antcolony
All repositories: gitoria
1.2 KB
#!/bin/sh# docker/pivot.sh — mission 028 (ticket antcolony#1): the ONLY part that runs as root, inside the busybox container.# The container bind-mounts the host's / at /host (recursive: /home, /media/STORAGE, /proc, /dev, /tmp …).# 1. make every mount in the CONTAINER's mount namespace private (nothing below propagates to the host),# 2. pivot_root into /host (NOT chroot: the kernel refuses user namespaces to chrooted processes, and Chrome's# sandbox needs them — seen in the m028 probe: "Failed to move to new namespace … Operation not permitted"),# the old busybox root lands on the host's empty /mnt (in this namespace only) and is detached at once,# 3. drop to uid/gid 1000 (mre) with all of mre's groups and exec docker/entrypoint.sh — from here on no root.# Needs cap SYS_ADMIN + seccomp unconfined (docker-compose.yml). Paths: this file is /host<scheduler>/docker/pivot.sh.set -eself="$0"case "$self" in /host/*) ;; *) echo "pivot.sh: REFUSED — expected to be started as /host/<path>/docker/pivot.sh, got $self"; exit 1;; esacdir="${self#/host}"dir="${dir%/*}"mount --make-rprivate /cd /hostpivot_root . mntcd /umount -l /mntexec /usr/bin/setpriv --reuid=1000 --regid=1000 --init-groups -- /bin/bash "$dir/entrypoint.sh"
Branches
- mainmain branch