FABRIC-3.5.md §XXXIII: size kernel-Hermes -- the rewrite is smaller than advertised
§XIV.1 made kernel-Hermes greenfield, which quietly exited this document's own reorganize-don't-rewrite scope discipline, and nobody counted the result. messaging.4th is 504 lines and 85 words; that number turns out to be misleading in the reassuring direction. Roughly 34 of the 85 are field accessors that vanish as C struct members. 28 are channel machinery -- and the entire CH-NEGOTIATING to CH-OPEN to CH-CLOSING handshake has no caller anywhere in capsules, src or experiments. CH-REQUEST, CH-ACCEPT, CH-CONFIRM, CH-CLOSE and CH-MINT-ID are referenced only by MANIFEST.md, which is documentation. The live channel lifecycle is one static channel created at boot with three members added via CH-ADD-MBR and never negotiated, closed or reaped, with console proxies opting out of channels entirely. Kernel-Hermes needs one broadcast membership list, not a channel subsystem. The three event words die with process.4th, which is EXEC'd nowhere, and take SPAWN-EVENT's unwired placeholder with them. What must survive is narrow: the heat-coupled allocator, about nine protocol words, one membership list, the live elevation path through zuse-eligibility.4th, and the status words that make the subsystem debuggable at all. States the caveat plainly: unexercised is not unwanted, and deleting the channel abstraction is Captain Bob's decision rather than an observation. Notes the evidence here is stronger than §XXII.2's capsule search, since FORTH words are invoked by literal text rather than runtime-assembled names, but that a human can still type CH-REQUEST at a REPL. Also flags MANIFEST.md describing the negotiation as live, another entry for the documentation sweep. Names the one genuinely hard piece and recommends building it first: the heat-coupled allocator, because K is continuously verified and any drift is visible. If K holds across alloc, free and evict under the new arbiter, the rest is protocol plumbing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
This commit is contained in:
+119
@@ -3341,3 +3341,122 @@ would have been unbuildable and identity VMs would have lost their delivery path
|
||||
would walk into. Examined, it is a defect the reshuffle *removes* — because the mechanism that
|
||||
creates it is the same FORTH messaging layer already ruled legacy. **The gap analysis found a
|
||||
problem that the design had already solved without noticing.**
|
||||
|
||||
---
|
||||
|
||||
## XXXIII. Sizing kernel-Hermes: what actually has to be reimplemented (2026-09-19)
|
||||
|
||||
**Why this section exists.** §XIV.1 ruled the FORTH messaging layer legacy and kernel-Hermes
|
||||
greenfield. That was the right call, but it quietly exited this document's own scope discipline
|
||||
— "a reorganization, not an invention… relocated and rewired rather than rewritten" — and
|
||||
**nobody counted what the rewrite actually amounts to.** With the build trigger approaching and
|
||||
confidence the stated concern, an unsized centerpiece is the wrong thing to carry into it.
|
||||
|
||||
`capsules/common/messaging.4th` is 504 lines defining **85 words**. That number is the reason
|
||||
to look, and it turns out to be badly misleading in the reassuring direction.
|
||||
|
||||
### XXXIII.1 — The 85 words, by category
|
||||
|
||||
| Category | Words | Fate in kernel C |
|
||||
|---|---|---|
|
||||
| **Field accessors** (`MSG-TYPE@/!`, `CH-ID@/!`, `MBR-VM@/!`, …) | ~34 | **Vanish** — they become struct members |
|
||||
| **Channel abstraction** (`CH-*`) | **28** | **Mostly unexercised — see §XXXIII.2** |
|
||||
| **Message core** (alloc/free, send, deliver, tick, reap, ack/nack, redeliver) | ~20 | **Must survive. The real work.** |
|
||||
| **Member list** (`MBR-*`) | 7 | Collapses to a small membership list |
|
||||
| **Events** (`EVENT-EMIT/WAIT/DRAIN`) | 3 | **Dead — see §XXXIII.3** |
|
||||
| **Elevation** (`ELEVATE-*`, `SEND-ELEVATE-REQUEST`) | 5 | **Live. Must survive.** |
|
||||
| **Status/diagnostics** (`MSG-USED`, `CH-USED`, `MSG-STATUS`) | 3 | Cheap, keep |
|
||||
|
||||
### XXXIII.2 — Finding: the channel abstraction serves exactly one static channel
|
||||
|
||||
**28 of the 85 words are channel machinery.** Traced across `capsules/`, `src/` and
|
||||
`experiments/` for callers outside `messaging.4th` itself:
|
||||
|
||||
| Word | Live callers outside `messaging.4th` |
|
||||
|---|---|
|
||||
| `CH-REQUEST` | **none** — only `capsules/MANIFEST.md` (documentation) |
|
||||
| `CH-ACCEPT` | **none** — documentation only |
|
||||
| `CH-CONFIRM` | **none** — documentation only |
|
||||
| `CH-CLOSE` | **none** — documentation only |
|
||||
| `CH-MINT-ID` | **none** — documentation only |
|
||||
| `CH-ADD-MBR` | **3** — the only live channel operation in the system |
|
||||
|
||||
**The entire `CH-NEGOTIATING → CH-OPEN → CH-CLOSING` handshake has no caller anywhere.** The
|
||||
whole live channel lifecycle is: Hermes creates `COMMON-CH` once at birth, adds itself and Hera
|
||||
(`hermes/init.4th:20-21`), Artemis adds itself (`artemis/init.4th:501`). **One channel, three
|
||||
members, created at boot and never negotiated, never closed, never reaped.**
|
||||
|
||||
So `CH-ARENA`, `CH-MAX 16`, `CH-ALLOC`, `CH-FREE-NODE`, `CH-FIND-FREE-SLOT`, `CH-COOL-ALL`,
|
||||
`CH-TOTAL-HEAT`, `CH-REAP-SAFE`, per-channel Stadium heat accounting and the three-state
|
||||
machine all exist to support a generality **nothing has ever used**. Console proxies explicitly
|
||||
opt out of channels entirely (`capsule_console.c:23`).
|
||||
|
||||
**Kernel-Hermes does not need a channel subsystem. It needs one broadcast membership list.**
|
||||
|
||||
### XXXIII.3 — Finding: the event words die with `process.4th`
|
||||
|
||||
`EVENT-EMIT`, `EVENT-WAIT`, `EVENT-DRAIN` have exactly one live caller — **`capsules/process.4th`,
|
||||
which §XIII.2 established is `EXEC`'d nowhere.** The only other reference is `MANIFEST.md`.
|
||||
|
||||
They go out with it, along with `SPAWN-EVENT` (§I.4: grepped tree-wide, zero consumers, "an
|
||||
unwired placeholder"). **Do not port the event layer.**
|
||||
|
||||
### XXXIII.4 — What must actually survive
|
||||
|
||||
Stripped of the above, kernel-Hermes's real surface is:
|
||||
|
||||
1. **Message allocation and release, coupled to Stadium heat.** `MSG-ALLOC` pulls `Q.SLOT` from
|
||||
the *caller's own* reservoir and rolls back on refusal; `MSG-FREE-NODE` returns it via
|
||||
`STADIUM-EVICT`. **This is the hard part, and the one that cannot be approximated** —
|
||||
§XV.4 established that K conservation is the only thing that must survive a death, and
|
||||
`fleet_conserved` verifies it continuously.
|
||||
2. **Send / deliver / deliver-all / tick / reap / ack / nack / redeliver-nacked** — the core
|
||||
protocol, ~9 words of real logic.
|
||||
3. **One broadcast membership list** (replacing 28 words of channel machinery).
|
||||
4. **The elevation path** — `SEND-ELEVATE-REQUEST` / `ELEVATE-GRANT`, live in
|
||||
`zuse-eligibility.4th` (loaded at boot by `init.4th`) and `mama_forth_words.c`. **Must
|
||||
survive; it is the word-ACL elevation ask carried to Zuse.**
|
||||
5. **Status words**, cheap and worth keeping for the same reason §XXVIII.1 gives: a subsystem
|
||||
that emits nothing by default cannot be debugged.
|
||||
|
||||
**Roughly half the file is accessors that become struct fields, and another third is
|
||||
generality with no caller. The genuinely new C is the heat-coupled allocator plus about nine
|
||||
protocol words.** That is a much smaller thing than "reimplement 504 lines of messaging," and
|
||||
it is the first honest estimate this document has had.
|
||||
|
||||
### XXXIII.5 — The caveat, and the part that is not mine to decide
|
||||
|
||||
**"Unexercised today" is not "unwanted."** The channel abstraction may have been built for a
|
||||
future that has not arrived — per-VM private channels, capability-scoped groups. Deleting it is
|
||||
a **decision**, not an observation, and it belongs to Captain Bob.
|
||||
|
||||
Two honest qualifications on the evidence:
|
||||
|
||||
- §XXII.2's lesson applies in weakened form. Capsules are birthed by name from runtime strings,
|
||||
which defeats grep; **FORTH words are not** — a word is invoked by its literal text, so this
|
||||
search is far more reliable than the capsule-reachability search that nearly deleted the
|
||||
`init-l8-*` family. **But a human can still type `CH-REQUEST` at a REPL**, and no grep sees
|
||||
that.
|
||||
- The negotiation machinery is *described* in `MANIFEST.md` as though live. That is the same
|
||||
class of stale-documentation problem §XIII.2 found for block 4055 — **another entry for item
|
||||
13's sweep.**
|
||||
|
||||
**Recommendation: build kernel-Hermes for one broadcast membership and no negotiation, and keep
|
||||
the FORTH channel words in the Category B strip until something asks for them.** If per-VM
|
||||
channels are wanted later, they are a clean addition to a working arbiter rather than a
|
||||
speculative port into a new one.
|
||||
|
||||
### XXXIII.6 — Effect on confidence, stated plainly
|
||||
|
||||
This was opened expecting to find the scope larger than advertised. **It is smaller**, and for
|
||||
a reason that generalizes: the FORTH layer accreted a general mechanism where the system only
|
||||
ever used a specific one. The reshuffle's value is partly that it forces that accounting.
|
||||
|
||||
**What remains genuinely hard is narrow and now named:** the heat-coupled allocator, because K
|
||||
is continuously verified and any drift is visible. **That is the piece to build first and prove
|
||||
first** — before send/deliver, before delivery hand-off, before the latch. If K holds across
|
||||
alloc/free/evict under the new arbiter, the rest is protocol plumbing.
|
||||
|
||||
**Punch list:** ⬜ **Item 27 — rule on §XXXIII.5**: does kernel-Hermes implement channel
|
||||
negotiation, or one broadcast membership? ⬜ **Item 28 — build and prove the heat-coupled
|
||||
allocator first**, verified against `fleet_conserved`, before any protocol work.
|
||||
|
||||
Reference in New Issue
Block a user