Commit 44a706bd by Serge Hallyn Committed by Stéphane Graber

btrfs: support unprivileged destroy

Do this by calling the bdev->destroy() hook from a user namespace configured as the container's. Signed-off-by: 's avatarSerge Hallyn <serge.hallyn@ubuntu.com> Acked-by: 's avatarStéphane Graber <stgraber@ubuntu.com>
parent 2659c7cb
...@@ -1987,10 +1987,41 @@ static int lxc_rmdir_onedev_wrapper(void *data) ...@@ -1987,10 +1987,41 @@ static int lxc_rmdir_onedev_wrapper(void *data)
return lxc_rmdir_onedev(arg); return lxc_rmdir_onedev(arg);
} }
static int do_bdev_destroy(struct lxc_conf *conf)
{
struct bdev *r;
int ret = 0;
r = bdev_init(conf->rootfs.path, conf->rootfs.mount, NULL);
if (!r)
return -1;
if (r->ops->destroy(r) < 0)
ret = -1;
bdev_put(r);
return ret;
}
static int bdev_destroy_wrapper(void *data)
{
struct lxc_conf *conf = data;
if (setgid(0) < 0) {
ERROR("Failed to setgid to 0");
return -1;
}
if (setgroups(0, NULL) < 0)
WARN("Failed to clear groups");
if (setuid(0) < 0) {
ERROR("Failed to setuid to 0");
return -1;
}
return do_bdev_destroy(conf);
}
// do we want the api to support --force, or leave that to the caller? // do we want the api to support --force, or leave that to the caller?
static bool lxcapi_destroy(struct lxc_container *c) static bool lxcapi_destroy(struct lxc_container *c)
{ {
struct bdev *r = NULL;
bool bret = false; bool bret = false;
int ret; int ret;
...@@ -2011,16 +2042,15 @@ static bool lxcapi_destroy(struct lxc_container *c) ...@@ -2011,16 +2042,15 @@ static bool lxcapi_destroy(struct lxc_container *c)
goto out; goto out;
} }
if (!am_unpriv() && c->lxc_conf && c->lxc_conf->rootfs.path && c->lxc_conf->rootfs.mount) { if (c->lxc_conf && c->lxc_conf->rootfs.path && c->lxc_conf->rootfs.mount) {
r = bdev_init(c->lxc_conf->rootfs.path, c->lxc_conf->rootfs.mount, NULL); if (am_unpriv())
if (r) { ret = userns_exec_1(c->lxc_conf, bdev_destroy_wrapper, c->lxc_conf);
if (r->ops->destroy(r) < 0) { else
bdev_put(r); ret = do_bdev_destroy(c->lxc_conf);
if (ret < 0) {
ERROR("Error destroying rootfs for %s", c->name); ERROR("Error destroying rootfs for %s", c->name);
goto out; goto out;
} }
bdev_put(r);
}
} }
mod_all_rdeps(c, false); mod_all_rdeps(c, false);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment