kernel: a refusal names its rule, and two bounds stop failing open
An AMD Ryzen booted to a working compositor with no USB and no storage, and the log said only "register refused". A tree-wide audit of every compile-time ceiling followed: 235 of them, 139 on quantities the machine or a file decides rather than us, 5 documented anywhere, 171 silent when reached. docs/fixed-bounds-audit.md has the inventory. Errno attribution. The errno space was split between the kernel and the envelope, free to drift; it is now one list in system/abi.zig, restated on both sides, with a comptime check in library/device/driver where the two halves are visible. device_register's six refusals and device_claim's three are distinct codes, so a bus driver can say which rule stopped it, and BadParent splits into NoSuchParent and NotYourParent. pci-bus reconciles found against registered instead of counting refused functions as found. Idempotency ordering. The child cap was checked before the identity match, so a restarted bus was refused its own devices — the supervision restart the system leans on ratcheted toward a degraded machine. A re-registration consumes no slot and is now admitted first. IOMMU fail-closed. confineDevice returned success for a device id past the confinement table, leaving the device outside every domain while the caller believed it confined — unreachable only while ids stop at 64, which both the inventory move and a hardware-reported domain count would change. It refuses now, and the coupling to the broker's device cap is a comptime assert rather than a sentence in a comment. PCI apertures. The bridge's MMIO apertures are derived from the holes in the firmware memory map, and the derivation copied sub-4 GiB entries into a fixed [64] array and skipped the rest. A skipped region is not merely lost: the gap finder concludes it is free, so a real machine's 60-200 entry map yields an aperture over live RAM, and containment then admits a child BAR covering kernel memory. Rewritten to walk the map in place, with the hole finder extracted as a pure function and driven by a synthetic 100-entry map in a new test case. Both new tests were verified to fail on the old code. parameters.zig gains the rationale it was missing and loses a stale sentence pointing at the wrong file; vdso.md documents the errno space, including EPEER, which had no written meaning anywhere. docs/os-development/bounds.md is how a ceiling is declared from here. docs/bounds-track-plan.md is the plan to remove the ones we invented. Suite 114 -> 115.
This commit is contained in:
@@ -978,9 +978,20 @@ CASES = [
|
||||
# device_register containment (in-kernel): registering a child whose MMIO window
|
||||
# escapes its parent's grant is refused (NotContained) — else dev_register would map
|
||||
# arbitrary physical memory — while an identical re-register stays idempotent.
|
||||
# Also pins the cap ordering: a parent already at maximum_children_per_parent must
|
||||
# still re-admit an identical child (a restarted bus consumes no slot re-reporting
|
||||
# what it rediscovers) while still refusing a genuinely new one.
|
||||
{"name": "containment",
|
||||
"expect": r"DANOS-TEST-RESULT: PASS",
|
||||
"fail": r"DANOS-TEST-RESULT: FAIL"},
|
||||
# PCI host-bridge apertures come from the holes in the firmware memory map, and a
|
||||
# registered BAR must fall inside one. The invariant is that an aperture never
|
||||
# covers memory the firmware described - otherwise device_register containment
|
||||
# admits a child BAR over live RAM. Driven with a synthetic 100-entry map, since
|
||||
# OVMF only ever produces 15-25 and real firmware 60-200.
|
||||
{"name": "apertures",
|
||||
"expect": r"DANOS-TEST-RESULT: PASS",
|
||||
"fail": r"DANOS-TEST-RESULT: FAIL"},
|
||||
# IRQ teardown: an exiting driver's line is masked and its slot cleared (so no
|
||||
# ISR notifies a freed endpoint), and a sibling owner sharing that endpoint
|
||||
# keeps its own binding. A long-running driver never reaches this teardown path.
|
||||
|
||||
@@ -22,10 +22,10 @@ pub fn main(init: process.Init) void {
|
||||
// The respawn only reaches this line because the kernel released the
|
||||
// previous instance's claim at death. A failed claim exits cleanly — the
|
||||
// manager reads "meant to stop" and the scenario fails loudly by silence.
|
||||
if (!device.claim(assigned)) {
|
||||
device.claim(assigned) catch {
|
||||
_ = logging.write("crash-test: claim failed\n");
|
||||
return;
|
||||
}
|
||||
};
|
||||
|
||||
var manager: ?ipc.Handle = null;
|
||||
var tries: u32 = 0;
|
||||
|
||||
@@ -71,10 +71,10 @@ pub fn main() void {
|
||||
return;
|
||||
};
|
||||
|
||||
if (!device.claim(nic_id)) {
|
||||
device.claim(nic_id) catch {
|
||||
_ = logging.write("iommu-fault-test: FAIL claim\n");
|
||||
return;
|
||||
}
|
||||
};
|
||||
var function = pci.Function.map(nic_id, &descriptor) orelse {
|
||||
_ = logging.write("iommu-fault-test: FAIL config-space map\n");
|
||||
return;
|
||||
|
||||
@@ -64,7 +64,7 @@ pub fn main() void {
|
||||
return;
|
||||
};
|
||||
writeLine("pci-cap-test: claiming ethernet function (device {d})\n", .{nic_id});
|
||||
if (!check("claim", device.claim(nic_id))) return;
|
||||
if (!check("claim", if (device.claim(nic_id)) |_| true else |_| false)) return;
|
||||
var function = pci.Function.map(nic_id, &descriptor) orelse {
|
||||
_ = logging.write("pci-cap-test: FAIL config-space map\n");
|
||||
return;
|
||||
|
||||
Reference in New Issue
Block a user