Files
LithosAnanake/src
Robert Allan JamesandClaude Sonnet 5 2fc55f47e1 Milestone 6: mkcapsule signing + capsule_birth.c wiring, WARN-only
First attempt shelled out to `openssl pkeyutl -sign` (fork/execlp, not
system() -- avoided shell string interpolation of the key path).
Corrected on request: no new external host binary dependency when the
repo's own code can do the job -- same standing preference as the
earlier anti-file correction. Rewritten to link ed25519_sign() (already
verified against OpenSSL in Phase B) directly into mkcapsule.

New tools/pkcs8_ed25519.c: a narrow DER walker (same shape as
x509_ed25519.c, deliberately not shared -- small enough that
duplicating a few TLV-walking lines beat threading a header between the
kernel crypto tree and host tooling) extracting the raw seed from the
intermediate's PKCS#8 private key, plus a minimal self-written base64
decoder (PEM is openssl genpkey's default output; no decoder existed
anywhere in the repo). Verified end-to-end before wiring anything in:
the extracted seed's derived pubkey matches the cert's exactly, and a
full self-contained sign+verify round-trip (zero openssl) passes.

CapsuleDesc had no spare bytes, so signatures live in a new parallel
CapsuleSigEntry array, emitted by a new `mkcapsule --sign-key <path>`
flag (omitted/missing key -> has_sig=0 everywhere, graceful, not a
build failure -- CI has no access to the offline key).

New capsule_sig.c/.h: capsule_verify_signature(), a separate function,
not folded into the already-tested capsule_validate(). Finds and caches
the embedded intermediate cert's pubkey once per boot, then verifies
against it. Wired into all three capsule_validate() call sites in
capsule_birth.c via log_message(LOG_WARN, ...) -- never refuses yet,
per the earlier staged-rollout decision.

Verified independently, both directions, live in the real kernel: a
full clean build (38 signed capsules) boots clean on all three
architectures with zero warnings. Separately, hand-corrupted one byte
of Mama's own init.4th capsule's stored signature (not its payload/hash,
which capsule_validate() already catches and would have masked the
test) and rebuilt just the changed object: produced exactly "capsule
sig: init.4th: INVALID -- signature does not verify" on boot, and the
kernel still reached ok> -- proving warn-only doesn't refuse anything
yet. Reverted before the final, untampered 3-arch acceptance pass.

Still open: flipping WARN to hard-refuse (separate, deliberate step)
and the BLOCK_MAP.md signature-status column. Documented in FABRIC-3.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
2026-08-26 21:32:29 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

src/

Hosted StarForth VM implementation (compiled by the root Makefile). Bare-metal kernel sources live in src/starkernel/; FORTH word implementations in src/word_source/; the test harness in src/test_runner/; platform shims in src/platform/.

Entry point / interpreter core

  • main.c — CLI entry point, VM init, DoE mode dispatch.
  • vm.c — interpreter loop, stacks, dictionary state (the central runtime file).
  • vm_api.c — external VM API implementation.
  • vm_bootstrap.c — VM bootstrap initialization.
  • vm_debug.c — debugging utilities.
  • vm_time.c — time-related VM operations.
  • vm_internal.h — internal-only declarations shared across the vm_*.c files, not part of the public include/vm_api.h surface.
  • repl.c — REPL read-eval-print loop.
  • cli.c — CLI argument parsing.
  • io.c — I/O operations.
  • log.c — logging infrastructure.

Memory / dictionary / blocks

  • memory_management.c — dictionary allocator.
  • dictionary_management.c — dictionary allocation and search.
  • dictionary_heat_optimization.c — Loop #1 execution-heat tracking.
  • word_registry.c — word registration system.
  • block_subsystem.c — logical→physical block mapper.
  • blkio_file.c, blkio_ram.c, blkio_factory.c — block I/O backends (file-backed, RAM-backed) and the factory that selects between them.
  • stack_management.c — stack operations.

Physics-driven adaptive runtime (7 feedback loops)

  • physics_runtime.c — main physics coordinator.
  • physics_hotwords_cache.c — Loop #1 hot-words caching.
  • physics_metadata.c — per-word metadata tracking.
  • physics_pipelining_metrics.c — Loop #4 word-transition prediction.
  • physics_execution_hooks.c — execution instrumentation.
  • rolling_window_of_truth.c — Loop #2 circular execution-history buffer.
  • inference_engine.c — Loops #5/#6, statistical inference (window-width, decay-slope).
  • ssm_jacquard.c — L8 Jacquard steady-state mode selector; consumes compudynamics.c for tuning-word/config lookups.
  • compudynamics.c — generic compudynamics module (cd_tuning_word(), cd_tuning_vm()); the score/UCB/reward/weight constants for the L8 adaptive table live here, not in ssm_jacquard.c.
  • heartbeat_export.c — heartbeat metrics export (CSV export function itself not yet implemented — see docs/working/architecture/heartbeat_csv_export.md).

Math / measurement

  • math_portable.c — portable math functions.
  • profiler.c — performance profiling.
  • doe_metrics.c — Design of Experiments metrics (2^7 factorial).

Any .bak file alongside a .c file here (doe_metrics.c.bak, inference_engine.c.bak, vm.c.bak) is a pre-edit backup left by a past maintenance script (see scripts/remove_loop_conditionals.sh), not a build input.