proof/FINDINGS.md's Isabelle/HOL word-source sweep (§1) found the two defects severe enough to actively corrupt the live Tripod multi-VM fleet: file-scope C statics standing in for state that belongs on struct VM. - vocabulary_words.c (highest severity in the sweep): forth_vocab/ context_vocab/current_vocab, context_var_addr/current_var_addr, the ctx_fc/forth_fc first-char search index, and the `initialized` guard were all process-wide statics. Only the first VM to touch any vocabulary word ever ran setup; every VM after that silently shared VM #1's dictionary-chain pointers and reused VM #1's byte-offset addresses as if valid in its own vm->memory. One VM's VOCABULARY/ DEFINITIONS/FORTH silently changed where every other VM looked up and defined words. - control_words.c: cf_stack/cf_sp/cf_last_mode (IF/THEN/BEGIN/DO/CASE compile-time nesting) and the LEAVE/ENDOF patch-site bookkeeping (leave_addrs/leave_sp/leave_mark_*, endof_addrs/endof_sp/endof_mark_*) were also process-wide statics. Two VMs compiling colon definitions at overlapping times would corrupt each other's nesting state. Both moved onto struct VM, following the existing hold_addr/hold_pos precedent in include/vm.h ("lives in each VM's own memory... so child VMs never alias Hera's buffer"): - New VocabularyState struct (vm->vocab): chain heads, VM-cell addresses, first-char index, initialized flag. - New ControlFlowState struct (vm->cf): cf_stack/cf_sp/cf_last_mode plus the LEAVE/ENDOF patch-site stacks. cf_tag_t/cf_item_t/CF_STACK_MAX moved from control_words.c into include/vm.h since they're now part of the struct VM field's type. - Sentinel fields (-1/-999, meaning "empty") explicitly initialized in both vm_init_with_host() implementations (hosted src/vm_bootstrap.c and kernel src/starkernel/vm/vm_bootstrap.c) alongside the existing dsp/rsp = -1 initialization, since the preceding zero-init leaves them at 0 rather than their empty sentinel. Every word function in both files already took VM *vm, so no call sites outside these two files needed to change; cf_push_item/cf_pop_item/ cf_peek_item gained a VM* parameter to reach vm->cf. Verified: hosted (amd64) and kernel (amd64, __STARKERNEL__) both build clean with -Wall -Werror after a full clean rebuild (struct VM's layout changed size, and this Makefile has no header-dependency tracking, so a stale incremental build would have linked mismatched object layouts). Hosted POST suite 1012/1012 passing (0 regressions). Manually exercised VOCABULARY/DEFINITIONS/FORTH/ORDER, and IF/ELSE, DO/LOOP/LEAVE, BEGIN/WHILE/REPEAT, and CASE/OF/ENDOF/ENDCASE (including nested DO with I/J) in the REPL -- all correct and unchanged from pre-refactor behavior. Note: a pre-existing CASE/ENDCASE default-clause bug (the code after the last OF...ENDOF pair does not correctly become the "default" value once DROP runs) was found while testing this refactor and confirmed present on unmodified master too -- not touched here, out of scope for this pass. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Qf6YcnHgaEtEygq3knx19
src/word_source/
FORTH-79 word implementations, one file per category, registered into the
dictionary via include/word_registry.h. Each .c file here has a
matching header in src/word_source/include/ and (for most categories) a
matching test module in src/test_runner/modules/.
FORTH-79 core
arithmetic_words.c,mixed_arithmetic_words.c—+ - * / MOD ABS MIN MAXand mixed-precision arithmetic.stack_words.c—DUP DROP SWAP ROT OVER NIP TUCK.control_words.c—IF ELSE THEN DO LOOP BEGIN UNTIL WHILE.defining_words.c—: ; CREATE DOES> VARIABLE CONSTANT.memory_words.c—@ ! C@ C! MOVE FILL.return_stack_words.c—>R R> R@ RDROP 2>R 2R@ 2R>.double_words.c—2DUP 2DROP 2SWAP 2@ 2! D+ D-.logical_words.c—AND OR XOR NOT INVERT LSHIFT RSHIFT.io_words.c—EMIT KEY TYPE CR TAB SPACE ACCEPT.string_words.c—S" SLITERALand other string operations.block_words.c—BLOCK BUFFER LOAD THRU FLUSH.format_words.c—.( .R .S HEX DECIMAL BASE.system_words.c—BYE ABORT INCLUDE STATE.dictionary_words.c—FIND SEARCH-WORDLIST WORDS.dictionary_manipulation_words.c— dictionary entry manipulation words.vocabulary_words.c—VOCABULARY DEFINITIONS FORTH-WORDLIST.editor_words.c— block editor words.defer_words.c—DEFER/ISdeferred-word mechanism, used by the Tripod message-dispatch shim (seetools/hermes_tripod_smoke.sh).
StarForth-specific extensions
q48_16_words.c,q48_words.c— Q48.16 fixed-point word bindings.starforth_words.c— StarForth-specific extensions.acl_words.c— word-level ACL system's FORTH-callable primitives (seedocs/03-architecture/word-acl/).lifecycle_words_hosted.c— hosted-build VM lifecycle words (birth/run primitives on the hosted side; kernel-only primitives live insrc/starkernel/capsule/mama_forth_words.c).log_words.c— FORTH-callable logging primitives.inference_words.c— FORTH-callable bindings for the statistical inference engine (Loops #5/#6).physics_benchmark_words.c— benchmark harness for the 7 physics feedback loops.physics_diagnostic_words.c— physics diagnostics (WORD-ENTROPY).physics_freeze_words.c—PHYSICS-FREEZE/PHYSICS-THAW.physics_pipelining_diagnostic_words.c— Loop #4 pipelining diagnostics.dictionary_heat_diagnostic_words.c— Loop #1 heat diagnostics.
See src/word_source/include/ for the matching headers (also includes
mama_forth_words.h, whose .c implementation lives under
src/starkernel/capsule/ since it's kernel-only).