Two driver-model milestones plus a tree-wide naming pass. Suite 35/35 (QEMU) + host tests green. M11 — IRQ-as-IPC. A ring-3 driver now sleeps until its device interrupts it. New src/kernel/irq.zig: per-GSI endpoint bindings, comptime per-vector trampolines, dispatch = mask GSI -> LAPIC EOI -> notifyLocked, all under one lock region. irq_bind/irq_ack syscalls, gated by the device claim like mmio_map. interruptDispatch no longer EOIs — each handler owns its EOI, because a level line must be masked before it is acknowledged (irq_ack is the unmask). Bindings are keyed on the owning task and released on exit (a shared endpoint's siblings survive). hpetd rewritten interrupt-driven. Tests: hpet (rewritten, reads back the I/O APIC routing) and irqfree. M12 — bus drivers. DeviceDesc gains a parent, making the device table a tree. dev_register (device_register) lets a process publish children below a device it claimed; the kernel enforces resource containment (a child's resources must nest in its parent's), so a descriptor can't fabricate a window over kernel RAM. Descriptor copied in via copyFromUser (physmap walk — an unmapped user pointer fails the call instead of faulting the kernel). Per-parent child cap bounds table exhaustion. sbin/busd.zig is a worked bus driver. Test: bus. Naming — per docs/coding-standards.md: non-acronym abbreviations spelled out (message, descriptor, device_service, scheduler, runtime, physical, interpreter, ...); acronyms kept (IPC, MMIO, DMA, HCD, ...); files are kebab-case (ipc-synchronous.zig, device-service.zig, vfs-protocol.zig, ...). Exceptions: POSIX/C ABI names and Zig idioms (init/len/ptr) kept. Module collisions resolved by specific naming (config -> parameters, device.zig alias -> device_model). AML op/Op disambiguated: op = opcode, Op = operation; per-opcode parse handlers renamed opX -> parseX. New driver docs: drivers.md, driver-model.md (bus/class/HCD shapes + the proposed M13–M16 ABI), coding-standards.md.
40 lines
1.8 KiB
Zig
40 lines
1.8 KiB
Zig
//! /sbin/init — the first user-space program, PID 1. Built as its own
|
|
//! freestanding binary (see build.zig), shipped on the boot volume at sbin/init,
|
|
//! loaded by the bootloader, and started in ring 3 as a scheduled process by the
|
|
//! kernel (src/kernel/process.zig). It links against the shared user runtime
|
|
//! library `runtime` and talks to the kernel only through `runtime`'s system_call wrappers.
|
|
//!
|
|
//! Today it proves the C-convention heap works, then settles into a heartbeat:
|
|
//! it prints a line and sleeps, forever — enough to show the system reaches user
|
|
//! space and stays alive with a real process scheduled alongside the kernel's
|
|
//! idle loop. It grows into the real init (service supervision) once there are
|
|
//! other user programs to supervise.
|
|
|
|
const runtime = @import("runtime");
|
|
|
|
pub fn main() void {
|
|
// Prove the heap end to end: allocate through the runtime allocator (which
|
|
// mmaps pages from the kernel and carves them with the free list), write into
|
|
// that heap buffer (exercising the widened debug_write bounds check), and
|
|
// free it. A fault here would kill init before it heartbeats — so the init
|
|
// test doubles as the heap regression test. (C code links the same heap via
|
|
// the extern malloc/free symbols; Zig code uses this allocator.)
|
|
const gpa = runtime.allocator();
|
|
if (gpa.alloc(u8, 64)) |buffer| {
|
|
const message = "init: heap ok\n";
|
|
@memcpy(buffer[0..message.len], message);
|
|
_ = runtime.system.write(buffer[0..message.len]);
|
|
gpa.free(buffer);
|
|
} else |_| {}
|
|
|
|
while (true) {
|
|
_ = runtime.system.write("init: heartbeat\n");
|
|
runtime.system.sleep(1000);
|
|
}
|
|
}
|
|
|
|
pub const panic = runtime.panic;
|
|
comptime {
|
|
_ = &runtime.start._start; // pull the runtime entry shim into the image
|
|
}
|