Repository navigation
Retire the dead v1 MAP_SHARED/Msync snapshot surface (ADR 0045 D1) - #9
Merged
Merged
Conversation
…strate + v3 vmstate-only) The engrams live-migration fork landed in three commits on upstream v1.16.0: v1 (5ca2fba — MAP_SHARED memory + Msync/MsyncAndState off-pause flush), v2 (MAP_PRIVATE base-file + MISSING|MINOR substrate), and v3 (vmstate_only create param). v1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate and the v3 post-copy path, and is dead: nothing emits it (the engrams host's SnapshotType is {Full, Diff}; there is no `shared` load param on the host side). engrams ADR 0045 D1 marked it for retirement. Remove the v1 surface (a revert of 5ca2fba reconciled with v2/v3): - SnapshotType::{Msync, MsyncAndState}. - The `shared` load param (LoadSnapshotParams/LoadSnapshotConfig + swagger). - vstate/memory.rs `msync()` + the `shared` MAP_PRIVATE->MAP_SHARED flag on `snapshot_file` (back to the upstream 3-arg, MAP_PRIVATE signature). - vstate/vm.rs msync dispatch in `snapshot_memory_to_file`. - persist.rs Msync state-file skip + the now-vacuous vmstate_only-vs-Msync guard (vmstate_only combines only with Full/Diff, the only remaining types). - api_server + rpc_interface surface; the integration test for the dead guard. v2 (substrate) and v3 (vmstate_only) are preserved intact; the v2 base-file path that passed `snapshot_file(.., shared=false)` now calls the reverted 3-arg signature (MAP_PRIVATE — its existing behavior). No change to src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock (the v1 commit's invariant). Validated: `cargo check -p vmm` (lib + tests) for aarch64-unknown-linux-musl is clean. The firecracker-binary build isn't musl-checkable here (the upstream `seccompiler` crate has no libc `memfd_create` on musl), so the full build + stock<->fork snapshot-compat test run in CI. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EkVddad6rxeV6xFfovQ8x
nikhilunni
added a commit
to cortexapps/engrams
that referenced
this pull request
Jun 29, 2026
…HARED/Msync surface Bumps third_party/firecracker d78c1dc1 -> 0e02b3a9 (cortexapps/firecracker#9), removing the dead v1 MAP_SHARED + Msync/MsyncAndState snapshot surface that was superseded by the v2 UFFD substrate and the v3 vmstate-only post-copy path. Nothing in engrams emits it (the host's SnapshotType is {Full, Diff}; there is no `shared` load param), and ADR 0045 D1 marked it for retirement. No change to src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock. This PR's CI (build-firecracker + the stock<->fork snapshot-compat test + the FC integration suite) is the authoritative end-to-end validation of the fork change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EkVddad6rxeV6xFfovQ8x
cortex-image-bot
pushed a commit
that referenced
this pull request
Jun 30, 2026
…strate + v3 vmstate-only) (#9) The engrams live-migration fork landed in three commits on upstream v1.16.0: v1 (5ca2fba — MAP_SHARED memory + Msync/MsyncAndState off-pause flush), v2 (MAP_PRIVATE base-file + MISSING|MINOR substrate), and v3 (vmstate_only create param). v1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate and the v3 post-copy path, and is dead: nothing emits it (the engrams host's SnapshotType is {Full, Diff}; there is no `shared` load param on the host side). engrams ADR 0045 D1 marked it for retirement. Remove the v1 surface (a revert of 5ca2fba reconciled with v2/v3): - SnapshotType::{Msync, MsyncAndState}. - The `shared` load param (LoadSnapshotParams/LoadSnapshotConfig + swagger). - vstate/memory.rs `msync()` + the `shared` MAP_PRIVATE->MAP_SHARED flag on `snapshot_file` (back to the upstream 3-arg, MAP_PRIVATE signature). - vstate/vm.rs msync dispatch in `snapshot_memory_to_file`. - persist.rs Msync state-file skip + the now-vacuous vmstate_only-vs-Msync guard (vmstate_only combines only with Full/Diff, the only remaining types). - api_server + rpc_interface surface; the integration test for the dead guard. v2 (substrate) and v3 (vmstate_only) are preserved intact; the v2 base-file path that passed `snapshot_file(.., shared=false)` now calls the reverted 3-arg signature (MAP_PRIVATE — its existing behavior). No change to src/vmm/src/snapshot/ and no SNAPSHOT_VERSION bump — byte-compatible with stock (the v1 commit's invariant). Validated: `cargo check -p vmm` (lib + tests) for aarch64-unknown-linux-musl is clean. The firecracker-binary build isn't musl-checkable here (the upstream `seccompiler` crate has no libc `memfd_create` on musl), so the full build + stock<->fork snapshot-compat test run in CI. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The engrams live-migration fork sits on upstream v1.16.0 + three commits:
5ca2fba4) — MAP_SHARED memory +Msync/MsyncAndStateoff-pause flush4a9636d0) — MAP_PRIVATE base-file +MISSING|MINORsubstrated78c1dc1) —vmstate_onlycreate paramv1's MAP_SHARED/msync design was superseded by the v2 UFFD substrate + the v3 post-copy path and is dead: nothing emits it (the engrams host's
SnapshotTypeis{Full, Diff}; there's nosharedload param on the host side). engrams ADR 0045 D1 marked it for retirement.What this removes
A revert of
5ca2fba4reconciled with v2/v3:SnapshotType::{Msync, MsyncAndState}sharedload param (LoadSnapshotParams/LoadSnapshotConfig+ swagger)vstate/memory.rsmsync()+ thesharedMAP_PRIVATE→MAP_SHARED flag onsnapshot_file(back to the upstream 3-arg, MAP_PRIVATE signature)vstate/vm.rsmsync dispatch insnapshot_memory_to_filepersist.rsMsyncstate-file skip + the now-vacuousvmstate_only-vs-Msyncguard (vmstate_onlycombines only withFull/Diff, the only remaining types)9 files, 24 insertions / 163 deletions.
Preserved / invariants
snapshot_file(.., shared=false)now uses the reverted 3-arg signature (MAP_PRIVATE — its existing behavior).src/vmm/src/snapshot/and noSNAPSHOT_VERSIONbump — byte-compatible with stock, the invariant the v1 commit itself established.Validation
cargo check -p vmm(lib and tests) foraarch64-unknown-linux-muslis clean. Thefirecrackerbinary crate isn't musl-checkable locally (the upstreamseccompilercrate has nolibc::memfd_createon musl), so the full build + the stock↔fork snapshot-compat test are left to CI / the engramsbuild-firecrackerstep. The api_server/swagger changes are mechanical field-drops matching the validatedvmmstruct change.Once green, the engrams repo bumps its
third_party/firecrackersubmodule to this commit (separate PR).🤖 Generated with Claude Code