FABRIC-3.md §I.5: Milestone 7 trust tiers (QEMU-vs-real-hardware), closing it

Closes the contributor-capsule/trust-tier punch-list item. Decided
direction: QEMU-vs-real-hardware conditional enforcement.

Found before building on that decision: the obvious mechanism (expose
TimerInfo.vm_mode) only works on amd64 -- aarch64 and riscv64 both had
vm_mode hardcoded to 1 unconditionally, meaning they'd always report
"running under QEMU" even on real hardware. Built real detection for
both instead of shipping that: aarch64 checks the ACPI RSDP's OEM ID
for QEMU's "BOCHS " SeaBIOS-heritage signature; riscv64 checks the
devicetree root compatible property for "qemu". Confirmed vm_mode was
otherwise unread anywhere else in either file first -- zero risk to
existing timing behavior.

CAPSULE_FLAG_CONTRIB (mkcapsule.c: FLAG_CONTRIB) path-matches on
capsules/contrib/, mirroring FLAG_MAMA_INIT's exact-match pattern.
contrib_capsule_refused() (capsule_birth.c) enforces: no additional
check under QEMU (same WARN-only as everything else); on real hardware,
a contrib capsule additionally requires CAPSULE_SIG_OK, since it has no
other provenance to fall back on. Wired into capsule_birth_baby() and
capsule_run_experiment().

Also updates §I.7 (Milestone 9): its stated precondition (Milestone 7
closing) is now met, flagged as stale rather than treated as a green
light to design networking from nothing.

Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the
foreground) -- compile/boot verification only; the real-hardware
enforcement branch is unverifiable from this environment, same as all
of §I.6. logs and DoE CSVs from this session's verification runs
included per this repo's own audit-artifact convention.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
This commit is contained in:
Robert Allan James
2026-09-04 11:04:25 -04:00
co-authored by Claude Sonnet 5
parent 5567d03c12
commit eeceec21a5
15 changed files with 27811 additions and 25 deletions
+8
View File
@@ -213,11 +213,16 @@ static void sign_capsule_bytes(const uint8_t *data, size_t len,
#define FLAG_PRODUCTION 0x00000010
#define FLAG_EXPERIMENT 0x00000020
#define FLAG_MAMA_INIT 0x00000040
#define FLAG_CONTRIB 0x00000080
/*
* Determine flags from the colon-separated capsule name.
*
* init.4th (bare) is Mama's canonical init — gets FLAG_MAMA_INIT only.
* Anything under capsules/contrib/ (name starts with "contrib:") gets
* FLAG_CONTRIB in addition to the usual PRODUCTION|EXPERIMENT pair
* (FABRIC-3.md §I.5, 2026-09-04) — path-match, mirrors FLAG_MAMA_INIT's
* own exact-match pattern one line up, just prefix instead of exact.
* All other capsules carry both FLAG_PRODUCTION and FLAG_EXPERIMENT so
* that birth eligibility is not gated on mode type (D2).
*/
@@ -228,6 +233,9 @@ static uint32_t flags_from_name(const char *name) {
flags |= FLAG_MAMA_INIT;
} else {
flags |= FLAG_PRODUCTION | FLAG_EXPERIMENT;
if (strncmp(name, "contrib:", 8) == 0) {
flags |= FLAG_CONTRIB;
}
}
return flags;