Experiment: pin x86_64 next and validate bare-metal paging compatibility - #47
Merged
Merged
Conversation
Pin upstream 78b81025 rather than a moving next branch, preserve effective features and the kernel toolchain, and migrate the MMIO mapper constructor. Add software-only paging tests, a TRUEOS-target compile probe, Cargo source checks, and a bare-metal impact/rollback guide. No VM ownership, EPT/VPID, GPU/DMA retirement, deployment, or running-kernel changes are performed.
Contributor
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Try the unreleased upstream paging changes through a root
[patch.crates-io], without waiting for publication and without mixing in a VM-memory ownership redesign.Upstream pin:
78b81025d65a3e899f48a6fded8b27889a09d70b(2026-09-16).TRUEOS base:
67631dcecdbbaf813a516aa91962f3790b56374b.PR head tested:
31d298ea57da19060a4a13281b5f6523e08062fe.Draft: isolated compatibility checks now PASS in GitHub-hosted CI. The complete kernel build/link and bare-metal boot/lifecycle validation remain outstanding. No deployment, reboot, release publication or live-kernel modification was performed.
Actual CI results — September 17, 2026
Successful workflow run / job log / compiler, metadata, lockfile and test evidence.
.cargo/x86_64-unknown-trueos.json, using build-std.nightly-2026-07-10is rustc 1.99.0-nightly (af3d95584 2026-07-09), so the tested probe meets upstream's Rust 1.98 requirement. No toolchain upgrade was needed.The authoring container itself had no Rust compiler, so local checks were limited to Python/static validation. Rust results above are from the completed GitHub job, whose logs were inspected. CI checked the PR merge ref
30be6b287c957ad321d5965ec42ab69a3ceb2f3f.Changes
nextstill declares0.15.5; use=0.15.5so a future registry patch version cannot silently win resolution. This remains unreleased, breaking source despite its version label.instructions,nightly, andmemory_encryptionexplicitly. Leave the toolchain and custom target unchanged.src/pci/mmio.rs::active_mapper:OffsetPageTable::newbecomesfrom_phys_offsetin an explicit unsafe block. Mapping flags, allocation policy, locks, CR3/HHDM calculation and local flushing policy are unchanged.tools/check_x86_64_next.py, software-only Rust paging tests, offline tests for the validation gate, and GitHub-hosted CI with retained evidence.--kernel-checkadditionally resolves/checks the real workspace in a fully provisioned checkout.tools/docs/x86_64-next.md.Bare-metal implications
The constructor removal is a concrete compile-time issue in the active host MMIO/RAM mapping path, addressed here. Upstream #603 changes address masking after memory encryption is configured; enabling the Cargo feature alone does not configure encryption. The configured C/S-bit path needs separate testing.
TRUEOS's custom
GuestTables/EptTables, EPT/VPID retirement, GPU PPGTT mappings, DMA pins and quarantine are not redesigned.clearandunmapdo not establish frame ownership or safely destroy a VM. Test tables are private and never loaded into CR3; ignoring flush tokens in those tests does not authorize ignoring them in the kernel.The review also documents pre-existing, unchanged MMIO behavior: ignored
PageAlreadyMapped/ParentEntryHugePageerrors and missing transaction rollback after partial allocation failure. This dependency change is not a fix for those policies.Full-check command
In the complete, provisioned TRUEOS checkout:
This needs the existing submodules/generated inputs and
../TRUEOS-Blueprints/crates/log-os. It verifies the real workspace graph and runscargo check --bin TRUEOS; it does not perform a final link or boot.The root Cargo.lock remains ignored by existing policy. The driver can update the local lockfile and preserves evidence copies; this PR does not pin the entire kernel dependency graph. Preserve matching baseline/candidate lockfiles when comparing images.
Before merging/deploying
A green isolated probe is not proof of correct TLB/EPT/VPID synchronization, device operation, leak-free teardown or bare-metal memory safety. Roll back the Git override and constructor migration together; removing only the override leaves code requiring the unreleased API.
Upstream references: release discussion #600, display #574, type alias/constructor #576, clear/unmap #484, encryption mask #603.