diff --git a/FABRIC-3.6.md b/FABRIC-3.6.md index 79244e7d..40aef18c 100644 --- a/FABRIC-3.6.md +++ b/FABRIC-3.6.md @@ -734,9 +734,12 @@ Hestia; headless policy intact. ## Phase 3 — Cutover — **UNBLOCKED, tasks not yet written** -**Not buildable until all three clear.** Shape once unblocked (§XXXIV.3): cut over -`BLK-ATTACH-EVENT` alone, then remaining types one at a time, under §XXXIV.2's partition rule — -one message type owned by exactly one layer, no message shared. +**Blockers cleared 2026-09-21 (§XLV). Task list drafted 2026-09-21, awaiting Captain Bob's +review — none started.** Shape (§XXXIV.3, amended by §XLV): build the negotiated pub/sub +plumbing inert, then cut over `BLK-ATTACH-EVENT` alone, then remaining types one at a time, +under §XXXIV.2's partition rule — one message type owned by exactly one layer, no message +shared. **Stop condition (§XXXIV.6): `dict_hash` diverging across ISAs, or Stage B evidence +(ledger + `stadium_conserved()`) going false — re-plan, do not push on.** - [x] **B1** — **CLEARED 2026-09-21 by `FABRIC-3.5.md` §XLV.1**: negotiated pub/sub channels — one common channel, private channels by request/grant/deny, ACK/NACK throughout. Overrules @@ -753,6 +756,56 @@ one message type owned by exactly one layer, no message shared. predates §XLV's negotiation. Writing the task list (and settling the §XLV.4 sub-items it depends on) is the next step, before any Phase 3 code. +### Phase 3 tasks (drafted 2026-09-21; **draft, not authorized**) + +Each is one commit with three-ISA acceptance, per the standing rules. Tasks marked **[needs +ruling]** cannot be written precisely until Captain Bob settles the named sub-item. + +- [ ] **3.0** — **Decision gate, not code.** Rule on the §XLV.4 sub-items: **(a)** ACK cadence + (advised: channel open + delivery, not every common-channel message); **(b)** where the + channel-open ACL hook lives in `ACL.4th`; **(c)** the dynamic switch-table sizing rule; + **(d)** chunk framing; **(e)** drain one message per checkpoint (§XLIII.6.3, recommended, + never ruled). *Check:* each answer recorded in `FABRIC-3.5.md`. +- [ ] **3.1** — **Dynamic switch table** (B2) **[needs ruling 3.0c]**. Read + `SK_SWITCH_MAX_SLOTS`'s every use first; replace the constant with a boot-time, + RAM-derived allocation (Stadium's `stadium_max_vm_count_val` pattern). *Check:* boot + byte-identical, `dict_hash` unmoved; a synthetic test drives more than 16 slots. +- [ ] **3.2** — **Channel table + common channel**, inert (B1). Dynamic table of topics, each + with its own `SkHermesMembership`; the common channel exists from boot; every VM is + subscribed at birth. Wired to nothing. *Check:* boot byte-identical; every born VM appears + in the common channel's membership; create/destroy a synthetic private topic. +- [ ] **3.3** — **Publish path, no dispatch** (§XLIII.3). Publish allocates via + `sk_hermes_alloc()`, enqueues onto each subscriber's own pending queue, and records the + fact; it dispatches nothing. Self-test only. *Check:* ledger audit and + `stadium_conserved()` hold across N publishes to M subscribers (heat cost per subscriber + is a design point to settle **before** writing this: one message per subscriber, or one + shared message with a reference count — **[needs ruling]**). +- [ ] **3.4** — **Drain at the outermost checkpoint** (§XLIII.3–.5). Reuse + `sk_vm_at_outermost_interpret()`; one message per checkpoint **[needs ruling 3.0e]**. + *Check:* a nested interpret does not drain; a queued payload is interpreted exactly once at + depth 1. +- [ ] **3.5** — **Payload bound and chunking** (B4) **[needs ruling 3.0d]**. Max 1024 bytes per + message; larger payloads sent as ordered chunks, reassembled before drain. *Check:* + 1024-byte payload single message; 3000-byte payload chunked and reassembled byte-exact; + 1025-byte single-message send refused. +- [ ] **3.6** — **ACK/NACK and private-channel negotiation** (B1) **[needs ruling 3.0a]**. + `request` → `grant`/`deny` on the common channel; a grant creates a private topic; + close tears it down. ACK/NACK are message types on the existing allocator. + *Check:* grant path, deny path, close path; heat conserved (ledger + `stadium_conserved()`) + across all three; a NACK'd request leaves no topic behind. +- [ ] **3.7** — **Channel-open policy hook** **[needs ruling 3.0b]**. Kernel-Hermes asks + `ACL.4th`, never decides in C, never gates on `zuse_session`. *Check:* a denied open is + denied by FORTH policy, with the C unchanged when the policy changes. +- [ ] **3.8** — **Stage C: cut over `BLK-ATTACH-EVENT` alone** (§XXXIV.3). One layer owns it; + FORTH Hermes still routes every other type. *Check:* the real Hera↔Artemis attach path + works end to end on all three ISAs; ledger and `stadium_conserved()` true before/after; + **`fleet_conserved` is not evidence** (§XXXIX). +- [ ] **3.9** — **Stage D: `CONSOLE-CMD-EVENT` (type 7)**, then **3.10 `ELEVATE-REQUEST` + (type 8)** — one type per task, each with the 3.8 check. Any type found live beyond these + three is added here, not bundled. +- [ ] **3.11** — **Phase 3 gate.** No FORTH-owned live message types remain; Stage B evidence + holds across a full boot on all three ISAs. **Do not start Phase 4 until this passes.** + ## Phase 4 — Category B strip Only after every live type is cut over. **Hermes leaves `is_fleet_foundation` and