Rename FABRIC series: FABRIC.md->0, FABRIC-2.md->1, FABRIC-3.md->2, FABRIC-4.md unchanged

FABRIC.md -> FABRIC-0.md
FABRIC-2.md -> FABRIC-1.md
FABRIC-3.md -> FABRIC-2.md (the current/living document)
FABRIC-4.md unchanged (new #3 to follow separately)

Every cross-reference repo-wide updated to match, including doc-comment
citations inside kernel source (.c/.h) files -- done via an ordered
placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md->
placeholder1, FABRIC.md->placeholder0, then placeholders resolved to
final names) in a single pass per file to avoid double-shifting
already-renamed references.

One line in capsules/font.4th grew past the 64-char block-format limit
as a side effect of the longer filename; shortened it and reverified
with mkcapsule --lint (34/34 pass) before rebuilding.

Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the
foreground) after the fix; logs and DoE CSVs from this session's
verification runs included per this repo's own audit-artifact
convention.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
This commit is contained in:
Robert Allan James
2026-09-04 11:22:51 -04:00
co-authored by Claude Sonnet 5
parent ff2941dfb9
commit b031b802e3
128 changed files with 37154 additions and 9572 deletions
+2 -2
View File
@@ -16,7 +16,7 @@
*
* Base addresses and the PPI INTID are QEMU-virt-machine constants, not
* device-tree-discovered, and that is a deliberate, recorded exception
* rather than an oversight (FABRIC.md item 0.6, GAP-B1 follow-up):
* rather than an oversight (FABRIC-0.md item 0.6, GAP-B1 follow-up):
* `fdt_valid(boot_info->dtb)` fails on this system's aarch64 firmware
* (qemu-efi-aarch64 2025.11-3ubuntu7 does not forward a devicetree to the
* guest), confirmed live rather than assumed. The values below were not
@@ -168,7 +168,7 @@ int apic_init(BootInfo *boot_info)
* 3. @c GICD_ITARGETSR (byte-indexed like IPRIORITYR) -- routes to CPU 0
* only; this target has no @c -smp, so no other bit is ever valid.
* 4. @c GICD_ICFGR is read back, not written, unless the readback disagrees
* with the expected level-triggered configuration -- FABRIC.md §27.5.1's
* with the expected level-triggered configuration -- FABRIC-0.md §27.5.1's
* decoded QEMU `interrupt-map` says PCI legacy INTx on this board already
* is level-triggered by default, so this keeps item 0.6's "don't touch
* ICFGR unless forced to" posture rather than writing it unconditionally.
+2 -2
View File
@@ -33,7 +33,7 @@ static int s_current_el = -1;
*
* EDK2 on QEMU's aarch64 @c virt machine has been observed to leave the
* kernel at either EL1 or EL2 depending on firmware build; nothing in this
* tree may assume one over the other (FABRIC.md §25.7.1 GAP-B3). Every
* tree may assume one over the other (FABRIC-0.md §25.7.1 GAP-B3). Every
* EL-dependent choice — @c VBAR_EL1 vs @c VBAR_EL2, the @c ELR_ELx /
* @c SPSR_ELx saved-state pair, and @c CNTP_*_EL0 vs @c CNTHP_*_EL2 — must
* read this accessor rather than hardcode a level.
@@ -129,7 +129,7 @@ void arch_cold_reset(void)
* arguments and has no SMC64 variant defined by the PSCI spec -- only
* the SMC32 encoding is valid (fixed 2026-08-18, was 0xC4000009).
*
* FABRIC-2.md Section I, 2026-08-18: live gdb tracing (using the real
* FABRIC-1.md Section I, 2026-08-18: live gdb tracing (using the real
* UEFI-relocated runtime address, not the standalone kernel.elf's
* link-time address -- see that section for why those differ) proved
* the SMC call itself traps: PC does not fall through to the wfi loop
+2 -2
View File
@@ -20,7 +20,7 @@
/* ─── ARM generic-timer helpers ─────────────────────────────────────── */
/* FABRIC-3.md §I.5, 2026-09-04: real hypervisor-vs-hardware detection.
/* FABRIC-2.md §I.5, 2026-09-04: real hypervisor-vs-hardware detection.
* s_cal.vm_mode was hardcoded to 1 unconditionally below (comment:
* "QEMU SBSA always uses virtualised Generic Timer") -- true for the
* *timing policy* this file cares about, but wrong to reuse as a
@@ -260,7 +260,7 @@ const timer_calibration_record_t *timer_calibration_record(void)
/**
* @brief Read the raw counter the aarch64 heartbeat is paced against.
*
* Item 0.8 (FABRIC.md §25.1): the shared heartbeat.c now owns
* Item 0.8 (FABRIC-0.md §25.1): the shared heartbeat.c now owns
* heartbeat_init()/heartbeat_tick()/heartbeat_service()/heartbeat_ticks()/
* heartbeat_trust()/heartbeat_state() and the per-arch @c g_heartbeat
* state that used to live in this file. This is the one piece that stays
+1 -1
View File
@@ -24,7 +24,7 @@
/**
* i8042.c - PS/2 keyboard controller driver (amd64)
*
* Item 4.3.5 (FABRIC.md §27.5).
* Item 4.3.5 (FABRIC-0.md §27.5).
*/
#ifndef __STARKERNEL__
+1 -1
View File
@@ -24,7 +24,7 @@
/**
* ioapic.c - I/O APIC driver (amd64)
*
* Item 4.3.5 (FABRIC.md §27.5). MADT parsing mirrors pci.c's RSDP -> XSDT ->
* Item 4.3.5 (FABRIC-0.md §27.5). MADT parsing mirrors pci.c's RSDP -> XSDT ->
* table-by-signature walk (the two files don't share a header for this —
* same duplication pci.c already has relative to a hypothetical shared
* acpi.c, not introduced fresh here).
+3 -3
View File
@@ -134,7 +134,7 @@ static uint64_t vm_ns_base = 0;
* @p b are both large (e.g., nanosecond conversion of multi-GHz tick counts).
* No libgcc dependency — pure inline assembly.
*
* FABRIC.md item 4.5d, 2026-08-11: this asm previously declared @c RDX as a
* FABRIC-0.md item 4.5d, 2026-08-11: this asm previously declared @c RDX as a
* plain output (@c "=d"(hi)), which tells GCC only "I want to read RDX's
* value after this block" — nothing told it that @c mulq writes RDX *before*
* @c divq needs to read a *different* value (the divisor @c c) out of it.
@@ -604,7 +604,7 @@ static uint64_t calibrate_tsc_with_pmtimer(void)
uint64_t elapsed_ns = muldiv64(elapsed_ticks, 1000000000ull, PMTIMER_FREQ_HZ);
if (elapsed_ns == 0) return 0;
/* FABRIC.md item 4.5d, 2026-08-11: this file's own comments already
/* FABRIC-0.md item 4.5d, 2026-08-11: this file's own comments already
* flag TSC non-monotonicity as a real risk under TCG ("invariant
* TSC not present under hypervisor... no determinism guarantees").
* If end_tsc < start_tsc, this subtraction wraps to a huge unsigned
@@ -1378,7 +1378,7 @@ const timer_calibration_record_t *timer_calibration_record(void)
/**
* @brief Read the raw counter the amd64 heartbeat is paced against.
*
* Item 0.8 (FABRIC.md §25.1): the shared heartbeat.c owns
* Item 0.8 (FABRIC-0.md §25.1): the shared heartbeat.c owns
* heartbeat_init()/heartbeat_tick()/heartbeat_service()/heartbeat_ticks()/
* heartbeat_trust()/heartbeat_state() and the variance/trust math that used
* to live in this file. This is the one piece that stays per-architecture
+1 -1
View File
@@ -69,7 +69,7 @@ void arch_early_init(void)
* activated here, per its own load_cr3() no-op outside __x86_64__) and
* has no present use for virtual memory on this ISA, so there is no
* reason to inherit firmware's Sv57 mapping -- which is confirmed to
* have at least one hole (PLIC_THRESHOLD, FABRIC.md item 4.3.5a).
* have at least one hole (PLIC_THRESHOLD, FABRIC-0.md item 4.3.5a).
* ExitBootServices() has already completed several checkpoints before
* this function runs (ConOut/GOP done, BootServices exited per the
* "[CKPT 008]" trace), so nothing downstream depends on firmware's
+3 -3
View File
@@ -16,7 +16,7 @@
* mixing the two counters would compare unrelated clocks; and `cycle` has no
* discoverable frequency, so every heartbeat variance and TIME-TRUST figure
* riscv64 produced before this was measured against a wrong expected interval
* (FABRIC.md §16.2). Figures from before and after are not comparable.
* (FABRIC-0.md §16.2). Figures from before and after are not comparable.
*/
#include "timer.h"
@@ -27,7 +27,7 @@
#include <stdint.h>
#include <string.h>
/* FABRIC-3.md §I.5, 2026-09-04: real hypervisor-vs-hardware detection.
/* FABRIC-2.md §I.5, 2026-09-04: real hypervisor-vs-hardware detection.
* s_cal.vm_mode was hardcoded to 1 unconditionally below -- see
* aarch64/timer.c's own running_under_hypervisor() doc comment for why
* that's wrong to reuse as a general "are we in QEMU" signal elsewhere
@@ -265,7 +265,7 @@ const timer_calibration_record_t *timer_calibration_record(void)
/**
* @brief Read the raw counter the riscv64 heartbeat is paced against.
*
* Item 0.8 (FABRIC.md §25.1): the shared heartbeat.c now owns
* Item 0.8 (FABRIC-0.md §25.1): the shared heartbeat.c now owns
* heartbeat_init()/heartbeat_tick()/heartbeat_service()/heartbeat_ticks()/
* heartbeat_trust()/heartbeat_state(). This is the one piece that stays
* per-architecture -- the same @c rdtime() the timer deadline is armed