Skip to content

std's ToyOS backend lives in sdk/std, and the fork names it by #[path] - #745

Merged
Japabu merged 3 commits into
mainfrom
wt/toyos-stdmove
Oct 7, 2026
Merged

Japabu merged 3 commits into
mainfrom
wt/toyos-stdmove

Conversation

@Japabu

@Japabu Japabu commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

What changed

The 21 files that implement std on ToyOS leave the rust fork for sdk/std/, laid out as std lays them out (os/, sys/, sys/pal/, sys/net/). Fork commit cc9c8b1be68 (on the fork's main, appended to 7fa3f566c28) removes them and gives each of the 14 arms that selects one a #[path] naming the file here; the rust gitlink moves to it. The owner ruled the move and the mechanism ("MOVE IT", by #[path]).

Why: of the 25 times main moved the fork pin (git log --first-parent origin/main -- rust, each compared with git -C rust diff --name-only <old pin> <new pin>), 13 changed nothing but these files and 4 more these and one shared std file. Such a change is now one commit in one repository.

files lines
fork, cc9c8b1be68 35 +14 −4,155
this tree, sdk/std 21 +4,155
this tree, src/ production 3 +10 −6 (one list entry in sysroot.rs, one in sourcegate.rs, three doc comments)
this tree, src/ tests 2 +3 −3
src/CLAUDE.md 1 +1 −1
issues/ 40 +145 −78 (3 filed, 2 renamed, the rest citations repointed and the track's tree)

git diff --shortstat origin/main...HEAD: 66 files, +4,315 −89.

Decisions

  • Where. sdk/std/. issues/the-tree-says-who-uses-each-thing.md, rule step 3: what something outside this repository uses goes to sdk/, and the rule already names std as that user ("what std links"). Step 3 is asked before step 4, and step 4's answer, inside its one user, is the fork. sdk/ did not exist; this is its first entry, at its final place, because a later move would break every fork commit pinned before it. The track's tree and its list of differences record it.
  • A move, and nothing else. No backend code changes. The two #[path]s the files hold themselves (os/unix/ffi/os_str.rs, sys/pal/unsupported/common.rs) now point back into the fork.
  • The build system: one list entry. sdk/std joins SYSROOT_SOURCES. That list is read by sysroot::witness, which is in the sysroot key a dev host builds under, in the key of the sysroot layer CI's toolchain job restores and saves (release::layers), and is the record an installed toolchain is matched to its checkout by (release::lay_out, toolchain::check_installed_toolchain). A backend edit moves the sysroot key alone; the fork's library/ no longer moves with it, so the freestanding libraries (the kernel's and the loader's) stay.
  • The dep-info gate is not extended. assert_std_built_from decides that std's toyos-abi and toyos sources are this worktree's, which says the fork checkout that built it is this worktree's own. The backend is named relative to the same fork checkout, so the same answer covers it. STD_SOURCES' comment and its test's fixture say so.
  • sourcegate's GUEST_CODE names sdk/std. The first --ci host was red on every_host_scratch_is_the_guard: temp_dir() in sdk/std/sys/pal/os.rs is std's own definition, in code compiled for the guest.
  • The tracker. The citations of the moved files in 35 issue files are repointed, and the sentences that placed them in the fork corrected. Two slugs the move refuted are renamed (two-std-maps-…, stds-toyos-files-carry-lines-rustfmt-would-rewrap; neither was cited anywhere). Three issues are filed for what the move leaves:
    • issues/std-names-its-toyos-backend-by-a-path-out-of-the-fork.md: the 14 lines are not upstream-mergeable as written, tree and fork each know the other's layout, and a panic in the backend prints its file through the arm (library/std/src/sys/time/../../../../../../sdk/std/sys/time.rs, read out of the built libstd; relative, so no checkout path enters the bytes).
    • issues/stds-toyos-backend-keeps-assembly-outside-an-architecture-module.md: sys/pal/mod.rs and sys/pal/tls.rs hold naked functions under target_arch, which reviewer.md's "Fit" keeps in an architecture's module. Restructuring them here would have made the move uncheckable as a move.
    • issues/nothing-refuses-a-std-that-read-a-worktree-file-its-key-does-not-name.md: the stale arm below, as a class.
  • src/CLAUDE.md's std type-check recipe gains the sdk symlink it now needs. Run once with it: std compiled from the recipe's tree (the probe program then failed to link, which the recipe does not ask for).

High-risk: the checks

Build system and toolchain. All at head 3831f291b, on an M4 Pro with 14 cores, shared with other agents' builds; each arm's log opens with uptime.

Negative control, three arms in one script, each a checked patch, built with cargo run -- --build-only --arch aarch64, run as cargo test --test toyos-build -- virt_readonly_copyout, restored, tree clean after. M2 makes std's start_rust exit with code + 1; M-key takes sdk/std off SYSROOT_SOURCES. Both patches are in the comment below.

arm sysroot key freestanding key std built build guest test
green: the tree 62be33c18be17168 5681eaf54286442e (already there) exit 0, 2.17 s exit 0
red: M2 b60346da611e8cea 5681eaf54286442e yes exit 0, 142.92 s exit 1, test_rs_abuse_readonly_copyout exit=1
stale base: M-key 46c572c6e5176094 5681eaf54286442e yes exit 0, 143.08 s exit 0
stale: M-key + M2 46c572c6e5176094 5681eaf54286442e no exit 0, 1.94 s exit 0, on the std built before M2

The fourth row is the scout's silent stale std: the tree says every program exits one higher and the guest test passes.

The key's own test. sysroot::tests::a_comment_is_the_same_sysroot_and_a_signature_is_another now edits sdk/std and asserts the sysroot key moves and the freestanding key does not. Under M-key: exit 101, sdk/std kept the old sysroot. This is a host test; the key is a function of files, so no guest is needed for it.

CI's layers, by the function CI runs. GITHUB_OUTPUT=<file> cargo run -- --ci toolchain in each arm, exit 0: llvm, compiler and freestanding keys identical in all arms (b84b400f23c42d55, c58d859550c29f65, 5681eaf54286442e), sysroot as in the table. These are this host's keys, not a runner's; what carries over is which layers move.

Independent oracles.

  • Differential against the fork: each of the 21 files, diffed against git show 7fa3f566c28:<its old path>. 19 identical; os/ffi.rs and sys/pal/mod.rs differ in the one #[path] line each.
  • Differential of the product: every defined symbol of libstd-*.rlib (GNU nm --defined-only -S) in main's sysroot 9c33148e3d5ab541 against the moved one's, with crate disambiguators, legacy hashes and anonymous-label numbers normalised: same names, types and sizes, 1,758 symbols for x86_64-unknown-toyos and 1,723 for aarch64-unknown-toyos, diff exit 0 for both.
  • The built library names all its backend files under sdk/std (strings in libstd), and the sysroot's SOURCES records 21 sdk/std witness lines.

Gates, at 3831f291b

command exit
cargo run -- --ci host 0 (Host: 75 step(s), all green)
cargo run -- --build-only 0
cargo run -- --build-only --arch aarch64 0
cargo test 0 (28 passed, 28 total, 30 guests; 4 x86-64 screen tests, 3 machine tests, 21 AArch64 virt_* boots)

AArch64 boots: the virt_* tests boot the AArch64 image and run programs built on the moved std to exit 0 (virt_user_mode, virt_smp, virt_readonly_copyout among them).

The first build of the move (measured on the branch before its rebase onto #743 and #744): --build-only exit 0 in 467 s, building the freestanding libraries and the sysroot once, since the fork's library/ changed; --arch aarch64 exit 0 in 79 s.

How long an edit takes to rebuild

cargo run -- --build-only, x86-64 image, same session, load average 25 to 36:

edit what is rebuilt wall
none nothing 6.1 s
one line in sdk/std/sys/time.rs sysroot (62be33c1… to d8831cdf…), then userland 201.5 s
one line in the fork's library/std/src/sys/time/mod.rs, as a backend edit was before freestanding libraries, sysroot, then kernel, loader and userland 314.2 s

A change under the fork's compiler/ builds a compiler first; that was not run here. The research report cites 12:58 to 22:05 for the compiler alone on this machine (#597's and #629's bodies).

Not measured, and unsure

  • CI did not run: ci.yml skips a draft. Read from the code and from the keys above, the first run builds the freestanding and sysroot layers and restores llvm and compiler; after landing, a backend edit moves the sysroot layer alone. git submodule update --init --depth 1 rust needs the fork commit reachable, and it is on the fork's main.
  • The hosted rustc was not built. Only the primary checkout builds it, in its own rust/ under the global lock (issues/a-worktree-cannot-build-a-hosted-rustc-of-its-own.md); src/build.rs refuses hosted-rustc = true; and the primary holds none today. By reading: its std is compiled in place from <primary>/rust/library, so the arms resolve to <primary>/sdk/std, which the primary has once it is at a main with this change. Nothing keys the hosted rustc on std's sources, before or after.
  • std's own tests are metal rows, and ran green on the T14 at 3831f291b (Round 2 below). wall_clock_now, std_fs and the rest run on the T14's shared boots, not in cargo test. The metal profile was staged without touching the machine: cargo test --test toyos-build -- --metal --metal-readback <dir>, exit 2, 28 images.
  • The fork's main already carries cc9c8b1be68, as the fork's rules ask. A branch that edits the backend in the fork meets a modify/delete conflict when it takes this one; its edit moves to sdk/std.
  • sdk/std has no formatter and no lint of its own; issues/stds-toyos-files-carry-lines-rustfmt-would-rewrap.md now names the files there.

Round 2: head d4452b4df

3831f291b, a merge of origin/main (257ebea2a: #740, #741, #713), and one commit answering review round 1. That commit touches issues/, src/CLAUDE.md and tests/metal alone (14 files, +74 −19): the hosted rustc's std is filed as issues/nothing-keys-the-hosted-rustc-on-stds-sources.md with the exit the review gave; the std type-check recipe says which fork files it reads through the sdk link; ten issue files stop placing the backend in the fork beside a path already repointed; the three boot.testcases-bounds rows the metal run asked for are recorded; and issues/the-t14s-record-keeps-three-rows-of-a-boot-nothing-stages.md is filed. The fork pin is unchanged, cc9c8b1be68.

Gates at d4452b4df, one script from a clean tree, each log opening with the head and status lines 0:

command exit
cargo run -- --build-only 0
cargo run -- --build-only --arch aarch64 0
cargo run -- --ci host 0, Host: 76 step(s), all green
cargo test 0, 30 passed, 30 total

The metal profile ran at 3831f291b, before the merge, on the T14: cargo test --test toyos-build -- --metal from the clean worktree, EXIT=0, [metal] 294 passed, 0 failed, 28 boot(s); each row that is std's only test ended exit=0 (std_alloc, std_fs, std_fs_write, std_io, std_mmap, std_process, std_sync, std_threading, std_tls, std_tls_cranelift, std_tls_dlopen, std_tls_multi_crate, std_unwind, std_unwind_so, wall_clock_now). It was not re-run at d4452b4df: the merge brings main's kernel and servers under the same moved std, and the guest suite above is the run of that combination.

Still not measured: the hosted rustc (the new issue), and CI on a runner, which runs when this is marked ready.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A

The 21 files that implement std on ToyOS leave the `rust` fork for
`sdk/std/`, laid out as std lays them out (`os/`, `sys/`, `sys/pal/`,
`sys/net/`). Fork commit cc9c8b1be68 removes them and gives each of the 14
arms that selects one a `#[path]` naming it here; the gitlink moves to it.
The files are byte for byte the fork's at 7fa3f566c28, save the two
`#[path]`s they hold themselves, which now point back into the fork.

Of the 20 times main moved the fork pin, 10 changed nothing but these
files and 4 more these and one shared std file. Such a change is now one
commit in one repository.

`sdk/std` is one more of the sysroot's keyed sources (`SYSROOT_SOURCES`),
which is the whole build-system change: the same list is the key of the
sysroot a dev host builds, of the layer CI's `toolchain` job restores, and
the witness an installed toolchain is matched to its checkout by. A backend
edit moves the sysroot key alone; the fork's `library/` no longer moves
with it, so the kernel's and the loader's libraries stay.

`sdk/` is where `issues/the-tree-says-who-uses-each-thing.md` puts what
something outside this repository uses (rule step 3), std among them.

The source gate's list of guest code names `sdk/std`: `temp_dir()` there
is std's own.

Three things the move leaves are filed: the paths out of and back into
the fork, the backend's assembly outside an architecture's module, and
that nothing refuses a std that read a file its key does not name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu

Japabu commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator Author

Mutation and timing patches behind the body's tables, each applied with git apply --check then git apply, and reversed with git apply -R in the same script.

M-key-no-backend-entry (this tree)

--- a/src/sysroot.rs
+++ b/src/sysroot.rs
@@ -63,10 +63,9 @@
 /// The per-worktree sources that end up inside a sysroot: std links `toyos-abi`
 /// and `toyos` and compiles its ToyOS backend from `sdk/std`, and
 /// `libtoyos_c.a` is `userland/libc` with `toyos-elf` and `toyos-osrelease`.
-pub const SYSROOT_SOURCES: [&str; 7] = [
+pub const SYSROOT_SOURCES: [&str; 6] = [
     "toyos-abi/src",
     "toyos/src",
-    "sdk/std",
     "toyos-elf/src",
     "toyos-osrelease/src",
     "userland/libc/src",

M2-every-program-exits-one-more (this tree)

--- a/sdk/std/sys/pal/mod.rs
+++ b/sdk/std/sys/pal/mod.rs
@@ -98,7 +98,7 @@
 
     let code = unsafe { main(argc as i32, argv) };
     crate::sys::stdio::finish();
-    toyos_abi::syscall::exit(code)
+    toyos_abi::syscall::exit(code + 1)
 }
 
 pub fn abort_internal() -> ! {

M1-clock-a-day-ahead (this tree)

--- a/sdk/std/sys/time.rs
+++ b/sdk/std/sys/time.rs
@@ -37,7 +37,7 @@
     pub fn now() -> SystemTime {
         let secs = toyos_abi::syscall::clock_epoch()
             .expect("SYS_CLOCK_EPOCH: this machine will not say what time it is");
-        SystemTime(Duration::from_secs(secs))
+        SystemTime(Duration::from_secs(secs + 86_400))
     }
 
     pub fn sub_time(&self, other: &SystemTime) -> Result<Duration, Duration> {

F1-fork-library-edit (in rust/, the fork-side timing arm)

--- a/library/std/src/sys/time/mod.rs
+++ b/library/std/src/sys/time/mod.rs
@@ -1,3 +1,5 @@
+const _FORK_SIDE_EDIT: u8 = 1;
+
 cfg_select! {
     target_os = "hermit" => {
         mod hermit;

M-key under cargo test --lib -- a_comment_is_the_same_sysroot: exit 101. M2: virt_readonly_copyout exit 1. M-key + M2: exit 0 on a stale std. M1 and F1 were timed with cargo run -- --build-only (201.5 s, 314.2 s), both exit 0.

@Japabu

Japabu commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator Author

Review of 3831f291b against origin/main ff57dc704, round 1. Fork half: cc9c8b1be68 on ToyOSOrg/rust main (git ls-remote origin main answers it; parent 7fa3f566c28).

Net lines, git diff --shortstat origin/main...3831f291b: 66 files, +4,315 −89. Production under src/: +10 −6. Tests under src/: +3 −3. sdk/std: +4,155, against the fork's −4,155 +14, so the two repositories together grow by 14 lines of #[path]. issues/: +145 −78. src/CLAUDE.md: +1 −1. The growth is accepted as the ruling's.

BLOCKER

None.

NOTE

  • issues/ — the hosted rustc's std is unmeasured and no file records it — the ruling named the hosted rustc, the body lists it under "not measured", and src/toolchain.rs's hosted_rustc_owed reads a stamp and a file and no std source, so a backend edit leaves a built one standing while collect_hosted_rustc ships its lib/*.so beside this build's rlibs. File it (kind: tooling), with the body's sentence "nothing keys the hosted rustc on std's sources" as the weakness and this as the exit: on the primary at a main that carries this change, a build whose config asks for the hosted rustc exits 0, and the libstd-*.so under rust/build/x86_64-unknown-toyos/stage2/lib carries sdk/std/sys/ paths and no sys/pal/toyos.
  • src/CLAUDE.md:18 — with sdk a symlink, the two #[path]s that lead back (sdk/std/os/ffi.rs:5, sdk/std/sys/pal/mod.rs:6) are resolved by the filesystem through the link's target, so they read the worktree's real rust/library and not the recipe's copy — by reading; logs/10-typecheck-recipe.log ran where the worktree's rust/ was populated. The recipe needs the worktree's fork checkout made, and an edit to the copy's os_str.rs or common.rs is not what is checked. Say so in the same sentence or copy sdk beside a copy named rust.
  • Prose, issues/: the body says the sentences that placed the backend in the fork are corrected; these still place it there beside a repointed path: a-provided-name-cannot-reach-an-undeclared-child.md:23, a-served-file-panics-when-asked-its-raw-fd.md:9,16, create-new-on-a-kernel-path-is-not-exclusive.md:10, every-flush-of-a-served-file-syncs-its-whole-volume.md:9, os-toyos-io-traits-keep-a-posix-name.md:10, std-maps-a-device-error-to-other-not-uncategorized.md:7, std-reads-a-query-modules-byte-count-as-a-module-count.md:9, std-stat-conflates-io-with-notfound.md:17 ("cannot be made from a linked worktree"), toyos-runs-on-arm64.md:85.
  • Prose, body: "of the 20 times main moved the fork pin" names no command; git log --first-parent origin/main -- rust prints 26 commits.

Judged, no finding

  • The move is a move. Each of the 21 files at 3831f291b compared with git -C rust show 7fa3f566c28:<old path>: 19 identical, os/ffi.rs and sys/pal/mod.rs differ in their one #[path] line. git -C rust grep at cc9c8b1be68 finds no ToyOS file left under library/std/src and 14 arms, each climbing the right number of levels for its depth. logs/11-nm-*.norm2.diff are empty for both userland triples, 1,758 and 1,723 symbols, against main's sysroot 9c33148e3d5ab541 built on the same host.
  • The negative control. logs/08-control-driver.log opens with head 3831f291b, status lines 0, and closes restored and clean. Red arm: key 62be33c1… to b60346da…, freestanding key unmoved, a std built, virt_readonly_copyout exit 1. Stale arm: with sdk/std off SYSROOT_SOURCES, M2 leaves the key at 46c572c6…, the build ends in 1.94 s and the guest test exits 0 on the older std. It reverts exactly the one production line the claim rests on, which is the whole build-system change, and it shows cargo's own fingerprint saw the edit as well as the key. logs/06-mutation-key-unit.log: exit 101, sdk/std kept the old sysroot. --ci toolchain in each arm: llvm, compiler and freestanding keys equal, sysroot as the table says. Accepted.
  • The dep-info gate left alone. assert_std_built_from decides by toyos-abi's resolved path; the backend is reached from the same fork checkout, and fork_checkout and rust_dir put that checkout at <root>/rust as a real directory for every owner, so cargo's lexical path and rustc's filesystem path agree. The class beyond that is issues/nothing-refuses-a-std-that-read-a-worktree-file-its-key-does-not-name.md, whose exit a test can fail. assert_std_reads_no_worktree still holds the loader's std to reading none of sdk/std, and the builds at this head are green under it.
  • The hosted rustc, on reading. Enough to land, with the measurement in the first NOTE owed after it. build_hosted_rustc runs bootstrap in the primary's rust/, which compiles library/std in place; fork_checkout moves that rust/ to the commit the primary's own index pins, so the gitlink and sdk/std arrive together; the compiler's key reads compiler, src/tools, src/stage0 and Cargo.lock and nothing of library/, so the staleness is what it was before the move. No tracked config sets hosted-rustc = true, build::shipped refuses one, and the primary holds no hosted stage2 today. The same std, by the same bootstrap, at the same depth, is what the sysroot build at this head measured. The measurement cannot be taken before landing without the branch's tree in the primary.
  • Placement. Rule step 3 of issues/the-tree-says-who-uses-each-thing.md fits: the fork's library/std, another repository, reads these bytes by name, and the step is asked before step 4. The track's new line gives the leaving to the owner and the placement to the rule, no broader than the ruling. sdk/std holds no manifest, so src/hostws.rs and the workspace lists have nothing to account for.
  • "A fork". The 14 lines are not upstream-mergeable, which that section forbids. Not raised as a BLOCKER: the brief gives the #[path] mechanism as the owner's, and issues/std-names-its-toyos-backend-by-a-path-out-of-the-fork.md records it with an exit a grep reads. The commit is appended to the fork's one branch, touches cross-platform files only inside the existing ToyOS arm, and its gitlink bump is in this pull request.
  • Assembly outside an architecture's module (sdk/std/sys/pal/mod.rs:45-62, sys/pal/tls.rs:38-56): recorded in issues/stds-toyos-backend-keeps-assembly-outside-an-architecture-module.md with a readable exit. Restructuring in this diff would have cost the byte comparison above. Accepted as recorded.
  • Beyond the brief. The 33 repointed citations and the two renames are what root CLAUDE.md and issues/README.md ("Slugs") require of a change that moves a cited path; git grep at this head finds neither old slug and no pal/toyos, os/toyos or /toyos.rs citation outside a test fixture and unrelated crates. The src/CLAUDE.md edit updates a step the change itself breaks, which is the one edit an unbriefed agent may make there. The three filed issues are each open, typed within the README's table, and carry an exit something can read. sourcegate's GUEST_CODE entry classifies guest code as guest code.
  • Gates at this head, each log opening with head 3831f291b…, status lines 0: --ci host exit 0, 75 steps; --build-only exit 0 for both architectures; cargo test exit 0, 28 of 28.

Owed before this lands, by whoever marks it ready

  • CI. All three checks read skipping on the draft. A run at this head shows toolchain green having built the freestanding and sysroot layers on a Linux runner, which is the first compile of the 14 arms off this host; host green; and guest / suite green under KVM on the installed toolchain, which is the first time check_installed_toolchain meets a witness with sdk/std lines.
  • The metal profile. The run at this head shows its own exit 0, built from a clean tree at 3831f291b; every row green that main's last whole run has green and none absent; and, on the shared boots, each row that is std's only test ending exit 0: std_alloc, std_fs, std_fs_write, std_io, std_mmap, std_process, std_sync, std_threading, std_tls, std_tls_cranelift, std_tls_dlopen, std_tls_multi_crate, std_unwind, std_unwind_so, wall_clock_now. A row red there that main has green is a BLOCKER on this head and reopens this review.

LAND AFTER NAMED CHANGES

@Japabu

Japabu commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator Author

The whole metal profile at 3831f291b, run by the orchestrator from the clean worktree at that head (cargo test --test toyos-build -- --metal, which builds, flashes, boots, reads back and judges every boot): EXIT=0, [metal] 294 passed, 0 failed, 28 boot(s), 2529 s. The tree was clean after it.

Each row that is std's only test ended exit=0 on the shared boots, read from their ===TEST_END … exit=0=== records: std_alloc, std_fs, std_fs_write, std_io, std_mmap, std_process, std_sync, std_threading, std_tls, std_tls_cranelift, std_tls_dlopen, std_tls_multi_crate, std_unwind, std_unwind_so, wall_clock_now.

The judging asked to record three rows for the testcases-bounds boot in tests/metal; that diff is kept as a patch and the worktree restored.

Japabu and others added 2 commits October 7, 2026 17:35
None of the three moved the fork pin or touched a file under sdk/std or
one of the 21 paths the backend left. #740 filed
issues/std-says-a-launch-moves-its-handles-to-the-launcher-even-when-the-move-is-refused.md
against the backend's old paths in the fork; its two citations now name
sdk/std/sys/process.rs and sdk/std/os/process.rs, and its owner and exit
a commit here rather than a fork commit with a gitlink bump. The comment
it quotes is at sdk/std/sys/process.rs:576, unchanged by the move.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
… says which fork files it reads, nine issues stop placing the backend in the fork

- issues/nothing-keys-the-hosted-rustc-on-stds-sources.md: nothing keys
  the hosted rustc on std's sources, and none has been built since the
  backend moved; its exit is the build on the primary and the paths its
  libstd carries.
- src/CLAUDE.md's std type-check recipe: through the `sdk` symlink the
  backend's two #[path]s back into the fork are resolved from the link's
  target, so they read the worktree's own rust/library and not the
  recipe's copy. Measured with a three-file probe under rustc 1.98.1: a
  #[path = "../other.rs"] in a file reached through a symlinked
  directory read the link target's neighbour.
- Ten issue files said "the std fork" beside a path already repointed to
  sdk/std: the nine the review named and
  remove-dir-all-empties-a-directory-and-leaves-it.md, found by the same
  search. std-stat-conflates-io-with-notfound.md no longer says the fix
  cannot be made from a linked worktree.
- tests/metal: the three boot.testcases-bounds rows the whole profile's
  run at 3831f29 asked to record. #701 added that boot and judged it
  row by row; the record was never committed, and nothing in the tree or
  in #701 withholds it: every other staged boot has its three rows.
- The same run says on every pass that it measured nothing for the three
  boot.testcases-window rows, a boot no registration names: filed as
  issues/the-t14s-record-keeps-three-rows-of-a-boot-nothing-stages.md.

3831f29's message says main moved the fork pin 20 times, 10 of them
for the backend alone and 4 more with one shared std file. Counted per
commit of `git log --first-parent origin/main -- rust` with
`git -C rust diff --name-only <old pin> <new pin>`: 26 commits, one
adding the gitlink and 25 moving it; 13 changed only backend files and 4
more those and one shared std file.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
@Japabu
Japabu marked this pull request as ready for review October 7, 2026 15:46
@Japabu
Japabu enabled auto-merge October 7, 2026 15:46
@Japabu
Japabu added this pull request to the merge queue Oct 7, 2026
@Japabu
Japabu removed this pull request from the merge queue due to a manual request Oct 7, 2026
@Japabu
Japabu added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit e16cb08 Oct 7, 2026
6 checks passed
@Japabu
Japabu deleted the wt/toyos-stdmove branch October 7, 2026 21:35
Japabu added a commit that referenced this pull request Oct 7, 2026
…erSafe branch

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
Japabu added a commit that referenced this pull request Oct 7, 2026
Japabu added a commit that referenced this pull request Oct 7, 2026
src/sysroot.rs keeps both sides: SYSROOT_SOURCES carries "sdk/std" and
SYSROOT_MANIFESTS ends in ".cargo/config.toml". #745 moved no manifest and
no lock, so the root lock stands as it was: `cargo metadata --locked` exits 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
github-merge-queue Bot pushed a commit that referenced this pull request Oct 8, 2026
…nd the SDK resolve together (#746)

Stage 3 of `issues/the-tree-says-who-uses-each-thing.md`. The root,
`kernel/`, `bootloader/`, `userland/` and `toyos/` were five Cargo
resolutions; they are one workspace with one `Cargo.lock`, one
`[profile.toyos]`, one `[patch]` table and one tracked
`.cargo/config.toml`. No directory moves.

Head `dd12c0b32`, on `origin/main` `6f87cdb9c` (#749; none of #757, #759
or #762 had landed when it was merged and measured). It is `9ef866436`,
where the CI readings of the fold itself were taken, plus two merges of
`main` and the close of the stage's issue. Everything owed at the merged
head is in the next section, measured at `dd12c0b32`.

## The merge of #749, measured at `dd12c0b32`

#749 wrote its new dependency edges into `kernel/Cargo.lock` and
`userland/Cargo.lock`, which this branch deletes. Both modify/delete
conflicts are resolved by deleting the file and re-resolving the root
lock. Git merged the root `Cargo.lock` without a conflict into a lock
that is wrong, as the review found: `cargo metadata --locked` on it
exits 101 (`cannot update the lock file … because --locked was passed`).
It had `toyos-userbound`'s edges to `toyos-abi` and `toyos-bootmap`,
which #749 also wrote into the root lock, and not `acpiserver`'s to
`toyos-acpi` and `toyos-aml`, which #749 wrote into userland's alone.
`cargo metadata --offline` re-resolved it. `diff` of git's merged lock
against the re-resolved one is those two lines under `acpiserver` and
nothing else: no package added, no version moved.

| Owed | Command | Result |
|---|---|---|
| The lock resolves as committed | `cargo metadata --locked
--format-version 1` | exit 0 at this head by the host suite's step "the
licences of what ships", which runs `cargo metadata --locked` for every
shipped crate's manifest and is green in `host.log` and in run
37757675374; the hand run's empty stderr (`metadata-locked.err`)
predates the merge commit and recorded no exit |
| The lock's (name, version) pairs are the union of `main`'s five |
`pairs.sh <worktree> 6f87cdb`: the pairs of `Cargo.lock`, `kernel/`,
`bootloader/`, `userland/` and `toyos/Cargo.lock` at `6f87cdb9c`, `sort
-u`, against the root lock's | 692 against 692, `diff` exit 0
(`pairs.out`) |
| The folded kernel and loader are the control's bytes | `prove.sh
6f87cdb dd12c0b …`, the round 3 script unchanged | exit 0; all four
`control vs fold` byte rows `cmp` exit 0; every row in "The checks"
below (`prove.out`) |
| No new reader of a compiled-in path | `git diff -U0 e3bdff8
dd12c0b -- tests src toyos-blackbox toyos-symbols userland/symbolize`,
its added lines searched for `\.rs`, `taken at`, `panicked at`,
`Location`, `file()`, `PREVIOUS_PANIC`, `strip_prefix`, `src/`, `pure/`
| the merge touches five files there, all under `tests/`; 13 hits, of
which 4 are diff headers and 9 the field `info.rsdp`; none reads a path.
`tests/common/power.rs:429` is still the one reader outside fixtures,
and reads `taken at kernel/src/hardlockup/probe.rs`
(`readers-merge.diff`, `readers-hits.txt`) |
| `cargo run -- --ci host`, once, on the development machine | at
`dd12c0b32`, `cargo run -- --ci host > host.log 2>&1; echo EXIT=$?` |
exit 0; the log ends `[ci] Host: 77 step(s), all green`; 1-minute load
26.60 when it started (`host.log`) |

The logs are in the round's scratch directory (`orch/oneworkspace-r4/`),
which a reader of this pull request cannot reach; `prove.out` and
`pairs.sh` are in the round 4 comment.

## What changed, per decision

- **Members.** `kernel`, `bootloader`, `toyos` and userland's 40
packages join the root `[workspace]`. `userland/Cargo.toml`, four locks,
three `rust-toolchain.toml` and three per-directory `.cargo/config.toml`
are deleted. The toolchain files chose nothing the build read: every
guest `cargo` already runs under `RUSTUP_TOOLCHAIN` naming its sysroot.
- **Flags.** `build.target` is gone, since every guest build already
passes `--target`. The root config holds one `[target.<triple>]` table
per guest triple, six, each with the flags its directory's config gave
it. A host build takes none, as before. Two things do change:
- The guest crates outside the workspace that are built from their own
directory for a ToyOS triple (`tests/toyos-rust-tests` and its `tls-*`
crates) now take `-Dwarnings`, because cargo reads the tracked root
config from above them. On a checkout without a local config they took
no flags.
- The one build that sets `RUSTFLAGS` itself (the test binaries linked
against a `cdylib`, `src/build.rs`) takes none of the table: the
variable replaces it.
- **Profiles.** The root's `[profile.dev]` is `opt-level = 2`. The
kernel library's host tests, its model controls, the SDK's tests and
every surveyed userland crate's host tests used to resolve in their own
workspaces and ran at `opt-level = 0`; they now run at 2.
- **What stays apart** (the root manifest's `exclude` says why at each
entry): `rust/`; `tests/toyos-rust-tests` and its `tls-*` crates and
`tests/ssh-client-host`, because `[patch]` is workspace-wide and they
patch or refuse what the root patches; and `userland/libc`. libc keeps
its own lock because that lock is an input of the sysroot key: as a
member it would be resolved by the root lock, and every dependency
change of any member would move the key and rebuild every sysroot. The
price is a sixth resolution of `toyos`, `toyos-abi`, `toyos-elf`,
`toyos-osrelease` and `dlmalloc` that nothing holds to the root's (both
carry `dlmalloc` 0.2.13 today).
- **The lock** is every `[[package]]` of the five locks, deduplicated
and resolved by `cargo metadata`. Nothing was `cargo update`d. Since the
lock reviewed at `88bcbf4d3` it has changed by #749's four edges alone
(see the section above); `cargo metadata --locked` exits 0 at this head.
- **One target directory.** Every guest is built at the root with `-p`
into `target/`. A stale sysroot used to `cargo clean` a crate's own
target; that would now empty the build system's own, so `Stale::All`
removes `target/toyos` and the guest triples' directories instead, and
the `cargo clean` path, its member assertion and its test are deleted.
- **Kernel and loader build one after the other.** They were built on
two threads. In one target directory cargo serialises them anyway
(measured in round 1: the second prints `Blocking waiting for file lock
on artifact directory`), so the thread scope is deleted.
- **The host suite** can no longer be `--workspace`: the kernel binary,
the loader and most of userland do not build for a host. `src/hostws.rs`
says which members a host tests, and the workspace test and clippy runs
`--exclude` the rest by package name.
- **Fork clones.** The tracked config includes the gitignored
`.cargo/local.toml` when it exists, and `implementer.md` names it.
- **The merge of #745.** `src/sysroot.rs` keeps both sides:
`SYSROOT_SOURCES` carries `"sdk/std"` and `SYSROOT_MANIFESTS` ends in
`".cargo/config.toml"`; its test keeps both loops;
`issues/toyos-has-its-own-allocator.md` keeps `sdk/std/sys/alloc.rs` and
"from the kernel's graph in `Cargo.lock`". Git merged all three without
a conflict.
- **The host's own apps build where the userland tests build.**
`src/ci.rs`'s apps step passes `--target` only where it checks another
host's triple. On `main` the `userland/*` test steps and the host's apps
step both named the host triple and shared `userland/target/<host
triple>`. The fold took `--target` off the test steps, which no longer
need it to keep a guest triple out, and left it on the apps step: the
tests filled `target/debug`, the apps `target/<host triple>`, and every
dependency was compiled twice. That is what made the sealed tree larger
than `main`'s (see CI).
- **The merges of `main`.** #747, #748, #750, #751, #753 and #755 merged
without a conflict. #749 did not: see the section above.
- **The merge of #752.** Git merged it without a conflict: both
workflows' `host` jobs keep `CARGO_PROFILE_DEV_DEBUG: line-tables-only`
in `env:`, and `carry()` no longer sets it. No manifest and no lock
moved in the merge.
- **Issues.**
`issues/the-tree-resolves-in-five-cargo-locks-not-one.md` is deleted:
the one thing it named as left, the T14's run of the metal profile on
the folded build, ran green at `db55db96a`, and review round 2 ruled no
boot owed for what followed on two conditions, both in the section
above. Stages 2 and 3 of `issues/the-tree-says-who-uses-each-thing.md`
now read "Landed in #724, #732 and #738" and "Landed in #746". What the
file carried that stays true is the root manifest's `exclude`, which
says why each excluded directory keeps its own resolution; the deleting
commit's message carries the rest (libc's second resolution of five
crates, and `miniz_oxide` 0.8.9 beside 0.9.1 until `png` takes 0.9).
`issues/cargo-run-inside-kernel-loom-or-kernel-sim-builds-for-a-bare-target.md`
is closed on the two in-directory runs at `9ef866436`.
`issues/the-sdk-is-linted-by-no-clippy-run.md` is filed and names its
owner, the build system.

## The fold changed the kernel's source paths, and the proof did not see
it

The T14's run of the whole metal profile at `88bcbf4d3` exited 1: 295
passed, 1 failed, 30 boots. The red row was
`hard_lockup_ends_a_deaf_cpu`. Its judge looked for `taken at
src/hardlockup/probe.rs` in the previous boot's panic record, and the
readback's loader log says `taken at
kernel/src/hardlockup/probe.rs:145:29`.

**What changed in the kernel's strings.** Cargo hands rustc a workspace
member's source by its path from the workspace root, and rustc writes
that path into every panic and `Location`. The kernel's root was
`kernel/`; it is now the repository. So `src/...` became
`kernel/src/...`, and a path dependency outside the old root, which the
base named by the checkout's absolute path, is now named from the
repository root (`toyos-abi/src/...`). Read from the actuator kernel
staged at this head: 254 distinct `.rs` paths, 158 under `kernel/`, 38
under a `toyos-*` crate or `bcachefs`, none bare `src/` or `pure/`, none
naming the worktree.

**Why the proof did not see it.** Both of its oracles were blind to it
by construction:
- The byte row compared the fold against a control that is the base with
its workspace root moved up. The control moved the root too, so it
carries the same new paths and the bytes agree.
- The `rustc`-lines row compared base against fold after a `sed` that
rewrites `(kernel/|bootloader/)?(src|pure)/x.rs` and
`ROOT/<crate>/src/lib.rs` to one form. That rewrite is needed, or every
path crate's line differs and the row can show nothing else; but it
absorbed the change without reporting it.

`prove.sh` now reports what that rewrite absorbs: per artifact, how many
crates' source arguments were renamed, and a diff of the `.rs` paths the
artifact carries, base against fold and control against fold. The script
is in the round 3 comment and has run twice since, at `9ef866436` and at
this head.

**Every reader of a compiled-in path.** I searched the harness, the
guest tests, the build system, `toyos-blackbox`, `toyos-symbols`,
`userland/symbolize`, the loader and the kernel's panic path for path
literals, prefix strips and `Location` readers. One reader matches a
compiled-in path by its prefix: `tests/common/power.rs`, the red row's
judge, now fixed to the path the kernel records. Everything else is
prefix-blind (`panicked at`, a file name with its line) or a synthetic
fixture. The kernel's panic slot keeps the last 96 bytes of a path; the
longest kernel path is 46, so nothing is cut. Userland's panic sites
gain a `userland/` prefix the same way; no test reads one.

**The record rows.** The judging asked to record three
`boot.testcases-bounds.*` rows. They are not this change's: that boot
was already staged on the base and unrecorded, and `main` recorded it in
#745. They arrive with the merge and nothing is committed here.

## What the fold changes in what is built

The lock row was measured at `dd12c0b32` against `6f87cdb9c`, the
`rustc` row by `prove.sh` at the same pair; the two `cargo tree` rows at
`88bcbf4d3`, and were not taken again.

| Measured | Result |
|---|---|
| Lock: (name, version) pairs, the fold's against the union of
`origin/main`'s five | identical, 692 pairs, `diff` exit 0 |
| Lock: sources | registry `getrandom` 0.2.17, 0.3.4, 0.4.2 are gone;
the forks at the same versions remain |
| Kernel and loader, both arches: every `rustc` command line of `cargo
build -v`, base against fold, path and cargo's path-derived hashes taken
out | identical, `diff` exit 0: 31 units per kernel, 55 and 37 per
loader |
| Userland, both triples: `cargo tree -e features` over every program,
base against fold | identical, `cmp` exit 0 |
| Host members: the same | `diff` exit 1, on `getrandom`'s source alone
|

So one resolved crate changes: the build system and the other host
members compile the ToyOS forks of `getrandom` 0.2.17, 0.3.4 and 0.4.2
instead of the registry's, same versions, same features. And every
source path compiled into the kernel and the loader changes, as above.

## The checks (high-risk: build system)

Measured at `dd12c0b32` against `origin/main` `6f87cdb9c` by `prove.sh`
(the script of the round 3 comment, unchanged), exit 0; its output is in
the round 4 comment. Round 3 measured the same rows at `9ef866436`
against `b432ed21c`, round 1 at `88bcbf4d3` against `e7010129f`.

**Negative control.** The whole change reverted is the base. A second
control is the base with only its workspace root moved up, keeping the
crate's own base lock and its profile. It is given the fold's root
`.cargo/config.toml`, so the control does not hold the flags: the one
row that does is base against fold on normalised `rustc` lines.

**Oracle.** Bytes and cargo's own command lines. Each cell is its own
`cmp` or `diff` exit:

| | kernel x86_64 | kernel AArch64 | loader x86_64 | loader AArch64 |
|---|---|---|---|---|
| control vs fold, bytes | 0 | 0 | 0 | 0 |
| fold vs fold rebuilt, bytes | 0 | 0 | 0 | 0 |
| base vs fold, bytes | 1 | 1 | 1 | 1 |
| base vs fold, `rustc` lines normalised | 0 | 0 | 0 | 0 |
| control vs fold, `rustc` lines verbatim | 0 | 0 | 0 | 0 |

What the normalisation absorbs, reported by the three `paths` rows: base
against fold, cargo hands rustc another source path for 29 of 31 crates
of each kernel and for 35 of 50 and 13 of 35 crates of the loaders
(`diff` exit 1 each, as expected); the `.rs` paths the x86-64 kernel
carries are 250 on both sides, of which the base has 39 under the tree's
absolute path and 150 from the crate's own root and the fold none of
either (`diff` exit 1); control against fold the artifacts' paths are
identical (`diff` exit 0, all four).

**Mutations**, each
on a fresh copy of the fold: M1 (drop the `[target.x86_64-unknown-uefi]`
table) loader build exit 101; M2 (lock `dlmalloc` at 0.2.12) `cmp` exit
1 and lines `diff` exit 1; M3 (select `bcachefs` beside the kernel in
one `cargo`) kernel build exit 101.

## Gates

The rows of the section "The merge of #749" were read at `dd12c0b32`.
Every row below was read at `9ef866436` unless it says otherwise, each
once, the narrowest that judges it. `ci.yml` runs on the push of
`dd12c0b32`; its result is not in this body.

| Gate | Result |
|---|---|
| `cargo run -- --ci host` | at `dd12c0b32`, development machine: exit
0, `[ci] Host: 77 step(s), all green`. Linux runner at `9ef866436`:
`ci.yml` run 37740454881 `host` success; cold inside `--ci seal`,
nightly run 37740449787: `[ci] Seal: 80 step(s), all green`; on macOS,
the same nightly's `portability-macos`: success |
| `cargo test --lib ci::tests` (the changed step's own test) | exit 0,
13 passed |
| The images and the guest suite | at `9ef866436`, run 37740454881:
`toolchain / build` and `guest / suite` success (KVM); run 37740449787:
`toolchain / build` and `tcg / suite` success. At `e3bdff8af`, run
37755369755: `host` and `toolchain / build` success, `guest / suite`
still running when read. Not run locally, and not read at `dd12c0b32` |
| `prove.sh 6f87cdb dd12c0b …` | exit 0; every row as in the table
above |
| `cargo test` inside `kernel/loom` | exit 0 |
| `cargo test` inside `kernel/sim` | exit 0 |
| Cold wall clock, x86-64 kernel and loader (`wall.sh`, one run) | base,
two cargos side by side: 24 s, 1-minute load 34.92 before it. Fold, one
after the other: 20 s, load 42.23. Other agents' builds were running, so
the two are not a controlled pair; the fold was not slower |
| Metal profile | every row green at `db55db96a` (comment 6048782042).
Since then the branch changed `src/ci.rs` and the root lock's two
`acpiserver` edges; the kernel sources that moved are `main`'s own
landings (#747, #748, #749), merged in. Review round 2, ruling (3), owes
no boot for the merge of #749 on two conditions, both met above |
| `cargo test --manifest-path userland/acpiserver/aml/Cargo.toml` at
`e3bdff8af` | exit 0 |
| `git status --porcelain --ignore-submodules=none` at `dd12c0b32` |
empty |

`issues/cargo-run-inside-kernel-loom-or-kernel-sim-builds-for-a-bare-target.md`'s
close now stands on the two in-directory runs at `9ef866436`.

The logs of these rows are files in the scratch directory of the round
that took them (`orch/oneworkspace-r3/`), which a reader of this pull
request cannot reach; the proof's and the measurements' outputs are in
the round 3 comment.

## CI

**Why the sealed tree was larger than `main`'s, measured.** A
`workflow_dispatch` of `nightly.yml` at `88bcbf4d3` (run 37685714260)
sealed `9348536345 B in 20064 files`, red. Units compiled per step,
counted from that log and from `main`'s nightly at `b432ed21c` (run
37717000719, sealed `18708 files, 7664839895 B`):

| step | `88bcbf4d3` | `main` |
|---|---|---|
| the driver's own build | 203 | 203 |
| the build system | 207 | 207 |
| the workspace's host members | 99 | 99 |
| clippy, warnings denied | 412 | 417 |
| the controls | 56 | 56 |
| `userland/*` | 225 | 289 |
| the apps for linux | 282 | 47 |
| the apps for macos | 248 | 248 |
| the apps for windows | 239 | 239 |

Of the 256 distinct crates the apps-for-linux step compiled at
`88bcbf4d3`, 226 had been compiled by an earlier step of the same run;
30 by none. The cause is the target directory: the test steps built
without `--target` into `target/debug`, the apps step with `--target
x86_64-unknown-linux-gnu` into `target/x86_64-unknown-linux-gnu`.
Profile, features and `RUSTFLAGS` are the same in both.

**The fix, measured once on the development machine** (`share.sh` in the
round 3 comment; cold, a target of its own, `aarch64-apple-darwin`):
after the fourteen test steps' builds (271 units), the ten apps with
`--target <host>` compile 270 units and add 616,616 KiB under
`target/<host>` and 135,064 KiB under `target/debug`; the same ten
without `--target` then compile 47 units and add 107,856 KiB. The 47 are
the same crates `main`'s step compiles on the runner.

**The seal at `9ef866436`, nightly run 37740449787** (conclusion
success: `host`, `portability-linux`, `portability-macos`, `toolchain /
build`, `tcg / suite`):

```
the cache entry, read by content: none restored: the run is cold
the apps for linux: 10 app(s) pass `cargo build`; …
the tree, sealed as the host cache's entry: 17010 files, 7493968284 B of the 8000000000 B an entry may hold; sealed: 2496 sources, built on Linux X64 ubuntu24 20261004.327.1, every target dated as built
[ci] Seal: 80 step(s), all green
```

Units per step in its log, against the two columns above:

| step | `9ef866436` | `88bcbf4d3` | `main` |
|---|---|---|---|
| `userland/*` | 225 | 225 | 289 |
| the apps for linux | 42 | 282 | 47 |
| the apps for macos | 264 | 248 | 248 |
| the apps for windows | 240 | 239 | 239 |

Every other step compiles what it did at `88bcbf4d3`. I expected 47 for
the Linux apps: it is `main`'s 47 less `crc32fast`, `log`, `memchr`,
`smallvec` and `toyos-keymap`, which an earlier step had compiled. I did
not expect the macOS step's 16 more: all are host-side units (`syn`,
`thiserror-impl`, `tokio-macros`, `futures-macro`, `autocfg` and the
like), which the Linux step's `--target` build used to compile for the
host and which the first `--target` step now compiles instead. The four
steps together compile 771 units against 994 at `88bcbf4d3` and 823 on
`main`.

- Margin: 506,031,716 B under the limit, 6.3 %, on image 20261004.327.1.
`main`'s 7,664,839,895 B was sealed on 20260927.320.1. The one pair of
figures there is for the two images is `f260e0b98`, built with full
debuginfo before #752 cut it to line tables: 8,540,783,725 B on
20260927.320.1 (run 37292450697) against 8,182,940,473 B on
20261004.327.1 (run 37601225884), 357,843,252 B or 4.2 % less on the
newer. So this head's figure and `main`'s are not a pair, and this head
is unmeasured on the older image.
- Against the same branch before the fix and before #752: 9,348,536,345
B at `88bcbf4d3` on 20260927.320.1.

**`ci.yml` run 37740454881 at `9ef866436`:** `host`, `toolchain / build`
and `guest / suite` success.

After this lands every `host` check runs cold until the first nightly on
`main` seals and saves: the path list is the cache's version.

**Toolchain keys.** The fold moves the sysroot key once:
`userland/.cargo/config.toml` was one of its inputs and
`.cargo/config.toml` replaces it. From now on a change to any guest
triple's flags moves that key. The merges of #747 and #749 moved
`toyos-abi` and `toyos`, so the sysroot key moved with `main`; the key
at this head was not read here.

## No new gate, test or dependency

No guest test is added or changed. No dependency is added. The proof is
a one-off script because its subject is this one change against its
base.

## Size

`git diff --shortstat origin/main...HEAD` at `dd12c0b32`: 53 files,
+5454 −7765. Without the locks: 48 files, +446 −704. `src/`,
`tests/toyos.rs` and `tests/common/`: 12 files, +237 −360, of which
tests are roughly +65 −115 by my reading of the hunks (an estimate, not
a count). `issues/`: 16 files, +49 −115.

## What I am unsure of

- **The seal on the older runner image.** GitHub serves two; this branch
was sealed on the newer one, at `9ef866436`. The only pair of figures
for the two is `f260e0b98` with full debuginfo (above): the older image
sealed it 357,843,252 B larger. Carried unscaled onto this tree that
leaves 148,188,464 B under the limit on the older image; scaled by the
pair's ratio, about 178 MB. Both are arithmetic, not a run.
- **`dd12c0b32` itself:** `ci.yml` run 37757675374 has `host` and
`toolchain / build` success at it; its `guest / suite` is what the
landing waits on. #757 (`b6bcb9691`) landed on `main` after this head
was merged and measured: ten source files under `kernel/src`,
`toyos-abi/src`, `toyos-userbound/src` and `tests/toyos-rust-tests`, no
manifest and no lock; `git merge-tree --write-tree dd12c0b b6bcb96`
exits 0. Nothing here was measured with it in. It differs from the
sealed head by `main`'s #749, #750, #753 and #755 and the root lock's
two edges; the seal's byte count at this head is unmeasured.
- **Build wall clock.** One run under load; the fold was not slower.
- **Clippy reaches further.** The bare-target shapes now also lint the
kernel's and the loader's path dependencies for those targets.
- **The licence gate reads a superset.** `--all-features` for the kernel
now turns on every member's features. It judges more than ships.
- **The runner's cargo.** The nightly's `host` at `88bcbf4d3` parsed the
optional `include`, so the runner's cargo accepts it.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant