Skip to content

Feature/new guest init - #11

Closed
reiase wants to merge 45 commits into
developfrom
feature/new_guest_init
Closed

reiase wants to merge 45 commits into
developfrom
feature/new_guest_init

Conversation

@reiase

@reiase reiase commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

reiase added 30 commits October 1, 2026 11:11
- Add `persisting-guest`, a Linux PID 1 supervisor that mounts
  filesystems,
  configures networking, launches the workload, and reports its exit
  code via
  libkrun's root filesystem ioctl.
- Build the guest as a static musl ELF with Rust's bundled linker,
  removing the
  Zig/macOS cross-compiler dependency and the vendored `krun-init-blob`
  C init.
- Add `persisting-journal`, a shared single-writer fact journal with
  causal
  ordering and poisoning, replacing the pVisor `trace` module and
  Gateway WAL.
- Migrate Gateway capture from `EventRecord`/`CaptureEventSink` to
  `trace::Event`
  and `CaptureEventObserver`, rebuilding Story and SessionIndex from
  committed
  facts on restart.
- Skip the re-export of legacy events; move them to `legacy_events` for
  historical JSONL reads only.
- Pin authorized CONNECT IPs through the ambient HTTP proxy, rejecting
  new DNS
  resolution.
- Add `guest_init.py` benchmark and static build support in CI, wheels,
  and
  `just build`.
- Reject unsupported mount options in overlayfs and shim, and require
  explicit
  namespace joins to succeed.
- Update docs and diagrams for the new journal and guest supervisor
  model.
Delete the v1 JSONL compatibility types and property tests, drop
legacy read paths in the Gateway egress and replay journals, and
reject non-fact journals instead of inspecting them read-only.

Remove the unused Engine/Backend/Admission interpreter from
persisting-pvisor along with its core_trace example and core_ir
tests. Clarify docs that RunPlan IR is an audit projection and the
only production dispatch path is PVisor::run -> RunExecutor::execute.

Replace the pinned musl targets in rust-toolchain.toml with an
opt-in static-musl input on the setup-build-env action, and have
libkrun locate rust-lld from the installed target instead of the
host sysroot.
Replace `ExecutorDescriptor` and `CapabilityEnforcementEvidence` in the
admission path with `ExecutorPlan` and `CapabilityEnforcementPlan`,
which
express expected controls rather than installed enforcement. Executors
now
return `ExecutorObservations` from setup receipts at teardown.

Bump `RUN_PLAN_VERSION` to 2 and Run Bundle schema to 3. Reject old
bundles
lacking the observation contract and drop the enforcement descriptor
from
`run.json`, which now retains only runtime facts and executor selection
identity.

Shift VM guest networking to a static IPv4 address configured by the
Rust
`persisting-guest` supervisor instead of DHCP, and document the guest
supervisor crate and revised benchmark results.
Move overlay apply/recovery logic into persisting-overlay-core and
network policy into persisting-control so executors, the CLI, and the
proxy share one implementation.

Add SessionPolicies with session/workspace/user scopes, loading
workspace and user policy defaults from .pvisor/policy.toml. Introduce
AuditScope on audit requests and FileAccessContext on file access
policies.

Add atomic_write to persisting-journal and re-export it from pvisor
utilities.
Replace the Python semantic test prototype with a standalone Rust
`semspec` tool under `tools/semspec`, wired into `just` and CI. Update
policy precedence, file policy loading and overlay generation code
accordingly, and refresh the network and architecture docs to match.

Conventional tests and unreviewed draft specs are included; human review
of the ledger and approved snapshots remains pending.
Split the Attempt lifecycle into a Session type in persisting-pvisor
that
owns drivers, controls and observations, replacing ExecutorSession. Add
a
versioned session control/observation protocol to persisting-control.

Introduce pvisor-NAME executable extensions with embedded inert JSON
manifests. Discovery reads manifests without executing them; dispatch
preserves argv, stdio, signals and exit status. pvisor-tui and
pvisor-replay
ship as extensions, with the core binary resolving their paths and all
build, install and wheel scripts staging the three executables.

Migrate the documented A01-M02 CLI cases into semspec as the DOC domain
(S-DOC-001..056), removing scripts/run-pvisor-cases.py. Semspec now
sources
vocabulary from hashed bytes in sorted filename order so configuration
ordering cannot silently change execution while preserving the digest.
The `env` subcommand and its reusable environment management have been
removed. Job lifecycle commands (`apply`, `drop`, `status`, `kill`,
`fork`,
`inspect`, `run`) remain built into `pvisor`, while cache moves to its
own
`pvisor-cache` executable alongside `pvisor-tui` and `pvisor-replay`.

semspec now reads DOC cases directly from
`docs/src/zh/reference/cases.md`
via a new `spec_dirs` entry and a `run <markdown>` selector; the old
`tests/semantics/documented-cases.md` catalog is deleted and L01/L02 are
retired as `S-DOC-053`/`S-DOC-054`.

Resource enforcement now considers a `resource.posix_rlimit` metric when
deciding whether the Resources dimension is enforced, and unsupported
memory limits on macOS no longer mask an observed file-size rlimit.
Wire ForegroundProcessGroup into VmExecutor so interactive
sessions over TTY stdin attach the VM runner to the foreground
process group, matching local execution behavior. Terminate the
process tree if the handoff fails.

Remove unused semspec vocab helpers and stale prototype notes.
Give VM runner a foreground terminal

Let the VM executor hand the controlling terminal to the spawned pvisor
process, matching the behavior of the direct executor, so interactive
VMs receive keyboard input.

Also adds a PTY-based integration test gated behind `--vm-bin`, drops
the obsolete Python semspec runner references, and prunes unused vocab
helpers.
Move benchmark and VM filesystem tests under tests/ so the default
Python suite picks them up, add a root conftest.py for shared options
and fixtures, and gate platform-specific benchmark checks on Linux.

Convert the zcode integration script into a pytest module and drop the
CI invocation of `just test-benchmark` now that its coverage is part
of the standard run. Update docs to point at the new test paths.
Move pvisor-tui into its own persisting-tui crate, pvisor-replay
into persisting-replay, and drop the pvisor-cache manifest shim.
Replace the embedded executable-manifest extension mechanism with a
static table of first-party companions resolved strictly from the
core's install directory.

Extract Gateway-independent config (CaptureLevel, ModelRoute,
OverlayConfig) and NetworkConfig/NetworkMode into persisting-control
and persisting-overlaynet so default pvisor builds no longer depend
on persisting-gateway. Gate Gateway capture behind a `gateway`
feature, add a plain explicit proxy using OverlayNet policy, and
remove SessionExtension, the Session control wire protocol, and the
ExecutorSession alias.

Make `--safe` presets Agent-independent, drop per-Agent egress
allowlists, split the DOC spec into semspec-doc.toml, and add a CI
core-dependency budget check.
Match `--safe` network grants and Codex environment
inheritance to the target executable, and document the
resulting default allowlists.
Rename all crates, binaries, environment variables, repository URLs,
and documentation references from the Persisting/PERSISTING namespace
to pVisor/PVISOR. Repository is now DeepLink-org/pvisor.
The reduced Rust line count reflects recent deletions; binary size and
workspace line budgets are updated to match. Installation docs now note
the `PVISOR_*` variable rename and unchanged local state paths.
Delete the operation-chain IR (Expression, Rule, Rewrite, text
parser, Context wrappers) and move the Run audit schema into a
dedicated run_plan module. RunPlan now carries run_id, ordered
VM/Overlay placements and plan rules directly, without deriving its
expression from IR rewrites. Bump trace to v4 and reject older plan
and event schemas.

Lower the isolated core budget to match the removed Control API
surface and update docs accordingly.
Drop StorylineId from NetworkAccessRequest and lease_epoch from
RunResult and delegated run outputs. Derived trajectory views are no
longer part of the online protocol-conversion path, so update docs,
diagrams, and call sites to match. Binary size baselines are refreshed.
Rename the shared contracts crate to `pvisor-core`, reorganize it
around Operation and Event schemas, and move runtime-owned pieces
(AgentCtl client, audit channel) into `pvisor`.

- Rename `run_plan` to `operation`, `trace` to `event`, `runtime` to
  `execution`; bump event schema to 5 and operation schema to 1
- Move `AgentCtlClient` and the audit socket implementation out of
  the shared crate into `pvisor`
- Add `audit` channel trait and `pvisor-core::audit` contracts
- Make Chinese docs authoritative; keep English for home, getting
  started, and CLI reference, and link other subjects to Chinese
- Stage workspace changes by default under `--safe`/`--ask`; update
  staging and storage docs accordingly
- Drop semspec approved snapshots, `revoke`, `retired` IDs, and
  requirement probes in favor of Bash exit-77 prerequisites; bump
  engine semantics to 2
Update `pvisor-core` module docs to describe Operations, Events, and
executor boundaries. Box `Fact::Rewritten.after` and bump the Run
Bundle schema to 4, raising the isolated core budget accordingly.

Rework Chinese docs around caps/evidence, remove the local-to-fleet
design page, and delete unused diagram, logo, and homepage assets.
Consolidate the concepts pages into the start section, add redirects,
and archive the Qwen3.6 SandboxReplay experiment report under benchmark.
Consolidate the operations-events content into the site under
docs/src/zh/design/, replacing the standalone docs/operations-events.md
with a redirect stub. Rewrite architecture and principles around the
core/implementation split, and update READMEs, nav, cross-links, and
related reference pages to the new paths.
Rewrite the zh/en home hero around the trust bottleneck, drop
outdated "Chinese is authoritative" statements, and remove scaffolding
sentences that merely point at adjacent pages.
concepts

Folded repeated definitions of Job/Run/Attempt, capability levels, and
staging scope into the shared concept pages, and updated architecture,
CLI, isolation, OverlayNet, principles, network, troubleshooting, and
start docs to link to them instead of restating.
Lead with "hands off, gate the result, keep a record" framing in
README, home page, and start pages. Rework first-run walkthrough to
use a fake agent script demonstrating edit, delete, denied read, and
blocked network, then identify which changes to keep.

Add a trust/scale ladder (L0-L3) to roadmap and clarify L1 scope.
Document packaging/naming conventions. Refactor what-is-pvisor to
compare against Docker, agent sandboxes, worktrees, cloud sandboxes,
and orchestrators.
Rewrite docs around scaling autonomous agent execution

Reframe README, homepage, and start guides around human
supervision bandwidth as the limit on autonomy rather than
compute. Present bounded, recoverable, and checkable execution
as the three properties that decouple supervision from volume.

Add an L0-L3 trust/scale ladder to the roadmap and shorten the
first-run walkthrough into a self-contained fake-agent demo.

Also fix `resolve_run` to fall back to `resolve_last` so an
implicit selector never returns another workspace's Job.
Move the semspec design doc to tools/semspec/DESIGN.md, relocate the
shared image cache doc into the site reference tree, and drop stale
logo assets. Update AGENTS.md, crate metadata, READMEs, and diagrams to
the new positioning line.
Reposition as scaling autonomous agent execution

Update taglines and metadata across Cargo.toml, pyproject.toml,
docs, examples, and diagrams. Point semspec references at
tools/semspec/DESIGN.md and relocate shared-image-cache and
semspec-design docs next to what they serve.
The roadmap page no longer reflects current plans. Redirect
`roadmap.md` to the development index, drop the page from nav and
README, and trim the links that referenced it.
Reorganize the Chinese docs from a mechanism-first taxonomy into a
value-first one: why → start → guides → concepts → benchmarks →
security → reference → design → community.

- Add new `why/`, `benchmarks/`, `security/`, and `community/` sections
- Split `guides/` into `agents/`, `policies/`, and `executors/`
- Move implementation detail out of `concepts/` into `design/`
- Rename scattered pages and update `redirects.json` and nav
- Add planning stubs marked `status: todo` for pages awaiting content
Replace TODO stubs across zh docs with written pages covering
security, benchmarks, design, community, and getting-started
topics. Update README and the English CLI/start docs to lead with
the `pvisor run --safe -- <agent>` flow and clarify `last` Job
resolution, and fix the home page example command.
Document the development loop, semspec rules, and PR expectations for
contributors, plus the private vulnerability reporting process, response
targets, and in-scope boundary guarantees.
reiase added 15 commits October 2, 2026 08:45
Every Chinese article now has a matching English page at the same
relative path. A translation ledger records approved revisions, and
docs checks plus tests fail on missing pages, status, anchor, case ID
and example drift between locales. Native breadcrumbs render
locale-specific home links.
Enforce recorded bilingual revisions in CI with check-docs
--require-recorded, and update test coverage for the strict flag.

Lock apply/drop and checkpoint mutations behind RunRecord::lock_current
so selectors read the authoritative record only after acquiring the
lease, instead of trusting an earlier snapshot.
Introduce attempt-local VM controls and live file-backed guest RAM with
optional Zstd Seekable base/delta generations. Expose the primitives
through RunHandle and the CLI, and add SDK-driven DOC cases
S-DOC-057..062.

The compressed adapter requires Linux FUSE or the macFUSE kernel
backend.
Files are not complete VM snapshots, and the reclaim report is a
best-effort residency sample rather than a guarantee.
Add a `vm_run_sdk` vocabulary helper that captures driver
output, prints it, and fails with the exit status so diagnostics
survive errexit. Update the English and Chinese VM reference
cases and the catalog test accordingly, and cover the helper's
failure path.
Introduce a shared compressed cold-page pool for macOS/Apple Silicon
with host-side block observation, deduplication, and restoration to
private RAM. Includes a foreground pool service, the `pvisor
memory-pool` CLI and `--vm-memory-pool SOCKET` option, and a
VM-local RAM fault resolver in a newly vendored `krun-hvf` patch for
retrying restored instruction faults before MMIO decoding.

Ship the runtime, pager, and transport fully disabled by default:
`VmSettings.memory_pool` stays unset unless the socket path is given,
and the FUSE compression and whole-VM offload paths are mutually
exclusive with it. Pool loss fails dependent VMs rather than returning
fabricated content.

Also add design docs and SVGs for the memory-sharing and offload
subsystems, wire `pvisor-memory-pool` into build and packaging
scripts, and record the current experiments as still unverified for
whole-host physical savings and tail latency.
Reformat chained let-else and argument lists, reorder VM/ram-backing
module declarations, and expand bilingual docs covering the OverlayCore
and Journal designs plus the VM memory measurement methodology.
Document the cold-memory pool benchmark (40-run matrix plus extended
2 GiB runs), add opt-in startup timing checkpoints, and cover the
guest init config transport plus Run index durability change.
The boot-parameter transport was experimental and is superseded by
the config file, so drop the base64/flate2 path, the
PVISOR_EXPERIMENTAL_INIT_ARGV env var, and the related boot profiling
in vstate.rs.

Consolidate the VM memory benchmark docs into the index pages.
Introduce `vm_ready.py` to measure full CLI-to-guest-marker
startup latency on Apple Silicon, plus diagnostics that split host
phases. Document the protocol, results, and retained optimizations
in the startup benchmark, and record raw samples for the
pvisor-vm-readiness/v1 run.
Implement stopped-vCPU state capture/restore in krun-hvf, backed by a
small C shim that bridges HVF's vector SIMD ABI. Snapshots are validated
against a closed register schema before restore and reject unsupported
extensions (SVE, SME, MTE).

Add an M0 cold-restore example and a `test-hvf-cold-restore` recipe to
validate persistence across processes on Apple Silicon. This covers CPU
and RAM only, not GIC, virtio or filesystem state.

Also make host startup checkpoints routine INFO diagnostics enabled by
default, with `PVISOR_STARTUP_TIMING=0` to suppress them. TUI runs route
parent and runner diagnostics into the frontend log via an inherited
descriptor; ordinary runs use stderr. Add run_id correlation, a
corresponding test, startup benchmark figures and docs updates.
- Introduced `CpuSnapshot` and `QueueSnapshot` structs for capturing the state of CPUs and queues.
- Enhanced `Vcpu` and `Queue` implementations to support state capture and restoration.
- Added `freeze` and `thaw` methods to `Rng` and `MmioTransport` for managing device states during snapshots.
- Updated `FsWorker` to handle inode allocation and state restoration on macOS.
- Modified `Cargo.toml` to enable serde features for serialization.
- Implemented snapshot profile feature in `Vmm` and `Vcpu` for macOS, allowing restricted CPU extensions and serializable software GIC.
- Ensured compatibility with existing functionality while introducing new snapshot capabilities.
Extend virtio device snapshot support to console and vsock, adding
frozen-worker state capture/restore so consoles and vsock workers can be
saved and resumed across processes.

- Add PortIoSnapshot and capture/restore hooks to console port I/O,
  covering empty, signal, and buffered-log endpoints
- Validate and persist console control messages in ConsoleSnapshot
- Track vsock worker threads to park and release them on freeze/thaw
- Reject snapshots with pending external effects or listeners that
  cannot be safely rebound
- Add device contract tests for console and vsock snapshot round-trips,
  including cross-process restart
  Add console and vsock device snapshots

Extend the snapshot state contract to virtio-console and vsock, plus
legacy RTC, GPIO, and serial devices.

Vsock: freeze parks the workers and drains queue events without reading
guest descriptors; capture is rejected while listeners or pending
external responses exist. Console: port endpoints expose an explicit
PortIoSnapshot so pipes and log buffers round-trip while unsupported
endpoints fail rather than silently drop external state. Balloon thaw
now only kicks the free-page-reporting queue.

Add DeviceSnapshotState::Console and ::Vsock variants, a
Bus::mapped_devices
inventory that covers legacy devices, and MachineRestore validation for
RAM mappings and CPU count.

Note the F_GETFL FWASWRITTEN mask when snapshotting passthrough handles,
since replaying that internal history bit would break reopen.

Tests are device-contract only (no Linux/HVF runtime); the example
vm_linux_cold_restore.rs is an internal API experiment gated to macOS
aarch64.
Introduce `pvisor snapshot` for full-copy Linux environment save,
restore, and fork on macOS Apple Silicon HVF, backed by a new
`environment_snapshot` store that inventories and copies owned trees
and supports raw or durably compressed RAM.

Add `pvisor review`, `checkpoint`, `suspend`, and `resume` as builtins
scoped to stopped Jobs. Workspace checkpoints capture staged upper
files and conflict preimages with idempotent request IDs and
branch-reference pinning; execution capture/resume currently returns
CAPABILITY_UNSUPPORTED rather than freezing ordinary VM Jobs.

Vendor `krun-devices` and `krun-vmm` snapshot support for full bus
device state, RAM capture, and verified filesystem rebinding, plus
`GuestConfig` cloning and an early-boot error marker in the guest
launcher.
@reiase reiase closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant