Unify console prompt to [user@VM]; fix real personality-block truncation; correct §XXV's wrong lockdown conclusion (FABRIC-3.md §XXVI)
Investigating the std79 lockdown finding from FABRIC-3.md §XXV led to a real discovery: WIREBIND births TWO VMs per identity, a console proxy under the plain username and the actual restricted identity under <username>~user (capsule_wirebind.c). Every test in §XXV targeted the console proxy, which was never locked down at all. Retested against the correct target (rajames~user): the lockdown works exactly as designed. §XXV's "lockdown never engages" conclusion was wrong -- corrected here, not deleted, since the mistake and how it was caught are worth keeping (see the new feedback memory: confirm which specific VM a name resolves to before concluding anything, when a subsystem is known to birth more than one VM per identity). Two real, separate things found along the way are kept regardless of that correction: - capsule_runcap.c: the reserved personality devblock was read in full (mostly zero-padding after a short ~200-byte string) with no terminator, producing "WARN: block 4998 exceeds 1KB, truncating" on every std79-locked identity's birth, universal, since at least 2026-09-10. Fixed by trimming to the first NUL byte actually found -- real, but harmless to execution (real content sat in the truncated block's surviving head); it mattered for capsule_id/ content_hash being computed over padding instead of real content. - console.h/console.c/repl.c: unified the prompt from a separately- computed "[VMName] (user)" into a single "[user@VMName]" line prefix -- exactly the ambiguity that caused the original misdiagnosis (the prompt showed only the WIREBIND username, identical whether USE had targeted the console proxy or the real ~user identity). Implemented as a registered callback (console_set_user_prefix_provider()) rather than console.c calling into WIREBIND/session logic directly, since console.c is a clean HAL module with no prior dependency on capsule-level subsystems. Verified: clean build on all 3 architectures, zero new warnings, identical dict_hash/capsule_hash to every prior boot this session (console/prompt-only change). Full 9-identity messaging campaign re-run end to end: 202s, zero faults, all 8 identities at 99/99 tokens, zero regression. Also surfaced, not yet acted on: the full campaign's own console tags now visibly show which VM each identity's tests actually reached ([zuse@rajames], not [zuse@rajames~user]) -- messaging.4th's VM-NAMES-INIT registers identities by plain username, so std79-doe. fth's turn-attractor has been dispatching to each identity's console proxy, not the actual locked-down identity, since the messaging rewrite. Flagged for a deliberate decision, not investigated further. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXieurDfDSsDFdnSyusuWo
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
cb32e6632b
commit
a8b16d41da
@@ -58,6 +58,34 @@ CapsuleRunResult capsule_runcap_birth(
|
||||
}
|
||||
}
|
||||
|
||||
/* FABRIC-3.md SXXV follow-up (2026-09-13): source_len above is the
|
||||
* FULL reserved region (source_devblocks worth of 4KiB devblocks) --
|
||||
* MINT (capsule_mint.c) only ever writes a short personality string
|
||||
* into it and memset()s the rest of that one devblock to 0 first, but
|
||||
* never touches whatever devblocks beyond the first were reserved for
|
||||
* identity_src, and this loop reads all of them regardless. Real
|
||||
* content is a handful of lines; everything past it, for the whole
|
||||
* remaining reserved region, is zero bytes with no "Block N" header
|
||||
* of its own to stop capsule_exec_payload()'s own block-flush scan --
|
||||
* confirmed live as the actual cause of "WARN: block 4998 exceeds
|
||||
* 1KB, truncating", firing for every std79-locked identity, every
|
||||
* boot, since before this was found: the parser had no way to tell
|
||||
* "real content ends here" from "just more of this same block," so it
|
||||
* walked the whole zero-padded region as one oversized block. FORTH
|
||||
* source never legitimately contains a raw NUL, so it's a safe,
|
||||
* ordinary C-string-style terminator here: trim source_len down to
|
||||
* the first NUL actually found, restoring the block-parser's normal
|
||||
* behavior instead of teaching it a special case for this one
|
||||
* caller's own padding convention. */
|
||||
{
|
||||
uint64_t real_len = source_len;
|
||||
uint64_t k;
|
||||
for (k = 0; k < source_len; k++) {
|
||||
if (arena[k] == '\0') { real_len = k; break; }
|
||||
}
|
||||
source_len = real_len;
|
||||
}
|
||||
|
||||
/* Heap-built single-entry directory -- exact shape §F.6 traced
|
||||
* against capsule_birth_baby()'s own parameters, not a new mechanism.
|
||||
* Never freed: matches kernel_main.c's own compile-time-directory
|
||||
|
||||
@@ -195,6 +195,18 @@ const char *console_get_vm_name(void) {
|
||||
return g_active_vm_name;
|
||||
}
|
||||
|
||||
/* FABRIC-3.md SXXV follow-up: see console.h's own doc comment on
|
||||
* console_set_user_prefix_provider() for why this is a registered
|
||||
* callback rather than console.c calling into capsule/WIREBIND logic
|
||||
* directly. NULL (the default, until repl.c registers one at boot) means
|
||||
* "no provider yet" -- emit_prefix() falls back to the bare "[VMName] "
|
||||
* form, identical to today's behavior. */
|
||||
static console_user_prefix_fn g_user_prefix_fn = (void *)0;
|
||||
|
||||
void console_set_user_prefix_provider(console_user_prefix_fn fn) {
|
||||
g_user_prefix_fn = fn;
|
||||
}
|
||||
|
||||
void console_save_vm_name(char *out, size_t cap) {
|
||||
if (!out || cap == 0) return;
|
||||
size_t i = 0;
|
||||
@@ -239,10 +251,19 @@ static void emit_prefix(void) {
|
||||
int fb = fb_is_available();
|
||||
static const char *color_on = "\x1b[38;2;255;165;0m";
|
||||
static const char *color_off = "\x1b[39m";
|
||||
const char *user = g_user_prefix_fn ? g_user_prefix_fn() : (void *)0;
|
||||
|
||||
for (p = color_on; *p; p++) { raw_putc(*p); if (fb) vt100_putc(*p); }
|
||||
raw_putc('[');
|
||||
if (fb) vt100_putc('[');
|
||||
if (user && user[0]) {
|
||||
for (p = user; *p; p++) {
|
||||
raw_putc(*p);
|
||||
if (fb) vt100_putc(*p);
|
||||
}
|
||||
raw_putc('@');
|
||||
if (fb) vt100_putc('@');
|
||||
}
|
||||
for (p = g_active_vm_name; *p; p++) {
|
||||
raw_putc(*p);
|
||||
if (fb) vt100_putc(*p);
|
||||
|
||||
+46
-37
@@ -60,31 +60,35 @@
|
||||
|
||||
const char lithos_version[64] = LITHOS_VERSION_STR;
|
||||
|
||||
/* FABRIC-0.md §27.8/4.4s, unblocked 2026-09-04: extends the prompt to
|
||||
* "[VM name] (user) ok>" (e.g. "[Hera] (zuse) ok>") whenever an
|
||||
* identity is currently attached -- Zuse (mama_vm->zuse_session; there
|
||||
* is only ever one, so no username lookup needed) or a regular WIREBIND
|
||||
* user (capsule_wirebind_attached_username()). Checked independently of
|
||||
* which VM's own bracket console.c is currently showing: both identities
|
||||
* are console-level attach state, not per-VM dictionary state, so the
|
||||
* segment reflects "who is at the console" the same way regardless of
|
||||
* which VM you've USE'd into. Prints nothing (bare "ok> ", today's
|
||||
* existing format, unchanged) when neither is attached -- Hera's own
|
||||
* documented normal steady state (FABRIC-2.md §D.2). */
|
||||
/* FABRIC-3.md SXXV follow-up (2026-09-13): was "[VM name] (user) ok>"
|
||||
* (e.g. "[Hera] (zuse) ok>") -- the VM-name bracket and the user segment
|
||||
* were computed independently, and neither one told you whether the
|
||||
* bracketed VM was the console proxy WIREBIND births per identity or the
|
||||
* actual restricted identity VM behind it (e.g. "rajames" vs.
|
||||
* "rajames~user") -- confirmed live to cause real confusion debugging
|
||||
* the std79 lockdown. Unified into the single "[user@VM name] ok>" line
|
||||
* prefix (console.c's emit_prefix(), via console_set_user_prefix_
|
||||
* provider() below) -- one tag, always accurate about both who's at the
|
||||
* console AND which VM a line actually came from/a command actually
|
||||
* reaches. This function now only prints the bare prompt text; the user
|
||||
* segment moved into the line prefix, which is a different call path per
|
||||
* console.c's own commenting elsewhere but reaches every line including
|
||||
* this prompt. */
|
||||
static void sk_print_prompt(void) {
|
||||
VM *mama_vm = (VM *)sk_get_mama_vm();
|
||||
const char *username;
|
||||
|
||||
if (mama_vm && mama_vm->zuse_session) {
|
||||
console_puts("(zuse) ");
|
||||
} else if ((username = capsule_wirebind_attached_username()) != (const char *)0) {
|
||||
console_puts("(");
|
||||
console_puts(username);
|
||||
console_puts(") ");
|
||||
}
|
||||
console_puts(SK_PROMPT_TEXT);
|
||||
}
|
||||
|
||||
/* console_user_prefix_fn provider (console.h) -- same zuse_session/
|
||||
* WIREBIND-username logic sk_print_prompt() used to compute inline
|
||||
* before this moved into the shared line prefix. Registered once at
|
||||
* boot (sk_repl_run()'s own init, see below); NULL until then, which
|
||||
* console.c's emit_prefix() already treats as "no provider yet." */
|
||||
static const char *sk_console_user_prefix(void) {
|
||||
VM *mama_vm = (VM *)sk_get_mama_vm();
|
||||
if (mama_vm && mama_vm->zuse_session) return "zuse";
|
||||
return capsule_wirebind_attached_username();
|
||||
}
|
||||
|
||||
|
||||
/*===========================================================================
|
||||
* USE-word dispatch: which VM receives REPL input.
|
||||
@@ -1215,16 +1219,15 @@ int sk_repl_step(VM *vm)
|
||||
|
||||
{
|
||||
/* Unified prompt (FABRIC-0.md 4.4a): console_putc()'s existing per-line
|
||||
* "[VMName] " prefix (console.c, g_active_vm_name) already supplies the
|
||||
* bracket -- print only "ok> " here, don't build a second one.
|
||||
* emergency_console is no longer set from here (FABRIC-2.md §F.20/
|
||||
* §F.21: the emergency-CLI ACL bypass is retired) -- it's driven
|
||||
* only by the genuine C-level fault handler now (vm.c's own
|
||||
* emergency-fault-recovery use, EMERGENCY_CONSOLE_ENABLED). Every
|
||||
* word run from this REPL, Hera's bare prompt included, goes
|
||||
* through ordinary ACL enforcement. FABRIC-0.md 4.4s (2026-09-04):
|
||||
* sk_print_prompt() extends this with a "(user)" segment when an
|
||||
* identity is attached -- see its own doc comment. */
|
||||
* "[user@VMName] " prefix (console.c's emit_prefix(), FABRIC-3.md
|
||||
* SXXV follow-up) already supplies the bracket -- print only
|
||||
* "ok> " here, don't build a second one. emergency_console is no
|
||||
* longer set from here (FABRIC-2.md §F.20/§F.21: the emergency-CLI
|
||||
* ACL bypass is retired) -- it's driven only by the genuine C-level
|
||||
* fault handler now (vm.c's own emergency-fault-recovery use,
|
||||
* EMERGENCY_CONSOLE_ENABLED). Every word run from this REPL,
|
||||
* Hera's bare prompt included, goes through ordinary ACL
|
||||
* enforcement. */
|
||||
sk_print_prompt();
|
||||
}
|
||||
|
||||
@@ -1276,6 +1279,12 @@ void sk_repl_run(VM *vm)
|
||||
char input[INPUT_BUFFER_SIZE]; /* FABRIC-0.md 4.4w: matches the strip's input width */
|
||||
VM *active;
|
||||
|
||||
/* FABRIC-3.md SXXV follow-up: one-time registration so console.c's
|
||||
* emit_prefix() can compose "[user@VMName] " instead of the bare
|
||||
* "[VMName] " it falls back to while this is still unregistered
|
||||
* (early boot output, before sk_repl_run() is ever reached). */
|
||||
console_set_user_prefix_provider(sk_console_user_prefix);
|
||||
|
||||
vm->halted = 0;
|
||||
|
||||
while (!vm->halted) {
|
||||
@@ -1299,12 +1308,12 @@ void sk_repl_run(VM *vm)
|
||||
active = g_repl_active_vm ? g_repl_active_vm : vm;
|
||||
|
||||
/* Unified prompt (FABRIC-0.md 4.4a): console_putc()'s existing per-line
|
||||
* "[VMName] " prefix (console.c, g_active_vm_name) already supplies the
|
||||
* bracket -- print only "ok> " here, don't build a second one.
|
||||
* emergency_console is no longer set from here (FABRIC-2.md §F.20/
|
||||
* §F.21: the emergency-CLI ACL bypass is retired) -- see sk_repl_
|
||||
* step()'s matching comment above. FABRIC-0.md 4.4s (2026-09-04):
|
||||
* sk_print_prompt() extends this with a "(user)" segment. */
|
||||
* "[user@VMName] " prefix (console.c's emit_prefix(), FABRIC-3.md
|
||||
* SXXV follow-up) already supplies the bracket -- print only "ok> "
|
||||
* here, don't build a second one. emergency_console is no longer
|
||||
* set from here (FABRIC-2.md §F.20/§F.21: the emergency-CLI ACL
|
||||
* bypass is retired) -- see sk_repl_step()'s matching comment
|
||||
* above. */
|
||||
sk_print_prompt();
|
||||
|
||||
int n = sk_console_readline(input, sizeof(input), active, 1);
|
||||
|
||||
Reference in New Issue
Block a user