Skip to content

[Bug Report] Cross-node resume of a paused sandbox fails after the export TTL (1 h): s3lvol auto-reaps the ref export while the sandbox is still paused #1690

Description

@fslongjin

Summary

A sandbox that is paused can no longer be resumed on a different node if the cross-node resume happens after the pause export's TTL (default 1 hour) expires.

When a sandbox is paused, the s3lvol side publishes a ref-layout export (lease-aware, pin=lease) so that a later cross-node resume can import it. If nothing imports it while the sandbox stays paused, the export becomes "terminal" once its lease is confirmed absent past the TTL deadline, and the reaper removes it automatically — manifest deleted, registry entry cleared. From that point on, any cross-node resume attempt fails because the manifest it must import returns 404. Same-node resume keeps working because it is served from the local pause catalog / lvstore snapshot volume and never depends on the export.

Environment

Description / mechanism

  1. Pause completes. The s3lvol side publishes a ref-layout export for the pause package (manifest under <lvstore>/meta/exports/<uuid>.json) with lease_aware=true and the default TTL S3LVOL_EXPORT_DEFAULT_TTL_SEC = 3600 (1 h).
  2. Cross-node resume depends on that export: restoreplace.Decide only allows a resume to leave the origin node while the pause record reports remote_status=ready (i.e. the export exists), and Cubelet on the destination node imports it through the export UUIDs (remoteUUIDs).
  3. If the export expires with no lease taken (lease_absent — nothing imported it during the pause), export_lease_is_terminal() becomes true and the periodic exports_reap poller reaps it automatically: the manifest is deleted and the registry entry cleared. No explicit delete / release request is involved.
  4. Any later cross-node resume reads the already-removed manifest → 404 → the resume fails. Same-node resume is unaffected: it goes through the local pause catalog + lvstore snapshot volume and does not depend on the export.

Expected Behavior

A sandbox that is still paused should remain resumable on another node (cross-node) without being silently limited to the ~1 h export TTL. Reaching the export deadline should not invalidate a pause that is still owed to a possible cross-node recovery.

Actual Behavior

  • The effective window for cross-node resume after a pause is the export TTL (default 1 h).
  • Beyond that window, only same-node resume works. Cross-node recovery for the scenarios the export exists to serve — origin node failure / removal / drift — fails with a 404 on the export manifest.

Additional Context

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions