Skip to content

Deploy infra in a new project - #1

Merged
ValentaTomas merged 9 commits into
mainfrom
change-project
Sep 7, 2023
Merged

ValentaTomas merged 9 commits into
mainfrom
change-project

Conversation

@ValentaTomas

Copy link
Copy Markdown
Member

No description provided.

@ValentaTomas
ValentaTomas merged commit d46ce47 into main Sep 7, 2023
@ValentaTomas
ValentaTomas deleted the change-project branch September 7, 2023 16:57
7wbjthrmk8-hub referenced this pull request Jan 23, 2026
levb pushed a commit that referenced this pull request Feb 24, 2026
Add sections F (failure modes + unresolved questions) and G (cost/benefit
from staging bucket sample: memfile 4.0x, storage/CPU/memory/net analysis).
Fix orphaned "The runtime stack is:" sentence. Reorder NFS cache TODO to #1.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
ValentaTomas added a commit that referenced this pull request May 2, 2026
…ernel redeliver

Folds audit findings #1 and #7 into one commit since they share the same
error arm in faultPage. The kernel surfaces concurrent mm churn (e.g.
balloon-driven madvise(MADV_DONTNEED), mremap, fork against the same mm)
through UFFDIO_COPY in two distinct ways: as an EAGAIN errno from the
syscall, or — once UFFD_FEATURE_EVENT_REMOVE is enabled — through the
partial-copy convention where the syscall returns 0 and cpy.copy carries
either -EAGAIN or 0..pagesize. Hugetlb pages can also surface a positive
short copy if a fault preempts the operation mid-page (#7).

Pre-#2520 the latter path went through fmt.Errorf("UFFDIO_COPY copied N
bytes...") and fell into the catch-all writeErr != nil arm — which calls
onFailure() / fdExit.SignalExit(), tears the uffd serve loop down, and
crashes the sandbox the moment the guest touches an unmapped page. The
pre-existing errno-EAGAIN soft handler covered only the syscall errno
path.

Move the partial-copy classification into a small helper so both surfaces
collapse onto the existing EAGAIN-returning-(false, nil) branch in
faultPage. No retry budget — matches Firecracker's reference handler in
src/firecracker/examples/uffd/uffd_utils.rs (Err(PartiallyCopied(n)) if
n == 0 || n == -EAGAIN ⇒ return false). Add a uffd.copy_eagain span
attribute for observability.

Tests: unit-test classifyCopyResult directly. faultPage doesn't expose
an Fd seam to mock UFFDIO_COPY without an interface refactor that would
materially expand the diff; per the audit's "smallest pragmatic test"
guidance the classifier covers the new branching and the existing
cross-process matrix tests cover the integration path.
ValentaTomas added a commit that referenced this pull request May 2, 2026
…ed-short-circuit race tests

Three race tests built on the unix-socket RPC harness and the test-only
fault-barrier hooks. None use sleeps, retries, or soak loops - each
test installs explicit barriers on the child's worker goroutine, drives
the racing kernel operation from the parent, and asserts on a concrete
post-state.

  - TestStaleSourceRaceMissingAndRemove: regression test for the
    stale-source bug. Plants a non-zero sentinel into the source page,
    parks the worker via barrierBeforeRLock, fires madvise, waits for
    the REMOVE batch to commit, releases the worker, then asserts the
    page is zero-filled. INTENTIONALLY FAILS on this PR with
    `page 1 first byte: want 0 ... got 0xc3` - the worker captured
    `source = u.src` in the parent loop before the REMOVE landed and
    UFFDIO_COPY'd the planted sentinel into the page after the kernel
    had MADV_DONTNEED'd it. PR #4 (#2512) makes this pass by re-reading
    state inside the worker under settleRequests.RLock.

  - TestNoMadviseDeadlockWithInflightCopy: liveness regression test.
    Parks the worker via barrierBeforeFaultPage (holding RLock), fires
    madvise, asserts madvise returns within 2s. Passes today; protects
    against any future change that accidentally couples readEvents to
    settleRequests.

  - TestFaultedShortCircuitOrdering: smoke test on the REMOVE-then-
    pagefault batch ordering using the gated harness. Pins the
    invariant that REMOVE batches drain before pagefault dispatch in
    a single Serve iteration.

Test infrastructure additions:
  - testHandler.installFaultBarrier / waitFaultHeld / releaseFault
    convenience wrappers around the Service.* RPCs from PR #1.
  - testConfig.sourcePatcher hook so race tests can plant a
    deterministic sentinel into the random source data BEFORE the
    content file is written, without depending on the happenstance
    value of any randomly-generated byte.

ALL OTHER TESTS in the package still pass on this PR; only the three
sub-tests of TestStaleSourceRaceMissingAndRemove fail (the bug
demonstration).
ValentaTomas added a commit that referenced this pull request May 3, 2026
…ed-short-circuit race tests

Three race tests built on the unix-socket RPC harness and the test-only
fault-barrier hooks. None use sleeps, retries, or soak loops - each
test installs explicit barriers on the child's worker goroutine, drives
the racing kernel operation from the parent, and asserts on a concrete
post-state.

  - TestStaleSourceRaceMissingAndRemove: regression test for the
    stale-source bug. Plants a non-zero sentinel into the source page,
    parks the worker via barrierBeforeRLock, fires madvise, waits for
    the REMOVE batch to commit, releases the worker, then asserts the
    page is zero-filled. INTENTIONALLY FAILS on this PR with
    `page 1 first byte: want 0 ... got 0xc3` - the worker captured
    `source = u.src` in the parent loop before the REMOVE landed and
    UFFDIO_COPY'd the planted sentinel into the page after the kernel
    had MADV_DONTNEED'd it. PR #4 (#2512) makes this pass by re-reading
    state inside the worker under settleRequests.RLock.

  - TestNoMadviseDeadlockWithInflightCopy: liveness regression test.
    Parks the worker via barrierBeforeFaultPage (holding RLock), fires
    madvise, asserts madvise returns within 2s. Passes today; protects
    against any future change that accidentally couples readEvents to
    settleRequests.

  - TestFaultedShortCircuitOrdering: smoke test on the REMOVE-then-
    pagefault batch ordering using the gated harness. Pins the
    invariant that REMOVE batches drain before pagefault dispatch in
    a single Serve iteration.

Test infrastructure additions:
  - testHandler.installFaultBarrier / waitFaultHeld / releaseFault
    convenience wrappers around the Service.* RPCs from PR #1.
  - testConfig.sourcePatcher hook so race tests can plant a
    deterministic sentinel into the random source data BEFORE the
    content file is written, without depending on the happenstance
    value of any randomly-generated byte.

ALL OTHER TESTS in the package still pass on this PR; only the three
sub-tests of TestStaleSourceRaceMissingAndRemove fail (the bug
demonstration).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants