feat: disconnect Bluetooth devices, flush disks on shutdown/reboot, display progress in login.elf window
This commit is contained in:
@@ -0,0 +1,189 @@
|
||||
/*
|
||||
* login_shutdown.cpp
|
||||
* Graceful shutdown view and staged power-off for the MontaukOS login screen
|
||||
* Copyright (c) 2026 Daniel Hammer
|
||||
*/
|
||||
|
||||
#include "login.hpp"
|
||||
#include <montauk/thread.h>
|
||||
|
||||
using namespace gui;
|
||||
|
||||
// Minimum time each shutdown stage stays on screen, so the status message is
|
||||
// readable even when the underlying work completes near-instantly.
|
||||
static constexpr uint64_t STAGE_MIN_VISIBLE_MS = 600;
|
||||
|
||||
// Per-stage watchdog budgets. Each stage's blocking work runs on a disposable
|
||||
// worker thread; if it overruns its budget we abandon the worker and move on,
|
||||
// so an unresponsive device can never wedge the power-off.
|
||||
// - Bluetooth: a disconnect is normally sub-second; 4 s tolerates a slow
|
||||
// controller. Bailing here is safe -- it does not risk data.
|
||||
// - Filesystem flush: kept generous (10 s) so a legitimately slow flush on
|
||||
// real hardware is never cut short and writes are not lost; only a truly
|
||||
// wedged storage controller hits this bound.
|
||||
static constexpr uint64_t BT_STAGE_TIMEOUT_MS = 4000;
|
||||
static constexpr uint64_t FS_STAGE_TIMEOUT_MS = 10000;
|
||||
|
||||
void draw_shutdown_screen(LoginState* ls, const char* heading, const char* status) {
|
||||
Framebuffer& fb = ls->fb;
|
||||
int sw = ls->screen_w;
|
||||
int sh = ls->screen_h;
|
||||
|
||||
// Same packed/scratch handling as draw_login_screen: Canvas assumes a
|
||||
// tightly packed buffer, so compose into the scratch buffer when the
|
||||
// framebuffer pitch is not width*4.
|
||||
bool packed = fb.pitch() == sw * (int)sizeof(uint32_t);
|
||||
uint32_t* target = packed ? fb.buffer() : ls->compose;
|
||||
if (!target) return;
|
||||
Canvas c(target, sw, sh);
|
||||
|
||||
const mtk::Theme& th = ls->theme;
|
||||
int sfh = system_font_height();
|
||||
|
||||
// ==== Layout (mirrors the login/setup card chrome, minus the footer) ====
|
||||
// Titlebar holds the app title; the body holds a heading + a status line,
|
||||
// matching the login/setup heading + subtitle. The card is sized to fit the
|
||||
// content with symmetric padding -- no empty footer band.
|
||||
const char* window_title = "MontaukOS";
|
||||
int content_x = CONTENT_PAD_X;
|
||||
|
||||
int y = TITLEBAR_H + CONTENT_TOP_PAD;
|
||||
int heading_y = y;
|
||||
y += sfh + 6;
|
||||
int status_y = y;
|
||||
y += sfh;
|
||||
|
||||
int card_h = y + CONTENT_TOP_PAD + 10;
|
||||
int card_x = (sw - CARD_W) / 2;
|
||||
int card_y = (sh - card_h) / 2;
|
||||
|
||||
Rect card = {card_x, card_y, CARD_W, card_h};
|
||||
Rect titlebar = {card_x, card_y, CARD_W, TITLEBAR_H};
|
||||
|
||||
// ==== Background ====
|
||||
if (ls->has_wallpaper && ls->bg_wallpaper) {
|
||||
montauk::memcpy(target, ls->bg_wallpaper,
|
||||
(uint64_t)sw * sh * sizeof(uint32_t));
|
||||
} else {
|
||||
c.fill(BG_COLOR);
|
||||
}
|
||||
|
||||
// ==== Card ====
|
||||
int so = 4; // drop-shadow offset
|
||||
c.fill_rect_alpha(card.x + so, card.y + card.h, card.w, so, colors::SHADOW);
|
||||
c.fill_rect_alpha(card.x + card.w, card.y + so, so, card.h, colors::SHADOW);
|
||||
c.fill_rect_alpha(card.x + card.w, card.y + card.h, so, so, colors::SHADOW);
|
||||
|
||||
c.fill_rect(card.x, card.y, card.w, card.h, CARD_BG);
|
||||
c.fill_rect(titlebar.x, titlebar.y, titlebar.w, titlebar.h, TITLEBAR_BG);
|
||||
c.rect(card.x, card.y, card.w, card.h, CARD_BORDER);
|
||||
c.hline(titlebar.x, titlebar.y + titlebar.h - 1, titlebar.w, CARD_BORDER);
|
||||
|
||||
// ==== Title + heading + status ====
|
||||
int window_tw = text_width(window_title);
|
||||
c.text(titlebar.x + (titlebar.w - window_tw) / 2,
|
||||
titlebar.y + (TITLEBAR_H - sfh) / 2, window_title, th.text);
|
||||
c.text(card_x + content_x, card_y + heading_y, heading, th.text);
|
||||
c.text(card_x + content_x, card_y + status_y, status, th.text_subtle);
|
||||
|
||||
// ==== Present ====
|
||||
if (!packed) fb.copy_from(ls->compose, sw * (int)sizeof(uint32_t));
|
||||
fb.flip();
|
||||
}
|
||||
|
||||
// Show a stage message, hold it on screen for a moment, then return so the
|
||||
// caller can perform the stage's work.
|
||||
static void show_stage(LoginState* ls, const char* heading, const char* status) {
|
||||
draw_shutdown_screen(ls, heading, status);
|
||||
montauk::sleep_ms(STAGE_MIN_VISIBLE_MS);
|
||||
}
|
||||
|
||||
namespace {
|
||||
|
||||
// A unit of shutdown work plus a flag the worker sets when it finishes. `done`
|
||||
// is polled across threads, so all access goes through atomics.
|
||||
struct StageWork {
|
||||
void (*fn)();
|
||||
volatile bool done;
|
||||
};
|
||||
|
||||
int stage_worker(void* arg) {
|
||||
StageWork* w = (StageWork*)arg;
|
||||
w->fn();
|
||||
__atomic_store_n(&w->done, true, __ATOMIC_RELEASE);
|
||||
return 0;
|
||||
}
|
||||
|
||||
// Run fn() on a worker thread, waiting up to timeout_ms for it to finish. If a
|
||||
// device wedges, only the disposable worker blocks (in its kernel syscall); the
|
||||
// shutdown flow keeps moving. Returns true if fn() completed in time, false if
|
||||
// it was abandoned. A timed-out worker is intentionally left running and never
|
||||
// joined (joining would re-block us) -- power-off reclaims it in moments.
|
||||
bool run_stage(void (*fn)(), uint64_t timeout_ms) {
|
||||
auto* w = (StageWork*)montauk::malloc(sizeof(StageWork));
|
||||
if (!w) { fn(); return true; } // no memory: best-effort inline
|
||||
w->fn = fn;
|
||||
w->done = false;
|
||||
|
||||
int tid = montauk::thread_spawn(stage_worker, w);
|
||||
if (tid < 0) { fn(); montauk::mfree(w); return true; } // can't isolate: inline
|
||||
|
||||
const uint64_t step = 50;
|
||||
uint64_t waited = 0;
|
||||
while (!__atomic_load_n(&w->done, __ATOMIC_ACQUIRE) && waited < timeout_ms) {
|
||||
montauk::sleep_ms(step);
|
||||
waited += step;
|
||||
}
|
||||
|
||||
if (__atomic_load_n(&w->done, __ATOMIC_ACQUIRE)) {
|
||||
montauk::thread_join(tid, nullptr); // reclaim the worker's stack
|
||||
montauk::mfree(w);
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
// Stage bodies -- no captured state, so they double as bare thread entries.
|
||||
void stage_disconnect_bluetooth() {
|
||||
Montauk::BtDevInfo devs[8];
|
||||
int n = montauk::bt_list(devs, 8);
|
||||
for (int i = 0; i < n; i++) {
|
||||
if (devs[i].connected) {
|
||||
montauk::bt_disconnect(devs[i].bdAddr);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void stage_flush_filesystems() {
|
||||
montauk::fs_sync();
|
||||
}
|
||||
|
||||
} // namespace
|
||||
|
||||
void perform_graceful_shutdown(LoginState* ls, int action) {
|
||||
const bool rebooting = (action == Montauk::POWER_REQ_REBOOT);
|
||||
const char* heading = rebooting ? "Restarting" : "Shutting Down";
|
||||
|
||||
// ==== Stage 1: disconnect connected Bluetooth devices ====
|
||||
// Bounded so an unresponsive controller cannot block the (critical)
|
||||
// filesystem flush that follows.
|
||||
show_stage(ls, heading, "Disconnecting Bluetooth devices...");
|
||||
if (!run_stage(stage_disconnect_bluetooth, BT_STAGE_TIMEOUT_MS)) {
|
||||
show_stage(ls, heading, "Bluetooth is unresponsive, continuing...");
|
||||
}
|
||||
|
||||
// ==== Stage 2: flush writes and unmount filesystems ====
|
||||
show_stage(ls, heading, "Flushing file systems...");
|
||||
if (!run_stage(stage_flush_filesystems, FS_STAGE_TIMEOUT_MS)) {
|
||||
show_stage(ls, heading, "Storage is unresponsive, continuing...");
|
||||
}
|
||||
|
||||
// ==== Stage 3: dispatch the ACPI power-off / reset ====
|
||||
show_stage(ls, heading, rebooting ? "Restarting now..." : "Powering off...");
|
||||
if (rebooting) {
|
||||
montauk::reset();
|
||||
} else {
|
||||
montauk::shutdown();
|
||||
}
|
||||
__builtin_unreachable();
|
||||
}
|
||||
Reference in New Issue
Block a user