Files
erofs-freebsd-out-tree/docs/pre15-stage0/P15-030.md
T
2026-08-18 09:20:44 +02:00

2.8 KiB

P15-030 Stage0 Decision

Status: STOP. B37a is STOP-NO-SOURCE.

G08 is replayed against frozen BASE 3e1d26a53eef30ecadc3407444d214feac861cb4. P15-030 may proceed only if all four conditions pass: an existing diagnostic or operational consumer, bounded atomic counters, a FreeBSD 15 native sysctl_ctx lifecycle that closes every required teardown path, and a stable privileged-read ABI that leaks no unauthenticated metadata.

The consumer condition is evaluated first because no prototype can create its own justification. The bounded inventory covers all 3,206 tracked paths under repo-pre-15 and planning/pre15 at BASE, without reading planning/pre15/introduction.md or treating this addendum as evidence. It finds 54 broad sysctl/sysfs references: 31 planning or audit records, one historical evidence record, 19 test-only paths, and three project reports or documents. There are zero production or operations paths and zero qualifying consumer declarations.

A qualifying future declaration must use schema pre15-p15-030-consumer-v1, identify a versioned diagnostic or operational consumer in production use, name its owner, workflow, deployment reference, privileged-read access mode, and consumed signals, and bind a tracked non-test implementation by path and SHA-256. The implementation must actually invoke sysctl and reference each declared signal. A hypothetical future user, Linux sysfs analogy, generic observability value, test script, or gate prototype is rejected. If a declaration appears, this STOP-only run refuses false GO and requires the FreeBSD 15 native lifecycle prototype before source authorization.

The first condition is STOP, so the bounded atomic-counter prototype, FreeBSD 15 parse-failure/normal-unmount/forced-unmount/delayed-handler/ sysctl_ctx_free-failure lifecycle work, and permissions/ABI/leak probes are all NOT_RUN. No host model is reported as native evidence and no prototype, KLD, QEMU process, feature test, or smoke test is built or run.

P15-068 and B37b also close as STOP / STOP-NO-SOURCE because the plan explicitly requires the P15-030 transport. This is capability dependency closure, not an independent decision about UUID or volume-label formatting. The identity oracle is NOT_RUN; no P15-068 gate addendum and no second sysctl lifecycle are created.

The committed replay evidence is recorded under planning/pre15/evidence/20260816T041649Z-G08-P15-030/. The gate owns one temporary directory, uses a 60-second internal timeout plus the recorded outer timeout, records argv, scope/source/addendum hashes, result, and cleanup, and rejects an existing output directory.

No production source, B37a/B37b case, fixture, or empty commit is created. Protected PID 26318, port 9222, and the immutable base image are outside the gate and are not addressed or hashed.