Skip to content

Where everything lives: the layout as ruled, and its first stage - #531

Merged
Japabu merged 9 commits into
mainfrom
wt/toyos-layout
Sep 26, 2026
Merged

Japabu merged 9 commits into
mainfrom
wt/toyos-layout

Conversation

@Japabu

@Japabu Japabu commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

The owner ruled on 2026-09-26 where everything in ToyOS lives. This PR records that ruling as a track and builds its first stage, the part that needs no isolation work.

What changed, and why

The layout is recorded in one place. issues/filesystem/where-everything-lives.md (a track) holds the tree, the rules and the stages with their exits. Every line in it is the owner's ruling, including the five the review asked about, which the orchestrator confirmed as owner-approved:

  • a third-party app may create a dotfile inside its own app folder (the honest limit);
  • /config overrides /system/etc;
  • per-user overrides of the keyboard layout and the language come with the users track;
  • an app finds its files next to its binary (current_exe());
  • /system is signed, because the self-update track signs the image. The track now says that nothing verifies it until that lands.

The stages are: 1 (this PR); 2, an app's HOME is its folder; 3, users; 4, the time zone (one file in /config, one writer, local time read through it, and no zone recovered by subtraction); 5, the language (one file in /config, one writer, init sets it on every program); 6, fonts ship as files (below); 7, the upstream arms. Each stage has an exit.

/config and /state exist. They are two more names DATA answers to. init makes /home/toy and its eight folders at boot, and makes a service's /state/<name> before each start. The kernel makes no home. A folder that fails now says which folder, not that the whole home is missing.

HOME is init's on every spawn path. This is the review's first blocker.

  • The launcher path. init sets HOME from the row on every start (Program::home), over whatever the caller carried: /state/<name> for a row marked service = true, the session's /home/toy for everything else.
  • The direct path. This is std's spawn of an undeclared program, or a spawn by a caller with no launcher, or by one that endowed a handle. Before, it handed the child the parent's whole environment, so an ssh exec of an undeclared binary ran with HOME=/state/sshd. Now init answers the launch of an undeclared program with the session's HOME (MSG_NOT_DECLARED carries it as its payload, and toyos::launch::Outcome::NotDeclared { home } holds it). std's direct spawn carries a HOME in only two cases: its caller named one, or init answered one. It never carries the parent's own. A direct spawn that init was not asked about carries no HOME.
  • Why init decides, and not a refusal. The isolation track (issues/isolation/every-program-sees-only-the-files-it-was-given.md) puts every location and every session in init's hands. A child's view is at most its parent's. At stage 3 a login authority asks init's launcher for a session instead of spawning one. Refusing the spawn would end the metal loop's and sshd_exec's runs of undeclared test binaries over ssh. Stripping the variable alone would give such a binary no HOME. Letting init answer is the one choice that keeps "a location reaches a program only from init" true today and that stage 3 needs no change to. The program's authority on the direct path is still inheritance, as before; only its HOME moved.

A serving row must be a service. toyos_manifest::render refuses a row that serves a port but is not marked service = true (ServesWithoutService). every_config_renders_its_manifest renders every config. A service that serves nothing, such as sshd, cannot be told apart from its row, so it is still marked by hand, and nothing in the build can refuse an unmarked sshd.

std answers $HOME. These are fork commits on ToyOSOrg/rust wt-toyos-layout:

The pin is 80ea645f.

An empty directory is listed. Vfs::list now names the directories the VFS carries in created_dirs, so an empty .config is in its parent's listing and the dotfile walk sees it. The listing still refuses past MAX_LIST_ENTRIES, as every FileSystem::list does. The filed DATA issue loses that bullet and is renamed issues/filesystem/a-directory-on-data-survives-no-reboot.md.

Machine settings leave the user's home. The keyboard layout is /config/keyboard-layout. sshd keeps its identity and key list in /state/sshd. The shell keeps its history in its own folder's State: $HOME/Apps/shell while HOME is the session's, and $HOME itself once stage 2 makes that folder its HOME (OWN_FOLDER), so the path does not double. Stage 2's exit names that line.

The SDK doc lines are now deleted, per the owner's rule. The prior state of this branch had corrected the 26 lines (/bin/x to /system/bin/x) instead, flagged as a deviation for the orchestrator to confirm. The owner's rule stands: /bin and /system/bin are both deleted from these sentences, leaving each program named by itself (`init`, `logd`, `toybox`, `ps`, `sshd`, `ls`, `terminal`, `console`) rather than by a path that names ToyOS's own tree inside a crate three external forks (winit, softbuffer, cpal) resolve by version — the concrete deployment path is exactly the free text that just rotted once and would rot again at the next layout move. cargo doc --no-deps on toyos-abi, toyos and userland/toyos-window builds clean (pre-existing unrelated warnings only, unchanged from before this edit).

This PR no longer ships JetBrains Mono. src/assets.rs and NOTICE are back to main's, which ends the collision with #528 (see below).

/log/lease.txt does not move. It is the metal loop's bench report on the FAT log volume, not netd's lease, and the track records this.

#528 and src/assets.rs

The resolution the track records (stage 6) is:

  • TTFs ship as files under /system/share/fonts from assets/fonts/;
  • the console raster stays its own asset, rasterized from the top-level TTF;
  • each OFL text ships once, under /system/share/licenses.

This branch no longer touches src/assets.rs or NOTICE, so the two branches share no hunk there, and neither has to change anything in those files to land after the other. At #528's head (42059f54, and 5fc53dbc in its worktree), the_system_fonts_ship_with_their_licence puts the Open Sans OFL at share/fonts/ofl.txt. That meets stage 6's "every OFL text in /system/share/licenses" only once assets/fonts/OFL.txt moves under assets/licenses/ and that test asserts the new path. JetBrains Mono as a file, assets/fonts/JetBrainsMono-Regular.ttf (the same blob as the top-level one), is stage 6's too. Whoever builds stage 6 owns both. Neither is a landing condition for either PR.

Tests

layout_fresh_boot (Fast, Parallel) boots tests/layoutcase on a blank DATA volume with a staged key: tests/sshdcase, plus a declared shell and the locale applet. Over ssh it checks:

  1. shell -c 'echo $HOME' prints /home/toy. The shell is a declared row, so its HOME comes from init's start, over sshd's /state/sshd.
  2. locale de sets the layout, and an interactive shell runs echo layout history.
  3. test_rs_layout_paths de 'echo layout history' runs. Nothing declares it, so sshd spawns it directly. It asserts:
    • HOME and home_dir() are /home/toy, and /home/root is absent;
    • /home/toy lists exactly the eight folders and /state lists exactly logd netd sshd;
    • /state/sshd/host_ed25519 is a file;
    • /config/keyboard-layout reads de and /home/toy/Apps/shell/State/history holds the typed line, both asked for by literal path;
    • no entry under /apps /config /home /log /state /tmp starts with a dot.

The host also checks sshd's minted a new host identity at /state/sshd/host_ed25519 line.

Negative controls

Each control was a checked patch against the committed green arm. The script applied it, ran layout_fresh_boot, reverse-applied it, and showed the tree clean. Every red names the mutated behaviour, which shows the mutated tree built and ran. The rows through m4b were measured at 75942e24; the kernel rows were measured again at 542f00ed.

mutation exit red because
B1: the whole HOME routing reverted (fork 957f1426 reversed in rust/, toyos/src/launch.rs to base, init's MSG_NOT_DECLARED back to a bare signal) 1 HOME is Ok("/state/sshd"), home_dir() is Some("/state/sshd")
B2: command.env("HOME", &home) deleted from start, boot path given HOME at its call site (the reviewer's) 1 a launched shell's HOME is "/state/sshd\n"
B3: ".config" added to init's HOME_FOLDERS (the reviewer's) 1 /home/toy lists [".config", …], a dotfile on a fresh boot: ["/home/toy/.config"]
B4a: LAYOUT_CONFIG = "/home/toy/.config/keyboard-layout" (the reviewer's) 1 /config/keyboard-layout: NotFound, a dotfile /home/toy/.config
B4b: history at $HOME/.shell_history (the reviewer's; OWN_FOLDER deleted with it so it builds) 1 …/Apps/shell/State/history: NotFound, a dotfile /home/toy/.shell_history
kernel: the Vfs::list change reverted 1 /home/toy lists ["Apps"], /state lists ["sshd"]
kernel reverted and B3 1 same, and no dotfile line: without the kernel change the walk cannot see .config, which is the review's finding
green arm at 75942e24 (twice) and at 542f00ed 0

Host: toyos-manifest's a_row_that_serves_a_port_and_is_no_service_is_refused pins the render refusal.

Independent oracle. For the HOME routing and the layout, the owner's ruling is the specification, and the test is written against the ruling, not against the code. For home_dir, the fork follows upstream std's unix idiom (var_os("HOME") filtered for empty), without the passwd fallback. For the listing, the oracle is the kernel's own created_dirs contract (cd and list already treat an entry there as a directory). No second implementation reads the DATA volume. The oracle stays partial.

Gates (exit codes)

gate exit
cargo run -- --ci host at 75942e24 (39 steps; the loom controls' FAILED lines are their expected verdicts) 0
cargo run -- --ci host at 542f00ed 0
cargo run -- --ci abi-split at 542f00ed 0 (toyos 0.13.0 -> 0.14.0, toyos-window 0.14.0 -> 0.15.0)
cargo test in toyos-manifest 0
guest layout_fresh_boot at 542f00ed 0
fast tier at 542f00ed, once 1: 396 passed, 2 red, 1 quarantined, 6 quarantined and green
cargo run -- --ci abi-split at fd454902 (after merging origin/main and the version bumps above) 0
cargo run -- --ci host at fd454902 0 (43 steps, all green)
guest layout_fresh_boot at fd454902 0

The fast tier's reds:

  • lan_mdns_answer failed with path must be shorter than SUN_LEN, both wide and alone. This is issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md, from Every test's scratch goes with it, and a killed run's with the next #529's scratch root.
  • quiesce_wakes_on_the_last_park failed with QEMU died before ===READY=== (status 0), red wide and GREEN alone. Its boot log shows the machine rebooting on purpose: test_rs_quiesce_last exits 0, then Syncing filesystems…, stop: 4 of 4 userland thread(s) stopped, Rebooting., all before test-runner's ready marker. That is not a kernel death. --known-red says it is not quarantined.
  • quiesce_leaves_the_volume_whole and metal_job_reboot, the two the review asked about, were green in this run. --known-red says neither is quarantined.

The same-session A/B against main awaits disk space. It needs a second worktree, and df -h /Users read 23 GiB free, then 28 GiB, both under the 30 GiB the brief requires. None of the three quiesce/metal reds is adjudicated.

ABI

#525 landed on main at 7345e3fe, taking toyos-abi to 0.13.0, toyos to 0.14.0 and toyos-window to 0.15.0 — the same versions this branch had independently bumped to, which collide. This branch has since merged origin/main (799f94bd) and moved each of the three past main's landed versions to the next free minor: toyos-abi 0.13.0 -> 0.14.0, toyos 0.14.0 -> 0.15.0, toyos-window 0.15.0 -> 0.16.0. Every in-tree pin (toyos/Cargo.toml, userland/toyos-window/Cargo.toml) moved with it, and every tracked lockfile was re-locked with cargo update -w in its own workspace (git diff on each shows only these three crates' version strings moving — no third-party drift). cargo run -- --ci abi-split is green at the head below.

The rust fork

The pin 80ea645f is wt-toyos-layout (pushed). It contains #520's pin 7a809b75, so whichever of #520 and #531 lands second pins a commit that already holds both, or a merge of the two, and never a cherry-pick. It is not based on toyos-inbox's current head f3492d92. That head's aarch64 commits move compiler/ (tree 734f975f against the 7641f053 every pin on main has), and src/sysroot.rs's check_compiler refuses a worktree build over a compiler/ that the primary's compiler was not built from. So that merge waits until the aarch64 compiler change lands and the primary rebuilds. wt-toyos-layout must not be deleted until toyos-inbox contains 80ea645f.

What I am unsure of

  • service = true is my spelling of "a system service". filepicker and compositor are marked because they serve machine-wide ports. The render rule now enforces that for every serving row.
  • On the direct path, a caller with no launcher now gives its child no HOME at all. No program in the tree relies on the old inheritance: the tests that read HOME are run over ssh or launched.
  • The shell's OWN_FOLDER rule compares path components. It answers the same file at stage 1 and stage 2, but it is one small piece of stage-2-aware code in stage 1.

🤖 Generated with Claude Code

https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK

Japabu and others added 4 commits September 26, 2026 17:12
… HOME from init

The owner ruled where everything lives on 2026-09-26, and
issues/filesystem/where-everything-lives.md records it: the tree, the rules
(no dotfiles, English names, a path is one file in every view with /tmp the
one exception, locations through environment variables init sets), and the
stages with their exits. The storage track's `## Paths` and the users track
now point at it instead of carrying their own `.config/<app>` layout.

The first stage, the part that needs no isolation:

- `/config` and `/state` are two more names DATA answers to
  (`ROOT_ENTRIES`, `DATA_PATHS`).
- The kernel makes no home. init makes `/home/toy` and Apps, Desktop,
  Documents, Downloads, Fonts, Music, Pictures and Videos at boot, and a
  service's `/state/<name>` before each start.
- A `system.toml` row says `service = true` for a system service, the
  manifest carries it as a `service` record, and `Program::home` answers
  `/state/<name>` for one and `/home/toy` for every other row. init sets
  `HOME` from it on every start, over whatever a launching caller carried.
- std's `home_dir` answers `$HOME`, or `None` when it is unset or empty. The
  runtime used to overwrite `HOME` with `/home/root` and set `XDG_CONFIG_HOME`
  at every process start, so nothing a parent passed could survive; that
  seeding is gone (fork commits on wt-toyos-layout).
- The keyboard layout is `/config/keyboard-layout`, a machine setting in no
  user's home (`surface::LAYOUT_CONFIG`; toyos 0.14.0 and toyos-window
  0.15.0, every pin and lockfile with them).
- sshd keeps its identity and key list in its own `HOME`, `/state/sshd`.
- The shell keeps its history in `$HOME/Apps/shell/State/history` and
  invents no `HOME`; the files app starts in `home_dir()`.
- JetBrains Mono ships as a TTF in `/system/share/fonts`, where the toolkits
  look, with its OFL text in `/system/share/licenses`; NOTICE says so.
- The 26 SDK doc lines naming `/bin` name `/system/bin`, and the Rights::LOG
  doc gate strips that prefix: the issue that tracked them is closed.

`/log/lease.txt` does not move. It is not netd's lease but the
`--exit-with-lease` bench report the metal loop reads off the stick's FAT log
volume, which cannot read DATA; the track says so.

Found on the way and filed: a directory on DATA is the VFS's in-memory
record, absent from every listing of its parent and from the next boot, and
it is taken with no parent — which is why init makes each level in turn.

`layout_fresh_boot` boots tests/sshdcase on a blank DATA volume and asks a
session program's child where everything is.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
A std whose `home_dir` answers `None` makes sshd refuse before it says
anything, and waiting on a line it never prints turned that red into a
300 s STALL the harness reads as saying nothing about the tree. The
kernel's `exit: sshd` record comes however sshd fares, so the wait ends on
the event and the mint line is then asserted by name.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
The fast tier on this branch, after merging origin/main at e48604c, reds
lan_mdns_answer wide and alone on a 104-byte socket path under the new
toyos-tmpdir scratch root. Nothing on this branch touches the lane or the
tap; filed for its owner.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
@Japabu
Japabu marked this pull request as ready for review September 26, 2026 16:08
@Japabu

Japabu commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #531 at 1b8d4599, against origin/main at e48604c0.

Readiness. CI run 36254168573: abi-split passed and host was skipped, which is how ci.yml treats a pull request. The body reports layout_fresh_boot at exit 0 and every guest arm with its exit code. No hardware is targeted. Ready for review.

Net lines (git diff --numstat origin/main...HEAD):

part added removed net
production (excluding tests/, issues/, locks and system.toml) +247 −94 +153
in-module #[cfg(test)] (part of the production row) about +50
tests/ (the *case/system.toml rows included) +231 −35 +196
issues/ +187 −74 +113
config (NOTICE and the three top-level system.toml) +19 −2 +17
locks +32 −32 0

The production growth is the feature. Nothing larger could be deleted in its place.

BLOCKER

  • userland/init/src/main.rs:1178, rust library/std/src/sys/process/toyos.rs (the routing rule) — HOME comes from init only on the launcher path. A direct SYS_SPAWN hands the child the parent's environment, and std takes that path in three cases: the program is undeclared (Outcome::NotDeclared), the caller holds no launcher, or the caller endowed a handle. So the child of a service inherits /state/<service>. Example: an ssh exec of any undeclared binary (userland/sshd/src/main.rs:238) runs with HOME=/state/sshd, the directory that holds the host private key. Before this branch std overwrote HOME in every process, so this inheritance is new here. It breaks the ruling that locations reach a program only through what init sets. Fix: the direct path carries no HOME that init did not set. Test: an undeclared program started by sshd reports a HOME other than /state/sshd. That test is red today.

  • userland/init/src/main.rs:1170-1178 — "overrides whatever a launching caller carried" is untested. Surviving mutation: delete command.env("HOME", &home); from start, and at :368 write start(Command::new(path).env("HOME", self.program.home()), …). Boot-started programs keep their HOME, and test_rs_layout_paths inherits test-runner's. So layout_fresh_boot and every arm in the body stay green. Test that must turn red: sshd launches /system/bin/shell -c 'echo $HOME' and the output must read /home/toy, not /state/sshd.

  • tests/toyos-rust-tests/src/bin/layout_paths.rs:83-902 — the walk cannot see a hidden folder, which is half of the ruling. A directory on DATA is in no listing until a file is under it, so an empty dot-directory is invisible to the walk. Surviving mutation: userland/init/src/main.rs:1496 const HOME_FOLDERS: [&str; 9] = [".config", "Apps", …], and layout_fresh_boot stays green. Fix: make the check able to see an empty directory. The straight route is Vfs::list naming created_dirs children, which also closes the filed issue's first bullet. The alternative is for the author to state in the body and in the filed issue that this half is unchecked, and to give it an exit.

  • toyos/src/surface.rs:52, userland/shell/src/main.rs:13 — two moves no test pins. layout_fresh_boot boots tests/sshdcase, where neither locale nor the interactive shell writes anything. Two mutations survive every test named in the body:

    • LAYOUT_CONFIG = "/home/toy/.config/keyboard-layout". The locale arms read the constant, so they cannot notice.
    • const HISTORY: &str = ".shell_history";. screen_console_shell saves history and nothing reads where it went.

    Fix: a guest check that asks for /config/keyboard-layout and /home/toy/Apps/shell/State/history by literal path after locale <name> and one shell command have run, with the dotfile walk run over the same boot.

  • PR body, "fast tier's three reds" — quiesce_leaves_the_volume_whole and metal_job_reboot are unadjudicated. Both are red when run wide and green when run alone, and --known-red says neither is quarantined. "Green alone" is the load-coincident pattern that CLAUDE.md says is investigated, never re-run away. The merge queue boots no guest, so the reds would enter main unseen. Could they be this diff's? Neither reads a moved path. Both are Metal-profile boots judged on the FAT log volume and on a shutdown bound (WAIT in power.rs, a 20 s drain in volumes.rs), and this branch adds only boot-time mkdirs in init and service = true on logd. So they plausibly are not, but that is not established. Required: a same-session run with the whole fast tier on e48604c0. If main reds the same way, file each red at its owner. If it does not, they are this diff's.

NOTE

REMOVE

  • issues/filesystem/where-everything-lives.md:34-35 — "A third-party program that hard-codes ~/.something may still create one, but only inside its own app folder." The ruling says no dotfile anywhere, and this sentence softens it.
  • issues/filesystem/where-everything-lives.md:18 — "signed". ROOT is not signed.
  • issues/filesystem/where-everything-lives.md:20 — "a file here overrides /system/etc". The owner did not rule this and nothing implements it.
  • issues/filesystem/where-everything-lives.md:50-51 — "and per-user overrides come with the users track". The ruling says machine-wide.
  • issues/filesystem/where-everything-lives.md:54 — "An app finds its own files next to its binary (current_exe())." The owner did not rule this.
  • NOTICE:164-165, src/assets.rs:528-529 and :550-551 — "where fontdb and fontique look" and "where the toolkits look". Neither looks anywhere on ToyOS until the upstream arms open.
  • tests/toyos-rust-tests/src/bin/layout_paths.rs:837-838 — "so a folder added to one reds here". This is false for a folder added to init's list, as the BLOCKER above shows.

SEND BACK

Japabu and others added 2 commits September 26, 2026 18:43
… is asked over ssh

The review of 1b8d459 found four blockers and a fast-tier question.

HOME on the direct path. std's direct spawn handed a child the parent's
whole environment, so an ssh exec of an undeclared binary ran with
HOME=/state/sshd. init now answers a launch of an undeclared program with
the session's HOME (MSG_NOT_DECLARED carries it; toyos::launch's
Outcome::NotDeclared has it), and std's direct spawn carries only a HOME
its caller named or init answered, never its own (fork commit 957f1426,
merged with toyos-inbox at 7a809b75, #520's pin, in 80ea645f).

The layout, asked over the cable. layout_fresh_boot boots
tests/layoutcase (sshdcase plus a declared shell and the locale applet)
with a staged key, then over ssh: `shell -c 'echo $HOME'` must print
/home/toy (a launched row's HOME is init's, over sshd's); `locale de` and
an interactive shell write /config/keyboard-layout and the shell's
history; and test_rs_layout_paths, declared nowhere so sshd spawns it
directly, asserts its HOME, both files by literal path, and the exact
listings of /home/toy and /state.

An empty directory is listed. Vfs::list names the directories the VFS
carries in created_dirs, so an empty dot-folder is in its parent's
listing and the dotfile walk sees it. The filed DATA-directory issue
loses that bullet and its slug says what is left.

Also: a manifest row that serves a port and is not marked a service is
refused at render, and every config is rendered by a host test; init's
folder failure no longer says the whole session home is missing; the
shell's history finds its own folder whether HOME is the session's or,
at stage 2, the folder itself; the track records the owner's rulings,
gains a time-zone, a language and a fonts stage, and no longer ships
JetBrains Mono here, which leaves src/assets.rs and NOTICE to #528;
the sshd fail-closed issue is closed, its exit met by the blank DATA
volume every image-less boot gets.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Vfs::list now adds the directories created_dirs carries, which could take
a listing past MAX_LIST_ENTRIES, the bound the files it lists already
respect. It refuses there as every FileSystem::list does, rather than
growing the answer past what the bound was derived for.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
@Japabu

Japabu commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator Author

Answer to the review of 1b8d4599. The head is now 542f00ed, and the rust pin is 80ea645f.

BLOCKERs

  1. The direct path's HOME. init answers MSG_NOT_DECLARED with the session's HOME, and std's direct spawn carries only a HOME its caller named or one init answered, never its own. I chose to have init decide over refusing the spawn, and the body gives the reasons against the isolation track. test_rs_layout_paths is undeclared, so sshd spawns it directly, and it must read /home/toy. With the whole routing reverted (fork 957f1426 reversed, launch.rs at base, init's bare signal), the test exits 1 with HOME is Ok("/state/sshd"). At head it exits 0.
  2. init's override. Over ssh, shell -c 'echo $HOME' must print /home/toy. Your mutation (the env line deleted from start, and the boot path given HOME at its call site) exits 1 with a launched shell's HOME is "/state/sshd\n".
  3. Hidden empty directories. Vfs::list now names the directories created_dirs carries, and /home/toy and /state are asserted as exact listings. Your ".config" mutation exits 1, both on the exact listing and with a dotfile … ["/home/toy/.config"]. With the kernel change reverted the test exits 1 on the listings, and kernel-reverted plus .config shows no dotfile line: that is your finding, reproduced.
  4. The layout and history paths. Over ssh, locale de runs and an interactive shell runs one line, and the judge reads both files by literal path. LAYOUT_CONFIG → /home/toy/.config/… exits 1. History → .shell_history exits 1, with OWN_FOLDER deleted with it so the mutated tree builds; the first attempt did not build and was discarded.
  5. The fast tier. The A/B against main awaits disk space: df read 23 GiB, then 28 GiB, under the 30 GiB required. I ran the fast tier once at 542f00ed: exit 1, 396 passed. The reds were lan_mdns_answer (the SUN_LEN issue, already filed) and quiesce_wakes_on_the_last_park: red wide, green alone, and a deliberate reboot before the ready marker. quiesce_leaves_the_volume_whole and metal_job_reboot were green in this run. --known-red says none of the four is quarantined.

NOTEs

REMOVE: the lines in NOTICE and src/assets.rs are gone (both files are back to main's), and so is the layout_paths line. I did not remove the track lines: the orchestrator ruled them owner-approved.

Exits

  • --ci host exited 0 at 75942e24 and 0 at 542f00ed.
  • --ci abi-split exited 0 at 542f00ed.
  • layout_fresh_boot exited 0 at 542f00ed.
  • The mutations above each exited 1.
  • The fast tier exited 1: two reds, both explained above.

Japabu and others added 3 commits September 26, 2026 19:21
# Conflicts:
#	issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md
#	tests/toyos-rust-tests/Cargo.lock
#	userland/Cargo.lock
PR #525 landed on main at the same 0.13.0/0.14.0/0.15.0 this branch's
toyos-abi, toyos and toyos-window sources had already moved past, so the
abi-split gate now judges this branch's changes against those taken
versions rather than the old base. Bump each to the next free minor
(0.14.0/0.15.0/0.16.0), move every in-tree pin, and re-lock every tracked
lockfile in its own workspace with `cargo update -w`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
The owner's rule on wrong prose is delete, not correct — the exit
condition of the deleted issues/build/twenty-seven-sdk-doc-lines-name-a-path-that-is-gone.md
said so. Correcting each `/bin/x` to `/system/bin/x` would only make the
same 26 lines wrong again at the next layout change; a bare-lined comment
line owed the same rewrite, so the path itself goes, leaving the program
name each sentence actually needed. `cargo doc --no-deps` still builds
clean on toyos-abi, toyos and toyos-window.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
@Japabu

Japabu commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator Author

Merged origin/main (#525 landed at 7345e3fe) into this branch at 799f94bd, resolving conflicts in issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md (took main's userland-file-server rewrite plus this branch's DATA-role and paths-doc-pointer edits) and in tests/toyos-rust-tests/Cargo.lock / userland/Cargo.lock (took main's side, then re-locked). Bumped the three published SDK crates this branch changes past main's already-landed versions, since both landed on the same numbers: toyos-abi 0.13.0 -> 0.14.0, toyos 0.14.0 -> 0.15.0, toyos-window 0.15.0 -> 0.16.0, moved every in-tree pin, and re-ran cargo update -w in each tracked lockfile's own workspace (Cargo.lock, bootloader/Cargo.lock, kernel/Cargo.lock, tests/ssh-client-host/Cargo.lock, tests/toyos-rust-tests/Cargo.lock, toyos/Cargo.lock, userland/Cargo.lock, userland/libc/Cargo.lock) — git diff on each shows only these three crates' version strings moving, no third-party drift. Deleted the 26 SDK doc lines this branch had corrected (/bin/x -> /system/bin/x) instead of correcting them, per the owner's rule recorded in the now-deleted twenty-seven-sdk-doc-lines-name-a-path-that-is-gone issue: each sentence now names the program alone (`init`, `logd`, `toybox`, `ps`, `sshd`, `ls`, `terminal`, `console`), with no path. cargo doc --no-deps still builds clean on toyos-abi, toyos and userland/toyos-window (only pre-existing, unrelated warnings). Gates at head fd454902: cargo run -- --ci abi-split exit 0 (bumped: toyos-abi 0.13.0 -> 0.14.0, toyos 0.14.0 -> 0.15.0, toyos-window 0.15.0 -> 0.16.0); cargo run -- --ci host exit 0 (43 steps, all green); cargo test --test toyos-build -- layout_fresh_boot exit 0 (PASS, 98.5s).

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK

@Japabu

Japabu commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator Author

Round-1 BLOCKERs closed and judged at 542f00e (HOME decided by init on every spawn path, the override pinned by an ssh echo, empty dot-folders seen via a kernel listing fix, keyboard-layout and history paths pinned, each red under its mutation); final round fd45490 takes toyos-abi 0.14.0 / toyos 0.15.0 / toyos-window 0.16.0 after #525 and deletes the 26 stale SDK doc paths. --ci host, abi-split and layout_fresh_boot exit 0. Landing.

@Japabu
Japabu added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 17eb66a Sep 26, 2026
2 checks passed
Japabu added a commit that referenced this pull request Sep 26, 2026
The fork pins meet in c34ecdf0ab6, a merge of this branch's 851c6bfcaa8 and
#531's 80ea645f83b, itself merged into toyos-inbox as 2434fb9d1bc. #531
moved toyos-window to 0.16.0, the number this branch had taken, so this
branch's toyos-window, whose scanout drain lives in arch modules, is 0.17.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 26, 2026
#531 landed issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md
for the same defect this branch had filed as
lan-sockets-under-the-suite-s-tmpdir-pass-the-unix-socket-limit.md, so this
branch's copy goes. Its measurements, for the record: a same-session A/B
with main at 17eb66a reddened lan_mdns_answer on every run with a verdict,
4 of 4 on main and 5 of 5 on the branch, each on `path must be shorter than
SUN_LEN`; the pid in the path is what makes the harness's ALONE line call two
readings of it "a DIFFERENT failure".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 26, 2026
#531 (17eb66a) gave daemons a `service` row and moved their state under
/state; this branch gave `update` a `slots` row and `swap` its own row. Every
conflict is the two additions side by side:

- src/build.rs, toyos-manifest/src/lib.rs: `ProgramConfig` and `Program`
  carry both `slots` and `service`; `render` and `parse` write and read both
  records, and the doc table lists both.
- system.toml and tests/{e1000talk,flrswap,lantalk,swap}case/system.toml:
  sshd is `service = true` (main) and receives `netd` and `launcher` only,
  since `swap` is its own row here, which receives `swap`.
- userland/Cargo.lock: init keeps `toyos-gpt` (this branch); sshd depends on
  neither `toyos` nor `toyos-swap` (its subsystem is deleted here, and
  main's sshd change uses neither).
- tests/updatecase/system.toml, new on this branch: logd, netd and sshd
  marked `service = true` as main marks them in every other config.
- issues/build/a-lane-socket-path-overruns-sun-len.md deleted: main filed
  the same defect as a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 26, 2026
#531 landed toyos-abi 0.14.0, toyos 0.15.0 and toyos-window 0.16.0, the
versions this branch had taken for its change to toyos_abi::boot. The
second to land bumps again: every manifest pin moves, and every tracked
lockfile carrying them is re-resolved with `cargo update -w --offline` in its
own workspace, which moved those three crates' versions and nothing else.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 26, 2026
main landed #525 (storage stage 3) and #531 (the layout), which moved the SDK
to toyos-abi 0.14.0, toyos 0.15.0 and toyos-window 0.16.0 and the rust pin to
80ea645f83b.

- SDK versions: this branch's ABI and SDK changes move past main's to 0.15.0,
  0.16.0 and 0.17.0; every tracked lockfile re-locked in its own workspace
  with `cargo update -w`.
- rust: pinned at 23783dc3524, main's 80ea645f83b merged with this branch's
  39c642fe04f; it is on the fork's toyos-inbox (merged there as 26f662d303a),
  and its compiler/ is main's.
- tests/logholdcase/system.toml: deleted here, and main's one hunk (`service =
  true` on logd) has no file to go to — log_hold runs on tests/testcases now,
  whose logd main marks a service. ALL_CONFIGS drops it.
- src/build.rs: both tests kept (main's `every_config_renders_its_manifest`,
  this branch's shipped-config derivation), and ALL_CONFIGS carries main's
  layoutcase and this branch's logkeepcase, whose logd is marked `service`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 26, 2026
…sions

Merging origin/main (#531) collided this branch's toyos/wake.rs and
toyos-window/wait.rs additions with main's own bump of the same two crates to
identical version numbers (0.15.0, 0.16.0) for different content. Move both
one minor past main's landed pins and re-lock every tracked workspace with
`cargo update -w`, which also drains the dead winit 0.31.0-beta.2 subgraph and
the stale getrandom/mio/socket2 fork pins the split-version gate (added on
this branch before the merge) then caught: real crates.io toyos/toyos-abi
0.1.0/0.2.0 resolving beside the tree's own path versions because those pins
predated the tree's `-sdk-0.12` branch renames and the getrandom `toyos-0.4`
branch fix already at its head.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
Japabu added a commit that referenced this pull request Sep 27, 2026
…, #531, #534) into the Netstack3 netd

Two conflicts. tests/common/origin.rs: main added `volumes` to the imports
this branch had split to name `segment`'s NEIGHBOUR and NEIGHBOUR_MAC; both
kept. userland/Cargo.lock: main's lock taken whole and re-locked against this
branch's manifests (`cargo metadata`), which adds the mirrored crates and their
dependencies and drops smoltcp and its defmt.

The rust gitlink fast-forwarded to main's fbf6ad143d8; this branch's pin
(7a809b7591f) is its ancestor, and the branch made no fork commit of its own.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iqcj4jDKpaiDX8B7CMvmK
@Japabu
Japabu deleted the wt/toyos-layout branch September 28, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant