Retire emergency CLI: Zuse goes thumbdrive-resident, ACL.4th activated

Three tightly-coupled changes, verified together per Captain Bob's own
"getting rid of the emergency cli" direction:

1. Zuse's identity is thumbdrive-resident, never system-resident. New
   zuse_genesis_marker_t (magic/version/zuse_pubkey[32]/crc) replaces
   zuse_cert_devblock_t's slot in the top-of-device fence -- the system
   now remembers only that a root identity exists and its pubkey, never
   a seed. zuse_cert_devblock_t is kept in the repo, marked superseded,
   no longer written by any code path.

   capsule_mint_identity() grows a genesis mode (issuer_vm=NULL): no
   cert is built or written (Zuse isn't verified against a separate
   signer -- she's recognized by pubkey match against the marker) and
   two new optional out-params (out_pubkey/out_seed) let the caller
   install the cert immediately after a genesis mint.

   New capsule_zuse_boot_try_attach() (capsule_zuse_boot.c), called
   from sk_repl_idle() on every fresh USB attach (the only point in the
   boot lifecycle a thumbdrive can actually be detected -- attach
   polling doesn't exist yet at kernel_main.c's old one-shot mint point,
   which is why that whole block is gone): no marker + blank drive ->
   genesis-mint; marker present + matching drive -> read its own
   user_identity_seed_t, install the cert. Either way, re-runs
   ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly like it
   always has for a same-boot cert install -- ACL-PIN only blocks
   redefinition, not re-execution, so no new C-side auth logic needed.

2. ACL.4th activated (capsules/init.4th) -- inactive all session until
   now. Found and fixed a real bug this immediately surfaced: zuse.4th's
   ACL-ZUSE-BOOT tried `['] ACL-ZUSE-BOOT ACL-PIN` from inside its own
   still-compiling definition -- the word isn't findable yet at that
   point, so the whole definition silently failed to compile every
   previous boot this session (dormant, since ACL.4th never loaded).
   Fixed: pin after the definition closes, not from within it -- it
   only needs to happen once anyway, and pinning doesn't block the
   re-invocation genesis/attach needs.

3. The unauthenticated emergency-CLI ACL bypass is retired
   (repl.c): `emergency_console = is_hera ? (zuse_session ? 0 : 1) : 0`
   deleted from both sk_repl_step and sk_repl_run. Every word run from
   Hera's own bare prompt now goes through ordinary ACL enforcement;
   emergency_console is driven only by the genuine C-level fault
   handler again.

Added ZUSE-SESSION? (starforth_words.c), a read-only diagnostic
matching ZUSE-PUBKEY@'s own precedent, to verify the whole chain
directly rather than by inference.

Verified end-to-end live in QEMU: fresh boot, no thumbdrive ->
ZUSE-SESSION? reads 0. Attach a genuinely blank drive via QMP -> genesis
mint fires automatically (no typing) -> ZUSE-SESSION? reads -1 (true).
Hermes/Artemis both birth clean on all three architectures with ACL
now actually enforced for the first time all session -- no denials, no
UNKNOWN WORD beyond the deliberate POST self-test cases.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
This commit is contained in:
Robert Allan James
2026-08-28 16:10:40 -04:00
co-authored by Claude Sonnet 5
parent 7fc3e93358
commit cc9521d2cc
20 changed files with 55353 additions and 118 deletions
+9 -9
View File
@@ -1,5 +1,5 @@
# Capsule Block Manifest — Auto-generated
<!-- Generated by mkcapsule --manifest 2026-08-28T19:31:45Z -->
<!-- Generated by mkcapsule --manifest 2026-08-28T20:09:16Z -->
<!-- DO NOT EDIT — re-run mkcapsule --manifest to refresh. -->
<!-- Hand-written justifications and immutability notes live -->
<!-- in MANIFEST.md alongside this auto-generated index. -->
@@ -33,21 +33,21 @@
| `init-l8-temporal.4th` | 4830, 4831 | `0x51abd4c138246651` | yes |
| `init-l8-transition.4th` | 4840, 4841, 4842 | `0xbcc1a81976f0a4c9` | yes |
| `init-l8-volatile.4th` | 4810, 4811, 4812, 4813 | `0x98caabbbd92abac4` | yes |
| `init.4th` | 2049, 2050, 2057 | `0xd1022c2e4331f244` | yes |
| `init.4th` | 2049, 2050, 2057 | `0x9ac6523d24b80cd0` | yes |
| `lib.4th` | 4050 | `0x4b216635c359ef73` | yes |
| `process.4th` | 4300, 4301 | `0x781afc1dbd0294f7` | yes |
| `sdk.4th` | 5109, 5110, 5111, 5112, 5113, 5114, 5115 | `0x008fdbbb62c94a3a` | yes |
| `turtle.4th` | 5100, 5101, 5102, 5103, 5104, 5105, 5106, 5107, 5108 | `0x4d470418ca543365` | yes |
| `user-font-demo.4th` | 4200, 4201, 4202 | `0xce1fd7d1b581a56d` | yes |
| `zuse.4th` | 4016, 4017, 4018 | `0x3b31872d02a43d83` | yes |
| `zuse.4th` | 4016, 4017, 4018 | `0x490ded9be257a90b` | yes |
## Block Map (sorted by LBN)
| LBN | Capsule | xxHash64 | Status |
|-----|---------|----------|--------|
| 2049 | `init.4th` | `0xd1022c2e4331f244` | ok |
| 2050 | `init.4th` | `0xd1022c2e4331f244` | ok |
| 2057 | `init.4th` | `0xd1022c2e4331f244` | ok |
| 2049 | `init.4th` | `0x9ac6523d24b80cd0` | ok |
| 2050 | `init.4th` | `0x9ac6523d24b80cd0` | ok |
| 2057 | `init.4th` | `0x9ac6523d24b80cd0` | ok |
| 2064 | `init-l8-omni.4th` | `0x5979e314d6452045` | ok |
| 2065 | `init-l8-omni.4th` | `0x5979e314d6452045` | ok |
| 2066 | `init-l8-omni.4th` | `0x5979e314d6452045` | ok |
@@ -104,9 +104,9 @@
| 4006 | `ACL.4th` | `0xd781d22148ff171d` | ok |
| 4007 | `ACL.4th` | `0xd781d22148ff171d` | ok |
| 4015 | `ACL.4th` | `0xd781d22148ff171d` | ok |
| 4016 | `zuse.4th` | `0x3b31872d02a43d83` | ok |
| 4017 | `zuse.4th` | `0x3b31872d02a43d83` | ok |
| 4018 | `zuse.4th` | `0x3b31872d02a43d83` | ok |
| 4016 | `zuse.4th` | `0x490ded9be257a90b` | ok |
| 4017 | `zuse.4th` | `0x490ded9be257a90b` | ok |
| 4018 | `zuse.4th` | `0x490ded9be257a90b` | ok |
| 4050 | `lib.4th` | `0x4b216635c359ef73` | ok |
| 4055 | `common:msg.4th` | `0x850a0382344ea6c4` | ok |
| 4060 | `doe-campaign.4th` | `0x3d4549142d91ec20` | ok |
+1 -1
View File
@@ -13,7 +13,7 @@ Block 2049
: VM-TREE ( -- ) ." Hera[0]" CR ;
: VM-PARENT ( -- id ) 0 ;
: VM-CHILDREN ( -- ) ." (none)" CR ;
\ S" ACL.4th" EXEC
S" ACL.4th" EXEC
S" lib.4th" EXEC
S" fabric.4th" EXEC
S" font.4th" EXEC
+16 -11
View File
@@ -3,31 +3,36 @@ Block 4016
( Named for Konrad Zuse, pioneer of programmable computers. )
( Sole superuser; mints credentials; owns emergency REPL. )
( Loaded by ACL.4th; must not load before ACL.4th. )
( FUTURE: Replace with thumbdrive Ed25519 PKI. )
( Thumbdrive-resident Ed25519 PKI (2026-08-28) -- her seed )
( lives only on her own minted drive, never system-resident. )
( HUMAN-REVIEW: capsule hash = root of superuser trust. )
( Cert (seed+pubkey) lives in C-only VM fields, installed by )
( kernel_main.c's first-boot mint-or-load (NVRAM ZuseCert). )
( capsule_zuse_boot.c on genesis-mint or thumbdrive attach. )
( NOT a CONSTANT: ACL-PIN blocks redefinition, not a )
( >BODY-then-store, so a pinned CONSTANT isn't tamper-proof. )
( Read with ZUSE-PUBKEY@ / ZUSE-CERT-INSTALLED? -- both C )
( primitives, read-only; the seed has no FORTH access at all. )
Block 4017
( ACL-ZUSE-BOOT ( -- ) )
( Only authenticates if a real cert was installed this boot -- )
( refuses god-mode to a Zuse with no real identity behind her )
( (no runtime services, no entropy). Pins itself against )
( redefinition either way. ZUSE-AUTHENTICATE is C-only; no )
( FORTH word grants god-mode except through this sequence. )
( ACL-ZUSE-BOOT ( -- ) re-invokable: capsule_zuse_boot.c )
( calls it again once a thumbdrive attach installs a cert. )
( Only authenticates if a real cert is installed -- refuses )
( god-mode to a Zuse with no real identity behind her. )
( ZUSE-AUTHENTICATE is C-only; no FORTH word grants god-mode )
( except through this sequence. )
: ACL-ZUSE-BOOT ( -- )
ZUSE-CERT-INSTALLED? IF
ZUSE-AUTHENTICATE
LOG-INFO" zuse: activated"
ELSE
LOG-INFO" zuse: NOT activated -- no cert installed"
THEN
['] ACL-ZUSE-BOOT ACL-PIN ;
THEN ;
Block 4018
( Self-activation )
( Pin against redefinition -- once, after definition closes; )
( ['] from inside its own body can't find itself mid-compile, )
( found live 2026-08-28 activating ACL.4th for the first time. )
( Pinning doesn't block re-EXECUTION, only redefinition -- the )
( re-invoke above still works after this runs. Self-activates. )
['] ACL-ZUSE-BOOT ACL-PIN
ACL-ZUSE-BOOT