Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file modified distro/rootfs/vms/SYS0/SYSCOMMON/SYSEXE/SYSUAF.DAT
Binary file not shown.
18 changes: 11 additions & 7 deletions docs/compat/facilities/decnet.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,14 @@ summary: >
adjacency state machine + hello/listen timers, and the NSP transport codec
(Connect Initiate oracle-verified; other PDUs self-round-trip). A live
engine/socket now drives real logical links over the datalink: inbound SET HOST
reaches an AUTHENTICATED LOGINOUT (decnet$cterm-session-auth), and the outbound
DCL SET HOST CLIENT is wired (decnet$set-host) -- it opens a CTERM terminal
session to a remote object 42 through the VMS terminal channel and returns with
%REM-S-END. Still open: general task-to-task ($QIO/FAL). NODE"acc"::file
filespec syntax parses but nothing downstream acts on it. 1.0 blocker (vms-30e).
last_reviewed: 2026-08-31
reaches an AUTHENTICATED LOGINOUT (decnet$cterm-session-auth), the outbound
DCL SET HOST CLIENT is wired (decnet$set-host), and inbound file COPY / FAL
(object 17) authenticates the connect-carried credentials and moves a file
through DAP + RMS (decnet$fal / decnet$dap). Still open: general task-to-task
($QIO), and the outbound COPY-over-datalink client wired into a DCL process.
NODE"acc"::file filespec syntax parses and DCL COPY now routes it to the FAL
path (reporting honestly until the outbound bridge lands). 1.0 blocker (vms-30e).
last_reviewed: 2026-09-09
items:
- {id: decnet$routing-hello, kind: protocol, status: verified, authenticity: real, vms: "Phase IV Ethernet Endnode Hello codec (encode/decode)", evidence: "src/vmsdecnet/routing/dnet_hello.c", verified_against: "docs/decnet-provenance-register.md sec 4.6 specimen #1 (lab capture, rd vms-3be/PR #665) round-tripped byte-identical by tests/vmsdecnet/test_dnet_hello.c", notes: "Pure byte-layout library, no socket/allocation; field-by-field mapped to the committed capture."}
- {id: decnet$router-hello, kind: protocol, status: implemented, authenticity: real, vms: "Phase IV Ethernet Router Hello codec (encode/decode)", evidence: "src/vmsdecnet/routing/dnet_router_hello.c", notes: "SPEC-DERIVED — no committed router-hello wire specimen exists, so not oracle-anchored; self round-trips in tests/vmsdecnet/test_dnet_router_hello.c (rd vms-0aba)."}
Expand All @@ -33,4 +35,6 @@ items:
- {id: decnet$netacp-device-face, kind: feature, status: implemented, authenticity: real, vms: "NETACP presents the DECnet device face _NET: + object-dispatch as EXECUTIVE-RESIDENT, cross-process-real state", evidence: "src/kernel-core/vms_devtab.c", notes: "P5 (rd vms-9ab, design vms-515 §3.3; vms_devtab_probe_net + src/vmsdecnet/engine/decnetd.c). The DECnet device _NET: is born in the executive I/O database at module init over the same primary NIC ETH0: rides (gated on the NIC -- no NIC, no _NET:, SS$_NOSUCHDEV, INV-6), so $ASSIGN/$GETDVI _NET: from a process that is NOT NETACP resolves a real DC$_SCOM device -- the §7.5 cross-process tell, same shape as the RTAn: proof. Asserted cross-process in tests/qemu/test_kmod_devtab.c (kmod leg) and via F$GETDVI _NET: in the shared acceptance battery. Object dispatch (42=CTERM) is executive-resident and cross-process-proven by the object-42->RTAn:->$GETDVI path (decnet$cterm-session-auth). NOT yet: a standalone NCP-style enumerable object REGISTRY query (its own executive ioctl, rd vms-9ab follow-on); the wire engine binary is not yet renamed NETACP.EXE (cosmetic, tracked)."}
- {id: decnet$wire-isolation, kind: feature, status: implemented, authenticity: real, vms: "A2/A8 isolation: attacker wire-parsing runs at LOW privilege and hands NETACP's privileged control path a VALIDATED TYPED DESCRIPTOR; the privileged path parses no attacker bytes", evidence: "src/vmsdecnet/cterm/dnet_cterm_host.c", notes: "P5 (rd vms-9ab, design vms-515 §3.4; low-priv parse dnet_conn_descriptor_from_wire in src/vmsdecnet/cterm/dnet_cterm.c, privileged consumer dnet_cterm_host_open_desc here). The low-privilege bounded parse distils untrusted NSP-connect bytes into a struct dnet_conn_descriptor carrying no wire pointer, no length, and no credential material; the privileged session-creating path (mints RTAn:, $CREPRCs LOGINOUT) takes ONLY that descriptor and refuses an unvalidated or wrong-object one BEFORE any device/process exists. Proven: the low-priv seam under 200k-frame mutation fuzz in tests/vmsdecnet/test_dnet_cterm.c (no malformed frame yields a validated/steered descriptor; every rejected frame leaves it all-zero), and the privileged double-door on the shipped binary in DECNETD.EXE --isolation-test (no /dev/vms needed), run by the acceptance battery. 'OVMX never crashes a peer': every hostile field is bounded and refused cleanly."}
- {id: decnet$set-host, kind: command, status: partial, authenticity: real, vms: "SET HOST — DECnet remote-node connection (outbound client)", evidence: "src/vmsdcl/dcl_cmd_set.c", notes: "DCL `SET HOST <node>` activates SYS$SYSTEM:DECNETD.EXE --set-host on the CALLER'S TERMINAL through the executive image activator (dcl_activate_image -> imgact_activate, with DCL's fork fallback -- the same path RUN uses, NOT a bare fork/exec). The client (src/vmsdecnet/engine/decnetd.c run_set_host_loop) opens a REAL NSP logical link to the remote's Session Control object 42, binds a CTERM terminal session, and bridges THIS process's local terminal to it. VMS-NATIVE terminal I/O (the anti-LARP core): the client does $ASSIGN SYS$INPUT/SYS$OUTPUT + $QIO IO$_SETMODE (OVMX pass-all selector IO$K_TT_PASSALL) + IO$_READVBLK/IO$_WRITEVBLK -- NEVER tcsetattr/cfmakeraw on fd 0/1; the termios that realises pass-all lives in the executive terminal driver (src/libvms/syssvc/sys_qio.c qio_terminal_setmode), below the $QIO interface. On teardown control returns with the canonical %REM-S-END (oracle docs/oracle/vax-sethost-cterm.console.txt). The remote authenticates FRESH (the carried --user is proxy only, never auto-login). The client contains NO fork/exec/openpty/dup2. Response decoders are bounded against a hostile remote (mutation fuzz of dnet_nsp_decode/dnet_cterm_rx, tests/vmsdecnet/test_dnet_cterm.c, clean under ASan/UBSan). PROVEN: the CLIENT drives a genuine Connect Initiate to object 42 over a real veth datalink and the server refuses honestly without an executive (tests/integration/decnet_set_host_live.sh reduced proof). partial (not implemented): the FULL authenticated end-to-end (client -> remote LOGINOUT challenge -> %REM-S-END) needs a CI leg with BOTH CAP_NET and a real executive (/dev/vms) plus DECNETD.EXE staged into the boot image -- the workflow_dispatch proof leg; tracked as follow-on."}
- {id: decnet$node-filespec-syntax, kind: feature, status: partial, authenticity: real, vms: "NODE\"acc\"::dev:[dir]file filespec syntax", evidence: "src/vmsrms/rms_parse.c", notes: "Syntax only — sets NAM$M_NODE, parses/reconstructs the node prefix; nothing downstream (no live DECnet transport) acts on it."}
- {id: decnet$node-filespec-syntax, kind: feature, status: partial, authenticity: real, vms: "NODE\"acc\"::dev:[dir]file filespec syntax", evidence: "src/vmsrms/rms_parse.c", notes: "Syntax sets NAM$M_NODE and parses/reconstructs the node prefix. DCL COPY now ACTS on it (rd vms-8c2): a NODE:: spec routes to the DECnet FAL/DAP path and, since the outbound COPY-over-datalink client is not yet wired into a DCL process, reports honestly (%COPY-I-NETNOTWIRED) rather than mis-copying it as a local file — src/vmsdcl/dcl_cmd_file.c copy_spec_has_node. Full outbound DCL->datalink bridge is a tracked follow-on."}
- {id: decnet$dap, kind: protocol, status: implemented, authenticity: real, vms: "DAP (Data Access Protocol) message codec — CONFIGURATION/ATTRIBUTES/ACCESS/CONTROL/DATA/STATUS/NAME/ACCESS-COMPLETE encode+decode", evidence: "src/vmsdecnet/dap/dnet_dap.c", verified_against: "docs/oracle/vax-copy-fal-dap.* (rd vms-cd3): the message SEQUENCE + carried values (filename, resolved full spec, owner UIC, verbatim records) are the real VAX<->VAX COPY's ground truth; the per-field framing is the PUBLIC DAP spec", notes: "Pure byte codec, self-round-tripping. CLEAN-ROOM (Rule 8): message set + generic framing from the public DEC DAP functional specification; sequence + credential/object/carried-value semantics from the oracle. FULLY BOUNDED against hostile input — decoder fuzzed 200k inputs + every truncated prefix, ASan/UBSan-clean (tests/vmsdecnet/test_dnet_dap.c). HONEST SCOPE (INV-6): the field sub-framing is NOT asserted byte-identical to the real-VAX DAP sub-framing (the oracle §3 does not transcribe every sub-field); two OVMX nodes interoperate over it faithfully, byte-level stock-VAX FAL wire interop is a filed follow-on."}
- {id: decnet$fal, kind: feature, status: partial, authenticity: real, vms: "FAL — File Access Listener (DECnet Session Control object 17): inbound file COPY authenticated at connect + served/stored via RMS; the COPY node:: client", evidence: "src/vmsdecnet/fal/dnet_fal.c", verified_against: "DECNETD.EXE --fal-accept-test in the booted acceptance battery (tests/qemu/lib/dcl_acceptance_battery.sh): real SYSUAF/Purdy auth (GUEST/GUEST accepted, a wrong password + DISABLED/DISUSER refused) then a sequential file transferred BOTH directions through real DAP over an NSP link + real RMS over the ACP, byte-verified", notes: "SECURITY SURFACE. An inbound object-17 connect CARRIES the username+password (oracle §1 — the OPPOSITE of CTERM's empty creds); FAL authenticates them through THE ONE faithful authenticator (sysuaf_lookup + sysuaf_authenticate Purdy + the disabled-account gate, the SAME path LOGINOUT/SSHD use) BEFORE accepting the link, and REFUSES with an NSP Disconnect on a bad password — the FAL analogue of the no-auth-CTERM hole (INV-6, no file served on an unauthenticated connect). The connect-carried creds are decoded by a bounded, fuzz-clean decoder (dnet_fal_access_decode) that never over-reads and wipes the password after the check. File I/O is rms_textfile_* (RMS over the ODS-2 ACP), fail-honest with no /dev/vms — no userspace fallback that fakes a transfer (Rule 9). No fork/exec/openpty/dup2, no raw-fd/termios file mechanics. HONEST FLOOR (no executive, runs anywhere): DECNETD.EXE --fal-selftest proves the client emits a real object-17 connect carrying the creds + the honest refusal + the DAP-over-NSP transport pump. NOT yet (filed follow-ons, never faked): the outbound COPY client wired into a DCL process over the live datalink; advanced DAP (indexed/relative files, wildcards, DIRECTORY, block mode, proxy-instead-of-password access); byte-level stock-VAX FAL wire interop; network-access-class (NETMBX) enforcement distinct from the password/DISUSER gates."}
Loading
Loading