M10: IO passthrough (MMIO grants) + first real driver (hpetd)

A user-space process can now touch real hardware directly, capability-gated by
the device tree — the microkernel driver model.

- src/kernel/devsvc.zig: flattens the discovered device tree into an
  id-indexed snapshot + a claim table at boot (devsvc.init from main.zig).
- Syscalls 11-13: dev_enumerate (snapshot the table), dev_claim (take
  exclusive ownership), mmio_map (map a claimed device's MMIO window into the
  caller's AS and return the register base). The claim is the capability:
  mmio_map refuses any device the caller doesn't own.
- paging.mapUserDeviceInto: maps device MMIO strong-uncacheable (PCD|PWT) and
  marks each leaf with a device_grant PTE bit; freeSubtree skips pmm.free on
  those leaves, so tearing down a driver never returns MMIO frames to the RAM
  pool (the teardown hazard). MMIO grants live in a distinct arena, PML4[226]
  (Task.dev_map_next), so device pages widen no kernel mapping.
- lib/dev.zig: user enumerate/claim/mmioMap wrappers; shared DeviceDesc/ResDesc
  in danos (root.zig). sbin/hpetd.zig: finds the HPET, claims it, maps its
  registers, enables the counter (an MMIO write) and reads it (0xF0) — proving
  read+write passthrough to real hardware.
- Tests: `hpet` (driver reads the counter advancing from ring 3) and `iopass`
  (device-granted frame survives address-space teardown). Suite 33/33.

irq_bind/irq_ack (IRQ-as-message) are stubbed (-1) pending; notifyFromIsr (M7)
is the hook they'll use.
This commit is contained in:
Daniel Samson
2026-07-09 08:03:21 +01:00
parent b0f894f50c
commit 83881641ca
14 changed files with 449 additions and 9 deletions
+32
View File
@@ -0,0 +1,32 @@
//! User-space device access: enumerate the kernel's device table, claim a
//! device, and map its MMIO. A driver uses these to find and take ownership of
//! its hardware; the claim is the capability the kernel checks before mapping.
const danos = @import("danos");
const sc = @import("syscall.zig");
pub const DeviceDesc = danos.DeviceDesc;
pub const ResDesc = danos.ResDesc;
pub const DeviceClass = danos.DeviceClass;
pub const ResourceKind = danos.ResourceKind;
inline fn failed(r: usize) bool {
return r > ~@as(usize, 0) - 4095;
}
/// Copy up to `buf.len` device descriptors into `buf`; returns the total count.
pub fn enumerate(buf: []DeviceDesc) usize {
return sc.syscall2(.dev_enumerate, @intFromPtr(buf.ptr), buf.len);
}
/// Take exclusive ownership of device `id`. Returns false if taken or invalid.
pub fn claim(id: u64) bool {
return !failed(sc.syscall1(.dev_claim, id));
}
/// Map resource `res_idx` (which must be an MMIO window) of claimed device
/// `dev_id` into this address space; returns the register base virtual address.
pub fn mmioMap(dev_id: u64, res_idx: u64) ?usize {
const r = sc.syscall2(.mmio_map, dev_id, res_idx);
return if (failed(r)) null else r;
}
+2
View File
@@ -20,6 +20,8 @@ pub const vfsproto = @import("vfs_proto.zig");
pub const unistd = @import("unistd.zig");
/// C stdio: fopen/fread/fwrite/fseek/ftell/fclose over unistd.
pub const stdio = @import("stdio.zig");
/// Device access for drivers: enumerate/claim/mmioMap.
pub const dev = @import("dev.zig");
/// Re-exported so a user binary can `pub const panic = rt.panic;`.
pub const panic = start.panic;