PCIe/CXL Deep Dive · All levels

Error Containment and Recovery Policies: Reports and Metrics

Reports and Metrics for Error Containment and Recovery Policies.

Reports and metrics

Reports and Metrics for Error Containment and Recovery Policies focuses on Blast radius of injected faults, mean time to recovery, and service availability during RAS events. The purpose is to turn memory observations into mechanism-backed actions with explicit owners and release-safe validation.

Reports should explain why Blast radius of injected faults, mean time to recovery, and service availability during RAS events moved, not simply that it moved. Require evidence that links the movement to command behavior, queue policy, PHY margin, or reliability controls.

Before/after trend

diagram
BEFORE/AFTER TREND - Error Containment and Recovery Policies

metric        before    after fix
------------  --------  ---------
bandwidth     42 GB/s   48 GB/s
p99 latency   18 us     9 us
error rate    12/hr     0/hr

Evidence matrix

diagram
PCIe/CXL EVIDENCE MATRIX - Error Containment and Recovery Policies

+-------------------------------+--------------------------------+--------------------------------+---------------------------+
| Evidence                      | Tells you                      | Does not prove                 | Next action               |
+-------------------------------+--------------------------------+--------------------------------+---------------------------+
| TLP type mix + credit stall counters    | protocol-layer stall cost    | link integrity and replay behavior   | inspect training margins  |
| queue age + class breakdown   | fairness and starvation risk   | command legality details       | parse command timeline    |
| LTSSM timeline + ordered set progression | timing-window pressure         | root cause by itself           | correlate with topology map|
| eye / Vref / skew snapshots   | PHY margin and drift behavior  | controller policy quality      | pair with schedule logs   |
| CE/UE + scrub telemetry       | reliability trajectory         | immediate perf bottleneck only | map to hotspot apcieesses  |
+-------------------------------+--------------------------------+--------------------------------+---------------------------+
  • Track p50/p95/p99 latency and effective bandwidth together.

  • Include command and queue context alongside high-level counters.

  • Tag reports with firmware, timing profile, and thermal state.

  • Call out contradictory evidence instead of hiding it.

PCIe/CXL deep dive

RAS closure maps AER, poison, and surprise-down events to bounded containment and recovery actions.

Concept diagram

diagram
RAS ESCALATION

detect -> classify -> contain -> recover -> validate

Metric graph

diagram
RAS EVENT MIX

correctable trend   ███████
uncorrectable       ██
surprise-down       █

Reports and artifacts

  • AER register dump

  • poison injection log

  • surprise-down timeline

  • containment action record

Mini case study

Masked correctable errors accumulated until a surprise-down during peak traffic forced unplanned failover.

Debug branches

  • Separate CE trend from UE containment paths

  • Validate poison handling end-to-end

  • Test surprise-down drain and driver recovery

Senior review question

Ask: which latency, bandwidth, and reliability evidence proves this PCIe/CXL topic is closed under real traffic?

Key takeaways

  • Always tie controller and PHY counter shifts to application latency and throughput outcomes.

  • Lock firmware timing profile, thermal condition, and DIMM state before comparing PCIe/CXL captures.

Common pitfalls

  • Chasing peak bandwidth while ignoring p99 latency and fairness tails.

  • Changing timing guardbands without separating SI noise from scheduling issues.

  • Declaring closure without reliability gates, fault injection, and regression replay.

Report interpretation

RAS policies define whether to reset a function, retrain a link, or failover a workload. Containment boundaries span PCIe hierarchy, CXL regions, and VM/device assignment models. PCIe/CXL inefficiency is multiplicative: one extra ACTIVATE, one unnecessary turnaround, one weak lane margin, or one refresh collision repeated across billions of accesses can dominate product tail latency and power.

Use Blast radius of injected faults, mean time to recovery, and service availability during RAS events as the opening signal, not the conclusion. A metric move only becomes actionable when paired with workload context, command traces, training telemetry, and evidence artifacts such as RAS policy matrix, fault injection report, and recovery playbook.

RAS policies translate PCIe/CXL errors into bounded blast radius and predictable recovery. Senior review quality comes from proving a complete chain: request pattern -> memory-state transition -> bottleneck mechanism -> smallest owner fix -> regression-safe validation.

For Error Containment and Recovery Policies, reports should explain why Blast radius of injected faults, mean time to recovery, and service availability during RAS events moved: fewer row misses, lower turnaround waste, better refresh placement, or stronger lane margin stability.

Strong reports include consistency checks: scheduler narrative matches command logs; PHY narrative matches margin sweeps; reliability narrative matches CE/UE trajectories.