9 ms·
ZeroVM: lightweight containers based on Google Native Client
- lbotos 15y agoI'm slightly confused as to if this has any use beyond "on-demand data access" use cases. I reviewed the site and I like the idea but I'm confused as to what else this could be used for. Would something like a "Heroku" style PaaS using PyPy or something that targets NaCL benefit from this is a process separation sense? Anybody care to clarify?
- almost 15y agoImagine if you could scale up and down the amount of computing capacity you were paying for on a second by second (or even ms by ms) basis! That would be pretty cool :)
- willvarfar 15y agoEver used distcc? (or even mosix?) Imagine that everyone in the office could be running your tests, compiles and such easily and transparently. There are lots of grids to do this now; but this seems like a new lighter-weight and faster solution that, as it'll run well on Windows too (in that Chrome proves it does), is going to be great. Here's hoping :)
- hobbyist 15y agohow is it different from freebsd jails or containers in linux?
- mike_ivanov 15y agoContainers/jails draw the isolation boundary around your processes, whilst this technology confines your code within a singe process and completely isolates it from the system.
- camuel 15y agoexactly! Further from being a different abstraction, container technologies (at-least in their current implementations of 'chroot on nukes') are not completely sealed or 'secure'. OpenVZ seems to be the most secured one over-there, requires kernel-patching and still... close but not 100% airtight. That is one of the reasons that many lightweight containers are used only as secondary sandbox (like Heroku) and not allowing you to run arbitrary C/assembly inside your environment. So, practically, LXC always ends up as secure-python-environment or ruby-environment as so on... never as secure x86 execution environment. Correct me here if I'm wrong...
- shykes 15y agodotCloud (http://dotcloud.com http://dotcloud.com) supports arbitrary code execution inside LXC containers (pre-2010 versions used OpenVZ, and very early versions were built on V-server). The main limitation is that the process runs under an unprivileged uid under a kernel managed and deployed by dotCloud. I agree with the assessment that containers are not "completely secure" - I would not trust it to contain a root-privileged process. However an unprivileged process running inside an lxc container on a recent kernel will have an extremely hard time escaping.
- camuel 15y agoWhat if I DoS attack some syscall? Or create zillions of files with 1 byte size driving crazy file-system or anything else. Kernel is such vast area vulnerable for an attack that it is scary even to think about securing all of it and not leaving a single weak point. Moreover, you will screw your syscall API to the point that it will become unusable. At bare least we need standard for the syscall capping and etc... so programmer will know what to expect. And thanks for the link, will check them and what solution they use and whether they are happy with it.
- StavrosK 15y agoI have never read so many words and understood so little about a technology before. The density of marketing-speak per word is approximately 1. Why can't some people just explain things simply?
- willvarfar 15y agoI read it the other way around: the prose is poor - perhaps not written by a native English speaker - but its very technical, accurate and not BS
- camuel 15y agoThanks for this. I'm indeed not a native English speaker. And I apologies for not having diagrams, in fact I was working on this part right now... And planned HN exposure little later after more diagrams are added to website, VirtualBox image ready with whole environment to save time for folks who want to experiment and a well tested initial version separated from development branch. However it went out earlier, uncontrollably, while I'm travelling... and I will play now a catch-game...
- StavrosK 15y agoWell, sure, but there's no high level overview. Even something like "It's a virtualizing solution, like Xen/VMware/VirtualBox, that uses Chrome's Native Client".
- reginaldo 15y agoFrom what I read it's something like this: It gives a bare-bones environment for you to run your programs that is presumably very low overhead. Think of it as an embedded system where programs run without an OS. This is the environment a program running inside zerovm will see. All you have is libc and the zerovm-provided APIs. If you want more, you'll have to statically link your programs. The thing is, you can run many, lets say thousands, of these little programs inside a single machine in such a way that each one can never see the other ones (as long as it's impossible to break out of the ZeroVM sandbox). Such a technology would enable neat stuff, like renting a server for someone to run a single program for some period of time and have the results sent back. Nobody does this for unrestricted programs today, for many reasons, a very important one being the fact that it would be very hard to do this in a secure way. The "run a C program for some period of time thing" would work kind of like the AWS dashboard, but instead of having to spin up a machine with linux on it and running your program inside that, you would only upload your binary and a manifest file. Kind of like what app engine does, but with less restrictions (you'll probably be able to do anything as long as you're able to compile a "safe" binary that does it).
- justauser 15y agoPerhaps the "motivation" section would serve as a better landing page. What's the current state of security with LXC? As I recall, Heroku relies on this for it's virtualization.
- mike_ivanov 15y agoLXC has its warts but generally it's ok.
- willvarfar 15y agoI will try and explain it as I understand it: Google Chrome has a sandboxed VM called Native Client (NaCl) that runs at near full speed. Its very neat. So they have taken that same VM and, instead of Chrome's Pepper API, they have a file-handle-based API and some message-passing between instances. Now you can compile your C/C++/whatever program and run it on the cloud! It seems an excellent building-block for big data and big crunching on the cloud, and it gets the benefit of Google's massive resources on security and performance fixes.
- ch0wn 15y agoIf I'm not mistaken, NaCl's integration with Chrome is actually implemented using Pepper. EDIT: I found something on this. "NaCl was integrated into Chrome 5 as an in-process Pepper plugin. The NaCl modules that it runs can utilize the Pepper API for browser interaction." (http://www.chromium.org/nativeclient/getting-started/getting-started-background-and-basics#TOC-Native-Client-NaCl- http://www.chromium.org/nativeclient/getting-started/getting...)
- willvarfar 15y agoExactly; that's what they don't do; they use a file-handle-based IO instead of peppar (which has file opening libraries and event loops of its own)
- vardump 15y agoI read this as RPC with code instead of just data. If so, this is exactly what I've been looking for a long time, because traditional RPC roundtrip latency is often high - so high, that you need to create a more complicated API to avoid excess iteration. Combine this with ZeroMQ and MessagePack, and you have some serious power at your fingertips. Messages can execute at destination, do iteration, API calls and return only needed part of the data and results back.
- ericbb 15y agoTypical solution is to use an interpreter (turning data into code). How often is it necessary to run arbitrary machine code on demand?
- camuel 15y agoIn most cases within distributed computing you need either move the data or move the code. It could also be something in between with the case of "request" and "query", if they simple they are surely data, if they are complex they look more like code. Ok, now if we agree that something should be moved lets think what makes more sense to move dataset or to move code? And my take is "it depends". Dataset size plays a role... security plays a role and etc.. think what if dataset for another reasons than size cannot be moved. In all these cases you need to move code. In the case the code is untrusted (malicious suspect or just being buggy) you will want some kind of sandbox.
- DavidGruzman 15y agoI would expect about order of magnitude speed difference between interpreted language and optimized machine code. I can recall case when reducing analytical request from 10 hours to 10 minutes changes the qualities of research company was doing - since analysts where able to do more queries selecting better dataset for the report. Order of magnitude response time might also be go/no go for interactive analytics. In case of clouds where we can assume infinite resources it can mean 1/10 of cost. For the private clusters - it can be differenace in buying 10 machines (something common in hadoop's word) and buying 100 machines - something very few groups can get.
- 15y ago
- equark 15y agoVery cool, I've been waiting for this to happen. I'm surprised that Google doesn't explicitly talk more about this use case for Native Client. It could be the backbone for an AWS/Heroku competitor. The ability to run lightweight tasklets securely would enable a lot of interesting scenarios. While not very significant, Google actually already started doing this with their Exacycle program: http://research.google.com/university/exacycle_program.html http://research.google.com/university/exacycle_program.html
- mike_ivanov 15y agoThis is a perfect Mobile Agent platform (http://en.wikipedia.org/wiki/Mobile_agent http://en.wikipedia.org/wiki/Mobile_agent)
- camuel 15y agoCorrect! I wonder how I missed this on zerovm site. For the folks not familiar with the issue, it is not about mobile phones :) With the emergence of large immobile datasets, software mobile agents may have a renaissance era... especially with AI being cool again.
- Tobu 15y agoThis is intended as a way to run computation close to data. Some databases embed Lua or pluggable languages for that; ZeroVM can run NaCL binaries (compiled with a special toolchain), verified in the same manner as the JVM checks bytecode, on a very limited sandbox (just some pre-configured data channels). Besides the NaCL verifications, they are enforcing functional programming: the program only has access to deterministic instructions and library calls.
- Tobu 15y agoWhy downvotes? I provided an explanation because the initial reaction on HN was confusion.
- skrebbel 15y agoThey're called the downvote mafia. Little to do about them.
- wladimir 15y agoIs it right to equate functional programming and determinism though? Functional programming implies a certain programming style / type of language, whose output is guaranteed to be deterministic if only pure functions are used. But they're not the same thing.
- 15y ago
- majke 15y agoIf you think NaCL is bloated, Russ Cox's vx32 may be a lightweight answer: http://pdos.csail.mit.edu/~baford/vm/ http://pdos.csail.mit.edu/~baford/vm/ Some of my experiments: http://www.lshift.net/blog/2010/03/31/what-has-happened-to-the-segment-registers http://www.lshift.net/blog/2010/03/31/what-has-happened-to-t... https://github.com/majek/vx32example https://github.com/majek/vx32example
- eklitzke 15y agoInteresting, Russ Cox works at Google. I'd have to imagine that he's talked to members of the NaCL team, and vice versa.
- bradfitz 15y agoHe works on Go at Google. He updated an earlier version of Go to run on an earlier version of NaCL, but it's since bitrot as NaCL's formats were changing at the time.
- iseyler 15y agoThis is very interesting! It will be even more interesting to see if it can be compiled to run on my OS. This is exatly the kind of application I have been looking for. ESXi is too big :) Shameless plug: http://www.returninfinity.com/baremetal.html http://www.returninfinity.com/baremetal.html
- camuel 15y agoI can assure you it can easily be ported and used on any OS. We just a few guys right now and don't have the capacity to test it on anything but Ubuntu. However, we are designed it to portable (and NaCl/Chrome code is also portable which helps a lot). Even to run on bare-hardware. So tried to keep OS usage to minimum. In fact, porting would be a more extensive effort to architectures not naively supported by Nacl. For example zerovm on tilera-linux (MIPS variant) will be much more effort then FreeBSD on x86-linux. As a side note, I personally convinced that today OSes are an overkill for cloud-based number crunching (the prime case for zerovm) wasting resources. I am looking forward for future a lot lighter 'cloudware'. Think 'opencompute' approach for OSes. zerovm is being a humble experiment here.
- iseyler 15y agoAgreed on the overkill part. That is the reasoning behind the work we are doing. I sent you an email to discuss further.
- xal 15y agoI love how many high level technologies are left to mature in the java environment and then are reintroduced on a level that's a lot closer to the kernel and the metal. ZeroMQ is another great example of the progression that started with AMQP. Hadoop hopefully will see a similar fate. ZeroMQ combined with ZeroVM actually offers two important building blocks.
- alexchamberlain 15y agoSo, does this mean, when implemented in a browser, I can use C instead of Javascript?
- justincormack 15y agoThats what you can o with native client in chrome right now. This reuses that code for server apps.
- karterk 15y agowhat is less known is that when deployed at cloud, Hadoop cannot access that enormous dataset locally due to security restrictions and therefore is screamingly inefficient compared to on-premise Hadoop deployment.[1] Can someone explain what that means? [1]: http://zerovm.org/killer-apps/ http://zerovm.org/killer-apps/
- deleted 15y ago[deleted]
- camuel 15y agoyou got (2) wrong, the reason is running code on S3 is insecure and would not be allowed and spawning VM inside S3 for some local calculation would be cumbersome at best as it is too bulky for such acrobatics.
- camuel 15y agoIf you use EMR or just roll your own Hadoop in EC2 then: 1. Hadoop runs on EC2 2. Data is stored on S3 3. Intermediary results stored in EC2 4. Hadoop loads the data from S3 to EC2 5. EC2<->S3 bandwidth is not that fast or efficient (S3 proxy, network contention, TCP/IP processing) Hypothetical MapReduce/ZeroVM/Swift scenario: 1. Data is stored on S3/Swift 2. Map and Reduce functions are run inside S3/Swift secured by ZeroVM in majority of cases accessing data locally without networking/proxies getting in the way. 3. Intermediate and final results are also stored within S3/Swift. 4. Local data access is efficient, fast and predictable 5. Local networking within S3/Swift is more efficient, fast and predictable than S3<->EC2 / Swift<->Nova Accelerated Hadoop scenario: Exactly as in #1, just Hadoop makes "predicate pushdown optimization" into S3/Swift secured by ZeroVM. Regarding 'due to security restrictions' I meant that cloud vendor would not let you run your own code in S3 or CloudFiles. Why? Because you could mess up other people data and storage system itself. Why not run in VM inside S3? well I guess it would be impractical due to long provisioning time of conventional VM.
- lobster_johnson 15y agoThat criticism is specific to S3, not EC2 or Hadoop. It's perfectly feasible and probably preferable to have Hadoop work on local files in instance store volumes (or EBS if you're mad).
- mcartyem 15y agoHow secure is the VM given a binary that can dynamically modify itself to bypass the inspection of the VM?
- camuel 15y agoI assume by VM you mean ZeroVM. Well, ZeroVM currently doesn't allow self modifying code at all. Nice try.... We haven't touched Google's provided validator in order not to break anything security-related. And if you think you have a good idea for vulnerability then you can claim some Google prizes. If you meant more practical uses for it then unfortunately modern JIT would be difficult to support efficiently as they constantly recompile and with ZeroVM it is not only recompilation but also validation. However, JIT that recompile only once, on loading, is easy to support. In fact, next version of NaCl dumps GNU toolchain in favor for JITy LLVM, but then recompilation is happening only once.
- deleted 15y ago[deleted]
- camuel 15y agoWell... this echoes ZeroVM ideas but so is PiCloud and a few others mentioned here. I think it goes without doubt that current OSes and VMs are not best suited for cloud technologies. How they can be? The were designed to completely different requirements.
- Ecio78 15y agosorry i deleted the post because i thought it was not useful. i was referring to this article http://highscalability.com/blog/2010/10/21/machine-vm-cloud-api-rewriting-the-cloud-from-scratch.html http://highscalability.com/blog/2010/10/21/machine-vm-cloud-...
- rektide 15y agoOpenMirage project is a similar-ish idea, providing numerous implementations of a std-lib for different targets (sample targets: Android, Linux OS, raw x86), and using this limited API. Sure, ZeroVM has it's own "vm instructions" rather than "library calls," but the ideas both reduce to building virtual machines for great glory and profit.