M14b: DMA memory (dma_alloc / dma_free)
An HCD programs a bus-master engine: it needs a descriptor ring that is physically contiguous, at a physical address it knows, uncacheable, and pinned. mmap gives none of those. Add dma_alloc(len, flags) -> vaddr (rax), paddr (rdx) and dma_free(vaddr, len): grant contiguous, zeroed, pinned, strong-uncacheable memory in a per-process DMA arena (PML4[228]) and hand back both addresses. Pieces: pmm.allocContiguous(count, max_phys) finds a run of contiguous free frames below a cap (dma_below_4g for 32-bit engines); mapUserDmaInto maps them uncacheable (PCD|PWT) but WITHOUT device_grant, so unlike an MMIO grant these frames are real RAM and freeSubtree returns them on teardown — a driver that dies leaks nothing. dma_free is bounded to the DMA arena so it can never unmap the caller's stack/heap/MMIO. dma_write_combining is accepted but falls back to coherent (WC needs PAT programming). Runtime: runtime.dma.alloc/free (a two-return-value stub, like replyWait). New `dma` kernel test drives the mechanism directly — contiguity, the below-4G cap, coherent mapping, and reclaim-on-teardown (no leak). The thin syscall wrappers follow the tested mmap/mmio_map shape and land their first real use with the first DMA driver. Suite 38/38 plus host tests.
This commit is contained in:
+13
-1
@@ -138,6 +138,13 @@ If a class driver needs `mmio`, it has become an HCD and should be one.
|
||||
table fails `-ENOSPC` and does not half-deliver. This is the "open" primitive — a bus
|
||||
driver mints a per-device endpoint and hands it to a class driver. The runtime exposes
|
||||
`callCap` and `replyWait(..., send_cap)`; no class driver consumes it yet.
|
||||
- **M14** — DMA memory + the memory-ordering layer. `/lib/mmio` gives drivers typed
|
||||
volatile access and `mb`/`rmb`/`wmb` (per-arch); `dma_alloc`/`dma_free` grant
|
||||
physically-contiguous, pinned, uncacheable, reclaim-on-teardown buffers with the
|
||||
physical address exposed (`pmm.allocContiguous`, a DMA arena, `mapUserDmaInto`).
|
||||
`dma_below_4g` caps the address for legacy engines; `dma_write_combining` is accepted
|
||||
but falls back to coherent until PAT is programmed. hpet is refactored onto `/lib/mmio`;
|
||||
no DMA driver consumes `dma_alloc` yet.
|
||||
- **`system_spawn`** — a user-space supervisor starts a driver: `system_spawn(name)`
|
||||
loads a binary bundled in the initial-ramdisk as a fresh ring-3 process. This is what
|
||||
turned the device manager from "log the match" into "run the driver": the kernel now
|
||||
@@ -194,7 +201,12 @@ const dev_ep = ipc.callCap(h, // ... mint a per-device endpoint,
|
||||
// now dev_ep is a private channel to that one device
|
||||
```
|
||||
|
||||
## M14 — DMA memory and the memory-ordering contract, for HCDs
|
||||
## M14 — DMA memory and the memory-ordering contract, for HCDs ✅ done
|
||||
|
||||
*Implemented: `/lib/mmio` (typed volatile access + `mb`/`rmb`/`wmb`, per-arch) and
|
||||
`dma_alloc`/`dma_free` (contiguous, pinned, uncacheable, reclaim-on-teardown, physical
|
||||
address exposed). `dma_write_combining` still falls back to coherent — real WC needs
|
||||
PAT, a small follow-up. The rest of this section is the original design note.*
|
||||
|
||||
**The blocker.** An HCD is a DMA-engine programmer. It needs a descriptor ring the
|
||||
device can read, which means memory that is (a) physically contiguous, (b) at a
|
||||
|
||||
Reference in New Issue
Block a user