Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ Only **Rust** and **QEMU** (for development), on any host OS and architecture

Vendor firmware a device verifies by its maker's signature may be shipped: pinned by version and hash, redistributable unmodified, recorded in `NOTICE`, and loaded only by that device's own driver through its IOMMU domain; it never executes on the CPU.

The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, four macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold.
The bar is not yet the tree. The standing failures are declared rather than removed — Python via `rust/x`, `cc` for every host link, two macOS FAT tools. `NOTICE` names every committed third-party file with its hash, upstream and licence; an image carrying `DOOM1.WAD` may not be sold.

- **toyos-ld** — frozen: everything links with rust-lld, and toyos-ld stays only as the linker inside ToyOS until lld runs there, then goes.
- **rust/** — Rust compiler/std fork with ToyOS platform support (submodule). Auto-bootstraps; kept current with upstream. Its rules: `src/forkcheck.rs`'s module header.
Expand Down
23 changes: 22 additions & 1 deletion issues/build/python-and-cc-are-declared.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ Rust bootstrap again as an incidental fix; do not soften the entry either.

`src/toolchain.rs:749` picks `./x` when `rust/x` exists, which it does. That file
is a `/bin/sh` script whose whole job is `SEARCH="python3 python py python2 uv"`,
and it execs `x.py` → `rust/src/bootstrap/bootstrap.py` (55,550 bytes). So a clean
and it execs `x.py` → `rust/src/bootstrap/bootstrap.py`. So a clean
clone cannot build a toolchain without Python 3. It is upstream's bootstrap and
not our code, which is why it is stated rather than blamed — but the bar has no
upstream exemption, and `bootstrap.py` can never run inside ToyOS.
Expand Down Expand Up @@ -70,3 +70,24 @@ their platform's own, which is their premise. Neither reaches a guest. The
exit condition is Python's: they go when the build no longer needs a host,
which is the self-hosting track's last stage
(`issues/build/toyos-builds-itself.md`).

**What removing each takes.**

- **Python.** Upstream has no Python-free entry: `x`, `x.py` and
`src/tools/x` all end in `bootstrap.py`. But `src/bootstrap` builds with
rustup's stable cargo, `--locked`, and no Python, and the binary downloads
its own stage0 (`download_beta_toolchain`) and looks for a Python only to run
tests. So `src/toolchain.rs` could build and run it in place of
`bootstrap.py`, with no change to the fork, taking over `bootstrap.py`'s
environment contract at every fork bump. That removes Python only from a
build that reuses a keyed LLVM: LLVM's own CMake requires a Python 3
(`find_package(Python3 … REQUIRED)`), so building an LLVM needs one until CMake goes.
- **`cc` has two jobs**: it links every host binary, and it is
the C++ compiler of LLVM, clang, LLD and `rustc_llvm` (`bootstrap.toml`'s
`cc`/`cxx`, named in `src/llvm.rs`, with `xcrun` asked for the SDK). It also
compiles `ring`'s C for `tests/https-server-host` and
`tests/https-fetch-host`. `rust-lld` can take only the link. Nothing replaces the compile but a clang the host did not build.
- **CMake and Ninja.** LLVM, clang and LLD are described in CMake. The only other build
descriptions upstream carries are an unsupported GN overlay (`BUILD.gn`)
and a Bazel one. Replacing CMake means writing one of those and keeping it
in Rust, which is M5's.
22 changes: 22 additions & 0 deletions issues/build/the-owners-flash-script-runs-diskutil.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
status: open
kind: tooling
opened: 2026-09-29
---

# The owner's flash script runs `diskutil`, and no ledger declares it

`diag/flash.sh` writes an image to a USB stick through `diskutil` and `plutil`,
which are macOS binaries, and through `shasum`, `dd` and `sudo`. The README's
flashing steps also run `diskutil`. None of these is in CLAUDE.md's standing
failures, and `src/sourcegate.rs`'s `HOST_SPAWNS` reads only `Command::new` in
Rust, so no gate sees them. The metal loop does not use this script: it flashes
the T14's stick over `ssh` from Ubuntu.

The script's two gates are what keep it off an internal drive: it takes only
disks that `diskutil list external physical` names, and it writes only to a
disk that reports `Internal=false` and `BusProtocol=USB` on its own account. A
replacement keeps both.

**Exit**: `rg -l "diskutil|plutil"` over the tree outside `rust/` finds nothing, and
the build system writes the stick.
11 changes: 8 additions & 3 deletions issues/kernel/every-driver-is-still-in-the-kernel.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,14 @@ is not built.

What is left of the staged work:

1. **The kernel's audio registry is a concrete match on a device type.** The
file this was scoped against has since been deleted, so this needs re-scoping
before it can start; the GPU trait is the model to copy.
1. **Audio and virtio-gpu, re-scoped.** `drivers/hda.rs` and
`drivers/virtio_sound.rs` bring their device up and gate soundd's register
access; `drivers/virtio_gpu.rs` is the only `Gpu` whose `SYS_GPU_*` calls do
anything, since GOP's are all no-ops. Each leaves when its userland holder
claims the function as `pci`, as netd does, retiring the `hda-audio` and
`virtio-sound` classes, their arms of `SYS_DEVICE_REG_READ`/`WRITE`, and
`SYS_GPU_*`, which is an ABI change. GOP stays: it is memory the loader
hands over, and the panic console paints it.
2. Done: **BAR sizing and re-assignment onto 2 MiB boundaries** is
`pcidev::place_bar`, with the overlap refusal kept as the assertion that it
worked rather than as the mechanism.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -136,7 +136,10 @@ times:
has no kernel hotkey from this step, declared. **Exit**, on the T14:
`/log` survives usbd killed mid-batch, the keyboard keeps working while
a stick misbehaves, and Ctrl+Alt+D on the machine's own keyboard files
the dump with usbd killed.
the dump with usbd killed. Where QEMU's and the T14's xHCI keep their
MSI-X tables is not measured: one in the BAR that holds the registers
refuses usbd's claim as it refuses blockd's
(`issues/kernel/a-controller-whose-msix-table-is-in-bar-0-cannot-be-driven-from-userland.md`).
5. **USB by userland**, with discovery and recovery
written once as straight-line code. **Exit**: no interrupts-off window
longer than a register access, and keyboard input keeps flowing while a
Expand Down
12 changes: 5 additions & 7 deletions issues/kernel/the-kernel-still-creates-threads.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,12 +21,10 @@ code creates a schedulable task other than the per-CPU idle loop.

**Stages:**

- **K2:** the reaper PR #549 introduces becomes last-thread-out: the victim's
last thread tears down its own process on its way out of the kernel, and the
scheduler frees that thread's kernel stack after switching away. Blocked on
#549 landing.
- **K4:** `klogd` goes: the owner-approved driver-model design moves the
console to logd, and this track owns that move.
- **K4:** `klogd` goes: the console moves to logd, and this track owns that move. The boot before logd runs
and the panic path write the console wire (`log::console::drain_inline`,
`serial::panic_flush`), so one wire's driver stays in the kernel whatever
K4 moves.
- **K5:** `iod` goes with the kernel's write-back queue; met only when #536
lands with no new `kthread::spawn`.
- **K6:** delete the machinery named above. Blocked on K2, K4 and K5.
- **K6:** delete the machinery named above. Blocked on K4 and K5.
5 changes: 1 addition & 4 deletions src/sourcegate.rs
Original file line number Diff line number Diff line change
Expand Up @@ -608,10 +608,7 @@ const HOST_SPAWNS: &[Spawn] = &[
arg: "\"/usr/bin/hdiutil\"",
sites: &[],
why: "the other one: newfs_msdos refuses a plain file, so the fixture is formatted \
through a device node. **Two, where CLAUDE.md says four macOS FAT tools**: \
`fsck_msdos` came out of all three of its call sites on 2026-08-08 \
(issues/filesystem/fat32-suite-needs-macos-binaries.md, which counts two left) \
and the sentence was not edited. The owner ruled on 2026-09-01 that `fatfs` \
through a device node. The owner ruled on 2026-09-01 that `fatfs` \
replaces both of these, so this scan is what will notice when it has",
},
Spawn {
Expand Down
Loading