Skip to content

[Backport 1.16] fix(vmm): commit virtio-mem block state after the KVM slot update (#6176) - #6184

Merged
ilstam merged 4 commits into
firecracker-microvm:firecracker-v1.16from
not4s:fix/virtio-mem-kvm-first-v1.16
Sep 3, 2026
Merged

[Backport 1.16] fix(vmm): commit virtio-mem block state after the KVM slot update (#6176)#6184
ilstam merged 4 commits into
firecracker-microvm:firecracker-v1.16from
not4s:fix/virtio-mem-kvm-first-v1.16

Conversation

@not4s

@not4s not4s commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Changes

Backport #6176 into v1.16

Reason

...

License Acceptance

By submitting this pull request, I confirm that my contribution is made under
the terms of the Apache 2.0 license. For more information on following Developer
Certificate of Origin and signing off your commits, please check
CONTRIBUTING.md.

PR Checklist

  • I have read and understand CONTRIBUTING.md.
  • I have run tools/devtool checkbuild --all to verify that the PR passes
    build checks on all supported architectures.
  • I have run tools/devtool checkstyle to verify that the PR passes the
    automated style checks.
  • I have described what is done in these changes, why they are needed, and
    how they are solving the problem in a clear and encompassing way.
  • I have updated any relevant documentation (both in code and in the docs)
    in the PR.
  • I have mentioned all user-facing changes in CHANGELOG.md.
  • If a specific issue led to this PR, this PR closes the issue.
  • When making API changes, I have followed the
    Runbook for Firecracker API changes.
  • I have tested all new and changed functionalities in unit tests and/or
    integration tests.
  • I have linked an issue to every new TODO.

  • This functionality cannot be added in rust-vmm.

ShadowCurse and others added 3 commits September 2, 2026 15:56
In `update_range` function, move kvm slot update before memory discard
to prevent a small time window when the guest can re-fault just
discarded memory before it is removed from kvm view.

(cherry picked from commit 8c4bc5a)
[backport: prerequisite for the firecracker-microvm#6176 backport that follows]
Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
update_range committed the block state (plugged_blocks, plugged_size)
for the whole request up front and only then updated the KVM slots, and
update_slot flipped its per-slot bitmap before issuing the KVM ioctl. On
a multi-slot request that failed part way through, the committed state
covered the whole range while KVM reflected only the slots that had been
updated, leaving the device's bookkeeping inconsistent with KVM.

Update KVM one slot at a time and commit that slot's block state only
after its KVM update succeeds; discard an unplugged slot only once it
is committed. A partial failure now stops with the block state and the
KVM slots reflecting exactly the slots that were updated, and never
discards a block that has not been committed as unplugged.

In update_slot, commit the slot bitmap only once both the protection
change and the KVM slot update have succeeded, and roll back the first
of the two when the second fails, so a failed slot update leaves the
slot exactly as it was. A failed rollback would leave the host mapping
and KVM out of sync with no way back, so it panics.

The whole-range discard is now done per slot as each slot commits. This
issues one discard per intersecting slot instead of one for the range,
which is not on a hot path.

Add a test that plugs a range spanning two KVM slots with the second
slot's memory-region update forced to fail, and checks that only the
first slot's block is left committed. A test-only fault injector on
set_user_memory_region drives the failure.

(cherry picked from commit 1e99e52)
[backport: depends on the KVM-first ordering from firecracker-microvm#5944, picked as the
previous commit; resolved a conflict with 1.16's discard block in
update_range, the result matches main]
Signed-off-by: Jay Chung <jaehoc@amazon.com>
Record that virtio-mem now commits a slot's block state only after its
KVM update succeeds, keeping the device's bookkeeping consistent with
KVM when a plug or unplug request fails part way through.

(cherry picked from commit 9384f39)
Signed-off-by: Jay Chung <jaehoc@amazon.com>
@codecov

codecov Bot commented Sep 2, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 93.75000% with 6 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.09%. Comparing base (12006e8) to head (c4d056d).

Files with missing lines Patch % Lines
src/vmm/src/devices/virtio/mem/device.rs 95.08% 3 Missing ⚠️
src/vmm/src/vstate/memory.rs 84.21% 3 Missing ⚠️
Additional details and impacted files
@@                  Coverage Diff                  @@
##           firecracker-v1.16    #6184      +/-   ##
=====================================================
+ Coverage              83.07%   83.09%   +0.02%     
=====================================================
  Files                    277      277              
  Lines                  30228    30285      +57     
=====================================================
+ Hits                   25111    25165      +54     
- Misses                  5117     5120       +3     
Flag Coverage Δ
5.10-m5n.metal 83.34% <93.75%> (+0.02%) ⬆️
5.10-m6a.metal 82.69% <93.75%> (+0.02%) ⬆️
5.10-m6g.metal 79.97% <93.75%> (+0.03%) ⬆️
5.10-m6i.metal 83.34% <93.75%> (+0.01%) ⬆️
5.10-m7a.metal-48xl 82.68% <93.75%> (+0.02%) ⬆️
5.10-m7g.metal 79.97% <93.75%> (+0.03%) ⬆️
5.10-m7i.metal-24xl 83.31% <93.75%> (+0.02%) ⬆️
5.10-m7i.metal-48xl 83.32% <93.75%> (+0.02%) ⬆️
5.10-m8g.metal-24xl 79.97% <93.75%> (+0.03%) ⬆️
5.10-m8g.metal-48xl 79.97% <93.75%> (+0.03%) ⬆️
5.10-m8i.metal-48xl 83.32% <93.75%> (+0.02%) ⬆️
5.10-m8i.metal-96xl 83.32% <93.75%> (+0.02%) ⬆️
6.1-m5n.metal 83.37% <93.75%> (+0.02%) ⬆️
6.1-m6a.metal 82.72% <93.75%> (+0.02%) ⬆️
6.1-m6g.metal 79.96% <93.75%> (+0.02%) ⬆️
6.1-m6i.metal 83.37% <93.75%> (+0.02%) ⬆️
6.1-m7a.metal-48xl 82.71% <93.75%> (+0.02%) ⬆️
6.1-m7g.metal 79.96% <93.75%> (+0.02%) ⬆️
6.1-m7i.metal-24xl 83.38% <93.75%> (+0.02%) ⬆️
6.1-m7i.metal-48xl 83.38% <93.75%> (+0.02%) ⬆️
6.1-m8g.metal-24xl 79.96% <93.75%> (+0.02%) ⬆️
6.1-m8g.metal-48xl 79.96% <93.75%> (+0.02%) ⬆️
6.1-m8i.metal-48xl 83.38% <93.75%> (+0.02%) ⬆️
6.1-m8i.metal-96xl 83.38% <93.75%> (+0.02%) ⬆️
6.18-m5n.metal 83.36% <93.75%> (+0.01%) ⬆️
6.18-m6a.metal 82.71% <93.75%> (+0.02%) ⬆️
6.18-m6g.metal 80.05% <93.75%> (+0.03%) ⬆️
6.18-m6i.metal 83.36% <93.75%> (+0.02%) ⬆️
6.18-m7a.metal-48xl 82.71% <93.75%> (+0.02%) ⬆️
6.18-m7g.metal 80.05% <93.75%> (+0.02%) ⬆️
6.18-m7i.metal-24xl 83.38% <93.75%> (+0.02%) ⬆️
6.18-m7i.metal-48xl 83.38% <93.75%> (+0.01%) ⬆️
6.18-m8g.metal-24xl 80.05% <93.75%> (+0.02%) ⬆️
6.18-m8g.metal-48xl 80.05% <93.75%> (+0.02%) ⬆️
6.18-m8i.metal-48xl 83.38% <93.75%> (+0.01%) ⬆️
6.18-m8i.metal-96xl 83.38% <93.75%> (+0.02%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@not4s not4s changed the title [Backport 1.16] virtio-mem block state consistency on partial failure (#6176) [Backport 1.16] fix(vmm): commit virtio-mem block state after the KVM slot update (#6176) Sep 2, 2026
@ilstam
ilstam enabled auto-merge (rebase) September 3, 2026 13:06
@ilstam
ilstam merged commit b3fcca9 into firecracker-microvm:firecracker-v1.16 Sep 3, 2026
7 checks passed
@not4s
not4s deleted the fix/virtio-mem-kvm-first-v1.16 branch September 3, 2026 14:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants