lxc: encode device permission into configuration
Closes: #804 Signed-off-by: Shengjing Zhu <i@zhsj.me>
This commit is contained in:
parent
04469cd38b
commit
3d05266cae
7 changed files with 30 additions and 23 deletions
|
|
@ -249,9 +249,9 @@ anbox::cmds::SessionManager::SessionManager()
|
||||||
};
|
};
|
||||||
|
|
||||||
container_configuration.devices = {
|
container_configuration.devices = {
|
||||||
{"/dev/binder"},
|
{"/dev/binder", {0666}},
|
||||||
{"/dev/ashmem"},
|
{"/dev/ashmem", {0666}},
|
||||||
{"/dev/fuse"},
|
{"/dev/fuse", {0666}},
|
||||||
};
|
};
|
||||||
|
|
||||||
dispatcher->dispatch([&]() {
|
dispatcher->dispatch([&]() {
|
||||||
|
|
|
||||||
|
|
@ -20,13 +20,15 @@
|
||||||
|
|
||||||
#include <string>
|
#include <string>
|
||||||
#include <unordered_map>
|
#include <unordered_map>
|
||||||
#include <vector>
|
|
||||||
|
|
||||||
namespace anbox {
|
namespace anbox {
|
||||||
namespace container {
|
namespace container {
|
||||||
|
struct DeviceSpecification {
|
||||||
|
uint32_t permission;
|
||||||
|
};
|
||||||
struct Configuration {
|
struct Configuration {
|
||||||
std::unordered_map<std::string, std::string> bind_mounts;
|
std::unordered_map<std::string, std::string> bind_mounts;
|
||||||
std::vector<std::string> devices;
|
std::unordered_map<std::string, DeviceSpecification> devices;
|
||||||
};
|
};
|
||||||
} // namespace container
|
} // namespace container
|
||||||
} // namespace anbox
|
} // namespace anbox
|
||||||
|
|
|
||||||
|
|
@ -166,7 +166,7 @@ void LxcContainer::setup_network() {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
void LxcContainer::add_device(const std::string& device) {
|
void LxcContainer::add_device(const std::string& device, const DeviceSpecification& spec) {
|
||||||
struct stat st;
|
struct stat st;
|
||||||
int r = stat(device.c_str(), &st);
|
int r = stat(device.c_str(), &st);
|
||||||
if (r < 0) {
|
if (r < 0) {
|
||||||
|
|
@ -176,7 +176,7 @@ void LxcContainer::add_device(const std::string& device) {
|
||||||
|
|
||||||
const auto major = device_major(st.st_rdev);
|
const auto major = device_major(st.st_rdev);
|
||||||
const auto minor = device_minor(st.st_rdev);
|
const auto minor = device_minor(st.st_rdev);
|
||||||
const auto mode = st.st_mode;
|
const auto mode = ((st.st_mode >> 9) << 9) | (spec.permission & ~(1 << 9));
|
||||||
const auto new_device_name = fs::basename(device);
|
const auto new_device_name = fs::basename(device);
|
||||||
const auto devices_path = fs::path(SystemConfiguration::instance().container_devices_dir());
|
const auto devices_path = fs::path(SystemConfiguration::instance().container_devices_dir());
|
||||||
const auto new_device_path = (devices_path / new_device_name).string();
|
const auto new_device_path = (devices_path / new_device_name).string();
|
||||||
|
|
@ -318,13 +318,13 @@ void LxcContainer::start(const Configuration &configuration) {
|
||||||
auto devices = configuration.devices;
|
auto devices = configuration.devices;
|
||||||
|
|
||||||
// Additional devices we need in our container
|
// Additional devices we need in our container
|
||||||
devices.push_back("/dev/console");
|
devices.insert({"/dev/console", {0600}});
|
||||||
devices.push_back("/dev/full");
|
devices.insert({"/dev/full", {0666}});
|
||||||
devices.push_back("/dev/null");
|
devices.insert({"/dev/null", {0666}});
|
||||||
devices.push_back("/dev/random");
|
devices.insert({"/dev/random", {0666}});
|
||||||
devices.push_back("/dev/tty");
|
devices.insert({"/dev/tty", {0666}});
|
||||||
devices.push_back("/dev/urandom");
|
devices.insert({"/dev/urandom", {0666}});
|
||||||
devices.push_back("/dev/zero");
|
devices.insert({"/dev/zero", {0666}});
|
||||||
|
|
||||||
// Remove all left over devices from last time first before
|
// Remove all left over devices from last time first before
|
||||||
// creating any new ones
|
// creating any new ones
|
||||||
|
|
@ -333,7 +333,7 @@ void LxcContainer::start(const Configuration &configuration) {
|
||||||
fs::create_directories(devices_dir);
|
fs::create_directories(devices_dir);
|
||||||
|
|
||||||
for (const auto& device : devices)
|
for (const auto& device : devices)
|
||||||
add_device(device);
|
add_device(device.first, device.second);
|
||||||
|
|
||||||
if (!container_->save_config(container_, nullptr))
|
if (!container_->save_config(container_, nullptr))
|
||||||
throw std::runtime_error("Failed to save container configuration");
|
throw std::runtime_error("Failed to save container configuration");
|
||||||
|
|
|
||||||
|
|
@ -40,7 +40,7 @@ class LxcContainer : public Container {
|
||||||
void set_config_item(const std::string &key, const std::string &value);
|
void set_config_item(const std::string &key, const std::string &value);
|
||||||
void setup_id_map();
|
void setup_id_map();
|
||||||
void setup_network();
|
void setup_network();
|
||||||
void add_device(const std::string& device);
|
void add_device(const std::string& device, const DeviceSpecification& spec);
|
||||||
|
|
||||||
State state_;
|
State state_;
|
||||||
lxc_container *container_;
|
lxc_container *container_;
|
||||||
|
|
|
||||||
|
|
@ -55,7 +55,7 @@ void ManagementApiSkeleton::start_container(
|
||||||
|
|
||||||
for (int n = 0; n < configuration.devices_size(); n++) {
|
for (int n = 0; n < configuration.devices_size(); n++) {
|
||||||
const auto device = configuration.devices(n);
|
const auto device = configuration.devices(n);
|
||||||
container_configuration.devices.push_back(device);
|
container_configuration.devices.insert({device.path(), {device.permission()}});
|
||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
|
|
|
||||||
|
|
@ -45,13 +45,14 @@ void ManagementApiStub::start_container(const Configuration &configuration) {
|
||||||
bind_mount_message->set_target(item.second);
|
bind_mount_message->set_target(item.second);
|
||||||
}
|
}
|
||||||
|
|
||||||
message.set_allocated_configuration(message_configuration);
|
for (const auto &item: configuration.devices) {
|
||||||
|
auto device_message = message_configuration->add_devices();
|
||||||
for (const auto &device : configuration.devices) {
|
device_message->set_path(item.first);
|
||||||
auto d = message_configuration->add_devices();
|
device_message->set_permission(item.second.permission);
|
||||||
*d = device;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
message.set_allocated_configuration(message_configuration);
|
||||||
|
|
||||||
{
|
{
|
||||||
std::lock_guard<decltype(mutex_)> lock(mutex_);
|
std::lock_guard<decltype(mutex_)> lock(mutex_);
|
||||||
c->wh.expect_result();
|
c->wh.expect_result();
|
||||||
|
|
|
||||||
|
|
@ -7,8 +7,12 @@ message Configuration {
|
||||||
required string source = 1;
|
required string source = 1;
|
||||||
required string target = 2;
|
required string target = 2;
|
||||||
}
|
}
|
||||||
|
message Devices {
|
||||||
|
required string path = 1;
|
||||||
|
required uint32 permission = 2;
|
||||||
|
}
|
||||||
repeated BindMount bind_mounts = 1;
|
repeated BindMount bind_mounts = 1;
|
||||||
repeated string devices = 2;
|
repeated Devices devices = 2;
|
||||||
}
|
}
|
||||||
|
|
||||||
message StartContainer {
|
message StartContainer {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue