Skip to content

Add durable snapshot and restore - #354

Open
simongdavies wants to merge 5 commits into
mainfrom
simongdavies-snapshot-and-restore
Open

simongdavies wants to merge 5 commits into
mainfrom
simongdavies-snapshot-and-restore

Conversation

@simongdavies

Copy link
Copy Markdown
Member

Summary

Adds durable OCI-backed snapshot and restore support for runtime-ready and loaded JavaScript sandboxes across Rust and Node.

API changes

Rust

  • JSSandbox now supports snapshot() and restore() before handlers are loaded.
  • LoadedJSSandbox snapshots preserve evaluated handlers and mutable guest state.
  • SandboxBuilder::build_from_snapshot() creates a SandboxRestorer.
  • SandboxRestorer::restore::<JSSandbox>() and restore::<LoadedJSSandbox>() enforce the captured lifecycle type.
  • Host functions, filters, module loaders, and print callbacks are configured on SandboxBuilder for fresh construction and restoration.

Node

  • JSSandbox now exposes snapshot() and restore().
  • SandboxBuilder.buildFromSnapshot() creates a SandboxRestorer.
  • SandboxRestorer.restoreJsSandbox() and restoreLoadedSandbox() restore the matching lifecycle.
  • Snapshot.save(), Snapshot.load(), and Snapshot.loadUnverified() provide OCI persistence.

Breaking changes

  • hyperlight_js::Snapshot now names the lifecycle-aware snapshot wrapper instead of re-exporting Hyperlight’s raw snapshot.
  • LoadedJSSandbox::snapshot() now returns Snapshot instead of Arc<hyperlight_host::Snapshot>.
  • LoadedJSSandbox::restore() now accepts and consumes the lifecycle-aware Snapshot.
  • Code explicitly typed against the old hyperlight_js::Snapshot alias must migrate to either the new wrapper or hyperlight_host::sandbox::snapshot::Snapshot.
  • Host modules are no longer cloneable. Reusable definitions must be factories that create fresh module and callback instances per sandbox.
  • Node ESM no longer exports internal *Wrapper aliases. Import Snapshot, JSSandbox, LoadedJSSandbox, SandboxBuilder, and SandboxRestorer.

Limitations

Hyperlight issue #1870 prevents complete preflight inspection of raw snapshot host requirements. Hyperlight JS records its logical host-function requirements in metadata, while module-loader requirements remain unknown until upstream introspection is available.

Add lifecycle-aware persistent snapshots for runtime-ready and loaded
JavaScript sandboxes across the Rust and Node APIs. Restore process-local
host resources through SandboxBuilder, keep captured requirements separate
from available host callbacks, and prevent accidental callback sharing.

BREAKING CHANGE: hyperlight_js::Snapshot now names the lifecycle-aware
snapshot wrapper, LoadedJSSandbox snapshot and restore use that wrapper,
HostModule is no longer cloneable, and Node ESM no longer exports internal
Wrapper aliases.

Signed-off-by: Simon Davies <simongdavies@users.noreply.github.com>
Explain durable and in-memory snapshot lifecycles, host-function factories,
required versus available capabilities, external and native module behavior,
and the current module-loader introspection limitation.

Include Rust and Node restoration examples and migration guidance for the
breaking snapshot API changes.

Signed-off-by: Simon Davies <simongdavies@users.noreply.github.com>
Clarify that generated GitHub release notes use pull-request labels rather
than commit-message footers, and require the breaking-change label for
released API incompatibilities.

Signed-off-by: Simon Davies <simongdavies@users.noreply.github.com>
@simongdavies simongdavies added kind/enhancement New feature or improvement breaking-change Breaking change requiring consumer migration labels Oct 8, 2026
Signed-off-by: Simon Davies <simongdavies@users.noreply.github.com>
Comment thread src/js-host-api/src/lib.rs Dismissed
Comment thread src/js-host-api/src/lib.rs Dismissed
Import the Node URL constructor explicitly now that generated-type scripts are
included in the JavaScript lint gate. Update custom native-module persistence
coverage to use the lifecycle-aware snapshot restorer API.

Signed-off-by: Simon Davies <simongdavies@users.noreply.github.com>
@simongdavies simongdavies added the ready-for-review PR is ready for (re-)review label Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking-change Breaking change requiring consumer migration kind/enhancement New feature or improvement ready-for-review PR is ready for (re-)review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants