M10: IO passthrough (MMIO grants) + first real driver (hpetd)
A user-space process can now touch real hardware directly, capability-gated by the device tree — the microkernel driver model. - src/kernel/devsvc.zig: flattens the discovered device tree into an id-indexed snapshot + a claim table at boot (devsvc.init from main.zig). - Syscalls 11-13: dev_enumerate (snapshot the table), dev_claim (take exclusive ownership), mmio_map (map a claimed device's MMIO window into the caller's AS and return the register base). The claim is the capability: mmio_map refuses any device the caller doesn't own. - paging.mapUserDeviceInto: maps device MMIO strong-uncacheable (PCD|PWT) and marks each leaf with a device_grant PTE bit; freeSubtree skips pmm.free on those leaves, so tearing down a driver never returns MMIO frames to the RAM pool (the teardown hazard). MMIO grants live in a distinct arena, PML4[226] (Task.dev_map_next), so device pages widen no kernel mapping. - lib/dev.zig: user enumerate/claim/mmioMap wrappers; shared DeviceDesc/ResDesc in danos (root.zig). sbin/hpetd.zig: finds the HPET, claims it, maps its registers, enables the counter (an MMIO write) and reads it (0xF0) — proving read+write passthrough to real hardware. - Tests: `hpet` (driver reads the counter advancing from ring 3) and `iopass` (device-granted frame survives address-space teardown). Suite 33/33. irq_bind/irq_ack (IRQ-as-message) are stubbed (-1) pending; notifyFromIsr (M7) is the hook they'll use.
This commit is contained in:
@@ -75,9 +75,56 @@ pub const Syscall = enum(u64) {
|
||||
ipc_lookup = 8, // ipc_lookup(service_id) -> handle: find a published endpoint
|
||||
ipc_call = 9, // ipc_call(h, msg, len, reply, cap) -> reply_len: send + block for reply
|
||||
ipc_reply_wait = 10, // ipc_reply_wait(h, reply, len, recv, cap) -> recv_len (+badge in rdx)
|
||||
dev_enumerate = 11, // dev_enumerate(buf, max) -> count: snapshot the device table
|
||||
dev_claim = 12, // dev_claim(id) -> ok: take exclusive ownership of a device
|
||||
mmio_map = 13, // mmio_map(id, res_idx) -> vaddr: map a claimed device's MMIO into this AS
|
||||
irq_bind = 14, // irq_bind(id, res_idx, endpoint): deliver a device IRQ as an IPC notification
|
||||
irq_ack = 15, // irq_ack(id, res_idx): re-arm a bound IRQ after servicing it
|
||||
_,
|
||||
};
|
||||
|
||||
/// A device class, mirroring src/device/device.zig's `DeviceClass` **in order**
|
||||
/// (its `@intFromEnum` values cross the syscall boundary in `DeviceDesc.class`).
|
||||
/// Keep the two in sync.
|
||||
pub const DeviceClass = enum(u32) {
|
||||
root,
|
||||
processor,
|
||||
interrupt_controller,
|
||||
timer,
|
||||
pci_host_bridge,
|
||||
pci_device,
|
||||
acpi_device,
|
||||
unknown,
|
||||
};
|
||||
|
||||
/// A resource kind, mirroring src/device/device.zig's `ResourceKind` in order.
|
||||
pub const ResourceKind = enum(u32) {
|
||||
memory,
|
||||
io_port,
|
||||
irq,
|
||||
bus_range,
|
||||
};
|
||||
|
||||
/// One device resource, as handed to a user-space driver (flat, extern).
|
||||
pub const ResDesc = extern struct {
|
||||
kind: u64, // a ResourceKind value
|
||||
start: u64,
|
||||
len: u64,
|
||||
};
|
||||
|
||||
pub const max_dev_resources = 8;
|
||||
|
||||
/// A device, as snapshotted for user space by `dev_enumerate`. A driver scans
|
||||
/// these to find the hardware it owns, claims it, and maps its MMIO.
|
||||
pub const DeviceDesc = extern struct {
|
||||
id: u64,
|
||||
class: u64, // a DeviceClass value
|
||||
hid_len: u64,
|
||||
resource_count: u64,
|
||||
hid: [8]u8,
|
||||
resources: [max_dev_resources]ResDesc,
|
||||
};
|
||||
|
||||
/// Well-known IPC service ids for the bootstrap name registry (create_endpoint +
|
||||
/// ipc_register/ipc_lookup). Small integers, so no string interning is needed
|
||||
/// during bring-up. The VFS server registers under `vfs`; clients look it up.
|
||||
|
||||
Reference in New Issue
Block a user