]>
git.proxmox.com Git - mirror_lxc.git/blob - src/lxc/namespace.c
2 * lxc: linux Container library
4 * (C) Copyright IBM Corp. 2007, 2009
7 * Daniel Lezcano <daniel.lezcano at free.fr>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2.1 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
31 #include <sys/param.h>
33 #include <sys/syscall.h>
34 #include <sys/types.h>
39 #include "memory_utils.h"
40 #include "namespace.h"
43 lxc_log_define(namespace, lxc
);
50 static int do_clone(void *arg
)
52 struct clone_arg
*clone_arg
= arg
;
53 return clone_arg
->fn(clone_arg
->arg
);
56 #define __LXC_STACK_SIZE 4096
57 pid_t
lxc_clone(int (*fn
)(void *), void *arg
, int flags
, int *pidfd
)
61 struct clone_arg clone_arg
= {
65 char *stack
[__LXC_STACK_SIZE
] = {0};
66 stack_size
= __LXC_STACK_SIZE
;
69 ret
= __clone2(do_clone
, stack
, stack_size
, flags
| SIGCHLD
, &clone_arg
, pidfd
);
71 ret
= clone(do_clone
, stack
+ stack_size
, flags
| SIGCHLD
, &clone_arg
, pidfd
);
74 SYSERROR("Failed to clone (%#x)", flags
);
79 /* Leave the user namespace at the first position in the array of structs so
80 * that we always attach to it first when iterating over the struct and using
81 * setns() to switch namespaces. This especially affects lxc_attach(): Suppose
82 * you cloned a new user namespace and mount namespace as an unprivileged user
83 * on the host and want to setns() to the mount namespace. This requires you to
84 * attach to the user namespace first otherwise the kernel will fail this check:
86 * if (!ns_capable(mnt_ns->user_ns, CAP_SYS_ADMIN) ||
87 * !ns_capable(current_user_ns(), CAP_SYS_CHROOT) ||
88 * !ns_capable(current_user_ns(), CAP_SYS_ADMIN))
93 * linux/fs/namespace.c:mntns_install().
95 const struct ns_info ns_info
[LXC_NS_MAX
] = {
96 [LXC_NS_USER
] = { "user", CLONE_NEWUSER
, "CLONE_NEWUSER", "LXC_USER_NS" },
97 [LXC_NS_MNT
] = { "mnt", CLONE_NEWNS
, "CLONE_NEWNS", "LXC_MNT_NS" },
98 [LXC_NS_PID
] = { "pid", CLONE_NEWPID
, "CLONE_NEWPID", "LXC_PID_NS" },
99 [LXC_NS_UTS
] = { "uts", CLONE_NEWUTS
, "CLONE_NEWUTS", "LXC_UTS_NS" },
100 [LXC_NS_IPC
] = { "ipc", CLONE_NEWIPC
, "CLONE_NEWIPC", "LXC_IPC_NS" },
101 [LXC_NS_NET
] = { "net", CLONE_NEWNET
, "CLONE_NEWNET", "LXC_NET_NS" },
102 [LXC_NS_CGROUP
] = { "cgroup", CLONE_NEWCGROUP
, "CLONE_NEWCGROUP", "LXC_CGROUP_NS" }
105 int lxc_namespace_2_cloneflag(const char *namespace)
109 for (i
= 0; i
< LXC_NS_MAX
; i
++)
110 if (!strcasecmp(ns_info
[i
].proc_name
, namespace))
111 return ns_info
[i
].clone_flag
;
113 ERROR("Invalid namespace name \"%s\"", namespace);
117 int lxc_namespace_2_ns_idx(const char *namespace)
121 for (i
= 0; i
< LXC_NS_MAX
; i
++)
122 if (!strcmp(ns_info
[i
].proc_name
, namespace))
125 ERROR("Invalid namespace name \"%s\"", namespace);
129 extern int lxc_namespace_2_std_identifiers(char *namespaces
)
134 /* The identifiers for namespaces used with lxc-attach and lxc-unshare
135 * as given on the manpage do not align with the standard identifiers.
136 * This affects network, mount, and uts namespaces. The standard identifiers
137 * are: "mnt", "uts", and "net" whereas lxc-attach and lxc-unshare uses
138 * "MOUNT", "UTSNAME", and "NETWORK". So let's use some cheap memmove()s
139 * to replace them by their standard identifiers.
140 * Let's illustrate this with an example:
147 * dest: del + 1 == OUNT|PID
148 * src: del + 3 == NT|PID
153 while ((del
= strstr(namespaces
, "MOUNT")))
154 memmove(del
+ 1, del
+ 3, strlen(del
) - 2);
156 for (it
= (char *[]){"NETWORK", "UTSNAME", NULL
}; it
&& *it
; it
++)
157 while ((del
= strstr(namespaces
, *it
)))
158 memmove(del
+ 3, del
+ 7, strlen(del
) - 6);
163 int lxc_fill_namespace_flags(char *flaglist
, int *flags
)
169 ERROR("At least one namespace is needed.");
173 lxc_iterate_parts(token
, flaglist
, "|") {
174 aflag
= lxc_namespace_2_cloneflag(token
);