aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/workflows/doc.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/workflows/doc.go')
-rw-r--r--internal/workflows/doc.go18
1 files changed, 15 insertions, 3 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go
index e34c59c8..a8f18ab4 100644
--- a/internal/workflows/doc.go
+++ b/internal/workflows/doc.go
@@ -20,7 +20,8 @@ The Gitea act_runner simply bind mounts whatever socket it sees into the
container. With a regular docker daemon, this allows not only a simple container
escape, but also privilege escalation as unconstrained root in the init
namespace. To mitigate this, set up an unprivileged podman daemon and expose its
-socket to the container instead.
+socket to the container instead. Since mountinfo always use credentials from the
+init user namespace, subordinate user and group ID must always be 100000.
On Alpine Linux, this is achieved by:
@@ -67,6 +68,7 @@ Before starting the container, configure act_runner via config.yaml:
-v /var/lib/rosa:/rosa
--security-opt='unmask=/proc/*'
--cap-add=SYS_ADMIN
+ --cap-add=SYS_PTRACE
--device=/dev/kvm
--device=/dev/fuse
valid_volumes:
@@ -76,8 +78,9 @@ where /var/lib/rosa is the absolute pathname of the cache directory in the init
namespace. Setting MBF_POISON_OPEN enables cmd/mbf to run as root. It is also
a good idea here to set runner.capacity to reflect the capacity of the guest, so
jobs can be consumed quicker. Removing mount points covering /proc enables
-testing of cmd/hakurei. Exposing the fuse device and adding capability SYS_ADMIN
-enables testing of cmd/sharefs.
+testing of cmd/hakurei. Exposing the fuse device and adding capability
+CAP_SYS_ADMIN enables testing of cmd/sharefs. Adding capability CAP_SYS_PTRACE
+enables dumping seccomp filters via ptrace on the patched kernel.
Build a statically-linked cmd/mbf:
@@ -120,6 +123,15 @@ this can be achieved by the init script:
It is often a good idea to populate the cache from a mirror service before the
first workflow job is started and re-populate it after every cmd/mbf update.
+# Configuring the kernel
+
+In order to attach to the container process, the sysctl kernel.yama.ptrace_scope
+must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to
+your kernel sources, compile and install the new kernel. Refer to
+https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux.
+If running podman or docker as root, the patch is not required. Do not apply
+this patch on a system meant to be secure.
+
# Security
The design of Microsoft Github workflows is inherently insecure: it requires