FABRIC-3.5.md §XIX: the third Tripod leg is named Hestia

The Tripod is Hera, Artemis, Hestia. 99 occurrences renamed; three
verbatim quotations deliberately left saying Console.

Records the naming convention, which had never been written down and was
being re-litigated for want of it: a Greek deity name, evocative rather
than literal. Captain Bob's reasoning, and it generalizes -- Hera and
Hermes are close fits, Artemis for block storage and freemap arbitration
is a loose one that has never caused anyone a problem. Fidelity was never
the standard.

antiprosopos was considered first and rejected for being the wrong kind
of word: a common noun straining for literal accuracy, which is the
opposite of how the other three work. Hestia is a deity, is evocative --
the hearth is the fixed centre where everyone gathers, which is what a
bind point is -- and carries an incidental that was not the reason for
choosing it: Hestia is the one who never leaves, which is the pinned
session model FABRIC-2 §H.1 already describes. It also retires both costs
the longer name carried, restoring the pattern fully and cutting twelve
characters of unusual spelling to six in a path where a name mismatch
fails silently.

The rename itself is structural rather than cosmetic. §XVII.1 found three
distinct things all called console, and that collision is what led
§XIII.5 to the wrong conclusion about whether a singular Console existed.
"Hestia owns console.c" is unambiguous in a way "Console owns console.c"
cannot be.

Deliberately narrow: the HAL stays console.c, the proxies stay console
proxies, and CONSOLE-ATTACH keeps its name since CLAUDE.md's rule against
modifying a registered tested word applies with more force to renaming
one. Keeps the ~user suffix question separate and still open as item 3,
with the buffer analysis recorded so the two are not conflated later.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
This commit is contained in:
Claude
2026-09-19 09:55:45 +00:00
parent 38735e52c2
commit 7a9a8ed698
+219 -95
View File
@@ -2,7 +2,7 @@
**Status:** Standalone working document, opened 2026-09-18 by direct instruction ("we write
this in `FABRIC-3.5.md` as its own document, it's this important"). Topic: **relocating Hermes
into the kernel, reconstituting the Tripod as Hera/Artemis/Console, generalizing `BIRTH`, and
into the kernel, reconstituting the Tripod as Hera/Artemis/Hestia, generalizing `BIRTH`, and
adopting one fleet-wide failure/recovery ladder.**
**Why 3.5 and not 4, and why not a section of 3.** `FABRIC-4.md` is explicitly the
@@ -128,7 +128,7 @@ in full:
**This is the single most important pre-existing fact in this document.** §VI is not a
redesign of `BIRTH`; it is a change to which VMs get it registered, plus an inheritance rule.
### I.6 — Console already has a real bind mechanism, built and live-verified
### I.6 — Hestia already has a real bind mechanism, built and live-verified
Per §XXXII.2, closed 2026-09-16: `CONSOLE-ATTACH ( name-c name-u -- ok? )` exists, is a plain
unconditional primitive (deliberately *not* an identity capability bit — that was tried and
@@ -172,8 +172,8 @@ gravity is already partly there.
Hermes stops being a peer VM on the Stadium floor and becomes a kernel-resident arbiter
between the floor and the HAL. It stops being a *client* of ACL-checked, Hermes-routed
messaging and becomes the routing and arbitration layer itself. The Tripod — which was Hera,
Hermes, Artemis — is reconstituted as **Hera, Artemis, Console**, with Artemis keeping its
existing storage/block-arbitration role and Console taking the vacated third slot. Console's
Hermes, Artemis — is reconstituted as **Hera, Artemis, Hestia**, with Artemis keeping its
existing storage/block-arbitration role and Hestia taking the vacated third slot. Hestia's
own role widens from owning the drawing fabric to being the **bind point** where users and
agent VMs (the GPIO VM of `FABRIC-4.md` §2, future networking VMs) attach. `BIRTH` becomes a
general primitive any VM with standing may invoke, with authority bounded by inheritance
@@ -261,12 +261,12 @@ test.
---
## IV. The Tripod reconstituted: Hera, Artemis, Console
## IV. The Tripod reconstituted: Hera, Artemis, Hestia
### IV.1 — Decided (Captain Bob, 2026-09-18)
Tripod = **Hera, Artemis, Console.** Artemis keeps its existing role (storage/block
arbitration) unchanged. Console takes the slot Hermes vacates.
Tripod = **Hera, Artemis, Hestia.** Artemis keeps its existing role (storage/block
arbitration) unchanged. Hestia takes the slot Hermes vacates.
### IV.2 — The "never renumbered" collision. Open, needs a ruling.
@@ -279,10 +279,10 @@ arbitration) unchanged. Console takes the slot Hermes vacates.
being renumbered. Hermes leaving index 1 forces a choice, and the existing comment forecloses
the laziest option:
1. **Console takes index 1.** Tidy, preserves the "Tripod occupies 0/1/2" shape, and requires
1. **Hestia takes index 1.** Tidy, preserves the "Tripod occupies 0/1/2" shape, and requires
no identity renumbering — but it silently redefines what slot 1 *means*, and
`artemis:init.4th`'s dependence on the numbering is on 2, not 1, so it may be survivable.
2. **Index 1 is retired; Console takes a fresh slot.** Honest, costs a slot out of 16, and
2. **Index 1 is retired; Hestia takes a fresh slot.** Honest, costs a slot out of 16, and
leaves a permanent hole that needs a comment explaining itself forever.
3. **The routing table stops being a FORTH array at all**, because §III moved routing into the
kernel — in which case this question dissolves into §III.4's arena question and should not
@@ -293,11 +293,11 @@ matters: answering IV.2 before III.4 risks ratifying a table that the kernel mov
---
## V. Console's role expands: the bind point
## V. Hestia's role expands: the bind point
### V.1 — Decided (Captain Bob, 2026-09-18)
Beyond owning the drawing fabric, Console becomes **the bind point for users and agent VMs** —
Beyond owning the drawing fabric, Hestia becomes **the bind point for users and agent VMs** —
GPIO VM, future networking VMs, and whatever follows. The attach point that was previously
implicit or undecided now lives here, explicitly.
@@ -321,13 +321,13 @@ different shape wearing the same word.
2. **Does binding an agent VM touch `g_wirebind_attached_username`?** It must not — §I.7. State
this as an explicit invariant in whatever implements it, exactly as §XXXII.2 required of
unattended birth.
3. **Is Console's bind role ACL-gated, and if so where?** Per `.claude/CLAUDE.md`'s hard rule
3. **Is Hestia's bind role ACL-gated, and if so where?** Per `.claude/CLAUDE.md`'s hard rule
and §XXXII.2 Q3's correction: policy belongs in `ACL.4th`, never in C. The shape is
`' CONSOLE-ATTACH ACL-PIN` (or a sibling word's equivalent) in `ACL.4th`, not a C-side
capability check — and specifically **not** a `vm_identity_has_cap()` gate, which §XXXII.2
proved unreachable because `identity.installed` is 0 for Hera/Hermes/Artemis and for every
console-proxy VM.
4. **Does Console-as-bind-point survive Console being a Tripod member?** A Tripod VM is pinned
4. **Does Hestia-as-bind-point survive Hestia being a Tripod member?** A Tripod VM is pinned
and born at boot (`session_register()`/`session_set_pinned()`, per `FABRIC-2.md` §H.12
step 4; "pinned sessions never leave," §H.1 — **cited from `.claude/CLAUDE.md`'s and §XX's
references, not re-read for this document; verify before relying on it**). Whether the
@@ -412,13 +412,13 @@ A single escalation shape, applied consistently across the fleet — current VMs
3. **Fail brutally once genuinely exhausted.** No lingering, no partial states. Once recovery
options are spent the failure is **fast and total, not a slow degrade.**
The value here is uniformity: one shape for Hera, Hermes, Console and every future VM, instead
The value here is uniformity: one shape for Hera, Hermes, Hestia and every future VM, instead
of bespoke handling per component.
### VII.2 — `SOS` as a standard message type
**Decided:** `SOS` is a standard message type **any** VM can emit — not specific to any one
component. It applies to non-Tripod VMs and to two of the three Tripod VMs (Hera and Console).
component. It applies to non-Tripod VMs and to two of the three Tripod VMs (Hera and Hestia).
Hermes is the exception, for a structural reason — §VIII.
**Grounding and open points:**
@@ -580,7 +580,7 @@ execution order.
9. ⬜ Assign `SOS` a message-type number deliberately (§VII.2), with a named consumer.
10. ⬜ Specify the sinking semaphore's mechanism and the clean-shutdown routine (§VIII.3).
11. ⬜ Answer §IX.3: what declares a birther dead, and what fleet shutdown means concretely.
12. ⬜ **NEW 2026-09-18 (§XIII.5).** Rule on whether the Console Tripod leg is a *new*
12. ⬜ **NEW 2026-09-18 (§XIII.5).** Rule on whether the Hestia Tripod leg is a *new*
singleton, distinct from today's plural per-attach console proxies. **Gates §IV.1 and
§IV.2** — sits above the slot-numbering question, not beside it.
13. ⬜ **NEW 2026-09-18 (§XIII.2), not part of this reshuffle.** Authorize a
@@ -617,12 +617,12 @@ build-time check.**
- **Item 18 (§XVI.7)** — if Hera is already dead, nobody performs the halt. Proposed shape (an
empty floor as a kernel-observable condition) is **analysis, not a ruling.**
§XIII.5's proposed Console resolution shape remains **analysis, not a ruling.** §XIV.4's and
§XIII.5's proposed Hestia resolution shape remains **analysis, not a ruling.** §XIV.4's and
§XIV.5's proposals were both superseded by §XV.4 and §XV.3 respectively.
What **is** decided, all by Captain Bob on 2026-09-18 and recorded in §III.1, §IV.1, §V.1,
§VI.1, §VII.1, §VII.2, §VIII.1 and §IX.1: Hermes goes into the kernel and becomes the arbiter
rather than a client; the Tripod becomes Hera/Artemis/Console; Console becomes the bind point;
rather than a client; the Tripod becomes Hera/Artemis/Hestia; Hestia becomes the bind point;
`BIRTH` is general with authority bounded by inheritance; the fleet shares one
gentle→from-scratch→brutal ladder; `SOS` is a standard message type with Hermes excepted via a
sinking semaphore; and a failed birther's authority is never provisionally handed off.
@@ -706,7 +706,7 @@ membership changes (§IV.1):
1. **`capsule_birth.c:793-796`** — `is_fleet_foundation` is literally
`vm_name_prefix_eq_nocase(capsule_name, "Hera") || ... "Hermes" || ... "Artemis"`. It gates
`StadiumPatronHeader` setup and the `session_register()`/`session_set_pinned()` pinning
calls. **This is the Tripod, encoded as a string test.** Swapping Hermes for Console is a
calls. **This is the Tripod, encoded as a string test.** Swapping Hermes for Hestia is a
one-line change here — and that single line is what makes a VM pinned.
2. **`kernel_main.c:864-874`** — `vm_interpret(mama, "S\" Hermes\" BIRTH")` plus a
`capsule_vm_find_by_name_nocase("Hermes", ...)` liveness check and console banner. The
@@ -743,43 +743,43 @@ rather than from the source. All three check out; §V.3.4 and §VII.4 may now be
`fleet_k_q48`/`fleet_conserved` CSV columns. §VII.4's warning stands as written: a brutal
death must still return what it held, or it breaks a continuously-verified invariant.
### XIII.5 — New finding, and the most consequential of this pass: Console today is plural, ephemeral, and capsule-less
### XIII.5 — New finding, and the most consequential of this pass: Hestia today is plural, ephemeral, and capsule-less
**This was not known to §IV or §V when they were written, and it changes what §IV.1 is asking
for.** Traced in `capsule_console.c`:
- **Console has no capsule.** `capsules/` contains `hermes/` and `artemis/` directories but
- **Hestia has no capsule.** `capsules/` contains `hermes/` and `artemis/` directories but
**no `console/`**. A console VM's entire personality is a 3-line C string literal,
`CONSOLE_IDENTITY_SRC` (`capsule_console.c:28-31`): `Block 4997`, `S" common:messaging.4th"
EXEC`, `MSG-CD-INIT`. That is all of it.
- **Console is deliberately *not* on the routing table.** The source comment is explicit: "No
- **Hestia is deliberately *not* on the routing table.** The source comment is explicit: "No
`COMMON-CH` subscription: a console's own traffic is direct 1:1 with its paired user VM
(`CONSOLE-CMD-EVENT`), not broadcast, so there's no need to resolve an index in Hermes's own
routing table for it."
- **Console is plural and per-attach.** `capsule_console_birth(const char *console_name, ...)`
- **Hestia is plural and per-attach.** `capsule_console_birth(const char *console_name, ...)`
is called from three sites (`capsule_wirebind.c:245`, `mama_forth_words.c:1591` and `:2015`)
and mints a fresh heap-built single-entry capsule directory each time. There are as many
console VMs as there are attachments.
**Consequence.** Hera, Hermes and Artemis are singular, pinned, born-at-boot, capsule-backed,
routing-table-indexed. Console today is **none of those five things.** So §IV.1's "Console
routing-table-indexed. Hestia today is **none of those five things.** So §IV.1's "Hestia
takes the vacated third slot" is **not** a relocation of an existing pinned VM — as stated it
would create a Console that does not currently exist. That is worth naming plainly, because it
would create a Hestia that does not currently exist. That is worth naming plainly, because it
is the one place this document's "reorganization, not invention" scope discipline is genuinely
strained.
> **CORRECTED 2026-09-18 by §XVII — the paragraph above compares the wrong object.** The
> singular pinned Console *does* already exist: it is the HAL drawing fabric
> singular pinned Hestia *does* already exist: it is the HAL drawing fabric
> (`hal/console.c`, `framebuffer.c`, `vt100.c`, `font_8x16.c`), already singular, permanent
> and kernel-resident — it simply has no VM face and no owner. The per-attach proxies this
> section measured against are what *binding produces*, not what Console *is*. The scope
> section measured against are what *binding produces*, not what Hestia *is*. The scope
> discipline is therefore **not** strained: the leg is an existing singleton given an owner,
> and the only genuinely new artifact is a capsule personality. The resolution shape proposed
> below was right; this justification for it was wrong. **RATIFIED — see §XVII.2.** Left in
> place, not rewritten.
**The shape that resolves it without inventing anything** — offered as analysis, **not
ratified, Captain Bob's call**: distinguish **Console** (singular, pinned, capsule-backed, the
ratified, Captain Bob's call**: distinguish **Hestia** (singular, pinned, capsule-backed, the
Tripod leg — owns the drawing fabric and is the bind point, per §V.1) from **console proxies**
(plural, ephemeral, per-attach — exactly what `capsule_console_birth()` mints today,
unchanged). The Tripod leg is new; the proxies are untouched. This reading makes §V.1's "bind
@@ -787,9 +787,9 @@ point" precise: the leg is what you bind *to*, the proxy is what binding *produc
### XIII.6 — §V and §VI are load-bearing for each other, which neither section noticed
If Console is the bind point (§V.1), it is Console that must mint console proxies — and
If Hestia is the bind point (§V.1), it is Hestia that must mint console proxies — and
minting a VM is `BIRTH`. Today all three `capsule_console_birth()` call sites run in Hera's or
the caller's context. **So "Console is the bind point" cannot be implemented while `BIRTH`
the caller's context. **So "Hestia is the bind point" cannot be implemented while `BIRTH`
remains Hera-exclusive; it requires §VI.1's generalization.** They are one change, not two.
Mechanically this already works, which strengthens both: two of the three call sites pass
@@ -799,7 +799,7 @@ Hera's). That matches §I.5's finding that `capsule_birth_baby()` treats `stadiu
generically as "whoever is birthing this VM." **Parentage is already generic; only
registration is not.**
This also supplies the first concrete answer to §VI.4's open "what is standing": Console needs
This also supplies the first concrete answer to §VI.4's open "what is standing": Hestia needs
`BIRTH` to do its declared job, so it has standing by role. That is evidence for reading (a)
(standing = having `BIRTH` registered), not a ruling.
@@ -809,7 +809,7 @@ Nothing found here dislodges §III.4 as the root dependency. Two adjustments:
- **§III.3 is cheaper than §I.2 implied** (3 live sites, not a broad web) and can be scoped as
soon as §III.4 lands.
- **§IV.1 needs a prior ruling that §IV.2 does not cover**: is the Tripod's Console leg a *new*
- **§IV.1 needs a prior ruling that §IV.2 does not cover**: is the Tripod's Hestia leg a *new*
singleton distinct from today's proxies (§XIII.5)? That question sits *above* the slot
numbering, not beside it. **Added to the punch list as item 12.**
@@ -818,7 +818,7 @@ Nothing found here dislodges §III.4 as the root dependency. Two adjustments:
- ✅ **Item 1 CLOSED** — inventory complete (§XIII.1), 14 FORTH sites + 3 C sites + 1 CSV
schema site; §I.2 corrected.
- ✅ **Item 2 CLOSED** — all three citations verified against source (§XIII.4).
- ⬜ **Item 12, NEW** — rule on §XIII.5: is the Console Tripod leg a new singleton, distinct
- ⬜ **Item 12, NEW** — rule on §XIII.5: is the Hestia Tripod leg a new singleton, distinct
from today's per-attach proxies? **Gates §IV.1 and §IV.2.**
- ⬜ **Item 13, NEW, not part of this reshuffle** — authorize a `capsules/MANIFEST.md`
correction pass for the two false claims in §XIII.2 (block 4055 "immutable ABI"; block 2049
@@ -1132,7 +1132,7 @@ death, turn order, conservation — is physics rather than policy.
- ⬜ **Item 10** (§VIII.3 — the sinking semaphore's mechanism, the clean-shutdown routine's
definition, and whether the window is bounded) — still open, and now the largest remaining
design item.
- ⬜ **Item 12** (§XIII.5 — is the Console Tripod leg a new singleton, distinct from today's
- ⬜ **Item 12** (§XIII.5 — is the Hestia Tripod leg a new singleton, distinct from today's
per-attach proxies?) — still open, and still gates §IV.
**Remaining open: items 9, 10, 12, 16.** Item 10 is the substantive one; 9 is downstream of it,
@@ -1256,7 +1256,7 @@ unallocated gaps, 10 is next in sequence).
mechanism exists on all three architectures.
- 🔶 **Item 9 (§VII.2) — HALF-ANSWERED** (§XVI.5). Consumer action defined for the two
fleet-fatal cases. Open: whether a peer `SOS` is actionable or advisory, plus the number.
- ⬜ **Item 12 (§XIII.5)** — Console Tripod leg: new singleton or not? Unchanged; still gates §IV.
- ⬜ **Item 12 (§XIII.5)** — Hestia Tripod leg: new singleton or not? Unchanged; still gates §IV.
- ⬜ **Item 16 (§XV.4)** — implementation check: teardown paths must reach `STADIUM-EVICT`.
- ⬜ **Item 17, NEW** (§XVI.2) — decide whether Hera's suicide replaces `BYE`'s cold-restart or
becomes a separate word. Small, but it changes a live registered word either way.
@@ -1279,12 +1279,12 @@ authority flowing only down the birth graph (§IX.2) while still terminating.
## XVII. Item 12 CLOSED — "Console" already exists as a singleton; it just has no VM face
Taken as closing **item 12** (§XIII.5's Console-singleton question), the largest remaining
Taken as closing **item 12** (§XIII.5's Hestia-singleton question), the largest remaining
design item and the one gating §IV.
**§XIII.5 framed this wrongly, and the error is worth naming before the answer.** It compared
the Tripod legs against `capsule_console_birth()`'s per-attach proxies, found Console "plural,
ephemeral and capsule-less," and concluded that a singular pinned Console "does not currently
the Tripod legs against `capsule_console_birth()`'s per-attach proxies, found Hestia "plural,
ephemeral and capsule-less," and concluded that a singular pinned Hestia "does not currently
exist" — so §IV.1 would be creating one, straining the reorganization-not-invention discipline.
**That comparison picked the wrong object.** Traced 2026-09-18: there are three distinct things
called "console" in this kernel, not two.
@@ -1301,19 +1301,19 @@ called "console" in this kernel, not two.
`console_get_vm_name()` (`include/starkernel/console.h:190-191`), swapped by every dispatch
in the "switch, do work, switch back" pattern.
### XVII.2 — RULING: the Console Tripod leg is (1), given a VM face. Not a promoted proxy.
### XVII.2 — RULING: the Hestia Tripod leg is (1), given a VM face. Not a promoted proxy.
The singular, permanent Console this design wants **already exists in substance** — it is the
The singular, permanent Hestia this design wants **already exists in substance** — it is the
drawing fabric. What it lacks is an *owner*: today the fabric is an ownerless kernel singleton
that any VM reaches into through a global. So §IV.1's "Console takes the vacated third slot"
that any VM reaches into through a global. So §IV.1's "Hestia takes the vacated third slot"
is **not** the invention §XIII.5 feared. It is giving an existing singleton a VM face.
That resolves the tension cleanly and without inventing anything:
- **The Console leg is singular, pinned and born-at-boot** — because the fabric it owns already
- **The Hestia leg is singular, pinned and born-at-boot** — because the fabric it owns already
is all three.
- **The proxies are untouched.** They stay plural and ephemeral, which is correct: they are
what *binding produces*, not what Console *is* (§XIII.5's own phrasing, now properly
what *binding produces*, not what Hestia *is* (§XIII.5's own phrasing, now properly
grounded).
- **§V.1's "bind point" falls out rather than being asserted.** The VM that owns the fabric is
necessarily what a user or agent VM binds *to*.
@@ -1339,31 +1339,31 @@ Bob's reshuffle that this document had not previously identified.
Consequences of the ruling, so they are not discovered late:
- **Console needs a capsule personality.** `capsules/console/init.4th` — a new directory beside
- **Hestia needs a capsule personality.** `capsules/hestia/init.4th` — a new directory beside
`hermes/` and `artemis/`. This is the one genuinely new artifact, and it is a capsule, not a
mechanism.
- **`is_fleet_foundation` changes membership** (`capsule_birth.c:793-796`): the name-prefix
triple becomes Hera / Artemis / Console. That single line is what makes a VM pinned
(§XIII.3), so it is also what makes Console a Tripod leg.
- **`kernel_main.c:865`'s `S" Hermes" BIRTH` becomes Console's birth**, and the switch-signal
triple becomes Hera / Artemis / Hestia. That single line is what makes a VM pinned
(§XIII.3), so it is also what makes Hestia a Tripod leg.
- **`kernel_main.c:865`'s `S" Hermes" BIRTH` becomes Hestia's birth**, and the switch-signal
registration at `:1007` follows it.
- **The DoE CSV schema changes** — `doe_log.c`'s six Tripod-named columns (§XIII.3). Still the
expensive consequence, still not to be resolved by quietly renaming a column.
- **Console must have `BIRTH` registered** (§XIII.6): binding mints a proxy, and minting is
- **Hestia must have `BIRTH` registered** (§XIII.6): binding mints a proxy, and minting is
`BIRTH`. Already settled in principle by §XV.1's "any VM can birth."
- **Console becomes the owner of the `console_set_vm_name()` discipline** — the fix in §XVII.3
- **Hestia becomes the owner of the `console_set_vm_name()` discipline** — the fix in §XVII.3
is available once there is an owner, but is **not** in this reshuffle's scope. Flagged, not
scheduled.
### XVII.5 — §IV is unblocked, and §XIII.5's marker corrected
With item 12 closed, **§IV.1 (Tripod = Hera/Artemis/Console) stands as ratified with no
With item 12 closed, **§IV.1 (Tripod = Hera/Artemis/Hestia) stands as ratified with no
outstanding objection**, and §IV.2 remains dissolved per §XIV.2. §XIII.5's "this is the one
place the scope discipline is genuinely strained" no longer holds and is corrected there.
### XVII.6 — Punch list after this ruling
- ✅ **Item 12 — CLOSED** (§XVII). The Console leg is the existing drawing-fabric singleton
- ✅ **Item 12 — CLOSED** (§XVII). The Hestia leg is the existing drawing-fabric singleton
given a VM face; proxies unchanged. §IV unblocked.
- 🔶 **Item 9** — half-answered (§XVI.5): open is whether an ordinary peer's `SOS` is actionable
or advisory, plus the number allocation.
@@ -1381,19 +1381,19 @@ ruled.
---
## XVIII. The Console component, designed in full (2026-09-18)
## XVIII. The Hestia component, designed in full (2026-09-18)
§XVII settled *what* the Console leg is. This section designs the component. Everything below
§XVII settled *what* the Hestia leg is. This section designs the component. Everything below
traced 2026-09-18 against `e56974e`; decisions are marked, proposals are marked, and open
questions are marked.
### XVIII.1 — Console is three layers, and only the middle one is new
### XVIII.1 — Hestia is three layers, and only the middle one is new
| Layer | What | Where it lives today | Change |
|---|---|---|---|
| **0 — the fabric** | Raw output: framebuffer, VT100, glyph raster, UART | `hal/console.c`, `framebuffer.c`, `vt100.c`, `font_8x16.c` (~98 KB C) | **None.** Stays kernel HAL. |
| **1 — Console the VM** | Tripod leg. Owns fabric *policy*, is the bind point | **Does not exist** | **New — and it is a capsule, not a mechanism.** |
| **2 — console proxies** | Per-attach relay VMs, one per bound user/agent | `capsule_console_birth()` | **None**, except their birther becomes Console. |
| **1 — Hestia the VM** | Tripod leg. Owns fabric *policy*, is the bind point | **Does not exist** | **New — and it is a capsule, not a mechanism.** |
| **2 — console proxies** | Per-attach relay VMs, one per bound user/agent | `capsule_console_birth()` | **None**, except their birther becomes Hestia. |
The design is almost entirely layer 1, and layer 1 is mostly a *relocation* of vocabulary that
already exists in the wrong dictionary (§XVIII.3).
@@ -1407,22 +1407,22 @@ already exists in the wrong dictionary (§XVIII.3).
> (`zuse_session`, `capsule_wirebind_attached_username()`) — pulling either in directly here
> would be a **real layering violation, not just a style preference.**
So **Console-the-VM may not be implemented by making `console.c` VM-aware.** Ownership flows one
way only: Console reaches *down* into the HAL; the HAL never reaches *up*.
So **Hestia-the-VM may not be implemented by making `console.c` VM-aware.** Ownership flows one
way only: Hestia reaches *down* into the HAL; the HAL never reaches *up*.
**The sanctioned pattern for the cases where the HAL does need something VM-shaped already
exists and should be reused rather than reinvented:** `console_set_user_prefix_provider()`
(`console.h:231`) — a callback that lets `repl.c` supply the "user" half of the `[user@VMName]`
prompt "without `console.c` knowing anything about VMs, sessions, or WIREBIND." Any further
HAL→Console coupling this design needs takes that shape: a registered callback, never an
HAL→Hestia coupling this design needs takes that shape: a registered callback, never an
include.
**Consequence, stated plainly:** Console's "ownership" of the fabric is by *convention,
**Consequence, stated plainly:** Hestia's "ownership" of the fabric is by *convention,
vocabulary and registration* — it is the VM that holds the drawing words — **not** by any
enforcement inside `console.c`. That is weaker than it sounds and is exactly right: it keeps
the HAL reusable and the layering intact.
### XVIII.3 — Console's dictionary: 1,051 lines of Console vocabulary currently live in Hera
### XVIII.3 — Hestia's dictionary: 1,051 lines of Hestia vocabulary currently live in Hera
**The most concrete finding in this section.** `capsules/fabric.4th`'s own header reads:
@@ -1430,48 +1430,48 @@ the HAL reusable and the layering intact.
> 45-degree cavalier orthographic projection... Raw pixel write (`PLOT`/`FB-WIDTH`/`FB-HEIGHT`)
> is C; **this capsule is the FORTH-side policy on top of it.**
It is named Console's fabric, it *is* the FORTH-side fabric policy — and it loads into **Hera's**
It is named Hestia's fabric, it *is* the FORTH-side fabric policy — and it loads into **Hera's**
dictionary (`capsules/init.4th` block 2049: `S" fabric.4th" EXEC`, `S" font.4th" EXEC`).
| Capsule | Lines | Loads into today | Should load into |
|---|---|---|---|
| `fabric.4th` | 319 | **Hera** (`init.4th` b2049) | **Console** |
| `font.4th` | 733 | **Hera** (`init.4th` b2049) | **Console** |
| `fabric.4th` | 319 | **Hera** (`init.4th` b2049) | **Hestia** |
| `font.4th` | 733 | **Hera** (`init.4th` b2049) | **Hestia** |
| `turtle.4th` | 99 | `sdk.4th` (opt-in, not boot) | unchanged — it is SDK, not fabric |
**Plus the C primitives underneath:** `PLOT`, `FB-WIDTH`, `FB-HEIGHT`
(`src/word_source/framebuffer_words.c:62-64`). Their *registration* moves to Console's word
(`src/word_source/framebuffer_words.c:62-64`). Their *registration* moves to Hestia's word
table; the implementations do not change.
**DECIDED (proposal — Captain Bob's call, but this is the direct consequence of §XVII.2):**
`fabric.4th` and `font.4th` move from `init.4th` to `capsules/console/init.4th`. This is a pure
`fabric.4th` and `font.4th` move from `init.4th` to `capsules/hestia/init.4th`. This is a pure
relocation of 1,051 lines — the single most obviously-correct edit in the whole reshuffle, and
the clearest evidence that the fabric wants an owner: it already *has* the vocabulary, just
attached to the wrong VM.
**Parity consequence** (§III.5): Hera's `dict_hash` will shrink, Console's is new. Per §XX's
**Parity consequence** (§III.5): Hera's `dict_hash` will shrink, Hestia's is new. Per §XX's
standard, the property that matters is cross-architecture identity, not an unchanging absolute.
### XVIII.4 — Console's capsule personality
### XVIII.4 — Hestia's capsule personality
`capsules/console/init.4th` — a new directory beside `hermes/` and `artemis/`, and **the one
`capsules/hestia/init.4th` — a new directory beside `hermes/` and `artemis/`, and **the one
genuinely new artifact this reshuffle creates.**
Contents, in load order:
1. `S" common:messaging.4th" EXEC` + `MSG-CD-INIT` — Console is a Tripod leg and a full
1. `S" common:messaging.4th" EXEC` + `MSG-CD-INIT` — Hestia is a Tripod leg and a full
messaging participant. **Note this differs from the proxies**, which deliberately skip
`COMMON-CH` (`capsule_console.c:23-26`: "a console's own traffic is direct 1:1 with its
paired user VM"). The *leg* subscribes; the *proxies* still do not.
2. `S" fabric.4th" EXEC` and `S" font.4th" EXEC` — per §XVIII.3.
3. Console's own bind vocabulary (§XVIII.5).
3. Hestia's own bind vocabulary (§XVIII.5).
4. A `WELCOME`/banner word, matching `hermes/init.4th`'s and `artemis/init.4th`'s shape.
**Block allocation is a real to-do, not a formality.** `mkcapsule`'s actual constraints, per
§XXXII.2's correction: block range **`[2048, 5120)`** and a hard **16-content-line-per-block**
cap (*not* the 1024-byte framing `.claude/CLAUDE.md` still describes — that doc error is
outstanding). **Block 4997 is already taken** by the proxy's own C string literal
(`capsule_console.c:28-31`), so Console's range must avoid it. Allocate against
(`capsule_console.c:28-31`), so Hestia's range must avoid it. Allocate against
`capsule-reserved.txt` and verify with `mkcapsule --lint capsules/` (§XXIV's collision
machinery covers this; it is blind to content, only to numbers).
@@ -1485,7 +1485,7 @@ machinery covers this; it is blind to content, only to numbers).
▼ ▼
WIREBIND path CONSOLE-ATTACH
│ │
└──────────► Console ◄───────────┘
└──────────► Hestia ◄───────────┘
│
BIRTH a proxy (§XV.1 makes this legal:
│ any VM may birth)
@@ -1498,9 +1498,9 @@ machinery covers this; it is blind to content, only to numbers).
closed 2026-09-16). It resolves the target's liveness *before* birthing, so a typo refuses
cleanly with no orphaned VM. **Keep it exactly as is.** The change is *who runs it*: today
the three `capsule_console_birth()` call sites run in Hera's or the caller's context
(`capsule_wirebind.c:245`, `mama_forth_words.c:1591`, `:2015`). Under this design Console is
(`capsule_wirebind.c:245`, `mama_forth_words.c:1591`, `:2015`). Under this design Hestia is
the birther.
- **This is why Console needs `BIRTH` registered** (§XIII.6) — binding *mints a proxy*, and
- **This is why Hestia needs `BIRTH` registered** (§XIII.6) — binding *mints a proxy*, and
minting is `BIRTH`. Already legal per §XV.1.
- **Mechanically this already works:** two of the three call sites pass `vm->stadium_vm_id` —
whichever VM invoked — so parentage is already generic (§I.5, §XIII.6). Only registration
@@ -1517,61 +1517,185 @@ no-bespoke-gate grounds but touches a live, bug-prone path; flagged rather than
### XVIII.6 — Headless-until-login survives, and the invariant that makes it survive
**Console the leg is born at boot. A console session is not.** These must not be conflated, or
**Hestia the leg is born at boot. A console session is not.** These must not be conflated, or
§VIII.1's ratified headless-until-login policy reopens — the exact failure §XXXII.2 warned
about for unattended birth.
**INVARIANT, to be stated in whatever code implements Console:**
**INVARIANT, to be stated in whatever code implements Hestia:**
> Console's birth at boot must not set `g_wirebind_attached_username`, must not cause
> Hestia's birth at boot must not set `g_wirebind_attached_username`, must not cause
> `sk_console_identity_present()` (`repl.c:122`) to report an identity, and must not mint a
> proxy. Console owns the fabric from boot; it presents nothing until something binds.
> proxy. Hestia owns the fabric from boot; it presents nothing until something binds.
This is the same invariant §XXXII.2 imposed on unattended identity birth, applied to a second
path. It is cheap to hold — Console births no proxy until asked — but it is exactly the kind of
path. It is cheap to hold — Hestia births no proxy until asked — but it is exactly the kind of
thing that gets violated by a well-meaning "initialise the console at startup" line.
### XVIII.7 — What Console does *not* own
### XVIII.7 — What Hestia does *not* own
Stated because a component that owns "the bind point" attracts responsibilities that belong
elsewhere, and this document has already had to defend against exactly that (§XV.3):
- **Not turn order.** Nothing owns it (§XV.3).
- **Not routing.** That is kernel-Hermes (§III), which sits *below* Console.
- **Not the lifecycle of anything but its own proxies.** Console births proxies; it does not
- **Not routing.** That is kernel-Hermes (§III), which sits *below* Hestia.
- **Not the lifecycle of anything but its own proxies.** Hestia births proxies; it does not
birth, kill, or supervise identity VMs. Authority flows down the birth graph only (§IX.2).
- **Not the prompt's user half.** That stays `repl.c`'s, supplied to the HAL via the existing
provider callback (§XVIII.2). Moving it into Console would be the layering violation
provider callback (§XVIII.2). Moving it into Hestia would be the layering violation
`console.h` explicitly names.
### XVIII.8 — Console's own failure behaviour
### XVIII.8 — Hestia's own failure behaviour
Console is a Stadium-floor VM **above** the routing layer, so §VIII.2's rule applies without an
exception: **Console emits `SOS`**; only Hermes uses the semaphore. Its clean shutdown is
Hestia is a Stadium-floor VM **above** the routing layer, so §VIII.2's rule applies without an
exception: **Hestia emits `SOS`**; only Hermes uses the semaphore. Its clean shutdown is
§XVI's: forced `blk_flush(0)`, then `BYE`.
**A pleasant property worth recording: Console's death degrades gracefully by construction.**
**A pleasant property worth recording: Hestia's death degrades gracefully by construction.**
Because layer 0 is HAL C (§XVIII.1) and ownership is by convention rather than enforcement
(§XVIII.2), a dead Console leaves the framebuffer, VT100 and UART fully functional — the fabric
(§XVIII.2), a dead Hestia leaves the framebuffer, VT100 and UART fully functional — the fabric
simply becomes ownerless again, which is precisely today's status quo. The kernel can still
print. **This is the opposite of Hermes**, whose death takes the transport with it. So the
Tripod's three legs have three genuinely different failure characters: Artemis's death costs
storage arbitration, Console's costs only fabric *policy*, Hermes's costs the transport itself —
storage arbitration, Hestia's costs only fabric *policy*, Hermes's costs the transport itself —
which is why only Hermes needed the semaphore.
### XVIII.9 — Punch list for Console
### XVIII.9 — Punch list for Hestia
Design items, in dependency order. **No code authorized.**
1. ⬜ Ratify §XVIII.3's relocation: `fabric.4th` + `font.4th` move from `init.4th` to
`capsules/console/init.4th`; `PLOT`/`FB-WIDTH`/`FB-HEIGHT` registration moves to Console.
2. ⬜ Allocate Console's block range against `capsule-reserved.txt`, avoiding 4997; verify with
`capsules/hestia/init.4th`; `PLOT`/`FB-WIDTH`/`FB-HEIGHT` registration moves to Hestia.
2. ⬜ Allocate Hestia's block range against `capsule-reserved.txt`, avoiding 4997; verify with
`mkcapsule --lint` (§XVIII.4).
3. ⬜ Decide §XVIII.5's agent-binding shape: widen the `~user` convention, or a sibling word.
**The only genuinely open design question in this section.**
4. ⬜ Confirm Console in the `is_fleet_foundation` triple (`capsule_birth.c:793-796`) and its
4. ⬜ Confirm Hestia in the `is_fleet_foundation` triple (`capsule_birth.c:793-796`) and its
birth at `kernel_main.c:865`, replacing Hermes's (§XVII.4).
5. ⬜ Handle the `doe_log.c` CSV schema change (§XIII.3) — still the expensive consequence.
6. ⬜ State §XVIII.6's headless invariant in the implementation.
7. ⬜ **Not in this reshuffle:** the `console_set_vm_name()` ownerless-global fix (§XVII.3) is
now *available* once Console exists, but remains out of scope. Flagged, not scheduled.
now *available* once Hestia exists, but remains out of scope. Flagged, not scheduled.
---
## XIX. RULING: the third Tripod leg is named Hestia, not Console (Captain Bob, 2026-09-19)
**The Tripod is: Hera, Artemis, Hestia.** Applied throughout this document — 99 occurrences
renamed; three verbatim quotations deliberately left saying "Console" (§XIX.4).
### XIX.1 — The naming convention, stated so it stops being re-litigated
`antiprosopos` (Gk. representative/delegate) was considered first and **rejected, on Captain
Bob's reasoning, which is the correct reasoning and is recorded here because it generalizes:**
> "Now this is just a name of a Greek mythos god, it doesn't have to carry full/perfect
> [fidelity], it's only a contextual display... After all, Artemis isn't exactly the perfect
> name for a memory manager/storage manager either."
That is the convention, and it had never been written down: **a Greek deity name, evocative
rather than literal.** Checked against what exists — Hera (queen/mother → the Mama VM) is a
close fit, Hermes (messenger → messaging) is the closest, and **Artemis (huntress, wilderness →
block storage and freemap arbitration) is a loose fit that has never caused anyone a
problem.** Fidelity was never the standard.
`antiprosopos` failed on being the wrong *kind* of word: a common noun straining for literal
accuracy, which is the opposite of how the other three work. `Hestia` — goddess of the hearth —
is a deity, is evocative (the hearth is the fixed centre of the household, where everyone
gathers), and carries a pleasing incidental: **Hestia is the one who never leaves.** That maps
onto the pinned-session model (`FABRIC-2.md` §H.1, "they never leave, permanently") without
having been chosen for it.
**Two costs that `antiprosopos` carried are retired by this choice, not merely tolerated:**
- **Pattern.** `antiprosopos` is Greek vocabulary, not a deity — it half-joined the set.
`Hestia` joins it fully.
- **Typo surface.** Twelve characters of unusual spelling, in a path where a VM-name mismatch
fails *silently* (§XIX.5). `Hestia` is six, comparable to `Hermes` and `Artemis`.
### XIX.2 — Why renaming at all is structural, not cosmetic
§XVII.1 found three distinct things in this kernel all called "console" — the HAL fabric, the
VM, and the per-attach proxies — and that collision is exactly what led §XIII.5 to the wrong
conclusion about whether a singular Console existed. Naming the VM separately resolves it by
construction:
| Layer | Name after this ruling |
|---|---|
| 0 — the drawing fabric (HAL C) | **the console** — `console.c`, unchanged |
| 1 — the Tripod leg, owns the fabric | **Hestia** |
| 2 — per-attach relay VMs | **console proxies** — unchanged |
"Hestia owns `console.c`" is unambiguous in a way "Console owns `console.c`" cannot be. This
document has already paid once for that ambiguity; the rename is what stops it recurring.
### XIX.3 — What is NOT renamed
The ruling names a VM. It does not rename the subsystem:
- **The HAL stays `console.c`/`console.h`** and every `console_*()` function. Renaming them
would be churn across ~98 KB of C for no gain, and would re-create the confusion by making
the HAL sound like the VM.
- **`capsule_console_birth()` / `CONSOLE_IDENTITY_SRC` stay** — they mint console proxies,
still called console proxies.
- **`CONSOLE-ATTACH` stays.** `.claude/CLAUDE.md`'s "never modify a registered, tested word"
applies with more force to *renaming* one, and the word remains accurate: it attaches a
console. **Recommended, not ruled.**
- **`CONSOLE-CMD-EVENT` and `sk_console_identity_present()` stay** — both are layer 0/2
business (a console session), not Hestia's (§XVIII.6).
**Net code-visible rename surface:** the VM's registry name, its capsule directory
(`capsules/hestia/init.4th`), and the places the Tripod is enumerated (§XIX.6).
### XIX.4 — Three quotations deliberately still say "Console"
Quoted source is not silently edited to match a later decision:
1. **Line 26** — the opening brief's own wording ("Hera lifecycle/ACL, Console framebuffer").
2. **§XVIII.3** — `capsules/fabric.4th`'s verbatim header, "Console drawing-fabric coordinate
machinery." That is what the file says *today*; it changes when the file is edited, and
**that edit belongs to the §XVIII.3 relocation, not to this ruling.**
3. **§XVII's heading** — a meta-reference to the name itself, which is that section's subject.
### XIX.5 — `~user` is a separate question, unaffected
`antiprosopos` was first raised as a replacement for the `~user` registry-name suffix. **That
remains punch item 3** (§XVIII.5), and the Hestia ruling does not touch it. Recorded so the two
never get conflated:
Traced 2026-09-18 — as a *suffix* it does not fit the buffers. `VM_NAME_MAX` is 64 and
`USER_IDENTITY_USERNAME_MAX` 32, so the name fits in principle, but every construction buffer
is sized `+ 8`, tuned exactly to `"~user"` (5 chars + NUL = 6): `capsule_wirebind.c:222` (=40),
`mama_forth_words.c:1855`/`:1991` and `repl.c:1243` (=72), each guarding on a hardcoded `+ 6`.
A 14-byte suffix would not overflow them — it would make them **refuse**, silently failing to
bind usernames over 26 characters and registry names over 58. Six `memcpy` sites and five
guards hardcode that `6`, and `FABRIC-3.md` §XXVI was itself a truncation fix.
**And it would not answer item 3 regardless:** a GPIO VM is neither a user nor a human's
representative. The structural fix is making the suffix a property of the *binding*; settle
that first and land any suffix rename inside it, since the same eleven sites are touched either
way.
### XIX.6 — Edit surface
All were already edit sites for the Tripod membership change (§XVII.4); the rename changes the
string, not the count:
- `capsule_birth.c:793-796` — `is_fleet_foundation`'s prefix triple becomes
Hera / Artemis / **Hestia** (matched by `vm_name_prefix_eq_nocase`, as today).
- `kernel_main.c:865` — `S" Hestia" BIRTH`; the liveness check and the switch-signal
registration at `:1007` follow.
- `capsules/hestia/init.4th` — the new capsule directory (§XVIII.4).
- `doe_log.c` — CSV columns become `hestia_heat_q48` and `switch_hestia_readiness`. Still the
expensive consequence (§XIII.3), but `hestia` is the same width as `hermes`, so the schema
churn is a rename rather than a reflow.
### XIX.7 — One hazard, recorded and generalized
A VM-name mismatch in this system **fails quietly.** §XXXII.2 records it caught live on the
first attempt: a console named anything other than the expected form "silently falls back to
direct interpretation with no error" — typing `5 6 + .` printed a direct `11` instead of a
relayed one, with nothing reported.
`Hestia` is short and ordinary enough that this is no longer an argument about the name. But
the class remains: **if the §XVIII.5 binding work touches that path anyway, making an
unresolved or mismatched name *say so* would retire the hazard for every VM name, not just this
one.** Raised as punch item 19, not scheduled.