Skip to content

tests: the measured schedule — Fast is every PR, then Nightly, then Weekly; 15 never-caught tests and the kernel code only they armed deleted - #564

Merged
Japabu merged 25 commits into
mainfrom
wt/toyos-schedule
Sep 28, 2026
Merged

Japabu merged 25 commits into
mainfrom
wt/toyos-schedule

Conversation

@Japabu

@Japabu Japabu commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

The guest suite runs on the schedule the owner adopted from what each test has caught: 426 of 524 CI-scheduled guest tests never caught a real defect, and they were 87% of guest time.

The schedule

Every price is the sum of the report's per-test medians (table_pertest.md, "cost s"). "Before" is the report's own tier column; "after" is cargo test --test toyos-build -- --list at 9b2645e, each name joined to its median. Counts are runnable tests; disabled rows run nowhere and are counted apart.

tier before: tests before: guest s after: tests after: guest s
Fast (cargo test, every PR) 393 614.4 227 84.0
Nightly (--nightly) 114 2617.3 143 751.9
Weekly (--weekly) — — 117 2247.1
Local (unsharded runs only) 3 unpriced 3 unpriced
disabled rows 17 — 22 (9 Fast, 12 Nightly, 1 Weekly) —
run before: guest s after: guest s
plain cargo test 614.4 84.0
--nightly 3231.7 835.9
--weekly — 3083.0

Unpriced after, and summed as 0: with no row in the report, in Fast, c_hello, doom_frames and netd_refused_accept, which main added at Fast, and eight C tests of the shared boot (03_struct, 33_ternary_op, 79_vla_continue, 85_asm_outside_function, 94_generic, 98_al_ax_extend, 122_vla_reuse, 127_asm_goto); in Nightly, heap_ceiling_bounds, heap_over_ceiling_halts, klogd_fault_halts, lock_across_switch_halts, syscall_fault_halts and syscall_panic_halts, which main added at Nightly. With a row whose median is n/m: abuse_shm_length in Fast, and audio_tone_load and tls_rebase_window in Nightly.

Where a registration differs from its bucket, the reason is one of these:

  • A boot group has one tier, its most frequent member's: metal_sim_scanout_wc, metal_sim_ipc_hostile_peer, metal_sim_compositor_stall, metal_sim_client_death, i8042_no_spurious_wake and locale_detect_unrecognized are weekly-bucket riders on a nightly boot, and stay Nightly.
  • Audio and timing rows wt/toyos-notiming rewrites keep the tier they had (below).
  • Five guards stay, Weekly (below).
  • Disabled rows keep their tier, and rows main added keep main's.

Decisions

  • src/tiers.rs: Tier gains Weekly, and a run's Reach (plain, --nightly, --weekly) selects its own tier and every narrower one. A test's tier is declared once, as the word in its registration row. Schedule is every registered name at its one tier: a second row for a name is refused by name. The harness builds it from the shared boot's binaries and the three declared registries; it replaces check_no_collisions and check_registration's duplicate loop, answers the redlist's "is this registered" (contains), and drives --list.
  • src/testargs.rs: --weekly. --nightly --weekly is refused, because the second would be read by nothing. Either reach beside --audio-gate or --metal is refused too: --metal --nightly used to be accepted and its --nightly dropped.
  • CI: nightly.yml has two crons, 0 3 * * 1-6 and 0 3 * * 0, and nothing else changes in YAML. The guest job reads the schedule that started it from $GITHUB_EVENT_PATH and runs --weekly on Sunday's and --nightly on the other, on a dispatch and off a runner (src/ci.rs's reach_of_event, host-tested). A schedule the file does not declare is a red step. A test holds the two crons in nightly.yml against the two in src/ci.rs.
  • Before a release: cargo test --test toyos-build -- --weekly.
  • A run that holds tiers back names each one with its flag: not run without --nightly: / --weekly:, and , N held back for --nightly, M held back for --weekly in the result line.
  • No boot names a binary the suite did not build, and --list says so. Every CARRIES row is checked against the built catalogue before --list, --debug and --audio-gate, not only before the first boot.
  • The harness's own checks leave the guest tiers. The eleven that boot nothing (serial_vocabulary, suspend_detector, suspend_invalidates_a_verdict, stall_is_not_a_verdict, nvme_image_is_held_by_one_guest, control_regs_verdict, i8042_quarantine_verdict, suite_split, run_exit_status, nightly_tier_is_announced, screen_decoder) are libtest tests of a new target, toyos-checks: tests/checks.rs includes tests/toyos.rs under the test harness and holds the checks and the helpers only they read. src/ci.rs's host job runs it, and so does every plain cargo test. No guest row, dispatch arm or duration line is left for any of them.
  • DRIVEN_AND_SHARED stays beside RUST_SKIP in tests/toyos.rs, since the two lists are one partition, and its block is main's byte for byte. Only toyos-checks' suite_split reads it, so the harness = false target carries one #[allow(dead_code, reason = …)] on it. #[cfg(test)] in its place does not tell the two targets apart: cargo run -- --clippy checks toyos-build under cfg(test) too, and fails there with "constant DRIVEN_AND_SHARED is never used" (EXIT=1).

Deleted: 15 of the 26

console_line_atomicity, home_budget_refusal_retried, i8042_keyboard, klogd_panic_halts, log_conservation_smp4, log_conservation_smp8, quiesce_dump_holds_the_stopped, quiesce_wakes_on_the_last_exit, screen_early_panic, so_cache_refusals, sshd_fail_closed, usb_disk_index_stable, wall_clock_file, xhci_hid_break, xhci_hotplug.

Each one went with its harness code, its dead helpers, its duration row, its redlist row and its CARRIES and RUST_SKIP rows. The guest binaries console_line_atomicity, home_fsync_budget and so_cache_policy went too, quiesce_last lost the exiting thread only the last-exit test held, and the test runner's CONSOLE_JOBS, whose one entry was test_rs_console_line_atomicity, went: every job's stdin is a pipe now. So did the kernel code only these tests armed: the actuators quiesce-last-exit, quiesce-dump, so-cache-tiny, xhci-hid-break-first, xhci-hid-break-late and klogd-panic, with quiesce::last's exit hold (Last collapses to the park it still stages), sched::dump::serve_for_the_stop, DumpRequest::file_and_take and its loom model, the cache's tiny budget, HidDevice::stage_break and its completion count, and klogd's staged panic. kernel/src is net −133 lines.

The three whose exit needs a run name their reproducer as it stands at 1808fb8d, this branch's base on main: console_line_atomicity with its CONSOLE_JOBS stdin, so_cache_refusals with the so-cache-tiny budget, and home_budget_refusal_retried, whose file now names its owner, the orchestrator. quiesce-wakes-on-the-last-exit-lost-its-serial-ready-beside-other-guests (kind: finding) goes with its test. a-quiesce-writers-first-pass-outlasts-the-jobs-five-second-spin-up stays expected-red behind quiesce_stops_the_machine, and its sentence naming the deleted quiesce_dump_holds_the_stopped as booting quiesce_writers goes.

Where coverage of a deleted test stands:

  • log_conservation_smp4/_smp8: kernel-loom log_ring's a_published_record_is_whole_and_read_once and a_lane_publishes_whole_and_reuses_only_after_a_read; log_conservation_smp1 remains, Weekly.
  • wall_clock_file's retention: userland/logd/src/store.rs's whole_old_boots_go_first_then_earlier_continuations and a_flooding_boot_costs_its_own_middle_and_nobody_elses_start.
  • xhci_hotplug: toyos-xhci's sim a_device_plugged_in_is_enumerated_once and unplugging_tears_the_device_down.
  • xhci_hid_break: teardown.rs's a_halted_endpoint_is_reset_cleared_and_delivering_again and a_recovery_the_controller_refuses_lets_the_device_go.
  • klogd_panic_halts: klogd_fault_halts drives the klogd context and syscall_panic_halts the panic! entry.
  • sshd_fail_closed: sshd's a_file_that_names_nobody_authorizes_nobody holds the authorization half. The "never listens" half (userland/sshd/src/main.rs) has no gate.
  • screen_early_panic: blackbox_early_panic_sealed_muted reads the early panic off the panel, without check_colors.

Kept, Weekly, and why:

  • syscall_window_nmi, syscall_window_nmi_controls and dump_nmi_probe. What they guard (IST fix NMI and #MC get stacks of their own, because three instructions of syscall entry run at CPL 0 on the user's stack #234, the NMI dump) is the frame an x86 CPU pushes for an NMI taken at CPL 0 on a user rsp, and whether vector 2's IST index keeps it off that stack. Only a CPU produces that frame. The controls' catch data predates The NMI window control holds its victim inside the entry instead of hoping a spray lands there #470's rewrite of the control, so fresh runs judge it. dump_nmi_probe's verdict is also a 1 ms NMI budget, flagged for wt/toyos-notiming.
  • fat_backing_revoked, the only gate on a revoked FAT32 backing never serving reallocated data, and launcher_refusals, the only gate on init refusing hostile launches and surviving them with no census growth. Neither can be held on the host without a new abstraction. The FAT revocation is FatFs::delete's revoke and FatBacking::read_page in kernel/src/fat32_adapter.rs, and no host test compiles the kernel. The launcher's refusals are /system/bin/init's serve_launch against real handles and the kernel's SYS_NAMESPACE_BUILD answer, and init builds only for the ToyOS target.

Left to wt/toyos-notiming (not touched here):

  • From the delete bucket: doom_sound_flood, metal_sim_null_audio, latency_wake, short_sleep_livelock, sched_check_build, and i8042_health_cadence, whose verdict is a cadence over a real span.
  • Rows it rewrites, left at their old tier: doom_music, soundd_log_stall, i8042_absent, null_sink_shipped_client, netd_stalled_peer, desktop_audio_client, hda_client_stall, hda_tone, kernel_heartbeat, xhci_slow_connect, audio_tone, audio_tone_load.

panic_halts_the_others_first is Nightly and hda_two_live_refused Weekly, by their buckets.

Host conversions: 5 of 13

defect host test arm exit the named reason
B02 initiators deadlocked kernel-loom an_initiator_answers_while_it_waits (already there) b02-initiator-stops-answering: wait_turn stops serving 101 "cpu 0 is waiting for cpu 1 and has stopped answering it"
A16 IRQ counted ahead of its bytes kernel-loom an_empty_interrupt_is_never_counted_as_one_that_carried, on main's model under #567's loom fork a16-counted-on-the-way-in: record counts "carried" first and corrects after the burst 101, at 617e934 "a reader saw Counts { carried: 1, empty: 0 } while the only interrupt on the machine carried nothing"
B22 waitpid stranded toyos-proclife a_poisoned_main_thread_takes_the_claim_and_ends_the_process (already there) b22-zombified-and-woke-nobody: zombify, name no wake 101 right: Process(
B09 dump on a syscall's pass kernel-loom only_a_pass_entered_at_depth_zero_takes_the_request (new) b09-any-pass-serves: every pass may serve 101 "a pass entered at preempt depth 1 took the request"
B23 join answered NotFound toyos-proclife a_join_asked_after_it_collected_keeps_its_answer (new) b23-join-collects-again: every ask collects 101, at b1d8472 "a join that collected its thread answered the ask after it with no such thread", left: Some(Err(NoSuchThread))
  • B09: Entered and its decision (may_serve) move from sched/dump.rs into sched/dump_request.rs, which kernel-loom already compiles. dump.rs mints its proof from that decision and re-exports the type.
  • B23, and the table lock: the kept answer is toyos_proclife::join::Join's, held in a Cell and asked through &self. sys_thread_join holds one Join and its ask closure borrows it, so no copy of the answer is taken out and written back. a_join_asked_after_it_collected_keeps_its_answer runs that shape: one join shared by the ask before the wait, the wait's predicate and the ask after it. Join::ask takes the collect as a closure and calls it only while the join is unsettled. process::ask_join, which replaces wait_thread_zombie, takes PROCESS_TABLE inside that closure, so a settled join answers without the lock, as main's answer.get().is_some() || did. That decision is toyos-proclife's, where a host test reaches it: a_settled_join_does_not_take_the_table_again asks a settled join with a closure that panics. Under join-asks-when-settled, which calls the collect every time but keeps the first answer, it exits 101 with "a settled join took the table lock to ask again", and a_join_asked_after_it_collected_keeps_its_answer stays green.
  • A16: the tally models are main's. Loom from a fork that races a store against every thread's last load #567 moved every loom model onto a fork that races a store against every thread's last load, and made both tally models require the case they are named for. So this branch's reordering of them, and its explored guard, went in the merge. The issue this branch had filed about the gap went too, since Loom from a fork that races a store against every thread's last load #567 meets its exit.

Not converted, and why:

  • The decision is in kernel code no host crate compiles, so a host test first needs it extracted: B29 (i8042::service's record-then-bytes read order), A48 (completion::post_n's claim count), B43 (the scheduler's wait loop), and B27, B28 and B30 (the i8042 health verdicts in kernel/src/drivers/i8042/mod.rs; toyos-ps2 holds only decoding).
  • B37 is a property of what a Rust scope releases at a -> ! call, not a decision any proclife function makes.
  • B36 is open: a host test would reproduce it, not guard it.

Gates

At 9b2645e, after the merge of origin/main (d4e4102):

gate exit
cargo test --lib 0 (392 passed, 1 ignored)
cargo test --workspace --exclude toyos-build 0
cargo run -- --clippy 0
cargo run -- --ci host 0 (Host: 50 step(s), all green; toyos-checks 11 passed)
cargo test --test toyos-build -- --list 0 (236 Fast, 155 Nightly, 118 Weekly, 3 Local; 22 disabled)
cargo run -- --build-only 0

Host arms. Each was applied as a checked patch, built, run, and reversed, and the tree was shown clean.

arm the mutation test at exit the named reason
exit-code-suspended-is-zero Tally::exit_code returns 0 for a suspended-only tally toyos-checks run_exit_status 617e934 101 "a suspended run exits 0, and it has to be 2"
join-asks-when-settled Join::ask calls the collect on a settled join and keeps its first answer a_settled_join_does_not_take_the_table_again b1d8472 101 "a settled join took the table lock to ask again"
b23-join-collects-again every ask collects a_join_asked_after_it_collected_keeps_its_answer b1d8472 101 "answered the ask after it with no such thread"
join-keeps-no-answer Join::ask returns what it collected and keeps none of it a_join_asked_after_it_collected_keeps_its_answer b1d8472 101 "answered the ask after it with no such thread", left: Some(Err(NoSuchThread))
a16-counted-on-the-way-in as above an_empty_interrupt_is_never_counted_as_one_that_carried 617e934 101 "a reader saw Counts { carried: 1, empty: 0 }"
checks-held-back-unsaid the result line drops its held-back counts toyos-checks nightly_tier_is_announced a9dfb9c 101 "a run holding tests back never says "2 held back for --nightly, 1 held back for --weekly""
ci-dispatch-runs-weekly a run no schedule started reaches weekly a_run_no_schedule_started_reaches_nightly a9dfb9c 101 "a None run", left: Ok("--weekly")
tiers-contains-a-prefix contains takes a prefix only_a_registered_name_is_contained a9dfb9c 101 "a prefix is not the name"

Guest arms, each applied as a checked patch at b1d8472, shown to build with cargo run -- --build-only (EXIT=0 each) and reversed: b23-join-collects-again, join-per-ask (sys_thread_join builds a fresh Join for every ask), b09-any-pass-serves, fat-delete-keeps-the-backing and init-keeps-a-refused-frames-handles.

Run by the orchestrator at 9b2645e (agents run no QEMU), on a clean tree:

  • The Fast tier, cargo test: EXIT=0, test result: ok. 230 passed, 230 total (52.9s), 143 held back for --nightly, 117 held back for --weekly.
  • EXIT=0 each: --nightly fpu_isolation, xhci_flap and usb_boot_stick_pulled.
  • The guest red arms, each EXIT=1 with the same assertion on --nightly fpu_isolation, thread_join failed, left: 18446744073709551614, right: 0:
    • b23-join-collects-again, in its form for the &mut self Join::ask.
    • join-per-ask (sys_thread_join builds a fresh Join for every ask).

High-risk parts: the kernel's join and dump paths, the deleted kernel code, and the harness's selection.

  • Mutations: the arms above.
  • Independent oracles: for the kernel, the recorded real failures the two guest red arms re-stage (fpu_isolation red at fd62f56 on thread_join, CI run 35360971260's dump panic); for the join's lock, main's own sys_thread_join, whose answer.get().is_some() || asked no table once settled; for the deletions, the compiler over every kernel feature set clippy checks; for the schedule, the report's independently measured buckets against --list.

Unsure

  • The weekly cron is proven by host tests of the mapping and the file, not by a run. github.event.schedule in the event payload is GitHub's documented field; the first Sunday is the proof.
  • The join's early return is Join::ask's rather than an answer() accessor read in ask_join. An accessor would put the lock decision in process.rs, where no host test reaches it.

Filed

  • issues/build/the-harness-carries-three-helpers-nothing-calls.md
  • issues/build/which-pass-drain-irqs-is-entered-from-is-gated-only-by-a-nightly-guest.md
  • issues/build/a-settled-thread-join-taking-the-table-lock-again-is-gated-by-nothing.md

Net lines against origin/main, 1550 insertions and 3703 deletions in all:

+ − net
kernel/src 62 195 −133
src/ (the build system, its unit tests included) 267 53 +214
toyos-proclife, toyos-quiesce (unit tests included) 78 4 +74
userland/ (the test runner) 2 13 −11
tests/ 1035 3350 −2315
kernel-loom/ 14 29 −15
issues/ 80 53 +27
.github/, Cargo.toml 10 4 +6
kernel/CLAUDE.md, tests/CLAUDE.md 2 2 0

🤖 Generated with Claude Code

https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j

Japabu and others added 9 commits September 28, 2026 00:06
…never-caught tests deleted

The owner adopted a schedule from what each guest test has caught: 426 of
524 CI-scheduled guest tests never caught a real defect and were 87% of
guest time.

- `src/tiers.rs`: `Tier` gains `Weekly`, and a run's `Reach` (plain,
  `--nightly`, `--weekly`) selects its own tier and every narrower one. A
  `Schedule` is every registered name at its one tier: a name registered
  twice is refused by name, and asking the tier of an unregistered one is
  refused by name. The harness builds it from the shared boot's discovered
  binaries and the three declared registries, which replaces
  `check_no_collisions` and `check_registration`'s duplicate loop; the
  redlist asks it what is registered, and `--list` prints every test at
  its tier.
- `src/testargs.rs`: `--weekly`; `--nightly --weekly` is refused (the
  second would be read by nothing), and either reach beside `--audio-gate`
  or `--metal` is refused — `--metal --nightly` used to be accepted and its
  `--nightly` dropped.
- `nightly.yml` runs Monday to Saturday at 03:00 and Sunday at 03:00; the
  guest job reads which schedule started it (`src/ci.rs`'s
  `guest_reach`) and runs `--nightly` or `--weekly`, and a schedule the
  file does not declare is a red step. Same jobs, one workflow.
- Every row's tier is its bucket's: Fast is the shared boot and the 22
  machine and screen tests of the every-PR bucket. A boot group takes its
  most frequent member's tier, so six weekly-bucket riders stay Nightly on
  the boot they share. The audio and timing rows `wt/toyos-notiming`
  rewrites keep the tier they had, and the fix-first rows are untouched.
- Deleted with their harness code, guest binaries, duration rows, redlist
  rows and the issues that existed only for them: console_line_atomicity,
  fat_backing_revoked, home_budget_refusal_retried, i8042_keyboard,
  klogd_panic_halts, launcher_refusals, log_conservation_smp4,
  log_conservation_smp8, quiesce_dump_holds_the_stopped,
  quiesce_wakes_on_the_last_exit, screen_early_panic, so_cache_refusals,
  sshd_fail_closed, usb_disk_index_stable, wall_clock_file,
  xhci_hid_break, xhci_hotplug. `quiesce_last` loses the exiting thread
  only the last-exit test held.
- `syscall_window_nmi`, `syscall_window_nmi_controls` and
  `dump_nmi_probe` stay, Weekly: what they guard is the frame an x86 CPU
  builds for an NMI at CPL 0 on a user `rsp`, which only a CPU produces.
- Stale tier reasons in the registration comments are deleted.

Filed: the seven kernel actuators no test arms any more, and three harness
helpers nothing calls.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ts for a bare pass

Two defects only a guest caught, now caught on the host:

- B23, #513's `thread_join` answering NotFound: the wait's predicate
  collected the zombie and the syscall collected again. The kept answer
  moves into `toyos_proclife::join::Join`, which asks the table until one
  ask settles and returns that ask after it; `sys_thread_join` asks it
  under the table lock through `process::ask_join`, which replaces
  `wait_thread_zombie`. `a_join_asked_after_it_collected_keeps_its_answer`
  reds on the re-collecting shape.
- B09, the blocked-task dump served on a syscall-driven pass: `Entered`
  and its decision, `may_serve`, move into `sched/dump_request.rs`, the file
  `kernel-loom` already compiles, and `dump.rs` mints its proof from it.
  `only_a_pass_entered_at_depth_zero_takes_the_request` reds on a pass
  entered above zero taking the request.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ore now

The two models over `Tally` spawned the ISR, and `Tally::record` begins with
its saturation check's load. Loom 0.7 explores only the first schedule when
a spawned thread's first operation is a load: measured on a bare loom
`AtomicU64`, two adds after a leading load gave 1 execution against 10
without it. So neither model checked an interleaving of the real word, and
A16's shape — an empty interrupt counted as one that carried until the
burst corrects it — passed both.

Both now spawn the reader and run the ISR on the model's own thread, and
`explored` refuses a model that ran one execution.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…m that it could not goes

With the models exploring, `a_counted_interrupt_carries_its_bytes_with_it`
reds with `record`'s release and `read`'s acquire both weakened to `Relaxed`:
the measurement that said loom could not see the weakening was taken on a
model that ran one execution.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…one execution

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…one execution

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu Japabu changed the title tests: the measured schedule — Fast is every PR, then Nightly, then Weekly tests: the measured schedule — Fast is every PR, then Nightly, then Weekly; 17 never-caught tests deleted Sep 27, 2026
@Japabu
Japabu marked this pull request as ready for review September 27, 2026 22:19
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Japabu

Japabu commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator Author

Missing at 6f9a317: CI has no conclusion (run 36354938564 host queued; the run at 42918cf was cancelled), and there are no guest runs for the branch (orch-runs/summary.txt has no 564 line): nothing for the Fast tier, for fpu_isolation and dump_left_pending_is_owed on the changed join/dump paths, or for the b23/b09 guest red arms.

NOT READY FOR REVIEW

Japabu and others added 3 commits September 28, 2026 07:36
`writeback_durability`'s CARRIES row still named `test_rs_fat_backing_revoked`,
which this branch deleted, so every run panicked in the catalogue check before
its first boot. That check ran after `--list` returned, so the list was green
over it; it now runs before `--list`, `--debug` and `--audio-gate`.

The test runner's `CONSOLE_JOBS` held only `test_rs_console_line_atomicity`,
also deleted, so it goes and every job's stdin is a pipe.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
… the word first

The filed claim, that a spawned thread opening with a load explores one
execution, is false: `dump_request`'s spawned threads open with
`DumpRequest::update`'s load and explore 16 to 5777 executions. Loom 0.7.2
keeps one last access per atomic, and a thread's own load overwrites it, so a
store is never raced against another thread's earlier load of the same word.
The issue now says that, and lists every loom model whose spawned thread
opens with a load with its measured execution count; `explored`'s doc in
`i8042_tally.rs` says the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
The tier tables keep main's deletions (`screen_recoverable_untouched`,
`screen_survived_panic_not_blamed` and `heap_ceiling_recovery`, with panic
recovery) and this branch's (`screen_early_panic`, `klogd_panic_halts`).
Main's new rows keep main's tiers: `netd_refused_accept` Fast, and
`klogd_fault_halts`, the four syscall-death rows and `heap_ceiling_bounds`
Nightly. Retiered rows keep this branch's tier: `netd_refused_pipes` Nightly,
`klogd_hosted` Weekly.

`src/ci.rs` keeps `guest_reach` and drops `suite_args`'s host-slot doc, which
main deleted with the slots. The actuator issue loses `usbd-panic`, which went
with usbd, and is six now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu

Japabu commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Review, round 2, at 4919fbd

Round 1 gave no findings: it was NOT READY FOR REVIEW because measurements were missing. Here is where those stand now.

  • CI: CLOSED. host SUCCESS, run 36384174766 at 4919fbd.
  • --nightly fpu_isolation, --nightly dump_left_pending_is_owed and --weekly iommu_empty_domain: CLOSED. EXIT=0 each (orch-runs/564r2-{fpu,dump,weekly}.log).
  • Arms b23 and b09: CLOSED. Both EXIT=1 with the named reasons: left: 18446744073709551614 and dump.rs:227:5 … preempt depth 2.
  • Fast tier: ran, 225 passed and 1 failed. The red is main's; see "handle_basic" below.
  • --nightly quiesce_wakes_on_the_last_park: OPEN. The branch changed its guest binary, and no run exists at 4919fbd. The 6f9a317 run panicked on the carry check before its first boot.

handle_basic is main's

  • Census::now() counts every object on the machine, but the guest runs one job at a time. userland/test-runner/src/main.rs:302-319 spawns a job and then calls child.wait(), so nothing runs beside handle_basic except the boot's daemons (tests/testcases, which this branch does not touch).
  • handle_basic runs on the actuator boot, and ACTUATOR_TESTS (tests/toyos.rs:119) is not in this diff. Its part has the same members at base and head, and it passed through no tier change.
  • The same assertion (handle_basic.rs:305) went red on CI run 33266767478, job 99138099030, on 2026-08-29. That was wt/toyos-wv-fs at b10c4da, with the same predecessor (abuse_kernel_addr), and it was GREEN alone.
  • The shape of the failure is PipeWrite +1 with PipeRead unchanged, which is the last round's drop(write) still in the release queue at the second reading. That is issues/kernel/deferred-release-outlives-its-syscall.md, which already disables handle_kill_policy, handle_transfer and kill_while_blocked on the same census instrument.
  • Disable handle_basic behind that issue as a fourth witness.

BLOCKER

  • kernel/src/actuator.rs:123,126,252,330,333,466 — the branch leaves six actuators that nothing arms: quiesce-last-exit, quiesce-dump, so-cache-tiny, xhci-hid-break-first, xhci-hid-break-late and klogd-panic. They are dead kernel code this branch created, and they are recorded instead of deleted. Delete them and everything only they reach, then delete issues/design-debt/six-kernel-actuators-lost-the-only-test-that-armed-them.md. That code is:

    • log/console.rs:422-424;
    • syscall/machine.rs:104-107, plus sched/dump.rs:160-172 serve_for_the_stop, plus DumpRequest::file_and_take (dump_request.rs:81, whose last caller was that function) and its loom model at kernel-loom/tests/dump_request.rs:125;
    • Last::Exit in quiesce.rs:268-308 and syscall/proc.rs:26;
    • elf/cache.rs:157-165;
    • drivers/xhci/hid.rs:113- (the boot-actuators impl HidDevice, break_at, stage_break) and its call at xhci/mod.rs:977.
  • issues/{build/console-line-atomicity-loses-five-of-a-thousand-lines-on-ci, filesystem/home-budget-refusal-retried-is-red-on-every-nightly, hardware/usb-disk-index-stable-nothing-enumerates-on-the-first-controller, kernel/quiesce-dump-holds-the-stopped-reds-wide-with-usb-transport-breaks, kernel/so-cache-refusals-saw-the-kernel-refuse-nothing-once}.md — five kind: defect records are closed with no evidence about the defect. Each records a product symptom that nobody has explained:

    • lines lost inside one guest's console path;
    • "the retry never ran" on a /home fsync, red on every nightly, against kernel/CLAUDE.md's BudgetExpired rule;
    • an empty first xHCI controller;
    • a /log writer's fsync held 5.8 s on a one-guest KVM lane (quiesce_writers, which quiesce_stops_the_machine still runs in Fast);
    • a cache budget that refused nothing.

    Deleting the instrument does not close the defect (issues/README.md: "closing it costs evidence"). Restore them. Only quiesce-wakes-on-the-last-exit… (kind: finding) is correctly gone.

  • tests/toyos-rust-tests/src/bin/fat_backing_revoked.rs (deleted) — this was the only gate on an information disclosure through a revoked FAT32 backing (FatBacking::revoke, kernel/src/file_backing.rs:37: open, unlink, reallocate, read the old descriptor). No host test takes the claim, and home_backing_revoked covers /home only. The ruling moves coverage to host tests; it does not drop it. Either keep the row, Weekly, until a host test holds the claim, or land that test.

  • tests/toyos-rust-tests/src/bin/launcher_refusals.rs (deleted) — this was the only gate on init refusing hostile launcher requests and surviving them, with no census growth. That is a security boundary, and userland/init has no host test at all. Same remedy as above.

  • tests/toyos.rs:1459 — nightly_tier_is_announced is the guard of the Tally::holding_back/summary code this branch rewrote. The branch rewrote the test too and moved it to Weekly, and it has no run at 4919fbd. It boots nothing, so the implementer can run cargo test --test toyos-build -- --weekly nightly_tier_is_announced and must report EXIT=0.

NOTE

  • The deleted tests that are covered, and what covers them:
    • log_conservation_smp4/_smp8: kernel-loom log_ring a_published_record_is_whole_and_read_once and a_lane_publishes_whole_and_reuses_only_after_a_read.
    • wall_clock_file's retention: userland/logd/src/store.rs whole_old_boots_go_first_then_earlier_continuations and a_flooding_boot_costs_its_own_middle_and_nobody_elses_start.
    • xhci_hotplug: toyos-xhci/sim a_device_plugged_in_is_enumerated_once and unplugging_tears_the_device_down.
    • xhci_hid_break: teardown.rs a_halted_endpoint_is_reset_cleared_and_delivering_again and a_recovery_the_controller_refuses_lets_the_device_go.
    • sshd_fail_closed: the authorization half is covered by sshd's a_file_that_names_nobody_authorizes_nobody. The "never listens" half (main.rs:730) now has no gate.
    • screen_early_panic: blackbox_early_panic_sealed_muted reads the early panic off the panel, but without check_colors.
    • klogd_panic_halts: klogd_fault_halts covers the klogd context and syscall_panic_halts covers the panic! entry. The deletion stands on the data: a=b=0 and 5 main reds. It stands only once its actuator goes (BLOCKER 1).
    • console_line_atomicity, quiesce_dump_holds_the_stopped, quiesce_wakes_on_the_last_exit, so_cache_refusals and usb_disk_index_stable: all were already disabled at base, so no running coverage is lost.
  • tests/toyos.rs:1058,1438 — panic_halts_the_others_first (nightly bucket) and hda_two_live_refused (weekly bucket) stay Fast on the premise that No QEMU test measures time, and audio is judged on metal only #562 deletes them. origin/wt/toyos-notiming keeps both registrations. The fix is one word each.
  • tests/toyos.rs:1021 — syscall_window_nmi, syscall_window_nmi_controls and dump_nmi_probe are kept against the delete bucket. No QEMU test measures time, and audio is judged on metal only #562 moves dump_nmi_probe to METAL. The controls' 15 main reds (cistats.json) predate 3ad278c (The NMI window control holds its victim inside the entry instead of hoping a spray lands there #470), which rewrote the control, so the data never saw today's control. The deviation needs the owner's sign-off.
  • The ten host-side self-tests are Weekly because they never caught anything, but they cost 0 s and boot nothing, so the price rule buys nothing there. It is the owner's call to make them host #[test]s or keep them Fast.
  • kernel/src/sched/driver.rs:587 — drain_irqs(Entered::Blocking) changed to Entered::Pass { depth: 0 } passes every host test and the Fast tier. Only Nightly blocked_dump reds. The host test pins only may_serve.
  • kernel/src/syscall/proc.rs:157-162 — dropping join.set(asked) passes host tests and Fast. Only Nightly fpu_isolation reds, the same as at base.
  • kernel/src/syscall/proc.rs:157 — ask() takes PROCESS_TABLE after Join has settled, which the old short-circuit avoided.
  • src/ci.rs:611 — guest_reach is untested. Returning WEEKLY for a non-schedule event passes every test.
  • src/tiers.rs:106 — the only production caller of Schedule::tier (tests/toyos.rs:19502) reads only is_ok(). A contains does the job.
  • tests/common/power.rs:340 — woken_by_the_held_thread now has one caller, and its armed parameter has one value. Inline it.
  • tests/toyos.rs:19502 — there is a blank line before }.
  • issues/build/loom-never-moves-a-store-before-a-load-another-thread-made-first.md and issues/build/the-harness-carries-three-helpers-nothing-calls.md name no owner. Loom from a fork that races a store against every thread's last load #567 (wt/toyos-loomfix) meets the loom issue's second exit.
  • kernel/CLAUDE.md:19 — an agent edited a CLAUDE.md. The orchestrator ratifies or places it. tests/CLAUDE.md:3 still points at "the fast tier's line in src/tiers.rs", which no longer exists.
  • Net lines: +924/−3653 in all. Tests are −2909 and issues −53. Production, which includes src/ unit tests, is +233, and the kernel is ≈+1. BLOCKER 1 is where the kernel should shrink.

REMOVE

  • src/tiers.rs:14-17 — "A test's tier is what it has caught: … A new test enters Nightly." This is an unenforced rule, and it is already false in the tree (netd_refused_accept entered Fast; see the NOTE on :1058/:1438).
  • src/tiers.rs:10-12 — the cron sentence restates src/ci.rs.
  • kernel-loom/tests/i8042_tally.rs:181-184 — "If a future loom … stops scheduling a reader … this reds". This branch's own finding falsified it: the models explored 1 execution while this test stayed green.
  • tests/toyos.rs:644, 694, 698-699, 852, 1254 — the "Nightly for …" tier reasons that the schedule falsified. The PR body says these were deleted.
  • PR body, "Unsure" — "Deleting wall_clock_file leaves logd's delete-oldest retention with none." False; see logd store.rs above.
  • PR body, "The schedule" — "…hda_two_live_refused (2.0 s), which wt/toyos-notiming deletes." False.

SEND BACK

Japabu and others added 4 commits September 28, 2026 10:14
The six actuators nothing arms go, with every line only they reached:
quiesce-last-exit (the exit hold in SYS_THREAD_EXIT, and `Last` collapses
to the one park it still stages), quiesce-dump (`serve_for_the_stop`,
`DumpRequest::file_and_take` and its loom model), so-cache-tiny (the tiny
budget), xhci-hid-break-first/-late (`stage_break`, `break_at` and the
completion count only they read) and klogd-panic. The design-debt issue
that recorded them goes with them.

The five defect records the deletions closed are restored: deleting a test
is no evidence about a defect. Each is `open`, since no redlist row
disables anything for them now, and the exit clauses that named a deleted
test as the witness are deleted.

`fat_backing_revoked` and `launcher_refusals` come back as Weekly guest
rows, with their binaries, the FAT oracle in `tests/common/volumes.rs`,
their skips, carries, dispatch arms and duration rows. Neither claim can
be held on the host without a new abstraction: the FAT revocation is
`FatFs::delete`/`revoke` and `FatBacking::read_page` in the kernel adapter,
which no host test compiles, and the launcher's refusals are init's
syscalls against the kernel's `SYS_NAMESPACE_BUILD` answer, with init
built only for the ToyOS target.

The ten harness self-checks that boot nothing leave the guest tiers and
become libtest tests: `tests/checks.rs` includes `tests/toyos.rs` under
the test harness, where its `cfg(test)` module runs them, and the host CI
job runs that target. `nvme_image_is_held_by_one_guest` names its claims
under CARGO_TARGET_TMPDIR, since a claim is a name and no run directory
exists outside a suite run.

Smaller findings: `Schedule::tier` becomes `contains`, `guest_reach`'s
event decision is a function a host test drives (a run no schedule started
reaches nightly), `woken_by_the_held_thread` is inlined into its one
caller, `panic_halts_the_others_first` is Nightly and
`hda_two_live_refused` Weekly by the data, the two filed issues name an
owner, and the REMOVEd sentences are deleted. Three issues are filed: the
two mutations only a nightly guest catches (`drain_irqs`'s `Entered`, the
join's write-back) and the settled join that still locks the process
table.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Cargo.toml: main's deletion of the target-lexicon patch, beside this
branch's `toyos-checks` target. src/redlist.rs: main's six new rows, less
the four whose tests this branch deletes (`quiesce_dump_holds_the_stopped`,
`quiesce_wakes_on_the_last_exit`, `so_cache_refusals`,
`usb_disk_index_stable`). Main's `c_hello` and `doom_frames` keep main's
tier.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
`tests/toyos.rs` is a `harness = false` target, so the ten checks' bodies
left there were dead in it, and clippy's `cfg(test)` pass over it drops a
`#[test]` without a harness. The bodies, and `hand_rolled_deaths`,
`needs_actuators`, `driven_binaries` and `DRIVEN_AND_SHARED`, which only
they read, move into `tests/checks.rs`'s `checks` module, which only the
libtest target compiles. `idle_trip_verdict` takes its test's name,
`i8042_quarantine_verdict`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…actuator

`the_asker_owns_the_report_it_asks_for` modelled `DumpRequest::file_and_take`,
which went with `quiesce-dump`, so its execution count describes nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu Japabu changed the title tests: the measured schedule — Fast is every PR, then Nightly, then Weekly; 17 never-caught tests deleted tests: the measured schedule — Fast is every PR, then Nightly, then Weekly; 15 never-caught tests and the kernel code only they armed deleted Sep 28, 2026
@Japabu

Japabu commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Review, round 3, at 3b94e06

CI: host SUCCESS, run 36397650628, headSha 3b94e06. The step "the harness's own checks: cargo test --test toyos-checks" ran 10 tests and all 10 passed. The loom controls each reached their verdicts.

Round-2 BLOCKERs

  • The six unarmed actuators: CLOSED. grep over kernel, kernel-loom, toyos-quiesce, tests, src and userland finds none of the six wire names, and none of serve_for_the_stop, file_and_take, Last::Exit, stage_break or break_at. kernel/src is 64+/190−. Clippy passed on every kernel feature set (schedule-r3/gate-clippy.log, EXIT=0). At 3b94e06 these runs are each EXIT=0: --nightly quiesce_ (4 of 4, quiesce_wakes_on_the_last_park among them), klogd_fault_halts, dump_left_pending_is_owed and blocked_dump.
  • The five defect issues: CLOSED. All five are back, at status: open. Their exit clauses are a NOTE below.
  • fat_backing_revoked: CLOSED. The Weekly row, the dispatch arm, the host body and the guest binary are byte-identical to main. --weekly fat_backing_revoked is EXIT=0. The arm fat-delete-keeps-the-backing is EXIT=1 with "the backing served another file's data". The stated reason holds: FatBacking lives in kernel/src/fat32_adapter.rs, and no host crate compiles it.
  • launcher_refusals: CLOSED. --weekly launcher_refusals is EXIT=0. The arm init-keeps-a-refused-frames-handles is EXIT=1 with "16 more refused launches left more live objects behind". The reason holds: serve_launch (userland/init/src/main.rs:986) is handle ownership against a real kernel table, inside a target-only binary.
  • nightly_tier_is_announced: CLOSED. It is in toyos-checks and green on CI at 3b94e06. The arm checks-held-back-unsaid is EXIT=101 with the named reason.
  • Round 2's OPEN measurement, quiesce_wakes_on_the_last_park: CLOSED. It is a PASS in 564r3-quiesce.log.

BLOCKER

  • tests/toyos.rs:1422,12481,18070 and tests/test-durations:185 — run_exit_status is the one harness check that boots nothing and is still a guest-tier row. The ruling was that the boot-nothing checks become host #[test]s, so this row is also a sibling of toyos-checks. It was Fast on main (origin/main:tests/toyos.rs:1586) and is now Nightly: every plain run holds it back (564r3-fast.log:934), and no PR runs it. Yet it gates Tally::exit_code and the test result: ok. line, which this branch rewrote (holding_back, relegated, summary). The fix: move fn run_exit_status into tests/checks.rs's mod checks as a #[test], and delete the row, the dispatch arm and the durations line. It must turn red under a patch that makes exit_code return 0 for a suspended-only tally.

NOTE

  • kernel/src/process.rs:1275 and kernel/src/syscall/proc.rs:154-165 — a settled join takes PROCESS_TABLE again at the top of the loop. Main's answer.get().is_some() || short-circuit avoided that lock. This is the branch's own regression, and it was filed (issues/kernel/a-settled-thread-join-takes-the-process-table-to-ask-again.md) rather than fixed. The fix: add pub fn answer(self) -> Option<Result<i32, JoinRefused>> { self.0 } to toyos_proclife::join::Join, and in ask_join do if let Some(a) = join.answer() { return Some(a); } before PROCESS_TABLE.lock(). Then delete the issue.
  • kernel/src/elf/cache.rs:231 — let budget = BUDGET_BYTES; is what the so-cache-tiny removal left behind. Use the const itself at its three uses.
  • Issue exits: at issues/filesystem/home-budget-refusal-retried-is-red-on-every-nightly.md:30, "the cause shown on a red run's log" can no longer be met, because the test is deleted and nothing can produce a red run. The file also still names no owner, although the branch edited that line. At issues/build/console-line-atomicity-loses-five-of-a-thousand-lines-on-ci.md:23 and issues/kernel/so-cache-refusals-saw-the-kernel-refuse-nothing-once.md:18, "the cause is fixed" names nothing that would show it. Each exit should name the reproducer the fix is shown against.
  • The three filed issues are which-pass-drain-irqs…, a-thread-join-keeping… and a-settled-thread-join…. Their owner, exit and frontmatter match the tracker's shape, and "Owner: orchestrator" is the tree's convention (14 files). The third should be deleted by the fix above, not kept.
  • Merge: git merge-tree --write-tree HEAD origin/main (a7cd327) is clean, tree 3f0c30f5, EXIT=0. The only file both sides touch is src/redlist.rs, in disjoint hunks. After the merge, every DISABLED name is registered, log_ring_keeps_the_owners_slots included (Nightly, tests/toyos.rs:719), so the tier table and the redlist agree. Two counts in the PR body then go stale: "18 disabled (11 Nightly)" and "145 held back for --nightly" become 19 (12 Nightly) and 144. Re-run --list after the merge, before the body becomes main's record.
  • Conflict risk, from the other branch's side:
  • tests/checks.rs — the toyos-checks target does what the ruling asks. CI's required host check runs it, clippy --all-targets covers it, and the arm proves it can red. Its price is a second compile of the whole harness: 46.11 s on the required check (CI log 08:35:38 to 08:36:24), and again on every plain local cargo test.
  • tests/checks.rs:412 — DRIVEN_AND_SHARED and RUST_SKIP (tests/toyos.rs) are one partition ("every driven name is on one list or the other"), and now they are in two files.
  • kernel/CLAUDE.md:19, tests/CLAUDE.md:3 — CLAUDE.md edits by an agent, still for the orchestrator to place or decline.
  • Net lines: +1653/−3717.
    • The kernel shrinks, as it should: kernel/src is 64+/190−, net −126.
    • src/ is +214 (the Weekly reach, the schedule, the cron mapping, and their unit tests).
    • toyos-proclife and toyos-quiesce are +39.
    • userland is −11.
    • tests/ is −2281 and kernel-loom −14.
    • issues/ is +109.
    • CI and Cargo.toml are +6.

REMOVE

  • tests/checks.rs:24-31 — "they used to disagree … All three ask serial::died now". Chronology, moved in with the block.
  • tests/checks.rs:211-216 — the reboot story and its date, "2026-08-17".
  • tests/checks.rs:281-282 — "read off this tree on 2026-08-08".
  • tests/checks.rs:326-329 — "UMIP used to be this file's example …".
  • tests/checks.rs:336-338 — "The bit that was on before this … reddened nothing at all".
  • tests/checks.rs:358-360 — "the closed vacuous-line-count entry asked for …".
  • tests/toyos.rs:477-478 — "screen_decoder needs no guest at all …" in SCREEN_TESTS' doc. It is no screen row now.
  • issues/build/loom-never-moves-a-store-before-a-load-another-thread-made-first.md:26-28 — "They now spawn the reader … (explored)". This is the story of the fix, and it belongs in the commit.
  • PR body — the scratchpad/schedule-r1/arms/, scratchpad/schedule-r3/ and scratchpad/schedule-r3/arms/ paths. These are session-local paths, and the body becomes main's record.
  • PR body, "Unsure" — "home-budget-refusal-retried-is-red-on-every-nightly names no owner, as it did before this branch." Name the owner instead.

SEND BACK

Japabu and others added 2 commits September 28, 2026 12:51
…lock

`run_exit_status` boots nothing and gates `Tally::exit_code` and the
result line this branch rewrote, so it becomes a `#[test]` in
`tests/checks.rs` and its guest row, dispatch arm and duration line go.
Under a patch making `exit_code` return 0 for a suspended-only tally it
reds with "a suspended run exits 0, and it has to be 2".

`Join::ask` takes the collect as a closure and calls it only while the
join is unsettled; `process::ask_join` takes `PROCESS_TABLE` inside that
closure, so a settled join answers without the lock, and the decision is
`toyos-proclife`'s where a host test reaches it.
`a_settled_join_does_not_take_the_table_again` reds when the collect runs
on a settled join, with the answer still kept. The issue that recorded
the regression is closed.

`DRIVEN_AND_SHARED` returns beside `RUST_SKIP` in `tests/toyos.rs`, the
partition's two halves in one file, byte-identical to main's block; the
libtest-free target does not read it, so it carries the one `allow`.
`elf/cache.rs` uses `BUDGET_BYTES` itself. The restored defect issues each
name the reproducer at `1808fb8d` their fix is shown against, and
home-budget names its owner. Chronology in `tests/checks.rs`, the
`screen_decoder` note under `SCREEN_TESTS` and the fix's story in the loom
issue are deleted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
#571's removal of `handle_basic` from `DRIVEN_AND_SHARED` merges on its
own, since the list is back in `tests/toyos.rs` byte for byte as main had
it.

`kernel-loom/tests/i8042_tally.rs` takes main's side whole: #567 moved
every loom model onto a fork that races a store against every thread's
last load, and asserts that the tally models reach their named cases, so
this branch's reordering and its `explored` guard, which worked around
the gap, go. The branch's issue about that gap
(`loom-never-moves-a-store-before-a-load-another-thread-made-first`)
closes with it, since #567 meets its exit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
…rences from it and the harness issue

The park issue's slug and title said "threads running" beside the held one,
but every record carries 2 thread(s) and one of the two is the held thread by
construction — so the stop gave up on one thread beside it, and "running"
never held as a scheduler state. Renamed to
issues/kernel/quiesce-wakes-on-the-last-park-gave-up-on-one-thread-beside-the-held-one.md
and the redlist row moved with it.

Deleted the park issue's false inference that 0 open block operations means
neither thread was parked: stop_if_blocked refuses a thread parked in
SYS_FSYNC's OpenUpdate, which adds 0 to in_flight, so logd parked between
refused fsync attempts is a candidate the records cannot exclude. Added it as
a second labelled hypothesis beside the dispose_yield one. Deleted the false
claim that none of four branches touch the guest's stop path (PR #510 changes
fat32_adapter's refused-write path, where an fsync park happens), and the
stale count of disabled guest tests that PR #564 moves.

Deleted the harness issue's false claim that returned_to_firmware runs before
the boot console is read (power.rs judges the boot console and the drained
tail first) and its false claim that every writers-issue sighting carries the
same never-asked message (a58abf5's give-up line was never recorded).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
…d's name open

Answers the SEND BACK on #575 at d346d9d.

- fsd's new name is open with the owner (candidate `fileserver`, `files`
  kept for the file manager); the invented rename of the file manager goes.
- The rename is stage 1, first after #536, briefed as an ABI brief since it
  touches toyos/src, toyos-abi/src, userland/libc/src and the rust fork's
  ToyOS files. Its exit is a case-insensitive substring search over the six
  daemon names and a letter-bounded search for `init`, each with an explicit
  exclusion list judged per match; issue bodies are excluded as recorded
  evidence. Measured outside issues/ at 62e7e8c: 3641 daemon substring hits
  (3419 outside the exclusions), 2289 `init` substring hits, 1589
  letter-bounded (1073 outside the exclusions).
- Stage 2's exit names the crate `toyos-supervisor` and its decisions, now
  including the stop-order derivation and a host test refusing an
  undeclared cycle; it is unmet today and cannot go vacuous under the rename.
- Stage 3's exit adds a two-service reverse-order test that reds on forward
  and all-at-once order.
- Stage 4's exit names the five claims the stop's coverage must assert, by a
  host test or a guest test at Tier::Fast or Tier::Nightly with no redlist
  row, so it cannot be met by deleting tests; the per-test lists that
  conflicted with #564 and #574 go.
- The power-broker track loses its false parenthetical and item 1: toybox
  holds the `power` connector, not the bit.
- Every REMOVE the review listed is taken.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu

Japabu commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Review, round 4, at 617e934

CI: host SUCCESS, run 36413265821, headSha 617e934. Both steps passed: --ci host and --ci gate-stage. The log shows toyos-checks running checks::run_exit_status ... ok, join::tests::a_settled_join_does_not_take_the_table_again ... ok, and Host: 50 step(s), all green.

The orchestrator's guest runs at 617e934, clean tree:

  • Fast: test result: ok. 231 passed ... 143 held back for --nightly, 118 held back for --weekly.
  • EXIT=0: fpu_isolation, quiesce_ (4 of 4), klogd_fault_halts, dump_left_pending_is_owed, blocked_dump, fat_backing_revoked and launcher_refusals.
  • Each arm is EXIT=1, for the reason it names:
    • b23 on fpu_isolation: thread_join failed, left 18446744073709551614.
    • b09-any-pass-serves: PANIC ... dump.rs:208:5: the blocked-task dump ran at preempt depth 2.
    • fat-delete-keeps-the-backing: "the backing served another file's data".
    • init-keeps-a-refused-frames-handles: "16 more refused launches left more live objects behind".

Round-3 BLOCKER

  • run_exit_status: CLOSED.
    • It is a #[test] in tests/checks.rs:576, and its row, dispatch arm and durations line are gone.
    • It is green on CI.
    • The arm exit-code-suspended-is-zero (exit_code returns 0 for a suspended-only tally) is EXIT=101 with "a suspended run exits 0, and it has to be 2" (schedule-r4/arms/exit-code-suspended-is-zero.log).

Round-3 NOTEs and REMOVEs

BLOCKER

NOTE

  • tests/toyos.rs:466 — the #[allow(dead_code, reason = …)] is truthful, but it also silences the one lint that would name this list if suite_split stopped reading it.
    • harness = false passes no --test, so cfg(test) holds in toyos-checks alone. #[cfg(test)] in place of the allow would carry the list only where it is read, and the list would warn if its reader went.
    • The mutation the allow survives is deleting tests/checks.rs:517-535.
  • kernel/src/syscall/proc.rs:154-159 — the Cell<Join> copy-out/write-back is what issues/build/a-thread-join-keeping-its-answer-is-gated-only-by-a-nightly-guest.md records: dropping join.set(asked) is red only on a nightly.
    • Hold the answer in Join as a Cell<Option<Result<i32, JoinRefused>>> and make it ask(&self, collect). The write-back then does not exist, the host test covers the whole path, and the issue is deleted.
    • This round rewrote ask's signature, so the change is cheap now.
  • kernel/src/process.rs:1276 — the claim "a settled join answers without the lock" is held for Join only. In the kernel, let mut g = PROCESS_TABLE.lock(); join.ask(|| join::collect_zombie(g.as_mut().unwrap(), parent_pid, tid)) passes every test.
    • That costs speed, not correctness, and the closure makes the correct form the natural one. It is recorded here, not sent back.
  • kernel/CLAUDE.md, tests/CLAUDE.md — agent edits to a CLAUDE.md, still for the orchestrator to place or decline.
  • Net lines: git diff --shortstat origin/main...HEAD is 54 files, +1548/−3702.
    • Production:
      • kernel/src +66/−194 (−128);
      • src/ +267/−53 (+214, its unit tests included);
      • toyos-proclife +24 for Join;
      • toyos-quiesce −1;
      • userland −11.
    • Tests:
      • tests/ +1040/−3351 (−2311);
      • kernel-loom −15;
      • toyos-proclife +40.
    • issues/ is +28, and CI plus Cargo.toml +6.
    • Since 3b94e06 the branch's own commit is +127/−145. I accept the production growth in src/ (Weekly reach, schedule, cron mapping) and in Join.

REMOVE

  • tests/checks.rs:573-574 — "what --land's gate reads off the process". --land is retired (src/pr.rs:75), so the line is false, and it came into this file with the move.
  • PR body, the deleted-tests paragraph — "quiesce-dump-holds-the-stopped-reds-wide-with-usb-transport-breaks … are status: open, since no redlist row disables anything for them". This is false once main is merged: Disable quiesce_stops_the_machine and quiesce_wakes_on_the_last_park behind their filed defects #574 renamed that file, and a disabled row cites it.
  • PR body, "Run by the orchestrator" — every "Expected green" / "expected red". These are predictions, not measurements, and the body becomes main's record.

SEND BACK

Japabu and others added 3 commits September 28, 2026 15:17
src/redlist.rs keeps main's ftruncate_flush_race, quiesce_stops_the_machine
and quiesce_wakes_on_the_last_park rows, drops quiesce_dump_holds_the_stopped
and quiesce_wakes_on_the_last_exit, whose tests this branch deletes, and takes
#554's removal of the xhci_flap row.

The writers issue #574 renamed stays expected-red with main's exit, since
quiesce_stops_the_machine's row cites it; its opening sentence named the
deleted quiesce_dump_holds_the_stopped as booting quiesce_writers and goes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…s read

`toyos_proclife::join::Join` keeps its answer in a `Cell` and is asked
through `&self`, so `sys_thread_join` holds one join and its `ask` closure
borrows it: there is no copy to take out and write back after each ask.
`a_join_asked_after_it_collected_keeps_its_answer` now runs the syscall's
shape, one join shared by the first ask, the wait's predicate and the ask
after the wait, so the mutation that keeps no answer reds a host test and
`issues/build/a-thread-join-keeping-its-answer-is-gated-only-by-a-nightly-guest.md`
meets its exit and goes.

`issues/build/a-settled-thread-join-taking-the-table-lock-again-is-gated-by-nothing.md`
records that whether `ask_join` takes `PROCESS_TABLE` inside `collect` is
held by no test.

`DRIVEN_AND_SHARED` is `#[cfg(test)]` rather than allowed dead, so it is
compiled only into `toyos-checks`, and the lint names it if `suite_split`
stops reading it.

`run_exit_status`'s doc loses the sentence about `--land`'s gate, which is
retired.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…under cfg(test)

`cargo run -- --clippy` runs `cargo clippy --workspace --all-targets`, which
compiles the `harness = false` target `toyos-build` with `cfg(test)` set too.
Under `#[cfg(test)]` the list is compiled there with no reader, and the gate
fails with "constant `DRIVEN_AND_SHARED` is never used" (`-D dead-code`), so
`cfg(test)` does not tell the two targets apart and the allow comes back.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu

Japabu commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Review, round 5, at 9b2645e

CI: host SUCCESS, run 36429966012, headSha 9b2645e. The log has clippy: workspace root — cargo clippy --workspace --all-targets ... -D warnings clean, join::tests::a_join_asked_after_it_collected_keeps_its_answer ... ok, a_settled_join_does_not_take_the_table_again ... ok and Host: 50 step(s), all green.

The orchestrator's guest runs at 9b2645e, on a clean tree:

  • Fast: EXIT=0, test result: ok. 230 passed, 230 total (52.9s), 143 held back for --nightly, 117 held back for --weekly.
  • EXIT=0 each: --nightly fpu_isolation, xhci_flap and usb_boot_stick_pulled.
  • b23-join-collects-again and join-per-ask on fpu_isolation: EXIT=1 each, with thread_join failed, left: 18446744073709551614.

Round-4 BLOCKER

  • Merge with main: CLOSED.
    • 4dff77b3 has parents 617e934f and d4e41022. git merge-tree --write-tree HEAD origin/main (ec06384) is EXIT=0, and A std build keeps nothing another compiler compiled, and a bootstrap run leaves the fork's lockfiles as it found them #573/Track: the supervisor is host-tested and owns the stop #575 touch no file this branch touches.
    • git show --remerge-diff 4dff77b3 has two conflicts, and each hunk of both sides is accounted for:
      • src/redlist.rs: the resolution keeps main's ftruncate_flush_race, quiesce_stops_the_machine and quiesce_wakes_on_the_last_park. It drops quiesce_dump_holds_the_stopped and quiesce_wakes_on_the_last_exit, whose tests are deleted, and it drops xhci_flap. Measured against main, git diff d4e41022 4dff77b3 -- src/redlist.rs is only the five rows of the tests this branch deletes.
      • The writers issue: the branch had two hunks, status: open and "A reproduction names" in place of "Re-enabled when". Both are reversed to main's text, so the file is expected-red behind main's row. One hunk belongs to neither side: the sentence naming the deleted test is dropped. The PR body states that.
    • tests/common/usb.rs and kernel/src/drivers/xhci/mod.rs auto-merged. On each file, the branch's change against the old base and the merge's change against main have identical -/+ lines (646 and 2; diff EXIT=0). So every hunk from main (xHCI: every report that moves a port's belief leaves it to be read #554) is present. xhci_flap and usb_boot_stick_pulled are green at the head.
    • Every issue a dropped row cited, and that is still in the tree, is at status: open.

Round-4 NOTEs

  • DRIVEN_AND_SHARED #[allow]: its justification is true, and the round-4 premise was false.
    • I reproduced it in a scratch crate: one harness = false test target holding a #[cfg(test)] const that it never reads, and one libtest target that include!s it and reads it.
    • cargo clippy --all-targets -v -- -D dead-code passes --cfg test to the harness = false target and fails there with "constant LIST is never used", EXIT=101. cargo test --no-run -v passes --cfg test to that target too.
    • So cfg(test) cannot tell toyos-build from toyos-checks, and CI's clippy step (--workspace --all-targets -D warnings) would red on it.
  • Join holds its own answer: CLOSED.
    • Join(Cell<Option<Result<i32, JoinRefused>>>), ask(&self, …), and sys_thread_join holds one join (kernel/src/syscall/proc.rs:154-155). The write-back is gone.
    • Host arms, each EXIT=101: join-keeps-no-answer reds both join tests, b23 reds both, and join-asks-when-settled reds the lock test alone.
  • Kernel-side issue: filed. Its evidence is a REMOVE below.

NOTE

  • kernel/src/syscall/proc.rs:154 — join-per-ask (a fresh Join for every ask) is red only on the nightly fpu_isolation (564r5-join-per-ask.log). a_join_asked_after_it_collected_keeps_its_answer runs a copy of the syscall's shape, not the syscall, so it stays green under that patch.
    • b1d84726 deleted a-thread-join-keeping-its-answer-is-gated-only-by-a-nightly-guest.md because round 4 said the host test "covers the whole path". It does not. The recorded weakness is still true, only now in its join-per-ask form, and nothing records it except the PR body's "Unsure".
    • Record it where the other kernel-wiring gap already is: add the join-per-ask mutation and its nightly red to issues/build/a-settled-thread-join-taking-the-table-lock-again-is-gated-by-nothing.md. The alternative is to move the ask/wait loop into toyos-proclife, so that the host test drives the real loop.
  • Arms b23-join-collects-again and join-per-ask:
    • Each is whole for the claim it controls. The is_none guard is all of Join::ask's keeping, and let join at proc.rs:154 is all of the syscall's sharing. Neither is a partial revert.
    • Neither is a negative control in CLAUDE.md's sense, and none can be. The join change is a behaviour-preserving move, and its whole revert onto d4e41022 is main's own sys_thread_join, which is green on fpu_isolation. They are mutations, which the rule's "negative control or mutation" admits. The PR body's "Negative controls: the arms above" should say mutations.
    • b23's guest red shows nothing its host arm (EXIT=101) does not. join-per-ask is the one arm that needs the guest.
  • PR body, "Run by the orchestrator at 617e934": the landing head's measurements are the 9b2645e runs listed above. The record should carry those, not the pre-merge head's.
  • Net lines: git diff --shortstat origin/main...HEAD is 54 files, +1550/−3703. Since the merge, the branch's own commits are +55/−53. kernel/src is +62/−195 and toyos-proclife +75. No new production growth.

REMOVE

  • toyos-proclife/src/join.rs:106 — "sys_thread_join's path: …". The test is a replica of that path, and join-per-ask on the real path leaves it green.
  • toyos-proclife/src/join.rs:59 — "and no caller holds a copy to write back". This describes the deleted implementation.
  • issues/build/a-settled-thread-join-taking-the-table-lock-again-is-gated-by-nothing.md:12-16 — "PR tests: the measured schedule — Fast is every PR, then Nightly, then Weekly; 15 never-caught tests and the kernel code only they armed deleted #564's round-4 review wrote it as …: every test passed" and "which costs contention … and not a wrong answer". No run stands behind either claim: no 564r4/564r5 summary line runs that patch.
  • PR body, "Unsure" — "join-per-ask … shown to build and not yet run on a guest". False: it ran at 9b2645e, EXIT=1.

LAND AFTER NAMED CHANGES

Japabu and others added 2 commits September 28, 2026 17:47
…issue, two false test-replica claims removed

The host test only replicates sys_thread_join's shape, so the syscall's
answer-keeping stays gated by nothing but the nightly guest fpu_isolation;
record that on the existing table-lock issue rather than filing a new one.
Delete the comment claiming to describe "sys_thread_join's path" (it
describes the test's replica of it) and the claim that no caller holds a
copy to write back (describes the deleted implementation). Drop the issue's
two unsupported claims ("every test passed", "costs contention ... not a
wrong answer") that no run backs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu
Japabu added this pull request to the merge queue Sep 28, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 28, 2026
origin/main brought #557 (clipboard fix), which registers
metal_sim_hostile_clipboard at Fast beside the metal_sim_window_drag row
this branch moved to Weekly. Kept #564's move and #557's own row and tier
for the new test, per this branch's stated rule that a row main added
keeps main's tier.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu
Japabu added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 807f456 Sep 28, 2026
1 check passed
@Japabu
Japabu deleted the wt/toyos-schedule branch September 28, 2026 16:45
Japabu added a commit that referenced this pull request Sep 28, 2026
#564 landed on main since this branch was cut and deleted 15
never-caught tests, five of them pre-existing redlist rows this branch
did not touch: console_line_atomicity, quiesce_dump_holds_the_stopped,
quiesce_wakes_on_the_last_exit, so_cache_refusals,
usb_disk_index_stable. Kept main's deletions for those and this
branch's own three additions (quiesce_leaves_the_volume_whole,
syscall_window_nmi, user_copy_races_munmap) in src/redlist.rs, in the
file's existing order.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
#564 (the measured schedule) moved the root_* boot-image group's tiers
(root_candidate_malformed, root_named_but_absent, root_named_twice to
Weekly; root_chunk_refused, root_candidate_overlaps,
root_named_twice_on_the_boot_disk to Nightly; log_partition_identity to
Weekly) while this branch changed root_chunk_refused's profile and added
root_chunk_refused_on_a_usb_stick at Fast, redlisted. Kept #564's tiers
for the rows it moved and this branch's Fast registration for the new
row, which #564's measured buckets and PR-body exceptions do not cover
(it did not exist when that report was measured).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
#564 deleted `quiesce_wakes_on_the_last_exit`, `quiesce_dump_holds_the_stopped`,
their actuators `quiesce-last-exit` and `quiesce-dump`, `quiesce_last`'s exiting
thread, and collapsed `quiesce::last::Last` to the park. This branch had edited
all of them only to carry its new `quiesce-last-teardown` beside them; those
edits have no purpose without their subjects, so the deletions are taken.

`quiesce-last-teardown` and `quiesce_wakes_on_the_last_teardown` are this
branch's own, not something #564 deleted: they are the guest check that the
stop waits for a teardown in flight (the last one out stays in its process
until `torn_down`). So they stay, and with them `Last` stays an enum of two
(Park, Teardown), `hold` keeps its `last` argument and `sys_nanosleep` passes
`Last::Park`, and `woken_by_the_held_thread` stays a helper with two callers.

- kernel/src/actuator.rs: `quiesce_last_exit` and `quiesce_dump` go (main);
  `quiesce_last_teardown` stays (branch).
- kernel/src/quiesce.rs: `last` keeps the branch's claimed-id hold, `ALONE`
  and the `may_yield` refusal; `Last::Exit` goes.
- kernel/src/syscall/proc.rs: main's `hold()` becomes `hold(Last::Park)`.
- tests/common/power.rs: `quiesce_wakes_on_the_last_exit` and
  `quiesce_dump_holds_the_stopped` go (main); the park and teardown verdicts
  keep the branch's `counts … alone` and teardown `exit:` checks.
- tests/toyos-rust-tests/src/bin/quiesce_last.rs: the exiting thread goes
  (main); the teardown child stays (branch).
- tests/toyos.rs: `quiesce_wakes_on_the_last_teardown` registered Nightly
  beside `quiesce_wakes_on_the_last_park`, which #564 moved to Nightly: same
  binary, same verdict, same disabling issue, and a new row has no catch
  record to put it anywhere else. Its CARRIES row and dispatch arm stay; the
  exit and dump rows go.
- toyos-quiesce `LAST_THREAD`, tests/quiescelastcase/system.toml and the two
  quiesce issues: name the teardown actuator beside the park, not the exit;
  the "in a Fast tier" of the gave-up issue's exit conditions is deleted,
  since both its tests are Nightly now.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
src/redlist.rs conflict: main's #564 deleted so_cache_refusals and
usb_disk_index_stable rows (their tests are gone); this branch's redial
fix deleted swap_crash_rolls_back, swap_netd and lan_swap rows (their
tests now pass). Both sets of deletions kept; no row this branch changed
was reverted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
#564's schedule and its 15 deletions meet this branch's storage move.
Where #564 deleted a test or the kernel code only it armed, the deletion
stands; where this branch deleted a test #564 retiered, this branch's
deletion stands; every surviving row takes #564's tier, and the five this
branch adds (fsd_restart, fsd_end_at_mount, fsd_claim_held, fsd_two_data,
blockd_serves_nothing) keep the Fast tier they were added at, as #564 kept
the tier of every row main added.

- kernel/src/actuator.rs: quiesce-last-exit and quiesce-dump go (#564);
  fat-flush-meta-refuse, resize-evict-window and resize-fault-refuse stay
  gone (this branch).
- kernel/src/syscall/machine.rs: the stop serves no dump (#564) and syncs
  no filesystem (this branch): neither block survives.
- toyos-quiesce/src/lib.rs: this branch's FILES_MS, FLUSH_MS and SYNC_MS,
  and #564's LAST_THREAD doc naming quiesce-last-park alone.
- tests/common/power.rs: quiesce_dump_holds_the_stopped goes with its
  actuator; quiesce_wakes_on_the_last_park is #564's inlined body with this
  branch's stop-record ordering in place of "Syncing filesystems...".
- tests/common/storage.rs and tests/toyos-rust-tests/src/bin/so_cache_policy.rs:
  so_cache_refusals and its binary go (#564); this branch's /tmp retarget of
  them serves no surviving test. The so-cache-tiny actuator went with them.
- issues/filesystem/home-budget-refusal-retried-is-red-on-every-nightly.md
  stays deleted: its test and binary are gone on both sides, and the
  reproducer #564's exit names is the kernel's /home over its NVMe driver,
  which this branch deletes. The fsync-budget-spent race it pointed at is
  still tracked by the partition-claim-gives-up issue.
- issues/README.md: boot-media is gated by esp_filesystem, kernel_log_file,
  log_partition_layout and log_partition_identity, plus toybox_cp_volume:
  wall_clock_file went in #564, log_backing_read_error and
  boot_volume_metadata_error on this branch.
- tests/toyos.rs: RUST_SKIP, MACHINE_TESTS, CARRIES and the dispatch lose
  so_cache_refusals, quiesce_wakes_on_the_last_exit and
  quiesce_dump_holds_the_stopped (#564) and keep this branch's deletions
  (cache_eviction, the writeback trio, page_cache_partition_offset,
  quiesce_leaves_the_volume_whole, ftruncate_flush_race,
  log_backing_read_error, boot_volume_metadata_error); the comment of the
  deleted ftruncate_flush_race row goes with it. #564's tier for
  block_duplicate_id, partition_claim_departure, quiesce_refuses_a_second_shutdown,
  quiesce_wakes_on_the_last_park, late_storage_connect, log_partition_layout,
  the root_* rows, log_partition_identity, tls_rebase_window,
  sysret_ss_reload, userdev_residue_is_its_own and
  blockd_lends_within_its_bound, beside this branch's comments.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
…-notiming

Where #564 deleted a test or helper this branch edits, the deletion stands:
home_budget_refusal_retried (with this branch's `fsync-budget-spent: staged
a spent budget on` record in kernel/src/object/ops.rs, which only that test
read), usb_disk_index_stable, wall_clock_file, quiesce_wakes_on_the_last_exit
and quiesce_dump_holds_the_stopped. wallclock's `after_the_base` stays: it
still bounds wall_clock_zone.

Rows both sides changed take this branch's Sched and comment and #564's tier
(netd_hostile_peer: Parallel, Weekly; hda_two_live_refused: Weekly;
panic_halts_the_others_first: Nightly). Rows #564 left to this branch keep
this branch's form. Tests this branch deleted stay deleted.

The harness's host checks live in tests/checks.rs now: stall_is_not_a_verdict
is renamed a_stall_stays_red there with this branch's backstop case,
i8042_quarantine_verdict goes with the idle-trip check this branch deleted,
and metal_audio_judges joins them as a libtest test instead of a guest row.
`schedule` and `--list` lose AUDIO_TESTS, `--audio-gate` leaves testargs
beside `--weekly`, and a reach is refused beside `--metal` only.

Sentences the merged tree makes false are deleted: the audio helpers
the-harness-carries-three-helpers-nothing-calls named as this branch's to
delete, and quiesce_wakes_on_the_last_exit in
timing-verdicts-ruled-off-qemu-have-no-metal-arm.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Japabu added a commit that referenced this pull request Sep 28, 2026
…t back i8042_health_cadence's dead registration

`git log -p -S i8042_health_cadence` on this branch: this branch's own "No
QEMU test measures time" commit (ad3448d) deleted the test in full —
registration, CARRIES binding, dispatch arm and its issue — ruling its
verdict a timing cadence over a real span with no event to wait on instead.
origin/main never deleted it (it still carries all three there). The later
merge of main's #564 (the measured schedule, which retiered several
neighbouring i8042 entries in the same MACHINE_TESTS hunk) reintroduced only
the registration line and its comment, while correctly keeping the CARRIES
entry and match arm deleted — a partial revert of ad3448d left by that
merge's conflict resolution. `cargo test --test toyos-build -- --list`
compared against every match arm in `run_machine_test` (the site
"unknown input test" comes from) and `run_screen_test` otherwise agrees
everywhere; this was the one gap.

Fix: delete the orphaned registration and comment. No dispatch to restore —
main's version is exactly the timing verdict #562 ruled out, and its issue
close and tracker mention already reflect the deletion.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant