ASELSANMicrokernel
S316 · SOURCE-BOUND GATE EVIDENCE

G8l: QEMU S143 reply-derived ACK writer-authority audit

Operations --test hedefi → test hedefiyle aynı adlı uygulama/model modülü → kaynak kesiti Bu sayfa yalnız S316 kapısına aittir; komşu kapıların kaynakları bu kabulün içine katılmaz.

S316Focused kod testiOperations id exactsource SHA exacttest target exact

operation: g8l-s316-qemu-s143-reply-derived-ack-writer-authority-audit-partial

uygulama/model · focused test · Operations · 3 exact excerpt

sequence-bound=true · implementation-bound=true
01 · Testin bağlı olduğu uygulama/model kodu

Kapının yürüttüğü gerçek kaynak

tam Rust öğesiL30–L103
kernel/src/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s316_qemu_s143_reply_derived_ack_writer_authority_audit.rs::S316_MAIN_REMAINING_UNAUDITED_WRITER_SITES

pub const S316_WRITER_BOUNDARY_SITES: usize = 1;
pub const S316_WRITER_AUTHORITY_SITES: usize = 0;
pub const S316_MAIN_EXPLICIT_WRITER_SITES: usize = 17;
pub const S316_MAIN_PREVIOUSLY_AUDITED_WRITER_SITES: usize = 6;
pub const S316_MAIN_REMAINING_UNAUDITED_WRITER_SITES: usize = 10;
pub const S316_S143_EXPLICIT_WRITER_SITES: usize = 1;
pub const S316_S143_REMAINING_UNAUDITED_WRITER_SITES: usize = 0;
pub const S316_DIRECT_SCHEDULER_ACCESS_SITES: usize = S315_DIRECT_SCHEDULER_ACCESS_SITES;
pub const S316_IMMUTABLE_READ_SITES: usize = S315_IMMUTABLE_READ_SITES;
pub const S316_WHOLE_SCHEDULER_GUARDED_SITES: usize = S315_WHOLE_SCHEDULER_GUARDED_SITES;
pub const S316_WHOLE_SCHEDULER_UNROUTED_SITES: usize = S315_WHOLE_SCHEDULER_UNROUTED_SITES;
pub const S316_OPEN_WRITER_SITES: usize = S315_OPEN_WRITER_SITES;

#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS316SchedulerWriterAuthorityAuditOutcome {
    Idle,
    AwaitingWriterAuthority {
        request_id: u64,
        guarded_sites: usize,
        writer_sites: usize,
    },
}

#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS316SchedulerWriterAuthorityAuditError {
    S315(G8lS315SchedulerWriterAuthorityAuditError),
    S245(G8lS245ExclusionAdmissionRequestError),
    PriorCoverageDrift {
        guarded_sites: usize,
        unrouted_sites: usize,
    },
}

/// Revalidate the prior fail-closed authority boundary without taking
/// admission or constructing a production exclusive wrapper.
pub fn preflight_s316_scheduler_writer_authority(
    caller_cpu: usize,
    request: Option<G8lS245WholeSchedulerExclusionAdmissionRequestView>,
) -> Result<G8lS316SchedulerWriterAuthorityAuditOutcome, G8lS316SchedulerWriterAuthorityAuditError>
{
    match preflight_s315_scheduler_writer_authority(caller_cpu, request)
        .map_err(G8lS316SchedulerWriterAuthorityAuditError::S315)?
    {
        G8lS315SchedulerWriterAuthorityAuditOutcome::Idle => {
            Ok(G8lS316SchedulerWriterAuthorityAuditOutcome::Idle)
        }
        G8lS315SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
            request_id,
            guarded_sites,
            writer_sites,
        } if guarded_sites == S316_WHOLE_SCHEDULER_GUARDED_SITES
            && writer_sites == S316_OPEN_WRITER_SITES =>
        {
            Ok(
                G8lS316SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
                    request_id,
                    guarded_sites,
                    writer_sites,
                },
            )
        }
        G8lS315SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
            guarded_sites,
            writer_sites: _,
            ..
        } => Err(
            G8lS316SchedulerWriterAuthorityAuditError::PriorCoverageDrift {
                guarded_sites,
                unrouted_sites: S316_DIRECT_SCHEDULER_ACCESS_SITES - guarded_sites,
            },
        ),
    }
}
snippet sha256: c03a5451bd2dfile sha256: 018aa8a4c004
02 · Doğrulayan test kodu

Operations komutuna bağlı focused test

tam Rust öğesiL275–L314
simulation/tests/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s316_qemu_s143_reply_derived_ack_writer_authority_audit.rs::s316_helper_revalidates_kernel_caller_send_and_linked_reply_under_transaction

#[test]
fn s316_helper_revalidates_kernel_caller_send_and_linked_reply_under_transaction() {
    let source = include_str!("../../kernel/src/task/scheduler.rs");
    let helper = kernel_call_and_wait_boundary(source);
    for required in [
        "IrqGuard::new()",
        "IPC_TRANSACTION_LOCK.lock()",
        "IPC_CALL_DEADLINES.lock()",
        ".filter(|task| !task.is_user)",
        ".filter(|task_id| *task_id != 0)",
        "current_endpoint_authority_is_live(",
        "CapabilityRights::ENDPOINT_SEND",
        "ENDPOINT_REGISTRY.lock()",
        "endpoint.id == target_endpoint && !endpoint.is_reply_cap",
        "endpoint.id == reply_cap_id",
        "endpoint.is_reply_cap",
        "endpoint.owner == caller_task",
        "endpoint.reply_target == Some(target_endpoint)",
        "if !reply_is_linked",
    ] {
        assert!(
            helper.contains(required),
            "missing S316 helper authority token: {required}"
        );
    }
    let irq = helper.find("IrqGuard::new()").unwrap();
    let transaction = helper.find("IPC_TRANSACTION_LOCK.lock()").unwrap();
    let caller = helper.find("let caller_task").unwrap();
    let send = helper.find("current_endpoint_authority_is_live(").unwrap();
    let endpoints = helper.find("ENDPOINT_REGISTRY.lock()").unwrap();
    let reply = helper.find("let reply_is_linked").unwrap();
    assert!(
        irq < transaction
            && transaction < caller
            && caller < send
            && send < endpoints
            && endpoints < reply
    );
}
snippet sha256: baa9da488852file sha256: bf46c7739710
03 · Kapı kimlik kaydı

Operations sıra, kimlik ve başlık bağı

tam Operations kaydıL15310–L15372
website/src/lib/operations.ts::g8l-s316-qemu-s143-reply-derived-ack-writer-authority-audit-partial
  {
    id: "g8l-s316-qemu-s143-reply-derived-ack-writer-authority-audit-partial",
    date: "2026-08-27",
    sequence: 316,
    status: "passed",
    umbrella_status: "partial",
    title: "G8l: QEMU S143 reply-derived ACK writer-authority audit",
    summary:
      "S316 focused 15/15 PASS ile main.rs kaynak sırasındaki bir sonraki explicit mutable scheduler sınırını doğrular: run_qemu_s143_reply_derived_broker_commit içindeki tek ipc_kernel_call_and_wait writer'ı. Nonzero controller task, controller-owned normal Endpoint SEND authority, strict EL0 supervisor RECV grant, task-bound broker session/lease, immutable exact message, linked one-shot reply capability ve pre-armed reply bridge writer'dan önce doğrulanır. Helper aynı IRQ/IPC transaction altında non-user caller SEND authority'sini, normal endpoint'i, linked reply'ı, optional receiver authority/deadline'ını ve tüm park kapasitesini yeniden doğrular; CALL publication/park ve optional delivery tek transaction içinde yapılır. Continuation aynı caller'ı resume eder, exact ordinary ACK'i yeniden kurar; S143 ancak exact label/badge/data doğrulamasından sonra bridge/broker commit ve session-close gözlemini kabul eder. Writer authority yalnız model gate'inin exclusive lease'iyle mümkündür; reader lease'i writer'ı açmaz. main.rs 17 explicit writer / 6 previously audited / 10 remaining unaudited; S143 işlevi 1 / 0 source/model covered; production inventory 113 direct / 44 immutable guarded / 69 open writer olarak değişmez ve production exclusive wrapper, provider authority, whole-scheduler exclusion veya scheduler mutation üretilmez.",
    evidence: [
      "S316 focused kaynak/model kapısı iki bağımsız koşuda 15/15 PASS verdi: 130 B / SHA-256 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3.",
      "main.rs içindeki 17 explicit addr_of_mut!(crate::task::scheduler::SCHEDULER) sitesinin positions[10], kaynakta alttan yedinci sınırı audit edilir. run_qemu_s143_reply_derived_broker_commit tek explicit alias taşır; işlevde 0, main.rs genelinde 10 alias ayrıca açık kalır.",
      "Nonzero controller kimliği, controller-owned normal Endpoint ve ENDPOINT_SEND authority, strict EL0 supervisor'a exact ENDPOINT_RECV grant, RuntimeOomTransportEvent, task-bound broker session/lease, immutable IpcMessage ve linked reply-cap writer'dan önce kurulur.",
      "Reply bridge publication_guard altında önce unarmed görülür, exact supervisor/reply/label/message/session/lease ile bir kez arm edilir ve IrqGuard writer'dan önce bırakılır.",
      "ipc_kernel_call_and_wait exact endpoint id/generation, reply id ve immutable message'i alır; S143 yalnız exact ordinary ACK label, supervisor-task badge ve message.data eşleşmesini kabul eder.",
      "Helper IrqGuard ve IPC_TRANSACTION_LOCK altında nonzero non-user caller, canlı ENDPOINT_SEND authority, normal target endpoint ve caller-owned linked reply-cap'i yeniden doğrular. Optional receiver varsa exact ENDPOINT_RECV generation/owner ve receive deadline da doğrulanır; ready/blocked kapasite preflight'ı mutation'dan önce gelir.",
      "CALL publish/finish-park, caller BlockedOnIpc publication ve optional receiver delivery/deadline retirement/Ready enqueue tek transaction içindedir. Transaction bırakıldıktan sonra aynı kernel caller resume edilir ve saved GPR'lerden exact reply yeniden kurulur.",
      "S143 exact ACK sonrasında armed=false, armed_count=1, committed_count=1, cancelled_count=0 bridge; queued/pending/in_flight=0, acknowledged=3, supervisor_sessions_started=5 broker; endpoint cleanup ve RuntimePmm baseline gözler. Controller doğrudan acknowledge_exact veya close_supervisor_session çağırmaz.",
      "Model gate reader membership exclusive writer authority'yi ExclusiveBusy ile bloklar; reader bırakıldıktan sonra non-zero token'lı exclusive lease alınır. Wrong CPU InvalidCpu ile fail-closed kalır. Bu host/model evidence'tır.",
      "S315 authority preflight yeniden doğrulanır; pending S245 request korunur ve sonuç AwaitingWriterAuthority { guarded_sites: 44, writer_sites: 69 } olarak döner.",
      "Dört AArch64 profil derlemesi iki koşuda byte-equal exit 0 verdi: QEMU 110646 B / e77da19c, RPi4 149371 B / 1ef70ff1, RPi5 457628 B / 024917c9 ve RPi5+SMP 457570 B / 1a6a2da8. Warning header'ları sırasıyla 291, 389, 975 ve 975'tir; zero-warning iddiası değildir.",
      "Birleşik board-rpi5,board-qemu özellikleri iki koşuda beklenen exit 101, 18590 B / 4761315c, 17 error ve 22 warning header ile fail-closed kaldı.",
      "S238–S316 dependency matrisi iki koşuda 80 grup / 1124/1124 PASS; ham loglar 10322 B / eff1532b ve 485b72f6, süre-normalize özetler byte-equal 10482 B / a318342b3f17a5a20697baff76b2f5036972be7c5ed065ba3fb925346c84bf01. Bu production writer-authority invocation kanıtı değildir.",
      "Ortak make verify-qemu iki koşuda PASS verdi: 116222 B / ab89b5d8 ve 116139 B / 385a910b; guest logları 2164581 B / 718dd318 ve 2143629 B / e02ce89f. W^X 31/31, S271 GRAPH_ABSENT=YES, RuntimePmm baseline, EL0 x4096, IPC 20/20, koşu başına tek FATAL_TASK_EXIT, SEC5 ve 13 KERNEL_FAULTS=0 marker'ı korunur. Bu ortak smoke S316 production writer-authority invocation kanıtı değildir.",
      "Exact yedi tarihsel G8h assertion adıyla dışlandığında workspace iki koşuda 278 sonuç grubu / 2930 PASS / 7 filtered verdi: ham loglar 63638 B / 59c1544e ve 06294970, sonuç özetleri 26293 B / 270b580c ve 50b46646, süre-normalize 26847 B özet byte-equal / SHA-256 ad176623c4721cd16a11b2c58dc926be287a028709a8e6835fbf202efc5f97ff. Filtresiz koşu exit 101, 58860 B / d9484feb ile frozen S96 exceptions.S identity kapısında RED kaldı; full-workspace GREEN iddia edilmez.",
      "S316 production exclusive wrapper, provider authority, whole-scheduler exclusion, QEMU fixture mutation veya scheduler mutation iddiası eklemez; physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S316=NO.",
    ],
    commands: [
      "cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s316_qemu_s143_reply_derived_ack_writer_authority_audit -- --test-threads=1",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-qemu",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi4",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,smp",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,board-qemu",
      "make verify-qemu",
    ],
    terminalSessions: [
      {
        id: "g8l-s316-qemu-s143-reply-derived-ack-writer-authority-audit",
        title: "G8l S316 QEMU S143 reply-derived ACK writer-authority audit",
        commandLines: [
          "cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s316_qemu_s143_reply_derived_ack_writer_authority_audit -- --test-threads=1",
        ],
        outputLines: [
          "test result: ok; S316 focused 1 group / 15 passed; 0 failed",
          "repeat-stable quiet output: 130 B / 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3",
          "QEMU S143 reply-derived ACK writer authority remains model-only: exact endpoint/reply/message forwarding and ordinary ACK continuation precede bridge/broker commit; S143 is 1/1 source/model covered, main.rs retains 10 unaudited aliases and all 69 production writer sites remain open",
          "dependency: S238–S316 · 80 groups · 1124/1124 PASS; workspace: 278 groups · 2930 PASS · 7 historical filtered",
        ],
        exitCode: 0,
        outputMode: "selected",
      },
    ],
    terminalSessionsNote:
      "S316 kaynak/model fail-closed authority boundary'sidir; production writer guard/migration, QEMU fixture mutation ve fiziksel/device execution claim edilmez.",
    limitations: [
      "S316 run_qemu_s143_reply_derived_broker_commit içindeki tek ipc_kernel_call_and_wait mutable scheduler aliasını audit eder; S143 işlevi 1/1 source/model covered olsa da main.rs genelinde 10 ve toplam 69 production writer site authority wrapper dışında açık kalır.",
      "Exclusive lease yalnız host/model gate'inde test edilir; production exclusive wrapper, provider authority ve whole-scheduler exclusion açık kalır.",
      "S238–S316 dependency matrisi exact 80 grup / 1124/1124 PASS'tir; bu production writer authority invocation kanıtı değildir.",
      "Filtresiz workspace frozen S96 identity kapısında RED'dir; workspace umbrella GREEN iddia edilmez.",
      "Supported-profile writer-authority runtime invocation, Generic SMP ve fiziksel RPi kabulü açık kalır; S316 physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S316=NO.",
    ],
  },
snippet sha256: 38dd96c734cdfile sha256: 9726dbf00f84
Focused test komutu
cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s316_qemu_s143_reply_derived_ack_writer_authority_audit -- --test-threads=1
proof: docs/M8.1-RPi5-G8l-S316-QEMU-S143-Reply-Derived-Ack-Writer-Authority-Audit-Proof.md
Registry schema v5 · generator website/scripts/generate-code-gates.mjs · Tam SHA-256: 91d38c7b6222f0b4c117be786454853543da55a160e543d9b951057cc20dcc06