Second stage of the preemptive context-switching plan. Every VM (Hera, every capsule_birth_baby()-born VM including WIREBIND identities) now gets its own dedicated 2 MiB native C stack at birth -- but nothing runs on it yet, that's Stage 2. Pure allocation-machinery proof. Design correction made before writing code: the plan called for cloning sk_vm_arena_alloc()'s guard-page pattern, but that pattern turns out to be Mama-only -- host_services.c's kernel_alloc() gives every baby VM a plain kmalloc() block for its dictionary arena, not a real guarded PMM allocation. Stacks get the real treatment instead (new sk_vm_native_stack_alloc()/_free() in arena.c): independent pmm_alloc_contiguous() + guard pages for every VM without exception, no singleton, no kmalloc fallback -- a stack overflow is exactly the failure mode guard pages exist for, and a corrupted stack could corrupt whatever saved context Stage 2 trusts. 2 MiB size matches this project's own established kernel-stack convention (g_kernel_stack/g_rpi5_native_stack), not a guess -- that one shared 2 MiB stack today already carries all VMs' combined nested VM-EXEC recursion. Three new VM struct fields, freed in vm_cleanup() alongside the existing call_stack free. Allocation failure is non-fatal to birth. All 3 architectures re-verified clean boot to ok>, no native-stack allocation failures for any Tripod-fleet VM. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016UNhH1mhi52i6Qihh7ZV5S
include/starkernel/
Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/).
Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared
with hosted code.
uefi.h— UEFI protocol/type definitions consumed by the loader.elf64.h,elf_loader.h— ELF64 parsing and kernel-image loading.boot_info_offsets.h— struct-offset constants shared between the assembly bootstrap and the C boot path.arch.h,apic.h,timer.h— architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).console.h,framebuffer.h,vt100.h— UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.pmm.h,vmm.h,kmalloc.h— physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.pci.h,virtio_blk.h— PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).capsule.h,capsule_birth.h,capsule_loader.h,capsule_run.h,capsule_vm_physics.h,capsule_generated.h— capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (seetools/mkcapsule.c).kernel_args.h,cmdline.h— boot-time kernel argument parsing (starforth.cfg/ command line).repl.h— kernel REPL.log.h,doe_log.h— kernel logging and DoE metrics logging.q48_16.h— kernel-build copy of Q48.16 fixed-point arithmetic.xxhash64.h— content-addressing hash used for capsule IDs.hal_memory.h— hardware-abstraction-layer memory interface.
Subdirectories:
hal/— top-level hardware-abstraction-layer interface.vm/— kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).freestanding/— minimal libc-shim headers (assert.h,ctype.h,errno.h,inttypes.h,math.h,sched.h,signal.h,stdio.h,stdlib.h,string.h,time.h,sys/time.h,sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.