diff --git a/FABRIC-3.5.md b/FABRIC-3.5.md index e8c638bd..19bd0c9c 100644 --- a/FABRIC-3.5.md +++ b/FABRIC-3.5.md @@ -1,7 +1,14 @@ # FABRIC-3.5.md — the Tripod/kernel reshuffle -**Status: DESIGN PHASE CLOSED as of 2026-09-19, by direct instruction ("close the document for -now"). Not yet archival.** +**Status: REOPENED 2026-09-19, by direct instruction ("reopen 3.5 and write it up as a gap +analysis section"), to add §XXXI — a gap-analysis sweep of the whole FABRIC set. The design +phase remains closed; §XXXI adds findings, not new design.** + +> **Prior status, kept rather than overwritten: DESIGN PHASE CLOSED as of 2026-09-19, by +> direct instruction ("close the document for now"). Not yet archival.** That close stood for +> the duration of the sweep and its substance is unchanged — every design question was and +> remains ruled. The reopen is recorded rather than the close deleted, per this series' own +> rule against silently rewriting a prior state. **What is closed, and what is deliberately not.** Every design question this document opened is ruled — see §XXX.7. **No code has been written and no code is authorized.** The execution @@ -3021,3 +3028,211 @@ removed 2026-08-15 as non-functional and must not be resurrected. **Every decision this document required is now made.** What remains is execution: the surgical strip, the build, the Isabelle pass, the sweep, the SBOM, the merge, the tag, and the close. + +--- + +## XXXI. Gap-analysis sweep of the FABRIC set (2026-09-19) + +Run by direct instruction — "we need a gap analysis sweep and I'd look HARD at the entire +fabric document set." The set is 25,493 lines across `FABRIC-0` … `FABRIC-4` plus this +document. + +**A gap analysis of a series whose central rule is "never silently drop a stale claim" is, in +effect, an audit of whether the series kept its own rule.** Mostly it did. Where it did not, +the failures are structural and in one case operationally urgent. + +### XXXI.1 — Method, and an honest statement of coverage + +**Done:** mechanical harvesting across all six documents — open/closed checkbox counts, +deferral vocabulary (`deferred`, `not in scope`, `for later`, `still open`, `NOT fixed`), +cross-document reference counts for every long-lived item id — followed by targeted reads of +everything the counts flagged. + +**Not done:** an end-to-end read of all 25,493 lines. `FABRIC-0.md` §1–24 (the theory) and the +bulk of `FABRIC-1.md`'s resolved narrative were not read line by line. **So this sweep finds +structural gaps and orphaned items; it does not certify that every claim in the set is +accurate.** Stated plainly because §XXII.2 was written about exactly this failure mode, and it +would be poor form for the sweep to repeat it. + +### XXXI.2 — The carry-forward chain held twice and then terminated + +The series' defining discipline is that closing a document carries its open items forward. +Audited mechanically: + +| Link | Status | Evidence | +|---|---|---| +| `FABRIC-0` → `FABRIC-1` | **Held** | F0's open item ids are referenced throughout F1 (1.11 ×8, 4.4s ×5, 4.6 ×9, 5.1 ×3) | +| `FABRIC-1` → `FABRIC-2` | **Held, and independently verifiable** | F2's header claims a "full, non-sampled carry-forward of every open item… **51 items**." `grep -c '^\s*-\s*\[ \]' FABRIC-1.md` returns **51** today. The claim is exactly true | +| `FABRIC-2` → `FABRIC-3` | **Terminated** | Every long-lived F0 id — 1.11, 4.4s, 4.6, 5.1, 5.2, 5.3 — returns **zero** references in `FABRIC-3.md` | + +**`FABRIC-3.md` contains no checkboxes at all** (0 open, 0 closed), having moved to a prose and +`CLOSED`-heading convention. That is a legitimate stylistic choice, but it ends the mechanical +audit trail that made the F1 → F2 link provable. **After `FABRIC-2`, "is anything still open?" +stops being a `grep` and becomes a reading exercise** — which is how the items in §XXXI.3 and +§XXXI.4 went quiet without anyone deciding to drop them. + +### XXXI.3 — `FABRIC-2`'s close claim is overstated: six design items are open, not hardware-blocked + +`FABRIC-2.md`'s close header states it was "closed after §I… was worked through to completion — +**every item either closed with a dated note or correctly left open pending a physical machine +(§I.6)**." + +It closed with **14 open checkboxes.** Eight are the real-hardware USB boot checklist (build +the ISO, `dd` it, boot the machine, capture with no serial log, confirm POST `1012/0/0`, reach +`ok>`, document the result) — **legitimately FABRIC-3's topic, correctly left open.** The claim +holds for those. + +**The other six have no hardware dependency and appear nowhere since:** + +| Item | Line | Picked up in F3 / F3.5? | +|---|---|---| +| **§17.4 — framebuffer heat/decay dynamics, undesigned** | 77, 4366 | **No** (§XXXI.6) | +| First-touch allocation (identity pubkey → claimed block range) | 192 | **No** | +| Migration state machine — states, transition triggers | 228 | **No** | +| Block-namespace sandboxing / `mkcapsule` conflict extension | 1011 | **No** | +| ACL `EXPIRE` — "confirmed genuinely unscoped (2026-08-26)" | 1219 | **No** | + +The one apparent hit for `EXPIRE` in this document is a **false positive** — §XXIV.3's +name-collision check for the suicide word, unrelated to the ACL item. + +**None of these is necessarily urgent. All of them are unowned**, and the close header says +otherwise. + +### XXXI.4 — `FABRIC-0`'s seven open items, three of which this document re-derived + +`FABRIC-0.md` closed 2026-08-12 with seven open items. All seven remain `- [ ]` today: + +| Item | Bearing on this reshuffle | +|---|---| +| **4.3 — Console** | **Direct. See below.** | +| 1.11 — Dirty-event granularity | Blocked on 4.3; unblocks with it | +| 4.4s — `(user)` prompt segment | Plausibly *done* — `FABRIC-3.md` §XXV's `[user@VMName]` work looks like it, never checked off | +| 4.6 — "Artemis last. It works today; it is the thing that cannot be broken" | Sequencing advice this reshuffle happens to follow (§IV.1 leaves Artemis unchanged) without citing it | +| 5.1 — Re-run the DoE on the new substrate | Overtaken by §XXV.1's DoE rewrite | +| **5.2 — Isabelle/HOL** | **Direct. See below.** | +| **5.3 — Shrink the subsystem documents** | **Direct. See below.** | + +**Three were re-derived by this document without either side knowing:** + +1. **4.3's deferred tail is this reshuffle's Hestia work.** Its 2026-08-07 discussion note + scopes 4.3.1–4.3.4 and defers, verbatim, "fonts, scrolling, cursor/VT100 semantics, the + Hermes message protocol, **and Console as a fleet VM under Hera's birth protocol** — later + 4.3.x items, scoped once this slice is reviewed." **That last clause is §XVII and §XVIII.** + Also worth noting: **4.3 carries a standing instruction** — "Captain Bob wants a discussion + before any work starts on this item… raise it and wait." Satisfied in substance (Captain Bob + directed this work personally), but the linkage was never recorded. + **The slices themselves are complete:** 4.3.1 through 4.3.7f — framebuffer, keyboard on all + three architectures, fonts, UTF-8, TTF rasterization — are **all `[x]`**. Only the parent + stays open, for the tail this document just designed. +2. **5.2 already specifies the Isabelle target §XXV left generic:** "**One datatype, one index + space, one conservation theorem.**" §XXV.5 mapped affected theories without citing it — and + "one conservation theorem" is almost certainly **K**, the fleet conservation invariant that + §XV.4 independently rediscovered as *the only thing that must survive a death*. Two + documents converged on the same theorem from opposite ends, a year apart in the series, with + no cross-reference. +3. **5.3 already asked for §XXVI.1's documentation work:** "`ARTEMIS.md`, `HERMES.md`, + `CONSOLE.md`, `TRIPOD.md` should each reduce to roughly three lines. **Any that grows is + fighting the design.**" It also flags that `TRIPOD.md`'s Immediate Goal "currently requires + Hera to spawn Hermes and Artemis at boot, which 0.1 undoes" — **worth checking, because + `kernel_main.c:865` does exactly that today** (§XIII.3), so either 0.1 was reverted or that + note is stale. + +### XXXI.5 — The urgent finding: `FABRIC-3` holds an open item that contradicts §XV.3 + +**This is the one that affects the build, and it should be reconciled before kernel-Hermes is +written.** + +`FABRIC-3.md` §XXVIII.2 records, and §XXXI restates as still open: + +> **Still open:** the MSG-TICK/Stage-3-switch dual-ownership rough edge §XXVIII itself flagged +> (**both mechanisms can independently move control between the same VMs**) is unchanged by +> this pass. + +…and in §XXXI's own summary: "the MSG-TICK/Stage-3 dual-ownership rough edge (**still open, not +observed failing**)." + +**§XV.3 of this document ruled that *nothing owns turn order*.** That ruling is a principle; +`FABRIC-3` records a **live, known, unfixed instance of exactly the dual ownership the +principle forbids** — two mechanisms independently moving control between the same VMs. + +**Three consequences:** + +- **§XIV.5's scheduler-firewall concern was a rediscovery**, not a new finding. `FABRIC-3` + named this seam first. This document should have cited it and did not. +- **Kernel-Hermes lands directly on it.** Per §XIV.5, once the FORTH layer is legacy, + kernel-Hermes becomes the caller of `sk_vm_switch_signal_mark_work()` — i.e. the reshuffle + moves one of the two owners into the new arbiter. Building on an open dual-ownership defect + is how it stops being "not observed failing." +- **"Not observed failing" is not "does not fail."** §XXVIII.2's own history is a record of this + neighbourhood producing switch storms — QEMU pinned near 100%, serial log frozen solid — when + two sources of truth disagreed. + +**Added as punch item 22, ahead of the kernel-Hermes work rather than alongside it.** + +### XXXI.6 — §17.4 became Hestia's problem and nothing says so + +`FABRIC-2.md` §17.4, still open: "**framebuffer utility's internal heat/decay dynamics.** +Undesigned, blocked on 1.11 specifically… **Still open 2026-09-04**: 1.11's *decision* closed, +but no dirty-region-tracking mechanism exists yet for this item's physics to attach to — that +mechanism, not a further ruling, is the real remaining blocker." + +§XVIII.3 relocated the drawing fabric's vocabulary to Hestia and §XVII.2 gave the fabric an +owner — **without inheriting this open item.** The framebuffer now has a VM that owns it and +an undesigned heat/decay story attached to nothing, and the two facts live in different +documents. + +Not a blocker for the reshuffle — §XVIII deliberately scoped Hestia to ownership and binding, +not physics. **But it is now unambiguously Hestia's, and should be recorded as such rather than +left in a closed document.** Punch item 23. + +### XXXI.7 — Three "reported, not scheduled" registries, with inconsistent hygiene + +The set carries at least three separate registries of found-but-unfixed defects — `FABRIC-0` +§25.7 "Reported, not scheduled", `FABRIC-1` §C "Reported bugs and dead code, not yet fixed", +and scattered prose flags through `FABRIC-2`/`FABRIC-3`. **They have no consolidated home and +no shared convention.** + +**§25.7 is actively misleading as a registry**, because resolved entries are sometimes struck +through and sometimes not: + +- `~~stadium_admit() never writes stadium_owner[idx]~~` — struck, correctly. +- **"Fleet heat leak… `vm_physics_touch()` integer-truncation drift"** — **not struck, but + resolved**: `FABRIC-1.md:468` carries it as `- [x] **Fleet heat leak.**` Anyone reading §25.7 + today would believe the project sits on an unmeasured monotonic leak in a conservation law it + makes claims about. +- **`bump-z`/`bump-y` broken** — **not struck, but resolved**: removed 2026-08-15 as + non-functional (§XXVIII.4). +- Still genuinely live in §25.7: `heartbeat_trust()` exported with zero callers; + `m5_time_trust`/`m5_variance` declared and never used; `hotwords_cache_promote()`'s NULL + write; Kconfig/`menuconfig` never exercised end to end; and **`src/*.c.bak` tracked in git** + — which is now reported in *three* places (§25.7, `.claude/CLAUDE.md`, and §XXII.5 of this + document) and actioned in none. + +**Punch item 24: consolidate the registries and apply one convention.** Reported, not fixed — +and deliberately not folded into this reshuffle. + +### XXXI.8 — What the sweep changes + +**Nothing in §I–§XXX is invalidated.** No ruling is contradicted by a finding here; §XXXI.5 is +a conflict between this document's *principle* and an open defect in the code, not an error in +the ruling. Every design decision stands. + +**New punch items, appended to §XXX.7's list:** + +- ⬜ **22 — Reconcile §XV.3 against the MSG-TICK/Stage-3 dual-ownership defect** (§XXXI.5). + **Before kernel-Hermes, not alongside it.** The reshuffle moves one of the two owners into + the new arbiter. +- ⬜ **23 — Re-home `FABRIC-2` §17.4** (framebuffer heat/decay) as Hestia's (§XXXI.6). +- ⬜ **24 — Consolidate the three "reported, not scheduled" registries** and mark the resolved + entries (§XXXI.7). +- ⬜ **25 — Decide the fate of `FABRIC-2`'s five other orphaned design items** (§XXXI.3): + first-touch allocation, migration state machine, block-namespace sandboxing, ACL `EXPIRE`. + Adopt, re-home, or explicitly abandon with a reason — but not leave unowned. +- ⬜ **26 — Reconcile `FABRIC-0`'s seven opens** (§XXXI.4): close 4.3 against §XVII/§XVIII, + check whether 4.4s is already done, fold 5.2 into item 12's Isabelle pass and 5.3 into item + 13's sweep, and confirm the `TRIPOD.md`/0.1 contradiction. + +**And one recommendation the sweep argues for on its own evidence:** the carry-forward +discipline was *verifiable* only while the documents used checkboxes (§XXXI.2). If the series +continues in prose, "what is still open" needs a deliberate mechanism — because two documents +have now closed with items nobody chose to drop.