Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

PPN architecture overview

← All revisions

b7f09af0 · PointSav Digital Systems ·

editorial(infrastructure): fix ppn-architecture-overview hypervisor/port claims (Track-B) — re-verified os-infrastructure has zero resource-pooling code, os-orchestration is still a 2-line scaffold, real command-broadcast port is 9206 not 8090; de-narrated, fixed missing index_group (compute-and-vm-fabric); EN+ES

View the full record as of this revision →

@@ -4,6 +4,7 @@ title: "PPN architecture overview"
slug: ppn-architecture-overview
short_description: "Physical infrastructure plane of the PointSav stack, enrolling nodes into a cryptographically authenticated mesh and hosting the fleet's virtual machines."
category: infrastructure
index_group: compute-and-vm-fabric
type: topic
content_type: topic
status: active
@@ -26,7 +27,7 @@ The operator layer is where a human administrator interacts with the fleet.

**`os-network-admin`** is the Foundation OS layer — the control plane for the PPN mesh. It runs on the operator's machine (bare metal or LXC container), manages peer-map distribution, and enforces the Diode rules that restrict command flow. It holds zero cryptographic authority: it cannot read archive data, it cannot approve data access, and it cannot issue identity credentials. Its role is to know which physical nodes are on the mesh and to enforce that membership — nothing more.

**`app-network-admin`** is the F8 Terminal interface that runs on top of `os-network-admin`. It accepts plain-language operator intent at HTTP port 8085, routes it through `service-slm` to produce an authorised 16-byte binary command, and broadcasts that command over UDP port 8090 to the mesh.
**`app-network-admin`** is the F8 Terminal interface. It accepts plain-language operator intent at HTTP port 8085, routes it through `service-slm` to produce an authorised 16-byte binary command, and broadcasts that command over UDP port 9206 to the mesh. `os-network-admin` itself is a separate, minimal node-join pairing-approval poller — it carries no mesh-broadcast logic of its own.

See: [[os-network-admin]], [[ppn-command-protocol]]

@@ -44,7 +45,7 @@ The **[[genesis-protocol]]** governs first boot: a node generates its keypair fr

The hypervisor layer is the compute substrate.

**`os-infrastructure`** is the hypervisor layer that hosts the virtual machines running Totebox Archives and orchestration gateways (QEMU/KVM-hosted today; **intended** to become a bare-metal Type-I hypervisor under NetBSD/NVMM in Phase 2 and seL4/Microkit in Phase 3). It manages a **per-node resource pool**: memory via `virtio_balloon` (inflation reclaims guest RAM into the node pool; deflation returns it) and CPU via cgroups v2 `cpu.weight` per QEMU process. (Correction, 2026-08-02, verified against canonical `origin/main`: no `virtio_balloon` or cgroups/`cpu.weight` code exists anywhere in `os-infrastructure` or `service-vm-fleet` — real `os-infrastructure/src/main.rs` is a bare-metal Multiboot2 boot stub doing framebuffer text + mDNS genesis handshake, with zero resource-pooling logic. Separately, `os-orchestration` — described elsewhere in this article as a stateless aggregator — is a 2-line placeholder scaffold on canonical, matching the finding on [[os-orchestration-stateless-hub]]. Flagged, not resolved.)
**`os-infrastructure`** is the planned hypervisor layer, intended to host the virtual machines running Totebox Archives and orchestration gateways (QEMU/KVM to start; a bare-metal Type-I hypervisor under NetBSD/NVMM in Phase 2, seL4/Microkit in Phase 3). It is designed to manage a **per-node resource pool** — memory via `virtio_balloon`, CPU via cgroups v2 `cpu.weight` per QEMU process — but neither mechanism is built yet: the real `os-infrastructure` boot code is a bare-metal Multiboot2 stub doing framebuffer text output and an mDNS genesis handshake, with no resource-pooling logic. `os-orchestration`, described elsewhere in this article as a stateless aggregator, is similarly a 2-line placeholder scaffold today, not a running system.

The pool is bounded to the physical node. Cross-node workload placement is the Totebox Orchestration layer's responsibility; once a VM is placed on a node, the hypervisor manages its local resource allocation.

@@ -96,7 +97,7 @@ This separation is intentional: the network control plane and the data access pl

- [[sovereign-mesh]] — WireGuard overlay, 16-byte binary command protocol, hub-spoke topology
- [[genesis-protocol]] — autonomous first-boot bootstrap sequence, deferred fleet assembly
- [[ppn-command-protocol]] — the 16-byte binary wire format broadcast over UDP port 8090
- [[ppn-command-protocol]] — the 16-byte binary wire format broadcast over UDP port 9206
- [[service-pointsav-link]] — hot-pluggable adapter connecting os-* nodes to the fleet
- [[os-network-admin]] — Foundation OS layer, zero crypto authority, node-join ceremony
- [[ppn-hypervisor-resource-pool]] — per-node virtio_balloon + vCPU scheduling
Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →