Module: OsCtld::Utils::SwitchUser

Instance Method Summary collapse

Instance Method Details

#ct_attach(ct, *args) ⇒ Object



43
44
45
46
47
48
49
50
51
52
53
54
55
56
# File 'lib/osctld/utils/switch_user.rb', line 43

def ct_attach(ct, *args)
  {
    cmd: ::OsCtld.bin('osctld-ct-exec'),
    args: args.map(&:to_s),
    env: Hash[ENV.select { |k,_v| k.start_with?('BUNDLE') || k.start_with?('GEM') }],
    settings: {
      user: ct.user.sysusername,
      ugid: ct.user.ugid,
      homedir: ct.user.homedir,
      cgroup_path: ct.cgroup_path,
      prlimits: ct.prlimits.export,
    },
  }
end

#ct_control(ct, cmd, opts = {}) ⇒ Object



6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# File 'lib/osctld/utils/switch_user.rb', line 6

def ct_control(ct, cmd, opts = {})
  r, w = IO.pipe

  ct_opts = {
    lxc_home: ct.lxc_home,
    user_home: ct.user.homedir,
    log_file: ct.log_path,
  }

  pid = SwitchUser.fork_and_switch_to(
    ct.user.sysusername,
    ct.user.ugid,
    ct.user.homedir,
    ct.cgroup_path,
    prlimits: ct.prlimits.export,
  ) do
    r.close

    ret = SwitchUser::ContainerControl.run(cmd, opts, ct_opts)
    w.write(ret.to_json + "\n")

    exit
  end

  w.close

  begin
    ret = JSON.parse(r.readline, symbolize_names: true)
    Process.wait(pid)
    ret

  rescue EOFError
    Process.wait(pid)
    {status: false, message: 'user runner failed'}
  end
end

#ct_exec(ct, opts) ⇒ Object



58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
# File 'lib/osctld/utils/switch_user.rb', line 58

def ct_exec(ct, opts)
  if ct.running?
    ct_control(ct, :ct_exec_running, {
      id: ct.id,
      cmd: opts[:cmd],
      stdin: opts[:stdin],
      stdout: opts[:stdout],
      stderr: opts[:stderr],
    })

  elsif !ct.running? && opts[:network]
    ct.mount

    init = init_script(ct)

    begin
      ct_control(ct, :ct_exec_network, {
        id: ct.id,
        init_script: File.join('/', File.basename(init.path)),
        net_config: NetConfig.create(ct),
        cmd: opts[:cmd],
        stdin: opts[:stdin],
        stdout: opts[:stdout],
        stderr: opts[:stderr],
      })
    ensure
      unlink_file(init.path)
    end

  else
    ct_control(ct, :ct_exec_run, {
      id: ct.id,
      cmd: opts[:cmd],
      stdin: opts[:stdin],
      stdout: opts[:stdout],
      stderr: opts[:stderr],
    })
  end
end

#ct_runscript(ct, opts) ⇒ Object



98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
# File 'lib/osctld/utils/switch_user.rb', line 98

def ct_runscript(ct, opts)
  script = Tempfile.create(['.runscript', '.sh'], ct.rootfs)
  script.chmod(0500)

  File.open(opts[:script], 'r') { |f| IO.copy_stream(f, script) }
  script.close

  if ct.running?
    ct_control(ct, :ct_runscript_running, {
      id: ct.id,
      script: File.join('/', File.basename(script.path)),
      stdin: opts[:stdin],
      stdout: opts[:stdout],
      stderr: opts[:stderr],
    })

  elsif !ct.running? && opts[:network]
    ct.mount

    init = init_script(ct)

    begin
      ct_control(ct, :ct_runscript_network, {
        id: ct.id,
        init_script: File.join('/', File.basename(init.path)),
        net_config: NetConfig.create(ct),
        script: File.join('/', File.basename(script.path)),
        stdin: opts[:stdin],
        stdout: opts[:stdout],
        stderr: opts[:stderr],
      })
    ensure
      unlink_file(init.path)
    end

  else
    ct_control(ct, :ct_runscript_run, {
      id: ct.id,
      script: File.join('/', File.basename(script.path)),
      stdin: opts[:stdin],
      stdout: opts[:stdout],
      stderr: opts[:stderr],
    })
  end

ensure
  script.close
  unlink_file(script.path)
end

#ct_syscmd(ct, cmd, opts = {}) ⇒ Object

Run a command `cmd` within container `ct`

Parameters:

  • ct (Container)
  • cmd (String)

    command to execute in shell

  • opts (Hash) (defaults to: {})

    options

Options Hash (opts):

  • :stdin (IO)
  • :stdout (IO)
  • :stderr (IO)
  • :run (Boolean)

    run the container if it is stopped?

  • :network (Boolean)

    setup network if the container is run?

  • :valid_rcs (Array<Integer>, Symbol)


158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
# File 'lib/osctld/utils/switch_user.rb', line 158

def ct_syscmd(ct, cmd, opts = {})
  opts[:valid_rcs] ||= []
  log(:work, ct, cmd)

  in_r, in_w = nil
  out_r, out_w = IO.pipe

  if opts[:stdin].is_a?(String)
    in_r, in_w = IO.pipe
    in_w.write(opts[:stdin])
    in_w.close

  elsif opts[:stdin]
    in_r = opts[:stdin]
  end

  if ct.running?
    ct_cmd = :ct_exec_running

  elsif opts[:run] && opts[:network]
    ct_cmd = :ct_exec_network

  elsif opts[:run]
    ct_cmd = :ct_exec_run

  else
    raise OsCtld::SystemCommandFailed, 'Container is not running'
  end

  ret = ct_control(ct, ct_cmd, {
    id: ct.id,
    cmd: cmd,
    stdin: in_r,
    stdout: out_w,
    stderr: out_w,
  })

  in_r.close if in_r && opts[:stdin].is_a?(String)
  out_w.close
  out = out_r.read
  out_r.close

  if !ret[:status]
    raise OsCtld::SystemCommandFailed, "Command '#{cmd}' within CT #{ct.id} failed"

  elsif ret[:output][:exitstatus] != 0 && \
        opts[:valid_rcs] != :all && \
        !opts[:valid_rcs].include?(ret[:output][:exitstatus])
    raise OsCtld::SystemCommandFailed,
          "Command '#{cmd}' within CT #{ct.id} failed with exit code "+
          "#{ret[:output][:exitstatus]}: #{out}"
  end

  {output: out, exitstatus: ret[:output][:exitstatus]}
end

#init_script(ct) ⇒ Object



214
215
216
217
218
219
220
221
222
# File 'lib/osctld/utils/switch_user.rb', line 214

def init_script(ct)
  f = Tempfile.create(['.runscript', '.sh'], ct.rootfs)
  f.chmod(0500)
  f.puts('#!/bin/sh')
  f.puts('echo ready')
  f.puts('read _')
  f.close
  f
end


224
225
226
227
228
# File 'lib/osctld/utils/switch_user.rb', line 224

def unlink_file(path)
  File.unlink(path)
rescue SystemCallError
  # pass
end