Unverified Commit af1893bf by Stéphane Graber Committed by GitHub

Merge pull request #2906 from brauner/2019-03-12/namespace_switching

utils: improve switch_to_ns()
parents c6494c4b b280bc38
...@@ -149,6 +149,7 @@ ...@@ -149,6 +149,7 @@
#define LXC_LINELEN 4096 #define LXC_LINELEN 4096
#define LXC_IDMAPLEN 4096 #define LXC_IDMAPLEN 4096
#define LXC_MAX_BUFFER 4096 #define LXC_MAX_BUFFER 4096
#define LXC_NAMESPACE_NAME_MAX 256
/* /proc/ = 6 /* /proc/ = 6
* + * +
......
...@@ -693,15 +693,18 @@ int detect_shared_rootfs(void) ...@@ -693,15 +693,18 @@ int detect_shared_rootfs(void)
bool switch_to_ns(pid_t pid, const char *ns) bool switch_to_ns(pid_t pid, const char *ns)
{ {
int fd, ret; __do_close_prot_errno int fd = -EBADF;
char nspath[PATH_MAX]; int ret;
char nspath[STRLITERALLEN("/proc//ns/")
+ INTTYPE_TO_STRLEN(pid_t)
+ LXC_NAMESPACE_NAME_MAX];
/* Switch to new ns */ /* Switch to new ns */
ret = snprintf(nspath, PATH_MAX, "/proc/%d/ns/%s", pid, ns); ret = snprintf(nspath, sizeof(nspath), "/proc/%d/ns/%s", pid, ns);
if (ret < 0 || ret >= PATH_MAX) if (ret < 0 || ret >= sizeof(nspath))
return false; return false;
fd = open(nspath, O_RDONLY); fd = open(nspath, O_RDONLY | O_CLOEXEC);
if (fd < 0) { if (fd < 0) {
SYSERROR("Failed to open \"%s\"", nspath); SYSERROR("Failed to open \"%s\"", nspath);
return false; return false;
...@@ -709,12 +712,11 @@ bool switch_to_ns(pid_t pid, const char *ns) ...@@ -709,12 +712,11 @@ bool switch_to_ns(pid_t pid, const char *ns)
ret = setns(fd, 0); ret = setns(fd, 0);
if (ret) { if (ret) {
SYSERROR("Failed to set process %d to \"%s\" of %d.", pid, ns, fd); SYSERROR("Failed to set process %d to \"%s\" of %d.", pid, ns,
close(fd); fd);
return false; return false;
} }
close(fd);
return true; return true;
} }
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment