An AMD Ryzen booted to a working compositor with no USB and no storage, and the log said only "register refused". A tree-wide audit of every compile-time ceiling followed: 235 of them, 139 on quantities the machine or a file decides rather than us, 5 documented anywhere, 171 silent when reached. docs/fixed-bounds-audit.md has the inventory. Errno attribution. The errno space was split between the kernel and the envelope, free to drift; it is now one list in system/abi.zig, restated on both sides, with a comptime check in library/device/driver where the two halves are visible. device_register's six refusals and device_claim's three are distinct codes, so a bus driver can say which rule stopped it, and BadParent splits into NoSuchParent and NotYourParent. pci-bus reconciles found against registered instead of counting refused functions as found. Idempotency ordering. The child cap was checked before the identity match, so a restarted bus was refused its own devices — the supervision restart the system leans on ratcheted toward a degraded machine. A re-registration consumes no slot and is now admitted first. IOMMU fail-closed. confineDevice returned success for a device id past the confinement table, leaving the device outside every domain while the caller believed it confined — unreachable only while ids stop at 64, which both the inventory move and a hardware-reported domain count would change. It refuses now, and the coupling to the broker's device cap is a comptime assert rather than a sentence in a comment. PCI apertures. The bridge's MMIO apertures are derived from the holes in the firmware memory map, and the derivation copied sub-4 GiB entries into a fixed [64] array and skipped the rest. A skipped region is not merely lost: the gap finder concludes it is free, so a real machine's 60-200 entry map yields an aperture over live RAM, and containment then admits a child BAR covering kernel memory. Rewritten to walk the map in place, with the hole finder extracted as a pure function and driven by a synthetic 100-entry map in a new test case. Both new tests were verified to fail on the old code. parameters.zig gains the rationale it was missing and loses a stale sentence pointing at the wrong file; vdso.md documents the errno space, including EPEER, which had no written meaning anywhere. docs/os-development/bounds.md is how a ceiling is declared from here. docs/bounds-track-plan.md is the plan to remove the ones we invented. Suite 114 -> 115.
96 lines
4.5 KiB
Zig
96 lines
4.5 KiB
Zig
//! The firmware-agnostic discovery facade.
|
|
//!
|
|
//! The kernel calls `platform.discover()` and gets back a generic `DeviceTree`
|
|
//! without ever naming ACPI or device-tree — the same way it imports `architecture`
|
|
//! without naming x86_64. Which backend runs is decided *at runtime* from what
|
|
//! the bootloader handed us (an ACPI RSDP today, a device-tree blob later),
|
|
//! because a single image — a future ARM kernel especially — may boot under
|
|
//! either firmware. That's a deliberate divergence from `architecture`, which is a
|
|
//! compile-time choice.
|
|
|
|
const std = @import("std");
|
|
const boot_handoff = @import("boot-handoff");
|
|
const device_model = @import("device-model.zig");
|
|
const acpi = @import("acpi.zig");
|
|
const fdt = @import("fdt.zig");
|
|
|
|
pub const DeviceTree = device_model.DeviceTree;
|
|
pub const Device = device_model.Device;
|
|
pub const DeviceClass = device_model.DeviceClass;
|
|
pub const Resource = device_model.Resource;
|
|
pub const ResourceKind = device_model.ResourceKind;
|
|
pub const Hal = device_model.Hal;
|
|
pub const PowerInformation = acpi.PowerInformation;
|
|
pub const PlatformInformation = acpi.PlatformInformation;
|
|
pub const RegisterAccess = acpi.RegisterAccess;
|
|
pub const IsoEntry = acpi.IsoEntry;
|
|
pub const Cpu = acpi.Cpu;
|
|
|
|
/// Where a PCI BAR may legitimately live: the holes in the firmware memory map.
|
|
/// Firmware-agnostic — it takes a boot-handoff map, not an ACPI table — and pure, so
|
|
/// the kernel self-test can drive it with a synthetic map. That is the only way to
|
|
/// check the invariant that matters here: an aperture must never cover memory the
|
|
/// firmware described, because containment would then admit a BAR over live RAM.
|
|
pub const AddressRange = acpi.AddressRange;
|
|
pub const largestHolesBelow4G = acpi.largestHolesBelow4G;
|
|
|
|
/// The FADT power register map discovery extracted (PM1 control, reset register),
|
|
/// for kernel reboot and diagnostics. Sleep-state values are userspace's (S5 is
|
|
/// owned by the ring-3 acpi service), so they are not here.
|
|
pub fn powerInformation() PowerInformation {
|
|
return acpi.power_information;
|
|
}
|
|
|
|
/// The scalar firmware facts the architecture layer needs to avoid legacy assumptions
|
|
/// (8259 presence, LAPIC base, PM timer, SPCR UART, IRQ overrides).
|
|
pub fn platformInformation() PlatformInformation {
|
|
return acpi.platform_information;
|
|
}
|
|
|
|
/// The usable logical processors discovered during enumeration — one entry per
|
|
/// core danos may schedule on, each carrying the Local APIC ID an SMP wake targets.
|
|
/// `len` is the hardware's degree of parallelism: how many tasks *could* run at the
|
|
/// same instant once the application processors are started. Today only the
|
|
/// bootstrap processor is actually running, so starting the rest is the pending SMP
|
|
/// step (see docs/smp.md). Borrowed from static storage populated by `discover`.
|
|
pub fn cpus() []const Cpu {
|
|
return acpi.cpu_information.cpus[0..acpi.cpu_information.count];
|
|
}
|
|
|
|
/// Non-zero only if enumeration found more processors than the static pool holds
|
|
/// (the surplus were dropped from `cpus()`); surfaced so the cap is never silent.
|
|
pub fn cpusDropped() usize {
|
|
return acpi.cpu_information.dropped;
|
|
}
|
|
|
|
/// Enumerate hardware into a fresh device tree. `hal` supplies the hardware
|
|
/// primitives the backend needs (MMIO mapping for PCIe configuration space, port I/O for
|
|
/// ACPI registers); pass the architecture implementation. Errors leave nothing to clean up
|
|
/// beyond the tree's own allocations.
|
|
pub fn discover(
|
|
boot_information: *const boot_handoff.BootInformation,
|
|
allocator: std.mem.Allocator,
|
|
hal: Hal,
|
|
) !DeviceTree {
|
|
var device_tree = try DeviceTree.init(allocator);
|
|
|
|
if (boot_information.acpi_rsdp != 0) {
|
|
const memory_regions = @as([*]const boot_handoff.MemoryRegion, @ptrFromInt(boot_handoff.physicalToVirtual(boot_information.memory_map.regions)))[0..boot_information.memory_map.len];
|
|
try acpi.discover(boot_information.acpi_rsdp, memory_regions, &device_tree, hal);
|
|
} else {
|
|
// No ACPI RSDP. A device-tree boot would parse its blob here; today that
|
|
// path is a stub, so this reports the machine described itself no way we
|
|
// understand yet.
|
|
try fdt.discover(&device_tree);
|
|
}
|
|
|
|
return device_tree;
|
|
}
|
|
|
|
/// Restart the machine. Never returns on success; returns only if no reset method
|
|
/// worked (extremely unlikely). Backend-agnostic entry the kernel calls. Soft-off
|
|
/// (S5) is not a kernel operation — the ring-3 acpi service owns it (docs/power.md).
|
|
pub fn reboot(hal: Hal) void {
|
|
acpi.reboot(hal);
|
|
}
|