Repository navigation
Add opt-in native-host image-backed edge lifecycle - #395
Closed
Enrique Saurez (esaurez) wants to merge 5 commits into
Closed
Enrique Saurez (esaurez) wants to merge 5 commits into
Enrique Saurez (esaurez) wants to merge 5 commits into
Conversation
Load a separately supplied, caller-approved native host library for scratchless image-backed provision/start/exec/stop/deprovision. Keep the direct backend as default, isolate persisted state, fence unsupported capabilities, and pin the RAM-overlay OpenVMM change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Bound guest-session disposal by each operation deadline, preserve zero as an unbounded command timeout while rejecting sub-second precision, keep native-only files outside direct-backend cleanup, and validate both derived Unix socket paths before loading the library. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Enrique Saurez (esaurez)
force-pushed
the
esaurez/edge-nvxhost-pre-time-abi
branch
from
October 5, 2026 23:16
e17cfae to
c35937b
Compare
Enrique Saurez (esaurez)
changed the base branch from
esaurez/baseline-before-nvx-86661676
to
dev
October 5, 2026 23:17
Show a concrete WHP invocation, the separately supplied artifacts and trust requirement, and the unverified MSHV path. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Enrique Saurez (esaurez)
force-pushed
the
esaurez/edge-nvxhost-pre-time-abi
branch
from
October 6, 2026 00:31
c35937b to
adfa167
Compare
Enrique Saurez (esaurez)
changed the base branch from
dev
to
esaurez/baseline-before-nvx-86661676
October 6, 2026 00:32
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Native execution currently has deadline, output-contract, and restart console-pump correctness issues.
Review effort: Balanced
Findings: 4
Open (4)
What changed in this PR
Adds an opt-in, image-backed nvxhost lifecycle while retaining direct OpenVMM as the default.
Changes:
- Adds native-library ABI bindings and guest lifecycle implementation.
- Adds isolated state, artifact verification, console capture, and tests.
- Documents and demonstrates configuration and required private assets.
| File | Description |
|---|---|
aci_edge_sandboxes/src/openvmm/native.rs |
Implements the native backend lifecycle. |
aci_edge_sandboxes/src/nvxhost.rs |
Adds checked native ABI bindings. |
aci_edge_sandboxes/src/openvmm/state.rs |
Adds native state and console artifacts. |
aci_edge_sandboxes/src/openvmm/config.rs |
Generalizes Unix socket validation. |
aci_edge_sandboxes/src/openvmm/mod.rs |
Exports and integrates the backend. |
aci_edge_sandboxes/src/openvmm/launch.rs |
Updates test records. |
aci_edge_sandboxes/src/lib.rs |
Registers the feature-gated module. |
aci_edge_sandboxes/src/client.rs |
Adds the client constructor. |
aci_edge_sandboxes/tests/nvxhost_guest.rs |
Adds an ignored WHP lifecycle test. |
aci_edge_sandboxes/examples/nvxhost_lifecycle.rs |
Adds a runnable lifecycle example. |
aci_edge_sandboxes/README.md |
Documents setup, trust, and limitations. |
aci_edge_sandboxes/Cargo.toml |
Adds the feature and dependencies. |
aci_edge_sandboxes/Cargo.lock |
Locks new dependencies. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+137
to
+140
| #[prost(string, tag = "2")] | ||
| stdout: String, | ||
| #[prost(string, tag = "3")] | ||
| stderr: String, |
| .console_pumps | ||
| .lock() | ||
| .map_err(|_| Error::backend_error("the boot-console pump table is unavailable"))?; | ||
| if pumps.contains_key(sandbox_id) { |
Comment on lines
+765
to
+776
| let remaining = deadline.saturating_duration_since(Instant::now()); | ||
| let mut session = self.connect(&runtime, &capability, remaining)?; | ||
| let grace_period_milliseconds = i64::try_from(remaining.as_millis()) | ||
| .map_err(|_| Error::backend_error("guest shutdown grace period is too long"))?; | ||
| let response = session.unary( | ||
| "Shutdown", | ||
| &ShutdownRequest { | ||
| grace_period_milliseconds, | ||
| } | ||
| .encode_to_vec(), | ||
| Some(remaining), | ||
| ); |
Comment on lines
+1021
to
+1025
| let reply = ExecuteCommandResponse::decode(response.as_slice()).map_err(|error| { | ||
| Error::backend_error("the guest returned an invalid execution result").with_source(error) | ||
| })?; | ||
| let _ = io.stdout.write(reply.stdout.as_bytes()); | ||
| let _ = io.stderr.write(reply.stderr.as_bytes()); |
OpenVMM serves one boot-console client at a time and retains guest output while none is connected. The native backend keyed its console listener by sandbox only, so a restart after an OpenVMM crash reused the finished listener of the crashed launch; with no listener, a verbose guest stalled until start timed out. A second backend instance that reattached to a running guest could not connect while the first one held the console, and stop then failed after the guest had already stopped. Key listeners by the OpenVMM process identity and retire stale ones before a launch. A listener that finds the console held elsewhere waits, without the start deadline, to take it over and ends quietly when OpenVMM exits; a reset after OpenVMM exits ends the log. Stop and deprovision report capture failures as consoleError metadata instead of failing. Extend the opt-in WHP suite with exec semantics, lifecycle errors and restarts, reattachment from a new backend, a crashed guest, a guest that outlives the process that started it, starts killed at several points, parallel sandboxes, and concurrent commands. List OpenVMM processes in a way that fails loudly, so the leak checks cannot pass vacuously. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Hash the image once when it is registered, or record a digest that the caller already verified, and refer to it by content ID. Provision and start compare cheap file seals instead of hashing again, and fail closed when a file changed. Hash OpenVMM, the kernel, and the initramfs once per backend, optionally against approved digests, and keep full re-hashing as an opt-in diagnostic. Starts now cost about the guest boot time. Windows seals omit the change time: writers can set it, and the system updates it when it caches a file hash in an extended attribute, which failed an unchanged OpenVMM executable closed during testing. Claim the OpenVMM log before a native launch. OpenVMM inherits the claim, so recovery can clear an interrupted start that recorded no process identity once nothing holds the log, instead of leaving the sandbox unusable. Markers of the default backend are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 6, 2026
Contributor
Author
|
Superseded by #418, which carries this change on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
nvxhostbackend to the edge sandbox crate. The caller supplies OpenVMM, a compatible kernel/initramfs and read-only GPT image, an absolute native-library path, and an independently approved SHA-256. The loader verifies ABI v1 and the required scratchless-launch and same-descriptor peer-check exports before use.<state_root>/nvxhost/, own the OpenVMM process and guest boot console, and implement provision/start/exec/guest logs/stop/deprovision through the native ttrpc channel.consoleErrormetadata instead of failing.sha256:<hex>). Registration hashes an image once, or records a digest that the caller's own policy verified; provision and start compare cheap file seals instead of hashing again and fail closed when a file changed. OpenVMM, the kernel, and the initramfs are hashed once per backend, optionally against approved digests. Hashing again before every start remains an opt-in diagnostic.register_image,images,verify_image, andunregister_imagemanage registrations; unregistering refuses while a provisioned sandbox uses the image.--image-sha256optionally requires the image digest.Dependencies and review base
9524065522764c8b80b3a4d48ec7877ddc16090b.esaurez/baseline-before-nvx-86661676branch atdb5138e361e26c698eaff9d627b8668899a1437d, the first parent of merge86661676. The newer OpenVMM pin rejects the available AMD validation hosts under an unrelated CPU-profile policy. Rebase ontodevafter that policy supports the hosts; do not merge into the temporary base branch. An earlier replay of this branch ontodevpassed the unit suites; it has not been refreshed for this head.Validation (head
ac47d53)cargo test --features nvxhost,testing,async(132 unit tests plus every integration suite) and the defaultcargo test(101 unit tests); Clippy with-D warningson all targets for both configurations;cargo +1.89 check(the declared minimum Rust version) for both.--release --test-threads=1) passes on an AMD WHP host: the earlier nine lifecycle and robustness tests plus image registration, reuse, fail-closed changes, unregistering, trusted digests, runtime-digest pinning, and content verification. Every test checks that no OpenVMM process outlives its sandbox.Notes
NvxHostConfigis now#[non_exhaustive]: construct it withNvxHostConfig::newand its builder methods.The independent review's four medium-severity findings and its follow-up zero-timeout compatibility finding are addressed in
e17cfae.adfa167changes documentation only.22cfcb1fixes the boot-console listener and adds the robustness suite; an independent review found no significant issues.ac47d53adds the image registry and the launch-log claim; its independent review raised the two compatibility points in the notes and nothing else.