M2 step 4: relink the kernel into the higher half

The kernel now links at 0xFFFF_FFFF_8000_0000 (code_model .kernel) and
loads low via the linker script's AT() clauses (.text at 1 MiB). A new
asm _start installs a 64 KiB kernel-owned .bss stack — the loader stack
is a low address that goes away with the identity map — and calls the
Zig entry, which reaches boot_info through the physmap. The user-pf test
blob reads the LAPIC through the physmap window (still present|user, ec
0x5). The low identity map still coexists in the kernel's tables as the
safety net. Suite 27/27.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Daniel Samson
2026-07-08 22:45:56 +01:00
co-authored by Claude Fable 5
parent 724de7bbd0
commit f57a73e8a1
4 changed files with 58 additions and 29 deletions
+17 -12
View File
@@ -1,12 +1,18 @@
/* Kernel link layout.
/* Kernel link layout — higher half.
*
* The kernel is linked at a fixed low physical address (set by `image_base` in
* build.zig). UEFI runs with memory identity-mapped, so the bootloader can load
* each PT_LOAD segment to the physical address matching its virtual address and
* jump straight to _start — no page tables to build yet. (Moving to a
* higher-half virtual base is a later step, once the bootloader sets up paging.)
* The kernel is linked to *run* in the higher half (virtual base
* 0xFFFF_FFFF_8000_0000, matching danos.kernel_virt_base and build.zig's
* image_base) but is *loaded* low. Each section's load address (LMA) is its
* virtual address minus KERNEL_VIRT_BASE via AT(), so the ELF's p_paddr lands
* at a low physical address (.text at 1 MiB) that the loader can allocate and
* copy into. The loader maps p_vaddr (high) -> p_paddr (low) in its bootstrap
* tables and jumps to the high entry; the kernel then builds its own tables
* with the physmap and abandons the identity map. Requires LLD (build.zig pins
* it) — the self-hosted linker ignores PHDRS/AT()/section order.
*/
KERNEL_VIRT_BASE = 0xFFFFFFFF80000000;
ENTRY(_start)
/* One loadable segment per permission set, so the loader can map .text as R+X,
@@ -18,23 +24,22 @@ PHDRS {
}
SECTIONS {
.text ALIGN(4K) : {
.text ALIGN(4K) : AT(ADDR(.text) - KERNEL_VIRT_BASE) {
*(.text .text.*)
} :text
.rodata ALIGN(4K) : {
.rodata ALIGN(4K) : AT(ADDR(.rodata) - KERNEL_VIRT_BASE) {
*(.rodata .rodata.*)
} :rodata
.data ALIGN(4K) : {
.data ALIGN(4K) : AT(ADDR(.data) - KERNEL_VIRT_BASE) {
*(.data .data.*)
} :data
/* .bss occupies memory but not file space. The loader zeroes it via the
* gap between each PT_LOAD segment's file size and memory size, so no
* boundary symbols are needed here. (Zig's self-hosted linker also does not
* yet honour linker-script symbol assignments.) */
.bss ALIGN(4K) : {
* boundary symbols are needed here. */
.bss ALIGN(4K) : AT(ADDR(.bss) - KERNEL_VIRT_BASE) {
*(.bss .bss.*)
*(COMMON)
} :data