ZUSE-ELIGIBILITY-ADD's own doc comment admitted "no authorization check here or anywhere else... applied later if and when actually needed -- not invented here." That's now: anyone reaching a Hera FORTH prompt could add their own pubkey to the eligibility list with zero legitimate identity material -- no minted drive, no WIREBIND, no cert-signature check involved at all. Once a future caller reaches ELEVATE-GRANT again, a self-added pubkey would pass zuse_eligibility_is_member() and grant ACL-ALLOW!/ACL-TTL! on any named word. Fixed the FORTH-only way, matching this project's own convention (ACL policy belongs in ACL.4th, never in C; never gate on zuse_session in C -- her power is the absence of ACLs, not a hardcoded session check): ZUSE-ELIGIBILITY-ADD is now denied by default (capsules/zuse.4th block 4016), granted and pinned only inside ACL-ZUSE-BOOT's already-existing authenticated branch (block 4017) -- the same gate her own god-mode already goes through, requiring a real cert-verified Zuse before it opens. Live-verified on all three architectures, not just boot-clean: after genesis authentication, ACL-ALLOW@ and ACL-PINNED? both read -1, and HERE ZUSE-ELIGIBILITY-ADD executes successfully past the ACL gate. Phase 8 v1 plan: /home/rajames/.claude/plans/jiggly-cuddling-stallman.md Part A (the ELEVATE-GRANT pointer-confusion fix, FABRIC-3.7.md) is separate, not yet built. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
capsules/
FORTH personality files loaded by the VM at boot. A capsule is an immutable, content-addressed payload; its XXHash64 hash is its identity. Any mutation changes the hash and the birth protocol rejects the image.
Key files
| File | Type | Purpose |
|---|---|---|
init.4th |
(m) MAMA_INIT |
Default Mama VM personality — loaded at LBN 2048 |
ACL.4th |
user | Word-level ACL system; self-activating at boot |
zuse.4th |
user | Bootstrap superuser; loaded by ACL.4th |
doe.4th |
user | DoE workload words (EXEC-DOE) — opt-in |
workload-0.4th … workload-9.4th |
(p) |
Numbered personality variants |
init-l8-*.4th |
(p) |
L8 Jacquard mode variants (stable/volatile/diverse/temporal/transition/omni) |
hermes/init.4th |
(p) |
Hermes baby VM personality |
artemis/init.4th |
(p) |
Artemis baby VM personality |
Block namespace
Block ranges are shared across all loaded capsules — collisions cause silent word-definition overwrites.
| Range | Owner |
|---|---|
| 2048–2099 | init.4th |
| 2100–2199 | doe.4th |
| 3000–3999 | workload capsules |
| 4000+ | user-defined (ACL.4th, zuse.4th, …) |
Each block is limited to 1024 bytes. Verify with wc -c before committing.
See also
experiments/bare_metal/README.md— DoE protocols and block namespace rulesdocs/03-architecture/word-acl/DESIGN.md— ACL system designtools/mkcapsule.c— assembles capsules intocapsule_generated.c- Project root