diff --git a/CLAUDE.md b/CLAUDE.md index 668e00682e8..7e88e73747c 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -62,7 +62,7 @@ Only **Rust** and **QEMU** (for development), on any host OS and architecture Vendor firmware a device verifies by its maker's signature may be shipped: pinned by version and hash, redistributable unmodified, recorded in `NOTICE`, and loaded only by that device's own driver through its IOMMU domain; it never executes on the CPU. -The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, four macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold. +The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, two macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold. - **toyos-ld** — frozen: everything links with rust-lld, and toyos-ld stays only as the linker inside ToyOS until lld runs there, then goes. - **rust/** — Rust compiler/std fork with ToyOS platform support (submodule). Auto-bootstraps; kept current with upstream. Its rules: `src/forkcheck.rs`'s module header. diff --git a/issues/build/python-and-cc-are-declared.md b/issues/build/python-and-cc-are-declared.md index 14274af8d1f..f73474271dc 100644 --- a/issues/build/python-and-cc-are-declared.md +++ b/issues/build/python-and-cc-are-declared.md @@ -40,7 +40,7 @@ Rust bootstrap again as an incidental fix; do not soften the entry either. `src/toolchain.rs:749` picks `./x` when `rust/x` exists, which it does. That file is a `/bin/sh` script whose whole job is `SEARCH="python3 python py python2 uv"`, -and it execs `x.py` → `rust/src/bootstrap/bootstrap.py` (55,550 bytes). So a clean +and it execs `x.py` → `rust/src/bootstrap/bootstrap.py`. So a clean clone cannot build a toolchain without Python 3. It is upstream's bootstrap and not our code, which is why it is stated rather than blamed — but the bar has no upstream exemption, and `bootstrap.py` can never run inside ToyOS. @@ -70,3 +70,24 @@ their platform's own, which is their premise. Neither reaches a guest. The exit condition is Python's: they go when the build no longer needs a host, which is the self-hosting track's last stage (`issues/build/toyos-builds-itself.md`). + +**What removing each takes.** + +- **Python.** Upstream has no Python-free entry: `x`, `x.py` and + `src/tools/x` all end in `bootstrap.py`. But `src/bootstrap` builds with + rustup's stable cargo, `--locked`, and no Python, and the binary downloads + its own stage0 (`download_beta_toolchain`) and looks for a Python only to run + tests. So `src/toolchain.rs` could build and run it in place of + `bootstrap.py`, with no change to the fork, taking over `bootstrap.py`'s + environment contract at every fork bump. That removes Python only from a + build that reuses a keyed LLVM: LLVM's own CMake requires a Python 3 + (`find_package(Python3 … REQUIRED)`), so building an LLVM needs one until CMake goes. +- **`cc` has two jobs**: it links every host binary, and it is + the C++ compiler of LLVM, clang, LLD and `rustc_llvm` (`bootstrap.toml`'s + `cc`/`cxx`, named in `src/llvm.rs`, with `xcrun` asked for the SDK). It also + compiles `ring`'s C for `tests/https-server-host` and + `tests/https-fetch-host`. `rust-lld` can take only the link. Nothing replaces the compile but a clang the host did not build. +- **CMake and Ninja.** LLVM, clang and LLD are described in CMake. The only other build + descriptions upstream carries are an unsupported GN overlay (`BUILD.gn`) + and a Bazel one. Replacing CMake means writing one of those and keeping it + in Rust, which is M5's. diff --git a/issues/build/the-owners-flash-script-runs-diskutil.md b/issues/build/the-owners-flash-script-runs-diskutil.md new file mode 100644 index 00000000000..611c778d8c7 --- /dev/null +++ b/issues/build/the-owners-flash-script-runs-diskutil.md @@ -0,0 +1,22 @@ +--- +status: open +kind: tooling +opened: 2026-09-29 +--- + +# The owner's flash script runs `diskutil`, and no ledger declares it + +`diag/flash.sh` writes an image to a USB stick through `diskutil` and `plutil`, +which are macOS binaries, and through `shasum`, `dd` and `sudo`. The README's +flashing steps also run `diskutil`. None of these is in CLAUDE.md's standing +failures, and `src/sourcegate.rs`'s `HOST_SPAWNS` reads only `Command::new` in +Rust, so no gate sees them. The metal loop does not use this script: it flashes +the T14's stick over `ssh` from Ubuntu. + +The script's two gates are what keep it off an internal drive: it takes only +disks that `diskutil list external physical` names, and it writes only to a +disk that reports `Internal=false` and `BusProtocol=USB` on its own account. A +replacement keeps both. + +**Exit**: `rg -l "diskutil|plutil"` over the tree outside `rust/` finds nothing, and +the build system writes the stick. diff --git a/issues/kernel/every-driver-is-still-in-the-kernel.md b/issues/kernel/every-driver-is-still-in-the-kernel.md index 74dd618ce25..e6bf7cd67f1 100644 --- a/issues/kernel/every-driver-is-still-in-the-kernel.md +++ b/issues/kernel/every-driver-is-still-in-the-kernel.md @@ -29,9 +29,14 @@ is not built. What is left of the staged work: -1. **The kernel's audio registry is a concrete match on a device type.** The - file this was scoped against has since been deleted, so this needs re-scoping - before it can start; the GPU trait is the model to copy. +1. **Audio and virtio-gpu, re-scoped.** `drivers/hda.rs` and + `drivers/virtio_sound.rs` bring their device up and gate soundd's register + access; `drivers/virtio_gpu.rs` is the only `Gpu` whose `SYS_GPU_*` calls do + anything, since GOP's are all no-ops. Each leaves when its userland holder + claims the function as `pci`, as netd does, retiring the `hda-audio` and + `virtio-sound` classes, their arms of `SYS_DEVICE_REG_READ`/`WRITE`, and + `SYS_GPU_*`, which is an ABI change. GOP stays: it is memory the loader + hands over, and the panic console paints it. 2. Done: **BAR sizing and re-assignment onto 2 MiB boundaries** is `pcidev::place_bar`, with the overlap refusal kept as the assertion that it worked rather than as the mechanism. diff --git a/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md b/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md index 614cc269375..696e5048872 100644 --- a/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md +++ b/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md @@ -136,7 +136,10 @@ times: has no kernel hotkey from this step, declared. **Exit**, on the T14: `/log` survives usbd killed mid-batch, the keyboard keeps working while a stick misbehaves, and Ctrl+Alt+D on the machine's own keyboard files - the dump with usbd killed. + the dump with usbd killed. Where QEMU's and the T14's xHCI keep their + MSI-X tables is not measured: one in the BAR that holds the registers + refuses usbd's claim as it refuses blockd's + (`issues/kernel/a-controller-whose-msix-table-is-in-bar-0-cannot-be-driven-from-userland.md`). 5. **USB by userland**, with discovery and recovery written once as straight-line code. **Exit**: no interrupts-off window longer than a register access, and keyboard input keeps flowing while a diff --git a/issues/kernel/the-kernel-still-creates-threads.md b/issues/kernel/the-kernel-still-creates-threads.md index a263a8df7e8..8fe48d7f639 100644 --- a/issues/kernel/the-kernel-still-creates-threads.md +++ b/issues/kernel/the-kernel-still-creates-threads.md @@ -21,12 +21,10 @@ code creates a schedulable task other than the per-CPU idle loop. **Stages:** -- **K2:** the reaper PR #549 introduces becomes last-thread-out: the victim's - last thread tears down its own process on its way out of the kernel, and the - scheduler frees that thread's kernel stack after switching away. Blocked on - #549 landing. -- **K4:** `klogd` goes: the owner-approved driver-model design moves the - console to logd, and this track owns that move. +- **K4:** `klogd` goes: the console moves to logd, and this track owns that move. The boot before logd runs + and the panic path write the console wire (`log::console::drain_inline`, + `serial::panic_flush`), so one wire's driver stays in the kernel whatever + K4 moves. - **K5:** `iod` goes with the kernel's write-back queue; met only when #536 lands with no new `kthread::spawn`. -- **K6:** delete the machinery named above. Blocked on K2, K4 and K5. +- **K6:** delete the machinery named above. Blocked on K4 and K5. diff --git a/src/sourcegate.rs b/src/sourcegate.rs index 4dd9dbcecb7..e2a37b0156c 100644 --- a/src/sourcegate.rs +++ b/src/sourcegate.rs @@ -608,10 +608,7 @@ const HOST_SPAWNS: &[Spawn] = &[ arg: "\"/usr/bin/hdiutil\"", sites: &[], why: "the other one: newfs_msdos refuses a plain file, so the fixture is formatted \ - through a device node. **Two, where CLAUDE.md says four macOS FAT tools**: \ - `fsck_msdos` came out of all three of its call sites on 2026-08-08 \ - (issues/filesystem/fat32-suite-needs-macos-binaries.md, which counts two left) \ - and the sentence was not edited. The owner ruled on 2026-09-01 that `fatfs` \ + through a device node. The owner ruled on 2026-09-01 that `fatfs` \ replaces both of these, so this scan is what will notice when it has", }, Spawn {