Stage 4 increment 1: per-device WIREBIND tracking, fixing a real multi-identity detach leak (FABRIC-3.md §XXVIII Stage 4)
capsule_wirebind_unclean_detach()/eject() tracked "the attached identity" as a single global, correct for the console-pairing UX (one physical console) but wrong for detach safety: since §XV/§XVI proved multiple identities genuinely live simultaneously via this same attach path, every attach after the first silently overwrote the singleton, so an unclean detach of any but the most-recently-attached identity was silently ignored -- that VM leaked forever, no trace in the log. Adds a per-device live-identity table, separate from the (unchanged) console-pairing singleton, so unclean-detach resolves any attached device to its own identity. Sized off messaging.4th's own VM-MAX (16) minus Tripod's 3 reserved slots, not an invented number. Corrects the stale "single-USB-device constraint" doc claim in capsule_wirebind.h, false since §XV/§XVI. Groundwork for Stage 4's real deliverable (WIREBIND VMs as switch-signal participants) -- this increment only fixes detach targeting; switch- signal registration is next. Verified clean on all 3 architectures (no WIREBIND attach happens in a plain boot, so this is a regression check on the existing Tripod-only path; live multi-identity verification comes with the switch-signal registration increment). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BWpNjdwPtFLuVLaAq44L9K
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
1c220ad4b4
commit
9f0f33dfc5
@@ -92,9 +92,16 @@ void capsule_wirebind_try_attach(struct blkio_dev *dev,
|
||||
* optional, to avoid a dangling console pointer; capsule_vm_kill() by
|
||||
* name; clear the tracked state.
|
||||
*
|
||||
* Single-USB-device constraint (§F.8) means there is never more than one
|
||||
* candidate, so this always targets "whatever's currently attached" --
|
||||
* no name argument.
|
||||
* EJECT is inherently about "whichever identity is currently paired to
|
||||
* the one physical console" -- targets that singleton, no name argument.
|
||||
* (Corrected 2026-09-14: this used to claim a "single-USB-device
|
||||
* constraint (§F.8)" meant there was never more than one candidate --
|
||||
* stale even at the time this correction was written; §XV/§XVI
|
||||
* (2026-09-11/12) proved 9 identities genuinely simultaneously live via
|
||||
* this same attach path. EJECT staying console-singleton-scoped is a
|
||||
* deliberate UX choice now, not a hardware constraint -- see
|
||||
* capsule_wirebind_unclean_detach()'s own doc below for the function
|
||||
* that DOES need to reach every live identity, not just this one.)
|
||||
*
|
||||
* @return 0 on success, -1 if nothing was attached to eject.
|
||||
*/
|
||||
@@ -107,14 +114,21 @@ int capsule_wirebind_eject(void);
|
||||
* bot_msc_detach_pending hot-unplug signal (repl.c) -- the device is
|
||||
* already gone by the time this runs, so no flush is attempted; data
|
||||
* since the last flush is lost, which is correct unclean-removal
|
||||
* semantics. Otherwise identical to capsule_wirebind_eject(): same
|
||||
* active-VM reset-before-kill step, same tracked-state clear.
|
||||
* semantics.
|
||||
*
|
||||
* FABRIC-3.md §VII follow-on, 2026-09-06: now requires the departing
|
||||
* device to actually be the one tracked as this WIREBIND user's own
|
||||
* (g_wirebind_attached_dev) -- a real bug otherwise, found live once
|
||||
* genuine multi-device attach made a *different* device's detach
|
||||
* reachable while a WIREBIND user's own stayed attached.
|
||||
* FABRIC-3.md §VII follow-on, 2026-09-06: requires the departing device
|
||||
* to actually be one WIREBIND is tracking -- a real bug otherwise, found
|
||||
* live once genuine multi-device attach made a *different* device's
|
||||
* detach reachable while a WIREBIND user's own stayed attached.
|
||||
*
|
||||
* FABRIC-3.md §XXVIII Stage 4, 2026-09-14: resolves the departing device
|
||||
* against a per-device live-identity table now, not the single
|
||||
* console-pairing global capsule_wirebind_eject() uses -- with several
|
||||
* identities simultaneously live (§XV/§XVI), any one of them can be the
|
||||
* device that just disappeared, not only the most recently attached.
|
||||
* Refuses (rather than freeing) a VM currently VM_STATE_SWITCHED_OUT --
|
||||
* see capsule_vm_kill()'s own guard -- leaving it tracked for the Stage 3
|
||||
* switcher to reap on its own next resume attempt instead.
|
||||
*
|
||||
* @param dev The device that just detached; every other value is a no-op.
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user