Repository navigation
The stop takes the console wire from klogd for good and holds it to the machine's end; flush_final goes - #805
Conversation
… the machine's end A stop could power the machine off or reset it with its last records on no console. Measured on 8-CPU virt guests under HVF with a probe on the stop's two drains: drain_for_the_stop held the wire and let it go to klogd, queued behind it; klogd's turn was posted and klogd was not dispatched. The last word's drain_inline then found the wire free with a ticket outstanding (ticket=197 now=196) and declined, and flush_final spun on try_wire until its count ran out (2.95 s and 4.16 s in two reds), with the stop's thread parking nowhere from there to the power-off and running with preemption off from xhci::seal_shut on. SYSTEM_OFF followed, and on virt no black-box page said what was lost. Now the stop asks klogd for the wire (log::handoff), and klogd lets it go between two writes, never takes it again, and posts that it has. The stop parks on that post, so its own CPU is free to run klogd, bounded by LET_GO, DEAF_CPU's span; it then holds the wire through power::shutdown and power::reboot, which drain under it (StopWire). A take past the bound alerts; no take by it alerts with the holder's name and writes every record over it through the registers. klogd logs that it let the wire go, so a console says why its backlog arrives at the last word. flush_final, and its spin on a count, is gone. The hand-off's two SeqCst fences are loom's (console_handoff). The staged holder is two actuators, wire-held-across-the-stop and wire-kept-through-the-stop, judged on one-CPU q35 at the power-off and on virt at the reboot; with the stop's path as main has it, all four stall waiting for the last word. Closes issues/the-power-offs-last-drain-gives-up-on-a-wire-whose-holder-cannot-run.md. Files issues/a-woken-klogd-can-wait-seconds-on-an-idle-cpu-under-hvf.md, the dispatch delay the probe found under it, which this does not fix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Evidence patches for head M1-ask-fence-off: red in
|
|
Review of Size ( BLOCKER
NOTE
SEND BACK |
…this defect, into the stop's hold of the console wire The one conflict is the virt screen-test table: main moved `virt_reboot_refused_without_psci` to HVF and added its EL2 and random rows; this branch's two staged reboot rows stay emulated beside them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… its own cursor, and a staging reds main through its last drain Answers the first review of #805. - Every holder that lets the wire go once the stop asked posts the stop (`let_wire_go`), and the stop always wakes `klogd`: a shipping and an actuator kernel take the same path, and a holder other than `klogd` (`drain_inline` at a backend's arrival) releases into the same store-buffering pair the loom model checks. - `StopWire::Kept` owns the cursor the stop took once and never publishes, so a `klogd` preempted inside `drain_records` cannot put a stale position back under the stop and have its records written twice after the last word. - The staged hold parks inside `body`'s own hold of the wire: the release under test is `body`'s, with no gap for the stop's try to take the wire in. - `wire-held-at-the-last-word` stages `klogd` inside its hold from the boot's last word until after `xhci::seal_shut`, where the stop does not hold the wire itself; `machine_shutdown_wire_at_the_seal` judges it on one CPU. On main's stop it reds through `serial::flush_final` expiring after the seal, the defect the closed issue names. - The staging says `klogd`'s scheduler state and the stop's CPU's run queue `DEAF_CPU` into its wait, and every staged test reds on that line. - `SleepLock::holder_name` names a holder, a context with no task, a contender whose turn came and has not taken it, or nobody; `try_wire` answers it on a refusal and `serial::wire_holder` is gone. - The tracker: main's record of this defect is folded into `issues/a-woken-klogd-can-wait-seconds-on-an-idle-cpu-under-hvf.md`, which keeps the virt stop tests emulated, and the one-CPU TCG staging red has its own defect, `issues/a-staged-klogd-went-unrun-for-five-seconds-on-a-one-cpu-guest.md`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Evidence for the second round, head The negative control: the fix reverted to
|
|
Review of Size ( Round-1 blockers
The question in the brief: no test stages a holder other than
BLOCKER
NOTE
SEND BACK |
|
T14 at |
… the wire, and the held judge drops the let-go order A shipping klogd never parks while it holds the wire (a virtio wait spins, and a wake reaches only a parked task), and an idle one holds nothing, so the stop's first try takes the wire. The only holder the wake at the ask released was the one `wire-held-across-the-stop` parks inside its hold: the wake now runs under `boot-actuators` and that staging's predicate, and an unstaged kernel runs the shipping stop. `drain_inline` drops the wire plainly: it runs only before klogd starts (the boot, and a backend's arrival, which precedes `log::console::start`), when the stop cannot have asked, so its post could never fire. `SleepLock::holder_name` names three states: a task, a context with no task, or nobody. The contender-whose-turn-came arm is cut: klogd queues on the wire only behind the stop itself, after the stop stopped asking. The held judge no longer orders klogd's let-go line before the stop's record: klogd posts RELEASED before it logs that line, and the woken stop races it to the census (1 ms apart on SMP; on one CPU a tick between the post and the log can leave the line uncommitted). The hold, the record and the last word stay ordered, and the console must be clean, which is what the release-never-posts and stop-wakes-no-klogd mutations red on. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… the stream end's order (#803), into the stop's hold of the console wire Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…e it forgot at its registration is not lost The whole guest suite at 6d1d1e6 redded virt_reboot_wire_held on the staging's capture: klogd Blocked on cpu1, the stop's cpu0 with 0 ready, 5 s into the stop's wait for klogd to take the wire. `stage` stores STAGED and then wakes klogd; a klogd that is running then is flagged, not claimed, and `Watch::register` forgets that flag before klogd reads its condition. klogd's park recheck read the record backlog and the queue, never STAGED, so it parked on a staging nothing would wake again. The recheck now reads STAGED under `boot-actuators`, the staging's own condition. A shipping klogd's every wake is posted after a condition its recheck reads (a committed record, a queued line, a backend's rewind), so the forgetting loses it nothing; a shipping kernel is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…n at klogd's registration, and the park now rechecks STAGED The cause, from the staging's capture: the whole guest suite at 6d1d1e6 redded virt_reboot_wire_held with `klogd is Blocked(CpuId(1)), and the stop's CpuId(0) has its run queue read, 0 ready`, 5 s into the stop's wait. `stage` stores STAGED and wakes klogd; a running klogd is flagged, not claimed; `Watch::register` forgets the flag; and klogd's recheck read the backlog and the queue but never STAGED, so it parked with nothing left to wake it. The same order loses the wake on one CPU, where a klogd preempted between its drain and its park is resumed after the stop's stage; the first, uncaptured one-CPU red is attributed by that mechanism, not by a capture of its own. Fixed in 7e5534d under `boot-actuators`. The exit, at 7e5534d: 20 + 23 rounds of `cargo test --test toyos-build -- machine_shutdown_wire_held` (10, then 14, side by side) and `virt_reboot_wire_held` (4 side by side) on a 14-core Apple-silicon host, 694 runs, every one EXIT=0: 522 machine_shutdown_wire_held, 172 virt_reboot_wire_held. 16 of those rounds began at 1-minute load 30 or more (up to 47.99), holding 200 machine_shutdown_wire_held runs, 200 green. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Evidence for round 4 at The red this round fixes (the before arm), whole suite at
|
|
Review of Size.
Since Round-2 blockers
The round-2 NOTEs are done. Shipping code since
The claim that no shipping wake is lost: holds, checked by reading.
The closed issue's exit: met.
Metal. The
So the boot the orchestrator is running at this head confirms; it is not owed. If that boot contradicts any line of the round-2 reading, this point reopens. Evidence at the measured heads.
BLOCKER
NOTE
SEND BACK |
…timing, into the stop's hold of the console wire The counters-stall issue keeps main's ScalarEvolution paragraph for the stalls it compared and this branch's fifth and sixth, which ran this branch's kernel at aa7448db0 under the compiler before the fix and were not compared; the paragraph citing the issue main closed goes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Round 5 logs at the merge head
|
|
Review of Size.
The merge changes no file under
Round-3 BLOCKER
Merge resolution.
Metal. The merge's diff to
The round-3 NOTEs are done:
BLOCKERNone. NOTENone. LAND |
|
T14 at |
|
CI at |
…ge (#823), ToyOS's own network stack (#801), the signed package repository (#808) and the HTTPS client (#810), into the stop's hold of the console wire No conflict. The merge's diff against 0d448b2 under kernel/ and tests/ is main's own change from 198a9d3 line for line, differing only in tests/toyos.rs's hunk offsets, so the T14 reading at 0d448b2 carries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 6, merge head build-x86_64build-aarch64 |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head |
|
Round 6, merge head namedsuite |
…e SSH server core (#817), toyos-usbhid (#821) and the stop's hold of the console wire (#805), into the batch Cargo.toml: both sides' build dependencies, the batch's libm (#813) and main's toyos-ssh (#817). Cargo.lock: git's merge, which cargo metadata --offline leaves as it is; every package it names is in one side's lock. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…nsole wire (#805), into usbd usbd_drives_the_spare and usb_keyboard_rollover read kernel records on the console wire the stop now takes from klogd; they are rerun at this merge. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…nsole wire (#805), into the per-partition block authority Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…nsole wire (#805), into wt/toyos-netperf Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
A machine could power off or reset with its last records on no console. The stop now takes the console's wire from
klogdfor good, parked and bounded, and holds it to the machine's end.klogd, once the stop has asked, lets the wire go between two writes and posts the stop. A holder that keeps it through the bound is written over from a cursor the stop alone walks.serial::flush_finaland its spin on a count are gone.Head:
96859ecbb, the merge ofmainat46632bf25into0d448b2ec, the head the fourth review judged LAND and the T14 confirmed. It is there for #823: the PR's own checks run the branch's workflow file, and0d448b2ec'sguest / suitefailed only on Docker Hub's anonymous pull limit, which #823's ECR Public copy removes. The merge also carries #801, #806, #807, #808 and #810. It had no conflict;tests/toyos.rsauto-merged. It moves no toolchain:git diff 198a9d38e 46632bf25 -- rust .gitmodulesis empty.The T14 reading carries.
git diff 0d448b2ec 96859ecbb -- kernel testsismain's own change,git diff 198a9d38e 46632bf25 -- kernel tests, line for line: the two diffs differ only intests/toyos.rs's@@offsets (compared with the@@andindexlines dropped: identical). Neither toucheskernel/, nor the metal judge (tests/checks.rs,tests/checks/metal.rs,tests/common/metal.rs). No kernel or test file of this branch's own changed in the merge.Earlier,
0d448b2ecwas the merge ofmainat198a9d38e(#790's LLVM fork bump, #804's boot timing). Its one conflict,issues/a-counters-read-under-host-load-can-go-silent-for-15-s.md, is resolved as the third review asked (Records, below).git diff 3f1dea947 0d448b2ec -- kernelis empty; its diff totests/is #804's metal judge, sometalcasewas staged and run again there (Metal, below).The defect, as measured
main's stop, one CPU (machine_shutdown_wire_at_the_sealagainst the control below).klogdis inside its hold of the wire as the last word is logged, and is made runnable only once the stop has taken the seal.drain_inlinedeclines the held wire. Fromxhci::seal_shuton, the stop's thread runs with preemption off.flush_finalthen spinsPANIC_LOCK_SPIN_LIMITtries on a holder that cannot run, gives up, and the machine powers off. A probe on the control'sflush_final, through the UART registers, printedPROBE flush_final beganand thenPROBE flush_final EXPIRED: wire holder is a task; the machine powers off now. The console has nothing after the supervisor's stop line. This is the defectissues/the-power-offs-last-drain-gives-up-on-a-wire-whose-holder-cannot-run.mdnamed, red onmainas its exit asks.klogd's turn at the wire posted and not taken. At3ebb28c70,main's stop (the control) with the HVF harness patch reds 2 of 100 runs of the five SMP tests, bothvirt_mask_windowsSTALLED: waiting for the boot's last word. The fix: 0 of 200 (below). The earlier probe at863d73ed3, which read the wire's words at the decline (ticket=197 now=196,flush_finalspinning 2.95 s), is recorded inissues/a-woken-klogd-can-wait-seconds-on-an-idle-cpu-under-hvf.md.The fix, per decision
log::console::take_for_the_stop). It armsRELEASED, asks (Handoff::ask), and tries the wire. Where the try fails it parks onRELEASEDuntilLET_GO.klogdin a shipping kernel. A shippingklogdnever parks while it holds the wire:virtio::wait_usedspins, andnotifyclaims only a parked task. So aklogdinside its hold is running or runnable, and an idleklogdholds nothing, so the stop's first try takes the wire. The wake at the ask runs only underboot-actuatorsandwire-held-across-the-stop, the staging that parksklogdholding the wire; an unstaged actuator kernel runs the shipping stop.klogd's release answers the ask (let_wire_go). It drops the wire, reads the ask, and postsRELEASEDwhere it was asked. The store-buffering pair (the stop's ask then try,klogd's release then read) is closed by the twoSeqCstfences inlog/handoff.rs, which loom checks. No other holder exists onceklogdruns:drain_inline's callers areemitinDrain::Inline(KLOGDnull) andbackend_changed, reached only fromserial::initandvirtio_console::init, both beforelog::console::start. Sodrain_inlinedrops the wire plainly and posts nothing.klogd, asked, lets go between two writes and never takes the wire again. It logsconsole: klogd let the wire go to the stopand parks for the machine's life.StopWire::Kept(Cursor)holds the position the stop took once fromDRAINED. The stop walks it through the registers for both its drains and never publishes it. Aklogdpreempted insidedrain_recordscan put its stale position back intoDRAINED, but nothing the stop writes readsDRAINEDagain. A type makes the rewind unrepresentable, so no test is added for it.SleepLock::holder_namereturns aHolder, which names a task, a context with no task, or nobody;try_wirereturns it on a refusal. It replacesOwnerName, which printed nobody as "a context with no task".LET_GOisDEAF_CPU's span, 5 s. Asked,klogdowes the one line it is writing: at mostLINE_BYTES, 992 + 160 = 1152 bytes, which takes 0.3 s on the 16550 at 38400 baud (1152 × 10 bits / 38400, arithmetic). Past the bound the stop alerts by name, and the alert says the queued lines are not on the console.the wire through the stop'sis inNEVER_CLEAN, so any boot whose stop needed the bound reds unless it staged it.quiesceand are both fixed. A panic does not have this defect:halt_all_cpusstops every other CPU first, andpanic_flushdrains through the registers.reset_nowdrains nothing, by design.Shapes not taken: a time bound on the old last drain, which is still a wait, preemption off, on a holder the stop keeps off its CPU. A bounded
SleepLock::lock: an expired ticket can never be handed back. A post on the lock's own watch, which can wake the stop in place of a real ticket holder. No ABI change, and no change toklogd's or the supervisor's protocol.What changed in shipping code since the reviewed
241832e01Three things, all in
a78f4a449; round 4 (7e5534dc1) changes only actuator code.kernel/src/sleeplock.rs:Holderloses itsturn_untakenarm (a contender whose turn came and has not taken it), which no caller ofholder_namecan see on this tree:klogdqueues on the wire only behind the stop, after the stop stopped asking.kernel/src/log/console.rs,take_for_the_stop: thepost_wake()at the ask is guarded by#[cfg(feature = "boot-actuators")]andactuator::wire_held_across_the_stop(), so a shipping kernel no longer wakesklogdthere.kernel/src/log/console.rs,drain_inline: drops the wire plainly instead of throughlet_wire_go, whose post could never fire there.The T14 ran
metalcaseat241832e01(comment #805 (comment)). The third review judged that reading to carry to3f1dea947past these three changes: only the stop's two alerts printHolder, and the T14's stop reaches neither.Round 4: a staged
klogd's park rechecksSTAGEDThe whole suite at
6d1d1e60breddedvirt_reboot_wire_heldon the staging's capture,klogd is Blocked(CpuId(1)), and the stop's CpuId(0) has its run queue read, 0 ready.staged::stagestoresSTAGEDand wakesklogd. Aklogdthat is running then is flagged, not claimed, andWatch::registerforgets the flag beforeklogdreads its condition (kernel/pure/sched/watch.rs,register).klogd's recheck read the backlog and the queue and neverSTAGED, so it parked with nothing left to wake it. The recheck now readsSTAGEDunderboot-actuators(staged::pending).A shipping
klogdloses no wake this way, by reading every shippingpost_wake:emit's andqueue's are made only aftersignal_after_commit's fence, following the commit or the queued line that the recheck reads (DRAINED.any_pending(),QUEUE.len) afterarm_waiter's fence;backend_changedrewindsDRAINEDbefore its post, and runs beforeklogdstarts. The ask's wake,stage's andsealed's are actuator-only, andhold_if_staged's own park readsHANDOFF.asked()andSEALEDafter its registration.The staging
body's own hold (staged::hold_if_staged, called afterbodytakes the wire). A stagedklogdparks there with the wire held. The release under test isbody's, and there is no gap between two holds for the stop's try to take the wire in.wire-held-across-the-stopholds until the stop asks.wire-kept-through-the-stopholds for good.wire-held-at-the-last-word. Just before the last word, if the running task holds the wire, the staging logsconsole: the stop holds the wire at the boot's last word, staged. Otherwiseklogdholds it inside its hold until the stop has taken the seal, and then lets it go as soon as it runs. On this branch the stop always holds the wire there. Onmain's stop it never does, and the machine powers off throughflush_final's expiry (above).DEAF_CPU. The staging's wait has no bound in guest time.DEAF_CPUinto it, it logsklogd's scheduler state, the stop's CPU, and that CPU's run queue (driver::for_each_ready, actuator-only), then goes on waiting. Every staged test reds on that line. It is what named round 4's cause.klogd's let-go line before the stop's record:klogdpostsRELEASEDbefore it logs that line, and the woken stop races it.Tests, and why each tier
kernel-loomconsole_handoff. The store-buffering race over the realSleepLock: the stop finds the wire free, orklogdsees the ask. No guest test can enumerate that interleaving.machine_shutdown_wire_heldand_kept(one-CPU q35, the power-off),virt_reboot_wire_heldand_kept(virt, the reboot), andmachine_shutdown_wire_at_the_seal(one-CPU q35, the seal).metalcasereadback is asked to show that it has no console backend for the stop to drain to.metalcase, below.Checks, each its command's own exit
At the merge head
96859ecbb. Logs, scrubbed of home-directory paths and user names, are comments #805 (comment) (both builds), #805 (comment) to #805 (comment) (--ci host, eight parts) and #805 (comment) (the named filter and the suite). Each log starts with the head, the command anduptime, and ends withuptimeand the exit.cargo run -- --build-only --arch x86_64: EXIT=0.cargo run -- --build-only --arch aarch64: EXIT=0.cargo run -- --ci host: EXIT=0,Host: 78 step(s), all green. It runskernel-loom'sconsole_handoff(the_stop_finds_the_wire_free_or_klogd_sees_the_ask ... ok).cargo test --test toyos-build -- machine_shutdown acpi_power_button virt_reboot virt_off_names_the_cpus_left_on virt_smp virt_el1_smp virt_mask_windows): EXIT=0, 14 passed of 14, 1-minute load 57.20 when it began and 56.01 when it ended, liveness ceilings at 1.25x. The filters takemachine_shutdown,_short_stop, the three_wire_tests,acpi_power_button,virt_reboot,virt_reboot_refused_without_psci, the twovirt_reboot_wire_tests,virt_off_names_the_cpus_left_on,virt_smp,virt_el1_smpandvirt_mask_windows.cargo test --test toyos-build): EXIT=0, 49 passed of 49 (46 at0d448b2ec), 1-minute load 56.01 when it began and 70.65 when it ended, liveness ceilings at 1.00x.cargo run -- --clippywas not re-run at96859ecbb; it was EXIT=0 at0d448b2ec(comment The stop takes the console wire from klogd for good and holds it to the machine's end; flush_final goes #805 (comment)), and the merge changes none of this branch's files.Earlier, each at the head it names, and not owed again: neither merge since changes a file under
kernel/, the third review's ground for not re-owing them. Round 5's logs at0d448b2ecare comments #805 (comment) to #805 (comment).6d1d1e60b: the whole suite EXIT=1, 45 of 46,virt_reboot_wire_heldon the capture above.241832e01; fix reverted, staging kept):machine_shutdown_wire_at_the_sealEXIT=1,STALLED: waiting for the boot's last word. With the probe: EXIT=1, and the UART showsflush_finalbegan and expired (above). The control ismain'smachine.rs,power.rs,serial.rs,log/console.rs,log/mod.rs,sleeplock.rsand loom crate, plus the at-the-last-word staging.ask's fence removed: loom EXIT=101,nobody posts(at241832e01).asked's fence removed: loom EXIT=101,nobody posts(at241832e01).RELEASED, at7e5534dc1: EXIT=1. Both held tests red on the stop's late alert,console: 1:0 held the wire through the stop's 5000ms …, and let it go only after.STALLED(at241832e01).klogd(the guarded wake removed), at7e5534dc1: EXIT=1. Both held tests red:klogd was asked for the wire, and the stop's alert is on line ….klogd: EXIT=1, both held tests red on the capture (at241832e01).3ebb28c70). The harness patch (in the evidence comment) putsvirt_mask_windows,virt_el1_smpandvirt_off_names_the_cpus_left_ononProfile::Virt, allows the PSCI trace under HVF, and reds on the stop's alert as well as on a missing last word. The five SMP tests ran side by side, onecargo testper round, on a 14-core Apple-silicon host.main's stop (the control): 20 rounds, 98 of 100 green, load 31.87 to 48.37. The 2 reds arevirt_mask_windows,STALLED: waiting for the boot's last word.mainby construction.Records
issues/the-power-offs-last-drain-gives-up-on-a-wire-whose-holder-cannot-run.md. Its exit is met: a one-CPU guest test whose actuator leavesklogdinside its hold from the last word past the seal readsShutting down., and the same test is red onmain's last drain (the control and its probe).issues/a-staged-klogd-went-unrun-for-five-seconds-on-a-one-cpu-guest.md, filed earlier on this branch. Its cause is named from its capture (the forgotten stage wake, round 4) and fixed. Its exit, 200 side-by-side runs ofmachine_shutdown_wire_heldat 1-minute load 30 or more, is met at7e5534dc1: 43 rounds of separatecargo testinvocations (10, then 14,machine_shutdown_wire_heldbeside 4virt_reboot_wire_held), 694 runs, every one EXIT=0 (522 and 172). The 16 rounds that began at load 30 or more (up to 47.99) hold 200machine_shutdown_wire_heldruns, 200 green. The first, uncaptured one-CPU red is attributed to the same cause by its mechanism, not by a capture of its own: one CPU loses the wake the same way whenklogdis preempted between its drain and its park.main'sissues/the-boots-last-word-can-miss-the-console-when-klogd-holds-the-wire.mdis deleted; its measurements and exit live inissues/a-woken-klogd-can-wait-seconds-on-an-idle-cpu-under-hvf.md. The citations intests/toyos.rsandissues/toyos-runs-on-arm64.mdare moved.issues/a-counters-read-under-host-load-can-go-silent-for-15-s.md: a fifth and sixth occurrence are added (a whole suite ataa7448db0red onvirt_smpandvirt_mask_windowsat load 35.09 to 79.44). The merge keepsmain's ScalarEvolution paragraph for the stallsmaincompared, and puts the fifth and sixth after it. Those two ran this branch's kernel ataa7448db0, built by the compiler before the fix, and the issue says they were not compared. The branch's paragraph citing the issuemainclosed is dropped.issues/the-panic-lock-spin-limit-is-a-count-its-comment-calls-a-second.md,issues/a-holders-queued-line-can-reach-the-console-after-the-last-word.mdandissues/the-power-offs-give-back-line-is-in-no-black-box-tail.md.Size
git diff --shortstat 46632bf25...96859ecbb: 22 files, +759 −249, unchanged since0d448b2ec. Production (kernel/src) is +466 −87. Of that, the actuator-only lines, compiled out of a shipping kernel, are the 183 counted at241832e01, the 3-line guard on the ask's wake, and round 4's 13: thestagedmodule and its hooks inlog/console.rs,actuator.rs,sched::driver::for_each_ready,serial::wire_is_mineand the staging calls insyscall/machine.rs. The rest is the hand-off,StopWirewith its own cursor,take_for_the_stop,let_wire_goandSleepLock::holder_name, and it deletesflush_final,drain_all,drain_for_the_stopandwire_holder. Tests and the loom crate are +190 −7, andissues/is +103 −155.Metal
Ran at
241832e01(comment #805 (comment)), by the orchestrator:metalcaseonly. The judgeblackbox_done_chain machine_reboot metal_sim_scanout_wcexited 0, all three passing. The tail holdsconsole: klogd let the wire go to the stop, thenRebooting.. No line containsthe wire through the stop's, and none is[serial] the stop's records are not on the console. The console backend is None (serial: 16550 loopback read 0xff,virtio-console: no device found). The third review judged this reading to carry to3f1dea947.Ran again at
0d448b2ec(comment #805 (comment)), by the orchestrator, staged because0d448b2ec's diff totests/held #804's metal judge:metalcase, image sha25611fc843a…af4fc527checked againstrequest.txt. The judgeblackbox_done_chain machine_reboot metal_sim_scanout_wcexited 0, all three passing. The tail holdsconsole: klogd let the wire go to the stopandRebooting.; no line containsthe wire through the stop'sor[serial] the stop's records are not on the console; the console backend is None.Carried to
96859ecbb, not run there: the merge's diff tokernel/andtests/ismain's own (Head, above), and touches neither the kernel nor the metal judge.Not measured, or unsure
96859ecbb. Its reading at0d448b2ecis carried by the kernel and test diffs; the image at96859ecbbstill differs from0d448b2ec's bymain's userland and build changes (The shipped netstack runs ToyOS's own network stack and smoltcp leaves the tree; libc reads a stream's end as std does #801, The C cases link without DWARF: the testcases ROOT goes from 305 to 209 MiB, and the checkout-path issue records the paths every guest binary carries #806, An installed app sees its own package read-only and its own folder as HOME, and nothing else of /apps or /home #807, toyos-update verifies a signed package repository and src/publish.rs writes one through it; pkg install <name> waits on an atomic directory rename on DATA #808, An unchanged ureq and rustls client on a ring fork fetches byte-exact over TLS 1.3 in a guest, trusting the Mozilla roots every image carries with their licence's text #810, The guest suite pulls its Debian image from ECR Public's copy of Docker Hub's, by the same digest #823), which no metal row has judged on this branch.mainhas moved past the merge to5a3b74345(DATA's filesystem commits atomically, a directory rename moves whole or not at all, and a full volume still shrinks #816, toyos-ssh: ToyOS's own SSH server core, sans-IO: strict curve25519 key exchange, Ed25519 host key, chacha20-poly1305, Ed25519 publickey authentication, and exec over session channels that never reuse an id #817, USB HID reports are decoded by toyos-usbhid, which believes a rollover report's modifiers and not its slots #821, the last touchingkernel/src/drivers/xhci,keyboard.rsandmouse.rs).git merge-tree --write-tree 5a3b74345 96859ecbbis clean (exit 0); it is not merged, so that the T14 reading carries.3ebb28c70.LET_GO's derivation holds for the 16550 only.issues/a-woken-klogd-can-wait-seconds-on-an-idle-cpu-under-hvf.md, its cause not captured.🤖 Generated with Claude Code
https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C