Phase D: RUNCAP -- runtime capsule construction from thumbdrive content

capsule_runcap_birth() (new capsule_runcap.h/.c): builds a heap-only,
single-entry CapsuleDirHeader + CapsuleDesc + CapsuleNameEntry + arena
from a home-blocks drive's identity_src region (skipping the first
devblock, reserved for MINT's user_identity_seed_t record) and hands it
to the existing, unmodified capsule_birth_baby() -- no new birth
mechanism, matching FABRIC-3.md §F.6's own trace.

Found and closed a real gap in that trace along the way:
capsule_birth_baby()'s signature check calls capsule_get_signatures(),
which unconditionally returns the compile-time-baked global array --
meaningless for a heap-built directory, where index 0 would compare
RUNCAP's own content against whatever real capsule happens to occupy
that slot in the baked array (guaranteed-wrong, not a security check).
Added an explicit skip_pki_sig flag (0 for all 4 existing call sites,
1 for RUNCAP): that content's trust comes from CERTVERIFY, a separate
root, not the capsule-PKI chain.

Also found live: capsule_birth_baby() never sets the registry entry's
own .name (every existing caller does this itself afterward via
capsule_vm_registry_set_name() -- RUNCAP now does too), and
capsule_exec_payload() requires a "Block NNNN" header per chunk of
content or it's silently skipped, never executed -- not a bug, but
necessary context for whoever authors MINT's default personality
content next.

Added a small accessor pair (repl.h/.c) exposing the currently attached
home-blocks device/sig -- the same gap F.9's own BINDSTEP scoping had
already flagged, needed by both.

Verified end-to-end live in QEMU: synthetic identity-source content
written directly to a thumbdrive image's raw devblocks (no capsule
build, no mkcapsule) was read, compiled, and executed by a genuinely
new VM via a diagnostic RUNCAP-TEST word -- confirmed via VM-EXEC
invoking a word defined only in that source. Clean 3-architecture
regression boot (no RUNCAP drive attached) confirms no side effects.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
This commit is contained in:
Robert Allan James
2026-08-28 14:29:42 -04:00
co-authored by Claude Sonnet 5
parent 75311967a7
commit e1e839258d
13 changed files with 37736 additions and 3 deletions
+18
View File
@@ -127,6 +127,23 @@ CapsuleRunResult capsule_birth_mama(
* @param descs Capsule descriptor array
* @param names Capsule name entry array (parallel to descs)
* @param arena Capsule payload arena
* @param skip_pki_sig 0 for every build-time capsule (the normal case --
* checked against the compile-time-baked signature
* array via capsule_get_signatures()). Non-zero only
* for RUNCAP (FABRIC-3.md §F.6/F.18): a heap-built,
* single-entry directory sourced from a user's own
* thumbdrive has no entry in that array at all --
* index 0 would silently compare against whatever
* real capsule happens to occupy slot 0, which is
* not a security check, just a guaranteed-wrong one.
* Trust for that content comes from CERTVERIFY (a
* separate root, the user's own Zuse-signed cert)
* already having run before RUNCAP is ever called,
* not from this flag -- this only skips a check that
* was never meaningful for that content in the first
* place. Deliberately a plain flag, not a new entry
* point, so the policy is one call-site decision,
* trivially reversible.
* @param out_vm_id Output: assigned VM ID
* @param out_vm_ctx Output: new VM context
* @return CAPSULE_RUN_OK on success, error code otherwise
@@ -137,6 +154,7 @@ CapsuleRunResult capsule_birth_baby(
const CapsuleDesc *descs,
const CapsuleNameEntry *names,
const uint8_t *arena,
int skip_pki_sig,
VMUuid *out_vm_id,
void **out_vm_ctx
);
+75
View File
@@ -0,0 +1,75 @@
/*
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 20232025 Robert A. James
All rights reserved.
Licensed under the StarForth License, Version 1.0
*/
/**
* capsule_runcap.h - RUNCAP: runtime capsule construction from thumbdrive
* content (FABRIC-3.md §F.6/§F.18).
*
* A user's identity source (raw FORTH init/personality text, minted by
* MINT into a home-blocks drive's identity_src region) never exists at
* build time, so it can never appear in the compile-time-baked capsule
* directory. This builds a heap-only, single-entry CapsuleDirHeader +
* CapsuleDesc + CapsuleNameEntry + arena from that region and hands it to
* the existing, unmodified capsule_birth_baby() -- no new birth mechanism,
* per §F.6's own trace ("capsule_birth_baby() is already generic").
*
* Does not verify the caller has already run CERTVERIFY -- that's the
* caller's responsibility (WIREBIND, not yet built). This function's own
* job is narrow: read the region, construct the directory, birth it.
*/
#ifndef STARKERNEL_CAPSULE_RUNCAP_H
#define STARKERNEL_CAPSULE_RUNCAP_H
#ifdef __STARKERNEL__
#include <stdint.h>
#include "starkernel/capsule_run.h" /* CapsuleRunResult */
#include "starkernel/vm_uuid.h" /* VMUuid */
#include "starkernel/homeblocks_sig.h" /* homeblocks_sig_t */
struct blkio_dev;
/**
* capsule_runcap_birth - Birth a VM from a home-blocks drive's own
* identity_src region.
*
* Reads sig->identity_src_devblocks devblocks starting at
* sig->identity_src_offset. The first devblock is the identity's own
* user_identity_seed_t record (MINT, §F.8) and is skipped here -- RUNCAP
* only cares about the FORTH source that follows it. Refuses cleanly
* (CAPSULE_RUN_ERR_INVALID) if identity_src_offset is 0 (never minted) or
* identity_src_devblocks < 2 (no source content beyond the seed record).
*
* The heap-allocated directory/descriptor/name/arena are never freed --
* deliberate, matching kernel_main.c's own compile-time-directory-to-heap
* copy at Mama's own birth (also never freed): a VM's IDENTITY exec reads
* directly from this arena, and nothing in this codebase frees capsule
* arenas after a successful birth today.
*
* @param dev Already-open block device for the attached drive.
* @param sig Already-verified homeblocks_sig_t read from it.
* @param vm_name Symbolic name for the new VM (becomes both the
* capsule's own single directory entry name and the
* VM registry name).
* @param out_vm_id Output: assigned VM ID.
* @param out_vm_ctx Output: new VM context (may be NULL if not needed).
* @return CAPSULE_RUN_OK on success, error code otherwise.
*/
CapsuleRunResult capsule_runcap_birth(
struct blkio_dev *dev,
const homeblocks_sig_t *sig,
const char *vm_name,
VMUuid *out_vm_id,
void **out_vm_ctx
);
#endif /* __STARKERNEL__ */
#endif /* STARKERNEL_CAPSULE_RUNCAP_H */
+13
View File
@@ -15,6 +15,9 @@
#define STARKERNEL_REPL_H
#include "vm.h"
#include "starkernel/homeblocks_sig.h"
struct blkio_dev;
#ifdef __cplusplus
extern "C" {
@@ -68,6 +71,16 @@ void sk_repl_set_active_vm(VM *vm);
*/
VM *sk_repl_get_active_vm(void);
/**
* sk_repl_get_homeblocks_dev / sk_repl_get_homeblocks_sig - The currently
* attached home-blocks USB drive, or NULL if none is attached / the
* attached drive didn't check out as HOMEBLOCKS_SIG_OK (FABRIC-3.md
* §F.6/§F.9/§F.18). Both return NULL together; never one without the
* other.
*/
struct blkio_dev *sk_repl_get_homeblocks_dev(void);
const homeblocks_sig_t *sk_repl_get_homeblocks_sig(void);
#ifdef __cplusplus
}
#endif