Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tarit snapshots currently restore with their original guest-visible memory. This adds opt-in virtio-mem templates: boot with 2048 MiB, reserve a 4096 MiB maximum, then restore with
target_memory_mib: 4096while preserving running process and RAM state.Draft: serial Linux/KVM acceptance passed with corrected test fixtures. Concurrent clone isolation, jailed hardware mode, overcommit and full integration/soak qualification remain untested.
The change carries the memory layout, device bitmap and requested target through snapshot/restore, CLI, orchestrator, peer RPC and generated SDKs. Restore publishes only after the device and guest agent confirm that the requested RAM is online. Shrinking and exceeding the saved maximum fail. Jailed preparation preserves the memory configuration, and pending memory IRQs are signalled after all restored vCPU/LAPIC state is installed.
The maximum remains reserved/backed from creation and determines admission, cgroup budgeting and snapshot extent size. A 2 GiB boot / 4 GiB maximum template has a 4 GiB RAM snapshot extent. This does not implement host-memory overcommit. Existing snapshots are not converted. New templates require the updated VMM, orchestrator, guest kernel and agent; older VMMs reject the new snapshot state. The pinned kernel candidate requires normal promotion/release before the download helper can fetch it.
Hardware evidence:
66f9333f0c2a8fca3eeb429b2e136c047792bd35passed the serial 2→4 GiB gate in 238.33 seconds with corrected fixtures and a shell driver adapted only to fixture/source paths. The unmodified old harness did not pass.MemTotalwas 2,043,016 KiB; restoredMemTotalwas 4,140,168 KiB. The running witness retained its PID, nonce and page markers, touched 3 GiB with zero bad pages, and survived a second snapshot/restore without a target override.18e142fbbcc625868a7fbaf0e70cb260034948a5addsMAP_NORESERVEto the witness's virtual mapping, checks the redacted public API error plus the internal reason in the private daemon log, and adds witness startup diagnostics. It changes no production code and does not enable host overcommit.6ad60bb244f526d955b2527c5917a25638a2484f. C fixture SHA256:dc8752e024805d2224c4d2bc3ba85f0aa615cc7a0fa564a66cd3ddc38c9bed27; Python fixture SHA256:426960c49dbe52e241efcbdfa96435c8337ef2e188c9e9c8c7d1a9d99e892943. This commit was not rerun on hardware after publication.Validation:
66f9333, protocol, VMM (including Linux/KVM compile/lint), SDK, musl and security CI passed. Kernel reproducibility CI passed config/hash verification, a clean byte-for-byte rebuild and candidate upload; production trees and kernel inputs are unchanged by the fixture commit.Before readiness claims: qualify concurrent clone isolation, production jail/cgroup/seccomp, authenticated lazy restore, SMP, network/volume load, forced agent/driver timeout and full integration/soak behavior. See
docs/memory-growth.mdfor resource semantics, rollout constraints and the test command. No merge, deployment or release publication is included.