isolation M1: ring 3 + a real /sbin/init, end to end

Ring 3 works: user GDT descriptors (sysret-ready layout), TSS.rsp0,
U/S-bit user mappings (W^X preserved), an int 0x80 syscall gate with a
mutable trap frame, and a setjmp-style enter/exit path. /sbin/init is a
real freestanding Zig binary built from sbin/, shipped on the ESP,
loaded by the bootloader (BootInfo.init_base/len), validated and mapped
by an in-kernel user-ELF loader, and run at CPL 3 — syscalls: exit,
ping, write. Tests: user, user-pf (U/S isolation proof, error code
0x5), init. Suite 27/27.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Daniel Samson
2026-07-08 22:15:07 +01:00
co-authored by Claude Fable 5
parent 7501bd1703
commit 546dd44a2a
17 changed files with 838 additions and 25 deletions
+8 -3
View File
@@ -81,11 +81,16 @@ prerequisites.
(with boot-services memory reclaimed), [paging](paging.md) with W^X, [exceptions and
interrupts](interrupts.md), a [calibrated timer + ns clock](device-interrupts.md), a
[heap](heap.md), a [fixed-priority preemptive scheduler](scheduling.md) with blocking,
and in-kernel [IPC channels](ipc.md) — plus a [test harness](testing.md).
in-kernel [IPC channels](ipc.md), SMP (all cores scheduling, with affinity), and
**ring 3**: user GDT/TSS plumbing, U/S-bit mappings, an `int 0x80` syscall gate, and
`/sbin/init` — a real user ELF built from `sbin/`, shipped on the boot volume, loaded
by the kernel, run at CPL 3 — plus a [test harness](testing.md).
- **Isolation track** — **user mode + address-space isolation** (higher-half kernel,
ring 3, per-process page tables). The substrate everything else needs. *Next, and a
prerequisite for the resilience and driver tracks.*
ring 3, per-process page tables). The substrate everything else needs. *In
progress: ring 3 + a loaded `/sbin/init` work (M1); next the higher-half move (M2),
then per-process address spaces + `syscall`/`sysret` + init as a real schedulable
process (M3), then ELF/initrd generalisation (M4).*
- **Resilience track** — fault → kill → notify, a supervisor/reincarnation server,
resource cleanup on death, then a restartable driver as proof. Needs isolation.
See [resilience.md](resilience.md).