code wiki / _hdl_build / _priv_gate.nx

_priv_gate.nx source

↩ module page · 101 lines · 6000 B

1// _priv_gate.nx -- gate for M/S/U PRIVILEGE + privilege-gated paging (privilege-levels capability). NO mocks. 2// 3// (1) PRIVILEGE-GATED -- emits + runs nx_priv_emit: the SAME VA 0xC0009000 reads as identity in 4// M-mode ("MID") and translates to the sentinel in S-mode after mret ("SOK") -> serial 5// "MIDSOK" + clean halt. Proves translation applies only in S/U and that mret M->S works. 6// (2) CONTROL -- re-emit with MPP=M (0x1800) so mret stays in M-mode: the second VA load is then 7// ALSO Bare (identity) -> "SX" instead of "SOK". Proves "SOK" REQUIRES S-mode (the gating is 8// real -- M-mode never translates). 9// 10// Evidence -> knowledge/status/priv.log (PRIVGATE row). Sovereign. license_tier: ORIGINAL 11import "nx_syscalls.nx" 12import "nx_gate_verdict.nx" 13 14const V_EMIT: *u8 = "_offc/nx_priv_emit.elf" 15const V_SOV: *u8 = "_offc/nx_boot_run_sov.elf" 16const V_BIN: *u8 = "runtime/_hdl_build/_priv_virt.bin" 17 18func g_p(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 } 19func g_fp(fd: i64, s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(fd,s,n); return 0 } 20func g_fn(fd: i64, v: i64) -> i64 { let bb: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m;sys_write(fd,"-" as *u8,1)}; let t: *u8=sys_mmap(28); var k: i64=0; if m==0{t[0]=48;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{bb[i]=t[k-1-i];i=i+1}; sys_write(fd,bb,k); return 0 } 21 22func g_run(prog: *u8, a1: *u8, a2: *u8, outpath: *u8) -> i64 { 23 let pid: i64 = sys_fork() 24 if pid == 0 { 25 if outpath != (0 as *u8) { let ofd: i64 = sys_openat_wr(outpath, 0x1a4); if ofd >= 0 { sys_dup3(ofd, 1, 0); sys_dup3(ofd, 2, 0) } } 26 let argv: *i64 = sys_mmap(32) as *i64 27 argv[0] = prog as i64 28 var k: i64 = 1 29 if a1 != (0 as *u8) { argv[k] = a1 as i64; k = k + 1 } 30 if a2 != (0 as *u8) { argv[k] = a2 as i64; k = k + 1 } 31 argv[k] = 0 32 let envp: *i64 = sys_mmap(16) as *i64 33 envp[0] = "PATH=/usr/bin:/bin" as *u8 as i64; envp[1] = 0 34 sys_execve(prog, argv, envp) 35 sys_exit(127) 36 } 37 let st: *i64 = sys_mmap(16) as *i64 38 sys_wait4(pid, st, 0) 39 let sg: i64 = st[0] & 0x7f 40 if sg != 0 { return 128 + sg } 41 return (st[0] >> 8) & 0xff 42} 43func g_read(path: *u8, buf: *u8, cap: i64) -> i64 { 44 let fd: i64 = sys_openat_rd(path) 45 if fd < 0 { return 0 } 46 var n: i64 = 0 47 var go: i64 = 1 48 while go == 1 { let r: i64 = sys_read(fd, (buf as i64 + n) as *u8, cap - 1 - n); if r <= 0 { go = 0 } else { n = n + r } if n >= cap - 1 { go = 0 } } 49 sys_close(fd) 50 return n 51} 52func g_has(buf: *u8, n: i64, pat: *u8, pl: i64) -> i64 { 53 if pl <= 0 { return 0 } 54 var i: i64 = 0 55 while i + pl <= n { var k: i64=0; var hit: i64=1; while k<pl { if buf[i+k]!=pat[k]{hit=0;k=pl}else{k=k+1} } if hit==1 { return 1 } i=i+1 } 56 return 0 57} 58 59func main() -> i64 { 60 g_p("=== M/S/U privilege gate (Sv39 translation only in S/U; mret M->S) ===\n" as *u8) 61 let lfd: i64 = sys_openat_append("knowledge/status/priv.log" as *u8, 0x1a4) 62 63 // (1) privilege-gated: MIDSOK 64 g_run(V_EMIT, 0 as *u8, 0 as *u8, "/tmp/_pv_emit.out" as *u8) 65 g_run(V_SOV, V_BIN, 0 as *u8, "/tmp/_pv_main.txt" as *u8) 66 let mb: *u8 = sys_mmap(65536); let mn: i64 = g_read("/tmp/_pv_main.txt" as *u8, mb, 65536) 67 var gated_ok: i64 = 0 68 if g_has(mb, mn, "MIDSOK" as *u8, 6) == 1 { if g_has(mb, mn, "BOOTSOV verdict=GREEN" as *u8, 21) == 1 { gated_ok = 1 } } 69 70 // (2) control: MPP=M (stay M) -> no S-mode -> 2nd load Bare -> "SX" not "SOK" 71 g_run(V_EMIT, "0x1800" as *u8, "/tmp/_pv_ctrl.bin" as *u8, "/tmp/_pv_ctrl_emit.out" as *u8) 72 g_run(V_SOV, "/tmp/_pv_ctrl.bin" as *u8, 0 as *u8, "/tmp/_pv_ctrl.txt" as *u8) 73 let cb: *u8 = sys_mmap(65536); let cn: i64 = g_read("/tmp/_pv_ctrl.txt" as *u8, cb, 65536) 74 var control_ok: i64 = 0 75 if g_has(cb, cn, "MID" as *u8, 3) == 1 { if g_has(cb, cn, "SOK" as *u8, 3) == 0 { control_ok = 1 } } 76 77 g_p(" privilege_gated=" as *u8); if gated_ok==1 { g_p("GREEN(MIDSOK: same VA identity in M, translated in S)" as *u8) } else { g_p("RED" as *u8) } 78 g_p(" control_stayM_no_SOK=" as *u8); g_fn(1, control_ok); g_p("\n" as *u8) 79 80 // ---- D001 MIGRATION 2026-08-06 -- IDIOM G (boolean conjunction, no counter) ------------------- 81 // Fourth of the family; see _mmu_gate for the full reasoning. ONE gv_check PER CONJUNCT creates the 82 // counter idioms A-F assume already exists, and gv_verdict is GREEN iff pass==total -- exactly the 83 // old `gated_ok && control_ok`. Teeth unchanged; only the verdict reporter moves to the base class 84 // so nx_gate_green can judge it and /api/promote stops refusing it. 85 let ctr: *i64 = gv_ctr() 86 gv_check("T1 privilege-gated translation (SAME VA is identity in M-mode [MID] and translates in S-mode after mret [SOK])" as *u8, gated_ok, ctr) 87 gv_check("T2 control MPP=M stays in M -> no translation -> no SOK -- proves the gating is the privilege level, not the page table" as *u8, control_ok, ctr) 88 let rc: i64 = gv_verdict("PRIVGATE" as *u8, ctr, "M/S/U privilege: Sv39 translation applies ONLY in S/U -- the SAME VA is identity in M-mode [MID] and translates in S-mode after mret [SOK]; the MPP=M control stays in M so there is no translation and no SOK. probe=privilege-levels" as *u8) 89 // knowledge/status/priv.log evidence row PRESERVED in both branches -- the rollup reads it. 90 if lfd >= 0 { 91 if rc == 0 { 92 g_fp(lfd, "PRIVGATE verdict=GREEN keystone=privilege-levels-msu probe=privilege-levels mret-M-to-S=yes M-mode-bare=yes S-mode-translate=yes control=stayM-no-SOK epoch=" as *u8); g_fn(lfd, sys_now_realtime_sec()); g_fp(lfd, "\n" as *u8) 93 } 94 if rc != 0 { 95 g_fp(lfd, "PRIVGATE verdict=RED gated=" as *u8); g_fn(lfd, gated_ok); g_fp(lfd, " control=" as *u8); g_fn(lfd, control_ok); g_fp(lfd, "\n" as *u8) 96 } 97 sys_close(lfd) 98 } 99 sys_exit(rc) 100 return rc 101}