Hermit is a hermetic and reproducible sandbox for running programs
github.com
github.com
At least it seems Hermit masks RDRAND and RDSEED via CPUID, but not every program is written to support ancient architectures which didn't support these instructions and therefore not every program tests availability via CPUID.
In addition, even if all of this was deterministic, CPU flags set by various instructions with "undefined" flags according to the CPU manual can slightly differ between different microarchitectures. A "normal" program should not be influenced by this, but it is still a source of non-reproducibility. This might be relevant for certain rare compiler bugs.
Others have commented on here before, it admittedly doesn't seem to be actively maintained.
> Just to let you know we’re not actively working on Hermit in the team
https://github.com/facebookexperimental/hermit/issues/34#iss...
[1] https://github.com/facebookexperimental/hermit/blob/bd3153b4...
> Since ptrace adds significant overhead when the guest has a syscall-heavy workload, Reverie will add similarly-significant overhead. The slowdown depends on how many syscalls are being performed and are intercepted by the tool.
> The primary way you can improve performance with the current implementation is to implement the subscriptions callback, specifying a minimal set of syscalls that are actually required by your tool.
This definitely isn't intended for general-purpose sandboxing. It's an interesting tool for analysis and debugging.
The most interesting part of Antithesis (to me) isn’t even the perfect reproducibility, but the autonomous state space exploration that finds the bugs in the first place. AFAIK Hermit doesn’t do that, though you might be able to get somewhere by running your program plus a conventional fuzzer under Hermit together?
Disclosure: I am one of the co-founders of Antithesis.
rr "sells" as a "reversible debugger", but it obviously needs the determinism for its record and replay to work, and AFAIK it employs similar techniques regarding system call interception and serializing on a single CPU. The reversible debugger aspect is built on periodic snapshotting on top of it and replaying from those snapshots, AFAIK. They package it in a gdb compatible interface.
Hermit also lists record/replay as a motivation, although it doesn't list reversible debugging in general.