M10: IO passthrough (MMIO grants) + first real driver (hpetd)

A user-space process can now touch real hardware directly, capability-gated by
the device tree — the microkernel driver model.

- src/kernel/devsvc.zig: flattens the discovered device tree into an
  id-indexed snapshot + a claim table at boot (devsvc.init from main.zig).
- Syscalls 11-13: dev_enumerate (snapshot the table), dev_claim (take
  exclusive ownership), mmio_map (map a claimed device's MMIO window into the
  caller's AS and return the register base). The claim is the capability:
  mmio_map refuses any device the caller doesn't own.
- paging.mapUserDeviceInto: maps device MMIO strong-uncacheable (PCD|PWT) and
  marks each leaf with a device_grant PTE bit; freeSubtree skips pmm.free on
  those leaves, so tearing down a driver never returns MMIO frames to the RAM
  pool (the teardown hazard). MMIO grants live in a distinct arena, PML4[226]
  (Task.dev_map_next), so device pages widen no kernel mapping.
- lib/dev.zig: user enumerate/claim/mmioMap wrappers; shared DeviceDesc/ResDesc
  in danos (root.zig). sbin/hpetd.zig: finds the HPET, claims it, maps its
  registers, enables the counter (an MMIO write) and reads it (0xF0) — proving
  read+write passthrough to real hardware.
- Tests: `hpet` (driver reads the counter advancing from ring 3) and `iopass`
  (device-granted frame survives address-space teardown). Suite 33/33.

irq_bind/irq_ack (IRQ-as-message) are stubbed (-1) pending; notifyFromIsr (M7)
is the hook they'll use.
This commit is contained in:
Daniel Samson
2026-07-09 08:03:21 +01:00
parent b0f894f50c
commit 83881641ca
14 changed files with 449 additions and 9 deletions
+75
View File
@@ -0,0 +1,75 @@
//! /sbin/hpetd — a user-space HPET driver, the first real device driver. It
//! proves IO passthrough end to end: enumerate the device table, find the HPET
//! (a timer with an MMIO window), claim it, map its registers directly into this
//! ring-3 address space (strong-uncacheable), then drive the hardware — enable
//! the main counter and read it. If the counter advances, a user process is
//! touching real hardware through a kernel-granted MMIO mapping.
//!
//! Register offsets (HPET spec): general config = 0x10 (bit 0 = ENABLE),
//! main counter = 0xF0.
const rt = @import("rt");
const dev = rt.dev;
pub fn main() void {
// Enumerate into a heap buffer (too big for the one-page user stack).
const buf = rt.allocator().alloc(dev.DeviceDesc, 32) catch {
_ = rt.sys.write("hpetd: out of memory\n");
return;
};
const total = dev.enumerate(buf);
const n = @min(total, buf.len);
// Find a timer-class device with an MMIO resource (the HPET).
var dev_id: u64 = 0;
var res_idx: u64 = 0;
var found = false;
var i: usize = 0;
outer: while (i < n) : (i += 1) {
const d = buf[i];
if (d.class != @intFromEnum(dev.DeviceClass.timer)) continue;
var j: usize = 0;
while (j < d.resource_count) : (j += 1) {
if (d.resources[j].kind == @intFromEnum(dev.ResourceKind.memory)) {
dev_id = d.id;
res_idx = j;
found = true;
break :outer;
}
}
}
if (!found) {
_ = rt.sys.write("hpetd: no HPET found\n");
return;
}
if (!dev.claim(dev_id)) {
_ = rt.sys.write("hpetd: claim failed\n");
return;
}
const base = dev.mmioMap(dev_id, res_idx) orelse {
_ = rt.sys.write("hpetd: mmio_map failed\n");
return;
};
// Drive the hardware: enable the counter (an MMIO write), then read it twice.
const config: *volatile u64 = @ptrFromInt(base + 0x10);
config.* |= 1; // ENABLE
const counter: *volatile u64 = @ptrFromInt(base + 0xF0);
const a = counter.*;
rt.sys.sleep(50);
const b = counter.*;
if (b > a) {
while (true) {
_ = rt.sys.write("hpetd: ok\n");
rt.sys.sleep(1000);
}
}
_ = rt.sys.write("hpetd: counter stuck\n");
}
pub const panic = rt.panic;
comptime {
_ = &rt.start._start;
}