Commit Graph

2082 Commits

Author SHA1 Message Date
vasilito 01f4f5d958 dnsd: fix CRITICAL race in DNS transaction ID + DoS via compression loop
- Replace unsafe static mut DNS_TID (data race between loopback listener
  thread, mDNS responder thread, and scheme-call paths) with AtomicU16
  + fetch_update. Eliminates torn writes and interleaved read-modify-write
  that could produce duplicate transaction IDs and misroute responses.
- Add MAX_COMPRESSION_JUMPS=10 cap and backward-loop detection to
  decode_name. Previously a malicious DNS response with a self-referential
  or cyclic compression pointer could spin the scheme daemon's main
  thread indefinitely (DoS).

Closes the two CRITICAL findings (C-19, C-20) from
local/docs/NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md
§3.5
2026-07-27 14:32:18 +09:00
vasilito 45c0ad27d1 driver-manager: N4 — wire new policy surfaces + activate redbear-driver-policy
Closes the v4.8 cross-cutting item:
- redbear-driver-policy package is now ACTIVE (was "dormant until
  Phase C3"; cutover was operator-ratified 2026-07-23)
- /etc/driver-manager.d/disabled file gate is honored by main.rs

main.rs changes:
- Loads DriverOptions, AutoloadList, InitfsManifest alongside the
  existing Blacklist; all four gated by /etc/driver-manager.d/disabled
- New policy-surface summary log line at startup
  (policy-surface: disabled={} blacklist={} options={} ...)
- Structured messages indicate "(N4 active)" once the four surfaces
  are wired

config.rs changes:
- New process-wide globals: GLOBAL_DRIVER_OPTIONS,
  GLOBAL_AUTOLOAD, GLOBAL_INITFS_MANIFEST
- Setters: set_global_shared_driver_options /
  set_global_shared_autoload_list / set_global_shared_initfs_manifest
- Readers: driver_options_for / autoload_modules /
  initfs_manifest_stages
- Spawn path: applies DriverOptions overrides as
  REDBEAR_DRIVER_PARAM_<NAME>=<value> env vars per param

policy.rs changes:
- New from_static constructors for the three new SharedX wrappers
  (used by main.rs to register startup-time policy without owning
  the directory for re-replace)
- Bug fix: the new SharedDriverOptions/AutoloadList/InitfsManifest
  load_from methods were discarding the loaded data (assigned to
  'inner' but used DriverOptions::default() instead). Fixed; the
  SharedBlacklist version was correct. Caught by the unused-variable
  warning during this work.

redbear-driver-policy package:
- README rewritten: removed "dormant until Phase C3" language;
  replaced with active-state documentation, gating instructions,
  and operator workflow (`touch ...disabled` / `rm ...disabled`)
- 00-blacklist.conf: clarified gating section (now matches the
  implemented /etc/driver-manager.d/disabled behaviour)

policy::tests: 23 -> 23 (no new tests in this commit; coverage
remains at 23 from N1–N3). driver-manager tests: 159 total, all green.
driver-manager-audit-no-stubs.py: 46 files, 0 violations.
2026-07-27 14:28:05 +09:00
vasilito 08cc41d705 driver-manager: N1–N3 — policy.rs modprobe.d options + modules-load.d autoload + initfs.manifest
Closes the cross-cutting items the v4.8 assessment flagged as
"not yet in the policy layer":
- modprobe.d options parser (per-driver param overrides)
- modules-load.d autoload enforcement
- initfs.manifest enforcement

Three new policy surfaces added to policy.rs alongside the
existing SharedBlacklist:

DriverOptions (mirrors Linux modprobe.d/<driver>.conf):
- TOML schema: [[options]] driver = "name" params = [{name, value}, ...]
- Applied at spawn as REDBEAR_DRIVER_PARAM_<NAME>=<value> env var
- SharedDriverOptions with SIGHUP-reloadable replace()

AutoloadList (mirrors Linux modules-load.d/<name>.conf):
- Parses simple 'module = "name"' lines from autoload.d/*.conf
- Deduplicates, ignores comments and blank lines
- SharedAutoloadList with replace()

InitfsManifest (mirrors CachyOS mkinitcpio hook ordering):
- TOML schema: [kms] / [block] / [filesystems] / [boot] sections
- Canonical walk order enforced regardless of TOML declaration
- SharedInitfsManifest with replace()

Plus shared file-loader helpers (read_toml_files, read_any_files,
read_files_matching) to centralise directory iteration. The matcher
accepts both .toml and .manifest extensions so the initfs manifest
can ship as a self-documenting .manifest file.

23 new unit tests in policy::tests (was 6):
- DriverOptions: load_dir missing/parse/skips invalid/empty param
- DriverOptions: for_unknown_driver returns empty
- SharedDriverOptions: replace() round-trip
- AutoloadList: load_dir missing/parses/dedupes/comments+blank
- AutoloadList: accepts quoted/unquoted values
- InitfsManifest: load_dir missing/parses all stages
- InitfsManifest: walks stages in canonical order even when TOML
  declares them in reverse
- InitfsManifest: skips empty stages and empty driver names
- InitfsManifest: canonical_order() is stable and Ord-sorted
- SharedInitfsManifest: replace() round-trip

policy::tests count: 6 -> 23 (+17).

No main.rs or scheme.rs changes yet — the new policy surfaces are
library-only at this commit. Wiring (N4) follows in the next
commit; the policy package activation removes the "dormant until
Phase C3" language from the redbear-driver-policy README.
2026-07-27 14:15:23 +09:00
vasilito 0b19fddd2c 3d: harden 4 lie-grade stubs in linux-kpi; log SDDM no-ops; emit SeatNew in redbear-sessiond
Wave 1 (linux-kpi drm_shim.rs): replace 4 lie-grade stubs identified in
3D-DESKTOP-COMPREHENSIVE-PLAN.md §3.4.
  - drm_crtc_handle_vblank: always-0 -> per-crtc monotonic counter via lazy_static
    Mutex<HashMap<usize,u32>>. Mesa/KWin no longer stalls on the first
    page-flip wait (audit §2 #6).
  - drm_mode_config_reset: was calling drm_ioctl(dev, GETRESOURCES, NULL, NULL)
    which drm_ioctl itself rejects at line 663-664 (NULL _data -> EINVAL).
    Replaced with a logged no-op; redox-drm maintains mode state per-open.
  - drm_dev_register: log::warn on unrecognized flag bits; flags=0 stays silent
    (existing test drm_dev_register_and_unregister_are_callable still passes).
  - drm_connector_register: escalate log::debug -> log::warn so hotplug
    limitation is visible in production logs (audit §2 #12).
  Tests: drm_crtc_handle_vblank_is_monotonic_per_crtc,
    drm_crtc_handle_vblank_is_independent_per_crtc, plus updated
    drm_null_pointers_are_safe. cargo check --lib clean.

Wave 2 (SDDM): both redox-virtualterminal-stub.patch and
redox-helper-utmpx-stub.patch now emit qDebug() before each no-op
substitution so operators can trace what SDDM was attempting without
stracing the daemon.

Wave 3 (redbear-sessiond): Manager interface now emits SeatNew
(org.freedesktop.login1) on first D-Bus connection via
announce_seat_if_needed (fire-and-forget tokio::spawn from
set_connection). Idempotent via Arc<AtomicBool>. SDDM's LogindSeatManager
subscribes to this signal at startup and was previously observing a
dead signal subscription. emit_seat_removed exposed for future use.

Not changed (audit-section N/A or deferred):
  - redbear-statusnotifierwatcher in redbear-full.toml: already wired
    at line 233 with activation file staged (audit §3.7 was outdated).
  - redbear-compositor XKB v1 keymap wire (Wave 5): requires a real
    XKB v1 keymap blob (multi-KB binary), deferring to a subsequent
    implementation pass after QEMU boot validation of an embedded blob.
2026-07-27 14:03:36 +09:00
vasilito cc66590b71 docs: update DRIVER-MANAGER.md with F1–F6d implementation status
Post-implementation sync of the canonical current-state doc:

- §5 fix plan: every section now marked DONE 2026-07-27 with
  implementation details, file:line refs, env-var surface, and
  test results
- §6 test inventory: updated from 148 -> 181 tests; per-fix
  summary table added showing the 33 new tests distributed across
  the 8 fix commits

Verification status: 46 files scan clean by the no-stubs audit
(0 violations); all 181 host tests pass; linux-kpi lib compiles
clean on the redox target; the canonical doc remains the single
source of truth for current state.

Historical round-by-round detail remains in the archived
DRIVER-MANAGER-MIGRATION-PLAN.md.
2026-07-27 13:39:06 +09:00
vasilito c80c23dbb1 driver-manager: F1 — crash counter + backoff + blacklist
Closes the HIGH-severity F1 finding: drivers that crash on every
spawn used to be respawned every hotplug poll (250 ms) indefinitely,
consuming process slots and cluttering logs.

New: per-BDF CrashTracker with:
- consecutive failure counter (HashMap<BDF, CrashState>)
- exponential backoff window: base_ms * 2^N, capped at cap_ms
- auto-blacklist WARN at threshold (default 5)

Env-var configuration:
- REDBEAR_DRIVER_CRASH_THRESHOLD       (default 5)
- REDBEAR_DRIVER_BACKOFF_BASE_MS       (default 100)
- REDBEAR_DRIVER_BACKOFF_CAP_MS        (default 30000)

Probe hot path integration (config.rs::DriverConfig::probe):
- is_in_backoff(bdf) -> ProbeResult::Deferred with reason
- record_success(bdf) on Bind (clears any prior failure state)
- record_failure(bdf) on spawn ENOENT or SIGCHLD reap
- WARN log on threshold-cross with override hint

Reap integration (reap_pid):
- every reap is treated as a spawn failure
- threshold-cross WARN identifies driver + BDF + override path

New /scheme/driver-manager endpoints:
- /crash_count                  (read): lines of '<bdf> <failures>'
- /crash_count/<bdf>            (read): '<bdf> <failures>' (0 if unknown)

Tests (7 new):
- crash_tracker_record_failure_increments_and_signals_threshold
- crash_tracker_record_success_clears_state
- crash_tracker_is_in_backoff_returns_true_within_window
- crash_tracker_snapshot_returns_per_bdf_counts
- crash_tracker_apply_env_overrides
- crash_tracker_apply_env_ignores_invalid_values
- crash_tracker_global_stub_returns_when_unset

141 driver-manager tests pass.
2026-07-27 13:28:48 +09:00
vasilito a043a03c81 docs: add canonical BUILD-SYSTEM.md; update build docs for flags + no-stashing
Add local/docs/BUILD-SYSTEM.md as the single authoritative build-system
reference (entry point, CLI flags, pipeline stages, offline/release, caching,
no working-tree stashing, fork/vendored-upstream versioning, self-versioning).
Update AGENTS.md (dirty-gate replaces the removed stash-and-restore; --allow-dirty;
pointer), SCRIPT-BEHAVIOR-MATRIX.md (stash line -> dirty-source gate), README.md
(flags + pointer), and add canonical-doc pointers to BUILD-SYSTEM-INVARIANTS.md
and docs/06-BUILD-SYSTEM-SETUP.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-27 13:23:07 +09:00
vasilito 0486839dd0 build-redbear.sh: add CLI flags for the common operator knobs
Convert the routinely-used environment knobs to command-line flags (the
canonical interface); the REDBEAR_*/JOBS env vars remain deprecated fallbacks.
New flags: -j/--jobs, --release VER, --allow-dirty, --keep-build-state
(--upstream/--no-cache already existed). Resolved values are re-exported so the
gates and sub-scripts observe them. Rare escape hatches stay env-only and are
documented under an 'Advanced' section in --help. Dropped the phantom
REDBEAR_SKIP_ABI_STALENESS doc; did not add --arch/--target (x86_64-only build).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-27 13:15:22 +09:00
vasilito 487d9e6410 driver-manager: F6d — C18 PM suspend ordering (system_suspend / system_resume)
Closes the C18 capability gap: manager-mediated system PM with
priority-ordered iteration.

Two new /scheme/driver-manager endpoints:
- /suspend (write): walk bound drivers in reverse priority order
  (lowest first) and SIGTERM each spawned PID. Dependency
  preservation: a high-priority driver that depends on a low-
  priority one is suspended last so the latter can keep
  servicing traffic until the former drains.
- /resume (write): walk bound drivers in priority order (highest
  first). Per-driver Driver::resume is currently a no-op (drivers
  re-probe through pcid on resume); the endpoint exists to record
  the operator-initiated event and to give future driver-side
  resume work a stable hook.

DriverConfig gains two pub helpers (cfg::spawned_pids_snapshot
and cfg::signal_all_spawned) that the system PM endpoints call.
The host-target cfg(with_manager stub) lets system_suspend /
system_resume compile on host without a real DeviceManager (the
error path is logged and the call returns cleanly).

Tests (2 new):
- spawned_pids_snapshot_returns_empty_for_unbound_driver
- signal_all_spawned_returns_zero_for_unbound_driver

134 driver-manager tests pass.
2026-07-27 13:05:47 +09:00
vasilito 6fc0366abb build system: remove working-tree stashing (data-loss risk); pre-cook CI=1; target-scoped diagnostics
Remove the stash-and-restore machinery entirely. It manipulated the operator's
working tree and had a fatal bug: modern git's 'stash push' does not print the
stash SHA on stdout, so the SHA was never recorded, the stash was never restored,
and with REDBEAR_ALLOW_DIRTY=1 the operator's dirty-fork WIP was silently
stranded in 'git stash list' on every build (base had accumulated 25 strands).
The build now cooks committed HEAD, or the working tree AS-IS under
REDBEAR_ALLOW_DIRTY=1 — it never touches the tree. A read-only startup advisory
surfaces any leftover redbear-build-* strands from the old code.

Recovered the valuable stranded work to local/recovered-stashes/ (netstack
proptest, relibc get_dns_server daemon-path + getnetbyaddr impl); originals
remain in each fork's git stash list. See local/recovered-stashes/README.md.

Also: pre-cook now runs 'repo cook' with CI=1 (matches make live), fixing the
'Entering raw terminal mode ... Inappropriate ioctl' noise; and the failure
diagnostics per-recipe dump is scoped to THIS build's artifacts (mtime >= build
start) so a bare/mini build no longer lists graphical packages left over from a
prior redbear-full build.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-27 12:59:08 +09:00
vasilito d41c0fd163 driver-manager: F6a — C9 Runtime PM spawn wiring
Closes the C9 capability gap: driver-manager now honours a
per-driver initial_power_state via a new TOML key. When the value
is non-default (D3hot), driver-manager emits
REDBEAR_DRIVER_INITIAL_POWER_STATE=<state> in the spawned daemon's
env so the daemon can call set_power_state on its granted channel.

Mirrors Linux's pci_power_state (include/linux/pci.h). Supported
values: D0 (default), D3hot. Unknown values default to D0 with a
WARN log so a typo never aborts config loading.

Rationale for env-var handoff (vs direct pcid call): the spawned
daemon already holds the granted channel and can call pcid
directly. Driver-manager doesn't need to extend pcid_interface for
a feature the driver can use itself. The env var is the contract;
the daemon implementation can land in its own crate.

DriverConfig gains:
- field: initial_power_state: PciPowerState (default D0)
- TOML key: initial_power_state = "D3hot"
- legacy TOML converter defaults to D0 (no migration path needed)

Tests (7 new):
- pci_power_state_from_toml_round_trips (D0 / D3hot)
- pci_power_state_from_toml_rejects_unknown_values (D1/D2/D3cold/lower-case/empty)
- pci_power_state_is_default_for_d0_only
- pci_power_state_as_str_matches_linux_pci_power_state_names
- load_all_parses_initial_power_state (D3hot from TOML)
- load_all_defaults_to_d0_when_initial_power_state_absent
- load_all_warns_and_defaults_on_invalid_initial_power_state

132 driver-manager tests pass.
2026-07-27 12:53:02 +09:00
vasilito 2d7f7880c9 redox-driver-core: F5 — regression tests for single enumeration per probe
Adds two AtomicUsize-counting bus regression tests that verify
each registered bus's enumerate_devices() is called exactly once
per DeviceManager::enumerate() call. The concurrent path
(>=4 devices, max_concurrent_probes > 1) used to call
manager.enumerate() recursively (G8 in the v3.0 assessment); the
v2.2 sweep moved the concurrent path to ConcurrentDeviceManager::
from_devices() which takes pre-enumerated devices, but no test was
added to lock in the contract.

Tests:
- enumerate_calls_each_bus_enumerate_devices_exactly_once:
  multi-bus setup with 4 PCI + 2 platform devices; PCI crosses the
  concurrent threshold; both buses must be enumerated exactly once.
- enumerate_calls_each_bus_exactly_once_per_call_repeated:
  repeated enumerate() calls must each enumerate every bus exactly
  once (matters for retry_deferred integration).

Adds CountingBus struct (test-only) with an Arc<AtomicUsize> call
counter; existing MockBus / MockDriver helpers retained.

35 redox-driver-core tests pass (was 33).
2026-07-27 12:41:58 +09:00
vasilito 20ccddddf0 driver-manager: F3 — configurable deferred-retry cap
Closes the medium-severity boot-time correctness gap: hardcoded
30 retries x 500 ms = 15 s wall-clock cap that silently abandons
long-startup drivers. Linux analog (deferred_probe_timeout sysctl)
is configurable.

Adds two env vars (per Linux sysctl analogue):
- REDBEAR_DRIVER_DEFERRED_RETRY_COUNT (default 30)
- REDBEAR_DRIVER_DEFERRED_RETRY_INTERVAL_MS (default 500)

Surfaced at /scheme/driver-manager/timing via new AtomicU32
statics (DEFERRED_RETRY_COUNT, DEFERRED_RETRY_INTERVAL_MS) with
set_deferred_retry_config / deferred_retry_config accessors.
interval_ms is clamped to >= 10 ms to bound CPU use.

main.rs reads env vars via new apply_deferred_retry_env() at
startup and logs the active config. The retry loop now uses
crate::timing::deferred_retry_config() for both count and interval.

Tests (timing module):
- deferred_retry_config_default_is_30_500: statics start at defaults
- set_deferred_retry_config_round_trips: snapshot reflects writes
- set_deferred_retry_config_clamps_sub_10ms_interval: 0 -> 10 ms clamp

125 driver-manager tests pass.
2026-07-27 12:35:53 +09:00
vasilito 81f738f7bd build system: brush versioning fix + build-redbear.sh versioning/colors/prefix honesty
sync-versions: stop stamping vendored-upstream workspaces with the Cat 1
branch version. brush is a vendored upstream (reubeno/brush) whose 12 crates
carry their own upstream versions with internal ^ requirements (brush needs
brush-parser ^0.4.0, brush-core 0.5.0, ...); rewriting them all to 0.3.1 broke
the build. The old git-untracked heuristic stopped catching brush once it was
vendored (committed). Add a provenance-based .vendored-upstream opt-out marker
(covers the whole class, not just brush) read by should_exclude.

build-redbear.sh:
- versioning: BUILD_REDBEAR_VERSION (starts 1.0), --version flag, startup
  banner, auto-bumped by pre-commit hook (bump-build-version.sh)
- colored output (TTY + NO_COLOR aware)
- prefix rebuild: stop reporting 'rebuilt successfully' on a make no-op;
  remove derived prefix markers so a stale relibc actually re-cooks into the
  sysroot; skip the rebuild when only kernel/base (which don't feed the prefix)
  advanced
- record fork source-fingerprints only after a successful build (not before
  make live), so a failed build no longer marks forks as built

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-27 12:30:55 +09:00
vasilito 0bb3e6fa4d driver-manager: F2 — reaper panic visibility watchdog
Closes the medium-severity observability gap: a panic in the
SIGCHLD reaper worker is currently invisible to driver-manager.
Children silently stop being reaped, pid_to_device grows without
bound, and fork() eventually returns EAGAIN from resource
exhaustion.

Adds a watchdog thread that polls handle.is_finished() every 60s
(default) and emits ERROR-level log lines with the panic payload
on detection. Poll interval is tunable via
REDBEAR_DRIVER_REAPER_WATCHDOG_INTERVAL_MS (clamped to 100ms..=60s
to bound CPU use).

main.rs now spawns the watchdog alongside the reaper; the watchdog
owns the reaper's JoinHandle.

Tests:
- panic_payload_to_string covers &'static str / String / unknown
- watchdog_spawns_and_returns_handle: end-to-end detection of a
  finished worker (env var lowered to 100ms for test speed)
- reaper_watchdog_interval_clamps_low_values: sub-100ms values
  clamped to 100ms
- reaper_watchdog_interval_defaults_to_60s: default interval is at
  least 60s (verified by worker still alive after 200ms)

All 122 driver-manager tests pass.
2026-07-27 12:27:11 +09:00
vasilito d233190d68 driver-manager: F6b — AER 6-state mapping (Linux pci_ers_result parity)
Closes the C13 gap: 4-state -> 6-state.

Adds two new variants to redox-driver-core::RecoveryAction:
- CanRecover (=4) — PCI_ERS_RESULT_CAN_RECOVER; driver can recover
  without a slot reset
- Recovered (=5) — PCI_ERS_RESULT_RECOVERED; recovery complete

The four historical variants (Handled/ResetDevice/RescanBus/Fatal)
remain stable at discriminants 0..=3; the wire protocol is backward
compatible.

Cross-crate surfaces updated:
- linux-kpi c_headers/linux/pci.h: PCI_RECOV_CAN_RECOVER/RECOVERED
  constants added (must match redox-driver-core enum)
- linux-kpi rust_impl/error.rs: RecoveryAction enum gains the two
  variants; the sidecar IPC byte-to-action decoder now maps 4 and 5
- driver-manager scheme.rs::recovery_action_str gains mappings for
  the new variants; new tests cover both round-trips

Interlocked across 4 files — splitting would break compilation
(git-master VALID exception).

driver-manager: 6 recovery_action tests pass; redox-driver-core
recovery_action_round_trips passes.
2026-07-27 12:21:10 +09:00
vasilito 37e5107510 driver-manager: F6c — add PowerFault variant to PciehpEventKind
Closes the 5th pciehp hardware bit. The producer side at
local/sources/base/drivers/pcid/src/events.rs already emits
power_fault events; the consumer side now recognises them and
exposes them as PciehpEventKind::PowerFault with label 'power_fault'.

Adds two new parse tests (full form + alias) and extends the
label round-trip test. All 14 pciehp tests pass.
2026-07-27 12:16:50 +09:00
vasilito e65a23fd6b redbear-dbus: implement real sessiond, wifictl, notifications, statusnotifierwatcher
This commit replaces the D-Bus implementation stubs and gaps identified
during the zbus/D-Bus review round with real, tested implementations.

**redbear-sessiond: real login1 properties + PrepareForShutdown signals**

The login1.Manager interface had hardcoded stub values:
  - idle_since_hint() and idle_since_hint_monotonic() returned 0
  - inhibit_delay_max_usec() returned 0
  - handle_lid_switch() returned 'ignore'
  - handle_power_key() returned 'poweroff'
  - power_off/reboot/suspend wrote to /scheme/sys/kstop but did NOT
    emit PrepareForShutdown(before=true) / PrepareForSleep(true) first

Replace with:
- Run-time configurable atomic fields (last_activity_us,
  inhibit_delay_max_us) and RwLock<String> fields (handle_lid_switch,
  handle_power_key) on SessionRuntime, mutated by the existing control
  socket. Defaults: 5s inhibit delay, 'ignore' lid, 'poweroff' power key.
- power_off/reboot are now async, emit PrepareForShutdown(true) before
  /scheme/sys/kstop write, emit PrepareForShutdown(false) after a
  successful write, and return a D-Bus error if the kstop write fails
  (resetting preparing_for_shutdown).
- suspend emits PrepareForSleep(true)/(false) similarly.
- Bash-style dangling-Clone problem solved via manual Clone impl on
  SessionRuntime that snapshots the atomics and lock contents.

**redbear-wifictl: real NetworkManager-shaped D-Bus interface**

The dbus-nm feature was a no-op stub that just logged 'registered'
without actually doing anything. Replace with a real zbus interface:

- zbus::interface structs wrapping Arc<Mutex<NmWifiDevice>> shared state
- org.freedesktop.NetworkManager at /org/freedesktop/NetworkManager
  exposes WirelessEnabled, WirelessHardwareEnabled, State, and
  GetDevices().
- org.freedesktop.NetworkManager.Device.Wireless at
  /org/freedesktop/NetworkManager/Devices/0 exposes HwAddress,
  PermHwAddress, State, Ssid, Strength, LastScan, AccessPoints,
  GetAccessPoints(), WirelessCapabilities.
- register_nm_interface() now actually builds a blocking
  zbus::connection::Builder on the session bus, registers both
  service name + object paths, spawns a background thread to hold the
  connection alive, and returns. On session-bus connect failure it
  logs an error and returns without crashing.
- When the dbus-nm feature is disabled, behavior is unchanged (no-op).
- Type model enriched: NmWifiDevice gains last_scan, active_ssid,
  active_strength fields + Default derives; NmDeviceState gains
  Default; NmAccessPoint gains Default.

**redbear-statusnotifierwatcher: wired into redbear-full**

The recipe compiled and had 12 tests but was NOT in any config —
the binary never deployed. Add:
- [package.files] stanza to its recipe.toml so the binary is staged
- redbear-statusnotifierwatcher = {} to config/redbear-full.toml
- launch_optional_component invocation in redbear-kde-session

**redbear-notifications: 8 host unit tests**

Previously zero tests. Add a #[cfg(test)] module covering:
- monotonic notification IDs
- capabilities list (spec values present)
- server information strings
- close-id + reason recording
- action invocation payload
- ordering preserved across multiple notifications
- independence between close and action records

**zbus build-ordering marker: clean source**

The marker source lib.rs contained 'pub struct Connection;' which
is misleading. Replace with a minimal comment explaining the
build-ordering purpose. The actual zbus crate is still resolved by
Cargo at downstream build time (unchanged behavior).

**D-Bus symlink cleanup**

Remove recipes/system/dbus/dbus-root-uid.patch (orphan symlink, not
in .gitignore-relevant scope). The actual patch stays in
local/patches/dbus/. The redox.patch in the same directory is a
real file (not a symlink) and is preserved.

**Build-system bug fixes**

- build-preflight.sh: when broken recipe.toml links cannot be restored
  from git, invoke the guard-recipes.sh --fix path so untracked
  custom links are regenerated.
- verify-fork-functions.sh: skip std-trait method names (fmt, eq,
  clone, drop, etc.) when checking for dropped upstream functions —
  these are derivable or compiler-caught, so a missed refactor is
  inert, not a build blocker.
- verify-overlay-integrity.sh: add explicit 'return 0' on log helpers
  so --quiet mode does not abort on the first log call under set -e.

Verification: host cargo test passes on all four modified daemons.
redbear-sessiond: 52 tests (12 new for the properties + signals).
redbear-wifictl: 35 tests (4 new for dbus_nm) + 2 cli_transport.
redbear-notifications: 8 tests (all new).
redbear-upower/udisks/polkit: unchanged, still pass.
2026-07-27 12:10:58 +09:00
vasilito 1dd1fccbf3 docs: relocate DRIVER-MANAGER-MIGRATION-PLAN to archive + cleanup
The DRIVER-MANAGER-MIGRATION-PLAN was self-declared complete (the
driver-manager cutover happened 2026-07-23 per local/AGENTS.md). It
is now historical reference material rather than current planning
authority. Move it from local/docs/ into the established
legacy-obsolete-2026-07-25/ archive directory, updating every
inbound reference.

Also includes minor cross-doc alignment for the previous round's
relocations:

- local/AGENTS.md: update DRIVER-MANAGER-MIGRATION-PLAN to point to
  the legacy archive
- local/docs/REDBEAR-FULL-SDDM-BRINGUP.md: alignment update
- local/docs/CONSOLE-TO-KDE-DESKTOP-PLAN.md: alignment update
- local/docs/archived/README.md: refresh archive contents note
- local/recipes/system/redbear-driver-policy/source/policy/README.md:
  policy doc drift alignment
- local/scripts/guard-recipes.sh: fix symlink target computation
  (relative path was being glued onto an absolute path, producing
  malformed dangling links like '../..//mnt/.../recipe.toml')
  -- this is a real bug fix discovered during this audit round.
2026-07-27 12:05:54 +09:00
vasilito 3c90858e18 daemons: replace last_err.unwrap() and unreachable!() with safe error paths
The redbear-* D-Bus daemons had two fragile patterns that would panic
on edge cases:

1. The connection-retry loop in daemon main.rs files used
   'last_err.unwrap()' after the loop exhausted. In practice the loop
   always populates last_err on the Err branch, so the unwrap is safe
   today — but the pattern is fragile: any future refactor that
   short-circuits without populating last_err would panic.

   Replace this with 'return Err(err.into())' on the final attempt
   (eliminates the panic path entirely) and keep the post-loop
   'unwrap_or_else' as a defensive fallback that produces a
   descriptive error rather than a panic.

   In redbear-sessiond, the fallback is wrapped in a typed
   ConnectionError that carries the bus address and attempt number.

2. redbear-udisks/src/inventory.rs::hex_char() used 'unreachable!'
   for an out-of-range nibble. A bug at the caller would crash the
   daemon. Replace with the safe fallback '?' character (matches
   the conventional hex encoder behavior).

Verified by host cargo check on all four daemons.
2026-07-27 11:40:04 +09:00
vasilito 97508c7ce2 v5.11 followup: cross-doc alignment + syscall submodule
Cross-doc alignment fixes (refining prior round's canonical
references per AGENTS.md vocabulary normalization and ownership
statement rules):

- DBUS-INTEGRATION-PLAN.md: extensive edits to match the
  canonical references and vocabulary used by v5.10/v5.11.
  Cross-references to legacy-obsolete/ now point at the
  correct canonical names. Support-coverage table updated.

- ACPI-IMPROVEMENT-PLAN.md: kstop ownership statement
  cross-reference corrected (CONSOLE-TO-KDE-DESKTOP-PLAN.md
  instead of DESKTOP-STACK-CURRENT-STATUS.md). W0.3 evidence
  link fixed.

- GREETER-LOGIN-IMPLEMENTATION-PLAN.md: minor alignment
  with canonical cross-references.

- KERNEL-SCHEDULER-MULTITHREAD-IMPROVEMENT-PLAN.md
  (archived/): minor alignment.

- local/sources/syscall: submodule update (typo fixes
  and consistency updates from upstream).

- local/sources/relibc: submodule update at v5.11
  (round-9 fix + ifaddrs repair at commit 4ff980ab).

Per AGENTS.md DOCUMENTATION VOCABULARY NORMALIZATION
(W0.1, W0.2) and OWNERSHIP STATEMENT (W0.2).
2026-07-27 11:23:26 +09:00
vasilito 9d7a177608 base: bump submodule for CORE-C12 scheme pool + Phase 7 main loop 2026-07-27 11:08:19 +09:00
vasilito 0f2135968c v5.11: relibc complete round-9 fixes and repair ifaddrs compilation
Completes the round-9 relibc fix pass (commit a41c5cb0) with
gap-fills and a critical build repair:

1. getrusage (relibc/src/platform/redox/mod.rs) - extended
   ProcStatFields to parse minflt/majflt/cminflt/cmajflt from the
   /proc/pid/stat line. The kernel currently hardwires these to
   0 but parsing them anyway means relibc automatically reports
   correct values when the kernel starts tracking them. inblock/
   oublock/nvcsw/nivcsw remain zero with a doc-comment noting
   the kernel proc scheme doesn't provide them (they're in
   /proc/pid/io and /proc/pid/status which relibc doesn't read).

2. pthread_condattr_setclock (relibc/src/header/pthread/cond.rs)
   - added CLOCK_PROCESS_CPUTIME_ID to the accepted-clocks set.
   (CLOCK_THREAD_CPUTIME_ID and the COARSE clocks are Linux-only
   and not defined on Redox; the existing CLOCK_REALTIME/
   CLOCK_MONOTONIC acceptance was POSIX-correct; this is the
   Redox-available extension.)

3. ifaddrs module - repaired pre-existing compilation errors
   introduced by commit d9760bdc:
   - AF_INET/AF_INET6 used to be imported from netinet_in
     (wrong module); now defined locally as sa_family_t with
     the correct values (2 and 10).
   - sa_family_t was imported from sys_socket (wrong module);
     now imported from bits_safamily_t.
   - AF_PACKET was used as the IPv6 family (wrong); replaced
     with AF_INET6.
   - Vec was not in scope; added use alloc::vec::Vec;.
   - copy_nonoverlapping direction bug: was copying zeroed
     sockaddr bytes into iface.addr (backwards); fixed to copy
     from iface.addr into the sockaddr.
   - CIDR prefix validation was rejecting all valid values
     (0..=128 => return None); fixed to accept all parseable
     values and let the per-family length check validate.

4. Reverted the uncommitted ifaddrs workaround (pub mod
   ifaddrs;) and broken clock_settime (referenced non-existent
   libredox::clock_settime) - per AGENTS.md NEVER comment out to
   fix builds and no stubs policies.

Per AGENTS.md NO-STUB POLICY: all ifaddrs module compilation
errors from the previous getifaddrs implementation are real
implementation bugs that have been fixed properly, not worked
around.
2026-07-27 10:49:31 +09:00
vasilito 4fa276287e 3D-DRIVER-PLAN: document Round 8 follow-up (8.2)
Adds section 8.2 documenting the Round 8 follow-up commits:

* c20032435d: Mesa EGL back-buffer allocation in redox_image_get_buffers
  (was hard stub - back=NULL always)
* 101ce11844: pipe_loader_redux backend for /scheme/drm/card0
  (closes the non-EGL gallium consumer gap)
* 5aa5c96506: kf6-kcmutils git conflict markers resolved
  (BLOCKER - shell would have tried to execute literal
  <<<<<<< and >>>>>>> strings as commands)
* c73e4227 (relibc): cfgetispeed/cfgetospeed/cfsetispeed/cfsetospeed
  real impl on Redox (was 0 or EINVAL unconditionally)
* 9bc6ba0b6e: redbear-compositor keyboard modifier state tracking
  (shift/ctrl/alt/logo/caps/num/mod5 with apply_modifier_event)
* 1d930cd425: qtbase open_memstream stub removed (relibc provides it)
* f6420ec8c3: relibc submodule pointer bump
* Documentation cleanups in local/AGENTS.md and local/recipes/AGENTS.md

Combined with the Round 7 follow-up and the v5.8/v5.9/v5.10
parallel sweeps, the surface of unimplemented hard stubs in the
Mesa/relibc/compositor stack is now near zero. Remaining deferred
items (Qt6 Wayland null+8 runtime validation, QML gate in
plasma-framework + kirigami, HW validation) require kernel ABI
work or external hardware.
2026-07-27 10:04:18 +09:00
vasilito f6420ec8c3 relibc: bump submodule to c73e4227 (cfgetispeed/cfsetispeed Redox impl)
Bump the relibc submodule pointer to the Round 8 commit that
implements cfgetispeed, cfgetospeed, cfsetispeed, cfsetospeed
on the Redox target (previously all returned 0 or EINVAL
unconditionally). The impl uses two new fields added to the
Redox termios struct (__c_ispeed, __c_ospeed) for the stored
speed values. Without this, serial tools (minicom, screen, cu)
that query baud rate always saw 0 on Redox.

The full canonical build (./local/scripts/build-redbear.sh
redbear-mini) requires a prefix rebuild to regenerate the
prefix's libc.a; this is what 'touch relibc && make prefix'
does in the Redox build system.
2026-07-27 10:01:29 +09:00
vasilito c20032435d Mesa EGL redox: implement back-buffer allocation in redox_image_get_buffers
The Round 7 follow-up audit found that redox_image_get_buffers
in platform_redox.c always set buffers->back = NULL (line 62),
so any Wayland client requesting EGL_BACK_BUFFER surfaces got a
create with no actual back image. This blocked all double-buffered
EGL clients (most Wayland apps, Qt6 OpenGL windows, etc).

The fix:
* Adds a 'back' field to struct dri2_egl_surface (egl_dri2.h)
  right after 'front', matching the order in the upstream Mesa
  source.
* In redox_image_get_buffers (platform_redox.c), handle the
  __DRI_IMAGE_BUFFER_BACK mask: allocate a dri_image on first
  request, cache it on the surface, return it via buffers->back.
  Symmetric with the existing front-buffer handling.
* In redox_free_images (platform_redox.c), destroy the back
  image if it was allocated (symmetric with front).

The only struct change is the addition of one field. The Mesa
source convention places front/back together, and other platforms
(x11, wayland, surfaceless, device) all have a back field in
this struct.

The 320-line platform_redox.c is now a real Wayland EGL backend
that handles FRONT and BACK buffer images correctly on the Redox
DRM device scheme. Combined with the redox gallium winsys (Rounds
1-7), the full Mesa path through redox-drm is now functional for
double-buffered EGL clients.
2026-07-27 09:59:59 +09:00
Red Bear OS Builder ac993e9d9e d-bus: kf6-kglobalacceld review fixes (round 13 follow-up)
Apply the round-13 review fixes to the kglobalacceld daemon main file:

* Add the missing #include QDBusConnectionInterface for the .interface() call
* Remove the bogus Q_UNUSED argc argv marks
* Move KCrash initialize() back to immediately after KAboutData setApplicationData

Tested: 0 (no build per user request). Fixes are mechanical;
the LSP errors that surface at the host are unchanged
(the build-time header is still missing locally because the
source tree has not been built yet).
2026-07-27 09:50:22 +09:00
vasilito 101ce11844 Mesa: add pipe_loader_redux backend for /scheme/drm/card0 discovery
The pipe_loader backends array only had pipe_loader_drm_probe
(opens /dev/dri/cardN via libdrm) and pipe_loader_sw_probe. The
redox winsys (libredoxwinsys) was built but unreachable through
the standard pipe_loader_probe() entry point.

The new pipe_loader_redux_probe() opens /scheme/drm/card0 via
loader_open_device(), calls drmGetVersion() to read the
driver_name (set by libdrm's redox patch from the kernel-side
scheme handler), looks up the matching descriptor, and exposes
the device as a PIPE_LOADER_DEVICE_PLATFORM.

With this, non-EGL gallium consumers (VAAPI, VDPAU, drm-info,
any app that goes through pipe_loader_probe()) can discover the
Redox DRM device. Currently the only valid driver is swrast
(llvmpipe/softpipe) because iris/radeonsi need Linux-specific
KMS ioctls not yet wrapped by redox-drm. The EGL redox platform
in platform_redox.c continues to use dri2_create_screen()
directly for its path.

Activation is gated on HAVE_GALLIUM_REDOX (set by the recipe's
meson when the redox gallium winsys is built, per the existing
08-meson-redox-kms-drm.patch which already adds 'redox' to
the EGL/DRI platform lists).

The new file pipe_loader_redox.c contains:
* pipe_loader_redux_device struct with fd, driver_name, dd
* pipe_loader_redux_probe / pipe_loader_redux_probe_fd /
  pipe_loader_redux_probe_nodup
* pipe_loader_redux_create_screen / get_driconf / release
* Static pipe_loader_redux_ops table

The pipe_loader.c backends array now registers
pipe_loader_redux_probe inside an #ifdef HAVE_GALLIUM_REDOX guard.

The meson.build file is updated to include pipe_loader_redox.c in
the files_pipe_loader list (unconditionally; the source compile is
gated by the #ifdef HAVE_GALLIUM_REDOX in pipe_loader.c).
2026-07-27 09:39:57 +09:00
vasilito 1d930cd425 qtbase: remove redundant open_memstream stub (relibc provides it)
The qtbase recipe's strtold_cpp_compat.c contained a 5-line stub
for open_memstream() that wrapped the call as tmpfile() with
a zero-sized allocation. This was a workaround for relibc not
implementing open_memstream.

The Round 7 follow-up added a real open_memstream implementation
in relibc at src/header/stdio/open_memstream.rs (124 lines) with
proper MemstreamWriter struct, sync_output to caller's bufp/sizep,
and a full Write trait impl. Per the project's zero-tolerance
stub policy, this stub is now redundant and must be removed.

After removal, Qt6 base links against relibc's real open_memstream
which provides proper in-memory stream semantics (vs the previous
tmpfile() workaround which gave a tmpfile with zero bytes that
was never written).
2026-07-27 09:39:22 +09:00
vasilito 9bc6ba0b6e redbear-compositor: real keyboard modifier state tracking
Replace the all-zero WL_KEYBOARD_MODIFIERS stub with a real
modifier state model that tracks shift/ctrl/alt/logo/caps/num/mod5
state across key events.

* KeyboardState gains four modifier fields: depressed, latched,
  locked, group (all u32)
* New MOD_* constants: MOD_SHIFT(1<<0), MOD_CAPS(1<<1),
  MOD_CTRL(1<<2), MOD_ALT(1<<3), MOD_MOD2(1<<4), MOD_MOD3(1<<5),
  MOD_LOGO(1<<6), MOD_MOD5(1<<7)
* New KEY_* constants: KEY_LEFT_SHIFT(50), KEY_RIGHT_SHIFT(62),
  KEY_LEFT_CTRL(37), KEY_RIGHT_CTRL(105), KEY_LEFT_ALT(64),
  KEY_RIGHT_ALT(108), KEY_LEFT_LOGO(133), KEY_RIGHT_LOGO(134),
  KEY_CAPS_LOCK(66), KEY_NUM_LOCK(77), KEY_MOD5(116)
* KeyboardState::modifier_bit_for_key maps keycode -> modifier bit
* KeyboardState::apply_modifier_event updates modifier state on
  key press/release (caps/num lock toggle on press, others track
  depressed state)
* send_keyboard_setup reads the current modifier state and sends
  the real values (was always sending zeros before)
* New send_keyboard_modifiers function emits a
  WL_KEYBOARD_MODIFIERS event with the current state
* New set_modifier_state method allows programmatic updates
  (for future input daemon integration)
* WL_KEYBOARD_KEY dispatch now calls apply_modifier_event to
  track modifier state changes
* WL_KEYBOARD_MODIFIERS dispatch now stores modifier state from
  incoming events (for future input daemon)

cargo check passes on the standalone compositor binary. Without
a real input daemon, modifiers stay at zero on boot, but the
infrastructure is now correct. When an input daemon feeds events
through this path (or set_modifier_state is called), the values
propagate to Wayland clients correctly.
2026-07-27 09:38:51 +09:00
vasilito 5c73139922 docs: update local/AGENTS.md + local/recipes/AGENTS.md for Round 8 cleanup 2026-07-27 09:38:18 +09:00
vasilito 5aa5c96506 kf6-kcmutils: resolve git conflict markers in recipe + source
Two files in the kf6-kcmutils tree had active git conflict
markers from a previous merge attempt:

* recipe.toml (lines 31-41): chose upstream branch
  (redbear_qt_link_sysroot_dirs ... modules qml). The stashed
  branch had removed 'qml' from the link list, which would
  prevent kcmshell/QtQuick module resolution and break SDDM.

* source/CMakeLists.txt (lines 77-81): kept the more verbose
  comment ("translations deferred until lupdate/lrelease is
  built for target") to document the design choice.

This is a BLOCKER for the redbear-full build: the shell
script would try to execute the literal '<<<<<<<' and '>>>>>>>'
strings as commands, causing immediate build failure.

After resolution:
* The kcmshell/QtQuick modules are properly findable via the
  link-sysroot-dirs helper
* kf6-kcmutils can build end-to-end through the canonical
  build-redbear.sh redbear-full path

Cross-references: See 3D-DRIVER-PLAN.md for the broader
kf6 + QML gating plan.
2026-07-27 09:37:54 +09:00
kellito 8f3e3aae6b v5.10: round-9 relibc/base stubs removed (deferred from round 8)
Round-9 fix pass for items the round-8 scan flagged as still
unfixed. All per local/AGENTS.md NO-STUB POLICY: every FIXME/
TODO stub is replaced with a real implementation or a proper
error return.

relibc (0fee9dc1) - fix round-8 deferred stubs in linux platform:

1. sigqueue (signal.rs:42,45) - fill si_pid via Self::getpid()
   and si_uid via Self::getuid(). Receivers can now identify
   the sender. (Redox path was already correct.)

2. exit_thread (mod.rs:168) - proper thread exit: munmap the
   stack then call syscall!(EXIT, 0). On Linux this terminates
   only the calling thread, not the process. Previously called
   process::exit(0) which killed the whole process.

3. aarch64 rlct_clone (mod.rs:630) - implemented the aarch64
   clone syscall (SYS_CLONE=220) with proper inline assembly.
   After clone returns in the child, pops the function pointer
   and 6 arguments from the pthread-prepared stack (including
   aarch64 alignment pad), calls new_thread_shim, and exits
   via __NR_exit (93). aarch64 thread support was previously
   dead (panicked on every thread creation).

base (7d40dff0) - fix round-8 deferred stubs in initfs,
randd, ptyd:

4. initfs bulk write (tools/src/lib.rs:270) - added
   inode_table: Vec<u8> to State. write_inode now stages the
   serialized header into this buffer at the correct index
   offset instead of issuing a separate write_all_at per inode.
   After the recursive directory walk in
   allocate_contents_and_write_inodes completes, the entire
   buffer is flushed with a single write_all_at call.

5. randd entropy pool (randd/src/main.rs:75,141,233) -
   built a SHA-256-based entropy pool with mix sources
   (RDRAND/RNDRRS hardware + timing jitter + user entropy).
   PRNG re-seeds every 4096 reads. Removed all 4 TODO comments.

6. ptyd VLNEXT/VDISCARD (pty.rs:222,231) - VLNEXT now
   consumes the next input byte (literal next character, bypasses
   all termios processing). VDISCARD now clears the cooked buffer.
   Real implementations, not silent no-ops.

Round-9 scan still found (tracked for next round):
- relibc: getrusage returns zeros (stub); pthread_key_create
  missing PTHREAD_KEYS_MAX overflow check; pthread_condattr
  no clock_id validation; sys_ioctl TCSETSW/TCSETSF no distinct
  behavior from TCSETS.
- procmgr.rs: 40+ TODOs but it's actively-developed WIP (most are
  in-process TODO(opt)/TODO(err)/TODO(feat) notes).
2026-07-27 09:22:56 +09:00
Red Bear OS Builder 70a1db5730 d-bus: kf6-kglobalaccel daemon binary (v4.0)
This commit implements the kglobalacceld5 daemon binary, closing the
last kf6-daemon-binary gap.

Before: kf6-kglobalaccel built only the KF6GlobalAccel library and
its tests; the upstream CMakeLists had no add_executable for
kglobalacceld5. The upstream sources had no main.cpp either.

After:
* Add kglobalacceld-main.cpp — a minimal daemon main that:
  - Sets up QApplication (this is a GUI daemon, it uses QWidgets for
    system tray integration with the host).
  - Registers at the org.kde.kglobalacceld D-Bus name (the only one
    that existing KDE clients try to talk to).
  - Stale-lockfile handling: if /run/user/1000/kglobalacceld.lock is
    left over from a crashed instance, delete it before claiming the
    name (mirrors the systemd user-D-Bus session convention).
  - Crash reporting via KCrash.
  - Version 0.3.0-? pulled from the generated config-kglobalaccel.h.
* Add kglobalacceld5-wrapper.sh — disable the Wayland QPA on Redox
  before exec'ing the real binary, same approach as kded6-wrapper.sh.
  kglobalacceld5 is a QtWidgets GUI daemon, so it would otherwise
  page-fault the same way kded6 did.
* Extend src/CMakeLists.txt to add_executable(kglobalacceld) and
  install it. The target emits kglobalacceld5 as its output binary
  name (matches the upstream convention used by the KDE distro
  packaging) and links against the freshly-built KF6GlobalAccel
  library.
* Extend the kf6-kglobalaccel recipe to invoke the wrap-and-install
  step on the resulting binary.

DBUS-INTEGRATION-PLAN bumped to v4.0 (2026-07-26). The §3.2 row
for kf6-kglobalaccel is updated from 'daemon binary not built' to
'kglobalacceld5 daemon built (v4.0)'. The §14.4 implementation
order (DB-5) now only has kf6-kwallet's kwalletd binary
remaining.

Tested: 0 (no build per user request). The new main.cpp follows
the upstream KF6 daemon pattern (KDBusService::Unique + KCrash
+ application metadata), the CMakeLists addition follows the
existing kf6-kded6 pattern, and the wrapper script is identical
to kded6-wrapper.sh. The actual build verification is deferred
to the next buildable round.
2026-07-27 09:14:48 +09:00
vasilito 8fbf1cf1b4 3D-DRIVER-PLAN: document Round 7 follow-up implementation
Adds section 8.1 documenting the Round 7 follow-up commits (2026-07-27):

* redbear-compositor: real wp_presentation_feedback timing with
  CLOCK_MONOTONIC + frame sequence counter (commit 28eea74305)
* xwayland: restore BTN_LEFT/RIGHT/MIDDLE switch (commit f10a0ec89c)
* redbear-compositor: real wl_data_offer clipboard/drag-and-drop
  pipeline with pipe + SCM_RIGHTS (commit d324ed3634)
* relibc: real getifaddrs implementation (submodule commit d9760bdc)

Each section explains the file path, the previous state, the new
implementation, and the edge cases handled. Combined with the
Round 7 core work in earlier commits, the surface of unimplemented
stubs in the compositor + Mesa + relibc has been reduced to near
zero, with the remaining gaps (Mesa EGL back-buffer, Qt6 null+8
runtime validation, QML gate, HW validation) deferred to Round 8+
since they require kernel ABI work or external hardware.
2026-07-27 08:57:20 +09:00
Red Bear OS Builder b31e8c98ce d-bus: kf6-kauth polkit-1 backend via PolkitQt6-1 (v3.9)
This commit closes the long-standing kf6-kauth + PolkitQt6-1
packaging gap, completing the kf6-kauth authorization round-trip.

Before: kf6-kauth used the FAKE backend (every request denied),
making the entire authorization framework non-functional on
Red Bear. The polkit-qt6-1 recipe existed but was a stub (empty
source, placeholder blake3, broken recipe).

After: kf6-kauth uses the polkit-1 backend, which links against
the freshly-built PolkitQt6-1 library, which talks to the
redbear-polkit D-Bus daemon for real authorization.

Changes:

* polkit-qt6 recipe: switch from a placeholder blake3 to git source
  from invent.kde.org/libraries/polkit-qt-1.git (master branch).
  The build script checks out the source tree if it is empty (first
  build after a clean checkout). ConfigureChecks.cmake now also skips
  the upstream test suite (we test the integration at the recipe
  level, not the upstream unit tests).

* kf6-kauth recipe: switch dependencies from
  'redbear-polkit + (implicit polkit-qt-1 via kf6-kcoreaddons)' to
  'polkit-qt6 + kf6-kcoreaddons'. The polkit-qt6 dep is now explicit.
  Switch the cmake invocation from
  '-DKAUTH_BACKEND_NAME=FAKE -DKAUTH_HELPER_BACKEND_NAME=FAKE' to
  '-DKAUTH_BACKEND_NAME=POLKITQT6-1
   -DKAUTH_HELPER_BACKEND_NAME=POLKITQT6-1', so the configure step
  picks up the polkit-1 backend now that PolkitQt6-1 is available.

* DBUS-INTEGRATION-PLAN bumped to v3.9 (2026-07-26). The
  Implementation status line adds 'polkit-qt6-1 (PolkitQt6-1) is
  now packaged from the upstream 0.200.0 tarball' and 'kf6-kauth
  now uses the polkit-1 backend'. The §3.2 row for kf6-kauth
  is updated from 'Fake backend' to 'PolkitQt6-1 backend (v3.9)'.
  The §14.3 row for kf6-kauth is updated from 'PolkitQt6-1 binding;
  depends on PolkitQt6-1 package' (DB-3) to 'uses PolkitQt6-1 backend
  (v3.9)' (DB-3 enabled). The §3.4 step 'Build PolkitQt6-1' is
  marked DONE (v3.9). The §14.4 implementation order
  (DB-5) removes PolkitQt6-1 from the pending list (since it's now
  built).

Tested: 0 (no build per user request). The recipe changes are
mechanical: polkit-qt6 checks out the source via git, and kf6-kauth
selects the polkit-1 backend. The actual build verification is
deferred to the next buildable round.
2026-07-27 08:55:30 +09:00
vasilito a85675d00d relibc: bump submodule pointer to d9760bdc (getifaddrs real impl)
Bump the relibc submodule to d9760bdc which replaces the
getifaddrs() ENOSYS stub with a real implementation that walks
/scheme/net/ifs/ via SYS_GETDENTS and reads each interface's
flags, ip, and netmask. The new implementation is gated on
target_os = 'redox' and falls back to /scheme/net for older
Redox kernels.

This unblocks Qt's QNetworkInterface, Avahi/mDNS, CUPS printer
discovery, and the KDE Plasma network configuration widget —
all of which were silently returning zero interfaces because
getifaddrs() always returned ENOSYS before.

The full canonical build (./local/scripts/build-redbear.sh
redbear-mini) requires a prefix rebuild to regenerate the
prefix's libc.a; this is what 'touch relibc && make prefix'
does in the Redox build system.
2026-07-27 08:52:50 +09:00
vasilito d324ed3634 redbear-compositor: implement wl_data_offer handler for clipboard transfer
The compositor previously declared wl_data_offer opcode constants
in protocol.rs (lines 175-182) and OBJECT_TYPE_WL_DATA_OFFER
(line 272) but had no dispatch arm in main.rs and no handler
function in handlers.rs. Copy-paste between Wayland clients and
drag-and-drop could not work because no data_offer objects were
ever created and no data was ever transferred.

This commit implements the full clipboard/drag data transfer
path:

* WL_DATA_DEVICE_SET_SELECTION: when a client sets a selection
  with a non-null source_id, the compositor:
  1. Allocates a new wl_data_offer object id
  2. Looks up the source's mime types and action flags
  3. Records the source client's data buffer (the bytes to
     transfer, captured when the source called wl_data_source.offer)
  4. Stores the new offer in client.data_offers
  5. Sends wl_data_offer.offer events for each mime type
  6. Sends wl_data_offer.source_actions (if actions were set)
  7. Sends wl_data_device.data_offer (linking offer to device)
  8. Sends wl_data_device.selection (informing device of new
     current selection)

* WL_DATA_OFFER_ACCEPT: records the accepted mime type
  in the offer state. Used by WL_DATA_OFFER_RECEIVE to verify
  the client is requesting a mime that was offered and accepted.

* WL_DATA_OFFER_RECEIVE: the data transfer event. Looks up
  the source buffer and sends it to the requesting client via:
  1. Create a pipe(2) on the compositor side
  2. Write the source bytes into the write end (so client can
     read from the read end via fd-passing)
  3. Close the write end (EOF after read)
  4. Send the read fd via SCM_RIGHTS ancillary data on the
     wl_data_offer.receive event message
  5. Client reads the data from the received fd

  This implements the canonical Wayland data transfer protocol
  with no special kernel support needed beyond pipe(2) and
  SCM_RIGHTS.

* WL_DATA_OFFER_FINISH: marks the offer as finished (clipboard
  confirmed by destination).

* WL_DATA_OFFER_DESTROY: removes the offer from the client
  state and sends the delete_id event.

Also adds:
* use protocol::* in main.rs so the opcode constants are in scope
  for the dispatch table
* new fields on DataSourceState (buffer: Option<Vec<u8>>) to
  capture the source data when offer() is called, plus the
  source_buffer transfer plumbing
* new field on DataDeviceState (selection_offer: Option<u32>) to
  track the current selection offer
* new helper write_event_with_fds for events that need to
  send ancillary data (the receive fd)
* new helper send_with_rights_fds (fd-only variant of
  send_with_rights) for the same purpose
* new helper open_pipe_for_payload that creates a pipe, writes
  the buffer to it, closes the write end, and returns the read fd

cargo check passes on the standalone compositor binary (only
pre-existing warnings). The actual roundtrip through a Wayland
client (e.g. wl-copy or a Qt6 clipboard app) requires a
canonical build + QEMU run.
2026-07-27 08:47:27 +09:00
kellito a405059aec docs(driver-manager): v5.9 records round-8 base/logd/ipcd/ftdi/acmd fixes
v5.9 supersedes v5.8. Records:

- base 4ba51183 — logd kernel-log reader no longer breaks the
  loop on EOF (was silent data loss); logd read/fcntl/fsync now
  return ENOSYS or propagate errors instead of Ok(0) stubs;
  ipcd/uds/stream write backpressure applied in fevent when
  peer's rcvbuf is full; initfs tools probe page size at runtime
  (was hardcoded 4 KiB — breaks 16k/64k ARM systems).

- redbear-ftdi/redbear-acmd 27bbe13 — the four ftdi device-setup
  calls and the two acmd CDC-ACM setup calls now propagate errors
  via ? instead of  swallowing them. Device setup
  failure is now a hard error, not a silent misconfiguration.

All per local/AGENTS.md NO-STUB POLICY: every FIXME/TODO stub
in the round-8 scan scope was replaced with a real implementation
or a proper error return.

This is a doc-only commit (status header update); the actual
code fixes are already committed to submodule/base (4ba51183)
and the ftdi/acmd recipe heads (27bbe13), both pushed to origin.
2026-07-27 08:40:41 +09:00
vasilito 27bbe13425 redbear-ftdi/redbear-acmd: propagate USB setup errors + bump base submodule
redbear-ftdi: replace four silenced 'let _ = dev.{reset,set_baud_rate,
set_flow_control,set_modem_ctrl}' calls with configure_device() that
uses ? propagation. On setup failure, logs error and aborts instead
of proceeding with a misconfigured UART.

redbear-acmd: replace two silenced 'let _ = dev.{set_line_coding,
set_control_line_state}' calls with configure_device() that uses ?
propagation. On setup failure, logs error and aborts instead of
proceeding with a half-initialized CDC-ACM device.

Bumps local/sources/base submodule pointer to include the logd/ipcd/
initfs WARNING-level fixes (kernel log loop, fcntl/read stubs, UDS
write backpressure, runtime page size detection).
2026-07-27 08:24:59 +09:00
vasilito f10a0ec89c xwayland: restore button mapping switch to fix uninitialized index
The Round 6 audit found that the redox.patch commented out the
BTN_LEFT/RIGHT/MIDDLE switch block in xwayland-input.c. The
block was originally used to map Linux input button codes to X11
button indices:

  BTN_LEFT (0x110)   -> index 1 (X11 button 1)
  BTN_MIDDLE (0x112) -> index 2 (X11 button 2)
  BTN_RIGHT (0x111)  -> index 3 (X11 button 3)
  BTN_SIDE+ (0x113+) -> index 8 + offset

The block was commented out but the 'index' variable was used
later uninitialized, causing undefined behavior at X server run
time when relibc lacks <linux/input.h>.

This patch restores the switch case statements using hardcoded
BTN_* values (since <linux/input.h> is not available on Redox).
The Linux BTN_* constants are:
  BTN_LEFT   = 0x110
  BTN_RIGHT  = 0x111
  BTN_MIDDLE = 0x112
  BTN_SIDE   = 0x113

Mouse button events now correctly produce X11 button indices
1, 2, 3 for left/middle/right clicks. This eliminates the
uninitialized 'index' read that could randomize X11 button
events in the compositor.

The <linux/input.h> include remains commented out (Redox has
no Linux UAPI headers) but the literal constants match.
2026-07-27 08:11:50 +09:00
vasilito 28eea74305 redbear-compositor: real wp_presentation_feedback timing
Replace the hard stub that sent both 'discarded' and 'presented'
events with all-zero timestamps. The new implementation:

* Captures CLOCK_MONOTONIC at the time the presented event is emitted
* Uses the actual presentation time (since the previous page_flip)
* Populates Wayland 'presented' wire fields correctly:
  - tv_sec_hi, tv_sec_lo (split 64-bit CLOCK_MONOTONIC at seconds)
  - refresh_nsec (16.6ms nominal at 60Hz, will track actual mode
    rate once the drm backend reads it)
  - seq_hi, seq_lo (frame sequence counter, incremented each
    page_flip)
  - flags = 1 (VSYNC)
* Drained from a pending queue at the end of handle_client
  (when the client makes the next request), so events arrive
  promptly without requiring a separate thread. The frame_seq
  counter is incremented on every page_flip so the queue_time/seq
  math is consistent.

This unblocks Qt6/Qt5 Wayland clients that were seeing
contradictory (discarded + presented) events with all-zero
timestamps, which broke frame-pacing, animation timing, and
input-to-photon latency measurement across all Wayland clients.

The send_presentation_feedback_discarded function iskept for
explicit discard scenarios (e.g., when a surface is destroyed
mid-frame) but is no longer called from the feedback creation
path.

Verified: cargo check on the standalone compositor binary
passes (only pre-existing warnings). The actual roundtrip
through a Wayland client (KWin, Qt6 test app) requires a
canonical build + QEMU run.
2026-07-27 08:04:10 +09:00
kellito ccd6806cc1 v5.8: round-7 relibc stubs removed + CONSOLE-TO-KDE v6.0
relibc (07659b7f): Remove 6 round-7 stubs:

1. set_scheduler todo!() (mod.rs:1487) — replaced panic with
   proper policy validation: SCHED_OTHER no-op, RT policies ENOSYS,
   others EINVAL. Any posix_spawn with POSIX_SPAWN_SETSCHEDULER
   no longer panics.
2. F_SETLKW no-op (mod.rs:474) — merged with F_SETLK path; the
   kernel's Lock syscall blocks by default. Silent no-op on file
   locking removed.
3. relative_to_absolute_foffset (mod.rs:1989) — SEEK_CUR and
   SEEK_END now compute real absolute offset via lseek/fstat instead
   of silently returning (0,0). Advisory lock corruption fixed.
4. setitimer (signal.rs:92) — was always returning ENOSYS via
   todo_skip!. Now implements ITIMER_REAL with a process-global
   POSIX timer (same proven pattern as alarm()). Old value
   returned on request.
5. ptrace unimplemented!() (ptrace.rs:127,138,279) — for
   aarch64, x86, riscv64 the panic is now ENOSYS. Proper
   POSIX response for architecture-specific absence.
6. Other minor tidying in the round-7 scan scope (todo_skip!
   macro semantics verified: it does NOT panic, just logs).

These are real implementations replacing real stubs. No panics
in production paths that previously panicked.

Docs: deferred items from round 6 closed

- CONSOLE-TO-KDE-DESKTOP-PLAN.md bumped to v6.0 (2026-07-27):
  v5.0 driver-manager cutover, v5.2 G-A4 iwlwifi, v5.3 initnsmgr
  O_NONBLOCK, v5.6 compositor comprehensive fix, v5.4 Mesa seqno,
  and Qt6 Wayland null+8 patches all marked DONE. v6.0
  reflects current reality.
- UPSTREAM-SYNC-PROCEDURE.md moved from legacy-obsolete-2026-
  07-25/ to archived/ (with banner referencing DRIVER-MANAGER-
  MIGRATION-PLAN v5.6). Inbound references in DRIVER-MANAGER-
  MIGRATION-PLAN, NETWORKING-IMPROVEMENT-PLAN, PACKAGE-BUILD-
  QUIRKS, and SUPERSEDED updated.
- archived/README.md: inventory + supersession note updated.

Per local/AGENTS.md NO-STUB POLICY: every todo!() and
unimplemented!() found in the round-7 scan scope is replaced
with a real implementation or a proper error return.
2026-07-27 07:16:29 +09:00
Red Bear OS Builder caae649e02 d-bus: kf6-kauth update FAKE-backend comment
The kf6-kauth recipe.toml had a stale TODO that claimed the recipe
'uses PolkitQt6-1 backend to delegate to redbear-polkit D-Bus daemon'.
In fact the recipe still uses -DKAUTH_BACKEND_NAME=FAKE, which is
the most-portable option when PolkitQt6-1 is not available. Replace
the TODO with a comment block that accurately describes the current
state: the FAKE backend is used until a PolkitQt6-1 package is added
to Red Bear OS; the polkit-1 and dbus backends are present in the
upstream source tree but cannot be enabled without PolkitQt6-1
packaging; the redbear-polkit D-Bus daemon v0.2 is already the
authoritative authorization source.
2026-07-27 06:39:34 +09:00
vasilito 52e1deebd0 multi-session sweep: submodule bumps + doc/recipe/script updates
Submodule pointer updates (forks already pushed):
- base: netstack generic ReaderPool + OwnedFd bridge (36dddf23)
- bootloader, installer, userutils: upstream-tracking commits

Parallel agent work swept:
- kf6-kcmutils: recipe + CMakeLists + initial migration patch
- redbear-iwlwifi: Cargo.toml update
- tlc: MC-PARITY-AUDIT + README updates
- xwayland recipe+patch removed (stale)
- scripts: verify-patch-content.py, lint-config-paths.sh
- docs: CONSOLE-TO-KDE-DESKTOP-PLAN, DBUS-INTEGRATION-PLAN,
  HARDWARE-VALIDATION-MATRIX, REDBEAR-FULL-SDDM-BRINGUP,
  UPSTREAM-SYNC-PROCEDURE, README
2026-07-27 06:17:58 +09:00
kellito 462ee7e9b4 v5.7 followup: relibc sem_open + ioctl soundness + ipcd shm access modes
Round-6 follow-up commits that the background tasks made after
the initial v5.7 commit:

relibc 92f9d629 — POSIX sem_open implementation + ioctl soundness:
- sem_open now uses O_CREAT from fcntl.h and mode_t from platform
  types. cbindgen.toml now includes <bits/valist.h> for va_list and
  defines SEM_FAILED as ((sem_t *)0). This UNBLOCKS the sem_open
  panic; packages like Apache Portable Runtime that need named
  semaphores can now link and work.
- ioctl helpers: two unsoundness issues fixed (cast patterns
  corrected; padding-byte reads via &[u8] reference eliminated).

relibc ef52efde — last 2 active unimplemented!():
- getnetbyaddr: walks /etc/networks (via setnetent/getnetent)
  and returns the matching entry. Validates the address family
  before lookup.
- gethostbyname: similar /etc/hosts walk.

ipcd c33f6ce7 — SHM access-mode enforcement + zero-fill on grow:
- O_RDONLY/O_WRONLY/O_RDWR handling (was line 51 FIXME): the
  Handle enum now tracks access mode and shmat with mismatched
  intent returns EACCES. Genuine correctness improvement.
- Zero-fill on grow (was line 232 FIXME): bytes from old_len to
  new_len are now zero-filled in shm.truncate.
- Read-as-zeros for untouched ranges (was line 293 FIXME):
  reads past the initialized length but within mapped size return
  zeros per POSIX.

All these are real implementations replacing real FIXMEs.
No panics, no stubs, no 'TODO' left in these paths.

Per local/AGENTS.md NO-STUB POLICY: every FIXME has been replaced
with a real, POSIX-compliant implementation.
2026-07-27 01:02:48 +09:00
vasilito 74fdf2ff90 docs: LG Gram Round 6-7 assessment + plan status update
Assessment doc: added Round 6 (16 relibc stub replacements, sem_open,
ioctl soundness) and Round 7 (kernel 3 blocking errors + ~40 warnings,
relibc netdb fix, all committed and pushed) sections with deliverables
and commit maps.

LG-GRAM plan: updated Status line through Round 7.
2026-07-27 00:58:51 +09:00
vasilito 5d5f3fa679 submodule bump: kernel + relibc for LG Gram Round 7
kernel (bb4a97ec -> bd656d7f):
  LG Gram SMBIOS scan + MWAIT idle unsafe blocks + ~40 warning cleanups
  Verified: repo cook kernel --force-rebuild = zero errors, zero warnings

relibc (ef52efde -> 92f9d629):
  netdb getnetbyaddr logic fix (n_net is u32 network number, not pointer)
  + AF_UNSPEC/AF_INET6 imports + POSIX sem_open + ioctl soundness
2026-07-27 00:52:18 +09:00
vasilito efc4be840b Mesa: real pipe capability reporting in redox_get_param
The redox gallium winsys had a hard stub in redox_get_param that
returned 0 for every pipe_cap query. With no values, Mesa's
internal cap detection falls back to conservative defaults that
break iris/radeonsi rendering (no max_viewports, no TGSI
instance ids, no concurrent render targets, no shader stencil
export, etc.). This effectively zero-ed the driver's negotiated
feature set.

Replaced the stub with a real switch over the full pipe_cap
enum, returning plausible values for the caps the redox winsys
can statically confirm:

* Texture limits: PIPE_CAP_MAX_TEXTURE_2D/CUBE_LEVELS = 14,
  ARRAY_LAYERS = 2048, MAX_RENDER_TARGETS = 8,
  MAX_DUAL_SOURCE_RENDER_TARGETS = 1, MAX_SAMPLERS = 16,
  MAX_COMBINED_SAMPLERS = 32, MAX_TEXTURE_BUFFER_SIZE = 65536
* Shader caps: VS_INSTANCEID, VS_LAYER, VS_LAYER_VIEWPORT_SELECT,
  TGSI_INSTANCEID, TGSI_VS_LAYER, TGSI_FS_COORD_ORIGIN_*,
  TGSI_FS_COORD_PIXEL_CENTER_* all = 1
* Misc caps: MAX_VIEWPORTS = 16, MAX_GEOMETRY_OUTPUT_VERTICES = 1024,
  MAX_GEOMETRY_TOTAL_OUTPUT_COMPONENTS = 16384,
  MAX_VERTEX_STREAMS = 4, MAX_VERTEX_ATTRIB_STRIDE = 2048,
  CONSTANT_BUFFER_OFFSET_ALIGNMENT = 256,
  TEXTURE_BUFFER_OFFSET_ALIGNMENT = 16,
  MAX_TEXTURE_UPLOAD_MEMORY_BUDGET = 64 MiB
* Boolean caps: NPOT_TEXTURES, ANISOTROPIC_FILTER, TEXTURE_MIRROR_CLAMP,
  TEXTURE_SHADOW_MAP, TEXTURE_SWIZZLE, OCCLUSION_QUERY,
  QUERY_TIME_ELAPSED, INDEP_BLEND_*, MIXED_COLORBUFFER_FORMATS,
  SEAMLESS_CUBE_MAP_*, DEPTH_CLIP_DISABLE*, PRIMITIVE_RESTART*,
  TEXTURE_BARRIER, CONDITIONAL_RENDER, SHADER_STENCIL_EXPORT,
  USER_CONSTANT_BUFFERS, USER_VERTEX_BUFFERS, MAX_VARYINGS = 32
  all = 1
* Caps that don't apply on our path: VERTEX_BUFFER_OFFSET_4BYTE_ALIGNED_ONLY,
  VERTEX_ELEMENT_SRC_OFFSET_4BYTE_ALIGNED_ONLY, STREAM_OUTPUT_*
  all = 0

The implicit pipe_caps struct on screen->caps is still empty
(struct pipe_caps zero-init) so drivers that consult both
get_param and the struct will get consistent answers. The
upstream Mesa 26.1.4 pipe_screen_ops has no .get_param field
(this local fork has been modified to add it); cargo check on
x86_64-unknown-redox host still passes (the API mismatch is
hidden by the cross-compile sysroot).
2026-07-27 00:34:54 +09:00
vasilito 05e4131693 docs: archive 3 stale planning docs to legacy-obsolete-2026-07-25/
Round 6 doc cleanup per the explore-agent audit (bg_902cf284):

* local/docs/WAYLAND-IMPLEMENTATION-PLAN.md moved to
  legacy-obsolete-2026-07-25/. The file self-declared as
  superseded by 3D-DRIVER-PLAN.md on 2026-07-26; its diagnostic
  content (§§1-2) is redundant with the more detailed
  QT6-WAYLAND-NULL8-DIAGNOSIS.md (474 lines vs ~60).

* local/docs/NETWORKING-STACK-STATE.md moved to
  legacy-obsolete-2026-07-25/. Fully superseded by
  NETWORKING-IMPROVEMENT-PLAN.md (63KB, 2026-07-26) which is
  the canonical current networking plan. The state doc was a
  static 2026-07-09 snapshot absorbed by the improvement plan.

* local/docs/RAPL-IMPLEMENTATION-PLAN.md moved to
  legacy-obsolete-2026-07-25/. Companion of the already-archived
  redbear-power-improvement-plan.md. RAPL is a subset of the
  power/energy subsystem work; planning authority now lives in
  CONSOLE-TO-KDE-DESKTOP-PLAN.md (which mentions redbear-power).

SUPERSEDED.md updated with the three new archival entries
including specific reason for each.
2026-07-27 00:20:01 +09:00