From 9db14e71b3ccb67e760ad99655ec64a29ced1d41 Mon Sep 17 00:00:00 2001 From: japabu Date: Tue, 29 Sep 2026 19:02:02 +0200 Subject: [PATCH 01/10] Metal timings are recorded per machine and judged against that machine's own record tests/metal-profile.toml priced every number the metal suite measures with a ceiling somebody typed, and refused any number nobody had priced: the full T14 run of 2026-09-29 (616) went red on boot.usbload.panel_max_us and boot.usbload.panel_us for exactly that. The file, src/metalprofile.rs and the list-sizing allowance derived from its job_ms ceilings are deleted. Machine identity. Nothing in a readback names the machine: the kernel log carries ACPI OEM "LENOVO", a PCI inventory and a CPUID-stated TSC, none of them a unit or a model. toyos-metal now reads SMBIOS over its existing ssh session before the flash (/sys/class/dmi/id/sys_vendor, product_name, bios_version, all 0444 in Linux's drivers/firmware/dmi-id.c, unlike product_serial and product_uuid which are 0400) and writes it into boot.txt as machine_vendor, machine_product and machine_bios. One file per machine, tests/metal/-.toml, holding the BIOS it was recorded under and a flat table of name -> value. A run writes it: an unknown machine, or a known one under another BIOS, is recorded whole and not judged; a name the record lacks is added and not judged; a recorded value is never moved by a run, so a slow run never becomes the next run's baseline. Re-recording a number is deleting its row. The harness prints the path when it changed the file, for whoever ran it to commit. The rule: a reading passes at most twice its record, a record of zero counting as one unit. The widest spread between the readings the deleted profile recorded and run 616's own is 1.55x (boot.hardlockup.back_secs, 170 against 110 s); complete_ms moved at most 1.08x, panel 1.21x, deadline lateness 1.1x, stick_secs was 0 in both and lockup_lateness_ms went 0 -> 2 ms, which the one-unit floor admits exactly. list.*.job_ms moved 2.4-5x, but between two runs whose lists had different members. Two ceilings in the profile were not timings and move to code: park_open_operations (must be 0) is checked in Readback::stop_completed, which also refuses a boot that handed the machine back with no stop record; the cyclictest p99 at its histogram's 4096 is refused as a floor in wake_latency_recorded. A shared list's chunk size was derived from its job_ms ceiling; it is now SharedBoot::members, set to what that derivation gave ((60000 - 6000) / 1400 = 38 for shared, / 2900 = 18 for shared-debug, / 600 = 90 for ccorpus), so the images are cut as run 616's were. The refusal of an authored arm longer than its allowance goes with the allowance. No record is seeded: no readback, log or file in the tree carries the T14's SMBIOS strings, so its record cannot be named until one run of this branch reads them; that run records it. issues/build/the-usbload-boot-measures-a-panel-no-profile-row-prices.md is closed: an unrecorded name is now recorded rather than refused. Every citation of the deleted file goes with it. Co-Authored-By: Claude Opus 5.5 --- ...al-loop-cannot-judge-a-boot-that-panics.md | 4 +- ...-measures-a-panel-no-profile-row-prices.md | 32 - ...-is-a-third-t14-flash-for-one-exit-code.md | 5 +- ...h-no-kernel-log-is-not-no-boot-complete.md | 3 +- ...-is-a-second-t14-flash-for-one-question.md | 7 +- ...eadline-fired-132859-ms-late-on-the-t14.md | 14 +- src/lib.rs | 2 +- src/metal.rs | 46 +- src/metaldevices.rs | 10 - src/metalprofile.rs | 386 ----- src/metaltimings.rs | 361 +++++ tests/checks.rs | 2 - tests/common/devices.rs | 16 +- tests/common/lan.rs | 23 +- tests/common/metal.rs | 257 ++- tests/common/power.rs | 3 +- tests/metal-profile.toml | 1439 ----------------- .../toyos-rust-tests/src/bin/lan_talk_hold.rs | 3 - tests/toyos.rs | 24 +- userland/metalprobe/src/main.rs | 5 +- 20 files changed, 561 insertions(+), 2081 deletions(-) delete mode 100644 issues/build/the-usbload-boot-measures-a-panel-no-profile-row-prices.md delete mode 100644 src/metalprofile.rs create mode 100644 src/metaltimings.rs delete mode 100644 tests/metal-profile.toml diff --git a/issues/build/the-metal-loop-cannot-judge-a-boot-that-panics.md b/issues/build/the-metal-loop-cannot-judge-a-boot-that-panics.md index 6d24968cf73..c90ef0f23f8 100644 --- a/issues/build/the-metal-loop-cannot-judge-a-boot-that-panics.md +++ b/issues/build/the-metal-loop-cannot-judge-a-boot-that-panics.md @@ -18,9 +18,7 @@ the T14, and the reason is the loop rather than the kernel. `Boot: complete (Nms)` *and* a trailing `Rebooting.`. A boot whose subject is a panic correctly writes neither the second word nor anything after it, so the loop refuses it — the readback is still written, and - `tests/common/metal.rs`'s `Mode::Drive` tolerates the non-zero exit, but the - boot-level rows `tests/metal-profile.toml` prices are then judged against a - log the loop has already called unfit. + `tests/common/metal.rs`'s `Mode::Drive` tolerates the non-zero exit. 2. `test-late-panic` fires in `kernel_main` after `spawn_init` and before `enter_idle_loop`, so `logd` has not run: that boot writes no `/log` file at diff --git a/issues/build/the-usbload-boot-measures-a-panel-no-profile-row-prices.md b/issues/build/the-usbload-boot-measures-a-panel-no-profile-row-prices.md deleted file mode 100644 index 4d22e673862..00000000000 --- a/issues/build/the-usbload-boot-measures-a-panel-no-profile-row-prices.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -status: open -kind: tooling -opened: 2026-09-29 ---- - -# The `usbload` boot measures a panel no `tests/metal-profile.toml` row prices - -`tests/metal-profile.toml` prices `panel_max_us` and `panel_us` for every -metal boot but `usbload`, whose sealed page carries the panel census like any -other. `tests/common/metal.rs` fails a measured number with no row, so every -run that flashes `usbload` reds for it, whatever -`usb_reset_records_the_phase_it_cut` — the boot's one rider — says. - -## Measured - -The full T14 run of `main` at `7e151819` -(EXIT=1): - -``` - usbload: Boot: complete 1166 ms, back in 164 s, the stick enumerated 0 s after that - the panel painted 10 time(s) and put 8741120 px on the glass - FAIL the metal suite measured "boot.usbload.panel_max_us" and tests/metal-profile.toml prices no such number; add a row with a ceiling and where it came from, because a measurement with no ceiling cannot fail - FAIL the metal suite measured "boot.usbload.panel_us" and tests/metal-profile.toml prices no such number; add a row with a ceiling and where it came from, because a measurement with no ceiling cannot fail -``` - -## Exit condition - -`tests/metal-profile.toml` carries `boot.usbload.panel_max_us` and -`boot.usbload.panel_us` rows, each ceiling taken from a measurement of that -boot rather than chosen, and a T14 run that flashes `usbload` prints -neither refusal. diff --git a/issues/diagnostics/the-lanleasecase-boot-is-a-third-t14-flash-for-one-exit-code.md b/issues/diagnostics/the-lanleasecase-boot-is-a-third-t14-flash-for-one-exit-code.md index 2b1db4a1aa5..731723d4006 100644 --- a/issues/diagnostics/the-lanleasecase-boot-is-a-third-t14-flash-for-one-exit-code.md +++ b/issues/diagnostics/the-lanleasecase-boot-is-a-third-t14-flash-for-one-exit-code.md @@ -17,8 +17,7 @@ reaches no file (`issues/diagnostics/the-cable-judge-reads-three-netd-records-that-cannot-arrive-on-the-t14.md`): the kernel's `exit: netd pid=N code=N` record and a file netd writes itself are the two words of a process that cross. It is the `lan_lease_report` metal row, -a third image flashed to the stick, a third boot of the machine and six rows of -`tests/metal-profile.toml`. +a third image flashed to the stick and a third boot of the machine. ## Owner @@ -32,7 +31,7 @@ which the shipping `lancase` arm carries netd's own lines about the lease and the probe answers a question already answered. Then the arm is: `tests/lanleasecase/system.toml`, its row in `src/build.rs`'s `ALL_CONFIGS`, the `lan_lease_report` metal row in `tests/toyos.rs` with `LANLEASECASE` and -`lan::leased_on_metal`, the six `tests/metal-profile.toml` rows, +`lan::leased_on_metal`, `userland/netd/src/report.rs` and `toyos-i219/src/lease.rs`'s report lines — and netd's `--exit-with-lease` with `tests/e1000leasecase` and the `lan_lease_report` QEMU registration, the arm that proves the channel. diff --git a/issues/hardware/a-boot-with-no-kernel-log-is-not-no-boot-complete.md b/issues/hardware/a-boot-with-no-kernel-log-is-not-no-boot-complete.md index b23fed10af3..8c350ce6f26 100644 --- a/issues/hardware/a-boot-with-no-kernel-log-is-not-no-boot-complete.md +++ b/issues/hardware/a-boot-with-no-kernel-log-is-not-no-boot-complete.md @@ -22,8 +22,7 @@ readback could say about the run-22 class of hang. **Exit condition**: the loop names that case as itself — a readback with no `logd` file and no harvested report reported as "wedged before its first durable -record", distinct from "no `Boot: complete`" and from "no readback at all" — and -a metal-profile row that says which of the three a boot is. +record", distinct from "no `Boot: complete`" and from "no readback at all". Off the path of whoever finds this: it is `src/metal.rs`'s verdict and belongs to the driver, not to the kernel side that produced the boot. diff --git a/issues/hardware/the-lanicscase-boot-is-a-second-t14-flash-for-one-question.md b/issues/hardware/the-lanicscase-boot-is-a-second-t14-flash-for-one-question.md index 27b2a5ff9c8..6f44546b60c 100644 --- a/issues/hardware/the-lanicscase-boot-is-a-second-t14-flash-for-one-question.md +++ b/issues/hardware/the-lanicscase-boot-is-a-second-t14-flash-for-one-question.md @@ -10,9 +10,7 @@ opened: 2026-09-13 `--provoke-message`, which writes one enabled cause to `ICS` so the kernel's `pcidev: slot N took its first message` record says whether delivery works at all. It is the `lan_message_delivery` metal row, a second image flashed to the -stick, a second boot of the machine and six rows of `tests/metal-profile.toml` -(`boot.lanicscase.{complete_ms,back_secs,stick_secs,panel_max_us,panel_us}`, -`list.lanicscase.job_ms`). +stick and a second boot of the machine. **A count of no messages is two facts** — a part nothing made speak and a message that reached no CPU — and only this arm separates them. On a card that @@ -30,8 +28,7 @@ The shipping `lancase` arm recording `pcidev: slot N took its first message` without the actuator. Then the actuator has no question left and the arm is four files: `tests/lanicscase/system.toml`, its row in `src/build.rs`'s `ALL_CONFIGS`, `tests/toyos.rs`'s `lan_message_delivery` row, its `METAL_ONLY` -entry and `LANICSCASE` with the judge `lan::provoked_on_metal`, and the six -`tests/metal-profile.toml` rows. +entry and `LANICSCASE` with the judge `lan::provoked_on_metal`. Metal run 57 recorded `pcidev: slot 0 took its first message on vector 0x28` after the I219's hand-over on that slot and vector, so the second fact is read: diff --git a/issues/kernel/a-120000-ms-boot-deadline-fired-132859-ms-late-on-the-t14.md b/issues/kernel/a-120000-ms-boot-deadline-fired-132859-ms-late-on-the-t14.md index 0516d530fa0..9005b87e26d 100644 --- a/issues/kernel/a-120000-ms-boot-deadline-fired-132859-ms-late-on-the-t14.md +++ b/issues/kernel/a-120000-ms-boot-deadline-fired-132859-ms-late-on-the-t14.md @@ -107,16 +107,10 @@ runner asks for no reboot; the deadline was the only bound left, and it fired ## The instrument that measures this already exists `src/metal.rs:1591-1597`'s `deadline_lateness_ms` computes exactly -`reached − bound` out of the `DEADLINE_EXPIRED` line (`src/bootlog.rs:28`); -`tests/common/metal.rs:274-275` reads it off every readback and `:895-919` -hands it to `profile.judge` as `boot.