Skip to content

Flash geometry v7: seven open items before any v7 code can run #752

Description

@Nicola-Ceornea

Tracking issue for the 2026-09-24 flash-geometry engagement. Full record, both drafts, three GPT-6 Astra rounds and the measured flash-budget research: docs/security/adversarial-review/findings/flash-geometry-v7-2026-09-24.md.

v7 is NOT ratified. Both drafts were rejected. This issue carries what is still open; the defects the rounds found in the geometry we ship today are already fixed (98bbb23d, 436341d5, 808c42f5, 03c95f03, 12b99eec, 05e5534f).

Why v7 exists

The owner decided to ship the pixel UI. It does not fit: ui-px costs 111,020 B marginal against 34,071 B of headroom in secure slot A (SECURE_SLOT_SPAN 0x72000 = 466,944 B) — a 76,949 B shortfall.

Caveat on every number here: the true shipping image cannot currently be compiled (RDP2_SELF_LOCK_REQUIRES_MODE_PRODUCTION and FW_ROLLBACK_PRODUCTION_BLOCKED both fire), so these are ship-shaped estimates.

Owner decisions already taken (inputs, not open questions)

  1. Ship the pixel UI.
  2. All screens must be viewed before signing (scroll-to-end consent).
  3. Shape B — secure flash in both banks, symmetric.
  4. Split 92/24 pages per bank.
  5. Do not remove the iota2 board code.

Open

  1. Artifact incompatibility is unspecified. No geometry digest exists. Choose a schema and domain; make legacy rejection a blocker across signer, updater and FSBL.
  2. Restore the production capacity gate. No split may be ratified before a physical LOAD-span measurement of both slot-linked S/NS pairs with the production feature set — which today cannot be built. 92/24 rests on ship-shaped numbers.
  3. The factory reservation has no owner, format bound, authentication, pre-lock failure behaviour or update/wipe preservation rule. Capacity is not authorisation.
  4. Factory sequencing / DFU cutoff — split out as its own issue, since it also binds the current geometry.
  5. The preserved-owner set must also name bank-2 pages 0-4, 6, 99-103.
  6. The watermark half of the round-2 CRITICAL finding. shared/src/lockdown.rs still rejects a v7 layout outright (it demands all-secure bank 1 / all-NS bank 2). That is correct today and must change with v7, never before it.
  7. Consumers that assume bank == security:
    • the FSBL's own SAU maps only bank 2 (fsbl/src/sau.rs)
    • atlas base, vectors, veneers, linker origins and measurement all use one constant instead of following the selected slot
    • write_slot_quadword_verified dispatches on alias, not bank, so a bank-2 secure address matches neither range and returns Err(()). It fails closed today; under v7 that refusal becomes wrong and the dispatch must be extended.
    • ns_ptr_validate needs two NS windows rather than one

Also blocked on #540 (the geometry-crate cutover).

Settled by the engagement: essentially nothing more can move to NS

  • The BIP-39 wordlist is a key-derivation input, not a display asset. bip39/src/full.rs:301 — Mnemonic::to_seed assembles the PBKDF2 password from WORDLIST_FLAT/WORDLIST_LENS. Control those tables and you control the password bytes; with an empty passphrase the derived seed becomes predictable. Wallet theft, not a WYSIWYS concern.
  • The bloom filter gates blind-sign downgrade. Clearing a queried bit makes a known tuple look absent and both redundant queries honestly agree on the wrong answer (tx/erc7730.rs:232). Do not truncate it either: folding to 8 KiB gives 38.84% occupancy against the generator's 25% cap (dbgen/src/erc7730.rs:3292).

Better, with no NS trust: compact in place. Pack eight letters as 5-bit symbols (10,240 B replacing FLAT+LENS's 18,432) -> 8,192 B; derive PREFIX5 from the full-word lookup -> 6,144 B; 14,336 B combined. Must preserve the deliberate full-scan constant-time behaviour at full.rs:29.

Where the bytes actually are (.text, 459,408 B), three evidenced targets:

  • sha2's force-soft-compact backend: SHA-512 27,806 + SHA-256 7,202
  • the two UserOp handlers duplicating envelope decode: cmd_sign_userop::run 14,224 + batch 18,088 = 32,312
  • the pixel scene: Anim::build 11,734 of 36,214 UI-crate bytes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions