Conversation
…VMe and FAT go (work in progress) A checkpoint of the file-server branch before main is merged in: the kernel's NVMe driver, page cache, read-write bcachefs adapter and FAT adapter are deleted; fsd serves each role's directories as capabilities init hands out; spawn and dlopen take an image a served file was read into. Tests are still being moved onto the servers. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…client (work in progress) The kernel tests whose subject was deleted go with it; the ones whose claim survives are retargeted onto blockd, fsd and the kernel's USB partition claims. fsd answers one request per client per wait and asks an acceptor before it accepts: a duplicate completion parked the log's server at boot. New: fs_escape, fsd_restart, and fsd's FAT read-error host tests. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…t-lld pin Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
… up to the tree The nightly storage tests are retargeted onto fsd, blockd and the USB partition claims, or deleted with their kernel subject (writeback's FAT arms, the truncate race and its actuator). The claim path says when a flush was answered on a retry. Every program keeps /boot in its view until the rows declare their own. Issues whose subject left the kernel are closed or re-pointed at fsd, and the weaknesses this change leaves are filed: C programs, a link from a kernel mount, a half-written btree, the slots of an NVMe-installed image, a file server's reach over blockd, duplicate completions, the metal read span, and the cached read's cost. The SDK crates take their minors: toyos-abi 0.17.0, toyos 0.19.0, toyos-window 0.21.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…e wizard its /config Both boots had no fsd row, so /config was nobody's and the locale applet was refused its write; locale_gate's wizard namespace now keeps fs:/config beside the surface. The lockfiles take the SDK's new minors. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
|
Review of #536 at 2aa73f1 (wt/toyos-fsd). Gate, not met at 2aa73f1:
NOT READY FOR REVIEW |
The ABI bump declared toyos 0.19.0, toyos-abi 0.17.0 and toyos-window 0.21.0, but toyos/Cargo.lock and tests/iced-counter/Cargo.lock still locked 0.18.0, 0.16.0 and 0.20.0, and `abi-split` refused them (run 36313219131). Moved with `cargo update --offline -p ...` against each lockfile's own manifest; every other tracked lockfile already held the new versions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
`cargo test --lib` in the root had 20 reds at 334fbd8, all this branch's, and no gate run on the branch had reached them: - `no_diag_program_claims_the_screen`: 2aa73f1 gave the diag boot blockd, which claims the NVMe controller, and the diag image's whole guarantee is a config that declares no `devices`. The diag boot now runs fsd for the log role alone: the log partition is the kernel's partition claim on the boot stick, so logd keeps its /log and nothing in the image claims a device. screen_diag_boot and screen_log_absent EXIT=0 after it. - `every_shipped_boot_config_is_covered`: tests/fsdrestartcase joins ALL_CONFIGS, and with it every per-config gate that list drives. - the 18 `heartbeat::tests`: tests/metalcase now starts blockd and fsd, and DONE had no done line for either. DONE carries one line per process a row starts: blockd's `NVMe up`, and fsd's `<Role> serving` for each of its three roles. The recorded nightly captures were booted without either program, so the tests replay them against that start list's lines, and the table is held against metalcase's own start list in `a_program_the_done_table_does_not_know_is_refused`. kernel_heartbeat EXIT=0 on a metalcase boot after it. `cargo test --lib`: 396 passed, EXIT=0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
lan_mdns_answer's two fast-tier failures are one defect of the dev host's scratch path, measured by an A/B at 16d2e64 against this branch, two runs per arm per $TMPDIR, one at a time: the default $TMPDIR reds on both with `path must be shorter than SUN_LEN` (a 104-byte socket path, which QEMU binds and the host's connect refuses); a $TMPDIR three bytes longer reds on both with QEMU refusing its own -chardev and exiting 1 before READY, the shape the fast tier showed on lane 11 (105 bytes); a $TMPDIR under target/ passes on both, with no IOMMU line from either guest. The IOMMU translation faults beside the fast-tier failure were other tests' deliberate foreign-DMA actuators interleaved into the shared log. The first shape is quarantined at the issue that owns it; the second cannot be, since its text is only the harness's boot-death framing. With the row, the default $TMPDIR run is XFAIL, EXIT=0. The cached-read issue now carries the measurement of where a request goes, fsd's READ arm timed from inside the server beside the kernel's /tmp in the same guest: a 104 us round trip against 2.6 us, and at 256 KiB the two volatile word copies through the window at ~87%. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
|
Review of #536 at 7e2e104 (wt/toyos-fsd), round 2: a full review after the gate stop at 2aa73f1. Gate at 7e2e104. PR CI is green: run 36315170451,
Net lines
BLOCKER
NOTE
REMOVE
SEND BACK |
`DataVolume::rename` marked every holder of `to` gone before asking the format for the rename, so a rename the format refused (EntryTooLarge, NoSpace, a device error) had already dropped `to`'s unsynced length and extents: `persist` skips a gone node, and `to` still named the file. The orphan now follows the format's answer, as fat.rs's rename and data.rs's own unlink already order it. Host test `a_refused_rename_over_an_open_file_keeps_its_unsynced_writes`: a rename refused EntryTooLarge (240 extents fit `from`'s short name and not `to`'s 300-byte one) leaves `to` readable and its length on the volume after the next sync. With the orphan moved back before the rename (a checked patch): EXIT=101, the read answers Gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…ounds what a client names The review of #536 at 7e2e104, blockers 1, 2, 3, 5 and 7: - init made its file calls (the session home, a service's home, a launch's `/apps` package) from its one loop, which is also where a file server that ended is started again: a call a server's end left in the port's queue waited for ever. They run on one worker thread now (`Worker`), and `Init::files` waits on the call and on a service's end together, restarting while it waits; a server alive and silent costs `FILES_BOUND` (30 s, policy). fsd's `--end-at-hello <dir>` actuator ends the server at the first hello on `dir` this boot; `tests/fsdrestartcase` arms it on `/apps`, and `fs_restart` launches an `/apps` path first: init's resolution is that hello, and the launch is answered. - `STREAM` refuses an offset past `MAX_FILE_BYTES` (`fs_stream_offset`), a drain ends its stream by name at that bound, and a drain takes one read per wake, `pump`'s fairness. Every other client number fsd keeps was already bounded where it is kept. - A handle held across a restart reopens by path and keeps the file only when the server answers the identity it last saw (`Stat::ident`, a hash of what the entry records: DATA's first block, length and mtime; FAT's short name, creation stamp, first cluster and length). `fs_restart` renames a file over a held one, ends the server, and the held handle's write is Gone; the host reads the replacement's bytes back untouched. - The window: one bounds-checked `copy_nonoverlapping` each way, never a reference over it, with who owns it when at the site; fsd's `READ` has the cache copy each block into the window once (`Out`, `Cache::visit`), and a `WRITE` lands in a kept scratch. - A client past `MAX_SERVED` is answered `ResourceExhausted` at its hello and let go by name; acceptors wait only on `MAX_HANDSHAKES`, each answered or let go within `HANDSHAKE_TIMEOUT` (`fs_client_bound`). Also: `Capability.writable` and `Dir::write`'s second generation check are gone; a blockd whose controller would not open answers `Unusable`, and fsd says DATA is absent rather than putting it in memory; `fs_cache_eviction` reads a file longer than the cache keeps back off the disk. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…es the kernel copies
Owner-approved revision of the image ABI this branch added. `SpawnArgs`
carries `image` (a handle to a shared memory object carrying `MAP`) and
`image_len` in place of a pointer and a length, and `SYS_DLOPEN`'s fourth
word points at an `ImageRef { handle, len }`. The caller reads the program
into an object it owns and is charged for; the kernel pages the child from
that object (`SharedImage`), copying each page once as it is read, and
refuses an object that is no memory it allocated or a length the object does
not hold. `SYS_DLOPEN` answers a name the process already holds before it
looks at the object. `ImageBacking`, which copied up to 256 MiB into kernel
pages charged to nobody, and `MAX_IMAGE_BYTES` go.
`spawn_image_object`: a program in an object runs; an object without `MAP`
is refused `PermissionDenied` and a length past it `InvalidArgument`; an
object overwritten with `hlt` right after the spawn ends its child and the
next spawn runs; and a held name's `dlopen` is answered through a handle it
could not read.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Blocker 6 of the review. The kernel's write-back queue is still the teardown path of every closed kernel file, and `/tmp` is the one writable directory the kernel serves; it cannot move to a file server while C programs name no served file (`issues/filesystem/c-programs-name-no-file-a-file-server-holds.md`). So the tests guard it there: - `writeback_reopen` and `writeback_spawn` stage `/tmp` files with `iod` parked, and the harness holds `iod`'s one line saying `writeback-stall` parked it. - `resize-fault-refuse` and `resize-evict-window` are deleted with their hooks: the device read a shrink made has no device under it any more. - `writeback_durability`, which nothing ran, is deleted with its sleeps. - `esp_files` stages the loader attack as a link on `/home`, absolute and climbing, where it resolves to something: both are refused for writing. The IOMMU actuators' staging (`STAGED`, `staged`, the xHCI class) is compiled only with `boot-actuators`. The review's REMOVE lines are deleted: NVMe in the foreign-DMA actuator's doc, the panel census and the USB id base, and a test doc left above the wrong test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
- a held file is known across a restart by what its entry records, which a same-length replacement in the freed first block within the second passes; - a file server maps a lent window at the size it expects; - every flush of a served file syncs its whole volume; - one write far past a file's end holds DATA's server; - the log's server ending under logd's append is unmeasured; - a served directory costs each process a 2 MiB window, unmeasured; - the boot volume's server is endowed a claim that writes (extends the isolation issue on blockd sessions). `lan_mdns_answer`'s issue is `expected-red`: `src/redlist.rs` quarantines it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…the deadlock was `--end-at-hello` ended the server at init's first hello on `/apps`, whose connect then failed and was answered: it never reached the retry that reconnects and waits in the port's queue, so init resolving from its loop passed it too. `--end-at-request` ends the server at the first request after a hello, on a connection init holds; its retry reconnects into the queue. With init's resolution moved back onto its loop (a checked patch), `fsd_restart` wedges the machine: fsd's end is the last line, and init starts nothing again (EXIT=1, 322 s, twice). With the worker: EXIT=0. The mark that makes the actuator once a boot is looked for and then made: the std fork's `create_new` on a kernel path is not exclusive, which two servers took as two first times; filed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
…, and what load showed, filed
`quiesce_stops_the_machine` counts every userland thread the stop names;
init's file worker is one more.
The cached read, measured by the same interleaved guest runs as before (an
uncommitted bench and a probe in fsd's `READ`, applied and restored), one
guest, 256 KiB requests on a 16 MiB file in DATA's cache against the kernel's
`/tmp`:
before (the volatile loops, a zeroed buffer per request):
fsd 1952-1975 us a request (127-128 MiB/s), 945-954 us of it in the server
after:
fsd 988-997 us (251-253 MiB/s), 107 us in the server
the kernel: 99.5-99.8 us
2 MiB requests went from 367-402 MiB/s to 1159-1392 MiB/s. What is left at
256 KiB is the client's one copy out of the window: a 256 KiB
`copy_nonoverlapping` out of a shared mapping costs 2.86 ns a byte under TCG
in the same guest, against 0.23 between two heap buffers. The issue that
recorded the copies as a compromise goes; one asking for the measurement on
metal takes its place.
Filed from load-coincident reds on a loaded dev host, each green alone:
threads of one process starving on one directory's connection
(`quiesce_stops_the_machine`), the stop's flush and syncs outlasting
`quiesce-last`'s 10 s hold (`quiesce_wakes_on_the_last_exit`), and
`swap_crash_rolls_back`'s log stream redial spending its ceiling inside the
swap's probation.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The four guest binaries this round adds to the shared block (`fs_stream_offset`, `fs_client_bound`, `fs_cache_eviction`, `spawn_image_object`) cut its T14 list in three, and the metal profile refuses a list nobody priced. `shared-3`'s rows carry `shared-2`'s ceilings, from the same constants, and no `measured`: no run has taken that boot yet. With them, `--metal --metal-readback` stages all 25 images (EXIT=2, staged and not judged, the machine untouched). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review, round 2, at e00e669Not ready. There is no CI result for this head. Because of that, the round-1 BLOCKERs B1–B7, the ABI's completeness and the size are not judged. The mutation EXITs in the PR body are local runs on a head that cannot land as it stands: the merge below rewrites the same kernel boot path and the same tests. What has to happen before the next round1. Merge origin/main and resolve these conflicts. I ran
2. Settle each of the three wide reds against main, with an A/B under the same load. Running them alone and getting green is a re-run; it does not adjudicate them.
3. The T14 images do not reflect what will land. The 25 images were staged after 06a6077. Production code last changed at 28094fd, so they may match e00e669's code. But the PR names no directory ( B3's identity, decided now so it does not cost a roundThe design doc is right: reopen answers Gone until the format carries an object id and a generation, and The ABI's syscall numbersThis branch neither adds nor retires a syscall number. In the brief's two-way verdict this counts as SEND BACK. NOT READY FOR REVIEW |
page_cache.rs stays deleted. #535's `partclaim-root-withheld` moves off its read-fault injector onto `block::unanswered`, which gains `answer`: the kernel drives only USB disks here, so the actuator refuses block 0 of each of those across `rootfs::hold_source` alone. main.rs keeps the branch's `gpt::probe_usb_disks` and drops the kernel mounts main still carries; main's move of `platform_devices` into the device phase merges as it is. partclaim.rs: both arms. `root_withheld` boots the partclaim config off its USB stick (`Profile::UsbDisk`) with the crafted disk beside it, because an NVMe boot here puts ROOT on a disk the kernel does not drive and would withhold it with no actuator armed at all. power.rs: the branch's `OTHERS`, with main's `console-queue-at-the-stop` actuator and its judge. storage.rs: `home_budget_refusal_retried` stays deleted with the kernel's NVMe fsync path. #535's claim that a refused flush is refused once and not on every `logd` flush moves to `log_flush_retry`'s first boot, where `/log`'s flush is fsd's claim flush: no `partclaim: a flush durable on attempt` line in the 2 s after the guest's. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The table-read injector's module doc, `root_withheld`'s doc and the storm check's comment were rewritten in the merge; they go, and the check keeps one clause for its fixed window. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tined The signature main's nightly at 1ce7183 left, "the stream's redial was turned away", is quarantined against main's issue, and what the branch's duplicate measured moves there. The duplicate's deletion went in with 506bbdc, as did the deletion of the hash identity's issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ory's connection is handed over in turn B3, the orchestrator's ruling: a hash of what an entry records is no identity, since the allocator hands a freed block back first and a same-length file written within the second passed it. `Stat::ident` goes from the protocol, fsd's two implementations and `toyos-fat32`'s accessor, and std (fork 2b2fb74a303) no longer reopens a held file by path: a handle whose server ended answers StaleNetworkFileHandle. `fs_restart` now expects Gone from a handle held on an unchanged file across an end, reads the flushed file through a new open, and still reds if a handle on a file renamed over is reopened into it. The exit is issues/filesystem/a-file-held-across-a-file-servers-restart-answers-gone.md. std's futex mutex let the thread that let go of a directory's connection take it back before the waiter it woke ran; `quiesce_stops_the_machine`'s six writers on `/log` starved five on a loaded host. Callers take a ticket and are served in order. `fs_turns` has six threads write one directory until one made 32 passes, and every one must have made 16. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review, round 13, at 5235eda (rounds 12 and 13, and the merge of a7cd327)Gate
Net lines (
Production grew 153 lines since r12 (+728). That is the SDK reader (+172) and the start refusal, less Earlier BLOCKERs
The two reds
BLOCKER
NOTE
REMOVE
Owed before LAND, at the landing head (after the merge with 69d1b53)
SEND BACK |
No conflict. main's rust pin is where the branch's fork merge left it behind (1b236638, an ancestor of the branch's 62fa74d7), so the branch's pin stands. No line main added cites a file the branch deletes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…er memory A controller blockd's row names that is on the machine and whose claim the kernel refused was served as no controller at all: blockd said none was on the machine, fsd said the machine had no DATA partition, and /apps, /config, /home and /state went into memory on every machine with no DMAR. init now tells a block service which of its row's claims were refused with anything but NotFound (`--claim-refused <name>`); blockd serves Drive::ClaimRefused, whose listing and opens are refused with the new wire word ClaimRefused, and fsd serves DATA absent by name. DATA's partition was decided three ways: two on the kernel's disks refused the start, two on blockd's went to memory, and one on each took the kernel's without asking blockd. init now claims every partition of a role the kernel's disks carry, and fsd::data::find counts those claims and blockd's TOYOS-DATA listing together once: none is memory, one is served, two or more are refused by name and DATA is absent, and a listing refused leaves the count unknown, so DATA is absent then too. A log or boot claim is by the loader's GUID, which the kernel refuses when two partitions carry it, so that arm is unchanged. iommu_virtio_platform's no-unit arm, which boots tests/netcase with its blockd row, accepts 00:02.0's refusal by name, and asserts init's, blockd's and fsd's lines and that the in-memory line is never said. fsd_two_data boots DATA on a stick and on NVMe and asserts the refusal, the absent volume, no format and the stick unchanged byte for byte. fsd_claim_held and the three partclaim boots, which stage DATA on a stick, get an NVMe disk with no table so the machine has one DATA. The two "plus 16" restatements of the kernel's headroom in heap_ceiling.rs are deleted. The issue on a worktree's bootstrap cache is restored: the pull request that fixes it is not merged. A foreign DATA partition still answered with memory is filed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…ion, claims as sentences The rename's init exclusions become one rule: a match stays only where init means initialise, initial or the CPU's INIT signal, or sits in third-party text; every other match names the program. The search is bounded so CamelCase joins hit: no lowercase letter follows, and a letter precedes only a capital I. The review's literal "no lowercase letter on either side" misses TimerInit, which occurs 6 times outside issues/ at origin/main cd2e630; this bound catches it. Stage 2's exit now requires each decision deleted from userland/supervisor, which calls the crate for it. Stage 4's claims are sentences. The tier-and-redlist clause covers every guest test the track names. "The fork's delta" is forkcheck's definition. soundd's and blockd's new names reopen with the owner beside fsd's: mixer and disks are words the tree already uses. Removed: the stop on #536, the manifest's current order, the file manager's name, and the power-broker clause citing the deleted applet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…le calls Every file call on this branch is a request on a connection to a file server and a blocking read of its reply, and sys_read/sys_write charged a connection's wait to WaitClass::Pipe. watch-window holds every pipe-class waiter in a Ring 0 spin of up to 50 ms with no preemption point, so under the actuator each of logd's writes through fsd, and fsd's through blockd, became such a spin beside blocking_read_window's canary. A connection's wait is now WaitClass::Ipc, which is also what the blocked-time breakdown should have said of it; a bare pipe's stays Pipe and stays held. process_stats gains the arm that names it: a child parked reading a connection, answered once the roster says it is blocked, charges its park to blocked_ipc_ns. home_overwrite_reads_back's guest fsyncs a file before the pinned overwrite, so the volume's format is on the device and the stop's sync is the only thing that carries the pinned file there: without that sync the host's read names the lost file rather than an unformatted volume. The comment naming SYS_SHUTDOWN's drain, which no longer exists, is deleted. Filed: watch-window spins out a hold whose poster is queued behind it on the same CPU, the mechanism the canary's 50 ms-a-half-trip reds fit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
One modify/delete conflict: main disabled ftruncate_flush_race behind issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md and gave that issue an expected-red status, a sighting, an exit condition and an owner. This branch deletes the test with the kernel flush it raced and the ftruncate-flush-stall actuator, so every one of those hunks is about a test that no longer exists: the issue stays deleted and main's redlist row for it is removed, since the harness refuses a row whose test nothing registers. main's rust pin did not move, so the fork merge stands. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…mpiler switch The issue's exit was a worktree's bootstrap cache keyed on, or cleared with, the compiler that builds it. The merge of ec06384 brought src/sysroot.rs's forget_another_compiler: build_std records the compiler's identity in <fork>/build/toyos-std/compiled-by, and on any other identity empties that directory of everything but bootstrap's downloads (cache, <host>/ci-llvm, <host>/rustfmt), so rust/build/toyos-std/bootstrap, where the stale serde rlibs lived, goes with it. The rule is stated at that function; nothing else cites the issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Review, round 15, at 069722cGate. CI Net lines (
Earlier BLOCKERs
Round 15's claim
BLOCKERNone open. NOTE
REMOVE
LAND AFTER NAMED CHANGES |
No conflict. The one file both sides change is tests/toyos.rs; main's hunks add metal_sim_hostile_clipboard (skip row, tier row, carries row, its function and dispatch arm) and a long-copy check in metal_sim_client_death, none of which this branch touches. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
… is chosen where the kind is - `ops::pipe_read` and `ops::pipe_write` answer a blocking read's or write's pipe together with its wait class, in the exhaustive matches that already name every pipe-bearing kind, so a new one cannot compile without choosing. `io.rs`'s `pipe_wait`, a `matches!` that fell back to `Pipe`, is deleted; `pipe_id_read` and `pipe_id_write` are those two with the class dropped. - `process_stats` gains `a_wait_to_write_a_full_connection_is_ipc`: a child fills a connection, parks writing one byte more, and this process reads to make room once the roster has it blocked. Both connection arms share `parked_on_a_connection`. - `tests/toyos-rust-tests/src/roster.rs` is the one roster decoder, its `BLOCKED`, the capability it reads with and the bounded poll, included by `process_stats` and `process_lifecycle` in place of their two copies. - Deleted: `watch_window`'s doc in `actuator.rs`, which said it holds every watch waiter; the narration in `a_wait_on_a_connection_is_ipc`'s doc; and a scratch log path cited in the watch-window issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
#564's schedule and its 15 deletions meet this branch's storage move. Where #564 deleted a test or the kernel code only it armed, the deletion stands; where this branch deleted a test #564 retiered, this branch's deletion stands; every surviving row takes #564's tier, and the five this branch adds (fsd_restart, fsd_end_at_mount, fsd_claim_held, fsd_two_data, blockd_serves_nothing) keep the Fast tier they were added at, as #564 kept the tier of every row main added. - kernel/src/actuator.rs: quiesce-last-exit and quiesce-dump go (#564); fat-flush-meta-refuse, resize-evict-window and resize-fault-refuse stay gone (this branch). - kernel/src/syscall/machine.rs: the stop serves no dump (#564) and syncs no filesystem (this branch): neither block survives. - toyos-quiesce/src/lib.rs: this branch's FILES_MS, FLUSH_MS and SYNC_MS, and #564's LAST_THREAD doc naming quiesce-last-park alone. - tests/common/power.rs: quiesce_dump_holds_the_stopped goes with its actuator; quiesce_wakes_on_the_last_park is #564's inlined body with this branch's stop-record ordering in place of "Syncing filesystems...". - tests/common/storage.rs and tests/toyos-rust-tests/src/bin/so_cache_policy.rs: so_cache_refusals and its binary go (#564); this branch's /tmp retarget of them serves no surviving test. The so-cache-tiny actuator went with them. - issues/filesystem/home-budget-refusal-retried-is-red-on-every-nightly.md stays deleted: its test and binary are gone on both sides, and the reproducer #564's exit names is the kernel's /home over its NVMe driver, which this branch deletes. The fsync-budget-spent race it pointed at is still tracked by the partition-claim-gives-up issue. - issues/README.md: boot-media is gated by esp_filesystem, kernel_log_file, log_partition_layout and log_partition_identity, plus toybox_cp_volume: wall_clock_file went in #564, log_backing_read_error and boot_volume_metadata_error on this branch. - tests/toyos.rs: RUST_SKIP, MACHINE_TESTS, CARRIES and the dispatch lose so_cache_refusals, quiesce_wakes_on_the_last_exit and quiesce_dump_holds_the_stopped (#564) and keep this branch's deletions (cache_eviction, the writeback trio, page_cache_partition_offset, quiesce_leaves_the_volume_whole, ftruncate_flush_race, log_backing_read_error, boot_volume_metadata_error); the comment of the deleted ftruncate_flush_race row goes with it. #564's tier for block_duplicate_id, partition_claim_departure, quiesce_refuses_a_second_shutdown, quiesce_wakes_on_the_last_park, late_storage_connect, log_partition_layout, the root_* rows, log_partition_identity, tls_rebase_window, sysret_ss_reload, userdev_residue_is_its_own and blockd_lends_within_its_bound, beside this branch's comments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
#572 deletes ovmf/ and aavmf/ so every guest boots the host QEMU's own edk2 firmware; this branch already deleted ftruncate_flush_race and its kernel actuator/vfs code as part of retargeting the nightly storage suite onto fsd (193600c). The two touch the same issue file: #572 appended a firmware-comparison row (stock edk2 vs. the committed ovmf/, both still flaky) to a table whose subject — the test binary and the VFS lock path it raced on — no longer exists on this branch (`rg ftruncate_flush_race` finds nothing under kernel/, tests/, or src/). The evidence adds nothing a surviving issue or test needs, so the deletion stands; no other file cites the issue by path or bare name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Review, round 17, at d5bbfbbGate. CI
The T14 reading is still owed. It is a landing condition and outside this review. Net lines (
Earlier findings (r15)
Merges
BLOCKER
NOTE
REMOVE
SEND BACK |
… a test this branch deletes, move the stop-sync's only guest control to Nightly, and rename a misnamed binding Merging origin/main (c089fce, #580) brought back a redlist row and issue for `quiesce_leaves_the_volume_whole`, a test this branch already deletes; the harness refuses a disabled row nothing registers, so both go. `home_overwrite_reads_back` is the only guest check on init's stop sync and was priced at Weekly for the old kernel-`/home` test it replaced, so a lost sync goes unseen by every PR and nightly; it moves to Nightly. `tests/common/power.rs`'s `synced_at` bound the stop record's line, not anything synced there. Also deletes two stale doc comments in `process_stats.rs` that only narrated the code below them, and a roster.rs clause the reviewer found false for `process_stats`'s own child. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Main's rust pin has not moved since the last merge, so the fork is unchanged. Every conflict, and how it was resolved: Modify/delete, main deleted: - issues/build/a-swaps-redial-races-a-hard-dial-ceiling-against-an-unbounded-guest-gap.md: #566 fixed the defect and deleted the issue. This branch had added one sighting to it, and a sighting of a fixed defect has no home, so the file stays deleted. - src/heartbeat.rs: #562 deleted `kernel_heartbeat`'s CPU-mask and gap verdicts with the file. This branch had given its done-line table blockd and fsd rows. The table goes with the verdict it served. - tests/doomcase/system.toml: #562 moved the doom audio tests to metal and deleted their QEMU config. This branch had added blockd and fsd rows to it. Nothing boots it now. Modify/delete, this branch deleted: - tests/toyos-rust-tests/src/bin/ftruncate_flush_race.rs, tests/toyos-rust-tests/src/bin/quiesce_fsync.rs, issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md, issues/build/quiesce-leaves-the-volume-whole-needs-its-flush-to-close-inside-the-stops-budget.md and issues/kernel/a-root-metadata-read-refused-on-budget-is-not-retried.md: main's hunks remove timing from them or note its own runs. They are about the kernel FAT flush, the stop's kernel sync and the kernel's metadata read, which this branch deletes, so they stay deleted. Content: - kernel/src/actuator.rs: main's `quiesce_last_teardown` (#549) is kept. The kernel FAT actuators `fat_flush_meta_refuse`, `resize_evict_window` and `resize_fault_refuse` stay deleted. `process_reopen_selftest` stays where this branch has it, with main's doc (#549 also opens every kernel thread's pid). - src/redlist.rs: both conflicted rows go. `doom_sound_flood` left QEMU with #562, and this branch deletes `ftruncate_flush_race`. - tests/common/gpt.rs: this branch's `device_saying` and decoy `boot` are kept. Main drops the `drain_serial` window, so its `qemu` binding is no longer `mut`. - tests/common/inspect.rs: main's "nothing plays audio" (#562 deleted `inspect_plays`) is taken, with this branch's clause on the boot stick. - tests/common/iommu.rs: main's `panic-reboot-fast` and its wait for the fatal path's reset are kept. This branch's `iommu_empty_domain` reads the xHCI's DCBAAP over QMP, and QEMU has exited by the time that reset is seen. So `fault_boot` now takes a `holding` read, which it runs after the fault line and before it waits for the reset, while the fatal path holds its panel. `iommu_context_absent` reads nothing there. - tests/common/origin.rs: main's judgement of `log_ring_keeps_the_owners_slots` is taken whole: init says it waited a flush out, or its stop line is missing. That drops the millisecond inference between two records, whose record this branch had changed from `Syncing filesystems...` to the stop record (#562: no QEMU test measures time). - tests/common/volumes.rs: main's timing edit to `ftruncate_flush_race` goes with the test. - tests/logstallcase/system.toml: main drops `power` and the `shutdown` symlink, since the metal row reads `/log` without a stop. This branch's blockd and fsd rows are kept, because fsd holds `/log`. - tests/toyos-rust-tests/src/bin/blockd_io.rs: main's `claim_when_free`, now generic and with no deadline, is taken inside this branch's `if let Some(syscap)`. `bench` is this branch's blockd-only arm with main's timing removed: no MiB/s, and the line says only how many Flushes each run took. The module doc's "timed" goes. - tests/toyos-rust-tests/src/roster.rs (add/add): both sides wrote one roster decoder. Main's is taken whole, because five binaries read it and it has no deadline (#562). This branch's copy had a 5 s give-up. - tests/toyos-rust-tests/src/bin/process_lifecycle.rs: main's is taken whole. This branch's only change to it was the move onto its own roster.rs. - tests/toyos-rust-tests/src/bin/process_stats.rs: main's `refused_calls_are_counted` and its roster wait for the held child are kept, and so are this branch's two connection arms. The system capability is taken once in `main` and passed to the three arms that read the roster, since a second take of the label finds nothing. The connection arms now wait on main's `threads_of` for the child's main thread to be blocked, with no deadline. - tests/toyos-rust-tests/src/bin/quiesce_twice.rs: main's `Duration`-only import. This branch deletes the owed file, so `File` and `Write` go. - tests/toyos.rs: - RUST_SKIP: main's audio rows are taken. `audio_tone_load` goes, since main deleted it. `log_volume_reread` goes, since this branch deletes it. - MACHINE_TESTS: `quiesce_leaves_the_volume_whole` stays deleted. `quiesce_wakes_on_the_last_teardown` comes from main with main's comment. `blockd_serves_nothing` is kept. `hda_tone` and `hda_client_stall` went to metal with #562, and `hda_two_live_refused` takes main's comment. - CARRIES and dispatch: the same. - `nvme_wide_sector`: this branch's blockd arm, which already had no drain window. - toyos-quiesce/src/lib.rs: this branch's `FILES_MS`, `FLUSH_MS` and `SYNC_MS` are kept, with main's `LAST_THREAD` doc, which names both quiesce-last actuators. - userland/logd/src/policy.rs: this branch deletes the module doc and the `LOG_WRITE_BUDGET` paragraphs main edited one line of, so they stay deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`issues/build/parallel-tests-red-under-other-suites.md` recorded `quiesce_leaves_the_volume_whole` red under `quiesce-fsync-refuse` with the kernel's log volume. The test, the actuator and that volume are all gone on this branch, so the sighting is deleted and not rewritten. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
On the T14 at b607ce7 metal_device_probe failed with nvme: no record carries "blockd: no NVMe controller this row names is on this machine" although the readback's log carries that line: {2026-09-29 08:43:12 1.162 blockd} blockd: no NVMe controller this row names is on this machine; serving no partition The judge handed `unmet` `Readback::kernel()`, which is the log with every program's line taken out (`bootlog::kernel_records`). On main the NVMe records were the kernel's; on this branch they are blockd's, a program's line, so the filter removed the one record the row owed, and `nvme-served` (NeverSays "blockd: partition ") could never have seen a served partition either. The unit fixture hid it by writing blockd's line as a kernel record. blockd's two records move to their own table, BLOCKD_RECORDS, judged against `bootlog::lines_of(log, "blockd")`; RECORDS stays judged against the kernel's records alone, now filtered inside `unmet`, which takes the whole log. A kernel line or another program saying blockd's words does not count, nor a program saying "Boot: complete (". A new test holds BLOCKD_RECORDS to blockd's source. The inventory reads the whole log so its "blockd: " row reports something. Oracle: the recorded T14 readback (target/metal/metaldevicecase), run through both readings as a temporary test: the old one reproduces the T14's single finding exactly, the new one reports none. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs
Brings #583, #586, #593, #597, #555, #600, #610 and #611. Every conflicted hunk, and where it went: - rust: 1471893e39c, which merges main's pin 9c3eea441d8 into this branch's 62fa74d7a50 with no conflict (main's three bootstrap commits and this branch's six std files do not meet). Pushed to ToyOSOrg/rust wt-toyos-fsd. - kernel/src/actuator.rs: #583 deletes `rtc-zone-east`, and that deletion stands. This branch's doc for `leak-rollback-selftest` stands, since the FAT reopen control went with the kernel's FAT adapter. - kernel/src/fat32_adapter.rs (modify/delete): the deletion stands. #583's hunk made FAT stamp UTC (`clock::utc_secs`) with the refusal reason at the site. FAT stamping is fsd's on this branch, so it is carried there: `local_secs`, which recovered a zone through `toyos_wallclock::resolve` (deleted by #583) and cited logd's `wall.rs` (deleted by #583), becomes `utc_secs`, `clock_epoch()` alone, with main's reason. fsd no longer depends on toyos-wallclock; userland/Cargo.lock drops the edge. - kernel/src/sched/kthread.rs: #586 deleted `lognest` and `log-storm`, and this branch deleted `iod`, so klogd is the one kernel thread in every build: MAX_KERNEL_TASKS = 1, with no feature split. - issues/kernel/the-kernel-still-creates-threads.md: #586 met K3 and deleted it; this branch meets K5 and deletes it. K6 is blocked on K2 and K4. - userland/logd/src/main.rs: #583's `boot_secs` rename, beside this branch's `Published::new()`, which takes no argument here. The `owed` and `retrying_since` fields stay deleted (this branch). - userland/logd/src/serve.rs: this branch's `serving` flag, with #583's `boot_secs`. - tests/test-durations: #586 deleted `log_conservation_smp1` and this branch deleted `log_backing_read_error`; neither row stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs
Review, round 19, at 27b5641 (806da12 and the merge of d1d83f6)Gate.
Net lines (
Earlier findings (r17)
806da12
The merge 27b5641: every conflict hunk is accounted for
BLOCKER
Owed before LAND, at the landing headThe controls below are the ones landing needs:
NOTE
REMOVE
SEND BACK 🤖 Generated with Claude Code |
Brings #587 (a file's mtime is UTC nanoseconds since the Unix epoch), #603, #614 and #615. Conflicts, every hunk of both sides: - kernel/src/fat32_adapter.rs (modify/delete): the deletion stands. #587's hunks there are `stamp(mtime)` as whole UTC seconds, `now()` as `stamp(mtime_now())`, `create` stamping the VFS's mtime, the flush stamping its own instant, and `file_mtime` answering seconds times 10^9. FAT stamping is fsd's on this branch: its `lstat`, `list` and `node_meta` already answer seconds times 10^9, its level stamps the flush's own instant, and the next commit gives it the nanosecond clock to divide. - kernel/src/vfs.rs: this branch deleted `open_backing_identified`'s flush of a dirty file, so #587's `mtime_now` there goes with it. #587's `file_mtime` doc hunk is taken. - kernel/src/object/ops.rs: the write and `ftruncate` stamps keep this branch's `file_cache::touch` and `set_size`, and stamp `mtime_now`; the two open stamps merged clean. #587's comment on dirty state in the cache is not taken: this branch's cache keeps no dirt. - kernel/src/leak_selftest.rs: this branch deleted `fat_reopen_census` with the FAT adapter it probed, so #587's `mtime_now` there goes too. - kernel/src/clock.rs (merged clean): `NANOS_PER_SEC` is private, since the FAT adapter it was made public for is gone. - issues/isolation/the-so-caches-refusals-are-narrower-than-its-reach.md: this branch deleted the FAT same-size-rewrite section, because the kernel's cache reaches no FAT mount. #587's undated paragraph is still true of `/tmp`, the one writable mount a kernel `dlopen` reaches, so the section stays for it, with #587's exit condition. - rust: c4c65e3e87a on ToyOSOrg/rust wt-toyos-fsd merges main's pin 90697f1401a with no conflict. Issues arriving with main, against this tree: - two-shared-members-assume-a-bcachefs-home-the-t14-does-not-have.md (#615) is deleted. Its premise is the kernel's tmpfs `/home` and `NvmeBacking`, and both are gone: on the T14 `/home` is fsd's bcachefs in memory. The T14 run at 27b5641 reads `fs_large_file` exit=0 and `home_backing_revoked` exit=0 beside fsd's "this machine has no DATA partition; ... are in memory" line. - the-last-handle-to-close-stamps-the-file-with-its-own-mtime.md is deleted. Its mechanism is the kernel write-back's last-close flush, which this branch deletes. `/tmp`'s mtime is the file's (`file_cache::touch`), and fsd's DATA keeps one mtime per node. What stays true of a handle's mtime is filed as a-kernel-files-fstat-answers-its-handles-mtime.md. - a-fat-files-mtime-reads-finer-through-its-writer-than-after-a-reopen.md is deleted. Its exit condition's second arm holds here: the kernel mounts no FAT volume a process writes. fsd's FAT reads the entry's stamp through a handle, which differs from a reopen's the other way. That is filed as a-fat-files-mtime-through-its-handle-is-its-last-level.md. - std-calls-undated-what-it-did-not-stat.md: the sentence that std reads an mtime only off SYS_FSTAT is deleted, since a served file's comes off fsd's stat. - tests/common/wallclock.rs: `mtime_boot`'s tmpfs guard looked for the kernel's "are a tmpfs", which nothing prints here. It reads fsd's `storage::IN_MEMORY` line instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs
#587's contract: a file's mtime is nanoseconds since the Unix epoch, UTC, DATA keeps the nanosecond, and 0 is undated. fsd stamped DATA with `clock_epoch()` times 10^9, whole seconds, so two writes to `/home` inside one second carried one mtime. It also read the clock a second time for FAT (`utc_secs`), with the same undated rule in another unit. - `fsd::volume::now_nanos` is the one reader. It derives the kernel's anchor exactly: `SYS_CLOCK_EPOCH` is `BOOT_SECS` plus the whole seconds of the counter at the call, and the process's clock page is the same counter on the kernel's formula, so a call bracketed by two readings inside one second names `BOOT_SECS`. A bracket that straddles a second is asked again, and three that straddle panic by name. The anchor is taken once: the kernel sets it once, before the first process. A refused clock is undated, 0. - FAT's volume takes the same clock and divides it, as main's `stamp(mtime_now())` did. `utc_secs` is deleted. - `file_mtime` judges `/home` too: two writes, the second strictly later, and not both whole seconds. `file_mtime undated` writes `/home` beside `/tmp` and requires both undated. - The host test `the_anchor_is_the_kernels` holds the derivation to the kernel's arithmetic, a straddled bracket included. - userlands-wall-clock-...md: the sentence that a file server can stamp only whole seconds is deleted; fsd stamps nanoseconds now. - home_overwrite_zero.rs: the comment that `fs::metadata` is the kernel's `file_cache::size` is deleted; `/home` is fsd's. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs
|
Mutation patches for round 19, head home-whole-seconds.patch: DATA stamps whole seconds, as `clock_epoch()·10⁹` did. Expect
|
Review, round 20, at 5337e79 (5337e79 and the merge 5d4174f of 8ee3c51)Gate.
Net lines (
Earlier findings (r19)
The merge 5d4174f: every conflict hunk is accounted for
The anchor, and the T14
BLOCKER
NOTE
REMOVE
SEND BACK 🤖 Generated with Claude Code |
Steps 5 to 7 of
issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.mdunder the owner's option B:/apps,/config,/home,/state,/logand/bootare served by/system/bin/fsd, one process per role (DATA, LOG, BOOT), and the kernel keeps ROOT in memory and/tmp. The kernel's NVMe driver, its read-write bcachefs adapter, its FAT32 adapter, every DATA,/bootand/logmount, and its write-back queue,iodand durability ledger are deleted.The owner accepted the gap this leaves: C programs reach no served path until libc is a client of the SDK's file-server crate (
issues/filesystem/c-programs-name-no-file-a-file-server-holds.mdstates the order).Decisions
CommandExt::prepare, which finds the program, judges the working directory and reads a program on a file server into atoyos::process::Image. The spawn on the loop then calls no file server. A relative working directory is refused before resolution.SpawnArgs::image), which the kernel pages it from, and only an object of ordinary memory the kernel allocated: a device aperture is refusedInvalidArgumentbefore anything else of the spawn is read. Its libraries come from/system/libalone (issues/filesystem/a-package-cannot-ship-its-own-libraries.md). dlopen from a memory object is not in the ABI, since nothing calls it until libc is a file-server client.toyos_abi::inventory::Record::Loaded(kind 6), the partition the loader named for a role (Role::Root,BootorLog) by its unique GUID, and blockd's--running <guid>, the running ROOT it serves no session on, which init passes from that record.toyos::syscap::SysCap::records, used by init and inspect). A refused count, a refused read and a record that does not decode are each the answer, never a shorter list. A machine that grew between the count and the read is asked again, at most four rounds, and one that grew on every round is refused by name. init's slot grant and a storage row's start read through it, so a storage row whose inventory is refused does not start, and says why; blockd is never started without--runningfor want of it.DIRTY_LIMITdirty blocks flushes first, and is refused whole when that flush is, so a disk that refuses leaves the cache no larger.home/a. On a volume whose free blocks are all apart, a file is refused at 250 blocks while blocks are free (issues/filesystem/a-file-on-data-is-refused-at-250-runs-while-blocks-are-free.md).SPREAD), so files growing in turn extend runs rather than alternate blocks.ResourceExhausted, said by name, and its allocations go back.syncwrites every file it can and names the ones it could not, so an fsync fails only for its own file. A close whose entry would not write answers the error and keeps the node, and each later sync names it again until it is written. The write-back (fsd::writeback::WriteBack) stays due after a sync that left a file unwritten. FAT's volume follows the same contract: a file that will not level is named, its close refused and its node kept, and each later sync names it again until it levels.Drive::Up, so nothing lists one without a controller.Service::listingandService::placeare the handshake's and the open's decisions:Drive::Absentlists nothing and opensNotFound,Drive::Unusablerefuses bothUnusable,Drive::ClaimRefusedrefuses bothClaimRefused, and fsd then says DATA is absent this boot rather than serving it from memory./tmp's pages are the file and ROOT is read-only, so the write-back queue,iod,durability.rsand its kernel-loom model are deleted. So are the file cache's dirt, pin, shrink mark and flush plan, the VFS's flush, sync and close surface,writeback-stall, the stop's sync,block::OpenUpdateand the scheduler'sMID_UPDATEbit.SYS_FSYNCanswers 0 on a kernel file; on a partition claim it is unchanged.toyos_quiesce::Record) is what a reader of the stop orders against.iod. With main's usbd,lognestandlog-stormgone too, klogd is the kernel's one thread in every build (MAX_KERNEL_TASKS = 1), andissues/kernel/the-kernel-still-creates-threads.mdloses K5.sched-operation-nesting's task half andsysret-ss-probeneed a task, and run once a boot on the first syscall, init's (syscall/dispatch.rs'stask_probes): the nesting gate in that task's own deadline slot as sitesyscall, and the SS probe's park, which switches away and back before that syscall'ssysretq.sysret_ss_reloadjudges the boot log alone, since init's first syscall precedes the ready marker.StaleNetworkFileHandle) and is never reopened by path. Exit:issues/filesystem/a-file-held-across-a-file-servers-restart-answers-gone.md.toyos_quiesce:FILES_MS(init's file-call bound),FLUSH_MSandSYNC_MS. The kernel's staged hold is their sum plusquiesce::PARK.BudgetExpired,RepairPending,RepairNoticeand the repair episode had no producer or caller once the kernel's FAT adapter went; logd'sWouldBlockflush retry goes with them.Holder::Claimcarries its GUID, and a claim's retried flush names its partition.iommu-userdev-foreign-dmastages a network function's first grant alone.Pid::MAX, which no writer has, so every writer leavesCHILD_KEEPslots. It names the program once the spawn returns its pid, before the ring goes to logd. logd writes no ring.--stallholds the stalled program's registration until--stall-untilinstead of skipping its reads. Solog_ring_keeps_the_owners_slotsholds whatever logd has done.--end-on <path>(a write),--end-at-read <path>(the first read-only open, once a boot),--end-at-mount <role>(that role's first server, once a connection waits on it and before it accepts one, once a boot) and--let-go-at-read <path>(the first read-only open, once a boot, syncs, lets the partition go and is refused; that client's next request ends the server).heap_ceiling_bounds' lowered bound is the machine's own live threads plus 16, counted at arming by the functionsys_sysinfocounts its roster with, so it moves with the daemons a boot runs rather than with a constant.NotFound(--claim-refused <name>, beside--running). blockd then servesDrive::ClaimRefused, whose listing and every open are refused with the new wire wordClaimRefused(6), and fsd serves DATA absent by name.NotFoundis a machine without the controller, and staysDrive::Absent.fsd::data::find). init claims every partition of a role the kernel's disks carry, and fsd counts those claims with blockd's TOYOS-DATA listing: none is memory, one is served, two or more are refused by name and DATA is absent. A listing blockd refuses leaves the count unknown, so DATA is absent then too, even beside a claim. A log or boot claim is by the loader's GUID, which the kernel refuses when two partitions carry it.sys_readandsys_writecharged a connection's wait toWaitClass::Pipe, and every file call is now a request on a connection and a wait for its reply. The class is chosen beside the pipe inops::pipe_readandops::pipe_write, whose matches name every object kind, so a new pipe-bearing kind does not compile without one. A bare pipe's wait staysPipe, the one classwatch-windowholds, so the canary's window is staged as before.StartError::Partitionin init's storage start. On a restart init closes the role's ports, as for any refused start; at boot it says the role did not start, closes its ports and goes on, where any other refused first start still panics init. Nothing serves the role's paths from memory, and fsd, never started with neither its claim nor its GUID, panics by name if it is.metaldevices::unmettakeslogd's whole file and judgesRECORDSagainst the kernel's records alone andBLOCKD_RECORDS(nvme,nvme-served) against blockd's own lines (bootlog::lines_of). A kernel line or another program saying blockd's words does not count, nor a program sayingBoot: complete (.blockd_writes_the_lines_its_table_readsholds the table touserland/blockd/src/main.rs, wheremainprints both lines.fsd::volume::now_nanos), which meets A file's mtime is wall-clock time: nanoseconds since the Unix epoch, UTC #587's contract: DATA keeps the nanosecond, FAT keeps the whole seconds of its level, and 0 is undated. The reader derives the kernel's anchorBOOT_SECSexactly, once:SYS_CLOCK_EPOCHis the anchor plus the whole seconds of the counter at the call, and the clock page is the same counter on the kernel's formula, so a call bracketed by two counter readings inside one second names it. A bracket that straddles a second is asked again, and three that straddle panic by name. FAT divides the same clock, and FAT stamps UTC. The kernel's/tmpstampsclock::mtime_nowat create, write andftruncate.The std fork:
ToyOSOrg/rustwt-toyos-fsdat c4c65e3e87a, which merges main's pin 90697f1401a into this branch's 1471893e39c with no conflict; over main's pin it is this branch's six std files alone.The merge of origin/main (a7cd327) is 1f96997. Its message says where each hunk of the two deleted issues went. The merge of origin/main (69d1b53) is e93d8c2, with no conflict; main's
rustpin had not moved, so the fork is unchanged. The merge of origin/main (ec06384) is b21e3dd. Main'srustpin had not moved, so the fork is unchanged there too. It had one modify/delete conflict: main disabledftruncate_flush_racebehindissues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.mdand gave that issue a status, a sighting, an exit and an owner. This branch deletes that test, with the kernel flush it raced and theftruncate-flush-stallactuator. So every one of those hunks is about a test that no longer exists: the issue stays deleted, and main'ssrc/redlist.rsrow for it goes too, because the harness refuses a row whose test nothing registers. That merge also brings #573'sforget_another_compiler, which meets the exit of this branch'sissues/build/a-worktrees-bootstrap-cache-outlives-a-compiler-rebuilt-at-the-same-version.md, so 069722c closes it. The merge of origin/main (ec0a91a) is 93435d5, with no conflict:tests/toyos.rsis the one file both sides change, and main's hunks there aremetal_sim_hostile_clipboardand a check inmetal_sim_client_death. Main'srustpin had not moved.The merge of origin/main (807f456, #564's measured schedule) is ead11ef; its message accounts for every conflicted hunk. Where #564 deleted a test or the kernel code only that test armed (
so_cache_refusalswithso-cache-tinyand theso_cache_policybinary this branch had moved onto/tmp;quiesce_wakes_on_the_last_exitandquiesce_dump_holds_the_stoppedwithquiesce-last-exitandquiesce-dump), the deletion stands: none of this branch's edits to them served a surviving test. Where this branch deleted a test #564 retiered, this branch's deletion stands, andissues/filesystem/home-budget-refusal-retried-is-red-on-every-nightly.mdstays deleted: its test is gone on both sides and the reproducer its exit names is the kernel's/homeover the NVMe driver this branch deletes. Every surviving row takes #564's tier. The five rows this branch adds,fsd_restart,fsd_end_at_mount,fsd_claim_held,fsd_two_dataandblockd_serves_nothing, keep the Fast tier they were added at, as #564 kept the tier of every row main added. Main'srustpin had not moved.The merge of origin/main (0368861, which brings #549, #562, #566, #581, #582, #584, #585, #591, #594, #595, #596 and #598) is 76e45e3. Its message accounts for every conflicted hunk. Main's
rustpin had not moved. Where main deleted what this branch had edited (src/heartbeat.rs,tests/doomcase, the swap-redial issue), main's deletion stands. Where this branch deleted what main edited (ftruncate_flush_race,quiesce_fsync, their issues, the root-metadata issue), this branch's deletion stands. Both sides wrote a roster decoder intests/toyos-rust-tests/src/roster.rs. Main's is kept, since it has no deadline, andprocess_stats' two connection arms read it. #562'siommu_*fault boots now wait for the fatal path's reset, and QEMU has exited by then. Sofault_boottakes aholdingread that runs before that wait, andiommu_empty_domainreads the xHCI'sDCBAAPover QMP there, while the panel holds. b607ce7 deletes thequiesce_leaves_the_volume_wholesighting fromissues/build/parallel-tests-red-under-other-suites.md.The merge of origin/main (d1d83f6, which brings #555, #583, #586, #593, #597, #600, #610 and #611) is 27b5641. Its message accounts for every conflicted hunk.
rustis 1471893e39c, which merges main's new pin with no conflict.kernel/src/fat32_adapter.rsstays deleted, and #583's UTC stamp is carried to fsd (the decision above). #586 met K3 of the kernel-threads track and this branch meets K5, so both go, and K6 waits on K2 and K4.The merge of origin/main (8ee3c51, which brings #587, #603, #614 and #615) is 5d4174f. Its message accounts for every conflicted hunk, and for the issues main brought that this tree makes false: #615's
two-shared-members-assume-a-bcachefs-home-the-t14-does-not-have.md,the-last-handle-to-close-stamps-the-file-with-its-own-mtime.mdanda-fat-files-mtime-reads-finer-through-its-writer-than-after-a-reopen.mdare deleted.Negative controls
Every patch the rows below name is in the PR comment of round 19 (issuecomment-5891368856). At 5337e79 each passes
git apply --check,cargo run -- --build-onlyexits 0 under it, andgit apply -Rleaves the tree clean. Arms marked "run by the orchestrator" are guest runs this branch's author did not make.fsd_restartfsd_end_at_mountcapability()connecting under the lock againfsdhostevery_file_reads_back_as_a_plain_map_of_its_accepted_writesbcachefs/srcanduserland/fsd/srcat 9b281ce, the test addedhome/a: 4096 bytes at 202574, of 200444 held,Err(ResourceExhausted)after the first write refused for want of blocksSPREAD = 2home/a: 4129 bytes at 1119843, refused past 250 pageshome/b: 4099 bytes at 1132859, refuseda_write_its_entry_could_not_name_is_refused_and_every_accepted_one_kept, and the map testlet _ = dropped;a_write_its_entry_could_not_name_is_refused_and_every_accepted_one_keptsyncwrites every file it canan_entry_refused_costs_only_its_own_filesyncreturns at the first refusalfsdhosta_file_that_will_not_level_costs_only_its_own_filesyncreturns at the first unlevel fileErr(Io), notOk([(1, Io)])return Err(e);deleted fromcloseOk(())r1-fat-sync-releases.patch)toyoshostsyscap::tests::a_machine_that_grew_once_is_read_grownanda_machine_that_grows_every_round_is_refused_by_nameResourceExhausted => continuearm deleted (b2-no-retry.patch)Err(Read(ResourceExhausted))against the grown list atsyscap.rs:274, and againstErr(Grew)at:289fsdhostat_the_dirty_limit_a_refused_flush_refuses_the_write_and_the_cache_grows_no_largerCache::writeas at b6bcd1e (r3-cache-old-write.patch)/system/libaloneabuse_elf_loader(Fast)red-arm-image-libs-beside.patch)536m-red-abuse.log:32–34), at fae0a5d (536r12-red-arm-image-libs-beside.log:39) and at 06c6195 (536r14-abuse.log:39), by the orchestrator:export_past_image as an image,Err(InvalidArgument)againstErr(NotFound). The first assert ends the process, sotpoff_overflow_spawn's image arm under the mutation is unmeasuredheap_ceiling_bounds(nightly)false && …(b1-control.patch)536r12-b1-control.log:39,536r14-heap-b1.log:39): "64 extra threads and sysinfo never refused"fsd_claim_held(Fast)claim-say-and-continue.patch)536r13-b3.log:47,536r14-claim-say.log:46): the guest's second open answeredNotFound, "not Gone", the restarted server having found no DATA and serving memoryiommu_virtio_platform(nightly), its no-unit armDrive::Absent(b1-refused-claim-absent.patch)536r14-b1.log:34): fsd's(Refused(ClaimRefused)); DATA is absent this bootnever reached the boot consolefsd_two_data(Fast)b2-kernel-claim-uncounted.patch)536r14-b2.log:33):this machine has 2 DATA partitions, 1 on the kernel's disks and 1 the block service servesnever reached the consoleprocess_stats(Fast),a_wait_on_a_connection_is_ipcipc-class-reverted536r15-ipc-reverted.log:45): "charged 0 ns to ipc and 2345422 ns to pipe"; EXIT=1 at 0baa8b3, by the orchestratorprocess_stats(Fast),a_wait_to_write_a_full_connection_is_ipcwrite-class-pipefsdhostdata_is_one_partition_counted_over_both_sourcesClaimed(h1-find-guesses.patch)home_overwrite_reads_back(Nightly)self.sync_files()deleted (b3-no-stop-sync)536r14-b3.log): "the NVMe image does not mount on the host: BadMagic { … got: [0, 0, 0, 0] }". That red says nothing fsd wrote that boot reached the device, the volume's format included. An absent format would red the same way, so it did not name the lost file. The guest now fsyncs/home/overwrite-looped.binbefore the pinned overwrite, so the format is on the device and only the stop's sync carries the pinned file there. At 069722c EXIT=1, by the orchestrator (536r15-b3.log:35): "reading home/overwrite-pinned.bin off the image: NotFound"blockdhostan_unusable_or_unclaimed_controller_is_refused_and_an_absent_one_lists_nothinglisting'sUnusablearm folded intoAbsent's;place's answeringNotFound;listing'sClaimRefusedarm answeringOk([])(h2-unclaimed-lists-nothing.patch)Ok([])andErr(NotFound)againstErr(Unusable);Ok([])againstErr(ClaimRefused)nvme_wide_sectorlisting'sUnusablearm folded intoAbsent'sfsdhosta_sync_that_left_a_file_unwritten_is_due_againsyncedforgets the write-backNoneagainstSome(2s)bcachefsa_split_short_of_a_sibling_gives_back_the_ones_it_tooka_refused_rename_over_an_open_file_keeps_its_unsynced_writesblockd_serves_nothingserve_nothingrestoreda listing that carries a payload was answered 5 None in 0 bytes, not 3 Some(Malformed)blockd_dma_outside_the_lent(Weekly since #564)|| object.ram().is_none()deleted fromSharedImage::overa spawn from the register window was answered Err(BadAddress)userdev_dma_faultowner=slot0for a function on slot 1log_flush_retrystaged_spentrefuses every first attemptlog_ring_keeps_the_owners_slots/log===TEST_END test_rs_log_flood exit=0===operation_nestingOperation::beginstores the asked deadline unnarrowed when a task is currentsyscall: level 3 asked for 4000000000 ns and the depth inside it recovered 4000000000 ns, against the 250000000 nssysret_ss_reloadmov ssinKernelHw::switchdeletedsysret-ss: NOT reloadedfile_mtime(Fast), its/homearmuserland/fsd/srcas at 27b5641 (fsd-clock-reverted)home-whole-secondsfile_mtime_undated(Nightly)home-undated-boot-nanos)/tmpstampsmtime_nowfile_mtime(Fast)site-114,m132-ops,m821-opsfile_mtime(Fast), its/logarmm926-fat-secondswall_clock_utc(Weekly)utc-plus-7200)fsdhostthe_anchor_is_the_kernels,a_clock_that_always_straddles_is_refused_by_nameanchor-no-retry)Some(2000000001)againstSome(2000000000), and "test did not panic as expected"Independent oracles:
HashMapof what each accepted write made each file, against DATA's volume read back after a remount (every_file_reads_back_as_a_plain_map_of_its_accepted_writes): no line of it is the writer's;toyos-fat32-check's own fixture, buta_file_that_will_not_level_costs_only_its_own_filereads its verdict back through the driver under test (v.lstat). The independent reader of FAT this branch writes islog_flush_retry(fatfsandtoyos-fat32-checkover the log partition), a nightly the orchestrator runs;SYS_SPAWN's order, image before argv: the same spawn from a RAM region answersBadAddress, soInvalidArgumentfrom the BAR object is the image refused;userdev_dma_fault);usb_transport_break,log_flush_retry);log_ring_keeps_the_owners_slots), where logd reported "1919 of its ring's 1919 records waiting". The green count is the ring's own arithmetic: 1853 = 1919 shared slots − 64 kept − test-runner's 2 lines.abuse_elf_loader): the kernel's own lines,export_past_image: ELF: a defined symbol's value is outside the imageon the path route andexport_past_image: failed to load export_dep.so: not foundon the image route, which is the answer the image arm now asserts;heap_ceiling_boundsEXIT=1): quiescecase's stop census counts 19 userland threads (536m-fast.log:861) against 10 on Kernel: every kernel panic halts and panic recovery is deleted; delete usbd; open the no-kernel-threads track (K1) #553 r4, so a constant bound of 16 was spent before the test spawned anything;SysCap::recordsby init's storage start and, in theupdate_*tests, by its slot grant;-rtc base=, read back off the image by the host's ownbcachefsreader (file_mtime_survives_a_reboot) and by the host's FAT reader (wall_clock_utc); and the kernel's arithmetic for the anchor (the_anchor_is_the_kernels).Gates, at 5337e79
cargo run -- --ci hostEXIT=0, "Host: 55 step(s), all green". That covers the build system's lib tests,toyos-checks, the host workspace, the licences, clippy with warnings denied, and every userland crate's host suite,fsdandblockdincluded.cargo run -- --build-onlyEXIT=0.cargo test --test toyos-build -- --listEXIT=0: 252 Fast, 144 Nightly, 108 Weekly and 3 Local; 20 disabled.git -C rust statusis clean, and therustgitlink is c4c65e3e87a, the commit pushed towt-toyos-fsd.Guest runs, by the orchestrator
At b6bcd1e:
fsd_end_at_mountEXIT=0 and EXIT=1 under its fork red arm;nvme_large_device,quiesce_refuses_a_second_shutdownandblockd_serves_nothingEXIT=0;nvme_wide_sectorEXIT=0 and EXIT=1 under its red arm; the nightlyblockd_dma_outside_the_lentEXIT=0.At bfb1763 (
orch-runs/536m-*.log): EXIT=0 for the sevenupdate_*, the fourblockd_*nightlies and the six panic-path rows. The Fast tier EXIT=1, 395 passed and 3 failed, all three main's:lan_mdns_answer(path must be shorter than SUN_LEN, fixed by #560), andlan_swapandswap_crash_rolls_back(the redial turned away 64 times while the guest finished, which #565 disables).heap_ceiling_boundsEXIT=1, this branch's, fixed at 4aef9a0. The red arm EXIT=1, as the table says.At fae0a5d (
orch-runs/536r12-*.log):fsd_claim_heldalone and the nightlyheap_ceiling_boundsEXIT=0, and the three guest arms EXIT=1, as the table says. The Fast tier EXIT=1, 400 passed and 2 failed, both this branch's:fs_claim_heldran on the shared boot and exited 101, andsuite_splitnamed it driven by a machine test and also shared. 5235eda puts it onRUST_SKIP.partition_claim,boot_partition_identityandpartition_claim_gives_up, which boot with a role's claim refused and so with that role absent, passed in it.At 5235eda (
orch-runs/536r13-*.log):fsd_claim_heldand the nightlyheap_ceiling_boundsEXIT=0, and the b3, b1 and abuse arms EXIT=1. Fast EXIT=1, 400 passed and 1 failed:blocking_read_window, main's filed flake (issues/build/blocking-read-window-reds-beside-other-guests.md). The full nightly EXIT=1, 513 passed and 2 failed: that flake, andiommu_virtio_platform, this branch's, which 06c6195 answers.At 06c6195 (
orch-runs/536r14-*.log,ab-brw-*.log):iommu_virtio_platform,fsd_two_data,home_overwrite_reads_back,fsd_claim_heldandheap_ceiling_boundsEXIT=0, and every guest arm EXIT=1, as the table says. Fast EXIT=0, 401 of 401. The full nightly EXIT=1, 515 passed and 1 failed:syscall_window_nmi, "36 sprayed window arrivals against 557 in Ring 3". That red is main's:kernel/src/archthis branch changes only the VT-d unit (vtd/domain.rs,vtd/mod.rs). It does not touch the NMI gate (nmi_gate.rs), the syscall entry, the test's binary (nmi_window_spin.rs) or its judge intests/common/faults.rs;issues/kernel/syscall-window-nmi-shortfalls-on-a-contended-host.md("44 window arrivals against 572");557r2-fast.log) is red on it too, with 25 in the window;blocking_read_windowwas red 2 of 10 at 06c6195 against 0 of 10 on main at cd2e630, interleaved in one session (ab-brw-536-7.log:35: "only 27 of 500 round trips completed inside 3s").At 069722c (
orch-runs/536r15-*.log):process_statsandhome_overwrite_reads_backEXIT=0, and their arms EXIT=1, as the table says.blocking_read_windowwas red 0 of 10 against 0 of 10 on main. Fast EXIT=0, 399 of 399. The full nightly EXIT=1, 512 of 514, both reds main's:syscall_window_nmi, whose storm boots withoutwatch-windowand whose arrivalsnmi_gate::observeclasses from the interrupted frame alone, so no wait class reaches it; anduser_copy_races_munmap, thecopy-meets-a-remapactuator's own bound, red on #562 too and disabled by #580. The orchestrator'sheap_ceiling_boundslog keeps only the harness's PASS line, so the machine's live thread count at arming is not recorded.At 0baa8b3 (
536r16):process_statsEXIT=0, and EXIT=1 under each ofwrite-class-pipeandipc-class-reverted, as the table says. Fast EXIT=0, 400 of 400. The full nightly EXIT=0, 515 of 515.At d5bbfbb (
orch-runs/536m-*.log):process_stats(Fast) EXIT=0;quiesce_refuses_a_second_shutdown(nightly) EXIT=0; the eleven--weeklyrows EXIT=0:home_overwrite_reads_back,blockd_dma_outside_the_lent,block_duplicate_id,late_storage_connect,log_partition_layout,log_partition_identity,root_candidate_malformed,root_named_but_absent,root_named_twice,sysret_ss_reloadandblockd_lends_within_its_bound. Fast EXIT=0, 240 of 240 (536m-fast.log:937). The full nightly EXIT=0, 383 of 383 (536m-nightly.log:1102). Theb3-no-stop-syncarm EXIT=1 (536m-b3.log:31): "reading home/overwrite-pinned.bin off the image: NotFound".At 806da12:
cargo test --lib -- metaldevicesEXIT=0, 8 of 8. Two mutations ofunmet's blockd reader, each shown to build: reading the kernel's records (the reading the T14 was judged with) EXIT=101, and reading the whole log unfiltered EXIT=101, both ineach_record_has_teeth. The oracle is the recorded T14 readback (target/metal/metaldevicecase), run through both readings as a temporary test and restored: the old reading returns exactly the T14's one finding,nvme: no record carries "blockd: no NVMe controller this row names is on this machine", and the new one returns none.cargo run -- --ci hostwas not run at 806da12.Owed at 5337e79, by the orchestrator:
file_mtime(Fast) EXIT=0, and EXIT=1 under each offsd-clock-reverted,home-whole-seconds,site-114,m132-ops,m821-opsandm926-fat-seconds;--nightly file_mtime_undatedEXIT=0, and EXIT=1 underhome-undated-boot-nanos;--nightly file_mtime_survives_a_rebootEXIT=0 on fsd's DATA;--weekly wall_clock_utcEXIT=0, and EXIT=1 underutc-plus-7200;--nightly home_overwrite_reads_backEXIT=0, and EXIT=1 underb3-no-stop-sync;process_stats(Fast) EXIT=0, and EXIT=1 under each ofipc-class-revertedandwrite-class-pipe;fs_large_fileandhome_backing_revokedexit 0, as at 27b5641, where Triage main's T14 metal reds: issues only, no redlist rows #615 had them red on main.Unsure
iommu_empty_domain's QMP read of the xHCI'sDCBAAPraces the fatal path'spanic-reboot-fasthold, which is 5 s on the guest's clock (kernel/src/panic_reboot.rs'sFAST_BOUND). Three monitor round trips fit inside it on an idle host. If the reset comes first, QEMU is gone and the read fails loudly. Nothing waits on a guest event there.tests/logstallcasehas nopowerand noshutdownsince No QEMU test measures time, and audio is judged on metal only #562, and its/logis fsd's now.soundd_log_stall's metal row reads its verdict off a/logthat only fsd's write-back puts on the stick.fs_turns' floor is one pass: the barging lock left the others at one, and a thread kept off-CPU for 31 of the first thread's turns reds it too (issues/filesystem/fs-turns-judges-the-scheduler-with-the-lock.md).file_cache::touch) is checked by no test.Syncing filesystems...,flush_file) are left as their authors wrote them./bootview: every program keepsfs:/boot(read-only), becauseesp_filesand the metal tests read it; the track wants it to be the updater's alone.a_placeholder_owned_ring_keeps_its_slots_from_every_pid_until_named, throughRing::lay_out_with_placeholder_owner, the one function init and the test call): EXIT=0, and EXIT=101 with the owner mutated toown(0).SPREAD = 2and cursor-only arms, each refused past 250 pages.sync_files,home_overwrite_reads_backis green only if fsd's 2 s write-back fires between the guest's last write and the stop. That write-back is due from the pinned file's first write, the first one after the guest's fsync. The test took 3 s whole at 06c6195, boot included; no test pins the window.fsd_claim_heldand thepartition_claimandpartition_claim_gives_upboots stage DATA on a stick and so give the NVMe controller a disk with no table (partclaim::tableless_nvme); the lane's blank NVMe image carries a second DATA, and two are now refused.faults::refused_claimtakes the other functions a machine refuses (beside), which only the no-unit arm names: 00:02.0, the NVMe controllertests/netcase's blockd row claims.issues/filesystem/the-tmpfs-fallback-for-apps-and-home-has-no-judge.mdstill describes the kernel'sopen_data, which this branch deletes, and says two DATA partitions land on memory, which is now false. Left as its author wrote it.fsd_claim_heldorders the claim against init's restart through the server's own actuator: the server is gone from the claim before the guest asks for it, and ends only on that guest's next request. Another client's request in between is answered by the absent volume and does not end it.Size
git diff --shortstat origin/main...HEADat b607ce7: 275 files, +10425 −10032. By path, fromgit diff --numstat:tests/+2769 −3004;toyos-fat32/tests,kernel-loom) +28 −339;src/+35 −81;issues/+664 −673;#[cfg(test)]modules included. Of that, the kernel is +623 −5007 and userland +5019 −653.The fork: +715 −189 over main's pin (
git -C rust diff --shortstat 9c3eea441d8 1471893e39c).Filed, known and still true
issues/filesystem/a-file-held-across-a-file-servers-restart-answers-gone.mdissues/filesystem/one-write-far-past-a-files-end-holds-data-s-server.mdissues/filesystem/a-file-server-maps-a-lent-window-at-the-size-it-expects.mdissues/filesystem/every-flush-of-a-served-file-syncs-its-whole-volume.mdissues/filesystem/create-new-on-a-kernel-path-is-not-exclusive.mdissues/filesystem/the-logs-server-ending-under-logds-append-is-unmeasured.mdissues/filesystem/a-served-directory-costs-each-process-a-two-mebibyte-window.mdissues/isolation/a-file-server-can-open-every-partition-blockd-serves.mdissues/isolation/one-program-can-take-every-file-servers-client-slot.md, held by the orchestrator, streams includedissues/filesystem/c-programs-name-no-file-a-file-server-holds.mdissues/filesystem/a-package-cannot-ship-its-own-libraries.mdissues/filesystem/a-file-server-killed-mid-sync-leaves-a-half-written-btree.mdissues/filesystem/a-link-on-a-kernel-mount-to-a-served-path-leads-nowhere.mdissues/filesystem/fs-turns-judges-the-scheduler-with-the-lock.mdissues/boot-media/an-image-on-a-disk-blockd-drives-cannot-write-its-slots.mdissues/kernel/two-completions-can-name-one-arrival-and-accept-parks.mdissues/hardware/metalprobes-usb-read-is-answered-from-fsds-cache.mdissues/filesystem/a-cached-read-from-a-file-server-is-measured-only-under-tcg.mdissues/filesystem/a-file-on-data-is-refused-at-250-runs-while-blocks-are-free.mdissues/filesystem/a-served-file-panics-when-asked-its-raw-fd.mdissues/filesystem/dir-symlink-skips-the-reconnect-every-other-path-call-makes.mdissues/filesystem/a-write-back-the-device-refused-waits-for-the-next-write.mdissues/build/needs-actuators-names-lower-sysinfo-bound-as-a-payload-action.mdissues/filesystem/a-foreign-data-partition-is-answered-with-memory.md: a TOYOS-DATA partition with neither our volume nor a designation stamp still serves DATA from memoryissues/kernel/watch-window-spins-out-a-hold-its-poster-is-queued-behind.md: awatch-windowhold spins out its 50 ms when the task that would post is queued behind it on the same CPUissues/filesystem/a-kernel-files-fstat-answers-its-handles-mtime.mdissues/filesystem/a-fat-files-mtime-through-its-handle-is-its-last-level.mdissues/filesystem/an-undated-file-on-fat-reads-back-as-1980.md, main's, now of fsd's FAT stamp🤖 Generated with Claude Code
https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs