Files
LithosAnanake/include/starkernel
Robert Allan JamesandClaude Sonnet 5 d9da82b065 Stage 4 increments 2+3: WIREBIND VMs as switch-signal participants + mark-and-defer tombstone reap (FABRIC-3.md §XXVIII Stage 4)
Increment 2: WIREBIND user VMs (the ones that actually run FORTH work;
console VMs are pure REPL proxies and never participate) register as
Stage 3 switch-signal participants at attach, unregister at teardown.
Slot table bumped 8 -> 16, matching messaging.4th's own VM-MAX -- a real,
already-agreed ceiling, not an invented number. Added
sk_vm_switch_signal_unregister() (compaction-based; Tripod VMs never
needed removal, WIREBIND VMs cycle constantly and would otherwise
exhaust the bounded table).

Increment 3: implements the plan's own ratified option (A) for the
async-detach UAF risk -- mark-and-defer via a new pending_reap flag on
VMRegistryEntry, deliberately not a new VMState (capsule_vm_kill()
already treats VM_STATE_DEAD as idempotent success, which would silently
swallow a reap attempt; SWITCHED_OUT still accurately describes a
tombstoned VM until the moment it's actually freed). unclean_detach()
sets it when capsule_vm_kill() refuses a SWITCHED_OUT target; the Stage 3
checkpoint (vm_core.c) checks it before ever attempting to resume a
pending switch target, and calls the new capsule_vm_force_reap() instead
-- the one caller allowed to bypass capsule_vm_kill()'s own refusal,
because it runs at the exact safe cooperative point the switcher itself
controls. A new idle-tick sweep cleans up the WIREBIND live-table entry
once the reap has actually happened.

Verified clean on all 3 architectures (baseline regression -- no
WIREBIND attach happens in a plain boot). The reap mechanism's own
correctness under a genuinely parked context is verified separately,
next, via a temporary deterministic probe.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BWpNjdwPtFLuVLaAq44L9K
2026-09-15 00:58:34 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

include/starkernel/

Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/). Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared with hosted code.

  • uefi.h — UEFI protocol/type definitions consumed by the loader.
  • elf64.h, elf_loader.h — ELF64 parsing and kernel-image loading.
  • boot_info_offsets.h — struct-offset constants shared between the assembly bootstrap and the C boot path.
  • arch.h, apic.h, timer.h — architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).
  • console.h, framebuffer.h, vt100.h — UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.
  • pmm.h, vmm.h, kmalloc.h — physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.
  • pci.h, virtio_blk.h — PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).
  • capsule.h, capsule_birth.h, capsule_loader.h, capsule_run.h, capsule_vm_physics.h, capsule_generated.h — capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (see tools/mkcapsule.c).
  • kernel_args.h, cmdline.h — boot-time kernel argument parsing (starforth.cfg / command line).
  • repl.h — kernel REPL.
  • log.h, doe_log.h — kernel logging and DoE metrics logging.
  • q48_16.h — kernel-build copy of Q48.16 fixed-point arithmetic.
  • xxhash64.h — content-addressing hash used for capsule IDs.
  • hal_memory.h — hardware-abstraction-layer memory interface.

Subdirectories:

  • hal/ — top-level hardware-abstraction-layer interface.
  • vm/ — kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).
  • freestanding/ — minimal libc-shim headers (assert.h, ctype.h, errno.h, inttypes.h, math.h, sched.h, signal.h, stdio.h, stdlib.h, string.h, time.h, sys/time.h, sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.