feat(snapshot): configure filesystem state limits - #1751
0xpolarzero wants to merge 16 commits into
Conversation
Closure admission capped every device state at 1 MiB, while restore already accepted 8 MiB for virtio-fs. A full checkpoint of a sandbox with enough retained host-directory inodes was therefore rejected when created, verified, exported or restored. DeviceStateRef::max_state_bytes is now the single limit.
Export and import a full checkpoint whose virtio-fs device state is 2 MiB, and assert the imported object bytes match. The resolver test now checks the size limit error for oversized states. COMPATIBILITY.md records the per-device limits and that v0.7.0 through v0.7.6 readers reject larger virtio-fs objects.
|
we could actually make all of this configurable through one global setting, something like: {
"snapshots": {
"max_filesystem_state_mib": 64
}
}this would set the backend state budget per virtio-fs device, with the enclosing device limits derived from it to allow for headers and transport state. the default could stay at the current 4 MiB backend limit. we’d need to carry that setting through capture, verification, export/import, restore, and live forks, including the limits in |
Alright! Marking draft again and making a PR in libkrun to implement this, so I can get back to this one once it's merged and released. |
|
@toksdotdev PR is ready right there superradcompany/libkrun#151 :) |
Add snapshots.max_filesystem_state_mib (default 4, 4..=4095) and carry it through the launch contract, runner, capture, verification, export/import, restore, and the filesystem backends in place of the fixed 8 MiB admission.
e81c429 to
37480c9
Compare
|
@0xpolarzero didn't intend to push. i've undone the commits. feel free to make the global config changes. 🫡 |
…ackend Filesystem backends take their state budget from their own configuration instead of a process-wide setting, and device-state admission comes from the libkrun state codec. The configurable budget range is 1 through 4095 MiB.
…te-limit # Conflicts: # sdk/rust/lib/backend/local/snapshot/archive/delta.rs
… budget Closure admission compared the whole device-state object with the budget plus the full envelope allowance, so a backend state up to about 1 MiB over the budget was admitted by verification, export and import and then refused at restore. Admission and restore now decode virtio-fs states and compare the backend state with the budget, naming snapshots.max_filesystem_state_mib.
|
need to cut a new libkrun version. after which i'll merge this 🫡 |
…te-limit # Conflicts: # crates/filesystem/lib/backends/passthroughfs/windows/mobility.rs
…te-limit # Conflicts: # Cargo.toml
Full snapshots fail once a sandbox's virtio-fs state outgrows its fixed limit. That happens after the guest reads a few thousand files from a host-directory mount (#1750). This PR adds one setting for that budget and carries it everywhere a snapshot is captured or read:
{ "snapshots": { "max_filesystem_state_mib": 64 } }The default stays 4 MiB, the current backend limit. The enclosing device-state limits come from msb_krun's
DeviceStateLimits/DeviceStateCodec(superradcompany/libkrun#151).msb_krun is pinned to the merged libkrun #151 revision until that API is released. The pin must be replaced with the registry version before release.
What changed
snapshots.max_filesystem_state_mibsetting (1–4095), validated with the other config layers.snapshots.max_filesystem_state_mib.docs/configuration.mdxandCOMPATIBILITY.md.How it was tested
cargo testfor the image, runtime, filesystem, cli and sdk crates,cargo fmt --check, and clippy as in CI.… filesystem state exceeds the 4 MiB budget; raise snapshots.max_filesystem_state_mib …, and the sandbox keeps running.No new blocking issue was identified; the PR appears safe to merge on the reviewed code.
What we checked:
Reviews (13) · Last reviewed commit: "Merge remote-tracking branch 'origin/mai..."