Milestone 6: hard-refuse flip, scoped to INVALID only -- closes Milestone 6
Before flipping, found CAPSULE_SIG_MISSING (no signature at all) is the normal state everywhere except this machine -- CI and any other checkout have no access to the offline key, by design. Refusing on MISSING the same as INVALID would brick boot everywhere but here. Decided (on request): enforce ONLY on CAPSULE_SIG_INVALID (a signature that IS present but doesn't verify -- unambiguous tampering/corruption evidence). MISSING/NO_ROOT_KEY stay WARN-only permanently. All three capsule_birth.c call sites now return CAPSULE_RUN_ERR_INVALID on CAPSULE_SIG_INVALID, after logging the same WARN as before. Verified on all three architectures, both directions, per the original rollout commitment: positive case (real signed capsules) reboots clean with zero warnings on amd64/aarch64/riscv64. Negative case (same one-byte signature corruption used for the WARN-only proof, on Mama's own init.4th) now genuinely refuses identically on all three: "capsule sig: init.4th: INVALID" then "Init: Mama birth FAILED". The feared "no ok> at all" blast radius didn't materialize -- kernel_main.c already had graceful error handling for a failed Mama birth (log and continue, pre-existing code); the kernel reaches a degraded ok> rather than crashing, on all three architectures. Final acceptance pass (real signed capsules, tampering reverted) clean on all three. Milestone 6 is now fully closed except magic-number content-type detection (shared with Milestone 4, separate scope, not started). Documented in FABRIC-3.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
c640f99211
commit
030a3e6dc0
@@ -416,9 +416,13 @@ CapsuleRunResult capsule_birth_mama(
|
||||
CapsuleValidateResult vr = capsule_validate(mama_cap, arena, dir->arena_size, 1);
|
||||
if (vr != CAPSULE_VALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
|
||||
/* Milestone 6 (Phase 8): WARN-only signature check, not yet enforced --
|
||||
* see capsule_sig.h's own doc comment for why (blast radius: a false
|
||||
* refusal here means Mama herself never births, no ok> on any arch). */
|
||||
/* Milestone 6 (Phase 8): signature check. Enforced ONLY on INVALID (a
|
||||
* signature that IS present but does not verify -- unambiguous
|
||||
* tampering/corruption evidence). MISSING and NO_ROOT_KEY stay
|
||||
* WARN-only: MISSING is the normal state on every machine without
|
||||
* access to the offline signing key (CI, any other checkout) --
|
||||
* refusing on it would brick boot everywhere but the one machine
|
||||
* that minted this key, not catch anything real. See capsule_sig.h. */
|
||||
{
|
||||
int idx = (int)(mama_cap - descs);
|
||||
CapsuleSigResult sr = capsule_verify_signature(
|
||||
@@ -426,6 +430,7 @@ CapsuleRunResult capsule_birth_mama(
|
||||
if (sr != CAPSULE_SIG_OK) {
|
||||
log_message(LOG_WARN, "capsule sig: %s: %s",
|
||||
names[idx].name, capsule_sig_result_str(sr));
|
||||
if (sr == CAPSULE_SIG_INVALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -488,7 +493,9 @@ CapsuleRunResult capsule_birth_baby(
|
||||
CapsuleValidateResult vr = capsule_validate(cap, arena, dir->arena_size, 1);
|
||||
if (vr != CAPSULE_VALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
|
||||
/* Milestone 6 (Phase 8): WARN-only, see capsule_sig.h. */
|
||||
/* Milestone 6 (Phase 8): enforced only on INVALID -- see the fuller
|
||||
* comment in capsule_birth_mama() above for why MISSING/NO_ROOT_KEY
|
||||
* stay WARN-only. */
|
||||
{
|
||||
int idx = (int)(cap - descs);
|
||||
CapsuleSigResult sr = capsule_verify_signature(
|
||||
@@ -496,6 +503,7 @@ CapsuleRunResult capsule_birth_baby(
|
||||
if (sr != CAPSULE_SIG_OK) {
|
||||
log_message(LOG_WARN, "capsule sig: %s: %s",
|
||||
names[idx].name, capsule_sig_result_str(sr));
|
||||
if (sr == CAPSULE_SIG_INVALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -634,7 +642,9 @@ CapsuleRunResult capsule_run_experiment(
|
||||
CapsuleValidateResult vr = capsule_validate(cap, arena, dir->arena_size, 1);
|
||||
if (vr != CAPSULE_VALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
|
||||
/* Milestone 6 (Phase 8): WARN-only, see capsule_sig.h. */
|
||||
/* Milestone 6 (Phase 8): enforced only on INVALID -- see the fuller
|
||||
* comment in capsule_birth_mama() above for why MISSING/NO_ROOT_KEY
|
||||
* stay WARN-only. */
|
||||
{
|
||||
int idx = (int)(cap - descs);
|
||||
CapsuleSigResult sr = capsule_verify_signature(
|
||||
@@ -642,6 +652,7 @@ CapsuleRunResult capsule_run_experiment(
|
||||
if (sr != CAPSULE_SIG_OK) {
|
||||
log_message(LOG_WARN, "capsule sig: %s: %s",
|
||||
names[idx].name, capsule_sig_result_str(sr));
|
||||
if (sr == CAPSULE_SIG_INVALID) return CAPSULE_RUN_ERR_INVALID;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user