kernel: record who gave each device away

One field, and the rest of the run follows from it. A device that was given
to someone is delegated hardware: it may be handed on, never taken, and when
its holder dies it goes back to whoever lent it instead of becoming free for
anyone to grab.

It also settles the framebuffer without mentioning it. Nobody delegates the
loader's framebuffer, so it has no giver, so the display service claims it
exactly as it always has — no exemption and no reference to display anywhere
in the rule.

No behaviour changes here; the field is recorded and read by nothing yet.

The test found a real bug on its first run, before the discrimination check.
The sentinel for "nobody gave this" was 0 — and task 0 is a real task, the
kernel's own, so a device given away by task 0 read back as belonging to
nobody. Both giver and registrar are optionals now. The second was a latent
bug from D9: the per-registrar allowance would have miscounted every device
task 0 registered.

Suite 118/118.
This commit is contained in:
Daniel Samson
2026-08-08 22:12:01 +01:00
parent ca1126537d
commit 4ca57fc37e
3 changed files with 46 additions and 7 deletions
+1 -1
View File
@@ -124,7 +124,7 @@ Two things fall out rather than being special-cased:
| Step | What |
|---|---|
| E1 | Record a giver per device; `device_transfer` and the spawn grant set it |
| E1 | Record a giver per device; `device_transfer` and the spawn grant set it — **done** |
| E2 | On task death a device reverts to its giver if alive, else its claim clears |
| E3 | `device_claim` refuses a device that has a giver |
| E4 | The manager claims every resource-bearing device at boot, so nothing is left takeable |