code wiki / _hdl_build / nx_boot_run_sov.nx
nx_boot_run_sov.nx source
↩ module page · 118 lines · 7133 B
1// nx_boot_run_sov.nx -- the SOVEREIGN boot runtime. Loads an emitter-authored rv64 flat binary
2// into the Nishi-owned rv64 emulator (rv64im_min_sim + its 16550 UART / SiFive finisher / M-mode
3// CSR / CLINT / virtio / NVMe / Sv39-MMU device models) and RUNS it -- the kernel boots on OUR
4// silicon model, not qemu. qemu stays a pure ALIGNMENT cross-check, never the runtime.
5//
6// ★FIXED 2026-07-31 (debt 1785517037): this runner used to decide its verdict from
7// `halted && halt_code==0` ALONE and NEVER READ THE SERIAL IT HAD JUST CAPTURED. Proven by
8// tamper: an image whose Sv39 walk was broken emitted "...TICK TX" -- the paging phase DEAD --
9// and BOOTSOV still returned verdict=GREEN exit=0; clearing medeleg dropped the USER marker and
10// it still returned GREEN. A runner that returns GREEN on a boot it can see is broken is not a
11// check. It now compares the captured transcript against the artifact's golden and goes RED on
12// mismatch. Backwards-compatible BY CONSTRUCTION: an image with NO golden behaves exactly as
13// before (halt-only verdict) and says so, so nothing that boots a golden-less payload changes.
14// nx_boot_run_sov [binpath] [goldpath]
15// exit 0 = booted + clean halt + (golden matched or absent); 1 = otherwise
16// Boot-and-capture comes from the shared nx_bootcap primitive so this runner, the gate, the
17// census and the adoption ruler cannot disagree about what "booting the image" means.
18// Sovereign: the emulator IS the runtime. license_tier: ORIGINAL
19import "nx_bootcap.nx"
20
21const BR_BIN: *u8 = "runtime/_hdl_build/_boot_nishi_virt.bin"
22const BR_BIN_ALT: *u8 = "_boot_nishi_virt.bin"
23const BR_GOLD_ALT: *u8 = "runtime/_hdl_build/_boot_nishi_virt.bin.gold"
24const BR_TX_CAP: i64 = 4096
25const BR_LOG: *u8 = "knowledge/status/boot_stub.log"
26
27func br_p(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 }
28func br_fp(fd: i64, s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(fd,s,n); return 0 }
29func br_fn(fd: i64, v: i64) -> i64 { let bb: *u8=sys_mmap(28); var m: i64=v; if m<0{m=0-m;sys_write(fd,"-" as *u8,1)}; let t: *u8=sys_mmap(28); var k: i64=0; if m==0{t[0]=48;k=1}; while m>0{t[k]=(48+(m%10)) as u8;m=m/10;k=k+1}; var i: i64=0; while i<k{bb[i]=t[k-1-i];i=i+1}; sys_write(fd,bb,k); return 0 }
30
31func br_eq(a: *u8, an: i64, b: *u8, bn: i64) -> i64 {
32 if an != bn { return 0 }
33 var i: i64 = 0
34 while i < an { if a[i] != b[i] { return 0 } i = i + 1 }
35 return 1
36}
37
38func main(argc: i64, argv: *i64) -> i64 {
39 var binp: *u8 = BR_BIN
40 if argc >= 2 { binp = argv[1] as *u8 }
41
42 let lenp: *i64 = sys_mmap(16) as *i64
43 let pathp: *i64 = sys_mmap(16) as *i64
44 let img: *u8 = bootcap_load(binp, BR_BIN_ALT, lenp, pathp)
45 let ilen: i64 = lenp[0]
46 if ilen <= 0 { br_p("BOOTSOV verdict=RED reason=binary-missing\n" as *u8); sys_exit(1); return 1 }
47 binp = (pathp[0]) as *u8
48
49 let tx: *u8 = sys_mmap(BR_TX_CAP)
50 let res: *i64 = sys_mmap(8 * BOOTCAP_R_N) as *i64
51 bootcap_run(img, ilen, tx, BR_TX_CAP, res)
52 let cnt: i64 = res[BOOTCAP_R_TXN]
53
54 br_p("SOVEREIGN-EMU serial: " as *u8)
55 sys_write(1, tx, cnt)
56 br_p("\n" as *u8)
57
58 // Resolve the golden: <binpath>.gold first (the golden travels with its artifact), then an
59 // explicit argv[2], then the buildroot location for images authored before that convention.
60 let gpath: *u8 = sys_mmap(512)
61 var gi: i64 = 0
62 while binp[gi] != (0 as u8) { gpath[gi] = binp[gi]; gi = gi + 1 }
63 let suf: *u8 = ".gold" as *u8
64 var si: i64 = 0
65 while suf[si] != (0 as u8) { gpath[gi + si] = suf[si]; si = si + 1 }
66 gpath[gi + si] = 0 as u8
67 var goldp: *u8 = gpath
68 if argc >= 3 { goldp = argv[2] as *u8 }
69 let glenp: *i64 = sys_mmap(16) as *i64
70 var gold: *u8 = sys_read_file(goldp, glenp)
71 // ★FIXED 2026-08-07: this fallback used to fire for ANY image whose <image>.gold was absent, so
72 // a golden-less payload was judged against the DEFAULT KERNEL's transcript -- a comparison of two
73 // unrelated artifacts, reported as a real verdict. MEASURED: _mmu_gate's device-base tamper run
74 // (/tmp/_mmu_t1.bin, no golden) was compared against _boot_nishi_virt.bin.gold, and the gate then
75 // credited the resulting mismatch as proof its tamper had worked -- it would have passed
76 // IDENTICALLY WITH THE MMU DEVICE DELETED. It also falsified this file's own header claim that
77 // "an image with NO golden behaves exactly as before (halt-only verdict)": the halt-only branch
78 // below was UNREACHABLE for such images, because this line always manufactured a golden.
79 // BR_GOLD_ALT is the LEGACY LOCATION OF THE DEFAULT KERNEL IMAGE'S golden, so it may only be
80 // consulted when this runner was invoked in its default no-argument mode. A NAMED image's golden
81 // is <image>.gold, an explicit argv[2], or genuinely ABSENT -- and absent must read ABSENT.
82 if glenp[0] <= 0 { if argc < 2 { goldp = BR_GOLD_ALT; gold = sys_read_file(goldp, glenp) } }
83 let glen: i64 = glenp[0]
84
85 var halted_ok: i64 = 0
86 if res[BOOTCAP_R_HALTED] == 1 { if res[BOOTCAP_R_CODE] == 0 { halted_ok = 1 } }
87
88 // A transcript that disagrees with the artifact's own golden is a FAILED boot, however
89 // cleanly it halted -- halting is not the same as working.
90 var tmatch: i64 = 1
91 var checked: i64 = 0
92 if glen > 0 { checked = 1; tmatch = br_eq(tx, cnt, gold, glen) }
93
94 let lfd: i64 = sys_openat_append(BR_LOG, 0x1a4)
95 if halted_ok == 1 {
96 if tmatch == 1 {
97 br_p("BOOTSOV verdict=GREEN (booted on the sovereign rv64 emu; clean finisher halt" as *u8)
98 if checked == 1 { br_p("; transcript==golden" as *u8) } else { br_p("; golden=ABSENT, transcript UNCHECKED" as *u8) }
99 br_p(") steps=" as *u8); br_fn(1, res[BOOTCAP_R_STEPS]); br_p("\n" as *u8)
100 if lfd >= 0 {
101 br_fp(lfd, "BOOTSOV verdict=GREEN steps=" as *u8); br_fn(lfd, res[BOOTCAP_R_STEPS])
102 br_fp(lfd, " bytes=" as *u8); br_fn(lfd, cnt)
103 if checked == 1 { br_fp(lfd, " transcript=matched-golden" as *u8) } else { br_fp(lfd, " transcript=unchecked-no-golden" as *u8) }
104 br_fp(lfd, "\n" as *u8); sys_close(lfd)
105 }
106 sys_exit(0); return 0
107 }
108 br_p("BOOTSOV verdict=RED reason=transcript-mismatch (it halted cleanly but did NOT do what the golden says) golden=" as *u8)
109 br_p(goldp); br_p(" expected=[" as *u8); sys_write(1, gold, glen); br_p("] got=[" as *u8); sys_write(1, tx, cnt); br_p("]\n" as *u8)
110 if lfd >= 0 { br_fp(lfd, "BOOTSOV verdict=RED reason=transcript-mismatch got=" as *u8); sys_write(lfd, tx, cnt); br_fp(lfd, "\n" as *u8); sys_close(lfd) }
111 sys_exit(1); return 1
112 }
113 br_p("BOOTSOV verdict=RED (no clean halt) halted=" as *u8); br_fn(1, res[BOOTCAP_R_HALTED])
114 br_p(" code=" as *u8); br_fn(1, res[BOOTCAP_R_CODE]); br_p("\n" as *u8)
115 if lfd >= 0 { br_fp(lfd, "BOOTSOV verdict=RED halted=" as *u8); br_fn(lfd, res[BOOTCAP_R_HALTED]); br_fp(lfd, "\n" as *u8); sys_close(lfd) }
116 sys_exit(1)
117 return 1
118}