Repository navigation
Conversation
… function as pci:1af4:1059 The kernel's drivers/virtio_sound.rs, its IDT vector 0x23, the virtio-sound device class, its arms of SYS_DEVICE_REG_READ/WRITE and of the read and poll paths, and toyos-abi's virtio_sound layout are deleted, with the kernel transport's code only that driver used (the split used-ring consumer, write_chain, bind_msix). soundserver holds the function as a PCI claim and drives it itself through toyos-virtio: the capability walk, §3.1.1's bring-up, the three queues in one grant from SYS_DEVICE_DMA_ALLOC behind the unit, and the transmit queue's MSI-X as the claim's interrupt record. The sound device's messages and queues are a pure crate beside the mixer, toyos-virtio-sound, host-tested against a model device that answers on the doorbell with VirtIO 1.2 §5.14's tables as the oracle: every request byte for byte, the stream information at its offsets, and each malformed answer — a short response, an undefined status, a short or failed period status, a short event — refused by name. toyos-virtio gains the capability walk (PCI 3.0 §6.7: links masked, a link into the header and a looped list refused, a refused read refused by the claim's own word), NO_VECTOR and a 32-bit device-configuration read (§4.1.3.1), and refuses a device-specific structure off four bytes (§4.1.4.6.1). netstack walks through it; its own walk and the issue against it go. The HDA path is untouched. The completion record soundserver's DLL reads is now stamped when soundserver reads the used ring, not in an ISR: a claim's interrupt record carries a count and no time. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… answers clippy Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… decline control gets a virtio-gpu the kernel still drives With the kernel's virtio-sound gone, virtio-no-access-platform reached no device on a Headless machine: every non-console virtio function there is a process's claim. HeadlessVirtioGpu adds one behind the unit, which the actuator declines and QEMU refuses FEATURES_OK for. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Mutation patches (applied as exact checked substitutions by the script below, each built, tested and restored; tree clean after). import subprocess, sys
root = "/Users/jan/Dev/jan/toyos-vsound"
muts = [
("m1-short-answer", "userland/soundserver/virtio-sound/src/lib.rs", " if written < response {", " if false && written < response {", "toyos-virtio-sound"),
("m2-period-status", "userland/soundserver/virtio-sound/src/lib.rs", " if written < wire::STATUS_BYTES {", " if false && written < wire::STATUS_BYTES {", "toyos-virtio-sound"),
("m3-walk-mask", "toyos-virtio/src/pci.rs", " next = read8(at + 1)? & !3;", " next = read8(at + 1)?;", "toyos-virtio"),
("m4-walk-refusal-as-zero", "toyos-virtio/src/pci.rs", " offset: read32(at + 8)?,", " offset: read32(at + 8).unwrap_or(0),", "toyos-virtio"),
]
for name, path, old, new, pkg in muts:
p = f"{root}/{path}"
s = open(p).read()
assert s.count(old) == 1, (name, s.count(old))
open(p, "w").write(s.replace(old, new))
try:
b = subprocess.run(["cargo", "test", "-p", pkg, "--no-run"], cwd=root, capture_output=True, text=True)
print(name, "BUILD EXIT", b.returncode)
r = subprocess.run(["cargo", "test", "-p", pkg], cwd=root, capture_output=True, text=True)
failed = [l for l in r.stdout.splitlines() if l.endswith("FAILED") and l.startswith("test ")]
print(name, "TEST EXIT", r.returncode, "RED" if r.returncode else "GREEN", failed)
finally:
subprocess.run(["git", "checkout", "--", path], cwd=root, check=True)
print("tree:", subprocess.run(["git", "status", "--porcelain"], cwd=root, capture_output=True, text=True).stdout or "clean")Result: |
|
Review, round 1, head Net lines ( BLOCKER
NOTE
SEND BACK |
|
T14 at |
…re one claim crate Review round 1 of #822. The kernel stamps each claimed function's interrupt record: DeviceIrqRecord grows `first_nanos`, when the first message a read counts landed, and `last_nanos`, never older than the newest it counts. The count shares one word with the number of reads that took one, so which read a message falls to and whether it is that read's first are one compare-exchange; the first message of read n stamps the slot of n's parity, so a message landing while a reader is between its exchange and its loads stamps the next read and never this one. `kernel/loom/tests/device_irq.rs` gains `a_reads_times_are_its_own_messages`, and `device-irq-lossy` still reds `every_message_is_counted_once`. soundserver's virtio-sound path is clocked by device time again: the wake's lateness splits at the first message's landing, as it split at the oldest record's ISR time when the kernel drove the device, and the DLL takes the newest message's landing as the last period's, which is dll.rs's own contract for a folded batch. The HDA backend hands its record's one timestamp as both, so the HDA path computes what it computed before. The backends answer one completion or none, which both already did. `userland/toyos-pci-claim` is the one home of what netstack and soundserver both copied: Bar and Grant as toyos-device-memory's boundary over the SDK's Window, KernelRefused, and `virtio::negotiate` — the claim's description, the capability walk, the BAR, `Offer::acknowledge` and `accept` — with the feature line each driver says under its own name. netstack's `device.rs` goes; its Latch moves into i219.rs, its one user. netstack's `config_space_is_bounded` goes: `vendor_caps` follows `u8` links masked to dword alignment and cannot read past 0x10F whatever the claim bounds, and the bound itself is `toyos_dma::register`'s, host-tested, and a `Register` witness `pcidev::config_read` takes. `iommu_virtio_platform` stops reading its line. `virtio_sound_counts` was already red with the transmit queue on NO_VECTOR: with no client soundserver's wait has no timeout, so the periods left in flight never come back and it never suspends; the job's doc says so. The format strings the test broke across raw newlines are escapes. The defensive status zeroing in `toyos-virtio-sound`'s submit goes. The decline control's dependence on virtio-gpu is recorded in the every-driver track's stage 1 with its exit, and the lending issue no longer cites virtio-sound's pool as present. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 2 mutations, each applied as a checked patch ( m5-one-first-slotRun: --- a/kernel/src/pcidev/record.rs 2026-10-10 08:47:09
+++ b/kernel/src/pcidev/record.rs 2026-10-10 08:59:35
@@ -140,7 +140,7 @@
let mut word = self.word.load(ORDER);
loop {
if word & COUNT == 0 {
- self.first[(word / READ) as usize & 1].store(now, ORDER);
+ self.first[0].store(now, ORDER);
}
match exchange!(self.word, word, word.wrapping_add(1), Ordering::Release) {
Ok(_) => return,
@@ -169,7 +169,7 @@
Some(DeviceIrqRecord {
count: (word & COUNT) as u32,
_pad: 0,
- first_nanos: self.first[(word / READ) as usize & 1].load(ORDER),
+ first_nanos: self.first[0].load(ORDER),
last_nanos: self.last.load(ORDER),
})
}m6-stamp-after-countRun: --- a/kernel/src/pcidev/record.rs 2026-10-10 08:47:09
+++ b/kernel/src/pcidev/record.rs 2026-10-10 08:59:35
@@ -139,11 +139,13 @@
self.last.store(now, ORDER);
let mut word = self.word.load(ORDER);
loop {
- if word & COUNT == 0 {
- self.first[(word / READ) as usize & 1].store(now, ORDER);
- }
match exchange!(self.word, word, word.wrapping_add(1), Ordering::Release) {
- Ok(_) => return,
+ Ok(_) => {
+ if word & COUNT == 0 {
+ self.first[(word / READ) as usize & 1].store(now, ORDER);
+ }
+ return;
+ }
Err(seen) => word = seen,
}
}m7-count-release-relaxedRun: --- a/kernel/src/pcidev/record.rs 2026-10-10 08:47:09
+++ b/kernel/src/pcidev/record.rs 2026-10-10 08:59:35
@@ -142,7 +142,7 @@
if word & COUNT == 0 {
self.first[(word / READ) as usize & 1].store(now, ORDER);
}
- match exchange!(self.word, word, word.wrapping_add(1), Ordering::Release) {
+ match exchange!(self.word, word, word.wrapping_add(1), ORDER) {
Ok(_) => return,
Err(seen) => word = seen,
}control
|
|
Review, round 2, head Round 1's BLOCKERs
Net lines ( BLOCKER
NOTE
SEND BACK |
|
T14 at |
…and, and Grant's host-test constructor is a dev feature Review round 2 on #822 named the `None => now` arm of `Virtio::completion`: with no record taken but a period on the used ring, it stamped the read time as the device's, the pickup-as-device-time round 1 removed, kept for the in-flight window. The arm goes. `Sound::played` takes the record the driver took and reads the ring only when there is one: the device writes a used element before the notification §2.7.7 owes for it, so a period on the ring with no record has a notification still to land, which makes the claim readable and soundserver wakes for it. The driver's order, take and then read, is now a type's: the ring is read through the record. `completed` is private. `no_period_is_stranded_between_its_used_element_and_its_notification` runs two periods (used element, then notification) against two driver wakes (take, then read) in all 70 interleavings, then wakes the driver while the claim reads ready, and asserts each period comes back exactly once. The review's other in-flight case — a record in hand while a newer period's notification has not landed — feeds the DLL a period stamped a notification early. It is recorded with an owner and an exit in issues/soundservers-virtio-clock-can-take-a-period-one-notification-early.md. `Grant::over` was public for netstack's host test alone; it is gone, and `Grant::leaked` behind the `host-grant` feature, which only netstack's dev-dependency turns on, is the test's constructor, with the leak and its `unsafe` inside the crate. toyos-abi's sentence that the virtio-sound driver builds an `AudioCompletionRecord` stamped at read time was false at this head and is deleted. diskserver's NVMe bring-up open-codes `Bar::map`, `Grant::alloc` and `KernelRefused`; filed as issues/diskservers-nvme-bring-up-open-codes-what-toyos-pci-claim-holds.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 3 mutation, applied as a checked patch ( m9-read-without-recordRun: --- a/userland/soundserver/virtio-sound/src/lib.rs
+++ b/userland/soundserver/virtio-sound/src/lib.rs
@@ -328,7 +328,10 @@
/// period already in it has a notification still to land, which makes the
/// record readable again, and it is read then.
pub fn played<R>(&mut self, taken: Option<R>) -> Result<Option<(u32, R)>, Refusal> {
- let Some(record) = taken else { return Ok(None) };
+ let Some(record) = taken else {
+ self.completed()?;
+ return Ok(None);
+ };
let mask = self.completed()?;
Ok((mask != 0).then_some((mask, record)))
} |
|
Review, round 3, head Round 2's BLOCKERs
Round 2's NOTEs: the false sentence in Gates at
Net lines ( On the
|
…e is owned by HDA's move to a pci claim src/clippy.rs gains a shape for `-p toyos-pci-claim --all-targets --features host-grant` with the adopted lints and warnings denied, as toyos-xhci has for its own feature: `$GUESTS` excludes the crate from both workspace shapes and NESTED reaches only crates nested under a program, so `Grant::leaked` was linted by nothing. The review's named shape exits 101 as written: clippy then lints the crate's path dependency `toyos`, a guest crate no shape lints, which carries 11 findings. `--no-deps` lints the claim crate alone. That checks the host crates it shares with the workspace shapes (toyos-abi, toyos-device-memory, toyos-virtio, toyos-untrusted) with plain rustc, so the shape takes its own target directory, as toyos-abi's does, rather than flip those units between the two checks every run (22M). A redundant clone planted in `Grant::leaked` reds the shape's command (exit 101) and restores clean. issues/soundservers-virtio-clock-can-take-a-period-one-notification-early.md was owned by "whoever next changes" two sites. It is now owned by stage 1 of issues/every-driver-is-still-in-the-kernel.md: HDA leaving the kernel for a pci claim feeds soundserver's DLL from a claim's record on every machine, and that stage now names this exit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 4 mutation m10, the clippy shape for --- a/userland/toyos-pci-claim/src/lib.rs
+++ b/userland/toyos-pci-claim/src/lib.rs
@@ -96,5 +96,6 @@
pub fn leaked(bytes: usize, device_base: u64) -> Self {
- let backing = vec![0u64; bytes.div_ceil(8)].leak();
+ let zeroed = vec![0u64; bytes.div_ceil(8)];
+ let backing = zeroed.clone().leak();
// SAFETY: `leak` gives the allocation the `'static` lifetime the window
// needs, and it is at least `bytes` long.
let window = unsafe { Window::new(backing.as_mut_ptr().cast(), bytes) }; |
|
I219 reading on the T14 for #822's head
#818 was closed, not landed, under the owner's testing ruling. So this boot stands in for the review's "merge |
|
Review, round 4, head Round 3's BLOCKERs
Round 3's NOTE: the virtio-clock issue's owner is now stage 1 of Net lines ( The other round-4 gates are all at
origin/mainMain has moved from
BLOCKERNone open. NOTE
LAND |
…812), TCP window scaling (#820) and the stop's hold of the console wire (#805), into virtio-sound and the shared PCI claim Both conflicts are two additions at one site, and both sides are kept whole: - tests/common/qemu.rs: this branch's Profile::HeadlessVirtioGpu and main's Profile::HeadlessUsbSpare, each in the enum, the x86-64 arm of arch() and shape(). - tests/toyos.rs: RUST_SKIP takes both virtio_sound_counts and usbd_spare; run_machine_test takes this branch's virtio_sound_counts arm beside main's machine_shutdown_wire_* , usbd_drives_the_spare and usb_keyboard_rollover. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge log at |
|
Merge of Each text conflictBoth are two independent additions at one site; every hunk of both sides is kept whole and nothing else in either file moved.
Auto-merged files that both sides touched were read at the merged head: usbd and
|
soundserver drives the virtio-sound function itself, as a PCI claim (
pci:1af4:1059), throughtoyos-virtio. The kernel'sdrivers/virtio_sound.rs, its IDT vector 0x23, thevirtio-sounddevice class (wire number 6), the class's arms ofSYS_DEVICE_REG_READ/WRITEand of the read and poll paths,toyos-abi::virtio_soundand the SDK'sVirtioSoundDevare all deleted. A claim's interrupt record now says when its messages landed, so a driver in a process is clocked by device time. HDA's path computes what it computed before.Head
ec1972ce2, which mergesorigin/mainat38df0b56d(#827's usbd, #812, #820, #805) intod49182ce2;d49182ce2is one commit on643bc63f6, which mergesorigin/mainat2c8a647eb. The merge's two conflicts,tests/common/qemu.rsandtests/toyos.rs, were each two additions at one site, both kept whole (issuecomment-6096680186). Net lines (git diff --shortstat origin/main...ec1972ce2, the same as atd49182ce2): 76 files, +2776 −1987. Of these,643bc63f6carried production +1476 −1866 (net −390); tests, loom model and stubs +1166 −58; issues and lockfile +108 −61.d49182ce2adds +29 −5 acrosssrc/clippy.rsand two issues.What changed, per decision
sound, soirq:lines lose a field on both sides), the class and its syscall arms are gone. Also gone is the kernel virtio transport's code that only this driver used: the split used-ring consumer,write_chain,from_separate,bind_msix,NoVectoranddevice_config. On AArch64Intid::VirtioSoundgoes.toyos_abi::pci::DeviceIrqRecordgrows from{count}(4 bytes) to{count, _pad, first_nanos, last_nanos}(24 bytes).first_nanosis when the first message the read counts landed.last_nanosis never older than the newest message it counts, and newer only by one landing as the read is made, which the next read counts.kernel/src/pcidev/record.rs: the count shares oneAtomicU64with the number of reads that took one. So which read a message falls to, and whether it is that read's first, is one compare-exchange (Releaseon the ISR's,Acquireon the reader's).clock::nanos_since_boot(), as HDA's ISR already reads it.isa_linesand the hand-layout issue's row follow the new size.Backend::completionanswers oneCompletion { mask, first_nanos, last_nanos }or none. Both backends already answered at most one; the 16-slot array had no second user once virtio stopped having a kernel ring.first_nanos. The kernel-driven device split it at the oldest record's ISR time.last_nanoswith the period count. That isdll.rs's own contract for a folded batch, whicha_batch_is_measured_against_its_last_grid_pointholds: reading the time as the first scores an (n−1)-period error.toyos_virtio_sound::Sound::played(taken)takes the record and answers the mask beside it, so take-then-read is the type's order and no completion exists without a device time. The device writes a used element before the notification §2.7.7 owes for it. A period on the ring with no record therefore has a notification still to land, which makes the claim readable, and soundserver wakes for it then. Round 2'sNone => nowarm, which stamped such a period with the read time, is deleted.irq_at = rec.first_nanos.max(t_est)anddll.update(rec.last_nanos, n)compute whatrecords[0].timestamp_nanosandrec.timestamp_nanoscomputed.({n_records} records)is 0 or 1 as it was.AudioCompletionRecordare not touched.userland/toyos-pci-claim, the one home of what netstack and soundserver both copied. It is a crate because two programs share it and U2/U3 will be the third and fourth. The SDK cannot take it:toyos-device-memoryandtoyos-virtioare unpublished, and the SDK is published.BarandGrantastoyos-device-memory's boundary overWindow, withBar::mapandGrant::allocas the oneunsafeWindow::neweach. It also holdsKernelRefused.Grant::leakedexists only under thehost-grantfeature, which only netstack's[dev-dependencies]turn on. The leak and itsunsafeare inside the crate, so netstack's test holds none.virtio::negotiatedoes the rest of the shared prefix: the claim's description, the capability walk, the BAR lookup,Offer::acknowledgeandaccept. It returnsFeatures, whoseDisplayis theVirtIO: PCI … access_platform=line each driver says under its own name.device.rsis deleted. ItsLatchmoves intoi219.rs, its one user, andi219.rsmaps and allocates through the crate too. soundserver's copies ofBar,GrantandClaimConfigare deleted.toyos,toyos-abi,toyos-device-memoryandtoyos-virtio.host-grantis linted.src/clippy.rshas a shape for it, astoyos-xhcihas forflaws:cargo clippy -p toyos-pci-claim --all-targets --features host-grant --no-deps --target-dir target/clippy-pci-claim -- $ADOPTED -D warnings. Without it nothing linted the crate:$GUESTSexcludes it from both workspace shapes, andNESTEDcovers only crates nested under a program.--no-depsexits 101. clippy then also lints the crate's path dependencytoyos, a guest crate that no shape lints and that has 11 findings. Lintingtoyosisissues/userland-programs-are-never-linted.md's, outside this fence.--no-depsmakes plain rustc check the host crates this crate shares with the workspace shapes (toyos-abi,toyos-device-memory,toyos-virtio,toyos-untrusted). The shape therefore gets its own target directory, astoyos-abi's does. That stops those units being re-checked every run, once by clippy and once by rustc. The directory is 22M.Grant::leaked, thehost-grantarm, and the shape's command reds on it (below).toyos-virtiogets three shared additions. The coordinator widened the fence to cover moving the walk.pci::vendor_capswalks the capability list through aConfigSpacetrait the caller implements over its claim.issues/the-virtio-capability-walk-reads-a-refused-configuration-read-as-zeros.mdis deleted.NO_VECTOR(§4.1.5.1.2).Setup::device_read32, because §4.1.3.1 has a 32-bit field read 32 bits wide. With it,acknowledgerefuses a device-specific structure that is not 4-byte aligned (§4.1.4.6.1).toyos-virtio-soundis a new pure crate beside the mixer: §5.14's messages asle32words, and the three queues in one grant.submitis deleted. The device writes the status before it reportslen, and §2.7.4 has the driver believelen.virtio.rsis what is left after the claim crate: the sound device's vectors, the completion times, and what becomes of a refusal.NO_VECTOR, so the claim reads ready exactly when a period has played. This matches the old kernel driver, which bound only TX.config_space_is_boundedis deleted, andiommu_virtio_platformno longer reads its line.vendor_capsfollowsu8links masked to dword alignment, so it cannot read past 0x10F whatever the claim bounds.toyos_dma::register's host tests cover past-the-end, straddling, unaligned and wrapping reads.pcidev::config_readtakes only theRegisterwitness that check answers.system.toml,tests/testcases,tests/metalcaseandtests/logstallcaseclaimpci:1af4:1059besidehda-audio.tests/netcasenow runs soundserver too, so every virtio function on that machine is either a process's claim or the console.issues/every-driver-is-still-in-the-kernel.mdstage 1 names the decline control's dependence on the kernel-driven virtio-gpu. Its exit: in the diff that moves virtio-gpu out, the decline moves totoyos-virtio'sOffer::acceptfor a function a process drives, andProfile::HeadlessVirtioGpugoes.issues/whether-a-region-may-be-lent-is-a-runtime-option.mdno longer cites virtio-sound's pool as present.issues/soundservers-virtio-clock-can-take-a-period-one-notification-early.md(new, defect): a record in hand while a newer period's notification is still in flight feeds the DLL that period at the older notification's time. Its owner is stage 1 ofissues/every-driver-is-still-in-the-kernel.md. When HDA leaves the kernel for apciclaim, soundserver's DLL is fed from a claim's record on every machine, so that stage now names this exit. The exit: the interleaving test asserts that no period comes back stamped earlier than its own notification.issues/diskservers-nvme-bring-up-open-codes-what-toyos-pci-claim-holds.md(new, defect):Controller::openopen-codesBar::map,Grant::allocandKernelRefused, outside this branch's fence.toyos-abi/src/audio.rsloses its false sentence that the virtio-sound driver builds anAudioCompletionRecordstamped at read time.Gates
At the merged head
ec1972ce2; each log opens with itsHEAD=line and ends withEXIT=, scrubbed and posted as the 13 comments from issuecomment-6096675137 to issuecomment-6096677474.cargo run -- --ci host=== clippy: cargo clippy -p toyos-pci-claim --all-targets --features host-grant --no-deps --target-dir target/clippy-pci-claim -- $ADOPTED -D warnings;[ci] Host: 79 step(s), all green. EveryFAILEDin the log is under an=== [ci] controlheading that reaches its verdict. It runstoyos-virtio-sound's host tests:tests::no_period_is_stranded_between_its_used_element_and_its_notification ... okcargo run -- --build-onlyBuild finished./Boot image: …/target/bootable.imgcargo run -- --build-only --arch aarch64Build finished./Boot image: …/target/bootable.aarch64.imgcargo test, the whole guest suitetest result: ok. 52 passed, 52 total (179.1s; workers: 1200s building, 841s testing);checks39 passed.uptimebefore: load averages 71.61 64.45 47.36; after: 74.88 67.40 52.22iommu_virtio_platform, inside that suite run[iommu] headless: 3 virtio function(s) negotiated, behind a unit = true; the audio function 00:04.0 among them;[iommu] headless-no-iommu: 1 virtio function(s) negotiated, behind a unit = false; the NIC's and the audio function 00:04.0's claims refused for want of a unit;[iommu] declined: … VirtIO GPU: PCI 00:03.0 refused the feature set 0x100000002 …virtio_sound_counts, inside that suite run[sound] virtio_sound_counts: 67 period(s) submitted for 64 filled, every one completed before the stream stoppedusbd_drives_the_spare, inside that suite runtoyos-pci-claimEarlier measurements, each at the head it names and not run again at
ec1972ce2:643bc63f6with the shaped49182ce2commits (r4/mut/m10.log)error: redundant cloneatuserland/toyos-pci-claim/src/lib.rs:98;RESTORED=0,STATUS=[]boot:testcasesatddb9068a1, run by the orchestrator[metal] 249 passed, 0 failed, 2 boot(s), withPASS hda_tone,PASS audio_idle_suspend,PASS hda_client_stall,PASS shipped_client_departuresandsupervisor: soundserver: no pci:1af4:1059 on this machine. Neither round 3 nor round 4 changes anything the HDA path runs, so it is not staged againtoyos-pci-claim:internet_downloadat9a7b7fe91(measurement-only:d49182ce2merged with the download row83ef5a9ae; no file on the I219 path differs fromd49182ce2), run by the orchestrator, sha256f71163b6…[metal] 1 passed, 0 failed, 1 boot(s):I219: PCI 00:1f.6 registers in BAR 0,link up at 1000 Mb/s full duplex, a DHCP lease, and the whole 170 MB download with its sha256 (issuecomment-6096213351)#818 was closed, not landed, so the I219 boot above ran on a measurement-only branch.
The checks this high-risk change names (a DMA device driver behind the IOMMU; a concurrency primitive; the ABI)
kernel/loom/tests/device_irq.rshas three messages landing at 1, 2 and 3 against a reader that takes once, anywhere among them, then takes what is left.a_reads_times_are_its_own_messagesasserts that each read'sfirst_nanosis its own first message's, and thatlast_nanosis at least its newest.every_message_is_counted_onceand thedevice-irq-lossycontrol stand as before.Relaxed: red.no_period_is_stranded_between_its_used_element_and_its_notification(toyos-virtio-sound's host tests) runs two periods, each a used element and then its notification, against two driver wakes, each a take and then a read, in all 70 interleavings. It then wakes the driver while the claim reads ready, which is all a waiting soundserver does, and asserts that each period comes back exactly once.643bc63f6, built (exit 0), run, and restored, withgit statusempty afterwards. Test exit 101:order 0b00011101: the periods that came back are []. The patch is in this round's PR comment.virtio_sound_countsis the guest arm: its suspend assertion reds when a submitted period never comes back (m8, below).NO_VECTORmutation (m8) turnsvirtio_sound_countsred: build exit 0, test exit 1,soundserver's stream still reads \running` with 0 client(s) 30s after its only client closed`.-D warnings(MSIX_ENTRYunused). The run usedMSIX_ENTRY | NO_VECTOR, the same 0xFFFF.channels/format/rate/paddingat 20–23) and PREPARE.hw/audio/virtio-snd.c:4 + payloadfor control, andsizeof(virtio_snd_pcm_status)= 8 for TX.virtio_sound_counts.a_malformed_control_answer_is_refused_by_name,a_period_given_back_wrongly_is_refused_by_nameandan_event_is_handed_up_and_its_buffer_posted_again. They cover a short response, an undefined status, alenpast the buffer, a well-formed no (Rejected(PCM_SET_PARAMS, NOT_SUPP)), a short, failed or undefined period status, a short event, and a TX head with no chain in flight. Round 1's mutations m1–m4 (short answer, short status, an unmasked link, a refused read as zero) are in that round's comment.iommu_virtio_platformcovers both arms (above). With no unit, the kernel refuses the sound claim (NOT HANDED OVER — its interrupts would not be remapped) and soundserver takes the null sink.declining_is_not_freerelied on the kernel's virtio-sound as the device thevirtio-no-access-platformactuator declines.Profile::HeadlessVirtioGpuadds avirtio-gpu-pcibehind the unit for that one boot, and QEMU refuses it (above). The issue records what the control needs when virtio-gpu leaves.Why the new guest test needs QEMU
virtio_sound_countsasserts order and counts only, never time. It reads soundserver'sinspectbefore and after one stream:virtio-sound;periods.submittedcovers at least the periods the client filled;suspendedwith no client.The suspend implies every submitted period came back, because soundserver suspends only at
unplayed == 0, and with no client only an interrupt brings one back. Its lines must appear once each, in order: connected, resumed,stream 0 started, removed,stream 0 stopped, suspended.No cheaper tier reaches it. A type cannot, and the host tests drive
toyos-virtio-soundagainst a model, not a device. virtio-sound exists only on a QEMU machine; the T14's sound is HDA. Its audio device isnone, so it plays nothing.What I am unsure of
issues/soundservers-virtio-clock-can-take-a-period-one-notification-early.md. A record in hand can come with a newer period on the ring whose notification has not landed. That period is then stamped with the record'slast_nanos, which is earlier. How often this happens is unmeasured.record.rs's header). soundserver reads its claim from one thread.virtuntil the gate stages (G2–G4) land. The kernel's old virtio-sound already refused on ARM (arch::msi_message).mainbrings up netstack's I219 path throughtoyos-pci-claim. It ran once, on the measurement-only boot in Gates. But every manifest's netstack row claims only virtio or the 82574, and the metal profile has no outbound or download row, so no routine T14 run reaches it.issues/the-intel-nics-room-and-wake-are-unread-on-hardware.mdrecords this.🤖 Generated with Claude Code
https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C