Settle is a program, and a machine with no fallback still starts

The boot state opened a loop that could not be closed from inside: the
machine said "settle it to try again" and gave you no way to do so. Settle
closes it, in 349 bytes.

A PROGRAM RATHER THAN A SHELL WORD. The shell is for the things that cannot
be done without it, and this is not one - it reaches the system through SWI
like anything else, which means it can be replaced, left off a disk, or
called by whatever comes to call programs in turn. That last one is the
point: a shell word is not callable by anything.

Two services for it. osBootState answers in Q, and a machine with no disk
answers settled, because there is nothing there to be unsettled about.
osBootSettle puts it back. SETTLING IS THE ONLY WRITE A PROGRAM GETS -
marking a start as trying or fallen back is the loader's business, and a
service that let a program claim either would let it lie about something
the loader has no way to check.

And a hole the tests walked into, which was mine rather than theirs. With
no fallback configured, a failed start left the machine unable to start at
all: the mark said do not use the system, and there was nothing else to
use. That turns "the last start failed" into "no start is permitted", which
is worse than the problem the mark was added to solve. With nothing to fall
back to it now tries the configuration again and says so - a failure that
was passing recovers, and one that is not leaves the machine exactly where
it would have been without any of this, which is the most that can be
promised when there is only one thing to start.

docs.sh caught both new services having no row in the services table before
anything else did.
This commit is contained in:
Anachronaut
2026-08-27 17:02:59 -04:00
parent dc74149321
commit ce2a2cd7e6
12 changed files with 248 additions and 1 deletions
+18
View File
@@ -135,3 +135,21 @@
; restore. The price is that it is part of the program: a build with breakpoints in it has
; different addresses from one without.
osBreak 0d25
; ---- How the last start went ----
;
; The loader marks the disk before it hands over and the system clears the mark on reaching
; its prompt, so a mark still set is a start that never arrived. See the boot state in
; sbfs.h for what the numbers mean.
;
; osBootState answers in Q: 0 settled, 1 trying, 2 fell back. A machine with no disk answers
; settled, because there is nothing there to be unsettled about.
;
; osBootSettle puts it back to settled, which is how a machine that fell back is told the
; situation has changed. Q is zero if the disk took it.
;
; THE ONLY WRITE A PROGRAM GETS IS SETTLING. Marking a start as trying or fallen back is
; the loader's business, and a service that let a program claim either would let it lie
; about something the loader has no way to check.
osBootState 0d33
osBootSettle 0d34