Device manager (increment 3): the kernel stops spawning the bundle
Retire the kernel's spawn-every-initial-ramdisk-binary loop, resolving the
service/driver split into a real three-level supervision hierarchy:
kernel -> spawns init (PID 1) only, and publishes the initial-ramdisk
init -> the service supervisor: spawns the system services (vfs, device-manager)
device-manager -> spawns the drivers it matches (hpet)
The kernel now only hands the initial-ramdisk image to the process layer
(publishInitialRamdisk) so user space can system_spawn from it; it launches nothing
bundled itself. init gains a boot-services list ("vfs", "device-manager") and spawns
them best-effort before settling into its heartbeat — policy lives in user space,
where a microkernel keeps it. Drivers are absent from that list on purpose: the
device manager owns them. Test-only binaries (vfs-test, bus) no longer run at boot;
their kernel self-tests still spawn them directly.
This removes increment 2's transitional double-spawn: a real boot now brings hpet up
exactly once (verified — kernel -> init -> vfs/device-manager -> hpet, zero "claim
failed"). The automated suite is unaffected: test builds run their case and halt
before the normal boot path, so each already spawns its own binaries. Suite 36/36
plus host tests; normal boot verified by hand under QEMU.
This commit is contained in:
+17
-28
@@ -11,7 +11,6 @@ const scheduler = @import("scheduler.zig");
|
|||||||
const process = @import("process.zig");
|
const process = @import("process.zig");
|
||||||
const devices_broker = @import("devices-broker.zig");
|
const devices_broker = @import("devices-broker.zig");
|
||||||
const irq = @import("irq.zig");
|
const irq = @import("irq.zig");
|
||||||
const initial_ramdisk = @import("initial-ramdisk");
|
|
||||||
const platform = @import("platform");
|
const platform = @import("platform");
|
||||||
const tests = @import("tests.zig");
|
const tests = @import("tests.zig");
|
||||||
const build_options = @import("build_options");
|
const build_options = @import("build_options");
|
||||||
@@ -272,10 +271,16 @@ fn kmain(boot_information: *const BootInformation) noreturn {
|
|||||||
log.checkpoint(cp_running);
|
log.checkpoint(cp_running);
|
||||||
status("kernel initialised.\n");
|
status("kernel initialised.\n");
|
||||||
|
|
||||||
// Hand over to user space: load /system/services/init (read off the boot volume by the
|
// Publish the initial-ramdisk so user space can `system_spawn` its bundled
|
||||||
// loader) and spawn it as a real ring-3 process, PID 1. It runs on its own
|
// binaries by name. The kernel no longer launches them itself: init is the
|
||||||
// address space, preemptively, alongside the kernel — no cooperative
|
// service supervisor and the device manager spawns the drivers it discovers.
|
||||||
// borrowing. This boot context then becomes the BSP's idle loop.
|
publishInitialRamdisk(boot_information);
|
||||||
|
|
||||||
|
// Hand over to user space: load /system/services/init (read off the boot volume by
|
||||||
|
// the loader) and spawn it as a real ring-3 process, PID 1. As the supervisor it
|
||||||
|
// brings up the system services (the VFS server, the device manager); the device
|
||||||
|
// manager then discovers the hardware and spawns each driver. init runs on its own
|
||||||
|
// address space, preemptively — this boot context becomes the BSP's idle loop.
|
||||||
if (boot_information.init_len != 0) {
|
if (boot_information.init_len != 0) {
|
||||||
status("starting /system/services/init...\n");
|
status("starting /system/services/init...\n");
|
||||||
const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.init_base)))[0..boot_information.init_len];
|
const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.init_base)))[0..boot_information.init_len];
|
||||||
@@ -286,38 +291,22 @@ fn kmain(boot_information: *const BootInformation) noreturn {
|
|||||||
status("no /system/services/init on the boot volume.\n");
|
status("no /system/services/init on the boot volume.\n");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Spawn the extra user binaries the loader ferried in the initial_ramdisk (the VFS
|
|
||||||
// server, and later device drivers). For now the kernel launches them all;
|
|
||||||
// once init is a real service supervisor it will spawn them itself (system_spawn).
|
|
||||||
startInitialRamdiskBinaries(boot_information);
|
|
||||||
|
|
||||||
// Become the idle task: drop below every real task and halt until an
|
// Become the idle task: drop below every real task and halt until an
|
||||||
// interrupt. The timer keeps preempting into init and any other work.
|
// interrupt. The timer keeps preempting into init and any other work.
|
||||||
scheduler.setPriority(0);
|
scheduler.setPriority(0);
|
||||||
status("\nkernel idle; /system/services/init is running.\n");
|
status("\nkernel idle; user space is running.\n");
|
||||||
architecture.halt();
|
architecture.halt();
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Spawn every program bundled in the initial_ramdisk as its own ring-3 process. A bad
|
/// Publish the initial-ramdisk image to the process layer so user space can
|
||||||
/// image or a program that fails to load is logged and skipped — the rest of the
|
/// `system_spawn` its bundled binaries by name. The kernel used to spawn every
|
||||||
/// system still runs.
|
/// bundled program here; now init (the service supervisor) and the device manager
|
||||||
fn startInitialRamdiskBinaries(boot_information: *const boot_handoff.BootInformation) void {
|
/// (drivers) own that, so this only hands the image over — nothing is launched from
|
||||||
|
/// the kernel.
|
||||||
|
fn publishInitialRamdisk(boot_information: *const boot_handoff.BootInformation) void {
|
||||||
if (boot_information.initial_ramdisk_len == 0) return;
|
if (boot_information.initial_ramdisk_len == 0) return;
|
||||||
const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.initial_ramdisk_base)))[0..boot_information.initial_ramdisk_len];
|
const image = @as([*]const u8, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.initial_ramdisk_base)))[0..boot_information.initial_ramdisk_len];
|
||||||
// Hand the image to the process layer so user space can `system_spawn` from it.
|
|
||||||
process.setInitialRamdisk(image);
|
process.setInitialRamdisk(image);
|
||||||
const rd = initial_ramdisk.Reader.init(image) orelse {
|
|
||||||
status("initial_ramdisk: bad image, skipping\n");
|
|
||||||
return;
|
|
||||||
};
|
|
||||||
var i: u32 = 0;
|
|
||||||
while (i < rd.count) : (i += 1) {
|
|
||||||
const item = rd.entry(i) orelse continue;
|
|
||||||
statusPrint("starting {s} (from initial-ramdisk)...\n", .{item.name});
|
|
||||||
process.spawnProcess(item.blob, 4) catch |err| {
|
|
||||||
statusPrint("initial_ramdisk: {s} failed to load: {s}\n", .{ item.name, @errorName(err) });
|
|
||||||
};
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Wake the application processors the firmware left parked. Allocates the low
|
/// Wake the application processors the firmware left parked. Allocates the low
|
||||||
|
|||||||
@@ -4,14 +4,21 @@
|
|||||||
//! kernel (system/kernel/process.zig). It links against the shared user runtime
|
//! kernel (system/kernel/process.zig). It links against the shared user runtime
|
||||||
//! library `runtime` and talks to the kernel only through `runtime`'s system_call wrappers.
|
//! library `runtime` and talks to the kernel only through `runtime`'s system_call wrappers.
|
||||||
//!
|
//!
|
||||||
//! Today it proves the C-convention heap works, then settles into a heartbeat:
|
//! It proves the C-convention heap works, then — as PID 1 — acts as the system's
|
||||||
//! it prints a line and sleeps, forever — enough to show the system reaches user
|
//! **service supervisor**: it spawns the user-space services danos brings up at boot
|
||||||
//! space and stays alive with a real process scheduled alongside the kernel's
|
//! (the VFS server, the device manager), and settles into a heartbeat so it stays
|
||||||
//! idle loop. It grows into the real init (service supervision) once there are
|
//! alive as the root of user space. Drivers are *not* its job: the device manager
|
||||||
//! other user programs to supervise.
|
//! discovers the hardware and spawns those. This is the service half of the
|
||||||
|
//! service/driver spawn split (docs/driver-model.md).
|
||||||
|
|
||||||
const runtime = @import("runtime");
|
const runtime = @import("runtime");
|
||||||
|
|
||||||
|
/// The system services init brings up at boot, in order. This is init's policy — the
|
||||||
|
/// microkernel keeps such choices in user space, not the kernel. Drivers are absent
|
||||||
|
/// on purpose: the device manager owns those. (A future init reads this from a
|
||||||
|
/// manifest under /system/services instead of a hardcoded list.)
|
||||||
|
const boot_services = [_][]const u8{ "vfs", "device-manager" };
|
||||||
|
|
||||||
pub fn main() void {
|
pub fn main() void {
|
||||||
// Prove the heap end to end: allocate through the runtime allocator (which
|
// Prove the heap end to end: allocate through the runtime allocator (which
|
||||||
// mmaps pages from the kernel and carves them with the free list), write into
|
// mmaps pages from the kernel and carves them with the free list), write into
|
||||||
@@ -27,6 +34,13 @@ pub fn main() void {
|
|||||||
gpa.free(buffer);
|
gpa.free(buffer);
|
||||||
} else |_| {}
|
} else |_| {}
|
||||||
|
|
||||||
|
// Bring up the boot services. Best-effort and silent: each service announces its
|
||||||
|
// own readiness (`vfs: ready`, ...), and in an isolation test that runs init with
|
||||||
|
// no initial-ramdisk the spawns simply no-op rather than deranging the heartbeat.
|
||||||
|
for (boot_services) |service| {
|
||||||
|
_ = runtime.system.spawn(service);
|
||||||
|
}
|
||||||
|
|
||||||
while (true) {
|
while (true) {
|
||||||
_ = runtime.system.write("init: heartbeat\n");
|
_ = runtime.system.write("init: heartbeat\n");
|
||||||
runtime.system.sleep(1000);
|
runtime.system.sleep(1000);
|
||||||
|
|||||||
Reference in New Issue
Block a user