An AMD Ryzen booted to a working compositor with no USB and no storage, and the log said only "register refused". A tree-wide audit of every compile-time ceiling followed: 235 of them, 139 on quantities the machine or a file decides rather than us, 5 documented anywhere, 171 silent when reached. docs/fixed-bounds-audit.md has the inventory. Errno attribution. The errno space was split between the kernel and the envelope, free to drift; it is now one list in system/abi.zig, restated on both sides, with a comptime check in library/device/driver where the two halves are visible. device_register's six refusals and device_claim's three are distinct codes, so a bus driver can say which rule stopped it, and BadParent splits into NoSuchParent and NotYourParent. pci-bus reconciles found against registered instead of counting refused functions as found. Idempotency ordering. The child cap was checked before the identity match, so a restarted bus was refused its own devices — the supervision restart the system leans on ratcheted toward a degraded machine. A re-registration consumes no slot and is now admitted first. IOMMU fail-closed. confineDevice returned success for a device id past the confinement table, leaving the device outside every domain while the caller believed it confined — unreachable only while ids stop at 64, which both the inventory move and a hardware-reported domain count would change. It refuses now, and the coupling to the broker's device cap is a comptime assert rather than a sentence in a comment. PCI apertures. The bridge's MMIO apertures are derived from the holes in the firmware memory map, and the derivation copied sub-4 GiB entries into a fixed [64] array and skipped the rest. A skipped region is not merely lost: the gap finder concludes it is free, so a real machine's 60-200 entry map yields an aperture over live RAM, and containment then admits a child BAR covering kernel memory. Rewritten to walk the map in place, with the hole finder extracted as a pure function and driven by a synthetic 100-entry map in a new test case. Both new tests were verified to fail on the old code. parameters.zig gains the rationale it was missing and loses a stale sentence pointing at the wrong file; vdso.md documents the errno space, including EPEER, which had no written meaning anywhere. docs/os-development/bounds.md is how a ceiling is declared from here. docs/bounds-track-plan.md is the plan to remove the ones we invented. Suite 114 -> 115.
49 lines
2.8 KiB
Zig
49 lines
2.8 KiB
Zig
//! Kernel tunables — the compile-time knobs, gathered in one place.
|
|
//!
|
|
//! These constants would otherwise be scattered across the files that use them,
|
|
//! hiding the trade-offs. Keeping them here makes them visible at a glance and gives
|
|
//! one spot to change them. They're plain `comptime` constants (zero runtime cost);
|
|
//! any one can later be promoted to a `-D` build option if a target needs to vary it
|
|
//! (see build.zig's `-Dtest-case` for the pattern). This keeps [[boot-handoff]] to what
|
|
//! it actually is — the loader↔kernel handoff *contract* — with tunables living here.
|
|
//!
|
|
//! **Kernel only, and deliberately so.** This file exists because tunables were
|
|
//! crowding the loader↔kernel contract they were split out of; it is not a registry for
|
|
//! the whole system. A driver's ring size belongs to that driver, a protocol's payload
|
|
//! cap to that protocol. How a ceiling is *declared*, wherever it lives, is
|
|
//! docs/os-development/bounds.md — a shape, not a shared list.
|
|
|
|
/// Ceiling on logical CPUs the kernel tracks — the size of the per-CPU bookkeeping
|
|
/// arrays (discovery pool, scheduler state, per-core GDT/TSS). Generous headroom:
|
|
/// those structs are small, and the *large* per-core resources (kernel and IST
|
|
/// stacks) are allocated at bring-up for cores that actually come online, so this
|
|
/// ceiling is cheap. A machine with more logical CPUs has its surplus reported and
|
|
/// left parked (see acpi `cpusDropped`).
|
|
pub const maximum_cpus = 128;
|
|
|
|
/// Maximum tasks (kernel threads) alive at once — the static task-table size. Each
|
|
/// online core consumes one slot for its idle task, plus task 0 on the BSP. Sized
|
|
/// for the initial-ramdisk sweep (the bundled binaries spawned at once) plus the
|
|
/// device manager's supervised children with room to grow — at 16 the sweep
|
|
/// started failing spawns once the bundle passed a dozen binaries. Raised to 48
|
|
/// for the USB stack: the xHCI bus driver spawns a supervised class-driver instance
|
|
/// per matched interface (keyboard, mouse, mass storage), on top of the FAT and
|
|
/// block servers and the growing ramdisk bundle.
|
|
pub const maximum_tasks = 48;
|
|
|
|
/// Each task's kernel stack (also each AP's bring-up stack), in bytes.
|
|
pub const kernel_stack_size = 16 * 1024;
|
|
|
|
/// Each user process's stack, in pages (32 KiB). Mapped just below a fixed top;
|
|
/// the System V entry block (argc/argv) occupies the top of the highest page, and
|
|
/// the page below the mapping is left unmapped as a guard, so an overflow faults
|
|
/// (killing only that process) instead of silently corrupting the image.
|
|
pub const user_stack_pages = 8;
|
|
|
|
/// Each core's IST (double-fault) stack, in bytes. The BSP's is static; an AP's is
|
|
/// heap-allocated at bring-up.
|
|
pub const ist_stack_size = 16 * 1024;
|
|
|
|
/// Scheduler tick / preemption rate, in Hz (the timer's periodic frequency).
|
|
pub const timer_hz = 1000;
|