FABRIC-3.5.md §XXIV: item 17 settled -- separate word for Hera's suicide, BYE untouched
Captain Bob, 2026-09-19. mama_word_bye() keeps its current behaviour exactly -- reap children, cold-restart -- which is the right thing for an operator typing BYE at Hera's REPL, the argument §XVI.2 flagged for two words. The larger consequence is that this reshuffle now modifies the behaviour of zero live registered words. §XVI.2 had flagged Hera's BYE as the one place the design proposed changing one; it is now not changed at all. The two words share their first half and differ only in the terminal action: cold reset versus a permanent arch_halt() loop behind disabled interrupts. That idiom is not new either -- it is what amd64's own arch_cold_reset() already uses as its unreachable fallback and what the panic path uses, and arch_halt() exists on all three architectures, so parity holds with no per-arch work. Hera-only registration, since §IX.1's no-handoff rule means no other VM may stop the machine on her behalf. All seven candidate names are unregistered. Recommends SCUTTLE without deciding it -- to scuttle is to deliberately sink the vessel you command, and it separates cleanly from Hermes sinking. Cautions against HALT, since vm->halted already means something different and reusing the stem invites the ambiguity §XIX renamed a Tripod leg to avoid. Records a three-way contradiction found while placing the new word's ACL pin. CLAUDE.md's hard rule forbids policy in C and specifically forbids vm_find_word plus field assignment for pinning in kernel_main.c; CLAUDE.md later says to pin kernel-only words in a kernel-specific capsule; and ACL.4th's own block-4005 comment says they are pinned in kernel_main.c so that file stays host-portable. The live code does the third: kernel_main.c:771-782 is exactly the forbidden construct, deliberate and working. Recommends matching the working code rather than the rule the working code already breaks, and files the reconciliation as item 20 -- reported, not fixed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
This commit is contained in:
+99
-2
@@ -617,8 +617,8 @@ build-time check.**
|
||||
counting semaphore. **This was the last open design question.**
|
||||
- **Item 16 (§XV.4)** — an implementation check rather than a decision: every message-holding
|
||||
teardown path must reach `STADIUM-EVICT`, verifiable via `fleet_conserved`.
|
||||
- **Item 17 (§XVI.2)** — does Hera's suicide replace `BYE`'s current cold-restart, or become a
|
||||
separate word? Small, but it changes a live registered word either way.
|
||||
- ~~**Item 17**~~ — **SETTLED 2026-09-19 by §XXIV**: a separate word; `BYE` left alone. The
|
||||
reshuffle therefore changes zero live registered words.
|
||||
- **Item 18 (§XVI.7)** — if Hera is already dead, nobody performs the halt. Proposed shape (an
|
||||
empty floor as a kernel-observable condition) is **analysis, not a ruling.**
|
||||
|
||||
@@ -2207,3 +2207,100 @@ and three small local decisions:
|
||||
**Items 8 and 9 are the only two carrying an unmade decision**; the rest are execution. Nothing
|
||||
on this list is authorized by this document — per Captain Bob's Law, no code without an
|
||||
explicit instruction.
|
||||
|
||||
---
|
||||
|
||||
## XXIV. Item 17 SETTLED: Hera's suicide is a separate word; `BYE` is left alone (Captain Bob, 2026-09-19)
|
||||
|
||||
**Captain Bob, 2026-09-19:** "Separate word for Hera's suicide, leave BYE alone."
|
||||
|
||||
### XXIV.1 — What this buys, beyond settling the question
|
||||
|
||||
`mama_word_bye()` (`mama_forth_words.c:2265-2271`) keeps its current behaviour exactly:
|
||||
`capsule_vm_kill_all_nonmama()` then `arch_cold_reset()` — reap children, cold-restart the
|
||||
machine. That is the right thing for an operator typing `BYE` at Hera's REPL (§XVI.2 flagged
|
||||
this as the argument for two words), and it stays untouched.
|
||||
|
||||
**The larger consequence: this reshuffle now modifies the behaviour of zero live registered
|
||||
words.** §XVI.2 flagged Hera's `BYE` as the one place the design proposed changing one, and
|
||||
noted that `.claude/CLAUDE.md`'s hard rule — "Never modify a registered, tested word to 'fix'
|
||||
it" — did not strictly apply to a *ruled* change but that the change should be made knowingly.
|
||||
It is now not made at all. Every word this design touches is either new or unchanged.
|
||||
|
||||
### XXIV.2 — The two words differ only in their terminal action
|
||||
|
||||
They share their first half. Per §XVI.1 and §XXIII.4 everything already exists:
|
||||
|
||||
| | `BYE` (unchanged) | the suicide word (new) |
|
||||
|---|---|---|
|
||||
| Reap remaining children | `capsule_vm_kill_all_nonmama()` | same |
|
||||
| Terminal action | `arch_cold_reset()` — reboot | `arch_disable_interrupts()` + `for(;;) arch_halt();` — stop |
|
||||
| Registered on | Hera only | Hera only |
|
||||
|
||||
**The permanent-halt idiom is not new either** — it is the pattern amd64's own
|
||||
`arch_cold_reset()` already uses as its unreachable fallback (`for (;;) __asm__ volatile
|
||||
("cli; hlt");`, `arch.c:218`) and the same shape the kernel panic path uses. `arch_halt()` is
|
||||
declared at `arch.h:64` and implemented on all three architectures (`amd64:207`,
|
||||
`aarch64:126`, `riscv64:170`), so three-arch parity holds with no per-arch work.
|
||||
|
||||
**Registration:** Hera-only, the same way `mama_word_bye` is registered only in
|
||||
`register_mama_forth_words()` and never by `register_child_vm_words()`. A child VM must not
|
||||
have it — §IX.1's no-handoff rule means no other VM may stop the machine on Hera's behalf.
|
||||
|
||||
### XXIV.3 — Naming: all candidates are free; `SCUTTLE` recommended, not ruled
|
||||
|
||||
Checked 2026-09-19 — `HALT`, `SCUTTLE`, `SINK`, `DIE`, `EXPIRE`, `SUICIDE` and `GO-DOWN` are
|
||||
**all unregistered**; none collides with an existing word.
|
||||
|
||||
**Recommendation: `SCUTTLE`.** To scuttle is to deliberately sink the vessel you command —
|
||||
which is exactly what this word does, performed by the one VM with the standing to do it. It
|
||||
also rhymes with the imagery already in the design without colliding with it: Hermes *sinks*
|
||||
(§VIII.1, a thing that happens to it), Hera *scuttles* (a thing she does).
|
||||
|
||||
**`HALT` is the obvious alternative and the one caution worth stating:** it reads naturally and
|
||||
matches `arch_halt()`, but `vm->halted` already exists and means something quite different — a
|
||||
single VM stopping, not the machine. Reusing the stem invites exactly the ambiguity §XIX
|
||||
renamed a Tripod leg to avoid.
|
||||
|
||||
**Captain Bob's call; this section does not decide it.**
|
||||
|
||||
### XXIV.4 — Where its ACL pin goes: the project's own docs give three different answers
|
||||
|
||||
The new word is kernel-only and privileged, exactly like `BIRTH` — so it needs the same ACL
|
||||
treatment, and **traced 2026-09-19, there is no single agreed answer in this repo:**
|
||||
|
||||
1. **`.claude/CLAUDE.md`'s hard rule:** "ACL policy belongs in `ACL.4th`, never in C. **No
|
||||
policy logic in `kernel_main.c`, no `vm_find_word` + field assignment for pinning.**"
|
||||
2. **`.claude/CLAUDE.md`, later:** "`' BIRTH` in shared capsules breaks the hosted build —
|
||||
BIRTH is kernel-only. **Pin it in a kernel-specific capsule**, not in `ACL.4th`."
|
||||
3. **`capsules/ACL.4th`'s own comment (block 4005):** "BIRTH/CAPSULE-BIRTH are omitted:
|
||||
kernel-only, not in hosted VM. **Pinned in C (`kernel_main.c`) after capsule load** instead,
|
||||
so this file stays host-portable."
|
||||
|
||||
**The live code does (3), and (3) is what (1) forbids.** `kernel_main.c:771-782` is literally
|
||||
`vm_find_word(mama_vm_ptr, "BIRTH", 5)` followed by `birth->acl_mode = ACL_MODE_STRICT;
|
||||
birth->acl_pinned = 1;` — a `vm_find_word` + field assignment for pinning, in `kernel_main.c`,
|
||||
printing "ACL: BIRTH pinned STRICT". It works and it is deliberate; it simply contradicts the
|
||||
stated rule.
|
||||
|
||||
**Recommendation: follow the live precedent — pin the suicide word in `kernel_main.c` beside
|
||||
`BIRTH` and `CAPSULE-BIRTH`** — on the grounds that matching working code beats matching a rule
|
||||
the working code already breaks, and that a lone exception is worse than a consistent one.
|
||||
`BYE`'s own pin stays where it is, in `ACL.4th:70` (`['] BYE ACL-STRICT ['] BYE ACL-PIN`),
|
||||
which is correct because `BYE` is not kernel-only.
|
||||
|
||||
**Reported, not fixed** (Captain Bob's Law): `.claude/CLAUDE.md` carries two statements that
|
||||
disagree with each other and with the code. **Added as punch item 20** — a documentation
|
||||
reconciliation, outside this reshuffle, and not something to resolve by quietly editing one of
|
||||
the three.
|
||||
|
||||
### XXIV.5 — Punch list
|
||||
|
||||
- ✅ **Item 17 — SETTLED** (§XXIV): separate word, `BYE` untouched. Reshuffle now changes zero
|
||||
live registered words.
|
||||
- ⬜ **Item 18** (§XVI.7) — the empty-floor halt when Hera is already gone. **The last
|
||||
undecided item in this document.**
|
||||
- ⬜ **Item 20, NEW** (§XXIV.4) — reconcile the three-way ACL-pinning contradiction between
|
||||
`.claude/CLAUDE.md` (twice) and `ACL.4th`/`kernel_main.c`. Documentation, not code; outside
|
||||
this reshuffle.
|
||||
- Build sequencing otherwise unchanged (§XXIII.6), with the surgical strip still item 1.
|
||||
|
||||
Reference in New Issue
Block a user