S293 · SOURCE-BOUND GATE EVIDENCE
G8l: task IPC lifecycle notification-grant revoke writer-authority audit
Operations --test hedefi → test hedefiyle aynı adlı uygulama/model modülü → kaynak kesiti Bu sayfa yalnız S293 kapısına aittir; komşu kapıların kaynakları bu kabulün içine katılmaz.
S293Focused kod testiOperations id exactsource SHA exacttest target exact
operation: g8l-s293-task-ipc-lifecycle-notification-grant-revoke-writer-authority-audit-partial
uygulama/model · focused test · Operations · 3 exact excerpt
sequence-bound=true · implementation-bound=true
01 · Testin bağlı olduğu uygulama/model kodu
Kapının yürüttüğü gerçek kaynak
tam Rust öğesiL22–L90
kernel/src/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s293_task_ipc_lifecycle_notification_grant_revoke_writer_authority_audit.rs::S293_WHOLE_SCHEDULER_GUARDED_SITES
pub const S293_WRITER_BOUNDARY_SITES: usize = 1;
pub const S293_WRITER_AUTHORITY_SITES: usize = 0;
pub const S293_DIRECT_SCHEDULER_ACCESS_SITES: usize = S292_DIRECT_SCHEDULER_ACCESS_SITES;
pub const S293_IMMUTABLE_READ_SITES: usize = S292_IMMUTABLE_READ_SITES;
pub const S293_WHOLE_SCHEDULER_GUARDED_SITES: usize = S292_WHOLE_SCHEDULER_GUARDED_SITES;
pub const S293_WHOLE_SCHEDULER_UNROUTED_SITES: usize = S292_WHOLE_SCHEDULER_UNROUTED_SITES;
pub const S293_OPEN_WRITER_SITES: usize = S292_OPEN_WRITER_SITES;
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS293SchedulerWriterAuthorityAuditOutcome {
Idle,
AwaitingWriterAuthority {
request_id: u64,
guarded_sites: usize,
writer_sites: usize,
},
}
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub enum G8lS293SchedulerWriterAuthorityAuditError {
S292(G8lS292SchedulerWriterAuthorityAuditError),
S245(G8lS245ExclusionAdmissionRequestError),
PriorCoverageDrift {
guarded_sites: usize,
unrouted_sites: usize,
},
}
/// Revalidate the prior fail-closed authority boundary without taking
/// admission or constructing a production exclusive wrapper.
pub fn preflight_s293_scheduler_writer_authority(
caller_cpu: usize,
request: Option<G8lS245WholeSchedulerExclusionAdmissionRequestView>,
) -> Result<G8lS293SchedulerWriterAuthorityAuditOutcome, G8lS293SchedulerWriterAuthorityAuditError>
{
match preflight_s292_scheduler_writer_authority(caller_cpu, request)
.map_err(G8lS293SchedulerWriterAuthorityAuditError::S292)?
{
G8lS292SchedulerWriterAuthorityAuditOutcome::Idle => {
Ok(G8lS293SchedulerWriterAuthorityAuditOutcome::Idle)
}
G8lS292SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
request_id,
guarded_sites,
writer_sites,
} if guarded_sites == S293_WHOLE_SCHEDULER_GUARDED_SITES
&& writer_sites == S293_OPEN_WRITER_SITES =>
{
Ok(
G8lS293SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
request_id,
guarded_sites,
writer_sites,
},
)
}
G8lS292SchedulerWriterAuthorityAuditOutcome::AwaitingWriterAuthority {
guarded_sites,
writer_sites: _,
..
} => Err(
G8lS293SchedulerWriterAuthorityAuditError::PriorCoverageDrift {
guarded_sites,
unrouted_sites: S293_DIRECT_SCHEDULER_ACCESS_SITES - guarded_sites,
},
),
}
}snippet sha256: 2839e0b1eb3e…file sha256: 822699dfe77e…
02 · Doğrulayan test kodu
Operations komutuna bağlı focused test
tam Rust öğesiL31–L41
simulation/tests/g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s293_task_ipc_lifecycle_notification_grant_revoke_writer_authority_audit.rs::s293_keeps_task_ipc_notification_grant_revoke_writer_open_until_exclusive_authority_exists
#[test]
fn s293_keeps_task_ipc_notification_grant_revoke_writer_open_until_exclusive_authority_exists() {
assert_eq!(S293_WRITER_BOUNDARY_SITES, 1);
assert_eq!(S293_WRITER_AUTHORITY_SITES, 0);
assert_eq!(S293_DIRECT_SCHEDULER_ACCESS_SITES, 113);
assert_eq!(S293_IMMUTABLE_READ_SITES, 44);
assert_eq!(S293_WHOLE_SCHEDULER_GUARDED_SITES, 44);
assert_eq!(S293_WHOLE_SCHEDULER_UNROUTED_SITES, 69);
assert_eq!(S293_OPEN_WRITER_SITES, 69);
}snippet sha256: 951653099d1d…file sha256: b4a73cdab103…
03 · Kapı kimlik kaydı
Operations sıra, kimlik ve başlık bağı
tam Operations kaydıL16680–L16738
website/src/lib/operations.ts::g8l-s293-task-ipc-lifecycle-notification-grant-revoke-writer-authority-audit-partial
{
id: "g8l-s293-task-ipc-lifecycle-notification-grant-revoke-writer-authority-audit-partial",
date: "2026-08-26",
sequence: 293,
status: "passed",
umbrella_status: "partial",
title:
"G8l: task IPC lifecycle notification-grant revoke writer-authority audit",
summary:
"S293 focused 15/15 PASS ile teardown_task_ipc_lifecycle içindeki üçüncü ve son explicit scheduler writer erişimini, derived notification-grant exact-revoke sınırını kaynakta doğrular. Immutable notification scan ve S260 reader altında typed parent-derived grant owned tuple olarak kopyalanır; reader bırakıldıktan sonra exact notification object yeniden bulunur, waiter/deadline iptali yapılır ve grant exact revoke edilir. Böylece helper'ın üç writer boundary'sinin kaynak/model audit'i tamamlanır; bu production migration değildir. Writer authority yalnız model gate'inin exclusive lease'iyle mümkündür, reader lease'i writer'ı açmaz. Production inventory 113 direct / 44 immutable guarded / 69 open writer olarak değişmez ve production exclusive wrapper, provider authority, whole-scheduler exclusion veya scheduler mutation üretilmez.",
evidence: [
"S293 focused kaynak/model kapısı iki bağımsız koşuda 15/15 PASS verdi: 130 B / SHA-256 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3.",
"teardown_task_ipc_lifecycle içindeki üç addr_of_mut!(crate::task::scheduler::SCHEDULER) writer'dan üçüncü ve son revoke_cap_for_task_exact(&grant) sınırı audit edilir. NOTIFICATION_REGISTRY immutable scan, S260 scheduler reader, capability_for_task(owner, object.id()), Notification kind + exact parent kontrolü, owned (object.id(), capability) tuple, reader drop, deadline ve mutable notification registry kilitleri, exact object revalidation, preflight_notification_wait_graph, owner-matching cancel_waiter_exact/cancel_exact, exact grant revoke ve count commit sırası kaynakta görünür. Helper'da audit edilmemiş writer boundary kalmaz.",
"Model gate reader membership exclusive writer authority'yi ExclusiveBusy ile bloklar; reader bırakıldıktan sonra non-zero token'lı exclusive lease alınır. Bu host/model evidence'tır.",
"S292 authority preflight yeniden doğrulanır; pending S245 request korunur ve sonuç AwaitingWriterAuthority { guarded_sites: 44, writer_sites: 69 } olarak döner.",
"Dört AArch64 profil derlemesi iki koşuda byte-equal exit 0 verdi: QEMU 110646 B / e3e36978, RPi4 149371 B / 9c3edc51, RPi5 398926 B / 89602345 ve RPi5+SMP 398868 B / 61a3a312. Warning header'ları sırasıyla 291, 389, 810 ve 810'dur; zero-warning iddiası değildir.",
"Birleşik board-rpi5,board-qemu özellikleri iki koşuda beklenen exit 101, 18590 B / 4c811f46, 17 error ve 22 warning header ile fail-closed kaldı; S293 writer boundary'si iki board profilinin birlikte etkinleşmesini açmaz.",
"S238–S293 dependency matrisi iki koşuda 57 grup / 779/779 PASS; ham loglar 7332 B / f05ef41e ve 3cc14372, süre-normalize özet 7446 B byte-equal / b47a4d12f78893bcdfecbc756b37e7389a88689037750285f60c5fe2771994cb. Bu production writer-authority invocation kanıtı değildir.",
"Ortak make verify-qemu iki koşuda PASS verdi: 116222 B / 3f62d43a ve 116139 B / 20a8da4f; W^X 31/31, S271 GRAPH_ABSENT=YES, RuntimePmm baseline, EL0 x4096, IPC 20/20, tek beklenen S142 fatal containment ve SEC5 korunur. Bu ortak smoke S293 production writer invocation kanıtı değildir.",
"Exact yedi tarihsel G8h assertion adıyla dışlandığında workspace iki koşuda 255 sonuç grubu / 2562 PASS / 7 filtered verdi: ham loglar 60625 B / 69bb1143 ve b1f965fd, süre-normalize 24616 B özet byte-equal / SHA-256 72fc0528192262b08965406986c25d1b52bbbef86a1e7f6607d8e5ca11056627. Filtresiz koşu exit 101, 55847 B / 9622ac55 ile frozen S96 exceptions.S identity kapısında RED kaldı; full-workspace GREEN iddia edilmez.",
"S293 production exclusive wrapper, provider authority, whole-scheduler exclusion, QEMU runtime fixture veya scheduler mutation iddiası eklemez; physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S293=NO.",
],
commands: [
"cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s293_task_ipc_lifecycle_notification_grant_revoke_writer_authority_audit -- --test-threads=1",
"cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-qemu",
"cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi4",
"cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5",
"cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,smp",
"cargo check --quiet -p aselsan_kernel --target aarch64-unknown-none --no-default-features --features board-rpi5,board-qemu",
"make verify-qemu",
],
terminalSessions: [
{
id: "g8l-s293-task-ipc-lifecycle-notification-grant-revoke-writer-authority-audit",
title:
"G8l S293 task IPC lifecycle notification-grant revoke writer-authority audit",
commandLines: [
"cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s293_task_ipc_lifecycle_notification_grant_revoke_writer_authority_audit -- --test-threads=1",
],
outputLines: [
"test result: ok; S293 focused 1 group / 15 passed; 0 failed",
"repeat-stable quiet output: 130 B / 0447f2fe9dc6fdf30815a6962cf23d978425e51bef2acde1efb27e5da13a78b3",
"task IPC lifecycle notification-grant revoke writer authority remains model-only: reader blocks exclusive lease; all three lifecycle boundaries are source/model audited while 69 production writer sites remain open",
"dependency: S238–S293 · 57 groups · 779/779 PASS; workspace: 255 groups · 2562 PASS · 7 historical filtered",
],
exitCode: 0,
outputMode: "selected",
},
],
terminalSessionsNote:
"S293 kaynak/model fail-closed authority boundary'sidir; production writer guard/migration, QEMU fixture mutation ve fiziksel/device execution claim edilmez.",
limitations: [
"S293 teardown_task_ipc_lifecycle içindeki üçüncü ve son notification-grant exact-revoke writer sınırını audit eder; helper'ın üç writer boundary'sinde kaynak/model audit coverage tamamdır fakat toplam 69 production writer site açık kalır.",
"Exclusive lease yalnız host/model gate'inde test edilir; production exclusive wrapper, provider authority ve whole-scheduler exclusion açık kalır.",
"S238–S293 dependency matrisi exact 57 grup / 779/779 PASS'tir; bu production writer authority invocation kanıtı değildir.",
"Filtresiz workspace frozen S96 identity kapısında RED'dir; workspace umbrella GREEN iddia edilmez.",
"Supported-profile runtime invocation, Generic SMP ve fiziksel RPi kabulü açık kalır; S293 physical/device operations=0 ve RUNBOOK_EXECUTED_IN_S293=NO.",
],
},snippet sha256: 4ae57fb87d34…file sha256: 9726dbf00f84…
Focused test komutu
cargo test --quiet -p aselsan_microkernel_simulation --test g8l_target_dispatch_scheduler_owner_scheduler_mutation_production_migration_lifecycle_s293_task_ipc_lifecycle_notification_grant_revoke_writer_authority_audit -- --test-threads=1proof: docs/M8.1-RPi5-G8l-S293-Task-IPC-Lifecycle-Notification-Grant-Revoke-Writer-Authority-Audit-Proof.md
Registry schema v5 · generator
website/scripts/generate-code-gates.mjs · Tam SHA-256: 3050638b71a684d8f8f947a8a6faa237a17fa8db5dc0db04fb207b668b462af9