Phase 8 C (5/n): Zuse's cert wired to the fence -- first-boot mint works
Replaces the crashed NVRAM approach entirely. New include/starkernel/zuse_cert_devblock.h: a standalone on-disk record (magic + version + 32-byte seed + 32-byte pubkey + a real CRC-64/ISO from day one, same discipline homeblocks_sig_t established) occupying devblock_from_top=0 of the fence. Its own header, not inlined at the boot call site, since the still-open MINT word will be a second consumer of this exact format. kernel_main.c's mint-or-load logic now reads the fence, installs an existing valid cert, or mints fresh via virtio_rng+ed25519_keygen and writes it. Runs right after virtio_rng_init(), before capsule_birth_mama() -- unlike the crashed NVRAM attempt, raw block I/O against Artemis's already-proven device has no boot-timing risk, so the earlier "re-invoke ACL-ZUSE-BOOT after Mama birth" workaround is gone; ACL.4th's self-activating ACL-ZUSE-BOOT sees a correct cert on its one ordinary pass. Verified independently across every real scenario, never trusting the kernel's own report: fresh mint decodes correctly on disk with a CRC confirmed by a from-scratch Python re-implementation of the algorithm; a reboot without reformatting loads back byte-for-byte identical seed/pubkey (genuinely "mint once, ever"); a pre-fence volume refuses cleanly (no crash, no silent data loss, honest "not persistent" reporting); the real, untouched disk/artemis.img exercises the same graceful-refusal path identically on all three architectures. Phase 8's core arc is now functionally complete: real entropy -> real signing -> real anti-file block-native persistence -> a first-boot mint that survives reboots. Still open: the ongoing MINT word for minting additional regular users. Documented in FABRIC-3.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U14ET9CWAtbQMbYqomKgXd
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
6e9c1d3bc2
commit
a8692681a8
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* zuse_cert_devblock.h -- on-disk record format for Zuse's cert, stored
|
||||
* in devblock_from_top=0 of the top-of-device system-metadata fence
|
||||
* (block_subsystem.h's blk_meta_zone_read()/write(), Phase 8, FABRIC-3.md
|
||||
* §C). Raw, unpacked 4 KiB devblock -- same convention as the volume
|
||||
* header itself (magic + version + fields + pad-to-4096, real CRC from
|
||||
* day one, matching homeblocks_sig_t's own precedent for exactly this
|
||||
* reason: this gates a real security check, not a placeholder).
|
||||
*
|
||||
* Deliberately its own header, not inlined at the one call site that
|
||||
* uses it today (kernel_main.c's first-boot mint-or-load): the ongoing
|
||||
* `MINT` word (still open, FABRIC-3.md) will be a second consumer of
|
||||
* this exact format later, and the format should be stable and
|
||||
* documented once rather than ad-hoc.
|
||||
*/
|
||||
#ifndef STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
||||
#define STARKERNEL_ZUSE_CERT_DEVBLOCK_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
/* Packed via shifts, not a hand-computed hex literal -- this project's
|
||||
* own standing lesson about hand-derived numeric constants in this
|
||||
* class of code (see FABRIC-3.md's Ed25519/scalar25519 writeups). */
|
||||
#define ZUSE_CERT_DEVBLOCK_MAGIC \
|
||||
((uint32_t)'Z' | ((uint32_t)'U' << 8) | ((uint32_t)'S' << 16) | ((uint32_t)'E' << 24))
|
||||
|
||||
#define ZUSE_CERT_DEVBLOCK_VERSION 1u
|
||||
|
||||
typedef struct {
|
||||
uint32_t magic; /* ZUSE_CERT_DEVBLOCK_MAGIC; anything else means
|
||||
* "not a real cert yet" (blank/foreign bytes),
|
||||
* not a format-corruption error */
|
||||
uint32_t version; /* ZUSE_CERT_DEVBLOCK_VERSION */
|
||||
uint8_t seed[32]; /* Ed25519 seed -- the private identity */
|
||||
uint8_t pubkey[32]; /* Ed25519 public key derived from seed at mint time */
|
||||
uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64())
|
||||
* over every byte of this struct up to (not
|
||||
* including) this field -- real from day one,
|
||||
* this gates a real security check */
|
||||
uint8_t _pad[4096 - (4 + 4 + 32 + 32 + 8)];
|
||||
} zuse_cert_devblock_t;
|
||||
|
||||
_Static_assert(sizeof(zuse_cert_devblock_t) == 4096,
|
||||
"zuse_cert_devblock_t must be exactly one 4 KiB devblock");
|
||||
|
||||
#endif /* STARKERNEL_ZUSE_CERT_DEVBLOCK_H */
|
||||
Reference in New Issue
Block a user