diff --git a/Makefile b/Makefile index 67f4fb735..8d3a60ea5 100644 --- a/Makefile +++ b/Makefile @@ -385,6 +385,7 @@ run_benchmark = \ ($(call header,BENCHMARK $(1)); \ set -euo pipefail; \ export T=$$(mktemp --tmpdir logs.$(1).XXXXXX); \ + export UNSANDBOXED_RUNTIME; \ if test "$(1)" = "runc"; then $(call sudo,$(BENCHMARKS_TARGETS),-runtime=$(1) $(BENCHMARKS_ARGS)) | tee $$T; fi; \ if test "$(1)" != "runc"; then $(call sudo,$(BENCHMARKS_TARGETS),-runtime=$(1) $(BENCHMARKS_ARGS) $(BENCHMARKS_PROFILE)) | tee $$T; fi; \ if test "$(BENCHMARKS_UPLOAD)" = "true"; then \ diff --git a/pkg/test/dockerutil/container.go b/pkg/test/dockerutil/container.go index 3e7eaac27..41f7aa63d 100644 --- a/pkg/test/dockerutil/container.go +++ b/pkg/test/dockerutil/container.go @@ -140,7 +140,11 @@ func MakeContainerWithRuntime(ctx context.Context, logger testutil.Logger, suffi // // Native containers aren't profiled. func MakeNativeContainer(ctx context.Context, logger testutil.Logger) *Container { - return makeContainer(ctx, logger, "" /*runtime*/) + unsandboxedRuntime := "runc" + if override, found := os.LookupEnv("UNSANDBOXED_RUNTIME"); found { + unsandboxedRuntime = override + } + return makeContainer(ctx, logger, unsandboxedRuntime) } // Spawn is analogous to 'docker run -d'. diff --git a/tools/bazel.mk b/tools/bazel.mk index 67da52e4b..5d7466677 100644 --- a/tools/bazel.mk +++ b/tools/bazel.mk @@ -21,18 +21,20 @@ ## container to simplify development. Some options are available to ## control the behavior of this container: ## -## USER - The in-container user. -## DOCKER_RUN_OPTIONS - Options for the container (default: --privileged, required for tests). -## DOCKER_NAME - The container name (default: gvisor-bazel-HASH). -## DOCKER_HOSTNAME - The container name (default: same as DOCKER_NAME). -## DOCKER_PRIVILEGED - Docker privileged flags (default: --privileged). -## PRE_BAZEL_INIT - If set, run this command with bash outside the Bazel -## server container. -## BAZEL_CACHE - The bazel cache directory (default: detected). -## GCLOUD_CONFIG - The gcloud config directory (detect: detected). -## DOCKER_SOCKET - The Docker socket (default: detected). -## DEVICE_FILE - An optional device file to expose in the container -## (default: no device file is exposed). +## USER - The in-container user. +## DOCKER_RUN_OPTIONS - Options for the container (default: --privileged, required for tests). +## DOCKER_NAME - The container name (default: gvisor-bazel-HASH). +## DOCKER_HOSTNAME - The container name (default: same as DOCKER_NAME). +## DOCKER_PRIVILEGED - Docker privileged flags (default: --privileged). +## UNSANDBOXED_RUNTIME - Name of the Docker runtime to use for the +## unsandboxed build container. Defaults to runc. +## PRE_BAZEL_INIT - If set, run this command with bash outside the Bazel +## server container. +## BAZEL_CACHE - The bazel cache directory (default: detected). +## GCLOUD_CONFIG - The gcloud config directory (detect: detected). +## DOCKER_SOCKET - The Docker socket (default: detected). +## DEVICE_FILE - An optional device file to expose in the container +## (default: no device file is exposed). ## ## To opt out of these wrappers, set DOCKER_BUILD=false. DOCKER_BUILD := true @@ -55,6 +57,7 @@ BUILDER_HOSTNAME := $(BUILDER_NAME) DOCKER_NAME := gvisor-bazel-$(HASH)-$(ARCH) DOCKER_HOSTNAME := $(DOCKER_NAME) DOCKER_PRIVILEGED := --privileged +UNSANDBOXED_RUNTIME ?= runc BAZEL_CACHE := $(HOME)/.cache/bazel/ GCLOUD_CONFIG := $(HOME)/.config/gcloud/ DOCKER_SOCKET := /var/run/docker.sock @@ -71,7 +74,7 @@ PRE_BAZEL_INIT ?= ## STARTUP_OPTIONS - Startup options passed to Bazel. ## STARTUP_OPTIONS := -BAZEL_OPTIONS := +BAZEL_OPTIONS ?= BAZEL := bazel $(STARTUP_OPTIONS) BASE_OPTIONS := --color=no --curses=no TEST_OPTIONS += $(BASE_OPTIONS) \ @@ -89,6 +92,9 @@ DOCKER_RUN_OPTIONS += --rm DOCKER_RUN_OPTIONS += --user $(UID):$(GID) DOCKER_RUN_OPTIONS += --entrypoint "" DOCKER_RUN_OPTIONS += --init +ifneq (,$(UNSANDBOXED_RUNTIME)) +DOCKER_RUN_OPTIONS += --runtime=$(UNSANDBOXED_RUNTIME) +endif DOCKER_RUN_OPTIONS += -v "$(shell realpath -m $(BAZEL_CACHE)):$(BAZEL_CACHE)" DOCKER_RUN_OPTIONS += -v "$(shell realpath -m $(GCLOUD_CONFIG)):$(GCLOUD_CONFIG)" DOCKER_RUN_OPTIONS += -v "/tmp:/tmp" @@ -214,6 +220,7 @@ bazel-image: load-default ## Ensures that the local builder exists. @docker rm -f $(BUILDER_NAME) 2>/dev/null || true @docker run --user 0:0 --entrypoint "" \ --name $(BUILDER_NAME) --hostname $(BUILDER_HOSTNAME) \ + $(shell test -n "$(UNSANDBOXED_RUNTIME)" && echo "--runtime=$(UNSANDBOXED_RUNTIME)") \ gvisor.dev/images/default \ bash -c "$(GROUPADD_DOCKER) $(USERADD_DOCKER) if test -e /dev/kvm; then chmod a+rw /dev/kvm; fi" >&2 @docker commit $(BUILDER_NAME) gvisor.dev/images/builder >&2