[Backport 1.16] fix(vmm): commit virtio-mem block state after the KVM slot update (#6176) - #6184
Merged
ilstam merged 4 commits intoSep 3, 2026
Conversation
In `update_range` function, move kvm slot update before memory discard to prevent a small time window when the guest can re-fault just discarded memory before it is removed from kvm view. (cherry picked from commit 8c4bc5a) [backport: prerequisite for the firecracker-microvm#6176 backport that follows] Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
update_range committed the block state (plugged_blocks, plugged_size) for the whole request up front and only then updated the KVM slots, and update_slot flipped its per-slot bitmap before issuing the KVM ioctl. On a multi-slot request that failed part way through, the committed state covered the whole range while KVM reflected only the slots that had been updated, leaving the device's bookkeeping inconsistent with KVM. Update KVM one slot at a time and commit that slot's block state only after its KVM update succeeds; discard an unplugged slot only once it is committed. A partial failure now stops with the block state and the KVM slots reflecting exactly the slots that were updated, and never discards a block that has not been committed as unplugged. In update_slot, commit the slot bitmap only once both the protection change and the KVM slot update have succeeded, and roll back the first of the two when the second fails, so a failed slot update leaves the slot exactly as it was. A failed rollback would leave the host mapping and KVM out of sync with no way back, so it panics. The whole-range discard is now done per slot as each slot commits. This issues one discard per intersecting slot instead of one for the range, which is not on a hot path. Add a test that plugs a range spanning two KVM slots with the second slot's memory-region update forced to fail, and checks that only the first slot's block is left committed. A test-only fault injector on set_user_memory_region drives the failure. (cherry picked from commit 1e99e52) [backport: depends on the KVM-first ordering from firecracker-microvm#5944, picked as the previous commit; resolved a conflict with 1.16's discard block in update_range, the result matches main] Signed-off-by: Jay Chung <jaehoc@amazon.com>
Record that virtio-mem now commits a slot's block state only after its KVM update succeeds, keeping the device's bookkeeping consistent with KVM when a plug or unplug request fails part way through. (cherry picked from commit 9384f39) Signed-off-by: Jay Chung <jaehoc@amazon.com>
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## firecracker-v1.16 #6184 +/- ##
=====================================================
+ Coverage 83.07% 83.09% +0.02%
=====================================================
Files 277 277
Lines 30228 30285 +57
=====================================================
+ Hits 25111 25165 +54
- Misses 5117 5120 +3
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Manciukic
approved these changes
Sep 3, 2026
ilstam
approved these changes
Sep 3, 2026
ilstam
enabled auto-merge (rebase)
September 3, 2026 13:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Backport #6176 into v1.16
Reason
...
License Acceptance
By submitting this pull request, I confirm that my contribution is made under
the terms of the Apache 2.0 license. For more information on following Developer
Certificate of Origin and signing off your commits, please check
CONTRIBUTING.md.PR Checklist
tools/devtool checkbuild --allto verify that the PR passesbuild checks on all supported architectures.
tools/devtool checkstyleto verify that the PR passes theautomated style checks.
how they are solving the problem in a clear and encompassing way.
in the PR.
CHANGELOG.md.Runbook for Firecracker API changes.
integration tests.
TODO.rust-vmm.