Repository navigation
Conversation
…wn ipc, uts and cgroup namespaces, as the architecture says docs/architecture.md gives zones their own user, pid, ipc, uts, mount, cgroup and time namespaces, and their own network namespace. The root launcher check that reads a running zone's pid 1 from the host compared five of them with the host's pid 1: user, pid, mnt, net and time. Nothing checked ipc or cgroup at run time, and uts only through the zone's hostname. It now compares all eight, so a zone that shared any of them with the host fails the check.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
docs/architecture.mdsays every zone gets its own user, pid, ipc, uts, mount, cgroup and time namespaces, plus its own network namespace. The launcher suite's T11 runs as root and reads a running zone's pid 1 from the host. It compared only five of the zone's namespaces with the host's pid 1: user, pid, mnt, net and time.Nothing checked the ipc or cgroup namespace at run time, anywhere:
adversarial.shonly checks thatisolate.rsnames the flags. The uts namespace was checked only indirectly, through J9's hostname. So a launch that lostCLONE_NEWIPC(SysV shared memory and message queues shared with zone 0) orCLONE_NEWCGROUPwould have passed every suite.What changed
T11 compares all eight namespaces (
user pid mnt net time ipc uts cgroup) between the zone's pid 1 and the host's pid 1, and its pass line names them.docs/architecture.mdneeds no change: each row of its zone table, and each claim of what a zone cannot do, now has a check behind it. While checking, I found thatcompartments/README.mdneeds none either: each of its five "cannot" claims has its own section incompartments/tests/adversarial.sh, and its example's limits are enforced by zones-check (pids-limit,cpu-max-set) and launcher F5 (io_max).How the run proves it
T11 runs in the Distro run's zones-test, step 3, where the launcher suite runs as root on the target kernel.
launcher suite exit 0and the accepted-gaps line together carry T11 passing with all eight namespaces compared.