docs.rs failed to build oci-runner-0.1.7
Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
oci-runner
Rust library (oci_runner) and CLI (oci-runner) for running foreground containers with embedded libcontainer. There is no runc, crun, or podman executable required on $PATH.
- Linux: Executes containers in-process via a statically linked Go C-archive (
-buildmode=c-archive) with priority 101nsexecconstructor, custom seccomp filtering, and native Linux namespaces. - macOS: Boots a lightweight Linux guest through Apple's Virtualization framework and coordinates execution over virtio-vsock (port 5253).
- Other OSes: Links a lightweight stub returning
ErrorCode::Unsupported.
Installation
Add as a Library Dependency
[]
= "0.1"
Install CLI Binary
Rust Library Usage
[!IMPORTANT] On Linux,
startup()must be called at the very beginning ofmain(), before spawning threads, Tokio runtimes, or parsing CLI arguments.libcontainerre-executes/proc/self/exeinto namespaces to initialize the container.
use ;
Capturing Container Output
You can stream stdout and stderr via run_with:
use Arc;
let on_output = new;
let exit_code = runtime.run_with?;
CLI Usage
Check Host Prerequisites
Run a Container Rootfs
With custom flags:
Build Requirements
- Linux: Go ≥ 1.26, C compiler (
gccorclang),pkg-config, and optionallylibseccomp-dev. - macOS: Built-in Apple Virtualization framework. Codesigning is automatically handled via
.cargo/config.tomlwith thecom.apple.security.virtualizationentitlement.
Limitations
- Process Re-execution Hook: On Linux,
startup()must execute at the very entrypoint ofmain().libcontainerspawns container processes by re-executing/proc/self/exe. If called after Tokio runtimes, thread pools, or signal handlers are established, initialization hangs or aborts. - Foreground Execution Only:
oci-runneris designed for synchronous, foreground execution (runwaits for the container process to exit). It does not manage long-running background container daemons, detachment, or state persistence across host reboots. - Rootfs Preparation: Does not include an image puller or layer unpacker. The container rootfs directory must be unpacked and mounted prior to invoking
RunRequest::new(rootfs, ...). - Not a Complete OCI CLI:
oci-runnerimplementsdiagnoseandrun. It is not a drop-in replacement for the multi-command OCI runtime specification (create,start,kill,delete,state). - macOS Host Isolation: On macOS, containers run in a Linux Virtualization guest kernel. They do not share the host macOS kernel or network interfaces directly; host filesystems must be shared via virtiofs.
- Linux Privilege Requirements: In-process namespace isolation requires either
rootprivileges or unprivileged user namespace support enabled in the host kernel (/proc/sys/kernel/unprivileged_userns_clone = 1). Mounting certain filesystems or creating devices requires appropriate Linux capabilities. - Platform Support: Fully supported on Linux and macOS (Apple Silicon and x86_64). Other operating systems link a stub implementation that returns
ErrorCode::Unsupported.