54 Commits
Author SHA1 Message Date
Claude eb6cad2330 FABRIC-3.6.md: add START HERE session handoff
Written so a cold session told "go build it" can begin without
re-deriving anything. Records where the code actually is -- the Gitea
instance, not the empty GitHub StarForth repo that cost this session time
at the outset, and not the read-only mirror -- plus the branch, its head,
and that no code has been written yet.

States the two-document split and the rule that 3.5 is authoritative and
a task proving a ruling wrong is a finding to record rather than a
divergence to make quietly.

Carries the five traps this project's own history proves are real, since
a fresh session would otherwise walk into each: silent failure is the
dominant mode and a green boot is weak evidence; grep cannot establish
capsule reachability, having put six live capsules at zero references;
fleet_conserved cannot see Stadium heat, so a leaking allocator leaves it
reporting fine; dict_hash changing is expected while diverging is the
stop condition; and CLAUDE.md carries four known-stale claims to trust
the code over.

Names the three blocked decisions and the standing prohibitions -- no
branches, no stashing, no fixing in passing, no bundling, nothing without
authorization.

No credentials committed; the handoff names the host and repo only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
2026-09-19 12:29:15 +00:00
Claude 2032974f3a FABRIC-3.6.md: add pre-flight -- three-ISA baseline as task 0.0, and why it gates
Records the branch state execution starts from: head 3a4e5cf, working
tree clean, pushed, 33 commits ahead of an unmoved master, all
documentation and no code.

Adds task 0.0, the three-ISA baseline smoke test on the unmodified
branch, and states why it is a gate rather than a formality. Every task
here takes the three-architecture boot as its acceptance, so without a
known-good baseline captured first the first red boot is ambiguous --
pre-existing fault, or something the task just did. This project has been
bitten by that exact ambiguity before, per FABRIC-3 §XXVI where the
lockdown was never broken and the wrong VM had been tested. The recorded
dict_hash triple also becomes the reference every later divergence check
compares against.

Records that it was not runnable in the authoring container and was
deliberately not faked: no qemu-system for any of the three targets, no
aarch64 or riscv64 cross compilers, no OVMF or AAVMF firmware, only host
gcc, clang and lld. It must be run on a machine with the real toolchain
and its result recorded here before task 0.1 begins.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
2026-09-19 12:25:04 +00:00
Claude 3a4e5cff07 FABRIC-3.5.md §XLIII: B3 settled -- the target drains its own queue at its own checkpoint
The last genuine design question in the reshuffle, and once again the
mechanism already exists, built for the structurally identical problem
and corrected twice in the field.

Delivery must execute the payload inside the target, but §XXXII retired
the pump so kernel-Hermes may not VM-EXEC into anyone. The payload must
wait somewhere the target consumes under its own power, at a moment when
doing so is safe -- and safe is the hard part, since interpreting
mid-word, mid-unwind or nested inside someone else's dispatch is the
reentrancy class this codebase has been bitten by repeatedly.

vm_core.c already has all of it: sk_vm_at_outermost_interpret() as the
predicate, a per-word checkpoint in execute_colon_word() gated on it, a
defer-don't-lose discipline for the nested case whose own comment
explains that a nested word does not own the stack it is running on, and
placement before the error and unwind checks so it only acts when the VM
is in a clean resumable state. That is the exact predicate, placement and
deferral semantics delivery needs, because the switcher had to answer the
same question.

Ruling: kernel-Hermes enqueues and publishes the fact, dispatching
nothing; the target drains its own queue in its own context at its own
outermost checkpoint. One published fact, two independent consumers --
the switcher for eligibility, the VM itself for drain -- and neither
dispatches into anyone.

Notes this is §XX's proven pattern generalized: the pump's defect was
never draining but draining from outside, and Hera was special-cased into
safety. Retire the pump and every VM does what she already does, so the
special case disappears by becoming universal. Also notes recursive drain
is prevented for free, since interpreting increments the same depth
counter that defines the boundary.

Names three constraints rather than leaving them to be discovered:
INPUT_BUFFER_SIZE is 1025 so a payload above 1024 bytes cannot be
interpreted in one drain, starvation is real but is the switcher's
existing risk rather than a new one, and draining one message per
checkpoint rather than the whole queue keeps the work bounded.

FABRIC-3.6.md: B3 cleared, B4 added for the payload bound.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
2026-09-19 12:18:46 +00:00
Claude dd255eac58 FABRIC-3.6.md: open the execution log; FABRIC-3.5.md §XLII records the split
Agreed to move the punchlist to its own document, on the series' own
rule rather than preference. FABRIC-1 closed at 4,420 lines because "the
still-open work [was] hard to find" among hundreds of resolved ones;
FABRIC-3.5 stands at 4,452 with 40+ open items in the same shape.
Annotating 25 tasks there, commit by commit, would bury the design record
it exists to be.

The split is strict and stated firmly, because §XXXI found this series'
documents losing track of each other. 3.5 holds the design record and
stays authoritative on conflict; 3.6 holds the work. Rulings are cited in
3.6, never restated, since duplication is how two documents begin to
disagree -- and a task that proves a ruling wrong is recorded as a
finding there and amended here, never silently diverged.

3.6 restores the checkbox convention. §XXXI.2 found the carry-forward
discipline was mechanically auditable through FABRIC-2 and broke at
FABRIC-3, which has no checkboxes, after which "is anything still open"
stopped being a grep and became a reading exercise -- which is how six
design items went quiet without anyone deciding to drop them. The next
document in the series does not repeat the defect the gap analysis found
in it.

§XLI stays in 3.5 as the source 3.6 instantiates: the phase structure,
why Phase 2 sits early, and the three Phase 3 blockers with their
justification. What moved is the checklist, not the argument. 3.6 also
carries an explicit out-of-scope section so deliberately excluded work is
not absorbed by an executing session.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
2026-09-19 12:16:37 +00:00