Commit Graph

2646 Commits

Author SHA1 Message Date
4lDO2 ff33090fd0 Check whether RCX is canonical in sysretq. 2021-02-15 19:53:41 +01:00
4lDO2 a183953ee8 Motivate usage of the IST without SWAPGS involved. 2021-02-15 19:53:37 +01:00
4lDO2 a3583a10ce Only swapgs when leaving/entering userspace code. 2021-02-15 19:53:37 +01:00
4lDO2 05db0f5977 Temporarily fix sysretq by swapping gs 4 times.
In order words, it swaps gs both directly at the start of the syscall
handler, then swaps it back, and the at the end of the syscall handler.
I cannot tell for sure why this is necessary, but probably since some
interrupt handler will execute swapgs in the wrong order or something.
2021-02-15 19:53:37 +01:00
4lDO2 1a8016b985 Give NMI, #DF, and #MC handlers a special stack.
This is done by allocating an extra 64 KiB per CPU, and putting it in
the Interrupt Stack Table.
2021-02-15 19:53:37 +01:00
4lDO2 5a638691e0 Treat GS as always pointing to TSS in kernel space. 2021-02-15 19:53:37 +01:00
4lDO2 c913c3be80 Use sysretq in usermode(). 2021-02-15 19:53:24 +01:00
4lDO2 a8dc3fcaf1 Begin using sysretq in the system call handler. 2021-02-15 19:53:01 +01:00
Jeremy Soller 6db78cce24 Use UTF-8 for all paths 2021-02-14 13:45:03 -07:00
Jeremy Soller 11b5e2fe59 Merge branch 'switch_to_safer' into 'master'
Prevent possible UB, and use naked functions correctly.

See merge request redox-os/kernel!167
2021-02-13 22:42:18 +00:00
4lDO2 a706a0dae4 Rewrite signal_handler_wrapper as single asm block.
The reason for these types of rewrites, is that more recent Rust
compilers have started to deprecate naked functions that consist of more
than only a single asm block, as they can trigger all sorts of UB.
2021-02-13 21:55:40 +01:00
4lDO2 47c3b2269f Fix context switching.
Previously there was a triple fault, due to a combination of reasons
(e.g. rsp and rbp being ordered in the struct and in the assembly).

Now, the locks will be held __all the way until the new context__ has
been switched to, which completely eliminates any possibility that the
"pcid fault" originates here.

While I am unsure whether this will work, this could also be an
opportunity to be able to remove CONTEXT_SWITCH_LOCK fully.
2021-02-13 21:55:40 +01:00
4lDO2 ef4270e473 WIP: Attempt to rewrite switch_to in assembly.
This is due to a warning in more recent compilers, which forbid anything
but a single inline assembly block, in naked functions. It does
unfortunately triple fault right now, but I hope I may be able to fix it
soon.
2021-02-13 21:55:36 +01:00
Jeremy Soller c19bd573b5 Switch Context::grants to RwLock 2021-02-13 13:06:13 -07:00
Jeremy Soller 2611985a38 Switch Context::actions to RwLock 2021-02-13 13:01:20 -07:00
Jeremy Soller bfaf8438a1 Switch Context::files to RwLock 2021-02-13 12:57:53 -07:00
Jeremy Soller 55d2467420 Switch Context::cwd to using RwLock 2021-02-13 12:24:19 -07:00
Jeremy Soller cd6ede84fe Fix warnings from futex changes 2021-02-13 12:16:55 -07:00
Jeremy Soller 238702f7d1 Require UTF-8 for context name 2021-02-13 12:16:47 -07:00
Jeremy Soller b9f4a915ea Make context name a RwLock 2021-02-13 11:10:21 -07:00
Jeremy Soller 76d8c1074c Merge branch 'futex-fix' into 'master'
Use physical addresses internally in futex, and fix a context switching data race

See merge request redox-os/kernel!166
2021-02-13 17:52:09 +00:00
4lDO2 6f3fc3a4f4 Make cpu_id_opt non-mutable. 2021-02-03 18:10:39 +01:00
4lDO2 44527a8340 Fix a very annoying multi_core data race*.
So, when I first introduced io_uring, it was not compiled with the
`multi_core` kernel feature, mainly to make development easier (I
thought). However, since io_uring allows multiple simultaneous system
calls, we cannot longer make the in-kernel contexts block, for example
when receiving a message from a pipe, if there can be multiple such
requests simultaneously.

This has required me to change WaitCondition into allowing multiple
simultaneous tasks; although, it introduces a potential race condition:
since a future can only return Pending and not block directly before
releasing the lock (condvar logic), we need some way to make sure that
nothing happens after the context finds out that it has to wait, and the
actual waiting. If a message is pushed in between, and the waker is
called (Context::unblock), just before it was going to block itself,
then we miss the message, and potentially cause a deadlock.

Fortunately, in order to block and unblock contexts, we need to
exclusively lock the context. So, what we can do to ensure that waking
while running is no longer a no-op, is to introduce a "wake flag", which
is set only if the context is currently running, and Runnable.

But, this still caused all weird kinds of hard-to-debug problems, with
arbitrary CPU exceptions and possibly memory corruption. The reason for
this, is that the context switching logic uses really unsafe operations,
which is why context switching (at the moment) requires an exclusive
lock. Before this commit, it would modify the `running` field after the
lock had been released, which obviously can cause a data race, when the
regular context waker code that is run within a system call, locks the
context but not the global switching lock.

The solution was to make sure that the locks were held, all the way
until the actual switching, which was done in assembly. There can still
be a race condition here, since it modifies memory containing registers
after the lock has been released, even if it may be behind &mut on
another context, which can be UB, but it has not contributed to any
actual bugs... yet.

* I have not yet done that rigorous testing, but it appears to work well
enough, and I have not encountered the bug after like 10 tries.
2021-02-03 18:06:42 +01:00
4lDO2 fec8f4aa0c Use physical addresses internally for futexes.
This solves a bug, that allows processes in different address spaces to
be the target of a futex wakeup call, even though that process is in
another address space!
2021-02-03 18:06:42 +01:00
Jeremy Soller 31887bf532 Merge branch 'floating-point-fixups' into 'aarch64-rebase'
Floating point fixups

See merge request redox-os/kernel!165
2021-01-28 17:02:32 +00:00
Robin Randhawa 1e10cac3e1 aarch64: Increase storage for FP context to consider AArch64's needs
Brute-forcing this at present. Would be better to wrap this
conditionally for the architecture.
2021-01-28 16:51:50 +00:00
Robin Randhawa afca6ab31c aarch64: Fix incorrect FP save/restore 2021-01-28 16:50:07 +00:00
Jeremy Soller a06636b77f Update syscall 2021-01-27 10:44:52 -07:00
Jeremy Soller f8f1596f67 Merge branch 'add-floating-point-support' into 'aarch64-rebase'
Add floating point support

See merge request redox-os/kernel!164
2021-01-27 17:43:57 +00:00
Robin Randhawa 4dbfaf3ec1 Nit: Add missing close brace in code comment 2021-01-27 17:19:37 +00:00
Robin Randhawa 1462fe8638 aarch64: context: Align with x86_64 code 2021-01-27 17:17:59 +00:00
Robin Randhawa 3afa0f0895 aarch64: Basic Floating-point/SIMD support 2021-01-27 17:17:11 +00:00
Robin Randhawa 00723c4ac2 aarch64: Make IRQs use the exception macros 2021-01-26 19:37:23 +00:00
Jeremy Soller 9621c64991 Update syscall 2021-01-26 11:46:09 -07:00
Jeremy Soller 81c33a3f6a Merge branch 'aarch64-base' into 'aarch64-rebase'
Misc exception handling fixups

See merge request redox-os/kernel!163
2021-01-26 18:41:53 +00:00
Robin Randhawa 28dfc0f46b aarch64: Basic exception handlers 2021-01-26 18:18:19 +00:00
Robin Randhawa 4a215c7c2c aarch64: exception management and clone fixups 2021-01-26 18:17:09 +00:00
Jeremy Soller fa62b48285 Merge branch 'fixes-for-grant-maps-and-others' into 'aarch64-rebase'
Fixes for grant maps and others

See merge request redox-os/kernel!162
2021-01-22 15:15:08 +00:00
Robin Randhawa 78d1cd1798 syscall: process: empty: Use user-space specific page table 2021-01-21 11:53:35 +00:00
Robin Randhawa 6cacbb47f6 scheme: user: Use user-space specific pagt table 2021-01-21 11:53:07 +00:00
Robin Randhawa 591775874b ptrace: with_context_memory: use user-space specific page table 2021-01-21 11:50:56 +00:00
Robin Randhawa 65448c2d48 aarch64: context: memory: Grant::map_inactive: Bugfix
When mapping one (from) virtual address range to another (to) virtual
address range, be mindful of which mapper type to use for each range.

Before this, the same mapper type was used for both ranges. This meant
that if from and to were different (as in not both kernel virtual
addresses or user virtual addresses) then it would appear that either
from or to was not mapped previously and the kernel would panic.
2021-01-21 11:41:26 +00:00
Robin Randhawa 75870a655f aarch64: context: Add separate kspace and uspace page table getters 2021-01-21 11:40:02 +00:00
Robin Randhawa 3da345867a aarch64: paging: Derive Debug, PartialEq for VirtualAddressType
This makes asserts on VirtualAddressType equality possible.
2021-01-21 11:38:46 +00:00
Robin Randhawa 452196b81f aarch64: consts: Use the same USER_TLS_SIZE as x86_64 2021-01-21 11:37:32 +00:00
Jeremy Soller d76298b3f8 Merge branch 'wip-clone-and-misc-fixes' into 'aarch64-rebase'
Wip clone and misc fixes

See merge request redox-os/kernel!161
2021-01-18 23:00:00 +00:00
Robin Randhawa f1db56f026 aarch64: clone: Further uspace and kspace mods 2021-01-18 21:55:42 +00:00
Robin Randhawa 9429032cec aarch64: clone: Further clone_ret + tpidr_el0 fixes 2021-01-18 21:53:04 +00:00
Robin Randhawa fd0336692d aarch64: clone: Introduce kernel and user space specific mods
At present these are done 'wholesale' without any regard for x86_64.
That needs to change eventually.
2021-01-18 21:50:19 +00:00
Robin Randhawa c188a60871 aarch64: Fix clone_ret
FIXME: Explain the magic numbers here later.
2021-01-18 21:47:28 +00:00