diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index 70a1bbd2..e8e68c2f 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -2,7 +2,7 @@ **Status:** Standalone working document, opened 2026-09-18 by direct instruction ("we write this in `FABRIC-3.5.md` as its own document, it's this important"). Topic: **relocating Hermes -into the kernel, reconstituting the Tripod as Hera/Artemis/Console, generalizing `BIRTH`, and +into the kernel, reconstituting the Tripod as Hera/Artemis/Hestia, generalizing `BIRTH`, and adopting one fleet-wide failure/recovery ladder.** **Why 3.5 and not 4, and why not a section of 3.** `FABRIC-4.md` is explicitly the @@ -128,7 +128,7 @@ in full: **This is the single most important pre-existing fact in this document.** §VI is not a redesign of `BIRTH`; it is a change to which VMs get it registered, plus an inheritance rule. -### I.6 — Console already has a real bind mechanism, built and live-verified +### I.6 — Hestia already has a real bind mechanism, built and live-verified Per §XXXII.2, closed 2026-09-16: `CONSOLE-ATTACH ( name-c name-u -- ok? )` exists, is a plain unconditional primitive (deliberately *not* an identity capability bit — that was tried and @@ -172,8 +172,8 @@ gravity is already partly there. Hermes stops being a peer VM on the Stadium floor and becomes a kernel-resident arbiter between the floor and the HAL. It stops being a *client* of ACL-checked, Hermes-routed messaging and becomes the routing and arbitration layer itself. The Tripod — which was Hera, -Hermes, Artemis — is reconstituted as **Hera, Artemis, Console**, with Artemis keeping its -existing storage/block-arbitration role and Console taking the vacated third slot. Console's +Hermes, Artemis — is reconstituted as **Hera, Artemis, Hestia**, with Artemis keeping its +existing storage/block-arbitration role and Hestia taking the vacated third slot. Hestia's own role widens from owning the drawing fabric to being the **bind point** where users and agent VMs (the GPIO VM of `FABRIC-4.md` §2, future networking VMs) attach. `BIRTH` becomes a general primitive any VM with standing may invoke, with authority bounded by inheritance @@ -261,12 +261,12 @@ test. --- -## IV. The Tripod reconstituted: Hera, Artemis, Console +## IV. The Tripod reconstituted: Hera, Artemis, Hestia ### IV.1 — Decided (Captain Bob, 2026-09-18) -Tripod = **Hera, Artemis, Console.** Artemis keeps its existing role (storage/block -arbitration) unchanged. Console takes the slot Hermes vacates. +Tripod = **Hera, Artemis, Hestia.** Artemis keeps its existing role (storage/block +arbitration) unchanged. Hestia takes the slot Hermes vacates. ### IV.2 — The "never renumbered" collision. Open, needs a ruling. @@ -279,10 +279,10 @@ arbitration) unchanged. Console takes the slot Hermes vacates. being renumbered. Hermes leaving index 1 forces a choice, and the existing comment forecloses the laziest option: -1. **Console takes index 1.** Tidy, preserves the "Tripod occupies 0/1/2" shape, and requires +1. **Hestia takes index 1.** Tidy, preserves the "Tripod occupies 0/1/2" shape, and requires no identity renumbering — but it silently redefines what slot 1 *means*, and `artemis:init.4th`'s dependence on the numbering is on 2, not 1, so it may be survivable. -2. **Index 1 is retired; Console takes a fresh slot.** Honest, costs a slot out of 16, and +2. **Index 1 is retired; Hestia takes a fresh slot.** Honest, costs a slot out of 16, and leaves a permanent hole that needs a comment explaining itself forever. 3. **The routing table stops being a FORTH array at all**, because §III moved routing into the kernel — in which case this question dissolves into §III.4's arena question and should not @@ -293,11 +293,11 @@ matters: answering IV.2 before III.4 risks ratifying a table that the kernel mov --- -## V. Console's role expands: the bind point +## V. Hestia's role expands: the bind point ### V.1 — Decided (Captain Bob, 2026-09-18) -Beyond owning the drawing fabric, Console becomes **the bind point for users and agent VMs** — +Beyond owning the drawing fabric, Hestia becomes **the bind point for users and agent VMs** — GPIO VM, future networking VMs, and whatever follows. The attach point that was previously implicit or undecided now lives here, explicitly. @@ -321,13 +321,13 @@ different shape wearing the same word. 2. **Does binding an agent VM touch `g_wirebind_attached_username`?** It must not — §I.7. State this as an explicit invariant in whatever implements it, exactly as §XXXII.2 required of unattended birth. -3. **Is Console's bind role ACL-gated, and if so where?** Per `.claude/CLAUDE.md`'s hard rule +3. **Is Hestia's bind role ACL-gated, and if so where?** Per `.claude/CLAUDE.md`'s hard rule and §XXXII.2 Q3's correction: policy belongs in `ACL.4th`, never in C. The shape is `' CONSOLE-ATTACH ACL-PIN` (or a sibling word's equivalent) in `ACL.4th`, not a C-side capability check — and specifically **not** a `vm_identity_has_cap()` gate, which §XXXII.2 proved unreachable because `identity.installed` is 0 for Hera/Hermes/Artemis and for every console-proxy VM. -4. **Does Console-as-bind-point survive Console being a Tripod member?** A Tripod VM is pinned +4. **Does Hestia-as-bind-point survive Hestia being a Tripod member?** A Tripod VM is pinned and born at boot (`session_register()`/`session_set_pinned()`, per `FABRIC-2.md` §H.12 step 4; "pinned sessions never leave," §H.1 — **cited from `.claude/CLAUDE.md`'s and §XX's references, not re-read for this document; verify before relying on it**). Whether the @@ -412,13 +412,13 @@ A single escalation shape, applied consistently across the fleet — current VMs 3. **Fail brutally once genuinely exhausted.** No lingering, no partial states. Once recovery options are spent the failure is **fast and total, not a slow degrade.** -The value here is uniformity: one shape for Hera, Hermes, Console and every future VM, instead +The value here is uniformity: one shape for Hera, Hermes, Hestia and every future VM, instead of bespoke handling per component. ### VII.2 — `SOS` as a standard message type **Decided:** `SOS` is a standard message type **any** VM can emit — not specific to any one -component. It applies to non-Tripod VMs and to two of the three Tripod VMs (Hera and Console). +component. It applies to non-Tripod VMs and to two of the three Tripod VMs (Hera and Hestia). Hermes is the exception, for a structural reason — §VIII. **Grounding and open points:** @@ -580,7 +580,7 @@ execution order. 9. ⬜ Assign `SOS` a message-type number deliberately (§VII.2), with a named consumer. 10. ⬜ Specify the sinking semaphore's mechanism and the clean-shutdown routine (§VIII.3). 11. ⬜ Answer §IX.3: what declares a birther dead, and what fleet shutdown means concretely. -12. ⬜ **NEW 2026-09-18 (§XIII.5).** Rule on whether the Console Tripod leg is a *new* +12. ⬜ **NEW 2026-09-18 (§XIII.5).** Rule on whether the Hestia Tripod leg is a *new* singleton, distinct from today's plural per-attach console proxies. **Gates §IV.1 and §IV.2** — sits above the slot-numbering question, not beside it. 13. ⬜ **NEW 2026-09-18 (§XIII.2), not part of this reshuffle.** Authorize a @@ -617,12 +617,12 @@ build-time check.** - **Item 18 (§XVI.7)** — if Hera is already dead, nobody performs the halt. Proposed shape (an empty floor as a kernel-observable condition) is **analysis, not a ruling.** -§XIII.5's proposed Console resolution shape remains **analysis, not a ruling.** §XIV.4's and +§XIII.5's proposed Hestia resolution shape remains **analysis, not a ruling.** §XIV.4's and §XIV.5's proposals were both superseded by §XV.4 and §XV.3 respectively. What **is** decided, all by Captain Bob on 2026-09-18 and recorded in §III.1, §IV.1, §V.1, §VI.1, §VII.1, §VII.2, §VIII.1 and §IX.1: Hermes goes into the kernel and becomes the arbiter -rather than a client; the Tripod becomes Hera/Artemis/Console; Console becomes the bind point; +rather than a client; the Tripod becomes Hera/Artemis/Hestia; Hestia becomes the bind point; `BIRTH` is general with authority bounded by inheritance; the fleet shares one gentle→from-scratch→brutal ladder; `SOS` is a standard message type with Hermes excepted via a sinking semaphore; and a failed birther's authority is never provisionally handed off. @@ -706,7 +706,7 @@ membership changes (§IV.1): 1. **`capsule_birth.c:793-796`** — `is_fleet_foundation` is literally `vm_name_prefix_eq_nocase(capsule_name, "Hera") || ... "Hermes" || ... "Artemis"`. It gates `StadiumPatronHeader` setup and the `session_register()`/`session_set_pinned()` pinning - calls. **This is the Tripod, encoded as a string test.** Swapping Hermes for Console is a + calls. **This is the Tripod, encoded as a string test.** Swapping Hermes for Hestia is a one-line change here — and that single line is what makes a VM pinned. 2. **`kernel_main.c:864-874`** — `vm_interpret(mama, "S\" Hermes\" BIRTH")` plus a `capsule_vm_find_by_name_nocase("Hermes", ...)` liveness check and console banner. The @@ -743,43 +743,43 @@ rather than from the source. All three check out; §V.3.4 and §VII.4 may now be `fleet_k_q48`/`fleet_conserved` CSV columns. §VII.4's warning stands as written: a brutal death must still return what it held, or it breaks a continuously-verified invariant. -### XIII.5 — New finding, and the most consequential of this pass: Console today is plural, ephemeral, and capsule-less +### XIII.5 — New finding, and the most consequential of this pass: Hestia today is plural, ephemeral, and capsule-less **This was not known to §IV or §V when they were written, and it changes what §IV.1 is asking for.** Traced in `capsule_console.c`: -- **Console has no capsule.** `capsules/` contains `hermes/` and `artemis/` directories but +- **Hestia has no capsule.** `capsules/` contains `hermes/` and `artemis/` directories but **no `console/`**. A console VM's entire personality is a 3-line C string literal, `CONSOLE_IDENTITY_SRC` (`capsule_console.c:28-31`): `Block 4997`, `S" common:messaging.4th" EXEC`, `MSG-CD-INIT`. That is all of it. -- **Console is deliberately *not* on the routing table.** The source comment is explicit: "No +- **Hestia is deliberately *not* on the routing table.** The source comment is explicit: "No `COMMON-CH` subscription: a console's own traffic is direct 1:1 with its paired user VM (`CONSOLE-CMD-EVENT`), not broadcast, so there's no need to resolve an index in Hermes's own routing table for it." -- **Console is plural and per-attach.** `capsule_console_birth(const char *console_name, ...)` +- **Hestia is plural and per-attach.** `capsule_console_birth(const char *console_name, ...)` is called from three sites (`capsule_wirebind.c:245`, `mama_forth_words.c:1591` and `:2015`) and mints a fresh heap-built single-entry capsule directory each time. There are as many console VMs as there are attachments. **Consequence.** Hera, Hermes and Artemis are singular, pinned, born-at-boot, capsule-backed, -routing-table-indexed. Console today is **none of those five things.** So §IV.1's "Console +routing-table-indexed. Hestia today is **none of those five things.** So §IV.1's "Hestia takes the vacated third slot" is **not** a relocation of an existing pinned VM — as stated it -would create a Console that does not currently exist. That is worth naming plainly, because it +would create a Hestia that does not currently exist. That is worth naming plainly, because it is the one place this document's "reorganization, not invention" scope discipline is genuinely strained. > **CORRECTED 2026-09-18 by §XVII — the paragraph above compares the wrong object.** The -> singular pinned Console *does* already exist: it is the HAL drawing fabric +> singular pinned Hestia *does* already exist: it is the HAL drawing fabric > (`hal/console.c`, `framebuffer.c`, `vt100.c`, `font_8x16.c`), already singular, permanent > and kernel-resident — it simply has no VM face and no owner. The per-attach proxies this -> section measured against are what *binding produces*, not what Console *is*. The scope +> section measured against are what *binding produces*, not what Hestia *is*. The scope > discipline is therefore **not** strained: the leg is an existing singleton given an owner, > and the only genuinely new artifact is a capsule personality. The resolution shape proposed > below was right; this justification for it was wrong. **RATIFIED — see §XVII.2.** Left in > place, not rewritten. **The shape that resolves it without inventing anything** — offered as analysis, **not -ratified, Captain Bob's call**: distinguish **Console** (singular, pinned, capsule-backed, the +ratified, Captain Bob's call**: distinguish **Hestia** (singular, pinned, capsule-backed, the Tripod leg — owns the drawing fabric and is the bind point, per §V.1) from **console proxies** (plural, ephemeral, per-attach — exactly what `capsule_console_birth()` mints today, unchanged). The Tripod leg is new; the proxies are untouched. This reading makes §V.1's "bind @@ -787,9 +787,9 @@ point" precise: the leg is what you bind *to*, the proxy is what binding *produc ### XIII.6 — §V and §VI are load-bearing for each other, which neither section noticed -If Console is the bind point (§V.1), it is Console that must mint console proxies — and +If Hestia is the bind point (§V.1), it is Hestia that must mint console proxies — and minting a VM is `BIRTH`. Today all three `capsule_console_birth()` call sites run in Hera's or -the caller's context. **So "Console is the bind point" cannot be implemented while `BIRTH` +the caller's context. **So "Hestia is the bind point" cannot be implemented while `BIRTH` remains Hera-exclusive; it requires §VI.1's generalization.** They are one change, not two. Mechanically this already works, which strengthens both: two of the three call sites pass @@ -799,7 +799,7 @@ Hera's). That matches §I.5's finding that `capsule_birth_baby()` treats `stadiu generically as "whoever is birthing this VM." **Parentage is already generic; only registration is not.** -This also supplies the first concrete answer to §VI.4's open "what is standing": Console needs +This also supplies the first concrete answer to §VI.4's open "what is standing": Hestia needs `BIRTH` to do its declared job, so it has standing by role. That is evidence for reading (a) (standing = having `BIRTH` registered), not a ruling. @@ -809,7 +809,7 @@ Nothing found here dislodges §III.4 as the root dependency. Two adjustments: - **§III.3 is cheaper than §I.2 implied** (3 live sites, not a broad web) and can be scoped as soon as §III.4 lands. -- **§IV.1 needs a prior ruling that §IV.2 does not cover**: is the Tripod's Console leg a *new* +- **§IV.1 needs a prior ruling that §IV.2 does not cover**: is the Tripod's Hestia leg a *new* singleton distinct from today's proxies (§XIII.5)? That question sits *above* the slot numbering, not beside it. **Added to the punch list as item 12.** @@ -818,7 +818,7 @@ Nothing found here dislodges §III.4 as the root dependency. Two adjustments: - ✅ **Item 1 CLOSED** — inventory complete (§XIII.1), 14 FORTH sites + 3 C sites + 1 CSV schema site; §I.2 corrected. - ✅ **Item 2 CLOSED** — all three citations verified against source (§XIII.4). -- ⬜ **Item 12, NEW** — rule on §XIII.5: is the Console Tripod leg a new singleton, distinct +- ⬜ **Item 12, NEW** — rule on §XIII.5: is the Hestia Tripod leg a new singleton, distinct from today's per-attach proxies? **Gates §IV.1 and §IV.2.** - ⬜ **Item 13, NEW, not part of this reshuffle** — authorize a `capsules/MANIFEST.md` correction pass for the two false claims in §XIII.2 (block 4055 "immutable ABI"; block 2049 @@ -1132,7 +1132,7 @@ death, turn order, conservation — is physics rather than policy. - ⬜ **Item 10** (§VIII.3 — the sinking semaphore's mechanism, the clean-shutdown routine's definition, and whether the window is bounded) — still open, and now the largest remaining design item. -- ⬜ **Item 12** (§XIII.5 — is the Console Tripod leg a new singleton, distinct from today's +- ⬜ **Item 12** (§XIII.5 — is the Hestia Tripod leg a new singleton, distinct from today's per-attach proxies?) — still open, and still gates §IV. **Remaining open: items 9, 10, 12, 16.** Item 10 is the substantive one; 9 is downstream of it, @@ -1256,7 +1256,7 @@ unallocated gaps, 10 is next in sequence). mechanism exists on all three architectures. - 🔶 **Item 9 (§VII.2) — HALF-ANSWERED** (§XVI.5). Consumer action defined for the two fleet-fatal cases. Open: whether a peer `SOS` is actionable or advisory, plus the number. -- ⬜ **Item 12 (§XIII.5)** — Console Tripod leg: new singleton or not? Unchanged; still gates §IV. +- ⬜ **Item 12 (§XIII.5)** — Hestia Tripod leg: new singleton or not? Unchanged; still gates §IV. - ⬜ **Item 16 (§XV.4)** — implementation check: teardown paths must reach `STADIUM-EVICT`. - ⬜ **Item 17, NEW** (§XVI.2) — decide whether Hera's suicide replaces `BYE`'s cold-restart or becomes a separate word. Small, but it changes a live registered word either way. @@ -1279,12 +1279,12 @@ authority flowing only down the birth graph (§IX.2) while still terminating. ## XVII. Item 12 CLOSED — "Console" already exists as a singleton; it just has no VM face -Taken as closing **item 12** (§XIII.5's Console-singleton question), the largest remaining +Taken as closing **item 12** (§XIII.5's Hestia-singleton question), the largest remaining design item and the one gating §IV. **§XIII.5 framed this wrongly, and the error is worth naming before the answer.** It compared -the Tripod legs against `capsule_console_birth()`'s per-attach proxies, found Console "plural, -ephemeral and capsule-less," and concluded that a singular pinned Console "does not currently +the Tripod legs against `capsule_console_birth()`'s per-attach proxies, found Hestia "plural, +ephemeral and capsule-less," and concluded that a singular pinned Hestia "does not currently exist" — so §IV.1 would be creating one, straining the reorganization-not-invention discipline. **That comparison picked the wrong object.** Traced 2026-09-18: there are three distinct things called "console" in this kernel, not two. @@ -1301,19 +1301,19 @@ called "console" in this kernel, not two. `console_get_vm_name()` (`include/starkernel/console.h:190-191`), swapped by every dispatch in the "switch, do work, switch back" pattern. -### XVII.2 — RULING: the Console Tripod leg is (1), given a VM face. Not a promoted proxy. +### XVII.2 — RULING: the Hestia Tripod leg is (1), given a VM face. Not a promoted proxy. -The singular, permanent Console this design wants **already exists in substance** — it is the +The singular, permanent Hestia this design wants **already exists in substance** — it is the drawing fabric. What it lacks is an *owner*: today the fabric is an ownerless kernel singleton -that any VM reaches into through a global. So §IV.1's "Console takes the vacated third slot" +that any VM reaches into through a global. So §IV.1's "Hestia takes the vacated third slot" is **not** the invention §XIII.5 feared. It is giving an existing singleton a VM face. That resolves the tension cleanly and without inventing anything: -- **The Console leg is singular, pinned and born-at-boot** — because the fabric it owns already +- **The Hestia leg is singular, pinned and born-at-boot** — because the fabric it owns already is all three. - **The proxies are untouched.** They stay plural and ephemeral, which is correct: they are - what *binding produces*, not what Console *is* (§XIII.5's own phrasing, now properly + what *binding produces*, not what Hestia *is* (§XIII.5's own phrasing, now properly grounded). - **§V.1's "bind point" falls out rather than being asserted.** The VM that owns the fabric is necessarily what a user or agent VM binds *to*. @@ -1339,31 +1339,31 @@ Bob's reshuffle that this document had not previously identified. Consequences of the ruling, so they are not discovered late: -- **Console needs a capsule personality.** `capsules/console/init.4th` — a new directory beside +- **Hestia needs a capsule personality.** `capsules/hestia/init.4th` — a new directory beside `hermes/` and `artemis/`. This is the one genuinely new artifact, and it is a capsule, not a mechanism. - **`is_fleet_foundation` changes membership** (`capsule_birth.c:793-796`): the name-prefix - triple becomes Hera / Artemis / Console. That single line is what makes a VM pinned - (§XIII.3), so it is also what makes Console a Tripod leg. -- **`kernel_main.c:865`'s `S" Hermes" BIRTH` becomes Console's birth**, and the switch-signal + triple becomes Hera / Artemis / Hestia. That single line is what makes a VM pinned + (§XIII.3), so it is also what makes Hestia a Tripod leg. +- **`kernel_main.c:865`'s `S" Hermes" BIRTH` becomes Hestia's birth**, and the switch-signal registration at `:1007` follows it. - **The DoE CSV schema changes** — `doe_log.c`'s six Tripod-named columns (§XIII.3). Still the expensive consequence, still not to be resolved by quietly renaming a column. -- **Console must have `BIRTH` registered** (§XIII.6): binding mints a proxy, and minting is +- **Hestia must have `BIRTH` registered** (§XIII.6): binding mints a proxy, and minting is `BIRTH`. Already settled in principle by §XV.1's "any VM can birth." -- **Console becomes the owner of the `console_set_vm_name()` discipline** — the fix in §XVII.3 +- **Hestia becomes the owner of the `console_set_vm_name()` discipline** — the fix in §XVII.3 is available once there is an owner, but is **not** in this reshuffle's scope. Flagged, not scheduled. ### XVII.5 — §IV is unblocked, and §XIII.5's marker corrected -With item 12 closed, **§IV.1 (Tripod = Hera/Artemis/Console) stands as ratified with no +With item 12 closed, **§IV.1 (Tripod = Hera/Artemis/Hestia) stands as ratified with no outstanding objection**, and §IV.2 remains dissolved per §XIV.2. §XIII.5's "this is the one place the scope discipline is genuinely strained" no longer holds and is corrected there. ### XVII.6 — Punch list after this ruling -- ✅ **Item 12 — CLOSED** (§XVII). The Console leg is the existing drawing-fabric singleton +- ✅ **Item 12 — CLOSED** (§XVII). The Hestia leg is the existing drawing-fabric singleton given a VM face; proxies unchanged. §IV unblocked. - 🔶 **Item 9** — half-answered (§XVI.5): open is whether an ordinary peer's `SOS` is actionable or advisory, plus the number allocation. @@ -1381,19 +1381,19 @@ ruled. --- -## XVIII. The Console component, designed in full (2026-09-18) +## XVIII. The Hestia component, designed in full (2026-09-18) -§XVII settled *what* the Console leg is. This section designs the component. Everything below +§XVII settled *what* the Hestia leg is. This section designs the component. Everything below traced 2026-09-18 against `e56974e`; decisions are marked, proposals are marked, and open questions are marked. -### XVIII.1 — Console is three layers, and only the middle one is new +### XVIII.1 — Hestia is three layers, and only the middle one is new | Layer | What | Where it lives today | Change | |---|---|---|---| | **0 — the fabric** | Raw output: framebuffer, VT100, glyph raster, UART | `hal/console.c`, `framebuffer.c`, `vt100.c`, `font_8x16.c` (~98 KB C) | **None.** Stays kernel HAL. | -| **1 — Console the VM** | Tripod leg. Owns fabric *policy*, is the bind point | **Does not exist** | **New — and it is a capsule, not a mechanism.** | -| **2 — console proxies** | Per-attach relay VMs, one per bound user/agent | `capsule_console_birth()` | **None**, except their birther becomes Console. | +| **1 — Hestia the VM** | Tripod leg. Owns fabric *policy*, is the bind point | **Does not exist** | **New — and it is a capsule, not a mechanism.** | +| **2 — console proxies** | Per-attach relay VMs, one per bound user/agent | `capsule_console_birth()` | **None**, except their birther becomes Hestia. | The design is almost entirely layer 1, and layer 1 is mostly a *relocation* of vocabulary that already exists in the wrong dictionary (§XVIII.3). @@ -1407,22 +1407,22 @@ already exists in the wrong dictionary (§XVIII.3). > (`zuse_session`, `capsule_wirebind_attached_username()`) — pulling either in directly here > would be a **real layering violation, not just a style preference.** -So **Console-the-VM may not be implemented by making `console.c` VM-aware.** Ownership flows one -way only: Console reaches *down* into the HAL; the HAL never reaches *up*. +So **Hestia-the-VM may not be implemented by making `console.c` VM-aware.** Ownership flows one +way only: Hestia reaches *down* into the HAL; the HAL never reaches *up*. **The sanctioned pattern for the cases where the HAL does need something VM-shaped already exists and should be reused rather than reinvented:** `console_set_user_prefix_provider()` (`console.h:231`) — a callback that lets `repl.c` supply the "user" half of the `[user@VMName]` prompt "without `console.c` knowing anything about VMs, sessions, or WIREBIND." Any further -HAL→Console coupling this design needs takes that shape: a registered callback, never an +HAL→Hestia coupling this design needs takes that shape: a registered callback, never an include. -**Consequence, stated plainly:** Console's "ownership" of the fabric is by *convention, +**Consequence, stated plainly:** Hestia's "ownership" of the fabric is by *convention, vocabulary and registration* — it is the VM that holds the drawing words — **not** by any enforcement inside `console.c`. That is weaker than it sounds and is exactly right: it keeps the HAL reusable and the layering intact. -### XVIII.3 — Console's dictionary: 1,051 lines of Console vocabulary currently live in Hera +### XVIII.3 — Hestia's dictionary: 1,051 lines of Hestia vocabulary currently live in Hera **The most concrete finding in this section.** `capsules/fabric.4th`'s own header reads: @@ -1430,48 +1430,48 @@ the HAL reusable and the layering intact. > 45-degree cavalier orthographic projection... Raw pixel write (`PLOT`/`FB-WIDTH`/`FB-HEIGHT`) > is C; **this capsule is the FORTH-side policy on top of it.** -It is named Console's fabric, it *is* the FORTH-side fabric policy — and it loads into **Hera's** +It is named Hestia's fabric, it *is* the FORTH-side fabric policy — and it loads into **Hera's** dictionary (`capsules/init.4th` block 2049: `S" fabric.4th" EXEC`, `S" font.4th" EXEC`). | Capsule | Lines | Loads into today | Should load into | |---|---|---|---| -| `fabric.4th` | 319 | **Hera** (`init.4th` b2049) | **Console** | -| `font.4th` | 733 | **Hera** (`init.4th` b2049) | **Console** | +| `fabric.4th` | 319 | **Hera** (`init.4th` b2049) | **Hestia** | +| `font.4th` | 733 | **Hera** (`init.4th` b2049) | **Hestia** | | `turtle.4th` | 99 | `sdk.4th` (opt-in, not boot) | unchanged — it is SDK, not fabric | **Plus the C primitives underneath:** `PLOT`, `FB-WIDTH`, `FB-HEIGHT` -(`src/word_source/framebuffer_words.c:62-64`). Their *registration* moves to Console's word +(`src/word_source/framebuffer_words.c:62-64`). Their *registration* moves to Hestia's word table; the implementations do not change. **DECIDED (proposal — Captain Bob's call, but this is the direct consequence of §XVII.2):** -`fabric.4th` and `font.4th` move from `init.4th` to `capsules/console/init.4th`. This is a pure +`fabric.4th` and `font.4th` move from `init.4th` to `capsules/hestia/init.4th`. This is a pure relocation of 1,051 lines — the single most obviously-correct edit in the whole reshuffle, and the clearest evidence that the fabric wants an owner: it already *has* the vocabulary, just attached to the wrong VM. -**Parity consequence** (§III.5): Hera's `dict_hash` will shrink, Console's is new. Per §XX's +**Parity consequence** (§III.5): Hera's `dict_hash` will shrink, Hestia's is new. Per §XX's standard, the property that matters is cross-architecture identity, not an unchanging absolute. -### XVIII.4 — Console's capsule personality +### XVIII.4 — Hestia's capsule personality -`capsules/console/init.4th` — a new directory beside `hermes/` and `artemis/`, and **the one +`capsules/hestia/init.4th` — a new directory beside `hermes/` and `artemis/`, and **the one genuinely new artifact this reshuffle creates.** Contents, in load order: -1. `S" common:messaging.4th" EXEC` + `MSG-CD-INIT` — Console is a Tripod leg and a full +1. `S" common:messaging.4th" EXEC` + `MSG-CD-INIT` — Hestia is a Tripod leg and a full messaging participant. **Note this differs from the proxies**, which deliberately skip `COMMON-CH` (`capsule_console.c:23-26`: "a console's own traffic is direct 1:1 with its paired user VM"). The *leg* subscribes; the *proxies* still do not. 2. `S" fabric.4th" EXEC` and `S" font.4th" EXEC` — per §XVIII.3. -3. Console's own bind vocabulary (§XVIII.5). +3. Hestia's own bind vocabulary (§XVIII.5). 4. A `WELCOME`/banner word, matching `hermes/init.4th`'s and `artemis/init.4th`'s shape. **Block allocation is a real to-do, not a formality.** `mkcapsule`'s actual constraints, per §XXXII.2's correction: block range **`[2048, 5120)`** and a hard **16-content-line-per-block** cap (*not* the 1024-byte framing `.claude/CLAUDE.md` still describes — that doc error is outstanding). **Block 4997 is already taken** by the proxy's own C string literal -(`capsule_console.c:28-31`), so Console's range must avoid it. Allocate against +(`capsule_console.c:28-31`), so Hestia's range must avoid it. Allocate against `capsule-reserved.txt` and verify with `mkcapsule --lint capsules/` (§XXIV's collision machinery covers this; it is blind to content, only to numbers). @@ -1485,7 +1485,7 @@ machinery covers this; it is blind to content, only to numbers). ▼ ▼ WIREBIND path CONSOLE-ATTACH │ │ - └──────────► Console ◄───────────┘ + └──────────► Hestia ◄───────────┘ │ BIRTH a proxy (§XV.1 makes this legal: │ any VM may birth) @@ -1498,9 +1498,9 @@ machinery covers this; it is blind to content, only to numbers). closed 2026-09-16). It resolves the target's liveness *before* birthing, so a typo refuses cleanly with no orphaned VM. **Keep it exactly as is.** The change is *who runs it*: today the three `capsule_console_birth()` call sites run in Hera's or the caller's context - (`capsule_wirebind.c:245`, `mama_forth_words.c:1591`, `:2015`). Under this design Console is + (`capsule_wirebind.c:245`, `mama_forth_words.c:1591`, `:2015`). Under this design Hestia is the birther. -- **This is why Console needs `BIRTH` registered** (§XIII.6) — binding *mints a proxy*, and +- **This is why Hestia needs `BIRTH` registered** (§XIII.6) — binding *mints a proxy*, and minting is `BIRTH`. Already legal per §XV.1. - **Mechanically this already works:** two of the three call sites pass `vm->stadium_vm_id` — whichever VM invoked — so parentage is already generic (§I.5, §XIII.6). Only registration @@ -1517,61 +1517,185 @@ no-bespoke-gate grounds but touches a live, bug-prone path; flagged rather than ### XVIII.6 — Headless-until-login survives, and the invariant that makes it survive -**Console the leg is born at boot. A console session is not.** These must not be conflated, or +**Hestia the leg is born at boot. A console session is not.** These must not be conflated, or §VIII.1's ratified headless-until-login policy reopens — the exact failure §XXXII.2 warned about for unattended birth. -**INVARIANT, to be stated in whatever code implements Console:** +**INVARIANT, to be stated in whatever code implements Hestia:** -> Console's birth at boot must not set `g_wirebind_attached_username`, must not cause +> Hestia's birth at boot must not set `g_wirebind_attached_username`, must not cause > `sk_console_identity_present()` (`repl.c:122`) to report an identity, and must not mint a -> proxy. Console owns the fabric from boot; it presents nothing until something binds. +> proxy. Hestia owns the fabric from boot; it presents nothing until something binds. This is the same invariant §XXXII.2 imposed on unattended identity birth, applied to a second -path. It is cheap to hold — Console births no proxy until asked — but it is exactly the kind of +path. It is cheap to hold — Hestia births no proxy until asked — but it is exactly the kind of thing that gets violated by a well-meaning "initialise the console at startup" line. -### XVIII.7 — What Console does *not* own +### XVIII.7 — What Hestia does *not* own Stated because a component that owns "the bind point" attracts responsibilities that belong elsewhere, and this document has already had to defend against exactly that (§XV.3): - **Not turn order.** Nothing owns it (§XV.3). -- **Not routing.** That is kernel-Hermes (§III), which sits *below* Console. -- **Not the lifecycle of anything but its own proxies.** Console births proxies; it does not +- **Not routing.** That is kernel-Hermes (§III), which sits *below* Hestia. +- **Not the lifecycle of anything but its own proxies.** Hestia births proxies; it does not birth, kill, or supervise identity VMs. Authority flows down the birth graph only (§IX.2). - **Not the prompt's user half.** That stays `repl.c`'s, supplied to the HAL via the existing - provider callback (§XVIII.2). Moving it into Console would be the layering violation + provider callback (§XVIII.2). Moving it into Hestia would be the layering violation `console.h` explicitly names. -### XVIII.8 — Console's own failure behaviour +### XVIII.8 — Hestia's own failure behaviour -Console is a Stadium-floor VM **above** the routing layer, so §VIII.2's rule applies without an -exception: **Console emits `SOS`**; only Hermes uses the semaphore. Its clean shutdown is +Hestia is a Stadium-floor VM **above** the routing layer, so §VIII.2's rule applies without an +exception: **Hestia emits `SOS`**; only Hermes uses the semaphore. Its clean shutdown is §XVI's: forced `blk_flush(0)`, then `BYE`. -**A pleasant property worth recording: Console's death degrades gracefully by construction.** +**A pleasant property worth recording: Hestia's death degrades gracefully by construction.** Because layer 0 is HAL C (§XVIII.1) and ownership is by convention rather than enforcement -(§XVIII.2), a dead Console leaves the framebuffer, VT100 and UART fully functional — the fabric +(§XVIII.2), a dead Hestia leaves the framebuffer, VT100 and UART fully functional — the fabric simply becomes ownerless again, which is precisely today's status quo. The kernel can still print. **This is the opposite of Hermes**, whose death takes the transport with it. So the Tripod's three legs have three genuinely different failure characters: Artemis's death costs -storage arbitration, Console's costs only fabric *policy*, Hermes's costs the transport itself — +storage arbitration, Hestia's costs only fabric *policy*, Hermes's costs the transport itself — which is why only Hermes needed the semaphore. -### XVIII.9 — Punch list for Console +### XVIII.9 — Punch list for Hestia Design items, in dependency order. **No code authorized.** 1. ⬜ Ratify §XVIII.3's relocation: `fabric.4th` + `font.4th` move from `init.4th` to - `capsules/console/init.4th`; `PLOT`/`FB-WIDTH`/`FB-HEIGHT` registration moves to Console. -2. ⬜ Allocate Console's block range against `capsule-reserved.txt`, avoiding 4997; verify with + `capsules/hestia/init.4th`; `PLOT`/`FB-WIDTH`/`FB-HEIGHT` registration moves to Hestia. +2. ⬜ Allocate Hestia's block range against `capsule-reserved.txt`, avoiding 4997; verify with `mkcapsule --lint` (§XVIII.4). 3. ⬜ Decide §XVIII.5's agent-binding shape: widen the `~user` convention, or a sibling word. **The only genuinely open design question in this section.** -4. ⬜ Confirm Console in the `is_fleet_foundation` triple (`capsule_birth.c:793-796`) and its +4. ⬜ Confirm Hestia in the `is_fleet_foundation` triple (`capsule_birth.c:793-796`) and its birth at `kernel_main.c:865`, replacing Hermes's (§XVII.4). 5. ⬜ Handle the `doe_log.c` CSV schema change (§XIII.3) — still the expensive consequence. 6. ⬜ State §XVIII.6's headless invariant in the implementation. 7. ⬜ **Not in this reshuffle:** the `console_set_vm_name()` ownerless-global fix (§XVII.3) is - now *available* once Console exists, but remains out of scope. Flagged, not scheduled. + now *available* once Hestia exists, but remains out of scope. Flagged, not scheduled. + +--- + +## XIX. RULING: the third Tripod leg is named Hestia, not Console (Captain Bob, 2026-09-19) + +**The Tripod is: Hera, Artemis, Hestia.** Applied throughout this document — 99 occurrences +renamed; three verbatim quotations deliberately left saying "Console" (§XIX.4). + +### XIX.1 — The naming convention, stated so it stops being re-litigated + +`antiprosopos` (Gk. representative/delegate) was considered first and **rejected, on Captain +Bob's reasoning, which is the correct reasoning and is recorded here because it generalizes:** + +> "Now this is just a name of a Greek mythos god, it doesn't have to carry full/perfect +> [fidelity], it's only a contextual display... After all, Artemis isn't exactly the perfect +> name for a memory manager/storage manager either." + +That is the convention, and it had never been written down: **a Greek deity name, evocative +rather than literal.** Checked against what exists — Hera (queen/mother → the Mama VM) is a +close fit, Hermes (messenger → messaging) is the closest, and **Artemis (huntress, wilderness → +block storage and freemap arbitration) is a loose fit that has never caused anyone a +problem.** Fidelity was never the standard. + +`antiprosopos` failed on being the wrong *kind* of word: a common noun straining for literal +accuracy, which is the opposite of how the other three work. `Hestia` — goddess of the hearth — +is a deity, is evocative (the hearth is the fixed centre of the household, where everyone +gathers), and carries a pleasing incidental: **Hestia is the one who never leaves.** That maps +onto the pinned-session model (`FABRIC-2.md` §H.1, "they never leave, permanently") without +having been chosen for it. + +**Two costs that `antiprosopos` carried are retired by this choice, not merely tolerated:** +- **Pattern.** `antiprosopos` is Greek vocabulary, not a deity — it half-joined the set. + `Hestia` joins it fully. +- **Typo surface.** Twelve characters of unusual spelling, in a path where a VM-name mismatch + fails *silently* (§XIX.5). `Hestia` is six, comparable to `Hermes` and `Artemis`. + +### XIX.2 — Why renaming at all is structural, not cosmetic + +§XVII.1 found three distinct things in this kernel all called "console" — the HAL fabric, the +VM, and the per-attach proxies — and that collision is exactly what led §XIII.5 to the wrong +conclusion about whether a singular Console existed. Naming the VM separately resolves it by +construction: + +| Layer | Name after this ruling | +|---|---| +| 0 — the drawing fabric (HAL C) | **the console** — `console.c`, unchanged | +| 1 — the Tripod leg, owns the fabric | **Hestia** | +| 2 — per-attach relay VMs | **console proxies** — unchanged | + +"Hestia owns `console.c`" is unambiguous in a way "Console owns `console.c`" cannot be. This +document has already paid once for that ambiguity; the rename is what stops it recurring. + +### XIX.3 — What is NOT renamed + +The ruling names a VM. It does not rename the subsystem: + +- **The HAL stays `console.c`/`console.h`** and every `console_*()` function. Renaming them + would be churn across ~98 KB of C for no gain, and would re-create the confusion by making + the HAL sound like the VM. +- **`capsule_console_birth()` / `CONSOLE_IDENTITY_SRC` stay** — they mint console proxies, + still called console proxies. +- **`CONSOLE-ATTACH` stays.** `.claude/CLAUDE.md`'s "never modify a registered, tested word" + applies with more force to *renaming* one, and the word remains accurate: it attaches a + console. **Recommended, not ruled.** +- **`CONSOLE-CMD-EVENT` and `sk_console_identity_present()` stay** — both are layer 0/2 + business (a console session), not Hestia's (§XVIII.6). + +**Net code-visible rename surface:** the VM's registry name, its capsule directory +(`capsules/hestia/init.4th`), and the places the Tripod is enumerated (§XIX.6). + +### XIX.4 — Three quotations deliberately still say "Console" + +Quoted source is not silently edited to match a later decision: + +1. **Line 26** — the opening brief's own wording ("Hera lifecycle/ACL, Console framebuffer"). +2. **§XVIII.3** — `capsules/fabric.4th`'s verbatim header, "Console drawing-fabric coordinate + machinery." That is what the file says *today*; it changes when the file is edited, and + **that edit belongs to the §XVIII.3 relocation, not to this ruling.** +3. **§XVII's heading** — a meta-reference to the name itself, which is that section's subject. + +### XIX.5 — `~user` is a separate question, unaffected + +`antiprosopos` was first raised as a replacement for the `~user` registry-name suffix. **That +remains punch item 3** (§XVIII.5), and the Hestia ruling does not touch it. Recorded so the two +never get conflated: + +Traced 2026-09-18 — as a *suffix* it does not fit the buffers. `VM_NAME_MAX` is 64 and +`USER_IDENTITY_USERNAME_MAX` 32, so the name fits in principle, but every construction buffer +is sized `+ 8`, tuned exactly to `"~user"` (5 chars + NUL = 6): `capsule_wirebind.c:222` (=40), +`mama_forth_words.c:1855`/`:1991` and `repl.c:1243` (=72), each guarding on a hardcoded `+ 6`. +A 14-byte suffix would not overflow them — it would make them **refuse**, silently failing to +bind usernames over 26 characters and registry names over 58. Six `memcpy` sites and five +guards hardcode that `6`, and `FABRIC-3.md` §XXVI was itself a truncation fix. + +**And it would not answer item 3 regardless:** a GPIO VM is neither a user nor a human's +representative. The structural fix is making the suffix a property of the *binding*; settle +that first and land any suffix rename inside it, since the same eleven sites are touched either +way. + +### XIX.6 — Edit surface + +All were already edit sites for the Tripod membership change (§XVII.4); the rename changes the +string, not the count: + +- `capsule_birth.c:793-796` — `is_fleet_foundation`'s prefix triple becomes + Hera / Artemis / **Hestia** (matched by `vm_name_prefix_eq_nocase`, as today). +- `kernel_main.c:865` — `S" Hestia" BIRTH`; the liveness check and the switch-signal + registration at `:1007` follow. +- `capsules/hestia/init.4th` — the new capsule directory (§XVIII.4). +- `doe_log.c` — CSV columns become `hestia_heat_q48` and `switch_hestia_readiness`. Still the + expensive consequence (§XIII.3), but `hestia` is the same width as `hermes`, so the schema + churn is a rename rather than a reflow. + +### XIX.7 — One hazard, recorded and generalized + +A VM-name mismatch in this system **fails quietly.** §XXXII.2 records it caught live on the +first attempt: a console named anything other than the expected form "silently falls back to +direct interpretation with no error" — typing `5 6 + .` printed a direct `11` instead of a +relayed one, with nothing reported. + +`Hestia` is short and ordinary enough that this is no longer an argument about the name. But +the class remains: **if the §XVIII.5 binding work touches that path anyway, making an +unresolved or mismatched name *say so* would retire the hazard for every VM name, not just this +one.** Raised as punch item 19, not scheduled.