group:member, or artifact path.
Guest writeback
Use.guest_flush(GuestFlush::Required) on snapshot, fork, or fork-many builders, or source.pause_with_guest_flush(GuestFlush::Required). Import GuestFlush from microsandbox::snapshot. The default Auto flushes live disk-only captures, but adds no optional flush to full captures, forks, or pause. Skip retains mandatory storage barriers. A paused disk capture needs a matching prior flush; cloud rejects non-Auto policies. See guest flush policy reference.
Static methods
Snapshot::builder()
from_sandbox(); see SnapshotBuilder for options.
Parameters
nameimpl Into<String>..Returns
Example
Example
Snapshot::create()
create() instead of constructing a SnapshotConfig by hand.
Parameters
configSnapshotConfigReturns
Example
Example
Snapshot::create_archive()
Example
Example
Snapshot::open()
Example
Example
group:member, or path. This is a fast metadata operation: it verifies the manifest structure, recomputes the manifest digest, and checks that the upper file exists with the recorded size. It does not read the full upper contents; use verify() for that.
For the local backend, relative artifact paths are resolved when the operation begins, and the returned snapshot retains that absolute location. Changing the process working directory later does not retarget an opened or listed snapshot. Local import, export, copy, and capture destinations are also resolved before asynchronous work starts. Group names and snapshot IDs continue to resolve through the snapshot store.
Parameters
path_or_nameimpl AsRef<str>group:member, or filesystem path to an artifact directory.Returns
Snapshot::open_ref()
SnapshotReference.
Use this when passing through a reference returned by another SDK operation;
it preserves whether the backend should resolve the value as an identifier or
a path.
Example
Example
Snapshot::get()
Example
Example
SnapshotHandle by group head, group:member, stable snapshot ID, descriptor digest, or artifact path. Global IDs and digests must resolve unambiguously.
Parameters
name_or_digest&strgroup:member, stable snapshot ID, descriptor digest, or artifact path.Returns
Snapshot::list()
Example
Example
Returns
Snapshot::list_dir()
snapshot.json) and malformed artifacts.
Parameters
dirimpl AsRef<Path>Returns
Snapshot::remove()
Example
Example
force is set. A group’s head cannot be removed while other members remain, even with force; select another head first.
Parameters
path_or_name&strgroup:member, unambiguous snapshot ID or digest, or artifact path.forcebooltrue, remove even if the snapshot has indexed children.Snapshot::remove_ref()
remove() when the value came from
Snapshot::reference() or SnapshotHandle::reference().
Snapshot::reindex()
dir.
Parameters
dirimpl AsRef<Path>Returns
Example
Example
Snapshot::reindex_default()
reindex() with the
local backend’s configured store and returns MicrosandboxError::Unsupported
on backends without a rebuildable artifact index.
Snapshot::save()
.msb archive (or plain .tar) at out. Recorded payload integrity is preserved but not executed implicitly; call verify() when an independent content scan is part of your workflow. See SaveOpts to also include ancestors and the OCI image cache.
Parameters
name_or_path&strgroup:member, or artifact path to save.out&PathoptsSaveOptsSaveOpts::default() writes the head snapshot only, zstd-compressed.Example
Example
Snapshot::load()
Example
Example
.msb or .tar, detected from magic bytes) into the snapshots directory (or dest), routing any bundled image-cache entries into the global cache and registering everything found in the index. Structural and archive-entry checks remain mandatory, while recorded payload integrity is preserved for explicit verify(). Returns a handle for the head snapshot.
Parameters
archive_path&PathdestOption<&Path>None uses the default snapshots directory.Returns
Example
Example
Instance methods
Methods on an openedSnapshot artifact.
Snapshot::load_with_base()
Snapshot::load_with_options()
Snapshot::load_many()
Snapshot::group_head()
group:member. Returns the group, previous and current snapshot IDs, reason, and whether the head changed. See group selection.
Import options
Options forLoadOpts.
Instance methods
snap.id()
snap_... identity. Copying, archiving, or relabeling the snapshot preserves this value.
snap.digest()
Returns
sha256:hex form.snap.reference()
Returns
snap.manifest()
Example
Example
Manifest: stable identity, state closure, capture provenance, pinned image, parent identity, and extensions. Mutable labels are exposed by labels() and are not part of this descriptor.
Returns
snap.size_bytes()
Returns
snap.path()
MicrosandboxError::Unsupported because managed and host-volume artifacts are
not paths on the client host. Use reference() for backend-neutral restore and
lifecycle operations.
snap.save_to()
MicrosandboxError::Unsupported.
snap.copy_to()
MicrosandboxError::Unsupported
when save() is awaited.
snap.verify()
Example
Example
NotRecorded without reading the payload when integrity is absent. Checkpoint state validates the root, manifests, disk layers, device/execution objects, and every referenced memory object, then returns the verified checkpoint root.
Returns
SnapshotHandle methods
Accessors and lifecycle on aSnapshotHandle returned by
the active backend. Returned by Snapshot::get(),
Snapshot::list(), and Snapshot::load().
h.digest()
sha256:hex), separate from the stable snapshot ID.
h.name()
None when no alias is recorded.
h.parent_digest()
None when no parent is known. The accessor retains its existing parent_digest name.
h.scope()
SnapshotScope::Disk for a disk-only snapshot or Full for disk plus VM execution state.
h.image_ref()
h.format()
Returns
Raw today).h.size_bytes()
h.path()
MicrosandboxError::Unsupported. Use reference() for backend-neutral restore
and lifecycle operations.
h.created_at()
h.open()
Example
Example
Returns
h.remove()
Example
Example
Parameters
forcebooltrue, remove even if the snapshot has indexed children.SnapshotBuilder
Builder for aSnapshotConfig. Obtained via Snapshot::builder(name). A source sandbox is required (from_sandbox); the other setters are optional. Every setter returns Self, so calls chain.
Example
Example
.from_sandbox()
build() and create() fail without it.
Parameters
source_sandboximpl Into<String>.group()
.dest_dir()
Parameters
dest_dirimpl Into<PathBuf>.label()
Parameters
keyimpl Into<String>valueimpl Into<String>.force()
.record_integrity()
verify() checks it explicitly; ordinary open, boot, save, load, and upgrade preserve the value without adding an independent payload pass.
snapshot_builder.full()
.guest_flush()
GuestFlush::Auto; see guest writeback.
.build()
SnapshotConfig without creating the snapshot. Errors with InvalidConfig if from_sandbox was not called. For capturing, use create instead; it calls build internally.
Returns
.create()
Snapshot::create(self.build()?).
Returns
SnapshotCopyBuilder
Returned bySnapshot::copy_to(). It reuses the source disk
data while replacing explicit-snapshot metadata in a new archive.
RestoreBuilder
Restore into a new detached sandbox. Disk boots fresh; full resumes execution. See restore examples and progress.Example
Example
allow_missing_resources() to resume with unavailable devices and warnings. This is separate from strict/relaxed validation of supplied mappings; inheritance does not waive missing backing. Root and owned storage remain required.
Destination options
Destination options
NetworkPolicy. Use |v| v.captured() for a private captured volume.Sandbox::restore_ref()
Snapshot or SnapshotHandle reference without reinterpreting an identifier as a path. This uses the same dedicated restore options and backend capability checks as Sandbox::restore().
Example
Example
h.snapshot()
SandboxHandle method. Snapshot this sandbox’s disk into its default group with the given member name. Use the returned artifact path or sandbox:member to open it later. Live captures are crash-consistent and preserve the source’s running/paused state. Local handles only. To place the artifact elsewhere, use Snapshot::save() / Snapshot::load() or move the self-contained artifact directory.
Parameters
name&strReturns
Example: capture under another group-store root
Example: capture under another group-store root
Compaction
Compact a local sandbox’s root or owned disks. See compaction for examples and recovery requirements.Options and results
Options and results
guest_path. materialized_bytes counts copied bytes, not reclaimed space. Times are microseconds: per-disk total_us covers preparation; aggregate total_us also includes switching; pause_us measures the shared VM pause.Types
SnapshotReference
A backend-neutral snapshot locator. Obtain one fromSnapshot::reference() or
SnapshotHandle::reference() and pass it to
Sandbox::restore_ref(), Snapshot::open_ref(), or
Snapshot::remove_ref(). This preserves whether a value is an identifier or a
path without exposing the selected backend.
SnapshotReference::auto(), id(), or path() to construct a reference.
value() returns the underlying string and kind() returns auto, id, or
path.
SnapshotHandle
Returned by Snapshot::get() · Snapshot::list() · Snapshot::load()
A lightweight handle returned by the active backend. Useopen() to
read the snapshot metadata. The handle retains its backend, so open() and
remove() work without the caller interpreting its storage location.
SnapshotConfig
Used by Snapshot::create() · returned by build()
Inputs to create a snapshot. A type alias forSnapshotSpec. Usually built via SnapshotBuilder rather than constructed directly.
SnapshotFormat
Used by format() · Manifest.format
On-disk format of the captured upper layer. Today onlyRaw is produced; the variant exists so qcow2 chains drop in later without a schema migration.
SnapshotScope
Used by scope() · Manifest.scope
Snapshot payload scope. Parsing accepts every known scope so older runtimes can still list and inspect artifacts they cannot restore; create and restore paths enforce support. Re-exported asmicrosandbox::snapshot::SnapshotScope.
SaveOpts
Used by Snapshot::save() and instance save_to() methods
Snapshot::save() and instance save_to() methods. Implements Default; SaveOpts::default() writes the head snapshot only, zstd-compressed.
SnapshotVerifyReport
Returned by verify()
Result of explicit snapshot verification.UpperVerifyStatus
Used by SnapshotVerifyReport.upper
Upper-layer content verification result.Manifest
Returned by manifest()
The snapshot artifact descriptor, serialized assnapshot.json (DESCRIPTOR_FILENAME) and re-exported as microsandbox::snapshot::Manifest. Its SHA-256 digest is computed over RFC 8785 canonical JSON. Stable lineage identity is the separate snapshot_id field.
ImageRef
Used by Manifest.image
Reference to the OCI image the snapshot was taken from. Re-exported asmicrosandbox::snapshot::ImageRef.
DiskLayer
Used by Manifest.upper
One member of the complete oldest-first file-layer closure. Re-exported asmicrosandbox::snapshot::DiskLayer; UpperLayer remains a source-compatibility alias.
UpperIntegrity
Used by DiskLayer.payload.integrity
Content integrity descriptor for the captured upper layer.