/* * zuse_cert_devblock.h -- on-disk record format for Zuse's cert, stored * in devblock_from_top=0 of the top-of-device system-metadata fence * (block_subsystem.h's blk_meta_zone_read()/write(), Phase 8, FABRIC-3.md * §C). Raw, unpacked 4 KiB devblock -- same convention as the volume * header itself (magic + version + fields + pad-to-4096, real CRC from * day one, matching homeblocks_sig_t's own precedent for exactly this * reason: this gates a real security check, not a placeholder). * * Deliberately its own header, not inlined at the one call site that * uses it today (kernel_main.c's first-boot mint-or-load): the ongoing * `MINT` word (still open, FABRIC-3.md) will be a second consumer of * this exact format later, and the format should be stable and * documented once rather than ad-hoc. */ #ifndef STARKERNEL_ZUSE_CERT_DEVBLOCK_H #define STARKERNEL_ZUSE_CERT_DEVBLOCK_H #include /* Packed via shifts, not a hand-computed hex literal -- this project's * own standing lesson about hand-derived numeric constants in this * class of code (see FABRIC-3.md's Ed25519/scalar25519 writeups). */ #define ZUSE_CERT_DEVBLOCK_MAGIC \ ((uint32_t)'Z' | ((uint32_t)'U' << 8) | ((uint32_t)'S' << 16) | ((uint32_t)'E' << 24)) #define ZUSE_CERT_DEVBLOCK_VERSION 1u typedef struct { uint32_t magic; /* ZUSE_CERT_DEVBLOCK_MAGIC; anything else means * "not a real cert yet" (blank/foreign bytes), * not a format-corruption error */ uint32_t version; /* ZUSE_CERT_DEVBLOCK_VERSION */ uint8_t seed[32]; /* Ed25519 seed -- the private identity */ uint8_t pubkey[32]; /* Ed25519 public key derived from seed at mint time */ uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64()) * over every byte of this struct up to (not * including) this field -- real from day one, * this gates a real security check */ uint8_t _pad[4096 - (4 + 4 + 32 + 32 + 8)]; } zuse_cert_devblock_t; _Static_assert(sizeof(zuse_cert_devblock_t) == 4096, "zuse_cert_devblock_t must be exactly one 4 KiB devblock"); #endif /* STARKERNEL_ZUSE_CERT_DEVBLOCK_H */