Two driver-model milestones plus a tree-wide naming pass. Suite 35/35 (QEMU) + host tests green. M11 — IRQ-as-IPC. A ring-3 driver now sleeps until its device interrupts it. New src/kernel/irq.zig: per-GSI endpoint bindings, comptime per-vector trampolines, dispatch = mask GSI -> LAPIC EOI -> notifyLocked, all under one lock region. irq_bind/irq_ack syscalls, gated by the device claim like mmio_map. interruptDispatch no longer EOIs — each handler owns its EOI, because a level line must be masked before it is acknowledged (irq_ack is the unmask). Bindings are keyed on the owning task and released on exit (a shared endpoint's siblings survive). hpetd rewritten interrupt-driven. Tests: hpet (rewritten, reads back the I/O APIC routing) and irqfree. M12 — bus drivers. DeviceDesc gains a parent, making the device table a tree. dev_register (device_register) lets a process publish children below a device it claimed; the kernel enforces resource containment (a child's resources must nest in its parent's), so a descriptor can't fabricate a window over kernel RAM. Descriptor copied in via copyFromUser (physmap walk — an unmapped user pointer fails the call instead of faulting the kernel). Per-parent child cap bounds table exhaustion. sbin/busd.zig is a worked bus driver. Test: bus. Naming — per docs/coding-standards.md: non-acronym abbreviations spelled out (message, descriptor, device_service, scheduler, runtime, physical, interpreter, ...); acronyms kept (IPC, MMIO, DMA, HCD, ...); files are kebab-case (ipc-synchronous.zig, device-service.zig, vfs-protocol.zig, ...). Exceptions: POSIX/C ABI names and Zig idioms (init/len/ptr) kept. Module collisions resolved by specific naming (config -> parameters, device.zig alias -> device_model). AML op/Op disambiguated: op = opcode, Op = operation; per-opcode parse handlers renamed opX -> parseX. New driver docs: drivers.md, driver-model.md (bus/class/HCD shapes + the proposed M13–M16 ABI), coding-standards.md.
33 lines
1.2 KiB
Zig
33 lines
1.2 KiB
Zig
//! The user-space process entry shim. Every user binary roots `_start` here (via
|
|
//! `entry = _start` in build.zig) and forces this file to be analysed with
|
|
//! `comptime { _ = &runtime.start._start; }`, so the whole runtime is linked in.
|
|
|
|
const std = @import("std");
|
|
const system = @import("system.zig");
|
|
|
|
/// The kernel enters at `_start` with rsp 16-aligned, but a SystemV function expects
|
|
/// rsp ≡ 8 (mod 16) on entry (as if reached by `call`). The `call` below pushes
|
|
/// the 8-byte return address, satisfying the ABI before any Zig frame runs; the
|
|
/// `ud2` is a safety net if `rt_start` ever returns.
|
|
pub export fn _start() callconv(.naked) noreturn {
|
|
asm volatile (
|
|
\\call rt_start
|
|
\\ud2
|
|
);
|
|
}
|
|
|
|
/// The first Zig frame. The heap is lazy (first alloc grows it), so there is no
|
|
/// runtime init to order here — just hand control to the program's `main`.
|
|
export fn rt_start() callconv(.c) noreturn {
|
|
const root = @import("root"); // the user binary's root source file
|
|
root.main();
|
|
system.exit(0);
|
|
}
|
|
|
|
/// No runtime to unwind into — report a panic as a nonzero exit code.
|
|
pub const panic = std.debug.FullPanic(struct {
|
|
fn panic(_: []const u8, _: ?usize) noreturn {
|
|
system.exit(127);
|
|
}
|
|
}.panic);
|