Files
LithosAnanake/include/starkernel/repl.h
T
Robert Allan JamesandClaude Sonnet 5 e1e839258d Phase D: RUNCAP -- runtime capsule construction from thumbdrive content
capsule_runcap_birth() (new capsule_runcap.h/.c): builds a heap-only,
single-entry CapsuleDirHeader + CapsuleDesc + CapsuleNameEntry + arena
from a home-blocks drive's identity_src region (skipping the first
devblock, reserved for MINT's user_identity_seed_t record) and hands it
to the existing, unmodified capsule_birth_baby() -- no new birth
mechanism, matching FABRIC-3.md §F.6's own trace.

Found and closed a real gap in that trace along the way:
capsule_birth_baby()'s signature check calls capsule_get_signatures(),
which unconditionally returns the compile-time-baked global array --
meaningless for a heap-built directory, where index 0 would compare
RUNCAP's own content against whatever real capsule happens to occupy
that slot in the baked array (guaranteed-wrong, not a security check).
Added an explicit skip_pki_sig flag (0 for all 4 existing call sites,
1 for RUNCAP): that content's trust comes from CERTVERIFY, a separate
root, not the capsule-PKI chain.

Also found live: capsule_birth_baby() never sets the registry entry's
own .name (every existing caller does this itself afterward via
capsule_vm_registry_set_name() -- RUNCAP now does too), and
capsule_exec_payload() requires a "Block NNNN" header per chunk of
content or it's silently skipped, never executed -- not a bug, but
necessary context for whoever authors MINT's default personality
content next.

Added a small accessor pair (repl.h/.c) exposing the currently attached
home-blocks device/sig -- the same gap F.9's own BINDSTEP scoping had
already flagged, needed by both.

Verified end-to-end live in QEMU: synthetic identity-source content
written directly to a thumbdrive image's raw devblocks (no capsule
build, no mkcapsule) was read, compiled, and executed by a genuinely
new VM via a diagnostic RUNCAP-TEST word -- confirmed via VM-EXEC
invoking a word defined only in that source. Clean 3-architecture
regression boot (no RUNCAP drive attached) confirms no side effects.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
2026-08-28 14:29:42 -04:00

89 lines
2.3 KiB
C
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/*
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 20232025 Robert A. James
All rights reserved.
Licensed under the StarForth License, Version 1.0
*/
/**
* repl.h - Emergency FORTH REPL for LithosAnanke kernel
*/
#ifndef STARKERNEL_REPL_H
#define STARKERNEL_REPL_H
#include "vm.h"
#include "starkernel/homeblocks_sig.h"
struct blkio_dev;
#ifdef __cplusplus
extern "C" {
#endif
/**
* sk_repl - Run the emergency FORTH REPL on the serial console.
*
* Blocks until vm->halted is set (BYE word) or the VM encounters a halt.
* Runs with interrupts enabled; the APIC heartbeat continues to fire.
*
* @param vm Mama VM instance (must be fully initialised)
*/
void sk_repl(VM *vm);
/**
* sk_repl_run - Bare REPL loop (no banner).
*
* Same as sk_repl but skips the version/welcome banner. Used by START
* to enter a child VM's interpreter loop without reprinting the header.
*
* @param vm Fully initialised VM instance
*/
void sk_repl_run(VM *vm);
/**
* sk_repl_step - Execute one REPL turn on a VM and return.
*
* Prints the VM's prompt, reads one line, interprets it, prints ok/ERROR,
* then returns. Used by the Compudynamics VM-STEP primitive so Hera can
* give a single REPL quantum to a child VM without surrendering control
* for the full sk_repl_run() loop.
*
* @param vm Fully initialised VM instance
* @return 1 if the VM is still running, 0 if it halted during this turn
*/
int sk_repl_step(VM *vm);
/**
* sk_repl_set_active_vm - Redirect REPL input to a different VM (USE word).
*
* Pass NULL to restore default dispatch (Mama's VM).
* The change takes effect on the next REPL iteration.
*
* @param vm Target VM, or NULL for default
*/
void sk_repl_set_active_vm(VM *vm);
/**
* sk_repl_get_active_vm - Return the current USE-redirected VM, or NULL.
*/
VM *sk_repl_get_active_vm(void);
/**
* sk_repl_get_homeblocks_dev / sk_repl_get_homeblocks_sig - The currently
* attached home-blocks USB drive, or NULL if none is attached / the
* attached drive didn't check out as HOMEBLOCKS_SIG_OK (FABRIC-3.md
* §F.6/§F.9/§F.18). Both return NULL together; never one without the
* other.
*/
struct blkio_dev *sk_repl_get_homeblocks_dev(void);
const homeblocks_sig_t *sk_repl_get_homeblocks_sig(void);
#ifdef __cplusplus
}
#endif
#endif /* STARKERNEL_REPL_H */