b438e97b93
apple/containerization currently runs containers in per-container VMs on macOS hosts via Virtualization.framework. This adds a second VMM backend so the same Swift orchestration layer (LinuxContainer / LinuxPod / Vminitd gRPC contract) runs on Linux hosts via cloud-hypervisor + KVM. **CloudHypervisor Swift package** (`Sources/CloudHypervisor/`) — a thin client for cloud-hypervisor's REST-over-UDS API, layered on AsyncHTTPClient. Endpoints cover VMM / VM lifecycle / hotplug (disk, fs, net, vsock, remove-device). Cross-platform (compiles on macOS for unit tests; consumed at runtime only by the Linux side of Containerization). **CH backend in Containerization** — one cloud-hypervisor subprocess per VM, gated behind `#if os(Linux)`. CHVirtualMachineManager / CHVirtualMachineInstance mirror the VZ shape behind the existing VirtualMachineManager / VirtualMachineInstance protocol. CHProcess and VirtiofsdProcess manage the binaries; CHHotplugProvider handles virtio-blk and virtio-fs runtime hotplug (with one virtiofsd per unique source-hash tag, refcounted across containers). **Linux host networking** — BridgeManager brings up a Linux bridge with an IPv4 subnet and (opt-in via `--enable-nat`) iptables MASQUERADE + scoped FORWARD rules. LinuxBridgedNetwork enslaves a fresh TAP per container to the bridge. State is recorded under `/run/containerization` so `cctl bridge delete` reverses exactly what create did. Bridge teardown verifies the link kind via sysfs to refuse deleting non-bridge interfaces. **cctl run / bridge** — end-to-end Linux container run path (image pull, ext4 rootfs assembly, VM boot, container exec) plus `cctl bridge create|delete` for the host network plumbing. **Build & dist** — `make linux-build` / `make linux-integration` build and exercise the host side inside an apple/container `--virtualization` dev container. `make dist-x86_64` produces a deployment tarball (cctl + cloud-hypervisor + virtiofsd + initfs + kernel) cross-compiled from the aarch64 dev container; pipeline documented in `docs/x86_64-build.md`. Static-musl C deps and the Zig cross compiler are pinned by SHA256. The host orchestrator runs as root. Per-VM runtime state lives under `/run/containerization/ch/<UUID>` with mode 0700; UDS sockets inside are bound with mode 0600. Vminitd's gRPC channel inherits that trust boundary — socket-file perms are the auth. Sandbox flags are upstream-secure by default. Two per-component opt-outs exist for the apple/container dev-container case (where the host seccomp profile SIGSYS-kills CH and virtiofsd): - `CONTAINERIZATION_NO_CH_SECCOMP=1` — `cloud-hypervisor --seccomp false`. - `CONTAINERIZATION_NO_VIRTIOFSD_SANDBOX=1` — `virtiofsd --sandbox none`. Each emits a one-shot `logger.warning` at process start. Legacy alias `CONTAINERIZATION_RELAXED_SANDBOX=1` flips both. cctl spawns both binaries with `setsid` and a minimal env allowlist (PATH / HOME / RUST_LOG / RUST_BACKTRACE) so the parent's secrets don't leak to children. `make linux-integration` runs the cross-platform integration suite against a real cloud-hypervisor VM inside the dev container. Linux runs the cross-platform subset (`process true`/`false`/`echo hi`, virtiofs round-trip, hotplug); the macOS suite is unchanged. Signed-off-by: michael_crosby <michael_crosby@apple.com>
69 lines
3.0 KiB
Swift
69 lines
3.0 KiB
Swift
//===----------------------------------------------------------------------===//
|
|
// Copyright © 2026 Apple Inc. and the Containerization project authors.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// https://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
import Foundation
|
|
|
|
/// Reads the host's default IPv4 egress interface from `/proc/net/route`.
|
|
///
|
|
/// `/proc/net/route` columns (tab-separated):
|
|
///
|
|
/// Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT
|
|
///
|
|
/// Numeric fields are hex with bytes in network order (so `0102A8C0` is
|
|
/// `192.168.2.1`). Pure-string parsing keeps this cross-platform-testable
|
|
/// even though `/proc/net/route` itself only exists on Linux.
|
|
enum HostDefaultRoute {
|
|
/// `RTF_GATEWAY` from `<linux/route.h>`. Set on rows representing a gateway route.
|
|
private static let RTF_GATEWAY: UInt32 = 0x0002
|
|
|
|
/// Parse the contents of `/proc/net/route` and return the iface for the
|
|
/// default route (destination 0.0.0.0 with `RTF_GATEWAY`). When multiple
|
|
/// default routes exist, the one with the lowest metric wins.
|
|
static func parseEgress(procNetRoute contents: String) -> String? {
|
|
var best: (iface: String, metric: UInt64)?
|
|
for (i, line) in contents.split(separator: "\n", omittingEmptySubsequences: true).enumerated() {
|
|
if i == 0 { continue } // header
|
|
let cols = line.split(separator: "\t", omittingEmptySubsequences: false)
|
|
.map { $0.trimmingCharacters(in: .whitespaces) }
|
|
guard cols.count >= 11 else { continue }
|
|
let iface = String(cols[0])
|
|
let destination = cols[1]
|
|
let flagsHex = cols[3]
|
|
let metricStr = cols[6]
|
|
|
|
guard destination == "00000000" else { continue }
|
|
guard let flags = UInt32(flagsHex, radix: 16),
|
|
flags & RTF_GATEWAY != 0
|
|
else { continue }
|
|
let metric = UInt64(metricStr) ?? UInt64.max
|
|
if let current = best, metric >= current.metric {
|
|
continue
|
|
}
|
|
best = (iface, metric)
|
|
}
|
|
return best?.iface
|
|
}
|
|
|
|
/// Read `/proc/net/route` and return the default-route iface, or nil if
|
|
/// the file is missing or no default route exists.
|
|
static func currentEgress() -> String? {
|
|
guard let contents = try? String(contentsOfFile: "/proc/net/route", encoding: .utf8) else {
|
|
return nil
|
|
}
|
|
return parseEgress(procNetRoute: contents)
|
|
}
|
|
}
|