Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Surviving microVM guests can recover an authenticated control connection after relay or runner loss when the operator enables guest recovery. Enrollment retains a process-memory key; reconnect proves that key against the current placement and accepted runner connection, applies fresh configuration, and fences the old relay before takeover.
Cold resume now commits an explicit
resumingclaim before launch and reconciles uncertain replies without creating a second placement. Durable launch ownership, process identity checks, terminal-generation fences, and exact counted placements prevent premature resource reuse and duplicate capacity reservations. Dedicated drain admission is handled by the paired Cloud change.The standalone PostgreSQL dispatcher checks the current owner and configured policy, strictly separates guest boot redemption from runner proof redemption, and commits capability mutations with audit events. Recovery negotiation requires host support plus both runner capabilities. The runner opt-in is
--microvm-guest-reconnect; it remains disabled by default. Volatile standalone stores do not negotiate recovery.Validation: full
make verify, focused host/driver/control race suites, Linux command cross-build, real PostgreSQL lock/expiry/replay tests, authenticated WebSocket round trips, and the shipping controld process including negotiated create. Independent and adversarial reviews addressed reproduced findings. Immediate numeric-PID check/signal races are documented; this change does not claim a pidfd guarantee.B1 remains incomplete. The final paired Cloud pin, reviewed live fixture adapters, disposable KVM recovery/agent-turn qualification, independent teardown, and final CI/review are required before merge. Unit and shipping-process tests do not establish live guest qualification. RAM snapshots are outside this change.
Stacked on #117; paired Cloud integration: https://github.com/tokencanopy/rainier-cloud/pull/149.