Add disk/zuse.img + bleach_zuse_img.sh: first-boot mint testing (Phase 8)
Resolves the acl_pinned punch-list item's open question: credential data (ZUSE-CERT-LO/HI, ACL-CA-KEY-LO/HI) are CONSTANT words, i.e. real DictEntrys, and acl_pinned's enforcement (vm_create_word()'s unconditional shadow-refusal for any pinned name) already covers this generally -- no new flag needed, zuse.4th's ACL-ZUSE-BOOT already pins both cert constants today. That investigation surfaced a real gap: ACL-ZUSE-BOOT pins the cert constants unconditionally on every boot, before any legitimate mint could ever run, permanently locking in the 0 placeholder on the very first boot. This directly shaped Captain Bob's next design pass: a dedicated zuse.img test thumbdrive, "bleachable" back to pristine state for repeated first-boot testing; a one-time mint-then-pin flow (fixing the gap above); a separate ongoing S" name" MINT word for minting additional regular users; and an explicitly-deferred Zuse recovery path question. This commit is the first piece: disk/zuse.img (64MB blank, matching the existing USB-fixture convention) + scripts/bleach_zuse_img.sh (idempotent reset). Verified live via QMP hotplug -- reads back as HOMEBLOCKS_SIG_BLANK, correctly simulating a genuine first boot. Deliberately flat/raw, not GPT-partitioned, matching homeblocks_sig_check()'s current sig_start_fblock=0 assumption; both move to a real GPT-relative offset together once a parser exists. No kernel code touched -- host-side test tooling only, no 3-arch acceptance boot needed. Still open: the mint-then-pin boot fix, the MINT word, Zuse recovery. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
28c1b12c7f
commit
35f84d4a45
@@ -83,6 +83,21 @@ carrying timestamp noise in git history.
|
||||
`BLK-CONFIRM-FORMAT`-committed in the repo copy — commit that step live if
|
||||
reusing this fixture for further reloc-table testing.
|
||||
|
||||
- `zuse.img` — 64MB raw image simulating the physical Zuse superuser
|
||||
thumbdrive for QEMU testing (FABRIC-3.md, Phase 8: `zuse.img` "bleach"
|
||||
mechanism, added 2026-08-26). Blank (all zero) at creation — reads back
|
||||
as `HOMEBLOCKS_SIG_BLANK` via `homeblocks_sig_check()`, confirmed live
|
||||
(`xhci: USB drive not recognized (blank or foreign media)`), simulating
|
||||
a genuine first boot for exercising the still-to-be-built one-time
|
||||
mint-Zuse flow. **"Bleach" it back to this pristine/unminted state with
|
||||
`scripts/bleach_zuse_img.sh`** before each first-boot test run, rather
|
||||
than hand-regenerating the file — same all-zero content either way, the
|
||||
script just makes the reset a single documented, repeatable command.
|
||||
Deliberately a flat/raw image, not GPT-partitioned, matching
|
||||
`homeblocks_sig_check()`'s current call site (`repl.c`,
|
||||
`sig_start_fblock=0`) — both will move to a real GPT-partition-relative
|
||||
offset together once a GPT parser exists, not attempted ahead of that.
|
||||
|
||||
**Convention, standing as of 2026-08-22: every virtual disk/thumb-drive image
|
||||
used for testing — Artemis persistence disks above, and USB Mass Storage
|
||||
backing images alike — lives in this directory and is a tracked, committed
|
||||
|
||||
Binary file not shown.
Reference in New Issue
Block a user