Skip to content

The T14 rows that need the host to reach the machine under ToyOS are deleted, with the swap chain and the machine's end of the stream: 27 boots to 26 - #773

Merged
Japabu merged 3 commits into
mainfrom
wt/toyos-lanrows
Oct 8, 2026
Merged

Japabu merged 3 commits into
mainfrom
wt/toyos-lanrows

Conversation

@Japabu

@Japabu Japabu commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

The development host reaches the T14 only while it runs Ubuntu: under ToyOS no connection it opens to the machine arrives. The owner: "we should disable or remove those tests." The tree has no disabled tests, so they are deleted, with the code only they used, on the host and on the machine.

What changed, per decision

The rows. lan_talk, lan_dhcp_lease and lan_message_delivery rode one boot, lantalkcase, which toyos-metal refused whole when the host's stream never opened, so all three were red on main (the stream never opened, at 6f87cdb9c and c84f5fafe). Deleted with them: tests/lantalkcase, the job lan_talk_hold, the harness's talking boots (Arm::talk, Arm::nic, the minted key, Readback::talk, the wire MAC), the judges and their fixture, toyos-metal's --talk and --nic with Refusal::Talk and Refusal::Wire, the ping (src/icmp.rs), and the boot's three rows in tests/metal/lenovo-20w0003amz.toml.

lan_message_delivery goes too, though it read only the stick. The card's first message came 8.499 s into the last boot read, with its link, so a boot that does not talk has to be held open for it. The one hold in the tree is lan_hold's flat sleep, which issues/lan-hold-holds-a-boot-open-for-a-flat-twenty-seconds.md already records; a job that waits on the message is new machinery.

The host's swap chain. The owner: "Delete the whole chain". Deleted: toyos-metal --swap and --binary, Refusal::Swap and Refusal::Cable, src/metalswap.rs, src/metaltalk.rs, src/lan.rs, tests/ssh-client-host and its workspace exclude entry, build_host_judges, ssh_client_host and copy_guest_program in src/build.rs, and toyos-swap's heard, outcome and Word::is_final, which only the host called. Two fixtures that spelled a deleted name spell a living one (src/cicache.rs, src/ci.rs).

The machine's end of the stream (second commit, answering the review). The owner: "If someone is blocking and its not needed then delete it ... We allow no slop". tests/lantalkcase was the only config whose logkeeper row received netstack, so its network half had no image to run in. Deleted: serve_network, bind_port, Carrier, Hub::carrier, the network readers' count and the stream word of logkeeper's inspect snapshot; toyos_logstream::PORT, CARRIER, CARRIER_LEAVING and the SWAP frames, with the supervisor's send of them; and no_shipped_image_serves_the_log_on_the_network, which then guarded nothing. A reader on the machine is served as before, under one count.

sshserver's image key file. /system/etc/ssh_authorized_keys was written only by a talking boot's staging. sshserver reads authorized_keys under its state directory and nothing else.

The swap's machine half stays. /system/bin/swap and the supervisor's swap path are reachable on a shipped machine: system.toml makes the desktop a login session ([programs.compositor] login = true) whose shell lists swap in starts, and gives a login over sshserver the same. Nothing on a host asks for one any more and no test performs one: launch_authority reads the rows that refuse to start it. The issue says so.

No outbound rows are added. The owner ruled that rows judged from the stick alone, the T14 reaching its router and the internet, are built on ToyOS's own network stack ("no smoltcp."); issues/toyos-has-its-own-network-stack.md now owns them in one line.

The record

809c33c0c restores everything named above. issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md says so, and carries:

  • the present-state weakness: no T14 row reads netstack on the I219, none reads a message the card raised, and no test performs a swap;
  • what the restored chain still owes, folded from nine issues about the deleted code and closed with it;
  • the exit: a connection the host opens to the T14 under ToyOS is answered, read as lan_talk restored and green.

Also closed: the cable refusal that hid the stick-only row, lan_talk unread since #763 (folded), lan_talk_host_closes' fixed window (29b4c651a deleted that test) and the unattributed swap_refused_device_fails red (test and client both gone). Every issue and track that cited a deleted row, boot, file or function is corrected; the ones that cited the ssh client, the swap or the served log as built now say it was built, is deleted, and where it comes back.

The review of round 1, finding by finding

  • BLOCKER, no --ci host and no guest suite at the head. Not closed by this branch's own runs: CI's host, toolchain / build and guest / suite on the pushed head are what close it. What was run locally is below.
  • BLOCKER, logkeeper's network half reached by no image. Deleted, with the supervisor's SWAP frames, the three toyos_logstream constants and the build gate.
  • BLOCKER, /system/etc/ssh_authorized_keys has no writer. The reader is deleted.
  • NOTE, the swap missing from "What stands in the meantime". Added, with why its machine half stays.
  • NOTE, the outbound rows owned by no file. issues/toyos-has-its-own-network-stack.md owns them.
  • NOTE, the usb-stick track's bullet. Past tense, with the deletion.
  • NOTE, the session track does not say it is blocked. It does now.
  • Round 2's NOTEs. "What stands in the meantime" now says the 6 s of refused connects after a swap is unread for sshserver's port, and that no test reaches the file that authorizes a login; the metalcase sentence below is corrected.
  • NOTE, toyos-swap does not link into sshserver. Right: it links into supervisor and swap. The sentence is gone from this body, and the root manifest's comment that said the same is corrected.

Gates, at 25766b613

The head is one commit past it, which changes issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md and nothing a build reads.

Run by the orchestrator from the branch's request (orch/builds/lanrows-r3.log), each by its own exit code:

step exit
cargo test --test toyos-build -- --metal --list on 809c33c0c 0
cargo metadata --locked --format-version 1 0
cargo test --test toyos-checks (36 tests) 0
cargo test --locked --lib -- metal build:: cicache:: ci:: (running 127 tests: 125 passed, 2 ignored) 0
cargo test --locked -p toyos-swap (5 tests) 0
cargo test --locked -p toyos-logstream (19 tests) 0
cargo test --locked --manifest-path userland/logkeeper/Cargo.toml (10 tests) 0
cargo test --locked --manifest-path userland/sshserver/Cargo.toml (29 tests) 0
cargo run -- --build-only 0
cargo test --test toyos-build -- machine_shutdown console_image_boots netstack_socket_churn (4 passed, 4 total) 0
cargo test --test toyos-build -- --metal --list on the branch 0

As the harness prints them:

before: [metal] 67 registration(s) and 229 shared member(s) over 27 boot(s)
after:  [metal] 64 registration(s) and 229 shared member(s) over 26 boot(s)

The guest filters, and why: machine_shutdown and machine_shutdown_short_stop boot through the supervisor's stop, where logkeeper answers its flush on the connection that lost the swap frames; console_image_boots boots the console, the one reader of the log on the machine, through logkeeper's log port; netstack_socket_churn boots netstack beside a logkeeper that no longer asks for it. No guest boots sshserver: only tests/metalcase starts it.

The T14, at 25766b613 (orch/builds/t14-lanrows.log), run by the orchestrator: testcases (image sha256 83c90d38d01f5c5d588ab54ef213de79a0132ea9d3f02f63b167c17885f8a8a6) rc 0 and testcases-watchdog (7b6d51e4f9fa2bf0275d232c900c2f60fe66de0a3488bc9cbc9fa3361e14d7ce) rc 0; the judge exit 0, 21 passed and 0 failed over 2 boots. The log reached the stick (kernel.log 16,960,405 bytes) and the supervisor stopped the machine.

boot:metalcase on the T14, at 25766b613, booted by the orchestrator to read sshserver's key-file change on metal (his two comments on this pull request): toyos-metal exit 0, and it does not show the change. sshserver says starting..., then no network on this machine, exiting, with code=0, so it leaves before it reads any key file. The boot is not judged. No test at any tier reaches the changed reader: sshserver's 29 host tests call authorizes(text, key) and none calls is_authorized, authorized_key_count or authorized_keys(), and no guest starts the daemon. It is carried by the diff alone, and the issue says so.

Not run here: cargo run -- --ci host and the whole guest suite; CI's host, toolchain / build and guest / suite on the pushed head are what close the review's open blocker.

For the reviewer to weigh

  • logkeeper, the supervisor and sshserver change in every image. What changed in each is deletion: no instruction a boot without a netstack row for logkeeper ran is different, and the T14 boot above read the log path and the stop.
  • No guest test is cut. The three rows are metal rows, deleted as root CLAUDE.md deletes a red test, with the issue recording the commit that restores them.
  • Net: 67 files, +329 −7589. Shipped programs and their crates (userland/, toyos-logstream/, toyos-swap/) +66 −412; issues/ +209 −451.

🤖 Generated with Claude Code

https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A

…deleted, and the host's swap chain with them

The development host reaches the T14 only while it runs Ubuntu, so the boot
the host talked to was refused whole on every run: `the stream never opened`,
at `6f87cdb9c` and at `c84f5fafe`. Its three rows were red with it, and a red
test is fixed or deleted.

Deleted: `lan_talk`, `lan_dhcp_lease` and `lan_message_delivery`; the boot
`lantalkcase`, its config and its hold job; the harness's talking boots
(`Arm::talk`, `Arm::nic`, the minted key, `Readback::talk`, the wire MAC);
`toyos-metal`'s `--talk` and `--nic`, with the host's reader of a served log,
its conversation, its ping and the lease, link and message readers.

`lan_message_delivery` read only the stick, and goes too: the card's first
message came 8.499 s into the last boot read, so a boot that does not talk
has to be held open for it, and the one hold in the tree is the flat sleep
its own issue records.

The owner ruled on the swap of a running service from the host: "Delete the
whole chain". So `toyos-metal --swap`, `src/metalswap.rs`, the rest of
`src/metaltalk.rs`, `tests/ssh-client-host` and the build's host-judge step
go, with `toyos-swap`'s readers of the supervisor's words, which only the
host called. `/system/bin/swap`, the supervisor and sshserver are untouched.
Two fixtures that spelled a deleted name now spell a living one.

`809c33c0c` restores all of it, and
`issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md` says so, with
what the restored chain still owes: the six issues about that code are folded
into it and closed, since their subject is gone and comes back only with it.
Also closed: the cable refusal that hid the stick-only row, `lan_talk` unread
since #763 (what it left unread is in the new issue), `lan_talk_host_closes`'
fixed window (`29b4c651a` deleted that test) and the unattributed
`swap_refused_device_fails` red, whose test and client are both gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
@Japabu
Japabu marked this pull request as ready for review October 8, 2026 17:46
@Japabu

Japabu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

Review of wt/toyos-lanrows at d7964d26b against origin/main 809c33c0c, round 1.

Net lines (git diff --shortstat origin/main...d7964d26b): 55 files, +233 −7143. Build system and crates (src/, toyos-swap/, Cargo.toml) +45 −3560; tests +16 −3220; issues/ +172 −363. No userland or kernel source is touched.

BLOCKER

  • PR body, "Not run" — cargo run -- --ci host and the guest suite have no measurement at this head — the body says so itself, and the local lib run was filtered (running 128 tests, 236 filtered out), so nothing has yet run the gates over a tree without tests/ssh-client-host in exclude, nor a guest on the rebuilt supervisor. Run 37819168028 measures d7964d26b and was still in progress when read. It closes with no change to the branch when all three hold and the body carries them:
    • host: conclusion success on head d7964d26b2a530cfbbff78e98db4b03680267078, and in its log the step cargo run -- --ci host ending exit 0, read from the step, not from a test result line.
    • toolchain / build: success on the same head (it read success, 3m15s).
    • guest / suite: success and not skipped on the same head, its closing line naming 0 failed. Every guest boots the supervisor this branch rebuilds.
  • userland/logkeeper/src/serve.rs:94-121,160-249 — the network half of logkeeper is reached by no image at this head, and is neither removed nor recorded — tests/lantalkcase/system.toml was the only config in the tree whose [programs.logkeeper] had a receives; at d7964d26b none has, so serve_network, bind_port, Carrier, Hub::carrier, the network reader count and toyos_logstream::PORT, CARRIER, CARRIER_LEAVING have no caller that can run. With it: the supervisor's SWAP frames (userland/supervisor/src/main.rs:2353-2362, userland/logkeeper/src/main.rs:337-341, toyos-logstream/src/lib.rs:102-107), which exist only to close that listener, and no_shipped_image_serves_the_log_on_the_network (src/build.rs:2946-2963), which now excuses tests/ configs for something none of them does. This is the machine's end of the stream src/metaltalk.rs read, so it is the deleted chain's other half. Two legal outcomes: delete it in this branch (809c33c0c restores it with the rest), or record it in issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md as shipped and unreachable, with its exit. Deleting it changes logkeeper in every image, and then the guest suite and a T14 boot whose log reaches the stick are owed; recording it owes neither.
  • userland/sshserver/src/main.rs:41-51 — the image's /system/etc/ssh_authorized_keys has no writer left — tests/common/ssh.rs's KEYS_ON_ROOT was the one thing in the tree that staged it, and it is deleted; git grep ssh_authorized_keys d7964d26b finds the reader alone. sshserver's second key file is now a path nothing can fill. Same two outcomes, in the same place.

NOTE

  • issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md:58-71 — "What stands in the meantime" omits the swap — at this head no test performs a swap and nothing outside the machine can ask for one; /system/bin/swap and the supervisor's swap path ship read by launch_authority's refusal rows alone. issues/a-childs-end-is-an-event-and-a-parent-takes-its-children-down.md:47 says it for one stage; the issue that deleted the last client says only that they "ship as before".
  • issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md:68-71 — the outbound rows are handed to issues/toyos-has-its-own-network-stack.md, which does not name them — no stage or exit of that track mentions a T14 row, a router or the internet, so the one thing that ends "no T14 row reads the wired card" other than the host reaching the machine is owed by no file that says so. One line in the track, or the exit here naming it.
  • issues/the-t14-answers-only-through-a-usb-stick.md:47-51 — "The machine serves its own log, and the Mac finds it by name" is false of this tree — no image gives logkeeper a netstack connector and nothing on the host asks. The file was corrected by this branch four lines above and this bullet was left.
  • issues/the-t14-reboots-through-ubuntu-for-every-test.md:44-60 — the track's next stage is the host driving a booted T14 over ssh, and it does not say it is blocked on issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md — it cites that file only for the deleted client and config.
  • PR body, "For the reviewer to weigh" — toyos-swap does not link into sshserver — userland/sshserver/Cargo.toml has no such dependency, Cargo.lock names it under supervisor and swap only, and build-only.log recompiles toyos-swap, swap and supervisor. Prose; the conclusion stands, since the supervisor is in every image.

Asked by the brief, no finding

  • Removed names: none of the functions, flags, files, config, job or row names the diff removes is left in src/, tests/, userland/, .github/, .claude/, any CLAUDE.md, a manifest or a lockfile at d7964d26b; in issues/ they stand only as history or as what the new issue lists. No deleted issue's slug is cited anywhere. Every issues/*.md path cited at the head resolves but the four the tracker's own fixtures spell, as on main.
  • Nothing live is gone: bootlog::message, lines_of, declares, compile::repo_root, metal_checks::plant, port_accepts and toyos_tmpdir keep callers; libc, toyos-logstream and toyos-swap are still used by the root package; no guest test used the deleted modules on main.
  • toyos-swap: heard, outcome and Word::is_final have no caller in userland/ or src/. What remains is reached by supervisor, swap or src/build.rs's gate; every Word is still said by the supervisor; digest is now called by verify alone.
  • The image note holds from the code: three uncalled functions of a pure library went, one of them generic, and no instruction a running supervisor or swap executes changed. No T14 run is owed for it. No boot of the 26 could show a swap regression anyway: none performs one.
  • lan_message_delivery: no remaining T14 boot claims 8086:15fc under netstack (tests/metalcase claims virtio-net, testcases-deaf starts no netstack), so the row had no boot to ride.
  • The records: the new issue's frontmatter fits issues/README.md, its owner exists, 809c33c0c holds everything it lists, and its exit is a T14 reading. The six folded issues are carried bullet for bullet; the four others closed name tests or a boot that no longer exist. issues/the-t14-stopped-answering-ssh-between-two-lan-boots.md is still true: its exit waits on lan_swap's restore, which issues/a-connect-between-two-accepts-is-reset.md records and now points on to this branch's issue.
  • The local evidence is of this head: lanrows-r2.log names HEAD=d7964d26b…, every step exit 0, list-before 67 registrations over 27 boots, list-after 64 over 26.

SEND BACK

… half, the swap frames that closed it, and sshserver's image key file

The review of #773 found the other halves of what `d7964d26b` deleted still
shipping with nothing able to reach them. The owner: "Delete the whole chain"
and "If someone is blocking and its not needed then delete it ... We allow no
slop".

`tests/lantalkcase` was the only config whose `logkeeper` row received
netstack, so `serve_network`, `bind_port`, `Carrier`, `Hub::carrier`, the
network readers' count and the `stream` word of the inspect snapshot had no
image to run in. They go, with `toyos_logstream::PORT`, `CARRIER` and
`CARRIER_LEAVING`, the `SWAP` frames the supervisor sent logkeeper to close
that listener across a swap of netstack, and
`no_shipped_image_serves_the_log_on_the_network`, which guarded nothing. A
reader on the machine is served as before, under one count.

sshserver read `/system/etc/ssh_authorized_keys`, which only a talking boot's
staging wrote. It reads `authorized_keys` under its state directory alone.

`/system/bin/swap` and the supervisor's swap path stay: `system.toml` makes
the desktop a login session whose shell starts `swap`, and gives a login over
sshserver the same, so a shipped machine can ask for one. No test performs a
swap, which the issue now says.

Three more issues about the deleted halves are folded into
`issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md` and closed: a
netstack that dies while serving, connects turned away after logkeeper listens
again, and a network reader that never reads. The review's notes are done: the
network stack track owns the T14's outbound rows, the session track says it is
blocked, and the usb-stick track's bullet is past tense.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
@Japabu Japabu changed the title The T14 rows that need the host to reach the machine under ToyOS are deleted, and the host's swap chain with them: 27 boots to 26 The T14 rows that need the host to reach the machine under ToyOS are deleted, with the swap chain and the machine's end of the stream: 27 boots to 26 Oct 8, 2026
@Japabu

Japabu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

T14, metalcase at 25766b613 (orchestrator): one boot, toyos-metal exit 0, image sha256 c158be60…32996e56. It was booted to read sshserver's key-file change on metal, and it does not show it.

On the stick, sshserver says starting..., then no network on this machine, exiting, and its exit record carries code=0: tests/metalcase gives netstack a card the T14 does not have, so sshserver leaves before it reads any key file. No T14 boot reaches the reader this branch changed; what measures it is sshserver's host tests (29 passed, round 3) and CI.

The boot is not judged: boot:metalcase stages metaldevicecase beside it, which was not booted, so the judge staged again and exited 2. Nothing is claimed from it beyond the lines above.

@Japabu

Japabu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

Review of wt/toyos-lanrows at 25766b613 against origin/main 809c33c0c, round 2. Read: git diff d7964d26b 25766b613, every file it changes whole at the head, the orchestrator's step logs and the T14 readback.

Net lines (git diff --shortstat origin/main...25766b613): 67 files, +329 −7589. Shipped programs and their crates (userland/, toyos-logstream/, toyos-swap/) +66 −412; build system and manifests (src/, Cargo.toml, Cargo.lock) +38 −3506; tests +16 −3220; issues/ +209 −451.

Round 1's BLOCKERs

  • No --ci host and no guest suite at the head — OPEN. Run 37824641864 measures 25766b613; when read, toolchain / build was pass (3m13s) and host and guest / suite were pending. Nothing in the branch has to change. It closes on reading all three, and the body carrying them:
    • host: conclusion success on head 25766b6135a284ea73cc9cc3e4f7e0804d96f713, and in its log the step cargo run -- --ci host ending exit 0, read from the step and not from a test result line. This is the first run of every host suite, clippy's shapes included, over logkeeper, supervisor, sshserver and toyos-logstream as they now stand; the local lib run was filtered (running 127 tests, 236 filtered out).
    • toolchain / build: success on the same head. Read: pass.
    • guest / suite: success and not skipped on the same head, its closing line naming 0 failed. Every guest boots the logkeeper and the supervisor this round rebuilt; four of them were run locally.
  • logkeeper's network half reached by no image — CLOSED. git grep at 25766b613 outside issues/ finds none of serve_network, bind_port, Carrier, Hub::carrier, MAX_NETWORK_READERS, MAX_LOCAL_READERS, hub.network, CARRIER, CARRIER_LEAVING, SWAP, SWAP_LEAVING, SWAP_BACK, 41337, toyos_logstream::PORT or no_shipped_image_serves_the_log_on_the_network. What the deletion owed is measured at this head (lanrows-r3.log, HEAD=25766b613…, each step by its own exit code): --build-only 0, logkeeper 10 tests 0, toyos-logstream 19 tests 0, guest filter 0 with machine_shutdown, machine_shutdown_short_stop, console_image_boots and netstack_socket_churn each PASS; and the T14, testcases and testcases-watchdog, both verdict.txt passed, judge exit 0, 21 passed, 0 failed, 2 boot(s), kernel.log 16,960,405 bytes off the stick with the supervisor's stop line in each boot's log.
  • /system/etc/ssh_authorized_keys has no writer — CLOSED. git grep ssh_authorized_keys 25766b613 finds one line, the issue's record of the deletion. sshserver 29 tests exit 0, --build-only exit 0.

Round 1's NOTEs

  • The swap missing from "What stands in the meantime" — CLOSED (issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md:76-80).
  • The outbound rows owned by no file — CLOSED (issues/toyos-has-its-own-network-stack.md:18).
  • The usb-stick track's bullet — CLOSED (issues/the-t14-answers-only-through-a-usb-stick.md:47-53).
  • The session track not saying it is blocked — CLOSED (issues/the-t14-reboots-through-ubuntu-for-every-test.md:44-45).
  • toyos-swap and sshserver — CLOSED: gone from the body, and Cargo.toml:179-180 and userland/swap/Cargo.toml:10 say what the lock says.

BLOCKER

None new.

NOTE

  • issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md:118-122 — the 6 s of refused connects is filed as the deleted chain's alone, and the tree does not say that — the deleted issue's exit was that "whatever holds a bound listener from accepting" be named, and it never was; sshserver binds again through a swapped netstack exactly as logkeeper did (userland/sshserver/src/main.rs:748-759), and this branch keeps the swap because a person can ask for one. Whether port 22 is turned away the same is unmeasured, so the line belongs under "What stands in the meantime" as unread at this head, not only under what 809c33c0c brings back.
  • issues/the-host-cannot-reach-the-t14-while-it-runs-toyos.md:66-80 — "What stands in the meantime" does not say that no test at any tier logs in over sshserver or reaches the file that authorizes one — sshserver's 29 host tests call authorizes(text, key); nothing calls is_authorized, authorized_key_count or authorized_keys(), no guest starts the daemon, and the metalcase boot leaves at no network on this machine before the read. The reader this round changed is carried by the diff alone, which is enough for a deletion of one of two paths, and the record should say so beside the swap's sentence.
  • PR comment of 2026-10-08T18:31Z — "what measures it is sshserver's host tests (29 passed, round 3) and CI" is false of the tree — as above, no host test and no CI job reaches the changed reader.
  • PR body, "Not run here" — boot:metalcase is listed as staged for the T14 next; it was booted at this head and the comment above reports it.

Asked by the brief, no finding

  • A swap is reachable by a person at the machine. system.toml: [programs.compositor] has login = true and starts terminal; terminal starts shell; shell's starts lists swap; [programs.swap] receives swap. toyos-manifest/src/launch.rs may_start: a login row's launch from the machine's session is Starts::Opening, every launch below it is In(Login), and a login_only row (receives holds SWAP_PORT) is refused only In(Machine). The shell parses < (userland/shell/src/main.rs), which is how swap takes its bytes. sshserver's row has login = true and the same list, and is itself in shell's starts. The issue says it plainly at :76-80, with "No test performs a swap". launch_authority also reads swap started in a login session, as a process and not as a swap, which that sentence does not contradict.
  • The three issues folded this round. A netstack that dies while serving, and a network reader that never reads: both describe the host's Stream and MAX_NETWORK_READERS, neither exists at this head, and each is carried with its exit at :113-117 and :123-125. The third is the first NOTE. No slug of the three is cited anywhere at the head, and issues/the-loader-does-only-what-must-precede-the-handover.md lost its citation in the same diff.
  • Nothing dead or missing after the deletion. No system.toml in the tree gives logkeeper a receives. The inspect snapshot's stream word had no reader: nothing outside logkeeper names volume.state, records.lost or stream as a key but toyos-inspect's own wire fixture. No line the deleted code said (serving this boot's log, stopped reading after, local reader) is read by a test or a judge. Every remaining public item of toyos-logstream has a user outside the crate or inside it, as on main. Poller::watch_raw, Pipe::read_nonblock and endow::namespace keep other callers.
  • The SWAP frames carried nothing else. Hub::carrier wrote one byte to the network server's pipe and returned at once without one; swapped at the head is the same say! of toyos_swap::said, and all eight Words are still said. The stop sequence (FLUSH, FLUSHED, RESUME, STOPPING) is untouched by the diff, and machine_shutdown and both T14 boots ran it.
  • sshserver at startup. An unreadable key file was a printed line and then no file names a usable key, and is now cannot read <path>; both end in the same exiting and return. No test or judge reads either line or the dropped key(s) authorized by line.

SEND BACK

@Japabu

Japabu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

Correction to my comment above (orchestrator): "what measures it is sshserver's host tests (29 passed, round 3) and CI" is false. The 29 host tests call authorizes(text, key); none calls is_authorized, authorized_key_count or authorized_keys(), no guest starts the daemon, and the metalcase boot leaves before the read. No test at any tier reaches the key-file reader this branch changed: it is carried by the diff alone, and the issue says so.

The review of #773's second round: the 6 s of refused connects after a swap
of netstack was filed as the deleted chain's alone, and sshserver binds again
through a swapped netstack as logkeeper did; and no test at any tier reaches
the file that authorizes a login, the T14's `metalcase` boot included, which
leaves at `no network on this machine` before the read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
@Japabu

Japabu commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

CI at 19b660d76, read against round 2's list (orchestrator): run 37825620132, event pull_request, conclusion success, each job by its own conclusion.

  • host: success; the step Run cargo run -- --ci host concluded success.
  • toolchain / build: success.
  • guest / suite: success, not skipped; [ci] the suite: test result: ok. 36 passed, 36 total; [ci] Guest: 5 step(s), all green.

Round 2's one open BLOCKER closes on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant