Execution timeouts without running in a separate thread
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- cpp, linux
- Domain
- operating-systems, performance, security
Research direction
Start by inspecting the existing virtual-hardware timer approach and the KVM guest execution path; the issue does not name specific files or tests. Investigate whether setitimer/SIGALRM or a signal handler can safely interrupt same-thread execution, and define done through reliable timeout behavior and latency measurements.
Written by the indexing model from the issue text.
Description
Just a thought after reading your excellent paper:
No matter which sandbox solution you chose, you will probably run the sandbox in a separate thread in order to have execution timeouts. Therefore, there will be overhead related to thread communication in most solutions. This latency will usually be approximately the same whether you run TinyKVM, V8 or wasmtime,
This isn't strictly accurate:
-
Wasmtime has a timeout mechanism that makes running on the same thread safe: https://docs.rs/wasmtime/latest/wasmtime/struct.Config.html#method.epoch_interruption
-
While with V8 one could avoid the thread communication overhead by running on the main thread and calling
v8::Isolate::TerminateExecution()with a timer from a watchdog thread. https://v8.github.io/api/head/classv8_1_1Isolate.html#ad212b2e0b66ff5d586cd79cfa0b555fb
So I wonder if TinyKVM implement a similar mechanism and I see you have already explored setting a timer in the virtual hardware here but found it to be slow. https://stackoverflow.com/questions/68590696/timeout-for-kvm-userspace-guest)
As I understand it an interrupt will cause a VMExit which will return control back to the VMM. This suggests installing a no-op signal handler on the thread running the kvm guest will give back control: https://gist.github.com/mcastelino/df7e65ade874f6890f618dc51778d83a
Perhaps this could even just be set with setitimer or SIGALRM so you wouldn't need a watchdog thread.
Of course for most many cases using a thread pool will still be desirable but the lower latency of running in thread like this could be useful for sandboxing routing logic where the thread switching overhead might be noticeable.
- Dominant language
- C++
- Stars
- 823
- Forks
- 23
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from varnish/tinykvm
-
dup2 registers the stale fd instead of the dup() result, leaking a host fd per callPossibly taken A pull request linked to this issue is open or already merged. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
[tracking] ARM64: 6 static-audit candidates needing an AArch64 host to confirm or killMay be free again @perbu claimed this 69 days ago, and no pull request is open. Openhelp wanted
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 76/100
-
ELF loader: section/symbol header fields used as offsets without validation against binary.size()Openbug
Difficulty 5/5 Over a week Newbie friendliness 38/100
Similar issues
-
new contributor
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
OpenMS/OpenMS#10512 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
mesonbuild/wrapdb#2961 ·
Maintainers usually reply within 1 day
-
80 Instance - Raid - Northrend
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
azerothcore/azerothcore-wotlk#28075 ·
Maintainers usually reply within 1 day
-
SCA cis_ubuntu24-04 35664 / cis_ubuntu26-04 41664 "Ensure sudo log file exists": sudoers.d rule is missing the r: prefix, so it can never matchPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
MrNeRF/LichtFeld-Studio#3205 ·
Maintainers usually reply within 1 day