Files
Robert Allan JamesandClaude Sonnet 5 51940f49d0
Build / build-amd64-iso (push) Canceled after 0s
Build / build-aarch64-iso (push) Canceled after 0s
Build / build-riscv64-img (push) Canceled after 0s
Add per-slot CRC + campaign crash-resume (DOE-RESUME-COUNT)
FABRIC-3.md §XXXV.12: closes two real gaps found by walking the disk-to-
PDF pipeline end to end. (1) doe_trial_slot_t had no integrity check of
its own -- 64 slots share one devblock via a read-modify-write, so a
crash mid-write to any slot could silently corrupt its siblings with
nothing to catch it. Added an 8-byte CRC (same discipline the control
header already had), computed/verified the same way. (2) The campaign
itself had no crash-resume -- a reboot always restarted the whole
18-trial loop from index 0 even with good persisted data already on
disk. Since the trial matrix is fully deterministic from (seed, n-reps),
resuming needs no persisted "which trials ran" state, just a count:
DOE-RESUME-COUNT (new kernel primitive, same pattern as
DOE-PERSIST-TRIAL) walks the ring counting CRC-valid records for a given
ISA; MU-EXEC-CAMPAIGN's signature changes to accept a start-idx and seeds
MU-RUN-ID/the DO loop from it. Each RUN-*-CAMPAIGN entry word now calls
DOE-RESUME-COUNT before launching. Both block-namespace-checked to fit
existing headroom before committing to the design -- no new blocks
needed.

Real bug caught by the build, not shipped: an implicit compiler-inserted
alignment byte before slot_crc silently broke the hand-computed trailing
pad size (doe_trial_slot_size_check failed to compile). Fixed with an
explicit alignment field, matching log_slot_t's own zero-implicit-
padding discipline.

extract_doe_region.py now verifies both CRCs with the REAL CRC-64/XZ
algorithm from block_subsystem.c's compute_crc64() (ported and verified
bit-for-bit against a native C reference this session), replacing
§XXXV.11's incorrect guessed implementation.

Verified: clean compile on all 3 ISAs (amd64/aarch64/riscv64 -- amd64
verified via isolated build only, not boot, since the real per-ISA
campaign is currently live on the only QEMU instance this project's own
rule allows), both capsules pass mkcapsule --lint, CRC64 bit-exact via
native reference. Live boot-verification explicitly deferred until that
campaign finishes or is interrupted -- not claimed as tested when it
wasn't. Found (not missed) a real compatibility consequence: the running
campaign's data is in the old pre-CRC format, so it reads as "corrupt"
under the new extractor and DOE-RESUME-COUNT will resume it from 0, not
mid-campaign -- no data loss, cheap redundant re-run of ~1-2 trials.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BWpNjdwPtFLuVLaAq44L9K
2026-09-17 19:17:04 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

include/starkernel/

Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/). Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared with hosted code.

  • uefi.h — UEFI protocol/type definitions consumed by the loader.
  • elf64.h, elf_loader.h — ELF64 parsing and kernel-image loading.
  • boot_info_offsets.h — struct-offset constants shared between the assembly bootstrap and the C boot path.
  • arch.h, apic.h, timer.h — architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).
  • console.h, framebuffer.h, vt100.h — UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.
  • pmm.h, vmm.h, kmalloc.h — physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.
  • pci.h, virtio_blk.h — PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).
  • capsule.h, capsule_birth.h, capsule_loader.h, capsule_run.h, capsule_vm_physics.h, capsule_generated.h — capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (see tools/mkcapsule.c).
  • kernel_args.h, cmdline.h — boot-time kernel argument parsing (starforth.cfg / command line).
  • repl.h — kernel REPL.
  • log.h, doe_log.h — kernel logging and DoE metrics logging.
  • q48_16.h — kernel-build copy of Q48.16 fixed-point arithmetic.
  • xxhash64.h — content-addressing hash used for capsule IDs.
  • hal_memory.h — hardware-abstraction-layer memory interface.

Subdirectories:

  • hal/ — top-level hardware-abstraction-layer interface.
  • vm/ — kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).
  • freestanding/ — minimal libc-shim headers (assert.h, ctype.h, errno.h, inttypes.h, math.h, sched.h, signal.h, stdio.h, stdlib.h, string.h, time.h, sys/time.h, sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.