PCIe/CXL Deep Dive · All levels

Poisoned TLPs and ECRC Protection: Worked Example

Worked Example for Poisoned TLPs and ECRC Protection.

Worked example

Worked Example for Poisoned TLPs and ECRC Protection focuses on Poisoned TLP count, ECRC mismatch rate, and containment success rate. The purpose is to turn memory observations into mechanism-backed actions with explicit owners and release-safe validation.

A field regression flags Poisoned TLP count, ECRC mismatch rate, and containment success rate. Proper triage locks environment tags, compares baseline vs failing traces, isolates first repeated loss transition, and validates one bounded mitigation before release.

This pattern prevents reactive tuning. The goal is to preserve both performance and reliability while avoiding hidden regressions that appear only at corner conditions.

System view

diagram
CREDIT FLOW VIEW - Poisoned TLPs and ECRC Protection

VC0 posted credits:     [####------] 4/10 available
VC0 non-posted credits: [######----] 6/10 available
VC0 completion credits: [###-------] 3/10 available

Stall signature:
- posted credit exhaustion -> write TLP backpressure
- completion credit exhaustion -> read latency cliff

Poison vs ECRC

diagram
INTEGRITY LAYERS

LCRC: per-link segment protection
ECRC: end-to-end TLP digest
Poison: mark corrupt data without silent delivery
  1. Capture baseline and failing command traces under fixed metadata.

  2. Verify TLP stall mix, credit ledger, and LTSSM recovery events.

  3. Collect Poison injection log, ECRC error trace, and containment action record.

  4. Patch one bounded fix with explicit owner signoff.

  5. Re-run closure matrix and choose ship/rollback.

PCIe/CXL deep dive

RAS closure maps AER, poison, and surprise-down events to bounded containment and recovery actions.

Concept diagram

diagram
RAS ESCALATION

detect -> classify -> contain -> recover -> validate

Metric graph

diagram
RAS EVENT MIX

correctable trend   ███████
uncorrectable       ██
surprise-down       █

Reports and artifacts

  • AER register dump

  • poison injection log

  • surprise-down timeline

  • containment action record

Mini case study

Masked correctable errors accumulated until a surprise-down during peak traffic forced unplanned failover.

Debug branches

  • Separate CE trend from UE containment paths

  • Validate poison handling end-to-end

  • Test surprise-down drain and driver recovery

Senior review question

Ask: which latency, bandwidth, and reliability evidence proves this PCIe/CXL topic is closed under real traffic?

Key takeaways

  • Always tie controller and PHY counter shifts to application latency and throughput outcomes.

  • Lock firmware timing profile, thermal condition, and DIMM state before comparing PCIe/CXL captures.

Common pitfalls

  • Chasing peak bandwidth while ignoring p99 latency and fairness tails.

  • Changing timing guardbands without separating SI noise from scheduling issues.

  • Declaring closure without reliability gates, fault injection, and regression replay.

Worked-example reasoning

Suppose Poisoned TLP count, ECRC mismatch rate, and containment success rate regresses on a production workload. A shallow response only tweaks timing or queue weights. A deeper response compares baseline and failing traces, then identifies the first repeated loss mechanism in Data corruption can be marked poisoned rather than silently delivered. ECRC validates end-to-end integrity; poisoned TLP handling requires coordinated driver, IOMMU, and memory manager response..

If command waste dominates, inspect row policy and turnaround cadence. If blocked cycles dominate, inspect refresh scheduling and QoS windows. If margin loss dominates, inspect lane shmoo and thermal drift.

Only then choose a bounded fix: mapping update, scheduler policy change, refresh strategy adjustment, firmware retrain rule, PHY calibration, or package/SI correction.