Skip to content
Open
Show file tree
Hide file tree
Changes from 63 commits
Commits
Show all changes
1004 commits
Select commit Hold shift + click to select a range
d1b6f39
feat(kobject-handle-v2-callers): complete subsystem [session Nathan-266]
Krilliac Aug 2, 2026
ffc8283
chore: claim subsystem 'service-endpoint-handle-rights-20260802' [ses…
Krilliac Aug 2, 2026
7a301e9
feat(net-stack-boot-order-20260802): complete subsystem [session Nath…
Krilliac Aug 2, 2026
dfadb63
chore: claim subsystem 'net-protocol-state-smp-p0-20260802' [session …
Krilliac Aug 2, 2026
89dd956
chore: claim subsystem 'net-protocol-state-smp-fixtures-20260802' [se…
Krilliac Aug 2, 2026
e8b65bd
chore: claim subsystem 'service-process-endpoint-teardown-20260802' […
Krilliac Aug 2, 2026
36c5a4e
feat(service-endpoint-handle-rights-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
5d67e02
feat(net-protocol-state-smp-p0-20260802): complete subsystem [session…
Krilliac Aug 2, 2026
9578beb
feat(net-protocol-state-smp-fixtures-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
1990991
feat(address-space-write-lease-20260802): complete subsystem [session…
Krilliac Aug 2, 2026
828147b
feat(channel-core-deferred-drain-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
08e4701
feat(service-endpoint-drain-handoff-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
404e767
feat(service-endpoint-drain-handoff-header-20260802): complete subsys…
Krilliac Aug 2, 2026
754ac4e
feat(service-endpoint-ingress-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
dbb6560
feat(net-protocol-state-smp-20260802): complete subsystem [session Na…
Krilliac Aug 2, 2026
b83a299
chore: claim subsystem 'root-service-endpoint-contract-drift-20260802…
Krilliac Aug 2, 2026
dfb3dcb
chore: claim subsystem 'service-stage-restage-20260802' [session Nath…
Krilliac Aug 2, 2026
c8812ea
feat(root-service-endpoint-contract-drift-20260802): complete subsyst…
Krilliac Aug 2, 2026
0d4bbfb
chore: claim subsystem 'service-deferred-endpoint-reaper-20260802' [s…
Krilliac Aug 2, 2026
30a9705
chore: claim subsystem 'service-endpoint-route-authority-20260802' [s…
Krilliac Aug 2, 2026
6ff1c8a
chore: claim subsystem 'service-endpoint-connect-send-ingress-2026080…
Krilliac Aug 2, 2026
47711ef
chore: claim subsystem 'service-stage-load-image-reset-20260802' [ses…
Krilliac Aug 2, 2026
40e978f
feat(exec-admission): complete subsystem [session Codex-Root-StaleCla…
Krilliac Aug 2, 2026
34daa07
chore: claim subsystem 'service-stage-exec-admission-reset-20260802' …
Krilliac Aug 2, 2026
7791232
chore: claim subsystem 'service-protocol-policy-20260802' [session Co…
Krilliac Aug 2, 2026
b8abfd0
chore: claim subsystem 'service-endpoint-connect-send-ingress-state-2…
Krilliac Aug 2, 2026
5c06028
feat(service-process-endpoint-teardown-20260802): complete subsystem …
Krilliac Aug 2, 2026
1d0e450
feat(service-deferred-endpoint-reaper-20260802): complete subsystem […
Krilliac Aug 2, 2026
253b1dc
feat(service-publication-directory-join-20260802): complete subsystem…
Krilliac Aug 2, 2026
93caa57
chore: claim subsystem 'service-joint-readiness-20260802' [session Na…
Krilliac Aug 2, 2026
ba6efc0
feat(host-sanitizer-ci-20260802): complete subsystem [session Codex-H…
Krilliac Aug 2, 2026
d74d1fd
chore: claim subsystem 'host-sanitizer-ci-finish-20260802' [session C…
Krilliac Aug 2, 2026
454a45f
test(host): expose hosted spinlock synchronization to TSan
Krilliac Aug 2, 2026
d3fdb58
feat(host-sanitizer-ci-finish-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
7288807
chore: claim subsystem 'service-exit-reap-ledger-20260802' [session F…
Krilliac Aug 2, 2026
c9d4bc1
chore: claim subsystem 'displayd-dormant-contract-drift-20260802' [se…
Krilliac Aug 2, 2026
ba198cf
test(displayd): track the authenticated ingress boundary
Krilliac Aug 2, 2026
b0997ad
feat(displayd-dormant-contract-drift-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
6b089dd
chore: claim subsystem 'service-object-package-lifecycle-link-2026080…
Krilliac Aug 2, 2026
f2a00e3
test(service): isolate package lifecycle directory leaves
Krilliac Aug 2, 2026
ed57cc1
feat(service-object-package-lifecycle-link-20260802): complete subsys…
Krilliac Aug 2, 2026
3c96d80
chore: claim subsystem 'service-object-package-joint-ready-stub-20260…
Krilliac Aug 2, 2026
24d65fd
test(service): follow joint readiness commit leaf
Krilliac Aug 2, 2026
98697d0
feat(service-object-package-joint-ready-stub-20260802): complete subs…
Krilliac Aug 2, 2026
1a5bdb4
chore: claim subsystem 'service-process-teardown-readiness-drift-2026…
Krilliac Aug 2, 2026
d3861d6
feat(service-endpoint): bind trusted live dataplane routes
Krilliac Aug 2, 2026
7446627
test(service): mark teardown fixture jointly ready
Krilliac Aug 2, 2026
a3ac647
feat(service-process-teardown-readiness-drift-20260802): complete sub…
Krilliac Aug 2, 2026
00438f5
feat(service-endpoint-ingress-names-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
754df70
service: add atomic joint readiness admission
Krilliac Aug 2, 2026
158cd85
chore: claim subsystem 'service-bootstrap-live-ready-oracle-20260802'…
Krilliac Aug 2, 2026
034429d
feat(service-endpoint-route-authority-20260802): complete subsystem […
Krilliac Aug 2, 2026
0e507fe
feat(service-joint-readiness-20260802): complete subsystem [session N…
Krilliac Aug 2, 2026
b7989ec
feat(service-endpoint-connect-send-ingress-20260802): complete subsys…
Krilliac Aug 2, 2026
a9ab7a8
test(service): freeze dormant joint readiness calls
Krilliac Aug 2, 2026
bf7e1f6
feat(service-bootstrap-live-ready-oracle-20260802): complete subsyste…
Krilliac Aug 2, 2026
d6391a0
feat(service-protocol-policy-20260802): complete subsystem [session C…
Krilliac Aug 2, 2026
ef602ed
feat(service-endpoint-connect-send-ingress-state-20260802): complete …
Krilliac Aug 2, 2026
46d4c09
chore: claim subsystem 'service-live-restage-banks-20260802' [session…
Krilliac Aug 2, 2026
58aacb9
ci: register integrated host and structural gates
Krilliac Aug 2, 2026
e4ab820
feat(fable-targeted-contract-ci-20260801): complete subsystem [sessio…
Krilliac Aug 2, 2026
98b441a
feat(service-driver-test-build-integration-20260801): complete subsys…
Krilliac Aug 2, 2026
af7b4b2
chore: claim subsystem 'service-control-syscall-20260802' [session Co…
Krilliac Aug 2, 2026
cef5ffa
chore: claim subsystem 'service-control-cap-name-20260802' [session C…
Krilliac Aug 2, 2026
2778626
chore: claim subsystem 'fuzz-pe-vm-reservation-shim-20260802' [sessio…
Krilliac Aug 2, 2026
733b15e
test(fuzz): mirror loader reservation sinks
Krilliac Aug 2, 2026
4269a69
feat(fuzz-pe-vm-reservation-shim-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
16cbfdf
chore: claim subsystem 'service-manifest-format-integration-20260802'…
Krilliac Aug 2, 2026
d27aee6
feat(service): enforce unique executable transfers
Krilliac Aug 2, 2026
58320ea
feat(service-manifest-format-integration-20260802): complete subsyste…
Krilliac Aug 2, 2026
79647f9
feat(service-stage-restage-20260802): complete subsystem [session Nat…
Krilliac Aug 2, 2026
caea539
feat(service-stage-load-image-reset-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
3d478ad
feat(service-stage-exec-admission-reset-20260802): complete subsystem…
Krilliac Aug 2, 2026
a79c9c8
feat(ipc-object-transfer): complete subsystem [session Nathan-1481]
Krilliac Aug 2, 2026
ad576cc
feat(ipc-object-transfer-source): complete subsystem [session Nathan-…
Krilliac Aug 2, 2026
ce3ec1a
feat(ipc-object-transfer-test): complete subsystem [session Nathan-1467]
Krilliac Aug 2, 2026
8c2aada
fix(parallel): normalize historical claim records
Krilliac Aug 2, 2026
83217af
chore: claim subsystem 'ipc-object-transfer-integration-20260802' [se…
Krilliac Aug 2, 2026
a0657f0
chore: claim subsystem 'registryd-store-integration-20260802' [sessio…
Krilliac Aug 2, 2026
174f8a8
chore: claim subsystem 'service-control-idl-counts-20260802' [session…
Krilliac Aug 2, 2026
6df0f3a
feat(service): provision live restage banks
Krilliac Aug 2, 2026
94b8ed0
feat(service-live-restage-banks-20260802): complete subsystem [sessio…
Krilliac Aug 2, 2026
703d15c
chore: claim subsystem 'service-control-manifest-policy-20260802' [se…
Krilliac Aug 2, 2026
6f5da9e
chore: claim subsystem 'resource-domain-integration-20260802' [sessio…
Krilliac Aug 2, 2026
4489e22
feat(ipc): reserve object transfer imports
Krilliac Aug 2, 2026
da792dd
feat(ipc-object-transfer-integration-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
fc0fde0
proc: add generation-safe resource domains
Krilliac Aug 2, 2026
ad0397a
fix(registryd-store): harden WAL torn-tail detection and commit fail-…
Krilliac Aug 2, 2026
b962ccf
feat(resource-domain-integration-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
eb944f1
feat(service): add native service control ingress
Krilliac Aug 2, 2026
f9f9204
feat(service-control-syscall-20260802): complete subsystem [session C…
Krilliac Aug 2, 2026
3e8540f
feat(service-control-cap-name-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
a25a329
feat(service-control-idl-counts-20260802): complete subsystem [sessio…
Krilliac Aug 2, 2026
5750013
feat(service-control-manifest-policy-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
8308cac
chore: claim subsystem 'service-foundation-dependency-integration-202…
Krilliac Aug 2, 2026
e89268f
feat(registryd-store-integration-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
7d835c7
feat(proc-credentials-api): complete subsystem [session Nathan-1200]
Krilliac Aug 2, 2026
e5da704
feat(proc-credentials-core): complete subsystem [session Nathan-418]
Krilliac Aug 2, 2026
87281a3
feat(proc-credentials-host): complete subsystem [session Nathan-383]
Krilliac Aug 2, 2026
d260b34
chore: claim subsystem 'process-authority-foundation-integration-2026…
Krilliac Aug 2, 2026
10c0e4d
core: add exact service exit observation
Krilliac Aug 2, 2026
1175515
core: bind immutable service object packages
Krilliac Aug 2, 2026
8f0fa58
core: own the service runtime statically
Krilliac Aug 2, 2026
6544762
feat(service-foundation-dependency-integration-20260802): complete su…
Krilliac Aug 2, 2026
8688c5d
feat(service-exit-reap-ledger-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
4670bd4
chore: claim subsystem 'service-exit-reap-ledger-fix-20260802' [sessi…
Krilliac Aug 2, 2026
8390c6c
feat(process-authority-foundation-integration-20260802): complete sub…
Krilliac Aug 2, 2026
336d745
chore: claim subsystem 'ipc-foundation-publish-20260802' [session Cod…
Krilliac Aug 2, 2026
a4d0af5
chore: claim subsystem 'process-authority-foundation-publish-20260802…
Krilliac Aug 2, 2026
2b7172f
chore: claim subsystem 'daemon-source-publish-20260802' [session Code…
Krilliac Aug 2, 2026
eb4c787
feat(process): add generation-safe authority foundations
Krilliac Aug 2, 2026
b78fa51
feat(process-authority-foundation-publish-20260802): complete subsyst…
Krilliac Aug 2, 2026
2813e23
feat(ipc): publish bounded channel foundation
Krilliac Aug 2, 2026
be926be
feat(ipc-foundation-publish-20260802): complete subsystem [session Co…
Krilliac Aug 2, 2026
dc85540
feat(serviced): add fixed-capacity supervisor core
Krilliac Aug 2, 2026
64cdf52
feat(execd): add authenticated worker policy core
Krilliac Aug 2, 2026
ed20240
chore: claim subsystem 'service-control-platform-adapter-20260802' [s…
Krilliac Aug 2, 2026
55be0d4
feat(displayd): add fixed-capacity display engine
Krilliac Aug 2, 2026
be4749c
feat(registryd): complete store recovery source closure
Krilliac Aug 2, 2026
15fa7d0
chore: claim subsystem 'elf-load-image-publish-20260802' [session Cod…
Krilliac Aug 2, 2026
abcb2eb
feat(daemon-source-publish-20260802): complete subsystem [session Cod…
Krilliac Aug 2, 2026
1ed6730
feat(loader): stage authenticated ELF load images
Krilliac Aug 2, 2026
e07e819
feat(elf-load-image-publish-20260802): complete subsystem [session Co…
Krilliac Aug 2, 2026
4790ceb
chore: claim subsystem 'service-control-event-sequence-abi-20260802' …
Krilliac Aug 2, 2026
4d0fa6c
fix(service-control): separate event and acknowledgement identity
Krilliac Aug 2, 2026
5d13ec7
feat(service-control): install typed kernel platform adapter
Krilliac Aug 2, 2026
2b07bc6
feat(service-control-event-sequence-abi-20260802): complete subsystem…
Krilliac Aug 2, 2026
5194fc6
feat(service-control-platform-adapter-20260802): complete subsystem […
Krilliac Aug 2, 2026
1209822
feat(immutable-load-plan): complete subsystem [session Codex-kobject-…
Krilliac Aug 2, 2026
8cdc0ad
chore: claim subsystem 'immutable-load-plan-recovery-20260802' [sessi…
Krilliac Aug 2, 2026
82d8111
feat(immutable-load-plan-recovery-20260802): complete subsystem [sess…
Krilliac Aug 2, 2026
46745ed
chore: claim subsystem 'immutable-load-plan-recovery-20260802b' [sess…
Krilliac Aug 2, 2026
62a97c9
feat(proc-thread-group-api): complete subsystem [session Codex-Thread…
Krilliac Aug 2, 2026
740e814
feat(proc-thread-group-core): complete subsystem [session Codex-Threa…
Krilliac Aug 2, 2026
80ea060
feat(proc-thread-group-host): complete subsystem [session Codex-Threa…
Krilliac Aug 2, 2026
be72da7
chore: claim subsystem 'proc-thread-group-closure-20260802' [session …
Krilliac Aug 2, 2026
f0ebd7e
feat(loader): publish immutable load plan validator
Krilliac Aug 2, 2026
c287f84
feat(service): add durable exit reap ledger
Krilliac Aug 2, 2026
d1676fd
feat(immutable-load-plan-recovery-20260802b): complete subsystem [ses…
Krilliac Aug 2, 2026
5ccee62
feat(service-exit-reap-ledger-fix-20260802): complete subsystem [sess…
Krilliac Aug 2, 2026
ae06526
feat(execd-protocol): complete subsystem [session Nathan-1607]
Krilliac Aug 2, 2026
c55e688
feat(execd-protocol-source): complete subsystem [session Nathan-922]
Krilliac Aug 2, 2026
7b847c9
feat(execd-protocol-test): complete subsystem [session Nathan-945]
Krilliac Aug 2, 2026
ab9e1a4
chore: claim subsystem 'execd-protocol-recovery-20260802' [session Co…
Krilliac Aug 2, 2026
25271e8
kernel/proc: add generation-safe thread groups
Krilliac Aug 2, 2026
2ac87b9
feat(proc-thread-group-closure-20260802): complete subsystem [session…
Krilliac Aug 2, 2026
25f4779
chore: claim subsystem 'service-live-control-integration-20260802' [s…
Krilliac Aug 2, 2026
62f47e5
chore: claim subsystem 'ipc-kmessage-port-recovery-20260802' [session…
Krilliac Aug 2, 2026
a0e450f
feat(loader): publish execd transport protocol
Krilliac Aug 2, 2026
946731e
feat(execd-protocol-recovery-20260802): complete subsystem [session C…
Krilliac Aug 2, 2026
8e4b358
chore: claim subsystem 'service-live-control-host-build-20260802' [se…
Krilliac Aug 2, 2026
9969233
feat(gui-broker-protocol): complete subsystem [session Nathan-1592]
Krilliac Aug 2, 2026
20808e9
kernel/ipc: add generation-safe message ports
Krilliac Aug 2, 2026
8635693
feat(ipc-kmessage-port-recovery-20260802): complete subsystem [sessio…
Krilliac Aug 2, 2026
368c950
chore: claim subsystem 'gui-broker-protocol-recovery-20260802' [sessi…
Krilliac Aug 2, 2026
06865d1
chore: claim subsystem 'service-runtime-reap-host-proof-20260802' [se…
Krilliac Aug 2, 2026
2c91240
feat(service): bind live control to runtime reap authority
Krilliac Aug 2, 2026
2eec683
feat(service-live-control-integration-20260802): complete subsystem […
Krilliac Aug 2, 2026
8cca40f
feat(service-live-control-host-build-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
0493dd3
feat(service-runtime-reap-host-proof-20260802): complete subsystem [s…
Krilliac Aug 2, 2026
ffbc506
chore: claim subsystem 'service-exit-directory-binding-20260802' [ses…
Krilliac Aug 2, 2026
c81545e
feat(video): publish GUI broker wire protocol
Krilliac Aug 2, 2026
46ef3fa
feat(gui-broker-protocol-recovery-20260802): complete subsystem [sess…
Krilliac Aug 2, 2026
9842715
chore: claim subsystem 'service-exit-binding-runtime-pristine-2026080…
Krilliac Aug 2, 2026
d83dae6
feat(gui-message-policy): complete subsystem [session Nathan-1665]
Krilliac Aug 2, 2026
9c89cb1
chore: claim subsystem 'gui-message-policy-recovery-20260802' [sessio…
Krilliac Aug 2, 2026
7fa34a8
feat(video): publish GUI message authorization policy
Krilliac Aug 2, 2026
6c02ec4
feat(gui-message-policy-recovery-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
c2c826e
chore: claim subsystem 'service-exit-binding-host-target-20260802' [s…
Krilliac Aug 2, 2026
58c1540
feat(gui-send-transaction): complete subsystem [session Nathan-960]
Krilliac Aug 2, 2026
6ab7349
chore: claim subsystem 'gui-send-transaction-recovery-20260802' [sess…
Krilliac Aug 2, 2026
bb78958
chore: claim subsystem 'mt7921-contract-recovery-20260802' [session N…
Krilliac Aug 2, 2026
9a16ba5
feat(service): carry exact directory identity through exit reap
Krilliac Aug 2, 2026
b0e796d
feat(service-exit-directory-binding-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
6c2cce9
feat(service-exit-binding-runtime-pristine-20260802): complete subsys…
Krilliac Aug 2, 2026
d0a319a
feat(service-exit-binding-host-target-20260802): complete subsystem […
Krilliac Aug 2, 2026
352cac7
chore: claim subsystem 'host-build-graph-closure-20260802' [session C…
Krilliac Aug 2, 2026
a7e70c4
feat(video): publish synchronous GUI send transactions
Krilliac Aug 2, 2026
d933eea
feat(gui-send-transaction-recovery-20260802): complete subsystem [ses…
Krilliac Aug 2, 2026
12a034a
test(host): close service and thread build graph
Krilliac Aug 2, 2026
8894465
feat(host-build-graph-closure-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
a4b71bd
feat(netd-socket-engine-split-20260801): complete subsystem [session …
Krilliac Aug 2, 2026
8f8852b
feat(netd-socket-engine-20260801): complete subsystem [session Codex-…
Krilliac Aug 2, 2026
1fcde0d
chore: claim subsystem 'netd-socket-engine-recovery-20260802' [sessio…
Krilliac Aug 2, 2026
ab40c21
feat(net): publish MT7921 preflight contract
Krilliac Aug 2, 2026
70ca0ba
feat(mt7921-contract-recovery-20260802): complete subsystem [session …
Krilliac Aug 2, 2026
8490d08
chore: claim subsystem 'resource-domain-channel-host-proof-20260802' …
Krilliac Aug 2, 2026
15dc8a6
chore: claim subsystem 'service-runtime-maintenance-bridge-20260802' …
Krilliac Aug 2, 2026
40c2bb2
test(proc): publish resource-domain channel proof
Krilliac Aug 2, 2026
62981d4
feat(resource-domain-channel-host-proof-20260802): complete subsystem…
Krilliac Aug 2, 2026
e816e01
feat(gui-message-queue-host-properties): complete subsystem [session …
Krilliac Aug 2, 2026
22f7fbf
chore: claim subsystem 'gui-message-queue-recovery-20260802' [session…
Krilliac Aug 2, 2026
2bf43f5
feat(service): drive bounded exit reap maintenance
Krilliac Aug 2, 2026
8a497f6
feat(service-runtime-maintenance-bridge-20260802): complete subsystem…
Krilliac Aug 2, 2026
70c9c0d
chore: claim subsystem 'service-runtime-reaper-bridge-20260802' [sess…
Krilliac Aug 2, 2026
fba6693
feat(gui): add transactional task message queues
Krilliac Aug 2, 2026
420a27f
feat(gui-message-queue-recovery-20260802): complete subsystem [sessio…
Krilliac Aug 2, 2026
2ca7028
feat(netd): add generation-safe socket engine
Krilliac Aug 2, 2026
27387d0
feat(netd-socket-engine-recovery-20260802): complete subsystem [sessi…
Krilliac Aug 2, 2026
7c41460
chore: claim subsystem 'pci-bar-endpoint-recovery-20260802' [session …
Krilliac Aug 2, 2026
54c4e73
feat(kobject-handle-v2): complete subsystem [session Codex-kobject-ha…
Krilliac Aug 2, 2026
5358223
chore: claim subsystem 'handle-table-extraction-recovery-20260802' [s…
Krilliac Aug 2, 2026
070f4b4
chore: claim subsystem 'process-key-foundation-20260802' [session Nat…
Krilliac Aug 2, 2026
980361c
feat(pci): harden BAR sizing and endpoint identity
Krilliac Aug 2, 2026
e2880de
feat(pci-bar-endpoint-recovery-20260802): complete subsystem [session…
Krilliac Aug 2, 2026
5f30952
feat(driver-id-watch-hardening-20260801): complete subsystem [session…
Krilliac Aug 2, 2026
e7bfbb7
feat(net-registry-snapshot-20260801): complete subsystem [session Cod…
Krilliac Aug 2, 2026
ddc4d48
chore: claim subsystem 'driver-network-registry-recovery-20260802' [s…
Krilliac Aug 2, 2026
e496eee
feat(net): add restart-safe driver worker leases
Krilliac Aug 2, 2026
824ecef
feat(proc): publish non-recycled process keys
Krilliac Aug 2, 2026
4bce07a
feat(net): classify NIC identities without probe authority
Krilliac Aug 2, 2026
9885fcb
feat(process-key-foundation-20260802): complete subsystem [session Na…
Krilliac Aug 2, 2026
bf51961
chore: claim subsystem 'net-stack-restart-recovery-20260802' [session…
Krilliac Aug 2, 2026
9e61c5c
feat(sched): drive service reap maintenance
Krilliac Aug 2, 2026
07aecf7
feat(service-runtime-reaper-bridge-20260802): complete subsystem [ses…
Krilliac Aug 2, 2026
800396c
chore: claim subsystem 'endpoint-ledger-identity-recovery-20260802' […
Krilliac Aug 2, 2026
4d2e3ef
ipc: close generation-safe HandleTable extraction
Krilliac Aug 2, 2026
f851725
feat(handle-table-extraction-recovery-20260802): complete subsystem […
Krilliac Aug 2, 2026
df97530
feat(ipc): bind request ledgers to directional identities
Krilliac Aug 2, 2026
3f597d0
feat(endpoint-ledger-identity-recovery-20260802): complete subsystem …
Krilliac Aug 2, 2026
63e22cf
chore: claim subsystem 'pcnet-virtio-restart-recovery-20260802' [sess…
Krilliac Aug 2, 2026
44c25d4
feat(net): make interface restart generation-safe
Krilliac Aug 2, 2026
8293f61
chore: claim subsystem 'net-protocol-state-p0-recovery-20260802' [ses…
Krilliac Aug 2, 2026
31b5601
chore: claim subsystem 'service-teardown-reaper-contract-recovery-202…
Krilliac Aug 2, 2026
f9d00c5
test(service): align teardown reaper contract
Krilliac Aug 2, 2026
767b996
feat(service-teardown-reaper-contract-recovery-20260802): complete su…
Krilliac Aug 2, 2026
c551a19
chore: claim subsystem 'net-stack-boot-order-recovery-20260802' [sess…
Krilliac Aug 2, 2026
5d72ec5
chore: claim subsystem 'process-lifecycle-integration-recovery-202608…
Krilliac Aug 2, 2026
0496d67
chore: claim subsystem 'process-lifecycle-callsite-recovery-20260802'…
Krilliac Aug 2, 2026
8fd0b87
fix(net): synchronize protocol state across SMP
Krilliac Aug 2, 2026
81accae
feat(net-protocol-state-p0-recovery-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
9257899
chore: claim subsystem 'process-authority-callsite-recovery-20260802'…
Krilliac Aug 2, 2026
3ec017a
chore: claim subsystem 'process-gdb-stop-support-recovery-20260802' […
Krilliac Aug 2, 2026
8fdc7e8
chore: claim subsystem 'task-create-result-callsite-recovery-20260802…
Krilliac Aug 2, 2026
5623a99
chore: claim subsystem 'kernel-service-package-build-graph-recovery-2…
Krilliac Aug 2, 2026
ac88a96
chore: claim subsystem 'service-endpoint-kobject-tag-recovery-2026080…
Krilliac Aug 2, 2026
0d451e6
fix(net): make pcnet and virtio restart-safe
Krilliac Aug 2, 2026
acfc23f
feat(pcnet-virtio-restart-recovery-20260802): complete subsystem [ses…
Krilliac Aug 2, 2026
f2e5e95
fix(net): harden registry driver admission
Krilliac Aug 2, 2026
e909ca6
fix(net): use registry snapshots during stack init
Krilliac Aug 2, 2026
590be6f
fix(boot): initialize stack before NIC activation
Krilliac Aug 2, 2026
f9517cd
docs(net): record restart and SMP contracts
Krilliac Aug 2, 2026
9963900
fix(net): migrate registry snapshot consumers
Krilliac Aug 2, 2026
9af8084
style(net): format wireless inventory migration
Krilliac Aug 2, 2026
7ea8bec
feat(net-stack-boot-order-recovery-20260802): complete subsystem [ses…
Krilliac Aug 2, 2026
7df2af3
feat(net-stack-restart-recovery-20260802): complete subsystem [sessio…
Krilliac Aug 2, 2026
4e72d32
feat(driver-network-registry-recovery-20260802): complete subsystem […
Krilliac Aug 2, 2026
658f50c
chore: claim subsystem 'arp-copyout-consumers-recovery-20260802' [ses…
Krilliac Aug 2, 2026
61b04ff
fix(net): copy ARP entries into concurrent consumers
Krilliac Aug 2, 2026
ac2de19
feat(arp-copyout-consumers-recovery-20260802): complete subsystem [se…
Krilliac Aug 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions docs/stability-audit-2026-07-31.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# DuetOS Stability Audit Ledger

Status: active; static and host-side partial verification complete. Full kernel/runtime verification is pending.

## Coverage

- 1,777 tracked kernel/tools sources checked by the include-tracking audit.
- Kernel passes covered architecture/core/CPU, scheduler/synchronization, memory, filesystems, networking, IPC, Linux and Win32 subsystems, drivers, loader, security, diagnostics, applications, shell, web, crypto, time, and utilities.
- Userland passes covered native apps, libc/CRT, Win32 DLL layers, graphics DLLs, networking DLLs, smoke tests, and PE/SEH/TLS fixtures.
- Boot coverage included UEFI source and boot metadata.
- Rust coverage included the 27 workspace crates and their FFI boundaries; hosted `unwrap` uses found were confined to test fixtures.
- Test assets inventoried: host tests and 35 fuzz targets/shims.

## Evidence

- `alloc-null-check-audit.py`: PASS.
- `include-tracked-audit.py`: PASS for 1,777 sources.
- `check-syscall-numbers.py`: 223 enum entries, 112 annotated sites, 274 assertions, 0 errors.
- `invariant-check.sh`: all gating invariants pass.
- `waitqueue-block-lock-audit.py`: 0 unguarded sites; 19 explicitly CLI-only sites; 2 spinlock untimed sites.
- Focused syntax-only compilation and cppcheck passes cover every modified translation unit.
- The address-space map-failure slice covered the production PE/ELF/DLL loaders, Linux `brk`/`mmap`/`mremap`/`munmap`/`mincore`, vDSO and stack growth, Win32 heap/vmap/fiber/thread allocation, and the shared page-table walker. The follow-on `mincore` validation also passed g++ C++23 syntax-only and focused cppcheck checks; the focused runs had no new correctness findings.
- The Linux socket/I/O boundary slice covered `recvmsg`/`accept4` output ownership, socket KFile-attachment failure cleanup, `recvmmsg`/`sendmmsg` address spans, and `readv`/`writev`/`preadv`/`pwritev` iovec arithmetic. The three changed translation units passed g++ C++23 syntax-only and focused cppcheck checks.
- The Linux timer/async timeout slice covered saturating alarm, interval-timer, and POSIX-timer nanosecond conversions/deadline rearming, timespec validation, timer output narrowing, overrun saturation, and `epoll_pwait2` negative/invalid/overflowing timeout handling. Both changed translation units passed g++ C++23 syntax-only and focused cppcheck checks; remaining cppcheck output was pre-existing style/flow guidance in surrounding code.
- A follow-up fd-lifetime review covered `pidfd_getfd`, cross-process Linux fd copying, shared OFD close/dup paths, and Win32 IOCP close/lookup behavior. `pidfd_splice.cpp` and `iocp_syscall.cpp` passed g++ C++23 syntax-only; the known target-fd concurrent-close race and first-duplicate-IOCP-close semantics remain explicitly isolated design gaps pending their owning lifetime contracts.
- Existing host CTest tree: 68 registered tests; 34 passed, 34 were not run because their prebuilt executables are absent. This tree was not rebuilt against the audit commits.

## Implemented hardening

Recent audit commits include teardown pinning for socket/IPC/async pools, timeout and overflow saturation, address-space map refusal/partial-table rollback, Linux mapping-span and `mincore` validation, socket boundary failure cleanup, PE-loader map refusal checks, driver/loader range arithmetic, diagnostic formatting safety, filesystem label walks, Linux directory-prefix copying, and explicit userland ABI/CRT contracts. The latest timer/async hardening code commit is `4d921155`; the branch is clean after the accompanying ledger update.

## Remaining verification

- Full MSVC build and link.
- Rebuilt host test suite for all 68 registered tests.
- QEMU boot, syscall/fuzz/stress campaigns, SMP/S3 paths, and graphical/runtime smoke tests.
- Hardware-dependent storage, networking, GPU, ACPI, and USB paths.
- Static analyzer residuals classified as intentional canary/SEH fixtures, linker/PE image-base contracts, inline-assembly parser limitations, or bounded NUL-terminated pointer contracts; they should be revisited after a target-aware compiler/analyzer run.
- Active-path design risks retained for follow-up: IOCP close currently marks the port closed on the first handle close if duplicate IOCP handles become supported; the current userland `DuplicateHandle` implementation aliases the numeric source handle, and no `NtDuplicateObject`/kernel duplicate dispatch exists for IOCP. `pidfd_getfd` reads a target Linux fd table without a per-process fd lock during concurrent close; the array is directly read by many Linux syscall paths, so adding a lock only at `pidfd_getfd` would not establish an invariant. Both require their owning handle/fd-lifetime contracts before a safe fix.

The machine preflight currently reports STOP-level resource pressure, so no build or QEMU process was launched during this audit slice.
2 changes: 1 addition & 1 deletion kernel/apps/calculator.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -173,7 +173,7 @@ constinit State g_state = {duetos::drivers::video::kWindowInvalid, {}, 0, {}, 0,
void SetDisplayLiteral(const char* s)
{
u32 n = 0;
while (s[n] != '\0' && n < kDisplayCap)
while (n < kDisplayCap && s[n] != '\0')
{
g_state.display[n] = s[n];
++n;
Expand Down
12 changes: 6 additions & 6 deletions kernel/apps/charmap.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -535,8 +535,8 @@ void RebindCharmapBounds(u32 cx, u32 cy, u32 cw, u32 ch)
void RefreshCharmapHeader()
{
u32 o = 0;
const char* prefix = "U+";
while (prefix[o] != '\0' && o + 1 < sizeof(g_header_text))
const char prefix[] = "U+";
while (o + 1 < sizeof(g_header_text) && o < sizeof(prefix) - 1 && prefix[o] != '\0')
{
g_header_text[o] = prefix[o];
++o;
Expand Down Expand Up @@ -620,8 +620,8 @@ void ClickCopy()
CopySelectionToClipboard();
char buf[64];
u32 o = 0;
const char* p = "copied U+";
while (p[o] != '\0' && o + 1 < sizeof(buf))
const char p[] = "copied U+";
while (o < sizeof(p) - 1 && o + 1 < sizeof(buf) && p[o] != '\0')
{
buf[o] = p[o];
++o;
Expand Down Expand Up @@ -751,8 +751,8 @@ bool CharMapFeedChar(char c)
CopySelectionToClipboard();
char buf[64];
u32 o = 0;
const char* p = "copied U+";
while (p[o] != '\0' && o + 1 < sizeof(buf))
const char p[] = "copied U+";
while (o < sizeof(p) - 1 && o + 1 < sizeof(buf) && p[o] != '\0')
{
buf[o] = p[o];
++o;
Expand Down
9 changes: 5 additions & 4 deletions kernel/apps/dbg_core.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -304,11 +304,12 @@ usize ScanBytes(u64 pid, const u8* needle, usize nlen, u64* hits, usize cap)
// and direct — no AS walks.
if (pid == kKernelPid)
{
const u8* lo = _text_start;
const u8* hi = _text_end;
if (hi <= lo)
const u64 lo_addr = reinterpret_cast<u64>(_text_start);
const u64 hi_addr = reinterpret_cast<u64>(_text_end);
if (hi_addr <= lo_addr)
return 0;
const u64 size = static_cast<u64>(hi - lo);
const u8* lo = reinterpret_cast<const u8*>(lo_addr);
const u64 size = hi_addr - lo_addr;
for (u64 off = 0; off + nlen <= size && hit_count < cap; ++off)
{
bool match = true;
Expand Down
12 changes: 6 additions & 6 deletions kernel/apps/files.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -2039,14 +2039,14 @@ bool MaybeLaunchRamfsExe(const duetos::fs::RamfsNode* sel)
return false;
char tag[40];
duetos::u32 ti = 0;
const char* prefix = "ramfs-launch:";
while (prefix[ti] != '\0' && ti < sizeof(tag) - 1)
const char prefix[] = "ramfs-launch:";
while (ti < sizeof(prefix) - 1 && ti < sizeof(tag) - 1 && prefix[ti] != '\0')
{
tag[ti] = prefix[ti];
++ti;
}
duetos::u32 ni = 0;
while (sel->name[ni] != '\0' && ti < sizeof(tag) - 1)
while (ti < sizeof(tag) - 1 && sel->name[ni] != '\0')
{
tag[ti++] = sel->name[ni++];
}
Expand Down Expand Up @@ -2117,13 +2117,13 @@ bool MaybeLaunchFat32Entry(const duetos::fs::fat32::DirEntry& e)
}
char tag[40];
duetos::u32 ti = 0;
const char* prefix = "fat32-launch:";
while (prefix[ti] != '\0' && ti < sizeof(tag) - 1)
const char prefix[] = "fat32-launch:";
while (ti < sizeof(prefix) - 1 && ti < sizeof(tag) - 1 && prefix[ti] != '\0')
{
tag[ti] = prefix[ti];
++ti;
}
for (duetos::u32 i = 0; e.name[i] != '\0' && ti < sizeof(tag) - 1; ++i)
for (duetos::u32 i = 0; ti < sizeof(tag) - 1 && e.name[i] != '\0'; ++i)
tag[ti++] = e.name[i];
tag[ti] = '\0';
// Build the volume-relative path so SpawnPeFile can derive the
Expand Down
2 changes: 1 addition & 1 deletion kernel/apps/imageview.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -410,7 +410,7 @@ enum class ImageFormat : u8
ImageFormat ClassifyByName(const char* name)
{
u32 len = 0;
while (name[len] != '\0' && len < kNameCap)
while (len < kNameCap && name[len] != '\0')
++len;
if (len < 5)
return ImageFormat::Unknown;
Expand Down
2 changes: 1 addition & 1 deletion kernel/apps/notes.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -902,7 +902,7 @@ void DrawFn(u32 cx, u32 cy, u32 cw, u32 ch, void* /*cookie*/)
// bytes ~= glyph cell count for the Caption role bitmap
// path, which is the v0 default).
u32 base_len = 0;
while (g_status_text[base_len] != '\0' && base_len < sizeof(g_status_text))
while (base_len < sizeof(g_status_text) - 1 && g_status_text[base_len] != '\0')
++base_len;
const u32 fx = sx + base_len * kGlyphW;
const u32 max_x = cx + cw - kPad;
Expand Down
8 changes: 4 additions & 4 deletions kernel/apps/screenshot.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -446,8 +446,8 @@ bool ScreenshotCapture()
// confirmation the F-key actually wrote anything.
char toast[40];
u32 to = 0;
const char* prefix = "saved ";
while (prefix[to] != '\0' && to + 1 < sizeof(toast))
constexpr char prefix[] = "saved ";
while (to < sizeof(prefix) - 1 && to + 1 < sizeof(toast) && prefix[to] != '\0')
{
toast[to] = prefix[to];
++to;
Expand Down Expand Up @@ -552,8 +552,8 @@ bool ScreenshotCaptureTga()
SetLastStatus("saved");
char toast[40];
u32 to = 0;
const char* prefix = "saved ";
while (prefix[to] != '\0' && to + 1 < sizeof(toast))
constexpr char prefix[] = "saved ";
while (to < sizeof(prefix) - 1 && to + 1 < sizeof(toast) && prefix[to] != '\0')
{
toast[to] = prefix[to];
++to;
Expand Down
14 changes: 7 additions & 7 deletions kernel/apps/settings_datetime.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -138,20 +138,21 @@ void AppendStr(char* out, u32 cap, u32* o, const char* s)

void AppendSignedDec(char* out, u32 cap, u32* o, i32 v)
{
if (v < 0)
i64 value = v;
if (value < 0)
{
if (*o + 1 < cap)
out[(*o)++] = '-';
v = -v;
value = -value;
}
char tmp[12];
u32 n = 0;
if (v == 0)
if (value == 0)
tmp[n++] = '0';
while (v > 0 && n < sizeof(tmp))
while (value > 0 && n + 1 < sizeof(tmp))
{
tmp[n++] = static_cast<char>('0' + (v % 10));
v /= 10;
tmp[n++] = static_cast<char>('0' + (value % 10));
value /= 10;
}
while (n > 0 && *o + 1 < cap)
out[(*o)++] = tmp[--n];
Expand Down Expand Up @@ -379,7 +380,6 @@ bool Key(char c)
{
// Well-known Google time server — same as the shell `ntp` command.
duetos::net::Ipv4Address srv{{216, 239, 35, 0}};
AppendStr(g_ntp_status, sizeof(g_ntp_status), nullptr, ""); // unused; direct write below
// Update status to "querying" immediately so the panel
// shows activity on the next frame.
g_ntp_status[0] = 'N';
Expand Down
8 changes: 6 additions & 2 deletions kernel/arch/x86_64/acpi_wakeup.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,9 @@ AcpiWakeContext& AcpiWakeContextGet()

bool AcpiWakeArm()
{
const u64 len = static_cast<u64>(acpi_wake_tramp_end - acpi_wake_tramp_start);
const u64 start = reinterpret_cast<u64>(acpi_wake_tramp_start);
const u64 end = reinterpret_cast<u64>(acpi_wake_tramp_end);
const u64 len = end >= start ? end - start : 0;
if (len == 0 || len > kTrampolineMaxLen)
{
KLOG_WARN_V("arch/acpi-wake", "wake trampoline image does not fit its page — S3 unavailable", len);
Expand Down Expand Up @@ -124,7 +126,9 @@ void AcpiWakeSelfTest()
{
using core::PanicWithValue;

const u64 len = static_cast<u64>(acpi_wake_tramp_end - acpi_wake_tramp_start);
const u64 start = reinterpret_cast<u64>(acpi_wake_tramp_start);
const u64 end = reinterpret_cast<u64>(acpi_wake_tramp_end);
const u64 len = end >= start ? end - start : 0;
if (len != kTrampolineMaxLen)
PanicWithValue("arch/acpi-wake", "wake trampoline blob is not exactly one page", len);

Expand Down
4 changes: 3 additions & 1 deletion kernel/arch/x86_64/smp.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -1024,7 +1024,9 @@ u64 SmpStartAps()
// Copy the trampoline image into physical 0x8000. Frame allocator
// has the low 1 MiB permanently reserved, so nobody else owns this
// memory.
const u64 tramp_len = static_cast<u64>(ap_trampoline_end - ap_trampoline_start);
const u64 tramp_start = reinterpret_cast<u64>(ap_trampoline_start);
const u64 tramp_end = reinterpret_cast<u64>(ap_trampoline_end);
const u64 tramp_len = tramp_end >= tramp_start ? tramp_end - tramp_start : 0;
if (tramp_len > 0x1000)
{
// Build-time invariant violated. Debug: panic so the
Expand Down
2 changes: 1 addition & 1 deletion kernel/core/boot_bringup.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -4239,7 +4239,7 @@ void BootBringupDesktop(duetos::uptr multiboot_info)
if (hit != nullptr)
{
duetos::u32 n = 0;
while (hit[n] != '\0' && hit[n] != ' ' && n < sizeof(g_peexec_path) - 1)
while (n < sizeof(g_peexec_path) - 1 && hit[n] != '\0' && hit[n] != ' ')
{
g_peexec_path[n] = hit[n];
++n;
Expand Down
5 changes: 4 additions & 1 deletion kernel/core/init.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -344,7 +344,10 @@ extern "C" void (*__init_array_end[])();

void RunInitArray()
{
const u64 count = static_cast<u64>(__init_array_end - __init_array_start);
const u64 begin = reinterpret_cast<u64>(__init_array_start);
const u64 end = reinterpret_cast<u64>(__init_array_end);
const u64 bytes = end >= begin ? end - begin : 0;
const u64 count = bytes / sizeof(__init_array_start[0]);
arch::SerialWrite("[init] _init_array: ");
arch::SerialWriteHex(count);
arch::SerialWrite(" entries\n");
Expand Down
2 changes: 0 additions & 2 deletions kernel/core/menu_dispatch.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -605,8 +605,6 @@ void DispatchMenuAction(duetos::u32 action, duetos::u32 ctx)
duetos::u64 v = pid;
char tmp[24];
duetos::u32 ti = 0;
if (v == 0)
tmp[ti++] = '0';
while (v != 0)
{
tmp[ti++] = static_cast<char>('0' + v % 10);
Expand Down
11 changes: 8 additions & 3 deletions kernel/debug/hot_patch.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -500,10 +500,15 @@ bool HotPatchSelfTest()
HotPatchBulkResult HotPatchApplyAll()
{
HotPatchBulkResult r{};
const auto* p = __duetos_hotpatch_pairs_start;
const auto* end = __duetos_hotpatch_pairs_end;
for (; p < end; ++p)
const u64 begin = reinterpret_cast<u64>(__duetos_hotpatch_pairs_start);
const u64 end = reinterpret_cast<u64>(__duetos_hotpatch_pairs_end);
if (end < begin)
return r;
const u64 count = (end - begin) / sizeof(HotPatchPair);
const auto* pairs = __duetos_hotpatch_pairs_start;
for (u64 index = 0; index < count; ++index)
{
const auto* p = &pairs[index];
++r.considered;
const u64 target_va = reinterpret_cast<u64>(p->target);
const u64 replacement_va = reinterpret_cast<u64>(p->replacement);
Expand Down
2 changes: 1 addition & 1 deletion kernel/diag/bsod.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -201,7 +201,7 @@ u32 DrawDecU32(u32 x, u32 y, u32 v, u32 fg, u32 bg)
}
else
{
while (v > 0 && n < sizeof(buf))
while (v > 0 && n + 1 < sizeof(buf))
{
buf[n++] = static_cast<char>('0' + v % 10);
v /= 10;
Expand Down
2 changes: 1 addition & 1 deletion kernel/diag/cleanroom_trace.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -163,7 +163,7 @@ void WriteDec(u64 v)
}
char buf[24];
u32 n = 0;
while (v > 0 && n < sizeof(buf))
while (v > 0 && n + 1 < sizeof(buf))
{
buf[n++] = static_cast<char>('0' + (v % 10));
v /= 10;
Expand Down
4 changes: 2 additions & 2 deletions kernel/diag/kpath_selftest.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -46,9 +46,9 @@ bool IterMatchCallback(const KPathIterRow& row, void* /*ctx*/)
// Pointer-equality is sufficient because both source sites
// use the same string literal (string-pooled by the linker).
const char* a = row.name;
const char* b = "kpath.selftest.site";
constexpr char b[] = "kpath.selftest.site";
bool match = true;
for (::duetos::u32 i = 0; i < 24; ++i)
for (::duetos::u32 i = 0; i < sizeof(b); ++i)
{
if (a[i] != b[i])
{
Expand Down
20 changes: 12 additions & 8 deletions kernel/diag/runtime_checker.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -909,9 +909,10 @@ DUETOS_NO_SANITIZE_WRAP u64 ComputeTextSpotHash()
constexpr u64 kFnvPrime = 0x100000001b3ULL;
constexpr u64 kSpotBytes = 4096;
u64 h = kFnvOffset;
const u8* s = _text_start;
const u8* e = _text_end;
const u64 text_bytes = u64(e - s);
const u64 start = reinterpret_cast<u64>(_text_start);
const u64 end = reinterpret_cast<u64>(_text_end);
const u64 text_bytes = end >= start ? end - start : 0;
const u8* s = reinterpret_cast<const u8*>(start);
const u64 head_bytes = (text_bytes < kSpotBytes) ? text_bytes : kSpotBytes;
for (u64 i = 0; i < head_bytes; ++i)
{
Expand All @@ -922,7 +923,7 @@ DUETOS_NO_SANITIZE_WRAP u64 ComputeTextSpotHash()
{
for (u64 i = 0; i < kSpotBytes; ++i)
{
h ^= e[-i64(kSpotBytes) + i64(i)];
h ^= s[text_bytes - kSpotBytes + i];
h *= kFnvPrime;
}
}
Expand All @@ -938,11 +939,14 @@ DUETOS_NO_SANITIZE_WRAP u64 ComputeTextFullHash()
constexpr u64 kFnvOffset = 0xcbf29ce484222325ULL;
constexpr u64 kFnvPrime = 0x100000001b3ULL;
u64 h = kFnvOffset;
const u8* s = _text_start;
const u8* e = _text_end;
for (const u8* p = s; p < e; ++p)
const u64 start = reinterpret_cast<u64>(_text_start);
const u64 end = reinterpret_cast<u64>(_text_end);
if (end < start)
return h;
const u8* s = reinterpret_cast<const u8*>(start);
for (u64 i = 0; i < end - start; ++i)
{
h ^= *p;
h ^= s[i];
h *= kFnvPrime;
}
return h;
Expand Down
6 changes: 3 additions & 3 deletions kernel/drivers/gpu/cea861.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,7 @@ void WriteDec(u32 v)
ConsoleWrite("0");
return;
}
while (v != 0 && i < sizeof(buf))
while (v != 0 && i + 1 < sizeof(buf))
{
buf[i++] = static_cast<char>('0' + (v % 10));
v /= 10;
Expand Down Expand Up @@ -318,9 +318,9 @@ const char* CeaVicName(u8 vic, char scratch[16])
// Format "vic-N" into scratch.
if (scratch == nullptr)
return "vic-?";
const char* p = "vic-";
constexpr char p[] = "vic-";
u32 i = 0;
while (p[i] != 0 && i < 15)
while (i < sizeof(p) - 1 && p[i] != 0)
{
scratch[i] = p[i];
++i;
Expand Down
2 changes: 1 addition & 1 deletion kernel/drivers/gpu/edid.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -304,7 +304,7 @@ void WriteDec(u32 v)
ConsoleWrite("0");
return;
}
while (v != 0 && i < sizeof(buf))
while (v != 0 && i + 1 < sizeof(buf))
{
buf[i++] = static_cast<char>('0' + (v % 10));
v /= 10;
Expand Down
Loading
Loading