This commit is contained in:
2026-08-18 09:20:44 +02:00
commit b826cd721a
522 changed files with 93730 additions and 0 deletions
+51
View File
@@ -0,0 +1,51 @@
# P15-030 Stage0 Decision
Status: `STOP`. B37a is `STOP-NO-SOURCE`.
G08 is replayed against frozen BASE
`3e1d26a53eef30ecadc3407444d214feac861cb4`. P15-030 may proceed only if all
four conditions pass: an existing diagnostic or operational consumer, bounded
atomic counters, a FreeBSD 15 native `sysctl_ctx` lifecycle that closes every
required teardown path, and a stable privileged-read ABI that leaks no
unauthenticated metadata.
The consumer condition is evaluated first because no prototype can create its
own justification. The bounded inventory covers all 3,206 tracked paths under
`repo-pre-15` and `planning/pre15` at BASE, without reading
`planning/pre15/introduction.md` or treating this addendum as evidence. It
finds 54 broad sysctl/sysfs references: 31 planning or audit records, one
historical evidence record, 19 test-only paths, and three project reports or
documents. There are zero production or operations paths and zero qualifying
consumer declarations.
A qualifying future declaration must use schema
`pre15-p15-030-consumer-v1`, identify a versioned diagnostic or operational
consumer in production use, name its owner, workflow, deployment reference,
privileged-read access mode, and consumed signals, and bind a tracked non-test
implementation by path and SHA-256. The implementation must actually invoke
sysctl and reference each declared signal. A hypothetical future user, Linux
sysfs analogy, generic observability value, test script, or gate prototype is
rejected. If a declaration appears, this STOP-only run refuses false GO and
requires the FreeBSD 15 native lifecycle prototype before source authorization.
The first condition is `STOP`, so the bounded atomic-counter prototype,
FreeBSD 15 parse-failure/normal-unmount/forced-unmount/delayed-handler/
`sysctl_ctx_free`-failure lifecycle work, and permissions/ABI/leak probes are
all `NOT_RUN`. No host model is reported as native evidence and no prototype,
KLD, QEMU process, feature test, or smoke test is built or run.
P15-068 and B37b also close as `STOP` / `STOP-NO-SOURCE` because the plan
explicitly requires the P15-030 transport. This is capability dependency
closure, not an independent decision about UUID or volume-label formatting.
The identity oracle is `NOT_RUN`; no P15-068 gate addendum and no second sysctl
lifecycle are created.
The committed replay evidence is recorded under
`planning/pre15/evidence/20260816T041649Z-G08-P15-030/`. The gate owns one
temporary directory, uses a 60-second internal timeout plus the recorded outer
timeout, records argv, scope/source/addendum hashes, result, and cleanup, and
rejects an existing output directory.
No production source, B37a/B37b case, fixture, or empty commit is created.
Protected PID 26318, port 9222, and the immutable base image are outside the
gate and are not addressed or hashed.