lxc: encode device permission into configuration

Closes: #804
Signed-off-by: Shengjing Zhu <i@zhsj.me>
This commit is contained in:
Shengjing Zhu 2018-07-13 13:23:14 +08:00
commit 3d05266cae
7 changed files with 30 additions and 23 deletions

View file

@ -249,9 +249,9 @@ anbox::cmds::SessionManager::SessionManager()
}; };
container_configuration.devices = { container_configuration.devices = {
{"/dev/binder"}, {"/dev/binder", {0666}},
{"/dev/ashmem"}, {"/dev/ashmem", {0666}},
{"/dev/fuse"}, {"/dev/fuse", {0666}},
}; };
dispatcher->dispatch([&]() { dispatcher->dispatch([&]() {

View file

@ -20,13 +20,15 @@
#include <string> #include <string>
#include <unordered_map> #include <unordered_map>
#include <vector>
namespace anbox { namespace anbox {
namespace container { namespace container {
struct DeviceSpecification {
uint32_t permission;
};
struct Configuration { struct Configuration {
std::unordered_map<std::string, std::string> bind_mounts; std::unordered_map<std::string, std::string> bind_mounts;
std::vector<std::string> devices; std::unordered_map<std::string, DeviceSpecification> devices;
}; };
} // namespace container } // namespace container
} // namespace anbox } // namespace anbox

View file

@ -166,7 +166,7 @@ void LxcContainer::setup_network() {
} }
} }
void LxcContainer::add_device(const std::string& device) { void LxcContainer::add_device(const std::string& device, const DeviceSpecification& spec) {
struct stat st; struct stat st;
int r = stat(device.c_str(), &st); int r = stat(device.c_str(), &st);
if (r < 0) { if (r < 0) {
@ -176,7 +176,7 @@ void LxcContainer::add_device(const std::string& device) {
const auto major = device_major(st.st_rdev); const auto major = device_major(st.st_rdev);
const auto minor = device_minor(st.st_rdev); const auto minor = device_minor(st.st_rdev);
const auto mode = st.st_mode; const auto mode = ((st.st_mode >> 9) << 9) | (spec.permission & ~(1 << 9));
const auto new_device_name = fs::basename(device); const auto new_device_name = fs::basename(device);
const auto devices_path = fs::path(SystemConfiguration::instance().container_devices_dir()); const auto devices_path = fs::path(SystemConfiguration::instance().container_devices_dir());
const auto new_device_path = (devices_path / new_device_name).string(); const auto new_device_path = (devices_path / new_device_name).string();
@ -318,13 +318,13 @@ void LxcContainer::start(const Configuration &configuration) {
auto devices = configuration.devices; auto devices = configuration.devices;
// Additional devices we need in our container // Additional devices we need in our container
devices.push_back("/dev/console"); devices.insert({"/dev/console", {0600}});
devices.push_back("/dev/full"); devices.insert({"/dev/full", {0666}});
devices.push_back("/dev/null"); devices.insert({"/dev/null", {0666}});
devices.push_back("/dev/random"); devices.insert({"/dev/random", {0666}});
devices.push_back("/dev/tty"); devices.insert({"/dev/tty", {0666}});
devices.push_back("/dev/urandom"); devices.insert({"/dev/urandom", {0666}});
devices.push_back("/dev/zero"); devices.insert({"/dev/zero", {0666}});
// Remove all left over devices from last time first before // Remove all left over devices from last time first before
// creating any new ones // creating any new ones
@ -333,7 +333,7 @@ void LxcContainer::start(const Configuration &configuration) {
fs::create_directories(devices_dir); fs::create_directories(devices_dir);
for (const auto& device : devices) for (const auto& device : devices)
add_device(device); add_device(device.first, device.second);
if (!container_->save_config(container_, nullptr)) if (!container_->save_config(container_, nullptr))
throw std::runtime_error("Failed to save container configuration"); throw std::runtime_error("Failed to save container configuration");

View file

@ -40,7 +40,7 @@ class LxcContainer : public Container {
void set_config_item(const std::string &key, const std::string &value); void set_config_item(const std::string &key, const std::string &value);
void setup_id_map(); void setup_id_map();
void setup_network(); void setup_network();
void add_device(const std::string& device); void add_device(const std::string& device, const DeviceSpecification& spec);
State state_; State state_;
lxc_container *container_; lxc_container *container_;

View file

@ -55,7 +55,7 @@ void ManagementApiSkeleton::start_container(
for (int n = 0; n < configuration.devices_size(); n++) { for (int n = 0; n < configuration.devices_size(); n++) {
const auto device = configuration.devices(n); const auto device = configuration.devices(n);
container_configuration.devices.push_back(device); container_configuration.devices.insert({device.path(), {device.permission()}});
} }
try { try {

View file

@ -45,13 +45,14 @@ void ManagementApiStub::start_container(const Configuration &configuration) {
bind_mount_message->set_target(item.second); bind_mount_message->set_target(item.second);
} }
message.set_allocated_configuration(message_configuration); for (const auto &item: configuration.devices) {
auto device_message = message_configuration->add_devices();
for (const auto &device : configuration.devices) { device_message->set_path(item.first);
auto d = message_configuration->add_devices(); device_message->set_permission(item.second.permission);
*d = device;
} }
message.set_allocated_configuration(message_configuration);
{ {
std::lock_guard<decltype(mutex_)> lock(mutex_); std::lock_guard<decltype(mutex_)> lock(mutex_);
c->wh.expect_result(); c->wh.expect_result();

View file

@ -7,8 +7,12 @@ message Configuration {
required string source = 1; required string source = 1;
required string target = 2; required string target = 2;
} }
message Devices {
required string path = 1;
required uint32 permission = 2;
}
repeated BindMount bind_mounts = 1; repeated BindMount bind_mounts = 1;
repeated string devices = 2; repeated Devices devices = 2;
} }
message StartContainer { message StartContainer {