Skip to content

Retire the dead v1 MAP_SHARED/Msync snapshot surface (ADR 0045 D1) - #9

Merged
nikhilunni merged 1 commit into
engram/live-migrationfrom
cleanup/retire-v1-mapshared
Jun 29, 2026
Merged

nikhilunni merged 1 commit into
engram/live-migrationfrom
cleanup/retire-v1-mapshared

Conversation

@nikhilunni

Copy link
Copy Markdown
Contributor

The engrams live-migration fork sits on upstream v1.16.0 + three commits:

  • v1 (5ca2fba4) — MAP_SHARED memory + Msync/MsyncAndState off-pause flush
  • v2 (4a9636d0) — MAP_PRIVATE base-file + MISSING|MINOR substrate
  • v3 (d78c1dc1) — vmstate_only create param

v1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate + the v3 post-copy path and is dead: nothing emits it (the engrams host's SnapshotType is {Full, Diff}; there's no shared load param on the host side). engrams ADR 0045 D1 marked it for retirement.

What this removes

A revert of 5ca2fba4 reconciled with v2/v3:

  • SnapshotType::{Msync, MsyncAndState}
  • the shared load param (LoadSnapshotParams/LoadSnapshotConfig + swagger)
  • vstate/memory.rs msync() + the shared MAP_PRIVATE→MAP_SHARED flag on snapshot_file (back to the upstream 3-arg, MAP_PRIVATE signature)
  • vstate/vm.rs msync dispatch in snapshot_memory_to_file
  • persist.rs Msync state-file skip + the now-vacuous vmstate_only-vs-Msync guard (vmstate_only combines only with Full/Diff, the only remaining types)
  • the api_server + rpc_interface surface; the integration test for the dead guard

9 files, 24 insertions / 163 deletions.

Preserved / invariants

  • v2 (substrate) and v3 (vmstate_only) are intact. The v2 base-file path that called snapshot_file(.., shared=false) now uses the reverted 3-arg signature (MAP_PRIVATE — its existing behavior).
  • No change to src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock, the invariant the v1 commit itself established.

Validation

cargo check -p vmm (lib and tests) for aarch64-unknown-linux-musl is clean. The firecracker binary crate isn't musl-checkable locally (the upstream seccompiler crate has no libc::memfd_create on musl), so the full build + the stock↔fork snapshot-compat test are left to CI / the engrams build-firecracker step. The api_server/swagger changes are mechanical field-drops matching the validated vmm struct change.

Once green, the engrams repo bumps its third_party/firecracker submodule to this commit (separate PR).

🤖 Generated with Claude Code

…strate + v3 vmstate-only)

The engrams live-migration fork landed in three commits on upstream v1.16.0:
v1 (5ca2fba — MAP_SHARED memory + Msync/MsyncAndState off-pause flush), v2
(MAP_PRIVATE base-file + MISSING|MINOR substrate), and v3 (vmstate_only create
param). v1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate and
the v3 post-copy path, and is dead: nothing emits it (the engrams host's
SnapshotType is {Full, Diff}; there is no `shared` load param on the host side).
engrams ADR 0045 D1 marked it for retirement.

Remove the v1 surface (a revert of 5ca2fba reconciled with v2/v3):
- SnapshotType::{Msync, MsyncAndState}.
- The `shared` load param (LoadSnapshotParams/LoadSnapshotConfig + swagger).
- vstate/memory.rs `msync()` + the `shared` MAP_PRIVATE->MAP_SHARED flag on
  `snapshot_file` (back to the upstream 3-arg, MAP_PRIVATE signature).
- vstate/vm.rs msync dispatch in `snapshot_memory_to_file`.
- persist.rs Msync state-file skip + the now-vacuous vmstate_only-vs-Msync guard
  (vmstate_only combines only with Full/Diff, the only remaining types).
- api_server + rpc_interface surface; the integration test for the dead guard.

v2 (substrate) and v3 (vmstate_only) are preserved intact; the v2 base-file path
that passed `snapshot_file(.., shared=false)` now calls the reverted 3-arg
signature (MAP_PRIVATE — its existing behavior). No change to
src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock
(the v1 commit's invariant).

Validated: `cargo check -p vmm` (lib + tests) for aarch64-unknown-linux-musl is
clean. The firecracker-binary build isn't musl-checkable here (the upstream
`seccompiler` crate has no libc `memfd_create` on musl), so the full build +
stock<->fork snapshot-compat test run in CI.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EkVddad6rxeV6xFfovQ8x
@nikhilunni
nikhilunni merged commit 6d0f0d4 into engram/live-migration Jun 29, 2026
3 checks passed
@nikhilunni
nikhilunni deleted the cleanup/retire-v1-mapshared branch June 29, 2026 14:45
nikhilunni added a commit to cortexapps/engrams that referenced this pull request Jun 29, 2026
…HARED/Msync surface

Bumps third_party/firecracker d78c1dc1 -> 0e02b3a9 (cortexapps/firecracker#9),
removing the dead v1 MAP_SHARED + Msync/MsyncAndState snapshot surface that was
superseded by the v2 UFFD substrate and the v3 vmstate-only post-copy path.
Nothing in engrams emits it (the host's SnapshotType is {Full, Diff}; there is
no `shared` load param), and ADR 0045 D1 marked it for retirement. No change to
src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock.

This PR's CI (build-firecracker + the stock<->fork snapshot-compat test + the FC
integration suite) is the authoritative end-to-end validation of the fork change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EkVddad6rxeV6xFfovQ8x
cortex-image-bot pushed a commit that referenced this pull request Jun 30, 2026
…strate + v3 vmstate-only) (#9)

The engrams live-migration fork landed in three commits on upstream v1.16.0:
v1 (5ca2fba — MAP_SHARED memory + Msync/MsyncAndState off-pause flush), v2
(MAP_PRIVATE base-file + MISSING|MINOR substrate), and v3 (vmstate_only create
param). v1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate and
the v3 post-copy path, and is dead: nothing emits it (the engrams host's
SnapshotType is {Full, Diff}; there is no `shared` load param on the host side).
engrams ADR 0045 D1 marked it for retirement.

Remove the v1 surface (a revert of 5ca2fba reconciled with v2/v3):
- SnapshotType::{Msync, MsyncAndState}.
- The `shared` load param (LoadSnapshotParams/LoadSnapshotConfig + swagger).
- vstate/memory.rs `msync()` + the `shared` MAP_PRIVATE->MAP_SHARED flag on
  `snapshot_file` (back to the upstream 3-arg, MAP_PRIVATE signature).
- vstate/vm.rs msync dispatch in `snapshot_memory_to_file`.
- persist.rs Msync state-file skip + the now-vacuous vmstate_only-vs-Msync guard
  (vmstate_only combines only with Full/Diff, the only remaining types).
- api_server + rpc_interface surface; the integration test for the dead guard.

v2 (substrate) and v3 (vmstate_only) are preserved intact; the v2 base-file path
that passed `snapshot_file(.., shared=false)` now calls the reverted 3-arg
signature (MAP_PRIVATE — its existing behavior). No change to
src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock
(the v1 commit's invariant).

Validated: `cargo check -p vmm` (lib + tests) for aarch64-unknown-linux-musl is
clean. The firecracker-binary build isn't musl-checkable here (the upstream
`seccompiler` crate has no libc `memfd_create` on musl), so the full build +
stock<->fork snapshot-compat test run in CI.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant