Qet4 OS - Phase 5 Completion Milestone
Metadata
- Date: 2026-09-28
- Time: 23:35 (EAT)
- Status: SUCCESS
- Milestone Name: Phase 5 Input Server & Tech Debt Resolution
Achievements
This milestone represents the completion of Phase 5 (Input Server) and the resolution of critical technical debt and security vulnerabilities accumulated during the initial kernel development.
1. Phase 5: Input Server Implementation
- Separation of Concerns: The input processing logic was successfully isolated into a dedicated user-space service (
input_server). - Secure Syscalls:
- Implemented
SYS_READ_KEY(0x100 = None, 0x01-0xFF = Scancode, >=1<<63 = Error). - Feature-gated
SYS_ARG_ECHO(98) andSYS_GET_SWITCH_COUNT(99) for ABI self-testing.
- Implemented
- IPC Security: Added
INPUT_SERVER_PIDatomic variable with a PID authentication gate.SYS_READ_KEYcan only be successfully called by the registeredinput_serverPID, preventing unauthorized tasks from consuming key presses. - Scancode Translation: Implemented a Set 1 US QWERTY layout mapping table within
input_serverto convert raw PS/2 scancodes to ASCII characters. - ABI Test Framework: Created a
spincompanion binary and updatedtools/build.shto support automated--abi-testruns that verify callee-saved register persistence (r12-r15) across context switches.
2. Security Blocker Resolutions (CVE Mitigations)
- TSS Stack Safety: Ensured NMI (IST2) and Double Fault (IST1) handlers use dedicated stacks defined in the TSS to prevent stack overflow panics from cascading.
- Flags Isolation (SFMASK): Modified
syscall_entry.asmand MSR setup to enforce anSFMASKof0x47700. This ensures thatIF,TF,DF,IOPL,NT, andACflags are explicitly cleared upon entering Ring 0, preventing user-space flag manipulation from compromising kernel state. - Instruction Leak Prevention: Explicitly disabled AVX/AVX2/AVX512 in the kernel target spec (
x86_64-qet4.json) to prevent the kernel from generating vector instructions that could leak state or cause#UDexceptions on unsupported hardware, while retaining required SSE/SSE2 support. - Syscall ABI Hardening: Fully rewrote
syscall_entry.asmto correctly push 15 registers (handling user RSP correctly before callee-saved registers) and map SysV ABI arguments correctly to internal kernel registers.
3. Critical Technical Debt Fixes
- FXSAVE/FXRSTOR Alignment & Usage:
- Added a 16-byte aligned
FxsaveArea(512 bytes) to theTaskstruct. - Updated the context switch mechanism to explicitly save (
fxsave) and restore (fxrstor) the XMM/FPU state. This prevents XMM register leakage between user processes (a critical security fix). - Ensured idle and newly spawned tasks have their
fxsave_areazero-initialized.
- Added a 16-byte aligned
- Paranoid NMI Handler:
- Implemented a GS-base check in the NMI handler. If an NMI occurs during the critical window between the
syscallinstruction and theswapgsinstruction (whereCSis Ring 0 butGSpoints to user-space), the handler detects this viaRDMSRon0xC000_0101and performs a protectiveswapgsbefore executing, preventing kernel memory corruption.
- Implemented a GS-base check in the NMI handler. If an NMI occurs during the critical window between the
- Init Registration Timing:
- Fixed a race condition where
input_serverwould fail to register withinitbecauseinithadn't fully initialized its IPC ports. The kernel now explicitly links theinitandinput_serverIPC ports viakernel_grant_port_pairimmediately after spawning them inkernel_main.
- Fixed a race condition where
Current System State
- The kernel boots successfully.
init(PID 1),vfs_server(PID 2),display_server(PID 3), andinput_server(PID 4) are spawned.- IPC ports are correctly linked.
- The system is stable without
#GPfaults.
Next Steps (Phase 6 - GUI Foundation)
With a stable input and display foundation, the next logical step is to introduce basic graphical capabilities.
- VGA Graphics Mode: Transition the
display_serverfrom text mode (0xB8000) to a graphical mode (e.g., Mode 13h or a VESA/GOP framebuffer if supported by the bootloader). - Basic Window Manager: Create a primitive window manager within user space capable of drawing rectangles, text (using a bitmap font), and managing basic Z-ordering.
- Mouse Support: Implement a PS/2 mouse driver in user space (similar to
input_server) and integrate it with the window manager to draw a cursor. - Event Routing: Establish an event queue system where
input_server(and the future mouse server) send events to the window manager, which then dispatches them to the focused window.