Repository navigation
hardware: report per-runtime CPU attributes at worker registration - #2345
Draft
shrutiyam-glitch wants to merge 1 commit into
Draft
shrutiyam-glitch wants to merge 1 commit into
shrutiyam-glitch wants to merge 1 commit into
Conversation
Workers registered only architecture, which is not enough to tell whether a snapshot's memory image will restore on a candidate worker. Each ateom now probes /proc/cpuinfo at registration and reports the attributes its runtime's restore path depends on: - ateom-gvisor: architecture and cpu_features, an FNV-1a hash of the sorted host flags. gVisor restores only when the checkpoint's feature set is a subset of the host's, so equal hashes guarantee that check passes. The host flags are hashed rather than runsc cpu-features because runsc is a per-SandboxConfig asset not present at registration. - ateom-microvm: architecture, cpu_vendor and cpu_model. Cloud Hypervisor has no compatibility gate of its own, so vendor and model are the coarse guard against cross-CPU restores. Attributes are declared once in the hardware package; hardware.Profile names the subset each runtime reports and hardware.Probe builds the identity, omitting any key it cannot read. ateom.Report takes the identity from its caller and requires one.
2 tasks
Davanum Srinivas (dims)
pushed a commit
to dims/substrate
that referenced
this pull request
Oct 9, 2026
…e#2381) Fixes agent-substrate#2348 Restoring a sandboxed actor from a checkpointed snapshot requires strict compatibility between the worker that created the snapshot and the worker restoring it — across the sandbox class (`gvisor`, `microvm`), the host hardware (`architecture`, `cpu_features`), and the sandbox runtime assets (`gvisor_asset_hash`, microVM kernel/rootfs digests). - **Unified compatibility identity (`SandboxRuntime` & `VersionedSandboxCompat`)**: Combines `sandbox_class`, an informational version `name`, and a `compat_version` (`schema_version` + `repeated AttributeEntry attributes`) into a single self-contained message. When an actor is checkpointed, the control plane can copy the worker's `default_runtime` directly onto the snapshot, and during warm restore the scheduler can match the snapshot's `SandboxRuntime` against candidate workers without inspecting runtime-specific fields. - **Zero-downtime runtime rollouts (`default_runtime` vs. `restorable_runtimes`)**: Workers report both a `default_runtime` (used for cold starts and new checkpoints) and `restorable_runtimes` (other enabled runtime versions on the worker that can still warm-restore existing snapshots while a new default version rolls out). - **Schema-versioned key-value attributes (`schema_version` + `AttributeEntry`)**: `compat_version.schema_version` (`"v1"`) versions the compatibility attribute schema itself, while `attributes` uses a list-map of `AttributeEntry` (`+k8s:listType=map`, `+k8s:listMapKey=key`) so declarative validation enforces required keys, values, and length bounds on every entry. #### Scope of This PR vs. Follow-ups - **In this PR**: Establishes the `SandboxRuntime` / `VersionedSandboxCompat` proto schema and declarative validation, updates `internal/hardware` (`ProbeHost` and `Matches`), and wires end-to-end registration of `default_runtime` (with `sandbox_class` and host architecture) and `restorable_runtimes` through `ateom`, `atelet`, `ate-api-server`, and `fake-workersync`. - **Follow-ups**: - Enrich `default_runtime` (`name`, `gvisor_asset_hash`) and `restorable_runtimes` from `SandboxConfig` once `SandboxConfig` moves to `WorkerPool`. - Probe CPU feature attributes (`cpu_features`) in `hardware.ProbeHost()` (agent-substrate#2345 - WIP) - Stamp `worker.status.default_runtime` onto snapshots at pause/checkpoint time and filter candidate workers with `hardware.Matches` during warm-restore scheduling. - [ ] Tests pass - [ ] Appropriate changes to documentation are included in the PR
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #2246
Workers registered only architecture, which is not enough to tell whether a snapshot's memory image will restore on a candidate worker. Each ateom now probes
/proc/cpuinfoat registration and reports the attributes its runtime's restore path depends on:ateom-gvisor:architectureandcpu_features, an FNV-1a hash of the sorted host flags. gVisor restores only when the checkpoint's feature set is a subset of the host's, so equal hashes guarantee that check passes. The host flags are hashed rather thanrunsc cpu-featuresbecauserunscis a per-SandboxConfig asset not present at registration.ateom-microvm:architecture,cpu_vendorandcpu_model. Cloud Hypervisor has no compatibility gate of its own, so vendor and model are the coarse guard against cross-CPU restores. Attributes are declared once in the hardware package;hardware.Profilenames the subset each runtime reports andhardware.Probebuilds the identity, omitting any key it cannot read. ateom.Report takes the identity from its caller and requires one.Tests pass
Appropriate changes to documentation are included in the PR