Phase 1a: add the native runtime.fs, retire the posix shim

The first step of the Zig self-hosting roadmap (docs/zig-self-hosting.md): give
danos programs a danos-native file API and remove the premature POSIX compatibility
shim. This also resolves the earlier misplacement of a full-write helper into the
compat layer — that behaviour now lives natively in runtime.fs.File.writeAll.

- library/runtime/fs.zig: the danos-native file client over the VFS (open/read/
  write/writeAll/seekTo/attributes/close, directory listing, mount). Handles are
  *values* — a File/Directory owns its VFS node id and byte offset — so there is no
  per-process fd table or descriptor limit, unlike the POSIX fd model the shim
  emulated. This is where the operations that later become std.os.danos are staged.
- Retire library/posix/ (unistd, stdio): only five call sites used it, all file
  operations, all migrated to runtime.fs — fat (mount), the vfs-test and fat-test
  clients, and init/log-flush (the boot-log flush). stdio was already dead.
- build.zig: drop the posix module, its addUserBinary parameter, the per-binary
  import, and the ~26 call-site arguments.
- Docs: the VFS protocol's client is now runtime.fs; the docs index and
  coding-standards note posix is retired and the foreign-ABI naming exception now
  applies to the future std.os.danos seam; the process-lifecycle note points the
  future musl layer at that same seam rather than the deleted directory.

Deferred by design (see the roadmap): the C-ABI runtime.os errno seam is built at
fork time (its shape must match std/os/danos.zig); truncate/mkdir/rename are
Phase 2; stdio-byte fds and cwd are later slices.

Verified: zig build, zig build test, zig build check-fat-image, and a sequential
QEMU sweep — vfs, vfs-client-death (the park/hold-handle path), fat-mount, log-flush,
orderly-shutdown, initial-ramdisk (log-flush silent in the bare sweep), smoke, init,
usb-storage, device-manager — all green.
This commit is contained in:
Daniel Samson
2026-07-13 19:43:56 +01:00
parent 53e42837e0
commit 347a041d85
15 changed files with 347 additions and 471 deletions
+15 -15
View File
@@ -6,6 +6,7 @@
const std = @import("std");
const runtime = @import("runtime");
const fs = runtime.fs;
fn writeLine(comptime fmt: []const u8, arguments: anytype) void {
var line: [128]u8 = undefined;
@@ -14,38 +15,37 @@ fn writeLine(comptime fmt: []const u8, arguments: anytype) void {
pub fn main(init: runtime.process.Init) void {
_ = init;
const unistd = @import("posix").unistd;
// Wait for /mnt/usb to be mounted — the fat server races us at boot (it must
// bring up the whole USB storage chain first).
var dir: i32 = -1;
var opened: ?fs.Directory = null;
var tries: u32 = 0;
while (dir < 0 and tries < 1400) : (tries += 1) {
dir = unistd.opendir("/mnt/usb");
if (dir < 0) runtime.system.sleep(50);
while (opened == null and tries < 1400) : (tries += 1) {
opened = fs.openDirectory("/mnt/usb");
if (opened == null) runtime.system.sleep(50);
}
if (dir < 0) {
var dir = opened orelse {
_ = runtime.system.write("fat-test: /mnt/usb never became available\n");
return;
}
};
var count: u32 = 0;
var entry: unistd.DirEntry = .{};
while (unistd.readdir(dir, &entry)) {
writeLine("fat-test: entry '{s}' kind={d} size={d}\n", .{ entry.name(), entry.kind, entry.size });
var entry: fs.Entry = .{};
while (dir.next(&entry)) {
writeLine("fat-test: entry '{s}' kind={d} size={d}\n", .{ entry.name(), @intFromEnum(entry.kind), entry.size });
count += 1;
if (count > 32) break;
}
unistd.closedir(dir);
dir.close();
writeLine("fat-test: listed {d} entries\n", .{count});
// Read a known file off the boot volume through the mount (best effort): the
// kernel image is an ELF, so its first bytes are the ELF magic.
const fd = unistd.open("/mnt/usb/system/kernel", 0);
if (fd >= 0) {
if (fs.open("/mnt/usb/system/kernel", .{})) |opened_file| {
var file = opened_file;
var magic: [4]u8 = undefined;
const n = unistd.read(fd, &magic);
unistd.close(fd);
const n = file.read(&magic) orelse 0;
file.close();
if (n == 4 and magic[0] == 0x7F and magic[1] == 'E' and magic[2] == 'L' and magic[3] == 'F') {
_ = runtime.system.write("fat-test: read /mnt/usb/system/kernel ELF magic ok\n");
} else {
+1 -2
View File
@@ -14,7 +14,6 @@ const runtime = @import("runtime");
const engine = @import("engine.zig");
const on_disk = @import("on-disk.zig");
const protocol = runtime.vfs_protocol;
const unistd = @import("posix").unistd;
const dma = runtime.dma;
fn writeLine(comptime fmt: []const u8, arguments: anytype) void {
@@ -106,7 +105,7 @@ fn initialise(endpoint: runtime.ipc.Handle) bool {
// comes up). From here the VFS routes /mnt/usb/... to this server.
var tries: u32 = 0;
while (tries < 100) : (tries += 1) {
if (unistd.mount(mount_point, endpoint) == 0) {
if (runtime.fs.mount(mount_point, endpoint)) {
writeLine("/system/services/fat: mounted {s}\n", .{mount_point});
return true;
}
+3 -5
View File
@@ -19,7 +19,6 @@
const std = @import("std");
const runtime = @import("runtime");
const unistd = @import("posix").unistd;
const power = runtime.power_protocol;
/// Where the kernel boot log is persisted on the USB FAT volume — an 8.3 name at
@@ -134,15 +133,14 @@ fn subscribePower() void {
/// USB volume is not mounted, the open fails and it does nothing. Must run while
/// the storage services are still alive (see shutDown).
fn flushKernelLog() void {
const fd = unistd.open(log_path, unistd.O_CREAT);
if (fd < 0) return; // no USB volume mounted — nothing to persist to
defer unistd.close(fd);
var file = runtime.fs.open(log_path, .{ .create = true }) orelse return; // no USB volume mounted
defer file.close();
var chunk: [4096]u8 = undefined;
var offset: usize = 0;
while (true) {
const got = runtime.system.klogRead(offset, &chunk);
if (got == 0) break; // reached the end of the accumulated log
if (unistd.writeAll(fd, chunk[0..got]) < 0) break; // storage went away
if (file.writeAll(chunk[0..got]) == null) break; // storage went away
offset += got;
}
var line: [96]u8 = undefined;
+18 -15
View File
@@ -16,19 +16,19 @@
const std = @import("std");
const runtime = @import("runtime");
const unistd = @import("posix").unistd;
const fs = runtime.fs;
const log_path = "/mnt/usb/DANOS.LOG";
/// Copy the whole kernel log to the open fd, looping klog_read -> write until the
/// log is exhausted. Returns the number of bytes written.
fn drainKernelLog(fd: i32) usize {
/// Copy the whole kernel log to the open file, looping klog_read -> write until
/// the log is exhausted. Returns the number of bytes written.
fn drainKernelLog(file: *fs.File) usize {
var chunk: [4096]u8 = undefined;
var offset: usize = 0;
while (true) {
const got = runtime.system.klogRead(offset, &chunk);
if (got == 0) break; // reached the end of the accumulated log
if (unistd.writeAll(fd, chunk[0..got]) < 0) break; // storage went away
if (file.writeAll(chunk[0..got]) == null) break; // storage went away
offset += got;
}
return offset;
@@ -38,19 +38,22 @@ pub fn main() void {
// Wait for the fat server to mount /mnt/usb (it must bring up the whole USB
// storage chain first, so it races us at boot). Bounded: if the mount never
// appears — no volume, or the no-VFS ramdisk sweep — give up silently.
var dir: i32 = -1;
var ready = false;
var tries: u32 = 0;
while (dir < 0 and tries < 1400) : (tries += 1) {
dir = unistd.opendir("/mnt/usb");
if (dir < 0) runtime.system.sleep(50);
while (tries < 1400) : (tries += 1) {
if (fs.openDirectory("/mnt/usb")) |directory| {
var dir = directory;
dir.close();
ready = true;
break;
}
runtime.system.sleep(50);
}
if (dir < 0) return; // /mnt/usb never became available — nothing to persist to
unistd.closedir(dir);
if (!ready) return; // /mnt/usb never became available — nothing to persist to
const fd = unistd.open(log_path, unistd.O_CREAT);
if (fd < 0) return; // could not create the file — exit quietly
const written = drainKernelLog(fd);
unistd.close(fd);
var file = fs.open(log_path, .{ .create = true }) orelse return; // could not create the file
const written = drainKernelLog(&file);
file.close();
var line: [96]u8 = undefined;
_ = runtime.system.write(std.fmt.bufPrint(&line, "log-flush: wrote {d} bytes to {s}\n", .{ written, log_path }) catch return);
+3 -4
View File
@@ -4,12 +4,11 @@
//! header followed by an inline payload (read bytes, or a FileStatus). Everything fits
//! in one IPC message (<= ipc MESSAGE_MAXIMUM = 256 bytes).
//!
//! This is a danos-native contract, so it uses danos names throughout — the POSIX
//! spellings (`stat`, `O_CREAT`, ...) live only in the POSIX layer
//! (library/posix/unistd.zig), which translates to these.
//! This is a danos-native contract, so it uses danos names throughout. The client
//! side is `runtime.fs` (library/runtime/fs.zig), which programs use directly.
//!
//! This is user-space only — the kernel knows nothing of files or paths; it only moves the bytes.
//! Shared by library/posix/unistd.zig (client) and system/services/vfs/vfs.zig (server).
//! Shared by library/runtime/fs.zig (client) and system/services/vfs/vfs.zig (server).
pub const Operation = enum(u32) {
open, // open(path) -> node id
+18 -18
View File
@@ -1,26 +1,26 @@
//! /system/services/vfs/vfs-test — a client that proves the VFS round trip end to end: open a
//! file through the `runtime` file API, write to it, seek back, read it, and compare.
//! file through the `runtime.fs` file API, write to it, seek back, read it, and compare.
//! On success it heartbeats "vfstest: ok" so the kernel test can observe it;
//! on failure it reports what went wrong. Shipped in the initial_ramdisk alongside vfs.
const std = @import("std");
const runtime = @import("runtime");
const fs = runtime.fs;
pub fn main(init: runtime.process.Init) void {
const u = @import("posix").unistd;
const payload = "hello-vfs";
// The "park" role (the vfs-client-death test): open a file, then hold the
// handle forever without closing — the kill and the VFS's release-on-death
// are the point.
if (init.arguments.count > 1) {
var fd: i32 = -1;
var parked: ?fs.File = null;
var tries: u32 = 0;
while (fd < 0 and tries < 200) : (tries += 1) {
fd = u.open("parked", u.O_CREAT);
if (fd < 0) runtime.system.sleep(20);
while (parked == null and tries < 200) : (tries += 1) {
parked = fs.open("parked", .{ .create = true });
if (parked == null) runtime.system.sleep(20);
}
if (fd < 0) {
if (parked == null) {
_ = runtime.system.write("vfstest: park open failed\n");
return;
}
@@ -31,28 +31,28 @@ pub fn main(init: runtime.process.Init) void {
}
// The VFS server may not have registered yet — retry open until it's up.
var fd: i32 = -1;
var opened: ?fs.File = null;
var tries: u32 = 0;
while (fd < 0 and tries < 200) : (tries += 1) {
fd = u.open("greeting", u.O_CREAT);
if (fd < 0) runtime.system.sleep(20);
while (opened == null and tries < 200) : (tries += 1) {
opened = fs.open("greeting", .{ .create = true });
if (opened == null) runtime.system.sleep(20);
}
if (fd < 0) {
var greeting = opened orelse {
_ = runtime.system.write("vfstest: open failed\n");
return;
}
};
if (u.write(fd, payload) != @as(isize, payload.len)) {
if ((greeting.write(payload) orelse 0) != payload.len) {
_ = runtime.system.write("vfstest: write failed\n");
return;
}
_ = u.lseek(fd, 0, u.SEEK_SET);
greeting.seekTo(0);
var buffer: [32]u8 = undefined;
const n = u.read(fd, &buffer);
u.close(fd);
const n = greeting.read(&buffer) orelse 0;
greeting.close();
if (n == @as(isize, payload.len) and std.mem.eql(u8, buffer[0..@intCast(n)], payload)) {
if (n == payload.len and std.mem.eql(u8, buffer[0..n], payload)) {
while (true) {
_ = runtime.system.write("vfstest: ok\n");
runtime.system.sleep(1000);