Glossary
| Term |
Meaning |
| Job |
A persistent unit of work in pVisor: command, evidence, and staged changes |
| Stage |
A copy-on-write staging workspace |
| apply / drop |
Selectively merge staged changes into the target / discard them |
| Run Bundle |
The result, control observations, artifacts, and summary of one run |
| Capability |
The request and actual control of one capability dimension (files, network, subprocess, …) |
| Evidence |
The controls an executor actually installed and the results observed, not the declaration |
| Placement |
The chosen execution location (host / container / VM, and Overlay combinations) |
| Plan level |
What the executor plans to install at admission: Unsupported, Cooperative, Planned—not proof it is installed |
| Observed level |
What the executor observes at teardown: Unenforced, Cooperative, Enforced |
| Interception |
Network-layer interception of egress traffic (explicit proxy or VM data plane) |
| L0–L3 |
Trust ladder levels |
For mechanisms and fields, see design and reference.