Implement homeblocks_sig_check(): the drive signature check (Phase 8)
Real, complete verification logic -- not yet wired to any write path. homeblocks_sig_check(dev, sig_start_fblock, out_sig) reads the 4 consecutive 1KB blkio forth-blocks the 4KB header spans, verifies magic -> version -> CRC-64 in order, returns HOMEBLOCKS_SIG_OK/_BLANK/ _BAD_VERSION/_BAD_CRC/_READ_ERROR. Reuses block_subsystem.c's existing CRC-64/ISO (compute_crc64, previously static/file-local, now exposed via block_subsystem.h) rather than a second CRC implementation -- same algorithm already proven via per-block checksums. Takes the header's starting block as a plain parameter rather than resolving it internally: verifies a signature given a location, finding that location (GPT-partition-relative) stays the caller's job. Verified against the actual shipped code, not a reimplementation: a standalone host test links the real homeblocks_sig.c against a fake in-memory blkio_dev and exercises all four outcomes -- blank media, a correctly-minted header (round-trips drive_uuid/minted_time_ns), a flipped CRC, an unrecognized version. All four pass. A full QEMU-hotplug live test isn't proportionate yet since nothing calls this function from the live kernel path -- wiring it into the attach path is the next punch-list item. Clean zero-warning compile and clean boot on all three architectures confirms no build/link regression from exposing compute_crc64 and adding the new source file to every kernel build. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
10b96870c5
commit
2c45744995
@@ -104,7 +104,7 @@ static void crc64_init(void) {
|
||||
crc64_inited = 1;
|
||||
}
|
||||
|
||||
static inline uint64_t compute_crc64(const uint8_t *data, size_t len) {
|
||||
uint64_t compute_crc64(const uint8_t *data, size_t len) {
|
||||
if (!crc64_inited) crc64_init();
|
||||
uint64_t crc = 0xFFFFFFFFFFFFFFFFULL;
|
||||
for (size_t i = 0; i < len; i++) {
|
||||
|
||||
@@ -0,0 +1,87 @@
|
||||
/*
|
||||
StarForth — Steady-State Virtual Machine Runtime
|
||||
|
||||
Copyright (c) 2023–2025 Robert A. James
|
||||
All rights reserved.
|
||||
|
||||
This file is part of the StarForth project.
|
||||
|
||||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
|
||||
You may obtain a copy of the License at:
|
||||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||||
|
||||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||
express or implied, including but not limited to the warranties of
|
||||
merchantability, fitness for a particular purpose, and noninfringement.
|
||||
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
*/
|
||||
|
||||
/**
|
||||
* homeblocks_sig.c - Drive signature check (FABRIC-3.md, Milestone 4).
|
||||
* See starkernel/homeblocks_sig.h for the format and interface design.
|
||||
*/
|
||||
|
||||
#include "starkernel/homeblocks_sig.h"
|
||||
|
||||
#include <stddef.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "blkio.h"
|
||||
#include "block_subsystem.h" /* compute_crc64() -- same CRC-64/ISO this file's
|
||||
* check reuses rather than duplicating */
|
||||
|
||||
uint64_t homeblocks_sig_compute_crc(const homeblocks_sig_t *sig) {
|
||||
/* Covers every field up to but not including hdr_crc itself (and never
|
||||
* _pad, which sits after it) -- offsetof is the exact boundary, not a
|
||||
* hand-counted byte offset that could drift out of sync with the
|
||||
* struct's own field list. */
|
||||
size_t crc_span = offsetof(homeblocks_sig_t, hdr_crc);
|
||||
return compute_crc64((const uint8_t *)sig, crc_span);
|
||||
}
|
||||
|
||||
homeblocks_sig_result_t homeblocks_sig_check(struct blkio_dev *dev,
|
||||
uint32_t sig_start_fblock,
|
||||
homeblocks_sig_t *out_sig) {
|
||||
uint8_t buf[4096];
|
||||
uint32_t i;
|
||||
homeblocks_sig_t local;
|
||||
uint64_t expected_crc;
|
||||
|
||||
if (!dev) return HOMEBLOCKS_SIG_READ_ERROR;
|
||||
|
||||
/* homeblocks_sig_t is exactly one 4KiB devblock; blkio's own unit is a
|
||||
* 1KiB "forth block" (BLKIO_FORTH_BLOCK_SIZE), so the header spans 4
|
||||
* consecutive reads starting at sig_start_fblock. */
|
||||
for (i = 0; i < 4; i++) {
|
||||
if (blkio_read((blkio_dev_t *)dev, sig_start_fblock + i,
|
||||
buf + (size_t)i * BLKIO_FORTH_BLOCK_SIZE) != BLKIO_OK) {
|
||||
return HOMEBLOCKS_SIG_READ_ERROR;
|
||||
}
|
||||
}
|
||||
|
||||
/* Copy into a properly-aligned local rather than reinterpreting buf's
|
||||
* address directly -- buf is only byte-aligned, and homeblocks_sig_t
|
||||
* has uint64_t members; a raw cast would be a strict-aliasing and
|
||||
* alignment violation for no benefit over one memcpy. */
|
||||
memcpy(&local, buf, sizeof(local));
|
||||
|
||||
if (HOMEBLOCKS_SIG_GET_MAGIC(local.magic) != (uint32_t)(HOMEBLOCKS_SIG_MAGIC & 0xFFFFFFFFULL)) {
|
||||
return HOMEBLOCKS_SIG_BLANK;
|
||||
}
|
||||
|
||||
if (HOMEBLOCKS_SIG_GET_VERSION(local.magic) != HOMEBLOCKS_SIG_VERSION_0) {
|
||||
return HOMEBLOCKS_SIG_BAD_VERSION;
|
||||
}
|
||||
|
||||
expected_crc = homeblocks_sig_compute_crc(&local);
|
||||
if (expected_crc != local.hdr_crc) {
|
||||
return HOMEBLOCKS_SIG_BAD_CRC;
|
||||
}
|
||||
|
||||
if (out_sig) *out_sig = local;
|
||||
return HOMEBLOCKS_SIG_OK;
|
||||
}
|
||||
Reference in New Issue
Block a user