Skip to content

Forward restorer build configuration when constructing a sandbox from a snapshot #337

Description

@simongdavies

Blocked by: hyperlight-dev/hyperlight#1862

Problem

hyperlight_js::SandboxBuilder stores Hyperlight construction settings in a SandboxConfiguration.

For a fresh sandbox, build() forwards that complete configuration to Hyperlight:

ProtoJSSandbox::new(
    guest_binary,
    Some(self.config),
    self.host_print_fn,
)

The persistent snapshot path does not:

pub fn build_from_snapshot(
    self,
    snapshot: Snapshot,
) -> Result<ProtoJSSandbox> {
    ProtoJSSandbox::from_snapshot(
        snapshot,
        self.host_print_fn,
    )
}

self.config is discarded.

ProtoJSSandbox::from_snapshot() creates a private hyperlight_host::SandboxBuilder::from_snapshot() using Hyperlight defaults. The eventual MultiUseSandbox is not created until restore_js_sandbox() or restore_loaded_sandbox(), but ProtoJSSandbox does not expose configuration methods for the private upstream builder.

Consequently, callers have no opportunity to reapply immutable construction settings before restoration completes.

Affected settings, where supported by the target and enabled features, include:

  • VCPU interrupt signal offset
  • Interrupt retry delay
  • Per-sandbox crashdump enablement
  • GDB configuration

After the restored MultiUseSandbox has been created, these settings cannot be changed.

Host print callbacks are not affected because they are stored and forwarded separately. Host functions are also re-registered before the upstream snapshot builder is built.

Heap, scratch, and transport geometry are snapshot-owned and should continue to come from the snapshot.

Proposed change

After the upstream API in hyperlight-dev/hyperlight#1862 is available, forward the existing configuration through the snapshot construction path:

pub fn build_from_snapshot(
    self,
    snapshot: Snapshot,
) -> Result<ProtoJSSandbox> {
    ProtoJSSandbox::from_snapshot(
        snapshot,
        self.config,
        self.host_print_fn,
    )
}

ProtoJSSandbox::from_snapshot() should apply it to the upstream builder:

let mut builder =
    HyperlightSandboxBuilder::from_snapshot(snapshot.inner())
        .sandbox_configuration(config);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions