Project 2: Application Container
One primary objective of operating systems is to provide a convenient and protected access to shared hardware resources, i.e., the abstraction in operating systems should allow multiple tasks running in the system to share hardware resources easily, effectively, and safely. Useful tasks to users generally belong to user applications or those that service the user applications.
The applications have dependencies, such as the libraries or the services that the applications rely on. Thanks to the process abstraction provided by modern operating systems, application containers have become a popular solution to orchestrate multiple applications and dependencies in isolated and protected environments. An application container is a package of applications and all of their dependencies. Multiple containers on a host share the same underlying operating system kernel. Popular application container orchestration and management tools include Docker and Kubernetes. Refer to the textbook for more detailed discussion (Silberschatz et al., 2018).
In this project we are to create a simple container launcher tool by ourselves. The objectives are 1) to gain a deep understanding of process abstraction and isolation as well as several other related concepts in modern operating systems and 2) to develop system programming skills.
GitHub Assignment Submission Setup
-
If not already, provide your GitHub username at:
-
Accept the assignment invitation after you complete the survey above.
-
Submit your work to the assignment Git repository created as a result of accepting the assignment invitation.
README File
The top directory of the repository should contain a README file. You shall create the file to provide a concise description of your work and the layout of the repository.
.gitignore
Add a .gitignore in the top-level directory to prevent accidentally putting
unnecessary files in the repository.
AI Use Disclosure
The use of AI assistants and coding agents (e.g., GitHub Copilot, Claude
Code, ChatGPT, Cursor) is permitted, but must be disclosed. For every
commit that contains AI-generated or AI-assisted content, include a
Co-authored-by trailer in the commit message naming the tool. For example:
Add --list-short implementation
Co-authored-by: GitHub Copilot <copilot@github.com>
Fix comm parsing for names with spaces
Co-authored-by: Claude Code <noreply@anthropic.com>
Commits without such a trailer are taken as the student’s own work. A single “initial commit” containing the entire final script will be treated as incomplete regardless of disclosure. Undisclosed AI use is an academic integrity violation.
Submission
To submit the work, complete the following:
- Your work resides on a GitHub repository. Make sure to push your work to the GitHub repository.
- Do not submit the solution as a single commit. Commit each feature completed as a single commit.
- Organize your work in the repository as follows:
README.md. The top-levelREADMEfile is for student information.- Directory
src. Source code goes here. - Directory
doc. This is where the presentation slides go.
- Make a short presentation and demo in class: 10 minutes, ideally with slides, a demo of the features of the program, and the discussion about the questions in this assignment.
The submission deadline and the demo deadline shall be on the class Website.
Deadline
Observe the submission deadline posted on the class portal website.
Tasks
Follow the Instructor’s tutorial given in the video below and complete the following tasks. Please be aware that the instructor recorded this video as a lecture given in a previous edition of the class, and you may ignore the semester-specific content.
Developing BCDocker
For this task, you are to create a container runtime tool from scratch in C
or C++ or a language of your choice that launches a Linux application container
and is able to run users’ Linux applications in the container. Let’s call this
container management tool BCDocker. The tool should meet the following
requirements: the usage of the tool mirrors the popular container management
tool Docker; however, in this project, we only implement a small subset of it.
An application container is a package of applications and all of their
dependencies. Multiple containers on a host share the same underlying operating
system kernel. First and foremost, the tool must be a container management
tool.
-
The following examples demonstrate that the tool should launch a container and run a containerized application.
$ sudo bcdocker run tinysys /bin/bash bash-5.0#In this example, the name of the container is
tinysysand the application is/bin/bash.$ sudo bccontainer/bcdocker run tinysys /bin/ls -l -t -r total 12 drwxr-xr-x 3 1000 1000 4096 Mar 13 01:16 usr drwxr-xr-x 3 1000 1000 4096 Mar 13 01:27 lib lrwxrwxrwx 1 1000 1000 8 Mar 13 01:28 bin -> /usr/bin drwxr-xr-x 2 1000 1000 4096 Mar 14 16:56 etc dr-xr-xr-x 153 0 0 0 Apr 15 15:34 procIn this example, the name of the container is
tinysys, the application is/bin/ls, and the command line options to/bin/lsare-l -t -r.$ sudo bcdocker run bctinysys /bin/ls bin etc lib proc usrIn this example, the name of the container is
bctinysys, a different container, and the application is/bin/ls. -
Process IDs start from 1 in the container. Observe the following two examples.
$ sudo bccontainer/bcdocker run bctinysys /bin/ps axf PID TTY STAT TIME COMMAND 1 ? S+ 0:00 bccontainer/bcdocker run bctinysys /bin/ps axf 14 ? R+ 0:00 /bin/ps axf$ sudo bccontainer/bcdocker run bctinysys /bin/bash bash-5.0# ps axf PID TTY STAT TIME COMMAND 1 ? S 0:00 bccontainer/bcdocker run bctinysys /bin/bash 14 ? S 0:00 /bin/bash 15 ? R+ 0:00 \_ ps axf bash-5.0# exit exit $
Creating a Tiny Linux System
Container management and orchestration tools like Docker and Kubernetes can
automate the process of creating application containers. In this project, we
will not automate the process; rather, we shall manually create application
containers. Generally, follow the steps:
- The containers we create here are for running Linux applications. First, we shall familiarize ourselves with Linux directory structures. Kyle Rankin has a short article about the File System Hierarchy Standard (missing reference). The report should minimally include the following items:
- Use either the ACM conference or IEEE conference proceedings template in writing the report (ACM, 2017; IEEE, 2018).
- Cite references properly.
- Describe the design of the container tool.
- Describe the process of creating a Linux container for an application.
- Discuss the lessons learned.
Oral Presentation
Prepare a deck of presentation slides and deliver a 10-minute oral slides presentation. You should allocate 7 minutes for the presentation and 3 minutes for questions from the audience.
Optional Tasks
The optional tasks are for individual students who wish to complete more than the minimum specified above. They are not required for the minimum deliverable.
Memory Limit
Docker can limit containers’ access to memory. To mirror this, enhance the
BCDocker with the ability to limit a container’s access to memory, e.g.:
sudo bccontainer/bcdocker run --memory=512m bctinysys /bin/bash
bash-5.0# exit
exit
$
where the container’s access to memory is limited at 512 MB. This requires
cgroups (the memory controller).
Limit Process IDs
Docker can limit the range of containers’ process IDs. To mirror this,
enhance the BCDocker with the ability to limit a container’s range of
process IDs, e.g.:
sudo bccontainer/bcdocker run --pids-limit=20 bctinysys /bin/bash
bash-5.0# exit
exit
$
This requires cgroups (the pids controller).
Enabling Networking
The BCContainer created thus far does not have any networking devices.
Configure the container with Ethernet devices and enable IP networking, e.g.:
$ sudo bccontainer/bcdocker run tinysys /bin/bash
bash-5.0# ip address show
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: bcvirt1@if50: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether c2:b5:28:6c:91:aa brd ff:ff:ff:ff:ff:ff link-netnsid 0
inet 192.168.57.2/24 scope global bcvirt1
valid_lft forever preferred_lft forever
inet6 fe80::c0b5:28ff:fe6c:91aa/64 scope link
valid_lft forever preferred_lft forever
bash-5.0# ping -c 1 www.google.com
PING www.google.com (172.217.165.132) 56(84) bytes of data.
64 bytes from lax30s03-in-f4.1e100.net (172.217.165.132): icmp_seq=1 ttl=116 time=11.8 ms
--- www.google.com ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 11.818/11.818/11.818/0.000 ms
bash-5.0# exit
exit
brooklyn@brooklyn:~$
This requires creating a network namespace, a virtual Ethernet pair, and configuring NAT on the host.
Reference
- Silberschatz, A., Galvin, P. B., & Gagne, G. (2018). Operating system concepts (10th edition). John Wiley & Sons.
- Booth, W. C., and Colomb, G. G., & Williams, J. M. (2003). The craft of research. University of Chicago press.
- Rankin, K. (2019). Filesystem Hierarchy Standard. In The Linux Journal.
- ACM. (2017). 2017 ACM Master Article Template.
- IEEE. (2018). IEEE Manuscript Templates for Conference Proceedings.