- Use direct host bind mounts for durable directories in gVisor
containers instead of internal overlay filestores.
- Move tarutil into internal/tarutil so it can be shared across ateom
packages.
- Archive durable directory bind mounts into durable-dir.tar on full and
data checkpoints (replacing runsc fscheckpoint).
- On restore, unpack durable-dir.tar into the host bind mount before
starting/restoring containers.
- Support SNAPSHOT_SCOPE_DATA_ON_GOLDEN in ateom-gvisor, combining
golden guest state with latest actor durable data.
- Allow atelet to narrow full gVisor captures to durable-dir.tar for
data snapshots.
- Remove CEL validation disallowing onResume.fromData: Golden for
gVisor, and enable combined restore demo tests for gVisor.
Fixes#451
This PR addresses the cold-start timeout issue reported in #811 by
driving down the decompression/extraction cost of gVisor release
archives on nodes, adding structured logging, and supporting context
cancellation during extraction.
* Ran unit tests locally: `go test -v ./cmd/atelet/... -run
TestExtractTarArchive` (PASS).
* Benchmarked extraction formats (Bzip2: 19.05s baseline vs Gzip: 1.50s
vs Uncompressed Tar: 0.25s).