| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157 |
- //go:build !windows
- /*
- Copyright The containerd Authors.
- Licensed under the Apache License, Version 2.0 (the "License");
- you may not use this file except in compliance with the License.
- You may obtain a copy of the License at
- http://www.apache.org/licenses/LICENSE-2.0
- Unless required by applicable law or agreed to in writing, software
- distributed under the License is distributed on an "AS IS" BASIS,
- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- See the License for the specific language governing permissions and
- limitations under the License.
- */
- package containerd
- import (
- "context"
- "errors"
- "github.com/containerd/containerd/runtime/linux/runctypes"
- "github.com/containerd/containerd/runtime/v2/runc/options"
- )
- // WithNoNewKeyring causes tasks not to be created with a new keyring for secret storage.
- // There is an upper limit on the number of keyrings in a linux system
- func WithNoNewKeyring(ctx context.Context, c *Client, ti *TaskInfo) error {
- if CheckRuntime(ti.Runtime(), "io.containerd.runc") {
- if ti.Options == nil {
- ti.Options = &options.Options{}
- }
- opts, ok := ti.Options.(*options.Options)
- if !ok {
- return errors.New("invalid v2 shim create options format")
- }
- opts.NoNewKeyring = true
- } else {
- if ti.Options == nil {
- ti.Options = &runctypes.CreateOptions{}
- }
- opts, ok := ti.Options.(*runctypes.CreateOptions)
- if !ok {
- return errors.New("could not cast TaskInfo Options to CreateOptions")
- }
- opts.NoNewKeyring = true
- }
- return nil
- }
- // WithNoPivotRoot instructs the runtime not to you pivot_root
- func WithNoPivotRoot(_ context.Context, _ *Client, ti *TaskInfo) error {
- if CheckRuntime(ti.Runtime(), "io.containerd.runc") {
- if ti.Options == nil {
- ti.Options = &options.Options{}
- }
- opts, ok := ti.Options.(*options.Options)
- if !ok {
- return errors.New("invalid v2 shim create options format")
- }
- opts.NoPivotRoot = true
- } else {
- if ti.Options == nil {
- ti.Options = &runctypes.CreateOptions{
- NoPivotRoot: true,
- }
- return nil
- }
- opts, ok := ti.Options.(*runctypes.CreateOptions)
- if !ok {
- return errors.New("invalid options type, expected runctypes.CreateOptions")
- }
- opts.NoPivotRoot = true
- }
- return nil
- }
- // WithShimCgroup sets the existing cgroup for the shim
- func WithShimCgroup(path string) NewTaskOpts {
- return func(ctx context.Context, c *Client, ti *TaskInfo) error {
- if CheckRuntime(ti.Runtime(), "io.containerd.runc") {
- if ti.Options == nil {
- ti.Options = &options.Options{}
- }
- opts, ok := ti.Options.(*options.Options)
- if !ok {
- return errors.New("invalid v2 shim create options format")
- }
- opts.ShimCgroup = path
- } else {
- if ti.Options == nil {
- ti.Options = &runctypes.CreateOptions{}
- }
- opts, ok := ti.Options.(*runctypes.CreateOptions)
- if !ok {
- return errors.New("could not cast TaskInfo Options to CreateOptions")
- }
- opts.ShimCgroup = path
- }
- return nil
- }
- }
- // WithUIDOwner allows console I/O to work with the remapped UID in user namespace
- func WithUIDOwner(uid uint32) NewTaskOpts {
- return func(ctx context.Context, c *Client, ti *TaskInfo) error {
- if CheckRuntime(ti.Runtime(), "io.containerd.runc") {
- if ti.Options == nil {
- ti.Options = &options.Options{}
- }
- opts, ok := ti.Options.(*options.Options)
- if !ok {
- return errors.New("invalid v2 shim create options format")
- }
- opts.IoUid = uid
- } else {
- if ti.Options == nil {
- ti.Options = &runctypes.CreateOptions{}
- }
- opts, ok := ti.Options.(*runctypes.CreateOptions)
- if !ok {
- return errors.New("could not cast TaskInfo Options to CreateOptions")
- }
- opts.IoUid = uid
- }
- return nil
- }
- }
- // WithGIDOwner allows console I/O to work with the remapped GID in user namespace
- func WithGIDOwner(gid uint32) NewTaskOpts {
- return func(ctx context.Context, c *Client, ti *TaskInfo) error {
- if CheckRuntime(ti.Runtime(), "io.containerd.runc") {
- if ti.Options == nil {
- ti.Options = &options.Options{}
- }
- opts, ok := ti.Options.(*options.Options)
- if !ok {
- return errors.New("invalid v2 shim create options format")
- }
- opts.IoGid = gid
- } else {
- if ti.Options == nil {
- ti.Options = &runctypes.CreateOptions{}
- }
- opts, ok := ti.Options.(*runctypes.CreateOptions)
- if !ok {
- return errors.New("could not cast TaskInfo Options to CreateOptions")
- }
- opts.IoGid = gid
- }
- return nil
- }
- }
|