Skip to content

Terminal browsing - #3

Merged
Asmodeus14 merged 3 commits into
masterfrom
terminal-browsing
Sep 9, 2026
Merged

Asmodeus14 merged 3 commits into
masterfrom
terminal-browsing

Conversation

@Asmodeus14

Copy link
Copy Markdown
Owner

No description provided.

Asmodeus14 and others added 3 commits September 9, 2026 11:23
The kernel heap was backed by physical memory below 1 MB, and AP bring-up
writes the real-mode trampoline to physical 0x8000. Every boot this project
has ever done, SMP startup scribbled through live heap pages.

BootInfoFrameAllocator walked Usable regions from the lowest address upward
and excluded nothing. UEFI marks conventional memory from roughly 0x1000 as
usable, so the earliest frames it handed out -- the ones backing the bottom
of the heap -- were inside the first megabyte. smp::init_aps then copied the
trampoline to 0x8000 and its argument block to 0x8F00. Those addresses are
not a choice: a starting AP begins in real mode and can only reach the first
megabyte.

Found by counting the ACPI namespace at boot checkpoints: 1802 root children
with a clean NULL tail before smp::init_aps, 637 and a dangling tail after.
The smashed node's Name field read 0xffff9000 -- the top half of
`*args_ptr.offset(3) = ap_stack_top`, a 0xFFFF_9000_... address from
allocate_kernel_stack, written straight through a heap block.

The namespace was only the WITNESS. It was the first structure
self-describing enough to notice the damage; everything else allocated early
was being corrupted too, silently. This is worth weighing against the
unexplained early-boot behaviour in this project's history.

Fix: LOW_MEM_RESERVED = 0x10_0000, honoured by a shared skip_low_memory()
that BOTH allocation paths call -- single-frame and multi-frame had already
drifted apart once, and a reservation only one of them respects is not a
reservation. A megabyte rather than just the trampoline page: below it are
the IVT, the BDA, the EBDA, VGA memory and option ROMs, none of it safe to
hand to a general allocator.

This unblocks AcpiInstallAddressSpaceHandler, and with it the EC handler,
_BIF/_BST, and the ACPI S5 shutdown path -- all of which had been written
off as "walks #GP this kernel".

Co-Authored-By: Claude <noreply@anthropic.com>
…p bug

SYS_POWER (568). Until now the only way to stop this machine was holding the
power button with a live ext4 mount; acpi::poweroff() had existed since the
thermal governor's 95 C emergency and nothing in userspace could reach it.

poweroff() is rewritten. The textbook AcpiEnterSleepStatePrep + EnterSleepState
pair red-screened the box on its first ever run -- it had shipped untested for
months because only an emergency reached it. ...StatePrep evaluates _PTS, a
real AML method that on this laptop writes to the embedded controller. The
narrow path now goes first: AcpiGetSleepTypeData reads \_S5_ (a static package,
evaluating nothing device-facing), then a read-modify-write of SLP_TYP+SLP_EN
into PM1a/PM1b_CNT preserving SCI_EN, then a spin -- not hlt, which makes a
machine that is not powering off look hung. Full ACPICA only as fallback.

restart() is four methods most-correct-first, because a reset that does not
reset leaves the machine in cli;hlt with the screen lit, which is
indistinguishable from the freezes this project has chased for months.

There is NO sleep action and there must not be a fake one: Nyx implements no
S3. Meridian's "sleep" is a shell state that dims the panel and says so.

boot_screen::farewell() paints a proper shutdown screen -- the cold-start
screen's mirror, same mark in the same place on the same black, so the machine
ends where it began. Painted by the KERNEL, not the shell: the shell is blocked
inside the syscall, and a shutdown reached any other way would otherwise show
nothing. No progress rule -- the cold-start rule advances on seven real
milestones and a bar that fills for decoration would be inventing progress.
poweroff()'s success-path chatter moved to serial so it cannot paint over it.

The instrumentation that found the heap corruption, kept because it is cheap
and it worked three times when reasoning did not:

  - c_stubs::walk_trace + panic_screen: a kernel #GP inside a namespace walk
    now NAMES the node on the red screen. The CMOS breadcrumb is one reliable
    byte on this board, which is why this does not go through it.
  - acpi::boot_checkpoint: counts the root chain at nine boot stages; panel
    prints them and flags the first drop.
  - per-tick chain watch across the governor's own ACPI calls.
  - pool counters -- a NULL from AcpiOsAllocate used to be entirely silent.
  - acpi probe 8: the same walk built on AcpiGetNextObject.

The panic background now fills the whole byte extent linearly instead of
looping per-pixel through byte_offset. A solid colour is swizzle-invariant, so
the background needs no tiling knowledge and gains none of the ways to be
wrong about it; the old loop left holes wherever the geometry was off. The
report is also painted twice, because the PANICKING flag stops presents from
starting but not one already past the check.

build.rs emits NYX_BUILD_STAMP, printed by panel. The .efi.img is the same
size every build, so a stale flash produced two boots of byte-identical
diagnostics and cost a power cycle chasing a code bug that did not exist.

Co-Authored-By: Claude <noreply@anthropic.com>
…retired

The 20-step build order is complete. Meridian is now the only window server:
$WINDOW_SERVER is gone, apps/compositor and apps/wifi are deleted, and there
is no fallback desktop. The recovery path is a `wifi` command in the terminal
(status/list/scan/join/leave/on/off/forget).

Step 20 -- the network drill-down on the Entity surface. The shell must never
call a blocking radio syscall: it IS the window server, and a 15 s
sys_wifi_connect freezes compositing while the HW cursor keeps gliding and
drops the 1 Hz heartbeat long enough for RC6 to eat MOCS. It delegates to
apps/wifiagent via sys_execve_arg and polls the published snapshot;
completion is the pid leaving the task table. Signal strength is OMITTED:
WifiNetwork has no RSSI field and the driver deliberately refuses to parse
iwl_rx_mpdu_desc, so a dBm would be a guessed offset producing a plausible
wrong number.

Step 19 -- idle, sleep and the lock. Two independent bugs made it never fire
on hardware: idle::chrome_alpha was specified, host-tested and had NO CALLER,
and process_input used prev_mx/prev_my as its input baseline -- a rendering
variable answering an input question. Presence is now a question of SPEED
(24 px in a 1 s window), not distance, because this trackpoint drifts and any
one-pixel test pins last_input to now forever. Chrome fades by COLOUR, not
alpha: build_ps_text carries one per-quad luminance and outputs RGB=lum,
A=coverage, so a Label's alpha is discarded and an alpha ramp is a no-op.

The shared font bundle. The five typefaces were include_bytes!'d into every
binary -- 10.6 MB of duplicate TTF measured, not guessed. They now ship once
in the initrd at /mnt/nvme/fonts/. Image 33.6 MB -> 24.2 MB, shell 3.3 -> 1.4.
The #[cfg(test)] seam is at face_bytes alone, so register_all/install and the
slot mapping are the same code on host and target.

Power lives in the Command's FOOTER as two icon-only glyphs, and it took
three placements to get there. Not result rows: a verb that ends the session
must not be reachable by typing three letters and pressing Return on the
first match. Not the Entity: that surface reports what the machine IS.
Icons::SHUTDOWN (IEC 5009) is a new symbol -- Icons::POWER is a BATTERY, and
shipping it on a Shut down control was spotted on screen within a minute.

Also: two symbols that were being drawn and were never packed (-- and ...),
libs/gui/src/ui.rs deleted (723 dead lines), the terminal's hardcoded dark
theme removed, and libs/crypto lifted out of iwlwifi.rs so the driver's
boot-time vectors are host tests. libs/meridian is 321 host tests.

Co-Authored-By: Claude <noreply@anthropic.com>
@Asmodeus14
Asmodeus14 merged commit fb884f6 into master Sep 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant