Second stage of the preemptive context-switching plan. Every VM (Hera, every capsule_birth_baby()-born VM including WIREBIND identities) now gets its own dedicated 2 MiB native C stack at birth -- but nothing runs on it yet, that's Stage 2. Pure allocation-machinery proof. Design correction made before writing code: the plan called for cloning sk_vm_arena_alloc()'s guard-page pattern, but that pattern turns out to be Mama-only -- host_services.c's kernel_alloc() gives every baby VM a plain kmalloc() block for its dictionary arena, not a real guarded PMM allocation. Stacks get the real treatment instead (new sk_vm_native_stack_alloc()/_free() in arena.c): independent pmm_alloc_contiguous() + guard pages for every VM without exception, no singleton, no kmalloc fallback -- a stack overflow is exactly the failure mode guard pages exist for, and a corrupted stack could corrupt whatever saved context Stage 2 trusts. 2 MiB size matches this project's own established kernel-stack convention (g_kernel_stack/g_rpi5_native_stack), not a guess -- that one shared 2 MiB stack today already carries all VMs' combined nested VM-EXEC recursion. Three new VM struct fields, freed in vm_cleanup() alongside the existing call_stack free. Allocation failure is non-fatal to birth. All 3 architectures re-verified clean boot to ok>, no native-stack allocation failures for any Tripod-fleet VM. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016UNhH1mhi52i6Qihh7ZV5S
97 lines
3.5 KiB
C
97 lines
3.5 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
This file is part of the StarForth project.
|
||
|
||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
|
||
You may obtain a copy of the License at:
|
||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||
|
||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||
express or implied, including but not limited to the warranties of
|
||
merchantability, fitness for a particular purpose, and noninfringement.
|
||
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|
||
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
This file is part of the StarForth project.
|
||
|
||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
|
||
You may obtain a copy of the License at:
|
||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||
|
||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||
express or implied, including but not limited to the warranties of
|
||
merchantability, fitness for a particular purpose, and noninfringement.
|
||
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|
||
|
||
*/
|
||
|
||
/**
|
||
* arena.h - VM arena management for StarKernel builds.
|
||
*
|
||
* Hosted builds never include this header. Kernel integration layers use it
|
||
* to provision the PMM-backed VM arena before handing memory to the VM core.
|
||
*/
|
||
|
||
#ifndef STARKERNEL_VM_ARENA_H
|
||
#define STARKERNEL_VM_ARENA_H
|
||
|
||
#ifdef __STARKERNEL__
|
||
|
||
#include <stddef.h>
|
||
#include <stdint.h>
|
||
|
||
uint64_t sk_vm_arena_alloc(void);
|
||
void sk_vm_arena_free(void);
|
||
uint8_t *sk_vm_arena_ptr(void);
|
||
size_t sk_vm_arena_size(void);
|
||
int sk_vm_arena_is_initialized(void);
|
||
void sk_vm_arena_assert_guards(const char *tag);
|
||
|
||
/**
|
||
* sk_vm_native_stack_t - one VM's own dedicated native (C) stack.
|
||
*
|
||
* FABRIC-3.md §XXVIII (Stage 1, preemptive-context-switch per-VM native
|
||
* stacks, 2026-09-13). Unlike sk_vm_arena_alloc() -- whose PMM+guard-page
|
||
* path is exercised only for Hera; every baby VM's "arena" is actually a
|
||
* plain kmalloc block, per host_services.c's kernel_alloc() -- every native
|
||
* stack, for every VM without exception, gets its own real, independent
|
||
* pmm_alloc_contiguous() allocation with guard pages. A stack overflow is
|
||
* exactly the failure mode guard pages exist for, and unlike the dictionary
|
||
* arena, a corrupted stack can also corrupt whatever saved context Stage 2
|
||
* later trusts -- worth the extra PMM pages every VM, not just Hera.
|
||
*
|
||
* Caller owns this struct (stored directly on the VM, mirroring how
|
||
* vm->memory already holds its own arena pointer directly rather than going
|
||
* through any module-level registry) and passes it back unchanged to
|
||
* sk_vm_native_stack_free().
|
||
*/
|
||
typedef struct {
|
||
uint64_t paddr; /* physical base (for pmm_free_contiguous) */
|
||
uint64_t guard_vaddr; /* virtual base of the whole guarded region */
|
||
uint64_t stack_top; /* initial SP value -- stacks grow down on all
|
||
* 3 arches, so this is guard_vaddr + one guard
|
||
* page + the full stack size */
|
||
} sk_vm_native_stack_t;
|
||
|
||
int sk_vm_native_stack_alloc(sk_vm_native_stack_t *out);
|
||
void sk_vm_native_stack_free(const sk_vm_native_stack_t *stack);
|
||
|
||
#endif /* __STARKERNEL__ */
|
||
|
||
#endif /* STARKERNEL_VM_ARENA_H */
|