gitoriaLog in with ident

antcolony

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commita6af7883a6af7883tracker: worker box sees calendar.worldapi.org (login to copy)mrea6af7883/docker/pivot.sh

1.2 KB

  1. #!/bin/sh
  2. # docker/pivot.sh — mission 028 (ticket antcolony#1): the ONLY part that runs as root, inside the busybox container.
  3. # The container bind-mounts the host's / at /host (recursive: /home, /media/STORAGE, /proc, /dev, /tmp …).
  4. # 1. make every mount in the CONTAINER's mount namespace private (nothing below propagates to the host),
  5. # 2. pivot_root into /host (NOT chroot: the kernel refuses user namespaces to chrooted processes, and Chrome's
  6. # sandbox needs them — seen in the m028 probe: "Failed to move to new namespace … Operation not permitted"),
  7. # the old busybox root lands on the host's empty /mnt (in this namespace only) and is detached at once,
  8. # 3. drop to uid/gid 1000 (mre) with all of mre's groups and exec docker/entrypoint.sh — from here on no root.
  9. # Needs cap SYS_ADMIN + seccomp unconfined (docker-compose.yml). Paths: this file is /host<scheduler>/docker/pivot.sh.
  10. set -e
  11. self="$0"
  12. case "$self" in /host/*) ;; *) echo "pivot.sh: REFUSED — expected to be started as /host/<path>/docker/pivot.sh, got $self"; exit 1;; esac
  13. dir="${self#/host}"
  14. dir="${dir%/*}"
  15. mount --make-rprivate /
  16. cd /host
  17. pivot_root . mnt
  18. cd /
  19. umount -l /mnt
  20. exec /usr/bin/setpriv --reuid=1000 --regid=1000 --init-groups -- /bin/bash "$dir/entrypoint.sh"

Branches

Latest commits

  • a6af7883tracker: worker box sees calendar.worldapi.org (login to copy)mre
  • c613d26btemplates: bridges to external components (login.js for ident's selector) are allowed (creator 2026-09-27)mre
  • 9062978ctracker: worker box sees /media/STORAGE/projects/old-tracker read-only (tracker#2 source data)mre
  • 7f9660eeState of 2026-09-27, before the move to gitoriamre