Skip to content

v0.14.1

Choose a tag to compare

@github-actions github-actions released this 23 Sep 04:31
· 61 commits to main since this release
2b4790d

Added

  • --port all lets the guest bind any port and --port LOW-HIGH a range, next to single ports; the library gains ListenPorts::all() and ListenPorts::with_range. all is for a container runtime, whose network namespace already scopes what the guest exposes, the way docker run -P publishes every port.
  • hluk --version.
  • --resolv-conf FILE installs a resolver configuration as the guest's /etc/resolv.conf, at boot and again on a restore, so a snapshot resolves names where it now runs rather than where it was taken; the library has SandboxBuilder::resolv_conf. Without it the rootfs's own file stands, and options single-request is added unless present. Under an allow list, the file's nameservers are exempt on port 53 like the host's own. Kernel: the new GetResolvConf host function is read once the rootfs is mounted and on resume.

Changed

  • A restored guest gets the mounts the restore names: on resume the kernel fetches the host's mount table (the new GetMounts host function) and makes its own match, mounting what is new, unmounting what is gone and remounting an entry whose index or read-only flag changed. A warm snapshot saved without mounts serves any mount set, so an embedder restores it to run a script over host directories, and hluk snapshot run --mount mounts what it is given. hluk bench takes --mount, and the new mount workload measures a mounted restore. A mount kept busy by a file open across the snapshot stays until a restore finds it free, its operations failing with ESTALE meanwhile; a mount table is at most 32 mounts and 3.5 KiB of entries (MOUNTS_MAX, FSTAB_ENTRIES_MAX).
  • A snapshot is named by its release and a snapshot key, <release>-k<kernel>-c<contract>: the embedded kernel's hash and a host contract number, the two things a snapshot depends on. A load matches the key, so a release that changes neither keeps every saved snapshot; one that does refuses them with Error::SnapshotRelease, which names the release that saved the snapshot and says to save it again, in hluk snapshot run, hluk bench and the library alike. hluk snapshot key prints this build's key; SNAPSHOT_KEY is the library's. Snapshots from 0.14.0, named by release alone, are refused the same way.
  • The net_* host functions exist on every path, refusing every socket() with EACCES when there is no network policy (before, they were absent and a guest without a policy got EIO). So a snapshot saved under a policy restores without one, its sockets dying on resume, and a snapshot saved without a policy restores under one; before, the first failed the restore for the missing host functions.
  • The urunc demo image (demos/urunc, published as hello-urunc) bakes its workload at /app/hello.py and declares it as the image's CMD, so docker run needs no command after the image name and the driver's fallback entrypoint stays out of the image contract. Its greeting now names Hyperlight.

Fixed

  • connect(2) with AF_UNSPEC dissolves a datagram socket's association, as on Linux, instead of failing. glibc's getaddrinfo relies on it to probe every candidate of a dual-stack answer through one IPv6 socket, so a passive lookup -- socket.getaddrinfo(None, port, AF_UNSPEC, SOCK_STREAM, 0, AI_PASSIVE), what Python's http.server does to bind -- no longer aborts the guest with a glibc assertion on the source address. Kernel: hostsock forwards it as the new net_disconnect host function.
  • A script, --exec or --guest-exec on a rootfs with no runtime driver is an error that names --entry, instead of a guest that exits with status 0 having run nothing.