Conversation
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Superseded by #51, which backports upstream RNG reseeding (agent-substrate#1524) and
kvm-clockselection (agent-substrate#1945). The replacement passed the full local kagent microVM suite on Cloud Hypervisor v53 (185 leaf cases passed, 10 existing skips), microVM race tests, and fullmake verify. Closing this custom implementation in favor of those upstream changes.Cloud Hypervisor restores preserve the guest's RNG state and can leave its wall clock behind the host. While testing kagent checkpoint forks, we reproduced duplicate SQLite event UUIDs and deadline cancellations reported as failures because the guest timestamp was several seconds behind.
This calls Kata's
ReseedRandomDevwith fresh host entropy andSetGuestDateTimeafter VM resume, before wakeup probes and actor network activation. Restore fails if either call fails. The same Kata connection stays open for logs and stats.The restore workflow owns entropy generation and call ordering;
AgentClientwraps the individual Kata RPCs. Added ttrpc tests for request encoding, timestamp conversion, and propagation of either RPC failure.go test ./cmd/ateom-microvm/...and the root-required microVM network tests pass. Checkpoint/fork and timeout E2E tests passed three consecutive runs across all four kagent harnesses (24 cases). The final worker is installed in the local Cloud Hypervisor Kind cluster and the full kagent microVM suite is running. The firstmake verifyattempt exhausted temporary disk space during linking; a retry with serialized package builds is running. Keeping this draft until that validation completes.Related: kagent-dev/kagent#3004
Upstream agent-substrate#1945 selects
clocksource=kvm-clockfor amd64 guests. Cloud Hypervisor 53 already advances that clock on restore, so this may replace theSetGuestDateTimeportion after validation in the kagent environment. RNG reseeding is separate and remains needed. The local validation described above uses this PR's explicit clock RPC, not the upstream clocksource change.