aboutsummaryrefslogtreecommitdiff
path: root/arch
AgeCommit message (Collapse)AuthorFilesLines
10 daysx86_64: remove unused includeFelix Morgner1-2/+0
10 daysx86_64: replace raw pointers with observer_ptrFelix Morgner16-45/+76
10 dayschore: replace some naked pointersFelix Morgner10-18/+29
The coding guidelines explicitly prohibit the use of "naked"/C-style pointers. However, there were some prominent examples in the kapi and the core kernel source. This changeset replaces them with the appropriate smart pointer types.
2026-09-05build: enable strong stack protectorFelix Morgner1-0/+11
2026-09-05x86_64: stop loading uninitialized dataFelix Morgner1-5/+5
2026-09-05x86_64/cpu: improve stack overflow detectionFelix Morgner2-2/+29
2026-09-04x86_64/cpu: fix asm input constraintFelix Morgner1-2/+2
The "X" constraint tells GCC that any operand whatsoever is valid to be placed in the assembler template. This makes no sense in this case, since that would allow for the exact expression to be inserted. If that happens, which it does when `-Og` is active, GCC is unable to assemble that template. The correct constraint is forcing the value into a register.
2026-09-04x86_64/boot: reduce kernel stack size to 8 KiBFelix Morgner1-1/+1
2026-09-04x86_64/cpu: handle #DF inside the arch codeFelix Morgner1-1/+12
A double fault is a very x86-64 specific type of exception and not recoverable in a generalized way. Thus we should handle it internally, with handling currently being triggering a panic, and not forward it to the architecture-independent kernel layer.
2026-09-04x86_64/cpu: use IST1 as the stack for #DFFelix Morgner3-12/+33
2026-09-04x86_64/cpu: isolate kernel and IST1 stackFelix Morgner1-1/+13
Previously, the kernel stack was allocated inside the .kernel_bss section, along other uninitialized data. While this works, it assumes that the section will always be laid out with the kernel stack at the top. If that is not the case, the allocated guard page before .kernel_bss would not trigger a #PF since out-of-bounds (overflow) access would quietly overwrite other data in the section, thus potentially corrupting global kernel data. At the same time, there was no separate section (and guard page) for the future #DF exception stack (IST1 in our case). Thus we allocate a section, and a guard page, while we are already modifying the linker script.
2026-09-04x86_64/cpu: reload the task registerFelix Morgner1-2/+6
When execution enters the kernel, no specific task register state has been established, leaving the power-on state of the CPU itself active. We have no control over that state, ergo we need to reload the task register to point to descriptor under our control. The earliest point when we can do that is after the new global descriptor table has been loaded. Thus this is the exact point where we do that. Additionally, reloading the TR has unveiled another latent bug that was present since the early days of the CPU initialization code: The TSS descriptor was actually incorrect. The reason for this not having been revealed earlier, is that the CPU was quietly using the TR set up by by its own power-on bootstrap. Once a load with the existing, non-TSS, descriptor was issued, A #GP was triggered because the CPU detected that the referenced TSS descriptor is not in fact a TSS descriptor (subtype 0x9): ----- BEGIN EXCEPTION DUMP ----- check_exception old: 0xffffffff new 0xd 0: v=0d e=0028 i=0 cpl=0 IP=0008:ffffffff80281b12 pc=ffffffff80281b12 SP=0010:ffffffff80216390 env->regs[R_EAX]=0000000000000028 RAX=0000000000000028 RBX=0000000000000000 RCX=ffffffff80216100 RDX=ffffffff8010fca0 RSI=0000000000000050 RDI=ffffffff80216260 RBP=ffffffff802163d0 RSP=ffffffff80216390 R8 =ffffffff802160f7 R9 =ffffffff80115328 R10=ffffffff8021626c R11=0000000000000000 R12=0000000000000000 R13=0000000000000000 R14=0000000000000000 R15=0000000000000000 RIP=ffffffff80281b12 RFL=00000092 [--S-A--] CPL=0 II=0 A20=1 SMM=0 HLT=0 ES =0010 0000000000000000 ffffffff 00cf9300 DPL=0 DS [-WA] CS =0008 0000000000000000 ffffffff 00af9800 DPL=0 CS64 [---] SS =0010 0000000000000000 ffffffff 00cf9300 DPL=0 DS [-WA] DS =0010 0000000000000000 ffffffff 00cf9300 DPL=0 DS [-WA] FS =0010 0000000000000000 ffffffff 00cf9300 DPL=0 DS [-WA] GS =0010 0000000000000000 ffffffff 00cf9300 DPL=0 DS [-WA] LDT=0000 0000000000000000 0000ffff 00008200 DPL=0 LDT TR =0000 0000000000000000 0000ffff 00008b00 DPL=0 TSS64-busy GDT= ffffffff801154e0 000001bf IDT= 0000000000000000 00000000 CR0=80000013 CR2=0000000000000000 CR3=0000000000102000 CR4=00000620 DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000 DR3=0000000000000000 DR6=00000000ffff0ff0 DR7=0000000000000400 CCS=0000000000000090 CCD=ffffffff802161f8 CCO=EFLAGS EFER=0000000000000500 ----- END EXCEPTION DUMP ----- Decoding the e= value of the exception shows that the #GP occurred while the CPU was trying to process index 5 of the GDT (bits 3-15 define the index, with e=0028 being 0000'0000'0010'1000 => index 5). The layout of a system segment descriptor differs from a normal segment descriptor in that the accessed, read/write, conforming, and executable bits change their meaning into a 4-bit subtype number. For a TSS descriptor, this subtype number must be 9. In the future, the data structures of the GDT implementation should be revised to ensure this kind of misconfiguration can not happen again.
2026-09-03x86_64/cpu: fix GDT size calculationFelix Morgner1-1/+1
The GDT pointer already receives the size in bytes when the GDT constructs it to activate the new GDT. Previously, the size in bytes got multiplied by the size of a single segment_descriptor before performing the mandatory subtraction of one. This means that the CPU lived in the believe that the GDT had a size of 448 bytes, instead of the true 56. Additionally, the calculation was flawed in another way, revealing the reason for why the size in bytes was passed to global_descriptor_table_pointer in the first place: it assumes that all entries in the GDT are of the same size. However, system descriptors are larger than basic segment descriptors.
2026-09-03x86_64: replace unreachable builtinFelix Morgner1-1/+2
2026-09-03fs, devices: fix undefined behavior in registrationFelix Morgner1-4/+13
2026-09-03chore: fix header guardsFelix Morgner29-59/+59
2026-09-03chore: add missing return typesFelix Morgner3-6/+6
2026-09-01chore: clean up facet idsFelix Morgner4-6/+9
2026-08-31chore: minor stylistic cleanupsFelix Morgner1-2/+1
2026-08-29chore: normalize panic messagesFelix Morgner11-30/+30
2026-08-29chore: apply stylistic cleanupsFelix Morgner2-16/+17
2026-08-26kernel/fs: rework filesystem probingFelix Morgner1-3/+3
2026-08-26build: fix include pathsFelix Morgner1-5/+1
2026-08-20chore: clean up some more doc commentsFelix Morgner1-4/+8
2026-08-20build: clean up header set verificationFelix Morgner1-4/+0
2026-08-20chore: normalize comment format in archFelix Morgner5-141/+107
2026-08-19kapi: use bytes for size in boot modulesFelix Morgner1-1/+3
2026-08-18kstd: flatten units namespaceFelix Morgner5-7/+6
2026-08-17kernel: minor post-epic cleanupsFelix Morgner1-2/+2
2026-08-01kapi: add automatic driver registrationFelix Morgner7-44/+72
2026-07-29x86_64: fix use-before-init in cpu bus initFelix Morgner1-3/+3
2026-07-29kernel: improve minor number allocationFelix Morgner2-3/+3
2026-07-28x86_64: move cpu related driversFelix Morgner3-5/+5
2026-07-28chore: post refactoring cleanupFelix Morgner7-13/+15
2026-07-28x86_64: split lapic according to UDMFelix Morgner19-232/+589
2026-07-27x86_64: port PIT to devices resourcesFelix Morgner4-12/+83
2026-07-26kapi: implement a simple, tracked mutexFelix Morgner1-0/+6
2026-07-26kapi: move protocol pointer to base busFelix Morgner2-14/+1
2026-07-26chore: minor cleanups after refactoringFelix Morgner1-4/+2
2026-07-26chore: replace "interface" with "facet"Felix Morgner6-19/+27
2026-07-25kapi: introduce driver namesFelix Morgner2-0/+7
2026-07-25chore: hide protocol implementationsFelix Morgner2-34/+34
2026-07-24kernel: remove boot modules registryFelix Morgner1-9/+14
2026-07-24x86_64: clean up isa driversFelix Morgner6-18/+29
2026-07-24kapi: rename interface to interface_idFelix Morgner6-7/+6
2026-07-24kapi: rename boot_module to moduleFelix Morgner1-3/+2
2026-07-24kapi: extract real boot module registry singletonFelix Morgner1-18/+4
2026-07-24kapi: clean up directory namesFelix Morgner1-2/+2
2026-07-24x86_64: split files for devices and driversFelix Morgner11-106/+179
2026-07-24kapi/interrupts: add ISR contextFelix Morgner2-7/+11