diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index 9e42d970..3f5b2fce 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -3341,3 +3341,122 @@ would have been unbuildable and identity VMs would have lost their delivery path would walk into. Examined, it is a defect the reshuffle *removes* — because the mechanism that creates it is the same FORTH messaging layer already ruled legacy. **The gap analysis found a problem that the design had already solved without noticing.** + +--- + +## XXXIII. Sizing kernel-Hermes: what actually has to be reimplemented (2026-09-19) + +**Why this section exists.** §XIV.1 ruled the FORTH messaging layer legacy and kernel-Hermes +greenfield. That was the right call, but it quietly exited this document's own scope discipline +— "a reorganization, not an invention… relocated and rewired rather than rewritten" — and +**nobody counted what the rewrite actually amounts to.** With the build trigger approaching and +confidence the stated concern, an unsized centerpiece is the wrong thing to carry into it. + +`capsules/common/messaging.4th` is 504 lines defining **85 words**. That number is the reason +to look, and it turns out to be badly misleading in the reassuring direction. + +### XXXIII.1 — The 85 words, by category + +| Category | Words | Fate in kernel C | +|---|---|---| +| **Field accessors** (`MSG-TYPE@/!`, `CH-ID@/!`, `MBR-VM@/!`, …) | ~34 | **Vanish** — they become struct members | +| **Channel abstraction** (`CH-*`) | **28** | **Mostly unexercised — see §XXXIII.2** | +| **Message core** (alloc/free, send, deliver, tick, reap, ack/nack, redeliver) | ~20 | **Must survive. The real work.** | +| **Member list** (`MBR-*`) | 7 | Collapses to a small membership list | +| **Events** (`EVENT-EMIT/WAIT/DRAIN`) | 3 | **Dead — see §XXXIII.3** | +| **Elevation** (`ELEVATE-*`, `SEND-ELEVATE-REQUEST`) | 5 | **Live. Must survive.** | +| **Status/diagnostics** (`MSG-USED`, `CH-USED`, `MSG-STATUS`) | 3 | Cheap, keep | + +### XXXIII.2 — Finding: the channel abstraction serves exactly one static channel + +**28 of the 85 words are channel machinery.** Traced across `capsules/`, `src/` and +`experiments/` for callers outside `messaging.4th` itself: + +| Word | Live callers outside `messaging.4th` | +|---|---| +| `CH-REQUEST` | **none** — only `capsules/MANIFEST.md` (documentation) | +| `CH-ACCEPT` | **none** — documentation only | +| `CH-CONFIRM` | **none** — documentation only | +| `CH-CLOSE` | **none** — documentation only | +| `CH-MINT-ID` | **none** — documentation only | +| `CH-ADD-MBR` | **3** — the only live channel operation in the system | + +**The entire `CH-NEGOTIATING → CH-OPEN → CH-CLOSING` handshake has no caller anywhere.** The +whole live channel lifecycle is: Hermes creates `COMMON-CH` once at birth, adds itself and Hera +(`hermes/init.4th:20-21`), Artemis adds itself (`artemis/init.4th:501`). **One channel, three +members, created at boot and never negotiated, never closed, never reaped.** + +So `CH-ARENA`, `CH-MAX 16`, `CH-ALLOC`, `CH-FREE-NODE`, `CH-FIND-FREE-SLOT`, `CH-COOL-ALL`, +`CH-TOTAL-HEAT`, `CH-REAP-SAFE`, per-channel Stadium heat accounting and the three-state +machine all exist to support a generality **nothing has ever used**. Console proxies explicitly +opt out of channels entirely (`capsule_console.c:23`). + +**Kernel-Hermes does not need a channel subsystem. It needs one broadcast membership list.** + +### XXXIII.3 — Finding: the event words die with `process.4th` + +`EVENT-EMIT`, `EVENT-WAIT`, `EVENT-DRAIN` have exactly one live caller — **`capsules/process.4th`, +which §XIII.2 established is `EXEC`'d nowhere.** The only other reference is `MANIFEST.md`. + +They go out with it, along with `SPAWN-EVENT` (§I.4: grepped tree-wide, zero consumers, "an +unwired placeholder"). **Do not port the event layer.** + +### XXXIII.4 — What must actually survive + +Stripped of the above, kernel-Hermes's real surface is: + +1. **Message allocation and release, coupled to Stadium heat.** `MSG-ALLOC` pulls `Q.SLOT` from + the *caller's own* reservoir and rolls back on refusal; `MSG-FREE-NODE` returns it via + `STADIUM-EVICT`. **This is the hard part, and the one that cannot be approximated** — + §XV.4 established that K conservation is the only thing that must survive a death, and + `fleet_conserved` verifies it continuously. +2. **Send / deliver / deliver-all / tick / reap / ack / nack / redeliver-nacked** — the core + protocol, ~9 words of real logic. +3. **One broadcast membership list** (replacing 28 words of channel machinery). +4. **The elevation path** — `SEND-ELEVATE-REQUEST` / `ELEVATE-GRANT`, live in + `zuse-eligibility.4th` (loaded at boot by `init.4th`) and `mama_forth_words.c`. **Must + survive; it is the word-ACL elevation ask carried to Zuse.** +5. **Status words**, cheap and worth keeping for the same reason §XXVIII.1 gives: a subsystem + that emits nothing by default cannot be debugged. + +**Roughly half the file is accessors that become struct fields, and another third is +generality with no caller. The genuinely new C is the heat-coupled allocator plus about nine +protocol words.** That is a much smaller thing than "reimplement 504 lines of messaging," and +it is the first honest estimate this document has had. + +### XXXIII.5 — The caveat, and the part that is not mine to decide + +**"Unexercised today" is not "unwanted."** The channel abstraction may have been built for a +future that has not arrived — per-VM private channels, capability-scoped groups. Deleting it is +a **decision**, not an observation, and it belongs to Captain Bob. + +Two honest qualifications on the evidence: + +- §XXII.2's lesson applies in weakened form. Capsules are birthed by name from runtime strings, + which defeats grep; **FORTH words are not** — a word is invoked by its literal text, so this + search is far more reliable than the capsule-reachability search that nearly deleted the + `init-l8-*` family. **But a human can still type `CH-REQUEST` at a REPL**, and no grep sees + that. +- The negotiation machinery is *described* in `MANIFEST.md` as though live. That is the same + class of stale-documentation problem §XIII.2 found for block 4055 — **another entry for item + 13's sweep.** + +**Recommendation: build kernel-Hermes for one broadcast membership and no negotiation, and keep +the FORTH channel words in the Category B strip until something asks for them.** If per-VM +channels are wanted later, they are a clean addition to a working arbiter rather than a +speculative port into a new one. + +### XXXIII.6 — Effect on confidence, stated plainly + +This was opened expecting to find the scope larger than advertised. **It is smaller**, and for +a reason that generalizes: the FORTH layer accreted a general mechanism where the system only +ever used a specific one. The reshuffle's value is partly that it forces that accounting. + +**What remains genuinely hard is narrow and now named:** the heat-coupled allocator, because K +is continuously verified and any drift is visible. **That is the piece to build first and prove +first** — before send/deliver, before delivery hand-off, before the latch. If K holds across +alloc/free/evict under the new arbiter, the rest is protocol plumbing. + +**Punch list:** ⬜ **Item 27 — rule on §XXXIII.5**: does kernel-Hermes implement channel +negotiation, or one broadcast membership? ⬜ **Item 28 — build and prove the heat-coupled +allocator first**, verified against `fleet_conserved`, before any protocol work.