capsule_runcap_birth() (new capsule_runcap.h/.c): builds a heap-only, single-entry CapsuleDirHeader + CapsuleDesc + CapsuleNameEntry + arena from a home-blocks drive's identity_src region (skipping the first devblock, reserved for MINT's user_identity_seed_t record) and hands it to the existing, unmodified capsule_birth_baby() -- no new birth mechanism, matching FABRIC-3.md §F.6's own trace. Found and closed a real gap in that trace along the way: capsule_birth_baby()'s signature check calls capsule_get_signatures(), which unconditionally returns the compile-time-baked global array -- meaningless for a heap-built directory, where index 0 would compare RUNCAP's own content against whatever real capsule happens to occupy that slot in the baked array (guaranteed-wrong, not a security check). Added an explicit skip_pki_sig flag (0 for all 4 existing call sites, 1 for RUNCAP): that content's trust comes from CERTVERIFY, a separate root, not the capsule-PKI chain. Also found live: capsule_birth_baby() never sets the registry entry's own .name (every existing caller does this itself afterward via capsule_vm_registry_set_name() -- RUNCAP now does too), and capsule_exec_payload() requires a "Block NNNN" header per chunk of content or it's silently skipped, never executed -- not a bug, but necessary context for whoever authors MINT's default personality content next. Added a small accessor pair (repl.h/.c) exposing the currently attached home-blocks device/sig -- the same gap F.9's own BINDSTEP scoping had already flagged, needed by both. Verified end-to-end live in QEMU: synthetic identity-source content written directly to a thumbdrive image's raw devblocks (no capsule build, no mkcapsule) was read, compiled, and executed by a genuinely new VM via a diagnostic RUNCAP-TEST word -- confirmed via VM-EXEC invoking a word defined only in that source. Clean 3-architecture regression boot (no RUNCAP drive attached) confirms no side effects. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
89 lines
2.3 KiB
C
89 lines
2.3 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
Licensed under the StarForth License, Version 1.0
|
||
*/
|
||
|
||
/**
|
||
* repl.h - Emergency FORTH REPL for LithosAnanke kernel
|
||
*/
|
||
|
||
#ifndef STARKERNEL_REPL_H
|
||
#define STARKERNEL_REPL_H
|
||
|
||
#include "vm.h"
|
||
#include "starkernel/homeblocks_sig.h"
|
||
|
||
struct blkio_dev;
|
||
|
||
#ifdef __cplusplus
|
||
extern "C" {
|
||
#endif
|
||
|
||
/**
|
||
* sk_repl - Run the emergency FORTH REPL on the serial console.
|
||
*
|
||
* Blocks until vm->halted is set (BYE word) or the VM encounters a halt.
|
||
* Runs with interrupts enabled; the APIC heartbeat continues to fire.
|
||
*
|
||
* @param vm Mama VM instance (must be fully initialised)
|
||
*/
|
||
void sk_repl(VM *vm);
|
||
|
||
/**
|
||
* sk_repl_run - Bare REPL loop (no banner).
|
||
*
|
||
* Same as sk_repl but skips the version/welcome banner. Used by START
|
||
* to enter a child VM's interpreter loop without reprinting the header.
|
||
*
|
||
* @param vm Fully initialised VM instance
|
||
*/
|
||
void sk_repl_run(VM *vm);
|
||
|
||
/**
|
||
* sk_repl_step - Execute one REPL turn on a VM and return.
|
||
*
|
||
* Prints the VM's prompt, reads one line, interprets it, prints ok/ERROR,
|
||
* then returns. Used by the Compudynamics VM-STEP primitive so Hera can
|
||
* give a single REPL quantum to a child VM without surrendering control
|
||
* for the full sk_repl_run() loop.
|
||
*
|
||
* @param vm Fully initialised VM instance
|
||
* @return 1 if the VM is still running, 0 if it halted during this turn
|
||
*/
|
||
int sk_repl_step(VM *vm);
|
||
|
||
/**
|
||
* sk_repl_set_active_vm - Redirect REPL input to a different VM (USE word).
|
||
*
|
||
* Pass NULL to restore default dispatch (Mama's VM).
|
||
* The change takes effect on the next REPL iteration.
|
||
*
|
||
* @param vm Target VM, or NULL for default
|
||
*/
|
||
void sk_repl_set_active_vm(VM *vm);
|
||
|
||
/**
|
||
* sk_repl_get_active_vm - Return the current USE-redirected VM, or NULL.
|
||
*/
|
||
VM *sk_repl_get_active_vm(void);
|
||
|
||
/**
|
||
* sk_repl_get_homeblocks_dev / sk_repl_get_homeblocks_sig - The currently
|
||
* attached home-blocks USB drive, or NULL if none is attached / the
|
||
* attached drive didn't check out as HOMEBLOCKS_SIG_OK (FABRIC-3.md
|
||
* §F.6/§F.9/§F.18). Both return NULL together; never one without the
|
||
* other.
|
||
*/
|
||
struct blkio_dev *sk_repl_get_homeblocks_dev(void);
|
||
const homeblocks_sig_t *sk_repl_get_homeblocks_sig(void);
|
||
|
||
#ifdef __cplusplus
|
||
}
|
||
#endif
|
||
|
||
#endif /* STARKERNEL_REPL_H */
|