Source tree reorganization: - Move StarForth v3 engine to v3/ (src/, include/, Makefile) - Move kernel to kernel/ (src/, include/, linker/, Makefile) - Create v4/ skeleton for F18-ISA golden model (DECOMPOSITION.md, JUSTIFICATION.md) - Move FABRIC-0..4.md to docs/fabric/ - Move ONTOLOGY.md and ROADMAP.md to docs/ Board infrastructure: - Add boards/ser5/, boards/raspi/, boards/milkv/, boards/zynq7020/ - Each board has board.mk (ISA, CPU flags, boot recipe) and README.md - Root Makefile becomes thin dispatcher: boot_image, all, clean, docs take TARGET - make boot_image TARGET=SER5|RASPI|MILKV builds one GPT/MBR image per board - ZYNQ7020 target exists but stops with clear error (ARMv7 port not built yet) - scripts/mkdiskimage.sh builds disk images for all boards Docs pipeline: - docs/book/ with LaTeX master (main.tex) and Makefile - pandoc converts Markdown to LaTeX at build time - Two Lua filters: table-widths.lua (wide tables wrap), code-breaks.lua (inline code breaks) - make docs builds single PDF (754 pages, 0 missing characters) - make docs TARGET=<board> adds board appendix - build/docs/<book|board>/meta.tex stamps git commit into PDF Bug fixes: - 42 include paths that only worked by accident now use correct relative paths - clang-18 hardcode replaced with configurable CC variable (fixed aarch64 build) - Pi 5: kernel_2712.img linked at 0x80000, .bss zeroed, memory reserved - Doxyfile, .clang-tidy, README.md, Kconfig paths updated Verified: - Hosted v3 build passes 1012 tests, 0 failures - SER5 image boots in QEMU (OVMF), POST passes, K exact (65536 = Q48_ONE) - Milk-V image boots in QEMU (OpenSBI + U-Boot + bootefi), POST passes - make clean TARGET=<board> removes only that board and its ISA objects - make all builds all boards, hosted v3, and docs in one run Co-authored-by: Junie <junie@jetbrains.com>
72 lines
3.7 KiB
C
72 lines
3.7 KiB
C
/*
|
|
* user_identity_seed.h -- on-disk record format for a minted user
|
|
* identity's own keypair and profile (FABRIC-2.md §F.8/§F.20), stored in
|
|
* the first devblock of a home-blocks drive's identity_src region
|
|
* (homeblocks_sig_t.identity_src_offset). The devblocks that follow it
|
|
* (identity_src_offset+1 .. identity_src_offset+identity_src_devblocks-1)
|
|
* hold this identity's own raw FORTH personality/init source, read by
|
|
* RUNCAP (capsule_runcap.h) at birth.
|
|
*
|
|
* Same raw-devblock, magic+version+fields+pad-to-4096, real-CRC-from-
|
|
* day-one convention as zuse_cert_devblock_t (zuse_cert_devblock.h) and
|
|
* homeblocks_sig_t -- a new, dedicated type rather than reusing
|
|
* zuse_cert_devblock_t, per this project's "give real-shaped data its
|
|
* own header" convention (Zuse's own record has no analogous public
|
|
* cert field; a regular user's does, stored separately in the cert
|
|
* region MINT also writes -- see homeblocks_sig_t.cert_offset).
|
|
*
|
|
* full_name/username/email/phone (added §F.20, 2026-08-28): deliberately
|
|
* NOT encoded into the DER cert's Subject field -- that would mean
|
|
* building a real X.509 RDNSequence (AttributeTypeAndValue, OIDs for
|
|
* commonName/emailAddress, PrintableString/UTF8String tagging), well
|
|
* past this project's own stated "deliberately NOT a general ASN.1/X.509
|
|
* parser [or builder]" scope (x509_ed25519.h). This human-readable
|
|
* profile data isn't security-relevant the way pubkey/serial are (those
|
|
* two alone are what CERTVERIFY/BINDSTEP actually check) -- it travels
|
|
* alongside the keypair in this plain record instead. email/phone are
|
|
* nullable (empty string, first byte 0x00); full_name/username are not.
|
|
*/
|
|
#ifndef STARKERNEL_USER_IDENTITY_SEED_H
|
|
#define STARKERNEL_USER_IDENTITY_SEED_H
|
|
|
|
#include <stdint.h>
|
|
|
|
#define USER_IDENTITY_SEED_MAGIC \
|
|
((uint32_t)'U' | ((uint32_t)'I' << 8) | ((uint32_t)'D' << 16) | ((uint32_t)'S' << 24))
|
|
|
|
#define USER_IDENTITY_SEED_VERSION 2u
|
|
|
|
#define USER_IDENTITY_FULL_NAME_MAX 64u
|
|
#define USER_IDENTITY_USERNAME_MAX 32u
|
|
#define USER_IDENTITY_EMAIL_MAX 64u
|
|
#define USER_IDENTITY_PHONE_MAX 24u
|
|
|
|
typedef struct {
|
|
uint32_t magic; /* USER_IDENTITY_SEED_MAGIC; anything else means
|
|
* "not yet minted" (blank/foreign bytes), not a
|
|
* format-corruption error. */
|
|
uint32_t version; /* USER_IDENTITY_SEED_VERSION */
|
|
uint8_t seed[32]; /* Ed25519 seed -- this identity's own private key.
|
|
* Regular users are thumbdrive-resident (unlike
|
|
* Zuse's system-resident one) -- this is the
|
|
* only copy. */
|
|
uint8_t pubkey[32]; /* Ed25519 public key derived from seed at mint
|
|
* time -- same value the cert region's
|
|
* SubjectPublicKeyInfo holds. */
|
|
char full_name[USER_IDENTITY_FULL_NAME_MAX]; /* NUL-terminated, required. */
|
|
char username[USER_IDENTITY_USERNAME_MAX]; /* NUL-terminated, required. */
|
|
char email[USER_IDENTITY_EMAIL_MAX]; /* NUL-terminated; empty = null. */
|
|
char phone[USER_IDENTITY_PHONE_MAX]; /* NUL-terminated; empty = null. */
|
|
uint64_t crc; /* CRC-64/ISO (block_subsystem.h's compute_crc64())
|
|
* over every byte of this struct up to (not
|
|
* including) this field. */
|
|
uint8_t _pad[4096 - (4 + 4 + 32 + 32 +
|
|
USER_IDENTITY_FULL_NAME_MAX + USER_IDENTITY_USERNAME_MAX +
|
|
USER_IDENTITY_EMAIL_MAX + USER_IDENTITY_PHONE_MAX + 8)];
|
|
} user_identity_seed_t;
|
|
|
|
typedef char user_identity_seed_size_check[
|
|
(sizeof(user_identity_seed_t) == 4096) ? 1 : -1];
|
|
|
|
#endif /* STARKERNEL_USER_IDENTITY_SEED_H */
|