FABRIC.md -> FABRIC-0.md FABRIC-2.md -> FABRIC-1.md FABRIC-3.md -> FABRIC-2.md (the current/living document) FABRIC-4.md unchanged (new #3 to follow separately) Every cross-reference repo-wide updated to match, including doc-comment citations inside kernel source (.c/.h) files -- done via an ordered placeholder substitution (FABRIC-3.md->placeholder2, FABRIC-2.md-> placeholder1, FABRIC.md->placeholder0, then placeholders resolved to final names) in a single pass per file to avoid double-shifting already-renamed references. One line in capsules/font.4th grew past the 64-char block-format limit as a side effect of the longer filename; shortened it and reverified with mkcapsule --lint (34/34 pass) before rebuilding. Verified 3-arch boot to ok> (amd64/aarch64/riscv64, each in the foreground) after the fix; logs and DoE CSVs from this session's verification runs included per this repo's own audit-artifact convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YcT3H2PQeyujrzjqS3Var
86 lines
3.6 KiB
C
86 lines
3.6 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
Licensed under the StarForth License, Version 1.0
|
||
*/
|
||
|
||
/**
|
||
* capsule_zuse_boot.h - Thumbdrive-resident Zuse genesis/attach
|
||
* (FABRIC-2.md §F.20/§F.21). Replaces kernel_main.c's old one-shot
|
||
* block-fence mint-or-load: Zuse's own identity now lives only on her
|
||
* own minted thumbdrive, never system-resident. Since USB attach
|
||
* detection only happens inside the idle loop (sk_repl_idle(), not at
|
||
* a fixed point in the boot sequence), this runs per-attach from there
|
||
* instead of once at boot.
|
||
*/
|
||
|
||
#ifndef STARKERNEL_CAPSULE_ZUSE_BOOT_H
|
||
#define STARKERNEL_CAPSULE_ZUSE_BOOT_H
|
||
|
||
#ifdef __STARKERNEL__
|
||
|
||
#include "starkernel/homeblocks_sig.h"
|
||
#include "vm.h"
|
||
|
||
struct blkio_dev;
|
||
|
||
/**
|
||
* capsule_zuse_boot_try_attach - Try to genesis-mint or authenticate
|
||
* Zuse from a just-attached drive.
|
||
*
|
||
* No-op if mama_vm->zuse_cert_installed is already 1 (Zuse already has a
|
||
* real identity this boot, from an earlier attach). Otherwise:
|
||
* - No genesis marker yet in the fence, drive reads HOMEBLOCKS_SIG_BLANK:
|
||
* mint Zuse's own identity onto it (capsule_mint_identity(), genesis
|
||
* mode), record the pubkey in the fence, install the cert, and
|
||
* re-run ACL-ZUSE-BOOT (zuse.4th) so zuse_session activates exactly
|
||
* like it always has for a same-boot-installed cert.
|
||
* - Genesis marker present, drive reads HOMEBLOCKS_SIG_OK: read its
|
||
* own user_identity_seed_t, compare pubkey against the marker: if it
|
||
* matches, install the cert and re-run ACL-ZUSE-BOOT the same way.
|
||
* If it doesn't match, this is some other identity's drive -- no-op
|
||
* here, that's a regular attach for BINDSTEP to handle later.
|
||
* - Anything else (foreign/corrupt media, no marker and non-blank
|
||
* drive): no-op.
|
||
*
|
||
* @param dev The just-attached, already-open block device.
|
||
* @param sig_rc homeblocks_sig_check()'s own result for this attach.
|
||
* @param sig The checked homeblocks_sig_t (only meaningful if
|
||
* sig_rc == HOMEBLOCKS_SIG_OK; may be NULL otherwise).
|
||
* @param mama_vm Hera's own VM (zuse_cert_seed/installed/session live
|
||
* here; also the target of the ACL-ZUSE-BOOT re-run).
|
||
*/
|
||
void capsule_zuse_boot_try_attach(struct blkio_dev *dev,
|
||
homeblocks_sig_result_t sig_rc,
|
||
const homeblocks_sig_t *sig,
|
||
VM *mama_vm);
|
||
|
||
/**
|
||
* capsule_zuse_boot_logout - End Zuse's session when her own attached
|
||
* drive detaches (FABRIC-2.md §I.8, re-scoped 2026-09-04: no identity is
|
||
* different here -- Zuse logs out on device removal exactly like a
|
||
* WIREBIND user does, not via a Stadium-patron TTL. She has no separate
|
||
* VM or blocks of her own, so unlike capsule_wirebind_eject()/
|
||
* _unclean_detach() there is no flush step to skip on the abrupt path --
|
||
* one function covers both the graceful (EJECT) and abrupt (hot-unplug)
|
||
* call sites identically.
|
||
*
|
||
* No-op if the currently-tracked attached device isn't Zuse's own
|
||
* (nothing to do -- some other identity's drive is what's leaving, or
|
||
* nothing is attached at all). Clears mama_vm->zuse_session only --
|
||
* zuse_cert_installed and the cert itself stay put, permanently, per
|
||
* vm_zuse_cert_install()'s own one-way design; re-attaching her own
|
||
* drive re-authenticates via capsule_zuse_boot_try_attach() without
|
||
* re-minting anything.
|
||
*
|
||
* @param mama_vm Hera's own VM (zuse_session lives here).
|
||
*/
|
||
void capsule_zuse_boot_logout(VM *mama_vm);
|
||
|
||
#endif /* __STARKERNEL__ */
|
||
|
||
#endif /* STARKERNEL_CAPSULE_ZUSE_BOOT_H */
|