Four bugs found live verifying the 8 identity thumbdrives (FABRIC-3.md §IX)
All found by actually running the identity workflow §VII/§VIII made possible, not by code review: 1. Zuse/WIREBIND cross-contamination on detach: capsule_zuse_boot_logout() and capsule_wirebind_unclean_detach() both had no device parameter, so an unrelated device detaching (while the real owner's own stayed attached) incorrectly tore down the wrong session. Both now compare the departing device against their own tracked one, mirroring capsule_wirebind.c's pre-existing g_wirebind_attached_dev precedent. 2. Dictionary-entry memory leak: vm_create_word()'s sf_malloc()'d DictEntry (plus a second per-entry allocation for transition_metrics) was never freed by vm_cleanup(), in both the hosted and kernel implementations. Caused a real kernel PANIC after 8-9 repeated VM birth/kill cycles in one boot. Fixed by walking vm->latest in both. 3. sf_malloc/sf_free (alloc_kernel.c) was a 4MB bump arena with a deliberate no-op free, sized on "VM born once, never killed" -- fix #2 alone didn't stop the panic because free() itself discarded the pointer regardless. Given a real free list (first-fit reuse). 4. Headless-console gate didn't re-engage after a mid-boot logout: the original fix (sk_console_mark_login(), one-way sticky) only gated the first login of the boot. Replaced with a live check (sk_console_identity_present()) re-evaluated continuously, including inside sk_console_readline()'s own blocking idle loop -- the console is normally sitting blocked there when a hot-unplug logout happens, so checking only at the top of the REPL loop wasn't enough. Also: MINT now verifies its own write (verify_mint(), capsule_mint.c) by reading back through the same check a real attach performs, rather than trusting blkio_write()'s BLK_OK alone -- logged via log_message(), not console_println(), per direct instruction. Verified live, amd64: the full 8-identity repeated attach/detach cycle that previously panicked at the same point every time now completes clean, and a full serial-log sweep found zero bare unauthenticated prompts anywhere in the run. Three-arch clean-qemu acceptance passed. Still open, not fixed here: a 3+-simultaneous-device USB enumeration failure found in a separate live test, not yet root-caused. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018EjXFo7mPXjUMjfJeuUUz4
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
0bae928aad
commit
2c1b3cd695
@@ -607,7 +607,14 @@ void mama_word_kill(VM *vm)
|
||||
void mama_word_eject(VM *vm)
|
||||
{
|
||||
capsule_wirebind_eject();
|
||||
capsule_zuse_boot_logout(vm);
|
||||
/* FABRIC-3.md §VII follow-on, 2026-09-06: capsule_zuse_boot_logout()
|
||||
* now requires the departing device to match the one tracked as
|
||||
* hers (the abrupt hot-unplug path's own fix) -- EJECT isn't reacting
|
||||
* to any specific device's detach event, so it passes her own tracked
|
||||
* device straight back in, which trivially matches when she's
|
||||
* genuinely attached and no-ops via the existing g_zuse_attached_
|
||||
* this_device check otherwise. */
|
||||
capsule_zuse_boot_logout(vm, capsule_zuse_boot_attached_dev());
|
||||
/* Stack clean on exit */
|
||||
}
|
||||
|
||||
@@ -926,6 +933,10 @@ static void mama_word_mint(VM *vm)
|
||||
case MINT_ERR_INVALID_PROFILE:
|
||||
console_println("MINT: refused -- full_name/username missing or a field too long");
|
||||
break;
|
||||
case MINT_ERR_VERIFY_FAILED:
|
||||
console_println("MINT: FAILED -- wrote identity but post-write verification failed "
|
||||
"(see log for which check)");
|
||||
break;
|
||||
}
|
||||
vm_push(vm, 0);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user