diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index 99f348c2..d820d87f 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -74,6 +74,12 @@ Hermes is distinguished only by convention (it holds `COMMON-CH`; it is routing ### I.2 — Hermes is a hard, by-name dependency of its peers +> **CORRECTED 2026-09-18 by §XIII.1 — this section undercounts.** It names two call sites; the +> full repo-wide inventory is **14 by-name FORTH references across 5 files, plus 3 C-side +> sites and a DoE CSV schema site.** The two below are real, are among the only three *live* +> ones, and remain the sharpest edge — but read §XIII.1 for the actual extent. Left in place +> rather than rewritten, per this series' own "never silently drop a stale claim" rule. + Artemis does not talk to an abstract routing layer. It talks to a VM called `Hermes`, by name, via `VM-EXEC`. Two live call sites in `capsules/artemis/init.4th`: @@ -528,10 +534,10 @@ dependency order that fell out of writing this up: Nothing here is started. Nothing here authorizes an edit. Numbered for discussion order, not execution order. -1. ⬜ Run the repo-wide `S" Hermes" VM-EXEC` grep and inventory every by-name Hermes dependency - (§III.3). Pure investigation; no design commitment. -2. ⬜ Re-verify the §V.3.4 and §VII.4 citations taken from headings and `.claude/CLAUDE.md` - rather than from the source (`FABRIC-2.md` §H.1/§H.12, `FABRIC-3.md` §XVIII). +1. ✅ **CLOSED 2026-09-18 (§XIII.1).** Repo-wide by-name Hermes inventory: 14 FORTH sites + across 5 files, 3 C-side sites, 1 DoE CSV schema site. Only 3 are live. §I.2 corrected. +2. ✅ **CLOSED 2026-09-18 (§XIII.4).** All three citations verified against source; §V.3.4 and + §VII.4 may now be relied on. 3. ⬜ Settle §III.4: routing-only vs. full arena centralization. **Root dependency — do first.** 4. ⬜ Settle §III.3 given 3. 5. ⬜ Settle §IV.2 if and only if 3 leaves a FORTH routing table standing. @@ -542,6 +548,13 @@ execution order. 9. ⬜ Assign `SOS` a message-type number deliberately (§VII.2), with a named consumer. 10. ⬜ Specify the sinking semaphore's mechanism and the clean-shutdown routine (§VIII.3). 11. ⬜ Answer §IX.3: what declares a birther dead, and what fleet shutdown means concretely. +12. ⬜ **NEW 2026-09-18 (§XIII.5).** Rule on whether the Console Tripod leg is a *new* + singleton, distinct from today's plural per-attach console proxies. **Gates §IV.1 and + §IV.2** — sits above the slot-numbering question, not beside it. +13. ⬜ **NEW 2026-09-18 (§XIII.2), not part of this reshuffle.** Authorize a + `capsules/MANIFEST.md` correction pass for two false claims: block 4055's "immutable ABI" + (`FABRIC-2.md` declared it stale and it was never corrected) and block 2049's stated + contents. Reported, not fixed, per Captain Bob's Law. **Acceptance for anything that eventually comes out of this list**, per `.claude/CLAUDE.md`'s non-negotiable criteria: three-arch QEMU boot (`amd64`, `aarch64`, `riscv64`, one at a time, in @@ -554,7 +567,9 @@ There is no other test. ## XII. Explicitly not decided anywhere in this document Collected so nothing here is mistaken for settled: §III.3, §III.4, §IV.2, §V.3 (all four), -§VI.3, §VI.4, §VII.2 (number and consumer), §VII.3, §VII.4, §VIII.3 (all three), §IX.3 (both). +§VI.3, §VI.4, §VII.2 (number and consumer), §VII.3, §VII.4, §VIII.3 (all three), §IX.3 (both), +and — added 2026-09-18 — §XIII.5's Console-singleton question (punch item 12), which gates +§IV entirely. §XIII.5's proposed resolution shape is **analysis, not a ruling.** What **is** decided, all by Captain Bob on 2026-09-18 and recorded in §III.1, §IV.1, §V.1, §VI.1, §VII.1, §VII.2, §VIII.1 and §IX.1: Hermes goes into the kernel and becomes the arbiter @@ -562,3 +577,192 @@ rather than a client; the Tripod becomes Hera/Artemis/Console; Console becomes t `BIRTH` is general with authority bounded by inheritance; the fleet shares one gentle→from-scratch→brutal ladder; `SOS` is a standard message type with Hermes excepted via a sinking semaphore; and a failed birther's authority is never provisionally handed off. + +--- + +## XIII. Punch-list items 1 and 2 worked — CLOSED 2026-09-18, with three corrections to this document's own §I + +Worked per the series' standing discipline: items 1 and 2 were the two pure-investigation +entries on §XI, carrying no design commitment, so they were executable without a ruling. All +findings below traced directly against the working tree at `e56974e` on 2026-09-18. **No code +written, no design question answered, nothing in the tree modified.** + +### XIII.1 — Item 1 CLOSED: the by-name Hermes inventory. §I.2 undercounted by an order of magnitude. + +**Correction to §I.2, which is wrong as written.** It claimed the by-name dependency was +Artemis's "two live call sites" and framed Artemis as *the* dependent. The real inventory is +**13 by-name FORTH references across 5 files, plus 3 independent C-side sites.** §I.2's two +sites are real and still the sharpest edge, but they are not the extent of it, and the +executive framing ("relocated and rewired") has to cover all of it. Full inventory: + +| # | Site | Call | Live? | +|---|---|---|---| +| 1 | `common/msg.4th:7` | `S" MSG-ACK-LAST" S" Hermes" VM-EXEC` | **dead** — §XIII.2 | +| 2 | `common/msg.4th:10` | `S" MSG-NACK-LAST" S" Hermes" VM-EXEC` | **dead** — §XIII.2 | +| 3 | `artemis/init.4th:138` | `S" 2 ENQUEUE-READY" S" Hermes" VM-EXEC` | live | +| 4 | `artemis/init.4th:501` | `S" 2 COMMON-CH @ CH-ADD-MBR" S" Hermes" VM-EXEC` | live | +| 5 | `process.4th:12` | `S" 1 EVENT-EMIT" S" Hermes" VM-EXEC` (SPAWN) | **dead** — §XIII.2 | +| 6 | `process.4th:15` | `S" 2 EVENT-EMIT" S" Hermes" VM-EXEC` (PAUSE) | **dead** | +| 7 | `process.4th:21` | `S" 3 EVENT-EMIT" S" Hermes" VM-EXEC` (RESUME) | **dead** | +| 8 | `process.4th:26` | `S" 4 EVENT-EMIT" S" Hermes" VM-EXEC` (KILL-VM) | **dead** | +| 9 | `doe-campaign.4th:6` | `S" Hermes" BIRTH` | not auto-run | +| 10 | `doe-campaign.4th:7` | `S" LOAD-DOE" S" Hermes" VM-EXEC` | not auto-run | +| 11 | `doe-campaign.4th:17` | `S" DOE-WORK" S" Hermes" VM-EXEC` | not auto-run | +| 12 | `doe-campaign.4th:28` | `S" DOE-WORK" S" Hermes" VM-EXEC` | not auto-run | +| 13 | `doe-campaign.4th:54` | `S" 1959 1 EXEC-DOE" S" Hermes" VM-EXEC` | not auto-run | +| 14 | `messaging.4th:77` | `S" Hermes" 1 VM-NAME-REG` | live (§I.3) | + +**The good news is real: only 3 of the 14 are live production paths** (#3, #4, #14). Seven are +dead code (§XIII.2), four are in a campaign orchestrator `docs/working/architecture/ +DOE-LIBRARY-HOWTO-20260819.md` itself records as "Not auto-run anywhere." **This materially +lowers the estimated cost of §III.3** — but it must be re-confirmed rather than trusted, since +"not auto-run" is a claim about today's boot path, not a guarantee nothing invokes it. + +### XIII.2 — Seven of those sites are dead code, and `MANIFEST.md` carries a claim FABRIC-2 already declared stale + +**`common/msg.4th` is loaded by nothing.** Traced: `S" common:msg.4th" EXEC` appears exactly +once in the tree — inside `common/msg.4th`'s own header comment, as usage documentation. No +capsule EXECs it. `capsules/init.4th` (block 2049) loads `ACL.4th`, `block-acl.4th`, +`zuse-eligibility.4th`, `lib.4th`, `fabric.4th`, `font.4th`, `common:messaging.4th` — and +nothing else. + +This is **already known and already written down.** `FABRIC-2.md:2770-2773` states it +outright: the `HERMES-ACK`/`HERMES-NACK` wrappers "are now obsolete (every VM has its own +local `MSG-ACK-LAST`/`MSG-NACK-LAST` — no `VM-EXEC` indirection needed) but the file itself +was left in place, unloaded, rather than deleted unprompted; `capsules/MANIFEST.md`'s +'immutable ABI' claim for block 4055 is now stale." `messaging.4th:411` carries the same note +from the other side: "common:msg.4th's HERMES-ACK/NACK indirection is retired." + +**`capsules/MANIFEST.md` was never corrected.** Line 317 still reads: "Immutable: this is the +cross-VM ACK/NACK ABI. Every messaging VM (Hera, Hermes, Artemis) loads this at birth. +Changing the block or the word names breaks the Hermes delivery protocol." That is false on +every clause. A second MANIFEST claim also fails against the source: line 52 describes block +2049 as loading "compudynamics, VM-INIT, lib, common:msg, fleet-k, process; BIRTHs Artemis + +Hermes" — `init.4th` block 2049 loads none of `common:msg`/`process` and contains no `BIRTH` +at all (Hermes and Artemis are birthed from C — §XIII.3). + +**`process.4th` is likewise EXEC'd nowhere**, making sites #5–#8 dead with it. + +**Reported, not fixed**, per Captain Bob's Law ("if you identify a bug, report it; do not fix +it unless the user says to"). Flagged here because a reshuffle that reads `MANIFEST.md` as +current will conclude the ACK/NACK path is a live immutable Hermes ABI and scope around a +constraint that stopped existing in `FABRIC-2.md`'s era. **Recommend a MANIFEST.md correction +pass as its own authorized item; it is not part of this reshuffle.** + +### XIII.3 — The Tripod is hardcoded as a name-triple in C, in three independent places + +Not previously recorded in this document. Each is an edit site the moment the Tripod's +membership changes (§IV.1): + +1. **`capsule_birth.c:793-796`** — `is_fleet_foundation` is literally + `vm_name_prefix_eq_nocase(capsule_name, "Hera") || ... "Hermes" || ... "Artemis"`. It gates + `StadiumPatronHeader` setup and the `session_register()`/`session_set_pinned()` pinning + calls. **This is the Tripod, encoded as a string test.** Swapping Hermes for Console is a + one-line change here — and that single line is what makes a VM pinned. +2. **`kernel_main.c:864-874`** — `vm_interpret(mama, "S\" Hermes\" BIRTH")` plus a + `capsule_vm_find_by_name_nocase("Hermes", ...)` liveness check and console banner. The + comment cites `FABRIC-2.md` D.7 (birth-by-message-only, 2026-08-28): the Tripod legs "must + be alive session-less so a later thumbdrive-attach flow has a running Hermes/Artemis to + message." **Note the stated rationale for Hermes being born early is precisely that other + flows need it available — which a kernel-resident arbiter satisfies trivially and + permanently.** §III is consistent with D.7's intent, not in tension with it. +3. **`kernel_main.c:1007-1009`** — `sk_vm_switch_signal_register(hermes_entry.vm_id)`, the + preemptive context-switch registration from `FABRIC-3.md` §XXVIII. + +**A fourth site is not code but schema, and is the expensive one: `doe_log.c`.** The per-tick +DoE CSV hardcodes the Tripod across six columns — 16/17/18 (`hera_heat_q48`, +`hermes_heat_q48`, `artemis_heat_q48`, populated by `doe_log_heat_by_name("Hera"/"Hermes"/ +"Artemis")` at lines 206-208) and 23/24/25 (`switch_*_readiness`), with column 22 documented +as "0=Hera, 1=Hermes, 2=Artemis by current registration order." **Changing Tripod membership +changes the DoE CSV schema**, which bears directly on comparability with every campaign +already run (§XXXIV/§XXXV's segmented per-ISA design in `FABRIC-3.md` is mid-flight). Flagged +as a real cost, not a blocker, and **not** something to resolve by quietly renaming a column. + +### XIII.4 — Item 2 CLOSED: all three flagged citations verified against source + +§XI item 2 flagged three citations this document took from headings and `.claude/CLAUDE.md` +rather than from the source. All three check out; §V.3.4 and §VII.4 may now be relied on. + +- **`FABRIC-2.md` §H.1** — real, at line 3699, "Session = Stadium patron, admission restated." + The pinning claim is at line 3713: pinned sessions are exempt from "the normal departure + path (heat decay / `COOL`): they never leave, permanently." Confirmed as §V.3.4 used it. +- **`FABRIC-2.md` §H.12** — real, at line 4057, "Implementation punch list (2026-09-03)." + Independently corroborated from the code side: `capsule_birth.c:785-788` cites "§H.12 step 4" + by name for the `session_register()`/`session_set_pinned()` soft-fail convention. +- **`FABRIC-3.md` §XVIII** — confirmed. `K` is `vm_physics_fleet_heat_sum()` over **all** live + VMs, which the reservoir-transfer accounting holds exactly at `Q48_ONE`, surfaced as the + `fleet_k_q48`/`fleet_conserved` CSV columns. §VII.4's warning stands as written: a brutal + death must still return what it held, or it breaks a continuously-verified invariant. + +### XIII.5 — New finding, and the most consequential of this pass: Console today is plural, ephemeral, and capsule-less + +**This was not known to §IV or §V when they were written, and it changes what §IV.1 is asking +for.** Traced in `capsule_console.c`: + +- **Console has no capsule.** `capsules/` contains `hermes/` and `artemis/` directories but + **no `console/`**. A console VM's entire personality is a 3-line C string literal, + `CONSOLE_IDENTITY_SRC` (`capsule_console.c:28-31`): `Block 4997`, `S" common:messaging.4th" + EXEC`, `MSG-CD-INIT`. That is all of it. +- **Console is deliberately *not* on the routing table.** The source comment is explicit: "No + `COMMON-CH` subscription: a console's own traffic is direct 1:1 with its paired user VM + (`CONSOLE-CMD-EVENT`), not broadcast, so there's no need to resolve an index in Hermes's own + routing table for it." +- **Console is plural and per-attach.** `capsule_console_birth(const char *console_name, ...)` + is called from three sites (`capsule_wirebind.c:245`, `mama_forth_words.c:1591` and `:2015`) + and mints a fresh heap-built single-entry capsule directory each time. There are as many + console VMs as there are attachments. + +**Consequence.** Hera, Hermes and Artemis are singular, pinned, born-at-boot, capsule-backed, +routing-table-indexed. Console today is **none of those five things.** So §IV.1's "Console +takes the vacated third slot" is **not** a relocation of an existing pinned VM — as stated it +would create a Console that does not currently exist. That is worth naming plainly, because it +is the one place this document's "reorganization, not invention" scope discipline is genuinely +strained. + +**The shape that resolves it without inventing anything** — offered as analysis, **not +ratified, Captain Bob's call**: distinguish **Console** (singular, pinned, capsule-backed, the +Tripod leg — owns the drawing fabric and is the bind point, per §V.1) from **console proxies** +(plural, ephemeral, per-attach — exactly what `capsule_console_birth()` mints today, +unchanged). The Tripod leg is new; the proxies are untouched. This reading makes §V.1's "bind +point" precise: the leg is what you bind *to*, the proxy is what binding *produces*. + +### XIII.6 — §V and §VI are load-bearing for each other, which neither section noticed + +If Console is the bind point (§V.1), it is Console that must mint console proxies — and +minting a VM is `BIRTH`. Today all three `capsule_console_birth()` call sites run in Hera's or +the caller's context. **So "Console is the bind point" cannot be implemented while `BIRTH` +remains Hera-exclusive; it requires §VI.1's generalization.** They are one change, not two. + +Mechanically this already works, which strengthens both: two of the three call sites pass +`vm->stadium_vm_id` — *whichever VM invoked* — rather than a hardcoded Hera +(`capsule_wirebind.c:245` passes `mama_vm->stadium_vm_id` because that path genuinely is +Hera's). That matches §I.5's finding that `capsule_birth_baby()` treats `stadium_vm_id` +generically as "whoever is birthing this VM." **Parentage is already generic; only +registration is not.** + +This also supplies the first concrete answer to §VI.4's open "what is standing": Console needs +`BIRTH` to do its declared job, so it has standing by role. That is evidence for reading (a) +(standing = having `BIRTH` registered), not a ruling. + +### XIII.7 — Effect on §X's sequencing + +Nothing found here dislodges §III.4 as the root dependency. Two adjustments: + +- **§III.3 is cheaper than §I.2 implied** (3 live sites, not a broad web) and can be scoped as + soon as §III.4 lands. +- **§IV.1 needs a prior ruling that §IV.2 does not cover**: is the Tripod's Console leg a *new* + singleton distinct from today's proxies (§XIII.5)? That question sits *above* the slot + numbering, not beside it. **Added to the punch list as item 12.** + +### XIII.8 — Punch-list status after this pass + +- ✅ **Item 1 CLOSED** — inventory complete (§XIII.1), 14 FORTH sites + 3 C sites + 1 CSV + schema site; §I.2 corrected. +- ✅ **Item 2 CLOSED** — all three citations verified against source (§XIII.4). +- ⬜ **Item 12, NEW** — rule on §XIII.5: is the Console Tripod leg a new singleton, distinct + from today's per-attach proxies? **Gates §IV.1 and §IV.2.** +- ⬜ **Item 13, NEW, not part of this reshuffle** — authorize a `capsules/MANIFEST.md` + correction pass for the two false claims in §XIII.2 (block 4055 "immutable ABI"; block 2049 + contents). Reported, not fixed. + +Items 3–11 unchanged and still open.