Files
Robert Allan JamesandClaude Sonnet 5 c640f99211 Milestone 6: BLOCK_MAP.md signature-status column
--manifest mode's file scan is a completely separate code path from
build mode (only ever walks .4th files, never the embedded PKI cert or
font capsule) -- extended it to accept the same optional --sign-key
<path> prefix build mode already has, factoring the key-loading code
into a shared load_sign_key(), so the manifest can report real
per-capsule signing status without touching or requiring a rebuild of
capsule_generated.c.

New "Signed" column on the capsule summary table: yes/no when
--sign-key was given, n/a (with an explanatory footnote) when it
wasn't -- never a bare blank that could be misread as "unsigned".
Makefile.starkernel's manifest-generation call site now passes the same
SIGN_KEY_ARGS the real build uses, so capsules/BLOCK_MAP.md reflects
this machine's actual signed state by default.

Verified: clean compile, BLOCK_MAP.md correctly shows "yes" for all 31
tracked capsules on a real signed build; a quick amd64 boot (no kernel
code touched, host tooling only) confirmed no regression.

This closes every open Milestone 6 item except magic-number
content-type detection (shared with Milestone 4, not started) and the
hard-refuse flip (deliberately deferred). Documented in FABRIC-3.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
2026-08-26 21:43:50 -04:00
..

tools/

Build-time and integration-test utilities for the StarForth / LithosAnanke toolchain.

Contents

File Purpose
mkcapsule.c Assembles .4th capsule files into capsule_generated.c baked into the kernel image. Invoked automatically by Makefile.starkernel.
mkcapsule Compiled host binary (rebuilt on demand).
ttftest.c Host TTF glyph-rendering test — font rasterization unit tests, no QEMU needed.
pe_reloc_gen.py Generates PE32+ relocation tables for the UEFI loader.
svg_to_png.py Renders every tracked .svg in the repo to a same-named .png via headless Chromium; leaves the source .svg untouched, run manually.
hermes_smoke.sh Hermes v1 hosted smoke test — swaps in the Hermes init capsule and prints values for manual inspection.
hermes_channel_smoke.sh Exercises the full Hermes channel-negotiation lifecycle (CH-REQUESTCH-ACCEPTCH-CLOSE → reap) per the protocol in .claude/HERMES.md.
hermes_tripod_smoke.sh Full Tripod integration test — exercises all 6 inter-VM message paths using the DEFER VM-EXEC/IS VM-EXEC dispatcher shim from init.4th.
kconfig/ Vendored Linux kernel Kconfig tooling (conf/mconf/qconf), GPL-2.0. See tools/kconfig/README.md.

mkcapsule

# Invoked automatically by the kernel build:
make -f Makefile.starkernel ARCH=amd64 clean qemu

# Manual invocation (for inspection):
./tools/mkcapsule capsules/ build/amd64/kernel/capsule_generated.c

Scans capsules/ for .4th files, computes XXHash64 per capsule, assigns type (m) to init.4th and (p) to everything else.

See also