Unify console prompt to [user@VM]; fix real personality-block truncation; correct §XXV's wrong lockdown conclusion (FABRIC-3.md §XXVI)
Build / build-amd64-iso (push) Canceled after 0s
Build / build-aarch64-iso (push) Canceled after 0s
Build / build-riscv64-img (push) Canceled after 0s

Investigating the std79 lockdown finding from FABRIC-3.md §XXV led
to a real discovery: WIREBIND births TWO VMs per identity, a console
proxy under the plain username and the actual restricted identity
under <username>~user (capsule_wirebind.c). Every test in §XXV
targeted the console proxy, which was never locked down at all.
Retested against the correct target (rajames~user): the lockdown
works exactly as designed. §XXV's "lockdown never engages" conclusion
was wrong -- corrected here, not deleted, since the mistake and how
it was caught are worth keeping (see the new feedback memory:
confirm which specific VM a name resolves to before concluding
anything, when a subsystem is known to birth more than one VM per
identity).

Two real, separate things found along the way are kept regardless
of that correction:

- capsule_runcap.c: the reserved personality devblock was read in
  full (mostly zero-padding after a short ~200-byte string) with no
  terminator, producing "WARN: block 4998 exceeds 1KB, truncating"
  on every std79-locked identity's birth, universal, since at least
  2026-09-10. Fixed by trimming to the first NUL byte actually found
  -- real, but harmless to execution (real content sat in the
  truncated block's surviving head); it mattered for capsule_id/
  content_hash being computed over padding instead of real content.

- console.h/console.c/repl.c: unified the prompt from a separately-
  computed "[VMName] (user)" into a single "[user@VMName]" line
  prefix -- exactly the ambiguity that caused the original
  misdiagnosis (the prompt showed only the WIREBIND username,
  identical whether USE had targeted the console proxy or the real
  ~user identity). Implemented as a registered callback
  (console_set_user_prefix_provider()) rather than console.c calling
  into WIREBIND/session logic directly, since console.c is a clean
  HAL module with no prior dependency on capsule-level subsystems.

Verified: clean build on all 3 architectures, zero new warnings,
identical dict_hash/capsule_hash to every prior boot this session
(console/prompt-only change). Full 9-identity messaging campaign
re-run end to end: 202s, zero faults, all 8 identities at 99/99
tokens, zero regression.

Also surfaced, not yet acted on: the full campaign's own console
tags now visibly show which VM each identity's tests actually
reached ([zuse@rajames], not [zuse@rajames~user]) -- messaging.4th's
VM-NAMES-INIT registers identities by plain username, so std79-doe.
fth's turn-attractor has been dispatching to each identity's console
proxy, not the actual locked-down identity, since the messaging
rewrite. Flagged for a deliberate decision, not investigated further.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EXieurDfDSsDFdnSyusuWo
This commit is contained in:
Robert Allan James
2026-09-13 06:44:58 -04:00
co-authored by Claude Sonnet 5
parent cb32e6632b
commit a8b16d41da
25 changed files with 84722 additions and 694 deletions
+28
View File
@@ -58,6 +58,34 @@ CapsuleRunResult capsule_runcap_birth(
}
}
/* FABRIC-3.md SXXV follow-up (2026-09-13): source_len above is the
* FULL reserved region (source_devblocks worth of 4KiB devblocks) --
* MINT (capsule_mint.c) only ever writes a short personality string
* into it and memset()s the rest of that one devblock to 0 first, but
* never touches whatever devblocks beyond the first were reserved for
* identity_src, and this loop reads all of them regardless. Real
* content is a handful of lines; everything past it, for the whole
* remaining reserved region, is zero bytes with no "Block N" header
* of its own to stop capsule_exec_payload()'s own block-flush scan --
* confirmed live as the actual cause of "WARN: block 4998 exceeds
* 1KB, truncating", firing for every std79-locked identity, every
* boot, since before this was found: the parser had no way to tell
* "real content ends here" from "just more of this same block," so it
* walked the whole zero-padded region as one oversized block. FORTH
* source never legitimately contains a raw NUL, so it's a safe,
* ordinary C-string-style terminator here: trim source_len down to
* the first NUL actually found, restoring the block-parser's normal
* behavior instead of teaching it a special case for this one
* caller's own padding convention. */
{
uint64_t real_len = source_len;
uint64_t k;
for (k = 0; k < source_len; k++) {
if (arena[k] == '\0') { real_len = k; break; }
}
source_len = real_len;
}
/* Heap-built single-entry directory -- exact shape §F.6 traced
* against capsule_birth_baby()'s own parameters, not a new mechanism.
* Never freed: matches kernel_main.c's own compile-time-directory
+21
View File
@@ -195,6 +195,18 @@ const char *console_get_vm_name(void) {
return g_active_vm_name;
}
/* FABRIC-3.md SXXV follow-up: see console.h's own doc comment on
* console_set_user_prefix_provider() for why this is a registered
* callback rather than console.c calling into capsule/WIREBIND logic
* directly. NULL (the default, until repl.c registers one at boot) means
* "no provider yet" -- emit_prefix() falls back to the bare "[VMName] "
* form, identical to today's behavior. */
static console_user_prefix_fn g_user_prefix_fn = (void *)0;
void console_set_user_prefix_provider(console_user_prefix_fn fn) {
g_user_prefix_fn = fn;
}
void console_save_vm_name(char *out, size_t cap) {
if (!out || cap == 0) return;
size_t i = 0;
@@ -239,10 +251,19 @@ static void emit_prefix(void) {
int fb = fb_is_available();
static const char *color_on = "\x1b[38;2;255;165;0m";
static const char *color_off = "\x1b[39m";
const char *user = g_user_prefix_fn ? g_user_prefix_fn() : (void *)0;
for (p = color_on; *p; p++) { raw_putc(*p); if (fb) vt100_putc(*p); }
raw_putc('[');
if (fb) vt100_putc('[');
if (user && user[0]) {
for (p = user; *p; p++) {
raw_putc(*p);
if (fb) vt100_putc(*p);
}
raw_putc('@');
if (fb) vt100_putc('@');
}
for (p = g_active_vm_name; *p; p++) {
raw_putc(*p);
if (fb) vt100_putc(*p);
+46 -37
View File
@@ -60,31 +60,35 @@
const char lithos_version[64] = LITHOS_VERSION_STR;
/* FABRIC-0.md §27.8/4.4s, unblocked 2026-09-04: extends the prompt to
* "[VM name] (user) ok>" (e.g. "[Hera] (zuse) ok>") whenever an
* identity is currently attached -- Zuse (mama_vm->zuse_session; there
* is only ever one, so no username lookup needed) or a regular WIREBIND
* user (capsule_wirebind_attached_username()). Checked independently of
* which VM's own bracket console.c is currently showing: both identities
* are console-level attach state, not per-VM dictionary state, so the
* segment reflects "who is at the console" the same way regardless of
* which VM you've USE'd into. Prints nothing (bare "ok> ", today's
* existing format, unchanged) when neither is attached -- Hera's own
* documented normal steady state (FABRIC-2.md §D.2). */
/* FABRIC-3.md SXXV follow-up (2026-09-13): was "[VM name] (user) ok>"
* (e.g. "[Hera] (zuse) ok>") -- the VM-name bracket and the user segment
* were computed independently, and neither one told you whether the
* bracketed VM was the console proxy WIREBIND births per identity or the
* actual restricted identity VM behind it (e.g. "rajames" vs.
* "rajames~user") -- confirmed live to cause real confusion debugging
* the std79 lockdown. Unified into the single "[user@VM name] ok>" line
* prefix (console.c's emit_prefix(), via console_set_user_prefix_
* provider() below) -- one tag, always accurate about both who's at the
* console AND which VM a line actually came from/a command actually
* reaches. This function now only prints the bare prompt text; the user
* segment moved into the line prefix, which is a different call path per
* console.c's own commenting elsewhere but reaches every line including
* this prompt. */
static void sk_print_prompt(void) {
VM *mama_vm = (VM *)sk_get_mama_vm();
const char *username;
if (mama_vm && mama_vm->zuse_session) {
console_puts("(zuse) ");
} else if ((username = capsule_wirebind_attached_username()) != (const char *)0) {
console_puts("(");
console_puts(username);
console_puts(") ");
}
console_puts(SK_PROMPT_TEXT);
}
/* console_user_prefix_fn provider (console.h) -- same zuse_session/
* WIREBIND-username logic sk_print_prompt() used to compute inline
* before this moved into the shared line prefix. Registered once at
* boot (sk_repl_run()'s own init, see below); NULL until then, which
* console.c's emit_prefix() already treats as "no provider yet." */
static const char *sk_console_user_prefix(void) {
VM *mama_vm = (VM *)sk_get_mama_vm();
if (mama_vm && mama_vm->zuse_session) return "zuse";
return capsule_wirebind_attached_username();
}
/*===========================================================================
* USE-word dispatch: which VM receives REPL input.
@@ -1215,16 +1219,15 @@ int sk_repl_step(VM *vm)
{
/* Unified prompt (FABRIC-0.md 4.4a): console_putc()'s existing per-line
* "[VMName] " prefix (console.c, g_active_vm_name) already supplies the
* bracket -- print only "ok> " here, don't build a second one.
* emergency_console is no longer set from here (FABRIC-2.md §F.20/
* §F.21: the emergency-CLI ACL bypass is retired) -- it's driven
* only by the genuine C-level fault handler now (vm.c's own
* emergency-fault-recovery use, EMERGENCY_CONSOLE_ENABLED). Every
* word run from this REPL, Hera's bare prompt included, goes
* through ordinary ACL enforcement. FABRIC-0.md 4.4s (2026-09-04):
* sk_print_prompt() extends this with a "(user)" segment when an
* identity is attached -- see its own doc comment. */
* "[user@VMName] " prefix (console.c's emit_prefix(), FABRIC-3.md
* SXXV follow-up) already supplies the bracket -- print only
* "ok> " here, don't build a second one. emergency_console is no
* longer set from here (FABRIC-2.md §F.20/§F.21: the emergency-CLI
* ACL bypass is retired) -- it's driven only by the genuine C-level
* fault handler now (vm.c's own emergency-fault-recovery use,
* EMERGENCY_CONSOLE_ENABLED). Every word run from this REPL,
* Hera's bare prompt included, goes through ordinary ACL
* enforcement. */
sk_print_prompt();
}
@@ -1276,6 +1279,12 @@ void sk_repl_run(VM *vm)
char input[INPUT_BUFFER_SIZE]; /* FABRIC-0.md 4.4w: matches the strip's input width */
VM *active;
/* FABRIC-3.md SXXV follow-up: one-time registration so console.c's
* emit_prefix() can compose "[user@VMName] " instead of the bare
* "[VMName] " it falls back to while this is still unregistered
* (early boot output, before sk_repl_run() is ever reached). */
console_set_user_prefix_provider(sk_console_user_prefix);
vm->halted = 0;
while (!vm->halted) {
@@ -1299,12 +1308,12 @@ void sk_repl_run(VM *vm)
active = g_repl_active_vm ? g_repl_active_vm : vm;
/* Unified prompt (FABRIC-0.md 4.4a): console_putc()'s existing per-line
* "[VMName] " prefix (console.c, g_active_vm_name) already supplies the
* bracket -- print only "ok> " here, don't build a second one.
* emergency_console is no longer set from here (FABRIC-2.md §F.20/
* §F.21: the emergency-CLI ACL bypass is retired) -- see sk_repl_
* step()'s matching comment above. FABRIC-0.md 4.4s (2026-09-04):
* sk_print_prompt() extends this with a "(user)" segment. */
* "[user@VMName] " prefix (console.c's emit_prefix(), FABRIC-3.md
* SXXV follow-up) already supplies the bracket -- print only "ok> "
* here, don't build a second one. emergency_console is no longer
* set from here (FABRIC-2.md §F.20/§F.21: the emergency-CLI ACL
* bypass is retired) -- see sk_repl_step()'s matching comment
* above. */
sk_print_prompt();
int n = sk_console_readline(input, sizeof(input), active, 1);