diff options
Diffstat (limited to 'container/init.go')
| -rw-r--r-- | container/init.go | 71 |
1 files changed, 35 insertions, 36 deletions
diff --git a/container/init.go b/container/init.go index 4d5bb8a9..f4796f1d 100644 --- a/container/init.go +++ b/container/init.go @@ -19,6 +19,7 @@ import ( "hakurei.app/container/seccomp" "hakurei.app/ext" "hakurei.app/fhs" + "hakurei.app/internal/params" "hakurei.app/message" ) @@ -147,35 +148,33 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { } var ( - params initParams - closeSetup func() error - setupFd uintptr - offsetSetup int + param initParams + closeSetup func() error + setupFd int ) - if f, err := k.receive(setupEnv, ¶ms, &setupFd); err != nil { + if f, err := k.receive(setupEnv, ¶m, &setupFd); err != nil { if errors.Is(err, EBADF) { k.fatal(msg, "invalid setup descriptor") } - if errors.Is(err, ErrReceiveEnv) { + if errors.Is(err, params.ErrReceiveEnv) { k.fatal(msg, setupEnv+" not set") } k.fatalf(msg, "cannot decode init setup payload: %v", err) } else { - if params.Ops == nil { + if param.Ops == nil { k.fatal(msg, "invalid setup parameters") } - if params.ParentPerm == 0 { - params.ParentPerm = 0755 + if param.ParentPerm == 0 { + param.ParentPerm = 0755 } - msg.SwapVerbose(params.Verbose) + msg.SwapVerbose(param.Verbose) msg.Verbose("received setup parameters") closeSetup = f - offsetSetup = int(setupFd + 1) } - if !params.HostNet { + if !param.HostNet { ctx, cancel := signal.NotifyContext(context.Background(), CancelSignal, os.Interrupt, SIGTERM, SIGQUIT) defer cancel() // for panics @@ -188,7 +187,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { k.fatalf(msg, "cannot set SUID_DUMP_USER: %v", err) } if err := k.writeFile(fhs.Proc+"self/uid_map", - append([]byte{}, strconv.Itoa(params.Uid)+" "+strconv.Itoa(params.HostUid)+" 1\n"...), + append([]byte{}, strconv.Itoa(param.Uid)+" "+strconv.Itoa(param.HostUid)+" 1\n"...), 0); err != nil { k.fatalf(msg, "%v", err) } @@ -198,7 +197,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { k.fatalf(msg, "%v", err) } if err := k.writeFile(fhs.Proc+"self/gid_map", - append([]byte{}, strconv.Itoa(params.Gid)+" "+strconv.Itoa(params.HostGid)+" 1\n"...), + append([]byte{}, strconv.Itoa(param.Gid)+" "+strconv.Itoa(param.HostGid)+" 1\n"...), 0); err != nil { k.fatalf(msg, "%v", err) } @@ -207,8 +206,8 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { } oldmask := k.umask(0) - if params.Hostname != "" { - if err := k.sethostname([]byte(params.Hostname)); err != nil { + if param.Hostname != "" { + if err := k.sethostname([]byte(param.Hostname)); err != nil { k.fatalf(msg, "cannot set hostname: %v", err) } } @@ -221,7 +220,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { } ctx, cancel := context.WithCancel(context.Background()) - state := &setupState{process: make(map[int]WaitStatus), Params: ¶ms.Params, Msg: msg, Context: ctx} + state := &setupState{process: make(map[int]WaitStatus), Params: ¶m.Params, Msg: msg, Context: ctx} defer cancel() /* early is called right before pivot_root into intermediate root; @@ -229,7 +228,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { difficult to obtain via library functions after pivot_root, and implementations are expected to avoid changing the state of the mount namespace */ - for i, op := range *params.Ops { + for i, op := range *param.Ops { if op == nil || !op.Valid() { k.fatalf(msg, "invalid op at index %d", i) } @@ -272,7 +271,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { step sets up the container filesystem, and implementations are expected to keep the host root and sysroot mount points intact but otherwise can do whatever they need to. Calling chdir is allowed but discouraged. */ - for i, op := range *params.Ops { + for i, op := range *param.Ops { // ops already checked during early setup if prefix, ok := op.prefix(); ok { msg.Verbosef("%s %s", prefix, op) @@ -328,7 +327,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { k.fatalf(msg, "cannot clear the ambient capability set: %v", err) } for i := uintptr(0); i <= lastcap; i++ { - if params.Privileged && i == CAP_SYS_ADMIN { + if param.Privileged && i == CAP_SYS_ADMIN { continue } if err := k.capBoundingSetDrop(i); err != nil { @@ -337,7 +336,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { } var keep [2]uint32 - if params.Privileged { + if param.Privileged { keep[capToIndex(CAP_SYS_ADMIN)] |= capToMask(CAP_SYS_ADMIN) if err := k.capAmbientRaise(CAP_SYS_ADMIN); err != nil { @@ -351,13 +350,13 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { k.fatalf(msg, "cannot capset: %v", err) } - if !params.SeccompDisable { - rules := params.SeccompRules + if !param.SeccompDisable { + rules := param.SeccompRules if len(rules) == 0 { // non-empty rules slice always overrides presets - msg.Verbosef("resolving presets %#x", params.SeccompPresets) - rules = seccomp.Preset(params.SeccompPresets, params.SeccompFlags) + msg.Verbosef("resolving presets %#x", param.SeccompPresets) + rules = seccomp.Preset(param.SeccompPresets, param.SeccompFlags) } - if err := k.seccompLoad(rules, params.SeccompFlags); err != nil { + if err := k.seccompLoad(rules, param.SeccompFlags); err != nil { // this also indirectly asserts PR_SET_NO_NEW_PRIVS k.fatalf(msg, "cannot load syscall filter: %v", err) } @@ -366,10 +365,10 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { msg.Verbose("syscall filter not configured") } - extraFiles := make([]*os.File, params.Count) + extraFiles := make([]*os.File, param.Count) for i := range extraFiles { // setup fd is placed before all extra files - extraFiles[i] = k.newFile(uintptr(offsetSetup+i), "extra file "+strconv.Itoa(i)) + extraFiles[i] = k.newFile(uintptr(setupFd+1+i), "extra file "+strconv.Itoa(i)) } k.umask(oldmask) @@ -447,7 +446,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { // called right before startup of initial process, all state changes to the // current process is prohibited during late - for i, op := range *params.Ops { + for i, op := range *param.Ops { // ops already checked during early setup if err := op.late(state, k); err != nil { if m, ok := messageFromError(err); ok { @@ -468,14 +467,14 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { k.fatalf(msg, "cannot close setup pipe: %v", err) } - cmd := exec.Command(params.Path.String()) + cmd := exec.Command(param.Path.String()) cmd.Stdin, cmd.Stdout, cmd.Stderr = os.Stdin, os.Stdout, os.Stderr - cmd.Args = params.Args - cmd.Env = params.Env + cmd.Args = param.Args + cmd.Env = param.Env cmd.ExtraFiles = extraFiles - cmd.Dir = params.Dir.String() + cmd.Dir = param.Dir.String() - msg.Verbosef("starting initial process %s", params.Path) + msg.Verbosef("starting initial process %s", param.Path) if err := k.start(cmd); err != nil { k.fatalf(msg, "%v", err) } @@ -493,7 +492,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { for { select { case s := <-sig: - if s == CancelSignal && params.ForwardCancel && cmd.Process != nil { + if s == CancelSignal && param.ForwardCancel && cmd.Process != nil { msg.Verbose("forwarding context cancellation") if err := k.signal(cmd, os.Interrupt); err != nil && !errors.Is(err, os.ErrProcessDone) { k.printf(msg, "cannot forward cancellation: %v", err) @@ -525,7 +524,7 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) { cancel() // start timeout early - go func() { time.Sleep(params.AdoptWaitDelay); close(timeout) }() + go func() { time.Sleep(param.AdoptWaitDelay); close(timeout) }() // close initial process files; this also keeps them alive for _, f := range extraFiles { |
