Skip to content

microVM: opt in to read-only distro with RAM overlay upper - #121

Merged
ppenna merged 1 commit into
mainfrom
esaurez/microvm-ramfs-overlay
Oct 8, 2026
Merged

ppenna merged 1 commit into
mainfrom
esaurez/microvm-ramfs-overlay

Conversation

@esaurez

@esaurez esaurez commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

  • Permit a microVM with exactly one read-only distro block and no scratch block only when the kernel command line contains exactly one nvx_overlay_upper=ramfs token.
  • Reject other scratchless layouts, malformed (including bare) or duplicate overlay tokens, and snapshot/restore for this profile. Existing scratch-backed layouts retain their behavior.
  • Exercise both the machine-contract and CLI validation paths.
  • Document the layout, its token, and its snapshot/restore restriction in the Guide's run page and CLI reference.

This replaces #112, which carried the same change on a historical base that predates the CPU profiles. On main it needed two adjustments: validate_microvm_command_line keeps main's validate_microvm_filesystem_devices check next to the sandbox-block check, and the new test passes &[] for the virtio-fs list that append_microvm_virtio_discovery now takes.

It is now rebased onto 96e2363, the current main and the revision that microsoft/nvx's dev pins. Since the previous base it adds the WHP CPUID fix, generation-bound microVM snapshots, scratch binding by file identity, and the fallback from --cpu-profile auto to a host profile. The change applied without conflicts.

Validation

  • At f12dcf5, on Windows with Rust 1.95.0: cargo clippy --all-targets, cargo doc --no-deps, and cargo nextest run --profile agent (20 and 184 tests) pass for openvmm_defs and openvmm_entry, and cargo xtask fmt --fix passes. The review fixes add regression cases for bare and repeated tokens to the two new tests.
  • cargo test --locked -p openvmm_defs -p openvmm_entry with Rust 1.95.0: 20 and 184 tests on Windows, and 20 and 217 on Linux, including the two new ones.
  • With a Windows release build, the dependent NVX native-host guest suite passes on an AMD EPYC 7763 WHP host, which amd.milan.v1 serves. Its 25 tests cover the lifecycle, streamed executions, robustness, image registration, host paths, network policies, the proxy, forwarded ports, and exec environments. NVX's openvmm_e2e suite (7 tests) passes too.
  • With a Linux build, the same suites pass on an AMD EPYC 9V74 MSHV host with the host CPU profile. On that host --cpu-profile auto selects amd.genoa.v1, which the hypervisor cannot present (E_PROFILE_UNSUPPORTED: it lacks tsa_l1_no_support and tsa_sq_no_support), so the fallback does not apply.
  • The guests boot NVX's Linux 6.18.38 kernel and tick on the LAPIC timer, as the time ABI requires.

The dependent opt-in consumer is microsoft/nvx#418.

@esaurez
esaurez force-pushed the esaurez/microvm-ramfs-overlay branch from 4744ee7 to e5547ce Compare October 7, 2026 18:37
esaurez added a commit to microsoft/nvx that referenced this pull request Oct 7, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed
overlay upper and no scratch disk. OpenVMM accepts that layout from
nanvix/openvmm#121, rebased here onto the previous pin.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@esaurez
esaurez force-pushed the esaurez/microvm-ramfs-overlay branch from e5547ce to fca408a Compare October 8, 2026 15:43
esaurez added a commit to microsoft/nvx that referenced this pull request Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed
overlay upper and no scratch disk. OpenVMM accepts that layout from
nanvix/openvmm#121, rebased here onto the previous pin.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@esaurez
esaurez marked this pull request as ready for review October 8, 2026 15:44
Copilot AI balanced review requested due to automatic review settings October 8, 2026 15:44

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Malformed bare overlay tokens bypass the new validation.

2 open findings
What changed in this PR

Adds an opt-in RAM-backed overlay for microVMs with one read-only distro block and no scratch device.

Changes:

  • Adds shared overlay-token and block-layout validation.
  • Rejects snapshot/restore options for this profile.
  • Adds machine-contract and CLI validation tests.
File Description
openvmm/​openvmm_entry/​src/​cli_args/​microvm.rs Enforces CLI restrictions and adds validation tests.
openvmm/​openvmm_defs/​src/​microvm.rs Adds overlay parsing, permits the distro-only layout, and tests discovery.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread openvmm/openvmm_defs/src/microvm.rs Outdated
Comment thread openvmm/openvmm_entry/src/cli_args/microvm.rs
@esaurez
esaurez force-pushed the esaurez/microvm-ramfs-overlay branch from fca408a to 09c16a4 Compare October 8, 2026 16:13
esaurez added a commit to microsoft/nvx that referenced this pull request Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed
overlay upper and no scratch disk. OpenVMM accepts that layout from
nanvix/openvmm#121, rebased here onto the previous pin.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Allow exactly one read-only distro block with the explicit nvx_overlay_upper=ramfs kernel token, and reject any other nvx_overlay_upper token, including a bare or repeated one. Keep existing scratch layouts unchanged and reject snapshot or restore for the scratchless profile. Document the layout and its restrictions in the Guide.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@ppenna
ppenna force-pushed the esaurez/microvm-ramfs-overlay branch from 09c16a4 to f12dcf5 Compare October 8, 2026 17:10
@github-actions github-actions Bot added the Guide label Oct 8, 2026
ppenna pushed a commit to microsoft/nvx that referenced this pull request Oct 8, 2026
The edge runtime boots a sandbox from one read-only image with a RAM-backed
overlay upper and no scratch disk. OpenVMM accepts that layout from
nanvix/openvmm#121, rebased here onto the previous pin.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@ppenna
ppenna merged commit f12dcf5 into main Oct 8, 2026
76 checks passed
@ppenna
ppenna deleted the esaurez/microvm-ramfs-overlay branch October 8, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants