Files
LithosAnanake/include/starkernel
Robert Allan JamesandClaude Sonnet 5 2c1b3cd695
Build / build-amd64-iso (push) Waiting to run
Build / build-aarch64-iso (push) Waiting to run
Build / build-riscv64-img (push) Waiting to run
Four bugs found live verifying the 8 identity thumbdrives (FABRIC-3.md §IX)
All found by actually running the identity workflow §VII/§VIII made
possible, not by code review:

1. Zuse/WIREBIND cross-contamination on detach: capsule_zuse_boot_logout()
   and capsule_wirebind_unclean_detach() both had no device parameter, so
   an unrelated device detaching (while the real owner's own stayed
   attached) incorrectly tore down the wrong session. Both now compare
   the departing device against their own tracked one, mirroring
   capsule_wirebind.c's pre-existing g_wirebind_attached_dev precedent.

2. Dictionary-entry memory leak: vm_create_word()'s sf_malloc()'d
   DictEntry (plus a second per-entry allocation for transition_metrics)
   was never freed by vm_cleanup(), in both the hosted and kernel
   implementations. Caused a real kernel PANIC after 8-9 repeated VM
   birth/kill cycles in one boot. Fixed by walking vm->latest in both.

3. sf_malloc/sf_free (alloc_kernel.c) was a 4MB bump arena with a
   deliberate no-op free, sized on "VM born once, never killed" -- fix #2
   alone didn't stop the panic because free() itself discarded the
   pointer regardless. Given a real free list (first-fit reuse).

4. Headless-console gate didn't re-engage after a mid-boot logout: the
   original fix (sk_console_mark_login(), one-way sticky) only gated the
   first login of the boot. Replaced with a live check
   (sk_console_identity_present()) re-evaluated continuously, including
   inside sk_console_readline()'s own blocking idle loop -- the console
   is normally sitting blocked there when a hot-unplug logout happens, so
   checking only at the top of the REPL loop wasn't enough.

Also: MINT now verifies its own write (verify_mint(), capsule_mint.c) by
reading back through the same check a real attach performs, rather than
trusting blkio_write()'s BLK_OK alone -- logged via log_message(), not
console_println(), per direct instruction.

Verified live, amd64: the full 8-identity repeated attach/detach cycle
that previously panicked at the same point every time now completes
clean, and a full serial-log sweep found zero bare unauthenticated
prompts anywhere in the run. Three-arch clean-qemu acceptance passed.

Still open, not fixed here: a 3+-simultaneous-device USB enumeration
failure found in a separate live test, not yet root-caused.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018EjXFo7mPXjUMjfJeuUUz4
2026-09-06 01:49:13 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

include/starkernel/

Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/). Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared with hosted code.

  • uefi.h — UEFI protocol/type definitions consumed by the loader.
  • elf64.h, elf_loader.h — ELF64 parsing and kernel-image loading.
  • boot_info_offsets.h — struct-offset constants shared between the assembly bootstrap and the C boot path.
  • arch.h, apic.h, timer.h — architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).
  • console.h, framebuffer.h, vt100.h — UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.
  • pmm.h, vmm.h, kmalloc.h — physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.
  • pci.h, virtio_blk.h — PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).
  • capsule.h, capsule_birth.h, capsule_loader.h, capsule_run.h, capsule_vm_physics.h, capsule_generated.h — capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (see tools/mkcapsule.c).
  • kernel_args.h, cmdline.h — boot-time kernel argument parsing (starforth.cfg / command line).
  • repl.h — kernel REPL.
  • log.h, doe_log.h — kernel logging and DoE metrics logging.
  • q48_16.h — kernel-build copy of Q48.16 fixed-point arithmetic.
  • xxhash64.h — content-addressing hash used for capsule IDs.
  • hal_memory.h — hardware-abstraction-layer memory interface.

Subdirectories:

  • hal/ — top-level hardware-abstraction-layer interface.
  • vm/ — kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).
  • freestanding/ — minimal libc-shim headers (assert.h, ctype.h, errno.h, inttypes.h, math.h, sched.h, signal.h, stdio.h, stdlib.h, string.h, time.h, sys/time.h, sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.