establishment: the two-controller proof, and the docs catch up

P4 of docs/establishment-planes-plan.md. The new usb-two-controllers case is
the Ryzen mouse bug pinned in the suite: a second xHCI controller with its
own keyboard while the boot controller keeps the default one — both must
come up, on different device ids, which requires each class driver to reach
ITS OWN controller. Discrimination: at 72807c2 (name-based establishment)
the case fails — one keyboard is unreachable, exactly the bench failure —
verified against a checkout of that merge; with lineage routing it passes.
The existing second-controller cases could not prove this: the boot bus
always carries a keyboard, so their expects were satisfiable by it.

Docs updated with the code: device-manager.md (hello moves the channels,
paged enumerate, delegation as built, reap-and-rebuild in the restart
sequence), device-authority.md (the fourth as-built decision: driver-layer
channels ride the hello; hello is no longer only the liveness handshake).

Full suite: 118/119, the one failure being iommu-fault's fixed 200 ms
fault window under end-of-run host load — 3/3 green standalone, deflake
flagged separately. usb-two-controllers passed inside the full run.
This commit is contained in:
Daniel Samson
2026-08-09 12:48:33 +01:00
parent 8710944a92
commit 3c9f454398
3 changed files with 67 additions and 13 deletions
+12
View File
@@ -173,3 +173,15 @@ Three details settled differently, or beyond, what the sections above say:
unconfined forever. Both give paths (`device_transfer` and spawn's give) share one
body in [process.zig](../../system/kernel/process.zig) (`giveDeviceLocked`), and the
`iommu` kernel test drives the death-and-respawn sequence against it directly.
A fourth followed on 2026-08-09, when a real three-controller machine broke the last
name-shaped assumption ([communication.md](communication.md) "Establishment: two
planes, one namespace"): **driver-layer channels ride the same hello.** A driver's
serving endpoint goes up as the hello's capability; consumers get their provider's
channel down in the reply, routed by the manager's lineage — the reporter for a
class driver, the bound driver for a `.consumer`. `usb-transfer` and `block`
stopped being registry names, and a reporter's death now reaps its class-driver
subtree so the re-report can rebuild it against the successor — the manager half of
the loan story above. One correction to the earlier bullet: `hello` is no longer
*only* the liveness handshake; it is also where establishment happens. The device
itself still arrives with the spawn.