diff --git a/Cargo.lock b/Cargo.lock index 13c286c2b33..e07e5c65ebe 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1090,7 +1090,7 @@ checksum = "5d99f8c9a7727884afe522e9bd5edbfc91a3312b36a77b5fb8926e4c31a41801" [[package]] name = "toyos-abi" -version = "0.13.0" +version = "0.14.0" dependencies = [ "rustc-std-workspace-core", ] diff --git a/bootloader/Cargo.lock b/bootloader/Cargo.lock index 35ed32ef024..928fd536ebf 100644 --- a/bootloader/Cargo.lock +++ b/bootloader/Cargo.lock @@ -110,7 +110,7 @@ dependencies = [ [[package]] name = "toyos-abi" -version = "0.13.0" +version = "0.14.0" [[package]] name = "toyos-acpi" diff --git a/console/system.toml b/console/system.toml index e4a9393a78f..64a7407a57f 100644 --- a/console/system.toml +++ b/console/system.toml @@ -27,6 +27,7 @@ start = ["logd", "console"] # reads the kernel's records with `logread`, which is `Rights::LOG | # Rights::WAIT` on a `SysCap` duplicate, and serves `log` to the console. [programs.logd] +service = true syscap = ["logread"] serves = ["log"] diff --git a/diag/system.toml b/diag/system.toml index 47b87060ebe..7892237af94 100644 --- a/diag/system.toml +++ b/diag/system.toml @@ -36,6 +36,7 @@ start = ["logd", "toybox"] # `Rights::LOG | Rights::WAIT` on a `SysCap` duplicate, and init hands it every # program's output beside that. [programs.logd] +service = true syscap = ["logread"] [programs.toybox] diff --git a/issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md b/issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md new file mode 100644 index 00000000000..a055bb032a6 --- /dev/null +++ b/issues/build/a-lane-s-tap-socket-path-is-past-sun-len-on-the-dev-host.md @@ -0,0 +1,27 @@ +--- +status: open +kind: tooling +opened: 2026-09-26 +--- + +# A lane's tap socket path is past `SUN_LEN` on the dev host + +`lan_mdns_answer` reds on the macOS dev host, wide and alone: + +``` +connect to QEMU's /private/var/folders/gr/mr4_fg4n34jb417sx1g5cgxc0000gp/T/toyos-tmp-89085-0/tests-0/lane-3/tap-out-0.sock: path must be shorter than SUN_LEN +``` + +That path is 104 bytes, and macOS's `sun_path` holds 104 including the NUL. +`tests/common/segment.rs`'s `Tap::in_lane` puts both sockets in +`lane::dir()`, which since `toyos-tmpdir` is +`$TMPDIR/toyos-tmp--/tests-/lane-/`, and the dev host's +`$TMPDIR` resolves to 57 bytes (`/private/var/folders/…/T/`) before any of +that. A five-digit pid is enough to cross the limit. Seen on +`wt/toyos-layout` after it merged `origin/main` at `e48604c0`; nothing on that +branch touches the lane or the tap. + +## Exit condition + +A tap socket's path fits `sun_path` on every host the suite runs on, and +`lan_mdns_answer` is green on the dev host. diff --git a/issues/build/sshd-fail-closed-assumes-a-home-no-earlier-boot-of-its-lane-wrote.md b/issues/build/sshd-fail-closed-assumes-a-home-no-earlier-boot-of-its-lane-wrote.md deleted file mode 100644 index 890e24edf3e..00000000000 --- a/issues/build/sshd-fail-closed-assumes-a-home-no-earlier-boot-of-its-lane-wrote.md +++ /dev/null @@ -1,24 +0,0 @@ ---- -status: open -kind: tooling -opened: 2026-09-24 ---- - -# `sshd_fail_closed` assumes a `/home` no earlier boot of its lane wrote - -`sshd_fail_closed` owes `sshd: minted a new host identity at -/home/root/.ssh/host_ed25519`, and boots `tests/sshdcase` on the lane's shared -scratch disk (`tests/common/qemu.rs`: "Reused across the boots of one lane"). -Any earlier boot of the same lane whose sshd ran leaves its identity on that -disk, and this boot then reads it and mints nothing. - -Seen on CI (run 35984557404, shard 5): `lan_talk` ran first in the lane and its -sshd minted a key; `sshd_fail_closed` then said `host identity SHA256:yYw2…` -with the same fingerprint on both of its runs and no `minted` line, red twice. -On main the two had not shared a shard. `lan_talk` now boots a disk of its own, -which removes this one neighbour and not the premise. - -## Exit condition - -`sshd_fail_closed` boots a disk of its own, as `tests/common/pkg.rs` does, so -its verdict does not depend on which tests the shard split put before it. diff --git a/issues/build/twenty-seven-sdk-doc-lines-name-a-path-that-is-gone.md b/issues/build/twenty-seven-sdk-doc-lines-name-a-path-that-is-gone.md deleted file mode 100644 index 0d2df595059..00000000000 --- a/issues/build/twenty-seven-sdk-doc-lines-name-a-path-that-is-gone.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -status: open -kind: tooling -opened: 2026-09-04 ---- - -# Twenty-seven SDK doc lines name `/bin`, which no longer exists - -## Reproduction - -``` -rg -n --pcre2 '(?`, a directory on DATA holding Documents, -Downloads, `.config/` and `.local/`; and a row in the manifest from +A user is two things: `/home/`, a directory on DATA laid out as +`issues/filesystem/where-everything-lives.md` rules; and a row in the manifest from which init builds a login session's namespace, the way it builds every system program's from `system.toml`. Nothing else names a user: no numeric id the kernel checks, no password file, no ambient "current user" a process can ask for. A session holds its home tree because init moved that directory's handle into it, and a program launched inside the session holds what the session's -launcher row grants it. Until this lands there is one implicit user and a -package writes under `/apps//` only. +launcher row grants it. Until this lands there is one user, `toy`, whose home +init makes at boot. Stage 3 of `issues/isolation/every-program-sees-only-the-files-it-was-given.md`, and blocked on its first two stages: a user is isolated only once a session's view is all it can name. The mount protocol and real bcachefs diff --git a/issues/filesystem/shell-c-discards-the-cwd-its-launch-carried.md b/issues/filesystem/shell-c-discards-the-cwd-its-launch-carried.md index 2664f9f715b..42ce55239fb 100644 --- a/issues/filesystem/shell-c-discards-the-cwd-its-launch-carried.md +++ b/issues/filesystem/shell-c-discards-the-cwd-its-launch-carried.md @@ -24,7 +24,7 @@ down, where `set_current_dir(&home)` is at least a stated policy. ## Reproduction -Spawn `/system/bin/shell` with `Command::current_dir("/home/root")` and the +Spawn `/system/bin/shell` with `Command::current_dir("/home/toy")` and the arguments `-c`, `pwd`. It answers `/`. Read from the source rather than measured: `pkg_install_gbae`'s diff --git a/issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md b/issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md index 21926aa1e54..ab75fa8b02a 100644 --- a/issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md +++ b/issues/filesystem/storage-is-layers-and-a-role-is-a-filesystem.md @@ -46,7 +46,7 @@ volume, handed to whichever server recognises its superblock. |---|---|---|---| | ESP | FAT32, firmware's rule | `/boot` | kernel only | | ROOT | bcachefs image the build writes | `/system` | no; versioned per release | -| DATA | bcachefs, formatted on first boot | `/apps`, `/home` | yes | +| DATA | bcachefs, formatted on first boot | `/apps`, `/config`, `/home`, `/state` | yes | | LOG | FAT32 while a Mac has to read the dev stick | `/log` | yes | `/tmp` has no backing. The dev loop keeps the ESP and ROOT on the stick and @@ -90,22 +90,13 @@ NTFS by the same shape if wanted. ## Paths -No drive letters, no `/usr`, `/var`, `/opt`, `/dev`, `/proc` or `/sys`: -devices and processes are capabilities and syscalls here, not files. Each -process sees the directories its parent gave it -(`issues/isolation/every-program-sees-only-the-files-it-was-given.md`). - -- `/boot` — bootloader, kernel, kernel arguments. -- `/system` — the OS image, read-only, versioned: today's `bin`, `lib`, `share` - and the manifest. -- `/apps/` — each installed program in its own directory with its own - binaries, data and manifest row; doom moves here with its WAD. -- `/home/` — Documents, Downloads, `.config/` for settings, - `.local/` for saves and caches. -- `/log`, `/tmp` — as today. -- `/media/