Signed-off-by: John Howard <jhoward@microsoft.com>
| ... | ... |
@@ -4,7 +4,9 @@ import ( |
| 4 | 4 |
"fmt" |
| 5 | 5 |
"os" |
| 6 | 6 |
"syscall" |
| 7 |
+ "unsafe" |
|
| 7 | 8 |
|
| 9 |
+ winio "github.com/Microsoft/go-winio" |
|
| 8 | 10 |
"github.com/Sirupsen/logrus" |
| 9 | 11 |
"github.com/docker/docker/pkg/signal" |
| 10 | 12 |
"github.com/docker/docker/pkg/system" |
| ... | ... |
@@ -13,18 +15,27 @@ import ( |
| 13 | 13 |
func setupDumpStackTrap(root string) {
|
| 14 | 14 |
// Windows does not support signals like *nix systems. So instead of |
| 15 | 15 |
// trapping on SIGUSR1 to dump stacks, we wait on a Win32 event to be |
| 16 |
- // signaled. |
|
| 16 |
+ // signaled. ACL'd to builtin administrators and local system |
|
| 17 |
+ ev := "Global\\docker-daemon-" + fmt.Sprint(os.Getpid()) |
|
| 18 |
+ sd, err := winio.SddlToSecurityDescriptor("D:P(A;;GA;;;BA)(A;;GA;;;SY)")
|
|
| 19 |
+ if err != nil {
|
|
| 20 |
+ logrus.Errorf("failed to get security descriptor for debug stackdump event %s: %s", ev, err.Error())
|
|
| 21 |
+ return |
|
| 22 |
+ } |
|
| 23 |
+ var sa syscall.SecurityAttributes |
|
| 24 |
+ sa.Length = uint32(unsafe.Sizeof(sa)) |
|
| 25 |
+ sa.InheritHandle = 1 |
|
| 26 |
+ sa.SecurityDescriptor = uintptr(unsafe.Pointer(&sd[0])) |
|
| 27 |
+ h, err := system.CreateEvent(&sa, false, false, ev) |
|
| 28 |
+ if h == 0 || err != nil {
|
|
| 29 |
+ logrus.Errorf("failed to create debug stackdump event %s: %s", ev, err.Error())
|
|
| 30 |
+ return |
|
| 31 |
+ } |
|
| 17 | 32 |
go func() {
|
| 18 |
- sa := syscall.SecurityAttributes{
|
|
| 19 |
- Length: 0, |
|
| 20 |
- } |
|
| 21 |
- ev := "Global\\docker-daemon-" + fmt.Sprint(os.Getpid()) |
|
| 22 |
- if h, _ := system.CreateEvent(&sa, false, false, ev); h != 0 {
|
|
| 23 |
- logrus.Debugf("Stackdump - waiting signal at %s", ev)
|
|
| 24 |
- for {
|
|
| 25 |
- syscall.WaitForSingleObject(h, syscall.INFINITE) |
|
| 26 |
- signal.DumpStacks(root) |
|
| 27 |
- } |
|
| 33 |
+ logrus.Debugf("Stackdump - waiting signal at %s", ev)
|
|
| 34 |
+ for {
|
|
| 35 |
+ syscall.WaitForSingleObject(h, syscall.INFINITE) |
|
| 36 |
+ signal.DumpStacks(root) |
|
| 28 | 37 |
} |
| 29 | 38 |
}() |
| 30 | 39 |
} |