Repository navigation
The T14 profile goes from 30 boots to 27: the orderly-reboot rows ride metalcase, the self-tests arm shared-debug, and netstack's lease probe is deleted - #770
Conversation
…se, and netstack's lease probe goes Step A of fewer, fuller boots, as far as the owner's rulings reach. jobcase's four rows move to metalcase. blackbox_done_chain, machine_reboot and machine_soft_off_decoded read the loader's pass after a reset and two boot records, and usb_reset_hands_devices_back's control arm reads the reset's own account; every boot that hands the machine back writes all of them. jobcase was a boot of its own by history: the same rows boot tests/jobcase under QEMU, where its committed job list is the one `reboot`. On the T14 every image's job list is derived, and metalcase's is that same empty list. A whole-profile readback of metalcase from 2026-10-07 carries every needle the four judges ask for. What changes for the rows: metalcase starts the compositor, soundserver, netstack and sshserver, so a stop that wedges on one of them now reds these four beside metal_sim_scanout_wc, where jobcase started none. The lease probe is deleted on the owner's word: the lan_lease_report row, tests/lanleasecase, netstack's --exit-with-lease with its report file and window, toyos_i219::lease, toyos_i219::phy::Outcome, the gate in src/build.rs that held the flag to a card the Intel driver opens, Readback::log_volume_file and tests/common/volumes.rs. lan_dhcp_lease on lantalkcase reads the lease off netstack's own lines. The harness no longer depends on toyos-i219. The driver's test of who stood beside another agent's flag asserts the refusal's own `beside` where it asserted an exit code. Closes issues/netstacks-lease-probe-answers-a-question-its-lines-already-answer.md. issues/lan-hold-holds-two-boots-open-for-a-flat-twenty-seconds.md is renamed: one boot is left holding the sleep. The machine record loses the rows of the two labels that go. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
tests/toyos.rs conflicted where #764 deleted machine_soft_off_decoded beside machine_reboot at the place this branch moved both rows from. Both sides stand: the rows are at metalcase, and the deleted row is deleted there too. The three moved rows that remain read the loader's pass after the reset and the kernel's reset-register decode, none of which #764 changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
…st job testcases-hold was a boot of its own for budget alone, and the owner ruled that a boot of its own must bring value. Its two rows name `testcases` and sit last in the table, because a batch's job list is its rows' jobs in table order and acpi_hold must be the last of them. The bound is unchanged and needs no change. The runner gives the whole list toyos_tco::JOB_BOUND_MS, 60 s from kernel start, and acpi_hold sleeps to a tenth short of it, 54 s, not for a span: on the whole profile of 2026-10-07 the nine jobs ahead of it ended 43.3 s after kernel start, so it sleeps 10.7 s there, and none once they run past 54 s. The list ends where testcases-hold ended it, with the tenth every shared boot's members leave. A bound that follows the list would be the runner's --bound-ms with the kernel's boot-deadline and toyos-metal's wait derived beside it, which is step B's. One reading the T14 has to answer: on that same profile the loaded testcases boot carries the server's first query and no count line in 42 s, where the quiet testcases-hold boot counted 14 queries in its first 30 s. With the hold the server has 10.7 s of an idle machine before the boot ends. A run filtered to either row alone stages `testcases` with the hold as its one job, which is the boot testcases-hold was. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
selftests and shared-debug are the same kernel on the same config, and the self-tests run at init and do nothing after it. shared-debug takes their eleven parameters and their ten rows name it, so the profile loses the selftests boot. On trial, and a commit of its own for that: the owner's ruling is that it lands if the seven members and the ten rows give on one boot the verdicts they give on two, read on the T14 at the parent of this commit and at this one. The machine record loses the selftests rows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
…the line they read This reverts 9ded907. On the T14 at that commit acpi_server_events was red on `testcases`: `the server logged 1 first sighting(s) and None for counts`. The server writes its count thirty seconds after it arms, about 42.9 s on the log's clock, and `testcases` logs some forty megabyte files under counters_metal where logkeeper keeps sixteen: the readback has no record between 34 s and 47 s, and says so fifteen times (`/log holds more than 16 logs, so ..._0012.log was deleted`). The server served throughout: cpu0's census reads userdev=48 at the end, as on the quiet boot. The boot's value is a log that is whole. issues/a-t14-boot-that-outlogs-its-retention-loses-its-middle-and-the-rows-whose-lines-sat-there.md records the weakness and what moves the rows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
|
T14 run 4, at
Judge (
|
|
Review of Net: 27 files, +178 −1276 ( BLOCKER
NOTE
What the brief asked to be checked
The two boots owedBoth came back to the orchestrator's disk while this was being written (
SEND BACK |
…dden row is filed Review of #770. The hole in `testcases`' log runs from 34.875 s to 47.220 s, and the fifteen deletion lines are the ones that survived. T14 run 4 read `lantalkcase` refused for the cable, at this branch's head as at main's 6f87cdb the same day, and the harness reds every row of a refused boot with the refusal. lan_message_delivery reads only the stick, which carries its two records on both boots. Filed, not changed here. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
|
Review of Net: 28 files, +231 −1276 ( Round 1's BLOCKERs
Round 1's NOTEs
BLOCKERNone. NOTE
LAND AFTER NAMED CHANGES |
Review of #770, round 2: the exit gave this file lan_lease_report and lanleasecase, which the lease probe's deletion took for good, and said so three lines later. One exit, lanswapcase's, waiting on its restore. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A
Step A of fewer, fuller boots on the T14: rows moved onto boots that already exist, and one boot deleted with the shipped code that existed only for it. No harness or runner code changes;
userland/test-runneris untouched.The owner's principle, verbatim: "we want as many test on the t14 as possible. its the only true tests we have. if the tests suck we delete them outright. tests that require their own boots must bring value."
Boot count
cargo test --test toyos-build -- --metal --list, as the harness prints it:d83ab1398(merge base)[metal] 68 registration(s) and 229 shared member(s) over 30 boot(s)c84f5fafe(the head run at; the commits after it change only files underissues/)[metal] 67 registration(s) and 229 shared member(s) over 27 boot(s)Lines: +236 −1281 over 28 files (
git diff --shortstat origin/main...HEAD). Production code (netstack,toyos-i219less its tests): +12 −638. Harness, tests, record and issues: the rest.What changed, per decision
jobcase's rows ridemetalcase.blackbox_done_chain,machine_rebootand the control arm ofusb_reset_hands_devices_backread the loader's pass after the reset, the kernel's reset-register decode and the reset's own account, which every boot that hands the machine back writes.jobcasewas its own boot by history: under QEMU the same rows boottests/jobcase, whose committed job list is the onereboot; on the T14 every job list is derived andmetalcase's is that same empty list. What a boot-mate's red now does:metalcasestarts the compositor, soundserver, netstack and sshserver, so a stop that wedges on one of them reds these rows besidemetal_sim_scanout_wc, wherejobcasestarted none. (machine_soft_off_decoded, the fourthjobcaserow, was deleted onmainby #764.)The lease probe is deleted, on the owner's ruling ("Yes, delete"): the
lan_lease_reportrow,tests/lanleasecase, netstack's--exit-with-leasewith its report file and window,toyos_i219::lease,toyos_i219::phy::Outcome, the gate insrc/build.rsthat held the flag to a card the Intel driver opens,Readback::log_volume_file,tests/common/volumes.rs, and the harness's dev-dependency ontoyos-i219.lan_dhcp_leaseonlantalkcasereads the lease off netstack's own lines. The driver's test of who stood beside another agent's flag asserts the refusal's ownbesidewhere it asserted an exit code.issues/netstacks-lease-probe-answers-a-question-its-lines-already-answer.mdis closed by deletion; it carried no rule to fold to a site. The records that cited the probe are corrected, and thelan_holdissue is renamed, one boot being left with the sleep.The init self-tests arm the
SYS_DEBUGmembers' boot.selftestsandshared-debugwere the same kernel on the same config;shared-debugtakes the eleven parameters and the ten rows name it. The owner's ruling: "Yes, after a trial". The trial is below, and the seventeen agree. What a boot-mate's red now means: the seven members run armed with the eleven self-tests on the T14 and unarmed under QEMU, so a member red on the T14 alone has the arming as a candidate cause, and a kernel death in a self-test at init reds the seven with the ten.The ACPI server's two rows keep
testcases-hold. They were moved ontotestcases(9ded9075c) and moved back (c84f5fafe) after the T14 read the move red; both commits are in the branch. See the first T14 run.Timing rows stay on
testcases-debug: the owner's ruling, "Wait for step B".The machine record loses the rows of the three labels that go (
jobcase,lanleasecase,selftests).The T14 runs
Images staged with
--metal --metal-readback, booted by the orchestrator, judged by the harness's own offline judge.9ded9075cmetalcase,metaldevicecase,testcases,testcases-watchdog,selftests,shared-debug(unarmed)4b53cd888shared-debug(armed with the eleven)c84f5fafetestcases-holdc84f5fafetestcases,testcases-watchdog(rc=0);lantalkcase(toyos-metalrc=1)Run 1's red:
FAIL acpi_server_events: the server logged 1 first sighting(s) and None for counts, ontestcaseswithtest_rs_acpi_holdits last job. The server was not at fault. It writes its count thirty seconds after it arms (armed at 12.851 s on the log's clock, so about 42.9 s), andtestcaseslogs about forty megabyte files undercounters_metal's dump wherelogkeeperkeeps sixteen and deletes the writing boot's own middle by design. The readback's last record before the hole is at 34.875 s and its first after it at 47.220 s; fifteen deletion lines survive in it, the firstlogkeeper: /log holds more than 16 logs, so /log/2026-10-08-140646_0012.log was deletedat 47.238 s, the earlier ones having gone with the parts that held them. cpu0's last census readsuserdev=48, as on the quiet boot, so the server served throughout. On the quiettestcases-holdboot the line is there (run 3:PASS acpi_server_events,PASS acpi_tables_loaded,test_rs_acpi_holdexit 0). Filed asissues/a-t14-boot-that-outlogs-its-retention-loses-its-middle-and-the-rows-whose-lines-sat-there.md: the hole is intestcases' readback of 2026-10-07 as well, the harness says nothing of it, and step B's merged boot logs more.Run 4:
testcasesat its nine-job list andtestcases-watchdog, every row PASS (21). The threelantalkcaserows are red with one line each, the boot's refusal and not a row's own finding:verdict.txtreadsrefused … the stream never opened: the host did not reach the machine. That is the harness's rule and not this diff:read_readback(tests/common/metal.rs, unchanged here but for the deletedlog_volume_file) answers a refused boot's readback with the refusal, and every row riding the boot takes it.maindoes the same for the same refusal:lantalkcasestaged from6f87cdb9cand booted the same day has the sameverdict.txt(issues/lan-talk-is-unread-on-the-t14-since-the-claims-binding-landed.md). So no row read this head's netstack on the T14, and the lease probe's deletion is not shown on metal by a judge.What the stick of run 4 carries, read by hand and not by a judge, beside the same lines of
main's boot:c84f5fafemain6f87cdb9cpcidev: PCI 00:1f.6 [8086:15fc] handed over on slot 0, vector 0x28pcidev: slot 0 took its first message on vector 0x28netstack: I219: link up at 1000 Mb/s full duplex, … ms after the driver came upnetstack: DHCP: lease …, … ms after netstack came upnetstack: ready, at most 103 piped connectionslan_dhcp_leaseis not a stick-only row:lan::on_metalholds the lease to the address the host reached the machine at (back.talk()), so it cannot pass while the cable path is down, whatever the harness did with a refused boot.lan_message_deliveryis stick-only and is hidden by the refusal; filed asissues/a-cable-refusal-hides-the-stick-only-row-of-the-talking-boot.md, the rule unchanged here.The seventeen (the trial of the self-test move): the seven members
abuse_kernel_addr,counters_silent,handle_lifetime,ring0_timer_in_syscall,shm_release_reclaims,spawn_child_ends_first,spawn_lands_claimedexit 0 on the unarmed boot of run 1 and on the armed boot of run 2; the ten rowspci_capability_walk,read_fault_selftests,leak_rollback_selftest,lapic_spurious_vector,xhci_xecp_walk,xhci_descriptor_walk,sysret_ss_reload,input_merge,operation_nesting,iommu_firmware_leftpass onselftestsin run 1 and onshared-debugin run 2.Which boots of this head were booted where
Of the boots whose membership or image this pull request changes:
testcases-holdc84f5fafe, this headshared-debug, armed, with the ten self-test rows4b53cd888git diff --stat 4b53cd888 c84f5fafeistests/toyos.rs(the two ACPI rows' arms), three rows of the machine record and one issue filemetalcase,metaldevicecase9ded9075cgit diff --stat 9ded9075c c84f5fafeis the same three files, and intests/toyos.rsonlyshared-debug's parameters and the ACPI rows' armstestcases,testcases-watchdogc84f5fafe(run 4)lantalkcasec84f5fafe(run 4), refused for the cable: booted, and no row judgedEvery other boot is the merge base's. The commits after
c84f5fafechange files underissues/and no input of any image.Every boot this head keeps, and what its own boot brings
testcasestests/testcasesshared,shared-debugSYS_DEBUG)windowscasemask_windowslatencycasetlb_shootdown_cost,latency_wakelogstallcasesoundserver_log_stalllogkeeper, and audiometalcasemetaldevicecaseusb_reset_hands_devices_back's first armproctreecaseacpicaseacpi_server_deathacpiservermay hold the claim the job hands overlantalkcasetestcases-watchdogloader_watchdog_arms,watchdog_fedtestcasestestcases-deafdump_nmi_probeiommu-no-remapclaim_refused_without_remappingisa-withhelddeadlinewedge,hardlockup,usbload,usbbreak,foreignrecordtestcases-holdacpi_server_events,acpi_tables_loadedtestcasesthe line the first row reads is deleted. Waits on the issue filed aboveBoots whose own boot brings no value and are not moved here, and what each waits for:
shared-2,ccorpus,testcases-boundstestcases-mkdir,testcases-readdirtestcases-debugtlb_shootdown_waitsandtrace_record_costread a clock, and the harness runs a shared boot's members before its rows' jobsNo row is proposed for deletion: neither the machine record nor the tracker holds a red history for one. What the tracker does hold against the profile is
issues/lan-hold-holds-a-boot-open-for-a-flat-twenty-seconds.md(a helper's flat sleep) andissues/the-t14s-record-keeps-three-rows-of-a-boot-nothing-stages.md.Gates
At
c84f5fafe:cargo metadata --locked0;cargo test --test toyos-checks0 (37 passed);cargo run -- --build-only0 (endsBuild finished.);--metal --list0 (67 / 229 / 27).At
4b53cd888, whose difference from this head is the three files named above:cargo test --lib testargs0 (17 passed);cargo test --lib build::0 (40 passed);cargo test -p toyos-i2190;cargo test --test toyos-checks0;--build-only0; and the harness's offline judge of the fourmetalcaserows over the T14'smetalcaseandmetaldevicecasereadbacks of 2026-10-07, 0 (made by a kernel older than #764: it shows the judges fitmetalcase's bytes, and run 1 is what shows this kernel).At
802287708,cirun 37793515070 (conclusionsuccess):hostends[ci] Host: 78 step(s), all green;toolchain / buildsucceeded;guest / suiteends[ci] the suite: test result: ok. 36 passed, 36 totaland[ci] Guest: 5 step(s), all green,netstack_socket_churnamong its PASS lines. The tip after it changes one issue file.No guest test is added, changed or cut. No dependency is added; one dev-dependency goes.
Unsure of
issues/the-t14-stopped-answering-ssh-between-two-lan-boots.md: its exit namedlanleasecaseandlanswapcase. It now nameslanswapcasealone, in the reviewer's wording; the owner has been told and may overrule it.readyand stayed up until the stop; no connection was served on the T14. The owner's ruling on the talking rows, verbatim: "we should disable or remove those tests". A later pull request does that, and closesissues/a-cable-refusal-hides-the-stick-only-row-of-the-talking-boot.mdin the same diff.🤖 Generated with Claude Code
https://claude.ai/code/session_01RvnWQFcMuGqTHYhvSnTe8A