Implement homeblocks_sig_check(): the drive signature check (Phase 8)

Real, complete verification logic -- not yet wired to any write path.
homeblocks_sig_check(dev, sig_start_fblock, out_sig) reads the 4
consecutive 1KB blkio forth-blocks the 4KB header spans, verifies
magic -> version -> CRC-64 in order, returns HOMEBLOCKS_SIG_OK/_BLANK/
_BAD_VERSION/_BAD_CRC/_READ_ERROR. Reuses block_subsystem.c's existing
CRC-64/ISO (compute_crc64, previously static/file-local, now exposed
via block_subsystem.h) rather than a second CRC implementation --
same algorithm already proven via per-block checksums. Takes the
header's starting block as a plain parameter rather than resolving it
internally: verifies a signature given a location, finding that
location (GPT-partition-relative) stays the caller's job.

Verified against the actual shipped code, not a reimplementation: a
standalone host test links the real homeblocks_sig.c against a fake
in-memory blkio_dev and exercises all four outcomes -- blank media,
a correctly-minted header (round-trips drive_uuid/minted_time_ns), a
flipped CRC, an unrecognized version. All four pass. A full
QEMU-hotplug live test isn't proportionate yet since nothing calls
this function from the live kernel path -- wiring it into the attach
path is the next punch-list item. Clean zero-warning compile and
clean boot on all three architectures confirms no build/link
regression from exposing compute_crc64 and adding the new source
file to every kernel build.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
Robert Allan James
2026-08-26 07:05:37 -04:00
co-authored by Claude Sonnet 5
parent 10b96870c5
commit 2c45744995
13 changed files with 27292 additions and 6 deletions
+6
View File
@@ -293,6 +293,12 @@ int blk_get_volume_meta(blk_volume_meta_t *meta);
int blk_set_volume_meta(const blk_volume_meta_t *meta);
/* CRC-64/ISO (poly 0x42F0E1EBA9EA3693), reflected, init/final all-ones --
* exposed for homeblocks_sig.c's drive-signature integrity check, which
* needs the exact same algorithm this file already uses for per-block
* checksums rather than a second, duplicate CRC implementation. */
uint64_t compute_crc64(const uint8_t *data, size_t len);
int blk_is_valid(uint32_t block_num);
uint32_t blk_get_total_blocks(void);
+50
View File
@@ -118,6 +118,56 @@ typedef struct {
* same discipline stadium.h's own header-size checks already use. */
typedef char homeblocks_sig_size_check[(sizeof(homeblocks_sig_t) == 4096) ? 1 : -1];
/*===========================================================================
* Signature check (FABRIC-3.md, Milestone 4)
*===========================================================================*/
typedef enum {
HOMEBLOCKS_SIG_OK = 0, /* magic, version, and crc all check out */
HOMEBLOCKS_SIG_BLANK, /* magic does not match -- blank or foreign media */
HOMEBLOCKS_SIG_BAD_VERSION, /* magic matches, version unrecognized */
HOMEBLOCKS_SIG_BAD_CRC, /* magic+version match, crc fails -- corrupt or tampered */
HOMEBLOCKS_SIG_READ_ERROR /* could not read from the device at all */
} homeblocks_sig_result_t;
/* Forward-declared, not included here -- avoids a hard dependency from this
* small format header onto blkio.h's full device/vtable machinery for
* callers that only need the struct layout (e.g. a future minting tool). */
struct blkio_dev;
/*
* homeblocks_sig_check - Read and verify the drive signature header.
*
* Reads 4 consecutive 1KB "forth blocks" (dev->read()'s own unit) starting
* at sig_start_fblock into a local 4KB buffer and interprets it as a
* homeblocks_sig_t. Deliberately takes the starting block as a plain
* parameter rather than resolving it internally -- this function verifies a
* signature given a location; finding that location (GPT-partition-relative
* today, once a GPT parser exists) is the caller's job, not invented here.
*
* @param dev Open block device to read from.
* @param sig_start_fblock First of 4 consecutive forth-blocks holding the
* 4KB header.
* @param out_sig On HOMEBLOCKS_SIG_OK, populated with the verified
* header. Left unspecified on any other result.
* @return HOMEBLOCKS_SIG_OK, or the specific reason for refusal.
*/
homeblocks_sig_result_t homeblocks_sig_check(struct blkio_dev *dev,
uint32_t sig_start_fblock,
homeblocks_sig_t *out_sig);
/*
* homeblocks_sig_compute_crc - CRC-64 over every field of `sig` up to but
* not including hdr_crc itself and the trailing padding -- the same
* boundary homeblocks_sig_check() verifies against and any future minting
* code must use when writing a fresh header. Exposed publicly since both
* directions (check and future mint) need the identical computation.
*
* @param sig Header to checksum. hdr_crc and _pad are not read.
* @return The CRC-64 value that hdr_crc should hold for `sig` to verify.
*/
uint64_t homeblocks_sig_compute_crc(const homeblocks_sig_t *sig);
#ifdef __cplusplus
}
#endif