The DRIVER-MANAGER-MIGRATION-PLAN was self-declared complete (the
driver-manager cutover happened 2026-07-23 per local/AGENTS.md). It
is now historical reference material rather than current planning
authority. Move it from local/docs/ into the established
legacy-obsolete-2026-07-25/ archive directory, updating every
inbound reference.
Also includes minor cross-doc alignment for the previous round's
relocations:
- local/AGENTS.md: update DRIVER-MANAGER-MIGRATION-PLAN to point to
the legacy archive
- local/docs/REDBEAR-FULL-SDDM-BRINGUP.md: alignment update
- local/docs/CONSOLE-TO-KDE-DESKTOP-PLAN.md: alignment update
- local/docs/archived/README.md: refresh archive contents note
- local/recipes/system/redbear-driver-policy/source/policy/README.md:
policy doc drift alignment
- local/scripts/guard-recipes.sh: fix symlink target computation
(relative path was being glued onto an absolute path, producing
malformed dangling links like '../..//mnt/.../recipe.toml')
-- this is a real bug fix discovered during this audit round.
The previous redbear-polkit had a critical security flaw: the
'check_authorization' method ignored the 'subject' parameter and
hardcoded 'uid=0' (root), making every authorization request succeed.
Any caller could perform any action as 'root'. This was flagged as
5/5 security fragility in the DBUS assessment.
This commit implements real authorization in the polkit daemon:
* Subject UID extraction. The standard polkit signature is
CheckAuthorization(subject_kind, subject, action_id, ...). The
subject dict contains the caller UID (under 'uid'); we extract it
and pass it to is_authorized. No more hardcoded root.
* Comprehensive policy syntax. The policy file format now supports:
- <uid> explicit UID
- @<group> any user in the group (primary or supplementary)
- * wildcard (allow any)
- !<uid> explicit deny
- !@<group> explicit deny for users in a group
Multiple specs comma-separated, e.g. '@wheel, 1000, !@restricted'.
* Default-deny for unknown actions. Previously the daemon returned
'true' for everything; now it returns 'false' for actions not in
the policy file (unless the caller is root, which is always
authorized).
* match_user_spec returns None for non-match. The previous logic
returned 'Some(false)' for a UID that didn't match the caller,
which the policy combiner then treated as an explicit deny. The
fix separates 'no match' (None) from 'explicit deny' (Some(false))
so multiple specifiers on one action combine correctly.
* Env-var override for tests. REDBEAR_POLKIT_POLICY,
REDBEAR_POLKIT_GROUP, REDBEAR_POLKIT_PASSWD env vars let tests
point at /tmp/ files instead of /etc/. 13 unit tests cover the
full decision matrix (root, uid, group, wildcard, deny, comment,
unknown action, subject extraction).
* Policy file staged in redbear-full.toml and redbear-mini.toml.
The default /etc/polkit-1/policy.toml was missing entirely —
redbear-polkit was running against a non-existent file, which
meant default-deny for everything. The new policy.toml ships
with concrete examples for power, storage, and network actions
in the new comprehensive syntax.
* BackendVersion bumped to 0.2.0 to reflect the contract change.
DBUS-PLAN bumped to v3.2 (2026-07-26). §3.1 status table now lists
redbear-polkit v0.2 as done. §14.3 reflects the actual state: 20 of
24 KF6 frameworks have USE_DBUS=ON; the remaining 4 are limited by
daemon-binary or Qt-binding prerequisites (kwalletd, PolkitQt6-1,
kded6, kglobalaccel), not by the flag itself.
Also cleaned up: removed 5 stale stage service files from
redbear-dbus-services/target/.../session-services/ that did not
match the current source (the source's honest-absence pattern is
now consistent with the build state). The cleanup is a local
filesystem operation; the .gitignore already excludes that path.
Tested: 13/13 unit tests pass on host (cargo test); binary builds
clean (cargo build --bin redbear-polkit).
Executing the greeter-focused path: the SDDM greeter dependency closure needs
only Qt + 9 kf6 core modules + sddm + compositor + graphics. The full Plasma
desktop (kwin, plasma-*, kirigami, konsole, kf6-ksvg/kio/solid/... - 42 packages
outside the greeter closure) is post-login and each has its own Redox porting
gaps (kf6-ksvg needs KirigamiPlatform, kf6-solid QSystemSemaphore, kwin private
Qt APIs, ...). Comment those [packages] entries (# GREETER-DEFER, easily
reverted) and drop kwin from the pre-cook list so the build reaches a bootable
SDDM-greeter image now. Re-enable for the full desktop once its stack is ported.
Assessing/fixing the boot->SDDM chain for the full ISO:
1. VirGL driver table: the INSTALLED /lib/drivers.d/30-graphics.toml is inline
data in config/redbear-full.toml (not local/config/drivers.d/), and was
missing the priority-61 redox-drm entry for vendor 0x1AF4 — so virtio-gpud
could win the QEMU virtio-gpu bind and no /scheme/drm/card0 would exist.
Add the VirGL entry to the inline table (the one actually shipped).
2. Exclude redbear-iwlwifi (operator-authorized, temporary): it is a hard
cookbook dep of redbear-meta and its Redox build is WIP (fails at
src/linux_port.c), which aborts make live before the image assembles. Comment
it out of redbear-meta dependencies; nothing else pulls it. Re-add when green.
3. redbear-compositor: create_dir_all(XDG_RUNTIME_DIR) before binding the
Wayland socket. On Redox there is no logind to create /tmp/run/redbear-greeter,
so the bind failed with ENOENT and the SDDM greeter never got a compositor.
Toward: launch redbear-full ISO in QEMU and reach the SDDM Wayland login.
Operator confirmed "SDDM is the only greeter". Disable the two competing
display entry points that would contend with SDDM for the single-owner
GPU/card0: 20_greeter (redbear-greeterd, an alternative greeter) and 20_display
(redbear-session-launch, a boot-time auto-KDE-session that bypasses the
greeter). Gated reversibly via condition_path_exists on a sentinel
(/etc/redbear/enable-legacy-greeter) the image does not install — definitions
preserved, re-enable with a single touch. 21_sddm remains ungated. Post-login
session launch is SDDMs job via SessionDir=/usr/share/wayland-sessions.
- base-initfs recipe: pcid-spawner removed from initfs BINS and the
lib/pcid.d initfs staging dropped (dead pcid-spawner config).
- acid.toml, redoxer.toml: requires_weak now points at
00_driver-manager.service.
- redbear-mini.toml: dead /etc/pcid.d/* staging removed; driver-manager
service override no longer gated on the retired fallback flag.
- redbear-full.toml: dead legacy-format /etc/pcid.d/ihdgd.toml and
virtio-gpud.toml removed (driver-manager's 30-graphics.toml covers
the same drivers in the current format).
- Comments updated: no fallback exists; driver-manager owns the path
unconditionally. Base submodule bump (0c11c2b5).
Runtime validation of the cutover in QEMU (q35, e1000 + AHCI):
- thread::scope's park/unpark path hangs on Redox (scoped worker
completed all work but the scope join never returned — the boot
stalled inside every concurrent enumeration). The concurrent probe
pool now uses plain thread::spawn + JoinHandle::join (all captures
were already owned/Arc); the counting semaphore is Arc-based so
guards are 'static. bound map is Mutex (RwLock write was unproven
on target).
- initfs driver-manager no longer registers scheme:driver-manager —
the transient initfs manager's registration survived into the
rootfs phase and made the resident manager's registration fail
EEXIST (which then exit(1)'d the rootfs manager).
- config: matchless [[driver]] entries now parse (serde default) —
70-usb-class.toml's USB-class drivers (no [[driver.match]]) broke
config loading entirely on the first gate. Includes a regression
test for load_all with matchless entries.
- graphics: 30-graphics.toml moves from the shared
redbear-device-services.toml to redbear-full.toml (redox-drm is a
full-only driver; mini no longer defers it every hotplug cycle).
vesad removed from drivers.d — it is an init-managed service, not
a spawnable driver.
Gate evidence: initfs 'bound: 0000--00--1f.2 -> ahcid', switchroot,
rootfs 'bound: 0000--00--02.0 -> e1000d' with ZERO deferred,
scheme:driver-manager registered, resident hotplug loop (250ms),
pcid-spawner dormant on both phases.
Operator-ratified cutover (the D5/C-phase gate):
- redbear-device-services.toml: driver-manager added to [packages]
(was 'intentionally not included'); /lib/drivers.d/70-wifi.toml
staged (redbear-iwlwifi --daemon); stale pre-cutover comments
replaced with the single-spawner invariant for driver-manager.
- redbear-mini.toml: /etc/init.d override now stages
00_driver-manager.service (--hotplug, gated !disabled) instead of
00_pcid-spawner.service; all requires_weak references switched to
00_driver-manager.service.
- redbear-full.toml, redbear-greeter-services.toml: same requires_weak
switch for iommu, greeter, SDDM.
- base submodule bump (c72d4247): init.d/init.initfs.d service gates —
pcid-spawner services start only when
/etc/driver-manager.d/disabled exists (operator fallback, never
deleted); driver-manager services run by default.
make lint-config: OK — no init service path violations.
These were set to "ignore" to prevent cascade rebuilds during
development, not because they fail to build. Per project policy,
packages must not be ignored without explicit user request.
The mc recipe exists at local/recipes/tui/mc. It was the last
remaining commented-out package in redbear-full.toml.
All previously commented-out packages are now re-enabled:
- libxkbcommon, xkeyboard-config (keyboard layouts)
- kirigami (KDE QML framework)
- konsole (KDE terminal)
- kf6-pty (PTY support)
- kde-cli-tools (KDE CLI tools)
- mc (midnight commander)
Three fixes from the stub audit:
1. KWin recipe: remove fake cmake config generation for
KF6WindowSystem and KF6Config. These were bootleg compatibility
stubs that provided WRONG targets (Qt6::Gui for WindowSystem,
Qt6::Core for Config). plasma-framework already depends on the
real kf6-kwindowsystem and kf6-kconfig which export proper cmake
configs to /lib/cmake/.
2. KIdleTime recipe: enable WITH_WAYLAND=ON (was OFF). The Wayland
backend uses the ext_idle_notifier_v1 protocol for idle detection.
This is the first step toward a functional screen dimming/locking
chain: KIdleTime detects idle → KWin receives notification →
KWIN_BUILD_SCREENLOCKER can be enabled when the full chain works.
3. Config: re-enable kde-cli-tools. Recipe exists with all
dependencies (kf6-kio, kf6-kwindowsystem, etc.). Previous
'direct repo cook fails' resolved by KF6 stack maturity.
Three packages that were commented out in redbear-full.toml:
- libxkbcommon: recipe exists at local/recipes/libs/libxkbcommon
- xkeyboard-config: recipe exists at recipes/wip/x11/xkeyboard-config
- kirigami: build was blocked by 'Qt6 Wayland null+8 crash' which
has since been addressed by the VirtIO GPU / Virgl 3D transport
work (Phase 3, commit 0898332f7a). Headers and libs exist.
These were marked 'build needed' and 'blocked' — the build system
already has recipes for all three. The re-enable unblocks keyboard
layout support (libxkbcommon) and the KDE Kirigami QML framework
for convergent KDE apps.
Both were set to 'ignore' with comment 'build needed'.
libxkbcommon provides keyboard handling for Wayland compositor.
xkeyboard-config provides keyboard layout definitions.
Without these, Wayland clients (KWin, Qt6 apps) cannot
process keyboard input.
Changed from 'ignore' to '{}' to enable building. This is
required for keyboard input in the graphical desktop.
- config/redbear-full.toml: 9 package groups defined (graphics-core,
input-stack, dbus-services, firmware-stack, qt6-core, qt6-extras,
kf6-frameworks, desktop-session, kde-desktop)
- Cargo.toml: switch redox_installer from upstream git to local fork
(path = "local/sources/installer") to use package group support
- Cargo.lock: remove installer git source entry
- local/sources/installer: bump to package groups commit
Groups are resolved transparently by Config::from_file() — the cookbook
repo binary sees expanded packages automatically.
Add explicit #include <stdlib.h> after #include_next <stdlib.h> in
GCC 13 cstdlib. This ensures ::strtold is declared before the
using-directives execute. Previously relibc's declaration was
not visible to the C++ wrapper.
Reverted unjustified ignores: qt6-sensors, kf6-ki18n, kf6-kidletime,
kf6-kwayland, redbear-greeter — per project policy: fix, don't ignore.
Also reverted kf6-ki18n to full build (stub removed).
strtold include chain fix applied but C++ <cstdlib> still fails.
KI18n is i18n — non-critical for bootable desktop. Re-enable when
strtold root cause is resolved in relibc or GCC <cstdlib>.
The local init fork's Service struct does not have a 'before' field
(it supports cmd, args, envs, inherit_envs, type only), and the
deny_unknown_fields attribute makes init panic at boot when it parses
'before':
init: /etc/init.d/12_dbus.service: unknown field 'before', expected
one of 'cmd', 'args', 'envs', 'inherit_envs', 'type' in 'service'
The 'before = [13_redbear-sessiond.service]' line was redundant
anyway: 13_redbear-sessiond.service already declares
requires_weak = ['12_dbus.service'], which orders it after dbus.
Fix both redbear-mini.toml and redbear-full.toml.
- Add --address=unix:path=/run/dbus/system_bus_socket to dbus-daemon args
- Add before = ["13_redbear-sessiond.service"] for strict ordering
- Fixes redbear-sessiond "failed to read from socket" errors
- Add x11proto to redbear-full.toml package list
- libxau recipe updated with x11proto dependency and custom build script
- Fixes libxau build failure: 'Package xproto was not found'
- Split filemanager/mod.rs into dispatch.rs, render.rs, dialog_ops.rs,
format_utils.rs (3567→~1200 lines in mod.rs)
- Comment out mc in redbear-mini.toml and redbear-full.toml per user request
- Enable tlc in redbear-full.toml (was temporarily disabled)
- 1022 tests pass, zero behavior changes
TLC (Twilight Commander) was missing from both ISO configs. Added
tlc = {} to [packages] in redbear-mini.toml and redbear-full.toml.
Created missing symlink: recipes/tui/tlc -> ../../local/recipes/tui/tlc.
The Wayland compositor was commented out, causing the greeter to fail
when trying to launch the UI. With the compositor enabled, the full
greeter flow now works: compositor starts, creates Wayland socket,
greeter UI launches on VT 3, and Qt6 client connects successfully.
Bootloader hardcoded RedoxFS partition offset at 2 MiB, which fails when
efi_partition_size > 1 (redbear-full, redbear-grub use 16 MiB, placing
RedoxFS at LBA 34816 = 17 MiB). Added GPT partition table parser that
scans for Linux filesystem GUID (0FC63DAF) to find the actual offset.
Also removed invalid 'respawn = true' from 31_debug_console.service in
redbear-full.toml — init's service format does not support this field.
Verified: all three ISOs boot in QEMU UEFI and reach login prompt.
5-phase hardening to prevent silent file-layer collisions (the D-Bus
regression class):
Phase 1: lint-config-paths.sh + make lint-config in depends.mk
Phase 2: CollisionTracker in installer (content-hash comparison)
Phase 3: installs manifests in recipe.toml + validate-file-ownership.sh
Phase 4: validate-init-services.sh + make validate in disk.mk
Phase 5: documentation (AGENTS.md, BUILD-SYSTEM-HARDENING-PLAN.md)
Both redbear-mini and redbear-full build and validate clean.
66 declared install paths in base, zero conflicts.
The [users.root] override in redbear-full.toml only set shell, which
replaced (not merged) the base.toml entry that had uid=0 gid=0
password="password". Without explicit uid/gid, the installer assigned
root UID 1000, causing D-Bus to fail looking up user "root" and
"messagebus" — all D-Bus clients (sessiond, polkit, udisks, upower)
timed out and exited.
Verified: D-Bus daemon starts, polkit registers PolicyKit1, sessiond
registers login1, zero timeouts or retries in QEMU boot.
Shell: Changed default shell from ion to zsh for all user accounts
in base.toml, redbear-mini.toml, redbear-full.toml, and greeter config.
zsh 5.9 is already ported and builds (ZSH-PORTING-PLAN — fully implemented).
ion is kept as fallback/alternative.
Cookbook: pkgar staging fallback — when a dependency's target pkgar
doesn't exist, fall back to repo/<target>/<pkg>.pkgar. This fixes the
kf6-kitemviews build failure where libwayland's pkgar was missing from
the target directory.