Files
LithosAnanake/include
Robert Allan JamesandClaude Sonnet 5 26c1117ccd
Build / build-amd64-iso (push) Canceled after 0s
Build / build-aarch64-iso (push) Canceled after 0s
Build / build-riscv64-img (push) Canceled after 0s
Phase 8 v3: refuse a same-VM, cross-device raw block copy from within StarshipOS
Two research passes confirmed the identity record itself (seed/pubkey/
cert) is already unreachable from any FORTH primitive -- only C-level
read_devblock/write_devblock touch it. But a device's ordinary user block
content CAN be copied between two attached devices today, using only
stock, unpinned words: <src> BLOCK <dst> BUFFER 1024 MOVE UPDATE
SAVE-BUFFERS, or the dedicated RELOCATE-BLOCK word (whose own doc comment
already admits "performs no policy validation of its own"). Checked
whether the existing per-block owner_fp/BLK-ACL-ALLOW@ metadata already
solves this -- it doesn't: owner_fp encodes who (a VM identity pubkey),
never where (physical device), and blk_get_buffer()/blk_update() never
consult acl_allow/acl_ttl at all -- those fields are completely inert.

Small, targeted fix, no rearchitecture:

- blk_subsys_relocate_block() (block_subsystem.c): same-device check.
  Its own documented purpose is wear-leveling (relocate on the SAME
  device) -- never stated as cross-device, and nothing enforced that
  until now.
- New public blk_lbn_device_handle() (block_subsystem.c/.h): the missing
  LBN-to-device direction (blk_get_device_range() already goes the other
  way). Opaque, stable, == comparable.
- MOVE (memory_words.c) and CMOVE/CMOVE> (string_words.c): refuse when
  both addresses are block-window addresses backed by two different
  devices -- the exact shape of the composed attack. A copy where either
  end is ordinary VM memory (the overwhelming common case: staging text
  from PAD, editing a block in place) is untouched.
- blk_vm_check_epoch()/blk_vm_slot_for_addr() exposed (block_words.h) so
  the two new call sites share the same window-slot invalidation contract
  rather than a second, divergent copy of it.

Verified live on all three architectures, not just boot-clean: same-
device MOVE/RELOCATE-BLOCK still succeed exactly as before; cross-device
MOVE/CMOVE/RELOCATE-BLOCK all refused. Zero UNKNOWN WORD, identical
dict_hash across all three (this change adds no FORTH-visible word, only
internal refusal conditions, as predicted).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 04:44:22 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

include/

Public headers for the hosted StarForth VM (src/). Kernel-only headers live under include/starkernel/.

Core VM

  • vm.h — the VM struct and all core types (DictEntry, DictPhysics, stacks, dictionary state); the central header most other files include.
  • vm_api.h — external VM API surface.
  • vm_host.h, vm_debug.h, startup.h, version.h — host integration, debug utilities, startup sequencing, version string.
  • cli.h, repl.h, io.h, log.h — CLI parsing, REPL loop, I/O, logging.
  • word_registry.h — word registration system shared by every src/word_source/*.c file.
  • compudynamics.h — the generic compudynamics module: tuning-word/config lookups (cd_tuning_word(), cd_tuning_vm()) consumed by ssm_jacquard.c.

Memory / blocks

  • memory_management.h, dictionary_management.h — dictionary allocator and search.
  • block_subsystem.h, blkcfg.h, blkio.h, blkio_factory.h — logical→ physical block mapper and pluggable block I/O backends (file/RAM).
  • platform_alloc.h, platform_lock.h, platform_time.h — platform abstraction shims (hosted vs. kernel allocation/locking/timing).

Physics-driven adaptive runtime (7 feedback loops)

  • physics_runtime.h — main physics coordinator.
  • physics_hotwords_cache.h — Loop #1, execution-heat hot-words cache.
  • physics_metadata.h — per-word DictPhysics metadata tracking.
  • physics_pipelining_metrics.h — Loop #4, word-transition prediction.
  • physics_execution_hooks.h — execution instrumentation hook points.
  • rolling_window_of_truth.h, rolling_window_knobs.h — Loop #2 circular execution-history buffer and its tuning knobs.
  • inference_engine.h — Loops #5/#6, window-width and decay-slope statistical inference.
  • dictionary_heat_optimization.h — Loop #1 heat counters.
  • ssm_jacquard.h — L8 Jacquard steady-state mode selector.
  • doe_metrics.h — Design of Experiments (2^7 factorial) metrics.
  • profiler.h — performance profiling hooks.

Arithmetic / codegen

  • q48_16.h — Q48.16 deterministic fixed-point arithmetic (used instead of IEEE-754 float specifically to keep cross-architecture behavior bit-identical).
  • math_portable.h — portable math helpers.
  • arch_detect.h, starforth_config.h — architecture detection and the build-flag fallback-default layer (used when a .c file is compiled by hand without make).
  • vm_asm_opt.h, vm_asm_opt_arm64.h, vm_asm_opt_riscv64.h, vm_inner_interp_asm.h, vm_inner_interp_arm64.h, vm_inner_interp_riscv64.h — per-architecture assembler-optimized inner interpreter (USE_ASM_OPT=1).

See include/starkernel/README.md for the bare-metal kernel headers.