These were the awkward ones. Each began with an operation packed into a single byte — two of them with a version wedged in beside it — so there was no wrapping them: the layouts had to be rebuilt. The device manager's own enumerate and subscribe become the reserved verbs that mean the same thing everywhere, its replies lose three status structs the envelope already carries, and a device id becomes the packet's target. Power drops the version it repeated on every request, because describe is the handshake, and stops claiming a 64-byte ceiling it never needed for calls. USB moves a control transfer's data to the packet tail in both directions, which makes the status length the transferred length and retires a field that had been saying the same thing twice. The danger in this one was not the protocols but their readers. Init recognised a power button by two bytes at the head of a message, the ACPI service dispatched on the first byte, the xHCI driver read its operation with a raw integer load, and the HID drivers reinterpreted a report wholesale — none of which would have failed to compile once the layouts moved. They would simply have stopped: no shutdown on the power button, no reports from the keyboard. Every one of them now reads through the generated types, and the shutdown gate that answers only a subscriber is the same code it was. Two sizes were decided by measuring rather than assuming. The child-added message is both a request and the event broadcast to subscribers, and alignment rounds it to 48 bytes, which puts its packet exactly on the 64-byte push floor — a test pins that, because a field added carelessly would now overflow it. The interrupt report gives up eight bytes of inline room to make space for the header; the two drivers that produce reports send eight and four. Suite 110/110.
53 lines
2.3 KiB
Zig
53 lines
2.3 KiB
Zig
//! crash-test — a test fixture, not a driver: claims the device it is assigned,
|
|
//! hellos the device manager, announces itself, then faults on purpose. The
|
|
//! driver-restart scenario drives the manager's whole restart machinery with
|
|
//! it: fault → exit reason → backoff → respawn → the **same claim succeeding
|
|
//! again** (claim release on death, M17.1, through the manager's path) → the
|
|
//! crash-loop cap. Spawned bare (the initial-ramdisk sweep starts every bundled
|
|
//! binary), it exits silently so it cannot derange other tests.
|
|
|
|
const std = @import("std");
|
|
const channel = @import("channel");
|
|
const ipc = @import("ipc");
|
|
const process = @import("process");
|
|
const time = @import("time");
|
|
const device = @import("driver");
|
|
const logging = @import("logging");
|
|
const device_manager_protocol = @import("device-manager-protocol");
|
|
|
|
pub fn main(init: process.Init) void {
|
|
const argument = init.arguments.get(1) orelse return; // bare: stay silent
|
|
const assigned = std.fmt.parseInt(u64, argument, 10) catch return;
|
|
|
|
// The respawn only reaches this line because the kernel released the
|
|
// previous instance's claim at death. A failed claim exits cleanly — the
|
|
// manager reads "meant to stop" and the scenario fails loudly by silence.
|
|
if (!device.claim(assigned)) {
|
|
_ = logging.write("crash-test: claim failed\n");
|
|
return;
|
|
}
|
|
|
|
var manager: ?ipc.Handle = null;
|
|
var tries: u32 = 0;
|
|
while (manager == null and tries < 100) : (tries += 1) {
|
|
manager = channel.openEndpoint("device-manager");
|
|
if (manager == null) time.sleepMillis(20);
|
|
}
|
|
const h = manager orelse return;
|
|
// The assigned device is the packet's target, the manager's object addressing.
|
|
var packet: [device_manager_protocol.message_maximum]u8 = undefined;
|
|
const framed = device_manager_protocol.Protocol.encodeRequest(
|
|
.hello,
|
|
assigned,
|
|
.{ .role = @intFromEnum(device_manager_protocol.Role.device) },
|
|
&.{},
|
|
&packet,
|
|
) orelse return;
|
|
var reply: [device_manager_protocol.message_maximum]u8 = undefined;
|
|
_ = ipc.call(h, framed, &reply) catch return;
|
|
|
|
_ = logging.write("crash-test: faulting now\n");
|
|
const poison: *volatile u32 = @ptrFromInt(0xdead0000);
|
|
poison.* = 1; // the restart machinery's fuel: a real segmentation fault
|
|
}
|