Skip to content

Qet4 OS - Phase 5 Completion Milestone ​

Metadata ​

  • Date: 2026-09-28
  • Time: 23:35 (EAT)
  • Status: SUCCESS
  • Milestone Name: Phase 5 Input Server & Tech Debt Resolution

Achievements ​

This milestone represents the completion of Phase 5 (Input Server) and the resolution of critical technical debt and security vulnerabilities accumulated during the initial kernel development.

1. Phase 5: Input Server Implementation ​

  • Separation of Concerns: The input processing logic was successfully isolated into a dedicated user-space service (input_server).
  • Secure Syscalls:
    • Implemented SYS_READ_KEY (0x100 = None, 0x01-0xFF = Scancode, >=1<<63 = Error).
    • Feature-gated SYS_ARG_ECHO (98) and SYS_GET_SWITCH_COUNT (99) for ABI self-testing.
  • IPC Security: Added INPUT_SERVER_PID atomic variable with a PID authentication gate. SYS_READ_KEY can only be successfully called by the registered input_server PID, preventing unauthorized tasks from consuming key presses.
  • Scancode Translation: Implemented a Set 1 US QWERTY layout mapping table within input_server to convert raw PS/2 scancodes to ASCII characters.
  • ABI Test Framework: Created a spin companion binary and updated tools/build.sh to support automated --abi-test runs that verify callee-saved register persistence (r12-r15) across context switches.

2. Security Blocker Resolutions (CVE Mitigations) ​

  • TSS Stack Safety: Ensured NMI (IST2) and Double Fault (IST1) handlers use dedicated stacks defined in the TSS to prevent stack overflow panics from cascading.
  • Flags Isolation (SFMASK): Modified syscall_entry.asm and MSR setup to enforce an SFMASK of 0x47700. This ensures that IF, TF, DF, IOPL, NT, and AC flags are explicitly cleared upon entering Ring 0, preventing user-space flag manipulation from compromising kernel state.
  • Instruction Leak Prevention: Explicitly disabled AVX/AVX2/AVX512 in the kernel target spec (x86_64-qet4.json) to prevent the kernel from generating vector instructions that could leak state or cause #UD exceptions on unsupported hardware, while retaining required SSE/SSE2 support.
  • Syscall ABI Hardening: Fully rewrote syscall_entry.asm to correctly push 15 registers (handling user RSP correctly before callee-saved registers) and map SysV ABI arguments correctly to internal kernel registers.

3. Critical Technical Debt Fixes ​

  • FXSAVE/FXRSTOR Alignment & Usage:
    • Added a 16-byte aligned FxsaveArea (512 bytes) to the Task struct.
    • Updated the context switch mechanism to explicitly save (fxsave) and restore (fxrstor) the XMM/FPU state. This prevents XMM register leakage between user processes (a critical security fix).
    • Ensured idle and newly spawned tasks have their fxsave_area zero-initialized.
  • Paranoid NMI Handler:
    • Implemented a GS-base check in the NMI handler. If an NMI occurs during the critical window between the syscall instruction and the swapgs instruction (where CS is Ring 0 but GS points to user-space), the handler detects this via RDMSR on 0xC000_0101 and performs a protective swapgs before executing, preventing kernel memory corruption.
  • Init Registration Timing:
    • Fixed a race condition where input_server would fail to register with init because init hadn't fully initialized its IPC ports. The kernel now explicitly links the init and input_server IPC ports via kernel_grant_port_pair immediately after spawning them in kernel_main.

Current System State ​

  • The kernel boots successfully.
  • init (PID 1), vfs_server (PID 2), display_server (PID 3), and input_server (PID 4) are spawned.
  • IPC ports are correctly linked.
  • The system is stable without #GP faults.

Next Steps (Phase 6 - GUI Foundation) ​

With a stable input and display foundation, the next logical step is to introduce basic graphical capabilities.

  1. VGA Graphics Mode: Transition the display_server from text mode (0xB8000) to a graphical mode (e.g., Mode 13h or a VESA/GOP framebuffer if supported by the bootloader).
  2. Basic Window Manager: Create a primitive window manager within user space capable of drawing rectangles, text (using a bitmap font), and managing basic Z-ordering.
  3. Mouse Support: Implement a PS/2 mouse driver in user space (similar to input_server) and integrate it with the window manager to draw a cursor.
  4. Event Routing: Establish an event queue system where input_server (and the future mouse server) send events to the window manager, which then dispatches them to the focused window.

تم تطويره بحب بواسطة مجتمع Qtoom.