|
Zbigniew Jędrzejewski-Szmek |
d66047 |
From c3f82c64d86432c7d4b0c3abf61b70fd88f1d9dd Mon Sep 17 00:00:00 2001
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
From: Lennart Poettering <lennart@poettering.net>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
Date: Wed, 20 Nov 2013 22:10:42 +0100
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
Subject: [PATCH] nspawn: add new --drop-capability= switch
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
---
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
man/systemd-nspawn.xml | 10 ++++++++++
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
src/nspawn/nspawn.c | 12 ++++++++++--
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
2 files changed, 20 insertions(+), 2 deletions(-)
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
diff --git a/man/systemd-nspawn.xml b/man/systemd-nspawn.xml
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
index ba9e516..c1a5cad 100644
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
--- a/man/systemd-nspawn.xml
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+++ b/man/systemd-nspawn.xml
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -304,6 +304,16 @@
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
</varlistentry>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
<varlistentry>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ <term><option>--drop-capability=</option></term>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ <listitem><para>Specify one or more
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ additional capabilities to drop for
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ the container. This allows running the
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ container with fewer capabilities than
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ the default (see above).</para></listitem>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ </varlistentry>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ <varlistentry>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
<term><option>--link-journal=</option></term>
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
<listitem><para>Control whether the
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
diff --git a/src/nspawn/nspawn.c b/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
index 85bbadf..7346253 100644
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
--- a/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+++ b/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -130,6 +130,7 @@ static int help(void) {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" --read-only Mount the root directory read-only\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" --capability=CAP In addition to the default, retain specified\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" capability\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ " --drop-capability=CAP Drop the specified capability from the default set\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" --link-journal=MODE Link up guest journal, one of no, auto, guest, host\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" -j Equivalent to --link-journal=host\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
" --bind=PATH[:PATH] Bind mount a file or directory from the host into\n"
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -148,6 +149,7 @@ static int parse_argv(int argc, char *argv[]) {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_UUID,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_READ_ONLY,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_CAPABILITY,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ ARG_DROP_CAPABILITY,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_LINK_JOURNAL,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_BIND,
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
ARG_BIND_RO
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -163,6 +165,7 @@ static int parse_argv(int argc, char *argv[]) {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "uuid", required_argument, NULL, ARG_UUID },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "read-only", no_argument, NULL, ARG_READ_ONLY },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "capability", required_argument, NULL, ARG_CAPABILITY },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ { "drop-capability", required_argument, NULL, ARG_DROP_CAPABILITY },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "link-journal", required_argument, NULL, ARG_LINK_JOURNAL },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "bind", required_argument, NULL, ARG_BIND },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
{ "bind-ro", required_argument, NULL, ARG_BIND_RO },
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -247,7 +250,8 @@ static int parse_argv(int argc, char *argv[]) {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
arg_read_only = true;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
break;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
- case ARG_CAPABILITY: {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ case ARG_CAPABILITY:
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ case ARG_DROP_CAPABILITY: {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
char *state, *word;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
size_t length;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
@@ -266,7 +270,11 @@ static int parse_argv(int argc, char *argv[]) {
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
}
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
free(t);
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
- arg_retain |= 1ULL << (uint64_t) cap;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ if (c == ARG_CAPABILITY)
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ arg_retain |= 1ULL << (uint64_t) cap;
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ else
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
+ arg_retain &= ~(1ULL << (uint64_t) cap);
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
}
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
|
|
Zbigniew Jędrzejewski-Szmek |
d66047 |
break;
|