volume-manager: the flip — fat is spawned, confined, and handed its channel (V3b)
The load-bearing step. The FAT service stops acquiring its own volume: the volume manager spawns it (per volume), defines its partition range on the storage driver BEFORE it runs, and answers its startup hello with the range-confined block channel over a new volume-manager protocol. fat never finds its storage by name and never sees the whole device — establishment by lineage, one layer up from the driver tree. - New library/protocol/volume-manager: one verb, hello(volume-id) -> the block channel as the reply capability (the P0 reply-cap path). - The volume manager becomes the confinement CONTROLLER: it defines the first range on usb-storage, so no other party can confine a filesystem. It supervises the filesystems it spawns and respawns one on death (the reap- and-rebuild the device manager proved, one layer up). - fat: drops acquireVolume(device-manager); hellos the volume manager for its channel; reads its volume id from argv[1]. main takes process.Init now. - init.csv no longer spawns fat (the volume manager does); protocol.csv rewires fat to be supervised by the volume manager (bind vfs, open volume-manager) and drops fat open device-manager. - The block-range fixture boots registry + device-manager only (not the full tree), so the volume manager is absent and the fixture stays the sole confinement definer — otherwise the volume manager would take the controller first and refuse it. Verified end to end (VM probes -> spawns fat -> confines it -> hands over the channel -> fat mounts) and neutral: 18/18 across the fat family, logging, shutdown, both IOMMU variants, usb restart, vfs, conformance, confinement.
This commit is contained in:
@@ -14,8 +14,9 @@
|
||||
# service args...
|
||||
/system/services/input
|
||||
/system/services/device-manager
|
||||
# fat is not here: the volume manager spawns one filesystem per volume it finds,
|
||||
# confined to that volume's partition (docs/file-system-development/storage-architecture.md).
|
||||
/system/services/volume-manager
|
||||
/system/services/fat
|
||||
/system/services/display
|
||||
/system/services/display-demo
|
||||
/system/services/logger
|
||||
|
||||
|
@@ -56,7 +56,9 @@
|
||||
/system/services/input, /system/services/init, bind, input
|
||||
/system/services/device-manager, /system/services/init, bind, device-manager
|
||||
/system/services/volume-manager, /system/services/init, bind, volume-manager
|
||||
/system/services/fat, /system/services/init, bind, vfs
|
||||
# fat is spawned and supervised by the volume manager now, not init — the volume
|
||||
# manager confines it to its partition and hands it the block channel.
|
||||
/system/services/fat, /system/services/volume-manager, bind, vfs
|
||||
/system/services/display, /system/services/init, bind, display
|
||||
|
||||
# The discovery service ships under one neutral name per firmware (docs/discovery.md);
|
||||
@@ -95,14 +97,13 @@
|
||||
# ============================================================================
|
||||
|
||||
# --- init's own services ----------------------------------------------------
|
||||
# fat reaches the device manager to be routed to its volume's block provider
|
||||
# (block is not a name — see the bind section); the compositor reaches the
|
||||
# scanout its driver announced, its own endpoint (the mouse-listener thread
|
||||
# opens /protocol/display like any other client — threads share no handles),
|
||||
# and the input stream that moves the cursor.
|
||||
/system/services/fat, /system/services/init, open, device-manager
|
||||
# fat reaches the volume manager to be handed its volume's block channel
|
||||
# (range-confined); the compositor reaches the scanout its driver announced, its
|
||||
# own endpoint (the mouse-listener thread opens /protocol/display like any other
|
||||
# client — threads share no handles), and the input stream that moves the cursor.
|
||||
/system/services/fat, /system/services/volume-manager, open, volume-manager
|
||||
# The volume manager reaches the device manager to be routed to each storage
|
||||
# provider's block channel, the same lineage acquisition fat makes today.
|
||||
# provider's block channel, then confines a filesystem to each volume.
|
||||
/system/services/volume-manager, /system/services/init, open, device-manager
|
||||
/system/services/display, /system/services/init, open, scanout
|
||||
/system/services/display, /system/services/init, open, display
|
||||
|
||||
|
Can't render this file because it contains an unexpected character in line 12 and column 15.
|
Reference in New Issue
Block a user