nvmedevice: fix tight event cycle grace period race conditions

This commit resolves two race conditions that could bypass the tight
event cycle grace period mitigation:

1. Ghost Callback Race: A `Degraded` or `Removed` event could be processed
   immediately after the grace period timer expires but before the ASIO
   queue executes the timer callback. Relying solely on `recovering` was
   insufficient (especially for `Removed` events), leading to an unwanted
   NVMe interface start on a device that was just stopped.
2. Consecutive Available Bypass: Back-to-back `Available` events during
   the grace period bypassed the `recovering` boolean logic and immediately
   started the interface, completely negating the grace period.

Both race conditions are now closed by introducing a `gracePeriodActive`
state variable. We now safely verify this state within the async timer
callback before starting the device, and explicitly ignore consecutive
`Available` events when the ASIO timer is actively running.

Testing:
- Added `consecutiveAvailableBypass` unit test to verify that consecutive
  `Available` events do not bypass the grace period timer.

Tested: all unitest passed
Change-Id: Iced289dd4da6692dc3353e4814228eacaa6f2c97
Signed-off-by: Hao Jiang <jianghao@google.com>
3 files changed
tree: b5a6c70b7ec036d163c7e2c6d469ed01a6889878
  1. gen/
  2. include/
  3. proto/
  4. service_files/
  5. src/
  6. subprojects/
  7. tests/
  8. yaml/
  9. .clang-format
  10. .clang-tidy
  11. .clang-tidy-ignore
  12. .gitignore
  13. build.md
  14. gemini.md
  15. lesson.md
  16. LICENSE
  17. meson.build
  18. meson_options.txt
  19. OWNERS
  20. README.md
README.md

dbus-sensors

dbus-sensors is a collection of sensor applications that provide the xyz.openbmc_project.Sensor collection of interfaces. They read sensor values from hwmon, d-bus, or direct driver access to provide readings. Some advance non-sensor features such as fan presence, pwm control, and automatic cpu detection (x86) are also supported.

key features

  • runtime re-configurable from d-bus (entity-manager or the like)

  • isolated: each sensor type is isolated into its own daemon, so a bug in one sensor is unlikely to affect another, and single sensor modifications are possible

  • async single-threaded: uses sdbusplus/asio bindings

  • multiple data inputs: hwmon, d-bus, direct driver access

dbus interfaces

A typical dbus-sensors object support the following dbus interfaces:

Path        /xyz/openbmc_project/sensors/<type>/<sensor_name>

Interfaces  xyz.openbmc_project.Sensor.Value
            xyz.openbmc_project.Sensor.Threshold.Critical
            xyz.openbmc_project.Sensor.Threshold.Warning
            xyz.openbmc_project.State.Decorator.Availability
            xyz.openbmc_project.State.Decorator.OperationalStatus
            xyz.openbmc_project.Association.Definitions

Sensor interfaces collection are described here.

Consumer examples of these interfaces are Redfish, Phosphor-Pid-Control, IPMI SDR.

Reactor

dbus-sensor daemons are reactors that dynamically create and update sensors configuration when system configuration gets updated.

Using asio timers and async calls, dbus-sensor daemons read sensor values and check thresholds periodically. PropertiesChanged signals will be broadcasted for other services to consume when value or threshold status change. OperationStatus is set to false if the sensor is determined to be faulty.

A simple sensor example can be found here.

configuration

Sensor devices are described using Exposes records in configuration file. Name and Type fields are required. Different sensor types have different fields. Refer to entity manager schema for complete list.

sensor documentation