aboutsummaryrefslogtreecommitdiffhomepage
path: root/container/init.go
diff options
context:
space:
mode:
Diffstat (limited to 'container/init.go')
-rw-r--r--container/init.go15
1 files changed, 15 insertions, 0 deletions
diff --git a/container/init.go b/container/init.go
index fa220f25..e5ca1718 100644
--- a/container/init.go
+++ b/container/init.go
@@ -49,6 +49,8 @@ type (
early(state *setupState, k syscallDispatcher) error
// apply is called in intermediate root.
apply(state *setupState, k syscallDispatcher) error
+ // late is called right before starting the initial process.
+ late(state *setupState, k syscallDispatcher) error
// prefix returns a log message prefix, and whether this Op prints no identifying message on its own.
prefix() (string, bool)
@@ -330,6 +332,19 @@ func initEntrypoint(k syscallDispatcher, msg message.Msg) {
}
k.umask(oldmask)
+ // called right before startup of initial process, all state changes to the
+ // current process is prohibited during late
+ for i, op := range *params.Ops {
+ // ops already checked during early setup
+ if err := op.late(state, k); err != nil {
+ if m, ok := messageFromError(err); ok {
+ k.fatal(msg, m)
+ } else {
+ k.fatalf(msg, "cannot complete op at index %d: %v", i, err)
+ }
+ }
+ }
+
if err := closeSetup(); err != nil {
k.fatalf(msg, "cannot close setup pipe: %v", err)
}