This commit is contained in:
2026-08-18 09:20:44 +02:00
commit b826cd721a
522 changed files with 93730 additions and 0 deletions
+45
View File
@@ -0,0 +1,45 @@
# P15-031 Stage0 Decision
Status: `STOP`. B38 is `STOP-NO-SOURCE`.
G08 is replayed against frozen BASE
`0f696ad1e2c6628022d02ce52d07eb66704769dd`. P15-031 may proceed only if all
five conditions pass: an existing project diagnostic consumer that has
actually captured the complete predeclared mount/map/vget/xattr/decode/cache
schema through FreeBSD DTrace/SDT or a justified KTR path; no pointer,
credential, or unauthenticated metadata leakage; an owned-temp FreeBSD 15
prototype with exact fields/counts and closed failure/detach/unload lifecycle;
disabled `WITH_ZSTDIO=0/1` builds with no new undefined symbols; and a 10-run
hot-path median regression of at most 3% with retained interleaved controls.
The consumer condition is evaluated first because neither a gate prototype nor
a proposed B38 test can create its own project need. The bounded inventory
covers all 3,243 tracked paths under `repo-pre-15` and `planning/pre15` at
BASE, without reading `planning/pre15/introduction.md` or treating this
addendum as evidence. It finds 33 native-tracing references: 16 planning or
audit records, three historical evidence files, 10 test-only paths, and four
reports or documents. There are zero production/operations paths, zero
consumer manifests, and zero qualifying consumers.
A future declaration uses schema `pre15-p15-031-consumer-v1` under
`repo-pre-15/diagnostics/`. It binds a versioned production implementation and
actual FreeBSD 15 capture by path and SHA-256, identifies owner/workflow/
deployment, records privileged access and DTrace/SDT or justified KTR
transport, binds the complete event-schema hash, and records a positive count
for every event. The gate rejects a hypothetical maintainer, Linux
tracepoints, generic usefulness, a proposed test, its own prototype, or merely
installed `dtrace`. If an approved declaration appears, this STOP-only version
refuses false GO and requires the remaining native prototype, privacy, build,
and benchmark stages before source authorization.
The first condition is `STOP`, so privacy execution, prototype generation,
`WITH_ZSTDIO=0/1` builds, undefined-symbol comparison, the 10-run benchmark,
D/H/K0/K1, targeted QEMU TC178, full feature, and smoke are all `NOT_RUN`.
The gate's seven decision controls prove that GO is emitted only when all five
conditions are `PASS`; no benchmark samples or later-stage metrics are
fabricated.
No `src/erofs_trace.h`, trace callsite, `src/Makefile` change,
`tests/pre15/cases/B38-trace.sh`, source commit, or empty commit is created.
Protected PID 26318, port 9222, and the immutable base image are outside this
STOP path and are not addressed or hashed.