Files
LithosAnanake/src/word_source
Robert Allan JamesandClaude Sonnet 5 e5cbc71f46 Phase 8 C (2/n): expand cert storage; NVRAM persistence crashed, reverted
Cert storage expanded from the old 16-byte placeholder to a real
32-byte seed + 32-byte pubkey. vm_zuse_cert_install() now has a
kernel-side duplicate in src/starkernel/vm/vm_core.c -- the kernel
build's VM_EXCLUDE list drops src/vm.c entirely (same reason
vm_set_base() already has two independent copies), so the hosted-only
version added earlier this session was never actually linked into the
kernel. FORTH-side ZUSE-CERT-LO@/HI@ replaced with ZUSE-PUBKEY@ (i -- u)
over the public half only; ACL-ZUSE-BOOT now checks
ZUSE-CERT-INSTALLED? before authenticating instead of unconditionally.

Attempted NVRAM-based persistence (GetVariable/SetVariable) for the
first-boot mint flow: page-faulted inside OVMF's variable service
(CR2 in the flash MMIO window). Moving the call site to match the one
proven-safe existing SetVariable call site in this codebase produced
the identical crash -- not a timing issue. Localized with debug
markers (one boot): GetVariable works; SetVariable with real data
never returns. The existing "working" precedent call is actually a
delete-of-nonexistent-variable (size=0, data=NULL), a cheaper path
that never touches flash, so it proved nothing about real writes.
Root cause: this kernel's VMM never maps the region OVMF's variable
service needs for real flash writes -- a genuine gap in UEFI runtime-
services support, not Zuse-specific, and not obviously fixable in a
3-arch-uniform way (flash window location is firmware/arch-specific).

Independently, storing the raw seed in RUNTIME_ACCESS NVRAM would have
been a real security defect regardless of the crash -- readable by any
later-loaded UEFI app or the booted OS.

Reverted to a known-safe state: all NVRAM/mint code removed from
kernel_main.c, init.4th's ACL.4th line back to its documented
commented-out default. Verified clean compile and clean boot on all
three architectures. Cert storage expansion (the part that works)
stays. A dedicated system-identity disk (virtio-blk, already proven
for writes via Artemis) is the recommended next substrate -- not yet
decided or built. Full investigation documented in FABRIC-3.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
2026-08-26 15:55:27 -04:00
..

src/word_source/

FORTH-79 word implementations, one file per category, registered into the dictionary via include/word_registry.h. Each .c file here has a matching header in src/word_source/include/ and (for most categories) a matching test module in src/test_runner/modules/.

FORTH-79 core

  • arithmetic_words.c, mixed_arithmetic_words.c+ - * / MOD ABS MIN MAX and mixed-precision arithmetic.
  • stack_words.cDUP DROP SWAP ROT OVER NIP TUCK.
  • control_words.cIF ELSE THEN DO LOOP BEGIN UNTIL WHILE.
  • defining_words.c: ; CREATE DOES> VARIABLE CONSTANT.
  • memory_words.c@ ! C@ C! MOVE FILL.
  • return_stack_words.c>R R> R@ RDROP 2>R 2R@ 2R>.
  • double_words.c2DUP 2DROP 2SWAP 2@ 2! D+ D-.
  • logical_words.cAND OR XOR NOT INVERT LSHIFT RSHIFT.
  • io_words.cEMIT KEY TYPE CR TAB SPACE ACCEPT.
  • string_words.cS" SLITERAL and other string operations.
  • block_words.cBLOCK BUFFER LOAD THRU FLUSH.
  • format_words.c.( .R .S HEX DECIMAL BASE.
  • system_words.cBYE ABORT INCLUDE STATE.
  • dictionary_words.cFIND SEARCH-WORDLIST WORDS.
  • dictionary_manipulation_words.c — dictionary entry manipulation words.
  • vocabulary_words.cVOCABULARY DEFINITIONS FORTH-WORDLIST.
  • editor_words.c — block editor words.
  • defer_words.cDEFER/IS deferred-word mechanism, used by the Tripod message-dispatch shim (see tools/hermes_tripod_smoke.sh).

StarForth-specific extensions

  • q48_16_words.c, q48_words.c — Q48.16 fixed-point word bindings.
  • starforth_words.c — StarForth-specific extensions.
  • acl_words.c — word-level ACL system's FORTH-callable primitives (see docs/03-architecture/word-acl/).
  • lifecycle_words_hosted.c — hosted-build VM lifecycle words (birth/run primitives on the hosted side; kernel-only primitives live in src/starkernel/capsule/mama_forth_words.c).
  • log_words.c — FORTH-callable logging primitives.
  • inference_words.c — FORTH-callable bindings for the statistical inference engine (Loops #5/#6).
  • physics_benchmark_words.c — benchmark harness for the 7 physics feedback loops.
  • physics_diagnostic_words.c — physics diagnostics (WORD-ENTROPY).
  • physics_freeze_words.cPHYSICS-FREEZE / PHYSICS-THAW.
  • physics_pipelining_diagnostic_words.c — Loop #4 pipelining diagnostics.
  • dictionary_heat_diagnostic_words.c — Loop #1 heat diagnostics.

See src/word_source/include/ for the matching headers (also includes mama_forth_words.h, whose .c implementation lives under src/starkernel/capsule/ since it's kernel-only).