Source tree reorganization: - Move StarForth v3 engine to v3/ (src/, include/, Makefile) - Move kernel to kernel/ (src/, include/, linker/, Makefile) - Create v4/ skeleton for F18-ISA golden model (DECOMPOSITION.md, JUSTIFICATION.md) - Move FABRIC-0..4.md to docs/fabric/ - Move ONTOLOGY.md and ROADMAP.md to docs/ Board infrastructure: - Add boards/ser5/, boards/raspi/, boards/milkv/, boards/zynq7020/ - Each board has board.mk (ISA, CPU flags, boot recipe) and README.md - Root Makefile becomes thin dispatcher: boot_image, all, clean, docs take TARGET - make boot_image TARGET=SER5|RASPI|MILKV builds one GPT/MBR image per board - ZYNQ7020 target exists but stops with clear error (ARMv7 port not built yet) - scripts/mkdiskimage.sh builds disk images for all boards Docs pipeline: - docs/book/ with LaTeX master (main.tex) and Makefile - pandoc converts Markdown to LaTeX at build time - Two Lua filters: table-widths.lua (wide tables wrap), code-breaks.lua (inline code breaks) - make docs builds single PDF (754 pages, 0 missing characters) - make docs TARGET=<board> adds board appendix - build/docs/<book|board>/meta.tex stamps git commit into PDF Bug fixes: - 42 include paths that only worked by accident now use correct relative paths - clang-18 hardcode replaced with configurable CC variable (fixed aarch64 build) - Pi 5: kernel_2712.img linked at 0x80000, .bss zeroed, memory reserved - Doxyfile, .clang-tidy, README.md, Kconfig paths updated Verified: - Hosted v3 build passes 1012 tests, 0 failures - SER5 image boots in QEMU (OVMF), POST passes, K exact (65536 = Q48_ONE) - Milk-V image boots in QEMU (OpenSBI + U-Boot + bootefi), POST passes - make clean TARGET=<board> removes only that board and its ISA objects - make all builds all boards, hosted v3, and docs in one run Co-authored-by: Junie <junie@jetbrains.com>
48 lines
2.3 KiB
C
48 lines
2.3 KiB
C
/* ed25519.h -- EdDSA (RFC 8032), freestanding C99.
|
|
*
|
|
* Originally verify-only ("this kernel never signs; signing happens in
|
|
* the host-side build tool") -- that was correct for capsule signing
|
|
* (build-time, offline, a normal Linux binary can link libsodium/
|
|
* OpenSSL) but conflicts with an on-device Zuse session minting new
|
|
* user certs live at runtime, which requires the kernel itself to sign.
|
|
* Decided (Phase 8, 2026-08-26): add real keygen/signing rather than
|
|
* reshape that flow around verify-only. Entropy for keygen comes from
|
|
* virtio_rng.h -- this header still has no RNG of its own, and takes a
|
|
* caller-supplied seed rather than generating one, deliberately: keygen
|
|
* has no business deciding how the seed's randomness quality is
|
|
* guaranteed, that's the caller's job.
|
|
*
|
|
* Signing is NOT constant-time (same non-constant-time double-and-add
|
|
* scalar_mult() verify already used) -- acceptable for this project's
|
|
* actual threat model (an emulated/embedded kernel with no untrusted
|
|
* co-tenant able to observe timing), not acceptable if this code is
|
|
* ever reused somewhere with a real timing-attack surface.
|
|
*/
|
|
#ifndef ED25519_H
|
|
#define ED25519_H
|
|
|
|
#include <stdint.h>
|
|
#include <stddef.h>
|
|
|
|
/* Returns 1 if signature (64 bytes: R || S) is a valid Ed25519 signature
|
|
* by pubkey (32 bytes, compressed point) over msg, else 0. Rejects
|
|
* malformed inputs (S >= L, an undecodable point) as invalid rather than
|
|
* faulting. */
|
|
int ed25519_verify(const uint8_t pubkey[32], const uint8_t *msg, size_t msg_len,
|
|
const uint8_t sig[64]);
|
|
|
|
/* Derive the public key (compressed point A = [a]B) from a 32-byte
|
|
* seed. seed must be real, uniformly random entropy -- see this file's
|
|
* header comment; ed25519_keygen() does not check or generate it. */
|
|
void ed25519_keygen(const uint8_t seed[32], uint8_t pubkey_out[32]);
|
|
|
|
/* Sign msg with the keypair derived from seed (the same seed passed to
|
|
* ed25519_keygen() to obtain the matching public key). Deterministic
|
|
* per RFC 8032 (the nonce is derived from seed + message, not fresh
|
|
* randomness at sign time) -- only keygen needs real entropy, signing
|
|
* needs none. */
|
|
void ed25519_sign(const uint8_t seed[32], const uint8_t *msg, size_t msg_len,
|
|
uint8_t sig_out[64]);
|
|
|
|
#endif /* ED25519_H */
|