Found and fixed a real bug before any campaign work could start: EXEC-DOE's own CSV output was almost entirely lost to console interleaving with the routine per-tick heartbeat export -- same bug class as Section L's PLOT case. Fix: HB-OFF immediately before EXEC-DOE, HB-ON after DOE: complete. Confirmed HB-ON-first (the reverse order) does NOT fix it -- tested directly, row loss recurred identically. Also found: L8-DOE/WL-HI/WL-LO (the mechanism bare_metal/README.md describes as auto-run) don't exist anywhere in capsules/, and Makefile. starkernel's DOE_SEED variable is declared but never referenced -- both vestigial, matching Section K's earlier staleness finding. Built QEMU-serial-socket injection tooling (socat) to drive EXEC-DOE interactively after boot, since it requires live REPL input, not just observation. Two real defects found and fixed in that tooling itself: a log-discovery race (self-excluding the very log it needed to find, causing two separate stuck-injector incidents, one overnight) and an unredirected background launch that deadlocked socat on a full stdout pipe. Both fixed by having the orchestrator pass exact log/socket paths directly and always launching through the harness's tracked-background mechanism. First full campaign attempt ran all 9 cells as three ISA-blocked loops, reusing one build per architecture -- caught mid-run: this confounds ISA with time/session-order, invalidating the Latin square design. Discarded (logs kept as audit artifacts, not treated as valid data) and re-run clean: all 9 (arch, seed) cells in fully randomized order, fresh clean rebuild before every single cell, one continuous sitting. Result: 4,320/4,320 rows captured, zero VM errors anywhere. This validates the campaign mechanism runs cleanly and reproducibly under the post-4.6 Stadium substrate -- satisfies item 5.1's own concern that a green POST suite isn't evidence determinism holds post-migration. It does NOT produce an ACL-RWT overhead number: ACL.4th is not self-activated in this repo's default init.4th, so these 9 cells ran with ACL inactive. Reproducing the original +0.0054%-+0.0088% measurement needs a paired ACL-enabled/disabled run using this now-validated mechanism -- scoped, not attempted here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
disk/
QEMU disk images used for Artemis (block-storage VM) persistence testing.
Mounted via Makefile.starkernel's ARTDISK variable (default
disk/artemis.img) as a virtio-blk-pci device on all three
architectures' kernel QEMU boots — not scripts/rundisk.sh, which targets
a separate, currently-unused disks/ (plural) directory for the hosted
VM's --disk-img= flag instead.
artemis.img— standard Artemis persistence test disk. Reformatted 2026-08-02: this image had been stuck in a corrupted state (validLithosAnankemagic header, but data not matching whatART-READ-TESTexpects) since before this repo's own git history begins (git logshows it already broken at the initial commit, carried over from the pre-split monorepo). Chasing down the resulting persistentFAIL: persist-readtraced to the data, not the code — the write→reboot→read round trip works correctly on a fresh image (seeartemis-debug-roundtrip.imgbelow). Reformatted by blanking the file and letting a normal boot format+write-test it; verifiedPASS: persist-readon amd64, aarch64, and riscv64 against the same image afterward (cross-arch resume, matching the arch-neutral on-disk format.claude/ARTEMIS.mdspecifies).artemis-debug-roundtrip.img— round-trip regression fixture created during that investigation. Known-good: format → self-test → write-test → reboot → resume →PASS: persist-read, confirmed 3 times in a row. Keep this in a passing state; if a future change breaks it, that's a real regression, not a stale-fixture artifact likeartemis.imgwas.artemis-persist-test.img— persistence round-trip test image (pre-existing; history/state not re-verified during the above investigation).artemis-poison.img— a separate test image (exact scenario not documented elsewhere in the repo as of this writing; name suggests an adversarial/corruption test, not confirmed).artemis-unrecognized-test.img— exercisesART-HALT-UNRECOG(.claude/ARTEMIS.mdacceptance criterion #6). Regenerated 2026-08-02: the previous copy of this file had itself been silently reformatted by a since-fixed bug in the generic block subsystem (src/block_subsystem.c) — it carried a valid low-level'STFR'/v2 header despite being meant to represent foreign disk content, direct forensic evidence of the bug described in.claude/ARTEMIS.md's Build Status item 6. Regenerated as 30MB of a repeatingPOISON-UNRECOGNIZED-DISK-TEST-FIXTURE--NOT-BLANK-NOT-STFR-NOT-ARTEMIS--ASCII pattern — deliberately neither blank, nor the block subsystem's own'STFR'magic, nor Artemis's"ARTEMIS\0"marker. Verified on amd64 and riscv64 post-fix: boot correctly halts (ARTEMIS HALT: unrecognized disk content) and the file's sha256 is now byte-for-byte identical before and after boot. Keep this fixture in this poisoned state — if a future change makes its sha256 change across a boot, that is exactly the regression this fixture exists to catch.
Note on incidental header churn: artemis.img picks up a few changed
header bytes on every ordinary boot even though no user data changes —
blk_subsys_attach_device() always records a fresh mounted_time on a
successfully recognized disk, which gets flushed at shutdown. This is
expected bookkeeping, not a bug; revert it before committing rather than
carrying timestamp noise in git history.
These are regenerable QEMU raw disk images, not source — see
.claude/ARTEMIS.md for the storage model they exercise.