Files
Joel Hooks cf55d75613 feat: one-shot microVM exec model — close the host↔guest gap
Fundamental fix: previous execInMicroVm used a poll-based protocol where
host wrote to a shared directory and polled for results. But Firecracker
uses virtio-block devices (not shared directories), so host and guest
can't simultaneously access the same filesystem without page cache issues.

New model (Lambda-style):
1. Host creates workspace ext4 image (64MB)
2. Host loop-mounts it, writes command.sh + request.json, unmounts
3. Host boots Firecracker VM with workspace as /dev/vdb
4. Guest-runner (one-shot) mounts /dev/vdb, executes command, writes
   result.json, powers off the VM
5. Host waits for VM process to exit
6. Host loop-mounts workspace, reads result.json, unmounts
7. Clean up

Changes:
- guest-runner.sh: converted from polling daemon to one-shot executor
  that halts the VM after writing results
- microvm.ts execInMicroVm: complete rewrite for sequential model with
  createWorkspaceImage, mountExt4, unmountExt4 helpers
- dag-orchestrator.ts executeMicroVm: simplified — no longer manages
  boot/destroy lifecycle, delegates to one-shot execInMicroVm

All existing tests pass. Rootfs rebuilt and deployed to PVC.
2026-03-17 08:32:09 -07:00
..