Skip to content

SharpMetal v1.1.0

Choose a tag to compare

@Sadik00789 Sadik00789 released this 12 Sep 16:11
· 6 commits to main since this release

SharpMetal v1.1.0 — Architecture Hardening

Hardened bare-metal C# microkernel running on native AOT with verified Layer 7 Ring 3 userland transition, serialized SMP initialization, and fault-tolerant storage/network device drivers.


1. Release Overview & Changelog

Layer 7 Ring 3 Transition & Privilege Drops

  • General Protection Fault Fix (#GP, Vector 0x0D): Resolved privilege mismatch panics during iretq by assigning valid Ring 3 segment selectors (0x23 for User 64-bit CS with RPL=3, 0x1B for User DS/SS with RPL=3) in UserTransition.asm and Gdt.cs.
  • Canonical Userland RIP Mapping: Updated ObjectSynthesizer.cs and RoottaskEntry.asm so the synthesized Root Task thread points to the userland PIE base in lower canonical memory rather than higher-half kernel return addresses (0xFFFF8001...).
  • Context Preservation: Retained IA32_GS_BASE per-CPU scratch mappings without executing ungrounded swapgs instructions during transitions.

Core SMP Real-Mode Bootstrap

  • Serialized AP Trampoline: Implemented an atomic 16-bit spinlock (trampoline_lock) in ApTrampoline.asm released once an AP transitions to long mode (long64_entry), preventing AP memory bus stomping on shared low-memory pages (0x8000).
  • Per-Core Stack Safety: SmpBootstrap.cs assigns dedicated 16 KiB stacks per core indexed by APIC ID (supporting topologies up to 16 cores) and guards against double-allocating live or booting processors.
  • Null-Stack Trap: Added an explicit null check in Entry.asm (ApEntry64) to force an AP halt (hlt) rather than jumping on unassigned stack pointers.

NVMe Storage Engine

  • Dynamic PRP Lists: Introduced a dynamic Page Request Principle (PRP) list arena at DMA address 0x71005000 in NvmeDriver.cs, allowing multi-block transfers exceeding 8 KiB (up to 2 MiB per transaction) without sector truncation.
  • Doorbell & Head Desynchronization Fix: Placed volatile memory barriers between SQE population and doorbell writes, and prevented CQ head advancement when polling cycles hit completion timeouts.

Subsystem Resiliency & IPC

  • Interrupt Stack Table (IST) Hardening: Assigned dedicated 16 KiB per-CPU IST1 stacks in Idt.cs across NMI (#2), Double Fault (#8), and Machine Check (#18) handlers to eliminate reentrancy races across GS-base structures.
  • Capability & Endpoint Sweep: Added Endpoint.PurgeThread() to sweep queued send/receive rendezvous states upon thread termination while preventing capability leaks in CapabilityDerivationTree.cs.
  • FAT32 Cluster Sanitization: Applied & 0x0FFFFFFF masking across directory cluster entries and root cluster fields in Fat32Driver.cs to ignore upper reserved bits.
  • VirtIO-Net Synchronization: Added acquire-side memory barriers across ring index polling loops in VirtioNetDriver.cs and hardened index calculations against modulo-65536 rollover.

2. Prerequisites & Environment Setup

Ensure the following toolchains are installed on the host system:

  • .NET SDK (matching the repo global configuration)
  • NASM (Netwide Assembler) for low-level x86_64 trampolines
  • QEMU x86_64 Emulator (qemu-system-x86_64) with OVMF firmware
  • Python 3 (for the automated verification harness)
  • Standard GNU Utilities (bash, mtools, xorriso)

3. Build & Packaging Instructions

Execute these commands from the repository root.

Step 1: Reassemble Low-Level Trampolines

nasm -f bin src/kernel/Arch/x86_64/Assembly/ApTrampoline.asm -o src/kernel/Arch/x86_64/Assembly/ApTrampoline.bin

Compiles the raw 16-bit real-mode bootstrap binary embedded directly into the kernel image.

Step 2: Compile the Microkernel Solution

dotnet build Microkernel.sln -c Release

Runs Native AOT compilation across all kernel modules, runtime libraries, drivers, and userland applications with zero warnings and zero errors.

Step 3: Pack Initrd & Build Bootable Disk Image

bash build/scripts/Make-DiskImage.sh

Packages userland servers into the initrd and formats build/disk.img containing the EFI System Partition and FAT32 layout.


4. Running the Kernel

Interactive Graphical Mode (GUI Framebuffer)

Launches the microkernel with the GOP framebuffer display server, PS/2 mouse/keyboard, NVMe storage, and VirtIO-net adapter attached:

bash build/scripts/Run-Qemu.sh

Headless Console Mode (Serial Debugging)

Routes COM1 early serial diagnostic logs directly to the active terminal stdout:

bash build/scripts/Run-Qemu.sh --headless

Automated Milestone Test Harness

Runs headless verification against all 10 architectural boot phases and asserts serial milestones:

python3 build/scripts/Test-Harness.py