Implement homeblocks_sig_check(): the drive signature check (Phase 8)

Real, complete verification logic -- not yet wired to any write path.
homeblocks_sig_check(dev, sig_start_fblock, out_sig) reads the 4
consecutive 1KB blkio forth-blocks the 4KB header spans, verifies
magic -> version -> CRC-64 in order, returns HOMEBLOCKS_SIG_OK/_BLANK/
_BAD_VERSION/_BAD_CRC/_READ_ERROR. Reuses block_subsystem.c's existing
CRC-64/ISO (compute_crc64, previously static/file-local, now exposed
via block_subsystem.h) rather than a second CRC implementation --
same algorithm already proven via per-block checksums. Takes the
header's starting block as a plain parameter rather than resolving it
internally: verifies a signature given a location, finding that
location (GPT-partition-relative) stays the caller's job.

Verified against the actual shipped code, not a reimplementation: a
standalone host test links the real homeblocks_sig.c against a fake
in-memory blkio_dev and exercises all four outcomes -- blank media,
a correctly-minted header (round-trips drive_uuid/minted_time_ns), a
flipped CRC, an unrecognized version. All four pass. A full
QEMU-hotplug live test isn't proportionate yet since nothing calls
this function from the live kernel path -- wiring it into the attach
path is the next punch-list item. Clean zero-warning compile and
clean boot on all three architectures confirms no build/link
regression from exposing compute_crc64 and adding the new source
file to every kernel build.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
Robert Allan James
2026-08-26 07:05:37 -04:00
co-authored by Claude Sonnet 5
parent 10b96870c5
commit 2c45744995
13 changed files with 27292 additions and 6 deletions
+25 -3
View File
@@ -212,10 +212,32 @@ decisions get added here, not to `FABRIC-2.md`. Follow the same discipline `FABR
3-arch acceptance boot needed for this step; that starts with the signature-check
implementation, the next punch-list item below.
- [ ] Implement the signature check, called before any write path touches a newly-inserted
drive.
- [x] **Implemented (2026-08-26): the check function itself, real and complete — not yet
wired to any write path.** `include/starkernel/homeblocks_sig.h` +
`src/starkernel/homeblocks_sig.c`: `homeblocks_sig_check(dev, sig_start_fblock, out_sig)`
reads the 4 consecutive 1KB `blkio` forth-blocks the 4KB header spans, verifies magic →
version → CRC-64 in order, returns one of `HOMEBLOCKS_SIG_OK`/`_BLANK`/`_BAD_VERSION`/
`_BAD_CRC`/`_READ_ERROR`. Reuses `block_subsystem.c`'s existing CRC-64/ISO
(`compute_crc64`, previously `static`/file-local, now exposed) rather than a second CRC
implementation — same algorithm already proven via per-block checksums. Takes the header's
starting block as a plain parameter rather than resolving it internally: this function
verifies a signature given a location; finding that location (GPT-partition-relative,
once a parser exists) stays the caller's job, not invented here.
- [ ] Implement the warn-and-refuse behavior for blank/foreign/unrecognized media.
**Verified against the actual shipped code**, not a reimplementation: a standalone host
test links the real `homeblocks_sig.c` against a fake in-memory `blkio_dev` and exercises
all four outcomes — blank media → `BLANK`, a correctly-minted header → `OK` (round-trips
`drive_uuid`/`minted_time_ns` correctly), a flipped CRC → `BAD_CRC`, an unrecognized
version → `BAD_VERSION`. All four pass. A full QEMU-hotplug live test isn't proportionate
yet — nothing calls this function from the live kernel path (deliberately; wiring it into
the attach path is the next item below), so a live boot check has nothing to exercise.
Clean zero-warning compile and clean boot on all three architectures confirms no
build/link regression from exposing `compute_crc64` and adding the new source file to
every kernel build.
- [ ] Implement the warn-and-refuse behavior for blank/foreign/unrecognized media — this is
where `homeblocks_sig_check()` above actually gets a live caller, wiring it into the real
drive-insertion path.
- [ ] Extend `acl_pinned`'s one-way-ratchet mechanism (already exists, already proven, just
needs applying) to gate zuse credential minting specifically — confirm whether this