device-manager: delete the delegated-set scaffolding

The name list and its predicate existed so drivers could move to delegation
one at a time with the suite green throughout. Every driver is delegated
now, so the manager simply hands over whatever device a driver was assigned.

Deleting it caught a real consequence: crash-test finally got delegated too,
and it was still claiming its device — so it got AlreadyClaimed because it
already held it, exited, and the restart drill had nothing to restart. Its
own comment named what the case was really checking: "the respawn only
reaches this line because the kernel released the previous instance's claim
at death". That property still holds, by a different mechanism — the device
reverts to the manager on death and is handed to the replacement, which is
the same guarantee without the race it used to rely on.

All four delegation paths verified: the xHCI controller, the PCI bridge, the
PS/2 two-node singleton, and virtio-gpu's restart re-attach.

Run 3 complete. Suite 118/118.
This commit is contained in:
Daniel Samson
2026-08-08 23:01:29 +01:00
parent df9c1ed827
commit 0eb2420690
3 changed files with 16 additions and 39 deletions
@@ -244,35 +244,6 @@ fn alreadySupervised(name: []const u8) bool {
return false;
}
/// Drivers that receive their device from the manager rather than claiming it
/// themselves. Scaffolding for the conversion, not a permanent concept: it exists so
/// each driver can move across one at a time with the suite green throughout, and it
/// disappears at D6 when `device_claim` stops being a way to acquire a device at all
/// (docs/bounds-track-plan.md, Run 2).
///
/// `usb-xhci-bus` is first because it was the first driver to conform to `hello`
/// (device-manager.md, M18.1), so it is the one whose handshake is best proven.
const delegated_drivers = [_][]const u8{
"usb-xhci-bus",
"pci-bus",
"virtio-gpu",
"ps2-bus",
"discovery",
};
/// Matched on the **last path component**, because a driver reaches this table under
/// two different spellings: the boot-snapshot match records the bare `pci-bus`, while a
/// devices.csv match records the full `/system/drivers/pci-bus`. Comparing whole
/// strings silently missed the bare form — pci-bus was left neither claiming nor
/// delegated, and died on `ECAM mmio_map failed`.
fn isDelegated(name: []const u8) bool {
const leaf = if (std.mem.lastIndexOfScalar(u8, name, '/')) |slash| name[slash + 1 ..] else name;
for (delegated_drivers) |candidate| {
if (std.mem.eql(u8, leaf, candidate)) return true;
}
return false;
}
/// Record a driver in the table and spawn its first instance.
fn addDriver(name: []const u8, device_id: u64, speaks_protocol: bool) void {
for (&drivers) |*driver| {
@@ -298,7 +269,7 @@ fn spawnDriver(driver: *Driver) void {
// rather than advisory. Re-claiming across a restart is expected to say
// AlreadyClaimed once the manager already holds it, and that is fine: it means the
// device never left our hands while the driver was dead.
if (isDelegated(driver.name()) and driver.device_id != device_manager_protocol.no_device) {
if (driver.device_id != device_manager_protocol.no_device) {
device.claim(driver.device_id) catch |e| switch (e) {
error.AlreadyClaimed => {}, // ours already, from a previous spawn of this driver
else => {
@@ -320,7 +291,7 @@ fn spawnDriver(driver: *Driver) void {
// A transfer *after* spawning would leave a window in which the child is running
// without its hardware — closed on one machine, open on another
// (docs/bounds-track-plan.md, "the grant rides system_spawn").
const give = if (isDelegated(driver.name())) driver.device_id else device_manager_protocol.no_device;
const give = driver.device_id;
if (give != device_manager_protocol.no_device)
std.log.info("delegated device {d} to {s}", .{ give, driver.name() });
const child = process.spawnSupervisedWithDevice(driver.name(), arguments[0..argument_count], manager_endpoint, give) orelse {