ZUSE-ELIGIBILITY-ADD's own doc comment admitted "no authorization check here or anywhere else... applied later if and when actually needed -- not invented here." That's now: anyone reaching a Hera FORTH prompt could add their own pubkey to the eligibility list with zero legitimate identity material -- no minted drive, no WIREBIND, no cert-signature check involved at all. Once a future caller reaches ELEVATE-GRANT again, a self-added pubkey would pass zuse_eligibility_is_member() and grant ACL-ALLOW!/ACL-TTL! on any named word. Fixed the FORTH-only way, matching this project's own convention (ACL policy belongs in ACL.4th, never in C; never gate on zuse_session in C -- her power is the absence of ACLs, not a hardcoded session check): ZUSE-ELIGIBILITY-ADD is now denied by default (capsules/zuse.4th block 4016), granted and pinned only inside ACL-ZUSE-BOOT's already-existing authenticated branch (block 4017) -- the same gate her own god-mode already goes through, requiring a real cert-verified Zuse before it opens. Live-verified on all three architectures, not just boot-clean: after genesis authentication, ACL-ALLOW@ and ACL-PINNED? both read -1, and HERE ZUSE-ELIGIBILITY-ADD executes successfully past the ACL gate. Phase 8 v1 plan: /home/rajames/.claude/plans/jiggly-cuddling-stallman.md Part A (the ELEVATE-GRANT pointer-confusion fix, FABRIC-3.7.md) is separate, not yet built. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
43 lines
1.8 KiB
Forth
43 lines
1.8 KiB
Forth
Block 4016
|
|
( zuse.4th - Bootstrap superuser for StarForth ACL )
|
|
( Named for Konrad Zuse, pioneer of programmable computers. )
|
|
( Sole superuser; mints credentials; owns emergency REPL. )
|
|
( Loaded by ACL.4th; must not load before ACL.4th. )
|
|
( Thumbdrive-resident Ed25519 PKI (2026-08-28) -- her seed )
|
|
( lives only on her own minted drive, never system-resident. )
|
|
( HUMAN-REVIEW: capsule hash = root of superuser trust. )
|
|
( Cert (seed+pubkey) lives in C-only VM fields, installed by )
|
|
( capsule_zuse_boot.c on genesis-mint or thumbdrive attach. )
|
|
( NOT a CONSTANT: ACL-PIN blocks redefinition, not a )
|
|
( >BODY-then-store, so a pinned CONSTANT isn't tamper-proof. )
|
|
( Read with ZUSE-PUBKEY@ / ZUSE-CERT-INSTALLED? -- both C )
|
|
( primitives, read-only; the seed has no FORTH access at all. )
|
|
( ZUSE-ELIGIBILITY-ADD denied by default -- see block 4017. )
|
|
0 ['] ZUSE-ELIGIBILITY-ADD ACL-ALLOW!
|
|
|
|
Block 4017
|
|
( ACL-ZUSE-BOOT ( -- ) re-invokable: capsule_zuse_boot.c )
|
|
( calls it again once a thumbdrive attach installs a cert. )
|
|
( Only authenticates if a real cert is installed -- refuses )
|
|
( god-mode to a Zuse with no real identity behind her. )
|
|
( ZUSE-AUTHENTICATE is C-only; no FORTH word grants god-mode )
|
|
( except through this sequence. )
|
|
: ACL-ZUSE-BOOT ( -- )
|
|
ZUSE-CERT-INSTALLED? IF
|
|
ZUSE-AUTHENTICATE
|
|
1 ['] ZUSE-ELIGIBILITY-ADD ACL-ALLOW!
|
|
['] ZUSE-ELIGIBILITY-ADD ACL-PIN
|
|
LOG-INFO" zuse: activated"
|
|
ELSE
|
|
LOG-INFO" zuse: NOT activated -- no cert installed"
|
|
THEN ;
|
|
|
|
Block 4018
|
|
( Pin against redefinition -- once, after definition closes; )
|
|
( ['] from inside its own body can't find itself mid-compile, )
|
|
( found live 2026-08-28 activating ACL.4th for the first time. )
|
|
( Pinning doesn't block re-EXECUTION, only redefinition -- the )
|
|
( re-invoke above still works after this runs. Self-activates. )
|
|
['] ACL-ZUSE-BOOT ACL-PIN
|
|
ACL-ZUSE-BOOT
|