Files
RedBear-OS/drivers
Red Bear OS 260003331e xhcid: fix restart_endpoint deadlock, doorbell ordering, NoOp priming (P2-C)
Three bugs in the xHCI endpoint-restart path used by all error recovery
(stall hard reset, transaction-error soft retry, resource retry,
split/babble hard reset):

1. Latent deadlock: restart_endpoint held the port_states write guard
   across set_tr_deque_ptr(), which internally re-acquires a read guard
   on the same key (std RwLock read-while-write on one thread).
   Unobserved because error injection is not yet exercised at runtime
   (P8-C). Fixed by scoping phase-1 ring priming so the guard drops
   before the async command.

2. Doorbell ordering violated xHCI spec 4.6.8/4.6.10: after Reset
   Endpoint the TR Dequeue Pointer is undefined, so Set TR Dequeue
   Pointer must complete BEFORE the doorbell transitions the endpoint
   Stopped->Running. The old order (doorbell first) ran the endpoint
   with an undefined dequeue pointer — undefined xHC behavior on real
   hardware. Linux rings the doorbell from the Set TR Dequeue command
   completion path (xhci_handle_cmd_set_deq, ring.c:1416-1554); xhcid
   now issues Set TR Dequeue, awaits completion, then rings.

3. Priming NoOp never executed: ring.register() was captured after
   ring.next() advanced the enqueue index, so the dequeue pointed past
   the NoOp (dead TRB). Now captured before next(), priming the
   hardware dequeue AT the NoOp so the xHC executes it on restart —
   same semantics as Linux xhci_move_dequeue_past_td pointing at the
   first valid TRB.

Verified: cargo check clean (138 warnings, unchanged), 43/43 tests pass.
2026-07-18 23:14:14 +09:00
..
2026-04-14 21:18:43 +02:00

Drivers

Libraries

  • amlserde - Library to provide serialization/deserialization of the AML symbol table from ACPI
  • common - Library with shared driver code
  • executor - Library to run Rust futures and integrate the executor in an interrupt+queue model without a separated reactor thread
  • graphics/console-draw - Library with shared terminal drawing code
  • graphics/driver-graphics - Library with shared graphics code
  • graphics/graphics-ipc - Library with graphics IPC shared code
  • net/driver-network - Library with shared networking code
  • storage/partitionlib - Library with MBR and GPT code
  • storage/driver-block - Library with shared storage code
  • virtio-core - VirtIO driver library

Services

  • graphics/fbbootlogd - Daemon for boot log drawing
  • graphics/fbcond - Terminal daemon
  • hwd - Daemon that handle the ACPI and DeviceTree booting
  • inputd - Multiplexes input from multiple input drivers and provides that to Orbital
  • pcid-spawner - Daemon for PCI-based device driver spawn
  • storage/lived - Daemon for live disk
  • redoxerd - Daemon that send/receive terminal text between the host system and QEMU

Hardware Interfaces

  • acpid - ACPI interface driver
  • pcid - PCI and PCI Express driver

Devices

CPU

  • rtcd - x86 Real Time Clock driver

Controllers

Storage

Graphics

Input

Sound

Networking

Virtualization

  • vboxd - VirtualBox driver

Some drivers are work-in-progress and incomplete, read this tracking issue to verify.

System Interfaces

This section explain the system interfaces used by drivers.

System Calls

  • iopl : system call that sets the I/O privilege level. x86 has four privilege rings (0/1/2/3), of which the kernel runs in ring 0 and userspace in ring 3. IOPL can only be changed by the kernel, for obvious security reasons, and therefore the Redox kernel needs root to set it. It is unique for each process. Processes with IOPL=3 can access I/O ports, and the kernel can access them as well.

Schemes

  • /scheme/memory/physical : Allows mapping physical memory frames to driver-accessible virtual memory pages, with various available memory types:
    • /scheme/memory/physical : Default memory type (currently writeback)
    • /scheme/memory/physical@wb Writeback cached memory
    • /scheme/memory/physical@uc : Uncacheable memory
    • /scheme/memory/physical@wc : Write-combining memory
  • /scheme/irq : Allows getting events from interrupts. It is used primarily by listening for its file descriptors using the /scheme/event scheme.

Contribution Details

Driver Design

A device driver on Redox is an user-space daemon that use system calls and schemes to work, while operating systems with monolithic kernels drivers use internal kernel APIs instead of common program APIs.

If you want to port a driver from a monolithic operating system to Redox you will need to rewrite the driver with reverse enginnering of the code logic, because the logic is adapted to internal kernel APIs (it's a hard task if the device is complex, datasheets are much more easy).

Write a Driver

Datasheets are preferable (much more easy depending on device complexity), when they are freely available. Be aware that datasheets are often provided under a Non-Disclosure Agreement from hardware vendors, which can affect the ability to create an MIT-licensed driver.

If datasheets aren't available you need to do reverse-engineering of BSD or Linux drivers (if you want use a Linux driver as reference for your Redox driver please ask in the Chat before the implementation to know/satisfy the license requirements and not waste your time, also if you use a BSD driver not licensed as BSD as reference).

Libraries

You should use the redox-scheme and redox_event libraries to create your drivers, you can also read the example driver or read the code of other drivers with the same type of your device.

Before testing your changes be aware of this.

References

If you want to reverse enginner the existing drivers, you can access the BSD code using these links:

How To Contribute

To learn how to contribute to this system component you need to read the following document:

Development

To learn how to do development with this system component inside the Redox build system you need to read the Build System and Coding and Building pages.

How To Build

To build this system component you need to download the Redox build system, you can learn how to do it on the Building Redox page.

This is necessary because they only work with cross-compilation to a Redox virtual machine or real hardware, but you can do some testing from Linux.

Back to top