Rename FABRIC series: FABRIC.md->0, FABRIC-2.md->1, FABRIC-3.md->2, FABRIC-4.md unchanged
FABRIC.md -> FABRIC-0.md FABRIC-2.md -> FABRIC-1.md FABRIC-3.md -> FABRIC-2.md (the current/living document) FABRIC-4.md unchanged (new #3 to follow separately) Every cross-reference repo-wide updated to match, including doc-comment citations inside kernel source (.c/.h) files -- done via an ordered placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md-> placeholder1, FABRIC.md->placeholder0, then placeholders resolved to final names) in a single pass per file to avoid double-shifting already-renamed references. One line in capsules/font.4th grew past the 64-char block-format limit as a side effect of the longer filename; shortened it and reverified with mkcapsule --lint (34/34 pass) before rebuilding. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground) after the fix; logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
ff2941dfb9
commit
b031b802e3
@@ -1,7 +1,7 @@
|
||||
/*
|
||||
* x509_ed25519.h -- minimal, targeted DER walkers for Ed25519-signed X.509
|
||||
* certificates (RFC 8410). Deliberately NOT a general ASN.1/X.509 parser
|
||||
* (Milestone 6 decision, FABRIC-2.md): each function walks exactly as far
|
||||
* (Milestone 6 decision, FABRIC-1.md): each function walks exactly as far
|
||||
* into the DER structure as its own job needs, nothing more.
|
||||
*
|
||||
* x509_extract_ed25519_pubkey() only ever reads SubjectPublicKeyInfo --
|
||||
@@ -11,7 +11,7 @@
|
||||
* never re-verified against the offline root CA at boot.
|
||||
*
|
||||
* x509_verify_signature()/x509_extract_serial() (added 2026-08-28,
|
||||
* FABRIC-3.md §F.7/§F.17) are for CERTVERIFY -- a regular user's cert,
|
||||
* FABRIC-2.md §F.7/§F.17) are for CERTVERIFY -- a regular user's cert,
|
||||
* which unlike the capsule-PKI chain is signed by Zuse's own on-device
|
||||
* key and genuinely needs its signature checked at attach time, not just
|
||||
* trusted by embedding. Two separate trust roots, two separate reasons
|
||||
@@ -62,7 +62,7 @@ int x509_extract_serial(const uint8_t *der, size_t der_len,
|
||||
size_t *serial_len_out);
|
||||
|
||||
/*
|
||||
* x509_build_user_cert (added 2026-08-28, FABRIC-3.md §F.8/§F.19, MINT):
|
||||
* x509_build_user_cert (added 2026-08-28, FABRIC-2.md §F.8/§F.19, MINT):
|
||||
* the encode-side counterpart to x509_verify_signature()/x509_extract_*
|
||||
* above. Builds a minimal DER-encoded X.509 certificate exercising
|
||||
* exactly the fields those functions read -- serialNumber, an Ed25519
|
||||
|
||||
Reference in New Issue
Block a user