Repository navigation
The owner's rulings of 2026-10-04 are recorded in their tracks, and the T14's root-bridge fixture becomes decoded values - #714
Conversation
… bytes
The owner ruled on 2026-10-04 ("Local only; decode the 186 bytes"): "Full
tables stay out of the repo (a copy you hold); the 186-byte fixture on main
is replaced by decoded values, as 'Extracts only' says."
`toyos-acpi/fixtures/thinkpad-t14/root-bridge-0.bin` was the 186 bytes the
T14's firmware answered through `EFI_PCI_ROOT_BRIDGE_IO_PROTOCOL::
Configuration`, off the loader log of metal run 33. It goes, with its
`SOURCE` and its `src/licence.rs` entry. In its place,
`tests/common::t14_root_bridge` lays the same list out of its decoded
fields: four QWORD Address Space Descriptors (I/O 0x3000..=0x3fff; memory
0xa2000000..=0xbcffffff and 0x4000000000..=0x603dbfffff, granularities
0x20 and 0x40; bus 0..=0x79) and the End Tag. Before the file went, a test
asserting the builder's output equal to the file's bytes ran green, so the
two tests that read the list run over the identical 186 bytes.
The descriptor builder moves into `tests/common` beside the table builders,
taking every field; `tests/resource.rs`'s well-formed `qword` is a call into
it. The OVMF list is QEMU's and stays as captured.
Mutations, each applied, built, run and reverted:
- the decoder's length truncated to 32 bits: the T14 decode test red
(101), the OVMF decode test green (0) — only the T14's numbers reach it;
- the zero-length guard dropped: the corpus sweep red (101);
- the T14 list's bus descriptor dropped: the corpus sweep red (101) on its
mutation count.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
Each is quoted as the option text he chose; what surrounds it is marked the orchestrator's or the design's. - The IOMMU track takes "Refuse external, record reflash", and for stage 2 "Display and USB only", "Accept and file" and "Allow it". The reflash weakness is filed as its own defect, owner the orchestrator, exit a ruled and built firmware verification held by a row. - The kernel heap's SLUB-hardening defect takes "Change the goal": its exit is the allocator's kernel front under the goal put to him, and the allocator track owns it. The allocator track takes "Yes, that bar" into its exit. - The tooling track takes "Design pass, then re-cut" on #629. - The latency and trace tracks take "Both in parallel". His text's "latency step 1 (interrupts on in system calls)" is the latency track's step 2; both files say so, as the orchestrator's mapping. - The ACPI track takes "Local only; decode the 186 bytes", which the previous commit carries out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
- The ACPI track takes "Like Windows, not Linux" on `_OSI`, quoted as far as the option's text was relayed, with the orchestrator's note that the answers are fixed before the first table loads; and "Yes, one path" on power-off, which applies from the interpreter's power-off stage on. - The IOMMU track's stage 2 takes "Apply it at hand-over" on reserved memory, and his answer on the undriven-NVMe row: "You can do with the t14 what you want", so the row is allowed on its own boot. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
|
Mutation and equivalence patches for this pull request, each applied with equivalence.patch--- a/toyos-acpi/tests/resource.rs
+++ b/toyos-acpi/tests/resource.rs
@@ -193,3 +193,8 @@
bytes.truncate(40);
assert_eq!(windows(&bytes, 8), Err(ResourceError::Unreadable { at: AT, len: 46 }));
}
+
+#[test]
+fn decoded_t14_values_are_the_committed_bytes() {
+ assert_eq!(common::t14_root_bridge(), include_bytes!("../fixtures/thinkpad-t14/root-bridge-0.bin").to_vec());
+}m1.patch--- a/toyos-acpi/src/resource.rs
+++ b/toyos-acpi/src/resource.rs
@@ -170,7 +170,7 @@
if kind == TYPE_MEMORY {
let min = u64le(phys, head, QWORD_MINIMUM);
let max = u64le(phys, head, QWORD_MAXIMUM);
- let length = u64le(phys, head, QWORD_LENGTH);
+ let length = u64le(phys, head, QWORD_LENGTH) & 0xffff_ffff;
let translation = u64le(phys, head, QWORD_TRANSLATION);
let flags = phys.byte(head + GENERAL_FLAGS as u64);
// A window of no length decodes nothing, and firmware emits onem3.patch--- a/toyos-acpi/src/resource.rs
+++ b/toyos-acpi/src/resource.rs
@@ -176,7 +176,7 @@
let flags = phys.byte(head + GENERAL_FLAGS as u64);
// A window of no length decodes nothing, and firmware emits one
// where a range is declared and unused.
- if length != 0 {
+ {
let refusal = if min.checked_add(length - 1) != Some(max) {
Some(ResourceError::Inconsistent { min, max, length })
} else if translation != 0 {m4.patch--- a/toyos-acpi/tests/common/mod.rs
+++ b/toyos-acpi/tests/common/mod.rs
@@ -148,6 +148,5 @@
qword_descriptor(IO, 0, 0x3000, 0x3fff, 0, 0x1000),
qword_descriptor(MEMORY, 0x20, 0xa200_0000, 0xbcff_ffff, 0, 0x1b00_0000),
qword_descriptor(MEMORY, 0x40, 0x40_0000_0000, 0x60_3dbf_ffff, 0, 0x20_3dc0_0000),
- qword_descriptor(BUS, 0, 0, 0x79, 0, 0x7a),
])
} |
|
Review round 1, head Net: 15 files, +186 −65. Production: Measurements read: BLOCKER
NOTE
REMOVE
SEND BACK |
…they bind has an owner and an exit - The "Like Windows, not Linux" option is quoted whole; the orchestrator's note that the answers are fixed before the first table loads goes (a track carries no rationale). - "Yes, one path" gets a named stage, the orchestrator's placement, whose exit is the kernel's \_S5_ reader (toyos-acpi/src/dsdt.rs and its caller in kernel/src/arch/x86_64/power.rs) deleted and a test red on a broken server. - The IOMMU track loses its "stage 2" label, which pointed at nothing, and gains an owner (the orchestrator) and an exit that reads each ruled refusal. - "Accept and file": the gap is filed now, as issues/kernel/a-unit-in-scalable-or-abort-mode-loses-translation-for-its-root-table-switch.md, with PMEN's protected memory regions as its exit. - "You can do with the t14 what you want" stands as his words, and the record says the grant goes beyond the question asked. - The reflash defect drops its citation of roasts nothing in reach carries. - resource.rs's header loses the line about committed bytes, now false of the T14's list. - The OVMF root-bridge list is one OVMF_ROOT_BRIDGE in tests/common, read by corpus.rs and fixtures.rs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
|
Review round 2, head Net: 17 files, +238 −68. Production: Measurements read:
Round 1
BLOCKER
NOTE
REMOVE
SEND BACK |
…ver ruling and the scope refusal - The hand-over bullet reads both halves of "Apply it at hand-over": a device that is neither display nor USB faults on its own RMRR region, is logged and stopped, and the machine keeps running; a display or USB controller its RMRR names alone keeps that region. Each half has its own negative control. The old bullet read only access to another device's region, which default-deny already faults. - The exit also reads the track's own headline refusal, the isolation-scope rule, which the kernel does not build yet. - The PMEN exit is bounded to units reporting CAP.PLMR and CAP.PHMR (VT-d Rev. 4.1 §11.4.8.1 treats PMEN_REG as read-only otherwise and plans it for deprecation); a unit without them is recorded as having no fix under this exit. The test is a host test: QEMU 11's unit always reports ESRTPS and defines PMEN_REG read-only zero, and the T14's units support neither mode. - The power-off stage names its blocker: the interpreter's evaluation of \_S5. - The track's sentence on the T14's ESRTPS/SMTS/ADMS bits is removed; the defect file carries it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
|
Review round 3, head Net: 17 files, +251 −68. Production: Measurements read:
Round 2
NOTE
REMOVE(none) LAND AFTER NAMED CHANGES |
…hared-RMRR display case - The scalable-mode defect gives §11.4.8.1's actual reason: with PLMR or PHMR clear that region's base and limit are read-only, so PMEN cannot cover all of memory (PMEN_REG is read-only only with both clear). - The defect stays open for units with either bit clear once the PMEN exit is met, and carries an exit of its own for them. - The IOMMU track's hand-over exit also reads a display or USB controller whose RMRR names another device: it faults on that region. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
#719 landed the same fix this branch made for virt_smp's job waits: one capture threaded through every wait. Its form is kept (`virt_console` and `judge_virt_job` taking the capture); this branch's `judge_virt_job_after` goes, and `test_rs_trace_read`'s wait is one more `judge_virt_job` call on the same capture. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8
The owner's rulings of 2026-10-04 are recorded in the tracks they change, each quoted as the option text he chose and dated; everything around a quote is marked as the orchestrator's or the design's. One raw firmware fixture is replaced by its decoded values.
Net (
git diff --shortstat origin/main...HEAD): 17 files, +251 −68. Production code:src/licence.rs−6 (one entry) and one doc line intoyos-acpi/src/resource.rs. Tests:toyos-acpi/tests+48 −41. Issues: +203 −9. Deleted: the 186-byte.binand itsSOURCE(−11).1. "Local only; decode the 186 bytes": the T14's root-bridge list is decoded values
His option: "Full tables stay out of the repo (a copy you hold); the 186-byte fixture on main is replaced by decoded values, as 'Extracts only' says."
toyos-acpi/fixtures/thinkpad-t14/root-bridge-0.binand itsSOURCEare deleted. So is its entry insrc/licence.rs, the tree's file-to-terms table.NOTICEnever named the file (grep -n "root-bridge\|thinkpad" NOTICEprints nothing).tests/common::t14_root_bridgebuilds the same list from its decoded fields:0x3000..=0x3fff;0xa2000000..=0xbcffffff, granularity0x20;0x4000000000..=0x603dbfffff, granularity0x40;0..=0x79;t14_root_bridge() == include_bytes!(…root-bridge-0.bin)was applied as a checked patch, run green (cargo test -p toyos-acpi --test resource, EXIT=0, 12 passed), and reverted.tests/common, next to the table builders, and now takes every field.tests/resource.rs's well-formedqwordcalls it. Before this there was one builder; there is still one.OVMF_ROOT_BRIDGEintests/common, beside the T14's, read bycorpus.rsandfixtures.rs.toyos-acpi/src/resource.rs's header line saying the corpus test runs over "both firmwares' committed bytes" is deleted: the T14's list is no longer committed as bytes.Mutations. Each was applied as a checked patch, built (build EXIT=0 each), run, and reverted, and the tree was clean afterwards. The patches are posted as a comment on this pull request.
fixtures::a_second_firmwares_bytes_decode_to_that_machines_own_windowsInconsistent,expectpanics)fixtures::the_windows_a_boot_printed_are_what_that_firmwares_own_bytes_say(OVMF)corpus::no_single_byte_mutation_of_a_firmwares_descriptor_list_panics_or_runs_awaylength - 1overflows,resource.rs:189)cargo test -p toyos-acpiat the fixture commit: EXIT=0.2. The IOMMU threat model, "Refuse external, record reflash"
issues/kernel/the-iommu-refuses-nothing-yet.md.issues/kernel/a-driver-that-reflashes-its-device-escapes-its-isolation.md:kind: defect;00:07.0and00:07.2(Thunderbolt root ports, device ids9a25and9a27), under units 1 and 2. Source: theiommu:lines oforch/536-metal-full.log. This is labelled the orchestrator's reading.3, 9, 10. The IOMMU's default-deny root and hand-over: "Display and USB only", "Accept and file", "Allow it", "Apply it at hand-over", and the NVMe row
All five are recorded in the IOMMU track under one heading, which names its subject; the track defines no stages.
TTM≠00withCAP.ESRTPSclear. The "older protection registers" arePMEN(§11.4.8.1).CAPbit 63 (ESRTPS) clear, andECAPbit 52 (ADMS) and bit 43 (SMTS) clear. Unit 0'scap=0x01c0000c40660462 ecap=0x0000029a00f0505e; units 1–3cap=0x00d2008c40660462 ecap=0x0000000000f050da. The same log names the one RMRR,0x9c000000..0xa07fffff, scoped to00:02.0alone.issues/kernel/a-unit-in-scalable-or-abort-mode-loses-translation-for-its-root-table-switch.md(kind: defect, owner the orchestrator under the IOMMU track). Its exit: on such a unit that reportsCAP.PLMRandCAP.PHMR,PMEN's protected memory regions cover all of memory before translation goes off for the switch and are released only once it is back on; a host test reads that order, and is red with thePMENstep removed. It is a host test because no machine reaches the path: QEMU 11'svtd_cap_initalways setsVTD_CAP_ESRTPSand definesPMEN_REGread-only zero, and the T14's units support neither mode. A unit reporting either bit clear has no fix under this exit: with either clear, that region's base and limit are read-only (§11.4.8.1), soPMENcannot cover all of memory, and the same section plans the registers for deprecation. The file stays open for such a unit once thePMENexit is met, with its own exit: no function behind it reaches memory while translation is off for the switch, read by a host test that is red with the fix removed. It namesissues/kernel/a-unit-left-translating-passes-dma-untranslated-while-programmed.mdas the defect that closes the gap where the switch may stay translating.4. The kernel heap's goal, "Change the goal"
issues/kernel/the-kernel-heap-has-none-of-slubs-hardening.mdquotes the ruling and the goal as it was put to him. Its owner is now the allocator track.dlmallocor against the front with that part removed:5. The allocator bar, "Yes, that bar"
issues/kernel/toyos-has-its-own-allocator.md.dlmalloceverywhere.6. #629, "Design pass, then re-cut"
Recorded in
issues/build/the-tooling-is-a-review-prompt-and-three-workflows.md, the track whose content-addressed-toolchain item #629 builds. #629 is not touched.7. Trace order, "Both in parallel"
issues/diagnostics/nothing-in-the-machine-can-read-the-trace-ring.md).issues/kernel/syscall-preemption-is-incidental.md), whose exit themask_windowsrow reads. Both files state this mapping and label it the orchestrator's.8, 11. The interpreter: "Like Windows, not Linux" and "Yes, one path"
_OSIoption is quoted whole: "Yes to every published Windows version string, no to 'Linux' and 'FreeBSD', as Linux itself answers. The T14 then runs the path it was tested on: Modern Standby, CPU performance tables, 101-step backlight, thermal profiles, all devices present." No rationale of the orchestrator's is attached to it, since a track carries none.\_S5. Its exit: the kernel's\_S5_reader,toyos-acpi/src/dsdt.rs, and its caller inkernel/src/arch/x86_64/power.rsare deleted, and a test that powers off through a broken server is red.Gates
cargo run -- --ci hostat27b7753e3: EXIT=0. During that run, the commit that came after it was being edited, and it changes only issue files.cargo run -- --ci hostat the pushed head77408f574: EXIT=0 (logorch/rulings2/ci-host2.log).cargo run -- --ci hostat the pushed head21ddf46c0: EXIT=0 (logorch/rulings2-r2/ci-host.log,Host: 73 step(s), all green).cargo run -- --ci hostat the pushed headbad9f2f2d: EXIT=0 (logorch/rulings2-r3/ci-host.log,Host: 73 step(s), all green).cargo run -- --ci hostat the pushed head1d2eee6c3: EXIT=0 (logorch/rulings2-r4/ci-host.log,Host: 73 step(s), all green).cargo test -p toyos-acpiafter the round-1 fixes: EXIT=0 (logorch/rulings2-r2/acpi-test.log).toyos-acpi, one doc line of its source and issue files, and no behaviour the image has.Unsure
a-unit-left-translating-passes-dma-untranslated-while-programmed.md, which is already onmain; the new scalable/abort-mode defect names it and covers only the units where §6.6 forbids the switch under translation. If IOMMU stage 1: a claimed function speaks only through its own remapping entry, has no untranslated space, and no domain reaches a host bridge's window #710 renames or closes it, that merge moves the citation.🤖 Generated with Claude Code
https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8