Milestone 6: mkcapsule signing + capsule_birth.c wiring, WARN-only
First attempt shelled out to `openssl pkeyutl -sign` (fork/execlp, not system() -- avoided shell string interpolation of the key path). Corrected on request: no new external host binary dependency when the repo's own code can do the job -- same standing preference as the earlier anti-file correction. Rewritten to link ed25519_sign() (already verified against OpenSSL in Phase B) directly into mkcapsule. New tools/pkcs8_ed25519.c: a narrow DER walker (same shape as x509_ed25519.c, deliberately not shared -- small enough that duplicating a few TLV-walking lines beat threading a header between the kernel crypto tree and host tooling) extracting the raw seed from the intermediate's PKCS#8 private key, plus a minimal self-written base64 decoder (PEM is openssl genpkey's default output; no decoder existed anywhere in the repo). Verified end-to-end before wiring anything in: the extracted seed's derived pubkey matches the cert's exactly, and a full self-contained sign+verify round-trip (zero openssl) passes. CapsuleDesc had no spare bytes, so signatures live in a new parallel CapsuleSigEntry array, emitted by a new `mkcapsule --sign-key <path>` flag (omitted/missing key -> has_sig=0 everywhere, graceful, not a build failure -- CI has no access to the offline key). New capsule_sig.c/.h: capsule_verify_signature(), a separate function, not folded into the already-tested capsule_validate(). Finds and caches the embedded intermediate cert's pubkey once per boot, then verifies against it. Wired into all three capsule_validate() call sites in capsule_birth.c via log_message(LOG_WARN, ...) -- never refuses yet, per the earlier staged-rollout decision. Verified independently, both directions, live in the real kernel: a full clean build (38 signed capsules) boots clean on all three architectures with zero warnings. Separately, hand-corrupted one byte of Mama's own init.4th capsule's stored signature (not its payload/hash, which capsule_validate() already catches and would have masked the test) and rebuilt just the changed object: produced exactly "capsule sig: init.4th: INVALID -- signature does not verify" on boot, and the kernel still reached ok> -- proving warn-only doesn't refuse anything yet. Reverted before the final, untampered 3-arch acceptance pass. Still open: flipping WARN to hard-refuse (separate, deliberate step) and the BLOCK_MAP.md signature-status column. Documented in FABRIC-3.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
431bcb1f34
commit
2fc55f47e1
+15
-4
@@ -101,8 +101,19 @@ DOE_LATEST_DIR := experiments/bare_metal/latest
|
||||
|
||||
CAPSULES_DIR ?= capsules
|
||||
ARTDISK ?= disk/artemis.img
|
||||
MKCAPSULE_SRC = tools/mkcapsule.c
|
||||
MKCAPSULE_SRC = tools/mkcapsule.c tools/pkcs8_ed25519.c \
|
||||
src/starkernel/crypto/ed25519.c \
|
||||
src/starkernel/crypto/fe25519.c \
|
||||
src/starkernel/crypto/scalar25519.c \
|
||||
src/starkernel/crypto/sha512.c
|
||||
MKCAPSULE_BIN = $(BUILD_DIR)/tools/mkcapsule
|
||||
# Milestone 6 (Phase 8): the snakeoil intermediate's private key, generated
|
||||
# offline outside this repo entirely (see FABRIC-3.md's Phase 8 §Milestone 6
|
||||
# writeup) -- not present in CI or a fresh checkout, so signing is skipped
|
||||
# gracefully ($(wildcard ...) below) rather than failing the build. Override
|
||||
# with `make SIGN_KEY=/path/to/key.pem ...` on a machine that holds it.
|
||||
SIGN_KEY ?= /home/rajames/CLionProjects/lithosananke-ca/intermediate/snakeoil-intermediate.key
|
||||
SIGN_KEY_ARGS = $(if $(wildcard $(SIGN_KEY)),--sign-key $(SIGN_KEY),)
|
||||
CAPSULE_GENERATED = $(BUILD_DIR)/capsule_generated.c
|
||||
CAPSULE_GENERATED_OBJ = $(BUILD_DIR)/capsule_generated.o
|
||||
CAPSULE_GENERATED_KOBJ = $(KERNEL_OBJ_DIR)/capsule_generated.o
|
||||
@@ -567,15 +578,15 @@ include/version.h:
|
||||
# Host tool: capsule packer
|
||||
$(MKCAPSULE_BIN): $(MKCAPSULE_SRC)
|
||||
@mkdir -p $(dir $@)
|
||||
@echo "HOSTCC $<"
|
||||
@cc -std=c99 -Wall -Wextra -O2 -o $@ $<
|
||||
@echo "HOSTCC $(MKCAPSULE_SRC)"
|
||||
@cc -std=c99 -Wall -Wextra -O2 -Iinclude -Itools -o $@ $(MKCAPSULE_SRC)
|
||||
|
||||
# Generate capsule_generated.c from capsules/
|
||||
CAPSULE_SRCS := $(shell find $(CAPSULES_DIR) -type f ! -name '.*' 2>/dev/null)
|
||||
$(CAPSULE_GENERATED): $(MKCAPSULE_BIN) $(CAPSULE_SRCS)
|
||||
@mkdir -p $(dir $@)
|
||||
@echo " MKCAP $(CAPSULES_DIR) -> $@"
|
||||
@$(MKCAPSULE_BIN) $(CAPSULES_DIR) $@
|
||||
@$(MKCAPSULE_BIN) $(SIGN_KEY_ARGS) $(CAPSULES_DIR) $@
|
||||
@echo " MKCAP $(CAPSULES_DIR) -> $(CAPSULES_DIR)/BLOCK_MAP.md"
|
||||
@$(MKCAPSULE_BIN) --manifest $(CAPSULES_DIR) $(CAPSULES_DIR)/BLOCK_MAP.md
|
||||
|
||||
|
||||
Reference in New Issue
Block a user