Three tightly-coupled changes, verified together per Captain Bob's own "getting rid of the emergency cli" direction: 1. Zuse's identity is thumbdrive-resident, never system-resident. New zuse_genesis_marker_t (magic/version/zuse_pubkey[32]/crc) replaces zuse_cert_devblock_t's slot in the top-of-device fence -- the system now remembers only that a root identity exists and its pubkey, never a seed. zuse_cert_devblock_t is kept in the repo, marked superseded, no longer written by any code path. capsule_mint_identity() grows a genesis mode (issuer_vm=NULL): no cert is built or written (Zuse isn't verified against a separate signer -- she's recognized by pubkey match against the marker) and two new optional out-params (out_pubkey/out_seed) let the caller install the cert immediately after a genesis mint. New capsule_zuse_boot_try_attach() (capsule_zuse_boot.c), called from sk_repl_idle() on every fresh USB attach (the only point in the boot lifecycle a thumbdrive can actually be detected -- attach polling doesn't exist yet at kernel_main.c's old one-shot mint point, which is why that whole block is gone): no marker + blank drive -> genesis-mint; marker present + matching drive -> read its own user_identity_seed_t, install the cert. Either way, re-runs ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly like it always has for a same-boot cert install -- ACL-PIN only blocks redefinition, not re-execution, so no new C-side auth logic needed. 2. ACL.4th activated (capsules/init.4th) -- inactive all session until now. Found and fixed a real bug this immediately surfaced: zuse.4th's ACL-ZUSE-BOOT tried `['] ACL-ZUSE-BOOT ACL-PIN` from inside its own still-compiling definition -- the word isn't findable yet at that point, so the whole definition silently failed to compile every previous boot this session (dormant, since ACL.4th never loaded). Fixed: pin after the definition closes, not from within it -- it only needs to happen once anyway, and pinning doesn't block the re-invocation genesis/attach needs. 3. The unauthenticated emergency-CLI ACL bypass is retired (repl.c): `emergency_console = is_hera ? (zuse_session ? 0 : 1) : 0` deleted from both sk_repl_step and sk_repl_run. Every word run from Hera's own bare prompt now goes through ordinary ACL enforcement; emergency_console is driven only by the genuine C-level fault handler again. Added ZUSE-SESSION? (starforth_words.c), a read-only diagnostic matching ZUSE-PUBKEY@'s own precedent, to verify the whole chain directly rather than by inference. Verified end-to-end live in QEMU: fresh boot, no thumbdrive -> ZUSE-SESSION? reads 0. Attach a genuinely blank drive via QMP -> genesis mint fires automatically (no typing) -> ZUSE-SESSION? reads -1 (true). Hermes/Artemis both birth clean on all three architectures with ACL now actually enforced for the first time all session -- no denials, no UNKNOWN WORD beyond the deliberate POST self-test cases. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
64 lines
2.5 KiB
C
64 lines
2.5 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
Licensed under the StarForth License, Version 1.0
|
||
*/
|
||
|
||
/**
|
||
* capsule_zuse_boot.h - Thumbdrive-resident Zuse genesis/attach
|
||
* (FABRIC-3.md §F.20/§F.21). Replaces kernel_main.c's old one-shot
|
||
* block-fence mint-or-load: Zuse's own identity now lives only on her
|
||
* own minted thumbdrive, never system-resident. Since USB attach
|
||
* detection only happens inside the idle loop (sk_repl_idle(), not at
|
||
* a fixed point in the boot sequence), this runs per-attach from there
|
||
* instead of once at boot.
|
||
*/
|
||
|
||
#ifndef STARKERNEL_CAPSULE_ZUSE_BOOT_H
|
||
#define STARKERNEL_CAPSULE_ZUSE_BOOT_H
|
||
|
||
#ifdef __STARKERNEL__
|
||
|
||
#include "starkernel/homeblocks_sig.h"
|
||
#include "vm.h"
|
||
|
||
struct blkio_dev;
|
||
|
||
/**
|
||
* capsule_zuse_boot_try_attach - Try to genesis-mint or authenticate
|
||
* Zuse from a just-attached drive.
|
||
*
|
||
* No-op if mama_vm->zuse_cert_installed is already 1 (Zuse already has a
|
||
* real identity this boot, from an earlier attach). Otherwise:
|
||
* - No genesis marker yet in the fence, drive reads HOMEBLOCKS_SIG_BLANK:
|
||
* mint Zuse's own identity onto it (capsule_mint_identity(), genesis
|
||
* mode), record the pubkey in the fence, install the cert, and
|
||
* re-run ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly
|
||
* like it always has for a same-boot-installed cert.
|
||
* - Genesis marker present, drive reads HOMEBLOCKS_SIG_OK: read its
|
||
* own user_identity_seed_t, compare pubkey against the marker: if it
|
||
* matches, install the cert and re-run ACL-ZUSE-BOOT the same way.
|
||
* If it doesn't match, this is some other identity's drive -- no-op
|
||
* here, that's a regular attach for BINDSTEP to handle later.
|
||
* - Anything else (foreign/corrupt media, no marker and non-blank
|
||
* drive): no-op.
|
||
*
|
||
* @param dev The just-attached, already-open block device.
|
||
* @param sig_rc homeblocks_sig_check()'s own result for this attach.
|
||
* @param sig The checked homeblocks_sig_t (only meaningful if
|
||
* sig_rc == HOMEBLOCKS_SIG_OK; may be NULL otherwise).
|
||
* @param mama_vm Hera's own VM (zuse_cert_seed/installed/session live
|
||
* here; also the target of the ACL-ZUSE-BOOT re-run).
|
||
*/
|
||
void capsule_zuse_boot_try_attach(struct blkio_dev *dev,
|
||
homeblocks_sig_result_t sig_rc,
|
||
const homeblocks_sig_t *sig,
|
||
VM *mama_vm);
|
||
|
||
#endif /* __STARKERNEL__ */
|
||
|
||
#endif /* STARKERNEL_CAPSULE_ZUSE_BOOT_H */
|