FABRIC-3.md §H.10: verify dictionaries are per-VM, not shared
Checked the load-bearing assumption underneath the word card's creator-ceiling invariant and the H.5 elevation trigger, both of which live on DictEntry ACL fields -- confirmed each VM gets its own separate memory/dictionary buffer at birth (vm_bootstrap.c:181), so DictEntry ACL state is already naturally scoped per-session. No conflict, no redesign. Also notes two smaller, lower-risk open items: pin-authority sync between Session and Stadium's flag, and the elevation trigger's dependency on not-yet-real Hermes messaging. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
ba97623349
commit
a93d4fa2cd
+26
@@ -3730,3 +3730,29 @@ Explicitly open items surfaced during this capture pass, none decided yet:
|
|||||||
H.4–H.8, is design capture only — no struct has been written, no `stadium_birth_hermes()`/
|
H.4–H.8, is design capture only — no struct has been written, no `stadium_birth_hermes()`/
|
||||||
`_artemis()` exists, no `Session` header exists. Standard for this document's own
|
`_artemis()` exists, no `Session` header exists. Standard for this document's own
|
||||||
discipline (see D's intro), but worth stating plainly given the size of this section.
|
discipline (see D's intro), but worth stating plainly given the size of this section.
|
||||||
|
|
||||||
|
### H.10 — Verification pass: "are we painting ourselves into a corner?" (2026-09-02)
|
||||||
|
|
||||||
|
Asked directly by Captain Bob. One load-bearing assumption underneath H.3/H.5 got checked
|
||||||
|
against the live code rather than left as an inference.
|
||||||
|
|
||||||
|
**The risk**: the word card's creator-ceiling invariant and the H.5 elevation trigger both
|
||||||
|
live on `DictEntry` (`acl_allow`/`acl_ttl`), which only works per-session if each VM has its
|
||||||
|
own separate dictionary — a shared/global dictionary would make a single `acl_allow` bit
|
||||||
|
unable to mean "yes for session A, no for session B" on the same word.
|
||||||
|
|
||||||
|
**Verified true, no conflict, no redesign needed.** `struct VM` (`include/vm.h:410-412`) owns
|
||||||
|
its own `uint8_t* memory` buffer and its own `DictEntry* latest` chain; `vm_bootstrap.c:181`
|
||||||
|
(`vm->memory = (uint8_t*)vm_host_alloc(vm, VM_MEMORY_SIZE, ...)`) allocates a fresh,
|
||||||
|
independent memory/dictionary buffer on every VM birth. Hera, Hermes, Artemis, and any future
|
||||||
|
child each get their own separate dictionary — `DictEntry` ACL fields are already naturally
|
||||||
|
scoped per-session. H.3's stack-of-cards model and H.5's word card/elevation trigger stand as
|
||||||
|
decided, unchanged by this check.
|
||||||
|
|
||||||
|
Two smaller, lower-risk items flagged in the same pass, not yet acted on:
|
||||||
|
- **Pin-authority sync risk (H.2).** Session.pinned is authoritative over Stadium's
|
||||||
|
`STADIUM_FLAG_PIN` bit — needs a single choke-point API so nothing ever writes the Stadium
|
||||||
|
flag directly and lets the two drift out of sync. Not yet designed.
|
||||||
|
- **Elevation trigger not yet usable (H.5/H.7).** Rides Hermes messaging, which per this
|
||||||
|
document's own standing completion criterion (D.1) isn't the real implementation yet.
|
||||||
|
Correct on paper, not usable until that substrate exists — expected, not a flaw.
|
||||||
|
|||||||
Reference in New Issue
Block a user