Skip to content

impl lazy oci image loading - #7

Merged
reiase merged 9 commits into
developfrom
feature/dev_on_macos
Sep 30, 2026
Merged

reiase merged 9 commits into
developfrom
feature/dev_on_macos

Conversation

@reiase

@reiase reiase commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@reiase reiase changed the title Feature/dev on macos impl lazy oci image loading Sep 30, 2026
Expose the server's OCI image store over a versioned read-only file
protocol (`pvisor cache serve`, plus prepare/list/stat/read commands)
and
mount demand-filled FUSE lowers for VM rootfs images. Clients probe the
default per-user Unix socket automatically and fall back to local OCI
preparation when no compatible server is running.

Also add a `warn` filesystem access level, `--ask` file approval UI and
persistent permission rules, a VM filesystem smoke test, and fix macOS
virtio-fs passthrough to pin inode paths for FSKit mounts.
Move CLI-adjacent runtime and executor code into focused
`executor/`, `image/`, and `runtime/` submodules; split the shared
image cache into protocol, transport, client, server, and CLI
files; and group replay protocol bridges under `bridge/`. Add host
diagnostics shared by services and the CLI, drop the thin control
re-export in favor of direct `persisting_control` exports, and
document the resulting ownership boundaries.

Also bound the cache server's metadata caches with an LRU, paginate
directory listings so frames stay within the protocol limit,
serialize image preparation onto a dedicated worker queue, and add
a `--refresh` flag to `pvisor cache prepare`. Trim the vendored
Zellij border glyphs to the rounded single-line subset actually
used.
Remove the test-only DelegatedRunFiles::new constructor and have tests
call new_with_stdio directly. Also drop the redundant
PERSISTING_AGENTCTL_
prefix check in the env filter.
Update CI, docs, and benchmark workflows to run on pushes
and pull requests to develop in addition to main. Sync the
engineering docs in both languages with the new triggers.
Move write_private_json into util and route delegated, VM, and
run-result writes through the shared atomic replacement path. Reuse the
replay sha256 helper in claude_resume.

Also harden the seatbelt proxy test against Xcode's python3 launcher by
resolving the real interpreter before sandboxing.
Permit `network-bind` on local TCP so `connect()` can implicitly bind an
ephemeral port, while listen and outbound peers stay restricted. Update
the
sandbox test to cover explicit and implicit local binds.
Allow network-bind and inbound Unix sockets directly while granting
outbound Unix connections positively by path. Negated Unix-path denies
could also reject permitted TCP connections on macOS, causing
intermittent failures across ephemeral ports.

Expand the test to cover local and denied socket roots and repeat it to
surface flakiness.
@reiase
reiase force-pushed the feature/dev_on_macos branch from dc9fe4d to 194a3c1 Compare September 30, 2026 04:20
@reiase
reiase merged commit 291826f into develop Sep 30, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant