FABRIC.md -> FABRIC-0.md FABRIC-2.md -> FABRIC-1.md FABRIC-3.md -> FABRIC-2.md (the current/living document) FABRIC-4.md unchanged (new #3 to follow separately) Every cross-reference repo-wide updated to match, including doc-comment citations inside kernel source (.c/.h) files -- done via an ordered placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md-> placeholder1, FABRIC.md->placeholder0, then placeholders resolved to final names) in a single pass per file to avoid double-shifting already-renamed references. One line in capsules/font.4th grew past the 64-char block-format limit as a side effect of the longer filename; shortened it and reverified with mkcapsule --lint (34/34 pass) before rebuilding. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground) after the fix; logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
capsules/contrib/
Milestone 7 (contributor capsules / trust tiers), FABRIC-2.md §I.5.
Any .4th file placed here gets FLAG_CONTRIB in addition to the usual
FLAG_PRODUCTION | FLAG_EXPERIMENT pair — tools/mkcapsule.c's
flags_from_name() path-matches on the colon-separated capsule name
starting with contrib:, mirroring FLAG_MAMA_INIT's own exact-match
pattern one line up in that same function.
Trust-tier direction, decided in conversation 2026-09-04: QEMU-vs-real-
hardware conditional enforcement — a contributor capsule is validated more
strictly on real hardware than under QEMU, using
timer_calibration_record()->vm_mode (include/starkernel/timer.h) as the
signal. vm_mode is a real per-architecture hypervisor-vs-hardware
detection as of this same pass (amd64: CPUID.1:ECX[31]; aarch64: ACPI
RSDP OEM ID; riscv64: devicetree compatible string) — not a build-time
flag, so the same binary enforces differently depending on where it
actually boots.
Enforcement rule, built 2026-09-04: contrib_capsule_refused()
(capsule_birth.c), called from both capsule_birth_baby() and
capsule_run_experiment() (never capsule_birth_mama() — Mama's own init
can never carry FLAG_CONTRIB, mutually exclusive with FLAG_MAMA_INIT by
construction). Under QEMU (vm_mode == 1): no additional check, same
WARN-only treatment every other capsule gets. On real hardware
(vm_mode == 0): a contrib capsule additionally requires CAPSULE_SIG_OK
— MISSING/NO_ROOT_KEY, which stay WARN-only for every other capsule
(most machines lack the offline signing key), are refused here specifically
because a contributor's capsule has no other provenance to fall back on.
Additive to, never a replacement for, the existing CAPSULE_SIG_INVALID
refusal already enforced on every capsule regardless of FLAG_CONTRIB.