]>
git.proxmox.com Git - mirror_lxc.git/blob - src/lxc/start.c
2 * lxc: linux Container library
4 * (C) Copyright IBM Corp. 2007, 2008
7 * Daniel Lezcano <dlezcano at fr.ibm.com>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2.1 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
33 #include <sys/param.h>
35 #include <sys/mount.h>
36 #include <sys/types.h>
37 #include <sys/prctl.h>
38 #include <sys/capability.h>
45 LXC_TTY_HANDLER(SIGINT
);
46 LXC_TTY_HANDLER(SIGQUIT
);
48 int lxc_start(const char *name
, char *argv
[])
50 char init
[MAXPATHLEN
];
52 char ttyname
[MAXPATHLEN
];
53 int fd
, lock
, sv
[2], sync
= 0, err
= -LXC_ERROR_INTERNAL
;
57 lock
= lxc_get_lock(name
);
59 lxc_log_error("'%s' is busy", name
);
60 return -LXC_ERROR_BUSY
;
64 lxc_log_error("failed to acquire lock on '%s':%s",
65 name
, strerror(-lock
));
66 return -LXC_ERROR_INTERNAL
;
69 /* Begin the set the state to STARTING*/
70 if (lxc_setstate(name
, STARTING
)) {
71 lxc_log_error("failed to set state %s", lxc_state2str(STARTING
));
75 if (readlink("/proc/self/fd/0", ttyname
, sizeof(ttyname
)) < 0) {
76 lxc_log_syserror("failed to read '/proc/self/fd/0'");
81 /* Synchro socketpair */
82 if (socketpair(AF_LOCAL
, SOCK_STREAM
, 0, sv
)) {
83 lxc_log_syserror("failed to create communication socketpair");
87 /* Avoid signals from terminal */
88 LXC_TTY_ADD_HANDLER(SIGINT
);
89 LXC_TTY_ADD_HANDLER(SIGQUIT
);
91 clone_flags
= CLONE_NEWPID
|CLONE_NEWIPC
|CLONE_NEWNS
;
92 if (conf_has_utsname(name
))
93 clone_flags
|= CLONE_NEWUTS
;
94 if (conf_has_network(name
))
95 clone_flags
|= CLONE_NEWNET
;
97 /* Create a process in a new set of namespaces */
98 pid
= fork_ns(clone_flags
);
100 lxc_log_syserror("failed to fork into a new namespace");
108 /* Be sure we don't inherit this after the exec */
109 fcntl(sv
[0], F_SETFD
, FD_CLOEXEC
);
111 /* Tell our father he can begin to configure the container */
112 if (write(sv
[0], &sync
, sizeof(sync
)) < 0) {
113 lxc_log_syserror("failed to write socket");
117 /* Wait for the father to finish the configuration */
118 if (read(sv
[0], &sync
, sizeof(sync
)) < 0) {
119 lxc_log_syserror("failed to read socket");
123 /* Setup the container, ip, names, utsname, ... */
124 if (lxc_setup(name
)) {
125 lxc_log_error("failed to setup the container");
126 if (write(sv
[0], &sync
, sizeof(sync
)) < 0)
127 lxc_log_syserror("failed to write the socket");
131 if (mount(ttyname
, "/dev/console", "none", MS_BIND
, 0)) {
132 lxc_log_syserror("failed to mount '/dev/console'");
136 if (prctl(PR_CAPBSET_DROP
, CAP_SYS_BOOT
, 0, 0, 0)) {
137 lxc_log_syserror("failed to remove CAP_SYS_BOOT capability");
141 execvp(argv
[0], argv
);
142 lxc_log_syserror("failed to exec %s", argv
[0]);
144 /* If the exec fails, tell that to our father */
145 if (write(sv
[0], &sync
, sizeof(sync
)) < 0)
146 lxc_log_syserror("failed to write the socket");
154 /* Wait for the child to be ready */
155 if (read(sv
[1], &sync
, sizeof(sync
)) < 0) {
156 lxc_log_syserror("failed to read the socket");
160 if (lxc_link_nsgroup(name
, pid
))
161 lxc_log_warning("cgroupfs not found: cgroup disabled");
163 /* Create the network configuration */
164 if (clone_flags
& CLONE_NEWNET
&& conf_create_network(name
, pid
)) {
165 lxc_log_error("failed to create the configured network");
166 goto err_create_network
;
169 /* Tell the child to continue its initialization */
170 if (write(sv
[1], &sync
, sizeof(sync
)) < 0) {
171 lxc_log_syserror("failed to write the socket");
175 /* Wait for the child to exec or returning an error */
176 err
= read(sv
[1], &sync
, sizeof(sync
));
178 lxc_log_error("failed to read the socket");
183 lxc_log_error("something went wrong with %d", pid
);
184 /* TODO : check status etc ... */
185 waitpid(pid
, NULL
, 0);
186 goto err_child_failed
;
189 asprintf(&val
, "%d\n", pid
);
191 snprintf(init
, MAXPATHLEN
, LXCPATH
"/%s/init", name
);
193 fd
= open(init
, O_WRONLY
|O_CREAT
|O_TRUNC
, S_IRUSR
|S_IWUSR
);
195 lxc_log_syserror("failed to open '%s'", init
);
199 if (write(fd
, val
, strlen(val
)) < 0) {
200 lxc_log_syserror("failed to write the init pid");
206 if (lxc_setstate(name
, RUNNING
)) {
207 lxc_log_error("failed to set state to %s",
208 lxc_state2str(RUNNING
));
209 goto err_state_failed
;
213 if (waitpid(pid
, NULL
, 0) < 0) {
216 lxc_log_syserror("failed to wait the pid %d", pid
);
217 goto err_waitpid_failed
;
220 if (lxc_setstate(name
, STOPPING
))
221 lxc_log_error("failed to set state %s", lxc_state2str(STOPPING
));
223 #ifdef NETWORK_DESTROY
224 if (clone_flags
& CLONE_NEWNET
&& conf_destroy_network(name
))
225 lxc_log_error("failed to destroy the network");
230 if (lxc_setstate(name
, STOPPED
))
231 lxc_log_error("failed to set state %s", lxc_state2str(STOPPED
));
233 lxc_unlink_nsgroup(name
);
237 LXC_TTY_DEL_HANDLER(SIGQUIT
);
238 LXC_TTY_DEL_HANDLER(SIGINT
);
249 #ifdef NETWORK_DESTROY
250 if (clone_flags
& CLONE_NEWNET
)
251 conf_destroy_network(name
);
256 if (lxc_setstate(name
, ABORTING
))
257 lxc_log_error("failed to set state %s", lxc_state2str(STOPPED
));