pci: the host bridge arrives by delegation too
pci-bus joins usb-xhci-bus in receiving its device from the manager rather
than claiming the id it found in argv[1]. Its hello moves ahead of the ECAM
mapping, since that is where the bridge now arrives, and its hello was
already mandatory so nothing about its failure behaviour changes.
isDelegated compared whole strings, which silently missed this driver: the
manager records the boot-snapshot match as the bare "pci-bus" and a
devices.csv match as the full "/system/drivers/pci-bus". pci-bus was then
neither claiming nor delegated and died on "ECAM mmio_map failed". It now
matches on the last path component. Reintroducing the whole-string compare
breaks usb-xhci-bus instead of pci-bus — the two spellings swap which driver
loses — so usb-hid is the case that catches it, not pci-scan.
pci-scan asserts the delegation on the initial bring-up AND after the
restart drill, with the device id backreferenced so both must name the same
device. That is what proves the manager re-takes a device when its driver
dies and hands it to the replacement, which is the property the whole
supervision design rests on.
The remaining three claimants are NOT converted, and the plan records why
rather than working around it. ps2-bus and the acpi service never hello at
all, which device-manager.md states deliberately ("legacy drivers ... not
yet required to hello"), so delegating to them means either promoting them
out of legacy or giving the grant a delivery point that is not hello.
virtio-gpu hellos best-effort by design — "standalone bring-up has no
manager" — and delegation would make it mandatory. Both are decisions, not
mechanical steps.
Consequence: D6 is blocked, because device_claim cannot be closed off while
three claimants still depend on it. D7-D9 are unaffected — they concern what
the kernel stores and how its table is sized.
Suite 118/118.
This commit is contained in:
@@ -43,7 +43,7 @@ that cannot safely run in user space.**
|
||||
| D2 | Adversarial case: a process handed nothing is refused, on a held device and a free one | **done** — `device-authority-test`; the claim half joins it at D6 |
|
||||
| D3 | The manager claims the seeded devices at boot, before any driver is spawned | **merged into D4** — see below |
|
||||
| D4 | The manager claims + delegates on `hello`; `usb-xhci-bus` is the first driver converted | **done** — caught an IOMMU regression I introduced; see below |
|
||||
| D5 | The other four claimants converted: `pci-bus`, `ps2-bus`, `virtio-gpu`, `acpi` | not started |
|
||||
| D5 | The other four claimants converted: `pci-bus`, `ps2-bus`, `virtio-gpu`, `acpi` | **partial** — `pci-bus` done; the other three need decisions, see below |
|
||||
| D6 | `device_claim` refuses a device the caller was not handed; the hole is closed | not started |
|
||||
| D7 | Zero-resource devices stop being kernel objects — inventory moves to the manager | not started |
|
||||
| D8 | **`maximum_children_per_parent` deleted** — the authorisation it stood in for exists | not started |
|
||||
@@ -80,6 +80,33 @@ They land together, with the manager claiming only for drivers in an explicit
|
||||
anything in D4 — recorded rather than dismissed, because D4 moved the `hello` earlier
|
||||
and so did shift boot timing. Watch it across the remaining steps.
|
||||
|
||||
### Open questions raised by D5 — three of the four claimants cannot be converted yet
|
||||
|
||||
Delegation is delivered in `onHello`. That works for a driver that says hello, and
|
||||
**two of the four do not**.
|
||||
|
||||
6. **`ps2-bus` and the `acpi` service never hello at all**, and that is deliberate:
|
||||
device-manager.md records "Legacy drivers (e.g. ps2-bus) are supervised and
|
||||
restarted but **not yet required to hello**", and the `Driver.speaks_protocol` flag
|
||||
exists to say so. Delegating to them means either making them speak the protocol —
|
||||
promoting them out of "legacy", which is a change to their documented status — or
|
||||
giving the grant a second delivery point that is not `hello`. Neither is written
|
||||
down. A second delivery point would also need its own answer to "when", since the
|
||||
whole value of `hello` here is that it is the moment the driver is known to be alive
|
||||
and is a synchronous point to hand something over.
|
||||
|
||||
7. **`virtio-gpu` hellos, but best-effort by design.** Its call is
|
||||
`_ = device_manager.hello(.device, device_id);` with the comment "Best-effort:
|
||||
standalone bring-up has no manager." Delegation would make the hello *mandatory* and
|
||||
move it to the front, so the driver could no longer come up without a manager. No
|
||||
test exercises standalone today (the `virtio-gpu` case boots the manager stack, and
|
||||
devices.csv matches it), so this is a documented intent rather than a live path —
|
||||
but discarding a documented intent is a decision, not a mechanical step.
|
||||
|
||||
Until these are answered, `device_claim` cannot be closed off at D6 for those three, so
|
||||
**D6 is blocked on question 6 and 7**. D7–D9 are not: they concern what the kernel
|
||||
stores and how the table is sized, and are independent of which drivers have converted.
|
||||
|
||||
### Settled, so the run does not re-litigate them
|
||||
|
||||
- **The manager claims, it is not granted.** No binary names in the kernel; the rule is
|
||||
|
||||
Reference in New Issue
Block a user