Retire emergency CLI: Zuse goes thumbdrive-resident, ACL.4th activated

Three tightly-coupled changes, verified together per Captain Bob's own
"getting rid of the emergency cli" direction:

1. Zuse's identity is thumbdrive-resident, never system-resident. New
   zuse_genesis_marker_t (magic/version/zuse_pubkey[32]/crc) replaces
   zuse_cert_devblock_t's slot in the top-of-device fence -- the system
   now remembers only that a root identity exists and its pubkey, never
   a seed. zuse_cert_devblock_t is kept in the repo, marked superseded,
   no longer written by any code path.

   capsule_mint_identity() grows a genesis mode (issuer_vm=NULL): no
   cert is built or written (Zuse isn't verified against a separate
   signer -- she's recognized by pubkey match against the marker) and
   two new optional out-params (out_pubkey/out_seed) let the caller
   install the cert immediately after a genesis mint.

   New capsule_zuse_boot_try_attach() (capsule_zuse_boot.c), called
   from sk_repl_idle() on every fresh USB attach (the only point in the
   boot lifecycle a thumbdrive can actually be detected -- attach
   polling doesn't exist yet at kernel_main.c's old one-shot mint point,
   which is why that whole block is gone): no marker + blank drive ->
   genesis-mint; marker present + matching drive -> read its own
   user_identity_seed_t, install the cert. Either way, re-runs
   ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly like it
   always has for a same-boot cert install -- ACL-PIN only blocks
   redefinition, not re-execution, so no new C-side auth logic needed.

2. ACL.4th activated (capsules/init.4th) -- inactive all session until
   now. Found and fixed a real bug this immediately surfaced: zuse.4th's
   ACL-ZUSE-BOOT tried `['] ACL-ZUSE-BOOT ACL-PIN` from inside its own
   still-compiling definition -- the word isn't findable yet at that
   point, so the whole definition silently failed to compile every
   previous boot this session (dormant, since ACL.4th never loaded).
   Fixed: pin after the definition closes, not from within it -- it
   only needs to happen once anyway, and pinning doesn't block the
   re-invocation genesis/attach needs.

3. The unauthenticated emergency-CLI ACL bypass is retired
   (repl.c): `emergency_console = is_hera ? (zuse_session ? 0 : 1) : 0`
   deleted from both sk_repl_step and sk_repl_run. Every word run from
   Hera's own bare prompt now goes through ordinary ACL enforcement;
   emergency_console is driven only by the genuine C-level fault
   handler again.

Added ZUSE-SESSION? (starforth_words.c), a read-only diagnostic
matching ZUSE-PUBKEY@'s own precedent, to verify the whole chain
directly rather than by inference.

Verified end-to-end live in QEMU: fresh boot, no thumbdrive ->
ZUSE-SESSION? reads 0. Attach a genuinely blank drive via QMP -> genesis
mint fires automatically (no typing) -> ZUSE-SESSION? reads -1 (true).
Hermes/Artemis both birth clean on all three architectures with ACL
now actually enforced for the first time all session -- no denials, no
UNKNOWN WORD beyond the deliberate POST self-test cases.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
This commit is contained in:
Robert Allan James
2026-08-28 16:10:40 -04:00
co-authored by Claude Sonnet 5
parent 7fc3e93358
commit cc9521d2cc
20 changed files with 55353 additions and 118 deletions
+18 -1
View File
@@ -58,16 +58,33 @@ typedef enum {
* @param dev Already-open block device for the target drive.
* @param issuer_vm The signing identity -- in practice always Hera's own
* VM (Zuse's cert lives there, vm.h's zuse_cert_seed).
* NULL means genesis mode (§F.21): no cert is built or
* written (cert_offset/cert_devblocks stay 0) and
* issuer_vm->zuse_cert_installed is never checked --
* used exactly once, to mint Zuse's own root identity,
* which by definition has no existing Zuse to sign it.
* @param full_name Required, NUL-terminated, fits user_identity_seed_t's
* full_name field (§F.20).
* @param username Required, NUL-terminated, fits its username field.
* @param email NULL or empty string = null (field stays empty).
* @param phone NULL or empty string = null (field stays empty).
* @param out_pubkey Optional (may be NULL): filled with the newly
* generated identity's own Ed25519 public key on
* success. Genesis mode's only caller needs this, to
* write it into the system-resident zuse_genesis_
* marker_t.
* @param out_seed Optional (may be NULL): filled with the newly
* generated identity's own Ed25519 seed on success.
* Genesis mode's only caller needs this too, to
* install the cert into Hera's own VM immediately
* (vm_zuse_cert_install()) -- the seed otherwise only
* ever lives on the minted thumbdrive.
* @return MINT_OK on success, an error code otherwise.
*/
MintResult capsule_mint_identity(struct blkio_dev *dev, VM *issuer_vm,
const char *full_name, const char *username,
const char *email, const char *phone);
const char *email, const char *phone,
uint8_t out_pubkey[32], uint8_t out_seed[32]);
#endif /* __STARKERNEL__ */
+63
View File
@@ -0,0 +1,63 @@
/*
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 20232025 Robert A. James
All rights reserved.
Licensed under the StarForth License, Version 1.0
*/
/**
* capsule_zuse_boot.h - Thumbdrive-resident Zuse genesis/attach
* (FABRIC-3.md §F.20/§F.21). Replaces kernel_main.c's old one-shot
* block-fence mint-or-load: Zuse's own identity now lives only on her
* own minted thumbdrive, never system-resident. Since USB attach
* detection only happens inside the idle loop (sk_repl_idle(), not at
* a fixed point in the boot sequence), this runs per-attach from there
* instead of once at boot.
*/
#ifndef STARKERNEL_CAPSULE_ZUSE_BOOT_H
#define STARKERNEL_CAPSULE_ZUSE_BOOT_H
#ifdef __STARKERNEL__
#include "starkernel/homeblocks_sig.h"
#include "vm.h"
struct blkio_dev;
/**
* capsule_zuse_boot_try_attach - Try to genesis-mint or authenticate
* Zuse from a just-attached drive.
*
* No-op if mama_vm->zuse_cert_installed is already 1 (Zuse already has a
* real identity this boot, from an earlier attach). Otherwise:
* - No genesis marker yet in the fence, drive reads HOMEBLOCKS_SIG_BLANK:
* mint Zuse's own identity onto it (capsule_mint_identity(), genesis
* mode), record the pubkey in the fence, install the cert, and
* re-run ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly
* like it always has for a same-boot-installed cert.
* - Genesis marker present, drive reads HOMEBLOCKS_SIG_OK: read its
* own user_identity_seed_t, compare pubkey against the marker: if it
* matches, install the cert and re-run ACL-ZUSE-BOOT the same way.
* If it doesn't match, this is some other identity's drive -- no-op
* here, that's a regular attach for BINDSTEP to handle later.
* - Anything else (foreign/corrupt media, no marker and non-blank
* drive): no-op.
*
* @param dev The just-attached, already-open block device.
* @param sig_rc homeblocks_sig_check()'s own result for this attach.
* @param sig The checked homeblocks_sig_t (only meaningful if
* sig_rc == HOMEBLOCKS_SIG_OK; may be NULL otherwise).
* @param mama_vm Hera's own VM (zuse_cert_seed/installed/session live
* here; also the target of the ACL-ZUSE-BOOT re-run).
*/
void capsule_zuse_boot_try_attach(struct blkio_dev *dev,
homeblocks_sig_result_t sig_rc,
const homeblocks_sig_t *sig,
VM *mama_vm);
#endif /* __STARKERNEL__ */
#endif /* STARKERNEL_CAPSULE_ZUSE_BOOT_H */
+14 -1
View File
@@ -1,5 +1,18 @@
/*
* zuse_cert_devblock.h -- on-disk record format for Zuse's cert, stored
* zuse_cert_devblock.h -- SUPERSEDED 2026-08-28 (FABRIC-3.md §F.20/§F.21).
* Zuse is now thumbdrive-resident, not system-resident: her seed lives
* only on her own minted thumbdrive, never written to the fence. The
* fence's devblock_from_top=0 slot this type used to occupy now holds
* zuse_genesis_marker_t (zuse_genesis_marker.h) instead -- pubkey only,
* no seed. This type is no longer written by any code path; kept in the
* repo as historical record of the format it replaced, per this
* project's own convention for superseded design (see e.g. the
* TRIPOD.md/HERMES.md/ARTEMIS.md/CONSOLE.md superseded-header pattern).
* Do not resurrect writes to this format.
*
* Original doc, kept for context:
*
* on-disk record format for Zuse's cert, stored
* in devblock_from_top=0 of the top-of-device system-metadata fence
* (block_subsystem.h's blk_meta_zone_read()/write(), Phase 8, FABRIC-3.md
* §C). Raw, unpacked 4 KiB devblock -- same convention as the volume
+46
View File
@@ -0,0 +1,46 @@
/*
* zuse_genesis_marker.h -- on-disk record format for the system-resident
* "a root Zuse identity already exists" marker (FABRIC-3.md §F.21),
* stored in devblock_from_top=0 of the top-of-device system-metadata
* fence (block_subsystem.h's blk_meta_zone_read()/write(), same location
* zuse_cert_devblock_t used to occupy).
*
* Supersedes zuse_cert_devblock_t (zuse_cert_devblock.h, kept in the repo
* as historical record, no longer written): that type stored Zuse's own
* *seed* system-resident. Under the thumbdrive-resident Zuse design
* (§F.20/§F.21), the seed lives only on Zuse's own minted thumbdrive --
* this record deliberately holds only her *public* key, enough to (a)
* know genesis has already happened, so a second blank thumbdrive
* attached on some later boot never mints a second competing root, and
* (b) recognize which attached identity is genuinely hers. Losing this
* fence record is not a security problem (it's not a secret); losing the
* thumbdrive itself is what actually loses the identity.
*/
#ifndef STARKERNEL_ZUSE_GENESIS_MARKER_H
#define STARKERNEL_ZUSE_GENESIS_MARKER_H
#include <stdint.h>
#define ZUSE_GENESIS_MARKER_MAGIC \
((uint32_t)'Z' | ((uint32_t)'G' << 8) | ((uint32_t)'E' << 16) | ((uint32_t)'N' << 24))
#define ZUSE_GENESIS_MARKER_VERSION 1u
typedef struct {
uint32_t magic; /* ZUSE_GENESIS_MARKER_MAGIC; anything else means
* "genesis has not happened yet" (blank/foreign
* bytes), not a format-corruption error. */
uint32_t version; /* ZUSE_GENESIS_MARKER_VERSION */
uint8_t zuse_pubkey[32]; /* Ed25519 public key of the root Zuse
* identity minted at genesis. No seed here --
* that lives only on Zuse's own thumbdrive. */
uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64())
* over every byte of this struct up to (not
* including) this field. */
uint8_t _pad[4096 - (4 + 4 + 32 + 8)];
} zuse_genesis_marker_t;
_Static_assert(sizeof(zuse_genesis_marker_t) == 4096,
"zuse_genesis_marker_t must be exactly one 4 KiB devblock");
#endif /* STARKERNEL_ZUSE_GENESIS_MARKER_H */