Skip to content

feat(control): add ExportZone and ImportZone RPCs - #62

Merged
azenla merged 3 commits into
mainfrom
azenla/prototype/xen-snapshot-restore
Oct 7, 2026
Merged

azenla merged 3 commits into
mainfrom
azenla/prototype/xen-snapshot-restore

Conversation

@azenla

@azenla azenla commented Oct 7, 2026

Copy link
Copy Markdown
Member

Adds the control API for zone export and import, which edera-dev/protect#3489 implements behind the snapshot-v0 feature flag.

  • ExportZone: a server-streaming RPC that returns a start message, then snapshot chunks, then a completion message.
  • ImportZone: a client-streaming RPC that takes a start message, then chunks, and returns the imported zone's id.
  • ZONE_STATE_IMPORTING = 12: a new zone state.
  • New enums: ZoneSnapshotBackend and ZoneSnapshotArch.

Every change is additive. No existing field or enum value is renumbered.

This should merge before protect#3489, which will then repin to the commit this lands as on main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LtsFZtSaaP4xAmfz8nFwZb


Generated by Claude Code

azenla added 3 commits October 7, 2026 17:44
`SnapshotZone` streams a zone's complete state -- vcpus, guest memory,
hypervisor configuration, device topology, and the zone's own
control-plane record and workloads -- out as opaque bytes for the caller
to store. `RestoreZone` streams them back and returns the restored
zone's id. The bytes are opaque on purpose: the client stores a
snapshot, it does not interpret one.

The backend and architecture tags are the load-bearing part of that
exchange, and the only part of the snapshot's own shape this API needs
to name, so they live in common.proto next to the virtualization backend
they mirror. A snapshot may only be restored on the hypervisor it came
from, since the guest-state records are backend-private, and tagging
them is what lets a KVM implementation be added later without either
backend being able to consume the other's stream.

Nothing else about the stream is described here. The records inside it
-- the manifest, the device topology, the guest memory -- belong to the
daemon and the hypervisor backend that write them, and describing them
in the public API would make a change to the format's framing a change
to this API. The one thing a caller does get is `total_bytes`, which
describes the transfer rather than the format and is what lets it
confirm it stored the whole stream.

`ZONE_STATE_RESTORING` covers a zone being rebuilt from a snapshot.
`SnapshotZone` becomes `ExportZone` and `RestoreZone` becomes
`ImportZone`, with their messages renamed to match. What an export
produces is still a snapshot, so the snapshot backend and architecture
tags keep their names. `ZONE_STATE_RESTORING` becomes
`ZONE_STATE_IMPORTING`.

`include_disk_contents` is removed and reserved: an export now always
carries the contents of a zone's writable disks. `allow_foreign_host` is
narrowed to snapshots that reference read-only images by host path, and
the import now checks the CPU, hypervisor and platform a snapshot was
exported on against the importing host.
The import no longer gates on the exporting host's id: it checks the
guest's cpu, clock, agent protocol and hypervisor against the importing
host, and that each read-only image the snapshot references exists at the
recorded size. The waiver has nothing left to waive, so the field is
removed and reserved.
@azenla
azenla requested a review from tycho October 7, 2026 22:16
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow Buf CI / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedOct 7, 2026, 10:16 PM

@azenla
azenla merged commit 74b44ff into main Oct 7, 2026
2 checks passed
@azenla
azenla deleted the azenla/prototype/xen-snapshot-restore branch October 7, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants