fix: stabilize microVM clocks and concurrent actor startup - #51
Merged
Merged
Conversation
This was referenced Sep 29, 2026
EItanya
force-pushed
the
fix/microvm-upstream-restore
branch
from
September 29, 2026 21:56
ebc7c1b to
4feb48b
Compare
EItanya
marked this pull request as ready for review
September 29, 2026 21:58
Actor setup changes network namespaces while retaining a shared mount namespace. Serialize writes and temporary remounts so one setup cannot restore /proc/sys to read-only while another is still writing. Exercise concurrent writes in isolated mount and network namespaces. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
EItanya
added a commit
that referenced
this pull request
Sep 30, 2026
* Select kvm-clock for amd64 micro-VM guests (cherry picked from commit e63120e) Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io> (cherry picked from commit b510de0) Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io> * fix: serialize sysctl writes across network namespaces Actor setup changes network namespaces while retaining a shared mount namespace. Serialize writes and temporary remounts so one setup cannot restore /proc/sys to read-only while another is still writing. Exercise concurrent writes in isolated mount and network namespaces. Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io> --------- Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io> Co-authored-by: Adhita Selvaraj <adhita.selvaraj@gmail.com> Signed-off-by: Eitan Yarmush <eitan.yarmush@solo.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cloud Hypervisor v53 corrects the guest's
kvm-clockacross restore, but our amd64 guests selectedtscand resumed 3–14 seconds behind the host. Backport agent-substrate#1945 to selectclocksource=kvm-clockfor amd64 guests. ARM64 keeps its existing clock configuration; v53 handles its clock correction through cloud-hypervisor/cloud-hypervisor#8343. Existing amd64 golden snapshots must be recreated to adopt the boot argument.The RNG fix from agent-substrate#1524, including mandatory reseeding and reuse of one Kata connection, is already in this fork's
main.Also fix the shared sysctl race exposed by this PR's gVisor E2E run. Concurrent actor starts use different network namespaces but share the
/proc/sysmount. One call can remount it read-only while another is writing, causing actor startup to fail withEROFS; overlapping writes can also prevent the read-only remount. Serialize the entire write/remount sequence. The regression uses real network namespaces and a private mount namespace so it leaves the host untouched.Validation:
make verifypassed.kvm-clockstayed within about 0.21 seconds. These runs used the previous fork base; they have not been rerun on the newly synced base.Related: kagent-dev/kagent#3004. CI still needs a Substrate release containing the fixes.