MakopaOS · Engineering note
MakopaOS checks component evidence before admission
OS041A adds bounded parsing, signatures, exact-byte binding and source inventory checks. A passing report still has admission_authority: false.
Source: https://louijiecompo.com/updates/makopa-component-precheck/
A passing precheck leaves authority unchanged
- Bound and bind the input. Parse fixed records, verify exact lengths and SHA-256 bindings, and reject malformed supporting documents.
- Verify the evidence. Check Ed25519 signatures, staged source inventory and the constrained Component Model/WIT profile.
- Report without execution. Return deterministic JSON with admission_authority: false. No compilation, instantiation or execution.
PR #22 adds a separate locked host workspace for the component-admission precheck. Fixed-record parsers, supporting-document checks, transitive SHA-256 binding, domain-separated key IDs and strict Ed25519 verification constrain the bundle before a deterministic JSON report.
The checker verifies the staged source inventory and a constrained Component Model/WIT boundary. It never compiles, instantiates or executes a component. Target boot, kernel and QEMU paths remain separate from the host dependencies.
OS041A remains in progress. Committed-Git reconstruction, pinned fixture production, contained metadata decoding, semantic graph comparison, compile-only measurements and link/disassembly evidence remain future gates. A pass deliberately retains admission_authority: false; it is not permission to execute.
Explore the topic
Follow the evidence
Read source evidence ↗ (opens in a new tab)
Related reading
Follow writing and engineering notes
Add this feed to your RSS reader to follow new articles and engineering notes. No signup or tracking on this site.
Follow via RSS