Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
4ab674b
update tests: reboot through the power connector, and bounds from wha…
Japabu Sep 27, 2026
3dc1f71
nightly-red: red on a registration red two nightlies running
Japabu Sep 27, 2026
40dd2f5
harness: sysret_ss_reload waits on its report, and a one-wide run rer…
Japabu Sep 27, 2026
bfe1199
Drop the red-streak gate and the update waits' derived bounds
Japabu Sep 27, 2026
cb008fa
redlist: a disabled list replaces the quarantine
Japabu Sep 27, 2026
72d8db5
redlist round 2: every disabled row's issue carries its exit conditio…
Japabu Sep 27, 2026
7befb95
Merge remote-tracking branch 'origin/main' into wt/toyos-testwins
Japabu Sep 27, 2026
7974763
Round 3: cut the dead ALONE arm in ci.rs::verdicts and every rewritte…
Japabu Sep 27, 2026
059c5de
qemu.rs: delete the investigation story naming the ALONE verdict
Japabu Sep 27, 2026
dd9f75f
Merge remote-tracking branch 'origin/main' into wt/toyos-testwins
Japabu Sep 27, 2026
b1aeafe
redlist: five reds disabled with their issues, four of them from nigh…
Japabu Sep 27, 2026
7e8cf34
shipped_config_boots waits for init's lines; every disabled test's ex…
Japabu Sep 27, 2026
22d6f42
issues: the STALL summary tells the reader to re-run a red
Japabu Sep 27, 2026
58f1c35
tests: a STALL is a red; the summary no longer says re-run
Japabu Sep 27, 2026
d97d93c
tests: cut stale prose the round-5 review named, and name the orchest…
Japabu Sep 27, 2026
126a594
Merge remote-tracking branch 'origin/main' into wt/toyos-testwins
Japabu Sep 27, 2026
a3c0591
CLAUDE.md files: no instruction to re-run a red is left
Japabu Sep 27, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,6 @@ command. An estimate says it is one. -->

## Anything a reader of `main` must not miss
<!--
A known red this leaves behind, a `src/redlist.rs` quarantine row it adds, an
A known red this leaves behind, a test it disables in `src/redlist.rs`, an
`issues/` file it closes or invalidates.
-->
4 changes: 2 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ The bar is not yet the tree. The standing failures are declared rather than remo

## Build & test

The testing rules live where they are enforced: instruments and known reds in `src/redlist.rs`, tiers in `src/tiers.rs`, the PR gate and the nightly in `.github/workflows/`. Operationally:
The testing rules live where they are enforced: known reds in `src/redlist.rs`, tiers in `src/tiers.rs`, the PR gate and the nightly in `.github/workflows/`. Operationally:

- `cargo run` builds everything (toolchain, kernel, bootloader, userland, image) and launches QEMU; `--build-only` skips the launch. `cargo test` runs the QEMU harness; `cargo test --workspace --exclude toyos-build` runs every host-crate suite.
- **Agents verify through `cargo test`, never `cargo run`** — the run path opens a QEMU window on the owner's desktop by design; the harness runs headless.
Expand Down Expand Up @@ -119,7 +119,7 @@ system.toml What to build and boot
- **Every written number comes from a command that was run.** An estimate or datasheet bound says so. Write commit messages with `git commit -F <file>`, never `-m` — a double-quoted `-m` substitutes backticks and the shell runs them.
- **Commit freely on your branch; land through a pull request.** `main` moves only through a merged PR, and `cargo run -- --pr` is the whole local half. `gh pr create --draft` at the first push — CI runs on PRs and nothing else; `gh pr ready` plus a written `--title`/`--body-file` when finished (never `--fill`); `gh pr merge --auto --merge` enqueues on `main`'s required merge queue, which builds each merge's exact composition and runs the required checks on it before `main` moves; `cargo run -- --sync` after it lands. Never merge into `main` by hand; `gate-stage` reads the protection back. The PR's title and body become the merge commit's: write them as main's record. A modify/delete conflict is resolved by accounting for every hunk of the modified side, never by checking its headings survived. A merge that deletes a document also deletes every citation to it in the same merge, checked by searching the bare name as well as the path. An ABI change lands with the work that needs it: every worktree builds the toolchain its own sources name, so branches that change the ABI run side by side and none waits on another. Every merge leaves `main`'s tip compiling. A branch lands after a review against `.claude/agents/reviewer.md`, spawned by the orchestrator with its brief and judged by it.
- **Never rewrite history, and never touch `main`.** No `--amend`, no `rebase`, no `--force` — on your own branch as much as anywhere: a pushed hash may already be cited. `main` is protected — PR required, no force-push, no deletion, no bypass.
- **A red is known only if `cargo run -- --known-red <test>` says so** (`src/redlist.rs`). A PR red not about the author's diff is adjudicated there and fixed at its owner, never re-run away.
- **A red test is a defect unless `src/redlist.rs` disables it with its issue (`cargo run -- --known-red <test>`); a flaky test is disabled at once, never re-run.**
- **A high-risk change names its two checks.** Security boundaries, the scheduler, the ABI, filesystems, devices, memory management, concurrency primitives: the PR names the negative control or mutation that fails if the implementation is wrong, and one epistemically independent oracle — an external specification, a differential implementation, real hardware, a third-party checker, a formal model, or a recorded real failure. A second agent is not independence: five artifacts from one wrong model still agree. A mutation is a negative control only if it reverts the *whole* change onto the base the green arm was measured on — a one-line revert of a change that moved two things measures neither.
- **Host load is not an excuse.** A load-coincident audio failure is investigated as a real defect, never re-run away as noise; evidence against that assumption goes to the owner, not into quiet workarounds.
- **Subagents wait in the foreground** — background notifications do not reliably re-wake them: explicit `timeout`s, and for longer work background once and block with a few long foreground waits, polling before each sleep.
Expand Down
4 changes: 2 additions & 2 deletions issues/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ Four fields, three required, no defaults.
|---|---|---|
| `status` | `open` | it is work, and nobody is holding it |
| | `assigned` | it is work, and somebody is — the body says who or which task |
| | `expected-red` | a test fails on this today and `src/redlist.rs` quarantines it |
| | `expected-red` | a test fails on this today and `src/redlist.rs` disables it |
| | `owner` | it is the owner's to decide, and nobody else may |
| | `none` | nothing is owed |
| `kind` | `defect` | real, reproducible, someone should fix it |
Expand Down Expand Up @@ -138,7 +138,7 @@ checkout (`git grep <rev>`): `rg` skips dotfile directories without `--hidden`,
and `.github/` holds citations too. Then read where the hits are. One in a comment
under `toyos-abi/src`, `toyos/src` or a published crate changes no identity
(`src/identity.rs`), so it owes no version and builds no sysroot. One in
`src/redlist.rs` is a quarantine row's `issue`: the row goes with the file.
`src/redlist.rs` is a disabled test's `issue`: the row goes with the file.

## Two area notes, carried over from the file this replaced

Expand Down
9 changes: 4 additions & 5 deletions issues/audio/doom-sound-flood-played-full-scale-once.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
status: open
status: expected-red
kind: defect
opened: 2026-09-04
---
Expand Down Expand Up @@ -36,7 +36,6 @@ whether it is the mixer's sum overflowing or the analysis reading a wrapped
value, and whether a listener would hear it. Nothing in the captured line
distinguishes those, and the WAV that would is not kept by a CI job.

**Exit condition.** A run that reproduces the peak with the capture retained,
and one sentence naming which of the three it is. `src/redlist.rs` carries the
rate (1 of the 3 nightlies of that week); the two rows for this name that were
about `timed out after 88s` are retired on the change of shape.
**Exit condition.** The full-scale sample's cause is fixed, and
`doom_sound_flood` green on the KVM `guest` shards where it went red. Owner:
orchestrator.
11 changes: 6 additions & 5 deletions issues/audio/hda-tone-phase-check.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,10 @@ task: 88

# HDA: the captured tone is not one sine

**This is the write-up `tests/toyos.rs`'s `EXPECTED_FAILURES` names for `hda_tone`.** Do not delete it without moving that pointer.

`hda_tone` plays the same 3.0 s 440 Hz tone the virtio arm plays, out of an
`intel-hda` controller soundd drives itself, and the capture comes back with
**8 to 16 phase discontinuities** where the virtio arm has none. Declared in
`EXPECTED_FAILURES` against the message "the captured tone is not one sine";
every other assertion that test makes still reds the run.
**8 to 16 phase discontinuities** where the virtio arm has none. Every other
assertion that test makes still reds the run.

What is *not* wrong, measured on this host (QEMU 11.0.3, 2026-08-07): the tone
is present at full amplitude, there is **no mid-tone silence at all** (`gaps
Expand Down Expand Up @@ -103,3 +100,7 @@ fresh one holds 139,253-142,325 of the 144,256 submitted frames, so the
adjacent-frame *pairs* with |period| in the hundreds, not the 118-frame
clusters. And the load dependence is sharp where it used to be a correlation:
0 of 8 alone against 3 of 11 beside other guests, same tree, same hour.

**Exit condition.** The adjacent-frame-pair breaks' cause is fixed, and
`hda_tone` reads 0 phase breaks beside other guests on the dev host and on
CI's KVM shards. Owner: orchestrator.
20 changes: 4 additions & 16 deletions issues/audio/hda-tone-red-beyond-its-exemption.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,23 +15,11 @@ FAIL hda_tone: 1 mid-tone silences in the capture: total 1 [1p×1]
the entry covers ["the captured tone is not one sine"]
```

The `EXPECTED_FAILURES` entry does what it is supposed to: it pins the assertion
rather than the test, so a *second* defect in the same test still reds the run
and says which. What is red is the mid-tone-silence assertion — a gap in the
capture, which is gate A's harm verdict — and not #88's spectral one. The entry
still says so at the site: it names only `"the captured tone is not one sine"`,
beside a comment listing "no mid-tone silence" among the things that red the run
"because each of those is the milestone rather than the open question".
**What has changed since, and what has not.** `hda_tone` is `Tier::Nightly` for
`Why::TimerAnchored` (`src/tiers.rs`), so a plain `cargo test` no longer runs
it and a landing whose gate is `cargo test` no longer meets this red at all.

**What has changed since, and what has not.** Two things narrow the harm this
was filed for. `hda_tone` is `Tier::Nightly` for `Why::TimerAnchored`
(`src/tiers.rs`), so a plain `cargo test` no longer runs it and a landing whose
gate is `cargo test` no longer meets this red at all; and `src/redlist.rs`
carries rows for the name — the dev-host-alone one sourced here retired on
3 of 3 green alone on 2026-09-04, and one at 4 of 5 on CI — so an agent who
does meet it is told whose it is rather than reading it as theirs.

Neither touches the verdict, and the verdict was owed a fresh sample: every
That doesn't touch the verdict, and the verdict was owed a fresh sample: every
capture behind it had gone through QEMU's 48000→44100 resampler, since removed.

**Re-judged 2026-08-29, and it stands.** On the current instrument (QEMU
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,11 +53,6 @@ nothing could see an idle wake when this was filed. The 2026-08-29 section
below is that instrument existing; a red taken since then decides the split by
itself.

Not on `src/redlist.rs` — `cargo run -- --known-red audio_idle_suspend` answers
`NOT ON THE LIST`. Adjudicating it there needs the rate above and a decision
about whether the row records a soundd defect or a `Sched::Parallel`
misclassification, and those are not the same row.

Gate A is unaffected and green throughout: `audio_tone` and `audio_tone_load` at
smp=1 and smp=8 all pass on `cf72c3dc` with 440.0 Hz, phase-breaks 0, gaps none,
0 underruns and 0 drains.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,7 @@ paid at 1.55x width
```

`cargo run -- --known-red kernel_log_file` answered `NOT ON THE LIST` when this
was filed and answers `KNOWN-RED` now: `src/redlist.rs` carries a row for the
name, sourced here, `Finding::Seen` with `no rate`. So the next reader of the
name gets the sighting instead of silence — but the row records the same single
observation this file does, and a `Seen` with no rate is what it says it is.
What is owed is unchanged and is the rate.
was filed. What is owed is unchanged and is the rate.

**The company is recorded, because the runner is the instrument.** A second
agent's `cargo test --workspace` was running in `toyos-banner` on the same
Expand All @@ -50,7 +46,5 @@ deletion of an unreachable `if rflags & TF != 0` branch in

## Promoted 2026-08-25

A known-red test with a `Seen`-and-no-rate row is real, owed work: the
`src/redlist.rs` row still records the single observation this file does.
Owed to whoever next runs a session free to measure the rate against an
unchanged tree.
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ is known fixed by that work.

Re-measure `log_flush_retry` (wide and alone) enough times, on a tree that
carries ROOT-in-memory, to say whether either mode still occurs; if seen
again, a `src/redlist.rs` row carries it with a measured rate, or it is fixed
at its owner (`kernel/src/drivers/xhci` for the transport line, the boot
again, it is disabled with a `src/redlist.rs` row and this file, or it is
fixed at its owner (`kernel/src/drivers/xhci` for the transport line, the boot
harness for the timeout). If not seen in that many runs, this file closes with
the count that supports it.
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
status: open
status: expected-red
kind: defect
opened: 2026-09-05
---
Expand All @@ -24,8 +24,12 @@ Two facts the log holds. test-runner was spawned at 0.635 s and its first act
is to print `===READY===`, which never reached the console in 31 s. The
SYNCHRONIZE CACHE (0x35) the boot issued to the USB disk got no status-phase
answer in 2000 ms and the transport was declared broken at 2.718 s. Whether the
second stalls the first is the question; the redlist row
(`src/redlist.rs`, `screen_fatal_halt`, `Instrument::Ci`) records the one
observation, and this file is its owner's: the usb-storage wait path
(`kernel/src/drivers/xhci/wait/msc.rs`) and whatever the runner's stdout
blocked on.
second stalls the first is the question, and this file is its owner's: the
usb-storage wait path (`kernel/src/drivers/xhci/wait/msc.rs`) and whatever the
runner's stdout blocked on.

**Exit condition.** Re-enabled when a reproduction pins whether the boot
runner's stdout was blocked behind the usb-storage transport break or the two
are independent, and the wait path stops holding the runner's own output
hostage. Owner: the usb-storage wait path,
`kernel/src/drivers/xhci/wait/msc.rs`; held by the orchestrator.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
---
status: expected-red
kind: defect
opened: 2026-08-20
---

# `console_line_atomicity` loses five of a thousand lines on CI, one guest per machine

First sighting on the CI instrument: PR #166 run `32364721784`, `guest (10)`,
`writer A declared 1000 whole lines and the capture carries 995`, `ALONE:
GREEN` in the same job. The diff it rode on is an issues-and-prose audit, so
the tree is not a suspect.

CI runs one guest per machine with `--jobs 1`, so whatever loses five of a
writer's thousand lines there is not host contention between suites — which
sharpens the question the test was built to ask rather than settling it: the
loss is inside one guest's own console path.

Split out of `issues/build/parallel-tests-red-under-other-suites.md`, whose
rate table was never this test's — CI's single-guest-per-machine shards rule
out the contention shape that file is about.

**Exit condition.** The lost lines' cause is fixed, and
`console_line_atomicity` green on CI's `guest` shards, one guest per machine.
Owner: orchestrator.
16 changes: 9 additions & 7 deletions issues/build/latency-wake-reds-on-the-dev-host-at-a-rate.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
status: open
status: expected-red
kind: finding
opened: 2026-09-07
---
Expand Down Expand Up @@ -28,9 +28,11 @@ A seventh sighting, in the whole-branch review's twelve-wide `cargo test` on
7294acef: `258 past the 4096us histogram`, and the harness's own isolated re-run
green.

So this is a rate on this host, not a classification and not a regression. The
rate is on the list — two `src/redlist.rs` rows under this name, `FIRES 1 of 6`
alone and one `SEEN` under load, both citing this file. What is still owed is
the other reading of the same evidence: whether cyclictest's 4,096-bucket
histogram is simply too low for a TCG guest on a loaded laptop, which is a
change to the instrument and not to the kernel.
What is still owed is the other reading of the same evidence: whether
cyclictest's 4,096-bucket histogram is simply too low for a TCG guest on a
loaded laptop, which is a change to the instrument and not to the kernel.

**Exit condition.** Re-enabled when the base's p99 is shown to genuinely
exceed 4096 us and that is fixed at the timer-interrupt entry the deadline arm
already touches. Owner: the boot-deadline work (`kernel/src/sched`'s
timer-interrupt entry); held by the orchestrator.
Loading
Loading