container: correct code formatting

This commit is contained in:
Simon Fels 2018-06-10 19:12:48 +02:00
commit a1738a5192
2 changed files with 17 additions and 23 deletions

View file

@ -39,7 +39,7 @@
namespace fs = boost::filesystem; namespace fs = boost::filesystem;
namespace { namespace {
constexpr unsigned int unprivileged_user_id{100000}; constexpr unsigned int unprivileged_uid{100000};
constexpr const char *default_container_ip_address{"192.168.250.2"}; constexpr const char *default_container_ip_address{"192.168.250.2"};
constexpr const std::uint32_t default_container_ip_prefix_length{24}; constexpr const std::uint32_t default_container_ip_prefix_length{24};
constexpr const char *default_host_ip_address{"192.168.250.1"}; constexpr const char *default_host_ip_address{"192.168.250.1"};
@ -69,31 +69,25 @@ LxcContainer::~LxcContainer() {
if (container_) lxc_container_put(container_); if (container_) lxc_container_put(container_);
} }
void LxcContainer::setup_id_maps() { void LxcContainer::setup_id_map() {
const auto base_id = unprivileged_user_id; const auto base_id = unprivileged_uid;
const auto max_id = 65536; const auto max_id = 65536;
set_config_item("lxc.id_map", set_config_item("lxc.id_map", utils::string_format("u 0 %d %d", base_id, creds_.uid() - 1));
utils::string_format("u 0 %d %d", base_id, creds_.uid() - 1)); set_config_item("lxc.id_map", utils::string_format("g 0 %d %d", base_id, creds_.gid() - 1));
set_config_item("lxc.id_map",
utils::string_format("g 0 %d %d", base_id, creds_.gid() - 1));
// We need to bind the user id for the one running the client side // We need to bind the user id for the one running the client side
// process as he is the owner of various socket files we bind mount // process as he is the owner of various socket files we bind mount
// into the container. // into the container.
set_config_item("lxc.id_map", set_config_item("lxc.id_map", utils::string_format("u %d %d 1", creds_.uid(), creds_.uid()));
utils::string_format("u %d %d 1", creds_.uid(), creds_.uid())); set_config_item("lxc.id_map", utils::string_format("g %d %d 1", creds_.gid(), creds_.gid()));
set_config_item("lxc.id_map",
utils::string_format("g %d %d 1", creds_.gid(), creds_.gid()));
set_config_item("lxc.id_map", set_config_item("lxc.id_map", utils::string_format("u %d %d %d", creds_.uid() + 1,
utils::string_format("u %d %d %d", creds_.uid() + 1, base_id + creds_.uid() + 1,
base_id + creds_.uid() + 1, max_id - creds_.uid() - 1));
max_id - creds_.uid() - 1)); set_config_item("lxc.id_map", utils::string_format("g %d %d %d", creds_.uid() + 1,
set_config_item("lxc.id_map", base_id + creds_.gid() + 1,
utils::string_format("g %d %d %d", creds_.uid() + 1, max_id - creds_.gid() - 1));
base_id + creds_.gid() + 1,
max_id - creds_.gid() - 1));
} }
void LxcContainer::setup_network() { void LxcContainer::setup_network() {
@ -148,7 +142,7 @@ void LxcContainer::setup_network() {
if (st.st_uid != 0 && st.st_gid != 0) if (st.st_uid != 0 && st.st_gid != 0)
continue; continue;
if (::chown(path.c_str(), unprivileged_user_id, unprivileged_user_id) < 0) if (::chown(path.c_str(), unprivileged_uid, unprivileged_uid) < 0)
WARNING("Failed to set owner for path '%s'", path); WARNING("Failed to set owner for path '%s'", path);
} }
@ -188,7 +182,7 @@ void LxcContainer::add_device(const std::string& device) {
throw std::runtime_error(msg); throw std::runtime_error(msg);
} }
auto base_uid = unprivileged_user_id; auto base_uid = unprivileged_uid;
if (privileged_) if (privileged_)
base_uid = 0; base_uid = 0;
@ -279,7 +273,7 @@ void LxcContainer::start(const Configuration &configuration) {
set_config_item("lxc.aa_profile", "anbox-container"); set_config_item("lxc.aa_profile", "anbox-container");
if (!privileged_) if (!privileged_)
setup_id_maps(); setup_id_map();
auto bind_mounts = configuration.bind_mounts; auto bind_mounts = configuration.bind_mounts;
for (const auto &bind_mount : bind_mounts) { for (const auto &bind_mount : bind_mounts) {

View file

@ -38,7 +38,7 @@ class LxcContainer : public Container {
private: private:
void set_config_item(const std::string &key, const std::string &value); void set_config_item(const std::string &key, const std::string &value);
void setup_id_maps(); void setup_id_map();
void setup_network(); void setup_network();
void add_device(const std::string& device); void add_device(const std::string& device);