docs: device-authority as built — spawn carries the device, the loan, confinement rebuilt on return
This commit is contained in:
@@ -149,3 +149,27 @@ on one nobody holds, and is refused each time with its own errno.
|
||||
|
||||
The Ryzen is the acceptance test for the ceiling half: it is the machine that found the
|
||||
constants, and the one that proves them gone.
|
||||
|
||||
## As built (2026-08-09)
|
||||
|
||||
Three details settled differently, or beyond, what the sections above say:
|
||||
|
||||
- **The device arrives with the spawn, not in the `hello` reply.** `system_spawn` grew a
|
||||
sixth argument: the manager names the device it is giving, the kernel verifies the
|
||||
caller holds it before the child exists, and the child holds it before its first
|
||||
instruction. A give that fails after the spawn (the device stopped being the giver's,
|
||||
or its confinement was refused) kills the child — a driver running without the
|
||||
hardware it was spawned for is worse than no driver. `hello` stays what it was: the
|
||||
liveness handshake.
|
||||
- **A given device is a loan.** When the holder dies, the device returns to the giver if
|
||||
the giver is still alive — so a respawned driver is handed the same device by its
|
||||
manager instead of racing anyone for a released claim. Only if the lender is also dead
|
||||
does the device become unheld.
|
||||
- **Confinement moves with the device, and is rebuilt when the loan comes back.** A
|
||||
transfer re-points the existing IOMMU record; but a death tears the domain down
|
||||
*before* the loan returns, so the next delegation of that device finds no record and
|
||||
confines afresh — under the same fail-closed rule as a first claim (`ECONFINE`, the
|
||||
give does not stand). Without that, one driver crash left its device silently
|
||||
unconfined forever. Both give paths (`device_transfer` and spawn's give) share one
|
||||
body in [process.zig](../../system/kernel/process.zig) (`giveDeviceLocked`), and the
|
||||
`iommu` kernel test drives the death-and-respawn sequence against it directly.
|
||||
|
||||
Reference in New Issue
Block a user