Stage B proof: add per-VM consumed term to stadium_conserved -- FABRIC-3.6.md task 2.7

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Robert Allan James
2026-09-20 21:31:45 -04:00
co-authored by Claude Sonnet 5
parent 313ffc89e6
commit 2a2bf6eb35
12 changed files with 55566 additions and 8 deletions
+1
View File
@@ -132,6 +132,7 @@ typedef struct {
uint32_t channel;
uint32_t orig_type;
int in_use;
VMUuid owner; /* VM whose reservoir funded this message (task 2.7) */
} SkHermesMessage;
/*
+18 -6
View File
@@ -375,12 +375,13 @@ uint64_t stadium_resident_sum(VMUuid vm_id);
*
* stadium_resident_sum(vm_id) + stadium_reservoir_peek(vm_id) == Q48_ONE
*
* FABRIC-3.5.md §XL.4 rules that the full invariant also adds a `consumed`
* term once kernel-Hermes exists and ledgers what its allocator consumes
* (Phase 2) -- until then nothing draws on a VM's Stadium quota, so the
* two-term form above is exact, not an approximation of the eventual one.
* A future caller adding the `consumed` term does so here, not by working
* around this function.
* FABRIC-3.5.md §XL.4: the full invariant also has a per-VM `consumed`
* term (task 2.7), recorded by kernel-Hermes when its messages decay:
*
* stadium_resident_sum + stadium_reservoir_peek + stadium_consumed_peek
* == Q48_ONE
*
* The two-term form above is the special case consumed == 0.
*
* Returns 0 (not conserved) for an unknown vm_id, same convention as
* stadium_reservoir_peek()/stadium_resident_sum() returning 0 for one.
@@ -390,6 +391,17 @@ uint64_t stadium_resident_sum(VMUuid vm_id);
*/
int stadium_conserved(VMUuid vm_id);
/*
* stadium_consumed_record - Add amount to vm_id's per-VM consumed total
* (heat destroyed by decay; FABRIC-3.5.md §XL.4). No-op if vm_id has no
* quota. Caller (kernel-Hermes decay) must have removed the same amount
* from a resident patron's heat.
*/
void stadium_consumed_record(VMUuid vm_id, uint64_t amount);
/* stadium_consumed_peek - vm_id's consumed total, 0 for an unknown vm_id. */
uint64_t stadium_consumed_peek(VMUuid vm_id);
/*
* stadium_evict - Reap the patron header at cell_index (FABRIC-0.md §17.2:
* "reap means leaves the floor, not destroyed"). Dispatches its behaviour