ASELSANMicrokernel
S318 · SOURCE-BOUND GATE EVIDENCE

G8l: QEMU S142 fault-cancelled CALL writer-authority audit

Operations --test hedefi → test hedefiyle aynı adlı uygulama/model modülü → kaynak kesiti Bu sayfa yalnız S318 kapısına aittir; komşu kapıların kaynakları bu kabulün içine katılmaz.

S318Focused kod testiOperations id exactsource SHA exacttest target exact

operation: g8l-s318-qemu-s142-fault-cancelled-call-writer-authority-audit-partial

uygulama/model · focused test · Operations · 3 exact excerpt

sequence-bound=true · implementation-bound=true
01 · Testin bağlı olduğu uygulama/model kodu

Kapının yürüttüğü gerçek kaynak

tam Rust öğesiL30–L103
kernel/src/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s318_qemu_s142_fault_cancelled_call_writer_authority_audit.rs::S318_MAIN_REMAINING_UNAUDITED_WRITER_SITES

pub const S318_WRITER_BOUNDARY_SITES: usize = 1;
pub const S318_WRITER_AUTHORITY_SITES: usize = 0;
pub const S318_MAIN_EXPLICIT_WRITER_SITES: usize = 17;
pub const S318_MAIN_PREVIOUSLY_AUDITED_WRITER_SITES: usize = 8;
pub const S318_MAIN_REMAINING_UNAUDITED_WRITER_SITES: usize = 8;
pub const S318_S142_EXPLICIT_WRITER_SITES: usize = 2;
pub const S318_S142_REMAINING_UNAUDITED_WRITER_SITES: usize = 0;
pub const S318_DIRECT_SCHEDULER_ACCESS_SITES: usize = S317_DIRECT_SCHEDULER_ACCESS_SITES;
pub const S318_IMMUTABLE_READ_SITES: usize = S317_IMMUTABLE_READ_SITES;
pub const S318_WHOLE_SCHEDULER_GUARDED_SITES: usize = S317_WHOLE_SCHEDULER_GUARDED_SITES;
pub const S318_WHOLE_SCHEDULER_UNROUTED_SITES: usize = S317_WHOLE_SCHEDULER_UNROUTED_SITES;
pub const S318_OPEN_WRITER_SITES: usize = S317_OPEN_WRITER_SITES;

#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS318SchedulerWriterAuthorityAuditOutcome {
    Idle,
    AwaitingWriterAuthority {
        request_id: u64,
        guarded_sites: usize,
        writer_sites: usize,
    },
}

#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS318SchedulerWriterAuthorityAuditError {
    S317(G8lS317SchedulerWriterAuthorityAuditError),
    S245(G8lS245ExclusionAdmissionRequestError),
    PriorCoverageDrift {
        guarded_sites: usize,
        unrouted_sites: usize,
    },
}

/// Revalidate the prior fail-closed authority boundary without taking
/// admission or constructing a production exclusive wrapper.
pub fn preflight_s318_scheduler_writer_authority(
    caller_cpu: usize,
    request: Option<G8lS245WholeSchedulerExclusionAdmissionRequestView>,
) -> Result<G8lS318SchedulerWriterAuthorityAuditOutcome, G8lS318SchedulerWriterAuthorityAuditError>
{
    match preflight_s317_scheduler_writer_authority(caller_cpu, request)
        .map_err(G8lS318SchedulerWriterAuthorityAuditError::S317)?
    {
        G8lS317SchedulerWriterAuthorityAuditOutcome::Idle => {
            Ok(G8lS318SchedulerWriterAuthorityAuditOutcome::Idle)
        }
        G8lS317SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
            request_id,
            guarded_sites,
            writer_sites,
        } if guarded_sites == S318_WHOLE_SCHEDULER_GUARDED_SITES
            && writer_sites == S318_OPEN_WRITER_SITES =>
        {
            Ok(
                G8lS318SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
                    request_id,
                    guarded_sites,
                    writer_sites,
                },
            )
        }
        G8lS317SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
            guarded_sites,
            writer_sites: _,
            ..
        } => Err(
            G8lS318SchedulerWriterAuthorityAuditError::PriorCoverageDrift {
                guarded_sites,
                unrouted_sites: S318_DIRECT_SCHEDULER_ACCESS_SITES - guarded_sites,
            },
        ),
    }
}
snippet sha256: 46165f1b3de3file sha256: 4545b8e80cec
02 · Doğrulayan test kodu

Operations komutuna bağlı focused test

tam Rust öğesiL259–L298
simulation/tests/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s318_qemu_s142_fault_cancelled_call_writer_authority_audit.rs::s318_helper_revalidates_kernel_caller_send_and_linked_reply_under_transaction

#[test]
fn s318_helper_revalidates_kernel_caller_send_and_linked_reply_under_transaction() {
    let source = include_str!("../../kernel/src/task/scheduler.rs");
    let helper = kernel_call_and_wait_boundary(source);
    for required in [
        "IrqGuard::new()",
        "IPC_TRANSACTION_LOCK.lock()",
        "IPC_CALL_DEADLINES.lock()",
        ".filter(|task| !task.is_user)",
        ".filter(|task_id| *task_id != 0)",
        "current_endpoint_authority_is_live(",
        "CapabilityRights::ENDPOINT_SEND",
        "ENDPOINT_REGISTRY.lock()",
        "endpoint.id == target_endpoint && !endpoint.is_reply_cap",
        "endpoint.id == reply_cap_id",
        "endpoint.is_reply_cap",
        "endpoint.owner == caller_task",
        "endpoint.reply_target == Some(target_endpoint)",
        "if !reply_is_linked",
    ] {
        assert!(
            helper.contains(required),
            "missing S318 helper authority token: {required}"
        );
    }
    let irq = helper.find("IrqGuard::new()").unwrap();
    let transaction = helper.find("IPC_TRANSACTION_LOCK.lock()").unwrap();
    let caller = helper.find("let caller_task").unwrap();
    let send = helper.find("current_endpoint_authority_is_live(").unwrap();
    let endpoints = helper.find("ENDPOINT_REGISTRY.lock()").unwrap();
    let reply = helper.find("let reply_is_linked").unwrap();
    assert!(
        irq < transaction
            && transaction < caller
            && caller < send
            && send < endpoints
            && endpoints < reply
    );
}
snippet sha256: c21dca0871cefile sha256: ad812f85594a
03 · Kapı kimlik kaydı

Operations sıra, kimlik ve başlık bağı

tam Operations kaydıL15184–L15244
website/src/lib/operations.ts::g8l-s318-qemu-s142-fault-cancelled-call-writer-authority-audit-partial
  {
    id: "g8l-s318-qemu-s142-fault-cancelled-call-writer-authority-audit-partial",
    date: "2026-08-27",
    sequence: 318,
    status: "passed",
    umbrella_status: "partial",
    title: "G8l: QEMU S142 fault-cancelled CALL writer-authority audit",
    summary:
      "S318 focused 15/15 PASS ile main.rs kaynak sırasındaki bir sonraki explicit mutable scheduler sınırını doğrular: run_qemu_s142_lower_el_fault_recovery içindeki iki ipc_kernel_call_and_wait writer'ından daha önceki fault-cancelled CALL. Nonzero controller, controller-owned normal Endpoint SEND authority, strict EL0 faulting-supervisor RECV grant, task-bound broker session/lease, immutable fault message ve linked cancelled reply writer'dan önce doğrulanır. Helper aynı IRQ/IPC transaction altında non-user caller SEND authority'sini, normal endpoint'i, linked reply'ı, optional receiver authority/deadline'ını ve park kapasitesini yeniden doğrular; CALL publication/park ve optional delivery tek transaction içindedir. Ordinary fatal lifecycle reply'ı retire eder, lease'i requeue eder, old lease'i stale yapar ve continuation yalnız exact InvalidCapability kabul eder; faulting supervisor daha sonraki S317 replacement CALL'den önce reclaim edilir. Writer authority yalnız model gate'inin exclusive lease'iyle mümkündür; reader lease'i writer'ı açmaz. main.rs 17 explicit writer / 8 previously audited / 8 remaining unaudited; S142 işlevi 2 / 0 ve tüm S142 aliasları source/model covered; production inventory 113 direct / 44 immutable guarded / 69 open writer olarak değişmez ve production exclusive wrapper, provider authority, whole-scheduler exclusion veya scheduler mutation üretilmez.",
    evidence: [
      "S318 focused kaynak/model kapısı iki bağımsız koşuda 15/15 PASS verdi: 130 B / SHA-256 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3.",
      "main.rs içindeki 17 explicit addr_of_mut!(crate::task::scheduler::SCHEDULER) sitesinin positions[8], kaynakta alttan dokuzuncu sınırı audit edilir. run_qemu_s142_lower_el_fault_recovery içindeki daha önceki fault-cancelled CALL kapanır; S142 işlevinde 0, main.rs genelinde 8 unaudited alias kalır.",
      "Nonzero controller, controller-owned normal Endpoint ENDPOINT_SEND authority, strict EL0 faulting supervisor'a exact ENDPOINT_RECV grant, task-bound broker session/lease, immutable fault IpcMessage ve controller-owned linked one-shot cancelled reply-cap writer'dan önce kurulur.",
      "ipc_kernel_call_and_wait exact endpoint id/generation, cancelled reply id ve immutable fault message'i alır. Ordinary fatal lifecycle cancelled reply'ı retire eder; broker pending=1/in_flight=0/acknowledged=1, sessions=3, crashes=2 ve recovered_inflight=2 olur; old lease StaleLease verir ve continuation yalnız exact InvalidCapability kabul eder.",
      "Helper IrqGuard ve IPC_TRANSACTION_LOCK altında nonzero non-user caller, canlı SEND authority, normal endpoint, linked reply, optional receiver authority/deadline ve ready/blocked kapasitesini yeniden doğrular. CALL publish/park, optional delivery ve aynı caller'ın saved GPR continuation'ı sıralıdır.",
      "Faulting supervisor exact reclaim ile RuntimePmm baseline'a döner ve daha sonraki S317 replacement CALL bundan sonra gelir. S142 içindeki iki explicit mutable aliasın ikisi de source/model düzeyinde kapsanmıştır.",
      "Model gate reader membership exclusive writer authority'yi ExclusiveBusy ile bloklar; reader bırakıldıktan sonra non-zero token'lı exclusive lease alınır. Wrong CPU InvalidCpu ile fail-closed kalır. Bu host/model evidence'tır.",
      "S317 authority preflight yeniden doğrulanır; pending S245 request korunur ve sonuç AwaitingWriterAuthority { guarded_sites: 44, writer_sites: 69 } olarak döner.",
      "Dört AArch64 profil derlemesi iki koşuda byte-equal exit 0 verdi: QEMU 110646 B / f9f7eb5f, RPi4 149371 B / 45c88b07, RPi5 464884 B / d4081ae3 ve RPi5+SMP 464826 B / 3524bcf0. Warning header'ları sırasıyla 291, 389, 995 ve 995'tir; zero-warning iddiası değildir.",
      "Birleşik board-rpi5,board-qemu özellikleri iki koşuda beklenen exit 101, 18590 B / 9a6c07b3, 17 error ve 22 warning header ile fail-closed kaldı.",
      "S238–S318 dependency matrisi iki koşuda 82 grup / 1154/1154 PASS; ham loglar 10582 B / aaad6444 ve 67fdab1f, süre-normalize özetler byte-equal 10746 B / a6dbb84dc3c3719e69dc18f404833512c8aef4ee668a28e03c53f16a37d61d6f. Bu production writer-authority invocation kanıtı değildir.",
      "Ortak make verify-qemu iki koşuda PASS verdi: 116222 B / 7baa14be ve 116139 B / 893d37c5; guest logları 2143107 B / 1b905369 ve 2136189 B / 91afa078. W^X 31/31, S271 GRAPH_ABSENT=YES, RuntimePmm baseline, EL0 x4096, IPC 20/20, koşu başına tek FATAL_TASK_EXIT, SEC5 ve 13 KERNEL_FAULTS=0 marker'ı korunur. Bu ortak smoke S318 production writer-authority invocation kanıtı değildir.",
      "Exact yedi tarihsel G8h assertion adıyla dışlandığında workspace iki koşuda 280 sonuç grubu / 2962 PASS / 7 filtered verdi: ham loglar 63900 B / eda19db5 ve 19ba0ad4, sonuç özetleri 26483 B / 37691503 ve 330e6bb2, süre-normalize 27041 B özet byte-equal / SHA-256 7b408301c39da6cd608412cb261b3a8f30ca27b71014dc2699313535aa514dc4. Filtresiz koşu exit 101, 59122 B / acc3bb0f ile frozen S96 exceptions.S identity kapısında RED kaldı; full-workspace GREEN iddia edilmez.",
      "S318 production exclusive wrapper, provider authority, whole-scheduler exclusion, QEMU fixture mutation veya scheduler mutation iddiası eklemez; physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S318=NO.",
    ],
    commands: [
      "cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s318_qemu_s142_fault_cancelled_call_writer_authority_audit -- --test-threads=1",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-qemu",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi4",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,smp",
      "cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,board-qemu",
      "make verify-qemu",
    ],
    terminalSessions: [
      {
        id: "g8l-s318-qemu-s142-fault-cancelled-call-writer-authority-audit",
        title: "G8l S318 QEMU S142 fault-cancelled CALL writer-authority audit",
        commandLines: [
          "cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s318_qemu_s142_fault_cancelled_call_writer_authority_audit -- --test-threads=1",
        ],
        outputLines: [
          "test result: ok; S318 focused 1 group / 15 passed; 0 failed",
          "repeat-stable quiet output: 130 B / 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3",
          "QEMU S142 fault-cancelled CALL writer authority remains model-only: reply retirement, broker lease requeue/staleness and exact InvalidCapability continuation precede the later replacement CALL; all S142 aliases are source/model covered, main.rs retains 8 unaudited aliases and all 69 production writer sites remain open",
          "dependency: S238–S318 · 82 groups · 1154/1154 PASS; workspace: 280 groups · 2962 PASS · 7 historical filtered",
        ],
        exitCode: 0,
        outputMode: "selected",
      },
    ],
    terminalSessionsNote:
      "S318 kaynak/model fail-closed authority boundary'sidir; production writer guard/migration, QEMU fixture mutation ve fiziksel/device execution claim edilmez.",
    limitations: [
      "S318 run_qemu_s142_lower_el_fault_recovery içindeki daha önceki fault-cancelled ipc_kernel_call_and_wait mutable scheduler aliasını audit eder; S142 source/model düzeyinde kapanırken main.rs genelinde 8 ve toplam 69 production writer site authority wrapper dışında açık kalır.",
      "Exclusive lease yalnız host/model gate'inde test edilir; production exclusive wrapper, provider authority ve whole-scheduler exclusion açık kalır.",
      "S238–S318 dependency matrisi exact 82 grup / 1154/1154 PASS'tir; bu production writer authority invocation kanıtı değildir.",
      "Filtresiz workspace frozen S96 identity kapısında RED'dir; workspace umbrella GREEN iddia edilmez.",
      "Supported-profile writer-authority runtime invocation, Generic SMP ve fiziksel RPi kabulü açık kalır; S318 physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S318=NO.",
    ],
  },
snippet sha256: 47e5442f84ecfile sha256: 9726dbf00f84
Focused test komutu
cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s318_qemu_s142_fault_cancelled_call_writer_authority_audit -- --test-threads=1
proof: docs/M8.1-RPi5-G8l-S318-QEMU-S142-Fault-Cancelled-Call-Writer-Authority-Audit-Proof.md
Registry schema v5 · generator website/scripts/generate-code-gates.mjs · Tam SHA-256: 91d38c7b6222f0b4c117be786454853543da55a160e543d9b951057cc20dcc06