Captain Bob, 2026-09-07: "starting with that 00 user we created, we're
going to give access only to FORTH 79 and 83 standard words. everything
else is locked down."
New capsules/acl-std79.4th (blocks 4023-4047): walks a VM's own
dictionary (>LINK/LINK> traversal, same as ACL-INIT-PRIMITIVES/WORDS
already use) and permanently denies+pins every word not on an explicit
FORTH-79/83 allowlist, extracted from the real registered word set
(stack_words.c through control_words.c), not recited from memory.
Deliberately excludes, beyond plain non-standard words: BYE (100% ACL
bypass to the emergency console -- "needs more discussion, exclude for
now"), COLD/WARM/REBOOT/SAVE-SYSTEM (system lifecycle), the block/screen
editor L/S/SHOW/EDIT/UPDATE/SAVE-BUFFERS (lets a session rewrite
persistent block/capsule content, defeating the lockdown even though
nominally standard), BLK-ACL-*/BLK-OWNER@ (StarForth-specific), and
FORGET/FENCE (flagged as an unrestricted superpower word, 2026-09-03
audit). Keeps WORDS/VLIST/SEE (introspection only -- ACL is enforced
per-target-word at execution time regardless of how an XT was
obtained) and the parenthesized control-flow runtime primitives
((BRANCH) etc. -- IF/DO/LOOP compile calls to these; denying them
breaks ordinary control flow, not security).
MintPersonality enum (capsule_mint.h) lets capsule_mint_identity()
select which personality-source template gets written to a new
identity's devblock -- MINT_PERSONALITY_DEFAULT (unchanged) or
MINT_PERSONALITY_STD79_LOCKDOWN (EXECs acl-std79.4th then
ACL-LOCKDOWN-STD79 as the VM's own last bootstrap step). The actual
restriction logic stays entirely in FORTH per .claude/CLAUDE.md's
Word-Level ACL System rules ("ACL policy belongs in ACL.4th, never in
C") -- capsule_mint.c only picks which few-line bootstrap stub to
write. MINT's own stack signature gains a trailing restrict? flag;
capsule_zuse_boot.c's genesis mint (Zuse herself) explicitly passes
MINT_PERSONALITY_DEFAULT -- the superuser is never restricted.
Two real bugs found and fixed live during testing, both the same class
of self-referential fault: ACL-LOCKDOWN-STD79's own walk loop calls
ACL-STD79-ALLOWED?/ACL-STD79-LIST/ACL-ALLOW!/ACL-PIN on every single
iteration to do its job -- none of those are FORTH-79/83 standard
words, so the walk was denying its own load-bearing infrastructure
partway through and then faulting the next time it tried to call it
("VM fault -- emergency console disabled; halting", reproduced twice
live). Fixed by explicitly protecting all four in the allowlist
(block 4047) -- they must stay allowed for the walk to finish, not
because they belong on a "standard words" list.
Verified live end-to-end: minted a throwaway test identity with the
restrict? flag, confirmed her WIREBIND birth completes cleanly (no
faults, no shadow conflicts) on a single real attach, then USE'd into
her VM and confirmed standard arithmetic and user-defined words work
(1 2 + . -> 3; : X 5 5 * . ; X -> 25) while KILL is entirely unknown to
her dictionary and VM-EXEC is denied. One real, non-fatal side effect
found and left as-is (not asked to fix): the fleet's inter-VM messaging
pump (MSG-ARENA) is also denied by the lockdown, logging a harmless
per-idle-tick warning -- a fully locked-down VM doesn't participate in
message routing.
Not yet applied to the real identity 00 -- this commit is the
mechanism, verified against a disposable test identity only.
Three-arch clean qemu acceptance (single Zuse device, standard
regression case) passed on amd64, aarch64, and riscv64.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014Ec88YKxxhZGG1RNnune78
include/
Public headers for the hosted StarForth VM (src/). Kernel-only headers
live under include/starkernel/.
Core VM
vm.h— theVMstruct and all core types (DictEntry,DictPhysics, stacks, dictionary state); the central header most other files include.vm_api.h— external VM API surface.vm_host.h,vm_debug.h,startup.h,version.h— host integration, debug utilities, startup sequencing, version string.cli.h,repl.h,io.h,log.h— CLI parsing, REPL loop, I/O, logging.word_registry.h— word registration system shared by everysrc/word_source/*.cfile.compudynamics.h— the generic compudynamics module: tuning-word/config lookups (cd_tuning_word(),cd_tuning_vm()) consumed byssm_jacquard.c.
Memory / blocks
memory_management.h,dictionary_management.h— dictionary allocator and search.block_subsystem.h,blkcfg.h,blkio.h,blkio_factory.h— logical→ physical block mapper and pluggable block I/O backends (file/RAM).platform_alloc.h,platform_lock.h,platform_time.h— platform abstraction shims (hosted vs. kernel allocation/locking/timing).
Physics-driven adaptive runtime (7 feedback loops)
physics_runtime.h— main physics coordinator.physics_hotwords_cache.h— Loop #1, execution-heat hot-words cache.physics_metadata.h— per-wordDictPhysicsmetadata tracking.physics_pipelining_metrics.h— Loop #4, word-transition prediction.physics_execution_hooks.h— execution instrumentation hook points.rolling_window_of_truth.h,rolling_window_knobs.h— Loop #2 circular execution-history buffer and its tuning knobs.inference_engine.h— Loops #5/#6, window-width and decay-slope statistical inference.dictionary_heat_optimization.h— Loop #1 heat counters.ssm_jacquard.h— L8 Jacquard steady-state mode selector.doe_metrics.h— Design of Experiments (2^7 factorial) metrics.profiler.h— performance profiling hooks.
Arithmetic / codegen
q48_16.h— Q48.16 deterministic fixed-point arithmetic (used instead of IEEE-754 float specifically to keep cross-architecture behavior bit-identical).math_portable.h— portable math helpers.arch_detect.h,starforth_config.h— architecture detection and the build-flag fallback-default layer (used when a.cfile is compiled by hand withoutmake).vm_asm_opt.h,vm_asm_opt_arm64.h,vm_asm_opt_riscv64.h,vm_inner_interp_asm.h,vm_inner_interp_arm64.h,vm_inner_interp_riscv64.h— per-architecture assembler-optimized inner interpreter (USE_ASM_OPT=1).
See include/starkernel/README.md for the bare-metal kernel headers.