diff options
Diffstat (limited to 'internal/app')
| -rw-r--r-- | internal/app/app_nixos_linux_test.go | 16 | ||||
| -rw-r--r-- | internal/app/app_pd_linux_test.go | 24 | ||||
| -rw-r--r-- | internal/app/container_linux.go | 14 | ||||
| -rw-r--r-- | internal/app/process_linux.go | 2 | ||||
| -rw-r--r-- | internal/app/seal_linux.go | 26 |
5 files changed, 41 insertions, 41 deletions
diff --git a/internal/app/app_nixos_linux_test.go b/internal/app/app_nixos_linux_test.go index a0da52c0..4b7b3d38 100644 --- a/internal/app/app_nixos_linux_test.go +++ b/internal/app/app_nixos_linux_test.go @@ -23,7 +23,7 @@ var testCasesNixos = []sealTestCase{ Container: &hst.ContainerConfig{ Userns: true, Net: true, MapRealUID: true, Env: nil, AutoEtc: true, Filesystem: []*hst.FilesystemConfig{ - {Src: "/bin", Must: true}, {Src: "/usr/bin", Must: true}, + {Src: "/bin", Must: true}, {Src: "/usr/bin/", Must: true}, {Src: "/nix/store", Must: true}, {Src: "/run/current-system", Must: true}, {Src: "/sys/block"}, {Src: "/sys/bus"}, {Src: "/sys/class"}, {Src: "/sys/dev"}, {Src: "/sys/devices"}, {Src: "/run/opengl-driver", Must: true}, {Src: "/dev/dri", Device: true}, @@ -116,11 +116,11 @@ var testCasesNixos = []sealTestCase{ "XDG_SESSION_TYPE=tty", }, Ops: new(container.Ops). - Proc("/proc"). + Proc("/proc/"). Tmpfs(hst.Tmp, 4096, 0755). - DevWritable("/dev", true). + DevWritable("/dev/", true). Bind("/bin", "/bin", 0). - Bind("/usr/bin", "/usr/bin", 0). + Bind("/usr/bin/", "/usr/bin/", 0). Bind("/nix/store", "/nix/store", 0). Bind("/run/current-system", "/run/current-system", 0). Bind("/sys/block", "/sys/block", container.BindOptional). @@ -130,11 +130,11 @@ var testCasesNixos = []sealTestCase{ Bind("/sys/devices", "/sys/devices", container.BindOptional). Bind("/run/opengl-driver", "/run/opengl-driver", 0). Bind("/dev/dri", "/dev/dri", container.BindDevice|container.BindWritable|container.BindOptional). - Etc("/etc", "8e2c76b066dabe574cf073bdb46eb5c1"). - Remount("/dev", syscall.MS_RDONLY). - Tmpfs("/run/user", 4096, 0755). + Etc("/etc/", "8e2c76b066dabe574cf073bdb46eb5c1"). + Remount("/dev/", syscall.MS_RDONLY). + Tmpfs("/run/user/", 4096, 0755). Bind("/tmp/hakurei.1971/runtime/1", "/run/user/1971", container.BindWritable). - Bind("/tmp/hakurei.1971/tmpdir/1", "/tmp", container.BindWritable). + Bind("/tmp/hakurei.1971/tmpdir/1", "/tmp/", container.BindWritable). Bind("/var/lib/persist/module/hakurei/0/1", "/var/lib/persist/module/hakurei/0/1", container.BindWritable). Place("/etc/passwd", []byte("u0_a1:x:1971:100:Hakurei:/var/lib/persist/module/hakurei/0/1:/run/current-system/sw/bin/zsh\n")). Place("/etc/group", []byte("hakurei:x:100:\n")). diff --git a/internal/app/app_pd_linux_test.go b/internal/app/app_pd_linux_test.go index 31a99f87..2dd83b70 100644 --- a/internal/app/app_pd_linux_test.go +++ b/internal/app/app_pd_linux_test.go @@ -44,18 +44,18 @@ var testCasesPd = []sealTestCase{ }, Ops: new(container.Ops). Root("/", "4a450b6596d7bc15bd01780eb9a607ac", container.BindWritable). - Proc("/proc"). + Proc("/proc/"). Tmpfs(hst.Tmp, 4096, 0755). - DevWritable("/dev", true). + DevWritable("/dev/", true). Bind("/dev/kvm", "/dev/kvm", container.BindWritable|container.BindDevice|container.BindOptional). Readonly("/var/run/nscd", 0755). Tmpfs("/run/user/1971", 8192, 0755). Tmpfs("/run/dbus", 8192, 0755). - Etc("/etc", "4a450b6596d7bc15bd01780eb9a607ac"). - Remount("/dev", syscall.MS_RDONLY). - Tmpfs("/run/user", 4096, 0755). + Etc("/etc/", "4a450b6596d7bc15bd01780eb9a607ac"). + Remount("/dev/", syscall.MS_RDONLY). + Tmpfs("/run/user/", 4096, 0755). Bind("/tmp/hakurei.1971/runtime/0", "/run/user/65534", container.BindWritable). - Bind("/tmp/hakurei.1971/tmpdir/0", "/tmp", container.BindWritable). + Bind("/tmp/hakurei.1971/tmpdir/0", "/tmp/", container.BindWritable). Bind("/home/chronos", "/home/chronos", container.BindWritable). Place("/etc/passwd", []byte("chronos:x:65534:65534:Hakurei:/home/chronos:/run/current-system/sw/bin/zsh\n")). Place("/etc/group", []byte("hakurei:x:65534:\n")). @@ -179,19 +179,19 @@ var testCasesPd = []sealTestCase{ }, Ops: new(container.Ops). Root("/", "ebf083d1b175911782d413369b64ce7c", container.BindWritable). - Proc("/proc"). + Proc("/proc/"). Tmpfs(hst.Tmp, 4096, 0755). - DevWritable("/dev", true). + DevWritable("/dev/", true). Bind("/dev/dri", "/dev/dri", container.BindWritable|container.BindDevice|container.BindOptional). Bind("/dev/kvm", "/dev/kvm", container.BindWritable|container.BindDevice|container.BindOptional). Readonly("/var/run/nscd", 0755). Tmpfs("/run/user/1971", 8192, 0755). Tmpfs("/run/dbus", 8192, 0755). - Etc("/etc", "ebf083d1b175911782d413369b64ce7c"). - Remount("/dev", syscall.MS_RDONLY). - Tmpfs("/run/user", 4096, 0755). + Etc("/etc/", "ebf083d1b175911782d413369b64ce7c"). + Remount("/dev/", syscall.MS_RDONLY). + Tmpfs("/run/user/", 4096, 0755). Bind("/tmp/hakurei.1971/runtime/9", "/run/user/65534", container.BindWritable). - Bind("/tmp/hakurei.1971/tmpdir/9", "/tmp", container.BindWritable). + Bind("/tmp/hakurei.1971/tmpdir/9", "/tmp/", container.BindWritable). Bind("/home/chronos", "/home/chronos", container.BindWritable). Place("/etc/passwd", []byte("chronos:x:65534:65534:Hakurei:/home/chronos:/run/current-system/sw/bin/zsh\n")). Place("/etc/group", []byte("hakurei:x:65534:\n")). diff --git a/internal/app/container_linux.go b/internal/app/container_linux.go index a0c81d7a..1ea23d44 100644 --- a/internal/app/container_linux.go +++ b/internal/app/container_linux.go @@ -81,13 +81,13 @@ func newContainer(s *hst.ContainerConfig, os sys.State, prefix string, uid, gid } params. - Proc("/proc"). + Proc(container.FHSProc). Tmpfs(hst.Tmp, 1<<12, 0755) if !s.Device { - params.DevWritable("/dev", true) + params.DevWritable(container.FHSDev, true) } else { - params.Bind("/dev", "/dev", container.BindWritable|container.BindDevice) + params.Bind(container.FHSDev, container.FHSDev, container.BindWritable|container.BindDevice) } /* retrieve paths and hide them if they're made available in the sandbox; @@ -111,7 +111,7 @@ func newContainer(s *hst.ContainerConfig, os sys.State, prefix string, uid, gid if path.IsAbs(pair[1]) { // get parent dir of socket dir := path.Dir(pair[1]) - if dir == "." || dir == "/" { + if dir == "." || dir == container.FHSRoot { os.Printf("dbus socket %q is in an unusual location", pair[1]) } hidePaths = append(hidePaths, dir) @@ -229,19 +229,19 @@ func newContainer(s *hst.ContainerConfig, os sys.State, prefix string, uid, gid if !s.AutoEtc { if s.Etc != "" { - params.Bind(s.Etc, "/etc", 0) + params.Bind(s.Etc, container.FHSEtc, 0) } } else { etcPath := s.Etc if etcPath == "" { - etcPath = "/etc" + etcPath = container.FHSEtc } params.Etc(etcPath, prefix) } // no more ContainerConfig paths beyond this point if !s.Device { - params.Remount("/dev", syscall.MS_RDONLY) + params.Remount(container.FHSDev, syscall.MS_RDONLY) } return params, maps.Clone(s.Env), nil diff --git a/internal/app/process_linux.go b/internal/app/process_linux.go index 516beb4b..088deab3 100644 --- a/internal/app/process_linux.go +++ b/internal/app/process_linux.go @@ -88,7 +88,7 @@ func (seal *outcome) Run(rs *RunState) error { defer cancel() cmd := exec.CommandContext(ctx, hsuPath) cmd.Stdin, cmd.Stdout, cmd.Stderr = os.Stdin, os.Stdout, os.Stderr - cmd.Dir = "/" // container init enters final working directory + cmd.Dir = container.FHSRoot // container init enters final working directory // shim runs in the same session as monitor; see shim.go for behaviour cmd.Cancel = func() error { return cmd.Process.Signal(syscall.SIGCONT) } diff --git a/internal/app/seal_linux.go b/internal/app/seal_linux.go index 6bf6c092..5b2b2c0e 100644 --- a/internal/app/seal_linux.go +++ b/internal/app/seal_linux.go @@ -242,19 +242,19 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co Tty: true, AutoEtc: true, - AutoRoot: "/", + AutoRoot: container.FHSRoot, RootFlags: container.BindWritable, } // bind GPU stuff if config.Enablements&(system.EX11|system.EWayland) != 0 { - conf.Filesystem = append(conf.Filesystem, &hst.FilesystemConfig{Src: "/dev/dri", Device: true}) + conf.Filesystem = append(conf.Filesystem, &hst.FilesystemConfig{Src: container.FHSDev + "dri", Device: true}) } // opportunistically bind kvm - conf.Filesystem = append(conf.Filesystem, &hst.FilesystemConfig{Src: "/dev/kvm", Device: true}) + conf.Filesystem = append(conf.Filesystem, &hst.FilesystemConfig{Src: container.FHSDev + "kvm", Device: true}) // hide nscd from container if present - const nscd = "/var/run/nscd" + const nscd = container.FHSVar + "run/nscd" if _, err := sys.Stat(nscd); !errors.Is(err, fs.ErrNotExist) { conf.Filesystem = append(conf.Filesystem, &hst.FilesystemConfig{Dst: nscd, Src: hst.SourceTmpfs}) } @@ -290,7 +290,7 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co } // inner XDG_RUNTIME_DIR default formatting of `/run/user/%d` as mapped uid - innerRuntimeDir := path.Join("/run/user", mapuid.String()) + innerRuntimeDir := path.Join(container.FHSRunUser, mapuid.String()) seal.env[xdgRuntimeDir] = innerRuntimeDir seal.env[xdgSessionClass] = "user" seal.env[xdgSessionType] = "tty" @@ -307,7 +307,7 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co runtimeDirInst := path.Join(runtimeDir, seal.user.aid.String()) seal.sys.Ensure(runtimeDirInst, 0700) seal.sys.UpdatePermType(system.User, runtimeDirInst, acl.Read, acl.Write, acl.Execute) - seal.container.Tmpfs("/run/user", 1<<12, 0755) + seal.container.Tmpfs(container.FHSRunUser, 1<<12, 0755) seal.container.Bind(runtimeDirInst, innerRuntimeDir, container.BindWritable) } @@ -319,11 +319,11 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co seal.sys.Ensure(tmpdirInst, 01700) seal.sys.UpdatePermType(system.User, tmpdirInst, acl.Read, acl.Write, acl.Execute) // mount inner /tmp from share so it shares persistence and storage behaviour of host /tmp - seal.container.Bind(tmpdirInst, "/tmp", container.BindWritable) + seal.container.Bind(tmpdirInst, container.FHSTmp, container.BindWritable) } { - homeDir := "/var/empty" + homeDir := container.FHSVarEmpty if seal.user.home != "" { homeDir = seal.user.home } @@ -337,9 +337,9 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co seal.env["USER"] = username seal.env[shell] = config.Shell - seal.container.Place("/etc/passwd", + seal.container.Place(container.FHSEtc+"passwd", []byte(username+":x:"+mapuid.String()+":"+mapgid.String()+":Hakurei:"+homeDir+":"+config.Shell+"\n")) - seal.container.Place("/etc/group", + seal.container.Place(container.FHSEtc+"group", []byte("hakurei:x:"+mapgid.String()+":\n")) } @@ -388,7 +388,7 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co } else { seal.sys.ChangeHosts("#" + seal.user.uid.String()) seal.env[display] = d - seal.container.Bind("/tmp/.X11-unix", "/tmp/.X11-unix", 0) + seal.container.Bind(container.FHSTmp+".X11-unix", container.FHSTmp+".X11-unix", 0) } } @@ -467,7 +467,7 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co seal.container.Bind(sessionPath, sessionInner, 0) seal.sys.UpdatePerm(sessionPath, acl.Read, acl.Write) if config.SystemBus != nil { - systemInner := "/run/dbus/system_bus_socket" + systemInner := container.FHSRun + "dbus/system_bus_socket" seal.env[dbusSystemBusAddress] = "unix:path=" + systemInner seal.container.Bind(systemPath, systemInner, 0) seal.sys.UpdatePerm(systemPath, acl.Read, acl.Write) @@ -475,7 +475,7 @@ func (seal *outcome) finalise(ctx context.Context, sys sys.State, config *hst.Co } // mount root read-only as the final setup Op - seal.container.Remount("/", syscall.MS_RDONLY) + seal.container.Remount(container.FHSRoot, syscall.MS_RDONLY) // append ExtraPerms last for _, p := range config.ExtraPerms { |
