firecracker-microvm / firecracker-microvm/firecracker-go-sdk

Difficult to override default firecracker command runner when not using jailer

Open
#605 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
672
Forks
166
PR merge metrics
No merged PRs in 30d

Description

I tried temporarily disabling jailer to try and debug an issue that I suspect might have been related to running firecracker under jailer.

When not using jailer, the default firecracker command runner sets stdin, stdout, stderr to os.Stdin, os.Stdout, os.Stderr respectively. I didn't want that behavior (especially stdin), because I'm running several VMs at once from the same go binary. So I tried to override it.

However, I discovered that the SDK makes it difficult to override these. The default firecracker command is set here: https://github.com/firecracker-microvm/firecracker-go-sdk/blob/e5e3dea5d1ee406faae110b72c9447c843b0348a/machine.go#L384

Note, it uses a private function, `configureBuilder`: https://github.com/firecracker-microvm/firecracker-go-sdk/blob/e5e3dea5d1ee406faae110b72c9447c843b0348a/machine.go#L352-L357

At first glance, that function seems small enough to just copy. However, it references this private `seccompArgs` function, which would also need to be copied: https://github.com/firecracker-microvm/firecracker-go-sdk/blob/e5e3dea5d1ee406faae110b72c9447c843b0348a/machine.go#L342-L350

I think maybe a better alternative to `WithProcessRunner` in this case could be to have a function like `WithCommandModifier(defaultBuilder VMCommandBuilder) VMCommandBuilder` that allows modifying the default command builder, instead of just the `WithProcessRunner(cmd *exec.Command)` which requires code-copying from the SDK.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.