Implement homeblocks_sig_check(): the drive signature check (Phase 8)

Real, complete verification logic -- not yet wired to any write path.
homeblocks_sig_check(dev, sig_start_fblock, out_sig) reads the 4
consecutive 1KB blkio forth-blocks the 4KB header spans, verifies
magic -> version -> CRC-64 in order, returns HOMEBLOCKS_SIG_OK/_BLANK/
_BAD_VERSION/_BAD_CRC/_READ_ERROR. Reuses block_subsystem.c's existing
CRC-64/ISO (compute_crc64, previously static/file-local, now exposed
via block_subsystem.h) rather than a second CRC implementation --
same algorithm already proven via per-block checksums. Takes the
header's starting block as a plain parameter rather than resolving it
internally: verifies a signature given a location, finding that
location (GPT-partition-relative) stays the caller's job.

Verified against the actual shipped code, not a reimplementation: a
standalone host test links the real homeblocks_sig.c against a fake
in-memory blkio_dev and exercises all four outcomes -- blank media,
a correctly-minted header (round-trips drive_uuid/minted_time_ns), a
flipped CRC, an unrecognized version. All four pass. A full
QEMU-hotplug live test isn't proportionate yet since nothing calls
this function from the live kernel path -- wiring it into the attach
path is the next punch-list item. Clean zero-warning compile and
clean boot on all three architectures confirms no build/link
regression from exposing compute_crc64 and adding the new source
file to every kernel build.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
Robert Allan James
2026-08-26 07:05:37 -04:00
co-authored by Claude Sonnet 5
parent 10b96870c5
commit 2c45744995
13 changed files with 27292 additions and 6 deletions
+1 -1
View File
@@ -104,7 +104,7 @@ static void crc64_init(void) {
crc64_inited = 1;
}
static inline uint64_t compute_crc64(const uint8_t *data, size_t len) {
uint64_t compute_crc64(const uint8_t *data, size_t len) {
if (!crc64_inited) crc64_init();
uint64_t crc = 0xFFFFFFFFFFFFFFFFULL;
for (size_t i = 0; i < len; i++) {
+87
View File
@@ -0,0 +1,87 @@
/*
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 20232025 Robert A. James
All rights reserved.
This file is part of the StarForth project.
Licensed under the StarForth License, Version 1.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at:
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
express or implied, including but not limited to the warranties of
merchantability, fitness for a particular purpose, and noninfringement.
See the License for the specific language governing permissions and
limitations under the License.
*/
/**
* homeblocks_sig.c - Drive signature check (FABRIC-3.md, Milestone 4).
* See starkernel/homeblocks_sig.h for the format and interface design.
*/
#include "starkernel/homeblocks_sig.h"
#include <stddef.h>
#include <string.h>
#include "blkio.h"
#include "block_subsystem.h" /* compute_crc64() -- same CRC-64/ISO this file's
* check reuses rather than duplicating */
uint64_t homeblocks_sig_compute_crc(const homeblocks_sig_t *sig) {
/* Covers every field up to but not including hdr_crc itself (and never
* _pad, which sits after it) -- offsetof is the exact boundary, not a
* hand-counted byte offset that could drift out of sync with the
* struct's own field list. */
size_t crc_span = offsetof(homeblocks_sig_t, hdr_crc);
return compute_crc64((const uint8_t *)sig, crc_span);
}
homeblocks_sig_result_t homeblocks_sig_check(struct blkio_dev *dev,
uint32_t sig_start_fblock,
homeblocks_sig_t *out_sig) {
uint8_t buf[4096];
uint32_t i;
homeblocks_sig_t local;
uint64_t expected_crc;
if (!dev) return HOMEBLOCKS_SIG_READ_ERROR;
/* homeblocks_sig_t is exactly one 4KiB devblock; blkio's own unit is a
* 1KiB "forth block" (BLKIO_FORTH_BLOCK_SIZE), so the header spans 4
* consecutive reads starting at sig_start_fblock. */
for (i = 0; i < 4; i++) {
if (blkio_read((blkio_dev_t *)dev, sig_start_fblock + i,
buf + (size_t)i * BLKIO_FORTH_BLOCK_SIZE) != BLKIO_OK) {
return HOMEBLOCKS_SIG_READ_ERROR;
}
}
/* Copy into a properly-aligned local rather than reinterpreting buf's
* address directly -- buf is only byte-aligned, and homeblocks_sig_t
* has uint64_t members; a raw cast would be a strict-aliasing and
* alignment violation for no benefit over one memcpy. */
memcpy(&local, buf, sizeof(local));
if (HOMEBLOCKS_SIG_GET_MAGIC(local.magic) != (uint32_t)(HOMEBLOCKS_SIG_MAGIC & 0xFFFFFFFFULL)) {
return HOMEBLOCKS_SIG_BLANK;
}
if (HOMEBLOCKS_SIG_GET_VERSION(local.magic) != HOMEBLOCKS_SIG_VERSION_0) {
return HOMEBLOCKS_SIG_BAD_VERSION;
}
expected_crc = homeblocks_sig_compute_crc(&local);
if (expected_crc != local.hdr_crc) {
return HOMEBLOCKS_SIG_BAD_CRC;
}
if (out_sig) *out_sig = local;
return HOMEBLOCKS_SIG_OK;
}