From c08b795494ff545e1406866a05566ab9c84a4379 Mon Sep 17 00:00:00 2001 From: Simon Fels Date: Tue, 23 May 2017 08:31:54 +0200 Subject: [PATCH] Assign current owner to the IP configuration dir If we don't assign the unprivileged user as owner the container will fail to start as the Android services wont be able to write anything into the created directory hierarchy. --- src/anbox/container/lxc_container.cpp | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/src/anbox/container/lxc_container.cpp b/src/anbox/container/lxc_container.cpp index ee388a9..485a6c2 100644 --- a/src/anbox/container/lxc_container.cpp +++ b/src/anbox/container/lxc_container.cpp @@ -36,6 +36,7 @@ namespace fs = boost::filesystem; namespace { +constexpr unsigned int unprivileged_user_id{100000}; constexpr const char *default_container_ip_address{"192.168.250.2"}; constexpr const std::uint32_t default_container_ip_prefix_length{24}; constexpr const char *default_host_ip_address{"192.168.250.1"}; @@ -58,8 +59,7 @@ LxcContainer::~LxcContainer() { } void LxcContainer::setup_id_maps() { - // FIXME make these id sets configurable - const auto base_id = 100000; + const auto base_id = unprivileged_user_id; const auto max_id = 65536; set_config_item("lxc.id_map", @@ -112,10 +112,22 @@ void LxcContainer::setup_network() { common::BinaryWriter writer(buffer.begin(), buffer.end()); const auto size = ip_conf.write(writer); - const auto ip_conf_dir = SystemConfiguration::instance().data_dir() / "data" / "misc" / "ethernet"; - if (!fs::exists(ip_conf_dir)) + const auto data_ethernet_path = fs::path("data") / "misc" / "ethernet"; + const auto ip_conf_dir = SystemConfiguration::instance().data_dir() / data_ethernet_path; + if (!fs::exists(ip_conf_dir)) { fs::create_directories(ip_conf_dir); + // We have to walk through the created directory hierachy now and + // ensure the permissions are set correctly. Otherwise the Android + // system will fail to boot as it isn't allowed to write anything + // into these directories. + for (auto iter = data_ethernet_path.begin(); iter != data_ethernet_path.end(); iter++) { + const auto path = SystemConfiguration::instance().data_dir() / *iter; + if (::chown(path.c_str(), unprivileged_user_id, unprivileged_user_id) < 0) + WARNING("Failed to set owner for path '%s'", path); + } + } + const auto ip_conf_path = ip_conf_dir / "ipconfig.txt"; if (fs::exists(ip_conf_path)) fs::remove(ip_conf_path);