Claude 3843e1d685 FABRIC-3.5.md §XXXIX: item 39 settled -- the accountings are not coupled, and §XXXIV.6 watched the wrong one
Traced both directions. capsule_vm_physics.c has zero references to
stadium and does not include its header; it has zero references to
reservoir. stadium.c's single vm_physics mention is a comment.
vm_physics_fleet_heat_sum() sums execution_heat_q48, whose only writers
are initialise, transfer between two VMs, and redistribute on death.
Message allocation cannot move it.

They are not even the same shape of invariant. StadiumVMQuota.reservoir's
own comment states Stadium conservation is per-VM -- resident patron heat
plus that VM's reservoir equals Q48_ONE each -- while vm-physics K is
fleet-wide across all VMs. Two scopes, two disjoint data sets, sharing
only the Q48.16 format, the constant, and the word heat. That shared
vocabulary is what made them look like one system.

Only one has a checker. vm_physics_conserved() is the sole *_conserved()
function in the kernel; the Stadium side has a documented invariant, a
human-readable diagnostic print, and MSG-K covering just the messaging
slice. So §XXXVIII's leak is invisible to every automated check -- not
because checks disagree, but because nothing is looking.

Corrects §XXXIV.6 in the dangerous direction: it made fleet_conserved the
tripwire for Stage B, but a kernel-Hermes allocator leaking every
reservation would leave it reporting a serene 1. That is §XXXV.0's
signature exactly, built into the plan, and item 39 existed to catch it
before it mattered. Stage B instead verifies kernel-Hermes's own ledger
and the Stadium per-VM invariant, and should add the missing
stadium_conserved() as its first act.

Two earlier rulings need consequent care. §XV.4's K must be qualified,
since the heat a dying arbiter holds is Stadium heat rather than the
verified fleet K -- substance stands, citation was wrong. And the
self-audit is promoted from safety net to sole instrument, which argues
for an independent Stadium checker rather than the arbiter policing
itself alone.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
2026-09-19 11:49:51 +00:00
2026-08-25 20:41:50 -04:00
2026-08-01 07:49:56 -04:00
2026-08-02 05:11:24 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-09-01 12:07:32 -04:00
2026-08-02 05:11:24 -04:00

LithosAnanke v2.0.1

UEFI-bootable FORTH microkernel. Boots from firmware, initialises memory and interrupts, then runs the StarForth VM as its sole userspace runtime. No libc. No OS. Just stone and necessity.

Lithos (foundation) + Ananke (necessity) — the kernel under StarshipOS.


Status — M7.1 (Capsule System · Multi-VM Fleet)

Milestone Status
M0–M6 UEFI boot · PMM · VMM · IDT · APIC · heap · framebuffer VT100 console (v1.5.1-FINAL) ✅ Complete
M7 StarForth VM integration + parity validation ✅ Complete
M7.1 Capsule birth protocol · Mama FORTH vocabulary · Tripod multi-VM fleet (Hermes/Artemis) · Word-level ACL (Phases 1–7) 🔄 In Progress
M8 REPL — keyboard input, interactive Forth Planned
M9 Block storage — AHCI driver Planned

POST at boot: parity hash verified across amd64/aarch64/riscv64 · Mama capsule dictionary: 453 words

What's live in M7.1

  • Tripod — a named multi-VM fleet (Hera the Mama VM, Artemis, two Hermes instances) births, runs, and re-births independently, verified booting live pre-REPL on all three architectures.
  • Hermes — a 17-block inter-VM messaging/channel layer between fleet members, with async delivery and channel negotiation.
  • Artemis — a Block Allocation Map (BAM) storage subsystem with Q48.16 block-heat tracking and cooldown/reclamation (ART-COOL/ART-REAP).
  • Word-level ACL — every dictionary entry carries a TTL/allow/mode/pin access-control record. Strict, TTL, and pinned modes; two console layers (emergency ok> and superuser zuse)ok>). Phases 1–7 complete (C infrastructure, FORTH policy layer, zuse bootstrap superuser, Isabelle proof stubs, kernel parity); Phase 8 (Ed25519 PKI / thumbdrive challenge-response) is the only item remaining. Measured overhead once active on every check: +0.0054%–+0.0088%, CV = 0.000%, across a 3×3 Latin-square DoE campaign (architecture × seed × 30 replicates) — three orders of magnitude below the measurement floor.
  • VM Fleet Attractor physics — the L8 Jacquard mode selector now has a real per-VM heat channel into fleet-wide tuning, replacing hardcoded compudynamics constants with a dynamically-inferred rate.
  • Kconfig build configuration — every physics/heartbeat/pipelining/ kernel-only tuning knob (~40 total) is now a discoverable, optional Kconfig symbol shared with the hosted VM build. See Quick Start below.

Quick Start

# Build kernel (requires cross-compilation toolchain, or native gcc)
make -f Makefile.starkernel ARCH=amd64

# Run in QEMU with OVMF
make -f Makefile.starkernel qemu

# Other architectures
make -f Makefile.starkernel ARCH=aarch64 qemu
make -f Makefile.starkernel ARCH=riscv64 qemu

Artifacts: build/amd64/kernel/starkernel_loader.efi · build/amd64/kernel/starkernel_kernel.elf

For the hosted VM by itself (Linux, no cross-compiler needed, no bare-metal tooling): see the separate StarForth repository — LithosAnanke used to be a branch inside that repo, now it's its own project with its own master.

Build configuration (optional)

Every kernel-only knob (STARFORTH_ENABLE_VM, PARITY_MODE, the shared physics/heartbeat family, etc.) is an optional Kconfig symbol — a plain make -f Makefile.starkernel uses the same defaults it always has unless you opt in:

make -f Makefile.starkernel ARCH=amd64 menuconfig
make -f Makefile.starkernel ARCH=amd64 kernel_amd64_defconfig

Documentation

System Architecture Full kernel + VM design
HAL Reference Hardware abstraction layer interfaces
Capsule System — M7.1 Capsule birth protocol design
VM Fleet Attractor design log Tripod/Hermes/Artemis physics + build-system history
Getting Started / Kconfig reference Full symbol reference for both build targets
Changelog Milestone-level history
Roadmap Milestone plan through self-hosting

License

Starship License 1.0 (SL-1.0) — free for personal, research, and educational use. Commercial use requires a separate agreement. Attribution to R.A. James (Captain Bob) must be preserved in all distributions.

Patent pending. USPTO provisional filed December 2025 — physics-grounded self-adaptive runtime system. This license does not grant patent rights. Licensing inquiries: rajames440@gmail.com


Robert A. James (Captain Bob) · Systems Engineer · Hacking since 1973

S
Description
No description provided
Readme
6.8 GiB
Languages
C 72.2%
Isabelle 10.4%
TeX 5%
Shell 3.4%
R 2.7%
Other 6.3%