Files
LithosAnanake/capsules/contrib/README.md
T
Robert Allan JamesandClaude Sonnet 5 b031b802e3 Rename FABRIC series: FABRIC.md->0, FABRIC-2.md->1, FABRIC-3.md->2, FABRIC-4.md unchanged
FABRIC.md -> FABRIC-0.md
FABRIC-2.md -> FABRIC-1.md
FABRIC-3.md -> FABRIC-2.md (the current/living document)
FABRIC-4.md unchanged (new #3 to follow separately)

Every cross-reference repo-wide updated to match, including doc-comment
citations inside kernel source (.c/.h) files -- done via an ordered
placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md->
placeholder1, FABRIC.md->placeholder0, then placeholders resolved to
final names) in a single pass per file to avoid double-shifting
already-renamed references.

One line in capsules/font.4th grew past the 64-char block-format limit
as a side effect of the longer filename; shortened it and reverified
with mkcapsule --lint (34/34 pass) before rebuilding.

Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the
foreground) after the fix; logs and DoE CSVs from this session's
verification runs included per this repo's own audit-artifact
convention.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
2026-09-04 11:22:51 -04:00

33 lines
1.8 KiB
Markdown

# capsules/contrib/
Milestone 7 (contributor capsules / trust tiers), FABRIC-2.md §I.5.
Any `.4th` file placed here gets `FLAG_CONTRIB` in addition to the usual
`FLAG_PRODUCTION | FLAG_EXPERIMENT` pair — `tools/mkcapsule.c`'s
`flags_from_name()` path-matches on the colon-separated capsule name
starting with `contrib:`, mirroring `FLAG_MAMA_INIT`'s own exact-match
pattern one line up in that same function.
**Trust-tier direction, decided in conversation 2026-09-04:** QEMU-vs-real-
hardware conditional enforcement — a contributor capsule is validated more
strictly on real hardware than under QEMU, using
`timer_calibration_record()->vm_mode` (`include/starkernel/timer.h`) as the
signal. `vm_mode` is a real per-architecture hypervisor-vs-hardware
detection as of this same pass (amd64: `CPUID.1:ECX[31]`; aarch64: ACPI
RSDP OEM ID; riscv64: devicetree `compatible` string) — not a build-time
flag, so the same binary enforces differently depending on where it
actually boots.
**Enforcement rule, built 2026-09-04:** `contrib_capsule_refused()`
(`capsule_birth.c`), called from both `capsule_birth_baby()` and
`capsule_run_experiment()` (never `capsule_birth_mama()` — Mama's own init
can never carry `FLAG_CONTRIB`, mutually exclusive with `FLAG_MAMA_INIT` by
construction). Under QEMU (`vm_mode == 1`): no additional check, same
WARN-only treatment every other capsule gets. On real hardware
(`vm_mode == 0`): a contrib capsule additionally requires `CAPSULE_SIG_OK`
`MISSING`/`NO_ROOT_KEY`, which stay WARN-only for every other capsule
(most machines lack the offline signing key), are refused here specifically
because a contributor's capsule has no other provenance to fall back on.
Additive to, never a replacement for, the existing `CAPSULE_SIG_INVALID`
refusal already enforced on every capsule regardless of `FLAG_CONTRIB`.