| ... | ... |
@@ -1,15 +1,10 @@ |
| 1 | 1 |
package network |
| 2 | 2 |
|
| 3 | 3 |
import ( |
| 4 |
- "errors" |
|
| 5 | 4 |
"github.com/dotcloud/docker/pkg/netlink" |
| 6 | 5 |
"net" |
| 7 | 6 |
) |
| 8 | 7 |
|
| 9 |
-var ( |
|
| 10 |
- ErrNoDefaultRoute = errors.New("no default network route found")
|
|
| 11 |
-) |
|
| 12 |
- |
|
| 13 | 8 |
func InterfaceUp(name string) error {
|
| 14 | 9 |
iface, err := net.InterfaceByName(name) |
| 15 | 10 |
if err != nil {
|
| ... | ... |
@@ -46,14 +41,6 @@ func SetInterfaceInNamespacePid(name string, nsPid int) error {
|
| 46 | 46 |
return netlink.NetworkSetNsPid(iface, nsPid) |
| 47 | 47 |
} |
| 48 | 48 |
|
| 49 |
-func SetInterfaceInNamespaceFd(name string, fd int) error {
|
|
| 50 |
- iface, err := net.InterfaceByName(name) |
|
| 51 |
- if err != nil {
|
|
| 52 |
- return err |
|
| 53 |
- } |
|
| 54 |
- return netlink.NetworkSetNsFd(iface, fd) |
|
| 55 |
-} |
|
| 56 |
- |
|
| 57 | 49 |
func SetInterfaceMaster(name, master string) error {
|
| 58 | 50 |
iface, err := net.InterfaceByName(name) |
| 59 | 51 |
if err != nil {
|
| ... | ... |
@@ -89,16 +76,3 @@ func SetMtu(name string, mtu int) error {
|
| 89 | 89 |
} |
| 90 | 90 |
return netlink.NetworkSetMTU(iface, mtu) |
| 91 | 91 |
} |
| 92 |
- |
|
| 93 |
-func GetDefaultMtu() (int, error) {
|
|
| 94 |
- routes, err := netlink.NetworkGetRoutes() |
|
| 95 |
- if err != nil {
|
|
| 96 |
- return -1, err |
|
| 97 |
- } |
|
| 98 |
- for _, r := range routes {
|
|
| 99 |
- if r.Default {
|
|
| 100 |
- return r.Iface.MTU, nil |
|
| 101 |
- } |
|
| 102 |
- } |
|
| 103 |
- return -1, ErrNoDefaultRoute |
|
| 104 |
-} |
| ... | ... |
@@ -8,65 +8,54 @@ import ( |
| 8 | 8 |
"github.com/dotcloud/docker/pkg/system" |
| 9 | 9 |
"github.com/dotcloud/docker/pkg/term" |
| 10 | 10 |
"io" |
| 11 |
- "log" |
|
| 11 |
+ "io/ioutil" |
|
| 12 | 12 |
"os" |
| 13 | 13 |
"os/exec" |
| 14 | 14 |
"syscall" |
| 15 | 15 |
) |
| 16 | 16 |
|
| 17 |
-func execCommand(container *libcontainer.Container) (pid int, err error) {
|
|
| 17 |
+func execCommand(container *libcontainer.Container) (int, error) {
|
|
| 18 | 18 |
master, console, err := createMasterAndConsole() |
| 19 | 19 |
if err != nil {
|
| 20 | 20 |
return -1, err |
| 21 | 21 |
} |
| 22 | 22 |
|
| 23 |
- // we need CLONE_VFORK so we can wait on the child |
|
| 24 |
- flag := uintptr(getNamespaceFlags(container.Namespaces) | CLONE_VFORK) |
|
| 25 |
- |
|
| 26 |
- command := exec.Command("nsinit", console)
|
|
| 23 |
+ command := exec.Command("nsinit", "init", console)
|
|
| 27 | 24 |
command.SysProcAttr = &syscall.SysProcAttr{
|
| 28 |
- Cloneflags: flag, |
|
| 25 |
+ Cloneflags: uintptr(getNamespaceFlags(container.Namespaces) | syscall.CLONE_VFORK), // we need CLONE_VFORK so we can wait on the child |
|
| 29 | 26 |
} |
| 30 | 27 |
|
| 31 | 28 |
inPipe, err := command.StdinPipe() |
| 32 | 29 |
if err != nil {
|
| 33 | 30 |
return -1, err |
| 34 | 31 |
} |
| 35 |
- |
|
| 36 | 32 |
if err := command.Start(); err != nil {
|
| 37 | 33 |
return -1, err |
| 38 | 34 |
} |
| 39 |
- pid = command.Process.Pid |
|
| 35 |
+ if err := writePidFile(command); err != nil {
|
|
| 36 |
+ return -1, err |
|
| 37 |
+ } |
|
| 40 | 38 |
|
| 41 | 39 |
if container.Network != nil {
|
| 42 | 40 |
name1, name2, err := createVethPair() |
| 43 | 41 |
if err != nil {
|
| 44 |
- log.Fatal(err) |
|
| 42 |
+ return -1, err |
|
| 45 | 43 |
} |
| 46 | 44 |
if err := network.SetInterfaceMaster(name1, container.Network.Bridge); err != nil {
|
| 47 |
- log.Fatal(err) |
|
| 45 |
+ return -1, err |
|
| 48 | 46 |
} |
| 49 | 47 |
if err := network.InterfaceUp(name1); err != nil {
|
| 50 |
- log.Fatal(err) |
|
| 48 |
+ return -1, err |
|
| 51 | 49 |
} |
| 52 |
- if err := network.SetInterfaceInNamespacePid(name2, pid); err != nil {
|
|
| 53 |
- log.Fatal(err) |
|
| 50 |
+ if err := network.SetInterfaceInNamespacePid(name2, command.Process.Pid); err != nil {
|
|
| 51 |
+ return -1, err |
|
| 54 | 52 |
} |
| 55 | 53 |
fmt.Fprint(inPipe, name2) |
| 56 | 54 |
inPipe.Close() |
| 57 | 55 |
} |
| 58 | 56 |
|
| 59 |
- go func() {
|
|
| 60 |
- if _, err := io.Copy(os.Stdout, master); err != nil {
|
|
| 61 |
- log.Println(err) |
|
| 62 |
- } |
|
| 63 |
- }() |
|
| 64 |
- |
|
| 65 |
- go func() {
|
|
| 66 |
- if _, err := io.Copy(master, os.Stdin); err != nil {
|
|
| 67 |
- log.Println(err) |
|
| 68 |
- } |
|
| 69 |
- }() |
|
| 57 |
+ go io.Copy(os.Stdout, master) |
|
| 58 |
+ go io.Copy(master, os.Stdin) |
|
| 70 | 59 |
|
| 71 | 60 |
ws, err := term.GetWinsize(os.Stdin.Fd()) |
| 72 | 61 |
if err != nil {
|
| ... | ... |
@@ -83,9 +72,11 @@ func execCommand(container *libcontainer.Container) (pid int, err error) {
|
| 83 | 83 |
defer term.RestoreTerminal(os.Stdin.Fd(), state) |
| 84 | 84 |
|
| 85 | 85 |
if err := command.Wait(); err != nil {
|
| 86 |
- return pid, err |
|
| 86 |
+ if _, ok := err.(*exec.ExitError); !ok {
|
|
| 87 |
+ return -1, err |
|
| 88 |
+ } |
|
| 87 | 89 |
} |
| 88 |
- return pid, nil |
|
| 90 |
+ return command.ProcessState.Sys().(syscall.WaitStatus).ExitStatus(), nil |
|
| 89 | 91 |
} |
| 90 | 92 |
|
| 91 | 93 |
func createMasterAndConsole() (*os.File, string, error) {
|
| ... | ... |
@@ -93,12 +84,10 @@ func createMasterAndConsole() (*os.File, string, error) {
|
| 93 | 93 |
if err != nil {
|
| 94 | 94 |
return nil, "", err |
| 95 | 95 |
} |
| 96 |
- |
|
| 97 | 96 |
console, err := system.Ptsname(master) |
| 98 | 97 |
if err != nil {
|
| 99 | 98 |
return nil, "", err |
| 100 | 99 |
} |
| 101 |
- |
|
| 102 | 100 |
if err := system.Unlockpt(master); err != nil {
|
| 103 | 101 |
return nil, "", err |
| 104 | 102 |
} |
| ... | ... |
@@ -119,3 +108,7 @@ func createVethPair() (name1 string, name2 string, err error) {
|
| 119 | 119 |
} |
| 120 | 120 |
return |
| 121 | 121 |
} |
| 122 |
+ |
|
| 123 |
+func writePidFile(command *exec.Cmd) error {
|
|
| 124 |
+ return ioutil.WriteFile(".nspid", []byte(fmt.Sprint(command.Process.Pid)), 0655)
|
|
| 125 |
+} |
| ... | ... |
@@ -1,7 +1,6 @@ |
| 1 | 1 |
package main |
| 2 | 2 |
|
| 3 | 3 |
import ( |
| 4 |
- "encoding/json" |
|
| 5 | 4 |
"fmt" |
| 6 | 5 |
"github.com/dotcloud/docker/pkg/libcontainer" |
| 7 | 6 |
"github.com/dotcloud/docker/pkg/libcontainer/capabilities" |
| ... | ... |
@@ -14,49 +13,21 @@ import ( |
| 14 | 14 |
"syscall" |
| 15 | 15 |
) |
| 16 | 16 |
|
| 17 |
-func loadContainer() (*libcontainer.Container, error) {
|
|
| 18 |
- f, err := os.Open("container.json")
|
|
| 19 |
- if err != nil {
|
|
| 20 |
- return nil, err |
|
| 21 |
- } |
|
| 22 |
- defer f.Close() |
|
| 23 |
- |
|
| 24 |
- var container *libcontainer.Container |
|
| 25 |
- if err := json.NewDecoder(f).Decode(&container); err != nil {
|
|
| 26 |
- return nil, err |
|
| 27 |
- } |
|
| 28 |
- return container, nil |
|
| 29 |
-} |
|
| 30 |
- |
|
| 31 |
-func main() {
|
|
| 32 |
- container, err := loadContainer() |
|
| 33 |
- if err != nil {
|
|
| 34 |
- log.Fatal(err) |
|
| 35 |
- } |
|
| 36 |
- |
|
| 37 |
- if os.Args[1] == "exec" {
|
|
| 38 |
- _, err := execCommand(container) |
|
| 39 |
- if err != nil {
|
|
| 40 |
- log.Fatal(err) |
|
| 41 |
- } |
|
| 42 |
- os.Exit(0) |
|
| 43 |
- } |
|
| 44 |
- console := os.Args[1] |
|
| 45 |
- |
|
| 17 |
+func initCommand(container *libcontainer.Container, console string) error {
|
|
| 46 | 18 |
if err := setLogFile(container); err != nil {
|
| 47 |
- log.Fatal(err) |
|
| 19 |
+ return err |
|
| 48 | 20 |
} |
| 49 | 21 |
|
| 50 | 22 |
rootfs, err := resolveRootfs() |
| 51 | 23 |
if err != nil {
|
| 52 |
- log.Fatal(err) |
|
| 24 |
+ return err |
|
| 53 | 25 |
} |
| 54 | 26 |
|
| 55 | 27 |
var tempVethName string |
| 56 | 28 |
if container.Network != nil {
|
| 57 | 29 |
data, err := ioutil.ReadAll(os.Stdin) |
| 58 | 30 |
if err != nil {
|
| 59 |
- log.Fatalf("error reading from stdin %s", err)
|
|
| 31 |
+ return fmt.Errorf("error reading from stdin %s", err)
|
|
| 60 | 32 |
} |
| 61 | 33 |
tempVethName = string(data) |
| 62 | 34 |
} |
| ... | ... |
@@ -68,48 +39,48 @@ func main() {
|
| 68 | 68 |
|
| 69 | 69 |
slave, err := openTerminal(console, syscall.O_RDWR) |
| 70 | 70 |
if err != nil {
|
| 71 |
- log.Fatalf("open terminal %s", err)
|
|
| 71 |
+ return fmt.Errorf("open terminal %s", err)
|
|
| 72 | 72 |
} |
| 73 | 73 |
if slave.Fd() != 0 {
|
| 74 |
- log.Fatalf("slave fd should be 0")
|
|
| 74 |
+ return fmt.Errorf("slave fd should be 0")
|
|
| 75 | 75 |
} |
| 76 | 76 |
if err := dupSlave(slave); err != nil {
|
| 77 |
- log.Fatalf("dup2 slave %s", err)
|
|
| 77 |
+ return fmt.Errorf("dup2 slave %s", err)
|
|
| 78 | 78 |
} |
| 79 | 79 |
if _, err := system.Setsid(); err != nil {
|
| 80 |
- log.Fatalf("setsid %s", err)
|
|
| 80 |
+ return fmt.Errorf("setsid %s", err)
|
|
| 81 | 81 |
} |
| 82 | 82 |
if err := system.Setctty(); err != nil {
|
| 83 |
- log.Fatalf("setctty %s", err)
|
|
| 83 |
+ return fmt.Errorf("setctty %s", err)
|
|
| 84 | 84 |
} |
| 85 | 85 |
if err := system.ParentDeathSignal(); err != nil {
|
| 86 |
- log.Fatalf("parent deth signal %s", err)
|
|
| 86 |
+ return fmt.Errorf("parent deth signal %s", err)
|
|
| 87 | 87 |
} |
| 88 | 88 |
if err := setupNewMountNamespace(rootfs, console, container.ReadonlyFs); err != nil {
|
| 89 |
- log.Fatalf("setup mount namespace %s", err)
|
|
| 89 |
+ return fmt.Errorf("setup mount namespace %s", err)
|
|
| 90 | 90 |
} |
| 91 | 91 |
if container.Network != nil {
|
| 92 | 92 |
if err := setupNetworking(container.Network, tempVethName); err != nil {
|
| 93 |
- log.Fatalf("setup networking %s", err)
|
|
| 93 |
+ return fmt.Errorf("setup networking %s", err)
|
|
| 94 | 94 |
} |
| 95 | 95 |
} |
| 96 | 96 |
|
| 97 | 97 |
if err := system.Sethostname(container.ID); err != nil {
|
| 98 |
- log.Fatalf("sethostname %s", err)
|
|
| 98 |
+ return fmt.Errorf("sethostname %s", err)
|
|
| 99 | 99 |
} |
| 100 | 100 |
if err := capabilities.DropCapabilities(container); err != nil {
|
| 101 |
- log.Fatalf("drop capabilities %s", err)
|
|
| 101 |
+ return fmt.Errorf("drop capabilities %s", err)
|
|
| 102 | 102 |
} |
| 103 | 103 |
if err := setupUser(container); err != nil {
|
| 104 |
- log.Fatalf("setup user %s", err)
|
|
| 104 |
+ return fmt.Errorf("setup user %s", err)
|
|
| 105 | 105 |
} |
| 106 | 106 |
if container.WorkingDir != "" {
|
| 107 | 107 |
if err := system.Chdir(container.WorkingDir); err != nil {
|
| 108 |
- log.Fatalf("chdir to %s %s", container.WorkingDir, err)
|
|
| 108 |
+ return fmt.Errorf("chdir to %s %s", container.WorkingDir, err)
|
|
| 109 | 109 |
} |
| 110 | 110 |
} |
| 111 | 111 |
if err := system.Exec(container.Command.Args[0], container.Command.Args[0:], container.Command.Env); err != nil {
|
| 112 |
- log.Fatalf("exec %s", err)
|
|
| 112 |
+ return fmt.Errorf("exec %s", err)
|
|
| 113 | 113 |
} |
| 114 | 114 |
panic("unreachable")
|
| 115 | 115 |
} |
| 116 | 116 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,42 @@ |
| 0 |
+package main |
|
| 1 |
+ |
|
| 2 |
+import ( |
|
| 3 |
+ "encoding/json" |
|
| 4 |
+ "github.com/dotcloud/docker/pkg/libcontainer" |
|
| 5 |
+ "log" |
|
| 6 |
+ "os" |
|
| 7 |
+) |
|
| 8 |
+ |
|
| 9 |
+func main() {
|
|
| 10 |
+ container, err := loadContainer() |
|
| 11 |
+ if err != nil {
|
|
| 12 |
+ log.Fatal(err) |
|
| 13 |
+ } |
|
| 14 |
+ |
|
| 15 |
+ switch os.Args[1] {
|
|
| 16 |
+ case "exec": |
|
| 17 |
+ exitCode, err := execCommand(container) |
|
| 18 |
+ if err != nil {
|
|
| 19 |
+ log.Fatal(err) |
|
| 20 |
+ } |
|
| 21 |
+ os.Exit(exitCode) |
|
| 22 |
+ case "init": |
|
| 23 |
+ if err := initCommand(container, os.Args[2]); err != nil {
|
|
| 24 |
+ log.Fatal(err) |
|
| 25 |
+ } |
|
| 26 |
+ } |
|
| 27 |
+} |
|
| 28 |
+ |
|
| 29 |
+func loadContainer() (*libcontainer.Container, error) {
|
|
| 30 |
+ f, err := os.Open("container.json")
|
|
| 31 |
+ if err != nil {
|
|
| 32 |
+ return nil, err |
|
| 33 |
+ } |
|
| 34 |
+ defer f.Close() |
|
| 35 |
+ |
|
| 36 |
+ var container *libcontainer.Container |
|
| 37 |
+ if err := json.NewDecoder(f).Decode(&container); err != nil {
|
|
| 38 |
+ return nil, err |
|
| 39 |
+ } |
|
| 40 |
+ return container, nil |
|
| 41 |
+} |
| ... | ... |
@@ -3,68 +3,47 @@ package main |
| 3 | 3 |
import ( |
| 4 | 4 |
"fmt" |
| 5 | 5 |
"github.com/dotcloud/docker/pkg/system" |
| 6 |
- "log" |
|
| 7 | 6 |
"os" |
| 8 | 7 |
"path/filepath" |
| 9 | 8 |
"syscall" |
| 10 | 9 |
) |
| 11 | 10 |
|
| 12 |
-var ( |
|
| 13 |
- // default mount point options |
|
| 14 |
- defaults = syscall.MS_NOEXEC | syscall.MS_NOSUID | syscall.MS_NODEV |
|
| 15 |
-) |
|
| 11 |
+// default mount point options |
|
| 12 |
+const defaultMountFlags = syscall.MS_NOEXEC | syscall.MS_NOSUID | syscall.MS_NODEV |
|
| 16 | 13 |
|
| 17 | 14 |
func setupNewMountNamespace(rootfs, console string, readonly bool) error {
|
| 18 | 15 |
if err := system.Mount("", "/", "", syscall.MS_SLAVE|syscall.MS_REC, ""); err != nil {
|
| 19 | 16 |
return fmt.Errorf("mounting / as slave %s", err)
|
| 20 | 17 |
} |
| 21 |
- |
|
| 22 | 18 |
if err := system.Mount(rootfs, rootfs, "bind", syscall.MS_BIND|syscall.MS_REC, ""); err != nil {
|
| 23 | 19 |
return fmt.Errorf("mouting %s as bind %s", rootfs, err)
|
| 24 | 20 |
} |
| 25 |
- |
|
| 26 | 21 |
if readonly {
|
| 27 | 22 |
if err := system.Mount(rootfs, rootfs, "bind", syscall.MS_BIND|syscall.MS_REMOUNT|syscall.MS_RDONLY|syscall.MS_REC, ""); err != nil {
|
| 28 | 23 |
return fmt.Errorf("mounting %s as readonly %s", rootfs, err)
|
| 29 | 24 |
} |
| 30 | 25 |
} |
| 31 |
- |
|
| 32 | 26 |
if err := mountSystem(rootfs); err != nil {
|
| 33 | 27 |
return fmt.Errorf("mount system %s", err)
|
| 34 | 28 |
} |
| 35 |
- |
|
| 36 | 29 |
if err := copyDevNodes(rootfs); err != nil {
|
| 37 | 30 |
return fmt.Errorf("copy dev nodes %s", err)
|
| 38 | 31 |
} |
| 39 |
- |
|
| 40 |
- ptmx := filepath.Join(rootfs, "dev/ptmx") |
|
| 41 |
- if err := os.Remove(ptmx); err != nil && !os.IsNotExist(err) {
|
|
| 42 |
- return err |
|
| 43 |
- } |
|
| 44 |
- if err := os.Symlink("pts/ptmx", ptmx); err != nil {
|
|
| 45 |
- return fmt.Errorf("symlink dev ptmx %s", err)
|
|
| 46 |
- } |
|
| 47 |
- |
|
| 48 | 32 |
if err := setupDev(rootfs); err != nil {
|
| 49 | 33 |
return err |
| 50 | 34 |
} |
| 51 |
- |
|
| 52 |
- if err := setupConsole(rootfs, console); err != nil {
|
|
| 35 |
+ if err := setupPtmx(rootfs, console); err != nil {
|
|
| 53 | 36 |
return err |
| 54 | 37 |
} |
| 55 |
- |
|
| 56 | 38 |
if err := system.Chdir(rootfs); err != nil {
|
| 57 | 39 |
return fmt.Errorf("chdir into %s %s", rootfs, err)
|
| 58 | 40 |
} |
| 59 |
- |
|
| 60 | 41 |
if err := system.Mount(rootfs, "/", "", syscall.MS_MOVE, ""); err != nil {
|
| 61 | 42 |
return fmt.Errorf("mount move %s into / %s", rootfs, err)
|
| 62 | 43 |
} |
| 63 |
- |
|
| 64 | 44 |
if err := system.Chroot("."); err != nil {
|
| 65 | 45 |
return fmt.Errorf("chroot . %s", err)
|
| 66 | 46 |
} |
| 67 |
- |
|
| 68 | 47 |
if err := system.Chdir("/"); err != nil {
|
| 69 | 48 |
return fmt.Errorf("chdir / %s", err)
|
| 70 | 49 |
} |
| ... | ... |
@@ -90,13 +69,10 @@ func copyDevNodes(rootfs string) error {
|
| 90 | 90 |
if err != nil {
|
| 91 | 91 |
return err |
| 92 | 92 |
} |
| 93 |
- |
|
| 94 | 93 |
var ( |
| 95 | 94 |
dest = filepath.Join(rootfs, "dev", node) |
| 96 | 95 |
st = stat.Sys().(*syscall.Stat_t) |
| 97 | 96 |
) |
| 98 |
- |
|
| 99 |
- log.Printf("copy %s to %s %d\n", node, dest, st.Rdev)
|
|
| 100 | 97 |
if err := system.Mknod(dest, st.Mode, int(st.Rdev)); err != nil && !os.IsExist(err) {
|
| 101 | 98 |
return fmt.Errorf("copy %s %s", node, err)
|
| 102 | 99 |
} |
| ... | ... |
@@ -134,24 +110,22 @@ func setupConsole(rootfs, console string) error {
|
| 134 | 134 |
if err != nil {
|
| 135 | 135 |
return fmt.Errorf("stat console %s %s", console, err)
|
| 136 | 136 |
} |
| 137 |
- st := stat.Sys().(*syscall.Stat_t) |
|
| 138 |
- |
|
| 139 |
- dest := filepath.Join(rootfs, "dev/console") |
|
| 137 |
+ var ( |
|
| 138 |
+ st = stat.Sys().(*syscall.Stat_t) |
|
| 139 |
+ dest = filepath.Join(rootfs, "dev/console") |
|
| 140 |
+ ) |
|
| 140 | 141 |
if err := os.Remove(dest); err != nil && !os.IsNotExist(err) {
|
| 141 | 142 |
return fmt.Errorf("remove %s %s", dest, err)
|
| 142 | 143 |
} |
| 143 |
- |
|
| 144 | 144 |
if err := os.Chmod(console, 0600); err != nil {
|
| 145 | 145 |
return err |
| 146 | 146 |
} |
| 147 | 147 |
if err := os.Chown(console, 0, 0); err != nil {
|
| 148 | 148 |
return err |
| 149 | 149 |
} |
| 150 |
- |
|
| 151 | 150 |
if err := system.Mknod(dest, (st.Mode&^07777)|0600, int(st.Rdev)); err != nil {
|
| 152 | 151 |
return fmt.Errorf("mknod %s %s", dest, err)
|
| 153 | 152 |
} |
| 154 |
- |
|
| 155 | 153 |
if err := system.Mount(console, dest, "bind", syscall.MS_BIND, ""); err != nil {
|
| 156 | 154 |
return fmt.Errorf("bind %s to %s %s", console, dest, err)
|
| 157 | 155 |
} |
| ... | ... |
@@ -168,10 +142,10 @@ func mountSystem(rootfs string) error {
|
| 168 | 168 |
flags int |
| 169 | 169 |
data string |
| 170 | 170 |
}{
|
| 171 |
- {source: "proc", path: filepath.Join(rootfs, "proc"), device: "proc", flags: defaults},
|
|
| 172 |
- {source: "sysfs", path: filepath.Join(rootfs, "sys"), device: "sysfs", flags: defaults},
|
|
| 171 |
+ {source: "proc", path: filepath.Join(rootfs, "proc"), device: "proc", flags: defaultMountFlags},
|
|
| 172 |
+ {source: "sysfs", path: filepath.Join(rootfs, "sys"), device: "sysfs", flags: defaultMountFlags},
|
|
| 173 | 173 |
{source: "tmpfs", path: filepath.Join(rootfs, "dev"), device: "tmpfs", flags: syscall.MS_NOSUID | syscall.MS_STRICTATIME, data: "mode=755"},
|
| 174 |
- {source: "shm", path: filepath.Join(rootfs, "dev", "shm"), device: "tmpfs", flags: defaults, data: "mode=1777"},
|
|
| 174 |
+ {source: "shm", path: filepath.Join(rootfs, "dev", "shm"), device: "tmpfs", flags: defaultMountFlags, data: "mode=1777"},
|
|
| 175 | 175 |
{source: "devpts", path: filepath.Join(rootfs, "dev", "pts"), device: "devpts", flags: syscall.MS_NOSUID | syscall.MS_NOEXEC, data: "newinstance,ptmxmode=0666,mode=620,gid=5"},
|
| 176 | 176 |
{source: "tmpfs", path: filepath.Join(rootfs, "run"), device: "tmpfs", flags: syscall.MS_NOSUID | syscall.MS_NODEV | syscall.MS_STRICTATIME, data: "mode=755"},
|
| 177 | 177 |
} {
|
| ... | ... |
@@ -189,7 +163,7 @@ func remountProc() error {
|
| 189 | 189 |
if err := system.Unmount("/proc", syscall.MNT_DETACH); err != nil {
|
| 190 | 190 |
return err |
| 191 | 191 |
} |
| 192 |
- if err := system.Mount("proc", "/proc", "proc", uintptr(defaults), ""); err != nil {
|
|
| 192 |
+ if err := system.Mount("proc", "/proc", "proc", uintptr(defaultMountFlags), ""); err != nil {
|
|
| 193 | 193 |
return err |
| 194 | 194 |
} |
| 195 | 195 |
return nil |
| ... | ... |
@@ -201,9 +175,20 @@ func remountSys() error {
|
| 201 | 201 |
return err |
| 202 | 202 |
} |
| 203 | 203 |
} else {
|
| 204 |
- if err := system.Mount("sysfs", "/sys", "sysfs", uintptr(defaults), ""); err != nil {
|
|
| 204 |
+ if err := system.Mount("sysfs", "/sys", "sysfs", uintptr(defaultMountFlags), ""); err != nil {
|
|
| 205 | 205 |
return err |
| 206 | 206 |
} |
| 207 | 207 |
} |
| 208 | 208 |
return nil |
| 209 | 209 |
} |
| 210 |
+ |
|
| 211 |
+func setupPtmx(rootfs, console string) error {
|
|
| 212 |
+ ptmx := filepath.Join(rootfs, "dev/ptmx") |
|
| 213 |
+ if err := os.Remove(ptmx); err != nil && !os.IsNotExist(err) {
|
|
| 214 |
+ return err |
|
| 215 |
+ } |
|
| 216 |
+ if err := os.Symlink("pts/ptmx", ptmx); err != nil {
|
|
| 217 |
+ return fmt.Errorf("symlink dev ptmx %s", err)
|
|
| 218 |
+ } |
|
| 219 |
+ return setupConsole(rootfs, console) |
|
| 220 |
+} |
| ... | ... |
@@ -2,27 +2,16 @@ package main |
| 2 | 2 |
|
| 3 | 3 |
import ( |
| 4 | 4 |
"github.com/dotcloud/docker/pkg/libcontainer" |
| 5 |
-) |
|
| 6 |
- |
|
| 7 |
-const ( |
|
| 8 |
- SIGCHLD = 0x14 |
|
| 9 |
- CLONE_VFORK = 0x00004000 |
|
| 10 |
- CLONE_NEWNS = 0x00020000 |
|
| 11 |
- CLONE_NEWUTS = 0x04000000 |
|
| 12 |
- CLONE_NEWIPC = 0x08000000 |
|
| 13 |
- CLONE_NEWUSER = 0x10000000 |
|
| 14 |
- CLONE_NEWPID = 0x20000000 |
|
| 15 |
- CLONE_NEWNET = 0x40000000 |
|
| 5 |
+ "syscall" |
|
| 16 | 6 |
) |
| 17 | 7 |
|
| 18 | 8 |
var namespaceMap = map[libcontainer.Namespace]int{
|
| 19 |
- "": 0, |
|
| 20 |
- libcontainer.CLONE_NEWNS: CLONE_NEWNS, |
|
| 21 |
- libcontainer.CLONE_NEWUTS: CLONE_NEWUTS, |
|
| 22 |
- libcontainer.CLONE_NEWIPC: CLONE_NEWIPC, |
|
| 23 |
- libcontainer.CLONE_NEWUSER: CLONE_NEWUSER, |
|
| 24 |
- libcontainer.CLONE_NEWPID: CLONE_NEWPID, |
|
| 25 |
- libcontainer.CLONE_NEWNET: CLONE_NEWNET, |
|
| 9 |
+ libcontainer.CLONE_NEWNS: syscall.CLONE_NEWNS, |
|
| 10 |
+ libcontainer.CLONE_NEWUTS: syscall.CLONE_NEWUTS, |
|
| 11 |
+ libcontainer.CLONE_NEWIPC: syscall.CLONE_NEWIPC, |
|
| 12 |
+ libcontainer.CLONE_NEWUSER: syscall.CLONE_NEWUSER, |
|
| 13 |
+ libcontainer.CLONE_NEWPID: syscall.CLONE_NEWPID, |
|
| 14 |
+ libcontainer.CLONE_NEWNET: syscall.CLONE_NEWNET, |
|
| 26 | 15 |
} |
| 27 | 16 |
|
| 28 | 17 |
// getNamespaceFlags parses the container's Namespaces options to set the correct |