Robert Allan JamesandClaude Opus 5 f3821ed686 riscv64: real trap entry with save/restore and SRET return
Punch list §25 item 0.2 complete.

Verified: riscv64 builds clean and boots to the ok> prompt with no regression;
dict_hash 0x3d4e1daf289da94f, unchanged from item 0.1's baseline. Disassembly
confirms the 320-byte frame, all 16 integer caller-saved registers, the FS
check, and SRET on exit; riscv64_trap_entry lands at 0x414fa8, 4-byte aligned
as stvec direct mode requires.

Not verified, and the item says so: neither new path was exercised. No timer is
armed until 0.3, so riscv64_interrupt_handler never ran, and no exception
occurred during boot, so the fatal path was not observed -- it is preserved
structurally, same branch to the same unchanged handler. This is why C2
rewrote the acceptance to no-regression rather than to having taken and
returned from a trap.

Register set is the LP64D psABI caller-saved list, not this document's summary:
integer ra/t0-t6/a0-a7 (16), FP ft0-ft11/fa0-fa7 (20) plus fcsr, and sepc +
sstatus. Callee-saved registers are the C handler's responsibility.

The FP half is conditional on sstatus.FS != Off, which the item did not
anticipate. Nothing in boot.S or kernel_entry.S programs FS, so its value is
whatever firmware leaves; touching an f-register with FS == Off raises an
illegal-instruction trap, and doing that inside the trap handler would be
unrecoverable. Omitting the FP save is not an option either -- the built
riscv64 image contains 530 FP instructions (fld, fmul.d, fcvt.lu.d among them),
confirming B2's finding against the binary rather than the build flags alone.
So the save is conditional, and sstatus is restored after the f-registers.

Dispatch: scause bit 63 routes to riscv64_interrupt_handler with scause in a0;
cause 5 (supervisor timer) calls heartbeat_tick(). Other causes are ignored
rather than fatal -- none are enabled to arrive. Everything else still falls
through to riscv64_exception_handler, unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-03 12:52:34 -04:00
2026-08-01 07:49:56 -04:00
2026-08-02 05:11:24 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 15:51:53 -04:00
2026-08-02 05:11:24 -04:00

LithosAnanke v1.5.4

UEFI-bootable FORTH microkernel. Boots from firmware, initialises memory and interrupts, then runs the StarForth VM as its sole userspace runtime. No libc. No OS. Just stone and necessity.

Lithos (foundation) + Ananke (necessity) — the kernel under StarshipOS.


Status — M7.1 (Capsule System · Multi-VM Fleet)

Milestone Status
M0M6 UEFI boot · PMM · VMM · IDT · APIC · heap · framebuffer VT100 console (v1.5.1-FINAL) Complete
M7 StarForth VM integration + parity validation Complete
M7.1 Capsule birth protocol · Mama FORTH vocabulary · Tripod multi-VM fleet (Hermes/Artemis) · Word-level ACL (Phases 17) 🔄 In Progress
M8 REPL — keyboard input, interactive Forth Planned
M9 Block storage — AHCI driver Planned

POST at boot: parity hash verified across amd64/aarch64/riscv64 · Mama capsule dictionary: 453 words

What's live in M7.1

  • Tripod — a named multi-VM fleet (Hera the Mama VM, Artemis, two Hermes instances) births, runs, and re-births independently, verified booting live pre-REPL on all three architectures.
  • Hermes — a 17-block inter-VM messaging/channel layer between fleet members, with async delivery and channel negotiation.
  • Artemis — a Block Allocation Map (BAM) storage subsystem with Q48.16 block-heat tracking and cooldown/reclamation (ART-COOL/ART-REAP).
  • Word-level ACL — every dictionary entry carries a TTL/allow/mode/pin access-control record. Strict, TTL, and pinned modes; two console layers (emergency ok> and superuser zuse)ok>). Phases 17 complete (C infrastructure, FORTH policy layer, zuse bootstrap superuser, Isabelle proof stubs, kernel parity); Phase 8 (Ed25519 PKI / thumbdrive challenge-response) is the only item remaining. Measured overhead once active on every check: +0.0054%+0.0088%, CV = 0.000%, across a 3×3 Latin-square DoE campaign (architecture × seed × 30 replicates) — three orders of magnitude below the measurement floor.
  • VM Fleet Attractor physics — the L8 Jacquard mode selector now has a real per-VM heat channel into fleet-wide tuning, replacing hardcoded compudynamics constants with a dynamically-inferred rate.
  • Kconfig build configuration — every physics/heartbeat/pipelining/ kernel-only tuning knob (~40 total) is now a discoverable, optional Kconfig symbol shared with the hosted VM build. See Quick Start below.

Quick Start

# Build kernel (requires cross-compilation toolchain, or native gcc)
make -f Makefile.starkernel ARCH=amd64

# Run in QEMU with OVMF
make -f Makefile.starkernel qemu

# Other architectures
make -f Makefile.starkernel ARCH=aarch64 qemu
make -f Makefile.starkernel ARCH=riscv64 qemu

Artifacts: build/amd64/kernel/starkernel_loader.efi · build/amd64/kernel/starkernel_kernel.elf

For the hosted VM by itself (Linux, no cross-compiler needed, no bare-metal tooling): see the separate StarForth repository — LithosAnanke used to be a branch inside that repo, now it's its own project with its own master.

Build configuration (optional)

Every kernel-only knob (STARFORTH_ENABLE_VM, PARITY_MODE, the shared physics/heartbeat family, etc.) is an optional Kconfig symbol — a plain make -f Makefile.starkernel uses the same defaults it always has unless you opt in:

make -f Makefile.starkernel ARCH=amd64 menuconfig
make -f Makefile.starkernel ARCH=amd64 kernel_amd64_defconfig

Documentation

System Architecture Full kernel + VM design
HAL Reference Hardware abstraction layer interfaces
Capsule System — M7.1 Capsule birth protocol design
VM Fleet Attractor design log Tripod/Hermes/Artemis physics + build-system history
Getting Started / Kconfig reference Full symbol reference for both build targets
Changelog Milestone-level history
Roadmap Milestone plan through self-hosting

License

Starship License 1.0 (SL-1.0) — free for personal, research, and educational use. Commercial use requires a separate agreement. Attribution to R.A. James (Captain Bob) must be preserved in all distributions.

Patent pending. USPTO provisional filed December 2025 — physics-grounded self-adaptive runtime system. This license does not grant patent rights. Licensing inquiries: rajames440@gmail.com


Robert A. James (Captain Bob) · Systems Engineer · Hacking since 1973

S
Description
No description provided
Readme
1.3 GiB
Languages
C 70.4%
Isabelle 11.8%
TeX 5.2%
Shell 3.8%
R 2.8%
Other 6%