Service responsibility convergence¶
Reduce duplicated management by giving each local resource a clear owner, not by combining every service into the daemon process. Sandbox lifecycle, native immutable backing and indispensable live RAM have different authority and failure boundaries.
Current responsibilities¶
| Responsibility | Owner | Relationship to daemon |
|---|---|---|
| Sandbox admission, intentions, expiration, endpoints | pvisor-daemon |
Implemented by VM-only NativeRuntime with integrated executable/CLI |
| Job/Attempt lifecycle, staging, Gateway and native VM checkpoints | pvisor Session/executors |
VM execution embedded in supervisors; staging/Gateway/checkpoint APIs not exposed |
| Immutable environment mounts and shared read-only RAM backing | Native node resource service (pvisor/src/node.rs) |
Runtime protocols for native callers; no daemon acquire/release adapter |
| Image preparation, publication, serving and reads | Independent pvisor-cache and runtime cache modules |
Separate executable, data path and budgets; not absorbed by daemon |
| Optional shared pages and session references | pvisor-daemon/src/memory_pool.rs |
serve --memory-pool starts/reuses a detached memory-pool --directory DIR component; off by default |
| Host selection, workflows and retry policy | External orchestration | Outside the product control plane |
Node runtime protocols are available to embedded native callers. Its identity is an image handle/digest or sealed RAM identity/compatibility, not a sandbox ID. A connection pins one owner. Same-identity preparation is single-flight; active owner/session/preparation counts and warming are bounded. A process-local registry remains available where native callers do not configure a node socket.
flowchart TB
Caller[Caller or external orchestration] --> Daemon[Sandbox daemon]
Daemon --> Supervisor[Native pVisor VM supervisor]
Supervisor --> Image[Prepared execd and egress image]
Native[Native pVisor execution] --> Node[Native node resource service]
Node --> Cache[Immutable cache and lazy reads]
Node --> RAM[Shared read-only RAM backing]
Daemon --> Pool[Optional detached shared-page pool]
Supervisor --> Pool
There is deliberately no daemon-to-node arrow. Shared packaging, a common launch entry or fewer ports does not supply a missing runtime adapter or establish faster startup, lower memory or improved useful-work density.
Data authority and restart boundaries¶
| Object | What may be reclaimed? | Failure boundary |
|---|---|---|
| Refetchable image/decoded blocks | Unpinned hot contents with a valid durable source | Hits do not replace publication authorization |
| Active read-only RAM/FUSE owner | Idle warmth after active pins end, not active mounts | Durable source does not automatically recover a live VM after owner failure |
| Private cold RAM transferred to pool | Not its only remaining copy | Lost sessions/pool contents may fail-stop dependent VMs |
| Published checkpoints/evidence | Only through their own retention and GC roots | Native registry warmth cannot authorize deletion |
| Daemon sandbox record | After confirmed native deletion | Normal daemon shutdown preserves supervisors/VMs and registry |
A daemon-only restart preserves detached native supervisors/VMs and the configuration-bound pool component. It does not recover a failed pool or recreate its live pages. Restarting a backing owner or cold pool is a different operation and cannot promise transparent session reconnect. Keep pins until native runners are reaped; without lossless draining, wait for dependent VMs before upgrades. Do not infer live RAM reconstruction from a restored metadata file.
Budgets and concurrency¶
Native node configuration bounds owners, warm owners, sessions, preparations and retained cache payload. That payload counter aggregates content blocks, paged metadata and Linux decoded RAM; it excludes complete metadata, scratch, external references and kernel residency. The daemon pool has separate bounded page/object/connection/reference budgets, outside individual sandbox cgroups. They are not dynamically arbitrated against node caches or equal to a whole-process cap; see pool budgets.
Reserve headroom for active objects and restoration before optional caches/prefetch. Under pressure, drop expendable warmth/refetchable contents or refuse new preparations, never the only live bytes. Slow teardown and I/O stay outside management map locks; same-identity serialization must retain authorization and compatibility checks.
Daemon CPU/memory admission remains a separate conservative sum of supervisor/VM-tree hard limits. It has no combined physical-memory accounting with native node/pool resources. Host cgroup supervision and observations must include services and transient work, not only workloads.
Integration direction¶
- Retain separate owners and failure scopes while obsolete distributed roles are retired.
- Before connecting the existing native runtime to node resources, define acquisition, private writable state, cancellation, native termination and pin release before sharing resources.
- Unify observations and controllable budgets only after distinguishing reservations, shared physical pages, evictable payload and indispensable RAM.
- Consider process merging only after explicit restart/drain and data-preservation contracts, followed by fixed-budget measurements.
No live-VM takeover, shared cold-pool arbitration, automatic node acquisition or density advantage is established by consolidation. Native resource correctness evidence and legacy service experiments keep their original scope; they are not daemon acceptance results.
The independent cache provides prepare, publish, serve, list, stat and read. Cache and node protocols have separate ownership from daemon sandbox lifecycle.
Related contracts: shared working sets, state and recovery, native shared image storage and experimental pool.