A boot's sockets are a TempDir under /tmp, reclaimed like all scratch; disable partition_claim_departure and i8042_mouse - #560
Conversation
…fusals, beside other guests Nightly run 36336701867, job guest (5), on PR #541's head 1c0f0c7, whose diff touches none of the partition-claim code: the departure role's guest_verdict failed with an empty stdout capture and exit 0, re-ran green alone immediately after. Same "reds beside other guests, green alone, no rate" shape already on record for partition_claim_gives_up, but a different failure signature (a guest_verdict stdout miss, not a kernel-log count mismatch), so it is filed separately and cross-linked rather than folded in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…oss under host contention lan_mdns_answer: QEMU's chardev refused the tap sockets' path once a macOS $TMPDIR plus this harness's own lane path had already spent every byte of Darwin's 104-byte sockaddr_un.sun_path, leaving nothing for a filename (orchestrator's Fast-tier run on PR #537's head 06b926b, a diff that touches neither). tests/common/segment.rs now names its sockets under /tmp directly, via the new toyos_build::socketpath, whose length never depends on $TMPDIR; open() unlinks both once connected, since /tmp is not this run's lane. i8042_mouse: a third sighting of the identical shape already tracked in issues/build/parallel-tests-red-under-other-suites.md's own entry for this test (872/876 packets, never more than the pacing's 12-of-16-byte bound outstanding) — inside the bound the first fix installed, so not that mechanism. Extended that entry with today's evidence and filed issues/hardware/i8042-mouse-loses-a-packet-under-host-contention.md for the redlist row, naming the plausible mechanism this tree's own qemu.rs already documents for the keyboard path: QEMU's PS/2 queue silently drops what a guest a starved host has not scheduled has not drained, which MOUSE_LEAD does not guard against the way the keyboard's own pacing against the guest's echo does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review r1 — PR #560 at
|
…ays what is known
The QMP socket was still `lane::dir()/qmp-{seq}.sock`, the same
`$TMPDIR`-depth path the tap moved off: 100 bytes at lane-2/seq 0 on the dev
host, and `lane-10/qmp-1000.sock` reaches the 104 Darwin's connect refuses.
It now comes from `socketpath::short("qmp", seq)`, as both tap sockets do.
`socketpath::short` returns a `Socket` that removes its name when dropped.
The `QemuInstance` holds the QMP socket and the `Tap`, so both names go once
QEMU is reaped. They also go on every early return and every unwind out of the
boot, including `mdns()` returning at `await_marker` before it ever opened the
tap. The unlink in `Tap::open` and the QMP `remove_file` in `drop` are gone.
`BootOptions::segment` is now a flag, and the test opens the segment through
`QemuInstance::segment`. `Tap::in_lane` becomes `Tap::of_boot(seq)`, keyed to
the boot's own sequence number. `profile_argv` builds the tap it is asked for
instead of dropping it.
The host test that asserted a literal's length is deleted. The remaining
tests pin that `short` lives under `/tmp` and fits, and that a dropped
`Socket` removes its name.
The i8042 issue's starvation mechanism is refuted: the mouse already paces
against the guest's own report. The file is renamed for what was measured:
872 of 876 in 17 s, a clean end, and a shortfall equal to `MOUSE_LEAD`. It
names the two paths the tree offers. One is a >5 ms decoder gap inside a -1
packet producing a right-button press and release, measured on the host
through `MouseDecoder`. The other is a non-zero exit this test never reads.
Neither is established, so the file says "mechanism not known".
The partition-claim issue loses its false "beside other guests" and
"23 other parallel tasks" claims (the job ran one wide). It also loses the
unsupported lost-output reading. Its exit now requires `guest_verdict`'s
exit-0 refusal to carry the kernel window. This branch's edit to
`parallel-tests-red-under-other-suites.md` is reverted to main's text.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`qemu_command` took eight arguments once the tap joined the QMP socket, which clippy refuses. `Sockets` holds both of a boot's `/tmp` names. `QemuInstance` drops it after QEMU is reaped, `qemu_command` reads it, and `profile_argv` builds one with the tap it is asked for and, as before, no QMP socket. `issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md` and `...-outgrows-sun-len-on-the-dev-host.md` are this defect. Their exit is "fits sun_path on every host, lan_mdns_answer green on the dev host". The first half is `socketpath::short`. The second half is the orchestrator's run of `lan_mdns_answer` on this head. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The `fire` closure only turned `Option<&PathBuf>` into `Option<&Path>`, which `Sockets::qmp` now returns. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The names moved out of the swept lane directory. A SIGKILLed run now leaves them, which is this branch's compromise, recorded with its exit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review r2: PR #560 at
|
…cratch `sun_path` is 104 bytes on Darwin and `$TMPDIR`'s depth is the host's, so a harness socket under the lane's directory can pass it. The previous fix named each socket under `/tmp` by hand (`src/socketpath.rs`), outside the tree `toyos_tmpdir` sweeps, so a SIGKILLed run left its names behind. toyos-tmpdir makes roots under a second base, `/tmp`: `TempDir::short` runs the same `Root::make`, owner lock, `GLOBAL` lock and sweep over its own `State`. A boot's `Sockets` holds one such directory with `qmp.sock`, `tap-in.sock` and `tap-out.sock` in it; the worst case, `/private/tmp/toyos-tmp-4194304-99/boot-99999/tap-out.sock`, is 57 bytes. `profile_argv` names its sockets under `/nonexistent`, like its other paths. `src/socketpath.rs` goes, with its pid-reuse unlink, the boot sequence in the names, and the issue that recorded the gap. `--ci host` and `--ci guest` also red on a `/tmp` root whose process died while their steps ran: `toyos_tmpdir::gone_roots` read before the steps and after. The partition-claim issue loses two speculative passages; the i8042 issue's exit condition requires its shortfall refusal to carry the guest's stdout and exit code, and its TEST_END reading names every tail that returns no error. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review r3: PR #560 at
|
Resolves the modify/delete conflict on issues/build/a-lane-s-tap-socket-path-outgrows-sun-len-on-the-dev-host.md by deleting it: main's rewrite of the issue restates the same evidence and adds the exit condition "fits sun_path ... wherever the scratch directory is, and lan_mdns_answer is green on the dev host", which this branch's fix already meets (lan_mdns_answer EXIT=0 at 6697367). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…le the shared-host /tmp check as an issue, and cut two REMOVEs
`a_socket_in_a_short_directory_fits_whatever_tmpdir_is` duplicated the base
check `reclaimed`'s own /tmp arm can make directly, so it folds into one
`starts_with(canonicalize("/tmp"))` assertion there; the worst-case socket
path length (57 bytes, measured by `wc -c`) goes in the PR body instead of a
104-byte fixture.
`src/ci.rs`'s /tmp leftover check has no way to tell its own job's dead root
from another worktree's harness killed on the same host in the same window
(the reclaim mechanism deliberately shares /tmp's lock across every worktree
on the host), so it is filed rather than fixed: a Sunday-morning "a few
lines" fix would need per-job pid tracking this tree has nowhere to hang.
Cuts the two REMOVEs: `src/ci.rs`'s doc comment claiming this check is a
refusal "only some later process's sweep would take" (false on a shared
host), and the partition-claim issue's speculation about which mechanism is
at fault.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
- rust: the fork's 62fa74d7a50 merges main's pin 1b236638a90 (#541) into this branch's fee9fa6f7bb; the two share no file, and the merge over main's pin is this branch's six std files alone. - issues/build/a-lane-s-tap-socket-path-outgrows-sun-len-on-the-dev-host.md: deleted as #560 deleted it. This branch's hunk was the two path lengths PR #536's lanes hit and an A/B on $TMPDIR's length; #560's short TempDir under /tmp is the fix for both lengths, so nothing of it is owed. - issues/build/swap-crash-rolls-back-redial-turned-away-once-on-mains-nightly.md: deleted as #565 deleted it, folding it into a-swaps-redial-races-a-hard-dial-ceiling-against-an-unbounded-guest-gap.md. This branch's hunks: the status moved to expected-red and the known-red line (both carried by #565's redlist rows for swap_crash_rolls_back and lan_swap); the mechanism, a probation-long gap against a ceiling of 64 refusals and not a time (carried by the folded issue's "What the code shows"); and the #536 sightings, added there as a seventh bullet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Takes #560, #541, #565, #563, #569 and #570. `src/ci.rs` and `tests/toyos.rs` merge without conflict; `rust` takes main's pin, 1b236638, since this branch carries no fork commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Summary
This PR fixes one harness defect and disables two tests.
1. A boot's Unix sockets live in a
toyos_tmpdirdirectory under/tmp(fixeslan_mdns_answer)lan_mdns_answerfailed withconnect to QEMU's /private/var/folders/.../T/toyos-tmp-55923-0/tests-0/lane-2/tap-out-0.sock: path must be shorter than SUN_LEN. A macOS$TMPDIRplus the lane path can fill all 104 bytes of Darwin'ssockaddr_un.sun_path. The QMP socket had the same shape (lane::dir()/qmp-{seq}.sock).toyos_tmpdirgains a second base.TempDir::short(label)isTempDir::newunderSHORT_BASE(/tmp) whatever$TMPDIRis. It runs the sameRoot::make, owner lock,GLOBALlock andState::sweep, over aStateof its own. So a SIGKILLed run's socket directory is reclaimed by the next process's first short directory, exactly as its lane scratch is.Socketsholds one such directory,boot-<n>, withqmp.sock,tap-in.sockandtap-out.sockin it.QemuInstanceowns it, so the directory goes afterdrophas reaped QEMU, and on any unwind out of a boot. The worst case,/private/tmp/toyos-tmp-4194304-99/boot-99999/tap-out.sock, is 57 bytes (wc -c).BootOptions::segmentis abool, and a test opens the segment withQemuInstance::segment().profile_argvnames its sockets under/nonexistent, like its other paths, and builds no live directory for an argv no boot runs./tmp.--ci hostand--ci guestreadtoyos_tmpdir::gone_roots("/tmp")before their steps. Their last step now also reds on a/tmproot whose process died while the steps ran.issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.mdandissues/build/a-lane-s-tap-socket-path-outgrows-sun-len-on-the-dev-host.mdare deleted, because this is their defect. Their exit also needslan_mdns_answergreen on the dev host.main'sc4fc16earewrote the second issue after this branch first deleted it; the merge below resolves that modify/delete conflict by deleting it again, having met the exit condition main's rewrite added.2.
partition_claim_departureis disabledNightly run 36336701867, job
guest (5), ran one wide.guest_verdictrefused withthe guest exited 0 having said 0 of its 1 refusals:and an empty stdout. The test was green when re-run alone.--known-redanswered NO.The issue is
issues/boot-media/partition-claim-departure-exits-clean-with-none-of-its-refusals-said.md. Its exit condition requires that refusal (tests/common/partclaim.rs) to carry the kernel window, as the refusal for a non-zero exit already does, so the next sighting is not blind.3.
i8042_mouseis disabled; mechanism not knownThe orchestrator's Fast-tier run on
06b926b1failed with872 pointer events reached userland out of 876 packets injected,FAIL i8042_mouse (17s). The issue isissues/hardware/i8042-mouse-ends-four-packets-short-with-a-clean-exit.md. It records what was measured:run_test_paced: noSTALLED.BURST's 1000 packets in.MOUSE_LEAD.RUN_CEILING.uart-*.log.The tree offers two paths to this shape:
toyos_ps2::MouseDecoder. A gap longer thanPACKET_GAP_NSbetween a −1 packet's head0x18and itsdx0xFFyields abuttons=0x07event and then abuttons=0x00one. That is the right-button press and release the guest exits 0 on.i8042_mousenever reads.Neither path is established. The exit condition requires the shortfall refusal to carry
result.stdoutandresult.exit_code.Merge
Merged
origin/main(1ec6daa9). Its only conflict was modify/delete onissues/build/a-lane-s-tap-socket-path-outgrows-sun-len-on-the-dev-host.md, whichc4fc16earewrote with the same evidence and the exit condition "fitssun_path… wherever the scratch directory is, andlan_mdns_answeris green on the dev host". Resolved by deleting the file: this branch meets that condition (lan_mdns_answerEXIT=0, below). The rest merged automatically.The
/tmpleftover check's scopesrc/ci.rs'sleft_behindnames every root under/tmpwhose process died during the job's steps that a snapshot taken before them did not name./tmpis shared by every worktree on the host by design — it is what lets a SIGKILLed run's socket directory be reclaimed by the next process to touch the base, whichever worktree that is — so the check cannot yet tell its own job's dead root from one another worktree's harness left on the same host in the same window. Filed asissues/build/the-tmp-leftover-check-can-name-another-worktrees-killed-run.md, with this mechanism as evidence and an exit condition; on the hosted runners the gate uses, each job has its own host, so the check is exact there.Gates
At
f31742b7(the merge above, plus the review-r3 fixes below it).cargo test --lib: EXIT=0cargo test -p toyos-tmpdir: EXIT=0cargo run -- --clippy: EXIT=0cargo test --test toyos-build --no-run: EXIT=0Red arms
Host mutations, each applied as a checked patch, built, run, and restored:
Statestarts withswept: true.cargo test -p toyos-tmpdir --test reclaimgives EXIT=101:a_killed_process_is_reclaimed_and_a_live_one_is_never_touchedfails witha killed process's root outlived the next process's sweep, in its/tmparm.TempDir::shorttakesstd::env::temp_dir()as its base. Same command, EXIT=101: the same test's/tmparm now fails its ownstarts_with(canonicalize("/tmp"))assertion,…/toyos-tmp-…/reclaim-0/toyos-tmp-…-0 is not under /private/tmp—a_socket_in_a_short_directory_fits_whatever_tmpdir_isfolded into that assertion, so one mutation now covers both claims.left_behindreads no/tmproots.cargo test --lib ci::testsgives EXIT=101:the_job_names_a_short_root_a_step_left_when_it_diedfails witha dead step's root is a red: "every test took its scratch with it".The guest red arm for the SUN_LEN fix is the recorded failure quoted above. The old construction is only over 104 bytes under a five-digit pid, so no deterministic guest mutation exists.
Guest arms
Measured by the orchestrator at
6697367d(this branch's head before the merge above; the merge touches nothing these depend on):cargo test --test toyos-build -- lan_mdns_answer: EXIT=0.cargo test --test toyos-build -- --nightly iommu_virtio_platform: EXIT=0./tmpentries across both runs./private/tmp/toyos-tmp-<pid>-0was left, the next suite exited 0, and then it was gone.Oracle
sockaddr_un.sun_pathof 104 bytes (<sys/un.h>), as enforced by the kernel's own refusal that Rust'sUnixStream::connectreports aspath must be shorter than SUN_LEN./tmparm SIGKILLs a real process holding a short directory, and the kernel's release of itsflockis what the next process's sweep reads.🤖 Generated with Claude Code