Expand description
Detcore is a Reverie tool that determinizes the execution of a process.
§Backend-abstraction commandment
Detcore is a tool written against Reverie’s abstract instrumentation
interface (the reverie crate). It depends only on those traits and types
and is deliberately ignorant of how a guest is actually traced.
Detcore MUST NEVER depend on or import a concrete Reverie backend or support
crate – any reverie-* crate other than the abstract reverie-core
interface. Choosing and instantiating a backend, and running a detcore tool
against it, is the sole responsibility of the hermit-cli package. There
are no backend-specific hacks in detcore: any tracing-mechanism-specific
behavior belongs behind the Reverie abstraction, not here.
Why: Hermit follows Reverie’s abstract model. A backend dependency in detcore would couple the determinism engine to one tracing mechanism and break the clean abstraction boundary that lets the same tool run over any backend.
The one allowed exception is test-only: detcore’s own integration tests
(under detcore/tests/, wired via the reverie-ptrace dev-dependency)
drive a real tracer to exercise the tool. That coupling never reaches the
shipped library. This invariant is enforced in CI by
scripts/check-detcore-backend-abstraction.sh.
Re-exports§
pub use util::punch_out_print;
Modules§
- detlog
- Module contains macroses that help tracing DETLOG entires for the purpose of verifiying determinism [‘detlog’] can be used to write a deterministic log entry at INFO level [’detlog_debug] can be use to write a deterministic log entry at DEBUG level
- edit_
distance - Schedule-alignment and edit-distance algorithms shared by Hermit tools.
- logdiff
- Everything to do with post-processing hermit/detcore logs.
- netlink_
route - Determinize the statistics counters carried by
NETLINK_ROUTElink dumps. - preemptions
- A datatype to abstract a record of thread preemptions, as generated during chaos mode execution.
- random
- Shared guest random-state and memory operations, independent of a backend. These synchronous operations preserve draws even when a later write fails.
- types
- Widely-shared type definitions.
- util
- Widely useful small utilities.
Macros§
- detlog
- Macro used to encapsulate tracing should-be-deterministic information. This is currently at the INFO log level.
- detlog_
debug - Macro used to encapsulate tracing should-be-deterministic information. This variant is at a higher log level and requires that logging verbosity is set to DEBUG.
- detlog_
observed - Whether a
detlog!record emitted at this point would reach anything.
Structs§
- Backend
Failure Cleanup - Separate terminal cleanup outcomes; neither replaces the backend failure.
- Config
- Configuration options for detcore.
- Detcore
- The detcore tool and its per-process state.
- Digest
- A SHA-256 content digest.
- File
Metadata - The metadata associated with the file system view of a particular process.
- Global
State - Global state associated with the detcore tool.
- Namespace
- A namespace that may be unshared with
Command::unshare. - Thread
State - The Detcore per-thread state.
- Thread
Stats - Various measurements of one guest thread’s execution. This is useful for printing context in logs as we go and printing a final summary.
- Unsupported
Syscall Error - Identifies an unsupported syscall that a backend must terminate without unwinding.
Enums§
- Blocking
Mode - How should we handle syscalls which may block, but are internal to the hermit container? These syscalls are determinizable, but there are multiple methods of doing so. These choices do not apply to blocking syscalls that wait for external conditions outside the container, such as network responses.
- Runs
Post Fork - Which side of an ordinary fork/clone receives the first post-registration turn.
- Sched
Heuristic - Apply a specialized scheduling heuristic which may help exercise certain bugs.
Constants§
- CONFIG_
FINGERPRINT_ ENV - N.B. we don’t want to specify two different notions of “default”, so we use the
Clapinstance above. Environment variable carrying the coordinator’sconfig_wire_fingerprintto an out-of-process plugin. - DEFAULT_
PRIORITY - The default priority for a thread. If chaos mode is not enabled, all threads have this priority.
- FIRST_
PRIORITY - The lowest/highest priority a thread can have.
- LAST_
PRIORITY - The last/lowest (numerically largest) priority a thread can have.
- ROOT_
DETPID - A convention of how we set up our PID namespace leaves us with a starting pid of 3.
Traits§
- Record
OrReplay - Helper trait.
Functions§
- all_
pinned_ syscalls - Every syscall in the pinned x86_64 table, including the final entry.
- config_
wire_ fingerprint - format_
unsupported_ syscall_ warning - Formats one deterministic warning for a set of unsupported syscall names.
- is_
deterministically_ refused_ syscall - Returns whether Detcore deterministically refuses
sysnowith a fixed errno when the fail-closed policy is active, without consulting the host. - is_
determinized_ syscall - Returns whether the audited runtime policy classifies
sysnoasDeterminized— that is, Detcore either models the syscall with a handler or applies an explicit deterministic refusal policy to it. - is_
kernel_ keyring_ syscall - Returns whether
sysnois a kernel-keyring syscall (add_key,request_key,keyctl) that Detcore hides behind a deterministicCONFIG_KEYS-absent boundary under the default fail-closed policy. - is_
strict_ only_ deterministic_ refusal_ syscall - Returns whether
sysnois refused by the default fail-closed policy but forwarded under the explicit compatibility opt-out. The legacystrict_onlyname is retained for API compatibility. - is_
unsupported_ syscall - Returns whether the audited runtime policy classifies
sysnoas unsupported. - prepare_
exec - Notifies the coordinator that
guestis about toexecve, recording the pre-exec address spacemmand any file-descriptor blocking overrides. A backend that handlesexecveoutside Detcore’s syscall handler must call this before the native syscall so the next image reconnects to the existing scheduler identity and logical clock. - thread_
rng_ from_ parent - Generate a new thread-local PRNG from the parent’s PRNG state, mixing in the new DetTid for some deterministic entropy. This ensures sequentially-spawned threads get distinct PRNG states.