Skip to content

fix(vm): recover overlay journal before generation cleanup - #3940

Closed
romainPellerin wants to merge 1 commit into
NVIDIA:mainfrom
romainPellerin:fix/vm-recover-before-auth-cleanup
Closed

romainPellerin wants to merge 1 commit into
NVIDIA:mainfrom
romainPellerin:fix/vm-recover-before-auth-cleanup

Conversation

@romainPellerin

Copy link
Copy Markdown

Summary

Recover the stopped VM's ext4 overlay before removing the previous generation's guest authentication files. Cleanup currently calls debugfs on an unrecovered journal; a subsequent start can fail with an unattached inode and e2fsck exit status 4.

Related Issue

No issue required: localized ordering fix in existing VM stop/start cleanup, with a regression test and no API or policy change.

Changes

  • Run the existing recover_rootfs_image check before the first offline deletion.
  • Preserve host authentication and generation markers when recovery fails so cleanup remains retryable.
  • Add a regression test for an unrecoverable overlay and extend VM overlay coverage to three stop/start cycles with flushed file contents.
  • Describe the recovery ordering in the VM driver README.

Testing

  • The new unit test fails on the unchanged base and passes with this fix; all 194 VM driver library tests pass.
  • VM overlay E2E passes on macOS arm64: three stop/start cycles preserve all 128 flushed files per cycle. The locally built driver used the v0.1.2 embedded runtime and v0.1.2 gateway/CLI.
  • cargo clippy -p openshell-driver-vm --all-targets --locked -- -D warnings passes.
  • E2E test Clippy, Rust formatting, changed-file SPDX checks and git diff --check pass.
  • mise run pre-commit passes: unavailable because mise is not installed. The same limitation prevents the full mise run ci suite; focused checks are listed above.
  • Unit tests added/updated
  • E2E tests added/updated

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Relevant driver documentation updated

This fix retains the existing automatic-repair policy and fails closed on unrecoverable disks. It does not make VM termination a graceful filesystem shutdown; the persistence test explicitly flushes writes before stopping.

Signed-off-by: romainPellerin <591564+romainPellerin@users.noreply.github.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@github-actions

Copy link
Copy Markdown

Thank you for your submission! We ask that you sign our Developer Certificate of Origin before we can accept your contribution. You can sign the DCO by adding a comment below using this text:


I have read the DCO document and I hereby sign the DCO.


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the DCO Assistant Lite bot.

@github-actions

Copy link
Copy Markdown

Thank you for your interest in contributing to OpenShell, @romainPellerin.

This project uses a vouch system for first-time contributors. Before submitting a pull request, you need to be vouched by a maintainer.

To get vouched:

  1. Open a Vouch Request discussion.
  2. Describe what you want to change and why.
  3. Write in your own words — do not have an AI generate the request.
  4. A maintainer will comment /vouch if approved.
  5. Once vouched, open a new PR (preferred) or reopen this one after a few minutes.

See CONTRIBUTING.md for details.

@github-actions github-actions Bot closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant