Add disk/zuse.img + bleach_zuse_img.sh: first-boot mint testing (Phase 8)

Resolves the acl_pinned punch-list item's open question: credential
data (ZUSE-CERT-LO/HI, ACL-CA-KEY-LO/HI) are CONSTANT words, i.e. real
DictEntrys, and acl_pinned's enforcement (vm_create_word()'s
unconditional shadow-refusal for any pinned name) already covers this
generally -- no new flag needed, zuse.4th's ACL-ZUSE-BOOT already pins
both cert constants today.

That investigation surfaced a real gap: ACL-ZUSE-BOOT pins the cert
constants unconditionally on every boot, before any legitimate mint
could ever run, permanently locking in the 0 placeholder on the very
first boot. This directly shaped Captain Bob's next design pass: a
dedicated zuse.img test thumbdrive, "bleachable" back to pristine
state for repeated first-boot testing; a one-time mint-then-pin flow
(fixing the gap above); a separate ongoing S" name" MINT word for
minting additional regular users; and an explicitly-deferred Zuse
recovery path question.

This commit is the first piece: disk/zuse.img (64MB blank, matching
the existing USB-fixture convention) + scripts/bleach_zuse_img.sh
(idempotent reset). Verified live via QMP hotplug -- reads back as
HOMEBLOCKS_SIG_BLANK, correctly simulating a genuine first boot.
Deliberately flat/raw, not GPT-partitioned, matching
homeblocks_sig_check()'s current sig_start_fblock=0 assumption; both
move to a real GPT-relative offset together once a parser exists. No
kernel code touched -- host-side test tooling only, no 3-arch
acceptance boot needed.

Still open: the mint-then-pin boot fix, the MINT word, Zuse recovery.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CXjAPTEKrgY2Mrk25KoLDn
This commit is contained in:
Robert Allan James
2026-08-26 07:51:44 -04:00
co-authored by Claude Sonnet 5
parent 28c1b12c7f
commit 35f84d4a45
5 changed files with 91 additions and 5 deletions
+6
View File
@@ -24,6 +24,12 @@ Utility scripts for building, profiling, DoE experiments, and documentation.
| `rundisk.sh` | Boot a disk image in QEMU |
| `qemu_screenshot.sh` | Capture QEMU serial output |
## Phase 8 / identity testing scripts
| Script | Purpose |
|--------|---------|
| `bleach_zuse_img.sh` | Reset `disk/zuse.img` back to pristine/unminted (blank) state, for repeatable first-boot mint-flow testing |
## FORTH capsule scripts
| Script | Purpose |