Skip to content

Experiment: pin x86_64 next and validate bare-metal paging compatibility - #47

Merged
t4ce merged 1 commit into
truefrom
exp/x86_64-next-pinned-paging
Sep 17, 2026
Merged

t4ce merged 1 commit into
truefrom
exp/x86_64-next-pinned-paging

Conversation

@t4ce

@t4ce t4ce commented Sep 17, 2026 •

Copy link
Copy Markdown
Owner

Purpose

Try the unreleased upstream paging changes through a root [patch.crates-io], without waiting for publication and without mixing in a VM-memory ownership redesign.

Upstream pin: 78b81025d65a3e899f48a6fded8b27889a09d70b (2026-09-16).
TRUEOS base: 67631dcecdbbaf813a516aa91962f3790b56374b.
PR head tested: 31d298ea57da19060a4a13281b5f6523e08062fe.

Draft: isolated compatibility checks now PASS in GitHub-hosted CI. The complete kernel build/link and bare-metal boot/lifecycle validation remain outstanding. No deployment, reboot, release publication or live-kernel modification was performed.

Actual CI results — September 17, 2026

Successful workflow run / job log / compiler, metadata, lockfile and test evidence.

  • PASS: 7 Python validation-gate tests and the static version/feature/constructor contract.
  • PASS: isolated Cargo metadata resolves the exact Git pin with required features.
  • PASS: all 3 Rust host tests, covering MMIO-style flags/display/unmap/table reclamation, non-present clear, and the default encryption-feature address mask.
  • PASS: no_std probe compiled against .cargo/x86_64-unknown-trueos.json, using build-std.
  • Toolchain unchanged: nightly-2026-07-10 is rustc 1.99.0-nightly (af3d95584 2026-07-09), so the tested probe meets upstream's Rust 1.98 requirement. No toolchain upgrade was needed.

The authoring container itself had no Rust compiler, so local checks were limited to Python/static validation. Rust results above are from the completed GitHub job, whose logs were inspected. CI checked the PR merge ref 30be6b287c957ad321d5965ec42ab69a3ceb2f3f.

Changes

  • Pin the implementation by full Git SHA. Upstream next still declares 0.15.5; use =0.15.5 so a future registry patch version cannot silently win resolution. This remains unreleased, breaking source despite its version label.
  • Preserve instructions, nightly, and memory_encryption explicitly. Leave the toolchain and custom target unchanged.
  • Change only the constructor expression in src/pci/mmio.rs::active_mapper: OffsetPageTable::new becomes from_phys_offset in an explicit unsafe block. Mapping flags, allocation policy, locks, CR3/HHDM calculation and local flushing policy are unchanged.
  • Add tools/check_x86_64_next.py, software-only Rust paging tests, offline tests for the validation gate, and GitHub-hosted CI with retained evidence. --kernel-check additionally resolves/checks the real workspace in a fully provisioned checkout.
  • Document impact, limitations, hardware acceptance and rollback in tools/docs/x86_64-next.md.

Bare-metal implications

The constructor removal is a concrete compile-time issue in the active host MMIO/RAM mapping path, addressed here. Upstream #603 changes address masking after memory encryption is configured; enabling the Cargo feature alone does not configure encryption. The configured C/S-bit path needs separate testing.

TRUEOS's custom GuestTables / EptTables, EPT/VPID retirement, GPU PPGTT mappings, DMA pins and quarantine are not redesigned. clear and unmap do not establish frame ownership or safely destroy a VM. Test tables are private and never loaded into CR3; ignoring flush tokens in those tests does not authorize ignoring them in the kernel.

The review also documents pre-existing, unchanged MMIO behavior: ignored PageAlreadyMapped/ParentEntryHugePage errors and missing transaction rollback after partial allocation failure. This dependency change is not a fix for those policies.

Full-check command

In the complete, provisioned TRUEOS checkout:

python3 tools/check_x86_64_next.py --kernel-check

This needs the existing submodules/generated inputs and ../TRUEOS-Blueprints/crates/log-os. It verifies the real workspace graph and runs cargo check --bin TRUEOS; it does not perform a final link or boot.

The root Cargo.lock remains ignored by existing policy. The driver can update the local lockfile and preserves evidence copies; this PR does not pin the entire kernel dependency graph. Preserve matching baseline/candidate lockfiles when comparing images.

Before merging/deploying

  • Pass isolated metadata checks, 3 Rust tests and the TRUEOS custom-target probe on the unchanged toolchain.
  • Resolve/check the real workspace with its required build inputs.
  • Complete the normal kernel release build/link and compare baseline/candidate evidence.
  • Deliberately boot a separate candidate with recovery available; validate PCI/MMIO, device interrupts, retained-firmware mappings, VM lifecycle/reuse across lanes, and GPU/DMA retirement/failure cases.

A green isolated probe is not proof of correct TLB/EPT/VPID synchronization, device operation, leak-free teardown or bare-metal memory safety. Roll back the Git override and constructor migration together; removing only the override leaves code requiring the unreleased API.

Upstream references: release discussion #600, display #574, type alias/constructor #576, clear/unmap #484, encryption mask #603.

Pin upstream 78b81025 rather than a moving next branch, preserve effective
features and the kernel toolchain, and migrate the MMIO mapper constructor.
Add software-only paging tests, a TRUEOS-target compile probe, Cargo source
checks, and a bare-metal impact/rollback guide. No VM ownership, EPT/VPID,
GPU/DMA retirement, deployment, or running-kernel changes are performed.
@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0a2a7189-9528-4043-b8dc-08986d6f6552


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@t4ce
t4ce marked this pull request as ready for review September 17, 2026 03:38
@t4ce
t4ce merged commit ac26e79 into true Sep 17, 2026
2 checks passed
@t4ce
t4ce deleted the exp/x86_64-next-pinned-paging branch September 23, 2026 17:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant