From: "Luck, Tony" <tony.luck@intel.com>
To: Breno Leitao <leitao@debian.org>
Cc: Borislav Petkov <bp@alien8.de>, Thomas Gleixner <tglx@kernel.org>,
"Ingo Molnar" <mingo@redhat.com>,
Dave Hansen <dave.hansen@linux.intel.com>, <x86@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>,
Jonathan Corbet <corbet@lwn.net>,
Shuah Khan <skhan@linuxfoundation.org>,
Randy Dunlap <rdunlap@infradead.org>,
<linux-edac@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<linux-doc@vger.kernel.org>, <kernel-team@meta.com>
Subject: Re: [PATCH 2/2] x86/mce: Add mce=panic_on_ce_count to panic on a corrected error flood
Date: Fri, 21 Aug 2026 09:50:19 -0700 [thread overview]
Message-ID: <aoiBy3vg9eSvGhIu@agluck-desk3> (raw)
In-Reply-To: <20260821-mce-panic-on-storm-v1-2-7a465c708d82@debian.org>
On Fri, Aug 21, 2026 at 03:24:08AM -0700, Breno Leitao wrote:
> A machine check bank producing corrected errors faster than the kernel can
> drain them is not a machine anyone wants to keep in service, but nothing
> takes it out. mce_track_storm() throttles CMCI for the bank and the
> machine stays up.
>
> Count corrected errors per bank and add mce=panic_on_ce_count=<count>
> and panic the host if we have more events than set.
FYI. I don't think this needs to be fixed, but you should be aware and
perhaps document the shared bank details.
This won't count accurately for banks that are shared by multiple logical
CPUs (you've inherited this from the storm detection code that introduces
this problem).
E.g. a machine check bank reporting L2 errors is shared by both logical CPUs
on a core on P-core systems, and by all cores on a module on E-core systems.
But the storm code keeps <per-CPU,per-bank> counts. So if an L2 instance
is throwing out many errors, some will be counted by one of the CPUs, while
other errors are counted separately by the other CPUs sharing the bank.
The net effect is that a storm won't be trigged until one of the CPUs tracking
a shared bank hits the threshold.
Similarly there may be more errors logged than you expect before your
panic fires.
-Tony
prev parent reply other threads:[~2026-08-21 16:50 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 10:24 [PATCH 0/2] x86/mce: Rate-limit storm notices and add a corrected error ceiling Breno Leitao
2026-08-21 10:24 ` [PATCH 1/2] x86/mce: Rate-limit the CMCI storm transition notices Breno Leitao
2026-08-21 16:18 ` Luck, Tony
2026-08-21 16:35 ` Breno Leitao
2026-08-21 10:24 ` [PATCH 2/2] x86/mce: Add mce=panic_on_ce_count to panic on a corrected error flood Breno Leitao
2026-08-21 16:50 ` Luck, Tony [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aoiBy3vg9eSvGhIu@agluck-desk3 \
--to=tony.luck@intel.com \
--cc=bp@alien8.de \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kernel-team@meta.com \
--cc=leitao@debian.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-edac@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=rdunlap@infradead.org \
--cc=skhan@linuxfoundation.org \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox