Files
Michael Crosby b438e97b93 Add cloud-hypervisor VMM backend for Linux hosts (#782)
apple/containerization currently runs containers in per-container VMs on
macOS hosts via Virtualization.framework. This adds a second VMM backend
so the same Swift orchestration layer (LinuxContainer / LinuxPod /
Vminitd gRPC contract) runs on Linux hosts via cloud-hypervisor + KVM.

**CloudHypervisor Swift package** (`Sources/CloudHypervisor/`) — a thin
client for cloud-hypervisor's REST-over-UDS API, layered on
AsyncHTTPClient. Endpoints cover VMM / VM lifecycle / hotplug (disk, fs,
net, vsock, remove-device). Cross-platform (compiles on macOS for unit
tests; consumed at runtime only by the Linux side of Containerization).

**CH backend in Containerization** — one cloud-hypervisor subprocess per
VM, gated behind `#if os(Linux)`. CHVirtualMachineManager /
CHVirtualMachineInstance mirror the VZ shape behind the existing
VirtualMachineManager / VirtualMachineInstance protocol. CHProcess and
VirtiofsdProcess manage the binaries; CHHotplugProvider handles
virtio-blk and virtio-fs runtime hotplug (with one virtiofsd per unique
source-hash tag, refcounted across containers).

**Linux host networking** — BridgeManager brings up a Linux bridge with
an IPv4 subnet and (opt-in via `--enable-nat`) iptables MASQUERADE +
scoped FORWARD rules. LinuxBridgedNetwork enslaves a fresh TAP per
container to the bridge. State is recorded under `/run/containerization`
so `cctl bridge delete` reverses exactly what create did. Bridge
teardown verifies the link kind via sysfs to refuse deleting non-bridge
interfaces.

**cctl run / bridge** — end-to-end Linux container run path (image pull,
ext4 rootfs assembly, VM boot, container exec) plus `cctl bridge
create|delete` for the host network plumbing.

**Build & dist** — `make linux-build` / `make linux-integration` build
and exercise the host side inside an apple/container `--virtualization`
dev container. `make dist-x86_64` produces a deployment tarball (cctl +
cloud-hypervisor + virtiofsd + initfs + kernel) cross-compiled from the
aarch64 dev container; pipeline documented in `docs/x86_64-build.md`.
Static-musl C deps and the Zig cross compiler are pinned by SHA256.

The host orchestrator runs as root. Per-VM runtime state lives under
`/run/containerization/ch/<UUID>` with mode 0700; UDS sockets inside are
bound with mode 0600. Vminitd's gRPC channel inherits that trust
boundary — socket-file perms are the auth.

Sandbox flags are upstream-secure by default. Two per-component opt-outs
exist for the apple/container dev-container case (where the host seccomp
profile SIGSYS-kills CH and virtiofsd):
- `CONTAINERIZATION_NO_CH_SECCOMP=1` — `cloud-hypervisor --seccomp
false`.
- `CONTAINERIZATION_NO_VIRTIOFSD_SANDBOX=1` — `virtiofsd --sandbox
none`. Each emits a one-shot `logger.warning` at process start. Legacy
alias `CONTAINERIZATION_RELAXED_SANDBOX=1` flips both. cctl spawns both
binaries with `setsid` and a minimal env allowlist (PATH / HOME /
RUST_LOG / RUST_BACKTRACE) so the parent's secrets don't leak to
children.

`make linux-integration` runs the cross-platform integration suite
against a real cloud-hypervisor VM inside the dev container. Linux runs
the cross-platform subset (`process true`/`false`/`echo hi`, virtiofs
round-trip, hotplug); the macOS suite is unchanged.

Signed-off-by: michael_crosby <michael_crosby@apple.com>
2026-07-02 11:20:22 -04:00

156 lines
5.3 KiB
Swift

//===----------------------------------------------------------------------===//
// Copyright © 2026 Apple Inc. and the Containerization project authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// https://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//===----------------------------------------------------------------------===//
#if os(Linux)
import CShim
import ContainerizationError
import ContainerizationExtras
import ContainerizationNetlink
import Foundation
import Synchronization
#if canImport(Musl)
import Musl
let osClose = Musl.close
#elseif canImport(Glibc)
import Glibc
let osClose = Glibc.close
#endif
/// A Linux TAP network device whose kernel interface lives only as long as
/// this `TAPDevice` instance. Created via `/dev/net/tun` + `ioctl(TUNSETIFF)`,
/// optionally enslaved to a pre-existing bridge, with MTU/MAC/UP applied via
/// netlink. The fd is held internally; closing it (explicitly or via deinit)
/// removes the interface from the kernel.
///
/// `TUNSETPERSIST` is never called, so process death also cleans up the
/// device automatically. Cloud-hypervisor opens the same TAP **by name**;
/// the held fd keeps the interface alive across CH's open/close cycle.
///
/// Requires `CAP_NET_ADMIN`.
public final class TAPDevice: Sendable {
/// The kernel-resolved interface name. May differ from the `name`
/// parameter passed to `init` if the kernel substituted one (e.g. when
/// `nil` was passed and the kernel picked `tapN`).
public let name: String
public let mtu: UInt32
/// The MAC address as set on init, or nil if the kernel auto-assigned one.
/// Not read back from the kernel.
public let macAddress: MACAddress?
private let _fd: Mutex<Int32?>
/// Create a TAP device.
///
/// - Parameters:
/// - name: Desired interface name. Empty or nil = kernel picks (`tap%d`).
/// Length must be < 16 (`IFNAMSIZ - 1`).
/// - bridge: Name of an existing bridge to enslave the TAP to, or nil.
/// - mtu: MTU in bytes (default 1500).
/// - macAddress: Hardware address to set, or nil to leave kernel default.
public init(
name: String? = nil,
bridge: String? = nil,
mtu: UInt32 = 1500,
macAddress: MACAddress? = nil
) throws {
if let n = name, n.utf8.count >= 16 {
throw ContainerizationError(
.invalidArgument,
message: "TAP name too long: \(n) (must be < 16 chars)"
)
}
// 1. Open + TUNSETIFF via CShim. Returns fd on success, -errno on failure.
var resolved = [CChar](repeating: 0, count: 16)
let fd: Int32 = resolved.withUnsafeMutableBufferPointer { buf in
(name ?? "").withCString { reqPtr in
cz_tap_create(reqPtr, buf.baseAddress, 16)
}
}
guard fd >= 0 else {
throw ContainerizationError(
.internalError,
message: "cz_tap_create failed: errno=\(-fd)"
)
}
// From here on, any failure must close `fd` to release the kernel iface.
var fdToClean: Int32? = fd
defer {
if let f = fdToClean {
_ = osClose(f)
}
}
let resolvedName: String = resolved.withUnsafeBufferPointer { buf in
// String(cString:) is deprecated in newer toolchains. Build the
// String from the NUL-terminated UTF-8 bytes directly.
let bytes = buf.prefix(while: { $0 != 0 }).map { UInt8(bitPattern: $0) }
return String(decoding: bytes, as: UTF8.self)
}
// 2. Apply MAC and master via netlink (single RTM_NEWLINK).
let session = try NetlinkSession(socket: DefaultNetlinkSocket())
do {
try session.linkSetAttributes(
interface: resolvedName,
macAddress: macAddress,
master: bridge
)
} catch {
throw ContainerizationError(
.internalError,
message: "linkSetAttributes failed for \(resolvedName): \(error)"
)
}
// 3. Bring UP and set MTU.
do {
try session.linkSet(interface: resolvedName, up: true, mtu: mtu)
} catch {
throw ContainerizationError(
.internalError,
message: "linkSet(up:mtu:) failed for \(resolvedName): \(error)"
)
}
// 4. Success — store and clear cleanup.
self.name = resolvedName
self.mtu = mtu
self.macAddress = macAddress
self._fd = Mutex(fd)
fdToClean = nil
}
/// Close the held fd, removing the interface from the kernel. Idempotent.
public func close() {
_fd.withLock { fd in
if let f = fd {
_ = osClose(f)
fd = nil
}
}
}
deinit {
close()
}
}
#endif