Stage 1: per-VM native stacks, allocated but not yet executed on (FABRIC-3.md §XXVIII)
Second stage of the preemptive context-switching plan. Every VM (Hera, every capsule_birth_baby()-born VM including WIREBIND identities) now gets its own dedicated 2 MiB native C stack at birth -- but nothing runs on it yet, that's Stage 2. Pure allocation-machinery proof. Design correction made before writing code: the plan called for cloning sk_vm_arena_alloc()'s guard-page pattern, but that pattern turns out to be Mama-only -- host_services.c's kernel_alloc() gives every baby VM a plain kmalloc() block for its dictionary arena, not a real guarded PMM allocation. Stacks get the real treatment instead (new sk_vm_native_stack_alloc()/_free() in arena.c): independent pmm_alloc_contiguous() + guard pages for every VM without exception, no singleton, no kmalloc fallback -- a stack overflow is exactly the failure mode guard pages exist for, and a corrupted stack could corrupt whatever saved context Stage 2 trusts. 2 MiB size matches this project's own established kernel-stack convention (g_kernel_stack/g_rpi5_native_stack), not a guess -- that one shared 2 MiB stack today already carries all VMs' combined nested VM-EXEC recursion. Three new VM struct fields, freed in vm_cleanup() alongside the existing call_stack free. Allocation failure is non-fatal to birth. All 3 architectures re-verified clean boot to ok>, no native-stack allocation failures for any Tripod-fleet VM. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016UNhH1mhi52i6Qihh7ZV5S
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
15672ce17c
commit
57ac3fc304
@@ -645,6 +645,16 @@ typedef struct VM
|
||||
int call_stack_max; /**< High-water mark depth (DoE metric) */
|
||||
/** @} */
|
||||
|
||||
/** @name Native execution stack (FABRIC-3.md §XXVIII, Stage 1, 2026-09-13)
|
||||
* @{
|
||||
*/
|
||||
uint64_t native_stack_paddr; /**< Physical base (for teardown); 0 = not allocated */
|
||||
uint64_t native_stack_guard_vaddr; /**< Virtual base of the whole guarded region */
|
||||
uint64_t native_stack_top; /**< Initial SP value once something switches onto
|
||||
* this stack -- Stage 1 only allocates it; nothing
|
||||
* yet runs here (that's Stage 2). */
|
||||
/** @} */
|
||||
|
||||
/** @name Stadium Identity (item 4.2, FABRIC-0.md §25.5)
|
||||
* @{
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user