FABRIC-3.md §XXXV.13. Quit the running amd64 campaign directly on request once §XXXV.12's build unblocked live testing -- first live check found the ISA-tagging mechanism completely non-functional, in two independent ways, both only caught by checking an actual printed value rather than "it resolves without error." Bug 1: per-isa-doe.4th's strategy of redefining MU-EMIT-TRIAL-MARKER never worked, structurally, from the moment it was written. This FORTH compiles a colon definition's word calls to a direct, early-bound reference at compile time -- MU-RUN-TRIAL's call to MU-EMIT-TRIAL-MARKER bound when multiuser-doe.4th loaded, before per-isa-doe.4th's later redefinition of the same name ever existed. Every trial the running campaign persisted had an empty isa tag, not "amd64". Fixed by moving ISA-tag storage (MU-ISA-TAG-BUF/LEN/!) and the one true MU-EMIT-TRIAL-MARKER into multiuser-doe.4th itself, reading a shared variable at run time instead. per-isa-doe.4th shrank from 3 blocks to 2 (Block 5118 freed) -- fixing this recovered namespace, didn't cost any. Bug 2: found immediately while verifying the fix. MU-ISA-TAG!'s CMOVE call was copied from the original PER-ISA-TAG! it replaced, which had its own latent stack-order bug -- passed the ISA string's length as the copy source address instead of the real address, silently copying blank/garbage bytes with no error. Never caught before because §XXXV.8's own verification only checked that the entry words resolved, not that the tag they set was actually correct. Fixed the stack order; the old buggy word no longer exists anywhere (removed with Bug 1's fix, not patched in place). Verified live, together, one boot: MU-ISA-TAG-BUF readback -> "amd64" (was blank), full MU-EMIT-TRIAL-MARKER with all 6 fields set manually -> exact match on every field, VM-ERROR? -> 0, DOE-RESUME-COUNT correctly isolates by ISA (amd64->1, riscv64->0 in the same ring). Clean BYE, zero leaked processes, synthetic test write reverted before committing. Preserved logs/CSVs from the killed campaign and both verification boots per this repo's own convention -- never delete these. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BWpNjdwPtFLuVLaAq44L9K
LithosAnanke v2.0.1
UEFI-bootable FORTH microkernel. Boots from firmware, initialises memory and interrupts, then runs the StarForth VM as its sole userspace runtime. No libc. No OS. Just stone and necessity.
Lithos (foundation) + Ananke (necessity) — the kernel under StarshipOS.
Status — M7.1 (Capsule System · Multi-VM Fleet)
| Milestone | Status | |
|---|---|---|
| M0–M6 | UEFI boot · PMM · VMM · IDT · APIC · heap · framebuffer VT100 console (v1.5.1-FINAL) | ✅ Complete |
| M7 | StarForth VM integration + parity validation | ✅ Complete |
| M7.1 | Capsule birth protocol · Mama FORTH vocabulary · Tripod multi-VM fleet (Hermes/Artemis) · Word-level ACL (Phases 1–7) | 🔄 In Progress |
| M8 | REPL — keyboard input, interactive Forth | Planned |
| M9 | Block storage — AHCI driver | Planned |
POST at boot: parity hash verified across amd64/aarch64/riscv64 · Mama capsule dictionary: 453 words
What's live in M7.1
- Tripod — a named multi-VM fleet (Hera the Mama VM, Artemis, two Hermes instances) births, runs, and re-births independently, verified booting live pre-REPL on all three architectures.
- Hermes — a 17-block inter-VM messaging/channel layer between fleet members, with async delivery and channel negotiation.
- Artemis — a Block Allocation Map (BAM) storage subsystem with Q48.16
block-heat tracking and cooldown/reclamation (
ART-COOL/ART-REAP). - Word-level ACL — every dictionary entry carries a TTL/allow/mode/pin
access-control record. Strict, TTL, and pinned modes; two console layers
(emergency
ok>and superuserzuse)ok>). Phases 1–7 complete (C infrastructure, FORTH policy layer,zusebootstrap superuser, Isabelle proof stubs, kernel parity); Phase 8 (Ed25519 PKI / thumbdrive challenge-response) is the only item remaining. Measured overhead once active on every check: +0.0054%–+0.0088%, CV = 0.000%, across a 3×3 Latin-square DoE campaign (architecture × seed × 30 replicates) — three orders of magnitude below the measurement floor. - VM Fleet Attractor physics — the L8 Jacquard mode selector now has a real per-VM heat channel into fleet-wide tuning, replacing hardcoded compudynamics constants with a dynamically-inferred rate.
- Kconfig build configuration — every physics/heartbeat/pipelining/ kernel-only tuning knob (~40 total) is now a discoverable, optional Kconfig symbol shared with the hosted VM build. See Quick Start below.
Quick Start
# Build kernel (requires cross-compilation toolchain, or native gcc)
make -f Makefile.starkernel ARCH=amd64
# Run in QEMU with OVMF
make -f Makefile.starkernel qemu
# Other architectures
make -f Makefile.starkernel ARCH=aarch64 qemu
make -f Makefile.starkernel ARCH=riscv64 qemu
Artifacts: build/amd64/kernel/starkernel_loader.efi · build/amd64/kernel/starkernel_kernel.elf
For the hosted VM by itself (Linux, no cross-compiler needed, no bare-metal tooling): see
the separate StarForth repository — LithosAnanke used to be a branch inside that repo,
now it's its own project with its own master.
Build configuration (optional)
Every kernel-only knob (STARFORTH_ENABLE_VM, PARITY_MODE, the shared
physics/heartbeat family, etc.) is an optional Kconfig symbol — a plain
make -f Makefile.starkernel uses the same defaults it always has unless
you opt in:
make -f Makefile.starkernel ARCH=amd64 menuconfig
make -f Makefile.starkernel ARCH=amd64 kernel_amd64_defconfig
Documentation
| System Architecture | Full kernel + VM design |
| HAL Reference | Hardware abstraction layer interfaces |
| Capsule System — M7.1 | Capsule birth protocol design |
| VM Fleet Attractor design log | Tripod/Hermes/Artemis physics + build-system history |
| Getting Started / Kconfig reference | Full symbol reference for both build targets |
| Changelog | Milestone-level history |
| Roadmap | Milestone plan through self-hosting |
License
Starship License 1.0 (SL-1.0) — free for personal, research, and educational use. Commercial use requires a separate agreement. Attribution to R.A. James (Captain Bob) must be preserved in all distributions.
Patent pending. USPTO provisional filed December 2025 — physics-grounded self-adaptive runtime system. This license does not grant patent rights. Licensing inquiries: rajames440@gmail.com
Robert A. James (Captain Bob) · Systems Engineer · Hacking since 1973