The compositor now boots on the GOP framebuffer and upgrades to the virtio-gpu driver the moment it announces itself — the pluggable-scanout payoff. The shared surface. The scanout resource is an shm region the driver creates (shm_physical, a new syscall, hands it the guest-physical for attach_backing) and passes to the compositor as a capability. The compositor maps it and composites straight into it: on x86 DMA is cache-coherent, so the cacheable shared pages the CPU paints are exactly what the device transfers-and-flushes — no copy, no explicit flush. The handshake. After bring-up the driver looks up .display and sends attach_scanout with the geometry + the surface capability. The compositor maps the surface, looks up the driver's .scanout endpoint itself (the driver registered it — no need to pass it), switches to backend.VirtioGpu, and re-composites the current frame. present() over the native backend is a present request on .scanout -> transfer-to-host + resource flush. The first native present is deferred to a one-shot timer: presenting inline from the announce handler would deadlock, since the driver is still blocked on our reply and not yet serving .scanout. After it lands, the compositor reads a pixel back from the shared surface to confirm the frame reached the device's backing. - shm_physical (syscall 36) + runtime.shm.physical. - scanout-protocol (the compositor->driver present channel), separate from the client-facing display protocol; the display protocol gains attach_scanout. - backend.VirtioGpu joins backend.Gop in the tagged union; select() still boots GOP. - the virtio-gpu driver's scanout backing is now shm (was DMA); it announces + serves .scanout present requests (transfer-to-host + flush of the shared surface). Also fixes a latent framebuffer-geometry corruption the display service hit only when it enumerated the device tree alongside a busy device-manager: Gop.init now captures the geometry into a small value the instant device_enumerate returns (rather than re-reading the 328-byte descriptor across the later claim/mmio_map syscalls) and retries on a zero geometry. The underlying device-table clobber is a separate kernel bug, tracked apart. Gate: python3 test/qemu_test.py display-native (QEMU -device virtio-gpu-pci) — "display: scanout upgraded to virtio-gpu" + "display: native present verified" + "display-demo: ok", passing 3/3. host tests, display-service, display-demo, shm, and virtio-gpu still pass.
58 lines
2.5 KiB
Zig
58 lines
2.5 KiB
Zig
//! User-space shared memory: `shm_create` / `shm_map`. A process creates a shareable,
|
|
//! zeroed, cacheable RAM region and gets back a pointer plus a **capability handle**; it
|
|
//! passes that handle to another process as an `ipc_call` send_cap, and the receiver
|
|
//! `shm_map`s it to map the same physical pages. The kernel primitive under the display
|
|
//! compositor↔native-driver and app↔compositor surface paths (docs/display-v2.md). The
|
|
//! generalization of capability passing from endpoints to memory objects.
|
|
|
|
const abi = @import("abi");
|
|
const sc = @import("system-call.zig");
|
|
const ipc = @import("ipc.zig");
|
|
|
|
inline fn failed(r: usize) bool {
|
|
return r > ~@as(usize, 0) - 4095; // a wrapped -errno lands in the top page
|
|
}
|
|
|
|
/// A shared region: the `ptr` the CPU touches, and the `handle` (a capability) to hand to
|
|
/// another process as an `ipc_call` send_cap.
|
|
pub const Region = struct {
|
|
ptr: [*]u8,
|
|
handle: ipc.Handle,
|
|
len: usize,
|
|
};
|
|
|
|
/// Grant `len` bytes (rounded up to whole pages) of shareable, zeroed, cacheable RAM.
|
|
/// Returns the region or null on failure. Two return values — vaddr in rax, handle in rdx —
|
|
/// so this is a hand-written stub like `dma.alloc`.
|
|
pub fn create(len: usize) ?Region {
|
|
var rax: usize = undefined;
|
|
var rdx: usize = undefined; // out: the capability handle
|
|
asm volatile ("syscall"
|
|
: [rax] "={rax}" (rax),
|
|
[rdx] "={rdx}" (rdx),
|
|
: [n] "{rax}" (@intFromEnum(abi.SystemCall.shm_create)),
|
|
[a0] "{rdi}" (len),
|
|
: .{ .rcx = true, .r11 = true, .memory = true });
|
|
if (failed(rax)) return null;
|
|
return .{ .ptr = @ptrFromInt(rax), .handle = rdx, .len = len };
|
|
}
|
|
|
|
/// Map the shared region named by a capability `handle` this process received (via an
|
|
/// `ipc_call` send_cap) into its address space — the same physical pages the creator sees.
|
|
/// Returns the pointer, or null on failure.
|
|
pub fn map(handle: ipc.Handle) ?[*]u8 {
|
|
const r = sc.systemCall1(.shm_map, handle);
|
|
if (failed(r)) return null;
|
|
return @ptrFromInt(r);
|
|
}
|
|
|
|
/// The guest-physical base of the shared region named by `handle` (which this process must
|
|
/// hold a capability for). The region's frames are contiguous, so this single address plus
|
|
/// the region length is all a device needs — e.g. a virtio-gpu driver programming an
|
|
/// `attach_backing`. Returns null on failure.
|
|
pub fn physical(handle: ipc.Handle) ?usize {
|
|
const r = sc.systemCall1(.shm_physical, handle);
|
|
if (failed(r)) return null;
|
|
return r;
|
|
}
|