Scope decided with Captain Bob before implementation: ring buffer + recall on today's full-screen vt100 grid, not also confining REPL text to the 4.4o 640x480 box (that confinement stays open as its own future item, not a third silent deferral). No keyboard input path exists yet (M8 unstarted), so the trigger is two new FORTH words, SCROLL-BACK ( n -- ) / SCROLL-FWD ( n -- ), exercised via serial injection. vt100.c gains a text-only 1000-line ring buffer (kmalloc'd, tens of KB -- not pixel snapshots, which would be ~1000x larger for no benefit) plus a shadow buffer mirroring the current screen. scroll_up() now pushes evicted rows into the ring before the pixel scroll. History is one continuous sequence (ring then shadow); scrolling always redraws from that sequence -- no separate pixel-scroll path for scrollback, decided up front to avoid retrofitting later. New src/word_source/scroll_words.c (Module 31), thin wrappers over console_fb_scroll_back()/_fwd() -> vt100_scroll_back()/_fwd(). Bug caught during live testing: both words initially used an off-by-one underflow check (dsp < 1) copied from a different, older dsp convention elsewhere in this codebase; vm_pop() (which these words actually call) uses dsp as a 0-based top-of-stack index, so the check rejected every legitimate single-argument call. Fixed by removing the separate precheck and relying on vm_pop()'s own guard. Live-verified on all three architectures (exceeds this item's amd64-minimum bar): generated 50+ lines via a FORTH loop, confirmed SCROLL-BACK recovers correctly older content, and on amd64 confirmed SCROLL-FWD returns to genuinely live state (not a frozen snapshot) by showing the injected commands' own echo. Known limitation confirmed by direct pixel measurement: redrawn lines lose their original SGR color (not stored per-cell) -- text recovers exactly, color does not. Three-arch verified: Failed: 0, dict-hashes identical across all three (values changed correctly from prior items -- two new words were added). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
disk/
QEMU disk images used for Artemis (block-storage VM) persistence testing.
Mounted via Makefile.starkernel's ARTDISK variable (default
disk/artemis.img) as a virtio-blk-pci device on all three
architectures' kernel QEMU boots — not scripts/rundisk.sh, which targets
a separate, currently-unused disks/ (plural) directory for the hosted
VM's --disk-img= flag instead.
artemis.img— standard Artemis persistence test disk. Reformatted 2026-08-02: this image had been stuck in a corrupted state (validLithosAnankemagic header, but data not matching whatART-READ-TESTexpects) since before this repo's own git history begins (git logshows it already broken at the initial commit, carried over from the pre-split monorepo). Chasing down the resulting persistentFAIL: persist-readtraced to the data, not the code — the write→reboot→read round trip works correctly on a fresh image (seeartemis-debug-roundtrip.imgbelow). Reformatted by blanking the file and letting a normal boot format+write-test it; verifiedPASS: persist-readon amd64, aarch64, and riscv64 against the same image afterward (cross-arch resume, matching the arch-neutral on-disk format.claude/ARTEMIS.mdspecifies).artemis-debug-roundtrip.img— round-trip regression fixture created during that investigation. Known-good: format → self-test → write-test → reboot → resume →PASS: persist-read, confirmed 3 times in a row. Keep this in a passing state; if a future change breaks it, that's a real regression, not a stale-fixture artifact likeartemis.imgwas.artemis-persist-test.img— persistence round-trip test image (pre-existing; history/state not re-verified during the above investigation).artemis-poison.img— a separate test image (exact scenario not documented elsewhere in the repo as of this writing; name suggests an adversarial/corruption test, not confirmed).artemis-unrecognized-test.img— exercisesART-HALT-UNRECOG(.claude/ARTEMIS.mdacceptance criterion #6). Regenerated 2026-08-02: the previous copy of this file had itself been silently reformatted by a since-fixed bug in the generic block subsystem (src/block_subsystem.c) — it carried a valid low-level'STFR'/v2 header despite being meant to represent foreign disk content, direct forensic evidence of the bug described in.claude/ARTEMIS.md's Build Status item 6. Regenerated as 30MB of a repeatingPOISON-UNRECOGNIZED-DISK-TEST-FIXTURE--NOT-BLANK-NOT-STFR-NOT-ARTEMIS--ASCII pattern — deliberately neither blank, nor the block subsystem's own'STFR'magic, nor Artemis's"ARTEMIS\0"marker. Verified on amd64 and riscv64 post-fix: boot correctly halts (ARTEMIS HALT: unrecognized disk content) and the file's sha256 is now byte-for-byte identical before and after boot. Keep this fixture in this poisoned state — if a future change makes its sha256 change across a boot, that is exactly the regression this fixture exists to catch.
Note on incidental header churn: artemis.img picks up a few changed
header bytes on every ordinary boot even though no user data changes —
blk_subsys_attach_device() always records a fresh mounted_time on a
successfully recognized disk, which gets flushed at shutdown. This is
expected bookkeeping, not a bug; revert it before committing rather than
carrying timestamp noise in git history.
These are regenerable QEMU raw disk images, not source — see
.claude/ARTEMIS.md for the storage model they exercise.