Repository navigation
test-microvm: pause and resume a microVM through OpenVMM state control - #405
Draft
Enrique Saurez (esaurez) wants to merge 1 commit into
Draft
Enrique Saurez (esaurez) wants to merge 1 commit into
Enrique Saurez (esaurez) wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Cross-platform runtime validation remains pending, the OpenVMM dependency is still draft, and the busy-workload overlap check has an unresolved false-pass path.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Integrates OpenVMM’s authenticated pause/resume endpoint and validates held guest time across host pauses.
Changes:
- Updates the OpenVMM pin and adds a protocol client.
- Adds cross-backend pause/resume testing.
- Documents endpoint security, lifecycle, and time semantics.
| File | Description |
|---|---|
openvmm |
Pins the state-control implementation. |
.github/actions/validate-nvx/action.yml |
Runs the new client tests. |
scripts/nvx_tools/control_session.py |
Exposes shared endpoint streams. |
scripts/nvx_tools/state_control.py |
Implements protocol v1 client. |
scripts/nvx_tools/microvm_tests.py |
Adds the pause/resume scenario. |
scripts/test_state_control.py |
Tests protocol encoding and validation. |
scripts/test_microvm_tests.py |
Tests scenario behavior and dispatch. |
doc/usage.md |
Documents scenario selection. |
doc/ci.md |
Describes CI acceptance checks. |
doc/design/time-abi.md |
Specifies guest time during pauses. |
doc/design/machine-and-device-abi.md |
Defines the endpoint’s ABI role. |
doc/design/host-attachment-model.md |
Documents restore attachment behavior. |
doc/design/concurrency-and-trust-boundaries.md |
Documents authentication and serialization. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| time.sleep(1) | ||
| busy_after = _process_cpu_seconds(pid) | ||
| # The VM has run without a pause so far, so its uptime follows the host. | ||
| pause_uptime = uptime_start + time.monotonic() - host_start |
Pick up nanvix/openvmm's authenticated microVM state-control endpoint (--microvm-state-control), which pauses, resumes, and queries a running microVM without a snapshot and holds its guest time while it is paused. Add a client for its protocol, sharing the control console's endpoint streams, and a pause-resume scenario that runs in the default suite and the debug-kernel jobs. On a managed VM it checks that hosts without the capability get no response; that a 30 s pause and two 2 s pauses are idempotent and stop a busy guest; that guest uptime counts only the time the VM ran; that no RCU stall or time ABI violation occurs; that the wall-clock discipline steps the guest clock back to host UTC; that a pause outlives the host that made it; and that OpenVMM can be terminated while the VM is paused. Specify host pause in the time ABI, and describe the endpoint in the machine ABI, the host attachment model, and the trust boundaries. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Enrique Saurez (esaurez)
force-pushed
the
esaurez/microvm-state-control
branch
from
October 6, 2026 15:55
b43c5ce to
77018ef
Compare
Enrique Saurez (esaurez)
changed the base branch from
dev
to
fix/issue-396-amd-cpu-profiles
October 6, 2026 15:55
Comment on lines
+1239
to
+1247
| used = cpu_after - cpu_before | ||
| if ( | ||
| used | ||
| > PAUSE_RESUME_PAUSED_CPU_SHARE * seconds | ||
| + PAUSE_RESUME_PAUSED_CPU_ALLOWANCE_SECONDS | ||
| ): | ||
| raise RuntimeError( | ||
| f"OpenVMM used {used:.2f} s of CPU time while paused for {seconds:.0f} s" | ||
| ) |
Comment on lines
+6
to
+7
| version 1 is documented in OpenVMM's Guide, in | ||
| ``reference/openvmm/management/state_control_protocol.md``. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
This picks up nanvix/openvmm#114, which adds
--microvm-state-control. It is an authenticated host endpoint that pauses, resumes, and queries a running microVM without a snapshot, and it holds guest time while the VM is paused. This PR:openvmmgitlink to that PR's head;Depends on nanvix/openvmm#114. Its base, #404 (AMD CPUs), has merged, so this PR now targets
devdirectly with its one commit,77018ef. The gitlink points at the head of nanvix/openvmm#114,647e635c3on branchesaurez/microvm-vm-state-control, two commits on nanvix/openvmm#115 (07850d27a, merged, the commit #404 pins). Once #114 merges, I will repoint the gitlink to the merged commit. Until then, it stays a draft.Changes
openvmm:07850d27a(time ABI: boot AMD CPUs on an EPYC Milan profile and AMD host profiles #404) →647e635c3.scripts/nvx_tools/state_control.pyis a client for state-control protocol version 1, which OpenVMM's Guide documents inreference/openvmm/management/state_control_protocol.md. It shares the control console's endpoint streams through a new publicEndpointStreamandconnect_endpoint()incontrol_session.py.test-microvmgets a newpause-resumescenario, in the default suite and under--debug-kernel. It runs a managed VM at the largest requested vCPU count:rcu_stall_countmust stay 0, and no time ABI violation may occur.NVX-PAUSE-RESUME:evidence line and adds about a minute per backend.doc/design/time-abi.mdgets a new "Host pause" section. It covers held monotonic time; the wall clock, which follows host UTC and is stepped by the discipline; the rejection of periodic and TSC-deadline LAPIC timers; and the interaction with snapshots.machine-and-device-abi.md,host-attachment-model.md, andconcurrency-and-trust-boundaries.mddescribe the endpoint.ci.mdandusage.mdcover the scenario.Testing
ruff check,ruff format --check, and strictpyrightfor Linux and Windows are clean.The CI unittest list passes on Windows: 751 tests on the branch rebased on time ABI: boot AMD CPUs on an EPYC Milan profile and AMD host profiles #404, 735 before. Before the rebase it also passed on Linux (689 tests). The new tests cover:
End to end,
test-microvm --scenario managed-lifecycle --scenario pause-resumepasses at 8 vCPUs on two backends:--cpu-profile host, whichtest-microvmcannot pass.amd.milan.v1.Windows reports no VMM CPU time, so the WHP line omits the two CPU fields.
Not run: KVM and Intel hosts. CI runs the scenario on its Intel runners once this PR leaves draft.