Skip to content

docs(adr): formalize two-stage EL2 bootstrap to EL1h kernel transition - #52

Merged
aien-dev merged 1 commit into
mainfrom
docs/adr-0009-el2-el1-transition
Sep 24, 2026
Merged

aien-dev merged 1 commit into
mainfrom
docs/adr-0009-el2-el1-transition

Conversation

@aien-dev

Copy link
Copy Markdown
Owner

Summary

Formalizes ADR 0009 defining the exception level architecture and execution transition for Milestone 3 (Kernel Isolation):

  • Resolves the architectural contradiction between firmware entry at EL2 and kernel supervisor operations targeting EL1 translation and exception registers.
  • Establishes a strict two-stage hierarchy:
    1. UEFI Firmware hands off to minimal early handoff stub at EL2.
    2. Minimal EL2 bootstrap stub configures EL2 registers (HCR_EL2, CPTR_EL2, CNTHCTL_EL2, CPACR_EL1), sets SPSR_EL2 = 0x3c5 (EL1h, SP_EL1, DAIF masked), sets ELR_EL2 to the kernel entrypoint, and executes eret.
    3. AIENOS Kernel Core executes strictly at EL1h, owning VBAR_EL1, TCR_EL1/TTBR0_EL1/MAIR_EL1 page tables, GICv3 CPU interface, and task scheduler.
  • Establishes the implementation precondition: The EL2 to EL1h transition must be implemented and QEMU-verified before mmu.rs page tables are introduced.

Security Invariant

  • NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS.
  • Zero Unslop: Zero em dashes, zero en dashes.

- Add docs/adr/0009-el2-bootstrap-to-el1h-kernel-transition.md defining EL2 to EL1h entry model
- Update docs/adr/README.md master index
- Establish strict M3 precondition: EL2 to EL1h eret transition must precede mmu.rs page tables
- Confine EL2 execution to early bootstrap stub (HCR_EL2, CPACR_EL1, CNTHCTL_EL2, SPSR_EL2=0x3c5)
- Invariant: NO PLAINTEXT SECRETS IN REPOSITORY OR BUILD ARTIFACTS
- Certified Unslop compliant

Co-authored-by: Drake Stapleton <drake@aienos.com>
Co-authored-by: Gemini 3.8 Flash <noreply@google.com>
@aien-dev
aien-dev merged commit a1babb4 into main Sep 24, 2026
1 check failed
@aien-dev
aien-dev deleted the docs/adr-0009-el2-el1-transition branch September 24, 2026 04:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants