establishment: block stops being a name, and enumerate learns to page

P2 of docs/establishment-planes-plan.md. usb-storage serves nameless — one
process per stick cannot share an exclusive bind, and a second stick used to
die silently on -EBUSY before ever helloing. Its one hello now moves both
directions at once: the block-serving endpoint up, its controller channel
down. fat finds its volume through the manager — a new `.consumer` role asks
for the channel of the driver BOUND TO a device (distinct from the device's
reporter), found by enumerating the tree for the mass-storage identity.
fat stays single-volume; the boot-volume-by-content choice is M21.

The conversion immediately caught a live truncation of exactly the audit's
shape: ChildEntry grew to 32 bytes, one enumerate reply holds ~7, and a real
tree carries a dozen ACPI nodes before the first USB child — the storage
entry silently never fit (the protocol comment already said "paging joins
the protocol if a tree ever outgrows one packet"). enumerate is now paged:
Header.target is the start cursor, a short page is the end; device-list's
page-0 read is unchanged.

Grant rows move with the code: the block bind and fat's block open die, fat
gains open device-manager. Gate: 18 cases green including the registry
trio, device-list, and both IOMMU storage variants.
This commit is contained in:
Daniel Samson
2026-08-09 12:24:25 +01:00
parent d603d40b5c
commit 1d7850239d
10 changed files with 155 additions and 61 deletions
+10 -5
View File
@@ -82,10 +82,13 @@ fn transact(cdb: []const u8, direction_in: bool, data_physical: u64, data_length
var bring_up_failed = false;
fn initialise(endpoint: ipc.Handle) bool {
_ = endpoint;
// The hello both meets the spawn deadline and brings back the channel to
// THIS device's controller — routed by lineage, never found by name.
const bus = device_manager.helloForChannel(.device, device_id) orelse return false;
// One hello, both directions: the block-serving endpoint goes UP (the
// manager routes fat's consumer hello here — this driver serves one
// volume, one process per stick, so `block` is never a registry name),
// and the channel to THIS device's controller comes DOWN, routed by
// lineage. A second stick used to die silently on the exclusive bind;
// now every instance is reachable through its lineage.
const bus = device_manager.helloForChannel(.device, device_id, endpoint) orelse return false;
device = usb.open(bus, device_id) orelse {
std.log.info("could not open device {d}", .{device_id});
return false;
@@ -224,8 +227,10 @@ pub fn main(init: process.Init) void {
std.log.info("malformed device id '{s}'", .{argument});
return;
};
// No `.service` name: several instances provide the block contract (one
// per stick), so consumers are routed here by the device manager's
// lineage, never by a registry bind — the endpoint goes up in the hello.
service.run(block_protocol.message_maximum, .{
.service = "block",
.init = initialise,
.on_message = onMessage,
});