Skip to content

feat(uffd): MAP_PRIVATE base-file backing + MISSING|MINOR registration (substrate v2b) - #4

Merged
nikhilunni merged 1 commit into
engram/live-migrationfrom
engram/substrate-v2
Jun 9, 2026
Merged

nikhilunni merged 1 commit into
engram/live-migrationfrom
engram/substrate-v2

Conversation

@nikhilunni

Copy link
Copy Markdown
Contributor

Summary

The engrams ADR 0045 unified-memory-substrate (v2b) fork surface — D1 of the substrate program. Clean-room (kernel primitives + the engrams spec; never any AGPL fork).

A new optional top-level load param uffd_base_file: when set with the Uffd memory backend, guest memory is created as MAP_PRIVATE of this shmem file (reusing the existing snapshot_file region builder with shared=false) instead of anonymous, and UFFD registration becomes MISSING|MINOR (userfaultfd crate feature linux5_13). The external handler then resolves:

  • base-identical pages → UFFDIO_CONTINUE: one page-cache copy shared by every same-template microVM on the host (the density mechanism, now available to restores)
  • session-divergent pages → UFFDIO_COPY: private
  • guest writes → kernel-native COW; the base file is never written through the mapping

Invariants held

  • Inert/opt-in: field unset ⇒ every path byte-identical to stock (the registration mode ternary is the only touched line on the default path).
  • Never touches src/vmm/src/snapshot/; SNAPSHOT_VERSION stays 10.0.0 (R2 byte-compat preserved).
  • Invalid with the File backend (loud error); rejected for hugetlbfs (MINOR is shmem-only here). Kernel floor ≥5.13.

Validation

  • Unit test (test_create_guest_memory_with_base_file): read-through from the base, COW privacy (write never reaches the file), mapping offsets, hugetlbfs rejection — green on engram-dev (kernel 6.8).
  • Pre-existing TAP-EPERM test failures confirmed identical on the base commit (environmental, unprivileged TAP creation).
  • Static musl release build green.
  • Kernel-level behaviors (cross-process CONTINUE on MAP_PRIVATE shm, COPY privacy, KVM-under-memslot, dirty-log) are gated by the engrams-side substrate_kernel_capabilities suite (engrams #163).

Consumed by the engrams D2 PR (client field + handler CONTINUE arm + base-shm provisioning); the submodule bump there runs the build-firecracker job + R2 diff-guard end-to-end.

🤖 Generated with Claude Code

The engrams ADR 0045 unified-memory-substrate (v2b) surface. Clean-room,
derived from kernel primitives + the engrams spec, NOT from any
AGPL-licensed fork. Inert/opt-in: without the new field every path is
byte-identical to stock; never touches src/vmm/src/snapshot/ and never
changes SNAPSHOT_VERSION (10.0.0).

A new optional top-level load param `uffd_base_file`: when set with the
Uffd memory backend, guest memory is created as MAP_PRIVATE of this
shmem file (reusing the snapshot_file region builder, shared=false)
instead of anonymous, and the UFFD registration uses MISSING|MINOR
(userfaultfd crate feature linux5_13). The external handler then
resolves base-identical pages with UFFDIO_CONTINUE — one page-cache
copy shared by every same-template microVM on the host — and
session-divergent pages with UFFDIO_COPY; guest writes COW natively to
private anon pages, so the shared base file is never written through
the mapping. Invalid with the File backend; rejected for hugetlbfs
(minor faults are shmem-only here). Requires kernel >= 5.13.

Unit test covers read-through, COW privacy, mapping offsets, and the
hugetlbfs rejection; the engrams-side substrate_kernel_capabilities
suite gates the kernel behaviors themselves.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@nikhilunni
nikhilunni merged commit 4a9636d into engram/live-migration Jun 9, 2026
3 checks passed
@nikhilunni
nikhilunni deleted the engram/substrate-v2 branch June 9, 2026 23:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant