2020-05-04 20:46:48 +00:00
|
|
|
// +build linux
|
|
|
|
|
|
|
|
package fs2
|
|
|
|
|
|
|
|
import (
|
|
|
|
"github.com/opencontainers/runc/libcontainer/cgroups/ebpf"
|
|
|
|
"github.com/opencontainers/runc/libcontainer/cgroups/ebpf/devicefilter"
|
|
|
|
"github.com/opencontainers/runc/libcontainer/configs"
|
2021-04-14 18:11:13 +00:00
|
|
|
"github.com/opencontainers/runc/libcontainer/devices"
|
|
|
|
"github.com/opencontainers/runc/libcontainer/userns"
|
|
|
|
|
2020-05-04 20:46:48 +00:00
|
|
|
"github.com/pkg/errors"
|
|
|
|
"golang.org/x/sys/unix"
|
|
|
|
)
|
|
|
|
|
2021-04-14 18:11:13 +00:00
|
|
|
func isRWM(perms devices.Permissions) bool {
|
2020-08-10 17:43:49 +00:00
|
|
|
var r, w, m bool
|
|
|
|
for _, perm := range perms {
|
|
|
|
switch perm {
|
2020-05-04 20:46:48 +00:00
|
|
|
case 'r':
|
|
|
|
r = true
|
|
|
|
case 'w':
|
|
|
|
w = true
|
|
|
|
case 'm':
|
|
|
|
m = true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return r && w && m
|
|
|
|
}
|
|
|
|
|
2021-04-14 18:11:13 +00:00
|
|
|
// This is similar to the logic applied in crun for handling errors from bpf(2)
|
|
|
|
// <https://github.com/containers/crun/blob/0.17/src/libcrun/cgroup.c#L2438-L2470>.
|
2021-06-18 20:46:09 +00:00
|
|
|
func canSkipEBPFError(r *configs.Resources) bool {
|
2021-04-14 18:11:13 +00:00
|
|
|
// If we're running in a user namespace we can ignore eBPF rules because we
|
|
|
|
// usually cannot use bpf(2), as well as rootless containers usually don't
|
|
|
|
// have the necessary privileges to mknod(2) device inodes or access
|
|
|
|
// host-level instances (though ideally we would be blocking device access
|
|
|
|
// for rootless containers anyway).
|
|
|
|
if userns.RunningInUserNS() {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
|
|
|
// We cannot ignore an eBPF load error if any rule if is a block rule or it
|
|
|
|
// doesn't permit all access modes.
|
|
|
|
//
|
|
|
|
// NOTE: This will sometimes trigger in cases where access modes are split
|
|
|
|
// between different rules but to handle this correctly would require
|
|
|
|
// using ".../libcontainer/cgroup/devices".Emulator.
|
2021-06-18 20:46:09 +00:00
|
|
|
for _, dev := range r.Devices {
|
2021-04-14 18:11:13 +00:00
|
|
|
if !dev.Allow || !isRWM(dev.Permissions) {
|
2020-05-04 20:46:48 +00:00
|
|
|
return false
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2021-06-18 20:46:09 +00:00
|
|
|
func setDevices(dirPath string, r *configs.Resources) error {
|
|
|
|
if r.SkipDevices {
|
2020-08-10 17:43:49 +00:00
|
|
|
return nil
|
2020-05-04 20:46:48 +00:00
|
|
|
}
|
2021-06-18 20:46:09 +00:00
|
|
|
insts, license, err := devicefilter.DeviceFilter(r.Devices)
|
2020-05-04 20:46:48 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2021-07-02 08:43:15 +00:00
|
|
|
dirFD, err := unix.Open(dirPath, unix.O_DIRECTORY|unix.O_RDONLY, 0o600)
|
2020-05-04 20:46:48 +00:00
|
|
|
if err != nil {
|
|
|
|
return errors.Errorf("cannot get dir FD for %s", dirPath)
|
|
|
|
}
|
|
|
|
defer unix.Close(dirFD)
|
|
|
|
if _, err := ebpf.LoadAttachCgroupDeviceFilter(insts, license, dirFD); err != nil {
|
2021-06-18 20:46:09 +00:00
|
|
|
if !canSkipEBPFError(r) {
|
2020-05-04 20:46:48 +00:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|