From f01ce872e87986785dc5a2f303e3e1cddf2a7d3d Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Thu, 8 Dec 2016 17:06:08 +0100 Subject: [PATCH 1/4] Drop static DHCP configuration of eth0 --- android/anboxd.rc | 6 ------ 1 file changed, 6 deletions(-) diff --git a/android/anboxd.rc b/android/anboxd.rc index 4a77419..5b70dac 100644 --- a/android/anboxd.rc +++ b/android/anboxd.rc @@ -1,8 +1,2 @@ service anboxd /system/bin/anboxd class core - -# We will ever only have a single network interface we need to care -# about so we can add static setup for this one here. -service anbox-network /system/bin/dhcptool eth0 - class main - oneshot From fc55e2c59a1675ba8ae1efa2bf6c7c7bb29d7b96 Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Thu, 8 Dec 2016 17:06:52 +0100 Subject: [PATCH 2/4] Get rid of dropping capabilities as this prevents gaining relevant ones in the container --- src/anbox/container/lxc_container.cpp | 4 ---- 1 file changed, 4 deletions(-) diff --git a/src/anbox/container/lxc_container.cpp b/src/anbox/container/lxc_container.cpp index 4167a1a..4d959f1 100644 --- a/src/anbox/container/lxc_container.cpp +++ b/src/anbox/container/lxc_container.cpp @@ -80,10 +80,6 @@ void LxcContainer::start(const Configuration &configuration) { if (container_->is_running(container_)) container_->stop(container_); } - // We drop all not needed capabilities - set_config_item("lxc.cap.drop", - "mac_admin mac_override sys_time sys_module sys_rawio"); - // We can mount proc/sys as rw here as we will run the container unprivileged // in the end set_config_item("lxc.mount.auto", "proc:mixed sys:mixed cgroup:mixed"); From 03583e360c0ca73a6d34d8e40ef73462d735ad17 Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Thu, 8 Dec 2016 17:07:36 +0100 Subject: [PATCH 3/4] Get rid of unwanted debug message --- src/anbox/bridge/android_api_stub.cpp | 2 -- 1 file changed, 2 deletions(-) diff --git a/src/anbox/bridge/android_api_stub.cpp b/src/anbox/bridge/android_api_stub.cpp index b26d383..9b1f11b 100644 --- a/src/anbox/bridge/android_api_stub.cpp +++ b/src/anbox/bridge/android_api_stub.cpp @@ -121,8 +121,6 @@ void AndroidApiStub::remove_task(const std::int32_t &id) { auto c = std::make_shared>(); - DEBUG(""); - protobuf::bridge::RemoveTask message; message.set_id(id); From cbb4beaac2e239f259090ac89b5e996154cb67bc Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Thu, 8 Dec 2016 17:08:18 +0100 Subject: [PATCH 4/4] Restructure container manager startup script Mount /cache and /data properly and stop bridge correctly. --- scripts/container-manager.sh | 78 ++++++++++++++++++++++-------------- snapcraft.yaml | 3 +- 2 files changed, 50 insertions(+), 31 deletions(-) diff --git a/scripts/container-manager.sh b/scripts/container-manager.sh index 8ff72ee..8dd9fe8 100755 --- a/scripts/container-manager.sh +++ b/scripts/container-manager.sh @@ -21,41 +21,59 @@ if [ ! -e $SYSTEM_IMG ]; then exit 1 fi -# Extract ramdisk content instead of trying to bind mount the -# cpio image file to allow modifications. -rm -Rf $RAMDISK_PATH -mkdir -p $RAMDISK_PATH -cd $RAMDISK_PATH -cat $INITRD | gzip -d | cpio -i +start() { + # Extract ramdisk content instead of trying to bind mount the + # cpio image file to allow modifications. + rm -Rf $RAMDISK_PATH + mkdir -p $RAMDISK_PATH + cd $RAMDISK_PATH + cat $INITRD | gzip -d | cpio -i -# FIXME those things should be fixed in the build process -chmod +x $RAMDISK_PATH/anbox-init.sh + # FIXME those things should be fixed in the build process + chmod +x $RAMDISK_PATH/anbox-init.sh -# Setup the read-only rootfs -mkdir -p $ROOTFS_PATH -mount -o bind,ro $RAMDISK_PATH $ROOTFS_PATH -mount -o loop,ro $SYSTEM_IMG $ROOTFS_PATH/system + # Setup the read-only rootfs + mkdir -p $ROOTFS_PATH + mount -o bind,ro $RAMDISK_PATH $ROOTFS_PATH + mount -o loop,ro $SYSTEM_IMG $ROOTFS_PATH/system -# but certain top-level directories need to be in a writable space -for dir in cache data; do - mkdir -p $DATA_PATH/android-$dir - mount -o bind $DATA_PATH/android-$dir $ROOTFS_PATH/$dir -done + # but certain top-level directories need to be in a writable space + for dir in cache data; do + mkdir -p $DATA_PATH/android-$dir + mount -o bind $DATA_PATH/android-$dir $ROOTFS_PATH/$dir + done -# Make sure our setup path for the container rootfs -# is present as lxc is statically configured for -# this path. -mkdir -p $SNAP_COMMON/lxc + # Make sure our setup path for the container rootfs + # is present as lxc is statically configured for + # this path. + mkdir -p $SNAP_COMMON/lxc -# We start the bridge here as long as a oneshot service unit is not -# possible. See snapcraft.yaml for further details. -$SNAP/bin/anbox-bridge.sh start + # We start the bridge here as long as a oneshot service unit is not + # possible. See snapcraft.yaml for further details. + $SNAP/bin/anbox-bridge.sh start -$SNAP/usr/sbin/aa-exec -p unconfined -- $SNAP/bin/anbox-wrapper.sh container-manager -pid=$! -waitpid $pid + exec $SNAP/usr/sbin/aa-exec -p unconfined -- $SNAP/bin/anbox-wrapper.sh container-manager +} -$SNAP/bin/anbox-bridge.sh stop +stop() { + for dir in cache data; do + umount $ROOTFS_PATH/$dir + done + umount $ROOTFS_PATH/system + umount $ROOTFS_PATH -umount $ROOTFS_PATH/system -umount $ROOTFS_PATH/data + $SNAP/bin/anbox-bridge.sh stop +} + +case "$1" in + start) + start + ;; + stop) + stop + ;; + *) + echo "ERROR: Unknown command '$1'" + exit 1 + ;; +esac diff --git a/snapcraft.yaml b/snapcraft.yaml index 95abac0..376defc 100644 --- a/snapcraft.yaml +++ b/snapcraft.yaml @@ -12,7 +12,8 @@ apps: anbox: command: bin/anbox-wrapper.sh container-manager: - command: bin/container-manager.sh + command: bin/container-manager.sh start + stop-command: bin/container-manager.sh stop daemon: simple # FIXME: a oneshot unit with start/stop commands needs also RemainAfterExit=yes # but this isn't supported by snapd yet. See LP #1647169 for details.