diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index c269aaa7..6b143a48 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -617,8 +617,8 @@ build-time check.** counting semaphore. **This was the last open design question.** - **Item 16 (§XV.4)** — an implementation check rather than a decision: every message-holding teardown path must reach `STADIUM-EVICT`, verifiable via `fleet_conserved`. -- **Item 17 (§XVI.2)** — does Hera's suicide replace `BYE`'s current cold-restart, or become a - separate word? Small, but it changes a live registered word either way. +- ~~**Item 17**~~ — **SETTLED 2026-09-19 by §XXIV**: a separate word; `BYE` left alone. The + reshuffle therefore changes zero live registered words. - **Item 18 (§XVI.7)** — if Hera is already dead, nobody performs the halt. Proposed shape (an empty floor as a kernel-observable condition) is **analysis, not a ruling.** @@ -2207,3 +2207,100 @@ and three small local decisions: **Items 8 and 9 are the only two carrying an unmade decision**; the rest are execution. Nothing on this list is authorized by this document — per Captain Bob's Law, no code without an explicit instruction. + +--- + +## XXIV. Item 17 SETTLED: Hera's suicide is a separate word; `BYE` is left alone (Captain Bob, 2026-09-19) + +**Captain Bob, 2026-09-19:** "Separate word for Hera's suicide, leave BYE alone." + +### XXIV.1 — What this buys, beyond settling the question + +`mama_word_bye()` (`mama_forth_words.c:2265-2271`) keeps its current behaviour exactly: +`capsule_vm_kill_all_nonmama()` then `arch_cold_reset()` — reap children, cold-restart the +machine. That is the right thing for an operator typing `BYE` at Hera's REPL (§XVI.2 flagged +this as the argument for two words), and it stays untouched. + +**The larger consequence: this reshuffle now modifies the behaviour of zero live registered +words.** §XVI.2 flagged Hera's `BYE` as the one place the design proposed changing one, and +noted that `.claude/CLAUDE.md`'s hard rule — "Never modify a registered, tested word to 'fix' +it" — did not strictly apply to a *ruled* change but that the change should be made knowingly. +It is now not made at all. Every word this design touches is either new or unchanged. + +### XXIV.2 — The two words differ only in their terminal action + +They share their first half. Per §XVI.1 and §XXIII.4 everything already exists: + +| | `BYE` (unchanged) | the suicide word (new) | +|---|---|---| +| Reap remaining children | `capsule_vm_kill_all_nonmama()` | same | +| Terminal action | `arch_cold_reset()` — reboot | `arch_disable_interrupts()` + `for(;;) arch_halt();` — stop | +| Registered on | Hera only | Hera only | + +**The permanent-halt idiom is not new either** — it is the pattern amd64's own +`arch_cold_reset()` already uses as its unreachable fallback (`for (;;) __asm__ volatile +("cli; hlt");`, `arch.c:218`) and the same shape the kernel panic path uses. `arch_halt()` is +declared at `arch.h:64` and implemented on all three architectures (`amd64:207`, +`aarch64:126`, `riscv64:170`), so three-arch parity holds with no per-arch work. + +**Registration:** Hera-only, the same way `mama_word_bye` is registered only in +`register_mama_forth_words()` and never by `register_child_vm_words()`. A child VM must not +have it — §IX.1's no-handoff rule means no other VM may stop the machine on Hera's behalf. + +### XXIV.3 — Naming: all candidates are free; `SCUTTLE` recommended, not ruled + +Checked 2026-09-19 — `HALT`, `SCUTTLE`, `SINK`, `DIE`, `EXPIRE`, `SUICIDE` and `GO-DOWN` are +**all unregistered**; none collides with an existing word. + +**Recommendation: `SCUTTLE`.** To scuttle is to deliberately sink the vessel you command — +which is exactly what this word does, performed by the one VM with the standing to do it. It +also rhymes with the imagery already in the design without colliding with it: Hermes *sinks* +(§VIII.1, a thing that happens to it), Hera *scuttles* (a thing she does). + +**`HALT` is the obvious alternative and the one caution worth stating:** it reads naturally and +matches `arch_halt()`, but `vm->halted` already exists and means something quite different — a +single VM stopping, not the machine. Reusing the stem invites exactly the ambiguity §XIX +renamed a Tripod leg to avoid. + +**Captain Bob's call; this section does not decide it.** + +### XXIV.4 — Where its ACL pin goes: the project's own docs give three different answers + +The new word is kernel-only and privileged, exactly like `BIRTH` — so it needs the same ACL +treatment, and **traced 2026-09-19, there is no single agreed answer in this repo:** + +1. **`.claude/CLAUDE.md`'s hard rule:** "ACL policy belongs in `ACL.4th`, never in C. **No + policy logic in `kernel_main.c`, no `vm_find_word` + field assignment for pinning.**" +2. **`.claude/CLAUDE.md`, later:** "`' BIRTH` in shared capsules breaks the hosted build — + BIRTH is kernel-only. **Pin it in a kernel-specific capsule**, not in `ACL.4th`." +3. **`capsules/ACL.4th`'s own comment (block 4005):** "BIRTH/CAPSULE-BIRTH are omitted: + kernel-only, not in hosted VM. **Pinned in C (`kernel_main.c`) after capsule load** instead, + so this file stays host-portable." + +**The live code does (3), and (3) is what (1) forbids.** `kernel_main.c:771-782` is literally +`vm_find_word(mama_vm_ptr, "BIRTH", 5)` followed by `birth->acl_mode = ACL_MODE_STRICT; +birth->acl_pinned = 1;` — a `vm_find_word` + field assignment for pinning, in `kernel_main.c`, +printing "ACL: BIRTH pinned STRICT". It works and it is deliberate; it simply contradicts the +stated rule. + +**Recommendation: follow the live precedent — pin the suicide word in `kernel_main.c` beside +`BIRTH` and `CAPSULE-BIRTH`** — on the grounds that matching working code beats matching a rule +the working code already breaks, and that a lone exception is worse than a consistent one. +`BYE`'s own pin stays where it is, in `ACL.4th:70` (`['] BYE ACL-STRICT ['] BYE ACL-PIN`), +which is correct because `BYE` is not kernel-only. + +**Reported, not fixed** (Captain Bob's Law): `.claude/CLAUDE.md` carries two statements that +disagree with each other and with the code. **Added as punch item 20** — a documentation +reconciliation, outside this reshuffle, and not something to resolve by quietly editing one of +the three. + +### XXIV.5 — Punch list + +- ✅ **Item 17 — SETTLED** (§XXIV): separate word, `BYE` untouched. Reshuffle now changes zero + live registered words. +- ⬜ **Item 18** (§XVI.7) — the empty-floor halt when Hera is already gone. **The last + undecided item in this document.** +- ⬜ **Item 20, NEW** (§XXIV.4) — reconcile the three-way ACL-pinning contradiction between + `.claude/CLAUDE.md` (twice) and `ACL.4th`/`kernel_main.c`. Documentation, not code; outside + this reshuffle. +- Build sequencing otherwise unchanged (§XXIII.6), with the surgical strip still item 1.