Conversation
nirs
force-pushed
the
time-sync
branch
4 times, most recently
from
September 5, 2026 19:38
484b499 to
3b3a6d2
Compare
Configure qemu-guest-agent to listen on vsock port 1234 and add
--timesync vsockPort=1234 to the vfkit command. This syncs the
guest clock after the host wakes from sleep.
The default qemu-guest-agent.service on Fedora depends on a
virtio-serial device that vfkit does not provide:
[Unit]
BindsTo=dev-virtio\x2dports-org.qemu.guest_agent.0.device
[Install]
WantedBy=dev-virtio\x2dports-org.qemu.guest_agent.0.device
The service would never start since the device does not exist.
We replace it with a unit file in /etc/systemd/system/ that uses
vsock and starts via multi-user.target. The runcmd uses "disable"
then "enable --now" to remove the stale symlinks from the original
device target and create new ones for multi-user.target.
The Fedora SELinux policy for virt_qemu_ga_t only allows
virtio-serial communication. We install a CIL policy module to
allow vsock socket operations, matching the policy used by
podman-machine-os.
When vfkit starts with --timesync vsockPort=1234, it monitors the
host for sleep/resume events. After resume, vfkit connects to the
guest agent over vsock port 1234 and sends the current host time
to correct the guest clock, which stopped during host sleep.
Same configuration as vfkit — krunkit supports the same --timesync vsockPort=1234 option.
Same approach as the podman tutorial. Unlike Fedora, Ubuntu minimal does not ship qemu-guest-agent, so we add it to the cloud-init packages list. No SELinux policy is needed since Ubuntu uses AppArmor which does not restrict vsock access.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Configure qemu-guest-agent to listen on vsock port 1234 and add
--timesync vsockPort=1234 to the vfkit and krunkit commands in the
podman and docker tutorials. This syncs the guest clock after the
host wakes from sleep.
The default qemu-guest-agent.service depends on a virtio-serial
device that neither vfkit nor krunkit provide. The service would
never start since the device does not exist. We replace it with a
unit file in /etc/systemd/system/ that uses vsock and starts via
multi-user.target. The runcmd uses "disable" then "enable --now"
to remove the stale symlinks from the original device target and
create new ones for multi-user.target.
On Fedora (podman tutorial), the SELinux policy for virt_qemu_ga_t
only allows virtio-serial communication. We install a CIL policy
module to allow vsock socket operations, matching the policy used
by podman-machine-os. On Ubuntu (docker tutorial), AppArmor does
not restrict vsock access so no policy changes are needed, but
qemu-guest-agent must be added to the cloud-init packages list
since it is not pre-installed.
When vfkit/krunkit starts with --timesync vsockPort=1234, it
monitors the host for sleep/resume events. After resume, it
connects to the guest agent over vsock port 1234 and sends the
current host time to correct the guest clock, which stopped
during host sleep.