Skip to content

SHARD-213: drive Virtualization.framework through a per-VM shim the daemon re-adopts by socket - #177

Merged
presmihaylov merged 3 commits into
mainfrom
shard-213-vz-driver
Sep 19, 2026
Merged

presmihaylov merged 3 commits into
mainfrom
shard-213-vz-driver

Conversation

@presmihaylov

@presmihaylov presmihaylov commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

SHARD-213. Fourth of the M10 stack, stacked on #176.

Why. M10 needs a Virtualization.framework driver that survives a daemon restart and stays under the framework's two-VMs-per-process ceiling.

How.

  • Look first at cmd/shard-vz-shim/main.go and pkg/vz/server.go: one detached shim per VM, one length-prefixed JSON request per unix connection; connect splices a vsock stream onto it.
  • pkg/vz/client.go keeps no connection between verbs, so re-adopting a VM is only dialing its socket.
  • machine_darwin.go follows hypeman's device assembly (NOTICE). Save and restore are darwin arm64 only; elsewhere ErrUnsupported.
  • Zero cpus keeps the framework default; zero memory is shard's 512 MiB DefaultMemory, not the 4 MiB floor. Out of range is refused, never clamped.
  • The restore test skips while the login session is locked: a locked screen withholds the Secure Enclave key (Code=12, permission denied, spike item 9).

What. pkg/vz, cmd/shard-vz-shim, make build-shard-vz-shim. Darwin tests passed on nairiclaw.

Comment thread pkg/vz/machine_darwin.go Outdated
Comment thread pkg/vz/machine_darwin.go
Comment thread cmd/shard-vz-shim/main.go Outdated
Comment thread pkg/vz/client.go Outdated
Comment thread pkg/vz/server.go
Comment thread Makefile
Comment thread pkg/vz/server.go
Comment thread pkg/vz/vz.go Outdated
…aemon re-adopts by socket

pkg/vz is the thin driver: a Config, the bounds and host probes on every platform, and the
darwin VM assembly behind a build tag. cmd/shard-vz-shim holds one VM and answers the verbs
over a length-prefixed unix socket, so a daemon restart re-adopts a running VM instead of
losing it, and the framework's two-VMs-per-process ceiling never binds.

The darwin tests boot a fixture PID 1 from the shard kernel, prove it answers over vsock,
save and restore under the same identifier, and re-adopt a VM whose starter was killed.
The restore test skips when the login session is locked: the helper unwraps the saved
state with a Secure Enclave key that a locked screen withholds (Code=12, permission denied).
…s, a claimed socket, and bounded socket calls

- A zero memory request boots on 512 MiB, as the docs promise, not the framework's 4 MiB minimum.
- The VM retains every *os.File behind a device and closes them after the VM ends, so a collection in the shim cannot close a live descriptor.
- The shim claims its socket before the boot: a live owner is refused, and Start refuses an answer from a pid it did not start.
- Every client call is bounded, dial to reply, and a connect stream clears the deadline once the handshake is in.
- Serve bounds the handshake and closes the connections still in it when the listener closes.
…every handshake, and say what a zero memory means

The guest fixture now writes to /dev/hvc0: on macOS 26 a write to /dev/console never reaches the host console file, and the GC regression read it.
@presmihaylov
presmihaylov changed the base branch from shard-232-guest-kernel to main September 19, 2026 18:17
@presmihaylov
presmihaylov merged commit e585c69 into main Sep 19, 2026
3 checks passed
@presmihaylov
presmihaylov deleted the shard-213-vz-driver branch September 24, 2026 05:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant