starkernel: item 3.8 -- VM identifiers as UUID/GUID
Punch list §25 item 3.8 complete. Added after starting item 4.1
surfaced the need to thread a vm_id into stadium_admit()'s new quota
parameter; Captain Bob ruled UUID/GUID rather than keeping the
narrower uint32_t.
New VMUuid type (vm_uuid.h/vm_uuid.c): two uint64_t halves, RFC-4122-
shaped for logging. Not real randomness -- checked directly against
QEMU 10.2.1's actual CPU feature set: amd64 RDRAND and riscv64 Zkr are
both real, available features here; aarch64 has no RNG property on any
CPU model including "max" (verified exhaustively via QMP
query-cpu-model-expansion). Captain Bob ruled a uniform fallback
across all three ISAs rather than a per-architecture split.
Fallback is a deterministic PRNG (splitmix64) seeded from the Mama
capsule's content hash, pre-filling a 16-entry FIFO pool at boot and
refilling with another batch of the same stream when exhausted --
exactly the shape requested. Same capsule booted twice produces the
same id sequence, preserving the dict_hash reproducibility this
session has relied on throughout.
Hera keeps a fixed, reserved all-zero id, not drawn from the pool --
capsule_birth.c uses vm_id == 0 as a load-bearing sentinel in three
places (KILL protection x2, fleet heat-fanout parent-chain
terminator), found by reading before writing any code.
Two real sentinel-collision bugs caught before shipping, same class as
STADIUM_CONTAINS_NONE: vm_uuid_none() (all-ones, not all-zero) for
"not yet assigned"/"no VM" placeholders; confirmed item 3.7's quota
table already used an in_use boolean rather than a vm_id sentinel, so
no second collision was actually possible there -- the dead,
never-referenced STADIUM_QUOTA_SLOT_EMPTY macro was removed.
Blast radius larger than first scoped, flagged mid-work rather than
silently absorbed: capsule_vm_physics.c/.h (the fleet heat-transfer
layer item 2.1 modified earlier this session) has its own vm_id-keyed
node table and walks parent_vm_id chains through the same identity
space, so it needed the same change, plus its callers in
mama_forth_words.c and sk_vm_bootstrap.c.
One live FORTH word contract changed, by explicit ruling: CAPSULE-BIRTH
was ( capsule-id -- vm-id ), a single cell -- can't hold 128 bits.
Captain Bob picked pushing two cells ("there is doubles support in the
FORTH std word set anyway"): ( capsule-id -- vm-id-hi vm-id-lo ).
MAMA-VM-ID changed the same way: ( -- 0 0 ).
Verified: full (not standalone-file) kernel rebuild to catch cross-file
breakage given the size of this change -- it surfaced the
capsule_vm_physics.c blast radius a narrower check would have missed.
Three-architecture boot (amd64, aarch64, riscv64), all reaching ok>
with identical dict_hash=0x3d4e1daf289da94f matching the item-3.7
baseline.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
ec2c97ef70
commit
9b305a5be7
@@ -37,6 +37,7 @@
|
||||
#include <stddef.h>
|
||||
#include <stdint.h>
|
||||
#include "starforth_config.h" /* STADIUM_CONTAINS_DEPTH_MAX, STADIUM_CAPACITY_TICK, STADIUM_MEMORY_PERCENT */
|
||||
#include "starkernel/vm_uuid.h" /* VMUuid -- FABRIC.md item 3.8 */
|
||||
|
||||
#define STADIUM_CELL_BYTES 64
|
||||
|
||||
@@ -272,19 +273,15 @@ int stadium_evict(size_t cell_index);
|
||||
/*
|
||||
* StadiumVMQuota - per-VM ownership of a subset of the global cell array
|
||||
* (FABRIC.md §22.3, item 3.7: "each VM holds its own free-list head index
|
||||
* into the global array"). A small table, linearly searched by vm_id --
|
||||
* capsule_birth.c's vm_id is monotonic and never reused (next_vm_id only
|
||||
* increments, even across VM death), so it cannot index this table
|
||||
* directly, and STADIUM_MAX_VM_COUNT is small enough (default 4) that a
|
||||
* linear scan costs nothing. Not exposed outside stadium.c: nothing outside
|
||||
* needs to inspect quota state directly yet.
|
||||
* into the global array"). A small table, linearly searched by vm_id -- a
|
||||
* VMUuid (item 3.8) can't be used as a direct array index anyway, and
|
||||
* STADIUM_MAX_VM_COUNT is small enough (default 4) that a linear scan costs
|
||||
* nothing. Not exposed outside stadium.c: nothing outside needs to inspect
|
||||
* quota state directly yet. Slot emptiness is tracked by an internal
|
||||
* `in_use` flag, not a vm_id sentinel value -- there is no unused vm_id bit
|
||||
* pattern to reserve for it.
|
||||
*/
|
||||
|
||||
/* Sentinel meaning "no VM owns this slot yet." Distinct from a real vm_id
|
||||
* (capsule_birth.c reserves 0 for Hera, so 0 cannot double as "unused" here
|
||||
* either -- same shape of mistake STADIUM_CONTAINS_NONE was fixed for). */
|
||||
#define STADIUM_QUOTA_SLOT_EMPTY ((uint32_t)-1)
|
||||
|
||||
/*
|
||||
* stadium_admit - Place a candidate patron header into the Stadium, scoped
|
||||
* to vm_id's quota (FABRIC.md §19.3, §22.3, item 3.7).
|
||||
@@ -301,9 +298,9 @@ int stadium_evict(size_t cell_index);
|
||||
* -- the item-3.6 rule that patron zero (Hera) must never actually be
|
||||
* selected is a separate, later check at the eviction site.
|
||||
*
|
||||
* REFUSES if vm_id has no quota granted (only Hera, vm_id 0, has one today
|
||||
* -- granted the entire array at stadium_boot_init(), since she is the only
|
||||
* VM that exists per item 0.1). Granting quota to additional VMs, and
|
||||
* REFUSES if vm_id has no quota granted (only Hera, vm_uuid_hera(), has one
|
||||
* today -- granted the entire array at stadium_boot_init(), since she is the
|
||||
* only VM that exists per item 0.1). Granting quota to additional VMs, and
|
||||
* transferring capacity between them, is capacity ARBITRATION -- item 1.3
|
||||
* left "how much capacity moves per eligible transfer" explicitly open, so
|
||||
* this item does not invent it. Only the boot-time all-to-Hera grant exists.
|
||||
@@ -336,7 +333,7 @@ int stadium_evict(size_t cell_index);
|
||||
* quota full and candidate not denser than its least-dense
|
||||
* evictable resident, or it has no evictable resident at all).
|
||||
*/
|
||||
size_t stadium_admit(uint32_t vm_id, const StadiumPatronHeader *candidate);
|
||||
size_t stadium_admit(VMUuid vm_id, const StadiumPatronHeader *candidate);
|
||||
|
||||
#endif /* __STARKERNEL__ */
|
||||
|
||||
|
||||
Reference in New Issue
Block a user