The source layout now mirrors the runtime filesystem hierarchy
(docs/danos-file-system-hierarchy-FSH.md): what lives under system/ in the
source is what a running danos represents under /system. Each service and
driver is a sub-project directory that is its own Zig module — cross-project
references go by module name, never by a path into another project's files.
Moves (all git mv, history preserved):
- src/ -> system/ (danos internals; the self-representation)
root.zig -> danos.zig (the kernel<->user contract module)
kernel/arch/ -> kernel/architecture/ (arch -> architecture)
device/ -> devices/ (what /system/devices reflects)
boot/ -> /boot (the loaders, top level)
- sbin/ -> split by role:
init, vfs -> system/services/<name>/<name>.zig
hpetd, busd -> system/drivers/<name>/<name>.zig
vfs-test -> system/services/vfs/vfs-test.zig (inside the vfs project)
- lib/ -> library/runtime/ (room for other libraries beside runtime)
The VFS wire protocol becomes its own module, system/services/vfs/protocol.zig
("vfs-protocol"): the vfs sub-project exposes its interface, and the runtime's
file layer imports it by name. First instance of the "protocol module" pattern
(docs/driver-model.md); usb/block will expose theirs the same way.
Also: fix a naming-standard violation in the protocol — Op -> Operation (and
req -> request, _pad -> _padding). Docs updated: /system/services added to the
FHS doc, a repository-layout section added to the docs index, and stale source
paths swept across comments and docs.
Runtime boot paths are unchanged (the bootloader still loads /sbin/init);
aligning the runtime filesystem to the FHS is a separate follow-up. Suite 35/35
plus host tests green.
55 lines
2.4 KiB
Zig
55 lines
2.4 KiB
Zig
//! Inter-process communication: message-passing channels.
|
|
//!
|
|
//! IPC is the backbone of a microkernel ([vision](../docs/vision.md)): once
|
|
//! drivers and services live in separate address spaces, a message is how they
|
|
//! talk. This first form is a **bounded blocking channel** — a ring buffer of
|
|
//! messages with a producer/consumer rendezvous, built on the scheduler's
|
|
//! [wait queues](scheduling.md). `send` blocks when the channel is full, `receive`
|
|
//! blocks when it's empty; neither busy-waits.
|
|
//!
|
|
//! For now both endpoints are kernel threads sharing the kernel address space.
|
|
//! When user mode arrives, the same primitive carries messages across the
|
|
//! isolation boundary (with the payload copied between address spaces).
|
|
|
|
const scheduler = @import("scheduler.zig");
|
|
const sync = @import("sync.zig");
|
|
|
|
/// A bounded blocking channel of `capacity` messages of type `T`.
|
|
pub fn Channel(comptime T: type, comptime capacity: usize) type {
|
|
return struct {
|
|
const Self = @This();
|
|
|
|
buffer: [capacity]T = undefined,
|
|
head: usize = 0, // next slot to read
|
|
tail: usize = 0, // next slot to write
|
|
count: usize = 0,
|
|
not_full: scheduler.WaitQueue = .{}, // senders wait here
|
|
not_empty: scheduler.WaitQueue = .{}, // receivers wait here
|
|
|
|
/// Send a message, blocking while the channel is full.
|
|
pub fn send(self: *Self, message: T) void {
|
|
const flags = sync.enter();
|
|
// Recheck the condition in a loop: a wakeup only means "try again"
|
|
// (another waiter may have taken the slot first).
|
|
while (self.count == capacity) scheduler.waitLocked(&self.not_full);
|
|
self.buffer[self.tail] = message;
|
|
self.tail = (self.tail + 1) % capacity;
|
|
self.count += 1;
|
|
scheduler.wakeLocked(&self.not_empty); // a receiver can now proceed
|
|
sync.leave(flags);
|
|
}
|
|
|
|
/// Receive a message, blocking while the channel is empty.
|
|
pub fn receive(self: *Self) T {
|
|
const flags = sync.enter();
|
|
while (self.count == 0) scheduler.waitLocked(&self.not_empty);
|
|
const message = self.buffer[self.head];
|
|
self.head = (self.head + 1) % capacity;
|
|
self.count -= 1;
|
|
scheduler.wakeLocked(&self.not_full); // a sender can now proceed
|
|
sync.leave(flags);
|
|
return message;
|
|
}
|
|
};
|
|
}
|