Skip to content

feat(vm): add host bind mount support via virtiofs (libkrun) - #3463

Open
benoitf wants to merge 1 commit into
NVIDIA:mainfrom
benoitf:feat/vm-bind-mounts
Open

benoitf wants to merge 1 commit into
NVIDIA:mainfrom
benoitf:feat/vm-bind-mounts

Conversation

@benoitf

@benoitf benoitf commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Add host directory bind mount support for libkrun VM sandboxes via the virtiofs4 API with simplified permission semantics. Operators enable the feature with enable_bind_mounts = true in [openshell.drivers.vm], and sandbox creators specify mounts in driver_config.mounts[].

note: it depends on a new release of kernel published at https://github.com/NVIDIA/OpenShell/actions/workflows/release-vm-kernel.yml for pre-built vm (with newer libkrun)

Related Issue

#2585

Changes

  • Gateway config (openshell-gateway): Accept enable_bind_mounts in VmComputeConfig and forward as --enable-bind-mounts CLI flag to the VM driver subprocess
  • FFI (openshell-driver-vm): Add krun_add_virtiofs4 binding (6-arg: ctx, tag, path, shm_size, read_only, semantics)
  • Runtime (openshell-driver-vm): New VmMount type and add_virtiofs() method calling virtiofs4 with SEMANTICS_SIMPLIFIED
  • Driver (openshell-driver-vm): VmMountConfig deserialization, path validation against reserved VM-internal directories, virtiofs tag generation, guest mount manifest injection into overlay disk, --vm-mount CLI arg forwarding
  • Init script: mount_virtiofs_shares() reads /.openshell/mounts.manifest and mounts virtiofs shares at boot
  • Kernel config: Enable CONFIG_FUSE_FS and CONFIG_VIRTIO_FS for guest virtiofs support
  • Docs: Add enable_bind_mounts to gateway-config.mdx reference

Testing

  • Unit tests for mount config deserialization (default read-write, explicit read-only)
  • Unit tests for mount validation (requires enable_bind_mounts, rejects QEMU, rejects relative source, rejects file source, rejects reserved paths, rejects duplicates)
  • Unit tests for --vm-mount CLI arg parsing
  • Unit test for manifest tab-separated rendering
  • Manual: create sandbox with driver_config.mounts and verify host directory is accessible in guest

Checklist

  • Conventional commit format
  • DCO sign-off
  • Docs updated (gateway-config.mdx)
  • No secrets or credentials committed
  • mise run pre-commit passes
  • mise run test passes

@copy-pr-bot

copy-pr-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@clholzin

Copy link
Copy Markdown

Confirming from the requester side: this matches what we asked for in #1509 — opt-in volume mounts for MicroVM sandboxes.

The core ask there was the ability to add virtiofs devices beyond the rootfs in a libkrun VM, behind an explicit operator opt-in, with the guest-side mount handled during the driver's boot sequence. That's what this implements. Thanks for picking it up.

@benoitf
benoitf force-pushed the feat/vm-bind-mounts branch from d7236e6 to 3c81133 Compare September 23, 2026 08:21
@benoitf

benoitf commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

I rebased the PR on top of the main branch due to conflicts

@benoitf
benoitf force-pushed the feat/vm-bind-mounts branch 3 times, most recently from bd1d7b2 to 135f022 Compare September 28, 2026 08:13
@benoitf

benoitf commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

rebased and added e2e tests

Introduce host directory bind mounts for libkrun VM sandboxes using
the virtiofs4 API with simplified permission semantics. The gateway
accepts `enable_bind_mounts` in the `[openshell.drivers.vm]` TOML
table and forwards it to the VM driver subprocess.

Mounts are specified per-sandbox in driver_config.mounts[] with
source, target, optional read_only (default: read-only), and an
optional `type` that must be `bind`, so Docker and Podman bind entries
parse unchanged.
At sandbox validation the driver rejects mounts unless bind mounts
are enabled and resource admission is disabled, and checks targets
against reserved VM-internal directories and each other (no nested
targets). Host source directories are checked at provisioning, so a
briefly missing source fails provisioning visibly instead of denying
recovery of a persisted sandbox. The driver generates virtiofs tags
and always writes a guest-side manifest into the overlay disk, so an
image-supplied manifest can never drive guest mounts.

Guest init mounts the shares after every /sandbox ownership fixup
and the init drop-ins, so recursive chowns never reach host files.
It refuses targets that traverse symlinks in the image and hands
newly created mount point parents under /sandbox to the sandbox user.

krun_add_virtiofs4 is resolved optionally, so older libkrun runtimes
still boot sandboxes without mounts.

Kernel config adds CONFIG_FUSE_FS and CONFIG_VIRTIO_FS to support
the virtiofs filesystem in the guest.

A vm_bind_mount e2e test checks a read-write share round-trips data
with the host and a read-only share rejects writes; the VM e2e gateway
enables bind mounts like the Docker and Podman e2e gateways.

Signed-off-by: Florent Benoit <fbenoit@redhat.com>
@benoitf
benoitf force-pushed the feat/vm-bind-mounts branch from 135f022 to 606a784 Compare October 1, 2026 08:14
@benoitf

benoitf commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

rebased to fix conflict

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants