Merge nucleic/fuzzy-yarn-otter-2pji into dev

This commit is contained in:
2026-08-05 18:19:16 -07:00
parent 17e84c9573
commit 37c33d305b
6 changed files with 1002 additions and 198 deletions
+42
View File
@@ -307,6 +307,48 @@ rebuild whenever a guest patch changes. Built locally, not in CI: the host frame
checked continuation; a wedged write costs one expendable GCD thread, and process
deletion closing the fd still unwedges it. Marked `[Nucleic vendored patch]`.
19. **Monotonic boundary deadlines and generation-scoped exec admission (`DeadlinePolicy.swift`,
`Vminitd.swift`, `VZVirtualMachineInstance.swift`, `LinuxContainer.swift`, `LinuxProcess.swift`).**
A central, tunable operation-class policy now supplies absolute monotonic deadlines to Phase-1
generated vminitd gRPC calls: statistics (2s), create (10s), start (15s), process control (3s),
delete (30s), and agent graceful close (3s), with bounded filesystem/config calls and explicit
process-wait timeouts. RPC expiry cancels the call; create/start timeout races schedule bounded
deletion of any partially committed guest record. Agent close force-cancels `runConnections()`
after its grace period, closing the transport, and `LinuxProcess` teardown inherits that bound.
A nil-timeout `waitProcess` remains the one intentionally greppable generated-call exception:
renewable leases are deferred until guest `ManagedProcess.wait()` removes cancelled waiters;
renewing today would leak one checked continuation per deadline.
VZ vsock connects now have a three-second exactly-once callback/deadline arbiter. Timeout or task
cancellation settles the continuation once; a Virtualization connection delivered after that is
immediately closed. The same absolute deadline covers waiting for the existing VM `AsyncLock`;
a timed-out waiter is cancelled and checks cancellation before it can connect after eventually
acquiring the lock. The lock remains in place pending the lifecycle-gate migration. Container
statistics snapshots VM/ID/generation under `LinuxContainer.state` and
performs dial/RPC/close entirely unlocked. Exec now reserves `(exec ID, operation UUID,
generation)`, dials unlocked, and commits only if the reservation and public `generation` still
match; stale completions close their new agent and throw
`LinuxContainerOperationError.staleGeneration`. Generation values now come from a process-wide
atomic sequence rather than restarting at zero per object, and public `markGenerationDead()`
lets an independent retirement lane invalidate old reservations before normal state cleanup.
Stop invokes the same invalidation before boundary cleanup; reservations are removed on dial
failure, stale commit, pause, or state replacement.
20. **Independent emergency VM stop handle (`EmergencyVMHandle.swift`,
`VZVirtualMachineInstance.swift`).** A retained, generation-labelled handle captures the raw
`VZVirtualMachine` and its required dispatch queue before higher layers expose a live container.
Its once-only `requestStop()` enqueues Virtualization's hard stop directly, without entering
`LinuxContainer.state`, the VZ instance lifecycle lock, vminitd RPCs, statistics, or the normal
engine lifecycle actor. `waitUntilStopped(deadline:)` provides a separately bounded completion
signal by observing Virtualization state on the VM queue, so callers can defer rootfs/network
reuse until the old VM is stopped and make any deadline-expiry force path explicit.
`VZVirtualMachineInstance.dialFreshAgent(deadlinePolicy:)` similarly
supplies a newly opened, caller-deadlined vsock/gRPC channel for independent health checks; it
never adopts a pooled channel or enters the instance lifecycle lock. These are generic framework
concurrency/escape primitives only; replacement quorum, admission, notification, and rate-limit
policy remain in NucleicCore.
## Re-vendoring a newer upstream commit
1. `git clone` upstream (or copy `.build/checkouts/containerization` after bumping the URL pin