- 
                Notifications
    You must be signed in to change notification settings 
- Fork 151
Fixes a race condition in killing Sandboxes #959
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
ad6647c    to
    96a6fce      
    Compare
  
    Signed-off-by: Simon Davies <[email protected]>
96a6fce    to
    d200c7c      
    Compare
  
    Signed-off-by: James Sturtevant <[email protected]>
…sted by us Signed-off-by: James Sturtevant <[email protected]>
| /// retrying until either: | ||
| /// - The signal is successfully delivered (VCPU transitions from running to not running) | ||
| /// - The VCPU stops running for another reason (e.g., call completes normally) | ||
| /// - No call is active (call_active=false) | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Does it block? I thought it would just return false?
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
| // The virtualization stack can use this function to return the control | ||
| // of a virtual processor back to the virtualization stack in case it | ||
| // needs to change the state of a VM or to inject an event into the processor | ||
| debug!("Internal cancellation detected, returning Retry error"); | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: James Sturtevant <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
4e211f2    to
    4de305a      
    Compare
  
    Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
Signed-off-by: Simon Davies <[email protected]>
| /// This is acceptable because the generation tracking provides an additional | ||
| /// safety layer. Even if a stale kill somehow stamped cancel_requested, the | ||
| /// generation mismatch would cause it to be ignored. | ||
| call_active: AtomicBool, | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this flag is redundant. We will already not send any signals when calling kill if the vcpu is not running
Fixes a race condition where a sandbox kill arrives after a sandbox has successfully exited causing the subsequent run to fail.
There is a breaking change in this PR, previously if kill was called on an
InterruptHandlebefore or while a guest call was not in progress the next guest call made on theSandboxwould be cancelled , now this scenario is a no-op. kill only takes effect if there is a guest call running.