FABRIC-3.5.md §XXIV: item 17 settled -- separate word for Hera's suicide, BYE untouched

Captain Bob, 2026-09-19. mama_word_bye() keeps its current behaviour
exactly -- reap children, cold-restart -- which is the right thing for an
operator typing BYE at Hera's REPL, the argument §XVI.2 flagged for two
words.

The larger consequence is that this reshuffle now modifies the behaviour
of zero live registered words. §XVI.2 had flagged Hera's BYE as the one
place the design proposed changing one; it is now not changed at all.

The two words share their first half and differ only in the terminal
action: cold reset versus a permanent arch_halt() loop behind disabled
interrupts. That idiom is not new either -- it is what amd64's own
arch_cold_reset() already uses as its unreachable fallback and what the
panic path uses, and arch_halt() exists on all three architectures, so
parity holds with no per-arch work. Hera-only registration, since §IX.1's
no-handoff rule means no other VM may stop the machine on her behalf.

All seven candidate names are unregistered. Recommends SCUTTLE without
deciding it -- to scuttle is to deliberately sink the vessel you command,
and it separates cleanly from Hermes sinking. Cautions against HALT,
since vm->halted already means something different and reusing the stem
invites the ambiguity §XIX renamed a Tripod leg to avoid.

Records a three-way contradiction found while placing the new word's ACL
pin. CLAUDE.md's hard rule forbids policy in C and specifically forbids
vm_find_word plus field assignment for pinning in kernel_main.c; CLAUDE.md
later says to pin kernel-only words in a kernel-specific capsule; and
ACL.4th's own block-4005 comment says they are pinned in kernel_main.c so
that file stays host-portable. The live code does the third:
kernel_main.c:771-782 is exactly the forbidden construct, deliberate and
working. Recommends matching the working code rather than the rule the
working code already breaks, and files the reconciliation as item 20 --
reported, not fixed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
This commit is contained in:
Claude
2026-09-19 10:41:48 +00:00
parent d0c4f60194
commit e0152381ea
+99 -2
View File
@@ -617,8 +617,8 @@ build-time check.**
counting semaphore. **This was the last open design question.**
- **Item 16 (§XV.4)** — an implementation check rather than a decision: every message-holding
teardown path must reach `STADIUM-EVICT`, verifiable via `fleet_conserved`.
- **Item 17 (§XVI.2)** — does Hera's suicide replace `BYE`'s current cold-restart, or become a
separate word? Small, but it changes a live registered word either way.
- ~~**Item 17**~~ — **SETTLED 2026-09-19 by §XXIV**: a separate word; `BYE` left alone. The
reshuffle therefore changes zero live registered words.
- **Item 18 (§XVI.7)** — if Hera is already dead, nobody performs the halt. Proposed shape (an
empty floor as a kernel-observable condition) is **analysis, not a ruling.**
@@ -2207,3 +2207,100 @@ and three small local decisions:
**Items 8 and 9 are the only two carrying an unmade decision**; the rest are execution. Nothing
on this list is authorized by this document — per Captain Bob's Law, no code without an
explicit instruction.
---
## XXIV. Item 17 SETTLED: Hera's suicide is a separate word; `BYE` is left alone (Captain Bob, 2026-09-19)
**Captain Bob, 2026-09-19:** "Separate word for Hera's suicide, leave BYE alone."
### XXIV.1 — What this buys, beyond settling the question
`mama_word_bye()` (`mama_forth_words.c:2265-2271`) keeps its current behaviour exactly:
`capsule_vm_kill_all_nonmama()` then `arch_cold_reset()` — reap children, cold-restart the
machine. That is the right thing for an operator typing `BYE` at Hera's REPL (§XVI.2 flagged
this as the argument for two words), and it stays untouched.
**The larger consequence: this reshuffle now modifies the behaviour of zero live registered
words.** §XVI.2 flagged Hera's `BYE` as the one place the design proposed changing one, and
noted that `.claude/CLAUDE.md`'s hard rule — "Never modify a registered, tested word to 'fix'
it" — did not strictly apply to a *ruled* change but that the change should be made knowingly.
It is now not made at all. Every word this design touches is either new or unchanged.
### XXIV.2 — The two words differ only in their terminal action
They share their first half. Per §XVI.1 and §XXIII.4 everything already exists:
| | `BYE` (unchanged) | the suicide word (new) |
|---|---|---|
| Reap remaining children | `capsule_vm_kill_all_nonmama()` | same |
| Terminal action | `arch_cold_reset()` — reboot | `arch_disable_interrupts()` + `for(;;) arch_halt();` — stop |
| Registered on | Hera only | Hera only |
**The permanent-halt idiom is not new either** — it is the pattern amd64's own
`arch_cold_reset()` already uses as its unreachable fallback (`for (;;) __asm__ volatile
("cli; hlt");`, `arch.c:218`) and the same shape the kernel panic path uses. `arch_halt()` is
declared at `arch.h:64` and implemented on all three architectures (`amd64:207`,
`aarch64:126`, `riscv64:170`), so three-arch parity holds with no per-arch work.
**Registration:** Hera-only, the same way `mama_word_bye` is registered only in
`register_mama_forth_words()` and never by `register_child_vm_words()`. A child VM must not
have it — §IX.1's no-handoff rule means no other VM may stop the machine on Hera's behalf.
### XXIV.3 — Naming: all candidates are free; `SCUTTLE` recommended, not ruled
Checked 2026-09-19 — `HALT`, `SCUTTLE`, `SINK`, `DIE`, `EXPIRE`, `SUICIDE` and `GO-DOWN` are
**all unregistered**; none collides with an existing word.
**Recommendation: `SCUTTLE`.** To scuttle is to deliberately sink the vessel you command —
which is exactly what this word does, performed by the one VM with the standing to do it. It
also rhymes with the imagery already in the design without colliding with it: Hermes *sinks*
(§VIII.1, a thing that happens to it), Hera *scuttles* (a thing she does).
**`HALT` is the obvious alternative and the one caution worth stating:** it reads naturally and
matches `arch_halt()`, but `vm->halted` already exists and means something quite different — a
single VM stopping, not the machine. Reusing the stem invites exactly the ambiguity §XIX
renamed a Tripod leg to avoid.
**Captain Bob's call; this section does not decide it.**
### XXIV.4 — Where its ACL pin goes: the project's own docs give three different answers
The new word is kernel-only and privileged, exactly like `BIRTH` — so it needs the same ACL
treatment, and **traced 2026-09-19, there is no single agreed answer in this repo:**
1. **`.claude/CLAUDE.md`'s hard rule:** "ACL policy belongs in `ACL.4th`, never in C. **No
policy logic in `kernel_main.c`, no `vm_find_word` + field assignment for pinning.**"
2. **`.claude/CLAUDE.md`, later:** "`' BIRTH` in shared capsules breaks the hosted build —
BIRTH is kernel-only. **Pin it in a kernel-specific capsule**, not in `ACL.4th`."
3. **`capsules/ACL.4th`'s own comment (block 4005):** "BIRTH/CAPSULE-BIRTH are omitted:
kernel-only, not in hosted VM. **Pinned in C (`kernel_main.c`) after capsule load** instead,
so this file stays host-portable."
**The live code does (3), and (3) is what (1) forbids.** `kernel_main.c:771-782` is literally
`vm_find_word(mama_vm_ptr, "BIRTH", 5)` followed by `birth->acl_mode = ACL_MODE_STRICT;
birth->acl_pinned = 1;` — a `vm_find_word` + field assignment for pinning, in `kernel_main.c`,
printing "ACL: BIRTH pinned STRICT". It works and it is deliberate; it simply contradicts the
stated rule.
**Recommendation: follow the live precedent — pin the suicide word in `kernel_main.c` beside
`BIRTH` and `CAPSULE-BIRTH`** — on the grounds that matching working code beats matching a rule
the working code already breaks, and that a lone exception is worse than a consistent one.
`BYE`'s own pin stays where it is, in `ACL.4th:70` (`['] BYE ACL-STRICT ['] BYE ACL-PIN`),
which is correct because `BYE` is not kernel-only.
**Reported, not fixed** (Captain Bob's Law): `.claude/CLAUDE.md` carries two statements that
disagree with each other and with the code. **Added as punch item 20** — a documentation
reconciliation, outside this reshuffle, and not something to resolve by quietly editing one of
the three.
### XXIV.5 — Punch list
- ✅ **Item 17 — SETTLED** (§XXIV): separate word, `BYE` untouched. Reshuffle now changes zero
live registered words.
- ⬜ **Item 18** (§XVI.7) — the empty-floor halt when Hera is already gone. **The last
undecided item in this document.**
- ⬜ **Item 20, NEW** (§XXIV.4) — reconcile the three-way ACL-pinning contradiction between
`.claude/CLAUDE.md` (twice) and `ACL.4th`/`kernel_main.c`. Documentation, not code; outside
this reshuffle.
- Build sequencing otherwise unchanged (§XXIII.6), with the surgical strip still item 1.