code wiki / _hdl_build / nx_boot_run_sov.nx

nx_boot_run_sov.nx source

↩ module page · 118 lines · 7133 B

1// nx_boot_run_sov.nx -- the SOVEREIGN boot runtime. Loads an emitter-authored rv64 flat binary 2// into the Nishi-owned rv64 emulator (rv64im_min_sim + its 16550 UART / SiFive finisher / M-mode 3// CSR / CLINT / virtio / NVMe / Sv39-MMU device models) and RUNS it -- the kernel boots on OUR 4// silicon model, not qemu. qemu stays a pure ALIGNMENT cross-check, never the runtime. 5// 6// ★FIXED 2026-07-31 (debt 1785517037): this runner used to decide its verdict from 7// `halted && halt_code==0` ALONE and NEVER READ THE SERIAL IT HAD JUST CAPTURED. Proven by 8// tamper: an image whose Sv39 walk was broken emitted "...TICK TX" -- the paging phase DEAD -- 9// and BOOTSOV still returned verdict=GREEN exit=0; clearing medeleg dropped the USER marker and 10// it still returned GREEN. A runner that returns GREEN on a boot it can see is broken is not a 11// check. It now compares the captured transcript against the artifact's golden and goes RED on 12// mismatch. Backwards-compatible BY CONSTRUCTION: an image with NO golden behaves exactly as 13// before (halt-only verdict) and says so, so nothing that boots a golden-less payload changes. 14// nx_boot_run_sov [binpath] [goldpath] 15// exit 0 = booted + clean halt + (golden matched or absent); 1 = otherwise 16// Boot-and-capture comes from the shared nx_bootcap primitive so this runner, the gate, the 17// census and the adoption ruler cannot disagree about what "booting the image" means. 18// Sovereign: the emulator IS the runtime. license_tier: ORIGINAL 19import "nx_bootcap.nx" 20 21const BR_BIN: *u8 = "runtime/_hdl_build/_boot_nishi_virt.bin" 22const BR_BIN_ALT: *u8 = "_boot_nishi_virt.bin" 23const BR_GOLD_ALT: *u8 = "runtime/_hdl_build/_boot_nishi_virt.bin.gold" 24const BR_TX_CAP: i64 = 4096 25const BR_LOG: *u8 = "knowledge/status/boot_stub.log" 26 27func br_p(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 } 28func br_fp(fd: i64, s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(fd,s,n); return 0 } 29func br_fn(fd: i64, v: i64) -> i64 { let bb: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m;sys_write(fd,"-" as *u8,1)}; let t: *u8=sys_mmap(28); var k: i64=0; if m==0{t[0]=48;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{bb[i]=t[k-1-i];i=i+1}; sys_write(fd,bb,k); return 0 } 30 31func br_eq(a: *u8, an: i64, b: *u8, bn: i64) -> i64 { 32 if an != bn { return 0 } 33 var i: i64 = 0 34 while i < an { if a[i] != b[i] { return 0 } i = i + 1 } 35 return 1 36} 37 38func main(argc: i64, argv: *i64) -> i64 { 39 var binp: *u8 = BR_BIN 40 if argc >= 2 { binp = argv[1] as *u8 } 41 42 let lenp: *i64 = sys_mmap(16) as *i64 43 let pathp: *i64 = sys_mmap(16) as *i64 44 let img: *u8 = bootcap_load(binp, BR_BIN_ALT, lenp, pathp) 45 let ilen: i64 = lenp[0] 46 if ilen <= 0 { br_p("BOOTSOV verdict=RED reason=binary-missing\n" as *u8); sys_exit(1); return 1 } 47 binp = (pathp[0]) as *u8 48 49 let tx: *u8 = sys_mmap(BR_TX_CAP) 50 let res: *i64 = sys_mmap(8 * BOOTCAP_R_N) as *i64 51 bootcap_run(img, ilen, tx, BR_TX_CAP, res) 52 let cnt: i64 = res[BOOTCAP_R_TXN] 53 54 br_p("SOVEREIGN-EMU serial: " as *u8) 55 sys_write(1, tx, cnt) 56 br_p("\n" as *u8) 57 58 // Resolve the golden: <binpath>.gold first (the golden travels with its artifact), then an 59 // explicit argv[2], then the buildroot location for images authored before that convention. 60 let gpath: *u8 = sys_mmap(512) 61 var gi: i64 = 0 62 while binp[gi] != (0 as u8) { gpath[gi] = binp[gi]; gi = gi + 1 } 63 let suf: *u8 = ".gold" as *u8 64 var si: i64 = 0 65 while suf[si] != (0 as u8) { gpath[gi + si] = suf[si]; si = si + 1 } 66 gpath[gi + si] = 0 as u8 67 var goldp: *u8 = gpath 68 if argc >= 3 { goldp = argv[2] as *u8 } 69 let glenp: *i64 = sys_mmap(16) as *i64 70 var gold: *u8 = sys_read_file(goldp, glenp) 71 // ★FIXED 2026-08-07: this fallback used to fire for ANY image whose <image>.gold was absent, so 72 // a golden-less payload was judged against the DEFAULT KERNEL's transcript -- a comparison of two 73 // unrelated artifacts, reported as a real verdict. MEASURED: _mmu_gate's device-base tamper run 74 // (/tmp/_mmu_t1.bin, no golden) was compared against _boot_nishi_virt.bin.gold, and the gate then 75 // credited the resulting mismatch as proof its tamper had worked -- it would have passed 76 // IDENTICALLY WITH THE MMU DEVICE DELETED. It also falsified this file's own header claim that 77 // "an image with NO golden behaves exactly as before (halt-only verdict)": the halt-only branch 78 // below was UNREACHABLE for such images, because this line always manufactured a golden. 79 // BR_GOLD_ALT is the LEGACY LOCATION OF THE DEFAULT KERNEL IMAGE'S golden, so it may only be 80 // consulted when this runner was invoked in its default no-argument mode. A NAMED image's golden 81 // is <image>.gold, an explicit argv[2], or genuinely ABSENT -- and absent must read ABSENT. 82 if glenp[0] <= 0 { if argc < 2 { goldp = BR_GOLD_ALT; gold = sys_read_file(goldp, glenp) } } 83 let glen: i64 = glenp[0] 84 85 var halted_ok: i64 = 0 86 if res[BOOTCAP_R_HALTED] == 1 { if res[BOOTCAP_R_CODE] == 0 { halted_ok = 1 } } 87 88 // A transcript that disagrees with the artifact's own golden is a FAILED boot, however 89 // cleanly it halted -- halting is not the same as working. 90 var tmatch: i64 = 1 91 var checked: i64 = 0 92 if glen > 0 { checked = 1; tmatch = br_eq(tx, cnt, gold, glen) } 93 94 let lfd: i64 = sys_openat_append(BR_LOG, 0x1a4) 95 if halted_ok == 1 { 96 if tmatch == 1 { 97 br_p("BOOTSOV verdict=GREEN (booted on the sovereign rv64 emu; clean finisher halt" as *u8) 98 if checked == 1 { br_p("; transcript==golden" as *u8) } else { br_p("; golden=ABSENT, transcript UNCHECKED" as *u8) } 99 br_p(") steps=" as *u8); br_fn(1, res[BOOTCAP_R_STEPS]); br_p("\n" as *u8) 100 if lfd >= 0 { 101 br_fp(lfd, "BOOTSOV verdict=GREEN steps=" as *u8); br_fn(lfd, res[BOOTCAP_R_STEPS]) 102 br_fp(lfd, " bytes=" as *u8); br_fn(lfd, cnt) 103 if checked == 1 { br_fp(lfd, " transcript=matched-golden" as *u8) } else { br_fp(lfd, " transcript=unchecked-no-golden" as *u8) } 104 br_fp(lfd, "\n" as *u8); sys_close(lfd) 105 } 106 sys_exit(0); return 0 107 } 108 br_p("BOOTSOV verdict=RED reason=transcript-mismatch (it halted cleanly but did NOT do what the golden says) golden=" as *u8) 109 br_p(goldp); br_p(" expected=[" as *u8); sys_write(1, gold, glen); br_p("] got=[" as *u8); sys_write(1, tx, cnt); br_p("]\n" as *u8) 110 if lfd >= 0 { br_fp(lfd, "BOOTSOV verdict=RED reason=transcript-mismatch got=" as *u8); sys_write(lfd, tx, cnt); br_fp(lfd, "\n" as *u8); sys_close(lfd) } 111 sys_exit(1); return 1 112 } 113 br_p("BOOTSOV verdict=RED (no clean halt) halted=" as *u8); br_fn(1, res[BOOTCAP_R_HALTED]) 114 br_p(" code=" as *u8); br_fn(1, res[BOOTCAP_R_CODE]); br_p("\n" as *u8) 115 if lfd >= 0 { br_fp(lfd, "BOOTSOV verdict=RED halted=" as *u8); br_fn(lfd, res[BOOTCAP_R_HALTED]); br_fp(lfd, "\n" as *u8); sys_close(lfd) } 116 sys_exit(1) 117 return 1 118}