Skip to content

fix: keep Go ADK SQLite connections out of VM snapshots - #3004

Merged
EItanya merged 8 commits into
mainfrom
fix/go-adk-sqlite-restore
Sep 30, 2026
Merged

EItanya merged 8 commits into
mainfrom
fix/go-adk-sqlite-restore

Conversation

@EItanya

@EItanya EItanya commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Cloud Hypervisor restores guest memory over new backing files for /data. The Go ADK retained idle SQLite connections from the golden snapshot, so the first message failed with SQLITE_READONLY_DBMOVED (1032).

Set the SQLite pool's idle connection count to zero so startup still validates and migrates the database, while quiescent snapshots contain no open database handles. Regression tests cover first-message creation, existing conversation history, and subsequent restores.

Run E2E tests on Cloud Hypervisor alongside gVisor, checking KVM_CREATE_VM before building images. Both lanes use Substrate v0.3.0-alpha3, which includes RNG reseeding and the clock/sysctl fixes. Keep the Kind wrapper because the released installer still resolves a removed temporary executable on a cold Go cache.

Update the Go client, local setup script, and vendored protobuf/UI schema together to alpha3, and compile its protocol-specific egress rules from each endpoint's scheme, hostname, and port. Each allowed destination has one deciding rule with its credential replacements. Alpha3 no longer supports IP allowlists, so endpoints must use DNS names; the host-based tracing fixture now has a Kubernetes Service and EndpointSlice. The vendored upstream alpha schema is excluded from kagent's compatibility check; its changed egress types are not exposed by kagent.

Validation: focused local Cloud Hypervisor v53 tests against the published alpha3 images passed first messages and credential delivery across kagent, Codex, Claude, and BYO, plus Claude/Codex trace export. Compiler, egress, session workflow, and controller tests, all-package compilation, Go lint, actionlint, protobuf generation/compatibility, UI type checking, ShellCheck error checks, and Bash syntax checks passed. Ran the full local microVM suite, then fixed first-page assumptions in the three CLI/MCP listing scenarios and reran them against the same populated cluster. Across those runs: 185 leaf cases passed, 10 existing skips, no remaining failures.

Removed the earlier scheduled-run clock workaround now that the runtime clock fix is included. Rebuilt and deployed the controller locally, then reran TestScheduledRunTimeout on Cloud Hypervisor with alpha3: kagent, Codex, Claude, and BYO ADK all passed without the workaround. Scheduled-run controller unit tests and lint also passed.

Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@github-actions github-actions Bot added the bug Something isn't working label Sep 29, 2026
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@blacksmith-sh

This comment has been minimized.

Classify deadline-triggered cancellation as a timeout despite guest clock skew, while preserving raced completion and failure outcomes. Include task errors in restore assertions and invoke Kind by name so version-manager shims work during local microVM setup.

Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Sep 29, 2026
@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Sep 29, 2026
Comment thread .github/workflows/ci.yaml
echo "key=${BRANCH_KEY}" >> $GITHUB_OUTPUT
echo "::notice title=Cache Key::Branch: ${BRANCH_KEY}"
test-e2e:
strategy:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ruleset still requires test-e2e, which this matrix renames away

Comment thread .github/workflows/ci.yaml
strategy:
fail-fast: false
matrix:
sandbox_class: [gvisor, microvm]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

microvm leg stays red until a substrate release ships?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, working on it now

@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Sep 29, 2026
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Sep 29, 2026
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@EItanya
EItanya requested a review from peterj as a code owner September 30, 2026 07:10
@github-actions github-actions Bot added bug Something isn't working and removed bug Something isn't working labels Sep 30, 2026
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
@github-actions github-actions Bot removed the bug Something isn't working label Sep 30, 2026
@github-actions github-actions Bot added the bug Something isn't working label Sep 30, 2026
@EItanya
EItanya merged commit 936ee56 into main Sep 30, 2026
32 checks passed
@EItanya
EItanya deleted the fix/go-adk-sqlite-restore branch September 30, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants