The flip: PCI enumeration leaves the kernel (M19.3)
enumeratePci, addBars, pciConfigurationPtr, and the PciHeader struct are deleted; the kernel seeds only the host bridge, and the ring-3 pci-bus driver's reports are the sole source of PCI function nodes. The manager matches PCI drivers from reported identity, deduped by registered device id so a bus restart never double-spawns. The flip did its job by exposing a latent SMP race: ring-3 device_register made the broker table concurrent for the first time, and mmio_map read it lock-free — under load a torn resource length mapped hpet's window wrong (its user fault) and underflowed r.len-1 into a kernel integer-overflow panic. Fixed: the broker read in mmio_map (and claim) runs under the big kernel lock, the arithmetic rejects zero-length and wrapping windows cleanly, and pci-bus no longer registers unimplemented size-0 BARs. driver-restart hammered 6x, suite 55/55.
This commit is contained in:
@@ -180,6 +180,7 @@ fn registerAndReport(bus: u64, dev: u64, function: u64, class_triple: u32) void
|
||||
configWrite(bus, dev, function, off, original);
|
||||
const mask = readback & 0xFFFF_FFFC;
|
||||
const size: u32 = if (mask == 0) 0 else (~mask +% 1) & 0xFFFF;
|
||||
if (size == 0) continue; // unimplemented BAR — nothing to register
|
||||
descriptor.resources[slot] = .{ .kind = @intFromEnum(device.ResourceKind.io_port), .start = original & 0xFFFF_FFFC, .len = size };
|
||||
descriptor.resource_count += 1;
|
||||
} else if ((original >> 1) & 0x3 == 2) {
|
||||
@@ -192,15 +193,17 @@ fn registerAndReport(bus: u64, dev: u64, function: u64, class_triple: u32) void
|
||||
configWrite(bus, dev, function, off + 4, original_high);
|
||||
const readback = (@as(u64, hi) << 32) | (lo & 0xFFFF_FFF0);
|
||||
const size: u64 = if (readback == 0) 0 else ~readback +% 1;
|
||||
i += 1; // consumed the high half regardless
|
||||
if (size == 0) continue;
|
||||
descriptor.resources[slot] = .{ .kind = @intFromEnum(device.ResourceKind.memory), .start = (@as(u64, original_high) << 32) | (original & 0xFFFF_FFF0), .len = size };
|
||||
descriptor.resource_count += 1;
|
||||
i += 1; // consumed the high half
|
||||
} else {
|
||||
configWrite(bus, dev, function, off, 0xFFFF_FFFF);
|
||||
const readback = configRead(bus, dev, function, off);
|
||||
configWrite(bus, dev, function, off, original);
|
||||
const mask = readback & 0xFFFF_FFF0;
|
||||
const size: u32 = if (mask == 0) 0 else ~mask +% 1;
|
||||
if (size == 0) continue;
|
||||
descriptor.resources[slot] = .{ .kind = @intFromEnum(device.ResourceKind.memory), .start = original & 0xFFFF_FFF0, .len = size };
|
||||
descriptor.resource_count += 1;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user