Skip to content

fix: refresh guest entropy and clock after microVM restore - #50

Closed
EItanya wants to merge 2 commits into
mainfrom
fix/microvm-restore-state
Closed

EItanya wants to merge 2 commits into
mainfrom
fix/microvm-restore-state

Conversation

@EItanya

@EItanya EItanya commented Sep 29, 2026 •

Copy link
Copy Markdown

Superseded by #51, which backports upstream RNG reseeding (agent-substrate#1524) and kvm-clock selection (agent-substrate#1945). The replacement passed the full local kagent microVM suite on Cloud Hypervisor v53 (185 leaf cases passed, 10 existing skips), microVM race tests, and full make verify. Closing this custom implementation in favor of those upstream changes.


Cloud Hypervisor restores preserve the guest's RNG state and can leave its wall clock behind the host. While testing kagent checkpoint forks, we reproduced duplicate SQLite event UUIDs and deadline cancellations reported as failures because the guest timestamp was several seconds behind.

This calls Kata's ReseedRandomDev with fresh host entropy and SetGuestDateTime after VM resume, before wakeup probes and actor network activation. Restore fails if either call fails. The same Kata connection stays open for logs and stats.

The restore workflow owns entropy generation and call ordering; AgentClient wraps the individual Kata RPCs. Added ttrpc tests for request encoding, timestamp conversion, and propagation of either RPC failure. go test ./cmd/ateom-microvm/... and the root-required microVM network tests pass. Checkpoint/fork and timeout E2E tests passed three consecutive runs across all four kagent harnesses (24 cases). The final worker is installed in the local Cloud Hypervisor Kind cluster and the full kagent microVM suite is running. The first make verify attempt exhausted temporary disk space during linking; a retry with serialized package builds is running. Keeping this draft until that validation completes.

Related: kagent-dev/kagent#3004

Upstream agent-substrate#1945 selects clocksource=kvm-clock for amd64 guests. Cloud Hypervisor 53 already advances that clock on restore, so this may replace the SetGuestDateTime portion after validation in the kagent environment. RNG reseeding is separate and remains needed. The local validation described above uses this PR's explicit clock RPC, not the upstream clocksource change.

  • Tests pass (focused tests pass; broader validation in progress)
  • Appropriate changes to documentation are included in the PR

Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant