The timer subsystem's reliable real-HW sources are all built but never called, and one calibration spin can hang boot.
Boot hang risk: arch/x86_64/time/timer/init.rs:56-58 calibrates the TSC against the PIT with an un-timed spin (while (inb(0x61)&0x20)==0 {}). On a modern board with no functional PIT (some laptops, some hypervisors) that gate bit never toggles and boot hangs. Add a timeout and prefer CPUID 0x15/0x16 then HPET before PIT.
Dead reliable paths:
- TSC-deadline mode is fully implemented (arch/.../apic/timer_ops.rs) but never called; the live LAPIC timer is hardcoded periodic and is_deadline_mode() hardcodes false. Deadline mode is the modern, C-state-robust source.
- HPET calibration and the HPET comparator IRQ exist but the only path that calls init_with_hpet (arch/x86_64/api.rs:31 init_with_acpi) has no caller, so HPET never calibrates the TSC.
- The RTC IRQ8 periodic heartbeat is fully built (rtc/periodic.rs:34, vector 40 ISR) but enable_periodic has no callers, so the sole scheduler heartbeat is the LAPIC tick with no independent backstop.
- Invariant-TSC detection (tsc/features.rs:40) has zero consumers; now_ns() trusts a possibly-variant TSC unconditionally, and there are four unreconciled TSC frequency stores plus a hardcoded 2.5 GHz fallback.
The C-state/C1E defense from the earlier "dead timer" bug IS correctly wired (ARAT + IA32_POWER_CTL + spin fallback), which is good; the gap is that everything meant to back it up is disconnected. Highest-value fix: call the ACPI init path so HPET calibrates the TSC, route the scheduler timer through timer_ops::timer_enable to pick TSC-deadline, and wire the RTC IRQ8 heartbeat as an independent backstop. All three already exist.
The timer subsystem's reliable real-HW sources are all built but never called, and one calibration spin can hang boot.
Boot hang risk: arch/x86_64/time/timer/init.rs:56-58 calibrates the TSC against the PIT with an un-timed spin (while (inb(0x61)&0x20)==0 {}). On a modern board with no functional PIT (some laptops, some hypervisors) that gate bit never toggles and boot hangs. Add a timeout and prefer CPUID 0x15/0x16 then HPET before PIT.
Dead reliable paths:
The C-state/C1E defense from the earlier "dead timer" bug IS correctly wired (ARAT + IA32_POWER_CTL + spin fallback), which is good; the gap is that everything meant to back it up is disconnected. Highest-value fix: call the ACPI init path so HPET calibrates the TSC, route the scheduler timer through timer_ops::timer_enable to pick TSC-deadline, and wire the RTC IRQ8 heartbeat as an independent backstop. All three already exist.