Code review fixes, all compile clean (hosted gcc + aarch64/riscv64 kernel flags):
- repl.c (H1): reentrancy guards on the MSG-TICK idle pump. sk_repl_idle()
now defers when Hera is mid-interpret (g_mama_interpreting) or when its
own vm_interpret is on the stack (g_idle_pump_active), so a blocking
KEY/EXPECT/QUERY inside a dispatched line can no longer re-enter the
interpreter and clobber the in-flight input buffer.
- virtio_rng.c: clamp device-returned used_len to VRNG_BUF_SIZE before the
caller's data_buf copy, closing a device-controlled OOB read.
- block_subsystem.c: first-write path now keys off created_time==0 instead
of dead magic==0 so fresh blocks get a real created_time stamp; first_free/
last_allocated fixed to absolute Forth LBNs (set in blk_compute_fresh_geometry
from slot->start_lbn, no longer the wrong physical-BAM-index values from
compute_totals_from_B); physical-bounds guard on blk_meta_zone_read/write
prevents unsigned underflow on a corrupt fence >= device size.
- capsule_zuse_boot.c / capsule_wirebind.c: identity seed validated magic ->
version -> CRC-64 (compute_crc64 over offsetof(crc)) before trusting it,
so a corrupt/format-mismatched record is refused, never loaded.
- log.h / starkernel/log.h: unused LOG_LINE_MAX 256 renamed LOG_MSG_LINE_MAX
to lift the include-order collision with vm.h's LOG_LINE_MAX 64; stale
include-order comments dropped (kernel_main.c, shim.c, capsule_birth.c).
- FABRIC-3.md: three stale-doc carry-forward items closed [x] with cbe7b49
notes.
Real KEY/?TERMINAL/QUERY/EXPECT bodies (console WIP):
- repl.h/repl.c: sk_console_getkey()/sk_console_key_available()/
sk_console_readline() public bodies; non-destructive peek buffers the
found byte so a following KEY returns it.
- shim.c: getchar()/fgetc()/fgets()/sf_terminal_ready() routed through the
real console paths instead of stubs; sf_terminal_ready() in platform_io.h
with sf_terminal_ready() implemented for the hosted build (linux/io.c,
POSIX select on fd 0) wired into Makefile.
- io_words.c: ?TERMINAL now returns actual terminal-readiness, not constant 0.
Artifacts: minted disk/artemis.img + rebuilt lfs kernel; BLOCK_MAP.md,
doe csv + qemu log regenerated.
120 lines
5.0 KiB
C
120 lines
5.0 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
Licensed under the StarForth License, Version 1.0
|
||
*/
|
||
|
||
#ifndef __STARKERNEL__
|
||
#error "capsule_zuse_boot.c is kernel-only"
|
||
#endif
|
||
|
||
#include "starkernel/capsule_zuse_boot.h"
|
||
#include "starkernel/capsule_mint.h"
|
||
#include "starkernel/zuse_genesis_marker.h"
|
||
#include "starkernel/user_identity_seed.h"
|
||
#include "starkernel/console.h"
|
||
#include "block_subsystem.h" /* compute_crc64(), blk_meta_zone_read/write */
|
||
#include "blkio.h"
|
||
#include <string.h>
|
||
#include <stddef.h>
|
||
|
||
/* Read exactly one devblock (4096 bytes) at devblock offset `devblock`,
|
||
* as 4 consecutive 1KiB forth-block reads -- mirrors capsule_runcap.c's
|
||
* and homeblocks_sig_check()'s own read convention. */
|
||
static int read_devblock(struct blkio_dev *dev, uint32_t devblock, uint8_t *buf4096) {
|
||
uint32_t base = devblock * 4u;
|
||
for (uint32_t i = 0; i < 4u; i++) {
|
||
if (blkio_read((blkio_dev_t *)dev, base + i,
|
||
buf4096 + (size_t)i * BLKIO_FORTH_BLOCK_SIZE) != BLKIO_OK) {
|
||
return -1;
|
||
}
|
||
}
|
||
return 0;
|
||
}
|
||
|
||
static int genesis_marker_read(zuse_genesis_marker_t *out) {
|
||
if (blk_meta_zone_read(0, (uint8_t *)out) != 0) return -1;
|
||
if (out->magic != ZUSE_GENESIS_MARKER_MAGIC) return -1;
|
||
if (out->version != ZUSE_GENESIS_MARKER_VERSION) return -1;
|
||
uint64_t want_crc = compute_crc64((const uint8_t *)out, offsetof(zuse_genesis_marker_t, crc));
|
||
if (want_crc != out->crc) return -1;
|
||
return 0;
|
||
}
|
||
|
||
static void install_and_activate(VM *mama_vm, const uint8_t seed[32], const uint8_t pubkey[32]) {
|
||
if (vm_zuse_cert_install(mama_vm, seed, pubkey) != 0) return;
|
||
/* zuse.4th's ACL-ZUSE-BOOT self-activated once already at Mama's own
|
||
* birth, when no cert was installed yet (the thumbdrive wasn't
|
||
* attached at that early, one-shot point) -- ACL-PIN only blocks
|
||
* *redefinition*, not re-execution, so re-running the same policy
|
||
* word here is the correct, already-designed way to activate
|
||
* zuse_session now that a cert genuinely exists. No new C-side auth
|
||
* logic; policy stays in ACL.4th/zuse.4th per this project's own
|
||
* convention. */
|
||
vm_interpret(mama_vm, "ACL-ZUSE-BOOT");
|
||
}
|
||
|
||
void capsule_zuse_boot_try_attach(struct blkio_dev *dev,
|
||
homeblocks_sig_result_t sig_rc,
|
||
const homeblocks_sig_t *sig,
|
||
VM *mama_vm) {
|
||
if (!dev || !mama_vm) return;
|
||
if (mama_vm->zuse_cert_installed) return; /* already have Zuse this boot */
|
||
|
||
zuse_genesis_marker_t marker;
|
||
int have_marker = (genesis_marker_read(&marker) == 0);
|
||
|
||
if (!have_marker) {
|
||
if (sig_rc != HOMEBLOCKS_SIG_BLANK) return; /* not eligible for genesis */
|
||
|
||
uint8_t seed[32], pubkey[32];
|
||
MintResult r = capsule_mint_identity(dev, (VM *)0, "Zuse", "zuse",
|
||
(const char *)0, (const char *)0,
|
||
pubkey, seed,
|
||
1 /* sig_rc already confirmed BLANK above */);
|
||
if (r != MINT_OK) {
|
||
console_println("Zuse: genesis mint failed");
|
||
return;
|
||
}
|
||
|
||
zuse_genesis_marker_t wm;
|
||
memset(&wm, 0, sizeof(wm));
|
||
wm.magic = ZUSE_GENESIS_MARKER_MAGIC;
|
||
wm.version = ZUSE_GENESIS_MARKER_VERSION;
|
||
memcpy(wm.zuse_pubkey, pubkey, 32);
|
||
wm.crc = compute_crc64((const uint8_t *)&wm, offsetof(zuse_genesis_marker_t, crc));
|
||
if (blk_meta_zone_write(0, (const uint8_t *)&wm) != 0) {
|
||
console_println("Zuse: genesis minted but fence marker write FAILED (not persistent)");
|
||
} else {
|
||
console_println("Zuse: genesis minted onto attached thumbdrive");
|
||
}
|
||
|
||
install_and_activate(mama_vm, seed, pubkey);
|
||
return;
|
||
}
|
||
|
||
/* Marker present: genesis already happened, on some thumbdrive.
|
||
* Only act if THIS attach is that drive. */
|
||
if (sig_rc != HOMEBLOCKS_SIG_OK || !sig) return;
|
||
if (sig->identity_src_offset == 0 || sig->identity_src_devblocks < 1) return;
|
||
|
||
user_identity_seed_t idrec;
|
||
if (read_devblock(dev, sig->identity_src_offset, (uint8_t *)&idrec) != 0) return;
|
||
/* Same magic -> version -> CRC-64 discipline as genesis_marker_read():
|
||
* this record carries Zuse's private key (the seed), so a corrupt or
|
||
* format-mismatched record must be refused, never loaded -- a bad CRC
|
||
* could otherwise install a garbage seed as Zuse's identity. */
|
||
if (idrec.magic != USER_IDENTITY_SEED_MAGIC) return;
|
||
if (idrec.version != USER_IDENTITY_SEED_VERSION) return;
|
||
uint64_t want_crc = compute_crc64((const uint8_t *)&idrec,
|
||
offsetof(user_identity_seed_t, crc));
|
||
if (want_crc != idrec.crc) return;
|
||
if (memcmp(idrec.pubkey, marker.zuse_pubkey, 32) != 0) return; /* not Zuse's drive */
|
||
|
||
console_println("Zuse: identity confirmed from attached thumbdrive");
|
||
install_and_activate(mama_vm, idrec.seed, idrec.pubkey);
|
||
}
|