From 9de6a6cee79a50bd3bc00ee800753270ebef8b03 Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Mon, 13 Jul 2026 22:03:03 -0700 Subject: [PATCH] =?UTF-8?q?docs:=20add=20CONTAINER=5FISOLATION.md=20?= =?UTF-8?q?=E2=80=94=20session-isolation=20model=20+=20build/validate=20wo?= =?UTF-8?q?rkflow?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Overview doc so other agents/humans understand the shared-control-container isolation work: the failure vectors + fixes (stdio wedge, connection leak, control-plane HOL, OOM cross-kill, CPU/fork-bomb, per-session memory.max), the host-vs-guest shipping surfaces, the per-exec cgroup layout + graceful fallback, and the local vminit-image build/validate workflow + -nucleicN tag invariant. Cross-linked from the vendored PATCHES.md. Co-Authored-By: Claude Opus 4.8 --- PATCHES.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/PATCHES.md b/PATCHES.md index b34a7f0..ba53678 100644 --- a/PATCHES.md +++ b/PATCHES.md @@ -1,5 +1,8 @@ # Vendored `containerization` — Nucleic patches +> Overview of *why* these patches exist (the session-isolation model) + the build/validate workflow: +> [`docs/CONTAINER_ISOLATION.md`](../../docs/CONTAINER_ISOLATION.md). This file is the per-patch detail. + This is a **vendored copy** of [apple/containerization](https://github.com/apple/containerization) at upstream commit `6b7b42ca3efeee8c706070e4355e6a807c5336ae`, referenced by the root `Package.swift` via `.package(path: "third_party/containerization")` instead of the github URL.