All found by actually running the identity workflow §VII/§VIII made
possible, not by code review:
1. Zuse/WIREBIND cross-contamination on detach: capsule_zuse_boot_logout()
and capsule_wirebind_unclean_detach() both had no device parameter, so
an unrelated device detaching (while the real owner's own stayed
attached) incorrectly tore down the wrong session. Both now compare
the departing device against their own tracked one, mirroring
capsule_wirebind.c's pre-existing g_wirebind_attached_dev precedent.
2. Dictionary-entry memory leak: vm_create_word()'s sf_malloc()'d
DictEntry (plus a second per-entry allocation for transition_metrics)
was never freed by vm_cleanup(), in both the hosted and kernel
implementations. Caused a real kernel PANIC after 8-9 repeated VM
birth/kill cycles in one boot. Fixed by walking vm->latest in both.
3. sf_malloc/sf_free (alloc_kernel.c) was a 4MB bump arena with a
deliberate no-op free, sized on "VM born once, never killed" -- fix#2
alone didn't stop the panic because free() itself discarded the
pointer regardless. Given a real free list (first-fit reuse).
4. Headless-console gate didn't re-engage after a mid-boot logout: the
original fix (sk_console_mark_login(), one-way sticky) only gated the
first login of the boot. Replaced with a live check
(sk_console_identity_present()) re-evaluated continuously, including
inside sk_console_readline()'s own blocking idle loop -- the console
is normally sitting blocked there when a hot-unplug logout happens, so
checking only at the top of the REPL loop wasn't enough.
Also: MINT now verifies its own write (verify_mint(), capsule_mint.c) by
reading back through the same check a real attach performs, rather than
trusting blkio_write()'s BLK_OK alone -- logged via log_message(), not
console_println(), per direct instruction.
Verified live, amd64: the full 8-identity repeated attach/detach cycle
that previously panicked at the same point every time now completes
clean, and a full serial-log sweep found zero bare unauthenticated
prompts anywhere in the run. Three-arch clean-qemu acceptance passed.
Still open, not fixed here: a 3+-simultaneous-device USB enumeration
failure found in a separate live test, not yet root-caused.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018EjXFo7mPXjUMjfJeuUUz4