Bug-fix sweep: repl reentrancy, virtio/blocksys bounds, identity CRCs, LOG_LINE_MAX
Code review fixes, all compile clean (hosted gcc + aarch64/riscv64 kernel flags):
- repl.c (H1): reentrancy guards on the MSG-TICK idle pump. sk_repl_idle()
now defers when Hera is mid-interpret (g_mama_interpreting) or when its
own vm_interpret is on the stack (g_idle_pump_active), so a blocking
KEY/EXPECT/QUERY inside a dispatched line can no longer re-enter the
interpreter and clobber the in-flight input buffer.
- virtio_rng.c: clamp device-returned used_len to VRNG_BUF_SIZE before the
caller's data_buf copy, closing a device-controlled OOB read.
- block_subsystem.c: first-write path now keys off created_time==0 instead
of dead magic==0 so fresh blocks get a real created_time stamp; first_free/
last_allocated fixed to absolute Forth LBNs (set in blk_compute_fresh_geometry
from slot->start_lbn, no longer the wrong physical-BAM-index values from
compute_totals_from_B); physical-bounds guard on blk_meta_zone_read/write
prevents unsigned underflow on a corrupt fence >= device size.
- capsule_zuse_boot.c / capsule_wirebind.c: identity seed validated magic ->
version -> CRC-64 (compute_crc64 over offsetof(crc)) before trusting it,
so a corrupt/format-mismatched record is refused, never loaded.
- log.h / starkernel/log.h: unused LOG_LINE_MAX 256 renamed LOG_MSG_LINE_MAX
to lift the include-order collision with vm.h's LOG_LINE_MAX 64; stale
include-order comments dropped (kernel_main.c, shim.c, capsule_birth.c).
- FABRIC-3.md: three stale-doc carry-forward items closed [x] with cbe7b49
notes.
Real KEY/?TERMINAL/QUERY/EXPECT bodies (console WIP):
- repl.h/repl.c: sk_console_getkey()/sk_console_key_available()/
sk_console_readline() public bodies; non-destructive peek buffers the
found byte so a following KEY returns it.
- shim.c: getchar()/fgetc()/fgets()/sf_terminal_ready() routed through the
real console paths instead of stubs; sf_terminal_ready() in platform_io.h
with sf_terminal_ready() implemented for the hosted build (linux/io.c,
POSIX select on fd 0) wired into Makefile.
- io_words.c: ?TERMINAL now returns actual terminal-readiness, not constant 0.
Artifacts: minted disk/artemis.img + rebuilt lfs kernel; BLOCK_MAP.md,
doe csv + qemu log regenerated.
This commit is contained in:
+7
-2
@@ -44,8 +44,13 @@
|
||||
#define LOG_H
|
||||
|
||||
/* Maximum log line size for persistent logging */
|
||||
#ifndef LOG_LINE_MAX
|
||||
#define LOG_LINE_MAX 256
|
||||
/* Renamed from LOG_LINE_MAX: vm.h owns that name for the persistent
|
||||
* block-log line width (64, unrelated concept). This is the in-memory log
|
||||
* message-formatting line length; keeping a distinct name removes the
|
||||
* include-order collision that forced a fragile "vm.h before log.h"
|
||||
* convention across the kernel (kernel_main.c/shim.c/capsule_birth.c). */
|
||||
#ifndef LOG_MSG_LINE_MAX
|
||||
#define LOG_MSG_LINE_MAX 256
|
||||
#endif
|
||||
|
||||
/* Forward declaration */
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
/*
|
||||
StarForth — Steady-State Virtual Machine Runtime
|
||||
|
||||
Copyright (c) 2023–2025 Robert A. James
|
||||
All rights reserved.
|
||||
|
||||
This file is part of the StarForth project.
|
||||
|
||||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
|
||||
You may obtain a copy of the License at:
|
||||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||||
|
||||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||
express or implied, including but not limited to the warranties of
|
||||
merchantability, fitness for a particular purpose, and noninfringement.
|
||||
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
|
||||
*/
|
||||
|
||||
/*
|
||||
* platform_io.h - Portable terminal-input-readiness check for StarForth
|
||||
*
|
||||
* One function, same shape as platform_lock.h/platform_time.h: a single
|
||||
* portable declaration, implemented once per platform (POSIX select() on
|
||||
* fd 0 for the hosted build, src/platform/linux/io.c; the kernel's own
|
||||
* console/keyboard-event bridge for the freestanding build, shim.c).
|
||||
* Backs the standard dictionary's ?TERMINAL word (io_words.c).
|
||||
*/
|
||||
|
||||
#ifndef STARFORTH_PLATFORM_IO_H
|
||||
#define STARFORTH_PLATFORM_IO_H
|
||||
|
||||
/**
|
||||
* @brief Non-blocking check for whether a key/character is available to read.
|
||||
*
|
||||
* Must not block and must not consume the byte if one is found (a
|
||||
* following KEY/getchar() must still return that same byte).
|
||||
*
|
||||
* @return 1 if input is ready, 0 otherwise
|
||||
*/
|
||||
int sf_terminal_ready(void);
|
||||
|
||||
#endif /* STARFORTH_PLATFORM_IO_H */
|
||||
@@ -29,8 +29,13 @@
|
||||
/* Forward declaration — matches hosted log.h */
|
||||
struct VM;
|
||||
|
||||
#ifndef LOG_LINE_MAX
|
||||
#define LOG_LINE_MAX 256
|
||||
/* Renamed from LOG_LINE_MAX: vm.h owns that name for the persistent
|
||||
* block-log line width (64, unrelated concept). This is the in-memory log
|
||||
* message-formatting line length; keeping a distinct name removes the
|
||||
* include-order collision that forced a fragile "vm.h before log.h"
|
||||
* convention across the kernel. */
|
||||
#ifndef LOG_MSG_LINE_MAX
|
||||
#define LOG_MSG_LINE_MAX 256
|
||||
#endif
|
||||
|
||||
/**
|
||||
|
||||
@@ -89,6 +89,44 @@ const homeblocks_sig_t *sk_repl_get_homeblocks_sig(void);
|
||||
*/
|
||||
struct blkio_dev *sk_repl_get_attached_blk_dev(void);
|
||||
|
||||
/**
|
||||
* sk_console_getkey - Real body of the standard dictionary's KEY word
|
||||
* (called from shim.c's getchar()). Blocks until a key is available from
|
||||
* either input source (serial console or the PS2/virtio keyboard-event
|
||||
* bridge), servicing the heartbeat/idle loop while waiting so a KEY call
|
||||
* from inside any word never stalls the heartbeat. No echo -- that's the
|
||||
* caller's responsibility, same as any standard KEY.
|
||||
*
|
||||
* @param active_vm VM whose idle dispatch runs while waiting (see
|
||||
* sk_repl_idle()'s own doc comment on why this is a
|
||||
* parameter rather than read via sk_repl_get_active_vm())
|
||||
* @return the key read, as an unsigned byte value
|
||||
*/
|
||||
int sk_console_getkey(VM *active_vm);
|
||||
|
||||
/**
|
||||
* sk_console_key_available - Real body of the standard dictionary's
|
||||
* ?TERMINAL word (called from sf_terminal_ready()). Non-blocking peek:
|
||||
* returns 1 if a key is ready without consuming it (a following
|
||||
* sk_console_getkey() returns that exact key), 0 otherwise.
|
||||
*/
|
||||
int sk_console_key_available(void);
|
||||
|
||||
/**
|
||||
* sk_console_readline - Real body of the standard dictionary's
|
||||
* QUERY/EXPECT words (called from shim.c's fgets()). Reads one line from
|
||||
* the console with echo and backspace support, servicing the heartbeat/
|
||||
* idle loop while waiting -- the same line editor the REPL's own prompt
|
||||
* uses internally, so a mid-word EXPECT behaves identically to typing at
|
||||
* "ok>" itself.
|
||||
*
|
||||
* @param buf Destination buffer
|
||||
* @param size Buffer capacity, including the NUL terminator
|
||||
* @param active_vm VM whose idle dispatch runs while waiting
|
||||
* @return number of characters placed in buf, not counting the NUL
|
||||
*/
|
||||
int sk_console_readline(char *buf, int size, VM *active_vm);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user