Files
Robert Allan JamesandClaude Sonnet 5 089ab2160e
Build / build-amd64-iso (push) Canceled after 0s
Build / build-aarch64-iso (push) Canceled after 0s
Build / build-riscv64-img (push) Canceled after 0s
Phase 8 Part B: gate ZUSE-ELIGIBILITY-ADD, closing the no-drive-needed privilege path
ZUSE-ELIGIBILITY-ADD's own doc comment admitted "no authorization check
here or anywhere else... applied later if and when actually needed --
not invented here." That's now: anyone reaching a Hera FORTH prompt
could add their own pubkey to the eligibility list with zero legitimate
identity material -- no minted drive, no WIREBIND, no cert-signature
check involved at all. Once a future caller reaches ELEVATE-GRANT again,
a self-added pubkey would pass zuse_eligibility_is_member() and grant
ACL-ALLOW!/ACL-TTL! on any named word.

Fixed the FORTH-only way, matching this project's own convention (ACL
policy belongs in ACL.4th, never in C; never gate on zuse_session in C --
her power is the absence of ACLs, not a hardcoded session check):
ZUSE-ELIGIBILITY-ADD is now denied by default (capsules/zuse.4th block
4016), granted and pinned only inside ACL-ZUSE-BOOT's already-existing
authenticated branch (block 4017) -- the same gate her own god-mode
already goes through, requiring a real cert-verified Zuse before it opens.

Live-verified on all three architectures, not just boot-clean: after
genesis authentication, ACL-ALLOW@ and ACL-PINNED? both read -1, and
HERE ZUSE-ELIGIBILITY-ADD executes successfully past the ACL gate.

Phase 8 v1 plan: /home/rajames/.claude/plans/jiggly-cuddling-stallman.md
Part A (the ELEVATE-GRANT pointer-confusion fix, FABRIC-3.7.md) is
separate, not yet built.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-22 22:57:10 -04:00

43 lines
1.8 KiB
Forth

Block 4016
( zuse.4th - Bootstrap superuser for StarForth ACL )
( Named for Konrad Zuse, pioneer of programmable computers. )
( Sole superuser; mints credentials; owns emergency REPL. )
( Loaded by ACL.4th; must not load before ACL.4th. )
( Thumbdrive-resident Ed25519 PKI (2026-08-28) -- her seed )
( lives only on her own minted drive, never system-resident. )
( HUMAN-REVIEW: capsule hash = root of superuser trust. )
( Cert (seed+pubkey) lives in C-only VM fields, installed by )
( capsule_zuse_boot.c on genesis-mint or thumbdrive attach. )
( NOT a CONSTANT: ACL-PIN blocks redefinition, not a )
( >BODY-then-store, so a pinned CONSTANT isn't tamper-proof. )
( Read with ZUSE-PUBKEY@ / ZUSE-CERT-INSTALLED? -- both C )
( primitives, read-only; the seed has no FORTH access at all. )
( ZUSE-ELIGIBILITY-ADD denied by default -- see block 4017. )
0 ['] ZUSE-ELIGIBILITY-ADD ACL-ALLOW!
Block 4017
( ACL-ZUSE-BOOT ( -- ) re-invokable: capsule_zuse_boot.c )
( calls it again once a thumbdrive attach installs a cert. )
( Only authenticates if a real cert is installed -- refuses )
( god-mode to a Zuse with no real identity behind her. )
( ZUSE-AUTHENTICATE is C-only; no FORTH word grants god-mode )
( except through this sequence. )
: ACL-ZUSE-BOOT ( -- )
ZUSE-CERT-INSTALLED? IF
ZUSE-AUTHENTICATE
1 ['] ZUSE-ELIGIBILITY-ADD ACL-ALLOW!
['] ZUSE-ELIGIBILITY-ADD ACL-PIN
LOG-INFO" zuse: activated"
ELSE
LOG-INFO" zuse: NOT activated -- no cert installed"
THEN ;
Block 4018
( Pin against redefinition -- once, after definition closes; )
( ['] from inside its own body can't find itself mid-compile, )
( found live 2026-08-28 activating ACL.4th for the first time. )
( Pinning doesn't block re-EXECUTION, only redefinition -- the )
( re-invoke above still works after this runs. Self-activates. )
['] ACL-ZUSE-BOOT ACL-PIN
ACL-ZUSE-BOOT