# capsules/contrib/ Milestone 7 (contributor capsules / trust tiers), FABRIC-3.md §I.5. Any `.4th` file placed here gets `FLAG_CONTRIB` in addition to the usual `FLAG_PRODUCTION | FLAG_EXPERIMENT` pair — `tools/mkcapsule.c`'s `flags_from_name()` path-matches on the colon-separated capsule name starting with `contrib:`, mirroring `FLAG_MAMA_INIT`'s own exact-match pattern one line up in that same function. **Trust-tier direction, decided in conversation 2026-09-04:** QEMU-vs-real- hardware conditional enforcement — a contributor capsule is validated more strictly on real hardware than under QEMU, using `timer_calibration_record()->vm_mode` (`include/starkernel/timer.h`) as the signal. `vm_mode` is a real per-architecture hypervisor-vs-hardware detection as of this same pass (amd64: `CPUID.1:ECX[31]`; aarch64: ACPI RSDP OEM ID; riscv64: devicetree `compatible` string) — not a build-time flag, so the same binary enforces differently depending on where it actually boots. **Enforcement rule, built 2026-09-04:** `contrib_capsule_refused()` (`capsule_birth.c`), called from both `capsule_birth_baby()` and `capsule_run_experiment()` (never `capsule_birth_mama()` — Mama's own init can never carry `FLAG_CONTRIB`, mutually exclusive with `FLAG_MAMA_INIT` by construction). Under QEMU (`vm_mode == 1`): no additional check, same WARN-only treatment every other capsule gets. On real hardware (`vm_mode == 0`): a contrib capsule additionally requires `CAPSULE_SIG_OK` — `MISSING`/`NO_ROOT_KEY`, which stay WARN-only for every other capsule (most machines lack the offline signing key), are refused here specifically because a contributor's capsule has no other provenance to fall back on. Additive to, never a replacement for, the existing `CAPSULE_SIG_INVALID` refusal already enforced on every capsule regardless of `FLAG_CONTRIB`.