Files
LithosAnanake/tools
Robert Allan JamesandClaude Sonnet 5 eeceec21a5 FABRIC-3.md §I.5: Milestone 7 trust tiers (QEMU-vs-real-hardware), closing it
Closes the contributor-capsule/trust-tier punch-list item. Decided
direction: QEMU-vs-real-hardware conditional enforcement.

Found before building on that decision: the obvious mechanism (expose
TimerInfo.vm_mode) only works on amd64 -- aarch64 and riscv64 both had
vm_mode hardcoded to 1 unconditionally, meaning they'd always report
"running under QEMU" even on real hardware. Built real detection for
both instead of shipping that: aarch64 checks the ACPI RSDP's OEM ID
for QEMU's "BOCHS " SeaBIOS-heritage signature; riscv64 checks the
devicetree root compatible property for "qemu". Confirmed vm_mode was
otherwise unread anywhere else in either file first -- zero risk to
existing timing behavior.

CAPSULE_FLAG_CONTRIB (mkcapsule.c: FLAG_CONTRIB) path-matches on
capsules/contrib/, mirroring FLAG_MAMA_INIT's exact-match pattern.
contrib_capsule_refused() (capsule_birth.c) enforces: no additional
check under QEMU (same WARN-only as everything else); on real hardware,
a contrib capsule additionally requires CAPSULE_SIG_OK, since it has no
other provenance to fall back on. Wired into capsule_birth_baby() and
capsule_run_experiment().

Also updates §I.7 (Milestone 9): its stated precondition (Milestone 7
closing) is now met, flagged as stale rather than treated as a green
light to design networking from nothing.

Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the
foreground) -- compile/boot verification only; the real-hardware
enforcement branch is unverifiable from this environment, same as all
of §I.6. logs and DoE CSVs from this session's verification runs
included per this repo's own audit-artifact convention.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
2026-09-04 11:04:25 -04:00
..

tools/

Build-time and integration-test utilities for the StarForth / LithosAnanke toolchain.

Contents

File Purpose
mkcapsule.c Assembles .4th capsule files into capsule_generated.c baked into the kernel image. Invoked automatically by Makefile.starkernel.
mkcapsule Compiled host binary (rebuilt on demand).
ttftest.c Host TTF glyph-rendering test — font rasterization unit tests, no QEMU needed.
pe_reloc_gen.py Generates PE32+ relocation tables for the UEFI loader.
svg_to_png.py Renders every tracked .svg in the repo to a same-named .png via headless Chromium; leaves the source .svg untouched, run manually.
hermes_smoke.sh Hermes v1 hosted smoke test — swaps in the Hermes init capsule and prints values for manual inspection.
hermes_channel_smoke.sh Exercises the full Hermes channel-negotiation lifecycle (CH-REQUESTCH-ACCEPTCH-CLOSE → reap) per the protocol in .claude/HERMES.md.
hermes_tripod_smoke.sh Full Tripod integration test — exercises all 6 inter-VM message paths using the DEFER VM-EXEC/IS VM-EXEC dispatcher shim from init.4th.
kconfig/ Vendored Linux kernel Kconfig tooling (conf/mconf/qconf), GPL-2.0. See tools/kconfig/README.md.

mkcapsule

# Invoked automatically by the kernel build:
make -f Makefile.starkernel ARCH=amd64 clean qemu

# Manual invocation (for inspection):
./tools/mkcapsule capsules/ build/amd64/kernel/capsule_generated.c

Scans capsules/ for .4th files, computes XXHash64 per capsule, assigns type (m) to init.4th and (p) to everything else.

See also