Repository navigation
microVM: opt in to read-only distro with RAM overlay upper - #121
Merged
Merged
Conversation
esaurez
force-pushed
the
esaurez/microvm-ramfs-overlay
branch
from
October 7, 2026 18:37
4744ee7 to
e5547ce
Compare
esaurez
added a commit
to microsoft/nvx
that referenced
this pull request
Oct 7, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed overlay upper and no scratch disk. OpenVMM accepts that layout from nanvix/openvmm#121, rebased here onto the previous pin. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 7, 2026
esaurez
force-pushed
the
esaurez/microvm-ramfs-overlay
branch
from
October 8, 2026 15:43
e5547ce to
fca408a
Compare
esaurez
added a commit
to microsoft/nvx
that referenced
this pull request
Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed overlay upper and no scratch disk. OpenVMM accepts that layout from nanvix/openvmm#121, rebased here onto the previous pin. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
esaurez
marked this pull request as ready for review
October 8, 2026 15:44
There was a problem hiding this comment.
🟡 Changes recommended
Malformed bare overlay tokens bypass the new validation.
2 open findings
What changed in this PR
Adds an opt-in RAM-backed overlay for microVMs with one read-only distro block and no scratch device.
Changes:
- Adds shared overlay-token and block-layout validation.
- Rejects snapshot/restore options for this profile.
- Adds machine-contract and CLI validation tests.
| File | Description |
|---|---|
openvmm/openvmm_entry/src/cli_args/microvm.rs |
Enforces CLI restrictions and adds validation tests. |
openvmm/openvmm_defs/src/microvm.rs |
Adds overlay parsing, permits the distro-only layout, and tests discovery. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
esaurez
force-pushed
the
esaurez/microvm-ramfs-overlay
branch
from
October 8, 2026 16:13
fca408a to
09c16a4
Compare
esaurez
added a commit
to microsoft/nvx
that referenced
this pull request
Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed overlay upper and no scratch disk. OpenVMM accepts that layout from nanvix/openvmm#121, rebased here onto the previous pin. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Allow exactly one read-only distro block with the explicit nvx_overlay_upper=ramfs kernel token, and reject any other nvx_overlay_upper token, including a bare or repeated one. Keep existing scratch layouts unchanged and reject snapshot or restore for the scratchless profile. Document the layout and its restrictions in the Guide. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
ppenna
force-pushed
the
esaurez/microvm-ramfs-overlay
branch
from
October 8, 2026 17:10
09c16a4 to
f12dcf5
Compare
ppenna
pushed a commit
to microsoft/nvx
that referenced
this pull request
Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed overlay upper and no scratch disk. OpenVMM accepts that layout from nanvix/openvmm#121, rebased here onto the previous pin. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
nvx_overlay_upper=ramfstoken.This replaces #112, which carried the same change on a historical base that predates the CPU profiles. On
mainit needed two adjustments:validate_microvm_command_linekeepsmain'svalidate_microvm_filesystem_devicescheck next to the sandbox-block check, and the new test passes&[]for the virtio-fs list thatappend_microvm_virtio_discoverynow takes.It is now rebased onto
96e2363, the currentmainand the revision that microsoft/nvx'sdevpins. Since the previous base it adds the WHP CPUID fix, generation-bound microVM snapshots, scratch binding by file identity, and the fallback from--cpu-profile autoto a host profile. The change applied without conflicts.Validation
f12dcf5, on Windows with Rust 1.95.0:cargo clippy --all-targets,cargo doc --no-deps, andcargo nextest run --profile agent(20 and 184 tests) pass foropenvmm_defsandopenvmm_entry, andcargo xtask fmt --fixpasses. The review fixes add regression cases for bare and repeated tokens to the two new tests.cargo test --locked -p openvmm_defs -p openvmm_entrywith Rust 1.95.0: 20 and 184 tests on Windows, and 20 and 217 on Linux, including the two new ones.amd.milan.v1serves. Its 25 tests cover the lifecycle, streamed executions, robustness, image registration, host paths, network policies, the proxy, forwarded ports, and exec environments. NVX'sopenvmm_e2esuite (7 tests) passes too.--cpu-profile autoselectsamd.genoa.v1, which the hypervisor cannot present (E_PROFILE_UNSUPPORTED: it lackstsa_l1_no_supportandtsa_sq_no_support), so the fallback does not apply.The dependent opt-in consumer is microsoft/nvx#418.