Repository navigation
Conversation
Restoring a snapshot and making one guest function call took about 12 VM exits; on a nested hypervisor each costs several microseconds. Each entry now costs one, the halt that ends it: - An entry returns its Yield as the guest function's result (a Vec<u8>: next wakeup, flags, status, then the call's result) rather than send it with a host call. The first entry after a restore reports a ready driver and a call in flight on that Yield, not with DriverReady and CallStarted host calls. - The resume entry carries the mounts, the clock, the resolver and, when it fits a host call's payload, the environment, which the kernel fetched with GetResumeState and, on the first call, GetEnvVars. - The kernel leaves the SYSCALL MSRs to hyperlight, which restores the ones the host declares. A kernel from before this (given with from_kernel) still works: its entries return nothing, it sends its Yield by host call, and GetResumeState stays for it. A result too short to be a Yield is an error of its own, MalformedYield. Bump the kernel to plat-hyperlight-v2 bd441efa -> fd70ccb9 (the three changes above, and bounds on the FlatBuffer offsets the guest reads), rebuild both kernels and the native test fixture, and bump SNAPSHOT_CONTRACT: every guest function now returns a Vec<u8>. Signed-off-by: danbugs <danilochiarlone@gmail.com>
There was a problem hiding this comment.
🟡 Changes recommended
The embedded kernels lack the new ABI, while legacy resume entries are called with an incompatible argument.
2 open findings
What changed in this PR
Optimizes restore and guest-call VM exits while testing a resident-scratch Hyperlight fork.
Changes:
- Returns
Yielddata through entry results and carries resume state directly. - Adds restore/environment tests and updates protocol documentation.
- Pins experimental Hyperlight dependencies and bumps snapshot compatibility.
| File | Description |
|---|---|
src/lib.rs |
Implements the new entry and resume protocol. |
tests/python.rs |
Tests environment restoration paths. |
docs/profiling.md |
Updates profiling examples. |
docs/fs.md |
Documents restored mount handling. |
docs/execution.md |
Documents entry results and resume state. |
docs/driver.md |
Updates driver restore behavior. |
docs/clock.md |
Updates restored clock behavior. |
CHANGELOG.md |
Records the protocol optimization. |
Cargo.toml |
Patches Hyperlight to an experimental fork. |
Cargo.lock |
Locks the fork revision. |
build.rs |
Bumps the snapshot contract. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
| fits.then(|| (self.config.env_version(), env.as_str())), | ||
| ); | ||
| drop((resolv, env)); | ||
| let yielded = self.config.enter(&mut self.sandbox, "resume", (state,))?; |
|
|
||
| ### Changed | ||
|
|
||
| - Restoring a snapshot and making one guest function call takes two VM exits on x86_64, the halts that end its two entries, where it took about 12 (arm64 adds one: its kernel reseeds its CSPRNG from the host). An entry returns its `Yield` as the guest function's result. The `resume` entry carries the mounts, clock and resolver, and the environment when it fits a host call (a larger one is fetched by the first call). The kernel leaves the SYSCALL MSRs to hyperlight, which restores them. A kernel built before this, given with `from_kernel`, still works, sending its `Yield` and fetching its state by host call. A kernel built from these sources needs this `hluk` or later. |
danbugs
force-pushed
the
restore-perf
branch
2 times, most recently
from
October 9, 2026 00:27
f62ccee to
82c468b
Compare
Patch hyperlight-host and hyperlight-common to danbugs/hyperlight c854bb43 (0.17.0 plus the scratch reset of hyperlight-dev/hyperlight#1901), to measure it in CI. Signed-off-by: danbugs <danilochiarlone@gmail.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


No description provided.