Skip to content

emulation: admit fixed Darwin symbolic links - #645

Merged
NeverSightAI merged 5 commits into
devfrom
codex/darwin-symbolic-links
Oct 8, 2026
Merged

NeverSightAI merged 5 commits into
devfrom
codex/darwin-symbolic-links

Conversation

@gmh5225

@gmh5225 gmh5225 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Darwin process inputs could not describe symbolic links, and raw readlink/readlinkat stopped as unsupported. This change admits an optional fixed initial darwin_files.symbolic_links catalogue and resolves links through the existing Darwin pathname owner across macOS, iOS and iOS simulator profiles.

Targets retain their exact bytes. The resolver handles relative/absolute targets, reparses trailing slashes after each expansion, bounds traversal to 32 expansions and preserves terminator-inclusive PATH_MAX checks. Link metadata and directory records describe the link itself; ordinary stat/open/access follow the actual target. No-follow and exclusive-open policies keep terminal retention separate from expansion refusal. Raw syscall 58 uses its signed low32 count, while 473 retains size_t width; both validate the count before pathname/dirfd imports and copy only the returned prefix without a NUL. Retained file descriptors, writable contents and mmap leases belong to the resolved target object.

The JSON decoder rejects malformed targets, inconsistent metadata, collisions and link ancestors before loading. Nonempty link catalogues currently exclude namespace mutation grants; fixed-name writable regular files remain supported. Dynamic symbolic/hard-link creation, link removal/rename, permission enforcement and full Apple runtime/framework execution remain outside this contract. All eleven Darwin guides and source-backed capability claims are updated.

This branch includes the open prerequisite #643 and the current dev baseline. #589 is already merged.

Validation on native ARM64 macOS, Release, with sequential execution and unchanged guest deadlines/budgets/quanta. Complete backend/owner/SDK/native acceptance below was executed at d859feda0, after the shared-backend dev integration. The subsequent 92f6fdc50 merge incorporates dev 8eee34cce and changes only the compiler output layer; all execution objects, fixtures and owner executables retain their accepted bytes:

  • Complete required Darwin gate: 1,625 registered, 1,037 passed, 588 unavailable-backend skips, zero failures. All 147 mandatory ARM64 HVF cases executed and passed; all original registrations are retained.
  • Complete public C API/CLI owner: 261 passed across all five profile/ISA pairs. Linux/shared report owner: 241 passed, 263 unavailable-platform/backend skips; service-request owner: 61 passed, 62 backend skips; execution budgets: 4 passed.
  • Shared integration controls: complete projection-cache, direct-x64, execution-session and run-control owners passed with host/backend skips retained; all six process-transfer tests passed. Generated-code write/watch controls passed over available backends.
  • Complete Python SDK method: 243 actual calls, 238 returned reports and 5 expected wrong-profile rejections, zero timeouts. All 243 requests and fixture bytes match the accepted link increment in order; that increment preserves the prior 238 requests and adds five symbolic-links calls. Python ABI and API checks passed.
  • Native original workloads: all 38 modes passed; the prior 37 inputs remain isolated, including exact before/after directory-name controls. Previously accepted pinned-XNU boundary invocations provide 189 observations and 26 additional review controls for the unchanged link implementation. They are retained as separate scopes and were not re-executed for this backend merge.
  • Current native inventory, API/ABI, SDK drift, capabilities, source provenance and complete merged documentation checks passed. Unchanged CI controls, 116 documentation-checker regressions and changed-range formatting retain their earlier accepted source bindings. Independent source and integration evidence review completed before publication.

Main commands: NEVERD_THREADS=1 python3 scripts/run_native_cpu_ci.py --build build-hvf-arm64 --evidence <directory> --parallel 1 --require-darwin-backend hvf, each affected complete GoogleTest owner, the recorded original SDK method, and python3 scripts/run_darwin_kernel_reference.py --architecture arm64 --evidence <directory>. The shared-backend merge rebuilt 13 targets with four workers. The subsequent compiler integration rebuilt the shared library/CLI with four workers; all 33 link-increment files and the accepted execution objects/archives/fixtures/owner executables are byte-identical. Its rebuilt public library passes six affected C API/CLI cases, 12 ABI tests and five actual SDK calls whose complete requests, fixture bytes and reports equal the accepted five-profile trace. Complete merged documentation checks also pass. Both source/artifact epochs are preserved; 1,748 actual selected artifacts are bound in the final epoch.

Physical iOS, native Intel, KVM/WHP and remote CI execution are outside this local acceptance.

Semantics were checked against pinned XNU namei, readlink/nameiat, open authorization, separator parsing, and directory/no-follow ordering.

@NeverSightAI
NeverSightAI merged commit 576e80e into dev Oct 8, 2026
16 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants