Repository navigation
Conversation
A microVM that has a live authenticated control console cannot use the management RPC, the console relay, or --paused, and its REPL is headless, so its host had no way to pause or resume it. Add --microvm-state-control listen=PATH, a separate local endpoint that is bound and peer-checked like the control console. A host authenticates with the control-console capability within the control-console authentication timeout, then sends QUERY, PAUSE, and RESUME requests. The endpoint serves one host at a time, answers while the VM is paused, and is never recorded in a snapshot. The Guide documents protocol version 1. The VM worker gains MicrovmPause, MicrovmResume, and MicrovmRunState. A host pause stops the state units and holds guest monotonic time: once the vCPUs stop, it takes VP 0's TSC and every LAPIC, and resume sets them back with the time ABI's synchronized TSC set before any vCPU runs. Wall-clock time is not held; the CMOS RTC keeps following host UTC. A pause is busy during a snapshot boundary or post-restore gate, and is rejected for periodic or TSC-deadline LAPIC timers, as capture is. A guest reset while paused keeps the pause but discards the held time; a failed reset ends the pause. Also make the Windows named-pipe serial backend listen again when an accepted client's identity cannot be resolved, instead of dropping the pipe and panicking on the next poll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The NVX guest's wall-clock discipline reads the time ABI's time sample, not the CMOS RTC. Both follow host UTC across a host pause; say so, and that the guest steps its clock from such a source at its next poll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
esaurez
force-pushed
the
esaurez/microvm-vm-state-control
branch
from
October 6, 2026 15:55
d3669f3 to
647e635
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A microVM launched with a live authenticated control console (
--microvm-control-console listen=... --microvm-control-auth-stdin) cannot use the management RPC, the console relay, or--paused, and its REPL is headless, so its host has no way to pause or resume it.This adds
--microvm-state-control listen=PATH, a separate local endpoint for host pause, resume, and run-state queries:0600socket in an owned0700directory with anSO_PEERCREDUID check. On Windows it is a named pipe with a protected DACL and a token-SID check.--microvm-control-auth-timeout-ms. A failed or stalled authentication, or a malformed request, closes the connection without a response. One host is served at a time, with a 60 s idle timeout.AUTHENTICATE,QUERY,PAUSE, andRESUMErequests. Each response carries the run state (RUNNING,PAUSED,STOPPED,BUSY), a transitions counter, and the broker instance ID. The protocol is documented inGuide/src/reference/openvmm/management/state_control_protocol.md.Worker semantics
This adds
VmRpc::MicrovmPause,VmRpc::MicrovmResume, andVmRpc::MicrovmRunState:BUSYduring a snapshot boundary or post-restore gate.TimeAbiBackend::set_synchronized_tscis now also called at each host resume. Every instantiated VP is bound before the VM loads, so MSHV's VP-creation seal is unaffected.Also
serial_socket: when an accepted client's identity cannot be resolved (for example, the client already exited), the Windows named-pipe backend now listens again. Previously it dropped the pipe instance and panicked on the next poll ("polled after completion"). This also affects the control console.Testing
These results are for the branch rebased on #115 (
07850d27a).Windows (
cargo +1.95):openvmm_core103,openvmm_entry191,vmm_core65,virt36,openvmm_defs18, andserial_socket4.serial_socketfix.clippy --all-targets -- -D warningsandxtask fmtare clean.Linux:
cargo checkandclippy --all-targets --target x86_64-unknown-linux-gnuare clean.Linux: the unit tests pass with Rust 1.98.1 in NVX's pinned build container on an MSHV host, including the real AF_UNIX endpoint session:
openvmm_core103,openvmm_entry223,vmm_core65,virt36,openvmm_defs18,cpu_profile111, andserial_socket1.Runtime: NVX's new
pause-resumescenario (test-microvm: pause and resume a microVM through OpenVMM state control microsoft/nvx#405) holds a managed 8-vCPU VM paused for 30 s and then twice for 2 s. It passes, together withmanaged-lifecycle, on two backends:--cpu-profile host;test-microvmhas no option for it.amd.milan.v1.On MSHV, OpenVMM used 1.01 CPU seconds per second while the guest was busy and none while it was paused. On both backends, hosts that did not authenticate or presented the wrong capability got no response.
Not run: KVM and Intel hosts. NVX CI runs the scenario on its Intel KVM, MSHV, and WHP runners and on the debug kernel once Cherry-pick: vmbus_server: call unstick_channels to mitigate the lost synic issue microsoft/openvmm#405 leaves draft.