docs: add CONTAINER_ISOLATION.md — session-isolation model + build/validate workflow
Overview doc so other agents/humans understand the shared-control-container isolation work: the failure vectors + fixes (stdio wedge, connection leak, control-plane HOL, OOM cross-kill, CPU/fork-bomb, per-session memory.max), the host-vs-guest shipping surfaces, the per-exec cgroup layout + graceful fallback, and the local vminit-image build/validate workflow + -nucleicN tag invariant. Cross-linked from the vendored PATCHES.md. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
@@ -1,5 +1,8 @@
|
|||||||
# Vendored `containerization` — Nucleic patches
|
# Vendored `containerization` — Nucleic patches
|
||||||
|
|
||||||
|
> Overview of *why* these patches exist (the session-isolation model) + the build/validate workflow:
|
||||||
|
> [`docs/CONTAINER_ISOLATION.md`](../../docs/CONTAINER_ISOLATION.md). This file is the per-patch detail.
|
||||||
|
|
||||||
This is a **vendored copy** of [apple/containerization](https://github.com/apple/containerization)
|
This is a **vendored copy** of [apple/containerization](https://github.com/apple/containerization)
|
||||||
at upstream commit `6b7b42ca3efeee8c706070e4355e6a807c5336ae`, referenced by the root `Package.swift`
|
at upstream commit `6b7b42ca3efeee8c706070e4355e6a807c5336ae`, referenced by the root `Package.swift`
|
||||||
via `.package(path: "third_party/containerization")` instead of the github URL.
|
via `.package(path: "third_party/containerization")` instead of the github URL.
|
||||||
|
|||||||
Reference in New Issue
Block a user