establishment: the two-controller proof, and the docs catch up
P4 of docs/establishment-planes-plan.md. The new usb-two-controllers case is
the Ryzen mouse bug pinned in the suite: a second xHCI controller with its
own keyboard while the boot controller keeps the default one — both must
come up, on different device ids, which requires each class driver to reach
ITS OWN controller. Discrimination: at 72807c2 (name-based establishment)
the case fails — one keyboard is unreachable, exactly the bench failure —
verified against a checkout of that merge; with lineage routing it passes.
The existing second-controller cases could not prove this: the boot bus
always carries a keyboard, so their expects were satisfiable by it.
Docs updated with the code: device-manager.md (hello moves the channels,
paged enumerate, delegation as built, reap-and-rebuild in the restart
sequence), device-authority.md (the fourth as-built decision: driver-layer
channels ride the hello; hello is no longer only the liveness handshake).
Full suite: 118/119, the one failure being iommu-fault's fixed 200 ms
fault window under end-of-run host load — 3/3 green standalone, deflake
flagged separately. usb-two-controllers passed inside the full run.
This commit is contained in:
@@ -173,3 +173,15 @@ Three details settled differently, or beyond, what the sections above say:
|
||||
unconfined forever. Both give paths (`device_transfer` and spawn's give) share one
|
||||
body in [process.zig](../../system/kernel/process.zig) (`giveDeviceLocked`), and the
|
||||
`iommu` kernel test drives the death-and-respawn sequence against it directly.
|
||||
|
||||
A fourth followed on 2026-08-09, when a real three-controller machine broke the last
|
||||
name-shaped assumption ([communication.md](communication.md) "Establishment: two
|
||||
planes, one namespace"): **driver-layer channels ride the same hello.** A driver's
|
||||
serving endpoint goes up as the hello's capability; consumers get their provider's
|
||||
channel down in the reply, routed by the manager's lineage — the reporter for a
|
||||
class driver, the bound driver for a `.consumer`. `usb-transfer` and `block`
|
||||
stopped being registry names, and a reporter's death now reaps its class-driver
|
||||
subtree so the re-report can rebuild it against the successor — the manager half of
|
||||
the loan story above. One correction to the earlier bullet: `hello` is no longer
|
||||
*only* the liveness handshake; it is also where establishment happens. The device
|
||||
itself still arrives with the spawn.
|
||||
|
||||
Reference in New Issue
Block a user