FABRIC-3.md §I.5: Milestone 7 trust tiers (QEMU-vs-real-hardware), closing it
Closes the contributor-capsule/trust-tier punch-list item. Decided direction: QEMU-vs-real-hardware conditional enforcement. Found before building on that decision: the obvious mechanism (expose TimerInfo.vm_mode) only works on amd64 -- aarch64 and riscv64 both had vm_mode hardcoded to 1 unconditionally, meaning they'd always report "running under QEMU" even on real hardware. Built real detection for both instead of shipping that: aarch64 checks the ACPI RSDP's OEM ID for QEMU's "BOCHS " SeaBIOS-heritage signature; riscv64 checks the devicetree root compatible property for "qemu". Confirmed vm_mode was otherwise unread anywhere else in either file first -- zero risk to existing timing behavior. CAPSULE_FLAG_CONTRIB (mkcapsule.c: FLAG_CONTRIB) path-matches on capsules/contrib/, mirroring FLAG_MAMA_INIT's exact-match pattern. contrib_capsule_refused() (capsule_birth.c) enforces: no additional check under QEMU (same WARN-only as everything else); on real hardware, a contrib capsule additionally requires CAPSULE_SIG_OK, since it has no other provenance to fall back on. Wired into capsule_birth_baby() and capsule_run_experiment(). Also updates §I.7 (Milestone 9): its stated precondition (Milestone 7 closing) is now met, flagged as stale rather than treated as a green light to design networking from nothing. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground) -- compile/boot verification only; the real-hardware enforcement branch is unverifiable from this environment, same as all of §I.6. logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
5567d03c12
commit
eeceec21a5
@@ -87,6 +87,16 @@ typedef enum {
|
||||
/** Mama init flag (exactly one capsule must have this) */
|
||||
#define CAPSULE_FLAG_MAMA_INIT 0x00000040 /* (m) Mama's init */
|
||||
|
||||
/** Contributor capsule flag (FABRIC-3.md §I.5, 2026-09-04) -- path-match
|
||||
* on capsules/contrib/, mirrors FLAG_MAMA_INIT's own exact-match pattern
|
||||
* in mkcapsule.c's flags_from_name(). Trust-tier enforcement (QEMU-vs-
|
||||
* real-hardware, decided in conversation) is a runtime check in
|
||||
* capsule_validate()'s callers, not encoded in this bit itself -- the
|
||||
* bit only marks "this capsule's provenance is a contributor, not this
|
||||
* project's own source," same as CAPSULE_FLAG_PRODUCTION/_EXPERIMENT
|
||||
* mark mode, not policy. */
|
||||
#define CAPSULE_FLAG_CONTRIB 0x00000080 /* (c) contributor-submitted */
|
||||
|
||||
/** Validate mode flags.
|
||||
* Mama: neither (p) nor (e) may be set.
|
||||
* Babies: at least one of (p) or (e) must be set (both is fine — D2). */
|
||||
|
||||
Reference in New Issue
Block a user