Repository navigation
doc: add the managed sandbox lifecycle to the responsibility map - #482
Merged
Pedro Henrique Penna (ppenna) merged 1 commit intoOct 10, 2026
Merged
Conversation
The component responsibility map named the NVX sandbox launcher and the aci_edge_sandboxes backends but not the NVX CLI's managed sandbox lifecycle, which #476 made serialize its transitions per state directory. Assign its state, fail-closed transitions, per-start control capability, and OpenVMM process identification to that component. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Pedro Henrique Penna (ppenna)
October 10, 2026 20:05
View session
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The documentation accurately reflects the implemented lifecycle and concurrency contracts.
0 open findings
What changed in this PR
Adds the NVX CLI’s managed sandbox lifecycle to the component responsibility map.
Changes:
- Documents lifecycle state, serialization, fail-closed behavior, process identity, and control-session ownership.
| File | Description |
|---|---|
doc/design/code-ownership-map.md |
Adds the managed sandbox lifecycle responsibility row. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Pedro Henrique Penna (ppenna)
deleted the
doc-sync/ownership-map-sandbox-lifecycle
branch
October 10, 2026 20:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The component responsibility map assigns each design area to a component, but it had no row for the NVX CLI's managed
sandboxlifecycle (provision,start,exec,stop,deprovision). It named the one-shot sandbox launcher and theaci_edge_sandboxesbackends only. #476 recently changed this component to serialize its transitions per state directory, so the map now omits a component with its own concurrency contract. This PR adds one row for it.Changes
doc/design/code-ownership-map.md: adds the row "Managedsandboxlifecycle of the NVX CLI", owned by "NVX managed sandbox lifecycle and its control-session client". Each claim in the row is checked againstscripts/nvx_tools/sandbox_lifecycle.pyatorigin/dev033abe2:provisionrefuses an existing configuration or runtime record._startrefuses any leftover runtime file.execandstoprequire a live process through_load_running.deprovisionrefuses a running sandbox or runtime files that no record covers.provision,start,stop, anddeprovisiontake effect one at a time per sandbox, andexecruns alongside them_LifecycleLock(state_dir, ...).exec_workloaddoes not take the lock.doc/run.md"Managed lifecycle" describes the same behavior._startcreatessecrets.token_bytes(32), writes it to the capability pipe on OpenVMM's stdin, and passes--microvm-control-auth-stdin.pidandstart_time, and_process_runningcompares both.startpings overControlSession, andexecandstopuse the same client.The row names components and behavior only. Following the chapter's rule, it doesn't list files or functions.
Pinned OpenVMM:
7bf0ee28b826374a2d386067df0456b81bcae818. The new row describes NVX-side behavior, and the OpenVMM-side control-session broker row is unchanged.Follow-ups (out of scope)
doc/project-structure.mddoes not listscripts/nvx_tools/host_telemetry.py(added in ci: record benchmark host provenance and storage telemetry #479) in the tooling tree or thescripts/prose.unittest_results.txt, has been tracked at the repository root since the initial commit. It looks accidental. Removing it is not a Markdown change, so this PR leaves it alone.scripts/setup/README.mdis documentation outsidedoc/. It was not relocated becausescripts/test_tool_versions.pyreads it andscripts/setup/tool-versions.confrefers to it, so moving it would require code changes.doc/ci.md,run.md,usage.md,setup.md,benchmarks.md, the upstream roadmap, and several design chapters. Those files were not reviewed for edits in this run.Validation
python -m unittest scripts.test_nvx_tools.CliTests scripts.test_performance.PerformanceTests: 117 tests, OK (1 skipped).doc/design.mdlinks every chapter indoc/design/. Result: OK.git diff --check: clean.python scripts\nvx.py verify: source tree and submodule metadata are consistent. The submodule HEAD equals the pinned gitlink7bf0ee28.doc/and 1 added line, with no code, workflow,data/, or gitlink changes.