Repository navigation
Ctrl+Alt+D and the blocked-task dump are removed, and the hard-lockup row holds the NMI frame's rip to the lock's spin - #824
Conversation
… are removed
The owner, told the hotkey was kept on purpose as the last-resort diagnostic
for a wedged machine, ruled: "i dont want it. i want it removed."
kernel/src/keyboard.rs no longer recognises Ctrl+Alt+D; every transition is
queued. Everything only the hotkey reached goes with it:
- kernel/src/sched/dump.rs (the request, the per-CPU report, the NMI probe of
a silent CPU, the process-table census and the summary) and
sched/dump_request.rs, with its loom model kernel/loom/tests/dump_request.rs,
the `dump-report-relaxed` negative control in both manifests and its row in
src/ci.rs. `drain_irqs` takes no `Entered` and serves no report.
- The driver's dump-only readers: `ready_len`, `for_each_stopped`,
`for_each_dying`, `running_id`, `ParkedInfo`, `for_each_parked`; the pure
core's `CpuSched::ready_len` and `ParkedView::{class, since, ext}`;
`process::try_for_each_thread`, `ThreadCensus` and `ThreadEntry::name_str`;
the console drain's `stats()` and its three counters, and
`log::read::Published::lost`.
- The NMI handler's `note_nmi` store; the handler is crate::hardlockup's
sample alone, and `send_nmi` compiles only into a test kernel, the only
caller left (the `nmi-nested` actuator and the hard-lockup probe).
- The panel's held report: `paint_report`, `hold_report`, the `REPORT` cell,
its hold timers, and the probe pixels that told a repaint from the report
(`Watch`, `PROBE_*`, `sample_probes`, `panel_carries_report`, `get_pixel`,
`glyph_ink`).
- The `dump-deaf-cpu` actuator and the T14 row `dump_nmi_probe` that judged
it, its `testcases-deaf` boot, its flashable-arm entry in src/metal.rs, its
measured prices, its judge in tests/common/faults.rs, and `lan_hold`, the
job that only held that boot open. tests/common/qemu.rs's `QmpInput`, whose
one caller pressed the hotkey, goes too.
What stays, and why: `irq_census::census` (crate::census prints it where the
machine stops), `kthread::is_kernel_task` (quiesce), `irqchip::kick_cpu`, the
NMI vector and its nested-NMI guard (crate::hardlockup), and the panel's
fatal-path latch with its outwait.
`screen_fatal_behind_a_painter` is rewritten rather than deleted: the latch a
fatal path must take from a painter that will never let go is still the
panel's, and only a boot checkpoint's painter is left to stage it. The
`panel-painter-stalls` actuator now takes the latch from the boot thread after
the last boot phase and goes fatal holding it, and the test no longer presses
anything.
Records: kernel/CLAUDE.md drops the caveat about pressing the hotkey; the
README's row no longer claims a dump on the panel. Five issues close, each
about the removed feature alone:
blocked-dump-cannot-fire-on-a-total-freeze (its residual line, that `ps` and
`stats` have no cross-CPU view of what the handles do not publish, is the
larger half issues/blocked-time-is-invisible-while-the-park-lasts.md already
records), nothing-can-freeze-this-machine-from-outside (a track to fire the
dump at a frozen machine), the-deaf-cpu-actuator-arms-on-three-seconds-of-
guest-clock, lan-hold-holds-a-boot-open-for-a-flat-twenty-seconds and
which-pass-drain-irqs-is-entered-from-is-gated-only-by-a-nightly-guest. The
small-kernel track's step 10 no longer keeps a hotkey on the i8042 or
declares a USB-only machine without one, and steps 6.5 and 7.2 no longer
carry the dump. Each issue that advised pressing it to read a wedge names
what exists instead: QMP `info registers -a` taken before any input, and on
metal crate::hardlockup's sealed black-box record; where nothing in the tree
meets an exit any more, the issue says so.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… a userland it never reaches The painter now goes fatal from the boot thread after the last boot phase, so the boot ends before `===READY===`; the test waits for the line the painter says as it goes fatal instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Mutation for --- a/kernel/src/drivers/panic_console/mod.rs
+++ b/kernel/src/drivers/panic_console/mod.rs
@@ -624,6 +624,5 @@ fn seize() -> bool {
core::hint::spin_loop();
}
}
- PAINTING.store(true, Ordering::SeqCst);
- true
+ false
} |
|
Review of BLOCKER
NOTE
SEND BACK |
|
T14 at |
…ss::name, which only the dump read Each is `pub` in a library crate, so `dead_code` never saw them go uncalled when the blocked-task dump, their last reader, was deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…our records say what the dump's removal left
The deleted `dump_nmi_probe` row was the one test that asserted the NMI
frame's `rip` lands where the CPU stood, and that `rip` still ships as the
lockup record's `pc=`. `hard_lockup_chain` now reads the record's own `pc`
line and requires it to resolve into `sync::Lock::lock`, whichever `Lock<T>`
the linker folded it under, the way `deadline_wedge_chain` holds `SEAL_PC` to
`WEDGE_SPIN`. On the boot-actuators kernel the probe's `PROBE_LOCK.lock()` is
a call into that function, whose spin calls out only to serve an owed
shootdown or SMI. `bootlog`'s source check pins the record's ` pc={}` and
`Lock::lock`'s signature.
Records:
- the small-kernel track states the owner's ruling as he gave it:
Ctrl+Alt+D removed, not every hotkey;
- the boot-stick issue keeps his acceptance test as he set it and leaves its
replacement to him;
- the window-child freeze's exit names the trace diary and `/system/bin/trace`
as what can read whether each CPU kept passing, and what limits that read;
- `spawned-process-never-starts` says the hard-lockup record reaches one of
the three causes the dump's probe told apart;
- `null-sink-applies-one-connect` no longer says no shipped program reads the
diary.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… run under load Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Mutation for --- a/kernel/src/arch/x86_64/idt/nmi.rs
+++ b/kernel/src/arch/x86_64/idt/nmi.rs
@@ -42,7 +42,7 @@
"push r10",
"push r11",
"push rbp",
- "mov rdi, [rsp + {rip_offset}]",
+ "mov rdi, [rsp + {rip_offset} + 8]",
"mov rsi, [rsp + {rsp_offset}]",
"mov rdx, [rsp + {rflags_offset}]",
"mov rbp, rsp", |
|
T14 at |
|
Round 2 review of First-round BLOCKERs
First-round NOTEs All five are answered at this head:
The guest-suite red (41 of 44 at
BLOCKER (none open) NOTE
LAND |
The stage 5 usbd step keeps main's MSI-X and decoder facts (#821) and this branch's removal of Ctrl+Alt+D; keyboard.rs takes main's toyos-usbhid `apply` and this branch's hotkey removal from handle_key. tests/common/qemu.rs keeps `QmpInput`: this branch deleted it with the hotkey test, its one caller then, and #821's usb_keyboard_rollover is a caller now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…nst the drain_irqs change Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…nsole wire (#805), into the Ctrl+Alt+D removal Three conflicts, each a hunk of #805's beside a hunk this branch deleted: - kernel/src/actuator.rs: #805's three wire actuators (wire-held-across-the-stop, wire-kept-through-the-stop, wire-held-at-the-last-word) stay; dump-deaf-cpu, which #805's side kept only as context, stays removed. - kernel/src/log/console.rs: #805's let_go and staged module stay; the RECORDS/LOST/PARKS counters and stats(), read only by the removed sched::dump, stay removed, as do their stores, which merged clean. - kernel/src/sched/driver.rs: #805's for_each_ready, read by console::staged::say_klogd_unrun, stays; ready_len, for_each_stopped, for_each_dying, running_id, ParkedInfo and for_each_parked, read only by the removed sched::dump, stay removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
Merge of
|
…ring-up (#825) and the hotkey removal (#824), into consent The one conflict is Profile::arch in tests/common/qemu.rs: main adds HeadlessUsbSpare and this branch adds Desktop to the same x86-64 arm; both stay. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…uthority (#826), the SMMUv3 bring-up (#825), the hotkey removal (#824) and evidence on the pull request (#835), into virtio-sound and the shared PCI claim Two conflicts, both resolved by keeping every hunk of both sides: - tests/common/qemu.rs: the virtio-gpu device arm (this branch) and the two iommu-testdev arms (#825) are separate `if`s on separate Shape fields; HeadlessVirtioGpu and VirtSmmu are disjoint profiles, so no machine gains or reorders a device. - tests/toyos.rs RUST_SKIP: virtio_sound_counts (this branch) and partition_grant, update_idle_slot (#826) all kept. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
… batch: the icons' and wallpaper's digests hash with toyos-sha2 Cargo.toml keeps both sides' entries: main's toyos-sha2 and usbd members and toyos-sha2 dependency, and the batch's removal of `image`. `sha2` was replaced by toyos-sha2 on main and left in place on the batch, whose #813 and #814 added two tests hashing with it; as main meant every SHA-256 the build takes to be toyos-sha2's, those two tests now hash with toyos-sha2 and the root manifest drops `sha2`. Cargo.lock is the batch's, re-resolved by `cargo metadata --offline`; its delta from the batch's head is exactly main's delta from the merge base. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
, #826, #835, #833, #831 and #822, into wt/toyos-netperf No hunk conflicted. userland/netstack/src/main.rs took both sides: main's removal of `mod device` and the branch's batched `node.receive` and its module-doc line. The TCP window-scaling and loss-probe commits main carries were already in the branch from #820, so their files merged to main's text plus the branch's own delta. Both lockfiles are main's and pass `cargo metadata --locked`. The branch's new issue still cites `VirtioNet::poll_rx` and `toyos_i219::RX_BUDGET` as they stand on main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
The owner, told Ctrl+Alt+D was kept on purpose as the last-resort diagnostic for a wedged machine, ruled: "i dont want it. i want it removed." This branch removes the hotkey and everything only it reached.
Net against
mainataade01db2: 60 files, +181 −1895. Production code (kernel/src,kernel/pure,src): +55 −1241. Tests (tests,kernel/loom,kernel/sim): +16 −309. Records (issues,README.md,kernel/CLAUDE.md): +110 −342.origin/mainata1eb2c0b9is merged in (#816, #817, #821, #805 and what came between).What changed, per decision
The hotkey.
kernel/src/keyboard.rsno longer recognises Ctrl+Alt+D, so every key transition is queued.The dump.
kernel/src/sched/dump.rsandsched/dump_request.rsare deleted: the request word, the per-CPU report, the NMI probe of a silent CPU, the process-table census and the summary. Their loom modelkernel/loom/tests/dump_request.rsgoes, and so do thedump-report-relaxednegative control in both manifests and its row insrc/ci.rs.drain_irqsno longer takes anEnteredor serves a report.Readers that only the dump called, each with no other caller (all searched with
git grepacross the tree):ready_len,for_each_stopped,for_each_dying,running_id,ParkedInfoandfor_each_parked.CpuSched::ready_lenandParkedView::{class, since, ext}, and behind themTask::since, the linear states'sinceandWaitClass::name: eachpubin a library crate, sodead_codenever saw them go uncalled.process::try_for_each_thread,ThreadCensusandThreadEntry::name_str.log::console::stats()with itsRECORDS/LOST/PARKScounters, andlog::read::Published::lost.The NMI vector now does only
crate::hardlockup's sample: thenote_nmistore is gone.irqchip::send_nmi(both arches) compiles only into a test kernel, because its only callers left are thenmi-nestedactuator and the hard-lockup probe. Without thecfgthe shipping kernel failsdead_code.The panel's held report is deleted:
paint_report,hold_report, theREPORTcell, its hold timers, and the probe pixels that told a repaint apart from the report (Watch,PROBE_*,sample_probes,panel_carries_report,get_pixel,glyph_ink).Tests and actuators that drove the dump:
dump-deaf-cpuactuator is deleted, along with the T14 rowdump_nmi_probe, itstestcases-deafboot, its entry insrc/metal.rs's flashable arms, its three measured prices intests/metal/, and its judge intests/common/faults.rs.lan_holdis deleted: it was the job that only held that boot open.What stays, and why:
irq_census::census:crate::censusprints it where the machine stops.kthread::is_kernel_task: quiesce uses it.irqchip::kick_cpu: the xHCI driver and the SMI path use it.crate::hardlockupneeds them.seize,OUTWAIT).screen_fatal_behind_a_painteris rewritten, not deleted.seize). No cheaper tier holds it.panel-painter-stallsnow takes the latch from the boot thread right afterboot_phase!("complete")and goes fatal holding it.ready_marker: HELD) instead of===READY===, and asserts as before: the fatal fill, the line on the panel, and the reset at the bound.Records.
kernel/CLAUDE.mddrops the caveat about pressing the hotkey.README.mdrow no longer claims a dump on the panel.hardlockup/mod.rs,clock.rs,irq_census.rs,src/sourcegate.rs,src/qemu.rs,kernel/sim/tests/deadline_claim_race.rs,tests/common/irqcensus.rs).Issues closed. Five are about the removed feature alone:
blocked-dump-cannot-fire-on-a-total-freeze. Its residual line ("psandstatshave no cross-CPU view of what the handles do not publish") is the larger half thatissues/blocked-time-is-invisible-while-the-park-lasts.mdalready records.nothing-can-freeze-this-machine-from-outside, a track to fire the dump at a frozen machine.the-deaf-cpu-actuator-arms-on-three-seconds-of-guest-clock.lan-hold-holds-a-boot-open-for-a-flat-twenty-seconds.which-pass-drain-irqs-is-entered-from-is-gated-only-by-a-nightly-guest.Enteredno longer exists.Every citation of their slugs is moved:
the-host-cannot-reach-the-t14-while-it-runs-toyos.mdno longer points atlan_hold.hard_lockup_chainasserts the NMI frame'srip. The deleteddump_nmi_proberow was the one test that held thatripto where the CPU stood, and theripstill ships as the lockup record'spc=. The judge now reads the record'spc=line (bootlog::LOCKUP_PC, afterLOCKED_UP) and requires it to resolve intosync::Lock::lock(bootlog::LOCK_SPIN:<kernel::sync::Lock<and>>::lock+), asdeadline_wedge_chainholdsSEAL_PCtoWEDGE_SPIN.probe::go_deafcalls<kernel::sync::Lock<()>>::lock, which the linker folds with otherLock<T>::locks at one address, so the name the symbol table returns is any of them; hence the two halves. Its spin calls out only toShootdown::serve_if_owedfor an owed shootdown or SMI.bootlog's source check pins the kernel's" pc={}", At(pc)andLock::lock's signature.+ 8mutation the pc iscs,0x8, which resolves to no symbol. The mutation is posted (Ctrl+Alt+D and the blocked-task dump are removed, and the hard-lockup row holds the NMI frame's rip to the lock's spin #824 (comment)). The T14 read both arms at427dce4b0(see Metal).The merge of USB HID reports are decoded by toyos-usbhid, which believes a rollover report's modifiers and not its slots #821.
kernel/src/keyboard.rsmerged without conflict. It keeps main'sapplyovertoyos_usbhidtransitions and this branch'shandle_keywith no hotkey.tests/common/qemu.rskeepsQmpInput. This branch had deleted it because its one caller pressed the hotkey, but USB HID reports are decoded by toyos-usbhid, which believes a rollover report's modifiers and not its slots #821'susb_keyboard_rollovernow calls it. The file is identical to main's.Small-kernel track (
issues/the-kernel-is-small-interrupts-post-and-threads-wait.md):pass, and drops the 2026-09-30 ruling about the dump's panel.Issues that advised pressing the hotkey now name what exists instead:
desktop-window-child-freeze.md: its exit named the dump's NMI probe. It now names the trace diary (kernel/src/trace.rs), which every CPU writes from its timer and its scheduler, printed by/system/bin/trace: a CPU whose newest record stands behind the others' stopped passing, and anIdleEnterthere says it went to halt. It also says what limits that read: 8192 records a CPU, and a program has to be spawned after the freeze to take it. It has never been taken on a reproduction.spawned-process-never-starts.md: QMPinfo registers -ain a guest, and on metalcrate::hardlockup's sealed record, which reaches one of the three causes the dump's probe told apart. Its header excludes a halted CPU and a CPU withIFset, and the issue says so.null-sink-applies-one-connect.md:/system/bin/tracesays whether soundd's mix thread parked and was never woken; no record carries the deadline it parked with.pulling-the-boot-stick-freezes-the-t14.md: the acceptance test the owner set was a stick pulled with Ctrl+Alt+D still answering; the hotkey is gone, so what the pull must leave answering is his to name again. The branch does not choose it.Owed by this change:
a-fatal-path-entered-outside-a-panic-holds-the-panel-with-interrupts-open.mdnow says itsIFreading was taken with the actuator in a scheduler pass and has not been taken since the move to the boot thread.Gates, at head
aade01db2aade01db2mergesorigin/mainata1eb2c0b9(#805, the stop takes the console wire). How each of its three conflicts was resolved is in the merge commit and in a comment on this PR. Logs are in the orchestrator's scratchpad, underorch/ctrlaltd/merge/.cargo run -- --ci host > ci-host.log 2>&1gaveEXIT=0("Host: 77 step(s), all green", 09:56:56 UTC).cargo run -- --build-onlygaveEXIT=0, thencargo run -- --build-only --arch aarch64gaveEXIT=0.cargo test > guest-suite.log 2>&1gaveEXIT=0: toyos-build 50 of 50 ("50 passed, 50 total"), and the harness's host-side tests 347 passed with 15 ignored. Ceilings were at 1.00x.uptimegave load 28.10 29.04 37.39 before and 21.98 27.12 35.61 after.a9b68f92b, before this merge, every gate gaveEXIT=0, and the guest suite passed 45 of 45 at load 90 to 98.22b7bb464, the suite gaveEXIT=1and passed 41 of 44:virt_smp,virt_mask_windowsandvirt_off_names_the_cpus_left_onwent silent together at load 54 to 72. That run is recorded inissues/a-counters-read-under-host-load-can-go-silent-for-15-s.md, together with the evidence against this branch'sdrain_irqschange as the cause:2375834a6already carries the change, and its guest kernel is the same. Its whole suite passed 43 of 43, those three included.seize: posted as a comment on this PR.427dce4b0. The stop takes the console wire from klogd for good and holds it to the machine's end; flush_final goes #805's kernel changes, which this merge brings in, have not been run on the T14 ataade01db2.git diff 427dce4b0 a9b68f92b -- kernelis hunk for hunkgit diff 46632bf25 5a3b74345 -- kernel; only blob ids and line offsets differ. Sokernel/src/keyboard.rschanged only by main's own lines, and the T14 readings at427dce4b0carry.427dce4b0, run by the orchestrator:boot:testcases boot:windowscase hard_lockup_ends_a_deaf_cpu,251 passed, 0 failed, 4 boot(s), withPASS hard_lockup_ends_a_deaf_cpu(pc=…<kernel::sync::Lock<()>>::lock+0x125).+ 8mutation on hardware:FAIL hard_lockup_ends_a_deaf_cpu … "pc=0x0000000000000008",JUDGE_EXIT=1,REVERT_EXIT=0. Both arms are posted.What I am unsure of
issues/clippy-stage-two-is-lints-one-at-a-time.mdandissues/idle-stack-guard-price-nearly-doubled-since-its-return.mdstill namedump.rs,deaf_windowanddump_nmi_probe. These are measurements recorded at a past commit and still true of that commit, so I left them as they are.pcassertion's two halves are read off this build's symbol table. ALock::lockthat the compiler inlines into its caller would name the caller and red the row, and that would be a correct red: the record would then no longer name the spin.🤖 Generated with Claude Code
https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C