38 KiB
AI working notes for mars-nwe
This file is for future ChatGPT sessions. It records general working rules and local build/test notes only. It should not be used as the current project status log; the current patch stack and task context should be pasted into a new chat separately.
Start of a new chat
When the user says this is a new chat or asks to continue mars-nwe work, first read this file before proposing patches or making assumptions. Then ask for, or use, the current project status that the user pasted into the chat.
Current handoff status after patch 0222
The current accepted patch line in this chat is expected to include:
- endpoint-audit/documentation patches through
0176-docs-audit-direct-lifecycle-buffer-endpoints.patch; - redesign documentation patches
0177through0198; - endpoint-audit/documentation patches
0199through0219; - redesign clarification patch
0220-docs-record-print-queue-redesign-link.patch; - endpoint-audit patch
0221-docs-audit-ncp-extension-stubs.patch; - endpoint-audit patch
0222-docs-audit-direct-file-metadata-stubs.patch; - latest expected patch name:
0222-docs-audit-direct-file-metadata-stubs.patch.
When continuing in a new chat, first ask the user which patch was actually last
applied. If they confirm 0222, build the next patch as 0223-... against a
tree that already contains 0222. If they only applied through 0221, apply or
rebuild 0222 before continuing endpoint work. If any patch failed or was skipped, rebuild
against the last confirmed applied patch instead of assuming the file in
/mnt/data was accepted.
Known numbering/patch-history notes from this chat:
0190-docs-clarify-imported-nwlog-backend-layout.patchwas superseded because patch number0189was accidentally skipped and the old0190failed after0188. Do not reuse that old file.- Use
0189-docs-clarify-imported-nwlog-backend-layout.patchinstead. - Then use
0190-docs-clarify-simple-syslog-nwlog-backends.patch, followed by0191...0203.
The user prefers patch verification snippets to contain only:
git am patchname.patch
Do not include git diff --check HEAD^..HEAD in the final summary unless the
user asks for it.
Current redesign decisions to preserve
REDESIGN.md is now the place for broad architecture notes. Do not keep
growing TODO.md with long-term redesign material. TODO.md should remain
for concrete endpoint/test/fix follow-ups.
High-level NCP architecture direction:
- Add a small internal NCP dispatch/handoff layer over time; avoid a large message-bus rewrite.
- Provider boundary is not the same as process boundary.
nwbindremains legacy bindery provider/service.- Queue is a strong candidate for a future
nwqueueprovider/process, but first split it logically from bindery.
NCP Extension note from patch 0221:
- SDK
0x2222/36/ wire0x24NCP Extension information and SDK0x2222/37/ wire0x25Execute NCP Extension are source-stub-audited as planned NetWare 4.x extension-registration work. src/nwconn.cnow contains disabledMARS_NWE_4stubs for36/00through36/06and direct37. They intentionally return0xfbif ever enabled without a real extension registry/provider.- Future owner is an extension registry/provider. Do not route extension
payloads through
nwservas a data-plane broker;nwservremains only control-plane/supervision/registry. - Patch
0222audits the remaining old direct file-metadata/open-create compatibility slots SDK0x2222/79,0x2222/84, and0x2222/85/ wire0x4f,0x54, and0x55. No active top-level handlers existed; the patch records disabled#if 0stubs insrc/nwconn.c. Future owner is the filesystem/namespace provider, not NDS. - The next patch number should be
0223if0222was applied.
Print/queue redesign note from patch 0220:
- Do not describe printing as entirely absent. Queue-backed printing already exists in the project through the queue/job printing paths.
- The old direct
0x2222/17Print/Spool NCP family is a separate compatibility surface and currently remains documented as disabled stubs. - Future direct
17/xximplementation should bridge to existing queue printing mechanics rather than creating a separate print subsystem. - Logical owner: queue/print-spool provider area, possible future
nwqueue; notnwnds, notnwdirectory. - Filesystem/volume/namespace should become a provider/module boundary first; a separate process would be risky and later only.
- Semaphore, server-management, and most small call families should remain modules/providers, not separate processes.
nwservis the control plane/supervisor/provider registry, not a data-plane payload router. Normal requests should flowclient -> nwconn -> provider -> nwconn -> client, not throughnwservas broker.- Provider processes must always return one formal internal handoff reply.
NO_REPLYis an explicit reply kind, not silence.nwconnowns the final client NCP reply envelope and send.
Transport direction:
- TCP/IP support is a transport split below
nwconn/nwserv, not a new daemon. - Planned code layout:
src/nwtransport.c,src/nwipx.c,src/nwtcp.c. nwtransportis a code/library boundary, not a process.- Higher providers must not depend on raw
ipxAddr_tlong-term. - IPX SAP/RIP/watchdog/broadcast behavior remains isolated as IPX-specific.
Secure IPC/TLS direction:
- Client-facing NetWare 4.x/NCP/NDS compatibility must not require TLS by default. Keep historical clients compatible.
- LDAP/LDAPS/StartTLS for
nwdirectoryuses wolfSSL at the external LDAP edge. - Internal provider IPC over TCP, if added later, must always use wolfSSL-backed TLS with mutual authentication. No plaintext fallback for TCP provider IPC.
- Local IPC may remain Unix-domain sockets, pipes, socketpairs, or inherited FDs with strict permissions; still avoid logging decoded secrets.
- Add
nwtlsas the internal TLS facade if/when wolfSSL is wired into runtime:include/nwtls.h,src/nwtls.c,src/nwtls_wolfssl.c.
Directory/NetWare 4.x direction:
libdirectoryis the shared internal C API/library used bynwbind, futurenwnds,nwdirectory, andnwsetup. These components should not talk LDAP internally just to reach the directory store.libflaimis the planned persistent store underlibdirectory. FLAIM is C++; keep its C++ API behindlibdirectoryso old mars-nwe C code does not include FLAIM C++ headers directly.nwdirectoryis the mars-nwe integration name for the tinyldap-derived LDAP/LDAPS service. Standalone/upstream identity remainstinyldap; inside mars-nwe it builds thenwdirectoryservice.- Future
nwndsis the NetWare 4.x/NDS compatibility layer and should uselibdirectory, not LDAP protocol calls, as its internal backend path. nwbindshould eventually become a legacy bindery adapter overlibdirectory/libflaim, not maintain a second persistent truth.- Do not mention or design Kerberos for the current NetWare 4.x target.
Configuration and setup direction:
- Move toward a real typed, documented INI format. Do not use JSON as the admin config format.
- The generated INI is also user documentation. Writers must preserve comments where possible or regenerate from a full documented template; never rewrite it into an undocumented minimal key/value dump.
nwsetupis the provisioning/setup tool. It should initialize thelibdirectory/libflaimstore, create initial schema/tree/admin/server objects, migrate bindery data later, and edit config atomically.- No reusable Admin/Supervisor/NDS/LDAP plaintext passwords in the new typed INI.
Initial passwords and recovery resets belong to explicit
nwsetupcommands and only hashes/verifiers go into the store. - Legacy bindery config-password reset may remain only as deprecated compatibility
behavior; Directory/NDS mode uses
nwsetuprecovery commands.
Logging direction:
- Add a small internal
nwlogfacade instead of direct zlog/log.c calls in handlers/providers. Project layout:include/nwlog.h,src/nwlog.c. - Category wrappers should exist for normal code:
nwlog_ncp(),nwlog_handoff(),nwlog_bindery(),nwlog_queue(),nwlog_directory(),nwlog_nds(),nwlog_ldap(),nwlog_auth(),nwlog_acl(),nwlog_recovery(),nwlog_security(). They populate an internalnwlog_eventand callnwlog_emit(). rxi/log.cmay be vendored/adapted asnwlog_simple, not exposed directly:include/nwlog_simple.h,src/nwlog_simple.c. It is a simple stderr/stdout/file/callback basis and is a good default for systemd/journald.nwlog_syslogmay later be derived/cloned from the simple backend for classicsyslog(3)explicitly:src/nwlog_syslog.c.zlogis the preferred optional advanced routing backend behind the facade:src/nwlog_zlog.c. It may live as athird_party/zlogsubmodule.- Never route raw decoded NCP/handoff/auth payloads to remote loggers. Only redacted structured events should leave the host.
Third-party/fork policy:
- Fixed third-party libraries live under
third_party/, such as existingyyjson, plannedwolfssl, plannedlibflaim, and optionalzlog. wolfSSLis the fixed bundled TLS implementation, similar in spirit toyyjson. Do not design a first-pass OpenSSL/LibreSSL backend matrix.libflaimshould live underthird_party/libflaimas a mars-nwe-maintained import/fork/mirror. Source may come from SourceForge/SVN and/or a distro source package such as openSUSElibflaim-4.9.1046. Document exact import, revision/version, license files, distro patches, and local patches inthird_party/libflaim/README.mars-nwe.md.- FLAIM r1112 has Autotools (
configure.ac,Makefile.am, libtool,config.h, subprojectsftk,flaim,sql,xflaim). Do not wrap Autotools from CMake; replace it with a real CMake build. First required targets areFLAIM::ftkandFLAIM::flaim; SQL/XFLAIM/tools/tests/docs can come later. - FLAIM source license observed by the user: library sources LGPL-2.1; helper
files like
svn2cl.xslmay have separate licenses such as BSD-3-Clause. Keep these separated in import docs. - Forked/integrated mars components that become project services live in the
repository root, matching existing style such as
mail,admin, anddosutils.mars-tinyldapbelongs in the root, notthird_party, because it will be heavily adapted intonwdirectory. - tinyldap currently has a hand-written Makefile and flat-file/mmap storage.
It needs a real CMake build, not a Makefile wrapper. Standalone remains
tinyldap; mars-nwe integration buildsnwdirectory. - For tinyldap/nwdirectory, first CMake split can expose internal targets such as
tinyldap::asn1,tinyldap::ldap,tinyldap::ldif,tinyldap::auth,tinyldap::storage, andtinyldap::server. Replace flat-file storage withlibdirectory -> libflaimlater. - Old tinyldap TLS code can remain reference/legacy/standalone-only; mars-nwe
nwdirectoryTLS should go throughnwtls/wolfSSL.
Schema/import direction:
- Do not invent NetWare 4.11 schema by hand if a real source can be obtained.
The user expects the complete schema to be hidden in NetWare 4.11 installation
material such as
install.dat; a real 4.11 install may be needed to extract it. .SCHfiles such as uploadedNLS.SCHare useful format examples/fragments. They contain readable ASN.1-likeATTRIBUTEandOBJECT-CLASSblocks, but are not the full schema truth.nwsetupshould eventually support native NetWare 4.11 schema import,.SCHfragment import, and LDIF import/export. LDIF remains human-readable, diffable, and testable, but the canonical runtime representation islibdirectoryschema objects stored inlibflaim.- tinyldap has useful ASN.1 BER/DER and LDIF code (
scan_asn1*,fmt_asn1*,asn1dump,ldif_parse.c), but it does not appear to be an NDS.SCHor NetWare schema importer. Reuse ideas/code carefully through thenwdirectoryfork, but plan a dedicated schema import layer. - Samba
source4/dsdb/schemaand setup schema conversion code are useful references for OID/prefixMap/schema-loading ideas, but Samba is GPL-family; do not blindly copy code into mars-nwe. Use as a reference and implement a mars-nwe-native importer/OID module.
Latest endpoint audit note:
- Patch
0221audits SDK0x2222/36/ wire0x24NCP Extension information and SDK0x2222/37/ wire0x25Execute NCP Extension as planned NetWare 4.x extension-registration work. src/nwconn.ccontains disabledMARS_NWE_4stubs for36/00through36/06and direct37; they are documentation/source markers only and do not change the default runtime.- Future implementation needs an extension registry/provider.
nwservmay supervise/register providers but must not become the data-plane broker for extension payloads. - Patch
0222audits SDK0x2222/79,0x2222/84, and0x2222/85/ wire0x4f,0x54, and0x55as old direct file-metadata/open-create and sparse-data compatibility gaps. It adds disabled#if 0stubs next to the old direct file-I/O switch insrc/nwconn.c; future owner is the filesystem/namespace provider. - Previous print note still applies: direct
17/xxspool NCPs are only the old direct-spool compatibility surface; queue-backed printing already exists.
The next patch number should be 0223 if 0222 was applied. Likely next
blocks are deeper 0x2222/23 bindery/property/admin subfunction coverage,
SDK 0x2222/90 scope, or another user-selected endpoint family.
Patch workflow
-
Produce patches that apply with exactly:
git am patchname.patch -
Assume the user has already applied and committed accepted earlier patches. Build every new patch against the current tree the user provides.
-
Do not ask the user to apply a long patch chain unless they explicitly say earlier patches were not committed.
-
Keep follow-up patches small and reviewable. Do not mix functional changes, cleanup, and logging refactors unless the user asks for that.
-
If a patch is only documentation or test cleanup, keep it that way.
Current protocol audit scope
- The current endpoint documentation/audit pass is scoped to compatibility NCPs through NetWare 3.x by default, including NetWare 1.x/2.x legacy calls where they are documented. Bucket endpoints by the oldest NetWare generation that documents them: put 1.x/2.x legacy calls in their own sections, keep the remaining through-3.x compatibility calls in the 3.x/default section, and put endpoints introduced in NetWare 4.x in a separate planning/stub section. Do not create stub work merely for NetWare 5.x/OES/MOAB/newer endpoints.
- NetWare 4.x-only endpoints are not part of the default implementation target yet, but they are the current forward-planning target. Already implemented compatibility code must not be removed or wrapped just because it is 4.x-era; only new, not-yet-implemented 4.x stubs should be placed behind
#if MARS_NWE_4. Do not add disabled stubs for 5.x/OES/MOAB/newer calls unless the user explicitly changes the target scope later.MARS_NWE_4is currently hard-disabled ininclude/config.h.cmakeand should stay0unless the user explicitly asks to start that work. - When a
0x2222group or subfunction is forwarded out ofnwconn.c, follow the handoff before declaring the endpoint documented.nwconn.cshould document the handoff and the exact header/payload bytes that are preserved or rewritten before forwarding; the destination file (for examplenwbind.c) must document the concrete subfunction request/reply layout at the real handler. Do not stop at a comment such asnwbind must do prehandling,nwbind must do the rest, orhandled by nwbind. - For forwarded paths, document any nwconn-side payload mutation as part of the audit. Examples in the current tree include queue create path expansion, queue job file-handle insertion, quota bindery prehandling, and semaphore/message group forwarding. If a forwarded subfunction is not audited yet, record it as a target-file follow-up rather than only documenting the nwconn dispatcher.
- For documentation-only endpoint patches, do not change parser offsets, byte order, reply layout, or completion behavior. Always compare the code parser/reply layout against the applicable SDK/WebSDK/PDF request format and, when available, the uploaded SDK include prototypes. If the code differs from the SDK layout, document the concrete difference inline and mirror it in
TODO.mdfor later testing. If it matches, say so in the patch summary so the audit trail is clear. - When an SDK/WebSDK/PDF endpoint number is written in decimal notation, convert it carefully to the wire
casevalue before adding inline documentation. Example: Directory Services0x2222/22/12in the PDF means SubFunctionCode decimal 12, i.e. wirecase 0x0c; it is not the existingcase 0x12/ decimal 18 Allocate Permanent Directory Handle. Place disabled stubs directly at the correct numeric slot inside the dispatcher, never appended at the end of the function. For implemented endpoints, keep the detailed documentation inside the relevantcaseblock, immediately after thecaselabel/opening brace, matching the local style; do not leave a large endpoint block before thecaselabel. - If a PDF/WebSDK page title and an internal table row disagree, prefer the endpoint title plus include/WebSDK cross-checks and record the mismatch instead of inventing a new wire case. Example:
0x2222/23 Verify Serializationis titled SDK decimal23/12/ wire0x0c, even though one PDF table row printsSubFunctionCode (212); do not add a wire0xd4case without a packet trace or include-level confirmation. - In
TODO.mdand endpoint summaries, avoid ambiguous mixed notation for grouped subfunctions. Write SDK/PDF numbers as decimal and include the wire byte explicitly when it differs or could be confused, for exampleSDK 22/18 / wire 0x12orSDK 22/12 / wire 0x0c. Do not write22/12for a wirecase 0x12unless the SDK number is actually decimal 12. - Do not assume every
0x2222endpoint key is onlyrequest_type/function/subfunction. Some SDK/PDF/WebSDK families have deeper selectors inside the subfunction payload, such as NDS0x2222/104/02with a 32-bit NDSVerb, statistical0x2222/123/34withInfoLevelNumber, NCP extension0x2222/36/37with dynamic extension numbers, or reply layouts selected by an information type. When auditing such a family, document the selector path explicitly, for example0x2222/104/02 verb=<n>or0x2222/123/34 level=<n>, and distinguish true wire dispatch bytes from payload fields that merely select a structure or backend operation. - Keep
TODO.mdendpoint audit notes grouped by endpoint family and NetWare generation instead of as one long flat list. - Before starting the next detailed endpoint block, maintain a coverage index for SDK/WebSDK-listed
0x2222groups that are not yet audited. Classify each group as present in code but not audited, missing a top-level handler, or likely later-generation/unclear. This index is only a planning aid: do not add active TODO work or source stubs until the specific block has been checked for handoffs and bucketed by oldest documented NetWare generation. - Before every new endpoint-family patch, first do a missing-endpoint pass for that family: enumerate the SDK/PDF/WebSDK/include endpoint list, compare it against actual
caselabels and forwarded destination handlers, then document implemented, disabled-stub, and absent slots separately. Do this retroactively for already documented families when touching them again. - Always document both the request handoff/parser and the reply builder. For forwarded calls, the
nwconn.ccomment should explain exactly whyreturn(-1)orreturn(-2)is used; the destination handler should explain the concrete request bytes and response payload. Do not treatreturn(-1)inside disabled#if 0snippets innwbind.cas a forwarding mechanism. - For SDK-listed groups that appear missing from
nwconn.c, also search destination files such asnwbind.c, queue helpers, salvage helpers, AFP/name-space dispatchers, and any prehandler path before declaring the endpoint absent. - The rejected
0152-docs-note-message-control-subfunction.patchmust not be applied: it documented0x2222/21/0x0c Connection Message Control, which is outside the default NetWare 1.x/2.x/3.x MARS-NWE target scope.
mars-nwe coding style rules
- Prefer existing mars_nwe / NetWare functions over new helper code.
- Before adding a helper, search the tree for an existing equivalent.
- Do not introduce parallel mechanisms for paths, trustees, xattrs, AFP metadata, copy/write/restore, u16/u32 packing, or logging.
- Use existing integer and wire-format macros such as
GET_16,GET_32,U16_TO_16,U32_TO_32, and related mars_nwe helpers instead of open-coded byte parsing/serialization. - Use existing namespace/path conversion and basehandle logic instead of parsing NetWare paths by hand.
- For file restore/copy/write behavior, prefer the existing Novell/mars_nwe file functions over direct POSIX operations. Use POSIX only where there is no suitable internal mechanism, and keep it clearly isolated.
- Do not add a new trustee or xattr database. Salvage JSON is a snapshot; real restore should feed existing mars_nwe trustee/xattr/AFP mechanisms.
NCP path and hidden repository notes
- Normal NCP path resolution intentionally treats Unix dot path components as
hidden/special. In the classic path resolver (
build_dir_name()inconnect.c), a component beginning with.is accepted only for./..semantics; a component such as.recycleor.salvagereturns invalid path (0x899c). nwattrib.calso marks Unix dot files/directories hidden by default when no explicit NetWare attributes are stored.- Therefore
.recycleand.salvageare backend repositories, not user-visible NCP paths. Tests must not expectSYS:.recycle/...orSYS:.salvage/...to open through ordinary NCP file calls. - Use the official salvage endpoints (
87/16scan,87/17recover,87/18purge, and old22/27-22/29) to observe or operate on salvage entries. Verify recovered payload content by reading the restored live file through NCP, not by opening backend repository paths through NCP.
Salvage endpoint rules
NCP 0x2222 / 87 / 16is decimal 87/16, implemented as function0x57, subfunction0x10.NCP 0x2222 / 87 / 17is decimal 87/17, function0x57, subfunction0x11.NCP 0x2222 / 87 / 18is decimal 87/18, function0x57, subfunction0x12.- Legacy salvage endpoints are old function
22decimal /0x16:22/27scan,22/28recover, and22/29purge. They should remain thin adapters over the same shared salvage backend, not a second implementation. - Keep
0x57subfunction dispatch inhandle_func_0x57()/ namespace code, not as a second subfunction switch innwconn.c. - Old
0x16calls need a minimal bridge in namespace code because short directory handles must be resolved through existingbuild_base()/dir_base[]internals before reaching the shared backend. - Versioned backend payload names follow Samba
vfs_recycleliterally:Copy #1 of NAME,Copy #2 of NAME, ... . Do not localize this string and do not run it through gettext; the NCP scan reply still reports the original deleted filename for every version. - Versioned salvage entries may have different
.recycle/.salvagenames but87/16returns the original deleted filename for every version. Do not match recover/purge by display name alone. - Scan must treat
.salvageJSON as a sidecar for the matching.recyclepayload. If an external tool such as Samba or an administrator removes the payload,87/16must not return the stale sidecar and should remove the JSON. The server log should contain a greppable line likeWARN SALVAGE 87/16 STALE ...for this cleanup. - Scan, recover, and purge should share the same scan/sequence/basehandle view so that a sequence returned by scan identifies the exact sidecar used later.
- The combined salvage smoke suite now covers NCP write/read payloads, 87/18 purge pre-clean, hidden backend repository behavior, stale sidecar cleanup with a manual payload-removal pause, three version captures, and recovering the oldest version via sequence 0.
- Append salvage endpoint tests to
tests/salvage/salvage_smoke_suite.shrather than creating unrelated top-level scripts, unless a helper binary is needed and then started by the suite.
AFP 0x13 deleted-file info notes
- AFP
0x13 Get Macintosh Info On Deleted Fileis NCP0x2222 / 35 / 19(wire subfunction byte0x13). The Micro Focus / Novell WebSDK request isVolumeNumberplusDOSDirectoryNumber; the reply is FinderInfo[32], ProDOSInfo[6], ResourceForkSize, FileNameLen, FileName. - Implement it only as an adapter over the shared mars_nwe salvage/deleted-entry
record. Do not expose or normally open
.recycleor.salvagethrough AFP code; those remain hidden backend repositories. - The implementation returns FinderInfo[32], ProDOSInfo[6], resource fork size, and deleted original name from the Salvage JSON snapshot. FinderInfo and ProDOSInfo are captured through the existing nwatalk xattr-backed AFP metadata store, not through a parallel AFP metadata database.
- The AFP smoke suite has a dedicated
afp_deleted_info_smokehelper. It pre-cleans salvage entries in the tested directory through NCP purge, creates a temporary AFP file, writes FinderInfo and ProDOSInfo, deletes it, verifies AFP0x13, and purges the tested deleted entry afterwards. - Verified AFP smoke status: the full suite completed with
failures=0after AFP 35/19 and ProDOSInfo work. It verifies live FinderInfo and ProDOSInfo xattrs onSYS:PUBLIC/pmdflts.ini, verifies AFP 35/19 returnsprodos=010203040506from the deleted-file Salvage snapshot, and leaves normal AFP-only attributes absent when Hidden/System/Archive map through the NetWare attribute path. - Reuse existing AFP/nwatalk metadata mechanisms for FinderInfo, AFP attributes, entry ids, resource fork state, and related restore/lookup behavior. Do not add a parallel AFP metadata database.
Logging rules
Desired future server log format:
<LVL4> <AREA> <DEC-CODE> <EVENT> key=value ...
-
LVL4is exactly four characters:INFO,DBUG,WARN,ERRR. -
AREAexamples:NCP,SALVAGE,AFP,MAP,BIND,TRUST,AUTH,CONN,FILE,QUEUE. -
The front code should be human/protocol decimal where applicable, for example
87/16,87/17,87/18. -
Exact wire values should still be logged later as key/value hex fields, for example
fn=0x57 sub=0x10 seq=0x00000000 base=0x00000004 result=0x89ff. -
Unknown or unimplemented endpoints should be easy to grep, for example:
INFO NCP 87/18 UNKNOWN fn=0x57 sub=0x12 msg="not implemented" INFO NCP 87/255 UNKNOWN fn=0x57 sub=0xff msg="unknown subfunction" INFO NCP 136 UNKNOWN fn=0x88 msg="unknown function" -
Do not invent a parallel logger casually. Reuse existing mars_nwe logging functions/macros and normalize message format gradually.
Build and test notes
Dependencies used during local checks in this conversation:
gdbm-1.26.tar.gzLinux-PAM-1.7.2.tar.xzfor PAM headers; link against system PAM if presentncpfs-master.zipfor the salvage smoke helper client buildyyjsonunderthird_party/yyjson
If CMake finds GDBM but a target still cannot see gdbm.h, pass include paths
explicitly for local verification, for example:
CFLAGS="-I/path/to/gdbm/include -I/path/to/Linux-PAM-1.7.2/libpam/include" \
cmake -S . -B build
cmake --build build --target nwconn ncp_salvage_scan_smoke ncp_salvage_recover_smoke
Useful quick checks:
bash -n tests/salvage/salvage_smoke_suite.sh
cc -DLINUX -fsyntax-only -Iinclude -Isrc -Ithird_party/yyjson/src src/nwsalvage.c src/namspace.c
When server-side code or smoke helper clients change, rebuild both the server and the helper targets so the runtime test is not using stale binaries:
cmake --build build --target nwserv ncpserv
cmake --build build --target \
ncp_delete_smoke \
ncp_read_smoke \
ncp_salvage_scan_smoke \
ncp_salvage_recover_smoke \
ncp_salvage_purge_smoke \
afp_entry_id_smoke \
afp_file_info_smoke \
afp_scan_info_smoke \
afp_set_file_info_smoke \
afp_deleted_info_smoke
Runtime smoke suites:
tests/salvage/salvage_smoke_suite.sh --out /tmp/mars-salvage-report.txt
tests/afp/afp_smoke_suite.sh --out /tmp/mars-afp-smoke.txt
The suite streams the report to --out while running, so a failure before the
end should still leave useful output. It has a manual stale-payload pause: the
script prints a sudo rm -f .../.recycle/... command; remove that payload in a
second shell and press Enter. The next scan should remove the stale sidecar and
grep /var/log/mars_nwe/nw.log for WARN SALVAGE 87/16 STALE.
Normal NCP reads of .recycle or .salvage are expected to fail with invalid
path. Verify payload data through the visible live file after NCP write or
recover, using ncp_read_smoke. Treat the final summary (failures=0,
ncp_warnings=0) as the important signal.
AFP ProDOSInfo storage
ProDOSInfo is AFP/NCP per-entry metadata. Store it in the existing nwatalk
AFP metadata layer, not in nwarchive/nwxattr directly and not in a parallel DB.
The xattr key is user.org.mars-nwe.afp.prodos-info via the mars_nwe xattr
wrapper name org.mars-nwe.afp.prodos-info; it is a raw 6-byte value, analogous
to FinderInfo's 32-byte org.mars-nwe.afp.finder-info.
Salvage captures this as prodos_info_hex (12 hex characters) beside
finder_info_hex. AFP 35/19 Get Macintosh Info On Deleted File returns
FinderInfo[32] followed by ProDOSInfo[6] from the Salvage snapshot. The
verified smoke value is 010203040506 and the Linux xattr dump should show:
user.org.mars-nwe.afp.prodos-info=0x010203040506
Latest endpoint audit checkpoint
As of patch 0212-docs-audit-namespace-lock-salvage-stubs.patch,
the latest audited endpoint block is the Name Space lock/quota/search/salvage-rights
subset of NCP 0x2222/87 / wire 0x57 in src/namspace.c.
nwconn.c still forwards requestdata starting at the Name Space SubFunction
byte to handle_func_0x57(), and the handler return convention remains
unchanged: non-negative values are reply payload lengths, negative values are
Completion codes.
The previous 87/16..87/29 block contains active source cases for:
87/16Scan Salvageable Files;87/17Recover Salvageable File;87/18Purge Salvageable File;87/20Search for File or Subdirectory Set;87/21Get Path String from Short Directory Handle;87/22Generate Directory Base and Volume Number;87/24Get Name Spaces Loaded List from Volume Number;87/26Get Huge NS Information;87/28Get Full Path String;87/29Get Effective Directory Rights.
Disabled source stubs exist for eligible 3.x/4.x metadata gaps from that range:
87/19Get NS Information;87/23Query NS Information Format;87/25Set NS Information;87/27Get Name Space Directory Entry.
Patch 0212 added the next set of disabled source stubs for eligible
1.x/2.x/3.x and planned-4.x namespace/file gaps that were missing from the
active switch range:
87/36Log File;87/37Release File;87/38Clear File;87/39Get Directory Disk Space Restriction;87/40Search for File or Subdirectory Set (Extended Errors);87/41Scan Salvageable File List;87/42Purge Salvageable File List;87/43Revoke File Handle Rights.
These stubs are under #if 0, document selector path/request/reply/provider
intent, and do not change runtime behavior. 87/44 Update File Handle Rights
is NetWare 5.x in the NDK material and was not stubbed under the current scope.
The existing 87/26 source slot is still effectively unimplemented and returns
the default 0xfb completion.
The next endpoint block can continue with 87/64..87/69, the matching 89
long-name-space family, or another unaudited top-level family such as AFP
0x2222/35, packet burst 0x2222/97/101, or deeper 0x2222/23
bindery/property/admin subfunction coverage, unless the user requests a
specific family first.
The next patch number should follow the latest applied patch; after patch 0223, use 0224.
Retro source-stub checkpoint from patch 0207:
- Already documented eligible gaps in Directory Services
22/12,22/35, and22/36have disabled source stubs at the correctsrc/nwconn.cdispatch slots. Do not rewrite those stubs unless implementing the endpoint. - Already documented File Server Environment
23queue/server-management gaps have disabled source stubs at the appropriatesrc/nwbind.cswitch slots. Some pre-existing disabled stubs still contain legacy placeholder control flow; leave existing stubs alone unless implementing or explicitly cleaning that exact block. - Message
21/04..21/08were not SDK/PDF server endpoints in the default audit set, so no stubs are required. Message21/12is later-generation only and remains prose-only/out-of-scope under the current rules. - Physical-record
26..31plus110, TTS34/00..34/10, and direct file59,61..77do not have additional eligible missing slots in the audited ranges; no new source stubs were needed. - Future retro-audits must distinguish three cases: add a disabled source stub for an eligible missing endpoint, leave an already-present stub unchanged and only document that it exists, or keep non-endpoints / 5.x+ endpoints out of source.
Remember: for every new endpoint-audit patch, also update this AI handoff file with the latest audited block and expected next patch number. Put detailed Coverage/Request/Reply/Known-difference notes inline at each endpoint case rather than as one large audit block before the switch range.
Missing-endpoint rule: when an audited SDK/PDF/WebSDK/Header endpoint is not
implemented but belongs to the compatibility scope, document it at the
appropriate dispatch location as a disabled #if 0 stub instead of only
mentioning it in prose. The compatibility scope for stubs is NetWare 1.x/2.x
legacy calls, NetWare 3.x/default compatibility calls, and explicitly planned
NetWare 4.x/NDS work. Do not add stubs merely for NetWare 5.x/OES/MOAB/newer
endpoints: those are outside the current target unless the user explicitly asks
for that later generation. A 3.x-compatible server should remain compatible
with documented 1.x/2.x calls, and the current forward plan is only through
4.x. Disabled stubs should include selector path, name, request/reply sketch,
provider/out-of-scope reason, and no active behavior change. Disabled stubs
must not use misleading control flow such as return(-1) where that return
value has no local handoff meaning.
Latest endpoint audit checkpoint from patch 0223:
- Direct
NCP 0x2222/111/ wire0x6fSemaphore is now source-stub-audited insrc/nwconn.c. There is no active top-level handler for this newer NetWare 3.x/4.x semaphore family. - Patch
0223records disabled#if 0selector slots for111/00Open/Create a Semaphore,111/01Examine Semaphore,111/02Wait On (P) Semaphore,111/03Signal (V) Semaphore, and111/04Close Semaphore. - The old
32/xxsemaphore implementation insrc/sema.cremains the active compatibility path. Future work should bridge both families through one semaphore provider/state table and verify the documented Lo-Hi handle order against existing MARS-NWE big-endian handle helpers before changing behavior. - This block is local synchronization, not
nwnds/directory work.
Next patch number should be 0224.
Latest endpoint audit checkpoint from patch 0224:
- SDK
0x2222/90/ wire0x5aData Migration / parse-tree / compression metadata is now source-stub-audited as planned NetWare-4.x filesystem and namespace work. There was no active top-level handler insrc/nwconn.c. - Patch
0224records the selector map behindMARS_NWE_4:90/00Parse Tree,90/10Get Reference Count from Dir Entry Number,90/11Get Reference Count from Dir Handle,90/12Set Compressed File Size,90/128Move File Data To DM,90/129DM File Information,90/130Volume DM Status,90/131Migrator Status Info,90/132DM Support Module Information,90/133Move File Data From DM,90/134Get/Set Default Read-Write Support Module ID,90/135DM Support Module Capacity Request,90/136RTDM Request, and90/150File Migration Request. - The future owner is the filesystem/namespace provider, not
nwnds. There is no active Data Migration support module, parse-tree engine, compressed file-size backend, or RTDM provider yet. Keep this as unsupported0xfbunless the filesystem provider grows real backing state.
Next patch number should be 0225.
Latest endpoint audit checkpoint from patch 0225:
- SDK
0x2222/92/ wire0x5cSecretStore is now scope-audited as later-generation and out of the current source-stub target. The NDK PDF marks SecretStore Services as NetWare Server 5.x and eDirectory 8.5 or later, with subverbs0Query Server through9Get Service Information. - No active top-level
case 0x5cexists insrc/nwconn.c, and no indirect handler/provider path was found during this audit. Do not add a disabled source stub for SecretStore while the target remains 1.x/2.x/3.x plus planned 4.x only. - SecretStore is not the same as the planned 4.x
libdirectory/nwndswork. If a future post-4.x/eDirectory target is ever added, it should be designed as a separate secure secret-storage provider with strict no-secret logging rules.
Next patch number should be 0226.