fix(os): cover full spec behavior-descriptor set (PDF §524-525)

cb.rs previously implemented only 3 of the 6 spec descriptors (pure/io/hot).
PDF §524-525 lists: pure function, I/O heavy, allocates memory, touches
network, hot path, security sensitive.

- Behavior now stores descriptor bits directly as dedicated header-flag bits
  in the spare 8..=15 range: PURE=9, IO_HEAVY=10, ALLOCATES=11, NETWORK=13,
  HOT_PATH=14, SECURITY_SENSITIVE=15. Bit 12 (ENCRYPTED) left clear; mask
  0xEE00. refresh_flags() preserves 8..=15 so round-trip is safe.
- K= CLI tokens gain alloc/net/sec (prog + kernel verbs).
- Add unit test for all-six round-trip + explicit security-sensitive bit.

Proven green via ./check quick.
This commit is contained in:
CUBELinux-2
2026-08-13 16:00:34 -04:00
parent 1539ecd1bb
commit 0074f3112c
2 changed files with 83 additions and 38 deletions
+6
View File
@@ -461,6 +461,9 @@ impl Session {
let bit = match flag {
"pure" => cubecode::Behavior::PURE,
"io" => cubecode::Behavior::IO_HEAVY,
"alloc" => cubecode::Behavior::ALLOCATES,
"net" => cubecode::Behavior::NETWORK,
"sec" => cubecode::Behavior::SECURITY_SENSITIVE,
"hot" => cubecode::Behavior::HOT_PATH,
other => return Err(format!("prog: unknown descriptor K={other}")),
};
@@ -591,6 +594,9 @@ impl Session {
let bit = match flag {
"pure" => cubecode::Behavior::PURE,
"io" => cubecode::Behavior::IO_HEAVY,
"alloc" => cubecode::Behavior::ALLOCATES,
"net" => cubecode::Behavior::NETWORK,
"sec" => cubecode::Behavior::SECURITY_SENSITIVE,
"hot" => cubecode::Behavior::HOT_PATH,
other => return Err(format!("kernel: unknown descriptor K={other}")),
};