Closes both remaining Milestone 6 (PKI) punch-list items. Signature-status column: doc-only closure -- the underlying need was already redirected to capsules/BLOCK_MAP.md's real Signed column (2026-08-26); checking the box off as moot-as-worded rather than leaving an accurate-but-permanently-unchecked marker. Magic-number content-type detection (Section U item 14): built in tools/mkcapsule.c. detect_content_type() classifies a file's actual leading bytes (TTF/OpenType sfnt tags, DER's 0x30 SEQUENCE tag, or a printable-ASCII/TAB/CR/LF heuristic for text) against expected_type_from_ext()'s .4th/.md/.der/.ttf mapping; process_file() warns on mismatch, never refuses -- same WARN-first rollout this project already used for capsule signing. Verified against every real capsule in the repo (38 files) with zero false positives. This is the shared primitive Milestone 7's contrib-capsule validation can reuse next. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground); logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
tools/
Build-time and integration-test utilities for the StarForth / LithosAnanke toolchain.
Contents
| File | Purpose |
|---|---|
mkcapsule.c |
Assembles .4th capsule files into capsule_generated.c baked into the kernel image. Invoked automatically by Makefile.starkernel. |
mkcapsule |
Compiled host binary (rebuilt on demand). |
ttftest.c |
Host TTF glyph-rendering test — font rasterization unit tests, no QEMU needed. |
pe_reloc_gen.py |
Generates PE32+ relocation tables for the UEFI loader. |
svg_to_png.py |
Renders every tracked .svg in the repo to a same-named .png via headless Chromium; leaves the source .svg untouched, run manually. |
hermes_smoke.sh |
Hermes v1 hosted smoke test — swaps in the Hermes init capsule and prints values for manual inspection. |
hermes_channel_smoke.sh |
Exercises the full Hermes channel-negotiation lifecycle (CH-REQUEST → CH-ACCEPT → CH-CLOSE → reap) per the protocol in .claude/HERMES.md. |
hermes_tripod_smoke.sh |
Full Tripod integration test — exercises all 6 inter-VM message paths using the DEFER VM-EXEC/IS VM-EXEC dispatcher shim from init.4th. |
kconfig/ |
Vendored Linux kernel Kconfig tooling (conf/mconf/qconf), GPL-2.0. See tools/kconfig/README.md. |
mkcapsule
# Invoked automatically by the kernel build:
make -f Makefile.starkernel ARCH=amd64 clean qemu
# Manual invocation (for inspection):
./tools/mkcapsule capsules/ build/amd64/kernel/capsule_generated.c
Scans capsules/ for .4th files, computes XXHash64 per capsule, assigns
type (m) to init.4th and (p) to everything else.
See also
capsules/README.md— capsule file format and block namespaceMakefile.starkernel— kernel build system- Project root