Skip to content

microVM: opt in to read-only distro with RAM overlay upper - #112

Closed
esaurez wants to merge 1 commit into
mainfrom
esaurez/microvm-ramfs-overlay-pre-time-abi
Closed

esaurez wants to merge 1 commit into
mainfrom
esaurez/microvm-ramfs-overlay-pre-time-abi

Conversation

@esaurez

@esaurez esaurez commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

  • Permit a microVM with exactly one read-only distro block and no scratch block only when the kernel command line contains exactly one nvx_overlay_upper=ramfs token.
  • Reject other scratchless layouts, malformed or duplicate overlay tokens, and snapshot/restore for this profile. Existing scratch-backed layouts retain their behavior.
  • Exercise both the machine-contract and CLI validation paths.

Validation

On main at 762bc1c:

  • cargo test --locked -p openvmm_defs -p openvmm_entry: 20 and 183 tests on Windows, and 20 and 216 on Linux, including the two new ones.
  • The dependent NVX native-host guest suite passes with release builds of this head. Its 25 tests cover the lifecycle, streamed executions, robustness, image registration, host paths, network policies, the proxy, forwarded ports, and exec environments.
    • Windows/WHP on an AMD EPYC 7763, with the built-in amd.milan.v1 profile.
    • Linux/MSHV on an AMD EPYC 9V74, with the host CPU profile.
  • The guests boot NVX's Linux 6.18.38 kernel and tick on the LAPIC timer, as the time ABI requires.

Base

This draft now targets main. It previously targeted the temporary base esaurez/baseline-openvmm-4355c010, because the newer OpenVMM pin rejected the available AMD validation hosts under its CPU-profile policy. main at 762bc1c, which NVX dev now pins, boots both hosts, so the change is rebased onto it. The rebase needed two adjustments:

  • validate_microvm_command_line keeps main's validate_microvm_filesystem_devices check next to the sandbox-block check.
  • The new test passes &[] for the virtio-fs list that append_microvm_virtio_discovery now takes.

The rebased head is the same commit as #121 (e5547ce31).

The dependent opt-in consumer is microsoft/nvx#418, which replaces microsoft/nvx#395.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

⚠️ Unsafe Code Detected

This PR modifies files containing unsafe Rust code. Extra scrutiny is required during review.

For more on why we check whole files, instead of just diffs, check out the Rustonomicon

@esaurez
esaurez changed the base branch from esaurez/baseline-openvmm-4355c010 to main October 5, 2026 23:16
@esaurez
esaurez force-pushed the esaurez/microvm-ramfs-overlay-pre-time-abi branch from c6429ab to 9524065 Compare October 6, 2026 00:31
@github-actions github-actions Bot removed the unsafe label Oct 6, 2026
@esaurez
esaurez changed the base branch from main to esaurez/baseline-openvmm-4355c010 October 6, 2026 00:32
Allow exactly one read-only distro block with the explicit nvx_overlay_upper=ramfs kernel token. Keep existing scratch layouts unchanged and reject snapshot or restore for the scratchless profile.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@esaurez
esaurez changed the base branch from esaurez/baseline-openvmm-4355c010 to main October 7, 2026 19:42
@esaurez
esaurez force-pushed the esaurez/microvm-ramfs-overlay-pre-time-abi branch from 9524065 to e5547ce Compare October 7, 2026 19:42
@esaurez

esaurez commented Oct 7, 2026 •

Copy link
Copy Markdown
Author

The previous head, 95240655, which microsoft/nvx#395 still pins, is preserved on esaurez/microvm-ramfs-overlay-pre-time-abi-9524065.

@esaurez

esaurez commented Oct 7, 2026

Copy link
Copy Markdown
Author

Closing in favor of #121, which carries this same change on main as the same commit (e5547ce31). microsoft/nvx#418 depends on #121.

@esaurez esaurez closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant