Files
LithosAnanake/src/starkernel
Robert Allan JamesandClaude Sonnet 5 d9da82b065 Stage 4 increments 2+3: WIREBIND VMs as switch-signal participants + mark-and-defer tombstone reap (FABRIC-3.md §XXVIII Stage 4)
Increment 2: WIREBIND user VMs (the ones that actually run FORTH work;
console VMs are pure REPL proxies and never participate) register as
Stage 3 switch-signal participants at attach, unregister at teardown.
Slot table bumped 8 -> 16, matching messaging.4th's own VM-MAX -- a real,
already-agreed ceiling, not an invented number. Added
sk_vm_switch_signal_unregister() (compaction-based; Tripod VMs never
needed removal, WIREBIND VMs cycle constantly and would otherwise
exhaust the bounded table).

Increment 3: implements the plan's own ratified option (A) for the
async-detach UAF risk -- mark-and-defer via a new pending_reap flag on
VMRegistryEntry, deliberately not a new VMState (capsule_vm_kill()
already treats VM_STATE_DEAD as idempotent success, which would silently
swallow a reap attempt; SWITCHED_OUT still accurately describes a
tombstoned VM until the moment it's actually freed). unclean_detach()
sets it when capsule_vm_kill() refuses a SWITCHED_OUT target; the Stage 3
checkpoint (vm_core.c) checks it before ever attempting to resume a
pending switch target, and calls the new capsule_vm_force_reap() instead
-- the one caller allowed to bypass capsule_vm_kill()'s own refusal,
because it runs at the exact safe cooperative point the switcher itself
controls. A new idle-tick sweep cleans up the WIREBIND live-table entry
once the reap has actually happened.

Verified clean on all 3 architectures (baseline regression -- no
WIREBIND attach happens in a plain boot). The reap mechanism's own
correctness under a genuinely parked context is verified separately,
next, via a temporary deterministic probe.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BWpNjdwPtFLuVLaAq44L9K
2026-09-15 00:58:34 -04:00
..
2026-09-01 12:07:32 -04:00

src/starkernel/

LithosAnanke — the bare-metal UEFI kernel that boots StarForth directly on hardware (amd64/aarch64/riscv64). Built only via Makefile.starkernel; the only valid acceptance test is the three-arch QEMU boot (see .claude/CLAUDE.md), never make test.

  • kernel_main.c — kernel entry point, driving the boot milestones (console init, PMM, VMM, interrupts, timers, kmalloc heap, VM bootstrap).
  • repl.c — kernel REPL.
  • doe_log.c — kernel-side DoE (Design of Experiments) metrics logging.

Subdirectories:

  • arch/{amd64,aarch64,riscv64}/ — per-architecture support (APIC/GIC/ PLIC interrupt controller, timers, boot/ISR assembly).
  • boot/ — UEFI loader, ELF loading, kernel command-line parsing.
  • capsule/ — capsule birth/run/load/validate pipeline.
  • hal/ — hardware-abstraction-layer implementation (console, framebuffer, VT100, memory, host services).
  • hash/ — XXHash64 content-addressing implementation.
  • math/ — kernel-build Q48.16 fixed-point arithmetic.
  • memory/ — physical/virtual memory managers and the kernel heap.
  • pci/ — PCI bus enumeration.
  • virtio/ — VirtIO block device driver.
  • vm/ — kernel VM subsystem (bootstrap, core interpreter, parity logging, capsule arena).

See include/starkernel/README.md for the corresponding headers.