Root cause of the G.1 follow-up boot-time attach race: on pathological controller behavior the xhci_poll_events() drain loop had no hard ceiling. ERDP is written back only when the loop exits, so the controller cannot reclaim event TRBs mid-drain; if it keeps producing events the head can chase the software dequeue pointer forever. xhci_poll_events() never returns, sk_repl_idle() never reaches its bot_msc_attach_pending check, and a fresh USB BOT device that finished SET_CONFIGURATION is left flagged-but-never- attached while the guest appears hung. Fix: bound the drain to a full ring (XHCI_EVT_RING_MAX_DRAIN = 256), so xhci_poll_events() always terminates and always writes ERDP each call. Unprocessed events keep their cycle bit and are re-read next poll; nothing is dropped. On the healthy path one drain processes only the one-or-few events the controller posts per chained command, so the bound never triggers except in the pathological case it breaks. Beyond the G.1 additions: a new macro in include/starkernel/xhci.h and a bounded loop in src/starkernel/usb/xhci.c. Builds clean on amd64. Verified across six consecutive fresh QEMU boots (previously intermittently hung).
include/starkernel/
Headers for LithosAnanke, the bare-metal UEFI kernel (src/starkernel/).
Built only via Makefile.starkernel; gated by __STARKERNEL__ when shared
with hosted code.
uefi.h— UEFI protocol/type definitions consumed by the loader.elf64.h,elf_loader.h— ELF64 parsing and kernel-image loading.boot_info_offsets.h— struct-offset constants shared between the assembly bootstrap and the C boot path.arch.h,apic.h,timer.h— architecture init, APIC interrupt controller, timer (TSC/HPET/APIC, 100 Hz heartbeat).console.h,framebuffer.h,vt100.h— UART 16550 console, framebuffer driver, and VT100 terminal emulation over the framebuffer.pmm.h,vmm.h,kmalloc.h— physical memory manager (bitmap allocator), 4-level x86_64 paging, kernel heap allocator.pci.h,virtio_blk.h— PCI enumeration and the VirtIO block device driver (disk backend for the kernel block subsystem).capsule.h,capsule_birth.h,capsule_loader.h,capsule_run.h,capsule_vm_physics.h,capsule_generated.h— capsule system types, birth protocol, physics-runtime capsule bindings, and the build-time- generated capsule directory (seetools/mkcapsule.c).kernel_args.h,cmdline.h— boot-time kernel argument parsing (starforth.cfg/ command line).repl.h— kernel REPL.log.h,doe_log.h— kernel logging and DoE metrics logging.q48_16.h— kernel-build copy of Q48.16 fixed-point arithmetic.xxhash64.h— content-addressing hash used for capsule IDs.hal_memory.h— hardware-abstraction-layer memory interface.
Subdirectories:
hal/— top-level hardware-abstraction-layer interface.vm/— kernel VM subsystem headers (capsule arena, parity logging, bootstrap wiring).freestanding/— minimal libc-shim headers (assert.h,ctype.h,errno.h,inttypes.h,math.h,sched.h,signal.h,stdio.h,stdlib.h,string.h,time.h,sys/time.h,sys/types.h) for building shared VM code in the freestanding kernel environment, where no real libc is available.