§XXII.1 says Category B is load-bearing until the replacement boots, which implies a window where both messaging layers are live, and nothing said how they behave in it. The hazard is not control but heat. Two allocators draw on the same per-VM Stadium reservoir, and the budget is explicit: Q.SLOT is the reservoir less COMMON-CH's third, split across 32 messages plus 15 channel slots. Conservation itself is not at risk, since K holds as long as each layer honestly pulls and returns; the budget is, because a pool sized for one layer is oversubscribed by two. The failure mode is allocation refusal rather than silent drift, and fleet_conserved makes it visible. Notes that §XXXIII's channel retirement removes 15 of those 47 slots, recovering roughly a third of the per-VM budget precisely when two layers share it. Rules the coexistence: every message type is owned by exactly one layer, and no message crosses. Double-accounting becomes structurally impossible rather than carefully avoided, which is the heat-side analogue of §XXXII's control-side ruling. Reuses §XXVIII's staging discipline rather than inventing one, since it solved the structurally identical problem of standing up a second control-transfer mechanism beside a live one. Five stages: inert structures, prove the allocator against fleet_conserved, cut over one narrow type, cut over the rest, then strip. Stage A feels like wasted work and is what makes every later stage a one-commit revert. Surfaces a coupling nobody had noticed. §XIX.6's obvious reading, swap Hermes for Hestia, would break the middle stages on first boot, because FORTH Hermes must keep routing every type not yet cut over. So is_fleet_foundation temporarily holds four names and both births run, with Hermes removed only at the strip. This sequences §XIX rather than contradicting it. Names the acceptance cost honestly -- at least eight full three-arch cycles -- and states three tripwires that would stop the plan rather than be pushed through. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VkM1zHGvBerLF6aqkHPweP
LithosAnanke v2.0.1
UEFI-bootable FORTH microkernel. Boots from firmware, initialises memory and interrupts, then runs the StarForth VM as its sole userspace runtime. No libc. No OS. Just stone and necessity.
Lithos (foundation) + Ananke (necessity) — the kernel under StarshipOS.
Status — M7.1 (Capsule System · Multi-VM Fleet)
| Milestone | Status | |
|---|---|---|
| M0–M6 | UEFI boot · PMM · VMM · IDT · APIC · heap · framebuffer VT100 console (v1.5.1-FINAL) | ✅ Complete |
| M7 | StarForth VM integration + parity validation | ✅ Complete |
| M7.1 | Capsule birth protocol · Mama FORTH vocabulary · Tripod multi-VM fleet (Hermes/Artemis) · Word-level ACL (Phases 1–7) | 🔄 In Progress |
| M8 | REPL — keyboard input, interactive Forth | Planned |
| M9 | Block storage — AHCI driver | Planned |
POST at boot: parity hash verified across amd64/aarch64/riscv64 · Mama capsule dictionary: 453 words
What's live in M7.1
- Tripod — a named multi-VM fleet (Hera the Mama VM, Artemis, two Hermes instances) births, runs, and re-births independently, verified booting live pre-REPL on all three architectures.
- Hermes — a 17-block inter-VM messaging/channel layer between fleet members, with async delivery and channel negotiation.
- Artemis — a Block Allocation Map (BAM) storage subsystem with Q48.16
block-heat tracking and cooldown/reclamation (
ART-COOL/ART-REAP). - Word-level ACL — every dictionary entry carries a TTL/allow/mode/pin
access-control record. Strict, TTL, and pinned modes; two console layers
(emergency
ok>and superuserzuse)ok>). Phases 1–7 complete (C infrastructure, FORTH policy layer,zusebootstrap superuser, Isabelle proof stubs, kernel parity); Phase 8 (Ed25519 PKI / thumbdrive challenge-response) is the only item remaining. Measured overhead once active on every check: +0.0054%–+0.0088%, CV = 0.000%, across a 3×3 Latin-square DoE campaign (architecture × seed × 30 replicates) — three orders of magnitude below the measurement floor. - VM Fleet Attractor physics — the L8 Jacquard mode selector now has a real per-VM heat channel into fleet-wide tuning, replacing hardcoded compudynamics constants with a dynamically-inferred rate.
- Kconfig build configuration — every physics/heartbeat/pipelining/ kernel-only tuning knob (~40 total) is now a discoverable, optional Kconfig symbol shared with the hosted VM build. See Quick Start below.
Quick Start
# Build kernel (requires cross-compilation toolchain, or native gcc)
make -f Makefile.starkernel ARCH=amd64
# Run in QEMU with OVMF
make -f Makefile.starkernel qemu
# Other architectures
make -f Makefile.starkernel ARCH=aarch64 qemu
make -f Makefile.starkernel ARCH=riscv64 qemu
Artifacts: build/amd64/kernel/starkernel_loader.efi · build/amd64/kernel/starkernel_kernel.elf
For the hosted VM by itself (Linux, no cross-compiler needed, no bare-metal tooling): see
the separate StarForth repository — LithosAnanke used to be a branch inside that repo,
now it's its own project with its own master.
Build configuration (optional)
Every kernel-only knob (STARFORTH_ENABLE_VM, PARITY_MODE, the shared
physics/heartbeat family, etc.) is an optional Kconfig symbol — a plain
make -f Makefile.starkernel uses the same defaults it always has unless
you opt in:
make -f Makefile.starkernel ARCH=amd64 menuconfig
make -f Makefile.starkernel ARCH=amd64 kernel_amd64_defconfig
Documentation
| System Architecture | Full kernel + VM design |
| HAL Reference | Hardware abstraction layer interfaces |
| Capsule System — M7.1 | Capsule birth protocol design |
| VM Fleet Attractor design log | Tripod/Hermes/Artemis physics + build-system history |
| Getting Started / Kconfig reference | Full symbol reference for both build targets |
| Changelog | Milestone-level history |
| Roadmap | Milestone plan through self-hosting |
License
Starship License 1.0 (SL-1.0) — free for personal, research, and educational use. Commercial use requires a separate agreement. Attribution to R.A. James (Captain Bob) must be preserved in all distributions.
Patent pending. USPTO provisional filed December 2025 — physics-grounded self-adaptive runtime system. This license does not grant patent rights. Licensing inquiries: rajames440@gmail.com
Robert A. James (Captain Bob) · Systems Engineer · Hacking since 1973