From 56110b0019b84e78a112f166a7a6d02b9e651fc9 Mon Sep 17 00:00:00 2001 From: Daniel Samson <12231216+daniel-samson@users.noreply.github.com> Date: Fri, 10 Jul 2026 18:36:07 +0100 Subject: [PATCH] Device manager (increment 3): the kernel stops spawning the bundle MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Retire the kernel's spawn-every-initial-ramdisk-binary loop, resolving the service/driver split into a real three-level supervision hierarchy: kernel -> spawns init (PID 1) only, and publishes the initial-ramdisk init -> the service supervisor: spawns the system services (vfs, device-manager) device-manager -> spawns the drivers it matches (hpet) The kernel now only hands the initial-ramdisk image to the process layer (publishInitialRamdisk) so user space can system_spawn from it; it launches nothing bundled itself. init gains a boot-services list ("vfs", "device-manager") and spawns them best-effort before settling into its heartbeat — policy lives in user space, where a microkernel keeps it. Drivers are absent from that list on purpose: the device manager owns them. Test-only binaries (vfs-test, bus) no longer run at boot; their kernel self-tests still spawn them directly. This removes increment 2's transitional double-spawn: a real boot now brings hpet up exactly once (verified — kernel -> init -> vfs/device-manager -> hpet, zero "claim failed"). The automated suite is unaffected: test builds run their case and halt before the normal boot path, so each already spawns its own binaries. Suite 36/36 plus host tests; normal boot verified by hand under QEMU. --- system/kernel/kernel.zig | 45 +++++++++++++---------------------- system/services/init/init.zig | 24 +++++++++++++++---- 2 files changed, 36 insertions(+), 33 deletions(-) diff --git a/system/kernel/kernel.zig b/system/kernel/kernel.zig index 7b83e0b..478ca60 100644 --- a/system/kernel/kernel.zig +++ b/system/kernel/kernel.zig @@ -11,7 +11,6 @@ const scheduler = @import("scheduler.zig"); const process = @import("process.zig"); const devices_broker = @import("devices-broker.zig"); const irq = @import("irq.zig"); -const initial_ramdisk = @import("initial-ramdisk"); const platform = @import("platform"); const tests = @import("tests.zig"); const build_options = @import("build_options"); @@ -272,10 +271,16 @@ fn kmain(boot_information: *const BootInformation) noreturn { log.checkpoint(cp_running); status("kernel initialised.\n"); - // Hand over to user space: load /system/services/init (read off the boot volume by the - // loader) and spawn it as a real ring-3 process, PID 1. It runs on its own - // address space, preemptively, alongside the kernel — no cooperative - // borrowing. This boot context then becomes the BSP's idle loop. + // Publish the initial-ramdisk so user space can `system_spawn` its bundled + // binaries by name. The kernel no longer launches them itself: init is the + // service supervisor and the device manager spawns the drivers it discovers. + publishInitialRamdisk(boot_information); + + // Hand over to user space: load /system/services/init (read off the boot volume by + // the loader) and spawn it as a real ring-3 process, PID 1. As the supervisor it + // brings up the system services (the VFS server, the device manager); the device + // manager then discovers the hardware and spawns each driver. init runs on its own + // address space, preemptively — this boot context becomes the BSP's idle loop. if (boot_information.init_len != 0) { status("starting /system/services/init...\n"); const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.init_base)))[0..boot_information.init_len]; @@ -286,38 +291,22 @@ fn kmain(boot_information: *const BootInformation) noreturn { status("no /system/services/init on the boot volume.\n"); } - // Spawn the extra user binaries the loader ferried in the initial_ramdisk (the VFS - // server, and later device drivers). For now the kernel launches them all; - // once init is a real service supervisor it will spawn them itself (system_spawn). - startInitialRamdiskBinaries(boot_information); - // Become the idle task: drop below every real task and halt until an // interrupt. The timer keeps preempting into init and any other work. scheduler.setPriority(0); - status("\nkernel idle; /system/services/init is running.\n"); + status("\nkernel idle; user space is running.\n"); architecture.halt(); } -/// Spawn every program bundled in the initial_ramdisk as its own ring-3 process. A bad -/// image or a program that fails to load is logged and skipped — the rest of the -/// system still runs. -fn startInitialRamdiskBinaries(boot_information: *const boot_handoff.BootInformation) void { +/// Publish the initial-ramdisk image to the process layer so user space can +/// `system_spawn` its bundled binaries by name. The kernel used to spawn every +/// bundled program here; now init (the service supervisor) and the device manager +/// (drivers) own that, so this only hands the image over — nothing is launched from +/// the kernel. +fn publishInitialRamdisk(boot_information: *const boot_handoff.BootInformation) void { if (boot_information.initial_ramdisk_len == 0) return; const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.initial_ramdisk_base)))[0..boot_information.initial_ramdisk_len]; - // Hand the image to the process layer so user space can `system_spawn` from it. process.setInitialRamdisk(image); - const rd = initial_ramdisk.Reader.init(image) orelse { - status("initial_ramdisk: bad image, skipping\n"); - return; - }; - var i: u32 = 0; - while (i < rd.count) : (i += 1) { - const item = rd.entry(i) orelse continue; - statusPrint("starting {s} (from initial-ramdisk)...\n", .{item.name}); - process.spawnProcess(item.blob, 4) catch |err| { - statusPrint("initial_ramdisk: {s} failed to load: {s}\n", .{ item.name, @errorName(err) }); - }; - } } /// Wake the application processors the firmware left parked. Allocates the low diff --git a/system/services/init/init.zig b/system/services/init/init.zig index 00901d3..e9f656c 100644 --- a/system/services/init/init.zig +++ b/system/services/init/init.zig @@ -4,14 +4,21 @@ //! kernel (system/kernel/process.zig). It links against the shared user runtime //! library `runtime` and talks to the kernel only through `runtime`'s system_call wrappers. //! -//! Today it proves the C-convention heap works, then settles into a heartbeat: -//! it prints a line and sleeps, forever — enough to show the system reaches user -//! space and stays alive with a real process scheduled alongside the kernel's -//! idle loop. It grows into the real init (service supervision) once there are -//! other user programs to supervise. +//! It proves the C-convention heap works, then — as PID 1 — acts as the system's +//! **service supervisor**: it spawns the user-space services danos brings up at boot +//! (the VFS server, the device manager), and settles into a heartbeat so it stays +//! alive as the root of user space. Drivers are *not* its job: the device manager +//! discovers the hardware and spawns those. This is the service half of the +//! service/driver spawn split (docs/driver-model.md). const runtime = @import("runtime"); +/// The system services init brings up at boot, in order. This is init's policy — the +/// microkernel keeps such choices in user space, not the kernel. Drivers are absent +/// on purpose: the device manager owns those. (A future init reads this from a +/// manifest under /system/services instead of a hardcoded list.) +const boot_services = [_][]const u8{ "vfs", "device-manager" }; + pub fn main() void { // Prove the heap end to end: allocate through the runtime allocator (which // mmaps pages from the kernel and carves them with the free list), write into @@ -27,6 +34,13 @@ pub fn main() void { gpa.free(buffer); } else |_| {} + // Bring up the boot services. Best-effort and silent: each service announces its + // own readiness (`vfs: ready`, ...), and in an isolation test that runs init with + // no initial-ramdisk the spawns simply no-op rather than deranging the heartbeat. + for (boot_services) |service| { + _ = runtime.system.spawn(service); + } + while (true) { _ = runtime.system.write("init: heartbeat\n"); runtime.system.sleep(1000);