My Proxmox 9 server keep hanging, completely frozen !?

shodan

Well-Known Member
Sep 1, 2022
334
78
48
Hi,

I cobbled together a bunch of parts into a nice new-to-me Proxmox server.

Unfortunately, it keeps hanging after a couple of hours no matter what I do !

This server has

Code:
CPU0: AMD Ryzen 7 1700 Eight-Core Processor (family: 0x17, model: 0x1, stepping: 0x1)

Gigabyte Technology Co., Ltd. B450M DS3H V2/B450M DS3H V2, BIOS F67h 08/12/2025

EFI v2.7 by American Megatrends

ACPI=0xbcf0b000 ACPI 2.0=0xbcf0b014 SMBIOS=0xbd9f2000 SMBIOS 3.0=0xbd9f1000 MEMATTR=0xb777f398 ESRT=0xb98f6b98 MOKvar=0xbda1f000 INITRD=0xb68aee18 RNG=0xbc830018

Memory slots populated: 1/4

These devices

Code:
00:00.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Root Complex
00:00.2 IOMMU: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) I/O Memory Management Unit
00:01.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:01.3 PCI bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) PCIe GPP Bridge
00:02.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:03.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:03.1 PCI bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) PCIe GPP Bridge
00:04.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:07.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:07.1 PCI bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Internal PCIe GPP Bridge 0 to Bus B
00:08.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-1fh) PCIe Dummy Host Bridge
00:08.1 PCI bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Internal PCIe GPP Bridge 0 to Bus B
00:14.0 SMBus: Advanced Micro Devices, Inc. [AMD] FCH SMBus Controller (rev 59)
00:14.3 ISA bridge: Advanced Micro Devices, Inc. [AMD] FCH LPC Bridge (rev 51)
00:18.0 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 0
00:18.1 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 1
00:18.2 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 2
00:18.3 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 3
00:18.4 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 4
00:18.5 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 5
00:18.6 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 6
00:18.7 Host bridge: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Data Fabric: Device 18h; Function 7
01:00.0 USB controller: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset USB 3.1 xHCI Compliant Host Controller (rev 01)
01:00.1 SATA controller: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset SATA Controller (rev 01)
01:00.2 PCI bridge: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset PCIe Bridge (rev 01)
02:00.0 PCI bridge: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset PCIe Port (rev 01)
02:01.0 PCI bridge: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset PCIe Port (rev 01)
02:04.0 PCI bridge: Advanced Micro Devices, Inc. [AMD] 400 Series Chipset PCIe Port (rev 01)
04:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd. RTL8111/8168/8211/8411 PCI Express Gigabit Ethernet Controller (rev 16)
06:00.0 VGA compatible controller: NVIDIA Corporation GP106 [GeForce GTX 1060 6GB] (rev a1)
06:00.1 Audio device: NVIDIA Corporation GP106 High Definition Audio Controller (rev a1)
07:00.0 Non-Essential Instrumentation [1300]: Advanced Micro Devices, Inc. [AMD] Zeppelin/Raven/Raven2 PCIe Dummy Function
07:00.2 Encryption controller: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) Platform Security Processor (PSP) 3.0 Device
07:00.3 USB controller: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) USB 3.0 Host Controller
08:00.0 Non-Essential Instrumentation [1300]: Advanced Micro Devices, Inc. [AMD] Zeppelin/Renoir PCIe Dummy Function
08:00.2 SATA controller: Advanced Micro Devices, Inc. [AMD] FCH SATA Controller [AHCI mode] (rev 51)
08:00.3 Audio device: Advanced Micro Devices, Inc. [AMD] Family 17h (Models 00h-0fh) HD Audio Controller


So, I tried testing stuff


Memtest ran a whole day, zero errors

Then I installed windows 10, I ran Prime95 all day, next day I ran a GPU stress test in a loop, CPU at
60C, GPU at 80C all day, not a single crash, hang, error or even stutter !!

Then I installed debian 13 standard without a graphical interface, left that running a few days, no issues

Lastly I installed debian 13 with KDE desktop, left that running a few days, still no hang, no crash, nothing wrong !


Now I've reinstalled Proxmox 9 and it's always hanging after a while.

I'm 99% there's nothing exactly wrong with the hardware.



Here is what happens in the logs when it crashes (nothing)

Code:
Sep 21 12:56:45 proutmox pvescheduler[1301]: starting server
Sep 21 12:56:45 proutmox systemd[1]: Started pvescheduler.service - Proxmox VE scheduler.
Sep 21 12:56:45 proutmox systemd[1]: Reached target multi-user.target - Multi-User System.
Sep 21 12:56:45 proutmox systemd[1]: Reached target graphical.target - Graphical Interface.
Sep 21 12:56:45 proutmox systemd[1]: Startup finished in 6.573s (firmware) + 8.144s (loader) + 5.579s (kernel) + 10.771s (userspace) = 31.069s.
Sep 21 12:59:06 proutmox chronyd[962]: Can't synchronise: no selectable sources
Sep 21 12:59:58 proutmox systemd[1]: Starting apt-daily-upgrade.service - Daily apt upgrade and clean activities...
Sep 21 12:59:59 proutmox systemd[1]: apt-daily-upgrade.service: Deactivated successfully.
Sep 21 12:59:59 proutmox systemd[1]: Finished apt-daily-upgrade.service - Daily apt upgrade and clean activities.
Sep 21 13:07:27 proutmox systemd[1]: Starting logrotate.service - Rotate log files...
Sep 21 13:07:27 proutmox pvefw-logger[757]: received terminate request (signal)
Sep 21 13:07:27 proutmox pvefw-logger[757]: stopping pvefw logger
Sep 21 13:07:27 proutmox systemd[1]: Stopping pvefw-logger.service - Proxmox VE firewall logger...
Sep 21 13:07:28 proutmox systemd[1]: pvefw-logger.service: Deactivated successfully.
Sep 21 13:07:28 proutmox systemd[1]: Stopped pvefw-logger.service - Proxmox VE firewall logger.
Sep 21 13:07:28 proutmox systemd[1]: Starting pvefw-logger.service - Proxmox VE firewall logger...
Sep 21 13:07:28 proutmox pvefw-logger[3052]: starting pvefw logger
Sep 21 13:07:28 proutmox systemd[1]: Started pvefw-logger.service - Proxmox VE firewall logger.
Sep 21 13:07:28 proutmox systemd[1]: logrotate.service: Deactivated successfully.
Sep 21 13:07:28 proutmox systemd[1]: Finished logrotate.service - Rotate log files.
Sep 21 13:12:17 proutmox systemd[1]: Starting systemd-tmpfiles-clean.service - Cleanup of Temporary Directories...
Sep 21 13:12:17 proutmox systemd-tmpfiles[3822]: /usr/lib/tmpfiles.d/legacy.conf:14: Duplicate line for path "/run/lock", ignoring.
Sep 21 13:12:17 proutmox systemd[1]: systemd-tmpfiles-clean.service: Deactivated successfully.
Sep 21 13:12:17 proutmox systemd[1]: Finished systemd-tmpfiles-clean.service - Cleanup of Temporary Directories.
Sep 21 13:17:01 proutmox CRON[4584]: pam_unix(cron:session): session opened for user root(uid=0) by root(uid=0)
Sep 21 13:17:01 proutmox CRON[4586]: (root) CMD (cd / && run-parts --report /etc/cron.hourly)
Sep 21 13:17:01 proutmox CRON[4584]: pam_unix(cron:session): session closed for user root
Sep 21 13:24:20 proutmox chronyd[962]: Source 149.56.19.163 replaced with 207.210.46.249 (2.debian.pool.ntp.org)
Sep 21 13:26:37 proutmox smartd[896]: Device: /dev/sda [SAT], SMART Usage Attribute: 190 Airflow_Temperature_Cel changed from 70 to 74
Sep 21 14:00:17 proutmox systemd[1]: Starting apt-daily.service - Daily apt download activities...
Sep 21 14:00:17 proutmox systemd[1]: apt-daily.service: Deactivated successfully.
Sep 21 14:00:17 proutmox systemd[1]: Finished apt-daily.service - Daily apt download activities.
-- Boot 0bf3e923f6304fe59ad8b9be83ccadb8 --
Sep 21 21:02:14 proutmox kernel: Linux version 6.14.8-2-pve (build@proxmox) (gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #1 SMP PREEMPT_DYNAMIC PMX 6.14.8-2 (2025-07-22T10:04Z) ()
Sep 21 21:02:14 proutmox kernel: Command line: BOOT_IMAGE=/boot/vmlinuz-6.14.8-2-pve root=/dev/mapper/pve-root ro quiet
Sep 21 21:02:14 proutmox kernel: KERNEL supported cpus:
Sep 21 21:02:14 proutmox kernel:   Intel GenuineIntel
Sep 21 21:02:14 proutmox kernel:   AMD AuthenticAMD
Sep 21 21:02:14 proutmox kernel:   Hygon HygonGenuine
Sep 21 21:02:14 proutmox kernel:   Centaur CentaurHauls
Sep 21 21:02:14 proutmox kernel:   zhaoxin   Shanghai
Sep 21 21:02:14 proutmox kernel: BIOS-provided physical RAM map:


So I'm at a loss of what to try next. I imagine something wrong about ACPI or C-States, power management ?
 
I ran my own above post into chatgpt

Here are the avenues it suggest

That the problem is somehow related to "C-state or SMM (System Management Mode)"
That Proxmox 9 is "known to be unstable with a Ryzen 1 CPU on B450 chipset"
That "Ryzen 1xxx has known C6 state bugs"

And to try the following

Code:
Global C-state Control → Disable
Power Supply Idle Control → Set to Typical Current Idle
Cool’n’Quiet → Disable
CPB (Core Performance Boost) → Disable

To try these kernel parameters

Code:
processor.max_cstate=1 idle=nomwait

To try "irqbalance"

To disable XMP/DOCP

Update microcode or AGESA ??


----

So I'm going to try the kernel parameters and see what happens overnight
 
I tried

Code:
processor.max_cstate=1 idle=nomwait


but it still crashed/ hung

Code:
Sep 22 06:25:01 proutmox CRON[9765]: (root) CMD (test -x /usr/sbin/anacron || { cd / && run-parts --report /etc/cron.daily; })
Sep 22 06:25:01 proutmox CRON[9763]: pam_unix(cron:session): session closed for user root
Sep 22 06:42:29 proutmox chronyd[975]: Source 155.138.155.0 replaced with 149.56.19.163 (2.debian.pool.ntp.org)
Sep 22 06:53:09 proutmox systemd[1]: Starting apt-daily-upgrade.service - Daily apt upgrade and clean activities...
Sep 22 06:53:09 proutmox systemd[1]: apt-daily-upgrade.service: Deactivated successfully.
Sep 22 06:53:09 proutmox systemd[1]: Finished apt-daily-upgrade.service - Daily apt upgrade and clean activities.
Sep 22 07:17:01 proutmox CRON[17988]: pam_unix(cron:session): session opened for user root(uid=0) by root(uid=0)
Sep 22 07:17:01 proutmox CRON[17990]: (root) CMD (cd / && run-parts --report /etc/cron.hourly)
Sep 22 07:17:01 proutmox CRON[17988]: pam_unix(cron:session): session closed for user root
Sep 22 07:34:14 proutmox chronyd[975]: Source 206.108.0.132 replaced with 206.108.0.133 (2.debian.pool.ntp.org)
-- Boot b66e9dc50dc64a1aa6dbf59a54f4e0d7 --
Sep 22 18:22:14 proutmox kernel: Linux version 6.14.8-2-pve (build@proxmox) (gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44) #1 SMP PREEMPT_DYNAMIC PMX 6.14.8-2 (2025-07-22T10:04Z) ()
Sep 22 18:22:14 proutmox kernel: Command line: BOOT_IMAGE=/boot/vmlinuz-6.14.8-2-pve root=/dev/mapper/pve-root ro processor.max_cstate=1 idle=nomwait
Sep 22 18:22:14 proutmox kernel: KERNEL supported cpus:
Sep 22 18:22:14 proutmox kernel:   Intel GenuineIntel
Sep 22 18:22:14 proutmox kernel:   AMD AuthenticAMD
Sep 22 18:22:14 proutmox kernel:   Hygon HygonGenuine
Sep 22 18:22:14 proutmox kernel:   Centaur CentaurHauls
Sep 22 18:22:14 proutmox kernel:   zhaoxin   Shanghai
Sep 22 18:22:14 proutmox kernel: BIOS-provided physical RAM map:


I think I'm going to revert to previous proxmox version see if that fixes it !
 
Tried Proxmox 8.4

Same thing

Code:
Sep 23 01:17:01 proutmox CRON[40271]: (root) CMD (cd / && run-parts --report /etc/cron.hourly)
Sep 23 01:17:01 proutmox CRON[40270]: pam_unix(cron:session): session closed for user root
Sep 23 01:36:42 proutmox systemd[1]: Starting pve-daily-update.service - Daily PVE download activities...
Sep 23 01:36:49 proutmox pveupdate[45127]: <root@pam> starting task UPID:proutmox:0000B06B:0011DFE7:68D231F1:aptupdate::root@pam:
Sep 23 01:51:16 proutmox chronyd[912]: Source 208.81.1.244 replaced with 199.182.221.110 (2.debian.pool.ntp.org)
-- Boot e6df29af363f41dea03f8292b39d5869 --
Sep 23 04:18:16 proutmox kernel: Linux version 6.8.12-9-pve (build@proxmox) (gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils for Debian) 2.40) #1 SMP PREEMPT_DYNAMIC PMX 6.8.12-9 (2025-03-16T19:18Z) ()
Sep 23 04:18:16 proutmox kernel: Command line: BOOT_IMAGE=/boot/vmlinuz-6.8.12-9-pve root=/dev/mapper/pve-root ro quiet
Sep 23 04:18:16 proutmox kernel: KERNEL supported cpus:


This person

https://old.reddit.com/r/Amd/comments/f9lbve/system_instability_with_linux_and_3600_on/fisl1ih/

Says, disable "Cool and quiet"

This theads says

https://news.ycombinator.com/item?id=22290758

Code:
Zen CPUs are notoriously broken on Linux and AMD doesn't seem to care.
If you ever try to install Linux on a first-get Ryzen box and want an uptime longer than 3 days, you'll want to keep this handy:

https://github.com/qrwteyrutiyoup/ryzen-stabilizator


So these things might be in cause

C6 C-state, processor boosting, ASLR and Power Supply Idle Control​


I wonder how severe the performance and power consumption impacts will be from disabling these !
 
Last edited:
I have a fix for now, these kernel parameters

either

Code:
processor.max_cstate=1
or
rcu_nocbs=0-15

Each stop the crashes individually, I don't know the side effects however.

Apparently rcu_nocbs reduces latency and stutters ?

I added the kernel parameter to

/etc/default/grub

and then ran update-grub and rebooted

This resolved the crashing.
 
Thank you @shodan for keeping such notes !
It turned out to be quite useful
I confirm this problem still exists in Proxmox 9.2

Here is some useful threads

Code:
https://github.com/qrwteyrutiyoup/ryzen-stabilizator
https://news.ycombinator.com/item?id=22290758
https://forum.proxmox.com/threads/random-freeze-of-proxmox.164858/
https://forum.proxmox.com/threads/max-cstate-1-fixed-freezing-on-ve-8-x-but-version-9-upgrade-fresh-seems-to-bring-the-issue-back-2400ge.177004/
https://forum.proxmox.com/threads/random-kernel-panics.127260/
https://forum.proxmox.com/threads/my-proxmox-9-server-keep-hanging-completely-frozen.172489/
https://forum.proxmox.com/threads/proxmox-kernel-6-8-12-2-freezes-again.154875/page-2
And also discussed with an LLM

https://chatgpt.com/share/6ac45eea-5198-83ea-a27b-298210b7410c

This time I will try another solution

Power Supply Idle Control → Typical Current

While "rcu_nocbs=0-15" it might have side effects on performance

processor.max_cstate=1 is not clear if it really works or did not wait long enough, since stability takes days to confirm

Maybe processor.max_cstate=5 would work

But I will try the BIOS fix, if that doesn't work I will try

https://github.com/qrwteyrutiyoup/ryzen-stabilizator

And if that still doesn't work, then I'll try rcu_nocbs=0-15 again
 
It did not take long
Crashed immediately, weird !

1791255828124.png

Turns out, the BIOS does not respect the setting

1791255872490.png
1791255887941.png
1791255909504.png
1791255925082.png
1791255941915.png


1791255951296.png


But then you reboot, and it did not honor the setting, it is BACK TO AUTO !!

1791255980699.png
 
It may also be useful to try with the kernel option: iommu=pt

I have a Ryzen based Proxmox system at home that will consistently crash until this option is used.
 
I don't want to install go-lang, and I want a offline fix.

So I will recreate the ryzen-stabilisator as pure POSIX shell script.

and using the debian msr-tools package (rdmsr/wrmsr)

Ok here is my fix

Code:
info(){ printf '%s[INFO]%s %s\n' "$CYAN" "$RESET" "$*"; printf '[INFO] %s\n' "$*" >>"${LOG_FILE:-/var/log/ryzen-stabilizator.log}" 2>/dev/null; return 0; }; pass(){ printf '%s[PASS]%s %s\n' "$GREEN" "$RESET" "$*"; printf '[PASS] %s\n' "$*" >>"${LOG_FILE:-/var/log/ryzen-stabilizator.log}" 2>/dev/null; return 0; }; warn(){ printf '%s[WARN]%s %s\n' "$YELLOW" "$RESET" "$*" >&2; printf '[WARN] %s\n' "$*" >>"${LOG_FILE:-/var/log/ryzen-stabilizator.log}" 2>/dev/null; return 0; }; fail(){ printf '%s[FAIL]%s %s\n' "$RED" "$RESET" "$*" >&2; printf '[FAIL] %s\n' "$*" >>"${LOG_FILE:-/var/log/ryzen-stabilizator.log}" 2>/dev/null; return 0; }; init_colors(){ if [ -t 1 ] && [ -z "${NO_COLOR:-}" ]; then RED=$(printf '\033[31m'); GREEN=$(printf '\033[32m'); YELLOW=$(printf '\033[33m'); CYAN=$(printf '\033[36m'); BOLD=$(printf '\033[1m'); RESET=$(printf '\033[0m'); else RED=; GREEN=; YELLOW=; CYAN=; BOLD=; RESET=; fi; }; define_constants(){ SYSTEMD_DIR=/etc/systemd/system; LOG_FILE=/var/log/ryzen-stabilizator.log; PSIC_SERVICE=ryzen-psic-workaround.service; CORE_C6_SERVICE=ryzen-disable-core-c6.service; BOOST_SERVICE=ryzen-disable-boost.service; ASLR_SERVICE=ryzen-disable-aslr.service; pass "Defined Ryzen stabilizator paths and services"; }; require_root(){ if [ "$(id -u)" -eq 0 ]; then pass "Running as root"; return 0; else fail "This installer must be run as root"; return 1; fi; }; setup_log(){ if touch "$LOG_FILE" 2>/dev/null && chmod 0644 "$LOG_FILE" 2>/dev/null; then pass "Logging to $LOG_FILE"; return 0; else fail "Cannot write log $LOG_FILE"; return 1; fi; }; log_unit_failure(){ info "Saving diagnostics for $1"; systemctl status "$1" --no-pager >>"$LOG_FILE" 2>&1; journalctl -u "$1" -n 100 --no-pager >>"$LOG_FILE" 2>&1; return 0; }; unit_state(){ us=$(systemctl is-enabled "$1" 2>/dev/null); [ -n "$us" ] || us=unknown; printf '%s' "$us"; return 0; }; reload_systemd(){ info "Reloading systemd configuration"; if systemctl daemon-reload >>"$LOG_FILE" 2>&1; then pass "Reloaded systemd configuration"; return 0; else fail "Failed to reload systemd configuration; see $LOG_FILE"; return 1; fi; }; require_msr_tools(){ if command -v rdmsr >/dev/null 2>&1 && command -v wrmsr >/dev/null 2>&1; then return 0; else fail "msr-tools is not installed; see $LOG_FILE"; return 1; fi; }; remove_unsigned_repos(){ info "Checking configured APT repositories with apt-secure"; rur_tmp=$(mktemp -d) || { fail "Could not create temporary directory for repository checks"; return 1; }; rur_removed=0; for rur_file in /etc/apt/sources.list /etc/apt/sources.list.d/*.list; do [ -f "$rur_file" ] || continue; cp "$rur_file" "$rur_tmp/source.list" || continue; rur_line=0; while IFS= read -r rur_entry || [ -n "$rur_entry" ]; do rur_line=$((rur_line+1)); case "$rur_entry" in ''|\#*) continue;; deb\ *|deb-src\ *) :;; *) continue;; esac; printf '%s\n' "$rur_entry" >"$rur_tmp/test.list"; rm -rf "$rur_tmp/lists"; mkdir -p "$rur_tmp/lists/partial"; rur_out=$(apt-get -o Dir::Etc::sourcelist="$rur_tmp/test.list" -o Dir::Etc::sourceparts=- -o Dir::State::lists="$rur_tmp/lists" -o Debug::NoLocking=1 -o Acquire::Languages=none -o Acquire::AllowInsecureRepositories=false -o Acquire::AllowDowngradeToInsecureRepositories=false update -qq 2>&1); rur_rc=$?; if printf '%s\n' "$rur_out" | grep -Eqi 'NO_PUBKEY|EXPKEYSIG|BADSIG|invalid signature|signatures? (couldn.t|could not) be verified|signatures? were invalid|At least one invalid signature|Clearsigned file .* isn.t valid|Signed file .* isn.t valid|repository .* (is|was) not signed|does not have a Release file'; then [ -e "$rur_file.before-remove-unsigned" ] || cp -p "$rur_file" "$rur_file.before-remove-unsigned"; awk -v n="$rur_line" 'NR==n{$0="# disabled by remove_unsigned_repos: "$0}{print}' "$rur_file" >"$rur_tmp/rewrite" && cat "$rur_tmp/rewrite" >"$rur_file"; warn "Disabled repository failing apt signature verification: $rur_entry"; printf '[WARN] apt-secure output for %s line %s:\n%s\n' "$rur_file" "$rur_line" "$rur_out" >>"$LOG_FILE"; rur_removed=$((rur_removed+1)); elif [ "$rur_rc" -eq 0 ]; then pass "Repository signature OK: $rur_entry"; else warn "Repository check inconclusive; leaving enabled: $rur_entry"; printf '[WARN] inconclusive repository check for %s line %s:\n%s\n' "$rur_file" "$rur_line" "$rur_out" >>"$LOG_FILE"; fi; done <"$rur_tmp/source.list"; done; for rur_file in /etc/apt/sources.list.d/*.sources; do [ -f "$rur_file" ] || continue; awk 'BEGIN{s=1;a=0;d=0} /^[[:space:]]*$/ {if(a&&!d)print s ":" NR-1;s=NR+1;a=0;d=0;next} /^[[:space:]]*(Types|URIs):/{a=1} /^[[:space:]]*Enabled:[[:space:]]*[Nn][Oo]([[:space:]]|$)/{d=1} END{if(a&&!d)print s ":" NR}' "$rur_file" >"$rur_tmp/ranges"; while IFS=: read -r rur_start rur_end; do [ -n "$rur_start" ] || continue; sed -n "${rur_start},${rur_end}p" "$rur_file" >"$rur_tmp/test.sources"; rm -rf "$rur_tmp/lists"; mkdir -p "$rur_tmp/lists/partial"; rur_out=$(apt-get -o Dir::Etc::sourcelist="$rur_tmp/test.sources" -o Dir::Etc::sourceparts=- -o Dir::State::lists="$rur_tmp/lists" -o Debug::NoLocking=1 -o Acquire::Languages=none -o Acquire::AllowInsecureRepositories=false -o Acquire::AllowDowngradeToInsecureRepositories=false update -qq 2>&1); rur_rc=$?; rur_name=$(awk '/^[[:space:]]*URIs:/{sub(/^[[:space:]]*URIs:[[:space:]]*/,"");print;exit}' "$rur_tmp/test.sources"); [ -n "$rur_name" ] || rur_name="$rur_file:$rur_start-$rur_end"; if printf '%s\n' "$rur_out" | grep -Eqi 'NO_PUBKEY|EXPKEYSIG|BADSIG|invalid signature|signatures? (couldn.t|could not) be verified|signatures? were invalid|At least one invalid signature|Clearsigned file .* isn.t valid|Signed file .* isn.t valid|repository .* (is|was) not signed|does not have a Release file'; then [ -e "$rur_file.before-remove-unsigned" ] || cp -p "$rur_file" "$rur_file.before-remove-unsigned"; awk -v s="$rur_start" -v e="$rur_end" 'NR>=s&&NR<=e&&$0!~/^[[:space:]]*#/&&$0!~/^[[:space:]]*$/{ $0="# disabled by remove_unsigned_repos: "$0 }{print}' "$rur_file" >"$rur_tmp/rewrite" && cat "$rur_tmp/rewrite" >"$rur_file"; warn "Disabled repository stanza failing apt signature verification: $rur_name"; printf '[WARN] apt-secure output for %s lines %s-%s:\n%s\n' "$rur_file" "$rur_start" "$rur_end" "$rur_out" >>"$LOG_FILE"; rur_removed=$((rur_removed+1)); elif [ "$rur_rc" -eq 0 ]; then pass "Repository signature OK: $rur_name"; else warn "Repository check inconclusive; leaving enabled: $rur_name"; printf '[WARN] inconclusive repository check for %s lines %s-%s:\n%s\n' "$rur_file" "$rur_start" "$rur_end" "$rur_out" >>"$LOG_FILE"; fi; done <"$rur_tmp/ranges"; done; rm -rf "$rur_tmp"; if [ "$rur_removed" -eq 0 ]; then pass "No repositories failing signature verification found"; else warn "Disabled $rur_removed repository entry/stanza(s); backups end in .before-remove-unsigned"; fi; return 0; }; install_dependencies(){ remove_unsigned_repos; for pkg in msr-tools; do if dpkg-query -W -f='${Status}' "$pkg" 2>/dev/null | grep -q 'ok installed'; then pass "$pkg already installed"; else info "Installing $pkg"; if apt-get update -qq >>"$LOG_FILE" 2>&1 && DEBIAN_FRONTEND=noninteractive apt-get install -y -qq -o=Dpkg::Use-Pty=0 "$pkg" >>"$LOG_FILE" 2>&1; then pass "Installed $pkg"; else fail "Failed to install $pkg; see $LOG_FILE"; return 1; fi; fi; done; }; verify_psic_workaround(){ require_msr_tools || return 1; modprobe msr >>"$LOG_FILE" 2>&1; vpw=$(rdmsr -a -f 32:32 -u 0xC0010292 2>>"$LOG_FILE") || { fail "Could not read package C6 MSR; see $LOG_FILE"; return 1; }; printf '[INFO] Package C6 MSR bit 32 readback:\n%s\n' "$vpw" >>"$LOG_FILE"; if printf '%s\n' "$vpw" | awk '$NF != 0 { bad=1 } END { exit bad }'; then pass "Verified package C6 is disabled on all CPUs"; return 0; else fail "Package C6 is still enabled on one or more CPUs; see $LOG_FILE"; return 1; fi; }; enable_ryzen_psic_workaround(){ info "Enabling Ryzen PSIC workaround (disables package C6)"; require_msr_tools || return 1; systemctl reset-failed "$PSIC_SERVICE" >>"$LOG_FILE" 2>&1; if systemctl enable "$PSIC_SERVICE" >>"$LOG_FILE" 2>&1 && systemctl restart "$PSIC_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Ryzen PSIC workaround enabled and applied"; verify_psic_workaround; return $?; else log_unit_failure "$PSIC_SERVICE"; fail "Failed to enable Ryzen PSIC workaround; see $LOG_FILE"; return 1; fi; }; disable_ryzen_psic_workaround(){ info "Disabling Ryzen PSIC workaround for future boots"; if systemctl disable "$PSIC_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Ryzen PSIC workaround disabled for future boots"; warn "Reboot to restore firmware/kernel C6 defaults"; return 0; else fail "Failed to disable Ryzen PSIC workaround; see $LOG_FILE"; return 1; fi; }; disable_ryzen_core_c6(){ info "Disabling Ryzen Core C6"; require_msr_tools || return 1; if systemctl enable "$CORE_C6_SERVICE" >>"$LOG_FILE" 2>&1 && systemctl restart "$CORE_C6_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Ryzen Core C6 disabled and service enabled"; return 0; else log_unit_failure "$CORE_C6_SERVICE"; fail "Failed to disable Ryzen Core C6; see $LOG_FILE"; return 1; fi; }; enable_ryzen_core_c6_on_next_boot(){ info "Removing Ryzen Core C6 disable for future boots"; if systemctl disable "$CORE_C6_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Core C6 disable removed for future boots"; warn "Reboot to restore firmware/kernel C6 defaults"; return 0; else fail "Failed to disable $CORE_C6_SERVICE; see $LOG_FILE"; return 1; fi; }; disable_ryzen_boost(){ info "Disabling Ryzen CPU boost"; if systemctl enable "$BOOST_SERVICE" >>"$LOG_FILE" 2>&1 && systemctl restart "$BOOST_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Ryzen CPU boost disabled and service enabled"; return 0; else log_unit_failure "$BOOST_SERVICE"; fail "Failed to disable Ryzen CPU boost; see $LOG_FILE"; return 1; fi; }; enable_ryzen_boost_on_next_boot(){ info "Removing Ryzen CPU boost disable for future boots"; if systemctl disable "$BOOST_SERVICE" >>"$LOG_FILE" 2>&1; then pass "CPU boost disable removed for future boots"; warn "Reboot to return to normal boot-time behavior"; return 0; else fail "Failed to disable $BOOST_SERVICE; see $LOG_FILE"; return 1; fi; }; disable_aslr(){ info "Disabling kernel ASLR"; if systemctl enable "$ASLR_SERVICE" >>"$LOG_FILE" 2>&1 && systemctl restart "$ASLR_SERVICE" >>"$LOG_FILE" 2>&1; then pass "Kernel ASLR disabled and service enabled"; return 0; else log_unit_failure "$ASLR_SERVICE"; fail "Failed to disable kernel ASLR; see $LOG_FILE"; return 1; fi; }; enable_aslr_on_next_boot(){ info "Removing ASLR disable for future boots"; if systemctl disable "$ASLR_SERVICE" >>"$LOG_FILE" 2>&1; then pass "ASLR disable removed for future boots"; warn "Reboot to return to normal boot-time behavior"; return 0; else fail "Failed to disable $ASLR_SERVICE; see $LOG_FILE"; return 1; fi; }; create_boost_service(){ if printf '%s\n' '[Unit]' 'Description=Ryzen disable CPU boost' 'Before=pve-guests.service' '' '[Service]' 'Type=oneshot' 'ExecStart=/bin/sh -c "[ -w /sys/devices/system/cpu/cpufreq/boost ] || exit 1; printf \"0\n\" >/sys/devices/system/cpu/cpufreq/boost"' 'RemainAfterExit=yes' '' '[Install]' 'WantedBy=multi-user.target' >"$SYSTEMD_DIR/$BOOST_SERVICE"; then pass "Created $BOOST_SERVICE"; return 0; else fail "Failed to create $BOOST_SERVICE"; return 1; fi; }; create_aslr_service(){ if printf '%s\n' '[Unit]' 'Description=Disable kernel ASLR' 'Before=pve-guests.service' '' '[Service]' 'Type=oneshot' 'ExecStart=/bin/sh -c "printf \"0\n\" >/proc/sys/kernel/randomize_va_space"' 'RemainAfterExit=yes' '' '[Install]' 'WantedBy=multi-user.target' >"$SYSTEMD_DIR/$ASLR_SERVICE"; then pass "Created $ASLR_SERVICE"; return 0; else fail "Failed to create $ASLR_SERVICE"; return 1; fi; }; create_psic_service(){ if printf '%s\n' '[Unit]' 'Description=Ryzen Power Supply Idle Control workaround (disable package C6)' 'After=systemd-modules-load.service' 'Before=pve-guests.service' '' '[Service]' 'Type=oneshot' 'ExecCondition=/bin/grep -qm1 AuthenticAMD /proc/cpuinfo' 'ExecCondition=/bin/grep -Eqm1 "cpu family[[:space:]]*:[[:space:]]*23" /proc/cpuinfo' 'ExecStart=/bin/sh -c "modprobe msr; for f in /dev/cpu/[0-9]*/msr; do [ -e \"$$f\" ] || continue; c=$$(basename $$(dirname \"$$f\")); v=$$(rdmsr -d -p \"$$c\" 0xC0010292) || exit 1; n=$$((v & ~4294967296)); h=$$(printf \"%%016x\" \"$$n\"); wrmsr -p \"$$c\" 0xC0010292 \"0x$$h\" || exit 1; done"' 'RemainAfterExit=yes' '' '[Install]' 'WantedBy=multi-user.target' >"$SYSTEMD_DIR/$PSIC_SERVICE"; then pass "Created $PSIC_SERVICE"; return 0; else fail "Failed to create $PSIC_SERVICE"; return 1; fi; }; create_core_c6_service(){ if printf '%s\n' '[Unit]' 'Description=Ryzen disable Core C6' 'After=systemd-modules-load.service' 'Before=pve-guests.service' '' '[Service]' 'Type=oneshot' 'ExecCondition=/bin/grep -qm1 AuthenticAMD /proc/cpuinfo' 'ExecCondition=/bin/grep -Eqm1 "cpu family[[:space:]]*:[[:space:]]*23" /proc/cpuinfo' 'ExecStart=/bin/sh -c "modprobe msr; for f in /dev/cpu/[0-9]*/msr; do [ -e \"$$f\" ] || continue; c=$$(basename $$(dirname \"$$f\")); v=$$(rdmsr -d -p \"$$c\" 0xC0010296) || exit 1; n=$$((v & ~4210752)); h=$$(printf \"%%016x\" \"$$n\"); wrmsr -p \"$$c\" 0xC0010296 \"0x$$h\" || exit 1; done"' 'RemainAfterExit=yes' '' '[Install]' 'WantedBy=multi-user.target' >"$SYSTEMD_DIR/$CORE_C6_SERVICE"; then pass "Created $CORE_C6_SERVICE"; return 0; else fail "Failed to create $CORE_C6_SERVICE"; return 1; fi; }; create_systemd_service_unit_files(){ info "Creating Ryzen stabilizator systemd units"; SERVICE_ERRORS=0; create_psic_service || SERVICE_ERRORS=1; create_core_c6_service || SERVICE_ERRORS=1; create_boost_service || SERVICE_ERRORS=1; create_aslr_service || SERVICE_ERRORS=1; if [ "$SERVICE_ERRORS" -eq 0 ]; then pass "Created all Ryzen stabilizator service units"; return 0; else fail "One or more Ryzen stabilizator service units could not be created"; return 1; fi; }; verify_systemd_service_unit_files(){ info "Verifying systemd service units"; if systemd-analyze verify "$SYSTEMD_DIR/$PSIC_SERVICE" "$SYSTEMD_DIR/$CORE_C6_SERVICE" "$SYSTEMD_DIR/$BOOST_SERVICE" "$SYSTEMD_DIR/$ASLR_SERVICE" >>"$LOG_FILE" 2>&1; then pass "All Ryzen stabilizator service units passed verification"; return 0; else fail "One or more Ryzen stabilizator service units failed verification; see $LOG_FILE"; return 1; fi; }; print_install_status(){ printf '\n%s%sRyzen stabilizator status%s\n' "$BOLD" "$GREEN" "$RESET"; printf '  %-38s %s\n' "$PSIC_SERVICE" "$(unit_state "$PSIC_SERVICE")"; printf '  %-38s %s\n' "$CORE_C6_SERVICE" "$(unit_state "$CORE_C6_SERVICE")"; printf '  %-38s %s\n' "$BOOST_SERVICE" "$(unit_state "$BOOST_SERVICE")"; printf '  %-38s %s\n\n' "$ASLR_SERVICE" "$(unit_state "$ASLR_SERVICE")"; info "Full diagnostics: $LOG_FILE"; }; install_ryzen_stabilizator(){ init_colors; define_constants; require_root || return 1; setup_log || return 1; info "Starting Ryzen stabilizator installation"; INSTALL_ERRORS=0; install_dependencies || INSTALL_ERRORS=1; create_systemd_service_unit_files || INSTALL_ERRORS=1; verify_systemd_service_unit_files || INSTALL_ERRORS=1; reload_systemd || INSTALL_ERRORS=1; if [ "$INSTALL_ERRORS" -eq 0 ]; then pass "Ryzen stabilizator installation is up to date"; else fail "Ryzen stabilizator installation completed with errors; see $LOG_FILE"; fi; print_install_status; return "$INSTALL_ERRORS"; }; uninstall_ryzen_stabilizator(){ init_colors; define_constants; require_root || return 1; setup_log || return 1; info "Removing Ryzen stabilizator services"; systemctl disable "$PSIC_SERVICE" "$CORE_C6_SERVICE" "$BOOST_SERVICE" "$ASLR_SERVICE" >>"$LOG_FILE" 2>&1; rm -f "$SYSTEMD_DIR/$PSIC_SERVICE" "$SYSTEMD_DIR/$CORE_C6_SERVICE" "$SYSTEMD_DIR/$BOOST_SERVICE" "$SYSTEMD_DIR/$ASLR_SERVICE"; reload_systemd; pass "Finished removing Ryzen stabilizator service units"; warn "Previously applied MSR settings remain until reboot"; }
install_ryzen_stabilizator
enable_ryzen_psic_workaround
#disable_ryzen_core_c6
#disable_ryzen_boost
#disable_aslr

1791265362786.png

Seems to work, now, all I have to do is wait 1 week to see if it crashed again...
 
@s.haigh
Thanks for the headsup
After disabling "package C6 with psic workaround" I still got a crash.

So I added your suggestion to see if that helps

I create this paste-to-run script to create service unit to switch and check iommu settings

Code:
 init_colors(){ if [ -t 1 ] && [ -z "${NO_COLOR:-}" ]; then RED=$(printf '\033[31m'); GREEN=$(printf '\033[32m'); CYAN=$(printf '\033[36m'); BOLD=$(printf '\033[1m'); RESET=$(printf '\033[0m'); else RED=; GREEN=; CYAN=; BOLD=; RESET=; fi; }; info(){ printf '%s[INFO]%s %s\n' "$CYAN" "$RESET" "$*"; }; pass(){ printf '%s[PASS]%s %s\n' "$GREEN" "$RESET" "$*"; }; fail(){ printf '%s[FAIL]%s %s\n' "$RED" "$RESET" "$*" >&2; }; require_root(){ if [ "$(id -u)" -eq 0 ]; then pass "Running as root"; return 0; else fail "This installer must be run as root"; return 1; fi; }; IOMMU_UNIT_DIR=/etc/systemd/system; IOMMU_UNITS='iommu-passthrough iommu-translated-lazy iommu-translated-strict iommu-status'; iommu_frag_find_tty(){ printf '%s' 'find_tty(){ tty=; i=0; ' 'while [ "$$i" -lt 10 ] && [ -z "$$tty" ]; do ' 'for p in /proc/[0-9]*; do ' 'case "$$(readlink "$$p/exe" 2>/dev/null)" in */systemctl) ' 'c=$$(tr "\0" " " <"$$p/cmdline" 2>/dev/null); ' 'case "$$c" in *'"$1"'*) ' 't=$$(readlink "$$p/fd/1" 2>/dev/null); ' 'case "$$t" in /dev/pts/*|/dev/tty*) tty=$$t; break;; esac;; ' 'esac;; ' 'esac; ' 'done; ' 'i=$$((i+1)); ' '[ -n "$$tty" ] || sleep 0.05; ' 'done; ' '}; '; }; iommu_frag_emit(){ printf '%s' 'emit(){ printf "%%s\n" "$$1"; ' '[ -n "$$tty" ] && [ -w "$$tty" ] && printf "%%b\n" "$${2:-$$1}" >"$$tty"; ' '}; '; }; iommu_frag_clean_args(){ printf '%s' 'clean_args(){ out=; ' 'for x in $$1; do ' 'case "$$x" in ' 'iommu=pt|iommu.strict=*|iommu.passthrough=*) :;; ' '*) out="$${out:+$$out }$$x";; ' 'esac; ' 'done; ' 'printf "%%s" "$$out"; ' '}; '; }; iommu_frag_setter_main(){ printf '%s' 'find_tty; ' 'C=$$(printf "\033[1;36m"); ' 'Y=$$(printf "\033[1;33m"); ' 'R=$$(printf "\033[1;31m"); ' 'Z=$$(printf "\033[0m"); ' 'M=$$(printf "\033['"$1"'m"); ' 'mode="'"$2"'"; ' 'name="'"$3"'"; ' '[ "$$(id -u)" -eq 0 ] || { emit "ERROR: run as root" "$${R}ERROR:$${Z} run as root"; exit 1; }; ' 'src=; ' 'if [ -f /etc/kernel/cmdline ] && [ -s /etc/kernel/proxmox-boot-uuids ]; then ' 'old=$$(cat /etc/kernel/cmdline) || exit 1; ' 'clean=$$(clean_args "$$old"); ' 'printf "%%s\n" "$${clean:+$$clean }$$mode" >/etc/kernel/cmdline || { emit "ERROR: could not update /etc/kernel/cmdline" "$${R}ERROR:$${Z} could not update /etc/kernel/cmdline"; exit 1; }; ' 'command -v proxmox-boot-tool >/dev/null 2>&1 || { emit "ERROR: proxmox-boot-tool not found" "$${R}ERROR:$${Z} proxmox-boot-tool not found"; exit 1; }; ' 'proxmox-boot-tool refresh || exit 1; ' 'src=/etc/kernel/cmdline; ' 'elif [ -f /etc/default/grub ] && command -v update-grub >/dev/null 2>&1; then ' 'tmp=$$(mktemp) || exit 1; ' 'found=0; ' ': >"$$tmp" || exit 1; ' 'while IFS= read -r line || [ -n "$$line" ]; do ' 'trim=$${line#"$${line%%%%[![:space:]]*}"}; ' 'case "$$trim" in ' 'GRUB_CMDLINE_LINUX_DEFAULT=*) ' 'val=$${trim#*=}; ' 'val=$$(printf "%%s" "$$val" | sed "s/^\"//;s/\"$$//"); ' 'clean=$$(clean_args "$$val"); ' 'printf "GRUB_CMDLINE_LINUX_DEFAULT=\"%%s\"\n" "$${clean:+$$clean }$$mode" >>"$$tmp"; ' 'found=1;; ' 'GRUB_CMDLINE_LINUX=*) ' 'val=$${trim#*=}; ' 'val=$$(printf "%%s" "$$val" | sed "s/^\"//;s/\"$$//"); ' 'clean=$$(clean_args "$$val"); ' 'printf "GRUB_CMDLINE_LINUX=\"%%s\"\n" "$$clean" >>"$$tmp";; ' '*) printf "%%s\n" "$$line" >>"$$tmp";; ' 'esac; ' 'done </etc/default/grub; ' '[ "$$found" -eq 1 ] || printf "GRUB_CMDLINE_LINUX_DEFAULT=\"%%s\"\n" "$$mode" >>"$$tmp"; ' 'cat "$$tmp" >/etc/default/grub; ' 'r=$$?; ' 'rm -f "$$tmp"; ' '[ "$$r" -eq 0 ] || { emit "ERROR: could not update /etc/default/grub" "$${R}ERROR:$${Z} could not update /etc/default/grub"; exit "$$r"; }; ' 'update-grub || exit 1; ' 'src=/etc/default/grub; ' 'else emit "ERROR: no supported Proxmox boot configuration found" "$${R}ERROR:$${Z} no supported Proxmox boot configuration found"; exit 1; ' 'fi; ' 'emit "Next boot configured: $$name" "$${C}Next boot configured:$${Z} $${M}$$name$${Z}"; ' 'emit "Boot config: $$src" "$${C}Boot config:$${Z} $$src"; ' 'emit "Reboot required for the change to take effect." "$${Y}Reboot required for the change to take effect.$${Z}"; ' 'emit "Status: systemctl start iommu-status" "$${C}Status:$${Z} systemctl start iommu-status"'; }; iommu_frag_status_main(){ printf '%s' 'mode_from_args(){ x=" $$1 "; ' 'case "$$x" in ' '*" iommu=pt "*|*" iommu.passthrough=1 "*|*" iommu.passthrough=Y "*|*" iommu.passthrough=y "*) printf "Pass-Through";; ' '*" iommu.strict=1 "*) printf "Translated - Strict";; ' '*" iommu.strict=0 "*) printf "Translated - Lazy";; ' '*) printf "DEFAULT";; ' 'esac; ' '}; ' 'kernel_default(){ k=/boot/config-$$(uname -r); ' 'if [ -r "$$k" ]; then ' 'if grep -q "^CONFIG_IOMMU_DEFAULT_PASSTHROUGH=y$$" "$$k"; then printf "Pass-Through"; ' 'elif grep -q "^CONFIG_IOMMU_DEFAULT_DMA_STRICT=y$$" "$$k"; then printf "Translated - Strict"; ' 'elif grep -q "^CONFIG_IOMMU_DEFAULT_DMA_LAZY=y$$" "$$k"; then printf "Translated - Lazy"; ' 'else printf "DEFAULT"; ' 'fi; ' 'else printf "DEFAULT"; ' 'fi; ' '}; ' 'color_mode(){ ' 'case "$$1" in ' '"Pass-Through") printf "\033[1;32m%%s\033[0m" "$$1";; ' '"Translated - Lazy") printf "\033[1;33m%%s\033[0m" "$$1";; ' '"Translated - Strict") printf "\033[1;31m%%s\033[0m" "$$1";; ' '*) printf "\033[1;35m%%s\033[0m" "$$1";; ' 'esac; ' '}; ' 'read_grub_args(){ boot=; ' 'while IFS= read -r line || [ -n "$$line" ]; do ' 'trim=$${line#"$${line%%%%[![:space:]]*}"}; ' 'case "$$trim" in ' 'GRUB_CMDLINE_LINUX_DEFAULT=*|GRUB_CMDLINE_LINUX=*) ' 'val=$${trim#*=}; ' 'val=$$(printf "%%s" "$$val" | sed "s/^\"//;s/\"$$//"); ' 'boot="$${boot:+$$boot }$$val";; ' 'esac; ' 'done </etc/default/grub; ' 'printf "%%s" "$$boot"; ' '}; ' 'find_tty; ' 'C=$$(printf "\033[1;36m"); ' 'B=$$(printf "\033[1m"); ' 'Y=$$(printf "\033[1;33m"); ' 'Z=$$(printf "\033[0m"); ' 'def=$$(kernel_default); ' 'cmd=$$(cat /proc/cmdline 2>/dev/null); ' 'p=; ' 's=; ' '[ -r /sys/module/iommu/parameters/passthrough ] && p=$$(cat /sys/module/iommu/parameters/passthrough 2>/dev/null); ' '[ -r /sys/module/iommu/parameters/strict ] && s=$$(cat /sys/module/iommu/parameters/strict 2>/dev/null); ' 'case "$$p" in ' 'Y|y|1) cur="Pass-Through";; ' '*) case "$$s" in ' 'Y|y|1) cur="Translated - Strict";; ' 'N|n|0) cur="Translated - Lazy";; ' '*) cur=$$(mode_from_args "$$cmd"); [ "$$cur" = DEFAULT ] && cur=$$def;; ' 'esac;; ' 'esac; ' '[ "$$cur" = DEFAULT ] && cur=Unknown; ' 'boot=; ' 'src=; ' 'if [ -r /etc/kernel/cmdline ] && [ -s /etc/kernel/proxmox-boot-uuids ]; then ' 'boot=$$(cat /etc/kernel/cmdline); ' 'src=/etc/kernel/cmdline; ' 'elif [ -r /etc/default/grub ]; then ' 'boot=$$(read_grub_args); ' 'src=/etc/default/grub; ' 'fi; ' 'if [ -n "$$src" ]; then ' 'next=$$(mode_from_args "$$boot"); ' '[ "$$next" = DEFAULT ] && next=$$def; ' '[ "$$next" = DEFAULT ] && next=Unknown; ' 'else next=Unknown; ' 'fi; ' 'emit "=== IOMMU Status ===" "$${B}$${C}=== IOMMU Status ===$${Z}"; ' 'if [ -z "$$src" ]; then ' 'emit "IOMMU mode    : $$cur" "$${C}IOMMU mode    :$${Z} $$(color_mode "$$cur")"; ' 'emit "Boot config   : Unknown (no supported boot configuration found)" "$${C}Boot config   :$${Z} \033[1;35mUnknown (no supported boot configuration found)\033[0m"; ' 'elif [ "$$cur" = "$$next" ]; then ' 'emit "IOMMU mode    : $$cur" "$${C}IOMMU mode    :$${Z} $$(color_mode "$$cur")"; ' 'else ' 'emit "Running kernel: $$cur" "$${C}Running kernel:$${Z} $$(color_mode "$$cur")"; ' 'emit "Next boot     : $$next" "$${C}Next boot     :$${Z} $$(color_mode "$$next")"; ' 'emit "Boot config   : $$src" "$${C}Boot config   :$${Z} $$src"; ' 'fi; ' 'emit ""; ' 'emit "Available settings:" "$${B}Available settings:$${Z}"; ' 'emit "systemctl start iommu-passthrough"; ' 'emit "systemctl start iommu-translated-lazy"; ' 'emit "systemctl start iommu-translated-strict"; ' 'emit ""; ' 'emit "All setting changes affect the next boot; reboot is required." "$${Y}All setting changes affect the next boot; reboot is required.$${Z}"'; }; iommu_setter_script(){ iommu_frag_find_tty "$1"; iommu_frag_emit; iommu_frag_clean_args; iommu_frag_setter_main "$2" "$3" "$4"; }; iommu_status_script(){ iommu_frag_find_tty iommu-status; iommu_frag_emit; iommu_frag_status_main; }; write_iommu_unit(){ if printf '%s\n' '[Unit]' "Description=$2" '' '[Service]' Type=oneshot "SyslogIdentifier=$1" "ExecStart=/bin/sh -c '$3'" StandardOutput=journal StandardError=journal >"$IOMMU_UNIT_DIR/$1.service"; then pass "Created $1.service"; else fail "Failed to create $1.service"; return 1; fi; }; create_iommu_setter_service(){ write_iommu_unit "$1" "Set IOMMU mode for next boot - $4" "$(iommu_setter_script "$1" "$2" "$3" "$4")"; }; create_iommu_status_service(){ write_iommu_unit iommu-status 'Show live and next-boot IOMMU mode' "$(iommu_status_script)"; }; verify_iommu_service_units(){ info 'Verifying systemd service units'; set --; for u in $IOMMU_UNITS; do set -- "$@" "$IOMMU_UNIT_DIR/$u.service"; done; if systemd-analyze verify "$@" >/dev/null 2>&1; then pass 'All IOMMU service units passed verification'; return 0; else fail 'One or more IOMMU service units failed verification'; systemd-analyze verify "$@" 2>&1; return 1; fi; }; install_iommu_service_units(){ init_colors; require_root || return 1; info 'Installing IOMMU one-shot service units'; create_iommu_setter_service iommu-passthrough '1;32' 'iommu=pt' 'Pass-Through' || return 1; create_iommu_setter_service iommu-translated-lazy '1;33' 'iommu.strict=0' 'Translated - Lazy' || return 1; create_iommu_setter_service iommu-translated-strict '1;31' 'iommu.strict=1' 'Translated - Strict' || return 1; create_iommu_status_service || return 1; verify_iommu_service_units || return 1; if systemctl daemon-reload >/dev/null 2>&1; then pass 'Reloaded systemd configuration'; else fail 'Failed to reload systemd configuration'; return 1; fi; pass 'IOMMU service units installed'; printf '\n%sInstalled commands%s\n' "$BOLD" "$RESET"; printf '  systemctl start iommu-status\n'; printf '  systemctl start iommu-passthrough\n'; printf '  systemctl start iommu-translated-lazy\n'; printf '  systemctl start iommu-translated-strict\n\n'; }; run_iommu_unit(){ systemctl reset-failed "$1" >/dev/null 2>&1 || :; systemctl start "$1"; }; set_iommu_to_lazy_tlb_translation(){ run_iommu_unit iommu-translated-lazy; }; set_iommu_to_strict_tlb_translation(){ run_iommu_unit iommu-translated-strict; }; set_iommu_to_passthrough(){ run_iommu_unit iommu-passthrough; }; get_iommu_passthrough_mode(){ run_iommu_unit iommu-status; };
install_iommu_service_units
#set_iommu_to_lazy_tlb_translation
#set_iommu_to_strict_tlb_translation
set_iommu_to_passthrough
get_iommu_passthrough_mode


result

1791550932125.png

and after reboot

1791550954875.png

We will see later this week if that does it!
 
Last edited: