docs: decision 4 settled — a loop with an open decision is not a loop

Per-sender range confinement at the provider, one serving endpoint: the
badge-scoped provider pattern the xHCI bus already uses (the per-client
device-token table), applied to blocks. Endpoint-per-volume would buy the
same enforced property only by inventing a multi-endpoint harness; it stays
available as a future refactor, same wire contract. The plan's flag-for-veto
is gone: nothing in the track waits on a choice.
This commit is contained in:
Daniel Samson
2026-08-09 16:34:04 +01:00
parent 60b41c0e82
commit b59f981c58
2 changed files with 23 additions and 21 deletions
+8 -16
View File
@@ -7,22 +7,14 @@
green at phase boundaries, every new test shown to fail against the old
behavior, one QEMU suite at a time, work on main.*
**One refinement of decision 4, flagged for sign-off rather than silently
applied.** The decision said endpoint-per-volume. The service harness serves one
endpoint per process, and kernel-ipc has no wait-on-many; a driver serving N
range endpoints would need threads or a multi-endpoint harness — real machinery,
none of it needed for the security property. The property ("a channel carries
exactly the authority it grants") is delivered instead by **per-sender range
confinement**: every packet already arrives with the kernel-stamped,
unforgeable badge; the storage driver keeps a per-badge range (set by the
volume manager, which spawned the filesystem process and knows its id) and
clamps-and-translates every transfer by the sender's range. A filesystem
process addresses volume-relative LBAs from 0; the provider adds the base —
offset translation at the provider, exactly the Fuchsia session-mapping shape,
and the FAT engine's `base_lba` code is deleted rather than moved.
Endpoint-per-volume can still arrive later with a multi-endpoint harness; the
wire contract does not change either way. **If this refinement is wrong, say so
before V2.**
**No open decisions.** Decision 4 is settled in the rationale as per-sender
range confinement at the provider on one serving endpoint — the badge-scoped
provider pattern the xHCI bus already uses, applied to blocks. The volume
manager sets each filesystem process's range; the driver clamps and translates
every transfer by the sender's kernel-stamped badge; filesystems address
volume-relative LBAs from 0 and the FAT engine's `base_lba` is deleted rather
than moved. Every other decision the phases below execute is recorded in the
rationale (decisions 1–8); nothing in this plan waits on a choice.
## V0 — `fs_unmount` ownership (the defect fix)