Source tree reorganization: - Move StarForth v3 engine to v3/ (src/, include/, Makefile) - Move kernel to kernel/ (src/, include/, linker/, Makefile) - Create v4/ skeleton for F18-ISA golden model (DECOMPOSITION.md, JUSTIFICATION.md) - Move FABRIC-0..4.md to docs/fabric/ - Move ONTOLOGY.md and ROADMAP.md to docs/ Board infrastructure: - Add boards/ser5/, boards/raspi/, boards/milkv/, boards/zynq7020/ - Each board has board.mk (ISA, CPU flags, boot recipe) and README.md - Root Makefile becomes thin dispatcher: boot_image, all, clean, docs take TARGET - make boot_image TARGET=SER5|RASPI|MILKV builds one GPT/MBR image per board - ZYNQ7020 target exists but stops with clear error (ARMv7 port not built yet) - scripts/mkdiskimage.sh builds disk images for all boards Docs pipeline: - docs/book/ with LaTeX master (main.tex) and Makefile - pandoc converts Markdown to LaTeX at build time - Two Lua filters: table-widths.lua (wide tables wrap), code-breaks.lua (inline code breaks) - make docs builds single PDF (754 pages, 0 missing characters) - make docs TARGET=<board> adds board appendix - build/docs/<book|board>/meta.tex stamps git commit into PDF Bug fixes: - 42 include paths that only worked by accident now use correct relative paths - clang-18 hardcode replaced with configurable CC variable (fixed aarch64 build) - Pi 5: kernel_2712.img linked at 0x80000, .bss zeroed, memory reserved - Doxyfile, .clang-tidy, README.md, Kconfig paths updated Verified: - Hosted v3 build passes 1012 tests, 0 failures - SER5 image boots in QEMU (OVMF), POST passes, K exact (65536 = Q48_ONE) - Milk-V image boots in QEMU (OpenSBI + U-Boot + bootefi), POST passes - make clean TARGET=<board> removes only that board and its ISA objects - make all builds all boards, hosted v3, and docs in one run Co-authored-by: Junie <junie@jetbrains.com>
66 lines
2.7 KiB
C
66 lines
2.7 KiB
C
/*
|
|
* rng.h — Unified entropy entry point for StarKernel
|
|
*
|
|
* The single place any kernel consumer (keygen, identity mint, drive_uuid,
|
|
* certificate serials, ...) asks for entropy. All entropy flows through
|
|
* rng_get_bytes() and never touches a backend directly.
|
|
*
|
|
* The set of active backends is determined at rng_init() time by probing,
|
|
* in order, until one (or more) come up:
|
|
* - v2.0.0 (QEMU): virtio-rng is the sole backend — there is no virtio-rng
|
|
* on real hardware, but QEMU exposes it uniformly on all three arches
|
|
* (amd64/aarch64/riscv64), and the paravirtualized device sidesteps the
|
|
* per-ISA gap where no single CPU RNG covers all three models (amd64 has
|
|
* RDRAND, riscv64 has Zkr, but QEMU's aarch64 CPU models expose neither —
|
|
* see virtio_rng.h / vm_uuid.h for the identical finding).
|
|
* - v2.5.0 (real hardware): real per-arch backends are inserted here without
|
|
* touching the call path — amd64 RDRAND, riscv64 Zkr (RNDR), aarch64
|
|
* peripheral RNG — each handled by a case in rng_init() and rng_get_bytes()
|
|
* (grid §G.4). On QEMU all three arches stay on virtio-rng; nothing changes.
|
|
*
|
|
* Probe-and-refuse-loudly contract (§G.2): if no backend comes up at
|
|
* rng_init(), the kernel prints a loud boot-time message. A later
|
|
* rng_get_bytes() call with no backend returns -1 (RNG_ERR_NO_BACKEND) rather
|
|
* than ever silently degrading to a deterministic throwaway — the exact failure
|
|
* Phases A/G call out as unacceptable. Callers (e.g. capsule_mint_identity)
|
|
* must surface that refusal as an explicit no-entropy error, never proceed with
|
|
* a deterministic seed.
|
|
*
|
|
* Important ordering: rng_init() must run before any rng_get_bytes()/mint call
|
|
* (it already does in kernel_main phase 8, ahead of Zuse boot attach, which is
|
|
* the only mint path in v2.0.0). rng_get_bytes() with rng_init() never
|
|
* successful returns RNG_ERR_NO_BACKEND, never blocks.
|
|
*/
|
|
|
|
#ifndef STARKERNEL_RNG_H
|
|
#define STARKERNEL_RNG_H
|
|
|
|
#include <stddef.h>
|
|
#include <stdint.h>
|
|
|
|
/* Return codes (negative = failure). */
|
|
#define RNG_ERR_NO_BACKEND (-1) /* rng_init() found no working entropy source */
|
|
|
|
/*
|
|
* rng_init — probe and bring up the entropy backends. Returns 0 if at least
|
|
* one backend is active (rng_get_bytes() will succeed), nonzero otherwise.
|
|
* Prints a loud boot-time message when no backend comes up. Call once, early.
|
|
*/
|
|
int rng_init(void);
|
|
|
|
/*
|
|
* rng_ready — 1 if at least one backend is active, 0 otherwise.
|
|
*/
|
|
int rng_ready(void);
|
|
|
|
/*
|
|
* rng_get_bytes — fill buf with n bytes of real entropy, blocking until all
|
|
* n bytes are obtained.
|
|
*
|
|
* Returns 0 on success (buf fully filled).
|
|
* Returns RNG_ERR_NO_BACKEND (-1) if no backend is active.
|
|
*/
|
|
int rng_get_bytes(uint8_t *buf, size_t n);
|
|
|
|
#endif /* STARKERNEL_RNG_H */
|