Repository navigation
Adopt bind-once microVM image slots - #406
Open
Enrique Saurez (esaurez) wants to merge 6 commits into
Open
Enrique Saurez (esaurez) wants to merge 6 commits into
Enrique Saurez (esaurez) wants to merge 6 commits into
Conversation
Promote the OpenVMM gitlink to 6c12f620, advertise microVM ABI 3, and document the fixed four-slot machine and restore contract. The promotion contains only the two image-slot commits and no unrelated fork changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add managed sandbox boot and bind controls, ABI-3 guest discovery and restore repair, cross-backend correctness coverage, and matched ABI-2/B=1/B=4 boot-cost benchmarks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
OpenVMM 6c12f620 rejected the image-slot transports during machine validation, so every slot-declaring launch failed before boot. Advance the gitlink to 10106b13, which admits exactly the declared slot transports and leaves machines without slots unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Image-slot activation reached the guest as a version-4 restore packet with no status bit of its own. A legacy-tier restore therefore skipped post-restore repair, left newly active slots unbound, and never released the restore gate. Pin OpenVMM bf98f65f, which advertises version-4 targets with portb status bit 6 and gates every explicit image-slot target. Route that bit to post-restore repair and keep it out of the base-memory fast path. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The image-slot boot benchmark closed its TCP console immediately after sending the guest exit command. On MSHV the guest then never received the command, so every sample timed out. Keep the console connected until OpenVMM exits, as the correctness tests already do. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
OpenVMM 6aaf6fb7 treats a client closing the host-control connection after its last response as a normal end of session instead of logging a failed connection. The protocol and ABI are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Pins OpenVMM to nanvix/openvmm#116 (
6aaf6fb7), which adds bind-once read-only virtio-blk image slots to the microVM profile, and adopts them in NVX. The repin contains only these commits on top of the current pin4355c010:368b9d2avirtio_blk: add bind-once image slots6c12f620openvmm_entry: add microVM image slots10106b13microvm: admit declared image-slot transports in machine validationbf98f65fmicrovm: advertise and gate image-slot restore targets6aaf6fb7microvm: end host-control sessions quietly on a clean closeNo other fork changes are included.
microvm_abi_versionis 3. VMs without slots keep ABI 2 unchanged.--image-slot-boot-countfor managed sandboxes,--restore-image-slots,query-image-slots, andbind-image-slot. Slot launches may omit thedistrolayer; ABI-2 launches keep the existing layer requirement.OPENVMM_ENTROPY_V4parsing, with portb status bit 6 routing image-slot targets to restore repair;/dev/nvx-imageNlinks. Placeholders stay unbound.benchmark --suite image-slot-bootcompares ABI 2, ABI 3 with one active slot, and ABI 3 with four active slots.Base
This PR is intentionally based on
db5138e3, before the CPU-profile repin ondev(#394), and targetsdev-pre-cpu-profile, created at that commit. CI workflows run only for pull requests intodev, so I validated this PR manually on an isolated MSHV host.Validation
Local (Windows):
1cbf5c7d:python scripts/nvx.py verify,compileall,pyright(Linux and Windows),ruff check,ruff format --check, andgit diff --checkpassed. Focused unit tests: 63 passed. Supporting suites: 108 passed, 17 skipped.ruff check,ruff format --check, andgit diff --checkpassed. The benchmark tests passed (83, with 1 skipped), and the new console-ordering test fails without its fix.shellcheck --shell=shandshfmt -d -ln posix -i 4 -cion the changed guest scripts: clean.nvx-port-io.ccompiles forx86_64-linux-muslwith-static -Os -Wall -Wextra -Werror.Linux/MSHV, head
402c01f2with OpenVMMbf98f65f:Host: AMD EPYC 9V74, Linux
6.6.148-200.mshv-b1f02da.azl3.python3 scripts/nvx.py build-guest(Docker) andbuild-openvmm --backend mshv(musl, Rust 1.95.0). Both built from clean sources.The CI CLI validation (
compileall, the sevenunittestmodules,test_adversarial.py,verify) passed: 540 tests passed (29 skipped), and 70 adversarial tests passed.test-microvm --backend mshv --scenario image-slots: passed.B = 1, then bind, idempotent rebind, rejection of a different identity, and a guest read of the bound media.--restore-image-slots 4, then bind and read slot 3.test-microvm --backend mshv(default suite, 36 scenarios): all passed. This covers boot, console, lifecycle, sandbox blocks, scratch/SMP/network/filesystem snapshots, restore processors/memory/TSC, snapshot tiers, network policy, and image slots.benchmark --suite image-slot-boot --backend mshv --processors 1 --warmups 5 --runs 51, measuring cold boot toALPINE-MICROVM-BOOT-OK:Configurations ran in consecutive blocks, not interleaved, on a host that also had an unrelated VM running.
Linux/MSHV, head
6da62e93with OpenVMM6aaf6fb7:6da62e93changes only the OpenVMM pin and the design doc. OpenVMM6aaf6fb7stops reporting a client's normal close of the host-control connection as a failed connection.build-guest(initramfsa04b57e4..., unchanged from402c01f2) andbuild-openvmm --backend mshv(bf0ec482..., source revision6aaf6fb7).test-microvm --backend mshv --scenario image-slots: passed.Live validation found four defects, all fixed in this PR:
10106b13).bf98f65fplus46c6f595).402c01f2).6aaf6fb7, pinned by6da62e93).Not yet validated
KVM and WHP live runs.