Skip to content

Integrate authenticated guest reconnect and guarded runner recovery - #118

Draft
jiashuoz wants to merge 11 commits into
feat/guest-reconnect-readinessfrom
feat/b1-recovery-integration
Draft

jiashuoz wants to merge 11 commits into
feat/guest-reconnect-readinessfrom
feat/b1-recovery-integration

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Surviving microVM guests can recover an authenticated control connection after relay or runner loss when the operator enables guest recovery. Enrollment retains a process-memory key; reconnect proves that key against the current placement and accepted runner connection, applies fresh configuration, and fences the old relay before takeover.

Cold resume now commits an explicit resuming claim before launch and reconciles uncertain replies without creating a second placement. Durable launch ownership, process identity checks, terminal-generation fences, and exact counted placements prevent premature resource reuse and duplicate capacity reservations. Dedicated drain admission is handled by the paired Cloud change.

The standalone PostgreSQL dispatcher checks the current owner and configured policy, strictly separates guest boot redemption from runner proof redemption, and commits capability mutations with audit events. Recovery negotiation requires host support plus both runner capabilities. The runner opt-in is --microvm-guest-reconnect; it remains disabled by default. Volatile standalone stores do not negotiate recovery.

Validation: full make verify, focused host/driver/control race suites, Linux command cross-build, real PostgreSQL lock/expiry/replay tests, authenticated WebSocket round trips, and the shipping controld process including negotiated create. Independent and adversarial reviews addressed reproduced findings. Immediate numeric-PID check/signal races are documented; this change does not claim a pidfd guarantee.

B1 remains incomplete. The final paired Cloud pin, reviewed live fixture adapters, disposable KVM recovery/agent-turn qualification, independent teardown, and final CI/review are required before merge. Unit and shipping-process tests do not establish live guest qualification. RAM snapshots are outside this change.

Stacked on #117; paired Cloud integration: https://github.com/tokencanopy/rainier-cloud/pull/149.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant