/* StarForth — Steady-State Virtual Machine Runtime Copyright (c) 2023–2025 Robert A. James All rights reserved. Licensed under the StarForth License, Version 1.0 */ /** * capsule_wirebind.h - WIREBIND: the real thumbdrive-attach call site * (FABRIC-3.md §F.5/§F.23). Assembles pieces already built and * individually verified this session -- CERTVERIFY (vm_identity.h's * vm_identity_from_cert()), RUNCAP (capsule_runcap.h), the console-VM + * user-VM pair (capsule_console.h, sk_repl_dispatch_line() in repl.c) -- * into one automatic sequence, replacing the RUNCAP-TEST/PAIR-TEST * diagnostic words that exercised each piece by hand. */ #ifndef STARKERNEL_CAPSULE_WIREBIND_H #define STARKERNEL_CAPSULE_WIREBIND_H #ifdef __STARKERNEL__ #include "starkernel/homeblocks_sig.h" #include "starkernel/vm_identity.h" #include "vm.h" struct blkio_dev; /** * capsule_wirebind_verify_cert - Read the cert region off dev and verify * it against mama_vm's own Zuse identity. Shared by both * capsule_wirebind_try_attach() (the original attach) and BINDSTEP * (mama_word_use(), mama_forth_words.c -- re-verifies live on every USE * of an identity-locked VM, per FABRIC-3.md §F.9 decision 1) so both * call sites check the exact same thing the exact same way. * * No-op-and-fail (-1) if sig->cert_offset is 0 (no cert region -- a * genesis-mode Zuse drive, or simply not a regular identity drive) or * mama_vm has no installed Zuse cert yet. * * @param dev Already-open block device to read the cert from. * @param sig Its already-checked homeblocks_sig_t. * @param mama_vm Hera's own VM -- the trust root (zuse_cert_pubkey). * @param out Filled with the verified identity on success. * @return 0 on success, -1 on any failure (read, verify, or precondition). */ int capsule_wirebind_verify_cert(struct blkio_dev *dev, const homeblocks_sig_t *sig, VM *mama_vm, VMIdentity *out); /** * capsule_wirebind_try_attach - Try to verify and bind a just-attached * regular (non-Zuse) identity drive. * * No-op if sig->cert_offset is 0 (a genesis-mode Zuse drive has no cert * region -- that's capsule_zuse_boot_try_attach()'s own job, not this * one's) or if mama_vm has no installed Zuse cert yet (nothing to verify * the attached cert against). Otherwise: reads the cert devblock(s), * calls vm_identity_from_cert() against mama_vm's own zuse_cert_pubkey * and sig->drive_uuid. On success, reads the drive's own * user_identity_seed_t for its username and births a console VM + * RUNCAP-born user VM pair (idempotent -- no-ops if that username is * already live this session), installs the verified VMIdentity onto the * user VM, and registers the "~user" pairing * (sk_repl_dispatch_line(), repl.c, looks for this). Does NOT USE the * new console automatically -- that stays an explicit, later, * ACL-gated step (BINDSTEP, §F.9), not something a bare attach should * trigger silently. * * @param dev The just-attached, already-open block device. * @param sig Its already-checked homeblocks_sig_t. * @param mama_vm Hera's own VM (the verifier -- her zuse_cert_pubkey is * the trust root regular user certs are checked against). */ void capsule_wirebind_try_attach(struct blkio_dev *dev, const homeblocks_sig_t *sig, VM *mama_vm); #endif /* __STARKERNEL__ */ #endif /* STARKERNEL_CAPSULE_WIREBIND_H */