Three tightly-coupled changes, verified together per Captain Bob's own "getting rid of the emergency cli" direction: 1. Zuse's identity is thumbdrive-resident, never system-resident. New zuse_genesis_marker_t (magic/version/zuse_pubkey[32]/crc) replaces zuse_cert_devblock_t's slot in the top-of-device fence -- the system now remembers only that a root identity exists and its pubkey, never a seed. zuse_cert_devblock_t is kept in the repo, marked superseded, no longer written by any code path. capsule_mint_identity() grows a genesis mode (issuer_vm=NULL): no cert is built or written (Zuse isn't verified against a separate signer -- she's recognized by pubkey match against the marker) and two new optional out-params (out_pubkey/out_seed) let the caller install the cert immediately after a genesis mint. New capsule_zuse_boot_try_attach() (capsule_zuse_boot.c), called from sk_repl_idle() on every fresh USB attach (the only point in the boot lifecycle a thumbdrive can actually be detected -- attach polling doesn't exist yet at kernel_main.c's old one-shot mint point, which is why that whole block is gone): no marker + blank drive -> genesis-mint; marker present + matching drive -> read its own user_identity_seed_t, install the cert. Either way, re-runs ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly like it always has for a same-boot cert install -- ACL-PIN only blocks redefinition, not re-execution, so no new C-side auth logic needed. 2. ACL.4th activated (capsules/init.4th) -- inactive all session until now. Found and fixed a real bug this immediately surfaced: zuse.4th's ACL-ZUSE-BOOT tried `['] ACL-ZUSE-BOOT ACL-PIN` from inside its own still-compiling definition -- the word isn't findable yet at that point, so the whole definition silently failed to compile every previous boot this session (dormant, since ACL.4th never loaded). Fixed: pin after the definition closes, not from within it -- it only needs to happen once anyway, and pinning doesn't block the re-invocation genesis/attach needs. 3. The unauthenticated emergency-CLI ACL bypass is retired (repl.c): `emergency_console = is_hera ? (zuse_session ? 0 : 1) : 0` deleted from both sk_repl_step and sk_repl_run. Every word run from Hera's own bare prompt now goes through ordinary ACL enforcement; emergency_console is driven only by the genuine C-level fault handler again. Added ZUSE-SESSION? (starforth_words.c), a read-only diagnostic matching ZUSE-PUBKEY@'s own precedent, to verify the whole chain directly rather than by inference. Verified end-to-end live in QEMU: fresh boot, no thumbdrive -> ZUSE-SESSION? reads 0. Attach a genuinely blank drive via QMP -> genesis mint fires automatically (no typing) -> ZUSE-SESSION? reads -1 (true). Hermes/Artemis both birth clean on all three architectures with ACL now actually enforced for the first time all session -- no denials, no UNKNOWN WORD beyond the deliberate POST self-test cases. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
60 lines
2.9 KiB
C
60 lines
2.9 KiB
C
/*
|
|
* zuse_cert_devblock.h -- SUPERSEDED 2026-08-28 (FABRIC-3.md §F.20/§F.21).
|
|
* Zuse is now thumbdrive-resident, not system-resident: her seed lives
|
|
* only on her own minted thumbdrive, never written to the fence. The
|
|
* fence's devblock_from_top=0 slot this type used to occupy now holds
|
|
* zuse_genesis_marker_t (zuse_genesis_marker.h) instead -- pubkey only,
|
|
* no seed. This type is no longer written by any code path; kept in the
|
|
* repo as historical record of the format it replaced, per this
|
|
* project's own convention for superseded design (see e.g. the
|
|
* TRIPOD.md/HERMES.md/ARTEMIS.md/CONSOLE.md superseded-header pattern).
|
|
* Do not resurrect writes to this format.
|
|
*
|
|
* Original doc, kept for context:
|
|
*
|
|
* on-disk record format for Zuse's cert, stored
|
|
* in devblock_from_top=0 of the top-of-device system-metadata fence
|
|
* (block_subsystem.h's blk_meta_zone_read()/write(), Phase 8, FABRIC-3.md
|
|
* §C). Raw, unpacked 4 KiB devblock -- same convention as the volume
|
|
* header itself (magic + version + fields + pad-to-4096, real CRC from
|
|
* day one, matching homeblocks_sig_t's own precedent for exactly this
|
|
* reason: this gates a real security check, not a placeholder).
|
|
*
|
|
* Deliberately its own header, not inlined at the one call site that
|
|
* uses it today (kernel_main.c's first-boot mint-or-load): the ongoing
|
|
* `MINT` word (still open, FABRIC-3.md) will be a second consumer of
|
|
* this exact format later, and the format should be stable and
|
|
* documented once rather than ad-hoc.
|
|
*/
|
|
#ifndef STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
|
#define STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
|
|
|
#include <stdint.h>
|
|
|
|
/* Packed via shifts, not a hand-computed hex literal -- this project's
|
|
* own standing lesson about hand-derived numeric constants in this
|
|
* class of code (see FABRIC-3.md's Ed25519/scalar25519 writeups). */
|
|
#define ZUSE_CERT_DEVBLOCK_MAGIC \
|
|
((uint32_t)'Z' | ((uint32_t)'U' << 8) | ((uint32_t)'S' << 16) | ((uint32_t)'E' << 24))
|
|
|
|
#define ZUSE_CERT_DEVBLOCK_VERSION 1u
|
|
|
|
typedef struct {
|
|
uint32_t magic; /* ZUSE_CERT_DEVBLOCK_MAGIC; anything else means
|
|
* "not a real cert yet" (blank/foreign bytes),
|
|
* not a format-corruption error */
|
|
uint32_t version; /* ZUSE_CERT_DEVBLOCK_VERSION */
|
|
uint8_t seed[32]; /* Ed25519 seed -- the private identity */
|
|
uint8_t pubkey[32]; /* Ed25519 public key derived from seed at mint time */
|
|
uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64())
|
|
* over every byte of this struct up to (not
|
|
* including) this field -- real from day one,
|
|
* this gates a real security check */
|
|
uint8_t _pad[4096 - (4 + 4 + 32 + 32 + 8)];
|
|
} zuse_cert_devblock_t;
|
|
|
|
_Static_assert(sizeof(zuse_cert_devblock_t) == 4096,
|
|
"zuse_cert_devblock_t must be exactly one 4 KiB devblock");
|
|
|
|
#endif /* STARKERNEL_ZUSE_CERT_DEVBLOCK_H */
|