FABRIC-3.5.md §XXXIII: size kernel-Hermes -- the rewrite is smaller than advertised

§XIV.1 made kernel-Hermes greenfield, which quietly exited this
document's own reorganize-don't-rewrite scope discipline, and nobody
counted the result. messaging.4th is 504 lines and 85 words; that number
turns out to be misleading in the reassuring direction.

Roughly 34 of the 85 are field accessors that vanish as C struct members.
28 are channel machinery -- and the entire CH-NEGOTIATING to CH-OPEN to
CH-CLOSING handshake has no caller anywhere in capsules, src or
experiments. CH-REQUEST, CH-ACCEPT, CH-CONFIRM, CH-CLOSE and CH-MINT-ID
are referenced only by MANIFEST.md, which is documentation. The live
channel lifecycle is one static channel created at boot with three
members added via CH-ADD-MBR and never negotiated, closed or reaped, with
console proxies opting out of channels entirely. Kernel-Hermes needs one
broadcast membership list, not a channel subsystem.

The three event words die with process.4th, which is EXEC'd nowhere, and
take SPAWN-EVENT's unwired placeholder with them.

What must survive is narrow: the heat-coupled allocator, about nine
protocol words, one membership list, the live elevation path through
zuse-eligibility.4th, and the status words that make the subsystem
debuggable at all.

States the caveat plainly: unexercised is not unwanted, and deleting the
channel abstraction is Captain Bob's decision rather than an observation.
Notes the evidence here is stronger than §XXII.2's capsule search, since
FORTH words are invoked by literal text rather than runtime-assembled
names, but that a human can still type CH-REQUEST at a REPL. Also flags
MANIFEST.md describing the negotiation as live, another entry for the
documentation sweep.

Names the one genuinely hard piece and recommends building it first: the
heat-coupled allocator, because K is continuously verified and any drift
is visible. If K holds across alloc, free and evict under the new
arbiter, the rest is protocol plumbing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
This commit is contained in:
Claude
2026-09-19 11:30:44 +00:00
parent 7aa9bad243
commit 71ef7914dd
+119
View File
@@ -3341,3 +3341,122 @@ would have been unbuildable and identity VMs would have lost their delivery path
would walk into. Examined, it is a defect the reshuffle *removes* — because the mechanism that
creates it is the same FORTH messaging layer already ruled legacy. **The gap analysis found a
problem that the design had already solved without noticing.**
---
## XXXIII. Sizing kernel-Hermes: what actually has to be reimplemented (2026-09-19)
**Why this section exists.** §XIV.1 ruled the FORTH messaging layer legacy and kernel-Hermes
greenfield. That was the right call, but it quietly exited this document's own scope discipline
— "a reorganization, not an invention… relocated and rewired rather than rewritten" — and
**nobody counted what the rewrite actually amounts to.** With the build trigger approaching and
confidence the stated concern, an unsized centerpiece is the wrong thing to carry into it.
`capsules/common/messaging.4th` is 504 lines defining **85 words**. That number is the reason
to look, and it turns out to be badly misleading in the reassuring direction.
### XXXIII.1 — The 85 words, by category
| Category | Words | Fate in kernel C |
|---|---|---|
| **Field accessors** (`MSG-TYPE@/!`, `CH-ID@/!`, `MBR-VM@/!`, …) | ~34 | **Vanish** — they become struct members |
| **Channel abstraction** (`CH-*`) | **28** | **Mostly unexercised — see §XXXIII.2** |
| **Message core** (alloc/free, send, deliver, tick, reap, ack/nack, redeliver) | ~20 | **Must survive. The real work.** |
| **Member list** (`MBR-*`) | 7 | Collapses to a small membership list |
| **Events** (`EVENT-EMIT/WAIT/DRAIN`) | 3 | **Dead — see §XXXIII.3** |
| **Elevation** (`ELEVATE-*`, `SEND-ELEVATE-REQUEST`) | 5 | **Live. Must survive.** |
| **Status/diagnostics** (`MSG-USED`, `CH-USED`, `MSG-STATUS`) | 3 | Cheap, keep |
### XXXIII.2 — Finding: the channel abstraction serves exactly one static channel
**28 of the 85 words are channel machinery.** Traced across `capsules/`, `src/` and
`experiments/` for callers outside `messaging.4th` itself:
| Word | Live callers outside `messaging.4th` |
|---|---|
| `CH-REQUEST` | **none** — only `capsules/MANIFEST.md` (documentation) |
| `CH-ACCEPT` | **none** — documentation only |
| `CH-CONFIRM` | **none** — documentation only |
| `CH-CLOSE` | **none** — documentation only |
| `CH-MINT-ID` | **none** — documentation only |
| `CH-ADD-MBR` | **3** — the only live channel operation in the system |
**The entire `CH-NEGOTIATING → CH-OPEN → CH-CLOSING` handshake has no caller anywhere.** The
whole live channel lifecycle is: Hermes creates `COMMON-CH` once at birth, adds itself and Hera
(`hermes/init.4th:20-21`), Artemis adds itself (`artemis/init.4th:501`). **One channel, three
members, created at boot and never negotiated, never closed, never reaped.**
So `CH-ARENA`, `CH-MAX 16`, `CH-ALLOC`, `CH-FREE-NODE`, `CH-FIND-FREE-SLOT`, `CH-COOL-ALL`,
`CH-TOTAL-HEAT`, `CH-REAP-SAFE`, per-channel Stadium heat accounting and the three-state
machine all exist to support a generality **nothing has ever used**. Console proxies explicitly
opt out of channels entirely (`capsule_console.c:23`).
**Kernel-Hermes does not need a channel subsystem. It needs one broadcast membership list.**
### XXXIII.3 — Finding: the event words die with `process.4th`
`EVENT-EMIT`, `EVENT-WAIT`, `EVENT-DRAIN` have exactly one live caller — **`capsules/process.4th`,
which §XIII.2 established is `EXEC`'d nowhere.** The only other reference is `MANIFEST.md`.
They go out with it, along with `SPAWN-EVENT` (§I.4: grepped tree-wide, zero consumers, "an
unwired placeholder"). **Do not port the event layer.**
### XXXIII.4 — What must actually survive
Stripped of the above, kernel-Hermes's real surface is:
1. **Message allocation and release, coupled to Stadium heat.** `MSG-ALLOC` pulls `Q.SLOT` from
the *caller's own* reservoir and rolls back on refusal; `MSG-FREE-NODE` returns it via
`STADIUM-EVICT`. **This is the hard part, and the one that cannot be approximated** —
§XV.4 established that K conservation is the only thing that must survive a death, and
`fleet_conserved` verifies it continuously.
2. **Send / deliver / deliver-all / tick / reap / ack / nack / redeliver-nacked** — the core
protocol, ~9 words of real logic.
3. **One broadcast membership list** (replacing 28 words of channel machinery).
4. **The elevation path** — `SEND-ELEVATE-REQUEST` / `ELEVATE-GRANT`, live in
`zuse-eligibility.4th` (loaded at boot by `init.4th`) and `mama_forth_words.c`. **Must
survive; it is the word-ACL elevation ask carried to Zuse.**
5. **Status words**, cheap and worth keeping for the same reason §XXVIII.1 gives: a subsystem
that emits nothing by default cannot be debugged.
**Roughly half the file is accessors that become struct fields, and another third is
generality with no caller. The genuinely new C is the heat-coupled allocator plus about nine
protocol words.** That is a much smaller thing than "reimplement 504 lines of messaging," and
it is the first honest estimate this document has had.
### XXXIII.5 — The caveat, and the part that is not mine to decide
**"Unexercised today" is not "unwanted."** The channel abstraction may have been built for a
future that has not arrived — per-VM private channels, capability-scoped groups. Deleting it is
a **decision**, not an observation, and it belongs to Captain Bob.
Two honest qualifications on the evidence:
- §XXII.2's lesson applies in weakened form. Capsules are birthed by name from runtime strings,
which defeats grep; **FORTH words are not** — a word is invoked by its literal text, so this
search is far more reliable than the capsule-reachability search that nearly deleted the
`init-l8-*` family. **But a human can still type `CH-REQUEST` at a REPL**, and no grep sees
that.
- The negotiation machinery is *described* in `MANIFEST.md` as though live. That is the same
class of stale-documentation problem §XIII.2 found for block 4055 — **another entry for item
13's sweep.**
**Recommendation: build kernel-Hermes for one broadcast membership and no negotiation, and keep
the FORTH channel words in the Category B strip until something asks for them.** If per-VM
channels are wanted later, they are a clean addition to a working arbiter rather than a
speculative port into a new one.
### XXXIII.6 — Effect on confidence, stated plainly
This was opened expecting to find the scope larger than advertised. **It is smaller**, and for
a reason that generalizes: the FORTH layer accreted a general mechanism where the system only
ever used a specific one. The reshuffle's value is partly that it forces that accounting.
**What remains genuinely hard is narrow and now named:** the heat-coupled allocator, because K
is continuously verified and any drift is visible. **That is the piece to build first and prove
first** — before send/deliver, before delivery hand-off, before the latch. If K holds across
alloc/free/evict under the new arbiter, the rest is protocol plumbing.
**Punch list:** ⬜ **Item 27 — rule on §XXXIII.5**: does kernel-Hermes implement channel
negotiation, or one broadcast membership? ⬜ **Item 28 — build and prove the heat-coupled
allocator first**, verified against `fleet_conserved`, before any protocol work.