Skip to content

fw(uno): Live migration support for mbor commands - #788

Draft
Wenbo Yuan (wenbo-yuan) wants to merge 1 commit into
mainfrom
wenboy/lm
Draft

Wenbo Yuan (wenbo-yuan) wants to merge 1 commit into
mainfrom
wenboy/lm

Conversation

@wenbo-yuan

Copy link
Copy Markdown
Contributor

Adds Live Migration (LM) support to the uno MBOR path so a partition's session and key state survives a save → restore migration cycle.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The SQ drain misses queued IIC work, malformed IPC can receive success, and existing partition-store tests no longer build or pass.

4 open findings
What changed in this PR

Adds Uno MBOR live-migration support so partition identity, sessions, and key state can survive save/restore cycles.

Changes:

  • Adds submission-queue management and migration draining.
  • Preserves VM GUID, BK3, and session state across migration.
  • Adds failed session-open/reopen rollback handling.
File Description
fw/​plat/​uno/​fw/​pal/​src/​session.rs Handles migrated and pending session cleanup.
fw/​plat/​uno/​fw/​pal/​src/​part.rs Preserves partition migration state.
fw/​plat/​uno/​fw/​pal/​src/​pal.rs Adds SQ IPC handling and drain accounting.
fw/​plat/​uno/​fw/​pal/​src/​ipc.rs Defines Create/Delete SQ wire messages.
fw/​plat/​uno/​fw/​pal/​src/​io.rs Tracks in-flight queue requests.
fw/​plat/​uno/​fw/​drivers/​session_store/​src/​session_store.rs Adds session backup, restore, and rollback.
fw/​plat/​uno/​fw/​drivers/​part_store/​src/​part_store.rs Updates GUID and sealed-BK3 storage APIs.
fw/​plat/​std/​pal/​src/​session.rs Adds reopen rollback behavior.
fw/​plat/​std/​pal/​src/​drivers/​session.rs Adds session-table rollback.
fw/​pal/​traits/​src/​session.rs Extends the session manager contract.
fw/​core/​lib/​src/​ddi/​mbor/​reopen_session.rs Rolls back failed reopens.
fw/​core/​lib/​src/​ddi/​mbor/​open_session.rs Cleans up failed opens.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +689 to +690
pub fn set_vm_launch_guid(mut self, v: &[u8; GUID_LEN]) {
self.slot_mut().vm_launch_guid.copy_from_slice(v);
// uno's hardware `queue_id` *is* the Admin `device_sq_id`
// (identity — the IIC tags each inbound IO with its source
// queue id), so the drain keys directly on it.
self.drain_sq(u16::from(msg.info.device_sq_id)).await;
Comment on lines +917 to +923
// Write-once per power cycle: a second `SetSealedBk3` without an
// intervening clear (partition free / NSSR) returns
// `SealedBk3AlreadySet`, matching the std PAL (`part.rs` setter)
// and the `part_set_sealed_bk3` contract. The blob is preserved
// across `Migrate` (NSSR), so this one-shot gate must survive a
// live migration. The low-level store accessor keeps plain
// overwrite semantics; the policy lives here.
Comment on lines +827 to +830
async fn try_handle_create_delete_sq(&self, channel: IpcChannel, buf: &[u32; 16]) -> bool {
let Some(msg) = decode_create_delete_sq(buf) else {
return false;
};
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants