M6: user runtime library rt + C-convention heap

Add lib/ — the shared user-space runtime every user binary links against
(init now, servers/drivers later): syscall wrappers, the heap, IPC stub,
and the process start shim.

- lib/heap.zig: the kernel first-fit free-list ported to user space, grown
  via the mmap syscall instead of pmm+mapPage. Dual API over one global free
  list: extern "C" malloc/free/calloc/realloc (C ABI for future C code) and a
  std.mem.Allocator adapter (with in-place resize) for Zig std containers.
- lib/syscall.zig + sys.zig: raw syscall0..5 (arg3 in r10) and typed
  yield/write/sleep/exit/mmap/munmap over danos.Syscall.
- lib/start.zig: naked _start -> rt_start -> root.main() (SysV realign via
  call), panic -> exit(127).
- lib/user.ld: the user link script, moved from sbin/linker.ld (shared by all
  user binaries).
- build.zig: register the `rt` module; add an addUserBinary() helper that is
  the one recipe for every user binary (freestanding, .large, use_lld,
  user.ld, image_base), replacing the bespoke init block.
- sbin/init.zig: migrated onto rt; drops its hand-rolled syscall2/shims. Now
  proves the heap (alloc -> write from a heap pointer -> free) before the
  heartbeat loop. Serial shows "init: heap ok". Suite 28/28.
This commit is contained in:
Daniel Samson
2026-07-09 07:08:32 +01:00
parent 9316f9f1c3
commit 0a8c81b17a
9 changed files with 448 additions and 82 deletions
+28 -54
View File
@@ -1,65 +1,39 @@
//! /sbin/init — the first user-space program, PID 1. Built as its own
//! freestanding binary (see build.zig), shipped on the boot volume at sbin/init,
//! loaded by the bootloader, and started in ring 3 as a scheduled process by the
//! kernel (src/kernel/process.zig). It talks to the kernel only through the
//! `syscall` instruction.
//! kernel (src/kernel/process.zig). It links against the shared user runtime
//! library `rt` and talks to the kernel only through `rt`'s syscall wrappers.
//!
//! Today it's a heartbeat: it prints a line and sleeps, forever — enough to show
//! the system reaches user space and stays alive with a real process scheduled
//! alongside the kernel's idle loop. It grows into the real init (service
//! supervision) once there are other user programs to supervise.
//! Today it proves the C-convention heap works, then settles into a heartbeat:
//! it prints a line and sleeps, forever — enough to show the system reaches user
//! space and stays alive with a real process scheduled alongside the kernel's
//! idle loop. It grows into the real init (service supervision) once there are
//! other user programs to supervise.
const std = @import("std");
const rt = @import("rt");
// Syscall numbers (see src/kernel/process.zig):
const sys_exit = 0;
const sys_write = 2;
const sys_sleep = 3;
pub fn main() void {
// Prove the heap end to end: allocate through the runtime allocator (which
// mmaps pages from the kernel and carves them with the free list), write into
// that heap buffer (exercising the widened debug_write bounds check), and
// free it. A fault here would kill init before it heartbeats — so the init
// test doubles as the heap regression test. (C code links the same heap via
// the extern malloc/free symbols; Zig code uses this allocator.)
const gpa = rt.allocator();
if (gpa.alloc(u8, 64)) |buf| {
const msg = "init: heap ok\n";
@memcpy(buf[0..msg.len], msg);
_ = rt.sys.write(buf[0..msg.len]);
gpa.free(buf);
} else |_| {}
fn syscall2(n: u64, a: u64, b: u64) u64 {
// The `syscall` instruction clobbers RCX (return RIP) and R11 (saved RFLAGS);
// the kernel entry stub preserves everything else.
return asm volatile ("syscall"
: [ret] "={rax}" (-> u64),
: [n] "{rax}" (n),
[a] "{rdi}" (a),
[b] "{rsi}" (b),
: .{ .rcx = true, .r11 = true, .memory = true });
}
fn write(msg: []const u8) void {
_ = syscall2(sys_write, @intFromPtr(msg.ptr), msg.len);
}
fn sleep(ms: u64) void {
_ = syscall2(sys_sleep, ms, 0);
}
fn exit(code: u64) noreturn {
_ = syscall2(sys_exit, code, 0);
unreachable; // the kernel never returns from exit
}
/// Entry. Naked: the kernel enters with rsp 16-aligned, but a SysV function
/// expects rsp ≡ 8 (mod 16) on entry (as if reached by `call`) — so re-enter
/// the ABI with an actual call. The trap after is a safety net.
pub export fn _start() callconv(.naked) noreturn {
asm volatile (
\\call init_main
\\ud2
);
}
export fn init_main() callconv(.c) noreturn {
while (true) {
write("init: heartbeat\n");
sleep(1000);
_ = rt.sys.write("init: heartbeat\n");
rt.sys.sleep(1000);
}
}
/// No runtime to unwind into — report the panic as a nonzero exit code.
pub const panic = std.debug.FullPanic(struct {
fn panic(_: []const u8, _: ?usize) noreturn {
exit(127);
}
}.panic);
pub const panic = rt.panic;
comptime {
_ = &rt.start._start; // pull the runtime entry shim into the image
}