Phase D: RUNCAP -- runtime capsule construction from thumbdrive content
capsule_runcap_birth() (new capsule_runcap.h/.c): builds a heap-only, single-entry CapsuleDirHeader + CapsuleDesc + CapsuleNameEntry + arena from a home-blocks drive's identity_src region (skipping the first devblock, reserved for MINT's user_identity_seed_t record) and hands it to the existing, unmodified capsule_birth_baby() -- no new birth mechanism, matching FABRIC-3.md §F.6's own trace. Found and closed a real gap in that trace along the way: capsule_birth_baby()'s signature check calls capsule_get_signatures(), which unconditionally returns the compile-time-baked global array -- meaningless for a heap-built directory, where index 0 would compare RUNCAP's own content against whatever real capsule happens to occupy that slot in the baked array (guaranteed-wrong, not a security check). Added an explicit skip_pki_sig flag (0 for all 4 existing call sites, 1 for RUNCAP): that content's trust comes from CERTVERIFY, a separate root, not the capsule-PKI chain. Also found live: capsule_birth_baby() never sets the registry entry's own .name (every existing caller does this itself afterward via capsule_vm_registry_set_name() -- RUNCAP now does too), and capsule_exec_payload() requires a "Block NNNN" header per chunk of content or it's silently skipped, never executed -- not a bug, but necessary context for whoever authors MINT's default personality content next. Added a small accessor pair (repl.h/.c) exposing the currently attached home-blocks device/sig -- the same gap F.9's own BINDSTEP scoping had already flagged, needed by both. Verified end-to-end live in QEMU: synthetic identity-source content written directly to a thumbdrive image's raw devblocks (no capsule build, no mkcapsule) was read, compiled, and executed by a genuinely new VM via a diagnostic RUNCAP-TEST word -- confirmed via VM-EXEC invoking a word defined only in that source. Clean 3-architecture regression boot (no RUNCAP drive attached) confirms no side effects. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
75311967a7
commit
e1e839258d
@@ -0,0 +1,75 @@
|
||||
/*
|
||||
StarForth — Steady-State Virtual Machine Runtime
|
||||
|
||||
Copyright (c) 2023–2025 Robert A. James
|
||||
All rights reserved.
|
||||
|
||||
Licensed under the StarForth License, Version 1.0
|
||||
*/
|
||||
|
||||
/**
|
||||
* capsule_runcap.h - RUNCAP: runtime capsule construction from thumbdrive
|
||||
* content (FABRIC-3.md §F.6/§F.18).
|
||||
*
|
||||
* A user's identity source (raw FORTH init/personality text, minted by
|
||||
* MINT into a home-blocks drive's identity_src region) never exists at
|
||||
* build time, so it can never appear in the compile-time-baked capsule
|
||||
* directory. This builds a heap-only, single-entry CapsuleDirHeader +
|
||||
* CapsuleDesc + CapsuleNameEntry + arena from that region and hands it to
|
||||
* the existing, unmodified capsule_birth_baby() -- no new birth mechanism,
|
||||
* per §F.6's own trace ("capsule_birth_baby() is already generic").
|
||||
*
|
||||
* Does not verify the caller has already run CERTVERIFY -- that's the
|
||||
* caller's responsibility (WIREBIND, not yet built). This function's own
|
||||
* job is narrow: read the region, construct the directory, birth it.
|
||||
*/
|
||||
|
||||
#ifndef STARKERNEL_CAPSULE_RUNCAP_H
|
||||
#define STARKERNEL_CAPSULE_RUNCAP_H
|
||||
|
||||
#ifdef __STARKERNEL__
|
||||
|
||||
#include <stdint.h>
|
||||
#include "starkernel/capsule_run.h" /* CapsuleRunResult */
|
||||
#include "starkernel/vm_uuid.h" /* VMUuid */
|
||||
#include "starkernel/homeblocks_sig.h" /* homeblocks_sig_t */
|
||||
|
||||
struct blkio_dev;
|
||||
|
||||
/**
|
||||
* capsule_runcap_birth - Birth a VM from a home-blocks drive's own
|
||||
* identity_src region.
|
||||
*
|
||||
* Reads sig->identity_src_devblocks devblocks starting at
|
||||
* sig->identity_src_offset. The first devblock is the identity's own
|
||||
* user_identity_seed_t record (MINT, §F.8) and is skipped here -- RUNCAP
|
||||
* only cares about the FORTH source that follows it. Refuses cleanly
|
||||
* (CAPSULE_RUN_ERR_INVALID) if identity_src_offset is 0 (never minted) or
|
||||
* identity_src_devblocks < 2 (no source content beyond the seed record).
|
||||
*
|
||||
* The heap-allocated directory/descriptor/name/arena are never freed --
|
||||
* deliberate, matching kernel_main.c's own compile-time-directory-to-heap
|
||||
* copy at Mama's own birth (also never freed): a VM's IDENTITY exec reads
|
||||
* directly from this arena, and nothing in this codebase frees capsule
|
||||
* arenas after a successful birth today.
|
||||
*
|
||||
* @param dev Already-open block device for the attached drive.
|
||||
* @param sig Already-verified homeblocks_sig_t read from it.
|
||||
* @param vm_name Symbolic name for the new VM (becomes both the
|
||||
* capsule's own single directory entry name and the
|
||||
* VM registry name).
|
||||
* @param out_vm_id Output: assigned VM ID.
|
||||
* @param out_vm_ctx Output: new VM context (may be NULL if not needed).
|
||||
* @return CAPSULE_RUN_OK on success, error code otherwise.
|
||||
*/
|
||||
CapsuleRunResult capsule_runcap_birth(
|
||||
struct blkio_dev *dev,
|
||||
const homeblocks_sig_t *sig,
|
||||
const char *vm_name,
|
||||
VMUuid *out_vm_id,
|
||||
void **out_vm_ctx
|
||||
);
|
||||
|
||||
#endif /* __STARKERNEL__ */
|
||||
|
||||
#endif /* STARKERNEL_CAPSULE_RUNCAP_H */
|
||||
Reference in New Issue
Block a user