FABRIC-3.6.md task 0.8: PLOT/FB-WIDTH/FB-HEIGHT reachability audit -- Phase 0 closed

Read-only audit, no code changed. Finding: reachable from every VM
today, not confined to one table, contrary to item 33's premise.

FORTH level matches expectation: fabric.4th/font.4th are EXEC'd only
from capsules/init.4th (Hera). C level does not: register_framebuffer_
words() (src/word_source/framebuffer_words.c:60-65) is called
unconditionally from register_forth79_words() (src/word_registry.c:
139), itself called unconditionally from vm_init()
(src/starkernel/vm/vm_bootstrap.c:263) -- the generic per-VM bootstrap
every VM goes through, no identity check.

Verified live rather than trusting the source trace alone: booted
amd64 and ran `S" FB-WIDTH ." S" Hermes" VM-EXEC` and the same against
Artemis -- both returned 1280, not UNKNOWN WORD. Neither loads
fabric.4th, so the raw C primitive itself is answering.

Not fixed here, per the task's own read-only scope. Gives task 1.8 a
concrete starting state: its own check ("a non-Hestia VM calling PLOT
gets UNKNOWN WORD") currently fails, and register_framebuffer_words()'s
call site will need to become conditional or move out of the universal
bootstrap -- not just the FORTH-level relocation tasks 1.6/1.7 already
plan for.

Phase 0 gate met across tasks 0.2-0.7 (three-arch boot, stadium_
conserved() true, zero UNKNOWN WORD, repeatedly). Phase 0 is closed;
Phase 1 (Hestia, messaging untouched) is next.

Authorized by Captain Bob ("Continue.").

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Robert Allan James
2026-09-19 14:04:50 -04:00
co-authored by Claude Sonnet 5
parent 380f0a09c9
commit eed2a9dfb5
4 changed files with 9215 additions and 2 deletions
+29 -1
View File
@@ -276,8 +276,36 @@ it has simply not been attempted.)*
(`stadium_words_print_boot_diagnostics()`, `kernel_main.c:810`, Hera only — the sole
existing call site) rather than adding a new one. No compiler warnings on either edited
file (checked with a forced recompile).
- [ ] **0.8** — Audit that `PLOT`/`FB-WIDTH`/`FB-HEIGHT` are registered **nowhere** but the
- [x] **0.8** — Audit that `PLOT`/`FB-WIDTH`/`FB-HEIGHT` are registered **nowhere** but the
table Hestia will own (item 33). *Check:* read-only; a second site is a defect to report.
2026-09-19 · read-only audit, no code changed. **Finding: they are reachable from every
VM today, not confined to one table.** Traced the two layers separately:
- **FORTH level** (the drawing vocabulary): `capsules/fabric.4th`/`font.4th` (which build
`CART-PLOT` etc. on top of raw `PLOT`) are `EXEC`'d only from `capsules/init.4th` — Hera
only. Neither `hermes/init.4th` nor `artemis/init.4th` load them. This layer matches
item 33's expectation and is exactly what tasks 1.6/1.7 move to `hestia/init.4th`.
- **C level** (the raw primitives themselves): `register_framebuffer_words()`
(`src/word_source/framebuffer_words.c:60-65`, registering `PLOT`/`FB-WIDTH`/
`FB-HEIGHT`) is called unconditionally from `register_forth79_words()`
(`src/word_registry.c:139`), which is itself called unconditionally from `vm_init()`
(`src/starkernel/vm/vm_bootstrap.c:263`) — **the generic per-VM bootstrap every VM goes
through, no identity check, no `#ifdef`.** So the raw primitives are already in every
VM's C-level dictionary at birth, Hestia or not.
- **Verified live, not just from source**: booted amd64 (`logs/20260919-140231/amd64/`)
and ran `S" FB-WIDTH ." S" Hermes" VM-EXEC` and the same against `Artemis` — **both
returned `1280`, not `UNKNOWN WORD`.** Neither loads `fabric.4th`, so this is the raw
C primitive itself answering, confirmed reachable from VMs that were never meant to
draw.
**Not fixed here** — read-only per the task, and this is exactly task 1.8's own stated
check ("a non-Hestia VM calling `PLOT` gets `UNKNOWN WORD` — verify positively"), which
this finding confirms currently **fails** and gives 1.8 a concrete starting state:
`register_framebuffer_words()`'s call site in `register_forth79_words()` will need to
become conditional on VM identity (or moved out of the universal bootstrap entirely),
not just the FORTH-level `fabric.4th` relocation tasks 1.6/1.7 already plan for.
**Phase 0 gate met**: all three architectures have repeatedly booted to `[zuse@Hera] ok>`
with `stadium_conserved()` true and zero `UNKNOWN WORD` across tasks 0.2–0.7. Phase 0 is
closed; Phase 1 (Hestia, messaging untouched) is next.
## Phase 1 — Hestia (messaging untouched)
+1 -1
View File
@@ -1,5 +1,5 @@
# Capsule Block Manifest — Auto-generated
<!-- Generated by mkcapsule --manifest 2026-09-19T17:54:15Z -->
<!-- Generated by mkcapsule --manifest 2026-09-19T18:02:29Z -->
<!-- DO NOT EDIT — re-run mkcapsule --manifest to refresh. -->
<!-- Hand-written justifications and immutability notes live -->
<!-- in MANIFEST.md alongside this auto-generated index. -->
File diff suppressed because it is too large Load Diff