/sim → kernel/sim
    • toyos_sched::/toyos_proclife:: → kernel::sched::/kernel::proclife::
    • toyos-proclife/toyos-pcid → kernel/pure/…

    Transcripts of past runs stay as written, because each is true of when it ran:

    • 739af0c2's sweeps;
    • the steal-probe loom run;
    • the two-watch model's evidence;
    • a CI panic log;
    • an aaddf38a^: path and a branch name;
    • parallel-tests-red-under-other-suites.md's toyos-sched-sim sighting.

    In spawn-thread-disagrees-about-a-reaped-parent.md, the test that file cited was deleted in fa1e3254d, and the file now says so. Whether the model that replaced it reaches the state is marked unread.

Gates

  • cargo run -- --ci host at accd59656: EXIT=0, "72 step(s), all green" (log /Users/jan/.claude/jobs/2280e09e/tmp/scratchpad/orch/rulings-r4/host.log).
  • No guest test is reached: the diff touches only issues/.

Unsure

🤖 Generated with Claude Code

https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8

Japabu and others added 2 commits October 4, 2026 01:43
Notes only. The observability umbrella track
issues/diagnostics/toyos-explains-itself.md, from strategy v2 and its
roast (adopt with named changes), with the owner's rulings: shipped
readers, "Keep crash records", "Only with permission", "General
counters", "Always on", symbols "adopt". The pillar tracks point at it.

The trace track keeps only the owner's words as his; the rest is
"proposal accepted". The memory-overwrite request is declined
(kind: rejected) and the parity track says so; the T14's MOR reads set
under Ubuntu, so clearing it is a new defect. The latency bar is
"131 µs". Linux's turbostat and perf msr readings of the T14 go into
the before-the-wipe issue with their commands. The ACPI rulings (back
to legacy mode, extracts only, clean-room AML) and the views rulings
(restrict, adopt, /tmp per session) go into their tracks. Issue files
naming toyos-sched, toyos-proclife or toyos-pcid point at kernel/pure,
kernel/loom and kernel/sim (#694), save transcripts run at a named
commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 1, head f5d965f2a. Net: +509 / −84 lines (git diff --shortstat origin/main...f5d965f2a), all under issues/, with no production or test lines. cargo run -- --ci host: EXIT=0, "69 step(s), all green", logged after the merge commit. No guest test is reached. Nothing that identifies a machine or network entered the tree: the turbostat and perf outputs match t14-reads/ byte for byte apart from trailing blanks, with no host, user, address or serial. The MOR GUID is the public TCG vendor GUID.

Every line attributed to the owner was checked against the orchestrator's record of his words. These match it: "Keep crash records", "General counters", "Always on", "131 µs", "Restrict", "Adopt", "Per session", "Back to legacy mode" and "Extracts only". The findings below are where a line says more than he did, or where a proposal is presented as his.

The implementer's Unsure points:

  • MOR as rejected stands. The file owes nothing, and the weakness is stated in the parity track. The ruling declines the request; it does not defer it.
  • "ended" against PermissionDenied in trace step 1's exit is not this branch's to change. It belongs with the owner.
  • Holding the woken thread to Linux's own figure, not to 131 µs, is the right reading of the question the owner answered.

BLOCKER

  • issues/diagnostics/toyos-explains-itself.md:47 — "The architecture (proposal accepted, 2026-10-03, with the roast's changes)" presents a design as the owner's. Nothing in the record says he accepted it. The record calls D2, D4, D6, D7, D8, D11, D12 and D13 the orchestrator's decisions, "told to the owner with veto", and the roast's changes were never put to him. The trace track uses "Proposal accepted (owner, …)" for his acceptance, so readers will take this heading the same way. issues/README.md also allows a track no design except a line the owner drew. Fix: name who decided each line, and cut the section to the owner's lines plus the bare constraints.

  • issues/diagnostics/toyos-explains-itself.md:28-30 — "Only with permission" is stated more broadly than he gave it. The record names power and per-device interrupts as the revealing counters. The line adds "frequency" and "per-CPU wake counts", and it drops "until per-program rights exist", so "toybox does not" reads as permanent.

  • issues/diagnostics/toyos-explains-itself.md:20-23 — Under "Shipped", "Every reader (trace, inspect kernel.*, size) is in every image, and access is by rights alone" is the strategy's D1. His quote is about understanding kernel metrics from inside ToyOS. size and "by rights alone" belong under the proposal, attributed to whoever decided them.

  • issues/diagnostics/toyos-explains-itself.md:38-39, issues/kernel/the-kernel-still-parses-what-userland-writes.md:44-47 — "the kernel keeps its own ELF reader (toyos-elf)" is recorded as part of the symbols "adopt" ruling. "adopt" did not say that. It came from the orchestrator's reading of the separate crate ruling ("we wrote our own elf parser … we do it"). Either cite that ruling for it or drop it from "adopt".

  • issues/kernel/the-kernel-still-parses-what-userland-writes.md:47-50 — "so what is left of this move is one decision: rustc-demangle's standing" is false once the ruling it follows is added. Two pieces of work are now owed:

    • the kernel stops naming killed programs;
    • the per-spawn symbol copy in kernel/src/loader/symbols.rs is deleted.

    No exit in any file reads that work, and the umbrella's pillar table sends it here.

  • issues/diagnostics/nothing-in-the-machine-can-read-the-trace-ring.md:34-36 — Step 3's title now includes slow system calls, but its exit reads only shootdown delays and window openers. The step can close with the "Always on" ruling unbuilt. Give the exit something that reads the slow-call record: its number and its program.

  • issues/kernel/toyos-runs-the-machine-in-acpi-mode-and-interprets-its-aml.md:53-55 — The "Ruled (owner)" block includes "uACPI and ACPICA are run only as black-box oracles". That is the orchestrator's derivation; his words are "full clean room write with the spec". Running them as oracles is a design choice he did not make. Move it out of the ruled block and attribute it.

NOTE

  • issues/kernel/toyos-runs-the-machine-in-acpi-mode-and-interprets-its-aml.md:47-49 — No exit reads "Back to legacy mode". Stage 1's exit does not cover the server dying and ACPI_DISABLE being written.
  • issues/kernel/toyos-beats-linuxs-latency-on-the-t14.md:39-41 — The exit names no load. Linux's 131 µs was read with every CPU spawning; idle it read 99 µs. An idle ToyOS reading would meet the exit without matching the comparison he ruled on.
  • issues/boot-media/a-memory-overwrite-request-ubuntu-left-set-stays-set-under-toyos.md:43-45 — "a boot that follows Ubuntu" stops being possible after the T14's wipe, though the variable stays set. Say "a boot that finds it set".
  • issues/hardware/linuxs-readings-of-the-t14-and-the-tcg-model-lack-reads-owed-before-the-t14s-wipe.md:476-478 — "the counters' host test reads them when it lands" points at a test nothing owns. The umbrella's exit (toyos-explains-itself.md:137-139) does not name it.
  • issues/kernel/spawn-thread-disagrees-about-a-reaped-parent.md:50 — The citation was re-pointed to kernel::proclife::interleave::tests::a_thread_exit_that_outlived_its_entry_still_leaves. That test was deleted in fa1e3254d and exists under neither name.
  • issues/build/parallel-tests-red-under-other-suites.md:146 — The branch rewrites a past sighting's toyos-sched-sim run as kernel-sim. It left the other transcripts as written because each is true of when it ran; this one should stay as written too.
  • issues/diagnostics/toyos-explains-itself.md — At 139 lines it is past the defect p90 of 72 lines, against README's "the length a defect is". Cutting the architecture section (BLOCKER 1) answers this.
  • branch — origin/main has moved to 7a6b667ed (Every crate with one consumer moves under it, and the track closes #703). The merge is clean. Run host again after merging.

SEND BACK

Japabu and others added 2 commits October 4, 2026 02:22
The umbrella track keeps only the owner's rulings, quoted, and a short list
of the orchestrator's decisions, each marked whether it was told to the owner
with his veto or came from the roast and was never put to him; the
architecture and shared-foundations sections go. The counters ruling is his
option text verbatim: power and per-device interrupts are the revealing
counters, and toybox goes without only until each program can be granted
rights on its own.

Move 3 cites the crate ruling for the kernel's ELF reader, names the work
"adopt" leaves (no kernel naming of a program's addresses, no per-spawn
backtrace table, a userland namer) and gains an exit. The diary's step 3 exit
reads a slow system call's record; ACPI stage 1 gains a T14 row for "Back to
legacy mode", and the oracle use of uACPI and ACPICA is the orchestrator's
reading, not the ruling. The latency exit names the spawning load under which
Linux read 131 us. The counters' Linux readings name the T14 row that reads
them; a deleted test's citation says it was deleted in fa1e325; a past
toyos-sched-sim transcript stays as written.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu Japabu changed the title The owner's 2026-10-03 rulings are recorded in their tracks, under one observability umbrella The owner's 2026-10-03 rulings are recorded in their tracks, quoted, under one observability umbrella Oct 4, 2026
@Japabu

Japabu commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 2, head e97189ac3. Net: +490 / −95 lines (git diff --shortstat origin/main...e97189ac3), all under issues/, with no production or test lines. cargo run -- --ci host at e97189ac3: EXIT=0, "72 step(s), all green" (rulings-r2/host.log, written after the commit). No guest test is reached. Every path the added lines cite resolves at head, except Linux's /bin/true and perf's msr/…/ events, which are not tree paths. resolve_user_symbol (kernel/src/process.rs:1672) and read_backtrace_table (kernel/src/loader/symbols.rs:86) exist. fa1e3254d deletes a_thread_exit_that_outlived_its_entry_still_leaves. Linux's loaded thread maximum is 503 µs on cpu1 (linuxcmp/linux-t14.log:34).

Round 1's BLOCKERs:

  • 1, the architecture presented as the owner's: OPEN. The section is now headed "Decided by the orchestrator, not ruled", and each line says who decided it. But issues/diagnostics/toyos-explains-itself.md:43 reads "the roast of it that he adopted". In this file "he" is the owner every other time (":26 the option he chose", ":39 He asked"), so this sentence says the owner adopted the roast. The record (session log, strategy-v2 roast) has the orchestrator adopting it; the owner never ruled on it.
  • 2, "Only with permission" stated too broadly: CLOSED. :26-30 is the option text word for word as the owner chose it.
  • 3, D1 under "Shipped": CLOSED. It is at :47-48, unmarked. The record's told list (D2, D4, D6, D7, D8, D11–D13) does not include D1.
  • 4, toyos-elf under "adopt": CLOSED. the-kernel-still-parses-what-userland-writes.md:48-51 cites the crate ruling verbatim, as the orchestrator's reading of it.
  • 5, Move 3's remaining work: CLOSED. :53-65 names the three pieces of work and the demangler decision, and its exit reads each.
  • 6, step 3's exit: CLOSED. nothing-in-the-machine-can-read-the-trace-ring.md:38-39 reads the slow call back with its number and its program.
  • 7, the oracles inside the clean-room ruling: CLOSED. toyos-runs-the-machine-in-acpi-mode-and-interprets-its-aml.md:56-58 attributes them to the orchestrator.

BLOCKER

  • issues/diagnostics/toyos-explains-itself.md:43 — "the roast of it that he adopted" says the owner adopted the roast. The record says the orchestrator did. Fix: "that the orchestrator adopted".
  • issues/diagnostics/toyos-explains-itself.md:85-89 — No exit reads the owner's "Only with permission" ruling.
    • The track holds the counters pillar, and no other track holds it.
    • The exit asks only that inspect kernel.*, trace and size answer under some right. So the track can close with counters readable by anyone, or with power and per-device interrupts behind the ordinary counters right instead of the diary right.
    • This is the same class as round 1's BLOCKER 6.
    • Fix: add to the exit that a program without the counters right is refused a counter read, and a program holding it but not trace is refused the power and per-device interrupt counters.

NOTE

  • issues/diagnostics/toyos-explains-itself.md:57-59 — The self-IPI sentence ("The roast's: a Ring 3 sample raises a self-IPI") sits inside a bullet marked Told. The record's told list has D6 and D7 but no self-IPI, so the bullet says it was told.

  • issues/diagnostics/toyos-explains-itself.md:51-53 — The Told item on the record is D2, "two kernel stores for history". This bullet instead states the four-places rule (strategy-v2 §1), which is not on the told list. Either state D2, or drop the Told mark.

  • PR body, "the roast's changes and the rest were never put to him" — this is false of D4. The record shows D4 was told "with bounded wait (serve own CPU, Watch, stale)", which the track marks Told at :54-56.

  • issues/diagnostics/toyos-explains-itself.md — At 89 lines it is past the defect p90 of 72 (379 defects, median 29). Three bullets are orchestrator design rather than constraints a reader would pay to re-derive, and issues/README.md says a track carries no design:

    • every reader in every image (:47-48);
    • the decoder crate, which root CLAUDE.md's self-hosting already says (:49-50);
    • the four places (:51-53).

    Cut them.

  • issues/kernel/toyos-beats-linuxs-latency-on-the-t14.md:38 — "every CPU spawning /bin/true" names a program ToyOS does not have: there is no true in userland/ and no row in system.toml. Name the ToyOS program the load spawns, or say it is a program that exits at once.

  • issues/kernel/toyos-runs-the-machine-in-acpi-mode-and-interprets-its-aml.md:62-67 — Stage 1's exit reads MSR_SMI_COUNT flat. It does not read it through the general counters, so "General counters" (:44-46) can be met by the one-off check the ruling rejects.

SEND BACK

…neral counters

- toyos-explains-itself: the roast was adopted by the orchestrator, not the
  owner; the exit refuses a counter read to a program without the counters
  right, and the power and per-device interrupt counters to one without
  `trace`, so the track cannot close past "Only with permission"; the self-IPI
  leaves the *told* bullet; the three design bullets (readers in every image,
  the decoder crate, the four places) are cut.
- ACPI stage 1's exit reads MSR_SMI_COUNT through the general counters, not a
  check of its own, so "General counters" is read by an exit.
- The latency exit's load names a program that exits at once, not a
  `/bin/true` ToyOS does not have.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu

Japabu commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator Author

Review round 3, head 566d07196. Net: +488 / −98 lines (git diff --shortstat origin/main...566d07196), all under issues/, with no production or test lines. origin/main (7a6b667ed) is an ancestor of head. cargo run -- --ci host at 566d07196: EXIT=0, "72 step(s), all green" (rulings-r3/host.log; its run starts at 00:43:43 UTC, after the commit at 00:43:28 UTC). No guest test is reached. Since round 2 three files changed: toyos-explains-itself.md, toyos-beats-linuxs-latency-on-the-t14.md and toyos-runs-the-machine-in-acpi-mode-and-interprets-its-aml.md. The PR body at head matches rulings-r3/body.md except for one trailing blank line.

Round 2's BLOCKERs:

  • 1, "the roast of it that he adopted": CLOSED. issues/diagnostics/toyos-explains-itself.md:43 now reads "that the orchestrator adopted".
  • 2, no exit reads "Only with permission": CLOSED. The exit at :80-82 refuses a counter read to a program without the counters right, and refuses the power and per-device interrupt counters to one that holds the counters right but not trace. trace is the diary's right (nothing-in-the-machine-can-read-the-trace-ring.md:23, :53), which is the "strict diary permission" of the option text at :26-30.

Round 2's NOTEs:

  • Self-IPI under Told: done. It is now its own untold bullet at :52.
  • D2 / four places marked Told: done. The bullet is cut.
  • PR body "never put to him" false of D4: done. The body now separates the told lines from the rest.
  • /bin/true: done (toyos-beats-linuxs-latency-on-the-t14.md:38).
  • ACPI stage 1 reads MSR_SMI_COUNT flat: done. It now reads it "through the general counters and not by a check of its own" (:63-65).
  • Track length: open, carried below.

BLOCKER

NOTE

  • issues/diagnostics/toyos-explains-itself.md:52 — Cut "The roast's: a Ring 3 sample raises a self-IPI."
    • The track is 84 lines. That is past the defect p90 of 72 (378 defects, median 29), and issues/README.md writes a track "to the length a defect is" and says it "does not carry a design".
    • This line is untold orchestrator design. No exit or build step at :67-84 reads it.
    • The request-vector bullet at :53-54 stays, because Lane A at :72 names the request vector.

REMOVE

LAND AFTER NAMED CHANGES

…-itself track

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
@Japabu
Japabu marked this pull request as ready for review October 4, 2026 01:00
@Japabu
Japabu enabled auto-merge October 4, 2026 01:00
@Japabu
Japabu added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 3f1db70 Oct 4, 2026
6 checks passed
@Japabu
Japabu deleted the wt/toyos-rulings branch October 4, 2026 01:42
Japabu added a commit that referenced this pull request Oct 4, 2026
Japabu added a commit that referenced this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant