Blocked by: hyperlight-dev/hyperlight#1862
Problem
hyperlight_js::SandboxBuilder stores Hyperlight construction settings in a SandboxConfiguration.
For a fresh sandbox, build() forwards that complete configuration to Hyperlight:
ProtoJSSandbox::new(
guest_binary,
Some(self.config),
self.host_print_fn,
)
The persistent snapshot path does not:
pub fn build_from_snapshot(
self,
snapshot: Snapshot,
) -> Result<ProtoJSSandbox> {
ProtoJSSandbox::from_snapshot(
snapshot,
self.host_print_fn,
)
}
self.config is discarded.
ProtoJSSandbox::from_snapshot() creates a private hyperlight_host::SandboxBuilder::from_snapshot() using Hyperlight defaults. The eventual MultiUseSandbox is not created until restore_js_sandbox() or restore_loaded_sandbox(), but ProtoJSSandbox does not expose configuration methods for the private upstream builder.
Consequently, callers have no opportunity to reapply immutable construction settings before restoration completes.
Affected settings, where supported by the target and enabled features, include:
- VCPU interrupt signal offset
- Interrupt retry delay
- Per-sandbox crashdump enablement
- GDB configuration
After the restored MultiUseSandbox has been created, these settings cannot be changed.
Host print callbacks are not affected because they are stored and forwarded separately. Host functions are also re-registered before the upstream snapshot builder is built.
Heap, scratch, and transport geometry are snapshot-owned and should continue to come from the snapshot.
Proposed change
After the upstream API in hyperlight-dev/hyperlight#1862 is available, forward the existing configuration through the snapshot construction path:
pub fn build_from_snapshot(
self,
snapshot: Snapshot,
) -> Result<ProtoJSSandbox> {
ProtoJSSandbox::from_snapshot(
snapshot,
self.config,
self.host_print_fn,
)
}
ProtoJSSandbox::from_snapshot() should apply it to the upstream builder:
let mut builder =
HyperlightSandboxBuilder::from_snapshot(snapshot.inner())
.sandbox_configuration(config);
Blocked by: hyperlight-dev/hyperlight#1862
Problem
hyperlight_js::SandboxBuilderstores Hyperlight construction settings in aSandboxConfiguration.For a fresh sandbox,
build()forwards that complete configuration to Hyperlight:The persistent snapshot path does not:
self.configis discarded.ProtoJSSandbox::from_snapshot()creates a privatehyperlight_host::SandboxBuilder::from_snapshot()using Hyperlight defaults. The eventualMultiUseSandboxis not created untilrestore_js_sandbox()orrestore_loaded_sandbox(), butProtoJSSandboxdoes not expose configuration methods for the private upstream builder.Consequently, callers have no opportunity to reapply immutable construction settings before restoration completes.
Affected settings, where supported by the target and enabled features, include:
After the restored
MultiUseSandboxhas been created, these settings cannot be changed.Host print callbacks are not affected because they are stored and forwarded separately. Host functions are also re-registered before the upstream snapshot builder is built.
Heap, scratch, and transport geometry are snapshot-owned and should continue to come from the snapshot.
Proposed change
After the upstream API in hyperlight-dev/hyperlight#1862 is available, forward the existing configuration through the snapshot construction path:
ProtoJSSandbox::from_snapshot()should apply it to the upstream builder: