Skip to content

Disable ftruncate_flush_race, and file the boot-timeout verdict's blind spot - #576

Merged
Japabu merged 4 commits into
mainfrom
wt/toyos-ftrunc
Sep 28, 2026
Merged

Japabu merged 4 commits into
mainfrom
wt/toyos-ftrunc

Conversation

@Japabu

@Japabu Japabu commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

What

  1. Disable ftruncate_flush_race in src/redlist.rs, behind its existing
    issue issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md.
    The issue gains one evidence line: red in the orchestrator's nightly for PR
    Every guest boots the UEFI firmware the host's QEMU declares; ovmf/ and aavmf/ go #572 at 87629411 with "the truncate did not serialise with the stalled
    flush". Status is set to expected-red, as src/redlist.rs's gate
    requires. A flaky test is disabled at once, never re-run. The issue also
    now names an owner and a machine-checkable exit condition.

  2. File a harness issue,
    issues/build/a-boot-timeout-verdict-quotes-stdio-alone-and-never-the-16550-log.md
    (kind: tooling, owner tests/common/qemu.rs, held by the orchestrator).
    wait_for_ready reads the 16550 log back only when the ready marker is not
    the default one, so a boot that panics before virtio-console comes up —
    which writes only to the 16550 — times out with a verdict that quotes stdio
    alone and never shows the panic. Evidence: the same PR Every guest boots the UEFI firmware the host's QEMU declares; ovmf/ and aavmf/ go #572 control run at
    87629411 held EARLY PANIC: panicked at library/alloc/src/alloc.rs:659:9: memory allocation of 4096 bytes failed
    in its 16550 log while the verdict said only "Boot timed out". Exit: the
    timeout verdict quotes the 16550 file's tail the same way the
    Disconnected arm already does, rather than adding a second reader, shown
    by a test that stages an early panic.

Gates

gate exit
cargo test --lib 0 (384 passed, 1 ignored)
cargo test --test toyos-build -- --list 0
cargo run -- --known-red ftruncate_flush_race 0, "YES, disabled"

🤖 Generated with Claude Code

https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j

…erdict's blind spot

The orchestrator's nightly reproduced the same failure on PR #572 at
8762941, whose diff is a firmware selection change that never touches the
VFS. A flaky test is disabled at once, never re-run.

That run also showed wait_for_ready (tests/common/qemu.rs:5157) reading the
16550 log only when the ready marker is not the default one: a boot that
panics before virtio-console comes up writes only to that file, and the
timeout's own panic quotes stdio alone, so the panic line never reached the
verdict. Filed as a defect for the harness to fix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
@Japabu
Japabu marked this pull request as ready for review September 28, 2026 11:52
@Japabu

Japabu commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Review of #576 at 50b02c76. CI host passed on this head (run 36418236106, conclusion success), and the PR is not a draft. The branch changes no production code: src/redlist.rs +4, issues/ +38/−2, 3 files, +42/−2. I re-ran the host gates at this head, each exit 0: cargo test --lib (384 passed, 1 ignored), cargo test --test toyos-build -- --list (the run names the test as disabled, with its issue), and cargo run -- --known-red ftruncate_flush_race ("YES, disabled — it does not run.").

Attribution. Nothing shows the red is #572's, so this disable does not hide a regression on main:

Coverage lost. This test was the only runtime witness that SYS_FTRUNCATE waits for a flush's metadata window. It was also the only host-FAT and fatgen103 check of a truncate that lands after a stalled flush. fs_truncate_persist and writeback_durability truncate with no flush racing them. The compile-time witness remains.

BLOCKER
(none)

NOTE

  • issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md:1 — the issue now backs a disable but has no owner and no exit condition — a disable is a compromise, and the tracker rule needs an owner, evidence and an exit for one.
  • issues/build/a-boot-timeout-verdict-quotes-stdio-alone-and-never-the-16550-log.md:3 — kind: defect — the README puts the harness under tooling, and says defect is the OS.
  • issues/build/a-boot-timeout-verdict-quotes-stdio-alone-and-never-the-16550-log.md:31 — "held by the orchestrator" contradicts status: open, which means nobody is holding it — pick one.
  • tests/common/qemu.rs:5145 — the Disconnected arm already reads uart_log and quotes it in its panic — the harness issue's exit should reuse that path instead of adding a second reader.
  • Every guest boots the UEFI firmware the host's QEMU declares; ovmf/ and aavmf/ go #572 — before its landing, it needs ftruncate_flush_race measured alone on stock edk2 (row lifted locally) against main. With the test disabled, nothing else will see a rate change caused by the firmware.

REMOVE

  • issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md:46-47 — "Every guest boots the UEFI firmware the host's QEMU declares; ovmf/ and aavmf/ go #572's diff is a firmware selection change; it does not touch the VFS." — misleading: this failure depends on timing and CPU placement, and Every guest boots the UEFI firmware the host's QEMU declares; ovmf/ and aavmf/ go #572 changes the platform every guest boots on.
  • issues/build/ftruncate-flush-race-reds-intermittently-and-nothing-says-why.md:49-50 — "A flaky test is disabled at once: … says YES, disabled." — status: expected-red and the redlist row already say this. It rewrites the deleted "NOT ON THE LIST" line when that line should simply have been deleted.
  • issues/build/a-boot-timeout-verdict-quotes-stdio-alone-and-never-the-16550-log.md:9-11 — "reads the 16550 log … back only inside the Err(RecvTimeoutError::Timeout) arm" — false: the Disconnected arm reads and quotes it too (tests/common/qemu.rs:5147-5151).
  • issues/build/a-boot-timeout-verdict-quotes-stdio-alone-and-never-the-16550-log.md:17-22 — the second paragraph — it quotes a source comment word for word, which will rot. Its example verdict "nothing at all" also contradicts the evidence run, whose verdict carried firmware and loader lines.
  • PR body — "so this is the same rate the issue already recorded, not a new mechanism" — the rate comes from one sample and was never measured. This becomes main's record.

LAND AFTER NAMED CHANGES

Japabu and others added 3 commits September 28, 2026 14:21
…ess issue to kind: tooling with a status that agrees with its owner, and reuse the Disconnected arm's uart_log read instead of adding a second one

The ftruncate-flush-race issue named a rate and a refutation but nothing
owed: it now names the actuator's owner and an exit a machine can check
(the capture starts holding when set_len entered the kernel relative to
the stall's start). Its two misleading sentences about #572 and about the
redlist disable are deleted rather than reworded.

The boot-timeout-verdict issue is the development machine, not the OS, so
it moves to kind: tooling per issues/README.md, and its status moves to
assigned to agree with its "held by the orchestrator" owner line. Its
false claim that wait_for_ready reads uart_log only inside the Timeout
arm is deleted (the Disconnected arm reads it too), and the paragraph
that quotes a source comment verbatim and gives a verdict example the
evidence run contradicts is deleted. Its exit condition now points at the
Disconnected arm's existing fs::read_to_string(uart_log) read rather than
asking for a second reader.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
…ing it reworded

Line-bounded deletion of the false claim about wait_for_ready's uart_log
read left a following sentence whose "that arm" had no antecedent.
Problematic prose is deleted, not reworded: the whole sentence goes. The
title already states the defect and the Evidence/Exit paragraphs already
carry the rest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W6rME2DoqwjcYFStYHHY4j
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant