diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index 73feb601..3f088688 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -1942,3 +1942,134 @@ because the birth graph says plainly whether a consumer exists. open design question in this document.** - ⬜ **Items 16, 17, 18** — the `STADIUM-EVICT` teardown check; `BYE` vs. a separate suicide word; the empty-floor halt when Hera is already gone. + +--- + +## XXII. Execution method: the surgical strip is punch item 1, and it is iterative (Captain Bob, 2026-09-19) + +**Captain Bob, verbatim:** "As far as any of the existing forth we anticipate will no longer be +used. That's probably going to get totally stripped out before we code. The existing gaps we +need to fill in will reveal themselves as we code/test iterate and dead FORTH code falls out at +the same time. That's going to be the first very surgical item on the punchlist." + +So the method is: **strip the anticipated-dead FORTH first, then code; further dead FORTH falls +out as coding and testing reveal the real gaps, and gets stripped in the same loop.** This +becomes **punch item 1**, ahead of everything else in §XVIII.9 and §XX. + +### XXII.1 — Two categories, and only one of them can be stripped first + +"Strip before we code" must not be read as "delete the working system before the replacement +exists." The legacy FORTH splits cleanly, and the split is the ordering: + +- **Category A — dead *today*, independent of this reshuffle.** Nothing loads or invokes it + now. Strippable immediately, before a line of new code, with no dependency on kernel-Hermes + existing. This is the genuine first item. +- **Category B — dead *on arrival* of kernel-Hermes.** `capsules/hermes/init.4th`, most of + `capsules/common/messaging.4th`, the routing table, the slot-3 pairing convention (§XX.1). + **These are load-bearing until the replacement boots.** Stripping them first would remove a + working messaging layer with nothing behind it. They fall out *during* the iterate loop, as + Captain Bob describes — not before it. + +§XIII.1's fourteen-site inventory is the map for both; §XIII.2 already identified the +Category A members it found. + +### XXII.2 — The trap: reachability here cannot be established by grep, in either direction + +**Recorded because this document nearly walked into it while building the strip inventory.** A +first pass counted textual references per capsule and produced a list with +`init-l8-diverse.4th`, `init-l8-omni.4th`, `init-l8-stable.4th`, `init-l8-temporal.4th`, +`init-l8-transition.4th`, `init-l8-volatile.4th`, `sdk.4th` and others at **zero references** — +i.e. apparently dead. + +**They are not dead. They are DoE experiment infrastructure**, and a second pass including +`experiments/`, `tools/` and `docs/` found **18–19 references each** for the `init-l8-*` family +and 9 for `sdk.4th`. The first pass searched only `capsules/` and `src/`. + +The failure is structural, not a careless grep: + +- **It under-reports.** Capsules are birthed *by name from runtime strings* — `S" " + BIRTH`, campaign scripts, `EXEC` of a name assembled at run time. Static reference counting + cannot see any of that. +- **It over-reports.** A capsule named for a common word returns noise: `process` scores 180 + hits across the tree, essentially all prose. (`process.4th`'s actual deadness was established + the other way — by confirming nothing `EXEC`s it — not by counting.) + +**So no strip list in this document is authoritative, including any list this document +produces.** Reachability must be established per capsule by all three routes: loaded from a +boot path, invoked from `experiments/`/tooling, or present in the capsule directory `mkcapsule` +bakes into the image. + +### XXII.3 — The acceptance asymmetry, which is what makes "surgical" necessary + +`.claude/CLAUDE.md` is unambiguous that the three-architecture QEMU boot is the only acceptance +test there is. **For this particular task it is necessary but not sufficient**, and the gap is +specific: + +- A boot exercises the **boot path**. Deleting something Category A and boot-reachable fails + loudly and immediately — good. +- A boot does **not** exercise DoE/experiment capsules. Deleting one **passes all three + architectures cleanly** and surfaces months later, when a campaign is run. + +That asymmetry is the real hazard of this item. And the stakes are not only code: +`.claude/CLAUDE.md` records that the `logs/` artifacts "are audit artifacts — they are +committed to the repo. Do not delete them," and that the DoE campaign report is **patent +support material**. Experiment infrastructure is part of a measurement apparatus with an +evidentiary role. + +**Rule, proposed: treat every `experiments/`-reachable and DoE-related capsule as live by +default.** Removing one is its own decision with its own justification, never a side effect of +a messaging cleanup. + +### XXII.4 — How the loop should run + +Consistent with this series' own discipline and with the acceptance criteria: + +1. **Strip Category A only**, in a commit *separate* from any new code, so a single file can be + restored without unpicking a feature. Nothing else in the same commit. +2. **Boot all three architectures** after the strip, before writing anything new — establishing + that the strip alone is clean, rather than discovering later which half of a mixed commit + broke something. +3. **Then code**, and let the gaps reveal themselves as Captain Bob describes. +4. **Each time coding proves a Category B item dead, strip it in its own commit too**, with its + own three-arch boot. + +**Expected and not a defect:** every strip changes `dict_hash`. Per §III.5 and §XX's standard, +the property that must hold is **cross-architecture identity**, never an unchanging absolute +value. `mkcapsule --lint capsules/` must stay clean throughout, and freed block ranges should +be returned to `capsule-reserved.txt` rather than silently reused (§XVIII.4). + +### XXII.5 — What rides along + +- **The `MANIFEST.md` corrections** (§XIII.2, formerly item 13) belong to this pass: block + 4055's "immutable ABI" claim that `FABRIC-2.md:2773` already declared stale, and block + 2049's wrong contents list. Correct them **as the files they describe are stripped**, so the + manifest never describes a file that no longer exists. +- **`SPAWN-EVENT`** (§I.4: zero consumers, confirmed twice) is Category A by definition. +- **`src/*.c.bak`** — `.claude/CLAUDE.md` flags `vm.c.bak`, `doe_metrics.c.bak` and + `inference_engine.c.bak` as tracked-but-stale repo hygiene debt, to "report it if it comes + up; don't delete unprompted." It has now come up. **Not part of this reshuffle**, but the + natural companion pass — flagged, not scheduled, and still requiring its own authorization. + +### XXII.6 — Punch list, re-ordered + +**1. ⬜ SURGICAL STRIP — Category A dead FORTH.** Establish reachability per §XXII.2's three +routes (never by grep alone), strip in isolated commits, three-arch boot each time, +`mkcapsule --lint` clean, MANIFEST corrected alongside, freed blocks returned. **Precedes all +other items.** + +Then, unchanged in content but now downstream of it: + +2. ⬜ Hestia: relocate `fabric.4th` + `font.4th`; move `PLOT`/`FB-WIDTH`/`FB-HEIGHT` + registration (§XVIII.9.1). +3. ⬜ Hestia's block range against `capsule-reserved.txt`, avoiding 4997 (§XVIII.9.2). +4. ⬜ Hestia into `is_fleet_foundation`; `kernel_main.c:865` birth; switch-signal registration + (§XVIII.9.4, §XIX.6). +5. ⬜ `doe_log.c` CSV schema change (§XIII.3) — still the expensive consequence. +6. ⬜ State §XVIII.6's headless invariant in the implementation. +7. ⬜ **§VIII.3 first bullet** — where the sinking semaphore mechanically lives. **The last open + design question.** +8. ⬜ Item 16 — every message-holding teardown path reaches `STADIUM-EVICT`; verify via + `fleet_conserved` (§XV.4). +9. ⬜ Item 17 — Hera's suicide: replace `BYE`'s cold-restart, or a separate word (§XVI.2). +10. ⬜ Item 18 — the empty-floor halt when Hera is already gone (§XVI.7). +11. ⬜ Category B strips, each as coding proves the item dead (§XXII.1, §XXII.4.4).