Milestone 6: hard-refuse flip, scoped to INVALID only -- closes Milestone 6
Before flipping, found CAPSULE_SIG_MISSING (no signature at all) is the normal state everywhere except this machine -- CI and any other checkout have no access to the offline key, by design. Refusing on MISSING the same as INVALID would brick boot everywhere but here. Decided (on request): enforce ONLY on CAPSULE_SIG_INVALID (a signature that IS present but doesn't verify -- unambiguous tampering/corruption evidence). MISSING/NO_ROOT_KEY stay WARN-only permanently. All three capsule_birth.c call sites now return CAPSULE_RUN_ERR_INVALID on CAPSULE_SIG_INVALID, after logging the same WARN as before. Verified on all three architectures, both directions, per the original rollout commitment: positive case (real signed capsules) reboots clean with zero warnings on amd64/aarch64/riscv64. Negative case (same one-byte signature corruption used for the WARN-only proof, on Mama's own init.4th) now genuinely refuses identically on all three: "capsule sig: init.4th: INVALID" then "Init: Mama birth FAILED". The feared "no ok> at all" blast radius didn't materialize -- kernel_main.c already had graceful error handling for a failed Mama birth (log and continue, pre-existing code); the kernel reaches a degraded ok> rather than crashing, on all three architectures. Final acceptance pass (real signed capsules, tampering reverted) clean on all three. Milestone 6 is now fully closed except magic-number content-type detection (shared with Milestone 4, separate scope, not started). Documented in FABRIC-3.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
c640f99211
commit
030a3e6dc0
@@ -5,13 +5,17 @@
|
||||
* signature/behavior stays untouched; this is a new, additive check
|
||||
* called alongside it, not folded into it.
|
||||
*
|
||||
* Currently WARN-only, not enforced -- see FABRIC-3.md's Milestone 6
|
||||
* rollout decision. A bug here has a larger blast radius than most of
|
||||
* this project's other checks: a false refusal on Mama's own capsule
|
||||
* would mean no `ok>` at all, on any architecture. Land warn-only,
|
||||
* prove correct against both a valid and a deliberately-corrupted
|
||||
* capsule on all three architectures, then flip to hard-refuse
|
||||
* separately.
|
||||
* Enforced ONLY on CAPSULE_SIG_INVALID (2026-08-26, after landing
|
||||
* WARN-only and proving correct on all three architectures against both
|
||||
* a valid and a deliberately-corrupted capsule -- see FABRIC-3.md's
|
||||
* Milestone 6 writeup). CAPSULE_SIG_MISSING and CAPSULE_SIG_NO_ROOT_KEY
|
||||
* stay WARN-only, deliberately: MISSING is the normal state on every
|
||||
* machine without access to the offline signing key (CI, any other
|
||||
* checkout) -- refusing on it would brick boot everywhere but the one
|
||||
* machine that minted the key, not catch anything real. Only INVALID
|
||||
* (a signature that IS present but does not verify) is unambiguous
|
||||
* tampering/corruption evidence, safe to refuse on regardless of who's
|
||||
* building.
|
||||
*/
|
||||
#ifndef STARKERNEL_CAPSULE_SIG_H
|
||||
#define STARKERNEL_CAPSULE_SIG_H
|
||||
|
||||
Reference in New Issue
Block a user