Merge branch 'master' into update-android-img
This commit is contained in:
commit
bd174b89e2
4 changed files with 85 additions and 18 deletions
|
|
@ -119,6 +119,12 @@ if (NOT "${HOST_CMAKE_C_COMPILER}" STREQUAL "")
|
||||||
message(STATUS "Host C compiler: ${HOST_CMAKE_CXX_COMPILER}")
|
message(STATUS "Host C compiler: ${HOST_CMAKE_CXX_COMPILER}")
|
||||||
endif()
|
endif()
|
||||||
|
|
||||||
|
option(SNAP_CONFINEMENT "Enable snap confinement support" OFF)
|
||||||
|
if (SNAP_CONFINEMENT)
|
||||||
|
message(STATUS "Building with support for snap confinement")
|
||||||
|
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -DENABLE_SNAP_CONFINEMENT")
|
||||||
|
endif()
|
||||||
|
|
||||||
install(FILES data/ui/loading-screen.png DESTINATION ${ANBOX_RESOURCE_DIR}/ui)
|
install(FILES data/ui/loading-screen.png DESTINATION ${ANBOX_RESOURCE_DIR}/ui)
|
||||||
|
|
||||||
# uninstall target
|
# uninstall target
|
||||||
|
|
|
||||||
|
|
@ -53,11 +53,6 @@ start() {
|
||||||
# lib directory as explicit search target here.
|
# lib directory as explicit search target here.
|
||||||
export LD_LIBRARY_PATH="$LD_LIBRARY_PATH:$SNAP/usr/lib/$ARCH"
|
export LD_LIBRARY_PATH="$LD_LIBRARY_PATH:$SNAP/usr/lib/$ARCH"
|
||||||
|
|
||||||
if [ -d /sys/kernel/security/apparmor ] ; then
|
|
||||||
# Load the profile for our Android container
|
|
||||||
"$SNAP"/sbin/apparmor_parser -r "$SNAP"/apparmor/anbox-container.aa
|
|
||||||
fi
|
|
||||||
|
|
||||||
enable_debug="$(snapctl get debug.enable)"
|
enable_debug="$(snapctl get debug.enable)"
|
||||||
if [ "$enable_debug" = true ]; then
|
if [ "$enable_debug" = true ]; then
|
||||||
export ANBOX_LOG_LEVEL=debug
|
export ANBOX_LOG_LEVEL=debug
|
||||||
|
|
|
||||||
|
|
@ -16,25 +16,44 @@ grade: devel
|
||||||
architectures: [amd64]
|
architectures: [amd64]
|
||||||
|
|
||||||
slots:
|
slots:
|
||||||
# Depending on in which environment we're running we either need
|
dbus-session-slot:
|
||||||
# to use the system or session DBus so we also need to have one
|
|
||||||
# slot for each.
|
|
||||||
dbus-session:
|
|
||||||
interface: dbus
|
interface: dbus
|
||||||
bus: system
|
bus: session
|
||||||
name: org.anbox
|
name: org.anbox
|
||||||
dbus-system:
|
|
||||||
|
plugs:
|
||||||
|
dbus-session-plug:
|
||||||
interface: dbus
|
interface: dbus
|
||||||
bus: system
|
bus: session
|
||||||
name: org.anbox
|
name: org.anbox
|
||||||
|
|
||||||
apps:
|
apps:
|
||||||
anbox:
|
anbox:
|
||||||
command: desktop-launch $SNAP/bin/anbox-wrapper.sh
|
command: desktop-launch $SNAP/bin/anbox-wrapper.sh
|
||||||
|
slots:
|
||||||
|
- dbus-session-slot
|
||||||
|
plugs:
|
||||||
|
- x11
|
||||||
|
- unity7
|
||||||
|
- network
|
||||||
|
- opengl
|
||||||
|
- wayland
|
||||||
|
- pulseaudio
|
||||||
|
- home
|
||||||
|
- process-control
|
||||||
|
- desktop
|
||||||
|
|
||||||
container-manager:
|
container-manager:
|
||||||
command: bin/container-manager.sh start
|
command: bin/container-manager.sh start
|
||||||
stop-command: bin/container-manager.sh stop
|
stop-command: bin/container-manager.sh stop
|
||||||
daemon: simple
|
daemon: simple
|
||||||
|
plugs:
|
||||||
|
- firewall-control
|
||||||
|
- kernel-module-control
|
||||||
|
- mount-observe
|
||||||
|
- network-control
|
||||||
|
- network-bind
|
||||||
|
|
||||||
collect-bug-info:
|
collect-bug-info:
|
||||||
command: bin/collect-bug-info.sh
|
command: bin/collect-bug-info.sh
|
||||||
shell:
|
shell:
|
||||||
|
|
@ -42,9 +61,36 @@ apps:
|
||||||
android-settings:
|
android-settings:
|
||||||
command: desktop-launch $SNAP/bin/app-android-settings.sh
|
command: desktop-launch $SNAP/bin/app-android-settings.sh
|
||||||
desktop: desktop/android-settings.desktop
|
desktop: desktop/android-settings.desktop
|
||||||
|
slots:
|
||||||
|
- dbus-session-slot
|
||||||
|
plugs:
|
||||||
|
- dbus-session-plug
|
||||||
|
- x11
|
||||||
|
- unity7
|
||||||
|
- network
|
||||||
|
- opengl
|
||||||
|
- wayland
|
||||||
|
- pulseaudio
|
||||||
|
- home
|
||||||
|
- process-control
|
||||||
|
- desktop
|
||||||
|
|
||||||
appmgr:
|
appmgr:
|
||||||
command: desktop-launch $SNAP/bin/app-appmgr.sh
|
command: desktop-launch $SNAP/bin/app-appmgr.sh
|
||||||
desktop: desktop/appmgr.desktop
|
desktop: desktop/appmgr.desktop
|
||||||
|
slots:
|
||||||
|
- dbus-session-slot
|
||||||
|
plugs:
|
||||||
|
- dbus-session-plug
|
||||||
|
- x11
|
||||||
|
- unity7
|
||||||
|
- network
|
||||||
|
- opengl
|
||||||
|
- wayland
|
||||||
|
- pulseaudio
|
||||||
|
- home
|
||||||
|
- process-control
|
||||||
|
- desktop
|
||||||
|
|
||||||
parts:
|
parts:
|
||||||
android:
|
android:
|
||||||
|
|
@ -102,7 +148,7 @@ parts:
|
||||||
lxc:
|
lxc:
|
||||||
source: https://github.com/lxc/lxc
|
source: https://github.com/lxc/lxc
|
||||||
source-type: git
|
source-type: git
|
||||||
source-tag: lxc-3.0.0
|
source-tag: lxc-3.0.1
|
||||||
build-packages:
|
build-packages:
|
||||||
- libapparmor-dev
|
- libapparmor-dev
|
||||||
- libcap-dev
|
- libcap-dev
|
||||||
|
|
@ -125,6 +171,16 @@ parts:
|
||||||
- --enable-capabilities
|
- --enable-capabilities
|
||||||
- --with-rootfs-path=/var/snap/anbox/common/lxc/
|
- --with-rootfs-path=/var/snap/anbox/common/lxc/
|
||||||
- --libexecdir=/snap/anbox/current/libexec/
|
- --libexecdir=/snap/anbox/current/libexec/
|
||||||
|
override-build: |
|
||||||
|
set -ex
|
||||||
|
git config user.email "buildbot@anbox.io"
|
||||||
|
git config user.name "Anbox Buildbot"
|
||||||
|
git remote add anbox https://github.com/anbox/lxc
|
||||||
|
git fetch anbox
|
||||||
|
# apparmor: don't require a transition for Anbox child profiles
|
||||||
|
git cherry-pick 2f81fb7c91560b32e506bb874f8cd63e37985906
|
||||||
|
set +ex
|
||||||
|
snapcraftctl build
|
||||||
organize:
|
organize:
|
||||||
snap/anbox/current/libexec: libexec
|
snap/anbox/current/libexec: libexec
|
||||||
prime:
|
prime:
|
||||||
|
|
@ -195,6 +251,9 @@ parts:
|
||||||
# that is fixed we can avoid using a prefix here.
|
# that is fixed we can avoid using a prefix here.
|
||||||
- -DCMAKE_INSTALL_PREFIX:PATH=/usr
|
- -DCMAKE_INSTALL_PREFIX:PATH=/usr
|
||||||
- -DANBOX_VERSION=$SNAPCRAFT_PROJECT_VERSION
|
- -DANBOX_VERSION=$SNAPCRAFT_PROJECT_VERSION
|
||||||
|
# FIXME: Once we have everything in place for full snap confinement we
|
||||||
|
# can securely enable this.
|
||||||
|
# - -DSNAP_CONFINEMENT=ON
|
||||||
build-packages:
|
build-packages:
|
||||||
- build-essential
|
- build-essential
|
||||||
- cmake
|
- cmake
|
||||||
|
|
|
||||||
|
|
@ -266,6 +266,13 @@ void LxcContainer::start(const Configuration &configuration) {
|
||||||
|
|
||||||
set_config_item("lxc.init.cmd", "/anbox-init.sh");
|
set_config_item("lxc.init.cmd", "/anbox-init.sh");
|
||||||
|
|
||||||
|
#if ENABLE_SNAP_CONFINEMENT
|
||||||
|
// If we're running inside the snap environment snap-confine already created a
|
||||||
|
// cgroup for us we need to use as otherwise presevering a namespace wont help.
|
||||||
|
if (utils::is_env_set("SNAP"))
|
||||||
|
set_config_item("lxc.namespace.keep", "cgroup");
|
||||||
|
#endif
|
||||||
|
|
||||||
auto rootfs_path = SystemConfiguration::instance().rootfs_dir();
|
auto rootfs_path = SystemConfiguration::instance().rootfs_dir();
|
||||||
if (rootfs_overlay_)
|
if (rootfs_overlay_)
|
||||||
rootfs_path = SystemConfiguration::instance().combined_rootfs_dir();
|
rootfs_path = SystemConfiguration::instance().combined_rootfs_dir();
|
||||||
|
|
@ -283,11 +290,11 @@ void LxcContainer::start(const Configuration &configuration) {
|
||||||
|
|
||||||
setup_network();
|
setup_network();
|
||||||
|
|
||||||
#if 0
|
#if ENABLE_SNAP_CONFINEMENT
|
||||||
set_config_item("lxc.apparmor.profile", "anbox-container");
|
// We take the AppArmor profile snapd has defined for us as part of the
|
||||||
|
// anbox-support interface. The container manager itself runs within a
|
||||||
const auto seccomp_profile_path = fs::path(utils::get_env_value("SNAP", "/etc/anbox")) / "seccomp" / "anbox.sc";
|
// child profile snap.anbox.container-manager//lxc too.
|
||||||
set_config_item("lxc.seccomp.profile", seccomp_profile_path.string().c_str());
|
set_config_item("lxc.apparmor.profile", "snap.anbox.container-manager//container");
|
||||||
#else
|
#else
|
||||||
set_config_item("lxc.apparmor.profile", "unconfined");
|
set_config_item("lxc.apparmor.profile", "unconfined");
|
||||||
#endif
|
#endif
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue