Implement homeblocks_sig_check(): the drive signature check (Phase 8)
Real, complete verification logic -- not yet wired to any write path. homeblocks_sig_check(dev, sig_start_fblock, out_sig) reads the 4 consecutive 1KB blkio forth-blocks the 4KB header spans, verifies magic -> version -> CRC-64 in order, returns HOMEBLOCKS_SIG_OK/_BLANK/ _BAD_VERSION/_BAD_CRC/_READ_ERROR. Reuses block_subsystem.c's existing CRC-64/ISO (compute_crc64, previously static/file-local, now exposed via block_subsystem.h) rather than a second CRC implementation -- same algorithm already proven via per-block checksums. Takes the header's starting block as a plain parameter rather than resolving it internally: verifies a signature given a location, finding that location (GPT-partition-relative) stays the caller's job. Verified against the actual shipped code, not a reimplementation: a standalone host test links the real homeblocks_sig.c against a fake in-memory blkio_dev and exercises all four outcomes -- blank media, a correctly-minted header (round-trips drive_uuid/minted_time_ns), a flipped CRC, an unrecognized version. All four pass. A full QEMU-hotplug live test isn't proportionate yet since nothing calls this function from the live kernel path -- wiring it into the attach path is the next punch-list item. Clean zero-warning compile and clean boot on all three architectures confirms no build/link regression from exposing compute_crc64 and adding the new source file to every kernel build. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
10b96870c5
commit
2c45744995
+25
-3
@@ -212,10 +212,32 @@ decisions get added here, not to `FABRIC-2.md`. Follow the same discipline `FABR
|
||||
3-arch acceptance boot needed for this step; that starts with the signature-check
|
||||
implementation, the next punch-list item below.
|
||||
|
||||
- [ ] Implement the signature check, called before any write path touches a newly-inserted
|
||||
drive.
|
||||
- [x] **Implemented (2026-08-26): the check function itself, real and complete — not yet
|
||||
wired to any write path.** `include/starkernel/homeblocks_sig.h` +
|
||||
`src/starkernel/homeblocks_sig.c`: `homeblocks_sig_check(dev, sig_start_fblock, out_sig)`
|
||||
reads the 4 consecutive 1KB `blkio` forth-blocks the 4KB header spans, verifies magic →
|
||||
version → CRC-64 in order, returns one of `HOMEBLOCKS_SIG_OK`/`_BLANK`/`_BAD_VERSION`/
|
||||
`_BAD_CRC`/`_READ_ERROR`. Reuses `block_subsystem.c`'s existing CRC-64/ISO
|
||||
(`compute_crc64`, previously `static`/file-local, now exposed) rather than a second CRC
|
||||
implementation — same algorithm already proven via per-block checksums. Takes the header's
|
||||
starting block as a plain parameter rather than resolving it internally: this function
|
||||
verifies a signature given a location; finding that location (GPT-partition-relative,
|
||||
once a parser exists) stays the caller's job, not invented here.
|
||||
|
||||
- [ ] Implement the warn-and-refuse behavior for blank/foreign/unrecognized media.
|
||||
**Verified against the actual shipped code**, not a reimplementation: a standalone host
|
||||
test links the real `homeblocks_sig.c` against a fake in-memory `blkio_dev` and exercises
|
||||
all four outcomes — blank media → `BLANK`, a correctly-minted header → `OK` (round-trips
|
||||
`drive_uuid`/`minted_time_ns` correctly), a flipped CRC → `BAD_CRC`, an unrecognized
|
||||
version → `BAD_VERSION`. All four pass. A full QEMU-hotplug live test isn't proportionate
|
||||
yet — nothing calls this function from the live kernel path (deliberately; wiring it into
|
||||
the attach path is the next item below), so a live boot check has nothing to exercise.
|
||||
Clean zero-warning compile and clean boot on all three architectures confirms no
|
||||
build/link regression from exposing `compute_crc64` and adding the new source file to
|
||||
every kernel build.
|
||||
|
||||
- [ ] Implement the warn-and-refuse behavior for blank/foreign/unrecognized media — this is
|
||||
where `homeblocks_sig_check()` above actually gets a live caller, wiring it into the real
|
||||
drive-insertion path.
|
||||
|
||||
- [ ] Extend `acl_pinned`'s one-way-ratchet mechanism (already exists, already proven, just
|
||||
needs applying) to gate zuse credential minting specifically — confirm whether this
|
||||
|
||||
Reference in New Issue
Block a user