From 4223c5f64bd9a9ccbad3ff6e8ddd3c7b2aa9fd71 Mon Sep 17 00:00:00 2001 From: japabu Date: Tue, 29 Sep 2026 09:58:35 +0200 Subject: [PATCH 1/2] issues: the standing debts' owners, re-scoped where the tree has moved The owner asked which known debts remain besides the crate sprawl and the C corpus. Research only; no code moves. - the-kernel-still-creates-threads: K2 is done (#549 deleted the reaper; `kthread::spawn` has two callers, klogd and iod), so K6 waits on K4 and K5 alone. K4 carries the constraint that the boot before logd and the panic path write the console wire, so one wire's driver stays. - every-driver-is-still-in-the-kernel: item 1 said it needed re-scoping because its file was deleted. It now names the HDA and virtio-sound stubs and virtio-gpu, which leave as `pci` claims the way netd did, and the ABI that retires with them. GOP stays for the panic console. - the-kernel-is-small: step 10 (usbd) meets the MSI-X-table-in-BAR-0 refusal that blocks blockd, and where either xHCI keeps its table is unmeasured. - python-and-cc-are-declared: what removing each takes, measured at the fork's pinned 9c3eea44. The Rust bootstrap builds with stable cargo and no Python, but LLVM's CMake requires Python 3. `cc` also compiles LLVM's C++, and rust-lld can take only the link, which on macOS still needs the SDK and fails on 27.0's TAPI stubs. CMake is 726 CMakeLists.txt and has no Rust replacement. - new: diag/flash.sh runs diskutil and plutil, and no ledger declares them. Co-Authored-By: Claude Opus 5.5 --- issues/build/python-and-cc-are-declared.md | 31 +++++++++++++++++++ .../the-owners-flash-script-runs-diskutil.md | 22 +++++++++++++ .../every-driver-is-still-in-the-kernel.md | 11 +++++-- ...-small-interrupts-post-and-threads-wait.md | 5 ++- .../the-kernel-still-creates-threads.md | 11 +++---- 5 files changed, 70 insertions(+), 10 deletions(-) create mode 100644 issues/build/the-owners-flash-script-runs-diskutil.md diff --git a/issues/build/python-and-cc-are-declared.md b/issues/build/python-and-cc-are-declared.md index 14274af8d1f..18a6e8ed1b2 100644 --- a/issues/build/python-and-cc-are-declared.md +++ b/issues/build/python-and-cc-are-declared.md @@ -70,3 +70,34 @@ their platform's own, which is their premise. Neither reaches a guest. The exit condition is Python's: they go when the build no longer needs a host, which is the self-hosting track's last stage (`issues/build/toyos-builds-itself.md`). + +**What removing each takes, measured at the fork's pinned `9c3eea44`.** + +- **Python.** Upstream has no Python-free entry: `x`, `x.py` and + `src/tools/x` all end in `bootstrap.py`. But `src/bootstrap` builds with + rustup's stable cargo, `--locked`, and no Python, and the binary downloads + its own stage0 (`download_beta_toolchain`) and looks for a Python only to run + tests. So `src/toolchain.rs` could build and run it in place of + `bootstrap.py`, with no change to the fork, taking over `bootstrap.py`'s + environment contract at every fork bump. That removes Python only from a + build that reuses a keyed LLVM: LLVM's own CMake requires a Python 3 + (`find_package(Python3 … REQUIRED)`, `llvm/CMakeLists.txt:1016` at the + pinned `src/llvm-project`), so building an LLVM needs one until CMake goes. + Nobody has run it end to end, and whether to try is the owner's call under + the ruling of 2026-09-01. +- **`cc` has two jobs**: it links every host binary, and it is + the C++ compiler of LLVM, clang, LLD and `rustc_llvm` (`bootstrap.toml`'s + `cc`/`cxx`, named in `src/llvm.rs`, with `xcrun` asked for the SDK). It also + compiles `ring`'s C for `tests/https-server-host` and + `tests/https-fetch-host`. `rust-lld` can take only the link. On the macOS dev + host, nightly's `rust-lld` (LLVM 22.1.0) links a host `hello` against + `MacOSX14.4.sdk` with `-Zunstable-options -C linker-flavor=darwin-lld`; the + flavor is unstable on stable 1.98.1. It refuses the default + `MacOSX27.0.sdk`'s TAPI stubs (`unknown architecture` at + `arm64e.x1-macos`), and it needs Apple's SDK in either case. + Nothing replaces the compile but a clang the host did not build. +- **CMake and Ninja.** LLVM, clang and LLD at the pinned `src/llvm-project` + have 726 `CMakeLists.txt` and 78 `.cmake` modules. The only other build + descriptions upstream carries are an unsupported GN overlay (740 `BUILD.gn`) + and a Bazel one. Replacing CMake means writing one of those and keeping it + in Rust, which is M5's. diff --git a/issues/build/the-owners-flash-script-runs-diskutil.md b/issues/build/the-owners-flash-script-runs-diskutil.md new file mode 100644 index 00000000000..ad1f4f93af9 --- /dev/null +++ b/issues/build/the-owners-flash-script-runs-diskutil.md @@ -0,0 +1,22 @@ +--- +status: open +kind: tooling +opened: 2026-09-29 +--- + +# The owner's flash script runs `diskutil`, and no ledger declares it + +`diag/flash.sh` writes an image to a USB stick through `diskutil` and `plutil`, +which are macOS binaries, and through `shasum`, `dd` and `sudo`. The README's +flashing steps also run `diskutil`. None of these is in CLAUDE.md's standing +failures, and `src/sourcegate.rs`'s `HOST_SPAWNS` reads only `Command::new` in +Rust, so no gate sees them. The metal loop does not use this script: it flashes +the T14's stick over `ssh` from Ubuntu. + +The script's two gates are what keep it off an internal drive: it takes only +disks that `diskutil list external physical` names, and it writes only to a +disk that reports `Internal=false` and `BusProtocol=USB` on its own account. A +replacement keeps both. + +**Exit**: no `diskutil` or `plutil` anywhere in the tree, and the stick is +written by the build system or by nothing. diff --git a/issues/kernel/every-driver-is-still-in-the-kernel.md b/issues/kernel/every-driver-is-still-in-the-kernel.md index 2bd6b1ef0c3..29212d75895 100644 --- a/issues/kernel/every-driver-is-still-in-the-kernel.md +++ b/issues/kernel/every-driver-is-still-in-the-kernel.md @@ -27,9 +27,14 @@ is not built. What is left of the staged work: -1. **The kernel's audio registry is a concrete match on a device type.** The - file this was scoped against has since been deleted, so this needs re-scoping - before it can start; the GPU trait is the model to copy. +1. **Audio and virtio-gpu, re-scoped.** `drivers/hda.rs` and + `drivers/virtio_sound.rs` bring their device up and gate soundd's register + access; `drivers/virtio_gpu.rs` is the only `Gpu` whose `SYS_GPU_*` calls do + anything, since GOP's are all no-ops. Each leaves when its userland holder + claims the function as `pci`, as netd does, retiring the `hda-audio` and + `virtio-sound` classes, their arms of `SYS_DEVICE_REG_READ`/`WRITE`, and + `SYS_GPU_*`, which is an ABI change. GOP stays: it is memory the loader + hands over, and the panic console paints it. 2. Done: **BAR sizing and re-assignment onto 2 MiB boundaries** is `pcidev::place_bar`, with the overlap refusal kept as the assertion that it worked rather than as the mechanism. diff --git a/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md b/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md index 614cc269375..696e5048872 100644 --- a/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md +++ b/issues/kernel/the-kernel-is-small-interrupts-post-and-threads-wait.md @@ -136,7 +136,10 @@ times: has no kernel hotkey from this step, declared. **Exit**, on the T14: `/log` survives usbd killed mid-batch, the keyboard keeps working while a stick misbehaves, and Ctrl+Alt+D on the machine's own keyboard files - the dump with usbd killed. + the dump with usbd killed. Where QEMU's and the T14's xHCI keep their + MSI-X tables is not measured: one in the BAR that holds the registers + refuses usbd's claim as it refuses blockd's + (`issues/kernel/a-controller-whose-msix-table-is-in-bar-0-cannot-be-driven-from-userland.md`). 5. **USB by userland**, with discovery and recovery written once as straight-line code. **Exit**: no interrupts-off window longer than a register access, and keyboard input keeps flowing while a diff --git a/issues/kernel/the-kernel-still-creates-threads.md b/issues/kernel/the-kernel-still-creates-threads.md index a263a8df7e8..e0da3f6f688 100644 --- a/issues/kernel/the-kernel-still-creates-threads.md +++ b/issues/kernel/the-kernel-still-creates-threads.md @@ -21,12 +21,11 @@ code creates a schedulable task other than the per-CPU idle loop. **Stages:** -- **K2:** the reaper PR #549 introduces becomes last-thread-out: the victim's - last thread tears down its own process on its way out of the kernel, and the - scheduler frees that thread's kernel stack after switching away. Blocked on - #549 landing. - **K4:** `klogd` goes: the owner-approved driver-model design moves the - console to logd, and this track owns that move. + console to logd, and this track owns that move. The boot before logd runs + and the panic path write the console wire (`log::console::drain_inline`, + `serial::panic_flush`), so one wire's driver stays in the kernel whatever + K4 moves. - **K5:** `iod` goes with the kernel's write-back queue; met only when #536 lands with no new `kthread::spawn`. -- **K6:** delete the machinery named above. Blocked on K2, K4 and K5. +- **K6:** delete the machinery named above. Blocked on K4 and K5. From 2e0775938b651b69cf03bcb0bb9637e632ba6f28 Mon Sep 17 00:00:00 2001 From: japabu Date: Tue, 29 Sep 2026 15:50:03 +0200 Subject: [PATCH 2/2] Answer the review of #607: cut point-in-time numbers, name checkable exits python-and-cc-are-declared.md loses its counts, versions, hash, the CMakeLists line cite, the unrun-bootstrap narration and the rust-lld measurement that named no command. The flash-script issue's exit is now `rg -l "diskutil|plutil"` outside rust/ finding nothing. K4 no longer cites a driver-model design the tree does not hold. CLAUDE.md says two macOS FAT tools, which is what the tree has, and the sourcegate clause that recorded the mismatch goes with it. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01U6SVYFkdvV2t38KzNrESxs --- CLAUDE.md | 2 +- issues/build/python-and-cc-are-declared.md | 22 +++++-------------- .../the-owners-flash-script-runs-diskutil.md | 4 ++-- .../the-kernel-still-creates-threads.md | 3 +-- src/sourcegate.rs | 5 +---- 5 files changed, 11 insertions(+), 25 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 668e00682e8..7e88e73747c 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -62,7 +62,7 @@ Only **Rust** and **QEMU** (for development), on any host OS and architecture Vendor firmware a device verifies by its maker's signature may be shipped: pinned by version and hash, redistributable unmodified, recorded in `NOTICE`, and loaded only by that device's own driver through its IOMMU domain; it never executes on the CPU. -The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, four macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold. +The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, two macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold. - **toyos-ld** — frozen: everything links with rust-lld, and toyos-ld stays only as the linker inside ToyOS until lld runs there, then goes. - **rust/** — Rust compiler/std fork with ToyOS platform support (submodule). Auto-bootstraps; kept current with upstream. Its rules: `src/forkcheck.rs`'s module header. diff --git a/issues/build/python-and-cc-are-declared.md b/issues/build/python-and-cc-are-declared.md index 18a6e8ed1b2..f73474271dc 100644 --- a/issues/build/python-and-cc-are-declared.md +++ b/issues/build/python-and-cc-are-declared.md @@ -40,7 +40,7 @@ Rust bootstrap again as an incidental fix; do not soften the entry either. `src/toolchain.rs:749` picks `./x` when `rust/x` exists, which it does. That file is a `/bin/sh` script whose whole job is `SEARCH="python3 python py python2 uv"`, -and it execs `x.py` → `rust/src/bootstrap/bootstrap.py` (55,550 bytes). So a clean +and it execs `x.py` → `rust/src/bootstrap/bootstrap.py`. So a clean clone cannot build a toolchain without Python 3. It is upstream's bootstrap and not our code, which is why it is stated rather than blamed — but the bar has no upstream exemption, and `bootstrap.py` can never run inside ToyOS. @@ -71,7 +71,7 @@ exit condition is Python's: they go when the build no longer needs a host, which is the self-hosting track's last stage (`issues/build/toyos-builds-itself.md`). -**What removing each takes, measured at the fork's pinned `9c3eea44`.** +**What removing each takes.** - **Python.** Upstream has no Python-free entry: `x`, `x.py` and `src/tools/x` all end in `bootstrap.py`. But `src/bootstrap` builds with @@ -81,23 +81,13 @@ which is the self-hosting track's last stage `bootstrap.py`, with no change to the fork, taking over `bootstrap.py`'s environment contract at every fork bump. That removes Python only from a build that reuses a keyed LLVM: LLVM's own CMake requires a Python 3 - (`find_package(Python3 … REQUIRED)`, `llvm/CMakeLists.txt:1016` at the - pinned `src/llvm-project`), so building an LLVM needs one until CMake goes. - Nobody has run it end to end, and whether to try is the owner's call under - the ruling of 2026-09-01. + (`find_package(Python3 … REQUIRED)`), so building an LLVM needs one until CMake goes. - **`cc` has two jobs**: it links every host binary, and it is the C++ compiler of LLVM, clang, LLD and `rustc_llvm` (`bootstrap.toml`'s `cc`/`cxx`, named in `src/llvm.rs`, with `xcrun` asked for the SDK). It also compiles `ring`'s C for `tests/https-server-host` and - `tests/https-fetch-host`. `rust-lld` can take only the link. On the macOS dev - host, nightly's `rust-lld` (LLVM 22.1.0) links a host `hello` against - `MacOSX14.4.sdk` with `-Zunstable-options -C linker-flavor=darwin-lld`; the - flavor is unstable on stable 1.98.1. It refuses the default - `MacOSX27.0.sdk`'s TAPI stubs (`unknown architecture` at - `arm64e.x1-macos`), and it needs Apple's SDK in either case. - Nothing replaces the compile but a clang the host did not build. -- **CMake and Ninja.** LLVM, clang and LLD at the pinned `src/llvm-project` - have 726 `CMakeLists.txt` and 78 `.cmake` modules. The only other build - descriptions upstream carries are an unsupported GN overlay (740 `BUILD.gn`) + `tests/https-fetch-host`. `rust-lld` can take only the link. Nothing replaces the compile but a clang the host did not build. +- **CMake and Ninja.** LLVM, clang and LLD are described in CMake. The only other build + descriptions upstream carries are an unsupported GN overlay (`BUILD.gn`) and a Bazel one. Replacing CMake means writing one of those and keeping it in Rust, which is M5's. diff --git a/issues/build/the-owners-flash-script-runs-diskutil.md b/issues/build/the-owners-flash-script-runs-diskutil.md index ad1f4f93af9..611c778d8c7 100644 --- a/issues/build/the-owners-flash-script-runs-diskutil.md +++ b/issues/build/the-owners-flash-script-runs-diskutil.md @@ -18,5 +18,5 @@ disks that `diskutil list external physical` names, and it writes only to a disk that reports `Internal=false` and `BusProtocol=USB` on its own account. A replacement keeps both. -**Exit**: no `diskutil` or `plutil` anywhere in the tree, and the stick is -written by the build system or by nothing. +**Exit**: `rg -l "diskutil|plutil"` over the tree outside `rust/` finds nothing, and +the build system writes the stick. diff --git a/issues/kernel/the-kernel-still-creates-threads.md b/issues/kernel/the-kernel-still-creates-threads.md index e0da3f6f688..8fe48d7f639 100644 --- a/issues/kernel/the-kernel-still-creates-threads.md +++ b/issues/kernel/the-kernel-still-creates-threads.md @@ -21,8 +21,7 @@ code creates a schedulable task other than the per-CPU idle loop. **Stages:** -- **K4:** `klogd` goes: the owner-approved driver-model design moves the - console to logd, and this track owns that move. The boot before logd runs +- **K4:** `klogd` goes: the console moves to logd, and this track owns that move. The boot before logd runs and the panic path write the console wire (`log::console::drain_inline`, `serial::panic_flush`), so one wire's driver stays in the kernel whatever K4 moves. diff --git a/src/sourcegate.rs b/src/sourcegate.rs index 4dd9dbcecb7..e2a37b0156c 100644 --- a/src/sourcegate.rs +++ b/src/sourcegate.rs @@ -608,10 +608,7 @@ const HOST_SPAWNS: &[Spawn] = &[ arg: "\"/usr/bin/hdiutil\"", sites: &[], why: "the other one: newfs_msdos refuses a plain file, so the fixture is formatted \ - through a device node. **Two, where CLAUDE.md says four macOS FAT tools**: \ - `fsck_msdos` came out of all three of its call sites on 2026-08-08 \ - (issues/filesystem/fat32-suite-needs-macos-binaries.md, which counts two left) \ - and the sentence was not edited. The owner ruled on 2026-09-01 that `fatfs` \ + through a device node. The owner ruled on 2026-09-01 that `fatfs` \ replaces both of these, so this scan is what will notice when it has", }, Spawn {