diff options
| author | Calvin <calvinm@kissingerassoc.com> | 2026-08-16 20:52:12 -0400 |
|---|---|---|
| committer | Calvin <calvinm@kissingerassoc.com> | 2026-08-16 20:52:12 -0400 |
| commit | 147b0ca1e4e00f66abb47fff3c543b853033f609 (patch) | |
| tree | a388172fc16723c139deff1e45a74c3d1c567cc0 /svc/doc/todo.md | |
Initial commit: svc supervisor, design docs, session transcript
Existing work moved from /storage/vms/9front/svc, previously unversioned.
Object files and linked binaries excluded via .gitignore.
Diffstat (limited to 'svc/doc/todo.md')
| -rw-r--r-- | svc/doc/todo.md | 101 |
1 files changed, 101 insertions, 0 deletions
diff --git a/svc/doc/todo.md b/svc/doc/todo.md new file mode 100644 index 0000000..5598ae3 --- /dev/null +++ b/svc/doc/todo.md @@ -0,0 +1,101 @@ +# TODO + +State as of the end of the second session. Ordered by what unblocks what, +not by size. + +## Do first: kill the serial dependency + +Everything else is cheaper once this is done. The serial shell wedged three +times in one session and is lossy, non-interactive, and hostile to quoting. + +- [ ] `/adm/keys` and a user: `auth/keyfs`, then `auth/changeuser glenda` +- [ ] service files for `keyfs`, `authsrv` (listener on 567), `listen` (rcpu + on 17019). This is literally `svc enable keyfs authsrv` from the man page +- [ ] add a 567 hostfwd to `run.sh` next to the existing 17019 one +- [ ] client: build conterm (github.com/0intro/conterm, text-only, drivable + over a pipe) or use the already-installed drawterm interactively + +`tcp17019` runs `tlssrv -a /bin/rc -c server`, so it authenticates through +factotum and needs the auth server to validate. `rc/bin/service.auth/` already +ships `tcp567`. `run.sh` already forwards 17019. + +## Unblocked, mechanical + +- [ ] drop `svc=`; the filename is the service name +- [ ] `.ndb` extension on service files, stripped to get the name +- [ ] migrate more services per `inventory.md` — `plumber`, `webfs`, + `webcookies`, `kbdfs`, `usbd`, `realemu` +- [ ] doc drift: `/log` → `/sys/log` in `design.md` and `man/init`, with the + reason (root is mounted without create permission) +- [ ] doc drift: ctl permissions are `0644`, not `0600` — reads must be open + or ctl cannot document itself +- [ ] record the session's gotchas in `CLAUDE.md`: non-interactive rc dies on + a syntax error and takes the serial with it; `pkill -f` kills the calling + shell even with the bracket trick; rc treats double quotes as literal + characters, so `|` inside them becomes a pipe + +## Needs a decision before code + +- [ ] **`stop` does not work for detaching services.** `Ksrv` services have no + pid init can signal, so `stopsvc` is a no-op and a later `restart` fails + with "another instance is running". Proposed: for `Ksrv` with no `stop=`, + remove the `/srv` entry, which hangs up the channel and a well-behaved + server exits. Untested. +- [ ] **Dynamic `/srv` names.** `plumber` posts `plumb.glenda.502`, `rio` posts + `rio.glenda.1483` — user and pid in the name. `ready=srv:` cannot express + it and it is a pattern, not an exception. Needs a glob, a new `ready=` + form, or accepting `ready=exec` and losing liveness. +- [ ] **Namespace profiles.** Ship `/lib/ns/{net,disk,draw,full}`, require + every service to name one, no default. Blocked on the item below. +- [ ] **The provider circularity.** A service that provides a namespace to + others (an `import` of a remote `/net`, say) must be able to mount *and* + must post to `/srv` so dependents can reach it — so it is simultaneously + the exception to "do not bind `#s`" and to freezing the namespace. Not + resolved. Profiles built before this is settled get built twice. + +## Unimplemented attributes and features + +Parsed and ignored today: `ns`, `user`, `stop`, `adopt`. + +- [ ] `ns=` inline lines and `nsfile=`, via `newns` +- [ ] `user=` via the capability device — note `#¤` must still be in the + namespace at the moment privilege is dropped +- [ ] `stop=` — `note:`, `write:file:word`, `exec:` forms +- [ ] `adopt=yes` for services init can stop but never started (the root file + server, `factotum`, `paqfs`) +- [ ] `halt`, `reboot`, `reset` ctl verbs and commands +- [ ] `reexec` +- [ ] rescue console when services will not come up +- [ ] base namespace construction by init, replacing the device-bind loop in + termrc + +## Environment + +- [ ] **The bootargs prompt needs a manual Enter every boot.** Listed as + unresolved in `CLAUDE.md`; it now blocks unattended testing, which makes + it worth actually fixing. +- [ ] sshfs has to be remounted by hand after every reboot — a candidate for + being a service itself, gated on a `sshkey` oneshot +- [ ] `9front-base.qcow2` is stale relative to `9front.qcow2`; overlays made by + `newvm.sh` lack the supervised serial shell and the rio change + +## Verification debts + +Claims the design rests on that have not been tested: + +- [ ] does `RFNOMNT` survive `exec`? That is the last step before a service + runs, and the plausible place for a flag to be cleared +- [ ] does binding a single `/srv` entry (`bind #s/cs /srv/cs`) work as cleanly + as binding the directory? The fine-grained capability story depends on it +- [ ] does `import` have a flag to post to `/srv`, or is `srvfs` needed? +- [ ] does `bootrc` honour `init=` in `plan9.ini`? That is the escape hatch if + we ever make init the boot program and get it wrong + +## Deferred deliberately + +- The filesystem hierarchy rework. Until then, do not churn `/lib/svc` → + `/lib/services`; every path in init is a flag, so it is a one-line change + whenever the hierarchy lands. +- `timesync` reaching an external NTP server. It fails on DNS resolution in a + NAT'd VM and is not worth chasing; the dependency machinery around it is + already proven. |
