Release a dead process's device claims (M17.1)
Every path out of a process (exit, fault, kill) now releases its device claims alongside its IRQ and MSI bindings, so a restarted driver can claim its hardware again — the cleanup half of process-lifecycle.md's iron rule 1. MSI vectors were already swept by irq.releaseOwner; claims were the gap. The claim-release test proves kill -> release -> re-claim, plus the broker release in isolation.
This commit is contained in:
@@ -29,7 +29,9 @@ only when its definition of green holds.
|
||||
- [x] **Phase 0** — baseline: docs committed, feat/usb merged to main, pushed;
|
||||
`usb-xhci-libary.zig` renamed to `usb-xhci-library.zig`; existing QEMU
|
||||
suite green from the worktree (48/48, 2026-07-12).
|
||||
- [ ] **M17.1** — kernel releases claims/MSI on death (branch `feat/process-lifecycle`)
|
||||
- [x] **M17.1** — kernel releases claims/MSI on death (claims: `releaseAllOwnedBy`
|
||||
in the reap; MSI was already swept by `irq.releaseOwner`; `claim-release`
|
||||
test; suite 49/49)
|
||||
- [ ] **M17.2** — exit reasons
|
||||
- [ ] **M17.3** — published exit events + VFS subscriber
|
||||
- [ ] **M17.4** — signals, timer notifications, `runtime.process`, the service harness
|
||||
|
||||
@@ -95,8 +95,11 @@ the architecture layer calls up into `tick`.
|
||||
|
||||
## Known gaps (bring-up honesty)
|
||||
|
||||
- Device **claims** are not released on death (pre-existing: the fault path has
|
||||
the same gap) — a killed driver's device stays claimed until reboot.
|
||||
- ~~Device claims are not released on death~~ Closed (M17.1): every path out of a
|
||||
process releases its device claims alongside its IRQ and MSI bindings
|
||||
(`releaseTaskResourcesLocked`), so a restarted driver can claim its hardware
|
||||
again — the cleanup half of [process-lifecycle.md](process-lifecycle.md)'s iron
|
||||
rule 1. The `claim-release` test proves the kill → release → re-claim cycle.
|
||||
- Kernel stacks of dead tasks are leaked, as on every exit path (no reaper yet).
|
||||
- There is no exit *status* in the notification, only the id; a supervisor that
|
||||
needs the code can grow a wait-style call later.
|
||||
@@ -109,4 +112,5 @@ the architecture layer calls up into `tick`.
|
||||
`process-list` (enumerate), `process-kill` (kernel-level kill paths, refusals,
|
||||
notifications), `supervision` (the whole user-side surface via the process-test
|
||||
service: spawn supervised → enumerate → kill blocked and spinning children →
|
||||
notifications → gone). See test/qemu_test.py.
|
||||
notifications → gone), `claim-release` (a killed claim-holder's device is
|
||||
claimable again). See test/qemu_test.py.
|
||||
|
||||
Reference in New Issue
Block a user