Last verified: 2026-10-07 09:01:56 Asia/Shanghai (UTC+08:00) / 2026-10-07 01:01:56 UTC
This is a bounded, point-in-time source and existing-evidence review. The roadmap, architecture, testing guide and contribution guidance remain authoritative. No completion percentage or release-readiness claim is implied.
Source review is pinned to db18af34, observed October 7 00:57 UTC. The previous reviewed source was 6f885ebb. Activity below runs from the previous report publication, October 6 01:06:21 UTC, through today's collection and excludes this new proposal.
| Measure | Verified state |
|---|---|
| Open ordinary issues | 18, up one; 14 epics, no milestones, only #12 assigned |
| Open PRs | 2: #589 and #605; yesterday's #525 and #565 merged |
| PRs merged in activity window | 40 including report-only #568; 39 after that exclusion |
| Closed PRs without merge | 0 |
| Ordinary issue activity | #580 opened; no other ordinary issue updated |
| Raw source inventory | 198 distinct commits; 557 changed file paths |
| Path classification | 385 modified, 170 added, 2 removed; no submodule revision changes |
| Report-only exclusion | 196 commits and 556 paths, excluding #568's content commit, merge commit and PROGRESS.md |
| Confirmed defects | One HighC forwarding miscompile fixed below; four-site Darwin compile blocker already repaired in open #589 |
| New code fixes from this review | 1 minimal HighC repair plus one focused regression, statically inspected only |
| Qualification | Current dev has observed failures and unfinished coverage; no complete green gate |
The source comparison was enumerated as 100 + 98 commits, then an empty third page. GitHub's comparison file list caps at 300. Path counts therefore use complete recursive trees of 6,099 and 6,278 entries, neither truncated, excluding directories and comparing path/blob identity; renames count as old/new paths. This inventory is not an exhaustive review count or a count of implementation-only commits.
#568 merged at October 6 05:42:05 UTC. Both 6e2272a1 and its 36e8142c merge change only PROGRESS.md and are excluded from substantive advancement. The entire current 135,547-character tracker, including manual edits and earlier history, is preserved below.
- Parallel checked CPUs/MMIO atomicity #565 and bounded Darwin services #525 merged. Darwin removal/rename #581, Windows preemption #582 and priorities #602 followed. Their broad concurrency/OS semantics are outside today's bounded audit.
- Linux trailing-slash and filesystem query contracts landed in #570 and #572. Process-observation unpacking #579, direct x64 execution #594, and execution watches #597 are delivered source, not independently established runtime coverage.
- Inference and solver work includes predicate retention #590, branch-local encodings #592, pristine finite-domain encodings #598, prepared keys #599, inline SAT watches #600, root queues #601 and reference bounds #604.
- ARM64 tail-frame checks #606, scalar C declarations/literals #607, and shared absolute dispatch #608 merged. HighIR forwarding was tightened at the pinned head. Individual author corpus/semantic results cannot establish this combined head's qualification.
- Issue #580 requests real end-to-end latency, memory and scaling baselines. It remains open, unassigned and without comments. Its measurement contract is future work, not a benchmark result.
Mode: Source, interfaces, relevant callers, declared regressions and existing CI only. No project execution, build, test, benchmark, repository script, formatter/linter or dynamic analyzer was run. No workflow was dispatched or rerun. No CI-skip marker is added; ordinary automatic checks may run.
Reviewed the full lib/analysis/core/{FiniteValues.h,FiniteValues.cpp,FiniteQueryCache.h,FiniteQueryCache.cpp,FrameOffsets.cpp}; focused clone contracts in include/neverd/solver/BitVectorSolver.h:150–168, lib/solver/bv/BitVectorSolver.cpp:141–154 and lib/solver/sat/SatSolver.cpp:340–350; and regression bodies in FiniteValuesTests.cpp:21–92,650–747, FiniteQueryCacheTests.cpp:399–506, and FrameOffsetsTests.cpp:393–434 under unittests/devirtualization.
- Finite projection validation checks nonzero/in-range references and widths before constant fast paths or node access. The existing #604 repair is present. Invalid input cannot invoke the observer, spend a solver query or create nodes through these entry points.
FiniteDomainEncodingfixes the context/settings, forces model construction and stores only a pristine predicate encoding. Each projection/search mutates an independent solver copy; replacing the predicate releases the old template. Clone eligibility rejects searched or failed encoding state. Full internal SAT/watch-list ownership was not audited.- Enumeration requests explicit joint model variables, refuses missing values and observer abandonment, and still requires the final UNSAT query. Budget/unknown failures return no partial tuples. Encoding reuse is distinct from reuse of a completed mathematical domain.
- Prepared keys own complete serialized keys and projection widths without retaining context references. Moves invalidate the source token. Serialization retains predicate, projection order, limit, widths, operator payloads, constant bits and consistent variable sharing. Only Complete/TooManyValues results are admitted; malformed, oversized and incomplete entries are refused before eviction.
FrameOffsetsprepares once, looks up and stores the same token. Its symbolic addend rewrite preserves full modular dependence on the root/predicate under a shared 16-visit budget. Singleton proof, node checks and infeasible/nonunique/invalid/budget distinctions remain explicit; this does not independently prove reachability or memory accessibility.- Declared regressions cover invalid predicate/projection references before fast paths; fresh/copy tuple and observer equivalence, exact/one-short budgets, predicate replacement and failed-projection isolation; prepared-key context destruction, renaming, moves, storage limits, projection order and empty/nonunique domains. These tests were read, not executed.
Result: No additional statically proven defect in this boundary; no speculative code change. This is not a proof of all recovery callers, the complete solver or native refinement.
Confirmed and fixed: collectValueForward recognizes Store statements and assignments to scalar/stack variables, but omitted the supported Assign-to-Load memory-write representation. For store(slot, x); t1 = load(slot); assign(load(slot), 5); return t1, it could replace the captured value with a fresh load after the overwrite, returning 5 instead of x. This is established by the source/control flow, not by executing the example.
- The old clobber check lacks this write form. Statement emission and existing
HighCStoreForwardingTests.cpp:651–674explicitly support it. - Earlier store forwarding refuses Assign-to-Load as an immutable-slot sequence; liveness/frame-write cleanup retain the overwrite and observed load. A pure-load candidate bypasses the later adjacency gate. The issue also exists in parent
fc969e8cf77f1371c2443000c76c0cddf4111093; the pinned head's scalar-copy repair does not cover it. - Fix a6468b80 classifies both statement forms through the existing address/overlap check, using the assignment destination's access width. It preserves the existing alias policy and changes no shared IR or LLVMC behavior.
- Added
HighValueForward.SlotLoadStaysBeforeAnAssignmentToItsSlotto the already-registeredNeverDHighControlFlowTests. It checks the retained temporary and declares O0/O2 emitted-C behavior for inputs 7 and 9 using the existing helper. Neither emitter nor regression was run. - #589 and #605 touch neither changed file; there is no existing unmerged related HighC proposal to reuse.
Reviewed ranges under lib/backend/c: HighC/HighCFuncWriter.cpp:324–435,946–1115,2330–2585,2826–3673,4720–4869; HighC/HighCExprWriter.cpp:84–154,1040–1090,2470–2520,3176–3204,3351–3364,3914–4055; HighC/HighCStmtWriter.cpp:282–555,3195–3344; HighC/HighCEmitter.cpp:2117–2245; pass/HighC/HighCStoreForwarding.cpp:34–210, HighCDeadStoreAnalysis.cpp:201–525 and HighCVoidAnalysis.cpp:316–346. Also reviewed HighIR statement/expression declarations, relevant HighCWriter/HighCPasses declarations, all HighValueForwardTests.cpp, HighCStoreForwardingTests.cpp:516–735, target registration and the parent's forwarding range.
Limits: No second HighC defect or corresponding LLVMC defect was established. Other forwarding passes, address-taken scalar effects, complete alias analysis and end-to-end native equivalence are not exhaustively proven.
Existing Linux CI reports conflicting initializer-list element types at unittests/emulation/DarwinFileTests.cpp:1076 and DarwinVectorTests.cpp:152,162,271. Static inspection confirms the cause: braced range initializers mix uint64_t/UINT64_MAX, which this Linux compiler defines as unsigned long, with ULL expressions, which are unsigned long long. The declared range variable does not select the initializer-list's element type. This is a compile blocker before the tests run, not evidence of failing Darwin runtime semantics.
All four type corrections already exist in #589, head dbb93b662f41b71b34ac76ac81833a977d04e66c: explicit uint64_t operands in DarwinFileTests.cpp and DarwinVectorTests.cpp. That branch is unmerged. Its existing exact-head Linux default-target build passed before later tests failed, supporting the compile repair on that PR only. No duplicate repair was created; this does not establish a completed dev build.
Re-read lib/sdk/capi/NeverDCAPIBench.cpp:58–140 at the pinned source; the blob is unchanged from the previous review. Loading still precedes T0Total, and LowIR, MedIR, HighIR and LLVM still use separate pipeline runs. Their total is not one load-to-final-output operation. #580 remains the relevant acceptance task: preserve completion denominators and strict semantics while measuring production workflows. No latency, memory, scaling improvement or regression is inferred from source inspection.
At October 7 01:01:56 UTC, db18af34bbac577289a83896c142eebaa4ac108d had four all-event workflows: main CI and Mobile Decompilation running, LLVM Style successful, Mobile Real Applications skipped. 19 checks: four successful, two failed, three running, ten skipped. Workflow and check collections used 100/page and explicitly empty second pages. Zero legacy commit statuses were returned; their empty aggregate “pending” is not an extra running check.
- Main Linux failed its default-target build at 00:53:16 UTC on the four Darwin initializer-list type errors above. Tests did not run in this leg.
- Mobile macOS failed at 00:15:02 UTC: Objective-C scalar, calls/Blocks and Swift source recovery rejected conditional or mutating preprocessor directives. Subsequent single-session parity had missing output evidence. No runtime root cause or speculative fix is inferred.
- Ubuntu mobile and both Windows caller-context jobs passed. Main macOS/Windows and mobile Windows were still running. A partial mobile pass does not establish integrated/native aggregate success.
- Real applications: all nine jobs, including release qualification, skipped. No actual current-head application-recovery/reconstruction/behavior qualification was obtained.
#589, head dbb93b662f41b71b34ac76ac81833a977d04e66c: open, non-draft, mergeable at the metadata sample. Four workflows: main/mobile running, style cancelled, Python SDK queued. Fifteen checks: eight success, one failure, one cancelled, one skipped, three running, one queued.
- Linux default-target build passed, but the job later failed at 01:00:50 UTC. Existing focused mobile-native artifact
11454033213selected/reported 522 tests: 521 passed, one failed.MachOInteriorCodePointerCFG.IndexedAbsoluteRootsKeepOwnershipAndRelayRejectionsexpected INDIR_CALL atMachOPointerRelocationBoundaryTests.cpp:7854and did not find it in six indexed cases. - Existing Linux CTest artifact
11453418469selected 69,734 registrations, reported four (two pass, two fail for the same Mach-O test under two registrations), and left 69,730 without results. Missing registrations are not passes or independent defect counts. - Mobile macOS passed at 00:37:08 UTC. Its log verifies scalar 22 methods/141 matching results, calls 21/134, and Swift 25 native bodies plus nine projections/858 checks for each variant, plus all 12 single-session cases. These are this PR's observed results, not transferable to dev.
- Ubuntu mobile, Windows caller-context and Python 3.10–3.13 passed; Python 3.14 remained queued. Main macOS/Windows and mobile Windows were incomplete.
- The description's local 1,413 Darwin registrations (897 pass, 516 unavailable-backend skips), 210 C/CLI and 33 native workloads are author-reported. It explicitly leaves physical iOS, Intel HVF and complete remote merge CI separate. Overlapping counts are not added.
#605, head afd6776df99001537a237f257c5bf3390e3a17bf: draft, mergeable false at the metadata sample. All three workflows terminal: style success, main CI and Mobile Decompilation failed. Ten checks: five success, four failure, one skipped.
- Linux has the same four Darwin compile errors.
- Windows failed compiling
JumpTableEnhancedTests.cppwith C1128: object section count exceeds the limit; the compiler suggests /bigobj. This older PR head's build configuration was not patched speculatively. - Mobile macOS has the same unsupported-preprocessor recovery failures. Main macOS artifact
11450905902reports 688 of 71,915 selected tests: 685 pass, three fail (NeverDMobileIOSBackend, NeverDMobileIOSCallsBackend, NeverDMobileSwiftBackend), 71,227 missing. - The description's 2,016 local passes, six optional Z3 skips, 60 native outcomes, 16 proof-statistics pairs and 45 ASan cases remain author-reported. Its “no CI wait required” statement is not evidence of remote acceptance.
Both open PRs have zero conversation comments, submitted reviews and inline comments in the sampled REST collections. No independent GitHub approval is inferred. Their complete code changes are outside today's source review except the four #589 compiler corrections.
- Previous source
6f885ebbnow has main/mobile workflows cancelled, style success and applications skipped. It is not a clean passing baseline. - At historical
253e5519, Markor official release failed October 5 01:16:38 UTC. Existing artifact11320698349records 10,713 classes, 67,111 methods and 63,750 bodies in the independent inventory; NeverD rejected RestrictTo on RemoteActionCompatParcelizer and published no output. Recompilation and original/reconstructed ART behavior remained incomplete. - That historical run's release qualification had zero qualified cases, seven received and 15 missing, plus incomplete independent holdouts/toolchain variation. These are historical failures, not claims about the new source's runtime behavior.
- No fresh result established resolution of the prior Android finalizer timeout, complete Intel HVF acceptance or complete current-head application qualification. Preserve those gates as open instead of carrying forward a green assumption.
Dependency: One exact candidate incorporating reviewed repairs; completed intended platform/application evidence. #589 has the narrow Linux compile repair but also a demonstrated Mach-O regression failure; #605 additionally has failing remote checks and mergeability false.
Next action: Reconcile the pending Darwin type repair, Mach-O INDIR_CALL expectation and mobile preprocessor rejection with their actual owners. Then inspect terminal existing results and missing registrations without weakening strict failure or shortening coverage.
Acceptance: Identified source compiles on intended platforms; required test registrations have terminal outcomes, all failures are resolved or explicitly blocking, and actual application recovery/reconstruction/behavior completes. Local receipts, skips and cancelled jobs remain separately labelled. This review initiates no run or merge.
Dependency: Review a6468b80 and its new regression in the existing target; unrelated dev build failures currently obstruct broader qualification.
Next action: Review statement-write classification and the preserved overlap policy. When execution is separately authorized, run the focused HighValueForward cases and relevant HighC memory/control-flow coverage on the actual final revision.
Acceptance: The captured value survives Assign-to-Load overwrites at O0/O2; existing disjoint-slot forwarding and scalar/loop controls still hold. Compilation/runtime/formatting remain unverified until real results exist.
Dependency: #580's measurement contract, a pinned corpus and one coherent Release candidate.
Next action: Prepare the load-to-final-output and persistent-session baseline design with completion denominators, process-tree memory, repeated-query growth, cache states and tail latency. Treat solver micro-optimizations as candidates until measured in that workflow.
Acceptance: Reproducible raw measurements and source/hardware/corpus identities demonstrate real latency, memory and scaling without reduced semantic coverage or omitted failures. Unavailable metrics are explicit; this review performs no benchmarks.
- Enumerated 198 commits and 557 changed paths; after the two pure report commits/path, 196 commits and 556 paths remain. Recorded 40 merges (39 excluding report-only #568), two open PRs and 18 ordinary issues; #580 is the only ordinary issue activity.
- Found and committed one statically demonstrated HighC captured-load miscompile repair plus a focused unexecuted regression. Reviewed finite projection validation, pristine encoding and prepared-key/frame ownership without finding another proven defect.
- Confirmed four Darwin compiler failures already repaired in unmerged #589, avoiding a duplicate patch. Distinguished that PR's passing Linux build/macOS mobile checks from its later Mach-O test failure and unfinished aggregate.
- Recorded pinned-dev failed/running/skipped CI, #605's failed/conflicting state and historical application/finalizer/native-acceptance limits.
- Preserved the complete prior English tracker verbatim. Only the bug-fix source/test and PROGRESS.md are changed; no other documentation, dependencies, security settings, issues, merge or deployment changed.
- No project execution, build, test, benchmark, script, formatter/linter, manual workflow dispatch or rerun.
- Open issues: 20 records (18 ordinary + two PRs), empty page 2. Open PRs: two, empty page 2. Activity since October 6 01:06:21 UTC: 43 records (42 PRs + #580), empty page 2. The update-sorted 100-PR page crosses the boundary and independently accounts for all 42 PR records: 40 merged, two open, zero closed without merge.
- Root AGENTS.md, CONTRIBUTING.md, relevant architecture/testing/roadmap and repository review guidance were read. Complete recursive trees contain no nested AGENTS.md.
- Existing workflow artifacts/logs were read only. Check-annotation endpoints were unavailable through the connector; #605 main macOS full log retrieval failed twice, so its existing CTest artifact supplied the failures. No full historical CI census was attempted.
- The prior history blob is
a3694489fd9b85b6f6f2bb36e596b2681541aa9d. Latest dev and affected file blobs were re-read before writes. Code commita6468b80f37d24146fd5a40a08eaf7be987ad58fhas exactly two changed files (26 added lines, three removed); its remote diff was inspected. The report is a separate documentation commit on the same focused branch, proposed as a draft PR. - The report/repair branch and its automatic CI are different from the reviewed dev and the two existing PR heads. Publishing a patch is not runtime validation or permission to merge.
- The remainder of the 557-path inventory, all solver/watch-list internals, broad emulation/unpack/native/SDK/GUI surfaces, native acceptance and other forwarding passes are not exhaustively reviewed. Static review establishes neither race freedom, performance, complete semantic equivalence nor release readiness. This is one daily sample, not continuous monitoring.
Complete October 6 tracker and earlier history, preserved verbatim
Last verified: 2026-10-06 09:03 Asia/Shanghai (UTC+08:00) / 2026-10-06 01:03 UTC
This is a point-in-time source and existing-evidence review. The roadmap, architecture, testing guide and contribution guidance remain authoritative. No completion percentage or release-readiness claim is implied.
Source review is pinned to 6f885ebb, observed at October 6 00:59 UTC. The prior reviewed source was 253e5519. Activity counts run from the previous publication sample, October 5 01:20 UTC, to today's collection; they precede this report-only proposal.
| Measure | Verified state |
|---|---|
| Open ordinary issues | 17, unchanged; 14 epics, no milestones, only #12 assigned |
| Open PRs | 2: #525 and #565, up from zero before yesterday's proposal |
| PRs merged in the activity window | 78: #487–494, #496–524, #526–564 and #566–567 |
| Closed PRs without merge | 0 |
| Ordinary issue activity | #495 was opened and closed; no other ordinary issue updated |
| Raw source inventory | 338 distinct commits; 744 changed file/submodule paths |
| Path classification | 513 modified, 229 added, 2 removed |
| Report-only exclusion | 337 commits and 743 paths after excluding the one PROGRESS-only commit/path; these are not all implementation commits |
| New statically proven code defects / fixes | 0 / 0 in the bounded scope |
| Existing documentation discrepancy | The Android guide still describes all NULL handle lookups as ESRCH; current getTID returns -1 |
The source comparison was enumerated as 100 + 100 + 100 + 38 commits, then an empty fifth page. GitHub's comparison file list stops at 300, so the path count comes from complete recursive trees of 5,871 and 6,099 entries, neither truncated, excluding directories and comparing path/blob identities. Rename pairs count as old/new paths. Three changed submodules (signatures, Capstone and Unicorn) are inventoried, not audited internally.
7e68c9f8 changes only PROGRESS.md and is excluded from implementation advancement. Its parent proposal #487 also contained three real corrections, so its mixed-purpose merge is retained rather than falsely counted as a report-only merge. The inventory is not an exhaustive review count.
- Yesterday's #487 merged at October 5 03:26:15 UTC as 6f798326. Its null TID and typed allocation-failure corrections survive the Bionic/thread dispatch refactor. The current dev PROGRESS blob exactly matches the published October 5 content; all 113,981 characters of that history are preserved below.
- Linux/Android gained shared bounded memory files, status/existence/pathname queries, explicit signal actions and opt-in relative sleep/virtual clocks (#497, #507, #545, #563, #566). File/status and sleep ownership were reviewed below; signal delivery and the complete Android surface were not.
- Native/checked instruction coverage added x64 flags, shifts, frame operations and wide compare-exchange, plus ARM64 exclusives and LSE atomics (#510, #534, #538, #543, #552). These changes are inventoried, not independently certified here.
- Loop inference gained projected counters/bounds, guarded repeated-PC contexts and completed-query reuse (#555–#561, #564, #567). Today's focused review covers the final entailment-cache boundary.
- Library recognition/presentation #537 and its validation follow-up #547 merged; issue #495 closed at October 5 15:54:19 UTC. This is delivered recognition/presentation work, not proof of all library behavior or completion of the older epics.
- ARM64 HVF research retained additional correctness regressions but rejected the proposed watchdog/completion performance changes. The published guide reports final source
a63d57e6a: CPU 1,434 passed / 12,693 skipped with 29/29 required; separate Darwin 65 passed / 221 skipped with 39/39 required. These are published local evidence, not artifacts independently re-audited today; overlapping inventories must not be added or transferred to this head. Intel complete acceptance remains open.
Mode: Source, interfaces, callers, declared regressions, configuration and already-existing CI only. No project execution, build, test, benchmark, linter, formatter, repository script or dynamic analyzer was run. No workflow was dispatched or rerun. This publication contains no CI-skip marker; ordinary automatic checks may run.
Full source reads:
lib/emulation/os/linux/kernel/{LinuxFiles.h,LinuxFiles.cpp,LinuxFilePaths.cpp,LinuxFileOptions.cpp,LinuxFileIO.cpp,LinuxFileStatus.cpp,LinuxUserMemory.cpp,LinuxTime.h,LinuxTime.cpp,LinuxClock.cpp,LinuxSleep.cpp,LinuxServices.cpp}lib/emulation/os/linux/android/{AndroidThreads.cpp,AndroidThreadCalls.cpp,AndroidThreadWaits.cpp,AndroidKernelCalls.cpp}unittests/emulation/{AndroidFileStatusAtTests.cpp,AndroidSleepTests.cpp,LinuxClockTests.cpp}- Focused current
AndroidFinalizerTests.cpp:222–243, architecture/testing contracts and the Android guide's NULL-handle wording
Static conclusions:
- One
LinuxFilesinstance owns descriptors and immutable catalogue observations. Path import stops at the first NUL and bounds addresses before reads. Catalogue validation rejects file/ancestor conflicts; status imports its pathname before output, so overlapping pathname/output is handled deliberately. Absolute paths ignore dirfd, empty-path descriptor queries use the same serializer, and unmodeled relative paths, CWD/directory metadata and version-specific flags fail explicitly. LinuxUserMemorydistinguishes wholly inaccessible output from mixed access without guessing native partial-copy bytes. File reads retain completed page prefixes and cursor updates; original address/signed extent checks precede EOF/clamping. Metadata is explicit rather than fabricated from contents.LinuxSleepcopies both request fields before value checks, preserves the successful remaining-time pointer and retains the consumed deadline.LinuxClock::advanceTochecks every supplied epoch for overflow before committing elapsed time.GuestThreads::scheduleadvances only with no runnable thread, choosing the earliest sleep deadline. Typed waits preserve request/event attribution; completion updates the original native-call or raw-service event. Bionic alone converts errno. The reviewed source does not introduce host sleeps or host filesystem access.- The existing
getTID(NULL)returnsUINT32_MAX; child mapping converts onlyGuestMemoryLimitErrorto EAGAIN before identity/output publication. No duplicate fix is needed.
Declared regressions cover direct/variadic/raw ABI routes, output/path aliases, missing metadata, low-word arguments, dynamic-provider lifetime, shared cursor state, consumed sleep inputs, deadline order, TLS/errno/context retention, joins/mutexes/once, budget stops and overflow. Native comparisons explicitly skip unavailable transports. They were read, not executed.
Result: No new statically proven defect in this scope; no speculative code patch. The Android guide still says NULL lookup returns ESRCH, which conflicts with the narrow TID exception. This known documentation discrepancy remains unchanged because only this tracker is authorized for documentation maintenance. No stable return contract is inferred for other malformed native handles.
Reviewed lib/analysis/core/LowIRUndefinedIndependence.cpp (Checker::chargeQuery/query, session binding, LoopPlanInference::entails/run, template/native-selector consumers and independent runRefinement), the budget contract in include/neverd/analysis/LowIRRefinement.h, stable interned references in include/neverd/symbolic/SymExpr.h, and the changed regression assertions/CMake ownership from #567.
- The cache key is the complete domain AND NOT fact, scoped to one inference's append-only symbolic context; a fact cannot be reused under a different domain by itself.
- The hit path checks node limits and charges the shared logical-query budget before recording a hit. Misses use a fresh checker. Unknown/invalid answers are rejected before insertion.
- Final refinement starts a separate session: inference results/budgets do not fund the proof.
CompletedEntailmentsStayInInferenceSession,CompletedEntailmentsKeepUnknownAndNodeLimits,MutablePrefixBoundsKeepIndependentBudgetsandNativeSelectorsProveRepeatedContextsdeclare session, nontermination, exact/one-short, node/query exhaustion and context-domain checks inNeverDLowIRRefinementTests. Author-reported passes are not independently executed evidence.
Result: No statically provable new cache defect; no fix proposed. This is a bounded review of cache ownership/budgets, not a proof of the complete solver, all loop inference or native refinement.
At October 6 01:03:15 UTC, 6f885ebb7fda032077838950be03e31b90ffa593 had four all-event workflows (one successful, one skipped, one running, one queued) and 19 checks: four successful, ten skipped, four running, one queued, zero failed. Both collections used 100/page and an explicitly empty second page.
- Main CI 37396172858: all three main platform legs were still at the Debug/Release-target preflight; their configure/build/native test stages had not run. Both Windows caller-context checks passed; the optional Native CPU job skipped.
- Mobile Decompilation 37396172710: overall queued; Linux passed, macOS running, Windows queued. The Linux job independently reports 366/366 CTest tests and separate 197-test/240-test Python suites passing. This is narrower mobile/prebuilt coverage, not the integrated-LLVM/native aggregate.
- LLVM Style 37396172784: passed.
- Mobile Real Applications 37396204608: all nine jobs skipped, including qualification; its graph skips cancelled upstream producers. It supplies no current-head application-recovery result.
Pending, skipped and partial results cannot establish a complete green gate.
- Android finalizers: the previous O0 registry-capacity timeout is not verified resolved on this head. The unchanged current regression still makes two separate emulation calls, each with a 30-second allowance. No runtime cause is inferred and no timeout changed.
- External compiler IR: merged #547 reports compatible host-compiler serialization and successful focused/replay checks. Its own account separates an earlier failing aggregate from later repair runs. This is delivered remediation and author-reported validation, not an independently observed final-revision green aggregate.
- Real applications: the October 5 official Markor job retains failed complete-APK recovery with reconstruction/behavior incomplete. Yesterday's artifact-level RestrictTo diagnosis is preserved below; today's stdout did not independently expose that detail. No new pinned-head real-application pass was found.
- The former main CI 37247600637 and application run 37249288624, both at
253e5519, now conclude cancelled overall. Their previously observed individual failures remain failures; cancellation is not a retroactive pass. - A later CI 37354456744, at
2b937f3192dce3d76bdabb7c18a2b56d4232f533, failed all three main legs before build on 149 benchmark-provenance findings. Merged repairsac78f59andf053fbbare present in today's ancestry. Independently, newer ancestorac8ae03passed Linux preflight/configure in job 112045285352, before build cancellation. This supports the historical preflight repair, not complete current-head qualification.
No complete historical workflow census was attempted today; these are targeted prior-blocker checks and an exhaustive exact-head census. The old Linux job-log fetch was unavailable, so the previous preserved artifact diagnosis was not independently repeated.
- #565, head
bfb56d8f932b40df4935fed2bf0d17ff1f67ac15: parallel checked CPUs and transactional MMIO atomics. At 01:02–01:03 UTC, 14 checks: seven successful, two skipped, five running; an already-existing native WHP run was running. The author reports KVM validation; full current-head completion and ARM64 native coverage remain distinct. This large open PR is outside today's source review. - #525, head
d05bd3fb772c983cfe20f42e8e005aa15aad2841: explicit Darwin file/directory/mapping/clock services. No exact-head workflow/check runs were returned. Its author records a full local Darwin gate with one HVF virtual-metadata timeout and a later unchanged-bound focused recheck; these must not be flattened into one all-green full gate. Its broad mutable filesystem/OS contract is outside today's source review. - Both PRs have no submitted reviews, inline review comments or conversation comments in the sampled 100/page endpoints. No independent approval is inferred. No reviewer was assigned and no PR state changed.
Dependency: Finish existing automatic CI and application producer/consumer chains for one identified source. Historical cancellation, optional Native CPU skips and separate replay receipts leave gaps.
Next action: Inspect terminal results, then isolate any remaining finalizer cost/budget, host-compiler IR or real-application coverage failures without weakening strict rejection. Keep already-delivered provenance/owner repairs separate from unresolved behavior.
Acceptance: One exact candidate has complete intended Linux/macOS/Windows execution and actual completed application recovery/reconstruction/behavior evidence, with required tests executed and skips/missing outcomes explicitly accounted for. No test or dispatch is initiated by this review.
Dependency: Stable heads and complete existing evidence for #565 and #525; platform-specific native results cannot substitute for each other.
Next action: Review CPU/provider atomicity and ownership in #565, and Darwin namespace/content/mapping/metadata lifetimes in #525; reconcile each pending/failed full gate with focused rechecks before integration.
Acceptance: Review conclusions and exact-head integration evidence preserve failure atomicity, bounded policy, complete required native outcomes and explicit unavailable-platform limits. No merge or deployment is authorized by this tracker.
Dependency: Original Intel fresh-Executor recovery, complete CPU inventory and independent Darwin evidence on one coherent candidate remain required; diagnostic controls and ARM64 results cannot satisfy them.
Next action: Reconcile the published native evidence without promoting incomplete prefixes or rejected performance candidates. Separately request the narrow Android guide wording correction through an authorized documentation change.
Acceptance: Intel's original recovery and complete inventories have terminal outcomes with process retirement/source identity; otherwise the gate remains open. Android documentation states the null-TID exception accurately without guessing other malformed-handle contracts.
- Enumerated 338 commits and 744 changed paths; separated the single pure report commit/path from substantive advancement. Reconciled 78 merges, two open PRs and issue #495's opening/closure, with 17 ordinary issues still open.
- Confirmed yesterday's merged Android corrections survive the source refactor. Completed the bounded file/status/sleep and loop-entailment cache reviews above; found no additional statically proven defect and made no speculative code change.
- Recorded exact-head pending CI, independently observed Linux mobile success, existing application skips and targeted historical blocker/remediation evidence.
- Preserved all previous tracker text, including manual edits/history; only this English PROGRESS.md is changed.
- No execution, build, test, benchmark, repository script, formatter/linter, CI trigger/rerun, issue mutation, dependency/security change, merge or deployment.
- Open issue collection: 19 records (17 ordinary issues + two PRs), then empty page 2. Separate open PR collection: two records, then empty page 2.
- Activity collection since October 5 01:20 UTC: 81 records (80 PRs + issue #495), then empty page 2. The 100 PRs ordered by update cross that boundary and include all 80 in-window PR records: 78 merged, two open, none closed without merge. Older complete PR history was not enumerated.
- Review submissions and inline comments were checked for #487, #525, #547, #563, #565, #566 and #567; all first pages were empty. Conversation comments were additionally checked for the two open PRs. Unsampled discussions are outside coverage.
- Root AGENTS.md, CONTRIBUTING.md, relevant architecture/testing/roadmap sections and applicable debugging guidance were read. The complete tree has no nested AGENTS.md. GitHub reports dev unprotected and no rulesets; no settings were changed.
- Publication uses a fresh focused topic branch and draft PR because yesterday's related #487 is merged; the two existing open PRs are unrelated. Latest dev/target file blobs are re-read before mutation, and remote content/commit/diff are checked after publication. The existing history blob is
5ebfc33554c723d17f2b07032d02b358f790b2a7. - The report's source/CI snapshot remains the pinned source above. Its subsequent documentation commit is a different head with separate checks; publishing it does not validate the reviewed source or imply permission to merge.
- Remaining 744-path inventory, full solver/loop/scalar proof machinery, library-recognition semantic correctness, all x64/ARM64 atomic instructions, broader OS/SDK/GUI surfaces, native backend internals, open PR source and submodule internals are not exhaustively reviewed.
- Static inspection does not establish compilation, formatting, runtime equivalence, race freedom, latency, full ISA/OS coverage or release readiness. This is one bounded daily sample, not continuous monitoring.
Complete October 5 tracker and earlier history, preserved verbatim
Last verified: 2026-10-05 09:20 Asia/Shanghai (UTC+08:00) / 2026-10-05 01:20 UTC
This point-in-time tracker separates delivered implementation, bounded static review and observed execution evidence. The roadmap, architecture, testing guide and contribution guidance remain authoritative. Suggested priorities are acceptance work, not deadlines or a completion percentage.
Source review is pinned to 253e5519, observed at October 5 00:59 UTC. Issue/PR counts below precede this proposal.
| Measure | Verified state |
|---|---|
| Open ordinary issues | 17, unchanged; 14 epics, no milestones, only #12 assigned |
| Open PRs | 0, down from the three open after yesterday's publication |
| PRs merged since October 4 01:05 UTC | 92: #394, #395 and #397–486 |
| Progress-only PR in that window | #397; excluded from implementation advancement |
| PR closures without merge / ordinary issue updates or closures | 0 / 0 |
| Previous source snapshot | 00f44615 |
| Raw change inventory | 400 commits; 613 file/submodule paths: 344 modified, 236 added, 33 removed |
| Excluding yesterday's progress-only commit and merge | 398 commits and 612 paths; these still include other documentation, tests and merges |
| New statically proven defects | 2 Android return/error mismatches and 1 CI expected-owner mismatch, corrected in this proposal |
| Other newly proven defects in the bounded audit | 0 |
The comparison was enumerated as four pages of 100 commits and an empty fifth page, with 400 distinct SHAs. GitHub caps comparison file lists at 300, so the 613-path inventory compares complete recursive trees of 5,661 and 5,871 entries, neither truncated. Directory entries are excluded; rename pairs count as old/new paths. The two changed submodule pointers are inventoried, not audited internally. Neither 613 paths nor 398 commits is a complete source-review count.
The source interval also includes #396, merged at October 4 01:01:05 UTC and already recorded in yesterday's publication note; it precedes today's PR activity window. Counts based on commit ancestry and counts based on merge time are intentionally distinct.
- #397 merged at October 4 03:32:46 UTC as 2598893f. The current dev tracker exactly matches its published blob; its complete text and all earlier human edits/history are preserved below.
- Yesterday's pending aggregate-value/ABI #394 and Android default-symbol-scope #395 are now merged. They are no longer open-PR blockers.
- Android gained guest once callbacks, mutexes, explicit clocks and file-backed inputs, bounded formatting, finalizers, thread attributes, cooperative threads and once waiters. The scheduler/callback boundary was reviewed; the whole Android implementation was not.
- Checked x64 gained packed integer/shift/shuffle/interleave/conversion operations, DAZ controls, native SIMD exception continuations and PAUSE. The latest capability, fault-to-Windows and checked execution boundaries were reviewed below; all newly admitted opcode semantics were not independently proved.
- Shared scalar equivalence/loop recovery, initialized private-frame projection, byte-cell scalarization, architecture separation and Swift/Objective-C recovery advanced. These were inventoried, not comprehensively audited.
- Exact-head Mobile Decompilation and LLVM Style pass. Main CI now has a failed Linux job, and real-application qualification has a failed Markor case; other jobs remain unfinished.
- New Intel diagnostic evidence includes independently inspected 1,000-repetition successes under specific retained-session/vCPU controls. Complete Intel CPU acceptance remains explicitly unverified.
Mode: Source, diffs, interfaces, callers, test declarations, configuration and already-existing CI evidence only. No project, build, test, benchmark, linter, formatter, repository script or dynamic analyzer was run. No workflow was manually dispatched or rerun. New commits contain no CI-skip marker; ordinary automatic checks may run.
Fix b43f50d6 corrects one production expression in GuestThreads::invoke. The shared null-handle branch returned positive ESRCH (3) before the TID-specific path, so a caller testing for -1 could interpret a failure as a positive thread ID.
The pinned Bionic implementation returns -1 for a null lookup. Its handle lookup explicitly permits NULL at the selected API boundary while retaining fatal handling of invalid non-null handles. This is an independently implemented API correction, not copied Bionic code.
The fix returns UINT32_MAX only for the null TID query, matching the project's existing zero-extended narrow-negative representation and presenting signed -1 to the C pid_t consumer. It preserves join/detach errors and the errno path. Direct and dynamically resolved imports converge through AndroidBionic.cpp into this owner; result publication writes the same result register without changing errno.
Added regression source in AndroidThreadTests.cpp and fixtures/android_threads.c checks both routes, signed -1, low-32-bit 0xffffffff, errno sentinel preservation and provider attribution. Existing O0/O2 and three relocation-packing fixture registrations include the new entry without a build-file change.
Verification: Remote commit/file readback matches the intended three-file patch. No tests, fixture compilation or formatter were run. The standalone guide's broad NULL-lookup wording is known to need a narrow correction, but that file is outside this proposal's authorized scope and was not changed.
Fix 7877e950 translates only GuestMemoryLimitError from initial child-region mapping into EAGAIN. Previously, the thread model checked total unmapped capacity but propagated a contiguous-allocation shortage as a terminal runtime failure.
The static chain is GuestThreads::create → AddressSpace::map → PhysicalMemory::allocate. Enough total free bytes do not guarantee one free span large enough for stack, guard and TLS. The allocator already reports this condition using the specific capacity-error type, and Linux memory services already distinguish that type from generic mapping failures. The former Android propagation reached the runner's RuntimeFailure path instead of its documented allocation refusal.
The correction leaves every non-capacity error unchanged and precedes guard changes, child TLS/context creation, output-handle publication and identity insertion. A new model-level regression in AndroidThreadTests.cpp constructs deterministic 4 KiB-owner fragmentation, explicitly checks the failed contiguous-allocation precondition, and checks EAGAIN with unchanged handle, errno, mapped/allocated bytes, mapping generation and entry-only identity. A separate occupied-slot control requires the generic mapping error to keep propagating. It avoids guest timing, fixture-size and scheduling assumptions.
Verification: The two-file remote diff and full file readback match the intended patch. Header declarations, transitive component linkage and the existing test target were inspected. Neither compilation nor the new regression was executed.
Fix 717c7928 changes exactly eleven expected-identity lines in .github/workflows/ci.yml, adding NeverDJumpTableTests alongside the retained NeverDLiftTests owner.
The same three JumpTable sources are registered in both targets in CMake; the shared registration helper supplies target labels. Preserved Linux and macOS discovery/execution data agree on every one of these eleven names and owner sets. The tests themselves passed 522/522 and 577/577, respectively; their mobile-native audits failed solely because the expected owner tuples omitted the newer target.
Test names, required counts, full-label equality, assertions, timeouts, workflow triggers, permissions and concurrency policy are unchanged. This repairs expected metadata without weakening the audit. Remote readback and the one-file 11-addition/11-deletion diff were verified; no workflow was dispatched or rerun.
Full production-source reads:
lib/emulation/os/linux/android/{AndroidThreads.cpp,AndroidThreads.h,AndroidThreads.def,AndroidThreadAttributes.cpp,AndroidThreadAttributes.def,AndroidMutex.cpp,AndroidMutex.def,AndroidFinalizers.cpp,AndroidOnce.def,AndroidInternal.h,AndroidNative.cpp,AndroidSymbols.def,AndroidDiagnostics.def}lib/emulation/runtime/ProcessAndroidJSON.cppinclude/neverd/emulation/{AndroidNative.h,ProcessCall.h}
Focused callers/interfaces: AndroidBionic.cpp TLS/errno and dynamic-provider helpers, once completion (249–292), thread dispatch (294–322) and kernel wrappers (491–520); Linux LinuxServices.cpp, LinuxServiceABI.cpp, LinuxMemory.cpp, LinuxKernel.h and LinuxValues.def; ExecutionSession.cpp continuation/quantum accounting; IntegerABI.cpp call preparation; AddressSpace.cpp:113–193; the complete PhysicalMemory.cpp; public ExecutionSession.h and ProcessSession.h.
Test/fixture reads: AndroidThreadTests.cpp and fixtures/android_threads.c; the Android finalizer, mutex and thread-attribute test/fixture pairs; AndroidNativeTests.cpp:101–269 and fixtures/android_once.c; fixture compilation/packing registration in AndroidFixtures.cmake; ProcessPublicTests.cpp:885–923; Python test_process_integration.py:19–67. Relevant changed-file inventories for #400, #405, #431, #435, #439 and #458 were read.
The audit traced saved CPU/TLS/errno ownership, the shared instruction budget, suspended service completion, join retirement, once-owner/waiter wakeup validation, guest destructor callbacks, mutex-owner identity and direct/dynamic import convergence. Two return/error-boundary defects were established above. No additional confirmed once-wait, mutex-owner, finalizer-order or callback-continuation defect emerged.
Separate uncertainty: pthread_getattr_np(NULL) is a malformed-input boundary whose pinned native implementation directly dereferences the handle. That does not establish a stable API return contract or justify guessing a new modeled result. It is not part of these fixes. Copied scheduling attributes under inherited policy match the inspected Bionic behavior and were not promoted to a defect.
CPU backend context implementations and ELF-linker internals were not deeply re-audited; their Android consumers were traced. No native Android equivalence, SMP correctness, runtime timing, executed regression or full C/Python surface verification is claimed.
Full-file reads:
lib/emulation/core/CheckedBackend.cpplib/emulation/arch/x86_64/{CheckedX64Backend.cpp,CheckedX64Backend.h,X64Machine.h,X64MachineProbe.cpp,X64MachineProbe.h,X64MachineProbe.def}lib/emulation/runtime/{BackendRegistry.cpp,ExecutionProfiles.def}lib/emulation/os/windows/exception/{X64SIMDException.cpp,X64SIMDException.h,X64SIMDException.def}lib/emulation/os/windows/process/WindowsProcessExceptions.cppunittests/emulation/{X64PauseTests.cpp,X64PauseCases.def,X64SIMDExceptionTests.cpp,X64ProbeExecutionTests.cpp,WindowsSIMDMappingTests.cpp,WindowsSIMDExecutionTests.cpp,WindowsSIMDExecutionCases.def}
Focused reads: ExecutionConfiguration.cpp:1-218; WindowsProcessContext.cpp:176-341; public CPU.h and ExecutionConfiguration.def changes; CheckedX64Instructions.def, NativeCPUTests.def and test-target registration changes; KVM/WHP startup call-site changes. Production patches in #482, #485 and the code/test changes in #486 were read.
Static conclusions:
- PAUSE is admitted through the existing checked single-instruction boundary. The shared loop offers a pre-effect observer stop, checks the same absolute deadline, and only publishes staged CPU/RAM effects after successful retirement. PAUSE is not a guest scheduler or a latency guarantee.
- Precise unmasked SIMD capability is qualified by backend, ISA and execution contract. Only the declared x64 KVM/WHP contracts add it; checked Unicorn and HVF do not acquire it from writable MXCSR bits.
- The KVM/WHP factory requests an authentic SIMD-fault startup probe plus masked and repaired-operand retries before publishing the discovered MXCSR mask. Probe state comparisons cover the full machine packet; a probe still does not certify every instruction or workload.
- A genuine machine exception retains architectural CPU status while speculative RAM is discarded. Windows classification requires an authenticated SIMD fault and consistent retained MXCSR; sticky status by itself does not invent a fault. Saved-context restoration validates both MXCSR copies, capability, reserved fields, executable PC and stack before restoring.
- Read regression sources describe full-state PAUSE stops/resumption, invalid LOCK refusal, real checked/native SIMD fault state, guest VEH/VCH execution, context repair and old sticky-status preservation. These are source assertions, not newly executed results.
No additional statically proven defect was established in this x64 scope. Broad native backend lifetime/state-transfer implementations, all SIMD opcode semantics and hardware behavior remain outside this bounded audit.
At October 5 01:20:30 UTC, 253e551961b18a784971244882e36f60eff64b96 had five workflows and 30 checks: ten successful, ten skipped, five running and five failed. This supersedes the earlier 01:04 sample (24 checks, zero failed).
- Main CI 37247600637: still running overall, with Linux job 111568535902 failed. macOS/Windows jobs remain running; macOS already has a failed mobile-native step. Both Windows caller-context checks passed; the optional manually selected Native CPU job skipped.
- Mobile Decompilation 37247600629: successful on Linux, macOS and Windows.
- LLVM Style 37247600645: successful.
- Mobile Real Applications 37249288624: running, with four failed Android checks: Markor official release, Gradle release and Gradle debug, plus calculator official release. Only the official Markor failure was diagnosed below; the three later failure causes were not audited before this snapshot.
- Earlier same-head real-application consumer 37247613656: skipped.
Legacy status contexts are empty. Their aggregate pending value is not an extra failed check. Running workflows with failed jobs, partial successes and skipped checks do not establish full integration or current native acceptance.
The complete dev Actions creation window October 4 01:05 UTC through October 5 01:00 UTC contains 501 distinct runs, enumerated as 100 + 100 + 100 + 100 + 100 + 1 and matching the API total. At collection: 85 successful, 292 cancelled, 116 skipped, six failed and two running. Its 118 main-CI runs are 117 cancelled and one running; zero completed main-CI successes. The mobile-fixture subset is two successful, 115 cancelled and one failed; real-application consumers are 116 skipped, two cancelled and one running. Cancellation is an evidence gap, not proof of a code defect. This window does not include every older run that happened to finish within it.
The failed Linux main-CI job and still-running macOS job have independently inspected preserved evidence. Original ZIP SHA-256 values matched GitHub metadata for Linux mobile-native artifact 11320976133, macOS mobile-native 11320292520, Linux emulation 11320706657 and Linux full-profile 11320282451. The full Linux job-log tool failed twice; these original artifacts supplied the diagnosis.
- Mobile-native owner drift: Linux 522/522 and macOS 577/577 selected/reported/started tests passed, but eleven expected label sets were stale. Fix 717c7928 above corrects only those metadata expectations; it is not yet verified by a new run.
- Android finalizer timeout: The Linux emulation profile has 16,456 registrations: 7,514 passed, 8,939 skipped and three failed. All O0 packaging variants of
AndroidFinalizers.FiniteRegistryRejectsBeforeSuccessAndCanBeReusedhit the outer 30-second CTest timeout; O2 variants pass. The fixture makes two emulation calls, each admitting 30 seconds, inside a 30-second test target. This exposes a possible outer/inner budget conflict but does not establish the runtime-cost root cause. No timeout was increased. - External LLVM-IR oracle compatibility:
LLVMScalarDecisionCompiled.DeepOneAndTwoBackedgeOraclesfails when the external compiler rejectstrunc nuw nsw i64 %shifted to i32with “expected type.” The fixture also useszext nneg, and sends that modern IR unchanged to discoveredNEVERD_TEST_CLANG. The configured external-tool contract has no matching syntax/version check. In-process proof success does not establish external-oracle compilation. The full profile reports 1,628 of 52,395 selected: 1,563 passed, one failed, 64 skipped, 50,767 missing after early stop. Missing tests are unexecuted. Semantic flags were not removed to silence the failure. - Real application coverage: Official Markor job 111577673147, exact consumer
253e5519, exits one because the DEX loader rejects an unsupported AndroidXRestrictToannotation onRemoteActionCompatParcelizer. Original artifact11320698349was digest-verified. Markor 2.16.1 / sourcef33eb6a8dfb210f27bfe7294430d4d39b795bd0findependently inventories two DEX files, 10,713 classes, 67,111 methods and 63,750 bodies; recovery fails, and recompilation/behavior are incomplete. Inventory success is not recovery success, and strict annotation admission was not weakened.
The timeout, external compiler contract and application-support gaps remain unresolved. The three later application failures named in the current check snapshot need their own diagnosis.
All six failed runs in that window were diagnosed from their original job logs:
- Windows mobile 37169700823, source
bc05c078: MSVC C1128 while compilingNeverDCAPIObjC.cpp, requiring/bigobj. 5a10380b added the MSVC-only source property; it remains in current CMake lines 50–55. Current Windows mobile success corroborates recovery for that scope. - Five LLVM Style failures: 37205055158 (
HvfExecutor.cpp), 37212958633 (HvfExecutorTests.cpp), 37222710688 (X86Lifter.cpp), 37228760523 (X64PackedFloatCases.def) and 37230834147 (X64PackedFloatIntegerCases.def). The pinned head's style check passes.
These are historical results, not six current-head failures. No duplicate fix or formatting sweep was made.
The public pinned HVF guide explicitly keeps the complete Intel CPU inventory unverified. This public tracker references only the repository's published technical summary:
- The guide records 1,000/1,000 retained-session recovery iterations on both Intel host images, with successful exit and retirement records. This establishes the admission-budget correction for that diagnostic, not the fresh-Executor production gate. Published summary
- A later vCPU-recreation control records 1,000/1,000 on one image; its counterpart preserves 460 completed / 461 started, followed by an uploader interruption rather than a completed native result. The public guide does not identify a root cause. Published summary
- The later control omitting an extra host kick records lost runner communication and 778/779 and 300/301 completed/started prefixes. Neither has a final native result or retirement record; the last marker does not locate the fault. Published summary
These published diagnostic outcomes advance the picture beyond yesterday's prefix but do not certify today's head. This update does not reproduce personal-repository evidence links, controller identifiers or raw host/crash details.
Yesterday's independently verified historical 26/26 Intel Darwin success and 252 complete / 253 started recovery prefix remain valid for their own NeverD runs, preserved below. Incomplete runs remain incomplete.
ARM64 HVF, documented local evidence: The public guide records clean source 389bebfdda31a0db19facc7ab8ca5461a8c8c1bc with CPU 2,546 passed / 4,710 skipped / zero failed and all 23 required native cases; separate Darwin 130 passed / 156 skipped / zero failed and all 39 required cases. Those local artifacts were not independently accessed today. CPU and Darwin totals overlap and must not be added; neither transfers to today's head or native ARM64 KVM/WHP.
Dependency: The focused proposal must pass its existing automatic workflow and matching guest regression matrix; source inspection alone is insufficient.
Next action: Review the narrow Android return/error ownership changes, regression declarations and eleven corrected JTE owner tuples. Reconcile the known outdated standalone Android documentation before treating its blanket NULL-handle statement as authoritative.
Acceptance: Direct and dynamic null TID queries report signed -1 with errno preserved; fragmented-memory thread creation returns EAGAIN without publishing an identity or output handle, preserving the capacity/generic-error boundary. Existing invalid-handle, generic-error and thread-lifetime behaviors remain intact. No execution or merge is initiated by this review.
Dependency: The finalizer timeout, external-compiler IR compatibility and Markor annotation-coverage blockers remain. One identified source needs complete terminal evidence.
Next action: Diagnose the O0 finalizer cost/budget boundary and define a compatible external-oracle compiler contract without deleting semantic proof coverage. Preserve strict annotation rejection while investigating the Markor coverage gap. Inspect already-authorized automatic results with exact source and producer/consumer identities. Map verified Android/x64 delivery to #104, and mobile acceptance to #101, without closing either by inference.
Acceptance: Intended Linux, macOS and Windows profiles complete with audited required execution. Real-application qualification provides actual completed results rather than a skipped consumer. Historical mobile/style recovery and a passing subset do not substitute for full integration.
Dependency: A coherent clean candidate and matching native evidence; diagnostic reuse controls are not the production gate.
Next action: Reconcile original fresh-Executor recovery, the complete CPU inventory and independent Darwin results on the same candidate. Keep assertion failure, uploader crash, runner loss and cancellation distinct.
Acceptance: Original fresh-Executor recovery completes 1,000 repetitions with final retirement, the complete native CPU inventory executes every required outcome, and the independent Darwin gate passes with exact source/attempt identity. Retained-session or vCPU-only controls, partial prefixes and unrelated-host results cannot satisfy this gate.
- Enumerated 400 commits and 613 raw paths; separated yesterday's progress-only commit/merge and reconciled 92 PR merges, 17 unchanged ordinary issues and zero open PRs before this proposal.
- Statically reviewed the bounded Android scheduler/callback and x64 checked/SIMD/Windows-continuation paths above.
- Submitted minimal corrections for two proven Android return/error-boundary defects with regression source, plus the eleven-entry CI expected-owner correction. No regression or project workload was executed.
- Confirmed exact-head mobile/style success, new main-CI/Markor failures and remaining running work; diagnosed six historical failures without duplicating delivered fixes. Retained finalizer timeout and external-compiler compatibility as separate unresolved blockers.
- Reconciled the public HVF guide's new 1,000-repetition diagnostic successes while retaining fresh-Executor/full-inventory acceptance and incomplete-run gaps.
- Preserved the complete October 4 tracker and earlier history. The standalone Android guide's narrow correction remains outside this proposal's authorized file scope; its blanket NULL-lookup statement is known to be outdated.
- No dependency or security-setting changes, issue mutation, manual CI dispatch/rerun, merge or deployment. New commit messages are English and contain no skip marker.
- Open issues: 17 records and an empty second page; separate open PR list empty. Updated issue/PR collection: 92 PRs and an empty second page, no ordinary issue. The first 100 PRs ordered by update cross the time boundary and contain every in-window record; older complete PR history was not enumerated.
- Review submissions, inline comments and conversation comments were sampled for #394, #395, #397, #439, #458, #482, #485 and #486. Each endpoint returned an empty first page (100/page). No independent approval is inferred, and unsampled PR discussions were not audited.
- Exact-head workflow/check collections included all event types/all checks; the early five/24-record collections had empty second pages. The later publication sample returned five workflows and 30 checks, both below 100/page. The complete dev creation-window inventory and its limits are stated above. Not every historical successful log or artifact was audited.
- Root AGENTS.md, CONTRIBUTING.md, relevant architecture/testing/roadmap sections and applicable repository debugging guidance were read. The complete tree contains no nested AGENTS.md. GitHub reports dev unprotected and an empty ruleset collection; no settings were changed.
- The publication follows a focused topic branch and draft PR against dev. Head/file blobs are re-read before mutation; expected remote contents and diffs are checked after each commit. Remote publication is not passing runtime verification or permission to merge.
- The other changed source paths, all scalar/loop/LLVM proof machinery, Swift/Objective-C recovery, broader loader/ABI changes, native backend lifetime internals and submodule internals remain outside this bounded audit.
- Static analysis does not establish compilation, formatting, runtime behavior, race freedom, complete ISA coverage, overall product completion or release readiness. This is a point-in-time snapshot, not a claim of continuous monitoring.
At 01:20 UTC, dev still points to the reviewed 253e5519, and its PROGRESS.md remains blob f07bf1e27c203670103795f589aaf58c3096d9a2. The three focused corrections are on dot/daily-static-review-2026-10-05: b43f50d6, 7877e950 and 717c7928. They are proposed, not merged. Commit/file/diff readback succeeded. A new-head passing result is not claimed; the final progress commit and draft PR are publication steps, not runtime validation.
October 4 tracker with complete October 3, October 2, October 1 and September 30 history
Last verified: 2026-10-04 09:05 Asia/Shanghai (UTC+08:00) / 2026-10-04 01:05 UTC
This point-in-time tracker separates delivered implementation, static review and observed execution evidence. The roadmap, architecture, testing guide and contribution guidance remain authoritative. Suggested priorities are acceptance work, not deadlines or a project completion percentage.
Source review is pinned to 00f44615, observed at 00:58 UTC. Counts below use that observation unless explicitly updated.
| Measure | Verified state |
|---|---|
| Open ordinary issues | 17, unchanged |
| Open PRs at initial observation | 3: #394, #395, #396; up from zero before yesterday's proposal |
| PRs merged since October 3 01:12 UTC, through 00:58 UTC | 31: #363–393; #363 is progress-only documentation, not product advancement |
| In-window PR closures without merge | 0 |
| Ordinary issue updates / closures in the window | 0 / 0 |
| Previous source snapshot | 99340b58 |
| Change inventory | 226 commits; 895 raw file/submodule paths: 395 modified, 327 added, 173 removed |
| New statically proven defects in reviewed scope | 0 |
| Proposed changes from this review | PROGRESS.md only; no duplicate code fix |
The comparison was enumerated across 100 + 100 + 26 commits and an empty fourth page. GitHub caps comparison file lists at 300; the inventory instead compares complete recursive trees of 5,496 and 5,661 entries, neither truncated. Renames count as old/new paths in this raw tree inventory, so 895 is not a count of independent behavioral changes or fully reviewed files.
- Yesterday's #363 merged at October 3 02:57:41 UTC as 988a6f01. Subsequent human/repository editing corrected the historical Windows policy path to its new
driver/location. That correction and the entire existing tracker are preserved below. - Windows process capabilities advanced through runtime DLL loading, Unicode environment APIs, heap reallocation, modeled system DLLs, VEH/VCH continuations, shared x64 SEH and caller-context capture: #368, #369, #371, #375–379, #381, #386 and #387. Their complete implementation is outside today's bounded audit.
- #383 added synchronous external C/Python decoder callbacks to the shared bytecode pipeline; #384 reconciled capability declarations.
- #391 separated Linux/Darwin kernel contracts from process startup. #392 added Linux/Bionic vectored output and corrected scalar zero-write address validation.
- Numeric memory, finite-value and modular predicate simplification, Swift/Objective-C recovery and LLVM C emission also advanced. These changes were inventoried, not comprehensively audited.
- Intel HVF now has independently inspected Darwin success, but complete Intel CPU acceptance remains open. The later 1,000-repetition recovery run failed after runner communication loss; preserved progress does not prove the requested total.
Mode: Source, diffs, interfaces, callers, test declarations, configuration and already-existing CI evidence only. No project, build, test, benchmark, linter, formatter, repository script or dynamic analyzer was run. No CI workflow was dispatched or rerun.
Full source/interface reads:
include/neverd/{analysis/BytecodeDecoder.h,pipeline/BytecodeRecovery.h,sdk/NeverDCAPIBytecode.h}lib/analysis/bytecode/{BytecodeDecoder.cpp,BytecodeProfile.cpp}lib/pipeline/BytecodeRecovery.cpplib/sdk/capi/NeverDCAPIBytecode.cpppluginsdk/python/neverd_plugin/bytecode.pyunittests/devirtualization/BytecodeCAPITests.cpppluginsdk/python/tests/{test_bytecode.py,test_bytecode_integration.py}
Focused reads: Python abi.py callback/function declarations; ffi.py::owned_string; BytecodeDecoderTests.cpp source/call/loop and floating-policy sections (lines 601–996); callback contract in docs/bytecode-profiles.md; the external-bytecode capability and expected-public-surface entries. The decoder and pipeline patches in #383 were also read.
Static conclusions:
- Input windows end at the declared function boundary and are capped at 4,096 bytes. Callback recipes pass the same operand-width, storage-range, temporary-definedness, operation and CFG checks as static profiles.
- Reply state is invocation-local. A repeated, missing, null, empty or oversized reply fails; accepted JSON is copied before the callback returns. The sink's return value means copied, not semantically validated.
- Python retains the trampoline through the native call, catches callback exceptions, avoids re-entering the decoder after an exception and re-raises after the native response is freed by
owned_string. - The graph and input limits do not preempt trusted callback code. Stable caller context and synchronous lifetime are explicit contracts, not sandbox guarantees. State-C output is not proof of equivalence to an unknown interpreter.
- Existing tests describe independent reply-buffer reuse, error ownership, 64-bit PCs, reentrancy/concurrency and both C routes. They were read, not executed today.
Full source reads: lib/emulation/os/linux/kernel/{LinuxOutput.cpp,LinuxKernel.h,LinuxServices.cpp}, lib/emulation/os/linux/LinuxValues.def, lib/emulation/os/linux/android/{AndroidBionic.cpp,AndroidKernelServices.def}, unittests/emulation/LinuxOutputNativeTests.cpp, and unittests/emulation/fixtures/{LinuxOutputCases.def,linux_output.c}. The #392 LinuxOutput patch was also read.
Focused caller/test reads: LinuxProcessTests.cpp scalar output cases and vectored registration/budget sections (lines 252–259, 281–289, 301–339); AndroidNativeTests.cpp vectored output/errno and budget sections (128–150), plus scalar-output and request-limit assertions.
Static conclusions:
- Descriptor lookup narrows to 32 bits before checking supported sinks; vector counts are bounded at 1,024. Descriptor metadata and signed lengths are imported before payload publication.
- Address extents are validated before payload access. The one-vector transfer cap and multi-vector original-extent checks are deliberately distinct.
- Whole-call output budgeting covers both streams before publishing that call. A later payload fault retains an earlier readable prefix; metadata errors publish no payload.
- Bionic alone translates negative Linux results to
-1and errno; raw services retain negative errno. The scalar zero-length path still checks user-address domain, whereas zero vectors ignore the table pointer. - The original Linux fixture compares regular-file redirects, not pipe atomicity. Native ARM64 backend coverage and complete process semantics cannot be inferred from these source checks.
No new defect in these paths was established strongly enough for an automatic correction. The known Android default-scope/flag work is already proposed in #395; it is not duplicated here.
Reviewed at the pinned source:
scripts/run_native_cpu_ci.py:30–286,run_native_cpu_methods.py:26–244,audit_hvf_shards.py:40–164,prepare_hvf_batches.py:26–89scripts/diagnose_hvf_methods.py:32–258,diagnose_hvf_recovery.py:21–159.github/actions/hvf-intel-diagnostic/{run.cjs,active-sample.cjs},.github/actions/hvf-intel-recovery/run.cjs.github/workflows/{hvf.yml,hvf-intel-recovery.yml},.github/actions/hvf-cpu-batches/action.ymlscripts/{NativeHVFTests.def,NativeDarwinTests.def}- Associated
scripts/tests/test_{run_native_cpu_methods,audit_hvf_shards,prepare_hvf_batches,diagnose_hvf_methods,diagnose_hvf_recovery}.py, both actions'run.test.cjsand diagnosticactive-sample.test.cjs
The audit checks exact command and CTest-property contracts, clean source/host/profile identity, whole-method shard membership, complete disjoint result union, required native outcomes, deadline and child-retirement records. The repetition path requires consecutive exact RUN/OK/PASSED records and final retirement. Partial plans/progress, missing shards, required skips and timed-out children cannot satisfy full acceptance. No new proven collector defect was found.
Separate uncertainty: Direct-child completion is recorded; absence of every possible descendant is not independently established. No concrete present failure path was demonstrated. Static inspection cannot diagnose the hosted runner loss.
At 01:04 UTC, the pinned 00f44615 had 10 checks: five successful, four cancelled and one skipped:
- Main CI 37165654041: cancelled. Linux/macOS/Windows integration jobs cancelled; both Windows caller-context jobs succeeded; optional native WHP skipped.
- Mobile Decompilation 37165654036: cancelled. Ubuntu/macOS succeeded; Windows cancelled.
- LLVM Style 37165654017: succeeded.
Legacy status contexts are empty. These partial successes do not establish full integration. Both CI/mobile workflow headers explicitly enable cancel-in-progress; no workflow policy was changed.
The dev Actions creation window October 3 01:12 UTC to October 4 00:58 UTC contains 461 runs, fully enumerated as 100 + 100 + 100 + 100 + 61 and an empty sixth page. At collection, its 99 main-CI runs were 96 cancelled, two failed and one in progress; that last run later cancelled as recorded above. No green completed main-CI run was observed in the window. The real-application collection had 96 skipped, two cancelled and one queued run; that queued run belongs to earlier source a4492d7b, not today's pinned head.
The two failed main-CI runs, 37144486804 and 37147321022, report the same capability-manifest failure in their inspected Linux logs. The workflow step is named “Verify Debug and Release target flags,” but the failing assertion was test_repository_manifest_is_honest_and_executable: the old unparameterized BytecodeCAPI test filter and missing C/JSON/Python callback declarations.
10198de5 synchronized the merged declarations; #384 added the expanded evidence. Today's capability entry and expected-surface assertions retain these corrections. They are existing delivered fixes, not new fixes from this review, and do not prove current full CI success.
Intel Darwin, independently inspected: Run 37106013999, source 8dcc74c59da303176801b99747a60339161b824b, succeeded. Artifact 11267489438 was downloaded and its SHA-256 matched cd8fabbd7d031ac4ad7b891b8e5a52f3e3abe3c39306d9c4a1893e40912e78ef. All 32 original XML/status/mapping sets reconcile: 286 unique results, 52 passed, 234 skipped, zero failed; all 26 required x64 HVF workloads passed, including the original DarwinNative reference. All 32 processes recorded exit zero, no timeout and retirement. Existing logs additionally confirm ten transport cases, 100 recovery repetitions and isolated CR8 success. This is historical bounded Darwin/transport evidence, not full Intel CPU acceptance or today's head.
Intel recovery, independently inspected incomplete evidence: Run 37159724276 ended in failure at October 3 23:41:30 UTC. Controller e4a8169e tested source bd284894c60427cf4e6a60e661a1fa0df8a070f5. Only the plan and eleven progress artifacts survive; there is no final retirement result and the job-log endpoint returns 404. The last artifact 11286787441 was downloaded and matched its server SHA-256. Its untruncated original log proves 252 complete consecutive repetitions and the start of 253, without a failure/skip in that preserved prefix. It does not prove iteration 253's outcome or the requested 1,000 repetitions. Repository documentation attributes the failure to lost runner communication; that annotation itself was not independently retrieved here. No root cause is inferred.
ARM64 HVF, maintainer-reported: Current HVF documentation reports clean source e4a8169e with 7,125 CPU registrations, 882 passed, 6,243 inapplicable skips, zero failed and 16/16 required native cases; independent Darwin profile 65 passed, 221 skipped and 39/39 required cases, plus 1,000 recovery repetitions and twelve transport cases. These are local evidence reported by the maintainer, not local logs independently accessed today. CPU and Darwin totals overlap and must not be added.
The complete Intel CPU gate, a complete uninterrupted current integration profile and native ARM64 KVM/WHP evidence remain distinct acceptance gaps.
Dependency: A matching native Intel execution with durable final evidence; the current preserved recovery prefix is insufficient.
Next action: Reconcile already-authorized full inventory/shard evidence against the exact tested source and attempt. Preserve controller/source distinctions and investigate missing final evidence separately from guest semantics.
Acceptance: All sixteen shards from one coherent clean source/attempt form the exact full inventory with every required native outcome passing and retirement recorded, or an equivalent complete unsharded gate. A transport success, partial shard or 252-of-1,000 recovery prefix does not qualify. This review initiates no execution.
Dependency: The capability-manifest corrections are present; one identified source still needs terminal complete evidence.
Next action: Inspect eventual authorized automatic results without transferring success between commits. Keep real-application producer/consumer identities separate from mobile fixture results.
Acceptance: Linux, macOS and Windows complete their intended audited integration profiles for the same identified source, with required cases executed; real-application qualification supplies actual completed evidence instead of skipped/queued consumers.
Dependency: Draft #394 (LLVM C aggregate values/ABI) and #395 (Android default symbol scopes) need review and exact-head evidence.
Next action: Review aggregate interoperability/rejection cases and explicit scope/residency/flag contracts before counting them delivered. Relate implemented Windows/emulator and Swift/Objective-C work to #104 and #101, preserving remaining unsupported cases.
Acceptance: Each selected criterion has an implementation/evidence link or explicit gap; draft work is not counted as merged acceptance. Seventeen issues remain open, including fourteen epics; no milestones, and only #12 is assigned. No issue is closed by inference from merged PRs.
- Enumerated 226 commits and 895 raw changed file/submodule paths since the previous pinned head.
- Reviewed callback lifetime/validation, Linux/Bionic output boundaries and native evidence collectors with the exact bounded scope above; found no new proven defect warranting a code correction.
- Counted 31 merged PRs by the initial observation, separating progress-only #363; ordinary issue count stayed 17.
- Independently reconciled historical Intel Darwin success and the incomplete 252-repetition recovery prefix; kept reported local ARM64 results separate.
- Diagnosed two historical main-CI failures as already-corrected capability drift. The pinned main CI and mobile workflows later cancelled.
- Preserved the complete existing tracker and its later Windows policy-path correction.
- Documentation-only topic-branch/draft-PR proposal. No tests, builds, repository scripts, manual CI, merge, deployment, dependency or security-setting changes. The English commit uses
[skip ci]; independently configured automatic checks may still occur.
At 01:05 UTC, dev had advanced to 064b01cc through #396, merged at 01:01:05 UTC. It factors shared LLVM C exit tests. This later change is outside the pinned 226-commit inventory and source review. Open PRs fell to two and merged PRs since yesterday became 32, including progress-only #363. The publication branch starts from the re-read current dev; PROGRESS.md was unchanged from the initially read blob.
Collection limits:
- Open issue/PR collection: twenty records (seventeen ordinary issues, three PRs), then empty second page. Updated collection: 34 PRs, no ordinary issue, then empty second page.
- The first 100 most recently updated PRs crossed the tracking boundary and cover all in-window records; older complete PR history was not enumerated.
- Exact-head workflows/checks: three/ten records, both followed by empty second pages. Six selected PRs (#363, #383, #392, #394–396) returned no submitted reviews, review threads or comments; this is not independent approval.
- Two failed-run job collections and selected Linux logs were inspected. Not every historical log, native artifact or PR diff was audited. Artifact verification read data only and did not execute repository workloads.
- AGENTS.md and CONTRIBUTING.md were read first; relevant architecture/testing/roadmap sections and repository guidance were consulted. Only the root AGENTS.md exists in the full tree.
- GitHub reports dev unprotected and an empty repository ruleset collection. The topic-branch/draft-PR workflow is still followed; no protection settings were changed.
- Broad Windows SEH/context/module semantics, Swift/Objective-C identity recovery, numeric optimization, all other changed paths and unmerged #394/#395 code remain outside today's bounded source audit. Static review cannot establish compilation, runtime behavior, race freedom, total ISA coverage or release readiness.
October 3 tracker with the complete October 2, October 1 and September 30 history
Last verified: 2026-10-03 09:12 Asia/Shanghai (UTC+08:00) / 2026-10-03 01:12 UTC
This is a point-in-time daily issue/PR and static-review tracker. The roadmap, architecture, testing guide and contribution guidance remain authoritative. Priorities below are proposed acceptance work, not assigned deadlines or an overall completion percentage.
Source review is pinned to the observed dev commit. Issue/PR counts precede this documentation proposal.
| Measure | Verified state |
|---|---|
| Open issues | 17; unchanged |
| Open pull requests | 0; unchanged before this proposal |
| PRs merged since 2026-10-02 01:11 UTC | 35: #328–362 |
| PRs closed without merge in that window | 0 |
| Ordinary issues updated/closed in the window | 0 / 0 |
| Observed dev commit | 99340b58 |
| Previous observed dev commit | d87f27d2 |
| Change inventory | 262 commits; 567 changed file/submodule paths, including 175 added and zero deleted |
| New statically confirmed defects | 0 in the bounded scope below |
| Proposed code fixes today | None; documentation-only update |
The comparison was read across 100 + 100 + 62 commit records and an empty fourth page. GitHub's comparison limits its file list to 300 paths; the 567-path inventory instead compares the complete recursive Git trees (5,313 and 5,496 entries, neither truncated), excluding directories. Enumeration is not a claim that every changed path was audited.
- Yesterday's PR #328 merged at 2026-10-02 01:29:42 UTC as 3c1f637f. The canonical WDK path assertion is present on the inspected dev tree. Its merged PROGRESS.md exactly matches the previous tracker preserved below.
- #329 expanded complete WDK corpus/SEH acceptance. Later x64 bit-string, string transfer and string comparison changes landed in #336, #338 and #342.
- Windows process memory, module graphs, lifetimes and exports landed through #346, #350, #352, #355 and #357. These changes enlarge the current Windows native requirement to 404 outcomes.
- Native macOS HVF and Darwin environments were integrated. The latest 99340b58 writes and captures Intel RIP/RFLAGS directly through VMCS after cancellation recovery. Its actual Intel full gate is still running.
- Interpreter recovery domains, bounded source generation, exported bytecode recovery, Swift/Objective-C binding and additional lifting changes were inventoried, not comprehensively source-reviewed today.
Mode: Read-only source, diffs, caller/test contracts, configuration and existing GitHub CI evidence. No repository program, build, test, script, linter or formatter was executed. No workflow was manually dispatched or rerun. No new defect was established strongly enough to justify an automatic code change.
HVF source coverage and findings are recorded below. Source invariants are not runtime acceptance.
The source/test audit covers 38 distinct artifacts in total, including the native-evidence and historical-failure sections below; four workflow files were additionally inspected.
Full HVF/adjacent source and test reads:
lib/emulation/backends/hvf/{HvfExecutor.cpp,HvfExecutor.h,HvfX64Machine.cpp,HvfX64Registers.def}lib/emulation/backends/RunDeadline.handlib/emulation/core/MachineRunControl.hlib/emulation/arch/x86_64/{X64Machine.cpp,X64Machine.h,X64MachineProbe.cpp,X64MachineProbe.def,X64OperandRegisters.def,CheckedX64Instructions.def}lib/emulation/os/windows/driver/WindowsX64ExecutionPolicy.cppandinclude/neverd/emulation/X64Registers.defunittests/emulation/{HvfExecutorTests.cpp,HvfTests.cpp,HvfTestPolicy.h,X64StateTransitionTests.cpp,MachineRunControlTests.cpp,RunControlTests.cpp,NativeEntryTests.cpp}scripts/NativeHVFTests.def, also included in the evidence inventory review below
Focused adjacent sections: CheckedX64Backend.cpp register validation, checked admission, native step/error handling and RAM/CPU publication (principally lines 191–204 and 265–590); unittests/emulation/CMakeLists.txt registrations for NeverDHvfTests, NeverDX64ExceptionTests and NeverDRunControlTests. The native-evidence script was also read in full below.
- Intel RIP/RFLAGS prepare and capture use the VMCS boundary on each step; their register-API entries are removed. Capture writes a staged next packet, so a failed field read does not publish partially captured caller state.
- Unsolicited Intel IRQ exits retry within one deadline invocation, preserving native state and the cancellation generation. Native errors return immediately. The watchdog is disarmed and acknowledged before cancelled vCPU teardown/recreation.
- Every Intel vCPU creation, including recovery, binds managed
IA32_KERNEL_GS_BASE, denies guest MSR access and initializes the private value. CR8 completion accepts only authenticated MOV-from-CR8 qualifications and validates privilege, GPR, instruction length and value before modifying state. - The checked caller discards speculative RAM on machine failure. Ordinary cancellation/capture failure does not publish staged CPU state; authenticated exceptions retain their precedence.
- The cancellation regression covers deadlines, stop tokens, unsolicited interrupt followed by stop, a real native return, retry at another RIP and completion-error precedence. After recreation it asserts RIP/RFLAGS/AX, not the complete state packet.
- The separate CR8 regression covers all 16 destination GPRs, priorities 0–15, supervisor success, user #GP(0), RF and complete unchanged-state comparisons. It belongs to
NeverDX64ExceptionTests, outside the 10-case Intel transport-only target. Startup full-state probing occurs at machine creation, not after every cancelled vCPU recreation.
Remaining uncertainty: Only matching-host execution can establish that Apple's framework preserves the intended native state after recreation. A green transport subset cannot replace the full CPU/Darwin gate or establish complete post-cancellation state coverage.
Read in full: run_native_cpu_ci.py, test_run_native_cpu_ci.py, NativeCPUTests.def, NativeDriverTests.def, NativeHVFTests.def, NativeDarwinTests.def, WhpMemoryCases.def, DriverBuiltinImages.def, DriverBackendParityCases.def, and test_build_wdk_driver_fixtures.py.
Also reviewed the shared TestRecord / parse_inventory boundary in audit_ci_test_inventory.py, and JUnit label, status, identity and count parsing in audit_ci_test_results.py.
- Required host-specific test names are selected by explicit ARM64/x64 identity; an unknown architecture is rejected.
- Native profiles reject missing registrations and non-passing required outcomes. JUnit infrastructure not-run, explicit skips, failures and disabled cases remain distinct. Outcome reconciliation retains test name and owner-label identity.
- The transport-only HVF profile is an explicit subset of the full inventory; the Darwin profile expands every declared workload across each matching guest platform.
- Static text inventory counts reconcile: 160 explicit CPU names + 16 WHP mapping cases = 176 CPU outcomes; 26 built-in images + 46 WDK images + 40 scenarios at two bases = 224 driver outcomes; four SEH cases bring the current Windows total to 404.
- These are declaration counts, not newly executed results. Existing regression source covers missing owners, missing results, skipped mandatory hardware cases, wrong owner identity, malformed host selections and deleted Darwin workload requirements.
Read both complete current shared-event headers: AndroidNative.h and ProcessCall.h, the recovery-surface expectations in test_check_capabilities.py, and the corresponding corrective commit patches.
- The two older main-CI failures in the “Verify Debug and Release target flags” step actually failed
test_repository_manifest_is_honest_and_executable, owing to missing recovery-v4 expectations. c4010c33 supplies those expectations; the inspected file retains them and later APIs. This was not evidence of incorrect Debug flags. - The third older main-CI failure was a duplicate
NativeCallEventdefinition while compiling Linux services. c3493d72 removes the Android duplicate and retains Library/Symbol in the shared header. The inspected source contains that correction. - These already-delivered fixes were not duplicated. No claim is made that current full integration has passed.
Relevant architecture/testing/HVF guidance, the complete HVF workflow, and CI/mobile/style trigger and concurrency sections were also inspected. The rest of the 567 changed paths, broader Windows loader/export semantics, Darwin syscall semantics, Objective-C/Swift source recovery and interpreter/refinement work remain outside this bounded audit.
Exact-head snapshot: 2026-10-03 01:12 UTC, for 99340b58657e3907588a33b363435f79b74b86fe.
| Workflow | Observed state | Evidence |
|---|---|---|
| CI | In progress; all three platform jobs at their configuration/script-verification step; optional WHP job skipped | 37084475387 |
| HVF hosted-intel / full | In progress at the required transport step; full CPU and Darwin stages not reached | 37084520059 |
| Mobile Decompilation | Workflow API reports queued; Ubuntu job succeeded, macOS in progress, Windows queued | 37084475394 |
| Mobile Real Applications | Skipped | 37084500511 |
| LLVM Style | Success | 37084475343 |
Exact-head check runs: 18 total: 2 successful, 10 skipped, 5 in progress and 1 queued; zero failed at this snapshot. Legacy statuses are empty; their combined pending state does not establish failure or success. The existing manually initiated Intel workflow was observed only; this review did not initiate it.
The dev Actions collection created from 2026-10-02 01:11 UTC through 2026-10-03 01:05 UTC contains 597 runs, across six non-empty pages (100 + 100 + 100 + 100 + 100 + 97) and an empty seventh page. Its 113 main CI runs comprise 109 cancelled, three failed and one in progress, with no completed green main CI run in that query. The three failures above were diagnosed from their Linux logs and corresponding source corrections. Yesterday's tracked main CI and Mobile Real Applications later cancelled; yesterday's mobile-fixture success stays scoped to yesterday's commit.
Windows WDK/CPU: The native WHP job at 9d4c130c2f11d95a2f80f1055dfdbb34de07715c reports 1,121 passed, 1,667 skipped, zero failed/disabled/not-run, no missing/unexpected identities, and all 359 required outcomes executed. This confirms substantial progress beyond yesterday's 197-outcome blocked gate. It does not validate the newer 404-outcome inventory or today's head.
Darwin on x64 KVM/WHP: The existing run at 36e11ca8a3d80aecf585d3328018839ce7fdb989 succeeded on both hosts. Both inspected job logs record 51 passed, 235 skipped, zero failed, with all 26 required Darwin workloads executed. This is Darwin guest-contract evidence on Linux/Windows native transports, not Intel macOS HVF acceptance. The separate native macOS kernel reference succeeded on both x86_64 and arm64 at e727d3eab7086063bb392444bd55014ac48d43c3; only its job/step metadata was checked here.
Intel HVF: The older transport job at 48042a5e90e0977585114de092e423cd64b7f95f had 9 passed / 1 failed / no skips. The exact failure was the first Prepare(RetryPC) after cancellation in NativeIntelCancellationAndCompletionFailureAllowRetry, reporting an unexpected VM exit. Full CPU and Darwin stages were skipped. The new VMCS correction is on today's head; its existing full workflow remains incomplete.
Apple Silicon HVF: macos-hvf.md reports a clean-source full gate at 48042a5e with 841 passed, 5,942 inapplicable skips and all 16 required outcomes, plus the 12-case transport subset. Those local results are maintainer-reported documentation, not logs independently accessed in this review. They must not be described as absent native ARM64 evidence, but also must not be transferred to Intel HVF or ARM64 KVM/WHP.
Status: The previous gate failed after cancellation; the exact-head full workflow is still at transport validation.
Next action: Review its eventual transport, full CPU and Darwin outcomes against the same source identity. Include the all-GPR CR8/CPL3 regression and distinguish the retry test's limited RIP/RFLAGS/AX assertions from complete state coverage.
Acceptance: The identified commit passes every required transport case, the complete full-profile CPU gate and all matching Darwin workloads, with no missing/skipped required tests. Probe-only or transport-only success is insufficient. No manual execution is part of this static review.
Status: Current main CI is incomplete; the bounded dev window has 109 cancellations and no green main CI. Current mobile fixtures are incomplete and real-application qualification is skipped.
Next action: Reconcile existing terminal outcomes after the source fixes already present. Keep any superseding commit separate. Record real-application producer/consumer identity and actual execution instead of carrying forward a historical green fixture result.
Acceptance: Linux, macOS and Windows complete the intended integration profile for one identified commit, with audited test execution. Real-application qualification supplies actual evidence; a skipped consumer does not satisfy acceptance.
Status: Historical Windows evidence passes 359 required outcomes; the current inventory requires 404. Seventeen issues remain open, including 14 epics; none has a milestone, and only #12 is assigned.
Next action: Evaluate authorized existing/native evidence for the expanded Windows process/module/export requirements. Map delivered work to #104, #101 and #4, separating implementation, verified platform scope and remaining gaps. The historical #12 report was not re-audited today.
Acceptance: Each selected criterion has an implementation/evidence link or an explicit gap; current Windows acceptance executes all 404 mandatory outcomes at an identified commit. Matching-host results remain distinct, and no issue is closed solely because related PRs merged.
- Inventoried 262 commits and 567 changed file/submodule paths since the previous source snapshot; reviewed the bounded HVF, native-evidence and historical-failure scope above.
- Found no new statically proven defect requiring a code change. Yesterday's WDK correction is merged.
- Reconciled 35 merged PRs, no unmerged closures, 17 open issues and no open PR before this proposal.
- Verified historical Windows 359-outcome success and x64 KVM/WHP Darwin 26-workload success, retaining the current 404-outcome and Intel HVF acceptance gaps.
- Diagnosed three older main-CI failures and verified their source corrections already exist. Current integration remains incomplete.
- Preserved the complete October 2 tracker, including October 1 and September 30 history, below.
- This English documentation-only proposal uses a topic branch and draft PR. No build, test, repository script, manual workflow trigger, merge, deployment, dependency revision or security-setting change was performed. The commit uses
[skip ci]; independently managed automatic checks may still occur.
- Open issue/PR collection returned 17 ordinary issues and no PRs, followed by an empty second page; a separate open-PR collection was empty. Updated issue/PR records returned 35 PRs and an empty second page, with no ordinary issue.
- The first 100 most recently updated PRs extend past the tracking boundary and include all 35 in-window records. Older complete PR history was not enumerated.
- Exact-head workflow/check collections returned five/18 records and empty second pages. Main CI and current HVF job collections returned four/one records with empty second pages. Selected historical job collections were small; not every historic log was inspected.
- The separate dev manual-event collection returned 34 records and an empty second page. The historical WHP success was followed directly from repository evidence and is separate from the dev-bound Actions count.
- PRs #328, #329, #357 and #362 returned no submitted reviews, inline review threads or conversation comments. This is not independent approval.
- GitHub reports dev unprotected and an empty repository ruleset collection. The topic-branch/PR contribution workflow is still followed; no protection was changed.
- PROGRESS.md was compared with yesterday's merged version and re-read before writing; preserve this full history and future human edits.
- Pending, skipped, cancelled, failed, maintainer-reported and independently inspected results remain distinct. Static review does not establish compilation, runtime behavior, race freedom, complete ISA coverage or release readiness.
At 2026-10-03 01:16 UTC, dev had advanced to eee92640, which separates and time-bounds Intel transport compilation/execution in the HVF workflow. Its one-file patch was read, and PROGRESS.md was unchanged. This later commit is outside the pinned 262-commit/567-path inventory and source snapshot above. The existing Intel run for 99340b58 was still in progress; no terminal acceptance is inferred.
2026-10-02 tracker, priorities, evidence and earlier history
Last verified: 2026-10-02 09:11 Asia/Shanghai (UTC+08:00) / 2026-10-02 01:11 UTC
This is a point-in-time daily issue/PR and static-review tracker. The roadmap, architecture, testing guide, and contribution guidance remain authoritative. Priorities are proposals, not assigned deadlines or a completion percentage.
The issue/PR snapshot precedes today's review PR. Source inspection is pinned to the observed dev commit, not to a moving branch.
| Measure | Verified state |
|---|---|
| Open issues | 17; unchanged |
| Open pull requests | 0; unchanged before this review PR |
| PRs merged since 2026-10-01 01:02 UTC | 41: #285–319 and #321, #323–327 |
| PRs closed without merge in that window | 2: #320 and #322 |
| Ordinary issues updated/closed in the window | 0 / 0 |
| Observed dev commit | d87f27d2 |
| Previous observed dev commit | 6eb2e5c6 |
| Change inventory | 266 commits; 521 changed file/submodule paths |
| Bounded source review | 31 source, test and build artifacts, with sections listed below |
| New confirmed defects | 1 test-portability defect; one-line correction committed |
| New production-code defects established | 0 in the sampled scope |
The comparison was read across three commit pages (100 + 100 + 66), followed by an empty page. GitHub limits the comparison's changed-file list to 300 paths; the 521-path inventory therefore comes from comparing complete recursive Git trees (5,154 and 5,313 entries, neither truncated). Enumeration is not a claim that every changed path was code-reviewed.
- Yesterday's tracking PR #285 merged at 2026-10-01 03:53:57 UTC. Its PROGRESS.md content is identical to the version on the inspected dev tree; the complete previous tracker is preserved below.
- #319 centralized width-aware absent-SIB-index handling across scalar address construction, metadata auditing and EVEX validation.
- #308, #311, #313 and #316 refined native x64 state ownership, XSAVE handling and physical x87 transition evidence.
- #317 expanded the native driver gate from the older 97 required CPU/driver outcomes to 197, including the reproducible WDK corpus. Its PR description's queued run has since failed before native execution; today's correction addresses the observed test assertion.
- Other delivered work includes Android ARM64 native environments, external bytecode profiles, preferred-base PE evidence, loop refinement, bounded frame transfers and Objective-C/Swift recovery. These were inventoried, not comprehensively audited.
Mode: Source, diff, caller, configuration and existing CI-log inspection only. No repository program, build, test, linter, formatter or script was executed. No workflow was manually dispatched or rerun.
Test-portability defect: test_build_wdk_driver_fixtures.py, test_cmake_paths_preserve_spaces_and_reject_list_or_code_expansion, compared the original path spelling with a cache entry that deliberately uses Path.resolve().
The historical Windows WHP job, at commit 9944433cc4593a59fe899f90c4a532306a4f9ed6, failed this exact assertion: the temporary path used the short Windows user-directory spelling while the emitted path used its resolved long spelling. The script suite reported 25 tests with one failure. The subsequent native build/verification step was skipped. This is not evidence of an XSAVE or WHP execution failure.
The same raw-path assertion was still present at today's pinned dev commit. Fix 9b5b23ef changes only the expected path to image.resolve().as_posix(). It retains the quoted-space assertion and the separate invalid-character rejection checks. Production canonicalization and validation are unchanged.
Verification: Independently checked the producer/test contract and historical log, then remotely read back the fixed file and commit diff. The commit changes one line in one test file. The fix has not been executed or validated by a new Windows run; it is proposed on today's topic branch and is not merged.
The following 31 artifacts were inspected at d87f27d2. Whole-file reads are distinguished from selected sections.
x86 SIB address semantics: 10 artifacts
- X86LiftDetail.h: shared
isNoSibIndexdeclaration and relevant PR patch - X86Lifter.cpp:
isNoSibIndex,computeEA, memory read/store callers, undefined-output memory audit, unmapped-register rejection and final sidecar publication - X86LiftSIMDMemory.cpp: ordinary memory validation, raw SIB/tail checks, EVEX/VEX3 adapters and masked memory-load construction
- X86LiftSIMDMove.cpp: masked memory-operand validation and full-vector move caller, including address construction and mask handling
- X86Regs.cpp: general-register mapping and invalid-register fallback
- Decoder.cpp:
liftToLowdispatch and undefined-effects initialization - X86Lifter.h: shared memory-intrinsic/address helpers
- X86_64_NoIndexAddressTests.cpp: all nine regression cases
- X86_64_EVEXMemoryBroadcastTests.cpp: absent-index masked-broadcast/move and contradictory-metadata cases, plus their helpers
- unittests/lift/CMakeLists.txt: dedicated no-index test-target registration
XSAVE/WHP state transfer: 19 artifacts, read in full
- X64FPState.cpp, .h, and .def
- X64Machine.h, X64MachineProbe.cpp, and X64MachineProbe.def
- WhpXsaveState.h, WhpXsaveRegisters.def, WhpProtocol.def, and WhpMachine.cpp
- X64XsaveTests.cpp, X64XsaveCases.def, WhpXsaveTests.cpp, and WhpHostFailureCases.def
- X64FPStateTests.cpp, X64FPCases.def, and X64MachineProbeTests.cpp
- X64StateTransitionTests.cpp and X64StateTransitionCases.def
WDK assertion and producer: 2 artifacts, read in full
- build_wdk_driver_fixtures.py: especially
cache_entry, its build caller and publication - test_build_wdk_driver_fixtures.py: especially path spelling, quoted spaces and pre-resolution rejection tests
Repository guidance, relevant architecture/testing sections, roadmap hardening scope, CI/mobile trigger and concurrency definitions, and the native CI configuration step were also inspected.
No new production-code correctness defect was established strongly enough for an automatic fix.
- Absent SIB indices are width-specific; they do not contribute a scaled register term. Effective addresses retain 32-bit wrapping/zero-extension and separate FS/GS offsets from ordinary address provenance. Real R12 indices remain ordinary mapped registers. Raw EVEX tail validation checks the encoded index extension before accepting absent-index aliases.
- Invalid pseudo-register bases or wrong-width pseudo-indices become unmapped register operands and are rejected transactionally in strict lifting. Existing tests cover address widths, all redundant scale encodings, loads/stores, relocation ownership, undefined sidecars, masked accesses and malformed metadata. These are descriptions of test source, not new test results.
- Standard initial-SSE XSAVE packets retain and validate MXCSR; compacted initial-SSE packets reset it. Both clear XMM lanes. The codec stages the next state before publication and rejects unsupported layout bits, inconsistent lengths and truncated extension storage.
- WHP capture stages XSAVE decode, named metadata reads, consistency checks and supplemented-state validation before publishing. The machine caller stages complete state around the transfer. x87 transition/cancellation fixtures retain exact physical-state assertions.
Limits: The remaining changed paths, Objective-C/Swift pipeline, Android environment, general loop/refinement work, resource-cache concurrency, ARM64 transport and PE refactor were not source-audited in this pass. Static inspection does not establish runtime behavior, compilation/linking, formatting, race freedom, release readiness or complete ISA coverage.
Exact-head CI snapshot: 2026-10-02 01:10 UTC, for d87f27d29ecb097d1fa8483006797dc4765c3972.
| Workflow | Observed state | Evidence |
|---|---|---|
| CI | In progress; Linux, macOS and Windows building; optional native WHP job skipped | 36947225176 |
| Mobile Decompilation | Success on Ubuntu, macOS and Windows | 36947225342 |
| Mobile Real Applications | Pending | 36949181960 |
| Push on dev | In progress | 36947225134 |
| LLVM Style | Success | 36947225307 |
| Code Quality: Push on dev | Success | 36947225199 |
| Prebuilt LLVM Audit | Success | 36947225314 |
| EVM Upstream Audit | Success | 36947225350 |
Exact-head check runs: 16 total: 11 successful, 1 skipped, 4 in progress, 0 failed. Legacy commit statuses are empty; their combined pending state alone is not a failure or an all-checks pass.
The dev Actions collection created from 2026-10-01 01:02 UTC through 2026-10-02 01:03 UTC contained 929 runs, across ten pages (nine of 100, one of 29). Its 115 main CI runs comprise 114 cancelled and one in progress; no completed green dev main CI run was observed in that window. This is an integration-evidence gap, not proof of a code failure. Yesterday's tracked main CI and mobile run both subsequently cancelled.
The older WHP run 36894495012, at e7f205ab4ecb5a91646e8ea9ee8dd6b74ecb230a, succeeded. Its job log records 803 passed, 1,522 skipped, zero failed/missing/not-run, and all 97 required native CPU/driver outcomes executed. This is real earlier Windows evidence, not current-head or expanded-corpus acceptance.
The later 197-outcome WDK/native run failed the path assertion before native verification. Today's one-line fix addresses that blocker but does not prove the expanded run will pass. The optional native job is skipped on today's ordinary dev push. Native ARM64 runtime evidence remains explicitly unavailable in the reviewed documentation.
Status: Mobile fixtures now pass on the inspected head; the three-platform main CI is still building. The preceding 114 dev main CI runs in the collection were cancelled.
Next action: Inspect the existing main CI's terminal platform/test outcomes, retaining exact commit identities and all skip/missing-test distinctions. If development supersedes the run, record the new integration gap rather than transferring a previous success.
Acceptance: All three platform jobs finish for one identified integration commit, with required test execution audited. No manual dispatch/rerun is included in this static-only review.
Status: The older 97-outcome native gate is green; the newer 197-outcome gate stopped before CPU verification. The canonical-path assertion correction is committed on today's review branch, unexecuted.
Next action: Review the one-line test fix and later evaluate an authorized Windows native CPU/driver run for a commit containing it. Preserve the original canonicalization and invalid-path protections.
Acceptance: Configuration passes, all 197 required native outcomes execute, and failed, missing or skipped required cases remain failures. The observed older 97-outcome run and portable XSAVE source coverage do not satisfy this larger gate.
Status: Exact-head Mobile Decompilation is green; Mobile Real Applications is pending. The 17 open issues retain unchanged planning metadata: 14 epics, no milestones, and only #12 assigned.
Next action: Record the real-application producer/consumer identities and actual result. Map merged implementation and current evidence to #101, #104 and #4, distinguishing delivered code from outstanding acceptance. The historical Windows report in #12 was not re-audited today.
Acceptance: Selected criteria have an implementation/evidence link or an explicit gap and a bounded next owner/action. A merged PR, stale unchecked issue or skipped consumer alone does not establish completion.
- Inventoried 266 commits and 521 changed paths; reviewed the bounded 31-artifact scope above.
- Corrected one statically confirmed test-portability defect in 9b5b23ef. No production-code change was justified.
- Recorded 41 PR merges, two unmerged closures, 17 open issues and no open PR before today's publication.
- Confirmed current-head three-platform mobile fixture success and the still-incomplete main CI/real-application result.
- Distinguished earlier 97-outcome WHP success from the later expanded 197-outcome configuration failure.
- Preserved the complete October 1 tracker, including the September 30 history, below. Yesterday's #285 is merged; today's focused topic-branch update requires its own draft PR.
- No repository code, builds, tests, scripts, linters or formatters ran; no manual CI trigger, merge, deployment, dependency revision or security-setting change was performed. Commits use English messages with
[skip ci]; automatically triggered GitHub checks can still occur independently.
- Source, issue and CI states are point-in-time observations, not continuous monitoring. New review PRs are excluded from pre-publication counts.
- Open issues returned 17 records and an empty second page; the separate open-PR query was empty. Updated issue/PR records returned 43 PRs and an empty second page, with no ordinary issues.
- The recent PR collection's first 100 updated records spans past the tracking boundary. All 43 in-window PRs are present; the older complete PR history was not enumerated.
- Exact-head workflows returned eight records and an empty second page; check runs returned 16 and an empty second page. Main/mobile job collections returned four/three records, each followed by an empty page.
- The separate manual-event collection through 01:10 UTC returned 29 existing runs and an empty second page. This review read it only; no run was created. Only the two native jobs discussed above were examined in log detail.
- Selected PRs #285, #308, #311, #313, #316 and #319 returned no submitted reviews, inline review threads or conversation comments. This is not an independent approval.
- GitHub reports dev unprotected and an empty repository ruleset collection. No protection/security setting was changed. The contribution guide's topic-branch/PR workflow was followed.
- PROGRESS.md was checked against yesterday's merged content and re-read before replacement. Preserve history and any human edits on later refreshes.
- Remote file/diff verification proves publication of the proposed correction, not passing validation or permission to merge.
2026-10-01 tracker, priorities, evidence and earlier history
Last verified: 2026-10-01 09:02 Asia/Shanghai (UTC+08:00) / 2026-10-01 01:02 UTC
This is a point-in-time daily issue/PR and static-review tracker. The roadmap, architecture, testing guide, and contribution guidance remain authoritative. Priorities are proposals, not assigned deadlines or a completion percentage.
Source snapshot is taken before opening the documentation-only daily-tracker draft PR.
| Measure | Verified state |
|---|---|
| Open issues | 17 |
| Open pull requests | 0 |
| PRs merged since 2026-09-30 03:51 UTC | 19: #220 and #267–284 |
| Issues closed in the same window | 0 |
| Observed dev commit | 6eb2e5c6 |
| Previous observed dev commit | 4097148c |
| Change inventory | 160 commits; 410 changed file/submodule paths |
| New confirmed defects in today's sampled code | 0; no production-code change proposed |
The comparison was read across two commit pages (100 + 60). Its changed-file response stops at 300 paths, so the 410-path inventory instead comes from comparing the two complete recursive Git trees; neither tree was truncated. Commit enumeration and path inventory are not claims that every change was code-reviewed.
- #220 is now merged. Its former draft state and failed historical head are no longer current open-PR blockers.
- All 18 subsequently created PRs, #267 through #284, are also merged.
- #283 consolidated failure-atomic ARM64 native integer-state capture.
- #284 corrected MMIO test callback ownership across standard-library implementations.
- Recent work also includes KVM thread/state reuse, native execution profiles, loop refinement, mobile recovery and documentation fixes. Those broader features were inventoried, not comprehensively audited today.
Mode: Static source and diff inspection only. No repository program, build, test, linter, formatter or script was executed. Existing GitHub Actions evidence was read without dispatching or rerunning workflows.
Primary change: 4f189d5e, inspected in the current dev tree, with related callers and rollback code. Secondary change: bfb9a527, the MMIO fixture-ownership fix.
The bounded review covered these 18 code, test and build artifacts. Relevant sections, rather than entire files, are identified explicitly.
- AArch64GeneralState.cpp, .h, and .def
- AArch64Machine.h and AArch64Machine.def
- Registers.h and ARM64 inventory/ordering in Registers.def
- KvmAArch64Machine.cpp and WhpAArch64Machine.cpp
- CheckedAArch64Backend.cpp
- RAMTransaction.h and RAMTransaction.cpp
- AArch64GeneralStateTests.cpp and AArch64GeneralStateCases.def
- lib/emulation/CMakeLists.txt and the ARM64 test-target stanza in unittests/emulation/CMakeLists.txt
- The
SharedDeviceRetirementReleasesCallbacksBeforeCPUsResumecase in MemoryLifecycleTests.cpp andExactUnmapRetiresCallbacksAndReturnsBudgetin UnicornMMIOTests.cpp
Repository guidance, relevant architecture/testing sections, and workflow trigger/concurrency definitions were also inspected.
No new correctness defect was established strongly enough to justify an automatic code fix in this scope.
- The ARM64 helper captures X0–X30, SP, PC, NZCV and TPIDR_EL0 into a copy, returns before publishing on any failed read, masks NZCV, then assigns the complete state. The register ordering and both native adapters agree with the 35-entry inventory.
- KVM raw reads and WHP captured-value indexes feed that same helper. The checked caller uses a separate next CPU state and publishes it only after the RAM transaction commits. The transaction destructor restores original RAM when native execution exits with an error before staging.
- The portable test source covers every register-read failure position, missing readers, retry, NZCV masking, both privilege modes, and preservation of vectors and untransferred registers. This describes test coverage, not a test result from this review.
- The MMIO regression fixtures now destroy caller-owned callback objects before testing mapping retirement. Their weak-reference assertions therefore do not depend on a moved-from callback container releasing its captures.
Limitations: The remaining changed paths, complete Objective-C/Swift pipeline, x64 state-reuse implementation and full issue backlog were not audited at source level. Static inspection does not establish native ARM64 KVM/WHP runtime behavior, cancellation interleavings, build/link success, formatting compliance or release readiness. Native ARM64 evidence remains explicitly outstanding in the project's documentation.
CI snapshot: 2026-10-01 01:01 UTC. Every row below is associated with observed dev head 6eb2e5c6423f7b2977568fe070c7cd334f503572.
| Workflow | Observed state | Evidence |
|---|---|---|
| CI | In progress; Linux, macOS and Windows jobs running | 36795886427 |
| Mobile Decompilation | Workflow API queued; Windows job succeeded, Ubuntu running, macOS queued | 36795886438 |
| EVM Upstream Audit | Queued | 36795886326 |
| Push on dev | Queued | 36795885475 |
| LLVM Style | Success | 36795886420 |
| Code Quality: Push on dev | Success | 36795885522 |
| Prebuilt LLVM Audit | Success | 36795886538 |
| Mobile Real Applications | Skipped | 36795891920 |
Exact-head check runs: 24 total: 6 successful, 9 skipped, 4 in progress, 5 queued, 0 failed. Workflow and job/check states are reported separately because their APIs can show different aggregate states. Legacy commit statuses are empty; the combined status's pending value alone is neither a failure nor a full pass.
The complete dev Actions collection created since 2026-09-30 03:51 UTC contained 503 runs, including 62 main CI runs: 61 cancelled and the current run in progress. There was no completed green main CI run in that window. Cancellation is not a code failure, but leaves a substantial integration-evidence gap.
Mobile Decompilation in the same window: 54 cancelled, 5 failed, 2 successful and 1 queued. The latest older success was 36769822465, completed at 2026-09-30 20:19:17 UTC on ac550f17d77d7e1f5e76fdf7b3509e8a7cea801d. It does not establish current-head acceptance. Historical Objective-C x86_64 fixture failures and the old #220 failures must not be relabeled as failures of today's head.
Status: Current main CI is still running; all other main CI runs in the tracking window were cancelled.
Next action: Inspect the existing run's final Linux/macOS/Windows results and preserve its commit identity. If subsequent development supersedes it, explicitly record that the replacement still needs full integration evidence. No workflow dispatch or rerun is part of this static-only review.
Acceptance: All three platform jobs reach terminal states for one identified current integration commit; failures and skipped suites are itemized. Pending or cancelled work is never counted as passing.
Status: #220 merged at 2026-09-30 04:39:17 UTC as 2bbd8019. Current Mobile Decompilation is not complete; Mobile Real Applications is skipped.
Next action: Use exact-head workflow evidence for Objective-C scalar/calls, Blocks and single-session qualification. Compare any remaining failures with the current source; do not reopen historical fixes merely because the previous tracker recorded a failed PR head. The PR's WMF recovery metrics remain author-reported evidence.
Acceptance: Required mobile fixture cases have explicit current-commit results, and real-application qualification has a recorded producer/consumer identity and actual result. A skipped consumer or an older green run does not satisfy this gate.
Status: Portable ARM64 capture tests are present, but native ARM64 KVM/WHP execution evidence is still outstanding. The 17 open issues have unchanged planning metadata; 14 are epics and only #12 is assigned.
Next action: Map delivered work to #104 and related acceptance criteria; separate portable static/test coverage from native transport evidence. Retain #4 release readiness and #12's remaining Windows report as open until verified evidence resolves their specific criteria.
Acceptance: Each chosen criterion has an implementation/test link or an explicit gap, native transport claims name the actual platform and result, and the next bounded task has an owner and verification requirement. No issue is closed merely because a related implementation PR merged.
- Inventoried 160 commits and 410 changed paths since the previous observed dev commit; reviewed the bounded 18-artifact ARM64 capture/rollback and MMIO test scope above.
- Found no new statically proven defect in the sampled scope; no production-code fix is included.
- Reconciled #220 and #267–284 as 19 merges; 17 issues remain open and no PR was open at the source snapshot.
- Recorded current-head CI separately from historical failures and successes, including the 61 cancelled main CI runs and outstanding current integration result.
- Preserved the complete prior tracker text below. Followed the contribution guide's topic-branch/draft-PR workflow for this documentation-only update; no merge was performed.
- No builds, tests, repository scripts, linters, formatters, manual CI triggers, dependency revisions or security settings were changed. The documentation commit uses
[skip ci].
- Source data and CI are point-in-time observations, not continuous monitoring.
- Issues and PRs were paginated separately: 17 open issues and zero open PRs, followed by empty pages. The changed issue/PR collection returned 82 PR records and an empty second page; no ordinary issue updated in the window.
- Exact-head workflows returned 8 records and an empty second page; check runs returned 24 records and an empty second page; legacy statuses were empty. Main CI job pagination returned 3 jobs and then an empty page.
- The dev-window Actions collection was read across six pages (100 + 100 + 100 + 100 + 100 + 3). Every count above is bounded by that query and snapshot.
- The branch metadata reports
devunprotected and the repository ruleset collection is empty. The connector does not support the branch-rules endpoint; no protection setting was changed or bypassed. - Newly created tracking PRs are excluded from the pre-publication source snapshot above. This update is proposed for
dev; its presence in a draft branch does not mean it has been merged. - Preserve history and human edits on subsequent refreshes; avoid treating an unchanged historical snapshot as current status.
2026-09-30 snapshot, priorities, evidence and initial daily log
Last verified: 2026-09-30 11:51 Asia/Shanghai (UTC+08:00) / 2026-09-30 03:51 UTC
This is the daily issue/PR execution tracker. The roadmap remains the long-term product plan; architecture and contribution guidance remain authoritative for implementation. Priorities below are proposed from current blockers and dependencies, not assigned deadlines or an overall completion percentage.
| Measure | Verified state |
|---|---|
| Open issues | 17 |
| Open pull requests | 1: #220, draft |
| PRs merged since 2026-09-29 00:00 UTC | 48 |
| Issues closed in the same window | 0 |
| Issue planning metadata | No milestones or explicit priority labels on the 17 open issues; 14 are labeled epic |
| Issue ownership | Only #12 has an assignee: NeverSightAI |
| Observed dev commit | 4097148c |
Counts come from GitHub issue search with explicit issue/PR and state filters.
Each query returned incomplete_results=false, with all results within the
100-item page. The activity window is not a rolling 24-hour window.
Recover WMF Objective-C source with verified callbacks and Swift storage
- Head:
c4d57f9ea95ad43da5382a9e03e4006d83416a30; base branch:dev - Open, draft, not merged; GitHub reports mergeable, which does not establish test readiness or permission to merge
- No submitted reviews, inline review threads, or requested reviewers were returned at this snapshot
- Author-reported validation: WMF recovery 4029/5046 methods, 47 gains and zero losses versus the PR base; latest focused suites report 692 Objective-C source tests and 19 metadata JSON tests passing
- Those reported results have not been independently rerun for this tracker
Verified Actions results associated with that PR head:
| Workflow | Result | Evidence |
|---|---|---|
| CI | Failure | Run 36662051074 |
| LLVM Style | Failure | Run 36662051100 |
| Mobile Decompilation | Failure | Run 36662051058 |
| Prebuilt LLVM Audit | Success | Run 36662051118 |
| EVM Upstream Audit | Success | Run 36662051077 |
At observed dev commit 4097148c, LLVM Style and Python Plugin SDK succeeded,
but Mobile Decompilation failed. Main CI, Push on dev, and Mobile Real
Applications were still in progress. Do not transfer success or failure from
one commit to another.
- dev LLVM Style: success
- dev Python Plugin SDK: success
- dev Mobile Decompilation: failure; its failure cause has not been compared with the PR run
- dev CI: in progress
- dev Mobile Real Applications: in progress
Status: Blocked by failed checks on the observed PR head.
The three main CI platform jobs failed in the step named
"Verify Debug and Release target flags". The inspected Linux log identifies
the actual terminating failure as the Python ABI inventory missing
neverd_devirtualize_source_v3 and
neverd_devirtualize_machine_source_v3; this is not evidence that Debug
compiler flags themselves are wrong. Linux job
LLVM Style reports clang-format 22.1.2 violations. Its proposed-formatting artifact is available. A later dev commit already addressed several dev formatting violations, and dev Python Plugin SDK is green, so compare against current dev before duplicating fixes or attributing them to #220.
Next action: Determine which failures remain on an updated PR comparison; address only the remaining ABI/formatting discrepancies.
Acceptance:
- Current PR head and corresponding workflow runs are recorded
- Python ABI inventory and LLVM Style pass on that exact head
- All three main CI platform jobs complete with explicit pass/skip evidence
Status: PR #220 Mobile Decompilation is failing.
The macOS job reports:
- Scalar fixture, x86_64-default: 20/22 methods recovered
- Calls fixture, x86_64-classic: 18/21 methods recovered
- Single-session qualification: 11/12
- Swift source acceptance passed in that job
Next action: Compare the failing fixture identities and diagnostics with current dev, resolve remaining source/metadata gaps, and preserve strict fail-closed behavior. Do not treat the larger WMF author-reported metric as proof these independent acceptance gates pass.
Dependencies: Current-head integration evidence from priority 1 and access to the supported macOS/x86_64 acceptance environment.
Acceptance:
- Requested scalar and calls fixture matrices meet their complete-recovery gates
- Single-session qualification completes all 12 cases
- Mobile workflow succeeds on the exact PR head, or a documented unsupported case is explicitly reviewed rather than counted as a pass
- Review readiness is assessed only after the draft's remaining scope is clear
Status: Planning metadata needs evidence reconciliation.
Apple analysis #101 and IR emulator #104 remain open, while related implementation PRs have landed. Unchecked historical criteria are not sufficient evidence that every feature is still absent.
Next action: Map each acceptance criterion to merged changes, current documentation, and tests; distinguish completed, partial, and still-blocked scope before changing issue status.
Release candidate: #4 release pipeline depends on or complements #1 CI and #3 prebuilt LLVM, both closed as completed. Closure alone does not establish current three-platform packaging readiness; verify artifacts and build consumers before planning a dry run.
Small-task candidate: #12's last Windows feedback reports executable/library PDB filename collisions after an earlier Debug flag fix. Verify whether that specific issue remains before implementing another fix.
Acceptance:
- Each selected epic criterion has a linked implementation/test or an explicit gap
- The next task has a bounded deliverable, dependency, and validation command
- No issue is marked complete solely because a related PR merged
These PRs were returned by the merged-PR query. Validation descriptions inside them are author reports unless separately confirmed by linked workflow results.
- #266: acknowledge cancellation of active KVM vCPU entries
- #265: prevent sibling loops from starving reachable entry-prefix witnesses
- #264: execute static PIE from original ELF bytes with explicit load bias
- #263: expose interpreter recovery field and query budgets
- #262: support compiler-generated static TLS across checked CPU backends
- Recorded 17 open issues, one draft PR, and 48 merged PRs since September 29 00:00 UTC; no issues closed in that window
- Identified three failed workflows on #220's observed head and recorded concrete ABI, formatting, and Objective-C acceptance evidence
- Distinguished later dev results: formatting and Python SDK are green; Mobile Decompilation is failing and other validation is still running
- Proposed three priorities with acceptance criteria; no code changes, workflow reruns, issue edits, or merge actions are part of this entry
- Refresh the snapshot and priorities, then append a dated daily-log entry; preserve prior entries and human edits
- Record exact commits and workflow URLs; pending, skipped, unavailable, and failed checks must remain distinct
- Compare changes against the previous recorded snapshot. Keep issue closure, merged implementation, and verified product acceptance separate
- PR workflow lookup covered the returned first page of PR-triggered runs. The separate dev Actions query returned nine runs for its exact SHA. This does not establish branch-protection requirements, every external check, or overall release readiness
- GitHub search and Actions may change after this timestamp. This document is a point-in-time record, not a claim of continuous monitoring or a committed delivery schedule