keep the AP trampoline inert between wakes, and retry failed cores

Arm the low frame (copy blob, make executable) only while a core climbs, then zero it and restore RW+NX; the frame stays reserved so cores can be re-woken. startSecondary is one re-runnable attempt; boot retries a non-responding core 3x. Validated the retry path by forcing a first-attempt failure.
This commit is contained in:
Daniel Samson
2026-07-08 13:32:34 +01:00
parent dba3939a0f
commit debe815a5c
4 changed files with 68 additions and 28 deletions
+6 -10
View File
@@ -102,16 +102,12 @@ pub fn cpuLocal() usize {
// --- SMP: application-processor bring-up ----------------------------------
/// Make a low RAM page executable (clear its NX bit) — the AP trampoline is fetched
/// from it under paging. Delegates to the VMM; see paging.setExecutable.
pub fn setPageExecutable(phys: u64) void {
paging.setExecutable(phys);
}
/// Copy the AP trampoline into its low page (allocated + made executable by the
/// caller). Run once before waking any application processor.
pub fn prepareSecondaries(tramp_phys: u64) void {
smp.prepare(tramp_phys);
/// Record the low (<1 MiB) frame reserved for the AP trampoline. Run once at boot.
/// The frame stays inert (zeroed, non-executable) between wakes and is armed only
/// while a core is climbing — so a core can be (re)woken at any time (retry, or a
/// future power manager) without leaving an executable page resident. See smp.zig.
pub fn setTrampolinePage(phys: u64) void {
smp.setTrampolinePage(phys);
}
/// Wake the core with Local APIC id `apic_id` as dense CPU `index`, giving it