device-manager: hold the seeded hardware so none is left lying around
A device nobody holds can be claimed by anyone, so the manager now takes every firmware-discovered device that carries mappable resources, whether or not a driver wants it. The real gap was the HPET: an MMIO window, an IRQ, no user-space driver, and there for the taking. Held by the manager it is inert; unheld it was a way into physical memory. Two deliberate exclusions. The loader's framebuffer, which the compositor claims and which the manager must not take because it starts first. And anything with no resources, which grants nothing worth holding. Scope is the boot snapshot. A device reported later and matched to no driver stays claimable — pci-cap-test and iommu-fault-test both reach an unmatched NIC that way, so narrowing it is a separate change with those fixtures in scope. Recorded in the plan rather than left implied. The attacker fixture gains the assertion deferred since D2: after the system settles, nothing with resources may be taken. That assertion defeated itself twice before it worked, and both failures are worth remembering. First it swept at 0.029 while the manager did not bind its protocol until 0.047, so it reported a hole that closed a millisecond later. The retry loop that "fixed" that was worse: the first pass TAKES the device, so the second finds it unavailable because this process now holds it, and concludes all is well — it passed with the manager's claiming removed entirely. It now settles once and sweeps once, and fails when the claiming is removed. Suite 118/118.
This commit is contained in:
@@ -4334,6 +4334,11 @@ fn deviceAuthorityTest(boot_information: *const BootInformation) void {
|
||||
};
|
||||
|
||||
process.setInitialRamdisk(image);
|
||||
// The manager must be up: it is what holds the seeded hardware, and without it
|
||||
// every device would be lying around unheld and the last assertion would have
|
||||
// nothing to observe — a test that cannot fail.
|
||||
check("registry (init) spawned", spawnRegistry(rd));
|
||||
check("device-manager spawned", spawnNamed(rd, "device-manager"));
|
||||
check("device-authority-test spawned", spawnNamedWithArg(rd, "device-authority-test", "run"));
|
||||
|
||||
// The VERDICT prefix matters: the fixture prints one "device-authority: ok <name>"
|
||||
|
||||
Reference in New Issue
Block a user