docs: decision 4 settled — a loop with an open decision is not a loop

Per-sender range confinement at the provider, one serving endpoint: the
badge-scoped provider pattern the xHCI bus already uses (the per-client
device-token table), applied to blocks. Endpoint-per-volume would buy the
same enforced property only by inventing a multi-endpoint harness; it stays
available as a future refactor, same wire contract. The plan's flag-for-veto
is gone: nothing in the track waits on a choice.
This commit is contained in:
Daniel Samson
2026-08-09 16:34:04 +01:00
parent 60b41c0e82
commit b59f981c58
2 changed files with 23 additions and 21 deletions
@@ -172,11 +172,21 @@ matrix-proven shape; genuinely open.
3. **One filesystem process per volume** (fat's binary becomes "the FAT 3. **One filesystem process per volume** (fat's binary becomes "the FAT
implementation", spawned per FAT volume). Recommendation: yes — it extends implementation", spawned per FAT volume). Recommendation: yes — it extends
recompile-and-restart-live to filesystems and isolates corrupt media. recompile-and-restart-live to filesystems and isolates corrupt media.
4. **Sub-range addressing**: `target` ids on the storage endpoint versus one 4. **Sub-range addressing — SETTLED as per-sender confinement at the
endpoint per volume handed out by the driver. Endpoint-per-volume matches provider, one serving endpoint.** The deciding argument is precedent: the
the establishment-plane machinery (a channel per party, caps at xHCI bus already serves every class driver on one endpoint with authority
establishment) and keeps per-client badge scoping simple. Recommendation: scoped by the kernel-stamped badge (the per-client device-token table) —
endpoint per volume. that IS danos's provider pattern, and per-badge range confinement is the
same pattern applied to blocks. The volume manager sets each filesystem
process's range on the driver; the driver clamps AND translates every
transfer by the sender's range, so filesystems address volume-relative
LBAs from 0 and the FAT engine's `base_lba` is deleted rather than moved.
The enforcement point (the clamp at the provider, never in the consumer)
is what carries the security property; endpoint-per-volume would deliver
the same property only by inventing a multi-endpoint harness the pattern
does not need. It stays available as a future refactor if a multi-endpoint
harness ever exists for other reasons; the wire contract is identical
either way.
5. **`fs_unmount` ownership** — a defect fix more than a decision. 5. **`fs_unmount` ownership** — a defect fix more than a decision.
6. **Later, kept open**: the shm-ring data plane (communication.md already 6. **Later, kept open**: the shm-ring data plane (communication.md already
names it as the 256-byte ceiling's unlock — Fuchsia's FIFO+VMO is the names it as the 256-byte ceiling's unlock — Fuchsia's FIFO+VMO is the
+8 -16
View File
@@ -7,22 +7,14 @@
green at phase boundaries, every new test shown to fail against the old green at phase boundaries, every new test shown to fail against the old
behavior, one QEMU suite at a time, work on main.* behavior, one QEMU suite at a time, work on main.*
**One refinement of decision 4, flagged for sign-off rather than silently **No open decisions.** Decision 4 is settled in the rationale as per-sender
applied.** The decision said endpoint-per-volume. The service harness serves one range confinement at the provider on one serving endpoint — the badge-scoped
endpoint per process, and kernel-ipc has no wait-on-many; a driver serving N provider pattern the xHCI bus already uses, applied to blocks. The volume
range endpoints would need threads or a multi-endpoint harness — real machinery, manager sets each filesystem process's range; the driver clamps and translates
none of it needed for the security property. The property ("a channel carries every transfer by the sender's kernel-stamped badge; filesystems address
exactly the authority it grants") is delivered instead by **per-sender range volume-relative LBAs from 0 and the FAT engine's `base_lba` is deleted rather
confinement**: every packet already arrives with the kernel-stamped, than moved. Every other decision the phases below execute is recorded in the
unforgeable badge; the storage driver keeps a per-badge range (set by the rationale (decisions 1–8); nothing in this plan waits on a choice.
volume manager, which spawned the filesystem process and knows its id) and
clamps-and-translates every transfer by the sender's range. A filesystem
process addresses volume-relative LBAs from 0; the provider adds the base —
offset translation at the provider, exactly the Fuchsia session-mapping shape,
and the FAT engine's `base_lba` code is deleted rather than moved.
Endpoint-per-volume can still arrive later with a multi-endpoint harness; the
wire contract does not change either way. **If this refinement is wrong, say so
before V2.**
## V0 — `fs_unmount` ownership (the defect fix) ## V0 — `fs_unmount` ownership (the defect fix)