Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Vsbox - #8

Closed
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox
Closed

Vsbox#8
Weiteng Chen (CvvT) wants to merge 12 commits into
mainfrom
vsbox

Conversation

@CvvT

Copy link
Copy Markdown
Contributor

Initial draft of platform for vsbox.

Run cargo doc --features platform_snp --open and navigate to the host module to see the interface design.

HostPunchthroughProvider: Interface for punchthrough requests
HostPunchthroughToken: A wrapper for PunchthroughToken that has lifetime
HyperCallInterface: Interface for hypercalls (See hypercall::HyperVInterface for example)

Comment threadCargo.toml
resolver = "2"
members = [
"litebox",
"litebox-platform-linux-kernel",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we keep the names consistent with "_"?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, I am to blame for this; I used to use - before deciding to make everything consistent in 1e6568d by switching to underscores (which turns out to be handled better by tooling and also make more sense in use ... declarations when specifying crates). Going forward, just using _ for all crate names should keep things nice, but yeah I believe Weiteng Chen (@CvvT) used - because I was using - at the point where he originally started working on this PR.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I remember we have a similar error file for the posix shim. Can we use a single error file?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be done in a separate PR to merge things into a shared crate litebox_linux_common or similar. I agree that currently this is essentially being duplicated.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(Fwiw, my suggestion for litebox_linux_common is a crate that also defines syscall punchthrough layer too, can explain more IRL if needed)

Comment thread.gitmodules
@@ -0,0 +1,3 @@
[submodule "litebox-platform-linux-kernel/sandbox_driver"]
path = litebox-platform-linux-kernel/sandbox_driver

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indexing by 4 spaces or 8 spaces?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the hypercall interface the same for SNP and VBS?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's not clear to me why we need a host subfolder here.

}
}

const NR_SYSCALL_KILL: u64 = 62;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define these two syscalls here? Do we need to define other syscall numbers as well?

punchthrough: SnpPunchthrough<'a>,
}

impl SnpPunchthroughToken<'_> {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we define both HostPunchThrough and SnpPunchthrough?

Comment on lines +22 to +23
RecvPacket(&'a mut [u8]),
SendPacket(&'a [u8]),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As I understand it, these are intended for the IP interface stuff, yes? In that case, it should not be part of punchthrough since we already have the IPInterfaceProvider trait.

Comment on lines +141 to +147
OtherPunchthrough::Syscall0(ref v) => v.into(),
OtherPunchthrough::Syscall1(ref v) => v.into(),
OtherPunchthrough::Syscall2(ref v) => v.into(),
OtherPunchthrough::Syscall3(ref v) => v.into(),
OtherPunchthrough::Syscall4(ref v) => v.into(),
OtherPunchthrough::Syscall5(ref v) => v.into(),
OtherPunchthrough::Syscall6(ref v) => v.into(),

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of match *req, if you use match req then I think you don't need these refs (modern-ish Rust tends to use refs very rarely).

@jaybosamiya-ms

Jay Bosamiya (Microsoft) (jaybosamiya-ms) commented Feb 11, 2025

Copy link
Copy Markdown
Member

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Quick question regarding the git-submodule for sandbox_driver; do we only need the .h files from there to set up bindings? If so, it may be a better idea for us to copy in the .h files, rather than deal with the complexity that comes from git-submodules especially for CI purposes (it is less of a complexity when things are public, but even then, it would lead to every user of litebox automatically cloning every submodule, even if not used, simply because of how Cargo does things conservatively). Having a sync_deps.sh or such script would make it easier for us to use a recent version, but it would allow us to decouple things better.

Thanks for the suggestion! Less complexity is better.


/// Interface for punchthrough requests
pub trait HostPunchthroughProvider<'a, InOut, Other> {
type Token: HostPunchthroughToken<'a, InOut>;

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Jay Bosamiya (Microsoft) (@jaybosamiya-ms) I was trying to use PunchthroughProvider but found that the associated PunchthroughToken does not have lifetime. The token may have shorter lifetime than the provider's.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed this IRL, we need to de-restrict the situations that are allowed here. Fixed by #9 which also demonstrates how a (borrowing) punchthrough and/or punchthroughtoken can be implemented.

@CvvT

Copy link
Copy Markdown
ContributorAuthor

Move to a new one: #10

Sangho Lee (sangho2) pushed a commit that referenced this pull request Mar 11, 2026
macOS ARM64 does not restore x18 (platform-reserved register) from
ucontext on sigreturn. This caused a crash at far=0x8 when
exception_callback tried to load host_sp from [x18, #8] with x18=0.
Switch to x9 (caller-saved temp register) for passing host_tls through
sigreturn: set_signal_return writes to sigctx.__ss.__x[9], and both
exception_callback and interrupt_callback read host_tls from x9.
For the direct-branch path (switch_to_guest interrupt trampoline), add
'mov x9, x18' before branching to interrupt_callback so both paths are
consistent.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@CvvT@jaybosamiya-ms@wdcui