FABRIC.md -> FABRIC-0.md FABRIC-2.md -> FABRIC-1.md FABRIC-3.md -> FABRIC-2.md (the current/living document) FABRIC-4.md unchanged (new #3 to follow separately) Every cross-reference repo-wide updated to match, including doc-comment citations inside kernel source (.c/.h) files -- done via an ordered placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md-> placeholder1, FABRIC.md->placeholder0, then placeholders resolved to final names) in a single pass per file to avoid double-shifting already-renamed references. One line in capsules/font.4th grew past the 64-char block-format limit as a side effect of the longer filename; shortened it and reverified with mkcapsule --lint (34/34 pass) before rebuilding. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground) after the fix; logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
60 lines
2.9 KiB
C
60 lines
2.9 KiB
C
/*
|
|
* zuse_cert_devblock.h -- SUPERSEDED 2026-08-28 (FABRIC-2.md §F.20/§F.21).
|
|
* Zuse is now thumbdrive-resident, not system-resident: her seed lives
|
|
* only on her own minted thumbdrive, never written to the fence. The
|
|
* fence's devblock_from_top=0 slot this type used to occupy now holds
|
|
* zuse_genesis_marker_t (zuse_genesis_marker.h) instead -- pubkey only,
|
|
* no seed. This type is no longer written by any code path; kept in the
|
|
* repo as historical record of the format it replaced, per this
|
|
* project's own convention for superseded design (see e.g. the
|
|
* TRIPOD.md/HERMES.md/ARTEMIS.md/CONSOLE.md superseded-header pattern).
|
|
* Do not resurrect writes to this format.
|
|
*
|
|
* Original doc, kept for context:
|
|
*
|
|
* on-disk record format for Zuse's cert, stored
|
|
* in devblock_from_top=0 of the top-of-device system-metadata fence
|
|
* (block_subsystem.h's blk_meta_zone_read()/write(), Phase 8, FABRIC-2.md
|
|
* §C). Raw, unpacked 4 KiB devblock -- same convention as the volume
|
|
* header itself (magic + version + fields + pad-to-4096, real CRC from
|
|
* day one, matching homeblocks_sig_t's own precedent for exactly this
|
|
* reason: this gates a real security check, not a placeholder).
|
|
*
|
|
* Deliberately its own header, not inlined at the one call site that
|
|
* uses it today (kernel_main.c's first-boot mint-or-load): the ongoing
|
|
* `MINT` word (still open, FABRIC-2.md) will be a second consumer of
|
|
* this exact format later, and the format should be stable and
|
|
* documented once rather than ad-hoc.
|
|
*/
|
|
#ifndef STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
|
#define STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
|
|
|
#include <stdint.h>
|
|
|
|
/* Packed via shifts, not a hand-computed hex literal -- this project's
|
|
* own standing lesson about hand-derived numeric constants in this
|
|
* class of code (see FABRIC-2.md's Ed25519/scalar25519 writeups). */
|
|
#define ZUSE_CERT_DEVBLOCK_MAGIC \
|
|
((uint32_t)'Z' | ((uint32_t)'U' << 8) | ((uint32_t)'S' << 16) | ((uint32_t)'E' << 24))
|
|
|
|
#define ZUSE_CERT_DEVBLOCK_VERSION 1u
|
|
|
|
typedef struct {
|
|
uint32_t magic; /* ZUSE_CERT_DEVBLOCK_MAGIC; anything else means
|
|
* "not a real cert yet" (blank/foreign bytes),
|
|
* not a format-corruption error */
|
|
uint32_t version; /* ZUSE_CERT_DEVBLOCK_VERSION */
|
|
uint8_t seed[32]; /* Ed25519 seed -- the private identity */
|
|
uint8_t pubkey[32]; /* Ed25519 public key derived from seed at mint time */
|
|
uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64())
|
|
* over every byte of this struct up to (not
|
|
* including) this field -- real from day one,
|
|
* this gates a real security check */
|
|
uint8_t _pad[4096 - (4 + 4 + 32 + 32 + 8)];
|
|
} zuse_cert_devblock_t;
|
|
|
|
_Static_assert(sizeof(zuse_cert_devblock_t) == 4096,
|
|
"zuse_cert_devblock_t must be exactly one 4 KiB devblock");
|
|
|
|
#endif /* STARKERNEL_ZUSE_CERT_DEVBLOCK_H */
|