Skip to content

The SMMUv3 comes up from the IORT with every stream aborting, and both IOMMU backends read one fault policy, which halts only for a function this kernel drives, and one address window - #825

Merged
Japabu merged 7 commits into
mainfrom
wt/toyos-arm-g2
Oct 10, 2026

Conversation

@Japabu

@Japabu Japabu commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Stage G2 of the AArch64 desktop plan: the SMMUv3 the IORT names is armed with every stream aborting, a domain can be created, mapped and attached through stage 1 context descriptors for G4's claims, and the unit's event-queue records reach pcidev::note_fault, or halt the machine, through its wired SPI. Builds on G1's toyos-acpi IORT decoder and toyos-smmu encodings (#798). What both IOMMU backends decide alike, the fault policy and a domain's address window, is declared once above kernel/src/arch/ and read by VT-d and the SMMUv3 both. One policy change reaches x86-64 too: a DMA fault record that names no enumerated function no longer halts the machine on either backend.

Head measured: 3fc00867c, on origin/main at a1eb2c0b9 (#805), which 93c4107c8 merged.

What changed, per decision

One home for what both backends decide alike (kernel/src/iommu/):

  • fault.rs holds the policy VT-d's handler applied: the enumerated functions published once before any unit is armed, BME cleared first, the per-function and per-unit counts, the first faulting function, and the iommu: DMA FAULT line. vtd/fault.rs keeps its fault recording registers and reason names; smmu/fault.rs keeps its event queue. A record names a Who: a requester id, or an SMMU StreamID no enumerated function is routed from.
  • Who a fault goes to, by what the record names. There are three answers, and the line's owner= says which:
    • An enumerated function only this kernel drives: owner=kernel, and the machine halts (conclude). Its fault is a defect of this kernel.
    • An enumerated function a process drives: owner=slot<N>, pcidev is told, and the machine goes on.
    • No enumerated function: owner=none, and the machine goes on. This is a requester this kernel never took on, whose write the unit has already refused. On main, VT-d halted here, and round 2 extended that to the SMMUv3. A hot-plugged function, a VF a claimed PF enabled, or any device writing under an unrouted StreamID could then halt the machine at will. "Fail fast" answers a defect in this kernel; a device's input that the unit already refused is not one.
    • An owner=none line is written only when its stray's count is a power of two. Nothing can stop such a requester, so a device writing without end under an unrouted stream would otherwise write one line per record and evict every other record from the log ring before logkeeper reads it. Each stray is counted apart, the first eight by Who::key in a lock-free table and every later one in a shared ninth count. The count is the line's streamfaults=, so each written line says how many were read since the last, and unitfaults= still counts every record. That is at most 32 lines per count for the boot. A function's records (owner=kernel, owner=slot<N>) are all written, as before.
    • tests/common/serial.rs reads only owner=kernel as a death. owner=none, like owner=slot, is in NEVER_CLEAN: a boot that did not stage one reds on it. tests/checks/serial.rs holds both directions.
  • Nothing can clear BME on a requester nobody enumerated, so each backend bounds a handler's work per interrupt by itself. VT-d already reads at most CAP.NFR records per interrupt. The SMMUv3 now reads at most its queue's entries (next section).
  • window.rs is a domain's addresses: the floor a quarter up what the unit translates and above memory, the ceiling under the first root-bridge window or reserved region over it, reserve, handed_out, and both backends' compile-time checks, the T14's windows and virt's among them. VT-d keeps translatable_bits (SAGAW against MGAW); the SMMUv3 passes its 48-bit input.
  • FIRST's address, reason and unit were written and never read, so they are gone, and pci::NO_FUNCTION, their only sentinel, goes with them. issues/each-iommu-backend-keeps-its-own-domain-address-window.md is closed: its exit rg -n 'fn handed_out|fn ceiling' kernel/src/arch prints nothing.

The SMMUv3 (kernel/src/arch/aarch64/smmu/, re-exported as iommu_unit the way x86-64 re-exports vtd):

  • Every SMMUv3 the IORT names gets GBPA.ABORT before any refusal. That covers a machine with more than one unit, which is then refused and every unit left aborting, since GBPA's reset value is IMPLEMENTATION DEFINED. The Update handshake runs, the value is read back and asserted, and a unit handed over enabled is turned off first.
  • No interrupt of the unit's can be a write. IRQ_CTRL is cleared and acked. Then GERROR_IRQ_CFG0, EVENTQ_IRQ_CFG0 and, where IDR0.PRI is set, PRIQ_IRQ_CFG0 are zeroed, as Linux's arm_smmu_setup_msis does. A non-zero ADDR makes the interrupt an MSI write that no STE governs. Each register resets UNKNOWN and can be written only while its interrupt is off (IHI 0070 H.a §3.18.2, §6.3.21, §6.3.30, §6.3.34).
  • Every stream on no domain aborts. No domain maps by identity and nothing bypasses.
    • An enumerated function's stream gets Ste::ABORT and records nothing. Firmware may leave a function mastering the bus until its driver resets it.
    • Every stream no enumerated function is routed from gets one answer, inside the table or past it. It is aborted and recorded (owner=none): C_BAD_STE on an entry left invalid, or C_BAD_STREAMID under CR2.RECINVSID.
    • QEMU 11.1.1's hw/arm/smmuv3.c stores CR2 and never reads RECINVSID. Measured in round 1: with RECINVSID clear, an out-of-range StreamID was still recorded as C_BAD_STREAMID. Recording both is what QEMU can hold. Since neither halts, it costs a log line.
  • Bring-up order is CR1/CR2, then the stream table and command queue, then CMDQEN, then CMD_CFGI_ALL + CMD_TLBI_NSNH_ALL + CMD_SYNC, waited on. Then come the event queue, EVENTQEN, IRQ_CTRL.EVENTQ_IRQEN and SMMUEN, each waited on its *ACK. Every wait is bounded by a one-second Tripwire and panics by name, and it panics on GERROR.CMDQ_ERR with CMDQ_CONS.ERR decoded.
  • Domains each have one context descriptor under an ASID of their own, and 2 MiB blocks from toyos_smmu::table::plan. The addresses come from window.rs.
    • unmap issues CMD_TLBI_NH_ASID + CMD_SYNC before it returns, and a test fails without it (nc6).
    • attach writes the STE's first doubleword last, then issues CMD_CFGI_STE + CMD_SYNC.
  • One interrupt reads at most the queue's entries (Events::entries, 128 here), and a drain that stops short of empty pends the SPI again through GICD_ISPENDR. The unit raises its interrupt only as the queue goes from empty to non-empty (§3.18.2: "Event queue transitions from empty to non-empty"), so a record left behind raises nothing. The re-pend is taken once end deactivates the SPI (IHI 0069D, under High-risk checks), so the CPU leaves the handler between batches, and a device that never stops writing cannot hold it. Round 2 drained until empty with no bound, which a stream with no BME to clear could make endless. An overflow is reported where it is seen, including mid-drain.
  • The SPI is edge-triggered. §3.18.2 says "The conditions that cause an interrupt to be triggered are all transient events and interrupt outputs are effectively edge-triggered", and §12.4 says "Interrupts in SMMUv3 are required to be edge-triggered or MSIs". Both are cited at irqchip::route_iommu_events. DEN 0049 gives the GSIV no trigger, and Linux's iort.c registers it edge-triggered.
  • SPI routing is kept to the one interrupt, because G3 (the ITS) edits irqchip.rs and trap.rs next. irqchip.rs gains route_iommu_events and pend_iommu_events; trap.rs's irq() gains one arm, under the preempt count.

toyos-smmu: GERROR_IRQ_CFG0, EVENTQ_IRQ_CFG0, PRIQ_IRQ_CFG0 and IDR0_PRI are declared, and each has a host test at its §6.2 offset or bit. A decoded Event carries its number, which feeds the line's reason=. Code::name() gives the §7.3 mnemonic. Round 2's per-mnemonic test is deleted: it was a second copy of name's match, and the two names a gate reads (F_TRANSLATION, C_BAD_STE) are held by virt_smmu. Events::entries is the drain's bound.

Harness: Profile::VirtSmmu adds a Shape::smmu dimension, Absent or WithTestdev. WithTestdev puts iommu=smmuv3 on the machine and two of QEMU's iommu-testdev on bus 0. A q35 that declares it is refused by name.

  • virt_smmu reads on to panic_reboot::arm's line. halt_all_cpus writes that line once every other CPU is stopped, so nothing the guest can still say is missed. The test reds on any smmu-selftest: FAIL line and on any death other than the owner=kernel record. Round 2 returned at the record and never read the selftest's "the machine went on" panic.

smmu-selftest, in order:

  1. A testdev's write on the entry its stream starts with is refused, with nothing recorded.
  2. On a domain of its own, its write lands where the domain maps it.
  3. The unrouted testdev writes three times with interrupts masked. One drain reads all three records; the first two are written (owner=none, streamfaults=1 and =2) and the third is counted and not, and the selftest says the machine went on.
  4. The first testdev writes again at the address its domain took back. That is refused, recorded as owner=kernel F_TRANSLATION with unitfaults=4, which is how the test sees the third stray record read and not written, and the machine halts.

The x86 side

VT-d's fault handler and domain window read the shared modules. Its behaviour changes in one case: a record whose source-id is no enumerated function was owner=kernel … bme=unknown-function domain=unknown and halted. It is now owner=none, and the machine goes on; its line is written only at a power of two of that source-id's count, which is its streamfaults= (was 0). Everything else is meant to be identical, and a reader can check it:

  • The DMA FAULT line's format string is unchanged; only that one case's Owner word, its streamfaults= and whether it is written differ.
  • The order is unchanged: the record's address is read, then BME is cleared, then the function and unit are counted, FIRST latched, pcidev told, the line logged and the record cleared. conclude halts before apic::eoi, as before.
  • Window::new refuses exactly where Domain::new did (WindowBelowMemory, NoRoom when below max(round(room), 2 MiB)), then reserves room, as create did. The one difference is where bytes.next_multiple_of(PAGE_2M) would overflow: before, that panicked in debug and wrapped in release; now reserve and handed_out refuse it.
  • rebind takes the domain's root, id and width instead of the Domain, so its compile-time check no longer builds a Domain.

What a run shows: the x86-64 image builds; the guest suite's x86 boots, every one of which creates domains through window.rs for its kernel drivers, are green. No guest test on this host reaches VT-d's fault handler. The orchestrator ran the T14's boot:testcases at 93c4107c8, round 3's head (comment 6096300030): both images' sha256 matched the staged ones (f8a91ae7…, 852c54d4…), each boot rc=0, and the judge returned EXIT=0, "249 passed, 0 failed, 2 boot(s)". That reads the moved VT-d policy and window on real hardware. This round's change is in the shared report, which the T14's VT-d handler also runs, so it is staged again at 3fc00867c with readback only (testcases sha256 16e8c2ec…9e1c8c2b, testcases-watchdog sha256 e6a7b1f4…2af7a971). That run is owed and not yet read. No row there stages a fault from an unenumerated source-id, so the new bound is reached on the SMMUv3 alone.

Gates (head 3fc00867c; logs under the orchestrator's arm-g2/r3/round4/logs/, each opening with its head)

Gate Exit
cargo run -- --ci host 0, "Host: 78 step(s), all green"
cargo run -- --build-only (x86-64) 0
cargo run -- --build-only --arch aarch64 0
cargo test --test toyos-build -- virt_smmu 0, "1 passed, 1 total"
cargo test --test toyos-build, the whole suite, virt_smmu in it 0, "51 passed, 51 total"
cargo test --test toyos-build -- --metal --metal-readback <dir> boot:testcases 2, staged and not run: "The machine was not touched, so this run establishes nothing about it"

cargo test -p toyos-smmu (exit 0 at 93c4107c8) was not re-run: this round does not touch toyos-smmu, and --ci host runs it. The whole suite ran under load: uptime read 11.67 17.00 28.21 before and 16.05 17.38 27.71 after.

virt_smmu's echo (HVF, QEMU 11.1.1), from its own run; the full log is a comment:

[ 0.413 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
GBPA 0x101000: ABORT
[ 0.412 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
[ 0.414 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
[ 0.415 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
[ 0.415 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.416 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.416 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.418 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0xdead0002: refused
[ 0.417 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
[ 0.417 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
[ 0.418 cpu0 kernel] iommu: DMA FAULT owner=kernel unit0 stream=00:04.0 addr=0x0000400000000040 access=write reason=0x10 domain=1 bme=cleared unitfaults=4 streamfaults=1 first=n F_TRANSLATION

(The echo prints the selftest's verdicts before the records, and not the "goes on" line. The test asserts the console's own order: the second owner=none record, then "the unrouted function's three events were read, and the machine goes on", then the owner=kernel record, then the stop's line. It also asserts exactly three records were written, so the third stray record's line is absent; unitfaults=4 shows it was read.)

bme=cleared says the handler found the function and wrote its COMMAND register. It is not read back. iommu-testdev writes whatever its COMMAND holds, so nothing on this architecture measures the storm ceiling that clearing BME is.

cargo run --arch aarch64, booted (round 2, at 9490bcfdf)

src/qemu.rs passes iommu=smmuv3 to cargo run --arch aarch64, so the unit is armed on that machine. Both boots ran src/qemu.rs's argv for --arch aarch64 (Profile::Virtio, --smp 8, HVF), changed only where it reaches the host. Both logs are posted in full as comments. Neither was re-run at this head. What this head changes on that machine is the drain's bound, the owner=none word and that line's bound, and neither boot had a DMA FAULT.

  • At origin/main (5a3b74345): IOMMU: the SMMUv3 is the port's stage 6; no device is translated this boot. The boot ends where compositor panics at session.rs:151, then 20 s of silence.
  • At 9490bcfdf: the unit is armed with 8 functions' streams. virtio-console, virtio-sound and virtio-gpu move to domains 1, 2 and 3. No DMA FAULT. The boot ends at the same compositor panic.

High-risk checks (device memory isolation)

Independent oracles.

  • QEMU 11.1.1's SMMUv3 model is a second implementation of IHI 0070, and it is asked through iommu-testdev, which makes a DMA write at a device address and reads the word back at a physical one.

    • 0xdead0002 means the unit refused the write.
    • 0x0 means it landed exactly where the domain maps it, which only an STE, CD and stage 1 walk that QEMU accepted can produce.
    • The model's own source was read where it departs from the spec (RECINVSID).
  • IHI 0070 H.a was read for the trigger (§3.18.2, §12.4), the *_IRQ_CFG0 registers (§6.3.21, §6.3.30, §6.3.34), RECINVSID (§6.3.12) and Service Failure Mode (§12.3).

  • IHI 0069D (GICv3/v4, issue D) was read for the re-pend. The PDF is Arm's documentation-service.arm.com/static/6012f2e54ccc190e5e681256, sha256 84aa6255…929957f4c. Three passages carry it:

    • §8.9.16, GICD_ISPENDR<n>: writing 1 "changes the state of the corresponding interrupt from inactive to pending, or from active to active and pending". pend_iommu_events writes it from inside the handler, while the SPI is active.
    • §4.1.2, the interrupt handling state machine: "Interrupts that are active and pending are never signaled to a connected PE". So the re-pend cannot re-enter the handler before end.
    • §4.1.1, Deactivation: deactivation is what changes an interrupt "from active and pending to pending". With ICC_CTLR_EL1.EOImode 0 the priority drop and deactivation happen together on the ICC_EOIR1_EL1 write, and irqchip.rs writes ICC_CTLR_EL1 as zero, so end is the deactivation. The SPI is then pending, routed to this CPU and enabled, and is signalled again.
    • Two of the register's "no effect" cases can apply here: the interrupt is already pending from an earlier GICD_ISPENDR write, or from the unit's own edge. Either way it is pending, which is all the re-pend needs.

    pend_iommu_events cites the three sections. nc11 measures the same thing on HVF's vGIC.

  • Linux's arm_smmu_setup_msis is the reference for the zeroing.

  • Every encoding is held on the host to H.a's field positions (toyos-smmu/tests/encodings.rs).

Negative controls. Each was applied as a checked patch, built, run through virt_smmu, and restored in the same script. nc12, nc8, nc10 and nc11 ran at 3fc00867c; their patches and logs are in this comment and this one. nc8, nc10 and nc11 were re-run because the selftest's stray now writes three times. The rest ran at 93c4107c8, and their patches are in an earlier comment.

Control Exit Red by
nc12: every stray record written (the bound's predicate made false && …) 1 virt_smmu: 4 events reached the handler, not 3
nc9: conclude never halts (the review's mutation) 1 smmu-selftest: FAIL: the handler read the event of a function this kernel drives and the machine went on
nc10: report halts on every record without a user owner (round 2's predicate) 1 the selftest never said "which its domain no longer maps": halted after the first drain's owner=none records
nc8: one record per interrupt, no re-pend 1 the handler had read 1 events, not 3, 1000ms … after the unrouted function's three refused writes
nc11: one record per interrupt, re-pend kept 0 green by design: the later records are read on the re-pended SPI
nc1: GBPA written without ABORT, the kernel's assert removed 1 GBPA does not read back aborting: Some(4096)
nc2: Ste::ABORT made Config 0b100 (bypass) 1 … on the entry its stream starts with, answered 0x0: FAIL
nc3: IRQ_CTRL.EVENTQ_IRQEN never written 1 the handler had read 0 events, not 2 …
nc5: the SPI's GICD_ISENABLER bit never written 1 the handler had read 0 events, not 2 …
nc6: unmap issues no CMD_TLBI_NH_ASID 1 the handler had read 2 events, not 3 … after the kernel-driven function's refused write
nc7: every entry Ste::ABORT 1 the handler had read 0 events, not 2 …
nc4: the whole kernel and toyos-smmu change reverted onto a1eb2c0b9, the test kept 1 "smmu-selftest" is a kernel_params and the kernel declares no such actuator

What no test here reaches.

  • Every SMMUv3 aborting before a multi-unit refusal: virt has one unit.
  • The *_IRQ_CFG0 zeroing: QEMU 11.1.1 sends no MSI from these registers; smmuv3_trigger_irq only pulses the wired line.
  • RECINVSID: QEMU records an out-of-range StreamID whatever CR2 says. Its bit is held on the host.
  • The drain's bound at a full queue: iommu-testdev writes once per trigger, so no guest fills 128 records in one interrupt. nc8/nc11 show the re-pend path at a bound of one.
  • VT-d's owner=none path: no guest on this host reaches VT-d's fault handler. The SMMUv3 reaches the same report.
  • The stray table past eight keys, or a count at 2^32: the selftest has one stray. The shared ninth count and the u32 wrap are read, not run.

Each of these is a reading of the diff against the spec.

Why the guest test needs QEMU

  • No type and no host test can make a device's DMA go through a unit, or take the unit's SPI through a GIC.
  • The T14 is x86-64 with VT-d and has no SMMUv3, so no metal row reaches this.
  • QEMU's virt with iommu-testdev is the cheapest tier where a DMA meets the unit.
  • It asserts content, order and counts only, never time.
  • The halt is the real kernel-owned policy, reached end to end, and the run goes on past the unrouted records.
  • A second iommu-testdev is the only function a guest can make write under a StreamID no function is routed from. The actuator leaves it unrouted, so its entry is the one a never-enumerated function would have.

Filed

  • issues/the-smmuv3s-global-errors-are-read-and-never-delivered.md: GERROR is read in waits and after drains, its SPI is not routed, and SFM_ERR and EVENTQ_ABT_ERR raised between reads go unseen. Owner: stage 6's ITS work.
  • issues/a-late-write-from-a-released-function-halts-the-machine.md: tear_down clears the ownership before the reset quiesces in-flight DMA, so a late faulting write is owner=kernel and halts. This holds on VT-d today. Owner: stage 6's claim through an SMMUv3 domain, which lands before G4.
  • issues/a-function-the-smmuv3-does-not-route-panics-at-attach.md: create takes no function, so a function the IORT routes elsewhere, or not at all, panics in Live::stream at attach instead of being refused at create. Not reachable on virt. Owner: stage 6's claim.
  • issues/the-smmuv3-and-its-crates-declare-what-the-aarch64-kernel-also-declares.md: the descriptor is re-owned to stage 4's owed break-before-make work, and GICD_TYPER's two decoders are added with an exit.

What I am unsure of

  • No Arm hardware. Nothing here has run on Arm hardware. HVF's vGIC and QEMU's model are the only instruments, and QEMU departs from the spec on RECINVSID.
  • Strays past the eighth share one count, so the ninth and later are written under whichever key hit a power of two, and a quiet stray among them can go unnamed. Eight is a guess with no measurement behind it: no machine here has more than one stray.
  • Stale prose in kernel/src/iommu/mod.rs. Its init doc still names a context entry per function.

Net lines

git diff --shortstat origin/main...3fc00867c: 30 files, +1898 / −566.

  • Kernel production (all of kernel/ but the selftest and the actuator): +1364 / −545.
  • Tests (tests/, toyos-smmu/tests, the selftest, the actuator): +381 / −10.
  • toyos-smmu/src, Cargo.lock, kernel/Cargo.toml: +51 / −4.
  • Issues: +104 / −7.

This round's own commit, 93c4107c8..3fc00867c: 5 files, +61 / −24.

🤖 Generated with Claude Code

https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C

… events reach the handler on their wired SPI

The AArch64 IOMMU stub becomes arch/aarch64/smmu/, programmed with
toyos-smmu's encodings (G1, #798):

- init finds the one SMMUv3 the IORT names, sets GBPA to abort before
  anything else is written (and reads it back), turns off a unit left
  enabled, probes IDR0/1/5, gives every enumerated function the IORT routes
  through the unit an aborting stream table entry, brings up the command
  queue (CMD_CFGI_ALL, CMD_TLBI_NSNH_ALL, then a CMD_SYNC it waits on), the
  event queue and its wired interrupt, and sets SMMUEN. Any refusal leaves
  the unit aborting and says why.
- domain: create/map/map_at/place/unmap/attach behind the generic seam, one
  stage 1 context descriptor per domain under its own ASID, 2 MiB leaves,
  addresses from 2^46 up to the first root-bridge window, unmap invalidated
  by ASID behind a CMD_SYNC, attach a CMD_CFGI_STE behind one.
- fault: the event queue drained from the SPI with no lock, each record's
  function stopped from mastering, a claim's fault handed to
  pcidev::note_fault, a kernel-owned one halting the machine after the line,
  in VT-d's line format.
- irqchip routes that one SPI, edge-triggered, to the boot CPU; trap's irq()
  takes it under the preempt count.
- toyos-smmu names each event by its mnemonic.

virt_smmu boots virt with iommu=smmuv3 and QEMU's iommu-testdev under the
smmu-selftest actuator: the device's write is refused on the entry it
starts with, lands where its own domain maps it, and where the domain maps
nothing is refused and recorded, the event reaching the handler on SPI 106
named F_TRANSLATION for that function and address.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Negative-control patches for head 562fc3a, each applied with git apply --check then git apply, run through cargo test --test toyos-build -- virt_smmu, and reversed in the same script. nc4 is the whole kernel and toyos-smmu change reverted onto the base (git diff HEAD origin/main -- kernel toyos-smmu Cargo.lock at that head, 2646 lines, not reproduced here).

nc1-gbpa-bypass (exit 1, red)

diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 8aba96fe5..5c153863c 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -260,13 +260,8 @@ pub fn init(rsdp_addr: u64, devices: &[PciDevice], windows: &[toyos_abi::boot::R
 fn abort_unprogrammed(regs: Registers, base: u64) {
     let gbpa = || regs.read(reg::GBPA);
     regs.wait("GBPA free to update", || gbpa() & reg::GBPA_UPDATE == 0);
-    regs.write(reg::GBPA, gbpa() | reg::GBPA_ABORT | reg::GBPA_UPDATE);
+    regs.write(reg::GBPA, gbpa() & !reg::GBPA_ABORT | reg::GBPA_UPDATE);
     regs.wait("GBPA updated", || gbpa() & reg::GBPA_UPDATE == 0);
-    assert!(
-        gbpa() & reg::GBPA_ABORT != 0,
-        "SMMU: GBPA reads {:#x} after ABORT was written: transactions bypass while SMMUEN is clear",
-        gbpa()
-    );
     let cr0 = regs.read(reg::CR0);
     if cr0 != 0 {
         log!("IOMMU: the SMMUv3 at {base:#x} was handed over with CR0 {cr0:#x}; it goes off first");

nc2-ste-bypass (exit 1, red)

diff --git a/toyos-smmu/src/config.rs b/toyos-smmu/src/config.rs
index 6c28c1b4c..0995a79c4 100644
--- a/toyos-smmu/src/config.rs
+++ b/toyos-smmu/src/config.rs
@@ -26,7 +26,7 @@ impl Ste {
     /// `V` set and `Config` `0b000`: every transaction of the stream is
     /// aborted, and no event is recorded for it. An entry of all zeroes
     /// aborts too, and records `C_BAD_STE` each time.
-    pub const ABORT: Self = Self([STE_V, 0, 0, 0, 0, 0, 0, 0]);
+    pub const ABORT: Self = Self([STE_V | 0b100 << 1, 0, 0, 0, 0, 0, 0, 0]);
 
     /// The stream translated by stage 1 through the one context descriptor
     /// at `context`: `S1ContextPtr` [55:6], `S1CDMax` [63:59] zero so a

nc3-no-event-irq (exit 1, red)

diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 8aba96fe5..35f7ebcdb 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -366,7 +366,6 @@ fn program(
     regs.write(reg::EVENTQ_CONS, 0);
     fault::arm(regs, window(events_at, 32 << events_log2), events, devices, &live.routes);
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN, "its event queue enabled");
-    regs.control(reg::IRQ_CTRL, reg::IRQ_EVENTQ, "its event interrupt enabled");
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN | reg::CR0_SMMUEN, "SMMUEN");
 
     log!(

nc5-spi-not-enabled (exit 1, red)

diff --git a/kernel/src/arch/aarch64/irqchip.rs b/kernel/src/arch/aarch64/irqchip.rs
index 863ce2afb..299ad0600 100644
--- a/kernel/src/arch/aarch64/irqchip.rs
+++ b/kernel/src/arch/aarch64/irqchip.rs
@@ -321,7 +321,6 @@ pub(super) fn route_iommu_events(intid: u32) -> Result<(), u32> {
     gicd.write_u64(GICD_IROUTER + 8 * u64::from(intid), toyos_gicv3::unpacked_affinity(cpu::hardware_id()));
     gicd.write_u32(GICD_ICPENDR + word, bit);
     IOMMU_EVENTS.store(intid, Relaxed);
-    gicd.write_u32(GICD_ISENABLER + word, bit);
     Ok(())
 }
 

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #825 at 562fc3a9e against .claude/agents/reviewer.md. This is round 1.

Net lines (git diff --shortstat origin/main...562fc3a9e): 16 files, +1296 / −96. Production is about +1018 / −93. Tests are about +246 / −3 (tests/, toyos-smmu/tests, smmu/selftest.rs, the actuator).

I checked that the x86 diff is empty: git diff --stat origin/main...562fc3a9e -- kernel/src/arch/x86_64 kernel/src/iommu kernel/src/pcidev kernel/src/drivers src/ prints nothing. toyos-phys and toyos-smmu go under [target.'cfg(target_os = "none")'.dependencies], as toyos-gicv3 already does.

I checked the register sequence against IHI 0070 and found it correct:

  • GBPA.Update is idle, then ABORT|Update is written, Update clears, and ABORT is read back. All of this happens before any other write.
  • A unit already enabled has CR0 cleared and waited on CR0ACK before CR1/CR2 are written.
  • STRTAB/CMDQ are set, then CMDQEN, then CFGI_ALL + TLBI_NSNH_ALL + CMD_SYNC (SIG_NONE, done once CONS passes it, §4.7.3). Then EVENTQ, EVENTQEN, IRQ_CTRL and SMMUEN, each acked. This matches the order Linux uses.
  • Ste::ABORT is V=1, Config=0b000, which aborts without recording an event.
  • The command-queue publish rests on Mmio's dmb before each register write.

BLOCKER

  • kernel/src/arch/aarch64/smmu/mod.rs:227 — the kernel touches no unit when the IORT names more than one SMMUv3. — The reset value of GBPA.ABORT is IMPLEMENTATION DEFINED, and firmware commonly leaves it at bypass, so every device on every unit would reach all memory. That is an isolation hole on a refusal path. The body also says a refusal "leaves the unit aborting", which is false here. Fix: run abort_unprogrammed on each SMMUv3 the IORT names, then refuse.
  • kernel/src/arch/aarch64/smmu/mod.rs:364-369 — SMMU_EVENTQ_IRQ_CFG0 (0x0B0) is never written. toyos-smmu/src/unit.rs does not even declare it. — When IDR0.MSI=1, a non-zero ADDR makes the unit send each event interrupt as an MSI write to that address instead of the wired SPI. The field's reset value is not guaranteed zero, and the CR0 != 0 hand-over path that abort_unprogrammed handles keeps whatever address the previous owner wrote. The result is a DMA write by the unit itself to an address no STE governs, and events never reach SPI 106. Linux's arm_smmu_setup_msis zeroes these registers for this reason. Fix: write EVENTQ_IRQ_CFG0 = 0 while IRQ_CTRL is clear, before IRQ_EVENTQ.
  • kernel/src/arch/aarch64/smmu/mod.rs:312 with :343 — the same untrusted condition gets two answers, decided by its number. — A StreamID that was never enumerated but is below 2^log2 aborts silently (Ste::ABORT, Config 0b000). One at or above it is recorded as C_BAD_STREAMID (CR2.RECINVSID is set), which is owner=kernel, which halts the machine. A hot-plugged function or an enabled VF halts the machine or not depending on whether its RID is above the highest enumerated one. The body says "VT-d does the same for a requester it never enumerated", but VT-d answers every unenumerated requester alike. Pick one answer for every unrouted stream and hold it in the selftest.
  • kernel/src/arch/aarch64/smmu/domain.rs:261 — unmap's claim "no device reaches them once this returns" (the CMD_TLBI_NH_ASID + CMD_SYNC) is high-risk, and no test can fail on it. — QEMU's SMMUv3 keeps an IOTLB, so this patch passes virt_smmu today: - live.issue(&[Command::InvalidateAsid(asid)]); + live.issue(&[]);. Make the selftest's third write the address it just landed at, after unmap, instead of the never-mapped at + PAGE_2M + 0x40 (selftest.rs:92). Run that patch, show it red with the selftest's FAIL, and post the log.
  • kernel/src/arch/aarch64/smmu/fault.rs:30-50 — Function, NO_SLOT, user_owned, attached, the Owner line and the owner-or-halt decision are a second declaration of kernel/src/arch/x86_64/vtd/fault.rs's fault policy. — This is a sibling of something the tree already has, and unlike the address window it is not even recorded. It belongs once above kernel/src/arch/, read by both backends. If the fence forbids that, the fence has to widen; recording an issue does not make a sibling landable. The same applies to smmu/domain.rs:31-93 (FLOOR, Addresses, ceiling) against vtd/table.rs, even though issues/each-iommu-backend-keeps-its-own-domain-address-window.md records it.
  • Evidence — cargo run --arch aarch64 (where src/qemu.rs:329 passes iommu=smmuv3) now arms the unit and gives every kernel driver an Own domain where it used to be Untranslated. Nothing booted that machine at this head; the body says so. That is one cheap measurement left as a guess. Boot it at 562fc3a9e and at origin/main, and post both logs through the furthest point each reaches.

NOTE

  • Edge trigger (irqchip.rs:320) — not a blocker. DEN 0049's SMMUv3 node carries no trigger flags, and Linux's iort.c registers every SMMUv3 GSIV ACPI_EDGE_SENSITIVE. That is a shipping implementation independent of QEMU and the de facto platform contract. Still, read the IHI 0070 clause before G4, and state in the body what was read.
  • fault.rs:138 — the drain stops at its budget with records still queued. A unit that raises its interrupt only when the queue goes from empty to non-empty never re-raises it, which strands them under edge triggering. Linux loops until the queue is empty. Either drain until empty or record why the budget is safe.
  • GERROR is read, not routed: service-failure mode and EVENTQ_ABT between waits go unseen. The body states this compromise, but no issues/ file records it with an owner and an exit.
  • Halt on a fault no process owns: the process path cannot be reached at this head, because no AArch64 function can be claimed until G3/G4. pcidev/mod.rs:1472 clears ownership before the reset quiesces in-flight DMA, so a late write from a released device is owner=kernel and halts. That holds on VT-d today too. File it against G4 before G4 lands.
  • irqchip.rs:307 decodes GICD_TYPER.ITLinesNumber, while toyos-its/src/lpi.rs decodes the same register's other fields. That is a second home for one register, the shape issues/the-smmuv3-and-its-crates-declare-what-the-aarch64-kernel-also-declares.md records for GICR_TYPER. Add it to that issue or move it.
  • issues/each-iommu-backend-keeps-its-own-domain-address-window.md — its exit rg -n 'fn handed_out|fn ceiling' kernel/src/arch is met by a rename. The exit has to name the one declaration both backends read.
  • issues/the-smmuv3-and-its-crates-declare-what-the-aarch64-kernel-also-declares.md names "the SMMUv3 unit" stage as owner of the descriptor, and that stage is this branch, which leaves it. Re-own it to the stage that edits paging.rs in this diff, so its owner is pending work rather than work that has landed.
  • fault.rs:169 — bme=cleared is printed from function.is_some(), not from a read of COMMAND. iommu-testdev ignores BME, so nothing measures the storm ceiling on this architecture. Say so in the body.
  • The PR body says the virt_smmu gate exited 0, but guest-virt_smmu-2.log (09:30, before the 09:31 commit) carries no exit line. The whole-suite run after the commit (guest-suite.log, EXIT=0, 44/44) covers it. Cite that log instead.

SEND BACK

Japabu and others added 3 commits October 10, 2026 09:54
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…y SMMUv3 the IORT names aborts before a refusal, its interrupts write nowhere, and every unrouted stream has one answer

The review of round 1 found the SMMUv3 bring-up's fault policy and domain
window to be second declarations of VT-d's, and four holes in the unit's
programming. This answers each.

One home for what both backends decide alike, above kernel/src/arch/:

- kernel/src/iommu/fault.rs holds the policy VT-d's handler applied: the
  enumerated functions published once, BME cleared first, the per-function
  and per-unit counts, the first faulting function, owner-or-halt, and the
  `iommu: DMA FAULT` line. vtd/fault.rs keeps its recording registers and
  reason names; smmu/fault.rs keeps its event queue. The line's format is
  VT-d's, unchanged; the SMMUv3's now carries `reason=0x..` and VT-d's
  `domain=` answer too. FIRST's address, reason and unit were written and
  never read, and go; pci::NO_FUNCTION, their only sentinel, goes with them.
- kernel/src/iommu/window.rs holds a domain's addresses: the floor a quarter
  up what the unit translates and above memory, the ceiling under the first
  reserved window over it, reserve and handed_out, and both backends'
  compile-time checks. VT-d keeps translatable_bits (SAGAW against MGAW).
  issues/each-iommu-backend-keeps-its-own-domain-address-window.md is met:
  `rg -n 'fn handed_out|fn ceiling' kernel/src/arch` prints nothing.

The SMMUv3:

- Every SMMUv3 the IORT names gets GBPA.ABORT before a machine with more
  than one is refused: GBPA's reset value is IMPLEMENTATION DEFINED.
- IRQ_CTRL is cleared, acked, and GERROR_IRQ_CFG0, EVENTQ_IRQ_CFG0 and,
  where IDR0.PRI is set, PRIQ_IRQ_CFG0 are zeroed before anything else, as
  Linux's arm_smmu_setup_msis does: a non-zero ADDR makes the interrupt an
  MSI write no STE governs, each resets UNKNOWN, and each is writable only
  with its interrupt off (IHI 0070 H.a 3.18.2, 6.3.21, 6.3.30, 6.3.34).
- Every stream no enumerated function is routed from is aborted and
  recorded, inside the stream table (an entry left invalid: C_BAD_STE) or
  past it (CR2.RECINVSID: C_BAD_STREAMID), and halts the machine, as VT-d's
  unenumerated requester does. Silence for both was tried first and is not
  holdable: QEMU 11.1.1's hw/arm/smmuv3.c stores CR2 and never reads
  RECINVSID, so an out-of-range StreamID is recorded there whatever CR2
  says; measured, a C_BAD_STREAMID with RECINVSID clear.
- The event queue drains until it reads empty: the unit raises its
  interrupt only as the queue goes from empty to non-empty (3.18.2), so a
  record left behind raises nothing. An overflow is reported where it is
  seen, mid-drain included.
- The edge trigger now cites IHI 0070 H.a 3.18.2 ("interrupt outputs are
  effectively edge-triggered") and 12.4 ("required to be edge-triggered or
  MSIs").

The selftest takes a second iommu-testdev, below the first, which the
actuator leaves unrouted, and writes four times: on the entry the routed one
starts with (refused, unrecorded), on its domain (lands), there again after
`unmap` (refused, recorded), and the unrouted one inside the table (refused,
recorded). The last two are made with interrupts masked so one drain reads
both; virt_smmu reads them as the unit's first and second events. The write
after `unmap` reds without its CMD_TLBI_NH_ASID: QEMU's SMMUv3 keeps an
IOTLB.

Issues: the SMMUv3's GERROR is filed as read and never delivered, owned by
stage 6's ITS work; a late write from a released function halting the
machine is filed against stage 6's claim through an SMMUv3 domain; the
descriptor half of the SMMUv3-and-ITS issue is re-owned to stage 4's owed
break-before-make work on paging.rs, and GICD_TYPER's two decoders are
added to its distributor half.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… and atomic DATA commits (#816), into the SMMUv3 bring-up

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Negative controls for round 2, at 9490bcfdf. Each patch was checked with git apply --check, applied, run through cargo test --test toyos-build -- virt_smmu, and restored in the same script (git checkout HEAD -- ., git clean -fd kernel toyos-smmu, then git status --porcelain asserted empty). nc4 reverts the whole kernel and toyos-smmu change onto 5a3b74345, the origin/main merged into this head, with the test kept; it is 3002 lines and is not reproduced here: it is git diff 9490bcfdf 5a3b74345 -- kernel toyos-smmu Cargo.lock.

Control Exit Red by
nc1-gbpa-bypass 1 GBPA does not read back aborting: Some(4096)
nc2-ste-bypass 1 smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0x0: FAIL
nc3-no-event-irq 1 0 events reached the handler, not 2
nc5-spi-not-enabled 1 0 events reached the handler, not 2
nc6-unmap-no-tlbi 1 smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0x0: FAIL
nc7-every-entry-aborting 1 1 events reached the handler, not 2
nc8-drain-one-record 1 1 events reached the handler, not 2
nc4-whole-change-reverted 1 "smmu-selftest" is a `kernel_params` and the kernel declares no such actuator or parameter
nc1-gbpa-bypass.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..5f68e1756 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -286,13 +286,8 @@ pub fn init(rsdp_addr: u64, devices: &[PciDevice], windows: &[toyos_abi::boot::R
 fn abort_unprogrammed(regs: Registers, base: u64) {
     let gbpa = || regs.read(reg::GBPA);
     regs.wait("GBPA free to update", || gbpa() & reg::GBPA_UPDATE == 0);
-    regs.write(reg::GBPA, gbpa() | reg::GBPA_ABORT | reg::GBPA_UPDATE);
+    regs.write(reg::GBPA, (gbpa() & !reg::GBPA_ABORT) | reg::GBPA_UPDATE);
     regs.wait("GBPA updated", || gbpa() & reg::GBPA_UPDATE == 0);
-    assert!(
-        gbpa() & reg::GBPA_ABORT != 0,
-        "SMMU: GBPA reads {:#x} after ABORT was written: transactions bypass while SMMUEN is clear",
-        gbpa()
-    );
     let cr0 = regs.read(reg::CR0);
     if cr0 != 0 {
         log!("IOMMU: the SMMUv3 at {base:#x} was handed over with CR0 {cr0:#x}; it goes off first");
nc2-ste-bypass.patch
diff --git a/toyos-smmu/src/config.rs b/toyos-smmu/src/config.rs
index 6c28c1b4c..0995a79c4 100644
--- a/toyos-smmu/src/config.rs
+++ b/toyos-smmu/src/config.rs
@@ -26,7 +26,7 @@ impl Ste {
     /// `V` set and `Config` `0b000`: every transaction of the stream is
     /// aborted, and no event is recorded for it. An entry of all zeroes
     /// aborts too, and records `C_BAD_STE` each time.
-    pub const ABORT: Self = Self([STE_V, 0, 0, 0, 0, 0, 0, 0]);
+    pub const ABORT: Self = Self([STE_V | 0b100 << 1, 0, 0, 0, 0, 0, 0, 0]);
 
     /// The stream translated by stage 1 through the one context descriptor
     /// at `context`: `S1ContextPtr` [55:6], `S1CDMax` [63:59] zero so a
nc3-no-event-irq.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..005776da1 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -402,7 +402,6 @@ fn program(
     regs.write(reg::EVENTQ_CONS, 0);
     fault::arm(regs, window(events_at, 32 << events_log2), events, &live.routes);
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN, "its event queue enabled");
-    regs.control(reg::IRQ_CTRL, reg::IRQ_EVENTQ, "its event interrupt enabled");
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN | reg::CR0_SMMUEN, "SMMUEN");
 
     log!(
nc5-spi-not-enabled.patch
diff --git a/kernel/src/arch/aarch64/irqchip.rs b/kernel/src/arch/aarch64/irqchip.rs
index 04ec59f72..717a6a712 100644
--- a/kernel/src/arch/aarch64/irqchip.rs
+++ b/kernel/src/arch/aarch64/irqchip.rs
@@ -321,7 +321,6 @@ pub(super) fn route_iommu_events(intid: u32) -> Result<(), u32> {
     gicd.write_u64(GICD_IROUTER + 8 * u64::from(intid), toyos_gicv3::unpacked_affinity(cpu::hardware_id()));
     gicd.write_u32(GICD_ICPENDR + word, bit);
     IOMMU_EVENTS.store(intid, Relaxed);
-    gicd.write_u32(GICD_ISENABLER + word, bit);
     Ok(())
 }
 
nc6-unmap-no-tlbi.patch
diff --git a/kernel/src/arch/aarch64/smmu/domain.rs b/kernel/src/arch/aarch64/smmu/domain.rs
index 4b61ff63c..4afeab440 100644
--- a/kernel/src/arch/aarch64/smmu/domain.rs
+++ b/kernel/src/arch/aarch64/smmu/domain.rs
@@ -167,7 +167,7 @@ pub fn unmap(id: DomainId, at: Iova, bytes: u64) -> Result<(), IommuError> {
         }
     }
     // Whatever was cleared before a refusal is gone from the unit too.
-    live.issue(&[Command::InvalidateAsid(asid)]);
+    live.issue(&[Command::InvalidateAsid(asid)][..0]);
     result
 }
 
nc7-every-entry-aborting.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..ee74eb7e7 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -358,9 +358,9 @@ fn program(
     let streams = window(table, 64 << log2);
     // Every other entry stays zero, invalid: a stream no function is routed
     // from is recorded, as one past the table is.
-    for (_, stream) in &routes {
+    for stream in 0..1u32 << log2 {
         for (i, word) in Ste::ABORT.words().iter().enumerate() {
-            streams.write_u64(u64::from(*stream) * 64 + 8 * i as u64, *word);
+            streams.write_u64(u64::from(stream) * 64 + 8 * i as u64, *word);
         }
     }
     let (commands_log2, events_log2) =
nc8-drain-one-record.patch
diff --git a/kernel/src/arch/aarch64/smmu/fault.rs b/kernel/src/arch/aarch64/smmu/fault.rs
index 8c273b10c..ba9b9f661 100644
--- a/kernel/src/arch/aarch64/smmu/fault.rs
+++ b/kernel/src/arch/aarch64/smmu/fault.rs
@@ -84,7 +84,7 @@ pub fn service() {
         }
         cons = events.after(cons, prod);
         regs.write(reg::EVENTQ_CONS, cons);
-        prod = regs.read(reg::EVENTQ_PROD);
+        prod = cons;
     }
     let errors = reg::active_errors(regs.read(reg::GERROR), regs.read(reg::GERRORN));
     if errors & reg::GERROR_EVENTQ_ABORT != 0 {

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

cargo run --arch aarch64's machine booted at this head, 9490bcfdf46af50ace42b4147b23f1ff3b34e9b5.

The argv is src/qemu.rs's launch for --arch aarch64 (Profile::Virtio, --smp 8, HVF), changed only where it reaches the host: the stick, NVMe and firmware variables are per-run copies, the console and the PL011 are files, QMP is a per-run socket, no host port is bound (no hostfwd, no -s), audio goes to QEMU's none backend, and -display none. Both boots ran the same script; it stops on QEMU's exit or 20 s of silence on both channels, under a 180 s ceiling, and kills QEMU by PID. <logs> and <qemu> stand for the run directory and QEMU's share directory.

head 9490bcfdf46af50ace42b4147b23f1ff3b34e9b5
$ qemu-system-aarch64 -nodefaults -accel hvf -cpu host -boot menu=on,splash-time=0 -machine virt,gic-version=3,iommu=smmuv3 -smp cores=8 -m 2G -drive if=pflash,format=raw,unit=0,file=<qemu>/edk2-aarch64-code.fd,readonly=on -drive if=pflash,format=raw,unit=1,file=<logs>/vars.fd,readonly=off -device nec-usb-xhci,id=xhci -drive if=none,id=stick,format=raw,file=<logs>/stick.img -device usb-storage,bus=xhci.0,drive=stick,bootindex=0 -drive if=none,id=nvme0,format=raw,file=<logs>/nvme.img -device nvme,serial=deadbeef,drive=nvme0,msix-exclusive-bar=on -device usb-kbd,bus=xhci.0 -device usb-tablet,bus=xhci.0 -vga none -device virtio-gpu-pci,xres=1280,yres=720,iommu_platform=on -device virtio-rng-pci -netdev user,id=net0 -device virtio-net-pci-non-transitional,netdev=net0,iommu_platform=on -audiodev none,id=audio0 -device virtio-sound-pci,audiodev=audio0,streams=1,iommu_platform=on -serial file:<logs>/pl011.log -chardev file,id=cs0,path=<logs>/console.log -device virtio-serial-pci-non-transitional,id=virtio-serial0,max_ports=1,iommu_platform=on -device virtconsole,chardev=cs0,id=console0 -no-reboot -qmp unix:<logs>/qmp.sock,server,nowait -display none
stopped: console and PL011 silent for 20 s at 27 s
virtio-console, whole (323 lines)
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HBdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01H[ 1.289 cpu0 loader] ToyOS Bootloader 1.0
[ 1.302 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 1.318 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 1.328 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 1.344 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-Ia153ea7a7aafc9c6 (image scope) holds 0
[ 1.358 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 1.363 cpu0 loader] RSDP address: 0xbcb43018
[ 1.366 cpu0 loader] Boot partition: LBA 2048+69632 signature [59, d0, 3d, 5b, df, e1, d1, 49, be, bb, 88, d1, 29, 5c, 01, 48]
[ 1.424 cpu0 loader] Log partition: signature [45, 10, 6e, af, c0, 0a, 2e, 47, 80, 9a, 81, f2, ac, 39, b6, 7c]
[ 1.601 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B present; the floor is 0
[ 1.639 cpu0 loader] Slot A: signed header 9b47c407c750fa52857784ff19b9d49726f2e67d6998ae5b39776d8f3e016fb5 verifies under this loader's key, version 1791622060
[ 2.130 cpu0 loader] ROOT: read into memory at 0xb88bf000+0x3c00000 from LBA 212992+122880, 1048576 bytes a request (optimal granularity: not reported), in 11105253 counter ticks
[ 2.543 cpu0 loader] Slot A: ROOT hashed in 9753164 counter ticks
[ 2.577 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 2.588 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 2.590 cpu0 loader] Kernel: 2547352 bytes
[ 2.598 cpu0 loader] Boot parameter: "root=af690b32d107eb7ce319fbdf205011ca,boot-slot=A"
[ 2.608 cpu0 loader] Loading kernel elf...
[ 2.611 cpu0 loader] Kernel stack size: 8388608
[ 2.629 cpu0 loader] Kernel memory size: 13725696
[ 2.635 cpu0 loader] Kernel memory located at: 0xb7a00000
[ 2.684 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 486556 }, filesz: 486556, file_offset: 0, flags: SegmentFlags(4) }
[ 2.707 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 552960, len: 1063588 }, filesz: 1063588, file_offset: 487424, flags: SegmentFlags(5) }
[ 2.723 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1682088, len: 1368 }, filesz: 240, file_offset: 1551016, flags: SegmentFlags(6) }
[ 2.732 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1747864, len: 3586805 }, filesz: 26640, file_offset: 1551256, flags: SegmentFlags(6) }
[ 2.816 cpu0 loader] Applied 2966 relocations
[ 2.820 cpu0 loader] GOP: 1280x720 is Blt-only, so this display publishes no framebuffer
[ 2.875 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 2.883 cpu0 loader] Starting kernel...
[ 2.916 cpu0 loader] CPU: entered at EL1
[ 2.927 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 2.977 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 2.995 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 3.051 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 3.092 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 3.137 cpu0 loader] Scanout: this machine has none
[ 3.142 cpu0 loader] Loader image: 0xbc730000+0x40000, mapped at identity as 0xbc600000+0x200000
[ 3.186 cpu0 loader] Boot map: root 0xb7999000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 3.199 cpu0 loader] Kernel image: 0xb7a00000+0xd17000 is inside the 0x100000000-byte boot map
[ 3.264 cpu0 loader] Parameter buffer: 0xbcb40818+0x31 is inside the 0x100000000-byte boot map
[ 3.339 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 3.345 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 3.378 cpu0 loader] Loader counter: 30547592 at entry, 81078247 at the handoff
[ 3.390 cpu0[ 3.406 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 3.406 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 3.407 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.407 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 3.408 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 3.408 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 3.408 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 3.408 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 3.409 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 3.409 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 3.409 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 3.410 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 3.410 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 3.410 cpu0 kernel] memory: 0x000048000000..0x0000b7995000 uefi type 7
[ 3.410 cpu0 kernel] memory: 0x0000b7995000..0x0000bc730000 uefi type 2
[ 3.411 cpu0 kernel] memory: 0x0000bc730000..0x0000bc770000 uefi type 1
[ 3.412 cpu0 kernel] memory: 0x0000bc770000..0x0000bc7f0000 uefi type 5
[ 3.412 cpu0 kernel] memory: 0x0000bc7f0000..0x0000bc960000 uefi type 6
[ 3.413 cpu0 kernel] memory: 0x0000bc960000..0x0000bc9b0000 uefi type 5
[ 3.413 cpu0 kernel] memory: 0x0000bc9b0000..0x0000bca50000 uefi type 6
[ 3.413 cpu0 kernel] memory: 0x0000bca50000..0x0000bcb40000 uefi type 5
[ 3.413 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 3.414 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 3.414 cpu0 kernel] memory: 0x0000bcb44000..0x0000bd833000 uefi type 7
[ 3.414 cpu0 kernel] memory: 0x0000bd833000..0x0000beea2000 uefi type 4
[ 3.415 cpu0 kernel] memory: 0x0000beea2000..0x0000beea3000 uefi type 7
[ 3.415 cpu0 kernel] memory: 0x0000beea3000..0x0000beea4000 uefi type 4
[ 3.415 cpu0 kernel] memory: 0x0000beea4000..0x0000beef5000 uefi type 7
[ 3.415 cpu0 kernel] memory: 0x0000beef5000..0x0000bfa38000 uefi type 4
[ 3.416 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb94000 uefi type 7
[ 3.416 cpu0 kernel] memory: 0x0000bfb94000..0x0000bfe20000 uefi type 3
[ 3.416 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 3.417 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 3.417 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 3.417 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 3.417 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 3.418 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 3.418 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 3.418 cpu0 kernel] memory: 35 ranges, as the loader handed them over
[ 3.419 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=2 mpidr=0x2 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=3 mpidr=0x3 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=4 mpidr=0x4 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=5 mpidr=0x5 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICC uid=6 mpidr=0x6 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICC uid=7 mpidr=0x7 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 3.422 cpu0 kernel] ACPI: MADT names 8 GIC CPU interfaces, 8 enabled
[ 3.422 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 3.422 cpu0 kernel] boot: memory map 0xb7997018+0x348, kernel 0xb7a00000+0xd17000, stack image+0x517000+0x800000
[ 3.423 cpu0 kernel] boot: kernel elf 0xbc4bf018+0x26de98, rsdp 0xbcb43018, boot pml4 0xb7999000
[ 3.423 cpu0 kernel] boot: gop 0x0+0x0 0x0 stride 0 format 0
[ 3.423 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [59, d0, 3d, 5b, df, e1, d1, 49, be, bb, 88, d1, 29, 5c, 01, 48]
[ 3.424 cpu0 kernel] boot: log partition guid [45, 10, 6e, af, c0, 0a, 2e, 47, 80, 9a, 81, f2, ac, 39, b6, 7c]
[ 3.425 cpu0 kernel] boot: cmdline 0xbcb40818+49
[ 3.425 cpu0 kernel] boot: root=af690b32d107eb7ce319fbdf205011ca
[ 3.425 cpu0 kernel] boot: slot A, the one the slot table marks
[ 3.425 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 3.426 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 3.426 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 3.426 cpu0 kernel] pmm: the firmware map calls 2141704192 bytes usable in 25 entries; managed=2044723200 withheld=79691776 unaligned=17289216, and the three sum to it; frames=975 reserved_frames=38 base=0x40000000 span=1023
[ 3.428 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1020 2 MiB blocks and 640 4 KiB pages
[ 3.429 cpu0 kernel] ACPI: APIC at 0xbcb43098 len=748 rev=4 oem="BOCHS" checksummed
[ 3.429 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 3.429 cpu0 kernel] ACPI: GTDT at 0xbcb43e18 len=104 rev=3 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: SPCR at 0xbcb43a98 len=80 rev=2 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: MCFG at 0xbcb43498 len=60 rev=1 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 3.431 cpu0 kernel] PSCI: 1.1 through HVC
[ 3.431 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 3.431 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 3.432 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 3.432 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 3.432 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 3.433 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.433 cpu0 kernel] symbols: loaded 18218 kernel symbols
[ 3.434 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 3.434 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 3.435 cpu0 kernel] Boot: CPU ready (1ms)
[ 3.435 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 3.435 cpu0 kernel] ACPI: MCFG found at 0xbcb43498
[ 3.435 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 3.436 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 3.436 cpu0 kernel] PCI: Enumerating devices...
[ 3.436 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 3.436 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000014000]
[ 3.437 cpu0 kernel]   PCI 00:02.0 [0108] vendor=1b36 device=0010 prog_if=02 bars=[bar0=0x8000018000 bar4=0x10045000]
[ 3.437 cpu0 kernel]   PCI 00:03.0 [0380] vendor=1af4 device=1050 prog_if=00 bars=[bar1=0x10044000 bar4=0x8000000000]
[ 3.438 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10043000 bar4=0x8000004000]
[ 3.439 cpu0 kernel]   PCI 00:05.0 [0200] vendor=1af4 device=1041 prog_if=00 bars=[bar1=0x10042000 bar4=0x8000008000]
[ 3.439 cpu0 kernel]   PCI 00:06.0 [0401] vendor=1af4 device=1059 prog_if=00 bars=[bar1=0x10041000 bar4=0x800000c000]
[ 3.440 cpu0 kernel]   PCI 00:07.0 [0780] vendor=1af4 device=1043 prog_if=00 bars=[bar1=0x10040000 bar4=0x8000010000]
[ 3.449 cpu0 kernel] PCI: Enumeration complete, 8 functions.
[ 3.451 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 3.452 cpu0 kernel] pcidev: 8 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 3.452 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x9011000..0x10040000 (112 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x10046000..0x40000000 (767 MiB)
[ 3.453 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 3.454 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 3.454 cpu0 kernel] pcidev:   0x800001a000..0xffffffffffffffff (17592185520127 MiB)
[ 3.454 cpu0 kernel] mmio: 0x9050000+0x20000 Uncacheable
[ 3.455 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000: GBPA 0x101000, every transaction aborts while SMMUEN is clear
[ 3.568 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 8 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
[ 3.570 cpu0 kernel] file cache: budget 7800 pages (30 MiB)
[ 3.572 cpu0 kernel] gpt: the boot volume names AF6E1045-0AC0-472E-809A-81F2AC39B67C as the log partition
[ 3.572 cpu0 kernel] gpt: firmware booted us from partition 5B3DD059-E1DF-49D1-BEBB-88D1295C0148 at LBA 2048+69632
[ 3.573 cpu0 kernel] Boot: peripherals ready (137ms)
[ 3.574 cpu1 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.574 cpu1 kernel] GIC: this CPU's redistributor at 0x80c0000, its SGIs and timer enabled
[ 3.575 cpu0 kernel] SMP: cpu1 mpidr=0x1 online
[ 3.575 cpu2 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.577 cpu2 kernel] GIC: this CPU's redistributor at 0x80e0000, its SGIs and timer enabled
[ 3.578 cpu0 kernel] SMP: cpu2 mpidr=0x2 online
[ 3.578 cpu3 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.579 cpu3 kernel] GIC: this CPU's redistributor at 0x8100000, its SGIs and timer enabled
[ 3.579 cpu0 kernel] SMP: cpu3 mpidr=0x3 online
[ 3.582 cpu4 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.582 cpu4 kernel] GIC: this CPU's redistributor at 0x8120000, its SGIs and timer enabled
[ 3.583 cpu0 kernel] SMP: cpu4 mpidr=0x4 online
[ 3.602 cpu5 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.604 cpu5 kernel] GIC: this CPU's redistributor at 0x8140000, its SGIs and timer enabled
[ 3.605 cpu0 kernel] SMP: cpu5 mpidr=0x5 online
[ 3.606 cpu6 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.608 cpu6 kernel] GIC: this CPU's redistributor at 0x8160000, its SGIs and timer enabled
[ 3.609 cpu0 kernel] SMP: cpu6 mpidr=0x6 online
[ 3.610 cpu7 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.611 cpu7 kernel] GIC: this CPU's redistributor at 0x8180000, its SGIs and timer enabled
[ 3.611 cpu0 kernel] SMP: cpu7 mpidr=0x7 online
[ 3.612 cpu0 kernel] SMP: 8 of 8 MADT CPUs online
[ 3.612 cpu0 kernel] root: mounted read-only from memory at 0xb88bf000+0x3c00000, filesystem af690b32d107eb7ce319fbdf205011ca, 15360 blocks
[ 3.612 cpu0 kernel] Boot: subsystems ready (39ms)
[ 3.614 cpu0 kernel] spawn: /system/bin/supervisor pid=0 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.615 cpu0 kernel] spawned /system/bin/supervisor pid=0
[ 3.615 cpu0 kernel] boot: the supervisor spawned with ROOT from memory; storage commands before it: 0
[ 3.615 cpu0 kernel] xHCI: found at PCI 00:01.0 1033:0194
[ 3.616 cpu0 kernel] xHCI: BAR0=0x8000014000
[ 3.630 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 3.638 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 3.755 cpu0 kernel] xHCI: NOT INITIALISED at PCI 00:01.0 — the controller offers neither MSI-X nor MSI, and this driver has no other way to be told it has anything to say. No USB device on it can be used.
[ 3.756 cpu0 kernel] xHCI: 1 controller(s) present, none of them usable, USB unavailable
[ 5.257 cpu0 kernel] usb-storage: 0 disk(s) on this machine and none carries the boot partition after 1500 ms of looking
[ 5.257 cpu0 kernel] root: the partition ROOT was read from, A1928416-B4F1-4910-92FB-D16A019B9F06, is not held because it is on no disk this kernel drives; every claim of it is refused; disks that did not answer: []
[ 5.258 cpu0 kernel] Boot: storage ready (1642ms)
[ 5.259 cpu0 kernel] virtio-console: found at PCI 00:07.0
[ 5.259 cpu0 kernel] iommu: domain1 root=0x40603000 context=0x40604000 asid=1 addresses from 0x400000000000 to 0x1000000000000
[ 5.260 cpu0 kernel] iommu: domain1 maps 0x41600000..0x41800000 at 0x400000000000
[ 5.260 cpu0 kernel] iommu: 00:07.0 moves to domain1
[ 5.260 cpu0 kernel] VirtIO: PCI 00:07.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 5.261 cpu0 kernel] mmio: 0x8000010000+0x4000 Uncacheable
[ 5.262 cpu0 kernel] VirtIO: PCI 00:07.0 features device=0x10330000004 negotiated=0x300000000 access_platform=y
[ 5.351 cpu0 kernel] virtio-console: initialized (8 RX bufs of 256 bytes, TX buf 4096 bytes)
[ 5.351 cpu0 kernel] virtio-sound: found at PCI 00:06.0
[ 5.351 cpu0 kernel] VirtIO: PCI 00:06.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 5.351 cpu0 kernel] mmio: 0x800000c000+0x4000 Uncacheable
[ 5.352 cpu0 kernel] VirtIO: PCI 00:06.0 features device=0x10379000000 negotiated=0x300000000 access_platform=y
[ 5.352 cpu0 kernel] virtio-sound: 0 jacks, 1 streams, 0 chmaps
[ 5.352 cpu0 kernel] iommu: domain2 root=0x40607000 context=0x40608000 asid=2 addresses from 0x400000000000 to 0x1000000000000
[ 5.352 cpu0 kernel] iommu: domain2 maps 0x41800000..0x41a00000 at 0x400000000000
[ 5.353 cpu0 kernel] iommu: domain2 maps 0x41a00000..0x41c00000 at 0x400000200000
[ 5.353 cpu0 kernel] iommu: 00:06.0 moves to domain2
[ 5.353 cpu0 kernel] PCI 00:06.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 5.353 cpu0 kernel] virtio-sound: NOT INITIALISED at PCI 00:06.0 — its MSI-X could not be armed and this driver has no other way to be told a period completed
[ 5.353 cpu0 kernel] VirtIO GPU: found at PCI 00:03.0
[ 5.353 cpu0 kernel] iommu: domain3 root=0x4060b000 context=0x4060c000 asid=3 addresses from 0x400000000000 to 0x1000000000000
[ 5.354 cpu0 kernel] iommu: domain3 maps 0x41c00000..0x41e00000 at 0x400000000000
[ 5.354 cpu0 kernel] iommu: 00:03.0 moves to domain3
[ 5.354 cpu0 kernel] VirtIO: PCI 00:03.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 5.355 cpu0 kernel] mmio: 0x8000000000+0x4000 Uncacheable
[ 5.356 cpu0 kernel] VirtIO: PCI 00:03.0 features device=0x10330000002 negotiated=0x300000002 access_platform=y
[ 5.356 cpu0 kernel] VirtIO GPU: display 1280x720
[ 5.358 cpu0 kernel] iommu: domain3 maps 0x41e00000..0x42200000 at 0x400000200000
[ 5.358 cpu0 kernel] VirtIO GPU: scanout buffer at 0xffff800041e00000 phys=0x41e00000 device=0x400000200000 (3686400 bytes)
[ 5.360 cpu0 kernel] iommu: domain3 maps 0x42600000..0x42800000 at 0x400000600000
[ 5.361 cpu0 kernel] VirtIO GPU: cursor resource at 0xffff800042600000 phys=0x42600000 device=0x400000600000
[ 5.361 cpu0 kernel] GPU: using VirtIO
[ 5.361 cpu0 kernel] mouse: rel scale x=36 y=64 (screen 1280x720)
[ 5.361 cpu0 kernel] Boot: devices ready (102ms)
[ 5.361 cpu0 kernel] log: /log is on a disk this kernel does not drive; its file server says whether it mounted
[ 5.361 cpu0 kernel] Boot: complete (1927ms)
[ 5.361 cpu0 kernel] boot: power-on to loader 1272 ms, loader 2105 ms (ROOT read 462 ms), kernel to Boot: complete 1983 ms
[ 5.361 cpu0 kernel] kthread: klogd pid=1 tid=0 runs in the kernel address space
[ 5.361 cpu2 kernel] counters: cpu2 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.361 cpu2 kernel] CPU 2: joining scheduler
[ 5.366 cpu0 kernel] pcidev: PCI 00:02.0 NOT HANDED OVER — its interrupts would not be remapped on this machine, and a message that is not remapped can raise any vector on any CPU
[ 5.366 cpu6 kernel] counters: cpu6 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.366 cpu6 kernel] CPU 6: joining scheduler
[ 5.366 cpu4 kernel] counters: cpu4 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.366 cpu4 kernel] CPU 4: joining scheduler
[ 5.368 cpu3 kernel] counters: cpu3 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.368 cpu3 kernel] CPU 3: joining scheduler
[ 5.368 cpu0 kernel] spawn: /system/bin/diskserver pid=2 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.372 cpu0 kernel] spawn: /system/bin/fileserver pid=3 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.374 cpu0 kernel] spawn: /system/bin/fileserver pid=4 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.377 cpu0 kernel] spawn: /system/bin/fileserver pid=5 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.404 cpu7 kernel] counters: cpu7 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.404 cpu7 kernel] CPU 7: joining scheduler
[ 5.404 cpu1 kernel] counters: cpu1 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.404 cpu1 kernel] CPU 1: joining scheduler
[ 5.435 cpu5 kernel] counters: cpu5 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 5.454 cpu5 kernel] CPU 5: joining scheduler
[ 5.476 cpu0 kernel] spawn: /system/bin/logkeeper pid=6 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.481 cpu0 kernel] spawn: /system/bin/compositor pid=7 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.363 supervisor] supervisor: build 9490bcfdf46af50ace42b4147b23f1ff3b34e9b5 clean, committed 2026-10-10 08:38:43 UTC, toolchain b3f5ad494486c67d, aarch64
[ 5.366 supervisor] supervisor: diskserver: pci:1b36:0010 is on this machine and could not be handed over; the kernel's `pcidev:`, `partclaim:`, `isa:` or `acpi:` line says why
[ 5.368 supervisor] supervisor: started diskserver
[ 5.372 supervisor] supervisor: started fileserver
[ 5.374 supervisor] supervisor: started fileserver
[ 5.377 supervisor] supervisor: started fileserver
[ 5.405 diskserver] diskserver: NOT SERVING — pci:1b36:0010 is on this machine and the kernel refused this service its claim; every partition on it is refused
[ 5.406 diskserver] diskserver: an open of AF6E1045-0AC0-472E-809A-81F2AC39B67C refused: ClaimRefused
[ 5.406 fileserver] fileserver: diskserver would not open the partition: Refused(ClaimRefused)
[ 5.406 fileserver] fileserver: Log serving /log — absent: the Log partition AF6E1045-0AC0-472E-809A-81F2AC39B67C is on no disk this server reaches
[ 5.424 diskserver] diskserver: an open of 5B3DD059-E1DF-49D1-BEBB-88D1295C0148 refused: ClaimRefused
[ 5.426 fileserver] fileserver: diskserver would not open the partition: Refused(ClaimRefused)
[ 5.426 fileserver] fileserver: Boot serving /boot — absent: the Boot partition 5B3DD059-E1DF-49D1-BEBB-88D1295C0148 is on no disk this server reaches
[ 5.458 fileserver] fileserver: the block service would not list its partitions (Refused(ClaimRefused)); DATA is absent this boot
[ 5.459 fileserver] fileserver: Data serving /apps, /config, /home, /state — absent: the block service would not list its partitions (Refused(ClaimRefused))
[ 5.466 supervisor tid=1] supervisor: /home/toy could not be made, so this boot has no session home: permission denied
[ 5.473 supervisor] supervisor: logkeeper: /state/logkeeper could not be made: permission denied
[ 5.476 supervisor] supervisor: started logkeeper
[ 5.478 supervisor] supervisor: compositor: /state/compositor could not be made: permission denied
[ 5.478 supervisor] supervisor: compositor: no keyboard on this machine
[ 5.478 supervisor] supervisor: compositor: no mouse on this machine
[ 5.480 logkeeper] logkeeper: cannot create /log/unknown-00.log: permission denied
[ 5.480 logkeeper] logkeeper: no /log on this machine - this boot's kernel log is on the console only (undated: this machine will not say what time it is)
[ 5.481 supervisor] supervisor: started compositor
[ 5.485 compositor error] 
[ 5.485 compositor error] thread 'main' (1) panicked at userland/compositor/src/session.rs:151:14:
[ 5.485 compositor error] the manifest gives this program the keyboard
[ 5.485 compositor error] stack backtrace:
[ 5.488 cpu5 kernel] exit: compositor pid=7 code=101 cpu=5ms peak=10MB allocs=5 frees=0 syscalls=43 syscall_wall=3ms 1=2 6=1 9=2 10=6 13=2 14=3 21=1 50=1 51=1 63=4 72=1 73=2 91=2 99=2 102=4 105=4 106=5
[ 5.488 compositor error]    0:      0x100001a8128 - _Unwind_Backtrace
[ 5.488 compositor error]    1:      0x10000191058 - <<std[d6d2712760615b7]::sys::backtrace::BacktraceLock>::print::DisplayBacktrace as core[f28ba090d62d1c7]::fmt::Display>::fmt
[ 5.488 compositor error]    2:      0x100001adcb0 - core[f28ba090d62d1c7]::fmt::write
[ 5.488 compositor error]    3:      0x10000195868 - <std[d6d2712760615b7]::sys::stdio::toyos::Stderr as core[f28ba090d62d1c7]::io::write::Write>::write_fmt
[ 5.488 compositor error]    4:      0x10000174964 - std[d6d2712760615b7]::panicking::default_hook::{closure#0}
[ 5.488 compositor error]    5:      0x1000018a7c0 - std[d6d2712760615b7]::panicking::default_hook
[ 5.488 compositor error]    6:      0x1000018a984 - std[d6d2712760615b7]::panicking::panic_with_hook
[ 5.488 compositor error]    7:      0x10000174a08 - std[d6d2712760615b7]::panicking::panic_handler::{closure#0}
[ 5.488 compositor error]    8:      0x1000016d378 - std[d6d2712760615b7]::sys::backtrace::__rust_end_short_backtrace::<std[d6d2712760615b7]::panicking::panic_handler::{closure#0}, !>
[ 5.488 compositor error]    9:      0x100001751e0 - __rustc[d0c72ce299f394e5]::rust_begin_unwind
[ 5.488 compositor error]   10:      0x100001ae4dc - core[f28ba090d62d1c7]::panicking::panic_fmt
[ 5.488 compositor error]   11:      0x100001ae208 - core[f28ba090d62d1c7]::option::expect_failed
[ 5.488 compositor error]   12:      0x1000009ed58 - <compositor[8b4d04b91d5c2cb1]::session::Session>::start
[ 5.488 compositor error]   13:      0x1000009876c - compositor[8b4d04b91d5c2cb1]::main
[ 5.488 compositor error]   14:      0x1000009578c - std[d6d2712760615b7]::sys::backtrace::__rust_begin_short_backtrace::<fn(), ()>
[ 5.488 compositor error]   15:      0x100000987ec - std[d6d2712760615b7]::rt::lang_start::<()>::{closure#0}
[ 5.488 compositor error]   16:      0x10000189ecc - std[d6d2712760615b7]::rt::lang_start_internal
[ 5.488 compositor error]   17:      0x100000987cc - main
[ 5.488 compositor error]   18:      0x1000018f0b8 - std[d6d2712760615b7]::sys::pal::toyos::start_rust
[ 5.488 compositor error]   19:      0x1000016399c - _start
[ 5.489 supervisor] supervisor: soundserver: /state/soundserver could not be made: permission denied
[ 5.489 supervisor] supervisor: soundserver: no hda-audio on this machine
[ 5.489 supervisor] supervisor: soundserver: no virtio-sound on this machine
[ 5.492 cpu0 kernel] spawn: /system/bin/soundserver pid=8 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.492 supervisor] supervisor: started soundserver
[ 5.494 cpu0 kernel] pcidev: PCI 00:05.0 NOT HANDED OVER — its interrupts would not be remapped on this machine, and a message that is not remapped can raise any vector on any CPU
[ 5.493 soundserver] soundserver: no audio device, presenting a null sink (44100Hz 2ch, 128 frames/period, streams discarded)
[ 5.493 soundserver] soundserver: null sink idle
[ 5.493 supervisor] supervisor: netstack: /state/netstack could not be made: permission denied
[ 5.494 supervisor] supervisor: netstack: pci:1af4:1041 is on this machine and could not be handed over; the kernel's `pcidev:`, `partclaim:`, `isa:` or `acpi:` line says why
[ 5.495 cpu0 kernel] spawn: /system/bin/netstack pid=9 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 5.497 cpu3 kernel] exit: netstack pid=9 code=0 cpu=1ms peak=2MB allocs=2 frees=0 syscalls=11 syscall_wall=0ms 6=1 14=1 50=1 51=1 63=1 72=1 73=2 91=1 99=1 106=1
[ 5.496 supervisor] supervisor: started netstack
[ 5.497 netstack] netstack: no NIC on this machine, exiting
[ 5.533 cpu0 kernel] spawn: /system/bin/filepicker pid=10 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=2ms total=2ms)
[ 5.530 supervisor] supervisor: filepicker: /state/filepicker could not be made: permission denied
[ 5.533 supervisor] supervisor: started filepicker
[ 5.562 cpu0 kernel] spawn: /system/bin/acpiserver pid=11 unresolved=0 (layout=23ms relocs=0ms deps=0ms tls=1ms total=24ms)
[ 5.537 supervisor] supervisor: acpiserver: /state/acpiserver could not be made: permission denied
[ 5.537 supervisor] supervisor: acpiserver: no acpi on this machine
[ 5.562 supervisor] supervisor: started acpiserver
[ 5.563 cpu7 kernel] exit: acpiserver pid=11 code=0 cpu=0ms peak=2MB allocs=2 frees=0 syscalls=11 syscall_wall=0ms 6=1 14=1 50=1 51=1 63=1 72=1 73=2 91=1 99=1 106=1
[ 5.563 acpiserver] acpiserver: no acpi claim, so the machine stays in the mode its firmware handed over
PL011, whole (214 lines; the console above carries the kernel's record from the start)
UEFI firmware (version edk2-stable202408-prebuilt.qemu.org built at 16:28:50 on Sep 12 2024)
ArmTrngLib could not be correctly initialized.
Error: Image at 000BFDB6000 start failed: 00000001
Error: Image at 000BFD6D000 start failed: Not Found
Error: Image at 000BFCBA000 start failed: Unsupported
Error: Image at 000BFC3F000 start failed: Not Found
Error: Image at 000BFB65000 start failed: Aborted
Tpm2SubmitCommand - Tcg2 - Not Found
Tpm2GetCapabilityPcrs fail!
Tpm2SubmitCommand - Tcg2 - Not Found
Image type X64 can't be loaded on AARCH64 UEFI system.
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HUsbBootExecCmd: Success to Exec 0x0 Cmd (Result = 1)
BdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
ConvertPages: failed to find range 140000000 - 14003FFFF
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01HConvertPages: failed to find range 8000000 - 8003FFF
[ 1.289 cpu0 loader] ToyOS Bootloader 1.0
[ 1.302 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 1.318 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 1.328 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 1.344 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-Ia153ea7a7aafc9c6 (image scope) holds 0
[ 1.358 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 1.363 cpu0 loader] RSDP address: 0xbcb43018
[ 1.366 cpu0 loader] Boot partition: LBA 2048+69632 signature [59, d0, 3d, 5b, df, e1, d1, 49, be, bb, 88, d1, 29, 5c, 01, 48]
[ 1.424 cpu0 loader] Log partition: signature [45, 10, 6e, af, c0, 0a, 2e, 47, 80, 9a, 81, f2, ac, 39, b6, 7c]
[ 1.601 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B present; the floor is 0
[ 1.639 cpu0 loader] Slot A: signed header 9b47c407c750fa52857784ff19b9d49726f2e67d6998ae5b39776d8f3e016fb5 verifies under this loader's key, version 1791622060
[ 2.130 cpu0 loader] ROOT: read into memory at 0xb88bf000+0x3c00000 from LBA 212992+122880, 1048576 bytes a request (optimal granularity: not reported), in 11105253 counter ticks
[ 2.543 cpu0 loader] Slot A: ROOT hashed in 9753164 counter ticks
[ 2.577 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 2.588 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 2.590 cpu0 loader] Kernel: 2547352 bytes
[ 2.598 cpu0 loader] Boot parameter: "root=af690b32d107eb7ce319fbdf205011ca,boot-slot=A"
[ 2.608 cpu0 loader] Loading kernel elf...
[ 2.611 cpu0 loader] Kernel stack size: 8388608
[ 2.629 cpu0 loader] Kernel memory size: 13725696
[ 2.635 cpu0 loader] Kernel memory located at: 0xb7a00000
[ 2.684 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 486556 }, filesz: 486556, file_offset: 0, flags: SegmentFlags(4) }
[ 2.707 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 552960, len: 1063588 }, filesz: 1063588, file_offset: 487424, flags: SegmentFlags(5) }
[ 2.723 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1682088, len: 1368 }, filesz: 240, file_offset: 1551016, flags: SegmentFlags(6) }
[ 2.732 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1747864, len: 3586805 }, filesz: 26640, file_offset: 1551256, flags: SegmentFlags(6) }
[ 2.816 cpu0 loader] Applied 2966 relocations
[ 2.820 cpu0 loader] GOP: 1280x720 is Blt-only, so this display publishes no framebuffer
[ 2.875 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 2.883 cpu0 loader] Starting kernel...
[ 2.916 cpu0 loader] CPU: entered at EL1
[ 2.927 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 2.977 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 2.995 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 3.051 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 3.092 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 3.137 cpu0 loader] Scanout: this machine has none
[ 3.142 cpu0 loader] Loader image: 0xbc730000+0x40000, mapped at identity as 0xbc600000+0x200000
[ 3.186 cpu0 loader] Boot map: root 0xb7999000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 3.199 cpu0 loader] Kernel image: 0xb7a00000+0xd17000 is inside the 0x100000000-byte boot map
[ 3.264 cpu0 loader] Parameter buffer: 0xbcb40818+0x31 is inside the 0x100000000-byte boot map
[ 3.339 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 3.345 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 3.378 cpu0 loader] Loader counter: 30547592 at entry, 81078247 at the handoff
[ 3.390 cpu0 loader] Loader log: the kernel handoff begins, so this file ends here
[ 3.406 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 3.406 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 3.407 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.407 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 3.408 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 3.408 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 3.408 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 3.408 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 3.409 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 3.409 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 3.409 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 3.410 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 3.410 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 3.410 cpu0 kernel] memory: 0x000048000000..0x0000b7995000 uefi type 7
[ 3.410 cpu0 kernel] memory: 0x0000b7995000..0x0000bc730000 uefi type 2
[ 3.411 cpu0 kernel] memory: 0x0000bc730000..0x0000bc770000 uefi type 1
[ 3.412 cpu0 kernel] memory: 0x0000bc770000..0x0000bc7f0000 uefi type 5
[ 3.412 cpu0 kernel] memory: 0x0000bc7f0000..0x0000bc960000 uefi type 6
[ 3.413 cpu0 kernel] memory: 0x0000bc960000..0x0000bc9b0000 uefi type 5
[ 3.413 cpu0 kernel] memory: 0x0000bc9b0000..0x0000bca50000 uefi type 6
[ 3.413 cpu0 kernel] memory: 0x0000bca50000..0x0000bcb40000 uefi type 5
[ 3.413 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 3.414 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 3.414 cpu0 kernel] memory: 0x0000bcb44000..0x0000bd833000 uefi type 7
[ 3.414 cpu0 kernel] memory: 0x0000bd833000..0x0000beea2000 uefi type 4
[ 3.415 cpu0 kernel] memory: 0x0000beea2000..0x0000beea3000 uefi type 7
[ 3.415 cpu0 kernel] memory: 0x0000beea3000..0x0000beea4000 uefi type 4
[ 3.415 cpu0 kernel] memory: 0x0000beea4000..0x0000beef5000 uefi type 7
[ 3.415 cpu0 kernel] memory: 0x0000beef5000..0x0000bfa38000 uefi type 4
[ 3.416 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb94000 uefi type 7
[ 3.416 cpu0 kernel] memory: 0x0000bfb94000..0x0000bfe20000 uefi type 3
[ 3.416 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 3.417 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 3.417 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 3.417 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 3.417 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 3.418 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 3.418 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 3.418 cpu0 kernel] memory: 35 ranges, as the loader handed them over
[ 3.419 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 3.419 cpu0 kernel] ACPI: MADT GICC uid=2 mpidr=0x2 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=3 mpidr=0x3 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=4 mpidr=0x4 enabled=true gicr=0x0
[ 3.420 cpu0 kernel] ACPI: MADT GICC uid=5 mpidr=0x5 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICC uid=6 mpidr=0x6 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICC uid=7 mpidr=0x7 enabled=true gicr=0x0
[ 3.421 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 3.422 cpu0 kernel] ACPI: MADT names 8 GIC CPU interfaces, 8 enabled
[ 3.422 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 3.422 cpu0 kernel] boot: memory map 0xb7997018+0x348, kernel 0xb7a00000+0xd17000, stack image+0x517000+0x800000
[ 3.423 cpu0 kernel] boot: kernel elf 0xbc4bf018+0x26de98, rsdp 0xbcb43018, boot pml4 0xb7999000
[ 3.423 cpu0 kernel] boot: gop 0x0+0x0 0x0 stride 0 format 0
[ 3.423 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [59, d0, 3d, 5b, df, e1, d1, 49, be, bb, 88, d1, 29, 5c, 01, 48]
[ 3.424 cpu0 kernel] boot: log partition guid [45, 10, 6e, af, c0, 0a, 2e, 47, 80, 9a, 81, f2, ac, 39, b6, 7c]
[ 3.425 cpu0 kernel] boot: cmdline 0xbcb40818+49
[ 3.425 cpu0 kernel] boot: root=af690b32d107eb7ce319fbdf205011ca
[ 3.425 cpu0 kernel] boot: slot A, the one the slot table marks
[ 3.425 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 3.426 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 3.426 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 3.426 cpu0 kernel] pmm: the firmware map calls 2141704192 bytes usable in 25 entries; managed=2044723200 withheld=79691776 unaligned=17289216, and the three sum to it; frames=975 reserved_frames=38 base=0x40000000 span=1023
[ 3.428 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1020 2 MiB blocks and 640 4 KiB pages
[ 3.429 cpu0 kernel] ACPI: APIC at 0xbcb43098 len=748 rev=4 oem="BOCHS" checksummed
[ 3.429 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 3.429 cpu0 kernel] ACPI: GTDT at 0xbcb43e18 len=104 rev=3 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: SPCR at 0xbcb43a98 len=80 rev=2 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: MCFG at 0xbcb43498 len=60 rev=1 oem="BOCHS" checksummed
[ 3.430 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 3.431 cpu0 kernel] PSCI: 1.1 through HVC
[ 3.431 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 3.431 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 3.432 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 3.432 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 3.432 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 3.433 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.433 cpu0 kernel] symbols: loaded 18218 kernel symbols
[ 3.434 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 3.434 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 3.435 cpu0 kernel] Boot: CPU ready (1ms)
[ 3.435 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 3.435 cpu0 kernel] ACPI: MCFG found at 0xbcb43498
[ 3.435 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 3.436 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 3.436 cpu0 kernel] PCI: Enumerating devices...
[ 3.436 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 3.436 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000014000]
[ 3.437 cpu0 kernel]   PCI 00:02.0 [0108] vendor=1b36 device=0010 prog_if=02 bars=[bar0=0x8000018000 bar4=0x10045000]
[ 3.437 cpu0 kernel]   PCI 00:03.0 [0380] vendor=1af4 device=1050 prog_if=00 bars=[bar1=0x10044000 bar4=0x8000000000]
[ 3.438 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10043000 bar4=0x8000004000]
[ 3.439 cpu0 kernel]   PCI 00:05.0 [0200] vendor=1af4 device=1041 prog_if=00 bars=[bar1=0x10042000 bar4=0x8000008000]
[ 3.439 cpu0 kernel]   PCI 00:06.0 [0401] vendor=1af4 device=1059 prog_if=00 bars=[bar1=0x10041000 bar4=0x800000c000]
[ 3.440 cpu0 kernel]   PCI 00:07.0 [0780] vendor=1af4 device=1043 prog_if=00 bars=[bar1=0x10040000 bar4=0x8000010000]
[ 3.449 cpu0 kernel] PCI: Enumeration complete, 8 functions.
[ 3.451 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 3.452 cpu0 kernel] pcidev: 8 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 3.452 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x9011000..0x10040000 (112 MiB)
[ 3.453 cpu0 kernel] pcidev:   0x10046000..0x40000000 (767 MiB)
[ 3.453 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 3.454 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 3.454 cpu0 kernel] pcidev:   0x800001a000..0xffffffffffffffff (17592185520127 MiB)
[ 3.454 cpu0 kernel] mmio: 0x9050000+0x20000 Uncacheable
[ 3.455 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000: GBPA 0x101000, every transaction aborts while SMMUEN is clear
[ 3.568 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 8 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
[ 3.570 cpu0 kernel] file cache: budget 7800 pages (30 MiB)
[ 3.572 cpu0 kernel] gpt: the boot volume names AF6E1045-0AC0-472E-809A-81F2AC39B67C as the log partition
[ 3.572 cpu0 kernel] gpt: firmware booted us from partition 5B3DD059-E1DF-49D1-BEBB-88D1295C0148 at LBA 2048+69632
[ 3.573 cpu0 kernel] Boot: peripherals ready (137ms)
[ 3.574 cpu1 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.574 cpu1 kernel] GIC: this CPU's redistributor at 0x80c0000, its SGIs and timer enabled
[ 3.575 cpu0 kernel] SMP: cpu1 mpidr=0x1 online
[ 3.575 cpu2 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.577 cpu2 kernel] GIC: this CPU's redistributor at 0x80e0000, its SGIs and timer enabled
[ 3.578 cpu0 kernel] SMP: cpu2 mpidr=0x2 online
[ 3.578 cpu3 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.579 cpu3 kernel] GIC: this CPU's redistributor at 0x8100000, its SGIs and timer enabled
[ 3.579 cpu0 kernel] SMP: cpu3 mpidr=0x3 online
[ 3.582 cpu4 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.582 cpu4 kernel] GIC: this CPU's redistributor at 0x8120000, its SGIs and timer enabled
[ 3.583 cpu0 kernel] SMP: cpu4 mpidr=0x4 online
[ 3.602 cpu5 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.604 cpu5 kernel] GIC: this CPU's redistributor at 0x8140000, its SGIs and timer enabled
[ 3.605 cpu0 kernel] SMP: cpu5 mpidr=0x5 online
[ 3.606 cpu6 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.608 cpu6 kernel] GIC: this CPU's redistributor at 0x8160000, its SGIs and timer enabled
[ 3.609 cpu0 kernel] SMP: cpu6 mpidr=0x6 online
[ 3.610 cpu7 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 3.611 cpu7 kernel] GIC: this CPU's redistributor at 0x8180000, its SGIs and timer enabled
[ 3.611 cpu0 kernel] SMP: cpu7 mpidr=0x7 online
[ 3.612 cpu0 kernel] SMP: 8 of 8 MADT CPUs online
[ 3.612 cpu0 kernel] root: mounted read-only from memory at 0xb88bf000+0x3c00000, filesystem af690b32d107eb7ce319fbdf205011ca, 15360 blocks
[ 3.612 cpu0 kernel] Boot: subsystems ready (39ms)
[ 3.614 cpu0 kernel] spawn: /system/bin/supervisor pid=0 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.615 cpu0 kernel] spawned /system/bin/supervisor pid=0
[ 3.615 cpu0 kernel] boot: the supervisor spawned with ROOT from memory; storage commands before it: 0
[ 3.615 cpu0 kernel] xHCI: found at PCI 00:01.0 1033:0194
[ 3.616 cpu0 kernel] xHCI: BAR0=0x8000014000
[ 3.630 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 3.638 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 3.755 cpu0 kernel] xHCI: NOT INITIALISED at PCI 00:01.0 — the controller offers neither MSI-X nor MSI, and this driver has no other way to be told it has anything to say. No USB device on it can be used.
[ 3.756 cpu0 kernel] xHCI: 1 controller(s) present, none of them usable, USB unavailable
[ 5.257 cpu0 kernel] usb-storage: 0 disk(s) on this machine and none carries the boot partition after 1500 ms of looking
[ 5.257 cpu0 kernel] root: the partition ROOT was read from, A1928416-B4F1-4910-92FB-D16A019B9F06, is not held because it is on no disk this kernel drives; every claim of it is refused; disks that did not answer: []
[ 5.258 cpu0 kernel] Boot: storage ready (1642ms)
[ 5.259 cpu0 kernel] virtio-console: found at PCI 00:07.0
[ 5.259 cpu0 kernel] iommu: domain1 root=0x40603000 context=0x40604000 asid=1 addresses from 0x400000000000 to 0x1000000000000
[ 5.260 cpu0 kernel] iommu: domain1 maps 0x41600000..0x41800000 at 0x400000000000
[ 5.260 cpu0 kernel] iommu: 00:07.0 moves to domain1
[ 5.260 cpu0 kernel] VirtIO: PCI 00:07.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 5.261 cpu0 kernel] mmio: 0x8000010000+0x4000 Uncacheable
[ 5.262 cpu0 kernel] VirtIO: PCI 00:07.0 features device=0x10330000004 negotiated=0x300000000 access_platform=y

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

cargo run --arch aarch64's machine booted at origin/main, 5a3b74345384de530e5dccf2124f057c29f85bcd, the base this head merged.

The argv is src/qemu.rs's launch for --arch aarch64 (Profile::Virtio, --smp 8, HVF), changed only where it reaches the host: the stick, NVMe and firmware variables are per-run copies, the console and the PL011 are files, QMP is a per-run socket, no host port is bound (no hostfwd, no -s), audio goes to QEMU's none backend, and -display none. Both boots ran the same script; it stops on QEMU's exit or 20 s of silence on both channels, under a 180 s ceiling, and kills QEMU by PID. <logs> and <qemu> stand for the run directory and QEMU's share directory.

head 5a3b74345384de530e5dccf2124f057c29f85bcd
$ qemu-system-aarch64 -nodefaults -accel hvf -cpu host -boot menu=on,splash-time=0 -machine virt,gic-version=3,iommu=smmuv3 -smp cores=8 -m 2G -drive if=pflash,format=raw,unit=0,file=<qemu>/edk2-aarch64-code.fd,readonly=on -drive if=pflash,format=raw,unit=1,file=<logs>/vars.fd,readonly=off -device nec-usb-xhci,id=xhci -drive if=none,id=stick,format=raw,file=<logs>/stick.img -device usb-storage,bus=xhci.0,drive=stick,bootindex=0 -drive if=none,id=nvme0,format=raw,file=<logs>/nvme.img -device nvme,serial=deadbeef,drive=nvme0,msix-exclusive-bar=on -device usb-kbd,bus=xhci.0 -device usb-tablet,bus=xhci.0 -vga none -device virtio-gpu-pci,xres=1280,yres=720,iommu_platform=on -device virtio-rng-pci -netdev user,id=net0 -device virtio-net-pci-non-transitional,netdev=net0,iommu_platform=on -audiodev none,id=audio0 -device virtio-sound-pci,audiodev=audio0,streams=1,iommu_platform=on -serial file:<logs>/pl011.log -chardev file,id=cs0,path=<logs>/console.log -device virtio-serial-pci-non-transitional,id=virtio-serial0,max_ports=1,iommu_platform=on -device virtconsole,chardev=cs0,id=console0 -no-reboot -qmp unix:<logs>/qmp.sock,server,nowait -display none
stopped: console and PL011 silent for 20 s at 24 s
virtio-console, whole (311 lines)
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HBdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01H[ 0.800 cpu0 loader] ToyOS Bootloader 1.0
[ 0.802 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 0.810 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 0.815 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 0.818 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-Ie1c3621a5aba3ea3 (image scope) holds 0
[ 0.821 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 0.840 cpu0 loader] RSDP address: 0xbcb43018
[ 0.843 cpu0 loader] Boot partition: LBA 2048+69632 signature [f5, b9, 1b, 88, 4e, 2b, 4c, 4d, 99, a9, 44, f3, a5, e7, fd, 8b]
[ 0.848 cpu0 loader] Log partition: signature [fd, 26, 7c, c6, ae, cd, 7d, 4c, b1, 7e, 2a, fe, f9, 11, 20, e2]
[ 0.875 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B present; the floor is 0
[ 0.893 cpu0 loader] Slot A: signed header d057d8b86b2fefaada91644d314213f398a0716fe9fc49cf3f3b040540c3947f verifies under this loader's key, version 1791623197
[ 1.091 cpu0 loader] ROOT: read into memory at 0xb88d6000+0x3c00000 from LBA 212992+122880, 1048576 bytes a request (optimal granularity: not reported), in 4255155 counter ticks
[ 1.229 cpu0 loader] Slot A: ROOT hashed in 3161177 counter ticks
[ 1.232 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 1.237 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 1.241 cpu0 loader] Kernel: 2452800 bytes
[ 1.244 cpu0 loader] Boot parameter: "root=e50e07dacc89a65f712a22d21874d893,boot-slot=A"
[ 1.248 cpu0 loader] Loading kernel elf...
[ 1.250 cpu0 loader] Kernel stack size: 8388608
[ 1.252 cpu0 loader] Kernel memory size: 13664256
[ 1.258 cpu0 loader] Kernel memory located at: 0xb7a00000
[ 1.261 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 465168 }, filesz: 465168, file_offset: 0, flags: SegmentFlags(4) }
[ 1.267 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 532480, len: 1024272 }, filesz: 1024272, file_offset: 466944, flags: SegmentFlags(5) }
[ 1.279 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1622288, len: 3824 }, filesz: 240, file_offset: 1491216, flags: SegmentFlags(6) }
[ 1.291 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1688064, len: 3586440 }, filesz: 26456, file_offset: 1491456, flags: SegmentFlags(6) }
[ 1.298 cpu0 loader] Applied 2789 relocations
[ 1.303 cpu0 loader] GOP: 1280x720 is Blt-only, so this display publishes no framebuffer
[ 1.307 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 1.313 cpu0 loader] Starting kernel...
[ 1.315 cpu0 loader] CPU: entered at EL1
[ 1.317 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 1.324 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.330 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.335 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.341 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 1.347 cpu0 loader] Scanout: this machine has none
[ 1.350 cpu0 loader] Loader image: 0xbc730000+0x40000, mapped at identity as 0xbc600000+0x200000
[ 1.357 cpu0 loader] Boot map: root 0xb79bf000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 1.360 cpu0 loader] Kernel image: 0xb7a00000+0xd08000 is inside the 0x100000000-byte boot map
[ 1.366 cpu0 loader] Parameter buffer: 0xbcb40818+0x31 is inside the 0x100000000-byte boot map
[ 1.371 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 1.373 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 1.377 cpu0 loader] Loader counter: 19099578 at entry, [ 1.395 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 1.395 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 1.396 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.397 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 1.398 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 1.398 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 1.398 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 1.399 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 1.399 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 1.399 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 1.400 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 1.400 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 1.400 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 1.401 cpu0 kernel] memory: 0x000048000000..0x0000b79bb000 uefi type 7
[ 1.401 cpu0 kernel] memory: 0x0000b79bb000..0x0000bc730000 uefi type 2
[ 1.401 cpu0 kernel] memory: 0x0000bc730000..0x0000bc770000 uefi type 1
[ 1.402 cpu0 kernel] memory: 0x0000bc770000..0x0000bc7f0000 uefi type 5
[ 1.402 cpu0 kernel] memory: 0x0000bc7f0000..0x0000bc960000 uefi type 6
[ 1.402 cpu0 kernel] memory: 0x0000bc960000..0x0000bc9b0000 uefi type 5
[ 1.403 cpu0 kernel] memory: 0x0000bc9b0000..0x0000bca50000 uefi type 6
[ 1.403 cpu0 kernel] memory: 0x0000bca50000..0x0000bcb40000 uefi type 5
[ 1.403 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 1.403 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 1.404 cpu0 kernel] memory: 0x0000bcb44000..0x0000bd833000 uefi type 7
[ 1.404 cpu0 kernel] memory: 0x0000bd833000..0x0000beea2000 uefi type 4
[ 1.404 cpu0 kernel] memory: 0x0000beea2000..0x0000beea3000 uefi type 7
[ 1.405 cpu0 kernel] memory: 0x0000beea3000..0x0000beea4000 uefi type 4
[ 1.405 cpu0 kernel] memory: 0x0000beea4000..0x0000beef5000 uefi type 7
[ 1.405 cpu0 kernel] memory: 0x0000beef5000..0x0000bfa38000 uefi type 4
[ 1.406 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb94000 uefi type 7
[ 1.406 cpu0 kernel] memory: 0x0000bfb94000..0x0000bfe20000 uefi type 3
[ 1.406 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 1.407 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 1.407 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 1.407 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 1.407 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 1.408 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 1.408 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 1.408 cpu0 kernel] memory: 35 ranges, as the loader handed them over
[ 1.409 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 1.409 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 1.409 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=2 mpidr=0x2 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=3 mpidr=0x3 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=4 mpidr=0x4 enabled=true gicr=0x0
[ 1.411 cpu0 kernel] ACPI: MADT GICC uid=5 mpidr=0x5 enabled=true gicr=0x0
[ 1.411 cpu0 kernel] ACPI: MADT GICC uid=6 mpidr=0x6 enabled=true gicr=0x0
[ 1.412 cpu0 kernel] ACPI: MADT GICC uid=7 mpidr=0x7 enabled=true gicr=0x0
[ 1.412 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 1.412 cpu0 kernel] ACPI: MADT names 8 GIC CPU interfaces, 8 enabled
[ 1.412 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 1.413 cpu0 kernel] boot: memory map 0xb79bd018+0x348, kernel 0xb7a00000+0xd08000, stack image+0x508000+0x800000
[ 1.413 cpu0 kernel] boot: kernel elf 0xbc4d6018+0x256d40, rsdp 0xbcb43018, boot pml4 0xb79bf000
[ 1.414 cpu0 kernel] boot: gop 0x0+0x0 0x0 stride 0 format 0
[ 1.414 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [f5, b9, 1b, 88, 4e, 2b, 4c, 4d, 99, a9, 44, f3, a5, e7, fd, 8b]
[ 1.415 cpu0 kernel] boot: log partition guid [fd, 26, 7c, c6, ae, cd, 7d, 4c, b1, 7e, 2a, fe, f9, 11, 20, e2]
[ 1.415 cpu0 kernel] boot: cmdline 0xbcb40818+49
[ 1.416 cpu0 kernel] boot: root=e50e07dacc89a65f712a22d21874d893
[ 1.416 cpu0 kernel] boot: slot A, the one the slot table marks
[ 1.416 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 1.416 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 1.417 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 1.417 cpu0 kernel] pmm: the firmware map calls 2141704192 bytes usable in 25 entries; managed=2044723200 withheld=79691776 unaligned=17289216, and the three sum to it; frames=975 reserved_frames=38 base=0x40000000 span=1023
[ 1.419 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1020 2 MiB blocks and 640 4 KiB pages
[ 1.420 cpu0 kernel] ACPI: APIC at 0xbcb43098 len=748 rev=4 oem="BOCHS" checksummed
[ 1.420 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: GTDT at 0xbcb43e18 len=104 rev=3 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: SPCR at 0xbcb43a98 len=80 rev=2 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: MCFG at 0xbcb43498 len=60 rev=1 oem="BOCHS" checksummed
[ 1.422 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 1.422 cpu0 kernel] PSCI: 1.1 through HVC
[ 1.423 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 1.423 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 1.423 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 1.423 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 1.424 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 1.424 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 1.425 cpu0 kernel] symbols: loaded 17534 kernel symbols
[ 1.426 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 1.426 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 1.426 cpu0 kernel] Boot: CPU ready (1ms)
[ 1.427 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 1.427 cpu0 kernel] ACPI: MCFG found at 0xbcb43498
[ 1.427 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 1.427 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 1.428 cpu0 kernel] PCI: Enumerating devices...
[ 1.428 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 1.428 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000014000]
[ 1.429 cpu0 kernel]   PCI 00:02.0 [0108] vendor=1b36 device=0010 prog_if=02 bars=[bar0=0x8000018000 bar4=0x10045000]
[ 1.429 cpu0 kernel]   PCI 00:03.0 [0380] vendor=1af4 device=1050 prog_if=00 bars=[bar1=0x10044000 bar4=0x8000000000]
[ 1.430 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10043000 bar4=0x8000004000]
[ 1.430 cpu0 kernel]   PCI 00:05.0 [0200] vendor=1af4 device=1041 prog_if=00 bars=[bar1=0x10042000 bar4=0x8000008000]
[ 1.431 cpu0 kernel]   PCI 00:06.0 [0401] vendor=1af4 device=1059 prog_if=00 bars=[bar1=0x10041000 bar4=0x800000c000]
[ 1.431 cpu0 kernel]   PCI 00:07.0 [0780] vendor=1af4 device=1043 prog_if=00 bars=[bar1=0x10040000 bar4=0x8000010000]
[ 1.440 cpu0 kernel] PCI: Enumeration complete, 8 functions.
[ 1.442 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 1.443 cpu0 kernel] pcidev: 8 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 1.444 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 1.444 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 1.444 cpu0 kernel] pcidev:   0x9011000..0x10040000 (112 MiB)
[ 1.445 cpu0 kernel] pcidev:   0x10046000..0x40000000 (767 MiB)
[ 1.445 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 1.445 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 1.446 cpu0 kernel] pcidev:   0x800001a000..0xffffffffffffffff (17592185520127 MiB)
[ 1.446 cpu0 kernel] IOMMU: the SMMUv3 is the port's stage 6; no device is translated this boot
[ 1.446 cpu0 kernel] file cache: budget 7800 pages (30 MiB)
[ 1.447 cpu0 kernel] gpt: the boot volume names C67C26FD-CDAE-4C7D-B17E-2AFEF91120E2 as the log partition
[ 1.447 cpu0 kernel] gpt: firmware booted us from partition 881BB9F5-2B4E-4D4C-99A9-44F3A5E7FD8B at LBA 2048+69632
[ 1.448 cpu0 kernel] Boot: peripherals ready (21ms)
[ 1.448 cpu1 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.450 cpu1 kernel] GIC: this CPU's redistributor at 0x80c0000, its SGIs and timer enabled
[ 1.451 cpu0 kernel] SMP: cpu1 mpidr=0x1 online
[ 1.451 cpu2 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.452 cpu2 kernel] GIC: this CPU's redistributor at 0x80e0000, its SGIs and timer enabled
[ 1.453 cpu0 kernel] SMP: cpu2 mpidr=0x2 online
[ 1.454 cpu3 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.455 cpu3 kernel] GIC: this CPU's redistributor at 0x8100000, its SGIs and timer enabled
[ 1.457 cpu0 kernel] SMP: cpu3 mpidr=0x3 online
[ 1.458 cpu4 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.459 cpu4 kernel] GIC: this CPU's redistributor at 0x8120000, its SGIs and timer enabled
[ 1.460 cpu0 kernel] SMP: cpu4 mpidr=0x4 online
[ 1.460 cpu5 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.462 cpu5 kernel] GIC: this CPU's redistributor at 0x8140000, its SGIs and timer enabled
[ 1.463 cpu0 kernel] SMP: cpu5 mpidr=0x5 online
[ 1.477 cpu6 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.478 cpu6 kernel] GIC: this CPU's redistributor at 0x8160000, its SGIs and timer enabled
[ 1.478 cpu0 kernel] SMP: cpu6 mpidr=0x6 online
[ 1.495 cpu7 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.506 cpu7 kernel] GIC: this CPU's redistributor at 0x8180000, its SGIs and timer enabled
[ 1.583 cpu0 kernel] SMP: cpu7 mpidr=0x7 online
[ 1.583 cpu0 kernel] SMP: 8 of 8 MADT CPUs online
[ 1.584 cpu0 kernel] root: mounted read-only from memory at 0xb88d6000+0x3c00000, filesystem e50e07dacc89a65f712a22d21874d893, 15360 blocks
[ 1.584 cpu0 kernel] Boot: subsystems ready (136ms)
[ 1.586 cpu0 kernel] spawn: /system/bin/supervisor pid=0 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 1.587 cpu0 kernel] spawned /system/bin/supervisor pid=0
[ 1.587 cpu0 kernel] boot: the supervisor spawned with ROOT from memory; storage commands before it: 0
[ 1.588 cpu0 kernel] xHCI: found at PCI 00:01.0 1033:0194
[ 1.604 cpu0 kernel] xHCI: BAR0=0x8000014000
[ 1.611 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 1.612 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 1.613 cpu0 kernel] xHCI: NOT INITIALISED at PCI 00:01.0 — the controller offers neither MSI-X nor MSI, and this driver has no other way to be told it has anything to say. No USB device on it can be used.
[ 1.616 cpu0 kernel] xHCI: 1 controller(s) present, none of them usable, USB unavailable
[ 3.117 cpu0 kernel] usb-storage: 0 disk(s) on this machine and none carries the boot partition after 1500 ms of looking
[ 3.118 cpu0 kernel] root: the partition ROOT was read from, A03EF61C-A218-408D-937C-C7A86F348603, is not held because it is on no disk this kernel drives; every claim of it is refused; disks that did not answer: []
[ 3.124 cpu0 kernel] Boot: storage ready (1536ms)
[ 3.125 cpu0 kernel] virtio-console: found at PCI 00:07.0
[ 3.126 cpu0 kernel] iommu: no domain of its own for a device: no unit on this machine translates
[ 3.126 cpu0 kernel] VirtIO: PCI 00:07.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 3.127 cpu0 kernel] mmio: 0x8000010000+0x4000 Uncacheable
[ 3.128 cpu0 kernel] VirtIO: PCI 00:07.0 features device=0x10330000004 negotiated=0x300000000 access_platform=y
[ 3.324 cpu0 kernel] virtio-console: initialized (8 RX bufs of 256 bytes, TX buf 4096 bytes)
[ 3.324 cpu0 kernel] virtio-sound: found at PCI 00:06.0
[ 3.324 cpu0 kernel] VirtIO: PCI 00:06.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 3.325 cpu0 kernel] mmio: 0x800000c000+0x4000 Uncacheable
[ 3.326 cpu0 kernel] VirtIO: PCI 00:06.0 features device=0x10379000000 negotiated=0x300000000 access_platform=y
[ 3.326 cpu0 kernel] virtio-sound: 0 jacks, 1 streams, 0 chmaps
[ 3.326 cpu0 kernel] iommu: no domain of its own for a device: no unit on this machine translates
[ 3.327 cpu0 kernel] PCI 00:06.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 3.330 cpu0 kernel] virtio-sound: NOT INITIALISED at PCI 00:06.0 — its MSI-X could not be armed and this driver has no other way to be told a period completed
[ 3.336 cpu0 kernel] VirtIO GPU: found at PCI 00:03.0
[ 3.336 cpu0 kernel] iommu: no domain of its own for a device: no unit on this machine translates
[ 3.339 cpu0 kernel] VirtIO: PCI 00:03.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 3.352 cpu0 kernel] mmio: 0x8000000000+0x4000 Uncacheable
[ 3.368 cpu0 kernel] VirtIO: PCI 00:03.0 features device=0x10330000002 negotiated=0x300000002 access_platform=y
[ 3.368 cpu0 kernel] VirtIO GPU: display 1280x720
[ 3.369 cpu0 kernel] VirtIO GPU: scanout buffer at 0xffff800041c00000 phys=0x41c00000 device=0x41c00000 (3686400 bytes)
[ 3.371 cpu0 kernel] VirtIO GPU: cursor resource at 0xffff800042400000 phys=0x42400000 device=0x42400000
[ 3.371 cpu0 kernel] GPU: using VirtIO
[ 3.372 cpu0 kernel] mouse: rel scale x=36 y=64 (screen 1280x720)
[ 3.372 cpu0 kernel] Boot: devices ready (246ms)
[ 3.372 cpu0 kernel] log: /log is on a disk this kernel does not drive; its file server says whether it mounted
[ 3.372 cpu0 kernel] Boot: complete (1946ms)
[ 3.372 cpu0 kernel] boot: power-on to loader 795 ms, loader 581 ms (ROOT read 177 ms), kernel to Boot: complete 1994 ms
[ 3.372 cpu0 kernel] kthread: klogd pid=1 tid=0 runs in the kernel address space
[ 3.372 cpu7 kernel] counters: cpu7 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.372 cpu7 kernel] CPU 7: joining scheduler
[ 3.372 cpu5 kernel] counters: cpu5 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.372 cpu5 kernel] CPU 5: joining scheduler
[ 3.372 cpu6 kernel] counters: cpu6 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.372 cpu6 kernel] CPU 6: joining scheduler
[ 3.375 cpu0 kernel] pcidev: PCI 00:02.0 NOT HANDED OVER — its interrupts would not be remapped on this machine, and a message that is not remapped can raise any vector on any CPU
[ 3.376 cpu2 kernel] counters: cpu2 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.376 cpu2 kernel] CPU 2: joining scheduler
[ 3.377 cpu0 kernel] spawn: /system/bin/diskserver pid=2 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.377 cpu4 kernel] counters: cpu4 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.377 cpu4 kernel] CPU 4: joining scheduler
[ 3.380 cpu0 kernel] spawn: /system/bin/fileserver pid=3 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.382 cpu0 kernel] spawn: /system/bin/fileserver pid=4 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.384 cpu1 kernel] counters: cpu1 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.384 cpu1 kernel] CPU 1: joining scheduler
[ 3.391 cpu3 kernel] counters: cpu3 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 3.391 cpu3 kernel] CPU 3: joining scheduler
[ 3.443 cpu0 kernel] spawn: /system/bin/fileserver pid=5 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=39ms total=39ms)
[ 3.493 cpu0 kernel] spawn: /system/bin/logkeeper pid=6 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=36ms total=36ms)
[ 3.502 cpu0 kernel] spawn: /system/bin/compositor pid=7 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.508 cpu5 kernel] exit: compositor pid=7 code=101 cpu=5ms peak=10MB allocs=5 frees=0 syscalls=43 syscall_wall=3ms 1=2 6=1 9=2 10=6 13=2 14=3 21=1 50=1 51=1 63=4 72=1 73=2 91=2 99=2 102=4 105=4 106=5
[ 3.511 cpu0 kernel] spawn: /system/bin/soundserver pid=8 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.517 cpu0 kernel] pcidev: PCI 00:05.0 NOT HANDED OVER — its interrupts would not be remapped on this machine, and a message that is not remapped can raise any vector on any CPU
[ 3.374 supervisor] supervisor: build 5a3b74345384de530e5dccf2124f057c29f85bcd clean, committed 2026-10-10 07:49:34 UTC, toolchain b3f5ad494486c67d, aarch64
[ 3.375 supervisor] supervisor: diskserver: pci:1b36:0010 is on this machine and could not be handed over; the kernel's `pcidev:`, `partclaim:`, `isa:` or `acpi:` line says why
[ 3.377 supervisor] supervisor: started diskserver
[ 3.380 supervisor] supervisor: started fileserver
[ 3.382 supervisor] supervisor: started fileserver
[ 3.395 diskserver] diskserver: NOT SERVING — pci:1b36:0010 is on this machine and the kernel refused this service its claim; every partition on it is refused
[ 3.397 diskserver] diskserver: an open of C67C26FD-CDAE-4C7D-B17E-2AFEF91120E2 refused: ClaimRefused
[ 3.400 fileserver] fileserver: the block service would not list its partitions (Refused(ClaimRefused)); DATA is absent this boot
[ 3.520 cpu0 kernel] spawn: /system/bin/netstack pid=9 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=2ms)
[ 3.522 cpu3 kernel] exit: netstack pid=9 code=0 cpu=1ms peak=2MB allocs=2 frees=0 syscalls=11 syscall_wall=0ms 6=1 14=1 50=1 51=1 63=1 72=1 73=2 91=1 99=1 106=1
[ 3.525 cpu0 kernel] spawn: /system/bin/filepicker pid=10 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=2ms total=2ms)
[ 3.531 cpu0 kernel] spawn: /system/bin/acpiserver pid=11 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 3.536 cpu7 kernel] exit: acpiserver pid=11 code=0 cpu=4ms peak=2MB allocs=2 frees=0 syscalls=11 syscall_wall=0ms 6=1 14=1 50=1 51=1 63=1 72=1 73=2 91=1 99=1 106=1
[ 3.400 fileserver] fileserver: Data serving /apps, /config, /home, /state — absent: the block service would not list its partitions (Refused(ClaimRefused))
[ 3.404 fileserver] fileserver: diskserver would not open the partition: Refused(ClaimRefused)
[ 3.404 fileserver] fileserver: Log serving /log — absent: the Log partition C67C26FD-CDAE-4C7D-B17E-2AFEF91120E2 is on no disk this server reaches
[ 3.443 supervisor] supervisor: started fileserver
[ 3.453 supervisor tid=1] supervisor: /home/toy could not be made, so this boot has no session home: permission denied
[ 3.455 supervisor] supervisor: logkeeper: /state/logkeeper could not be made: permission denied
[ 3.471 diskserver] diskserver: an open of 881BB9F5-2B4E-4D4C-99A9-44F3A5E7FD8B refused: ClaimRefused
[ 3.479 fileserver] fileserver: diskserver would not open the partition: Refused(ClaimRefused)
[ 3.479 fileserver] fileserver: Boot serving /boot — absent: the Boot partition 881BB9F5-2B4E-4D4C-99A9-44F3A5E7FD8B is on no disk this server reaches
[ 3.493 supervisor] supervisor: started logkeeper
[ 3.499 supervisor] supervisor: compositor: /state/compositor could not be made: permission denied
[ 3.499 supervisor] supervisor: compositor: no keyboard on this machine
[ 3.499 supervisor] supervisor: compositor: no mouse on this machine
[ 3.502 supervisor] supervisor: started compositor
[ 3.505 compositor error] 
[ 3.505 compositor error] thread 'main' (1) panicked at userland/compositor/src/session.rs:151:14:
[ 3.505 compositor error] the manifest gives this program the keyboard
[ 3.505 compositor error] stack backtrace:
[ 3.508 compositor error]    0:      0x100001a8128 - _Unwind_Backtrace
[ 3.508 compositor error]    1:      0x10000191058 - <<std[d6d2712760615b7]::sys::backtrace::BacktraceLock>::print::DisplayBacktrace as core[f28ba090d62d1c7]::fmt::Display>::fmt
[ 3.508 compositor error]    2:      0x100001adcb0 - core[f28ba090d62d1c7]::fmt::write
[ 3.508 compositor error]    3:      0x10000195868 - <std[d6d2712760615b7]::sys::stdio::toyos::Stderr as core[f28ba090d62d1c7]::io::write::Write>::write_fmt
[ 3.508 compositor error]    4:      0x10000174964 - std[d6d2712760615b7]::panicking::default_hook::{closure#0}
[ 3.508 compositor error]    5:      0x1000018a7c0 - std[d6d2712760615b7]::panicking::default_hook
[ 3.508 compositor error]    6:      0x1000018a984 - std[d6d2712760615b7]::panicking::panic_with_hook
[ 3.508 compositor error]    7:      0x10000174a08 - std[d6d2712760615b7]::panicking::panic_handler::{closure#0}
[ 3.508 compositor error]    8:      0x1000016d378 - std[d6d2712760615b7]::sys::backtrace::__rust_end_short_backtrace::<std[d6d2712760615b7]::panicking::panic_handler::{closure#0}, !>
[ 3.508 compositor error]    9:      0x100001751e0 - __rustc[d0c72ce299f394e5]::rust_begin_unwind
[ 3.508 compositor error]   10:      0x100001ae4dc - core[f28ba090d62d1c7]::panicking::panic_fmt
[ 3.508 compositor error]   11:      0x100001ae208 - core[f28ba090d62d1c7]::option::expect_failed
[ 3.508 compositor error]   12:      0x1000009ed58 - <compositor[8b4d04b91d5c2cb1]::session::Session>::start
[ 3.508 compositor error]   13:      0x1000009876c - compositor[8b4d04b91d5c2cb1]::main
[ 3.508 compositor error]   14:      0x1000009578c - std[d6d2712760615b7]::sys::backtrace::__rust_begin_short_backtrace::<fn(), ()>
[ 3.508 compositor error]   15:      0x100000987ec - std[d6d2712760615b7]::rt::lang_start::<()>::{closure#0}
[ 3.508 compositor error]   16:      0x10000189ecc - std[d6d2712760615b7]::rt::lang_start_internal
[ 3.508 compositor error]   17:      0x100000987cc - main
[ 3.508 compositor error]   18:      0x1000018f0b8 - std[d6d2712760615b7]::sys::pal::toyos::start_rust
[ 3.508 compositor error]   19:      0x1000016399c - _start
[ 3.509 supervisor] supervisor: soundserver: /state/soundserver could not be made: permission denied
[ 3.509 supervisor] supervisor: soundserver: no hda-audio on this machine
[ 3.509 supervisor] supervisor: soundserver: no virtio-sound on this machine
[ 3.511 supervisor] supervisor: started soundserver
[ 3.516 soundserver] soundserver: no audio device, presenting a null sink (44100Hz 2ch, 128 frames/period, streams discarded)
[ 3.517 logkeeper] logkeeper: cannot create /log/unknown-00.log: permission denied
[ 3.517 logkeeper] logkeeper: no /log on this machine - this boot's kernel log is on the console only (undated: this machine will not say what time it is)
[ 3.517 supervisor] supervisor: netstack: /state/netstack could not be made: permission denied
[ 3.517 supervisor] supervisor: netstack: pci:1af4:1041 is on this machine and could not be handed over; the kernel's `pcidev:`, `partclaim:`, `isa:` or `acpi:` line says why
[ 3.518 soundserver] soundserver: null sink idle
[ 3.520 supervisor] supervisor: started netstack
[ 3.522 netstack] netstack: no NIC on this machine, exiting
[ 3.522 supervisor] supervisor: filepicker: /state/filepicker could not be made: permission denied
[ 3.525 supervisor] supervisor: started filepicker
[ 3.529 supervisor] supervisor: acpiserver: /state/acpiserver could not be made: permission denied
[ 3.529 supervisor] supervisor: acpiserver: no acpi on this machine
[ 3.531 supervisor] supervisor: started acpiserver
[ 3.536 acpiserver] acpiserver: no acpi claim, so the machine stays in the mode its firmware handed over
PL011, whole (210 lines; the console above carries the kernel's record from the start)
UEFI firmware (version edk2-stable202408-prebuilt.qemu.org built at 16:28:50 on Sep 12 2024)
ArmTrngLib could not be correctly initialized.
Error: Image at 000BFDB6000 start failed: 00000001
Error: Image at 000BFD6D000 start failed: Not Found
Error: Image at 000BFCBA000 start failed: Unsupported
Error: Image at 000BFC3F000 start failed: Not Found
Error: Image at 000BFB65000 start failed: Aborted
Tpm2SubmitCommand - Tcg2 - Not Found
Tpm2GetCapabilityPcrs fail!
Tpm2SubmitCommand - Tcg2 - Not Found
Image type X64 can't be loaded on AARCH64 UEFI system.
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HUsbBootExecCmd: Success to Exec 0x0 Cmd (Result = 1)
BdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
ConvertPages: failed to find range 140000000 - 14003FFFF
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE 1-0000:00:01.0-1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01HConvertPages: failed to find range 8000000 - 8003FFF
[ 0.800 cpu0 loader] ToyOS Bootloader 1.0
[ 0.802 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 0.810 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 0.815 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 0.818 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-Ie1c3621a5aba3ea3 (image scope) holds 0
[ 0.821 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 0.840 cpu0 loader] RSDP address: 0xbcb43018
[ 0.843 cpu0 loader] Boot partition: LBA 2048+69632 signature [f5, b9, 1b, 88, 4e, 2b, 4c, 4d, 99, a9, 44, f3, a5, e7, fd, 8b]
[ 0.848 cpu0 loader] Log partition: signature [fd, 26, 7c, c6, ae, cd, 7d, 4c, b1, 7e, 2a, fe, f9, 11, 20, e2]
[ 0.875 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B present; the floor is 0
[ 0.893 cpu0 loader] Slot A: signed header d057d8b86b2fefaada91644d314213f398a0716fe9fc49cf3f3b040540c3947f verifies under this loader's key, version 1791623197
[ 1.091 cpu0 loader] ROOT: read into memory at 0xb88d6000+0x3c00000 from LBA 212992+122880, 1048576 bytes a request (optimal granularity: not reported), in 4255155 counter ticks
[ 1.229 cpu0 loader] Slot A: ROOT hashed in 3161177 counter ticks
[ 1.232 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 1.237 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 1.241 cpu0 loader] Kernel: 2452800 bytes
[ 1.244 cpu0 loader] Boot parameter: "root=e50e07dacc89a65f712a22d21874d893,boot-slot=A"
[ 1.248 cpu0 loader] Loading kernel elf...
[ 1.250 cpu0 loader] Kernel stack size: 8388608
[ 1.252 cpu0 loader] Kernel memory size: 13664256
[ 1.258 cpu0 loader] Kernel memory located at: 0xb7a00000
[ 1.261 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 465168 }, filesz: 465168, file_offset: 0, flags: SegmentFlags(4) }
[ 1.267 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 532480, len: 1024272 }, filesz: 1024272, file_offset: 466944, flags: SegmentFlags(5) }
[ 1.279 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1622288, len: 3824 }, filesz: 240, file_offset: 1491216, flags: SegmentFlags(6) }
[ 1.291 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1688064, len: 3586440 }, filesz: 26456, file_offset: 1491456, flags: SegmentFlags(6) }
[ 1.298 cpu0 loader] Applied 2789 relocations
[ 1.303 cpu0 loader] GOP: 1280x720 is Blt-only, so this display publishes no framebuffer
[ 1.307 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 1.313 cpu0 loader] Starting kernel...
[ 1.315 cpu0 loader] CPU: entered at EL1
[ 1.317 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 1.324 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.330 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.335 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 1.341 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 1.347 cpu0 loader] Scanout: this machine has none
[ 1.350 cpu0 loader] Loader image: 0xbc730000+0x40000, mapped at identity as 0xbc600000+0x200000
[ 1.357 cpu0 loader] Boot map: root 0xb79bf000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 1.360 cpu0 loader] Kernel image: 0xb7a00000+0xd08000 is inside the 0x100000000-byte boot map
[ 1.366 cpu0 loader] Parameter buffer: 0xbcb40818+0x31 is inside the 0x100000000-byte boot map
[ 1.371 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 1.373 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 1.377 cpu0 loader] Loader counter: 19099578 at entry, 33065212 at the handoff
[ 1.381 cpu0 loader] Loader log: the kernel handoff begins, so this file ends here
[ 1.395 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 1.395 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 1.396 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.397 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 1.398 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 1.398 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 1.398 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 1.399 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 1.399 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 1.399 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 1.400 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 1.400 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 1.400 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 1.401 cpu0 kernel] memory: 0x000048000000..0x0000b79bb000 uefi type 7
[ 1.401 cpu0 kernel] memory: 0x0000b79bb000..0x0000bc730000 uefi type 2
[ 1.401 cpu0 kernel] memory: 0x0000bc730000..0x0000bc770000 uefi type 1
[ 1.402 cpu0 kernel] memory: 0x0000bc770000..0x0000bc7f0000 uefi type 5
[ 1.402 cpu0 kernel] memory: 0x0000bc7f0000..0x0000bc960000 uefi type 6
[ 1.402 cpu0 kernel] memory: 0x0000bc960000..0x0000bc9b0000 uefi type 5
[ 1.403 cpu0 kernel] memory: 0x0000bc9b0000..0x0000bca50000 uefi type 6
[ 1.403 cpu0 kernel] memory: 0x0000bca50000..0x0000bcb40000 uefi type 5
[ 1.403 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 1.403 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 1.404 cpu0 kernel] memory: 0x0000bcb44000..0x0000bd833000 uefi type 7
[ 1.404 cpu0 kernel] memory: 0x0000bd833000..0x0000beea2000 uefi type 4
[ 1.404 cpu0 kernel] memory: 0x0000beea2000..0x0000beea3000 uefi type 7
[ 1.405 cpu0 kernel] memory: 0x0000beea3000..0x0000beea4000 uefi type 4
[ 1.405 cpu0 kernel] memory: 0x0000beea4000..0x0000beef5000 uefi type 7
[ 1.405 cpu0 kernel] memory: 0x0000beef5000..0x0000bfa38000 uefi type 4
[ 1.406 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb94000 uefi type 7
[ 1.406 cpu0 kernel] memory: 0x0000bfb94000..0x0000bfe20000 uefi type 3
[ 1.406 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 1.407 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 1.407 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 1.407 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 1.407 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 1.408 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 1.408 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 1.408 cpu0 kernel] memory: 35 ranges, as the loader handed them over
[ 1.409 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 1.409 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 1.409 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=2 mpidr=0x2 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=3 mpidr=0x3 enabled=true gicr=0x0
[ 1.410 cpu0 kernel] ACPI: MADT GICC uid=4 mpidr=0x4 enabled=true gicr=0x0
[ 1.411 cpu0 kernel] ACPI: MADT GICC uid=5 mpidr=0x5 enabled=true gicr=0x0
[ 1.411 cpu0 kernel] ACPI: MADT GICC uid=6 mpidr=0x6 enabled=true gicr=0x0
[ 1.412 cpu0 kernel] ACPI: MADT GICC uid=7 mpidr=0x7 enabled=true gicr=0x0
[ 1.412 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 1.412 cpu0 kernel] ACPI: MADT names 8 GIC CPU interfaces, 8 enabled
[ 1.412 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 1.413 cpu0 kernel] boot: memory map 0xb79bd018+0x348, kernel 0xb7a00000+0xd08000, stack image+0x508000+0x800000
[ 1.413 cpu0 kernel] boot: kernel elf 0xbc4d6018+0x256d40, rsdp 0xbcb43018, boot pml4 0xb79bf000
[ 1.414 cpu0 kernel] boot: gop 0x0+0x0 0x0 stride 0 format 0
[ 1.414 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [f5, b9, 1b, 88, 4e, 2b, 4c, 4d, 99, a9, 44, f3, a5, e7, fd, 8b]
[ 1.415 cpu0 kernel] boot: log partition guid [fd, 26, 7c, c6, ae, cd, 7d, 4c, b1, 7e, 2a, fe, f9, 11, 20, e2]
[ 1.415 cpu0 kernel] boot: cmdline 0xbcb40818+49
[ 1.416 cpu0 kernel] boot: root=e50e07dacc89a65f712a22d21874d893
[ 1.416 cpu0 kernel] boot: slot A, the one the slot table marks
[ 1.416 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 1.416 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 1.417 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 1.417 cpu0 kernel] pmm: the firmware map calls 2141704192 bytes usable in 25 entries; managed=2044723200 withheld=79691776 unaligned=17289216, and the three sum to it; frames=975 reserved_frames=38 base=0x40000000 span=1023
[ 1.419 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1020 2 MiB blocks and 640 4 KiB pages
[ 1.420 cpu0 kernel] ACPI: APIC at 0xbcb43098 len=748 rev=4 oem="BOCHS" checksummed
[ 1.420 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: GTDT at 0xbcb43e18 len=104 rev=3 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: SPCR at 0xbcb43a98 len=80 rev=2 oem="BOCHS" checksummed
[ 1.421 cpu0 kernel] ACPI: MCFG at 0xbcb43498 len=60 rev=1 oem="BOCHS" checksummed
[ 1.422 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 1.422 cpu0 kernel] PSCI: 1.1 through HVC
[ 1.423 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 1.423 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 1.423 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 1.423 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 1.424 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 1.424 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 1.425 cpu0 kernel] symbols: loaded 17534 kernel symbols
[ 1.426 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 1.426 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 1.426 cpu0 kernel] Boot: CPU ready (1ms)
[ 1.427 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 1.427 cpu0 kernel] ACPI: MCFG found at 0xbcb43498
[ 1.427 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 1.427 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 1.428 cpu0 kernel] PCI: Enumerating devices...
[ 1.428 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 1.428 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000014000]
[ 1.429 cpu0 kernel]   PCI 00:02.0 [0108] vendor=1b36 device=0010 prog_if=02 bars=[bar0=0x8000018000 bar4=0x10045000]
[ 1.429 cpu0 kernel]   PCI 00:03.0 [0380] vendor=1af4 device=1050 prog_if=00 bars=[bar1=0x10044000 bar4=0x8000000000]
[ 1.430 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10043000 bar4=0x8000004000]
[ 1.430 cpu0 kernel]   PCI 00:05.0 [0200] vendor=1af4 device=1041 prog_if=00 bars=[bar1=0x10042000 bar4=0x8000008000]
[ 1.431 cpu0 kernel]   PCI 00:06.0 [0401] vendor=1af4 device=1059 prog_if=00 bars=[bar1=0x10041000 bar4=0x800000c000]
[ 1.431 cpu0 kernel]   PCI 00:07.0 [0780] vendor=1af4 device=1043 prog_if=00 bars=[bar1=0x10040000 bar4=0x8000010000]
[ 1.440 cpu0 kernel] PCI: Enumeration complete, 8 functions.
[ 1.442 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 1.443 cpu0 kernel] pcidev: 8 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 1.444 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 1.444 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 1.444 cpu0 kernel] pcidev:   0x9011000..0x10040000 (112 MiB)
[ 1.445 cpu0 kernel] pcidev:   0x10046000..0x40000000 (767 MiB)
[ 1.445 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 1.445 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 1.446 cpu0 kernel] pcidev:   0x800001a000..0xffffffffffffffff (17592185520127 MiB)
[ 1.446 cpu0 kernel] IOMMU: the SMMUv3 is the port's stage 6; no device is translated this boot
[ 1.446 cpu0 kernel] file cache: budget 7800 pages (30 MiB)
[ 1.447 cpu0 kernel] gpt: the boot volume names C67C26FD-CDAE-4C7D-B17E-2AFEF91120E2 as the log partition
[ 1.447 cpu0 kernel] gpt: firmware booted us from partition 881BB9F5-2B4E-4D4C-99A9-44F3A5E7FD8B at LBA 2048+69632
[ 1.448 cpu0 kernel] Boot: peripherals ready (21ms)
[ 1.448 cpu1 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.450 cpu1 kernel] GIC: this CPU's redistributor at 0x80c0000, its SGIs and timer enabled
[ 1.451 cpu0 kernel] SMP: cpu1 mpidr=0x1 online
[ 1.451 cpu2 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.452 cpu2 kernel] GIC: this CPU's redistributor at 0x80e0000, its SGIs and timer enabled
[ 1.453 cpu0 kernel] SMP: cpu2 mpidr=0x2 online
[ 1.454 cpu3 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.455 cpu3 kernel] GIC: this CPU's redistributor at 0x8100000, its SGIs and timer enabled
[ 1.457 cpu0 kernel] SMP: cpu3 mpidr=0x3 online
[ 1.458 cpu4 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.459 cpu4 kernel] GIC: this CPU's redistributor at 0x8120000, its SGIs and timer enabled
[ 1.460 cpu0 kernel] SMP: cpu4 mpidr=0x4 online
[ 1.460 cpu5 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.462 cpu5 kernel] GIC: this CPU's redistributor at 0x8140000, its SGIs and timer enabled
[ 1.463 cpu0 kernel] SMP: cpu5 mpidr=0x5 online
[ 1.477 cpu6 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.478 cpu6 kernel] GIC: this CPU's redistributor at 0x8160000, its SGIs and timer enabled
[ 1.478 cpu0 kernel] SMP: cpu6 mpidr=0x6 online
[ 1.495 cpu7 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1
[ 1.506 cpu7 kernel] GIC: this CPU's redistributor at 0x8180000, its SGIs and timer enabled
[ 1.583 cpu0 kernel] SMP: cpu7 mpidr=0x7 online
[ 1.583 cpu0 kernel] SMP: 8 of 8 MADT CPUs online
[ 1.584 cpu0 kernel] root: mounted read-only from memory at 0xb88d6000+0x3c00000, filesystem e50e07dacc89a65f712a22d21874d893, 15360 blocks
[ 1.584 cpu0 kernel] Boot: subsystems ready (136ms)
[ 1.586 cpu0 kernel] spawn: /system/bin/supervisor pid=0 unresolved=0 (layout=0ms relocs=0ms deps=0ms tls=1ms total=1ms)
[ 1.587 cpu0 kernel] spawned /system/bin/supervisor pid=0
[ 1.587 cpu0 kernel] boot: the supervisor spawned with ROOT from memory; storage commands before it: 0
[ 1.588 cpu0 kernel] xHCI: found at PCI 00:01.0 1033:0194
[ 1.604 cpu0 kernel] xHCI: BAR0=0x8000014000
[ 1.611 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 1.612 cpu0 kernel] PCI 00:01.0: not armed — AArch64 delivers no message-signalled interrupt to this kernel: the GICv3 ITS is unported
[ 1.613 cpu0 kernel] xHCI: NOT INITIALISED at PCI 00:01.0 — the controller offers neither MSI-X nor MSI, and this driver has no other way to be told it has anything to say. No USB device on it can be used.
[ 1.616 cpu0 kernel] xHCI: 1 controller(s) present, none of them usable, USB unavailable
[ 3.117 cpu0 kernel] usb-storage: 0 disk(s) on this machine and none carries the boot partition after 1500 ms of looking
[ 3.118 cpu0 kernel] root: the partition ROOT was read from, A03EF61C-A218-408D-937C-C7A86F348603, is not held because it is on no disk this kernel drives; every claim of it is refused; disks that did not answer: []
[ 3.124 cpu0 kernel] Boot: storage ready (1536ms)
[ 3.125 cpu0 kernel] virtio-console: found at PCI 00:07.0
[ 3.126 cpu0 kernel] iommu: no domain of its own for a device: no unit on this machine translates
[ 3.126 cpu0 kernel] VirtIO: PCI 00:07.0 names BAR 0 and firmware assigned it no address — skipping every capability in it
[ 3.127 cpu0 kernel] mmio: 0x8000010000+0x4000 Uncacheable
[ 3.128 cpu0 kernel] VirtIO: PCI 00:07.0 features device=0x10330000004 negotiated=0x300000000 access_platform=y

@Japabu Japabu changed the title The SMMUv3 comes up from the IORT with every stream aborting, and its events reach the handler on their wired SPI The SMMUv3 comes up from the IORT with every stream aborting and every unrouted one recorded, and both IOMMU backends read one fault policy and one address window Oct 10, 2026
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #825 at 9490bcfdf against .claude/agents/reviewer.md. This is round 2. It reviews the changes since 562fc3a9e, the merges of origin/main aside.

Round-1 BLOCKERs

  • Every SMMUv3 aborting before a multi-unit refusal: CLOSED. smmu/mod.rs:230-253 runs abort_unprogrammed on every unit the IORT names before any refusal. virt has one unit, so this rests on a reading of the code against IHI 0070. I accept that.
  • EVENTQ_IRQ_CFG0 never written: CLOSED. smmu/mod.rs:304-309 clears and acks IRQ_CTRL, then zeroes GERROR_IRQ_CFG0 and EVENTQ_IRQ_CFG0, and PRIQ_IRQ_CFG0 where IDR0.PRI is set. The offsets are held on the host (encodings.rs). QEMU sends no MSI, so this too rests on a reading. I accept that.
  • Two answers for one unrouted condition: CLOSED as asked. An invalid entry and RECINVSID both record. nc7 (every entry Ste::ABORT) reds with 1 events reached the handler, not 2 (control-nc7-every-entry-aborting.log). The answer chosen is the subject of the first new BLOCKER below.
  • unmap's invalidation untested: CLOSED. nc6 (issue(&[..][..0])) reds with … again, which its domain no longer maps, answered 0x0: FAIL (control-nc6-unmap-no-tlbi.log, head 9490bcfdf).
  • Sibling fault policy and window: CLOSED. Both now live once, in kernel/src/iommu/fault.rs and window.rs, and both backends read them. rg 'fn handed_out|fn ceiling' kernel/src/arch prints nothing.
  • Evidence, cargo run --arch aarch64 booted: CLOSED. Both boots are posted with their argv. Each ends at the same compositor panic. At this head virtio-console, virtio-sound and virtio-gpu are on domains 1-3 and no DMA FAULT appears.

I read the x86 side line by line against origin/main's vtd/fault.rs and found it unchanged:

  • The format string matches character for character. Who::Function's Display is StreamId's, and Blamed/Owner print the same words.
  • The order is unchanged: the address is read before BME, then BME, the counts, FIRST, the owner, note_fault and the line.
  • conclude still runs before apic::eoi.
  • An unenumerated requester still prints bme=unknown-function domain=unknown owner=kernel and halts.
  • Window::new refuses where Domain::new did.

Ruling: unrouted streams

Aborted and recorded, yes. Halting, no, on either backend.

  • kernel/src/iommu/fault.rs:214 returns owner.is_none(), and that is true for function == None. So a record that names no enumerated function halts the machine, on VT-d (main's behaviour) and now on the SMMUv3.
  • Root CLAUDE.md's "fail fast" answers a defect in this kernel. A function the kernel itself drives that faults is such a defect, and halting on it stays right. A requester the kernel never enumerated is not this kernel's code. It is a device's input that crossed the trust boundary the unit exists to hold, and the unit already refused it. "Input that crossed a trust boundary … is refused", and here it has been. Halting on top of that turns a refused input into a machine-wide outage.
  • A hot-plugged or USB4/Thunderbolt function, which is the classic DMA-attack shape, would then halt the machine at will. Once a claim can enable VFs, so could a process, which breaks "the kernel never crashes from userland".
  • QEMU's ignoring of RECINVSID argues only about recording, and recording can stay. Once neither path halts, it no longer matters whether an out-of-range StreamID is recorded or silent.

The right answer for both backends:

  1. Halt only on Some(function) with no user slot.
  2. A record naming no enumerated function is counted and logged under an owner word of its own, which tests/common/serial.rs does not read as a death, and the machine goes on.
  3. Not halting removes the only stop such a stream had, because BME cannot be cleared on a function nobody enumerated. So the handler's work per interrupt must be bounded by something other than the device. VT-d already is: at most CAP.NFR records per interrupt. The SMMUv3 is not (next finding).

BLOCKER

  • kernel/src/iommu/fault.rs:214 with smmu/selftest.rs:15-17 and tests/toyos.rs:2028-2036 — an unrouted stream's refused write halts the machine. — Untrusted device input takes the machine down. The SMMUv3 half is new in this branch, and the shared predicate makes this one fix for both backends. Fix:
    • Make report answer "halt" only for an enumerated, kernel-driven function, and give the unrouted record its own owner word.
    • In the selftest, make the unrouted writer write twice and assert two records with the machine still running. Then make the kernel-owned F_TRANSLATION write last, as the halting one.
  • kernel/src/arch/aarch64/smmu/fault.rs:67-88 — the drain loops until EVENTQ_PROD reads equal to CONS, with no bound. A device that keeps writing keeps the handler in the interrupt forever, preempt count raised, logging a line per record, and the CPU neither halts nor returns. A function honouring a cleared BME stops, but an unrouted stream has no BME to clear, and the PR body itself names a function that ignores BME. The round-1 NOTE asked for "drain until empty or record why the budget is safe"; until-empty without a bound swaps a stranded record for a livelock. Fix: drain at most the queue's 1 << events_log2 records per interrupt. If records remain, re-pend the SPI (GICD_ISPENDR) before end, so no edge is lost and the CPU leaves the handler between batches. Keep nc8 red.
  • tests/toyos.rs:2052 — virt_smmu returns at the line carrying unitfaults=2. The selftest's FAIL: … the machine went on panic (selftest.rs:143) comes after that line and is never read, so the halt the test's doc claims is not asserted. Patch kernel/src/iommu/fault.rs:231, - if kernel_owned > 0 { → + if kernel_owned > usize::MAX - 1 {, and run cargo test --test toyos-build -- virt_smmu. I expect it green. It must turn red: read on until the guest is silent after a death line, or until the selftest's FAIL line, whichever comes first. This applies to whichever record is the halting one once the first BLOCKER is fixed.
  • Evidence — the VT-d domain window and fault policy moved, and the T14 reading of boot:testcases at 9490bcfdf is staged and not yet read (metal-readback.log, exit 2, "The machine was not touched"). This stays open until the orchestrator posts that run: its command, exit code and log, at this head or at the head that fixes the above.

NOTE

  • kernel/src/arch/aarch64/smmu/mod.rs:152 — Live::stream panics when a kernel driver's DeviceSpace::create succeeds and its function is enumerated but the IORT routes it elsewhere or its route was refused (mod.rs:268-269). A firmware table's gap then becomes a kernel panic at attach, where it should be a refusal at create. It is not reachable on virt. Refuse Own for a function this unit does not route, or file it.
  • toyos-smmu/tests/encodings.rs each_event_is_named_by_its_own_mnemonic — a second copy of Code::name's match, which a reader checks against §7.3 headings. Delete it. The two names a gate reads are already held by virt_smmu (F_TRANSLATION, C_BAD_STE).
  • PR body, "What I am unsure of", says the drain runs on without bound and a halt hits every unrouted stream. Both are compromises that are neither removed nor filed. The BLOCKERs above remove them.

SEND BACK

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

T14 at 9490bcfdf, run by the orchestrator: boot:testcases, two boots (testcases f5d1dc74…ea3c96b5, testcases-watchdog 4b9420cb…836092d67, hashes checked against request.txt), each toyos-metal --fat32-check exit 0; judge cargo test --test toyos-build -- --metal --metal-readback <dir> boot:testcases: EXIT=0, [metal] 249 passed, 0 failed, 2 boot(s) (VT-d's moved fault policy and window on hardware). Superseded by the fix round, which changes the shared fault predicate.

Japabu and others added 2 commits October 10, 2026 11:21
…805), into the SMMUv3 bring-up

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…goes on; the SMMUv3 reads at most a queue's worth of events per interrupt

The shared fault policy halted on every record with no user owner, and
that included a record naming no enumerated function: a requester this
kernel never took on, whose write the unit had already refused. A
hot-plugged function, a VF a claimed PF enabled, or any device writing
under a StreamID no route names could then halt the machine at will.
Fail-fast answers a defect of this kernel; a refused device input is
not one. `report` now answers "halt" only for an enumerated function
this kernel drives, and a record naming none is logged under
`owner=none`, which the harness reads as a record (never clean) and not
as a death. The VT-d line is unchanged but for that word, and an
unenumerated requester on VT-d no longer halts.

Nothing can clear `BME` on a requester nobody enumerated, so the
handler's work per interrupt is bounded by itself: VT-d's already reads
at most `CAP.NFR` records, and the SMMUv3's drain now reads at most the
queue's entries per interrupt and, if records remain, pends its SPI
again through `GICD_ISPENDR`, because the unit raises no edge for a
record left behind (IHI 0070 H.a §3.18.2).

`smmu-selftest` now has the unrouted testdev write twice, both read in
one drain, and says the machine went on; the kernel-driven function's
write on its taken-back address comes last and is the halting one.
`virt_smmu` reads on to `panic_reboot::arm`'s line, which the halt path
writes once every other CPU is stopped, and reds on a `FAIL` line or
any death but the record: before, it returned at the record and never
read the selftest's "the machine went on" panic.

`toyos-smmu`'s per-mnemonic name test is deleted: it was a second copy
of `Code::name`'s match, and the two names a gate reads are held by
`virt_smmu`. A function the SMMUv3 does not route still panics at
`attach` rather than being refused at `create`; filed with an owner and
an exit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Negative controls for round 3, at 93c4107c8. Each patch was checked with git apply --check, applied, run through cargo test --test toyos-build -- virt_smmu, and restored in the same script (git checkout HEAD -- ., git clean -fd kernel toyos-smmu, then git status --porcelain --ignore-submodules=none read empty after each). nc4 is git diff 93c4107c8 origin/main -- kernel toyos-smmu Cargo.lock (origin/main at a1eb2c0b9, the base this head merged), 2583 lines, not reproduced. nc1-nc3 and nc5-nc7 are round 2's patches unchanged; nc8 is redefined for the bounded drain. nc11 is the one arm meant to stay green: it shows the GICD_ISPENDR re-pend delivers what a drain left behind, and nc8 is the same patch without the re-pend.

Control Exit Verdict
nc9-conclude-never-halts (the review's mutation) 1 smmu-selftest: FAIL: the handler read the event of a function this kernel drives and the machine went on
nc10-unrouted-halts (round 2's predicate: halt on every record without a user owner) 1 the selftest never said "which its domain no longer maps": the machine halted on the first owner=none record
nc8-one-record-not-repended (drain bound 1, no re-pend) 1 smmu-selftest: FAIL: the handler had read 1 events, not 2, 1000ms … after the unrouted function's two refused writes
nc11-one-record-repended (drain bound 1, re-pend kept) 0 green: three records, the second read on the re-pended SPI
nc1-gbpa-bypass 1 GBPA does not read back aborting: Some(4096)
nc2-ste-bypass 1 … on the entry its stream starts with, answered 0x0: FAIL
nc3-no-event-irq 1 smmu-selftest: FAIL: the handler had read 0 events, not 2 …
nc5-spi-not-enabled 1 smmu-selftest: FAIL: the handler had read 0 events, not 2 …
nc6-unmap-no-tlbi 1 smmu-selftest: FAIL: the handler had read 2 events, not 3 … after the kernel-driven function's refused write
nc7-every-entry-aborting 1 smmu-selftest: FAIL: the handler had read 0 events, not 2 …
nc4-whole-change-reverted 1 "smmu-selftest" is a kernel_params and the kernel declares no such actuator or parameter
nc9-conclude-never-halts.patch
diff --git a/kernel/src/iommu/fault.rs b/kernel/src/iommu/fault.rs
index 8c6eb26e6..54615c5ca 100644
--- a/kernel/src/iommu/fault.rs
+++ b/kernel/src/iommu/fault.rs
@@ -234,7 +234,7 @@ pub fn report(unit: usize, count: &AtomicU32, fault: Fault) -> bool {
 /// other drivers are untouched — goes on. A requester nobody enumerated has
 /// no driver here to be wrong, and the unit already refused what it sent.
 pub fn conclude(kernel_owned: usize) {
-    if kernel_owned > 0 {
+    if kernel_owned > usize::MAX - 1 {
         crate::drivers::panic_console::capture();
         crate::panic::halt_all_cpus();
     }
nc10-unrouted-halts.patch
diff --git a/kernel/src/iommu/fault.rs b/kernel/src/iommu/fault.rs
index 8c6eb26e6..289be3913 100644
--- a/kernel/src/iommu/fault.rs
+++ b/kernel/src/iommu/fault.rs
@@ -216,7 +216,7 @@ pub fn report(unit: usize, count: &AtomicU32, fault: Fault) -> bool {
         if FIRST.load(Ordering::Relaxed) == key { 'y' } else { 'n' },
         fault.name,
     );
-    matches!(owner, Owner::Kernel)
+    !matches!(owner, Owner::Slot(_))
 }
 
 /// The end of a drain that read `kernel_owned` faults on functions this kernel
nc8-one-record-not-repended.patch
diff --git a/kernel/src/arch/aarch64/smmu/fault.rs b/kernel/src/arch/aarch64/smmu/fault.rs
index 995602fd0..9b715459c 100644
--- a/kernel/src/arch/aarch64/smmu/fault.rs
+++ b/kernel/src/arch/aarch64/smmu/fault.rs
@@ -67,7 +67,7 @@ pub fn service() {
     let mut kernel_owned = 0usize;
     let mut cons = regs.read(reg::EVENTQ_CONS);
     let mut prod = regs.read(reg::EVENTQ_PROD);
-    for _ in 0..events.entries() {
+    for _ in 0..1 {
         if events.is_empty(prod, cons) {
             break;
         }
@@ -93,7 +93,6 @@ pub fn service() {
         prod = regs.read(reg::EVENTQ_PROD);
     }
     if !events.is_empty(prod, cons) {
-        super::super::irqchip::pend_iommu_events();
     }
     let errors = reg::active_errors(regs.read(reg::GERROR), regs.read(reg::GERRORN));
     if errors & reg::GERROR_EVENTQ_ABORT != 0 {
nc11-one-record-repended.patch
diff --git a/kernel/src/arch/aarch64/smmu/fault.rs b/kernel/src/arch/aarch64/smmu/fault.rs
index 995602fd0..19f7966a2 100644
--- a/kernel/src/arch/aarch64/smmu/fault.rs
+++ b/kernel/src/arch/aarch64/smmu/fault.rs
@@ -67,7 +67,7 @@ pub fn service() {
     let mut kernel_owned = 0usize;
     let mut cons = regs.read(reg::EVENTQ_CONS);
     let mut prod = regs.read(reg::EVENTQ_PROD);
-    for _ in 0..events.entries() {
+    for _ in 0..1 {
         if events.is_empty(prod, cons) {
             break;
         }
nc1-gbpa-bypass.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..5f68e1756 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -286,13 +286,8 @@ pub fn init(rsdp_addr: u64, devices: &[PciDevice], windows: &[toyos_abi::boot::R
 fn abort_unprogrammed(regs: Registers, base: u64) {
     let gbpa = || regs.read(reg::GBPA);
     regs.wait("GBPA free to update", || gbpa() & reg::GBPA_UPDATE == 0);
-    regs.write(reg::GBPA, gbpa() | reg::GBPA_ABORT | reg::GBPA_UPDATE);
+    regs.write(reg::GBPA, (gbpa() & !reg::GBPA_ABORT) | reg::GBPA_UPDATE);
     regs.wait("GBPA updated", || gbpa() & reg::GBPA_UPDATE == 0);
-    assert!(
-        gbpa() & reg::GBPA_ABORT != 0,
-        "SMMU: GBPA reads {:#x} after ABORT was written: transactions bypass while SMMUEN is clear",
-        gbpa()
-    );
     let cr0 = regs.read(reg::CR0);
     if cr0 != 0 {
         log!("IOMMU: the SMMUv3 at {base:#x} was handed over with CR0 {cr0:#x}; it goes off first");
nc2-ste-bypass.patch
diff --git a/toyos-smmu/src/config.rs b/toyos-smmu/src/config.rs
index 6c28c1b4c..0995a79c4 100644
--- a/toyos-smmu/src/config.rs
+++ b/toyos-smmu/src/config.rs
@@ -26,7 +26,7 @@ impl Ste {
     /// `V` set and `Config` `0b000`: every transaction of the stream is
     /// aborted, and no event is recorded for it. An entry of all zeroes
     /// aborts too, and records `C_BAD_STE` each time.
-    pub const ABORT: Self = Self([STE_V, 0, 0, 0, 0, 0, 0, 0]);
+    pub const ABORT: Self = Self([STE_V | 0b100 << 1, 0, 0, 0, 0, 0, 0, 0]);
 
     /// The stream translated by stage 1 through the one context descriptor
     /// at `context`: `S1ContextPtr` [55:6], `S1CDMax` [63:59] zero so a
nc3-no-event-irq.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..005776da1 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -402,7 +402,6 @@ fn program(
     regs.write(reg::EVENTQ_CONS, 0);
     fault::arm(regs, window(events_at, 32 << events_log2), events, &live.routes);
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN, "its event queue enabled");
-    regs.control(reg::IRQ_CTRL, reg::IRQ_EVENTQ, "its event interrupt enabled");
     regs.control(reg::CR0, reg::CR0_CMDQEN | reg::CR0_EVENTQEN | reg::CR0_SMMUEN, "SMMUEN");
 
     log!(
nc5-spi-not-enabled.patch
diff --git a/kernel/src/arch/aarch64/irqchip.rs b/kernel/src/arch/aarch64/irqchip.rs
index 04ec59f72..717a6a712 100644
--- a/kernel/src/arch/aarch64/irqchip.rs
+++ b/kernel/src/arch/aarch64/irqchip.rs
@@ -321,7 +321,6 @@ pub(super) fn route_iommu_events(intid: u32) -> Result<(), u32> {
     gicd.write_u64(GICD_IROUTER + 8 * u64::from(intid), toyos_gicv3::unpacked_affinity(cpu::hardware_id()));
     gicd.write_u32(GICD_ICPENDR + word, bit);
     IOMMU_EVENTS.store(intid, Relaxed);
-    gicd.write_u32(GICD_ISENABLER + word, bit);
     Ok(())
 }
 
nc6-unmap-no-tlbi.patch
diff --git a/kernel/src/arch/aarch64/smmu/domain.rs b/kernel/src/arch/aarch64/smmu/domain.rs
index 4b61ff63c..4afeab440 100644
--- a/kernel/src/arch/aarch64/smmu/domain.rs
+++ b/kernel/src/arch/aarch64/smmu/domain.rs
@@ -167,7 +167,7 @@ pub fn unmap(id: DomainId, at: Iova, bytes: u64) -> Result<(), IommuError> {
         }
     }
     // Whatever was cleared before a refusal is gone from the unit too.
-    live.issue(&[Command::InvalidateAsid(asid)]);
+    live.issue(&[Command::InvalidateAsid(asid)][..0]);
     result
 }
 
nc7-every-entry-aborting.patch
diff --git a/kernel/src/arch/aarch64/smmu/mod.rs b/kernel/src/arch/aarch64/smmu/mod.rs
index 6df76be26..ee74eb7e7 100644
--- a/kernel/src/arch/aarch64/smmu/mod.rs
+++ b/kernel/src/arch/aarch64/smmu/mod.rs
@@ -358,9 +358,9 @@ fn program(
     let streams = window(table, 64 << log2);
     // Every other entry stays zero, invalid: a stream no function is routed
     // from is recorded, as one past the table is.
-    for (_, stream) in &routes {
+    for stream in 0..1u32 << log2 {
         for (i, word) in Ste::ABORT.words().iter().enumerate() {
-            streams.write_u64(u64::from(*stream) * 64 + 8 * i as u64, *word);
+            streams.write_u64(u64::from(stream) * 64 + 8 * i as u64, *word);
         }
     }
     let (commands_log2, events_log2) =

@Japabu Japabu changed the title The SMMUv3 comes up from the IORT with every stream aborting and every unrouted one recorded, and both IOMMU backends read one fault policy and one address window The SMMUv3 comes up from the IORT with every stream aborting, and both IOMMU backends read one fault policy, which halts only for a function this kernel drives, and one address window Oct 10, 2026
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

T14 reading at 93c4107c8, run by the orchestrator from metal-r2/request.txt. It covers two images, and each image's sha256 was checked in the same command that flashed it:

  • testcases: f8a91ae7…, boot rc=0
  • testcases-watchdog: 852c54d4…, boot rc=0

Judge (boot:testcases): EXIT=0, 249 passed, 0 failed, 2 boot(s). The x86 IOMMU path is on the shared fault predicate, and its fault and refusal rows all pass.

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #825 at 93c4107c8 against .claude/agents/reviewer.md, round 3. It reviews 3029565d8..93c4107c8 (12 files, +217 / −107), the merges of origin/main aside. Branch net: 30 files, +1861 / −566 (git diff --shortstat origin/main...93c4107c8). The kernel's production code grows about +1329 / −545, and tests grow +379 / −10. This round's production growth is the drain bound, the re-pend and the three-way Owner, and I accept it.

Round-2 BLOCKERs

  • An unrouted stream's refused write halts the machine: CLOSED.
    • kernel/src/iommu/fault.rs:219 now returns matches!(owner, Owner::Kernel), and Owner::Nobody prints owner=none.
    • tests/common/serial.rs reads only owner=kernel as a death and lists owner=none in NEVER_CLEAN. tests/checks/serial.rs holds both directions.
    • nc10 restores round 2's predicate (!matches!(owner, Owner::Slot(_))) and goes red (exit 1, the selftest never said "which its domain no longer maps"). The selftest's two unrouted writes, then the kernel-owned write as the last one, are what I asked for.
  • The drain had no bound: CLOSED.
    • smmu/fault.rs:70 reads at most events.entries() records. When the queue is not empty afterwards, :96 pends the SPI again through GICD_ISPENDR, before trap.rs calls end.
    • A record that arrives after the last PROD read finds the queue empty in the unit's view (CONS was written), so the unit raises its own edge and nothing is lost.
    • nc8 (bound 1, no re-pend) goes red with read 1 events, not 2. nc11 (bound 1, re-pend kept) stays green, which shows the re-pend path delivers.
  • virt_smmu returned before the halt was asserted: CLOSED.
    • tests/toyos.rs:2070 now reads on to panic_reboot::arm's line, and :2076 goes red on any smmu-selftest: FAIL.
    • The test asserts the order: the second owner=none record, then WENT_ON, then the owner=kernel record, then the stop.
    • nc9 is my exact patch (kernel_owned > usize::MAX - 1) and goes red (exit 1, smmu-selftest: FAIL: the handler read the event of a function this kernel drives and the machine went on).
  • Evidence, the T14 reading of the moved VT-d policy and window: CLOSED. Comment 6096300030 is the orchestrator's boot:testcases run at 93c4107c8. Both images' sha256 (f8a91ae7…, 852c54d4…) match the ones the PR body staged, and the judge returned EXIT=0, 249 passed, 0 failed, 2 boot(s). That covers the x86 side of the predicate change, which no guest test on the development host reaches.

Round-2 NOTEs

  • Live::stream panics at attach: filed as issues/a-function-the-smmuv3-does-not-route-panics-at-attach.md. It has an owner (issues/toyos-runs-on-arm64.md's stage 6, which exists) and an exit a test can fail. Closed.
  • each_event_is_named_by_its_own_mnemonic: deleted. Closed.
  • Unfiled compromises (an unbounded drain, a halt on every unrouted stream): both are removed. Closed.

BLOCKER

None.

NOTE

  • kernel/src/iommu/fault.rs:201 — every owner=none record writes one log! line, with no per-requester limit. A device that writes without end under an unrouted stream refills the shard ring at the unit's event rate, up to 128 records per interrupt, and evicts other records before logkeeper reads them. Nothing can clear that device's BME. The PR body's "What I am unsure of" names this, so it is a compromise the branch found, and it is neither removed nor filed. File it with an owner, the evidence and an exit, or log only the first record per stream and count the rest.
  • kernel/src/arch/aarch64/irqchip.rs:331 — the re-pend rests on GICv3's active-and-pending state. Only HVF's vGIC measures it (nc11), and the body says IHI 0069 was not read. The spec is the independent oracle and a cheap one: read the section that defines the active-and-pending state and record it in the body's oracles.
  • PR body — "Gates" lists the T14 row as exit 2, "staged and not run", and "The x86 side" says the reading is "owed and not yet read". Comment 6096300030 has since read it: EXIT=0, 249 passed.

LAND AFTER NAMED CHANGES

…he re-pend cites IHI 0069D

A requester no enumerated function is cannot be stopped from here: its
BME is nobody's to clear, so a device writing without end under an
unrouted stream wrote one owner=none line per record, up to a queue's
worth per interrupt, and could evict every other record from the shard
ring before logkeeper read it. Each stray is now counted apart (the
first eight by key, every later one in a shared ninth count), the count
goes in streamfaults=, and only a record whose count is a power of two
is written: at most 32 lines per count for the boot, and each written
line says how many were read since the last. unitfaults= still counts
every record, so a later line shows the gap.

The selftest's unrouted function now writes three times: records 1 and
2 are written, 3 is counted and not, and the kernel-owned record reads
unitfaults=4, which is how virt_smmu sees a record read and not written.

The comment at pend_iommu_events cites the GICv3 sections the re-pend
rests on: GICD_ISPENDR makes an active SPI active and pending (8.9.16),
which is never signalled (4.1.2), and deactivation leaves it pending
(4.1.1, with EOImode 0 as init writes ICC_CTLR_EL1).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Round 4 at 3fc00867c: the negative control for the stray line bound, and the drain controls re-run because the selftest's stray now writes three times. Each patch was checked with git apply --check, applied, run through cargo test --test toyos-build -- virt_smmu, and restored in the same script (git checkout HEAD -- ., then git status --porcelain --ignore-submodules=none read empty). Home paths are shortened to ~, the worktrees' directory to <worktrees>.

Control Exit Verdict
nc12-every-stray-record-written 1 virt_smmu: 4 events reached the handler, not 3
nc8-one-record-not-repended 1 the handler had read 1 events, not 3, 1000ms … after the unrouted function's three refused writes
nc10-unrouted-halts 1 the selftest never said "which its domain no longer maps"
nc11-one-record-repended 0 green by design: four records read, the later ones on the re-pended SPI

nc12-every-stray-record-written.patch

diff --git a/kernel/src/iommu/fault.rs b/kernel/src/iommu/fault.rs
index f55043863..d2718ab58 100644
--- a/kernel/src/iommu/fault.rs
+++ b/kernel/src/iommu/fault.rs
@@ -228,7 +228,7 @@ pub fn report(unit: usize, count: &AtomicU32, fault: Fault) -> bool {
     let count = count.fetch_add(1, Ordering::Relaxed) + 1;
     // A stray's line is bounded by its count, never by the device: the next
     // line it writes says how many were read in between.
-    if function.is_none() && !seen_here.is_power_of_two() {
+    if false && function.is_none() && !seen_here.is_power_of_two() {
         return false;
     }
     log!(

nc8-one-record-not-repended.patch

diff --git a/kernel/src/arch/aarch64/smmu/fault.rs b/kernel/src/arch/aarch64/smmu/fault.rs
index 995602fd0..9b715459c 100644
--- a/kernel/src/arch/aarch64/smmu/fault.rs
+++ b/kernel/src/arch/aarch64/smmu/fault.rs
@@ -67,7 +67,7 @@ pub fn service() {
     let mut kernel_owned = 0usize;
     let mut cons = regs.read(reg::EVENTQ_CONS);
     let mut prod = regs.read(reg::EVENTQ_PROD);
-    for _ in 0..events.entries() {
+    for _ in 0..1 {
         if events.is_empty(prod, cons) {
             break;
         }
@@ -93,7 +93,6 @@ pub fn service() {
         prod = regs.read(reg::EVENTQ_PROD);
     }
     if !events.is_empty(prod, cons) {
-        super::super::irqchip::pend_iommu_events();
     }
     let errors = reg::active_errors(regs.read(reg::GERROR), regs.read(reg::GERRORN));
     if errors & reg::GERROR_EVENTQ_ABORT != 0 {

nc10-unrouted-halts.patch

diff --git a/kernel/src/iommu/fault.rs b/kernel/src/iommu/fault.rs
index 8c6eb26e6..289be3913 100644
--- a/kernel/src/iommu/fault.rs
+++ b/kernel/src/iommu/fault.rs
@@ -216,7 +216,7 @@ pub fn report(unit: usize, count: &AtomicU32, fault: Fault) -> bool {
         if FIRST.load(Ordering::Relaxed) == key { 'y' } else { 'n' },
         fault.name,
     );
-    matches!(owner, Owner::Kernel)
+    !matches!(owner, Owner::Slot(_))
 }
 
 /// The end of a drain that read `kernel_owned` faults on functions this kernel

nc11-one-record-repended.patch

diff --git a/kernel/src/arch/aarch64/smmu/fault.rs b/kernel/src/arch/aarch64/smmu/fault.rs
index 995602fd0..19f7966a2 100644
--- a/kernel/src/arch/aarch64/smmu/fault.rs
+++ b/kernel/src/arch/aarch64/smmu/fault.rs
@@ -67,7 +67,7 @@ pub fn service() {
     let mut kernel_owned = 0usize;
     let mut cons = regs.read(reg::EVENTQ_CONS);
     let mut prod = regs.read(reg::EVENTQ_PROD);
-    for _ in 0..events.entries() {
+    for _ in 0..1 {
         if events.is_empty(prod, cons) {
             break;
         }
virt_smmu at 3fc0086, EXIT=0
head 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38: cargo test --test toyos-build -- virt_smmu
   Compiling toyos-build v0.1.0 (<worktrees>/toyos-arm-g2)
    Finished `test` profile [optimized + debuginfo] target(s) in 5.61s
     Running tests/toyos.rs (target/debug/deps/toyos_build-a969be0cacbee86c)

10:06:18 running 1 tests, 12 wide

10:06:18   RUN   virt_smmu
10:06:18   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu
10:06:24   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu  (6s)
10:06:24   [virt] [ 0.413 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
10:06:24   [virt] GBPA 0x101000: ABORT
10:06:24   [virt] [ 0.412 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
10:06:24   [virt] [ 0.414 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
10:06:24   [virt] [ 0.415 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
10:06:24   [virt] [ 0.415 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:24   [virt] [ 0.416 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:24   [virt] [ 0.416 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:24   [virt] [ 0.418 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0xdead0002: refused
10:06:24   [virt] [ 0.417 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
10:06:24   [virt] [ 0.417 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
10:06:24   [virt] [ 0.418 cpu0 kernel] iommu: DMA FAULT owner=kernel unit0 stream=00:04.0 addr=0x0000400000000040 access=write reason=0x10 domain=1 bme=cleared unitfaults=4 streamfaults=1 first=n F_TRANSLATION
10:06:24   PASS  virt_smmu  (680ms)
10:06:24   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

10:06:24 host: fastest boot 521 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
10:06:24 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
10:06:24 test result: ok. 1 passed, 1 total (6.6s; workers: 6s building, 680ms testing)
EXIT=0
control nc12-every-stray-record-written, EXIT=1
head 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38 control nc12-every-stray-record-written
    Finished `test` profile [optimized + debuginfo] target(s) in 0.25s
     Running tests/toyos.rs (target/debug/deps/toyos_build-a969be0cacbee86c)

10:06:25 running 1 tests, 12 wide

10:06:25   RUN   virt_smmu
10:06:25   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu
10:06:28   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu  (3s)
10:06:29   [virt] [ 0.419 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
10:06:29   [virt] GBPA 0x101000: ABORT
10:06:29   [virt] [ 0.419 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
10:06:29   [virt] [ 0.420 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
10:06:29   [virt] [ 0.421 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
10:06:29   [virt] [ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:29   [virt] [ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:29   [virt] [ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
10:06:29   [virt] [ 0.425 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0xdead0002: refused
10:06:29   [virt] [ 0.423 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
10:06:29   [virt] [ 0.423 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
10:06:29   [virt] [ 0.424 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=3 streamfaults=3 first=y C_BAD_STE
10:06:29   [virt] [ 0.425 cpu0 kernel] iommu: DMA FAULT owner=kernel unit0 stream=00:04.0 addr=0x0000400000000040 access=write reason=0x10 domain=1 bme=cleared unitfaults=4 streamfaults=1 first=n F_TRANSLATION
10:06:29 FAIL virt_smmu: 4 events reached the handler, not 3
serial:
UEFI firmware (version edk2-stable202408-prebuilt.qemu.org built at 16:28:50 on Sep 12 2024)
ArmTrngLib could not be correctly initialized.
Error: Image at 000BFDB6000 start failed: 00000001
Error: Image at 000BFCB2000 start failed: Unsupported
Error: Image at 000BFC37000 start failed: Not Found
Error: Image at 000BFB5D000 start failed: Aborted
Tpm2SubmitCommand - Tcg2 - Not Found
Tpm2GetCapabilityPcrs fail!
Tpm2SubmitCommand - Tcg2 - Not Found
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HUsbBootExecCmd: Success to Exec 0x0 Cmd (Result = 1)
BdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
ConvertPages: failed to find range 140000000 - 14003FFFF
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01HConvertPages: failed to find range 8000000 - 8003FFF
[ 0.309 cpu0 loader] ToyOS Bootloader 1.0
[ 0.310 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 0.310 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 0.311 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 0.311 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-I69da31ad0b28c30e (image scope) holds 0
[ 0.312 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 0.312 cpu0 loader] RSDP address: 0xbcb43018
[ 0.313 cpu0 loader] Boot partition: LBA 2048+69632 signature [b9, 2d, ce, 7e, c6, 1e, db, 4f, aa, 7e, fc, 96, 83, 43, 9a, 12]
[ 0.313 cpu0 loader] Log partition: signature [6a, 45, 5c, bc, c0, c7, 85, 4f, a6, a5, 93, 09, c3, e0, 42, d0]
[ 0.320 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B absent; the floor is 0
[ 0.324 cpu0 loader] Slot A: signed header dabf18b498ff08afc8dcbd41c0dfb8a71c58052661951a596b71469c1a98b534 verifies under this loader's key, version 1791626785
[ 0.342 cpu0 loader] ROOT: read into memory at 0xbb7a4000+0xa00000 from LBA 212992+20480, 1048576 bytes a request (optimal granularity: not reported), in 220500 counter ticks
[ 0.363 cpu0 loader] Slot A: ROOT hashed in 480793 counter ticks
[ 0.364 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 0.365 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 0.365 cpu0 loader] Kernel: 2657672 bytes
[ 0.366 cpu0 loader] Boot parameter: "root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A"
[ 0.366 cpu0 loader] Loading kernel elf...
[ 0.366 cpu0 loader] Kernel stack size: 8388608
[ 0.366 cpu0 loader] Kernel memory size: 13799424
[ 0.370 cpu0 loader] Kernel memory located at: 0xbaa00000
[ 0.370 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 515952 }, filesz: 515952, file_offset: 0, flags: SegmentFlags(4) }
[ 0.371 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 581632, len: 1108384 }, filesz: 1108384, file_offset: 516096, flags: SegmentFlags(5) }
[ 0.372 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1755552, len: 1632 }, filesz: 240, file_offset: 1624480, flags: SegmentFlags(6) }
[ 0.373 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1821328, len: 3588192 }, filesz: 26800, file_offset: 1624720, flags: SegmentFlags(6) }
[ 0.374 cpu0 loader] Applied 3194 relocations
[ 0.374 cpu0 loader] GOP: mode 800x600 stride=800 format=1 fb=0xbc7a0000 size=3145728
[ 0.374 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 0.375 cpu0 loader] Starting kernel...
[ 0.375 cpu0 loader] CPU: entered at EL1
[ 0.376 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 0.376 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.377 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.377 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.378 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 0.378 cpu0 loader] Scanout: 0xbc7a0000+0x300000 mapped as the scanout in 2 MiB pages at identity and at PHYS_OFFSET, in 4 page directories
[ 0.379 cpu0 loader] Loader image: 0xbc430000+0x40000, mapped at identity as 0xbc400000+0x200000
[ 0.380 cpu0 loader] Boot map: root 0xba86c000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 0.380 cpu0 loader] Kernel image: 0xbaa00000+0xd29000 is inside the 0x100000000-byte boot map
[ 0.381 cpu0 loader] Parameter buffer: 0xbcb40298+0x3f is inside the 0x100000000-byte boot map
[ 0.381 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 0.382 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 0.382 cpu0 loader] Loader counter: 7415264 at entry, 9189359 at the handoff
[ 0.383 cpu0 loader] Loader log: the kernel handoff begins, so this file ends here
[ 0.385 cpu0 kernel] panic console: armed 800x600 stride=800 format=1 at 0xbc7a0000, write-combining
[ 0.385 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 0.385 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 0.386 cpu0 kernel] actuators: root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A
[ 0.386 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1

[ 0.387 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 0.387 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 0.387 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 0.387 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 0.388 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 0.388 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 0.388 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 0.388 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 0.389 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 0.389 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 0.389 cpu0 kernel] memory: 0x000048000000..0x0000ba869000 uefi type 7
[ 0.389 cpu0 kernel] memory: 0x0000ba869000..0x0000bc430000 uefi type 2
[ 0.389 cpu0 kernel] memory: 0x0000bc430000..0x0000bc470000 uefi type 1
[ 0.390 cpu0 kernel] memory: 0x0000bc470000..0x0000bc4f0000 uefi type 5
[ 0.390 cpu0 kernel] memory: 0x0000bc4f0000..0x0000bc660000 uefi type 6
[ 0.390 cpu0 kernel] memory: 0x0000bc660000..0x0000bc6b0000 uefi type 5
[ 0.390 cpu0 kernel] memory: 0x0000bc6b0000..0x0000bc750000 uefi type 6
[ 0.390 cpu0 kernel] memory: 0x0000bc750000..0x0000bc7a0000 uefi type 5
[ 0.391 cpu0 kernel] memory: 0x0000bc7a0000..0x0000bcaa0000 uefi type 0
[ 0.391 cpu0 kernel] memory: 0x0000bcaa0000..0x0000bcb40000 uefi type 5
[ 0.391 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 0.391 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 0.391 cpu0 kernel] memory: 0x0000bcb44000..0x0000be0f5000 uefi type 7
[ 0.392 cpu0 kernel] memory: 0x0000be0f5000..0x0000bfa38000 uefi type 4
[ 0.392 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb8c000 uefi type 7
[ 0.392 cpu0 kernel] memory: 0x0000bfb8c000..0x0000bfe20000 uefi type 3
[ 0.392 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 0.392 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 0.393 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 0.393 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 0.393 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 0.393 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 0.393 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 0.394 cpu0 kernel] memory: 33 ranges, as the loader handed them over
[ 0.394 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 0.394 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 0.394 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 0.394 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 0.395 cpu0 kernel] ACPI: MADT names 2 GIC CPU interfaces, 2 enabled
[ 0.395 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 0.395 cpu0 kernel] boot: memory map 0xba86a018+0x318, kernel 0xbaa00000+0xd29000, stack image+0x529000+0x800000
[ 0.395 cpu0 kernel] boot: kernel elf 0xbc1a4018+0x288d88, rsdp 0xbcb43018, boot pml4 0xba86c000
[ 0.396 cpu0 kernel] boot: gop 0xbc7a0000+0x300000 800x600 stride 800 format 1
[ 0.396 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [b9, 2d, ce, 7e, c6, 1e, db, 4f, aa, 7e, fc, 96, 83, 43, 9a, 12]
[ 0.396 cpu0 kernel] boot: log partition guid [6a, 45, 5c, bc, c0, c7, 85, 4f, a6, a5, 93, 09, c3, e0, 42, d0]
[ 0.397 cpu0 kernel] boot: cmdline 0xbcb40298+63
[ 0.397 cpu0 kernel] boot: root=5e0a13aab4ef5ccc658186be8bcc260d
[ 0.397 cpu0 kernel] boot: slot A, the one the slot table marks
[ 0.397 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 0.397 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 0.398 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 0.398 cpu0 kernel] pmm: the firmware map calls 2138558464 bytes usable in 21 entries; managed=2097152000 withheld=27262976 unaligned=14143488, and the three sum to it; frames=1000 reserved_frames=13 base=0x40000000 span=1023
[ 0.399 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1019 2 MiB blocks and 384 4 KiB pages
[ 0.400 cpu0 kernel] mmio: 0xbc7a0000+0x300000 WriteCombining
[ 0.400 cpu0 kernel] ACPI: APIC at 0xbcb43c98 len=268 rev=4 oem="BOCHS" checksummed
[ 0.400 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 0.400 cpu0 kernel] ACPI: GTDT at 0xbcb43098 len=104 rev=3 oem="BOCHS" checksummed
[ 0.401 cpu0 kernel] ACPI: SPCR at 0xbcb43818 len=80 rev=2 oem="BOCHS" checksummed
[ 0.401 cpu0 kernel] ACPI: MCFG at 0xbcb43a98 len=60 rev=1 oem="BOCHS" checksummed
[ 0.401 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 0.401 cpu0 kernel] PSCI: 1.1 through HVC
[ 0.402 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 0.402 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 0.402 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 0.402 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 0.403 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 0.403 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 0.403 cpu0 kernel] symbols: loaded 18977 kernel symbols
[ 0.404 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 0.404 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 0.404 cpu0 kernel] Boot: CPU ready (0ms)
[ 0.405 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 0.405 cpu0 kernel] ACPI: MCFG found at 0xbcb43a98
[ 0.405 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 0.405 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 0.405 cpu0 kernel] PCI: Enumerating devices...
[ 0.405 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 0.406 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000004000]
[ 0.406 cpu0 kernel]   PCI 00:02.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10002000 bar4=0x8000000000]
[ 0.406 cpu0 kernel]   PCI 00:03.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10001000]
[ 0.407 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10000000]
[ 0.415 cpu0 kernel] PCI: Enumeration complete, 5 functions.
[ 0.416 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 0.416 cpu0 kernel] pcidev: 5 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 0.417 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 0.417 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 0.417 cpu0 kernel] pcidev:   0x9011000..0x10000000 (111 MiB)
[ 0.417 cpu0 kernel] pcidev:   0x10003000..0x40000000 (767 MiB)
[ 0.417 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 0.418 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 0.418 cpu0 kernel] pcidev:   0x8000008000..0xffffffffffffffff (17592185520127 MiB)
[ 0.418 cpu0 kernel] mmio: 0x9050000+0x20000 Uncacheable
[ 0.418 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000: GBPA 0x101000, every transaction aborts while SMMUEN is clear
[ 0.419 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
[ 0.419 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
[ 0.420 cpu0 kernel] mmio: 0x10000000+0x1000 Uncacheable
[ 0.420 cpu0 kernel] mmio: 0x10001000+0x1000 Uncacheable
[ 0.420 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
[ 0.421 cpu0 kernel] iommu: domain1 root=0x40603000 context=0x40604000 asid=1 addresses from 0x400000000000 to 0x1000000000000
[ 0.421 cpu0 kernel] iommu: 00:04.0 moves to domain1
[ 0.421 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
[ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.422 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.423 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
[ 0.423 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
[ 0.424 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=3 streamfaults=3 first=y C_BAD_STE
[ 0.424 cpu0 kernel] smmu-selftest: the unrouted function's three events were read, and the machine goes on
[ 0.425 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0xdead0002: refused
[ 0.425 cpu0 kernel] iommu: DMA FAULT owner=kernel unit0 stream=00:04.0 addr=0x0000400000000040 access=write reason=0x10 domain=1 bme=cleared unitfaults=4 streamfaults=1 first=n F_TRANSLATION
[ 0.426 cpu0 kernel alert] panic: rebooting in 60 s, timed by the calibrated clock

10:06:29   FAIL  virt_smmu  (593ms)
10:06:29   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

10:06:29 host: fastest boot 437 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
10:06:29 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
10:06:29 failures:
10:06:29     virt_smmu: 4 events reached the handler, not 3

10:06:29 test result: FAILED. 0 passed, 1 failed, 0 invalidated, 1 total (4.0s; workers: 3s building, 593ms testing)
10:06:29 [toyos] this red run's serial logs are kept at <worktrees>/toyos-arm-g2/target/red-run-serial/toyos-tmp-155-0
error: test failed, to rerun pass `--test toyos-build`

Caused by:
  process didn't exit successfully: `<worktrees>/toyos-arm-g2/target/debug/deps/toyos_build-a969be0cacbee86c virt_smmu` (exit status: 1)
EXIT=1
control nc11-one-record-repended, EXIT=0
head 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38 control nc11-one-record-repended
    Finished `test` profile [optimized + debuginfo] target(s) in 0.25s
     Running tests/toyos.rs (target/debug/deps/toyos_build-a969be0cacbee86c)

10:07:39 running 1 tests, 12 wide

10:07:39   RUN   virt_smmu
10:07:39   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu
10:07:43   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu  (3s)
10:07:43   [virt] [ 0.408 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
10:07:43   [virt] GBPA 0x101000: ABORT
10:07:43   [virt] [ 0.408 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
10:07:43   [virt] [ 0.409 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
10:07:43   [virt] [ 0.410 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
10:07:43   [virt] [ 0.411 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:43   [virt] [ 0.411 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:43   [virt] [ 0.411 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:43   [virt] [ 0.413 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040 again, which its domain no longer maps, answered 0xdead0002: refused
10:07:43   [virt] [ 0.412 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
10:07:43   [virt] [ 0.412 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
10:07:43   [virt] [ 0.413 cpu0 kernel] iommu: DMA FAULT owner=kernel unit0 stream=00:04.0 addr=0x0000400000000040 access=write reason=0x10 domain=1 bme=cleared unitfaults=4 streamfaults=1 first=n F_TRANSLATION
10:07:43   PASS  virt_smmu  (576ms)
10:07:43   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

10:07:43 host: fastest boot 427 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
10:07:43 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
10:07:43 test result: ok. 1 passed, 1 total (4.0s; workers: 3s building, 576ms testing)
EXIT=0

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

Round 4 at 3fc00867c, continued: the full logs of the two drain controls that went red.

control nc8-one-record-not-repended, EXIT=1
head 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38 control nc8-one-record-not-repended
    Finished `test` profile [optimized + debuginfo] target(s) in 0.43s
     Running tests/toyos.rs (target/debug/deps/toyos_build-a969be0cacbee86c)

10:07:28 running 1 tests, 12 wide

10:07:28   RUN   virt_smmu
10:07:28   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu
10:07:32   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu  (4s)
10:07:34 FAIL virt_smmu: smmu-selftest: FAIL: the handler had read 1 events, not 3, 1000ms (the unit records each event and pulses its interrupt while the refused write is still being made) after the unrouted function's three refused writes
serial:
UEFI firmware (version edk2-stable202408-prebuilt.qemu.org built at 16:28:50 on Sep 12 2024)
ArmTrngLib could not be correctly initialized.
Error: Image at 000BFDB6000 start failed: 00000001
Error: Image at 000BFCB2000 start failed: Unsupported
Error: Image at 000BFC37000 start failed: Not Found
Error: Image at 000BFB5D000 start failed: Aborted
Tpm2SubmitCommand - Tcg2 - Not Found
Tpm2GetCapabilityPcrs fail!
Tpm2SubmitCommand - Tcg2 - Not Found
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HUsbBootExecCmd: Success to Exec 0x0 Cmd (Result = 1)
BdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
ConvertPages: failed to find range 140000000 - 14003FFFF
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01HConvertPages: failed to find range 8000000 - 8003FFF
[ 0.301 cpu0 loader] ToyOS Bootloader 1.0
[ 0.301 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 0.302 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 0.303 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 0.303 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-I5bfc765aee0dfd79 (image scope) holds 0
[ 0.304 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 0.304 cpu0 loader] RSDP address: 0xbcb43018
[ 0.305 cpu0 loader] Boot partition: LBA 2048+69632 signature [1c, 1e, 98, 5b, 54, 5e, 39, 4b, a5, 5f, 70, 58, 97, 36, 26, ea]
[ 0.305 cpu0 loader] Log partition: signature [e0, 0c, 5c, 30, f2, 71, ad, 40, 97, 2f, e3, 98, d6, 62, 14, a2]
[ 0.311 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B absent; the floor is 0
[ 0.315 cpu0 loader] Slot A: signed header 65715b23c843cca3c135cb7f025bd0c4013c7106af19d7647c3e2a01024d3de4 verifies under this loader's key, version 1791626848
[ 0.332 cpu0 loader] ROOT: read into memory at 0xbb7a4000+0xa00000 from LBA 212992+20480, 1048576 bytes a request (optimal granularity: not reported), in 202024 counter ticks
[ 0.352 cpu0 loader] Slot A: ROOT hashed in 457749 counter ticks
[ 0.352 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 0.353 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 0.354 cpu0 loader] Kernel: 2656704 bytes
[ 0.354 cpu0 loader] Boot parameter: "root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A"
[ 0.354 cpu0 loader] Loading kernel elf...
[ 0.355 cpu0 loader] Kernel stack size: 8388608
[ 0.355 cpu0 loader] Kernel memory size: 13799424
[ 0.358 cpu0 loader] Kernel memory located at: 0xbaa00000
[ 0.358 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 515612 }, filesz: 515612, file_offset: 0, flags: SegmentFlags(4) }
[ 0.359 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 581632, len: 1108228 }, filesz: 1108228, file_offset: 516096, flags: SegmentFlags(5) }
[ 0.360 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1755400, len: 1784 }, filesz: 240, file_offset: 1624328, flags: SegmentFlags(6) }
[ 0.361 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1821176, len: 3588344 }, filesz: 26800, file_offset: 1624568, flags: SegmentFlags(6) }
[ 0.362 cpu0 loader] Applied 3191 relocations
[ 0.362 cpu0 loader] GOP: mode 800x600 stride=800 format=1 fb=0xbc7a0000 size=3145728
[ 0.363 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 0.364 cpu0 loader] Starting kernel...
[ 0.364 cpu0 loader] CPU: entered at EL1
[ 0.364 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 0.365 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.365 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.366 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.366 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 0.367 cpu0 loader] Scanout: 0xbc7a0000+0x300000 mapped as the scanout in 2 MiB pages at identity and at PHYS_OFFSET, in 4 page directories
[ 0.368 cpu0 loader] Loader image: 0xbc430000+0x40000, mapped at identity as 0xbc400000+0x200000
[ 0.368 cpu0 loader] Boot map: root 0xba86c000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 0.369 cpu0 loader] Kernel image: 0xbaa00000+0xd29000 is inside the 0x100000000-byte boot map
[ 0.369 cpu0 loader] Parameter buffer: 0xbcb40298+0x3f is inside the 0x100000000-byte boot map
[ 0.370 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 0.370 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 0.371 cpu0 loader] Loader counter: 7213412 at entry, 8917716 at the handoff
[ 0.371 cpu0 loader] Loader log: the kernel handoff begins, so this file ends here
[ 0.374 cpu0 kernel] panic console: armed 800x600 stride=800 format=1 at 0xbc7a0000, write-combining
[ 0.374 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 0.374 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 0.375 cpu0 kernel] actuators: root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A
[ 0.375 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1

[ 0.375 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 0.376 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 0.376 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 0.376 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 0.376 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 0.376 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 0.377 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 0.377 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 0.377 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 0.377 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 0.377 cpu0 kernel] memory: 0x000048000000..0x0000ba869000 uefi type 7
[ 0.378 cpu0 kernel] memory: 0x0000ba869000..0x0000bc430000 uefi type 2
[ 0.378 cpu0 kernel] memory: 0x0000bc430000..0x0000bc470000 uefi type 1
[ 0.378 cpu0 kernel] memory: 0x0000bc470000..0x0000bc4f0000 uefi type 5
[ 0.378 cpu0 kernel] memory: 0x0000bc4f0000..0x0000bc660000 uefi type 6
[ 0.378 cpu0 kernel] memory: 0x0000bc660000..0x0000bc6b0000 uefi type 5
[ 0.379 cpu0 kernel] memory: 0x0000bc6b0000..0x0000bc750000 uefi type 6
[ 0.379 cpu0 kernel] memory: 0x0000bc750000..0x0000bc7a0000 uefi type 5
[ 0.379 cpu0 kernel] memory: 0x0000bc7a0000..0x0000bcaa0000 uefi type 0
[ 0.379 cpu0 kernel] memory: 0x0000bcaa0000..0x0000bcb40000 uefi type 5
[ 0.379 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 0.379 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 0.380 cpu0 kernel] memory: 0x0000bcb44000..0x0000be0f5000 uefi type 7
[ 0.380 cpu0 kernel] memory: 0x0000be0f5000..0x0000bfa38000 uefi type 4
[ 0.380 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb8c000 uefi type 7
[ 0.380 cpu0 kernel] memory: 0x0000bfb8c000..0x0000bfe20000 uefi type 3
[ 0.380 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 0.381 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 0.381 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 0.381 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 0.381 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 0.381 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 0.382 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 0.382 cpu0 kernel] memory: 33 ranges, as the loader handed them over
[ 0.382 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 0.382 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 0.382 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 0.383 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 0.383 cpu0 kernel] ACPI: MADT names 2 GIC CPU interfaces, 2 enabled
[ 0.383 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 0.383 cpu0 kernel] boot: memory map 0xba86a018+0x318, kernel 0xbaa00000+0xd29000, stack image+0x529000+0x800000
[ 0.384 cpu0 kernel] boot: kernel elf 0xbc1a4018+0x2889c0, rsdp 0xbcb43018, boot pml4 0xba86c000
[ 0.384 cpu0 kernel] boot: gop 0xbc7a0000+0x300000 800x600 stride 800 format 1
[ 0.384 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [1c, 1e, 98, 5b, 54, 5e, 39, 4b, a5, 5f, 70, 58, 97, 36, 26, ea]
[ 0.384 cpu0 kernel] boot: log partition guid [e0, 0c, 5c, 30, f2, 71, ad, 40, 97, 2f, e3, 98, d6, 62, 14, a2]
[ 0.385 cpu0 kernel] boot: cmdline 0xbcb40298+63
[ 0.385 cpu0 kernel] boot: root=5e0a13aab4ef5ccc658186be8bcc260d
[ 0.385 cpu0 kernel] boot: slot A, the one the slot table marks
[ 0.385 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 0.386 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 0.386 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 0.386 cpu0 kernel] pmm: the firmware map calls 2138558464 bytes usable in 21 entries; managed=2097152000 withheld=27262976 unaligned=14143488, and the three sum to it; frames=1000 reserved_frames=13 base=0x40000000 span=1023
[ 0.388 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1019 2 MiB blocks and 384 4 KiB pages
[ 0.388 cpu0 kernel] mmio: 0xbc7a0000+0x300000 WriteCombining
[ 0.388 cpu0 kernel] ACPI: APIC at 0xbcb43c98 len=268 rev=4 oem="BOCHS" checksummed
[ 0.388 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 0.389 cpu0 kernel] ACPI: GTDT at 0xbcb43098 len=104 rev=3 oem="BOCHS" checksummed
[ 0.389 cpu0 kernel] ACPI: SPCR at 0xbcb43818 len=80 rev=2 oem="BOCHS" checksummed
[ 0.389 cpu0 kernel] ACPI: MCFG at 0xbcb43a98 len=60 rev=1 oem="BOCHS" checksummed
[ 0.389 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 0.390 cpu0 kernel] PSCI: 1.1 through HVC
[ 0.390 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 0.390 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 0.391 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 0.391 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 0.391 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 0.391 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 0.392 cpu0 kernel] symbols: loaded 18964 kernel symbols
[ 0.392 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 0.393 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 0.393 cpu0 kernel] Boot: CPU ready (0ms)
[ 0.393 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 0.394 cpu0 kernel] ACPI: MCFG found at 0xbcb43a98
[ 0.394 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 0.394 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 0.394 cpu0 kernel] PCI: Enumerating devices...
[ 0.394 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 0.395 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000004000]
[ 0.395 cpu0 kernel]   PCI 00:02.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10002000 bar4=0x8000000000]
[ 0.395 cpu0 kernel]   PCI 00:03.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10001000]
[ 0.396 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10000000]
[ 0.405 cpu0 kernel] PCI: Enumeration complete, 5 functions.
[ 0.405 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 0.406 cpu0 kernel] pcidev: 5 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 0.406 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 0.406 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 0.406 cpu0 kernel] pcidev:   0x9011000..0x10000000 (111 MiB)
[ 0.407 cpu0 kernel] pcidev:   0x10003000..0x40000000 (767 MiB)
[ 0.407 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 0.407 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 0.407 cpu0 kernel] pcidev:   0x8000008000..0xffffffffffffffff (17592185520127 MiB)
[ 0.407 cpu0 kernel] mmio: 0x9050000+0x20000 Uncacheable
[ 0.408 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000: GBPA 0x101000, every transaction aborts while SMMUEN is clear
[ 0.408 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
[ 0.409 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
[ 0.409 cpu0 kernel] mmio: 0x10000000+0x1000 Uncacheable
[ 0.409 cpu0 kernel] mmio: 0x10001000+0x1000 Uncacheable
[ 0.410 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
[ 0.410 cpu0 kernel] iommu: domain1 root=0x40603000 context=0x40604000 asid=1 addresses from 0x400000000000 to 0x1000000000000
[ 0.411 cpu0 kernel] iommu: 00:04.0 moves to domain1
[ 0.411 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
[ 0.411 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.411 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.412 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.412 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
[ 1.413 cpu0 kernel alert] PANIC: panicked at kernel/src/arch/aarch64/smmu/selftest.rs:155:9:
smmu-selftest: FAIL: the handler had read 1 events, not 3, 1000ms (the unit records each event and pulses its interrupt while the refused write is still being made) after the unrouted function's three refused writes
[ 1.413 cpu0 kernel]   Backtrace:
[ 1.414 cpu0 kernel]     0xffff8000bab99930  core::panicking::panic_fmt+0x28
[ 1.414 cpu0 kernel]     0xffff8000bab06b4c  kernel::arch::aarch64::smmu::selftest::events_reach_this_cpu+0x158
[ 1.414 cpu0 kernel]     0xffff8000bab071ec  kernel::arch::aarch64::smmu::selftest::run+0x694
[ 1.415 cpu0 kernel]     0xffff8000baab8010  kernel::arch::aarch64::smmu::init+0x128c
[ 1.415 cpu0 kernel]     0xffff8000bab73a4c  kernel::kernel_main+0xc2c
[ 1.415 cpu0 kernel]     0xffff8000bab03318  _start+0x50
[ 1.415 cpu0 kernel]   Contexts: cpu0 crashed at sp=0xffff8000bb727fb0, asking about ctx 0x0
[ 1.415 cpu0 kernel]   cpu0 is on ctx 0x0 (never switched, or not a context)
[ 1.416 cpu0 kernel alert] panic: rebooting in 60 s, timed by the calibrated clock

10:07:34   FAIL  virt_smmu  (2s)
10:07:34   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

10:07:34 host: fastest boot 427 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
10:07:34 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
10:07:34 failures:
10:07:34     virt_smmu: smmu-selftest: FAIL: the handler had read 1 events, not 3, 1000ms (the unit records each event and pulses its interrupt while the refused write is still being made) after the unrouted function's three refused writes

10:07:34 test result: FAILED. 0 passed, 1 failed, 0 invalidated, 1 total (5.9s; workers: 4s building, 2s testing)
10:07:34 [toyos] this red run's serial logs are kept at <worktrees>/toyos-arm-g2/target/red-run-serial/toyos-tmp-21602-0
error: test failed, to rerun pass `--test toyos-build`

Caused by:
  process didn't exit successfully: `<worktrees>/toyos-arm-g2/target/debug/deps/toyos_build-a969be0cacbee86c virt_smmu` (exit status: 1)
EXIT=1
control nc10-unrouted-halts, EXIT=1
head 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38 control nc10-unrouted-halts
    Finished `test` profile [optimized + debuginfo] target(s) in 0.25s
     Running tests/toyos.rs (target/debug/deps/toyos_build-a969be0cacbee86c)

10:07:34 running 1 tests, 12 wide

10:07:34   RUN   virt_smmu
10:07:34   BUILD aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu
10:07:38   BUILT aarch64 kernel boot-actuators,test-actuators, loader, ROOT of tests/testcases, for virt_smmu  (4s)
10:07:39   [virt] [ 0.411 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
10:07:39   [virt] GBPA 0x101000: ABORT
10:07:39   [virt] [ 0.410 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
10:07:39   [virt] [ 0.412 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
10:07:39   [virt] [ 0.413 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
10:07:39   [virt] [ 0.413 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:39   [virt] [ 0.414 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:39   [virt] [ 0.414 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
10:07:39 FAIL virt_smmu: the selftest never said "which its domain no longer maps"
serial:
UEFI firmware (version edk2-stable202408-prebuilt.qemu.org built at 16:28:50 on Sep 12 2024)
ArmTrngLib could not be correctly initialized.
Error: Image at 000BFDB6000 start failed: 00000001
Error: Image at 000BFCB2000 start failed: Unsupported
Error: Image at 000BFC37000 start failed: Not Found
Error: Image at 000BFB5D000 start failed: Aborted
Tpm2SubmitCommand - Tcg2 - Not Found
Tpm2GetCapabilityPcrs fail!
Tpm2SubmitCommand - Tcg2 - Not Found
�[2J�[01;01H�[=3h�[2J�[01;01H�[2J�[01;01H�[=3h�[2J�[01;01HUsbBootExecCmd: Success to Exec 0x0 Cmd (Result = 1)
BdsDxe: loading Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
ConvertPages: failed to find range 140000000 - 14003FFFF
BdsDxe: starting Boot0001 "UEFI QEMU QEMU USB HARDDRIVE TOYOS0BOOTSTICK1" from PciRoot(0x0)/Pci(0x1,0x0)/USB(0x0,0x0)
�[2J�[01;01HConvertPages: failed to find range 8000000 - 8003FFF
[ 0.304 cpu0 loader] ToyOS Bootloader 1.0
[ 0.306 cpu0 loader] Loader clock: each line opens with the seconds since the counter's zero, at the counter's stated 24000000 Hz
[ 0.306 cpu0 loader] Black box: firmware would not give 0x8000000+0x4000 (UEFI Error NOT_FOUND: ()), so this boot leaves nothing behind and the next one has nothing to read
[ 0.307 cpu0 loader] Boot attempts: this image has had the machine 0 time(s) without reporting; now 1
[ 0.308 cpu0 loader] Anti-rollback floor: ToyOSImageFloor-Ia0af7f1d32244d2b (image scope) holds 0
[ 0.308 cpu0 loader] Firmware watchdog: 60 s, until ExitBootServices disables it
[ 0.309 cpu0 loader] RSDP address: 0xbcb43018
[ 0.309 cpu0 loader] Boot partition: LBA 2048+69632 signature [72, db, 3b, ab, 58, f1, fb, 4d, b6, 86, c7, 26, b7, 55, 6c, 82]
[ 0.310 cpu0 loader] Log partition: signature [41, ba, d7, 2f, 77, 0e, 68, 48, a7, e5, 57, 21, 7d, 5b, ed, b2]
[ 0.315 cpu0 loader] Slots: the table marks A (sequence 1); slot A present, slot B absent; the floor is 0
[ 0.319 cpu0 loader] Slot A: signed header d0aa1a390c1228abe626b602796154f2ce775b88fac59e8f444cdf134cd420f5 verifies under this loader's key, version 1791626854
[ 0.336 cpu0 loader] ROOT: read into memory at 0xbb7a4000+0xa00000 from LBA 212992+20480, 1048576 bytes a request (optimal granularity: not reported), in 194665 counter ticks
[ 0.356 cpu0 loader] Slot A: ROOT hashed in 454353 counter ticks
[ 0.356 cpu0 loader] Slot A: kernel, cmdline and ROOT are the bytes the signed header names
[ 0.357 cpu0 loader] Boot attempts: slot A's image is written down as the one this pass boots
[ 0.358 cpu0 loader] Kernel: 2657680 bytes
[ 0.358 cpu0 loader] Boot parameter: "root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A"
[ 0.358 cpu0 loader] Loading kernel elf...
[ 0.359 cpu0 loader] Kernel stack size: 8388608
[ 0.359 cpu0 loader] Kernel memory size: 13799424
[ 0.361 cpu0 loader] Kernel memory located at: 0xbaa00000
[ 0.362 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 0, len: 515944 }, filesz: 515944, file_offset: 0, flags: SegmentFlags(4) }
[ 0.363 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 581632, len: 1108384 }, filesz: 1108384, file_offset: 516096, flags: SegmentFlags(5) }
[ 0.364 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1755552, len: 1632 }, filesz: 240, file_offset: 1624480, flags: SegmentFlags(6) }
[ 0.364 cpu0 loader] Loading segment: Segment { image: ImageRange { start: 1821328, len: 3588192 }, filesz: 26800, file_offset: 1624720, flags: SegmentFlags(6) }
[ 0.365 cpu0 loader] Applied 3194 relocations
[ 0.366 cpu0 loader] GOP: mode 800x600 stride=800 format=1 fb=0xbc7a0000 size=3145728
[ 0.366 cpu0 loader] Boot chain: no Boot#### entry on this machine names the partition this image came off, so the boot after a reset is the firmware's own
[ 0.367 cpu0 loader] Starting kernel...
[ 0.367 cpu0 loader] CPU: entered at EL1
[ 0.368 cpu0 loader] GCD: 0x4000000+0x4000000 mmio cap=0xc000000000000001 attr=0x8000000000000001 free
[ 0.368 cpu0 loader] GCD: 0x10100000+0x2ef00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.369 cpu0 loader] GCD: 0x4010000000+0x10000000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.369 cpu0 loader] GCD: 0x8000100000+0x7ffff00000 mmio cap=0xc000000000000001 attr=0x1 free
[ 0.370 cpu0 loader] GCD: 14 descriptor(s); 4 free mmio range(s) of 0x200000 bytes or more handed to the kernel, 0 past its room
[ 0.370 cpu0 loader] Scanout: 0xbc7a0000+0x300000 mapped as the scanout in 2 MiB pages at identity and at PHYS_OFFSET, in 4 page directories
[ 0.371 cpu0 loader] Loader image: 0xbc430000+0x40000, mapped at identity as 0xbc400000+0x200000
[ 0.372 cpu0 loader] Boot map: root 0xba86c000, 0x100000000 bytes at identity and at PHYS_OFFSET
[ 0.372 cpu0 loader] Kernel image: 0xbaa00000+0xd29000 is inside the 0x100000000-byte boot map
[ 0.373 cpu0 loader] Parameter buffer: 0xbcb40298+0x3f is inside the 0x100000000-byte boot map
[ 0.373 cpu0 loader] Seed: 32 bytes from EFI_RNG_PROTOCOL for the kernel's generator
[ 0.374 cpu0 loader] Kernel arguments: 0x47685df0+0x520 is inside the 0x100000000-byte boot map
[ 0.374 cpu0 loader] Loader counter: 7296888 at entry, 8997335 at the handoff
[ 0.375 cpu0 loader] Loader log: the kernel handoff begins, so this file ends here
[ 0.377 cpu0 kernel] panic console: armed 800x600 stride=800 format=1 at 0xbc7a0000, write-combining
[ 0.377 cpu0 kernel] black box: this boot's parameter line names no page, so a panic reaches the panel and nowhere else
[ 0.377 cpu0 kernel] serial: PL011 at 0x9000000 (SPCR, GSIV 33)
[ 0.378 cpu0 kernel] actuators: root=5e0a13aab4ef5ccc658186be8bcc260d,smmu-selftest,boot-slot=A
[ 0.378 cpu0 kernel] control registers: SCTLR_EL1=0x30d0199d TCR_EL1=0x12b5103510 MAIR_EL1=0x44ff04 CPACR_EL1=0x300000 CNTKCTL_EL1=0x2, as declared; entered at EL1

[ 0.379 cpu0 kernel] memory: 0x000040000000..0x000044000000 uefi type 7
[ 0.379 cpu0 kernel] memory: 0x000044000000..0x000044020000 uefi type 4
[ 0.379 cpu0 kernel] memory: 0x000044020000..0x000047666000 uefi type 7
[ 0.379 cpu0 kernel] memory: 0x000047666000..0x000047687000 uefi type 4
[ 0.379 cpu0 kernel] memory: 0x000047687000..0x0000476cc000 uefi type 3
[ 0.380 cpu0 kernel] memory: 0x0000476cc000..0x000047eea000 uefi type 4
[ 0.380 cpu0 kernel] memory: 0x000047eea000..0x000047ef2000 uefi type 3
[ 0.380 cpu0 kernel] memory: 0x000047ef2000..0x000047ff3000 uefi type 4
[ 0.380 cpu0 kernel] memory: 0x000047ff3000..0x000047ffa000 uefi type 3
[ 0.380 cpu0 kernel] memory: 0x000047ffa000..0x000048000000 uefi type 4
[ 0.381 cpu0 kernel] memory: 0x000048000000..0x0000ba869000 uefi type 7
[ 0.381 cpu0 kernel] memory: 0x0000ba869000..0x0000bc430000 uefi type 2
[ 0.381 cpu0 kernel] memory: 0x0000bc430000..0x0000bc470000 uefi type 1
[ 0.381 cpu0 kernel] memory: 0x0000bc470000..0x0000bc4f0000 uefi type 5
[ 0.381 cpu0 kernel] memory: 0x0000bc4f0000..0x0000bc660000 uefi type 6
[ 0.382 cpu0 kernel] memory: 0x0000bc660000..0x0000bc6b0000 uefi type 5
[ 0.382 cpu0 kernel] memory: 0x0000bc6b0000..0x0000bc750000 uefi type 6
[ 0.382 cpu0 kernel] memory: 0x0000bc750000..0x0000bc7a0000 uefi type 5
[ 0.382 cpu0 kernel] memory: 0x0000bc7a0000..0x0000bcaa0000 uefi type 0
[ 0.382 cpu0 kernel] memory: 0x0000bcaa0000..0x0000bcb40000 uefi type 5
[ 0.383 cpu0 kernel] memory: 0x0000bcb40000..0x0000bcb41000 uefi type 2
[ 0.383 cpu0 kernel] memory: 0x0000bcb41000..0x0000bcb44000 uefi type 9
[ 0.383 cpu0 kernel] memory: 0x0000bcb44000..0x0000be0f5000 uefi type 7
[ 0.383 cpu0 kernel] memory: 0x0000be0f5000..0x0000bfa38000 uefi type 4
[ 0.383 cpu0 kernel] memory: 0x0000bfa38000..0x0000bfb8c000 uefi type 7
[ 0.384 cpu0 kernel] memory: 0x0000bfb8c000..0x0000bfe20000 uefi type 3
[ 0.384 cpu0 kernel] memory: 0x0000bfe20000..0x0000bfeb0000 uefi type 5
[ 0.384 cpu0 kernel] memory: 0x0000bfeb0000..0x0000bfec0000 uefi type 7
[ 0.384 cpu0 kernel] memory: 0x0000bfec0000..0x0000bffe0000 uefi type 6
[ 0.384 cpu0 kernel] memory: 0x0000bffe0000..0x0000bffff000 uefi type 7
[ 0.385 cpu0 kernel] memory: 0x0000bffff000..0x0000c0000000 uefi type 4
[ 0.385 cpu0 kernel] memory: 0x000004000000..0x000008000000 uefi type 11
[ 0.385 cpu0 kernel] memory: 0x000009010000..0x000009011000 uefi type 11
[ 0.385 cpu0 kernel] memory: 33 ranges, as the loader handed them over
[ 0.385 cpu0 kernel] ACPI: MADT GICD at 0x8000000, GIC version 3
[ 0.386 cpu0 kernel] ACPI: MADT GICC uid=0 mpidr=0x0 enabled=true gicr=0x0
[ 0.386 cpu0 kernel] ACPI: MADT GICC uid=1 mpidr=0x1 enabled=true gicr=0x0
[ 0.386 cpu0 kernel] ACPI: MADT GICR range 0x80a0000+0xf60000
[ 0.386 cpu0 kernel] ACPI: MADT names 2 GIC CPU interfaces, 2 enabled
[ 0.386 cpu0 kernel] ACPI: GTDT timers: EL1 physical GSIV 30, EL1 virtual GSIV 27, EL2 GSIV 26 (level)
[ 0.387 cpu0 kernel] boot: memory map 0xba86a018+0x318, kernel 0xbaa00000+0xd29000, stack image+0x529000+0x800000
[ 0.387 cpu0 kernel] boot: kernel elf 0xbc1a4018+0x288d90, rsdp 0xbcb43018, boot pml4 0xba86c000
[ 0.387 cpu0 kernel] boot: gop 0xbc7a0000+0x300000 800x600 stride 800 format 1
[ 0.388 cpu0 kernel] boot: boot partition present=1 lba 2048 +69632 blocks guid [72, db, 3b, ab, 58, f1, fb, 4d, b6, 86, c7, 26, b7, 55, 6c, 82]
[ 0.388 cpu0 kernel] boot: log partition guid [41, ba, d7, 2f, 77, 0e, 68, 48, a7, e5, 57, 21, 7d, 5b, ed, b2]
[ 0.388 cpu0 kernel] boot: cmdline 0xbcb40298+63
[ 0.388 cpu0 kernel] boot: root=5e0a13aab4ef5ccc658186be8bcc260d
[ 0.389 cpu0 kernel] boot: slot A, the one the slot table marks
[ 0.389 cpu0 kernel] random: the loader's seed is mixed into the generator's key
[ 0.389 cpu0 kernel] random: RNDR is not mixed: ID_AA64ISAR0_EL1.RNDR is zero, so this CPU has no RNDR
[ 0.389 cpu0 kernel] random: the generator is keyed from 1 source(s), and every random byte is its ChaCha20
[ 0.390 cpu0 kernel] pmm: the firmware map calls 2138558464 bytes usable in 21 entries; managed=2097152000 withheld=27262976 unaligned=14143488, and the three sum to it; frames=1000 reserved_frames=13 base=0x40000000 span=1023
[ 0.391 cpu0 kernel] paging: the direct map holds memory below 0xc0000000 in 1019 2 MiB blocks and 384 4 KiB pages
[ 0.392 cpu0 kernel] mmio: 0xbc7a0000+0x300000 WriteCombining
[ 0.392 cpu0 kernel] ACPI: APIC at 0xbcb43c98 len=268 rev=4 oem="BOCHS" checksummed
[ 0.392 cpu0 kernel] ACPI: FACP at 0xbcb43b18 len=276 rev=6 oem="BOCHS" checksummed
[ 0.392 cpu0 kernel] ACPI: GTDT at 0xbcb43098 len=104 rev=3 oem="BOCHS" checksummed
[ 0.392 cpu0 kernel] ACPI: SPCR at 0xbcb43818 len=80 rev=2 oem="BOCHS" checksummed
[ 0.393 cpu0 kernel] ACPI: MCFG at 0xbcb43a98 len=60 rev=1 oem="BOCHS" checksummed
[ 0.393 cpu0 kernel] ACPI: 5 of 5 tables checksummed under the RSDP at 0xbcb43018
[ 0.393 cpu0 kernel] PSCI: 1.1 through HVC
[ 0.393 cpu0 kernel] percpu: BSP cpu_id=0 mpidr=0x0
[ 0.394 cpu0 kernel] mmio: 0x80a0000+0xf60000 Uncacheable
[ 0.394 cpu0 kernel] mmio: 0x8000000+0x10000 Uncacheable
[ 0.394 cpu0 kernel] GIC: v3 distributor at 0x8000000; SGIs and the virtual timer's PPI 27 (level) taken at priority 0x80
[ 0.394 cpu0 kernel] GIC: this CPU's redistributor at 0x80a0000, its SGIs and timer enabled
[ 0.395 cpu0 kernel] counters: cpu0 reads smi=false aperf=false mperf=false hwp_request=false hwp_request_pkg=false energy_perf_bias=false
[ 0.395 cpu0 kernel] symbols: loaded 18977 kernel symbols
[ 0.395 cpu0 kernel] clock: the generic timer counts at 24000000 Hz; no wall clock is read on this architecture
[ 0.396 cpu0 kernel] timer: the EL1 virtual timer, PPI 27, stopped until the scheduler arms it
[ 0.396 cpu0 kernel] Boot: CPU ready (0ms)
[ 0.396 cpu0 kernel] ACPI: RSDP at 0xbcb43018
[ 0.396 cpu0 kernel] ACPI: MCFG found at 0xbcb43a98
[ 0.397 cpu0 kernel] ACPI: ECAM base address: 0x4010000000
[ 0.397 cpu0 kernel] mmio: 0x4010000000+0x10000000 Uncacheable
[ 0.397 cpu0 kernel] PCI: Enumerating devices...
[ 0.397 cpu0 kernel]   PCI 00:00.0 [0600] vendor=1b36 device=0008 prog_if=00 bars=[]
[ 0.397 cpu0 kernel]   PCI 00:01.0 [0c03] vendor=1033 device=0194 prog_if=30 bars=[bar0=0x8000004000]
[ 0.398 cpu0 kernel]   PCI 00:02.0 [00ff] vendor=1af4 device=1005 prog_if=00 bars=[bar0=none(it is an I/O BAR at port 0x0, not memory) bar1=0x10002000 bar4=0x8000000000]
[ 0.398 cpu0 kernel]   PCI 00:03.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10001000]
[ 0.398 cpu0 kernel]   PCI 00:04.0 [00ff] vendor=1b36 device=0005 prog_if=00 bars=[bar0=0x10000000]
[ 0.407 cpu0 kernel] PCI: Enumeration complete, 5 functions.
[ 0.408 cpu0 kernel] pcidev: firmware declared root bridge memory: mem 0x10000000..0x10100000, mem 0x8000000000..0x8000100000, mem 0x4000000..0x8000000, mem 0x10100000..0x3f000000, mem 0x4010000000..0x4020000000, mem 0x8000100000..0x10000000000
[ 0.408 cpu0 kernel] pcidev: 5 functions; 5 run(s) of 2 MiB or more below 0xfec00000 and 2 from 0x100000000
[ 0.408 cpu0 kernel] pcidev:   0x0..0x4000000 (64 MiB)
[ 0.409 cpu0 kernel] pcidev:   0x8000000..0x9010000 (16 MiB)
[ 0.409 cpu0 kernel] pcidev:   0x9011000..0x10000000 (111 MiB)
[ 0.409 cpu0 kernel] pcidev:   0x10003000..0x40000000 (767 MiB)
[ 0.409 cpu0 kernel] pcidev:   0xc0000000..0xfec00000 (1004 MiB)
[ 0.409 cpu0 kernel] pcidev:   0x100000000..0x8000000000 (520192 MiB)
[ 0.410 cpu0 kernel] pcidev:   0x8000008000..0xffffffffffffffff (17592185520127 MiB)
[ 0.410 cpu0 kernel] mmio: 0x9050000+0x20000 Uncacheable
[ 0.410 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000: GBPA 0x101000, every transaction aborts while SMMUEN is clear
[ 0.410 cpu0 kernel] smmu-selftest: 00:03.0, StreamID 0x18, is given no route, as a function never enumerated is not
[ 0.411 cpu0 kernel] IOMMU: SMMUv3 at 0x9050000 armed, CR0ACK 0xd: 4 functions' streams aborting in a table of 64, every other entry invalid; a CMD_SYNC consumed; events on SPI 106
[ 0.411 cpu0 kernel] mmio: 0x10000000+0x1000 Uncacheable
[ 0.412 cpu0 kernel] mmio: 0x10001000+0x1000 Uncacheable
[ 0.412 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x40800000, on the entry its stream starts with, answered 0xdead0002: refused
[ 0.413 cpu0 kernel] iommu: domain1 root=0x40603000 context=0x40604000 asid=1 addresses from 0x400000000000 to 0x1000000000000
[ 0.413 cpu0 kernel] iommu: 00:04.0 moves to domain1
[ 0.413 cpu0 kernel] smmu-selftest: 00:04.0's write at 0x400000000040, mapped to 0x40800040, answered 0x0: landed there
[ 0.413 cpu0 kernel] smmu-selftest: 00:03.0's write 1 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.414 cpu0 kernel] smmu-selftest: 00:03.0's write 2 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.414 cpu0 kernel] smmu-selftest: 00:03.0's write 3 at 0x40800000, under no route, answered 0xdead0002: refused
[ 0.414 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=1 streamfaults=1 first=y C_BAD_STE
[ 0.415 cpu0 kernel] iommu: DMA FAULT owner=none unit0 stream=0x18 addr=0x0000000000000000 access=none reason=0x04 domain=unknown bme=unknown-function unitfaults=2 streamfaults=2 first=y C_BAD_STE
[ 0.415 cpu0 kernel alert] panic: rebooting in 60 s, timed by the calibrated clock

10:07:39   FAIL  virt_smmu  (572ms)
10:07:39   --- 1 guests, 1 of them not the shipping kernel, 1 kernel build(s): ["boot-actuators,test-actuators"]

10:07:39 host: fastest boot 432 ms against the reference 1424 ms — liveness ceilings paid at 1.00x
10:07:39 host: 14 core(s); a guest wider than that waits vcpus/cores longer again
10:07:39 failures:
10:07:39     virt_smmu: the selftest never said "which its domain no longer maps"

10:07:39 test result: FAILED. 0 passed, 1 failed, 0 invalidated, 1 total (4.3s; workers: 4s building, 572ms testing)
10:07:39 [toyos] this red run's serial logs are kept at <worktrees>/toyos-arm-g2/target/red-run-serial/toyos-tmp-22564-0
error: test failed, to rerun pass `--test toyos-build`

Caused by:
  process didn't exit successfully: `<worktrees>/toyos-arm-g2/target/debug/deps/toyos_build-a969be0cacbee86c virt_smmu` (exit status: 1)
EXIT=1

@Japabu

Japabu commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator Author

T14 reading at 3fc00867c, run by the orchestrator from metal-r3/request.txt.

The staged request carried no sha256 lines. The orchestrator therefore hashed the two staged images (testcases 16e8c2ec…, testcases-watchdog e6a7b1f4…) and checked each hash in the same command that flashed that image. Both boots' supervisor line reads build 3fc00867c70fd4e1ec9586b819ba85e48e9ecc38 clean, which ties the images to this head.

Judge (boot:testcases): EXIT=0, 249 passed, 0 failed, 2 boot(s).

@Japabu
Japabu marked this pull request as ready for review October 10, 2026 10:15
@Japabu
Japabu enabled auto-merge October 10, 2026 10:15
@Japabu
Japabu added this pull request to the merge queue Oct 10, 2026
Merged via the queue into main with commit a09dce9 Oct 10, 2026
6 checks passed
@Japabu
Japabu deleted the wt/toyos-arm-g2 branch October 10, 2026 10:54
Japabu added a commit that referenced this pull request Oct 10, 2026
…ring-up (#825) and the hotkey removal (#824), into consent

The one conflict is Profile::arch in tests/common/qemu.rs: main adds
HeadlessUsbSpare and this branch adds Desktop to the same x86-64 arm;
both stay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant