Skip to content

fix(test): align snapshot disk gate with runtime contracts - #89

Merged
mkagenius merged 2 commits into
mainfrom
codex/fix-snapshot-disk-handles
Oct 5, 2026
Merged

mkagenius merged 2 commits into
mainfrom
codex/fix-snapshot-disk-handles

Conversation

@mkagenius

@mkagenius mkagenius commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The snapshot-disk KVM gate no longer matches the current API and runtime records: it reads a removed path response field, sends the rejected snapshot_path restore field, and expects restored writable overlays at the obsolete <vm-id>.cow filename. These assumptions abort the gate before it proves disk isolation.

Use the public opaque snapshot_id for snapshot and restore requests. Resolve artifact and per-VM overlay paths through read-only queries of the harness's private SQLite store. Keep checks that the snapshot survives source deletion, restored overlays exist and differ, checkpoint contents are preserved, and writes remain private to each restore.

Add six black-box regressions that execute the real shell harness against a small local fake API. Restored overlay filenames deliberately differ from cold-boot filenames. Cases cover success, missing snapshot record/artifact, missing runtime record/overlay, and shared restored disk state. Ordinary CI runs these without KVM. No production API, VMM, protocol, restore-sizing, Rust source, or dependency changes.

Validation

  • Regression reproduction: the original script fails on the removed path field. A mutation retaining snapshot_path fails with HTTP 400. The first corrected script failed on real KVM because of its stale overlay filename; the updated fake also reproduces that failure.
  • Final head 8e6eb14c4711a5a436744c8af2001db80b2ccb6b: all six harness regressions pass on macOS, Azure Linux, and GitHub Actions Linux. bash -n, git diff --check, Ruff 0.16.5 E/F/I lint, and Ruff formatting pass.
  • Live KVM gate passes on the final harness: RESULT: SNAPSHOT_DISK_PASS, 11.36 seconds total, snapshot capture 6,711 ms. Ubuntu 24.04 x86_64 on Azure E2ds_v6 with real nested KVM and Btrfs/NVMe scratch. The test created a source, captured its checkpoint, changed and deleted it, restored twice, and verified private writes. Existing release binaries were reused only after verifying that the follow-up changes exactly two harness files and leaves all production sources identical. Kernel and binary hashes were recorded.
  • The same bounded hardware session passed 122 baseline VMM library tests and eight focused live-guest lifecycle/restore checks. This is focused qualification, not a full integration suite or soak test.
  • Before the harness-only follow-up, the unchanged orchestrator workspace passed Rust 1.88 formatting, strict Clippy, all-target checks, and a final 461-test run. An initial connection reset in an unchanged WebSocket test passed its isolated retry and full rerun.
  • CI for the final head: all six new harness tests and the VMM, protocol, SDK, and musl jobs pass. The orchestrator job fails only on the three existing Rust 1.99 fetch_update deprecations at metrics.rs:320/326 and pty.rs:119, before its Rust suite. Separate draft fix(orch): preserve saturating atomic updates on Rust 1.99 #87 addresses those errors. Security passes. The guest-kernel workflow also passes; it is separate from the completed live gate.

Checklist

  • Focused regression, lint, syntax, and formatting checks pass.
  • Corrected live snapshot-disk gate passes with real KVM.
  • No production runtime or stable control-contract changes.
  • Final diff reviewed; pushed commit and draft state verified.

@mkagenius mkagenius changed the title fix(test): use opaque snapshot handles in disk isolation gate fix(test): align snapshot disk gate with runtime contracts Oct 5, 2026
@mkagenius
mkagenius marked this pull request as ready for review October 5, 2026 20:07
@mkagenius
mkagenius merged commit 256b66a into main Oct 5, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant