One primary objective of operating systems is to provide a convenient and protected access to shared hardware resources, i.e., the abstraction in operating systems should allow multiple tasks running in the system to share hardware resources easily, effectively, and safely. Useful tasks to users generally belong to user applications or those that service the user applications.

The applications have dependencies, such as the libraries or the services that the applications rely on. Thanks to the process abstraction provided by modern operating systems, application containers have become a popular solution to orchestrate multiple applications and dependencies in isolated and protected environments. An application container is a package of applications and all of their dependencies. Multiple containers on a host share the same underlying operating system kernel. Popular application container orchestration and management tools include Docker and Kubernetes. Refer to the textbook for more detailed discussion (Silberschatz et al., 2018).

In this project we are to create a simple container launcher tool by ourselves. The objectives are 1) to gain a deep understanding of process abstraction and isolation as well as several other related concepts in modern operating systems and 2) to develop system programming skills.

GitHub Assignment Submission Setup

  1. If not already, provide your GitHub username at:

    CISC 7310X Brightspace Survey

  2. Accept the assignment invitation after you complete the survey above.

  3. Submit your work to the assignment Git repository created as a result of accepting the assignment invitation.

README File

The top directory of the repository should contain a README file. You shall create the file to provide a concise description of your work and the layout of the repository.

.gitignore

Add a .gitignore in the top-level directory to prevent accidentally putting unnecessary files in the repository.

AI Use Disclosure

The use of AI assistants and coding agents (e.g., GitHub Copilot, Claude Code, ChatGPT, Cursor) is permitted, but must be disclosed. For every commit that contains AI-generated or AI-assisted content, include a Co-authored-by trailer in the commit message naming the tool. For example:

Add --list-short implementation

Co-authored-by: GitHub Copilot <copilot@github.com>
Fix comm parsing for names with spaces

Co-authored-by: Claude Code <noreply@anthropic.com>

Commits without such a trailer are taken as the student’s own work. A single “initial commit” containing the entire final script will be treated as incomplete regardless of disclosure. Undisclosed AI use is an academic integrity violation.

Submission

To submit the work, complete the following:

  1. Your work resides on a GitHub repository. Make sure to push your work to the GitHub repository.
  2. Do not submit the solution as a single commit. Commit each feature completed as a single commit.
  3. Organize your work in the repository as follows:
    • README.md. The top-level README file is for student information.
    • Directory src. Source code goes here.
    • Directory doc. This is where the presentation slides go.
  4. Make a short presentation and demo in class: 10 minutes, ideally with slides, a demo of the features of the program, and the discussion about the questions in this assignment.

The submission deadline and the demo deadline shall be on the class Website.

Deadline

Observe the submission deadline posted on the class portal website.

Tasks

Follow the Instructor’s tutorial given in the video below and complete the following tasks. Please be aware that the instructor recorded this video as a lecture given in a previous edition of the class, and you may ignore the semester-specific content.

Container Tutorial

Developing BCDocker

For this task, you are to create a container runtime tool from scratch in C or C++ or a language of your choice that launches a Linux application container and is able to run users’ Linux applications in the container. Let’s call this container management tool BCDocker. The tool should meet the following requirements: the usage of the tool mirrors the popular container management tool Docker; however, in this project, we only implement a small subset of it. An application container is a package of applications and all of their dependencies. Multiple containers on a host share the same underlying operating system kernel. First and foremost, the tool must be a container management tool.

  1. The following examples demonstrate that the tool should launch a container and run a containerized application.

    $ sudo bcdocker run tinysys /bin/bash
    bash-5.0#
    

    In this example, the name of the container is tinysys and the application is /bin/bash.

    $ sudo bccontainer/bcdocker run tinysys /bin/ls -l -t -r
    total 12
    drwxr-xr-x   3 1000 1000 4096 Mar 13 01:16 usr
    drwxr-xr-x   3 1000 1000 4096 Mar 13 01:27 lib
    lrwxrwxrwx   1 1000 1000    8 Mar 13 01:28 bin -> /usr/bin
    drwxr-xr-x   2 1000 1000 4096 Mar 14 16:56 etc
    dr-xr-xr-x 153    0    0    0 Apr 15 15:34 proc
    

    In this example, the name of the container is tinysys, the application is /bin/ls, and the command line options to /bin/ls are -l -t -r.

    $ sudo bcdocker run bctinysys /bin/ls
    bin  etc  lib  proc  usr
    

    In this example, the name of the container is bctinysys, a different container, and the application is /bin/ls.

  2. Process IDs start from 1 in the container. Observe the following two examples.

    $ sudo bccontainer/bcdocker run bctinysys /bin/ps axf
      PID TTY      STAT   TIME COMMAND
       1 ?        S+     0:00 bccontainer/bcdocker run bctinysys /bin/ps axf
      14 ?        R+     0:00 /bin/ps axf
    
    $ sudo bccontainer/bcdocker run bctinysys /bin/bash
    bash-5.0# ps axf
      PID TTY      STAT   TIME COMMAND
        1 ?        S      0:00 bccontainer/bcdocker run bctinysys /bin/bash
       14 ?        S      0:00 /bin/bash
       15 ?        R+     0:00  \_ ps axf
    bash-5.0# exit
    exit
    $
    

Creating a Tiny Linux System

Container management and orchestration tools like Docker and Kubernetes can automate the process of creating application containers. In this project, we will not automate the process; rather, we shall manually create application containers. Generally, follow the steps:

  1. The containers we create here are for running Linux applications. First, we shall familiarize ourselves with Linux directory structures. Kyle Rankin has a short article about the File System Hierarchy Standard (missing reference). The report should minimally include the following items:
  • Use either the ACM conference or IEEE conference proceedings template in writing the report (ACM, 2017; IEEE, 2018).
  • Cite references properly.
  • Describe the design of the container tool.
  • Describe the process of creating a Linux container for an application.
  • Discuss the lessons learned.

Oral Presentation

Prepare a deck of presentation slides and deliver a 10-minute oral slides presentation. You should allocate 7 minutes for the presentation and 3 minutes for questions from the audience.

Optional Tasks

The optional tasks are for individual students who wish to complete more than the minimum specified above. They are not required for the minimum deliverable.

Memory Limit

Docker can limit containers’ access to memory. To mirror this, enhance the BCDocker with the ability to limit a container’s access to memory, e.g.:

sudo bccontainer/bcdocker run --memory=512m bctinysys /bin/bash
bash-5.0# exit
exit
$

where the container’s access to memory is limited at 512 MB. This requires cgroups (the memory controller).

Limit Process IDs

Docker can limit the range of containers’ process IDs. To mirror this, enhance the BCDocker with the ability to limit a container’s range of process IDs, e.g.:

sudo bccontainer/bcdocker run --pids-limit=20 bctinysys /bin/bash
bash-5.0# exit
exit
$

This requires cgroups (the pids controller).

Enabling Networking

The BCContainer created thus far does not have any networking devices. Configure the container with Ethernet devices and enable IP networking, e.g.:

$ sudo bccontainer/bcdocker run tinysys /bin/bash
bash-5.0# ip address show
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: bcvirt1@if50: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether c2:b5:28:6c:91:aa brd ff:ff:ff:ff:ff:ff link-netnsid 0
    inet 192.168.57.2/24 scope global bcvirt1
       valid_lft forever preferred_lft forever
    inet6 fe80::c0b5:28ff:fe6c:91aa/64 scope link
       valid_lft forever preferred_lft forever
bash-5.0# ping -c 1 www.google.com
PING www.google.com (172.217.165.132) 56(84) bytes of data.
64 bytes from lax30s03-in-f4.1e100.net (172.217.165.132): icmp_seq=1 ttl=116 time=11.8 ms

--- www.google.com ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 11.818/11.818/11.818/0.000 ms
bash-5.0# exit
exit
brooklyn@brooklyn:~$

This requires creating a network namespace, a virtual Ethernet pair, and configuring NAT on the host.

Reference

  1. Silberschatz, A., Galvin, P. B., & Gagne, G. (2018). Operating system concepts (10th edition). John Wiley & Sons.
  2. Booth, W. C., and Colomb, G. G., & Williams, J. M. (2003). The craft of research. University of Chicago press.
  3. Rankin, K. (2019). Filesystem Hierarchy Standard. In The Linux Journal.
  4. ACM. (2017). 2017 ACM Master Article Template.
  5. IEEE. (2018). IEEE Manuscript Templates for Conference Proceedings.