Files
LithosAnanake/include/starkernel
Robert Allan JamesandClaude Sonnet 5 0ec91b517a Implement CERTVERIFY -- real DER cert verification, tested against OpenSSL
Phase B of the identity pipeline (FABRIC-3.md §F.7/§F.17):

- x509_ed25519.c/.h: two new DER walkers alongside the existing pubkey
  extractor -- x509_verify_signature() (verifies a cert's outer Ed25519
  signature over the raw, exactly-as-encoded tbsCertificate bytes, real
  signature verification against issuer_pubkey, rejects non-Ed25519
  signatureAlgorithm) and x509_extract_serial() (extracts the
  serialNumber INTEGER, stripping a DER padding byte if present, for the
  drive_uuid binding decided in §F.7).

- vm_identity.c: vm_identity_from_cert(), ties the three DER primitives
  together into the actual CERTVERIFY check -- signature verifies against
  issuer_pubkey, serialNumber matches this drive's own drive_uuid,
  subject pubkey extracts cleanly -- and populates a VMIdentity on
  success. acl_caps is caller-supplied, not read from the cert (nothing
  in the decided cert fields encodes capabilities); deciding what a
  verified identity is allowed to do is policy for the caller (WIREBIND,
  not yet built), not this function's job.

Verified two ways: a standalone host-side test harness (not part of the
kernel build) links the real source files against a real openssl-
generated Ed25519 X.509 cert -- extracted pubkey, extracted serial, and
signature verification all match ground truth, plus two negative tests
(wrong issuer pubkey, corrupted signature) both correctly rejected. Then
the actual kernel build verified live on all three architectures: clean
compile, clean boot to ok>, Hermes/Artemis both live with no KILL. Same
pre-existing, unrelated Zuse fence-write anomaly observed on all three
(not caused by this change, not chased here).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
2026-08-28 09:38:18 -04:00
..
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00
2026-08-01 07:49:56 -04:00

include/starkernel/

Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/). Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared with hosted code.

  • uefi.h — UEFI protocol/type definitions consumed by the loader.
  • elf64.h, elf_loader.h — ELF64 parsing and kernel-image loading.
  • boot_info_offsets.h — struct-offset constants shared between the assembly bootstrap and the C boot path.
  • arch.h, apic.h, timer.h — architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).
  • console.h, framebuffer.h, vt100.h — UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.
  • pmm.h, vmm.h, kmalloc.h — physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.
  • pci.h, virtio_blk.h — PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).
  • capsule.h, capsule_birth.h, capsule_loader.h, capsule_run.h, capsule_vm_physics.h, capsule_generated.h — capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (see tools/mkcapsule.c).
  • kernel_args.h, cmdline.h — boot-time kernel argument parsing (starforth.cfg / command line).
  • repl.h — kernel REPL.
  • log.h, doe_log.h — kernel logging and DoE metrics logging.
  • q48_16.h — kernel-build copy of Q48.16 fixed-point arithmetic.
  • xxhash64.h — content-addressing hash used for capsule IDs.
  • hal_memory.h — hardware-abstraction-layer memory interface.

Subdirectories:

  • hal/ — top-level hardware-abstraction-layer interface.
  • vm/ — kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).
  • freestanding/ — minimal libc-shim headers (assert.h, ctype.h, errno.h, inttypes.h, math.h, sched.h, signal.h, stdio.h, stdlib.h, string.h, time.h, sys/time.h, sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.