restore.go 7.85 KB
Newer Older
1
package executor
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16

import (
	"bytes"
	"context"
	"encoding/json"
	"fmt"
	"os"
	"os/exec"
	"path/filepath"
	"strconv"
	"strings"
	"time"

	"github.com/containerd/containerd"
	"github.com/go-logr/logr"
17
	"k8s.io/client-go/kubernetes"
18

19
20
21
22
23
	"github.com/ai-dynamo/dynamo/deploy/snapshot/internal/criu"
	"github.com/ai-dynamo/dynamo/deploy/snapshot/internal/cuda"
	"github.com/ai-dynamo/dynamo/deploy/snapshot/internal/logging"
	snapshotruntime "github.com/ai-dynamo/dynamo/deploy/snapshot/internal/runtime"
	"github.com/ai-dynamo/dynamo/deploy/snapshot/internal/types"
24
25
26
27
)

// RestoreRequest holds the parameters for a restore operation.
type RestoreRequest struct {
28
29
	CheckpointID       string
	CheckpointLocation string
30
	StartedAt          time.Time
31
32
33
34
35
	NSRestorePath      string
	PodName            string
	PodNamespace       string
	ContainerName      string
	Clientset          kubernetes.Interface
36
37
38
39
40
41
42
43
44
}

// Restore performs external restore for the given request.
// Returns the namespace-relative PID of the restored process.
// The DaemonSet side inspects the placeholder and launches nsrestore,
// which handles rootfs application, CRIU restore, and CUDA restore inside the namespace.
func Restore(ctx context.Context, ctrd *containerd.Client, log logr.Logger, req RestoreRequest) (int, error) {
	restoreStart := time.Now()
	log.Info("=== Starting external restore ===",
45
		"checkpoint_id", req.CheckpointID,
46
47
48
49
50
		"pod", req.PodName,
		"namespace", req.PodNamespace,
		"container", req.ContainerName,
	)

51
52
	// Phase 1: Host inspect — resolve placeholder, discover target GPUs, build device map
	hostInspectStart := time.Now()
53
54
55
56
	snap, err := inspectRestore(ctx, ctrd, log, req)
	if err != nil {
		return 0, err
	}
57
	hostInspectDuration := time.Since(hostInspectStart)
58
59

	// Phase 2: Execute — nsrestore handles rootfs, CRIU restore, and CUDA restore inside namespace
60
	result, err := execNSRestore(ctx, log, req, snap)
61
62
63
	if err != nil {
		return 0, fmt.Errorf("nsrestore failed: %w", err)
	}
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
	restoreDuration := hostInspectDuration + result.NSRestoreSetupDuration + result.CRIURestoreDuration + result.CUDADuration
	log.Info("Restore timing summary",
		"restore", map[string]any{
			"duration": restoreDuration.String(),
			"phases": map[string]string{
				"host_inspect_duration":    hostInspectDuration.String(),
				"nsrestore_setup_duration": result.NSRestoreSetupDuration.String(),
				"criu_restore_duration":    result.CRIURestoreDuration.String(),
				"cuda_duration":            result.CUDADuration.String(),
			},
		},
	)
	if !req.StartedAt.IsZero() {
		log.Info("Restore wall time from agent detection",
			"started_to_restore_complete", time.Since(req.StartedAt),
		)
	}
81
82

	// Validate restored process from the host side
83
	validationStart := time.Now()
84
	procRoot := filepath.Join(snap.TargetRoot, "proc")
85
	if err := snapshotruntime.ValidateProcessState(procRoot, result.RestoredPID); err != nil {
86
		restoreLogPath := filepath.Join(snap.TargetRoot, "var", "criu-work", criu.RestoreLogFilename)
87
		logging.LogProcessDiagnostics(procRoot, result.RestoredPID, restoreLogPath, log)
88
89
90
		return 0, fmt.Errorf("restored process failed post-restore validation: %w", err)
	}

91
92
93
94
95
	log.Info("=== External restore completed ===",
		"restored_pid", result.RestoredPID,
		"validation_duration", time.Since(validationStart),
		"total_duration", time.Since(restoreStart),
	)
96

97
	return result.RestoredPID, nil
98
99
100
}

func inspectRestore(ctx context.Context, ctrd *containerd.Client, log logr.Logger, req RestoreRequest) (*types.RestoreContainerSnapshot, error) {
101
102
103
104
105
106
	if req.CheckpointLocation == "" {
		return nil, fmt.Errorf("checkpoint location is required")
	}

	checkpointPath := req.CheckpointLocation
	baseAbs, err := filepath.Abs(filepath.Dir(checkpointPath))
107
108
109
110
111
112
113
114
	if err != nil {
		return nil, fmt.Errorf("failed to resolve checkpoint base path: %w", err)
	}
	checkpointAbs, err := filepath.Abs(checkpointPath)
	if err != nil {
		return nil, fmt.Errorf("failed to resolve checkpoint path: %w", err)
	}
	if checkpointAbs != baseAbs && !strings.HasPrefix(checkpointAbs, baseAbs+string(os.PathSeparator)) {
115
		return nil, fmt.Errorf("invalid checkpoint id %q", req.CheckpointID)
116
117
118
119
120
121
122
123
124
125
126
127
	}

	m, err := types.ReadManifest(checkpointPath)
	if err != nil {
		return nil, fmt.Errorf("failed to read checkpoint manifest: %w", err)
	}

	containerName := req.ContainerName
	if containerName == "" {
		containerName = "main"
	}

128
	placeholderPID, _, err := snapshotruntime.ResolveContainerByPod(ctx, ctrd, req.PodName, req.PodNamespace, containerName)
129
130
131
	if err != nil {
		return nil, fmt.Errorf("failed to resolve placeholder container: %w", err)
	}
132
	log.V(1).Info("Resolved placeholder container", "pid", placeholderPID)
133

134
	cgroupRoot, err := snapshotruntime.ResolveCgroupRootFromHostPID(placeholderPID)
135
136
137
138
139
140
141
142
143
144
145
146
147
148
	if err != nil {
		log.Error(err, "Failed to resolve placeholder cgroup root; proceeding without explicit cgroup remap")
		cgroupRoot = ""
	}

	cudaDeviceMap := ""
	if !m.CUDA.IsEmpty() {
		if len(m.CUDA.SourceGPUUUIDs) == 0 {
			return nil, fmt.Errorf("missing source GPU UUIDs in checkpoint manifest")
		}
		targetGPUUUIDs, err := cuda.GetPodGPUUUIDs(ctx, req.PodName, req.PodNamespace, containerName)
		if err != nil {
			return nil, fmt.Errorf("failed to get target GPU UUIDs: %w", err)
		}
149
150
		if len(targetGPUUUIDs) == 0 {
			log.Info("PodResources API returned no target GPU UUIDs, falling back to nvidia-smi", "pid", placeholderPID)
151
			targetGPUUUIDs, err = cuda.GetGPUUUIDsViaNvidiaSmi(ctx, snapshotruntime.HostProcPath, placeholderPID)
152
153
154
155
156
			if err != nil {
				return nil, fmt.Errorf("nvidia-smi GPU UUID fallback failed for restore target: %w", err)
			}
			log.Info("nvidia-smi fallback discovered target GPU UUIDs", "uuids", targetGPUUUIDs)
		}
157
158
159
		if len(targetGPUUUIDs) == 0 {
			return nil, fmt.Errorf("missing target GPU UUIDs for %s/%s container %s", req.PodNamespace, req.PodName, containerName)
		}
160
		cudaDeviceMap, err = cuda.BuildDeviceMap(m.CUDA.SourceGPUUUIDs, targetGPUUUIDs, log)
161
162
163
		if err != nil {
			return nil, fmt.Errorf("failed to build CUDA device map: %w", err)
		}
164
		log.V(1).Info("GPU UUIDs for device map",
165
166
167
168
			"source_uuids", m.CUDA.SourceGPUUUIDs,
			"target_uuids", targetGPUUUIDs,
			"device_map", cudaDeviceMap,
		)
169
170
171
172
173
	}

	return &types.RestoreContainerSnapshot{
		CheckpointPath: checkpointPath,
		PlaceholderPID: placeholderPID,
174
		TargetRoot:     fmt.Sprintf("%s/%d/root", snapshotruntime.HostProcPath, placeholderPID),
175
176
177
178
179
180
181
		CgroupRoot:     cgroupRoot,
		CUDADeviceMap:  cudaDeviceMap,
	}, nil
}

// execNSRestore launches the nsrestore binary inside the placeholder container's
// namespaces via nsenter and parses the restored PID from stdout JSON.
182
func execNSRestore(ctx context.Context, log logr.Logger, req RestoreRequest, snap *types.RestoreContainerSnapshot) (*RestoreInNamespaceResult, error) {
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
	args := []string{
		"-t", strconv.Itoa(snap.PlaceholderPID),
		// Intentionally exclude cgroup namespace (-C): CRIU must manage cgroups
		// from the host-visible hierarchy so --cgroup-root remap works.
		"-m", "-u", "-i", "-n", "-p",
		"--", req.NSRestorePath,
		"--checkpoint-path", snap.CheckpointPath,
	}
	if snap.CUDADeviceMap != "" {
		args = append(args, "--cuda-device-map", snap.CUDADeviceMap)
	}
	if snap.CgroupRoot != "" {
		args = append(args, "--cgroup-root", snap.CgroupRoot)
	}

	cmd := exec.CommandContext(ctx, "nsenter", args...)
199
200
	// Inherit the agent environment so nsrestore uses the same logger settings.
	cmd.Env = os.Environ()
201
202
203
204
205
206
207
	log.V(1).Info("Executing nsenter + nsrestore", "cmd", cmd.String())

	var stdout bytes.Buffer
	cmd.Stdout = &stdout
	cmd.Stderr = os.Stderr

	if err := cmd.Run(); err != nil {
208
		return nil, fmt.Errorf("nsrestore failed: %w\nstdout: %s", err, stdout.String())
209
210
	}

211
	var result RestoreInNamespaceResult
212
	if err := json.Unmarshal(stdout.Bytes(), &result); err != nil {
213
		return nil, fmt.Errorf("failed to parse nsrestore result: %w\nstdout: %s", err, stdout.String())
214
215
	}
	if result.RestoredPID <= 0 {
216
		return nil, fmt.Errorf("nsrestore returned invalid PID %d", result.RestoredPID)
217
218
	}

219
	return &result, nil
220
}